Okay, like I said, I couldn't run vundofix but here's the logs.Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:59:13 PM, on 3/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\OneStepSearch\onestep.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\OneStepSearch\onestep.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AdvancedCleaner Free\UADC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AdvancedCleaner Free\ian_monitor.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\MySoftware\NewsFlsh.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\PROGRA~1\Yahoo!\browser\ybrowser.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\TeamViewer3\TeamViewer.exe
C:\PROGRA~1\Yahoo!\browser\ybrowser.exe
C:\Documents and Settings\harold\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?T...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cus...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?T...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/cus...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cus...
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb106\Dealio.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
O4 - HKLM\..\Run: [a442b0f1] rundll32.exe "C:\WINDOWS\system32\girtrfiv.dll",b
O4 - HKLM\..\Run: [AdvancedCleaner Free] "C:\Program Files\AdvancedCleaner Free\UADC.exe" /min
O4 - HKLM\..\Run: [SM_IAN] C:\Program Files\AdvancedCleaner Free\ian_monitor.exe
O4 - HKLM\..\Run: [BMa771836d] Rundll32.exe "C:\WINDOWS\system32\vmohugeu.dll",s
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: MySoftware NewsFlash.lnk = C:\Program Files\Common Files\MySoftware\NewsFlsh.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: Compare Prices with &Dealio - C:\Program Files\Dealio\kb106\res\DealioSearch.html
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Acez.com - Download Free Screen Savers - {88E50F1D-4790-4C6B-BEE3-D54E46B6EEF6} - C:\WINDOWS\acezlink.htm
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb106\Dealio.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows
O23 - Service: OneStep Search Service - OneStepSearch.net, Inc. - C:\Program Files\OneStepSearch\onestep.exe
--
End of file - 6246 bytes
and here's the combofix log
ComboFix 08-03-09.1 - harold 2008-03-09 15:16:49.1 - NTFSx86
Running from: C:\Documents and Settings\harold\Desktop\ComboFix.exe
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
[i] ADS - svchost.exe: deleted 228 bytes in 1 streams. [/i]
[i] ADS - ntoskrnl.exe: deleted 68 bytes in 1 streams. [/i]
[i] ADS - explorer.exe: deleted 132 bytes in 1 streams. [/i]
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\bravesentry
C:\Program Files\bravesentry\BraveSentry.exe
C:\Program Files\bravesentry\BraveSentry.lic
C:\Program Files\bravesentry\BraveSentry0.bs
C:\Program Files\bravesentry\BraveSentry0.dll
C:\Program Files\bravesentry\BraveSentry1.bs
C:\Program Files\bravesentry\BraveSentry2.dll
C:\Program Files\bravesentry\BraveSentry3.dll
C:\Program Files\bravesentry\Uninstall.exe
C:\Program Files\Internet Explorer\lavulaxas.dll
C:\Program Files\screensavers.com
C:\Program Files\screensavers.com\ActiveDesktop\bin\ActiveDesktopExe.exe
C:\Program Files\screensavers.com\SSSInstaller\bin\screensavers.exe
