OK, another job done and logs below:
vundofix
VundoFix V5.1.1
Running as SYSTEM
from c:\windows\system32\VundoFix.exe
Checking Java version...
Java version is 1.5.0.3
Scan started at 18:47:38 10/07/2006
Listing files found while scanning....
C:\windows\system32\byxyawt.dll
C:\windows\system32\efcbaby.dll
C:\windows\system32\gebcbby.dll
C:\windows\system32\gebxxxy.dll
C:\windows\system32\iifcaba.dll
C:\windows\system32\iifdayy.dll
C:\windows\system32\khfggdd.dll
C:\windows\system32\ljjgfca.dll
C:\windows\system32\mljjhgd.dll
C:\windows\system32\nnnnoop.dll
C:\windows\system32\opnkkhf.dll
C:\windows\system32\opnligh.dll
C:\windows\system32\rqrqnoo.dll
C:\windows\system32\rqrqpqr.dll
C:\windows\system32\ssqqoom.dll
C:\windows\system32\ssqqrqo.dll
C:\windows\system32\tuvuvsq.dll
C:\windows\system32\urqnn.dll
C:\windows\system32\nnqru.ini
C:\windows\system32\nnqru.bak2
C:\windows\system32\nnqru.ini2
C:\windows\system32\nnqru.tmp
C:\windows\system32\wvusrrr.dll
C:\windows\system32\yaywtts.dll
C:\windows\system32\yayxwus.dll
C:\windows\system32\yayxxuu.dll
Beginning removal...
The process smss.exe was successfully stopped
The process winlogon.exe was successfully stopped
The process explorer.exe was successfully stopped
The process iexplore.exe was successfully stopped
The process rundll32.exe was successfully stopped
Attempting to delete C:\windows\system32\byxyawt.dll
C:\windows\system32\byxyawt.dll Has been deleted!
Attempting to delete C:\windows\system32\efcbaby.dll
C:\windows\system32\efcbaby.dll Has been deleted!
Attempting to delete C:\windows\system32\gebcbby.dll
C:\windows\system32\gebcbby.dll Has been deleted!
Attempting to delete C:\windows\system32\gebxxxy.dll
C:\windows\system32\gebxxxy.dll Has been deleted!
Attempting to delete C:\windows\system32\iifcaba.dll
C:\windows\system32\iifcaba.dll Has been deleted!
Attempting to delete C:\windows\system32\iifdayy.dll
C:\windows\system32\iifdayy.dll Has been deleted!
Attempting to delete C:\windows\system32\khfggdd.dll
C:\windows\system32\khfggdd.dll Has been deleted!
Attempting to delete C:\windows\system32\ljjgfca.dll
C:\windows\system32\ljjgfca.dll Has been deleted!
Attempting to delete C:\windows\system32\mljjhgd.dll
C:\windows\system32\mljjhgd.dll Has been deleted!
Attempting to delete C:\windows\system32\nnnnoop.dll
C:\windows\system32\nnnnoop.dll Has been deleted!
Attempting to delete C:\windows\system32\opnkkhf.dll
C:\windows\system32\opnkkhf.dll Has been deleted!
Attempting to delete C:\windows\system32\opnligh.dll
C:\windows\system32\opnligh.dll Has been deleted!
Attempting to delete C:\windows\system32\rqrqnoo.dll
C:\windows\system32\rqrqnoo.dll Has been deleted!
Attempting to delete C:\windows\system32\rqrqpqr.dll
C:\windows\system32\rqrqpqr.dll Has been deleted!
Attempting to delete C:\windows\system32\ssqqoom.dll
C:\windows\system32\ssqqoom.dll Has been deleted!
Attempting to delete C:\windows\system32\ssqqrqo.dll
C:\windows\system32\ssqqrqo.dll Has been deleted!
Attempting to delete C:\windows\system32\tuvuvsq.dll
C:\windows\system32\tuvuvsq.dll Has been deleted!
Attempting to delete C:\windows\system32\urqnn.dll
C:\windows\system32\urqnn.dll Has been deleted!
Attempting to delete C:\windows\system32\nnqru.ini
C:\windows\system32\nnqru.ini Has been deleted!
Attempting to delete C:\windows\system32\nnqru.bak2
C:\windows\system32\nnqru.bak2 Has been deleted!
Attempting to delete C:\windows\system32\nnqru.ini2
C:\windows\system32\nnqru.ini2 Has been deleted!
Attempting to delete C:\windows\system32\nnqru.tmp
C:\windows\system32\nnqru.tmp Has been deleted!
Attempting to delete C:\windows\system32\wvusrrr.dll
C:\windows\system32\wvusrrr.dll Has been deleted!
Attempting to delete C:\windows\system32\yaywtts.dll
C:\windows\system32\yaywtts.dll Has been deleted!
Attempting to delete C:\windows\system32\yayxwus.dll
C:\windows\system32\yayxwus.dll Has been deleted!
Attempting to delete C:\windows\system32\yayxxuu.dll
C:\windows\system32\yayxxuu.dll Has been deleted!
Performing Repairs to the registry.
Done!
hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 18:58:07, on 10/07/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\blueyonder\PCguard\fws.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\blueyonder\PCguard advisor\PCguardadvisor.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\blueyonder\PCguard\Rps.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\Program Files\TClock\TClock.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\sllights.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about
:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about
:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.blueyonder.co.uk/blueyonder/index.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://bt.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://uk.red.clientapps.yahoo.com/c...o/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about
:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about
:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://uk.red.clientapps.yahoo.com/c...rch.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by blueyonder
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\system32\khfggdd.dll (file missing)
O2 - BHO: (no name) - {DD8E4C55-280A-43DB-83B3-484E36EA43AC} - C:\WINDOWS\System32\urqnn.dll (file missing)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Repair Registry Pro] C:\Program Files\Repair Registry Pro\RepairRegistryPro.exe -s
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Windows AntiVirus] yrxhijfwscx.exe
O4 - HKLM\..\Run: [PCguardadvisor.exe] "C:\Program Files\blueyonder\PCguard advisor\PCguardadvisor.exe"
O4 - HKLM\..\Run: [kxm8fbbd] RUNDLL32.EXE w0057584.dll,n 0018fbbc0000000a0057584
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [PCguard] C:\Program Files\blueyonder\PCguard\Rps.exe
O4 - HKLM\..\RunServices: [Microsoft Windows AntiVirus] yrxhijfwscx.exe
O4 - HKLM\..\RunServices: [Windows Recylinder Check] mclgnyeoqj.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [Pldo] "C:\PROGRA~1\PPATCH~1\msconfig.exe" -vt yazr
O4 - HKCU\..\Run: [Ihdz] C:\DOCUME~1\khatri\APPLIC~1\SSTEM~1\RNDLL~1.EXE
O4 - HKCU\..\Run: [rmkw] C:\PROGRA~1\COMMON~1\rmkw\rmkwm.exe
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://bt.yahoo.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) -
https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsu...?1147983702001
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsof...?1151692057018
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://messenger.zone.msn.com/binary...o.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) -
http://messenger.zone.msn.com/binary...t.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: antivirus - Unknown owner - C:\WINDOWS\antivirusguard.exe (file missing)
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PCguard Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\blueyonder\PCguard\fws.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Cheers
Phil