Hey sorry for the delay and thank you in advance for all of your help. I should add that though I use firefox for all of my web browsing....in the past 2 days explorer has been opening up randomly on its own.
Here is the log from Hijack This.
Logfile of HijackThis v1.99.1
Scan saved at 11:25:33 PM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Admin\Desktop\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.c...//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: {db757d87-dbcf-3139-ad94-cc2a09abb6ba} - {ab6bba90-a2cc-49da-9313-fcbd78d757bd} - C:\WINDOWS\system32\gjdtlstr.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE" -quiet
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{265B5D3E-1390-4283-89A4-5DE8CC80BB3C}: NameServer = 209.163.146.254,209.163.146.253
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
And here is the one from Combofix
ComboFix 08-01-06.3 - Admin 2008-01-06 23:09:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.701 [GMT -6:00]
Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .EXE
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE
C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\default.htm
C:\WINDOWS\system32\agwdndww.dll
C:\WINDOWS\system32\cbayv.dll
C:\WINDOWS\system32\cbayv.exe
C:\WINDOWS\system32\drivers\4_stars.gif
C:\WINDOWS\system32\drivers\5_stars.gif
C:\WINDOWS\system32\drivers\alert_icon.gif
C:\WINDOWS\system32\drivers\buy_btn.gif
C:\WINDOWS\system32\drivers\close_icon.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_btn.gif
C:\WINDOWS\system32\drivers\features.gif
C:\WINDOWS\system32\drivers\header_bg.gif
C:\WINDOWS\system32\drivers\icon_warning.gif
C:\WINDOWS\system32\drivers\logo_bg.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\perfect_cleaner_box_small.jpg
C:\WINDOWS\system32\drivers\perfect_cleaner_header.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_header_small.gif
C:\WINDOWS\system32\drivers\protect.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\remove_spyware_button.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\secuity_center_logo.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\spy_away_box_small.jpg
C:\WINDOWS\system32\drivers\spy_away_header.gif
C:\WINDOWS\system32\drivers\spy_away_header_small.gif
C:\WINDOWS\system32\drivers\users_rating.gif
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\gtv_sd.bin
C:\WINDOWS\system32\ipsnce.dll
C:\WINDOWS\system32\lnxrbxds.exe
C:\WINDOWS\system32\nscytwbn.exe
C:\WINDOWS\system32\RCXC.tmp
C:\WINDOWS\system32\sl.bin
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\tmp190.tmp.dll
C:\WINDOWS\system32\tmp7BE.tmp.dll
C:\WINDOWS\system32\tuvlmxvx.dll
C:\WINDOWS\system32\vyabc.ini
C:\WINDOWS\system32\vyabc.ini2
C:\WINDOWS\system32\wwdndwga.ini
C:\WINDOWS\system32\xvxmlvut.ini
C:\WINDOWS\system32\xwwdphcs.dll
C:\WINDOWS\system32\yayawur.dll
C:\WINDOWS\utwyxx.ini
C:\WINDOWS\xxywtu.dll
<pre>
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe" replaces infected copy of "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater .exe" replaces infected copy of "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe" moved to QooBox
"C:\Program Files\Yahoo!\Messenger\YAHOOM~1 .EXE" replaces infected copy of "C:\Program Files\Yahoo!\Messenger\YAHOOM~1.EXE"
</pre>
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-12-07 to 2008-01-07 )))))))))))))))))))))))))))))))
.
2008-01-06 23:08 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-06 23:00 . 2008-01-06 23:01 75,840 --a------ C:\WINDOWS\system32\gjdtlstr.dll
2008-01-05 01:02 . 2008-01-05 01:04 <DIR> d-------- C:\WINDOWS\nview
2008-01-05 01:02 . 2006-03-09 15:29 180,224 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-01-05 01:02 . 2008-01-06 23:21 50,257 --a------ C:\WINDOWS\system32\nvapps.xml
2008-01-05 01:02 . 2006-03-09 15:29 16,960 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-01-05 01:01 . 2006-03-09 17:59 180,224 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-01-04 21:37 . 2008-01-04 21:37 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-01-04 21:36 . 2008-01-04 21:37 <DIR> d-------- C:\Documents and Settings\Admin\Application Data\SystemRequirementsLab
2007-12-15 14:02 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-14 05:20 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-05-14 05:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Macrovision
2008-01-07 03:54 --------- d-----w C:\Program Files\City of Heroes
2008-01-06 23:59 --------- d-----w C:\Documents and Settings\Admin\Application Data\U3
2008-01-04 16:35 --------- d-----w C:\Program Files\World of Warcraft
2008-01-04 16:35 --------- d-----w C:\Program Files\QuickTime
2008-01-04 16:35 --------- d-----w C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor
2008-01-04 16:35 --------- d-----w C:\Program Files\7-Zip
2008-01-04 16:34 --------- d-----w C:\Program Files\Sex Tetris
2008-01-04 09:42 --------- d-----w C:\Documents and Settings\Admin\Application Data\AVG7
.
<pre>
----a-w 139,367 2008-01-05 05:28:41 C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ab6bba90-a2cc-49da-9313-fcbd78d757bd}]
2008-01-06 23:01 75840 --a------ C:\WINDOWS\system32\gjdtlstr.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1 .exe" [ ]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-01-05 01:16 2321600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-05 01:16 40048]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 15:29 7561216]
"nwiz"="nwiz.exe" [2006-03-09 15:29 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-03-09 15:29 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-03-16 21:34 145920]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-05-29 19:34 5419008]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a------ 2006-11-07 09:29 50736 C:\Program Files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio]
-ra------ 2002-06-27 10:33 524288 C:\WINDOWS\system32\CMICNFG.CPL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kav]
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2006-07-29 19:34 5354792 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
--a------ 2007-05-29 19:34 5419008 C:\Program Files\MySpace\IM\MySpaceIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-03-09 15:29 1519616 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\setup]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
C:\WINDOWS\xxywtu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2008-01-05 01:16 4670968 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2006-02-14 16:02]
S3 bfastfao;bfastfao;C:\DOCUME~1\Admin\LOCALS~1\Temp\bfastfao.sys [2002-03-05 10:08]
S4 Crymanser;Crymanser;C:\WINDOWS\system32\drivers\nabtsfec.sys [2004-08-03 23:10]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1e93d19-e7b5-11db-a5fb-000ae6817ce6}]
\Shell\AutoRun\command - F:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c5eccf43-9c41-11db-b8a0-806d6172696f}]
\Shell\AutoRun\command - D:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd360eb6-be35-11db-992d-000ae6817ce6}]
\Shell\AutoRun\command - F:\LaunchU3.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-01-06 06:00:25 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 15:00:00 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 16:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 17:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 18:00:00 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 19:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 20:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 21:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 22:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 23:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-07 00:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 07:00:01 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-07 01:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-07 02:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-07 03:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-07 04:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-07 05:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 08:00:01 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 09:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 10:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 11:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 12:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 13:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
"2008-01-06 14:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\Mj6XN2Ab.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-06 23:21:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-06 23:23:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-07 05:23:11
Edited by MikaelB, 06 January 2008 - 11:31 PM.