C:\Program Files\screensavers.com\SSSInstaller\bin\sinstaller3.exe
C:\Program Files\screensavers.com\SSSInstaller\bin\SSSInstaller.dll
C:\Program Files\screensavers.com\SSSUninst.exe
C:\Program Files\Windows Media Player\niqaxidiq89104.dll
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\isgTi19
C:\Temp\isgTi19\lPig.log
C:\WINDOWS\BMa771836d.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\a1
C:\WINDOWS\system32\aakohcop.dll
C:\WINDOWS\system32\aakypsfg.dll
C:\WINDOWS\system32\adeeg.ini
C:\WINDOWS\system32\adeeg.ini2
C:\WINDOWS\system32\aeuwxrsy.dll
C:\WINDOWS\system32\barjphok.dll
C:\WINDOWS\system32\bnwfigtv.dll
C:\WINDOWS\system32\cxxkpopc.dll
C:\WINDOWS\system32\dektimok.dll
C:\WINDOWS\system32\dlfchsex.dll
C:\WINDOWS\system32\eifusoln.dll
C:\WINDOWS\system32\emrdrnxp.ini
C:\WINDOWS\system32\euqxwvrc.dll
C:\WINDOWS\system32\fbeyiqey.dll
C:\WINDOWS\system32\fnotwboi.ini
C:\WINDOWS\system32\foqiyjxu.ini
C:\WINDOWS\system32\fwstwgxt.dll
C:\WINDOWS\system32\gchkgxvn.dll
C:\WINDOWS\system32\geeda.dll
C:\WINDOWS\system32\girtrfiv.dll
C:\WINDOWS\system32\hkdjynup.ini
C:\WINDOWS\system32\ilxvgvou.dll
C:\WINDOWS\system32\ipsqyfyn.dll
C:\WINDOWS\system32\iunnsvfy.ini
C:\WINDOWS\system32\jlngbygb.dll
C:\WINDOWS\system32\kvckoygc.ini
C:\WINDOWS\system32\kvwvmxsj.dll
C:\WINDOWS\system32\kyhnxfkk.dll
C:\WINDOWS\system32\lptpgxkx.dll
C:\WINDOWS\system32\lseapteo.dll
C:\WINDOWS\system32\lskjhlva.dll
C:\WINDOWS\system32\mbyqcaih.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mfaehecl.dll
C:\WINDOWS\system32\mwqnibgf.ini
C:\WINDOWS\system32\mxljiwmc.dll
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\nsksbqvd.ini
C:\WINDOWS\system32\nxcubkfe.ini
C:\WINDOWS\system32\oetpaesl.ini
C:\WINDOWS\system32\oxqcqgdr.dll
C:\WINDOWS\system32\p9
C:\WINDOWS\system32\p9\liopud89104.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pfyhfiuj.ini
C:\WINDOWS\system32\punyjdkh.dll
C:\WINDOWS\system32\qmduohum.dll
C:\WINDOWS\system32\qomklli.dll
C:\WINDOWS\system32\qxmnixve.dll
C:\WINDOWS\system32\rmrqvrif.dll
C:\WINDOWS\system32\sighbgmx.ini
C:\WINDOWS\system32\sklxbbgc.dll
C:\WINDOWS\system32\snqjlitt.dll
C:\WINDOWS\system32\uayygheq.dll
C:\WINDOWS\system32\ujajrcud.dll
C:\WINDOWS\system32\unuvbjwa.dll
C:\WINDOWS\system32\uorhhjuc.dll
C:\WINDOWS\system32\urqqqrs.dll
C:\WINDOWS\system32\usmwcego.dll
C:\WINDOWS\system32\utixhyri.dll
C:\WINDOWS\system32\uxjyiqof.dll
C:\WINDOWS\system32\v6
C:\WINDOWS\system32\vifrtrig.ini
C:\WINDOWS\system32\vllyrtoy.dll
C:\WINDOWS\system32\vmohugeu.dll
C:\WINDOWS\system32\w11
C:\WINDOWS\system32\w11\hiba3133.exe
C:\WINDOWS\system32\waoupilw.dll
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\wsnpoem
C:\WINDOWS\system32\wwcennky.ini
C:\WINDOWS\system32\xhyjigvv.ini
C:\WINDOWS\system32\xknbbahw.ini
C:\WINDOWS\system32\xnesrjkq.dll
C:\WINDOWS\system32\yknnecww.dll
C:\WINDOWS\system32\yykmfvoo.dll
C:\WINDOWS\system32\zaahufmp.dll
C:\WINDOWS\tk58.exe
.
((((((((((((((((((((((((( Files Created from 2008-02-10 to 2008-03-10 )))))))))))))))))))))))))))))))
.
2008-03-09 15:05 . 2008-03-09 15:06 <DIR> d-------- C:\ComboFix[1]
2008-03-09 00:46 . 2008-03-09 12:39 <DIR> d-------- C:\Documents and Settings\Administrator.HOME-E1E53A042E\Application Data\Yahoo!
