Vundofix found 3 vundo, entitled "efhkj.bak1.bad" "efhkj.ini.bad" and "jkhfe.dll.bad"
When you say "logs" do you mean from HijackThis?
Here's the log from ComboFix.
ComboFix 07-06-18.2 - C:\Documents and Settings\Larry\Desktop\ComboFix.exe
"Larry" - 2007-06-25 23:06:44 - Service Pack 2 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\gebcc.dll
C:\WINDOWS\system32\ccbeg.bak1
C:\WINDOWS\system32\ccbeg.ini
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\inetget2
C:\Program Files\Internet Explorer\rteremejyfs.html
C:\Program Files\outerinfo
C:\Program Files\outerinfo\OinUninstall.exe
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\Outerinfo.dll
C:\Program Files\outerinfo\Outerinfo.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\OuterinfoUpdate.exe
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\web buying
C:\Program Files\web buying\v1.7.4\wbuninst.exe
C:\Program Files\web buying\v1.7.4\webbuying.exe
C:\Temp\0b9
C:\Temp\0b9\tmpTF.log
C:\Temp\tn3
C:\WINDOWS\b122.exe
C:\WINDOWS\retadpu1000106.exe
C:\WINDOWS\retadpu2000219.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\winnb58.dll
C:\WINDOWS\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CORE
-------\core
((((((((((((((((((((((((( Files Created from 2007-05-26 to 2007-06-26 )))))))))))))))))))))))))))))))
2007-06-25 23:04 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-25 22:58 <DIR> d-------- C:\Program Files\CCleaner
2007-06-25 22:51 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-06-25 21:26 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-06-25 20:41 1,308,216 --a------ C:\Program Files\imsubtle.exe
2007-06-25 20:24 83,024 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-06-25 20:24 57,424 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-06-25 20:24 53,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-06-25 20:24 39,376 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-06-25 20:24 29,264 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-06-25 20:24 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-06-25 20:24 <DIR> d-------- C:\DOCUME~1\Larry\APPLIC~1\PC Tools
2007-06-25 20:24 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-06-25 20:23 31,254 --a------ C:\WINDOWS\system32\xxyvsrr.dll
2007-06-25 20:18 <DIR> d-------- C:\Program Files\WinPop
2007-06-25 20:15 31,254 --a------ C:\WINDOWS\system32\opnmlmm.dll
2007-06-25 20:15 172,544 --a------ C:\WINDOWS\system32\bxvymww.dll
2007-06-25 20:15 <DIR> d-------- C:\WINDOWS\system32\win
2007-06-25 20:15 <DIR> d-------- C:\WINDOWS\system32\o02PrEz
2007-06-25 20:15 <DIR> d-------- C:\WINDOWS\system32\B4
2007-06-25 20:15 <DIR> d-------- C:\WINDOWS\system32\B3
2007-06-25 20:15 <DIR> d-------- C:\WINDOWS\system32\B2
2007-06-25 20:15 <DIR> d-------- C:\WINDOWS\system32\B1
2007-06-25 20:15 <DIR> d-------- C:\Temp\iee
2007-06-25 20:15 <DIR> d-------- C:\Temp
2007-06-25 00:50 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2007-06-24 22:05 <DIR> d-------- C:\Program Files\Psicraft
2007-06-24 22:05 <DIR> d-------- C:\DOCUME~1\Larry\APPLIC~1\Psicraft
2007-06-24 21:35 <DIR> d-------- C:\Program Files\Line6
2007-06-24 21:35 <DIR> d-------- C:\DOCUME~1\Larry\APPLIC~1\Line 6
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-26 03:22:22 -------- d-----w C:\DOCUME~1\Larry\APPLIC~1\Xfire
2007-06-26 03:21:56 -------- d-s---w C:\Program Files\Xfire
