Alrite, that sounds like a good virus. Fix the following:
R3 - Default URLSearchHook is missing
O4 - HKLM\..\RunServices: [Microsoft System Support] spool.exe
O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe
O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe
O15 - Trusted Zone: http://*.billingnow.com
O15 - Trusted Zone: http://*.reliablestats.com
O15 - Trusted Zone: http://*.winantispyware.com
O15 - Trusted Zone: http://*.winantivirus.com
O15 - Trusted Zone: http://*.winantiviruspro.com
O15 - Trusted Zone: http://*.winnanny.com
O15 - Trusted Zone: http://*.winsoftware.com
After this, install Ewido and CCleaner (both links are in my signature below) and update definitions for both, but DON'T run them yet.
After doing this, reboot into safe mode, and first, delete this folder if found:
C:\Program Files\Common Files\VCClient
Then, run Ewido and CCleaner, fixing everything that's found. Save the Ewido log.
Then, reboot into normal mode again, run HJT, and post a new log along with the saved Ewido log.
Then, we'll work from there.
Thanks.
(justdrw, ignore this below)
Also (to Mods): Anybody know anything about:
O20 - Winlogon Notify: ShellScrap - C:\WINDOWS\system32\gplql3351.dll
Looks REAL suspicious to me.