2008-03-08 15:16 . 2008-03-08 19:30 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-03-08 02:42 . 2008-03-08 02:46 <DIR> d-------- C:\Program Files\AdvancedCleaner Free
2008-03-08 01:49 . 2008-03-08 19:33 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
2008-03-07 20:57 . 2008-03-07 20:57 <DIR> d-------- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\TeamViewer
2008-03-07 20:53 . 2008-03-07 20:53 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2008-03-07 20:29 . 2008-03-08 21:32 <DIR> d-------- C:\Program Files\TeamViewer3
2008-03-07 20:29 . 2008-03-07 20:29 <DIR> d-------- C:\Documents and Settings\harold\Application Data\TeamViewer
2008-03-07 13:18 . 2008-03-07 20:16 1,307,355 ---hs---- C:\WINDOWS\system32\ospdmdka.ini
2008-03-06 13:17 . 2008-03-07 13:17 1,307,115 ---hs---- C:\WINDOWS\system32\grscsqje.ini
2008-03-04 13:12 . 2008-03-05 13:12 1,308,214 ---hs---- C:\WINDOWS\system32\untaweop.ini
2008-03-01 10:45 . 2008-03-01 10:45 3,120 --a------ C:\WINDOWS\D9H7ADCC.ocx
2008-02-20 12:07 . 2008-02-20 12:07 26,048 --a------ C:\WINDOWS\system32\tuvtrrq.dll
2008-02-19 00:25 . 2008-03-09 15:17 20,612 ---hs---- C:\WINDOWS\system32\zaahufmp.dllbox
2008-02-18 12:13 . 2008-03-09 15:20 <DIR> d-------- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-08 03:56 --------- d-----w C:\Program Files\Stamps.com Internet Postage
2008-03-04 22:53 --------- d-----w C:\Program Files\SiteError Search
2008-03-04 22:53 --------- d-----w C:\Program Files\OneStepSearch
2008-03-01 16:41 --------- d-----w C:\Program Files\McAfee AntiSpyware 1.00 Install
2008-02-25 16:32 --------- d-----w C:\Documents and Settings\harold\Application Data\AdobeUM
2008-02-19 18:58 --------- d-----w C:\Program Files\BroadJump
2008-02-19 18:52 --------- d-----w C:\Program Files\Haunted House Horrors Screen Saver 1.3
2008-02-19 18:51 --------- d-----w C:\Program Files\DivX
2008-01-27 18:21 --------- d-----w C:\Documents and Settings\harold\Application Data\Creative
2007-05-19 00:50 1,174,284 ----a-w C:\Documents and Settings\Harold Millsap\Application Data\Install.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-01 18:11 4670968]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 05:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00 455168]
"YBrowser"="C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 16:19 129536]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-26 10:15 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-26 10:15 536576]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2003-10-30 01:46 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2003-10-30 01:33 118784]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2004-04-30 10:32 208958]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-04-21 11:28 286720]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-05-25 19:27 98304]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-07-30 08:33 286720]
"au"="C:\Program Files\Dealio\DealioAU.exe" [2007-06-27 12:46 238936]
"AdvancedCleaner Free"="C:\Program Files\AdvancedCleaner Free\UADC.exe" [2007-10-02 17:11 1558528]
"SM_IAN"="C:\Program Files\AdvancedCleaner Free\ian_monitor.exe" [2007-12-19 11:59 241152]
C:\Documents and Settings\harold\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2008-01-25 17:39:53 225280]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
AT&T Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2007-01-07 08:11:26 217088]
MySoftware NewsFlash.lnk - C:\Program Files\Common Files\MySoftware\NewsFlsh.exe [2007-11-24 15:26:14 261120]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2004-01-28 23:36:18 57344]
ymetray.lnk - C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2006-10-03 11:04:38 54776]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\TeamViewer3\\TeamViewer.exe"=
R2 OneStep Search Service;OneStep Search Service;"C:\Program Files\OneStepSearch\onestep.exe" "C:\Program Files\OneStepSearch\onestep.dll" Service []
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-09 17:16:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????9?4?4?8??P???? ???B???????????????B? ??????
SM_IAN = C:\Program Files\AdvancedCleaner Free\ian_monitor.exe??|??????????@???@????????????????|??@?????????p???????? A?3??|???|??C???@???@???????C????????|??@?????????,?????@???@?d???u)?|??@??????????)?|???|??C???@?3??|??????C???@???@?????????? A????|??????@?d??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
r Running Proce
.
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\OneStepSearch\onestep.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\OneStepSearch\onestep.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
.
**************************************************************************
.
Completion time: 2008-03-09 17:22:28 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-10 00:22:22
.
2008-02-14 11:06:22 --- E O F ---
Thanks so much, it's already made it so much better. All the files are already gone in the documents. There's still those icons on the desktop though, they don't look like they're in use though. Let me know, thanks.