Here is my log report. I have an issue with an urqrspp.dll that won't remove itself after using this program, then Spybot SD and Ad-Aware. Spybot keeps finding the dll and wanting to scan on a reboot to get rid of it, but it finds it (the dll) in memory and can't remove it.

I have also put the HiJackThis! in it's own folder as requested.

TC Dale
—————————————————————————————–




StartupList report, 6/11/2007, 12:11:24 PM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\Terry\Desktop\My Downloads\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16441)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Tablet.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Terry\Desktop\My Downloads\HijackThis.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

IgfxTray = C:\WINDOWS\system32\igfxtray.exe
HotKeysCmds = C:\WINDOWS\system32\hkcmd.exe
dla = C:\WINDOWS\system32\dla\tfswctrl.exe
YBrowser = C:\Program Files\Yahoo!\browser\ybrwicon.exe
AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
Motive SmartBridge = C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
Windows Defender = "C:\Program Files\Windows Defender\MSASCui.exe" -hide
SunJavaUpdateSched = C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
PrevxOne = C:\Program Files\Prevx1\PXConsole.exe
mmtask = C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
ApachInc = rundll32.exe "C:\WINDOWS\system32\rjlqctsf.dll",realset

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

H/PC Connection Agent = "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
EasyLinkAdvisor = "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - (no file) - {09C5CA05-9347-4F1E-9893-0AB71CCF4B29}
(no name) - C:\WINDOWS\system32\ddccd.dll - {158DB481-7071-467F-8AF4-4247FAFC7EBD}
(no name) - (no file) - {290E34D6-5F88-4F4F-A83D-FC53B5271146}
Malicious Scripts Scanner - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll (file missing) - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB}
(no name) - C:\WINDOWS\system32\snltvigm.dll (file missing) - {596FE6D2-E666-406F-AE87-826F5BD03C72}
(no name) - C:\WINDOWS\_MWOLTB.DLL - {5ADA9CAC-04F9-4DD2-ABFD-74D673BE8624}
(no name) - C:\WINDOWS\system32\dla\tfswshx.dll - {5CA3D70E-1895-11CF-8E15-001234567890}
(no name) - (no file) - {7E853D72-626A-48EC-A868-BA8D5E23E045}
(no name) - C:\WINDOWS\system32\urqrspp.dll - {8C616D74-ACA5-4E55-8482-A11C2B0AFAE1}
Mouse Gestures - C:\Program Files\Internet Explorer\Plugins\Drowse\MouseGestures.dll - {A6A49249-57AE-4295-8D4D-18A9502C7D8E}

————————————————–

Enumerating Task Scheduler jobs:

MP Scheduled Scan.job

————————————————–

Enumerating Download Program Files:

[ActiveGS.cab]
CODEBASE = http://www.virtualapple.com/activegs.cab
OSD = C:\WINDOWS\Downloaded Program Files\OSDA56.OSD

[SysProWmi Class]
InProcServer32 = C:\WINDOWS\System32\Dell\SystemProfiler\SysPro.ocx
CODEBASE = http://support.dell.com/systemprofiler/SysPro.CAB

[Microsoft Office Template and Media Control]
InProcServer32 = C:\PROGRA~1\MICROS~4\Office12\IEAWSDC.DLL
CODEBASE = http://office.microsoft.com/templates/ieawsdc.cab

[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://a1540.g.akamai.net/7/1540/52/200612…ex/qtplugin.cab

[Office Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\OGACheckControl.DLL
CODEBASE = http://download.microsoft.com/download/e/7…/OGAControl.cab

[PCPitstop Utility]
InProcServer32 = C:\WINDOWS\DOWNLO~1\PCPITS~1.DLL
CODEBASE = http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

[Anark Client 3.0 ActiveX Control]
InProcServer32 = C:\Program Files\Anark\Anark Client 3\AMClient.dll
CODEBASE = http://install.anark.com/client/version3/w…en/AMClient.cab

[Macromedia Authorware Web Player Control]
InProcServer32 = C:\WINDOWS\System32\macromed\authorwa\awswax.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa…re/awswax65.cab

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll
CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM32\Macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/pub/shock…director/sw.cab

[Scanner Class]
InProcServer32 = C:\temp\TDECntrl\TDECntrl.dll
CODEBASE = http://www.trojanscan.com/trojanscan/TDECntrl.CAB

[Symantec AntiVirus scanner]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\avsniff.dll
CODEBASE = http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab

[{2D360201-FFF5-11D1-8D03-00A0C959BC0A}]
CODEBASE = http://download.macromedia.com/pub/shockwa…ash/swflash.cab

[YInstStarter Class]
InProcServer32 = C:\Program Files\Yahoo!\Common\yinsthelper.dll
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab

