Thank's so much for helping me.
Also, I seem to have lost the use of the XP theme for my desktop, any ideas on how to fix that as well?
Here is the Hijack log.
Logfile of HijackThis v1.99.1
Scan saved at 11:11:37 PM, on 24/03/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Tim Cassibo Jr\Desktop\hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe
O4 - HKCU\..\Run: [zmqi] C:\PROGRA~1\COMMON~1\zmqi\zmqim.exe
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and Settings\Tim Cassibo Jr\Desktop\HijackThis.exe /startupscan
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
and the look log
Look2Me-Destroyer V1.0.11
Scanning for infected files.....
Scan started at 24/03/2006 11:01:30 PM
Infected! C:\WINDOWS\system32\q4rq0e95eh.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017943.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017947.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017949.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017953.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017956.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017960.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017978.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017982.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0018018.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0018175.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019175.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019189.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019194.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019195.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019205.dll
Infected! C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019206.dll
Infected! C:\WINDOWS\system32\lv6209joe.dll
Infected! C:\WINDOWS\system32\nohwvid.dll
Infected! C:\WINDOWS\system32\q4rq0e95eh.dll
Infected! C:\WINDOWS\system32\guard.tmp
Attempting to delete infected files...
Attempting to delete: C:\WINDOWS\system32\q4rq0e95eh.dll
C:\WINDOWS\system32\q4rq0e95eh.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017943.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017943.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017947.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017947.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017949.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017949.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017953.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017953.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017956.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017956.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017960.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017960.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017978.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017978.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017982.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0017982.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0018018.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0018018.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0018175.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0018175.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019175.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019175.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019189.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019189.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019194.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019194.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019195.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019195.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019205.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019205.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019206.dll
C:\System Volume Information\_restore{069491D8-E09F-4F1D-AF9F-DE3A25A528A6}\RP205\A0019206.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\lv6209joe.dll
C:\WINDOWS\system32\lv6209joe.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\nohwvid.dll
C:\WINDOWS\system32\nohwvid.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\q4rq0e95eh.dll
C:\WINDOWS\system32\q4rq0e95eh.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\guard.tmp
C:\WINDOWS\system32\guard.tmp Deleted successfully!
Making registry repairs.
Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WebCheck
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{E8197A41-9BFF-4AC2-A028-311DFB14BF5C}"
HKCR\Clsid\{E8197A41-9BFF-4AC2-A028-311DFB14BF5C}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{AAD5025E-A128-457F-B96F-87A60975B8FA}"
HKCR\Clsid\{AAD5025E-A128-457F-B96F-87A60975B8FA}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{81980A0D-F71B-4728-A35B-EE93619B2B20}"
HKCR\Clsid\{81980A0D-F71B-4728-A35B-EE93619B2B20}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{0E3BFEA6-0224-4D13-B8C0-035DF5661D09}"
HKCR\Clsid\{0E3BFEA6-0224-4D13-B8C0-035DF5661D09}
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
Restoring SeDebugPrivilege for Administrators - Succeeded
Edited by Neskit, 24 March 2006 - 10:43 PM.