Youve been busy! its alot cleaner and no more Nail infection
Im gona repeat a few things just to be sure:
Before using Hijack This Can you please do this for me:
Show hidden files and folders:
For XP:
1.On the Tools menu in Windows Explorer, click Folder Options.
2.Click the View tab.
3.Under Hidden files and folders, click Show hidden files and folders.
4.If you see a warning message, click Yes.
5.Click Apply.
6.Click OK.
Then disable system restore to prevent re-infection.
(if you have/use it.)
(you can turn it back on when youre pc is clean).
How to disable system restore:
WinXP.
Click the Start button.
Right-click My Computer, and then click Properties.
On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.
And then do some pre-work clean up
In safemode: (hit f8 when booting up)
empty the C:\windows\prefetch folder ,
empty the c:\windows\temp folder ,
empty the C:\Documents and Settings\Administrator\Local Settings\Temp folder ,
empty the C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files folder EXCEPT the content.ie5 folder (may be hidden).
(replace administrator with youre user name) and (replace windows with winnt if needed)
And close all instances of IE and OE ,then go to: Control Panel / Internet Options / General tab ,
Click the "Delete Files" button.
When prompted place a check in: "Delete all offline content", click OK. This removes the junk files such as downloaded files,
zero byte files created by Outlook Express and many other hidden files that reside in your cache.
Then still in safemode , fix these with hijackthis:
O2 - BHO: (no name) - {00F1D395-4744-40f0-A611-980F61AE2C59} - (no file)
O2 - BHO: MapQuest Toolbar - {4E7BD74F-2B8D-469E-A0EC-FE6EA084B77D} - E:\PROGRA~1\mqtbar2\mqtbar2.dll (file missing)
O3 - Toolbar: MapQuest Toolbar - {4E7BD74F-2B8D-469E-A0EC-FE6EA084B77D} - E:\PROGRA~1\mqtbar2\mqtbar2.dll (file missing)
O4 - HKLM\..\Run: [wwqmwu] e:\windows\system32\kbbfxjc.exe r
O4 - HKLM\..\Run: [NI.UWFX5LP_0001_0803] "E:\WINDOWS\Downloaded Program Files\UWFX5LP_0001_0803NetInstaller.exe"
O4 - HKCU\..\Run: [LDM] \Program\
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O20 - Winlogon Notify: Hints - E:\WINDOWS\system32\pprfproc.dll
Then delete from youre e:\windows\system32 folder:
kbbfxjc.exe
pprfproc.dll
And from youre E:\WINDOWS\Downloaded Program Files folder:
UWFX5LP_0001_0803NetInstaller.exe
Then reboot and post a new log please.