[Microsoft PID Sniffer]
InProcServer32 = C:\WINDOWS\system32\odc.dll
CODEBASE = https://support.microsoft.com/OAS/ActiveX/odc.cab

[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB

[{39B0684F-D7BF-4743-B050-FDC3F48F7E3B}]
CODEBASE = http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.1.74.cab

[Merriam-Webster Online Toolbar]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\mwolinstaller.dll
CODEBASE = http://www.merriam-webster.com/toolbar/webinstall.cab

[Office Update Installation Engine]
InProcServer32 = C:\WINDOWS\opuc.dll
CODEBASE = http://office.microsoft.com/officeupdate/content/opuc3.cab

[LinkedIn ContactFinderControl]
InProcServer32 = C:\WINDOWS\DOWNLO~1\LINKED~1.DLL
CODEBASE = http://www.linkedin.com/cab/LinkedInContactFinderControl.cab

[Malicious Software Removal Tool]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\WebCleaner.dll
CODEBASE = http://download.microsoft.com/download/5/c…/WebCleaner.cab

[Microsoft.WinRep]
InProcServer32 = C:\WINDOWS\System32\Winrep.dll
CODEBASE = https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab

[Microsoft Virtual Server VMRC Advanced Control]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\VMRCActiveXClient.dll
CODEBASE = https://www.microsoft.com/resources/virtual…iveXClient1.cab

[MSN Photo Upload Tool]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll
CODEBASE = http://by20fd.bay20.hotmail.msn.com/resources/MsnPUpld.cab

[Windows Live Safety Center Base Module]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\wlscBase.dll
CODEBASE = https://scan.safety.live.com/resource/downl…lscbase3401.cab

[Symantec RuFSI Utility Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\rufsi.dll
CODEBASE = http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab

[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://update.microsoft.com/microsoftupdat…b?1136926181812

[DASWebDownload Class]
InProcServer32 = C:\WINDOWS\DASAct.dll
CODEBASE = http://das.microsoft.com/activate/cab/x86/…tail/DASAct.cab

[mhLabel Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\mhLbl.dll
CODEBASE = http://www.pcpitstop.com/mhLbl.cab

[ActiveScan Installer Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\asinst.dll
CODEBASE = http://acs.pandasoftware.com/activescan/as5free/asinst.cab

[RegConfig Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\yregcfg.dll
CODEBASE = http://download.yahoo.com/dl/installs/bkm/prod/yregcfg.cab

[F-Secure Online Scanner 3.0]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\fscax.dll
CODEBASE = http://support.f-secure.com/ols/fscax.cab

[{9F1C11AA-197B-4942-BA54-47A8489BB47F}]
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/…8030.6585416667

[YahooYMailTo Class]
InProcServer32 = C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
CODEBASE = http://download.yahoo.com/dl/installs/ymail/ymmapi.dll

[WebResponseAttachments Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\FILETR~1.OCX
CODEBASE = https://webresponse.one.microsoft.com/oas/A…eX/FileXfer.cab

[InetDownload Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\WMDownload.dll
CODEBASE = https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab

[LinkSys Content Update]
InProcServer32 = C:\WINDOWS\system32\GTDownLS_125.ocx
CODEBASE = http://www.linksysfix.com/netcheck/53/install/gtdownls.cab

[{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}]

[Office Update Installation Engine]
InProcServer32 = C:\WINDOWS\opuc.dll
CODEBASE = http://office.microsoft.com/officeupdate/content/opuc4.cab

[{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}]

[{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}]

[{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}]

[{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}]

[PhotosCtrl Class]
InProcServer32 = C:\Program Files\Yahoo!\Common\YPhotos.dll
CODEBASE = http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab

[Measurement Service Client v.3.4]
InProcServer32 = C:\WINDOWS\system32\FUTURE~1\MSC\MSC3.ocx
CODEBASE = http://ccon.futuremark.com/global/msc34.cab

[{D27CDB6E-AE6D-11CF-96B8-444553531000}]
CODEBASE = http://active.macromedia.com/flash2/cabs/swflash.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa…ash/swflash.cab

[{DBA230D1-8467-4e69-987E-5FAE815A3B45}]

[{DC187740-46A9-11D5-A815-00B0D0428C0C}]

[Dell PC Checkup Installer Control]
InProcServer32 = C:\WINDOWS\system32\GTDownDE_113.ocx
CODEBASE = http://pccheckup.dellfix.com/rel/35/install/gtdownde.cab

[{F919FBD3-A96B-4679-AF26-F551439BB5FD}]

————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\WINDOWS\system32\SET1C.tmp => C:\WINDOWS\system32\msi.dll| =>

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
UPnPMonitor: C:\WINDOWS\system32\upnpui.dll

————————————————–
End of report, 13,563 bytes
Report generated in 0.157 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only