2007-06-26 02:51:45 1,100 ----a-w C:\WINDOWS\system32\d3d8caps.dat
2007-06-26 02:46:32 -------- d-----w C:\Program Files\Google
2007-06-26 00:35:57 -------- d-----w C:\DOCUME~1\Larry\APPLIC~1\Google
2007-06-26 00:15:29 -------- d-----w C:\Program Files\Windows NT
2007-06-23 13:41:51 -------- d-----w C:\Program Files\World of Warcraft
2007-06-19 19:04:30 -------- d-----w C:\Program Files\GCH Guitar academy
2007-06-19 03:43:07 -------- d-----w C:\DOCUME~1\Larry\APPLIC~1\IGN_DLM
2007-06-16 05:16:32 -------- d-----w C:\Program Files\Mp3 My Mp3 2.0
2007-06-08 03:42:21 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-02 22:58:50 -------- d-----w C:\Program Files\Steam
2007-05-20 00:20:05 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-09 01:51:20 -------- d-----w C:\Program Files\AGEIA Technologies
2007-05-09 01:51:14 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-05-09 01:46:54 -------- d-----w C:\Program Files\Timeline Interactive
2007-05-05 06:52:33 -------- d-----w C:\Program Files\e frontier
2007-04-27 18:30:05 -------- d-----w C:\Program Files\Common Files\Alias Shared
2007-04-27 18:28:06 -------- d-----w C:\Program Files\Autodesk
2007-04-27 00:17:01 -------- d-----w C:\Program Files\Alias
2007-04-27 00:10:28 -------- d-----w C:\Program Files\Common Files\AliasWavefront Shared
2007-04-27 00:07:41 -------- d--h--w C:\Program Files\Zero G Registry
2007-04-26 22:12:43 -------- d-----w C:\Program Files\eMedia Guitar Method 1
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-19 17:26:00 888,832 ----a-w C:\WINDOWS\system32\nvmobls.dll
2007-04-19 17:26:00 86,016 ----a-w C:\WINDOWS\system32\nvmctray.dll
2007-04-19 17:26:00 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll
2007-04-19 17:26:00 794,624 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-04-19 17:26:00 7,700,480 ----a-w C:\WINDOWS\system32\nvcpl.dll
2007-04-19 17:26:00 581,632 ----a-w C:\WINDOWS\system32\nvhwvid.dll
2007-04-19 17:26:00 5,644,288 ----a-w C:\WINDOWS\system32\nvoglnt.dll
2007-04-19 17:26:00 5,619,712 ----a-w C:\WINDOWS\system32\nvdisps.dll
2007-04-19 17:26:00 5,255,168 ----a-w C:\WINDOWS\system32\nvdispsr.dll
2007-04-19 17:26:00 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll
2007-04-19 17:26:00 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll
2007-04-19 17:26:00 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-04-19 17:26:00 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe
2007-04-19 17:26:00 425,984 ----a-w C:\WINDOWS\system32\keystone.exe
2007-04-19 17:26:00 4,543,616 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-04-19 17:26:00 35,840 ----a-w C:\WINDOWS\system32\nvcodins.dll
2007-04-19 17:26:00 35,840 ----a-w C:\WINDOWS\system32\nvcod.dll
2007-04-19 17:26:00 335,872 ----a-w C:\WINDOWS\system32\nvwrses.dll
2007-04-19 17:26:00 335,872 ----a-w C:\WINDOWS\system32\nvwrsel.dll
2007-04-19 17:26:00 327,680 ----a-w C:\WINDOWS\system32\nvwrsfr.dll
2007-04-19 17:26:00 327,680 ----a-w C:\WINDOWS\system32\nvwrsesm.dll
2007-04-19 17:26:00 323,584 ----a-w C:\WINDOWS\system32\nvwrspt.dll
2007-04-19 17:26:00 323,584 ----a-w C:\WINDOWS\system32\nvwrsit.dll
2007-04-19 17:26:00 323,584 ----a-w C:\WINDOWS\system32\nvrshe.dll
2007-04-19 17:26:00 323,584 ----a-w C:\WINDOWS\system32\nvrsar.dll
2007-04-19 17:26:00 319,488 ----a-w C:\WINDOWS\system32\nvwrsptb.dll
2007-04-19 17:26:00 319,488 ----a-w C:\WINDOWS\system32\nvwrsnl.dll
2007-04-19 17:26:00 315,392 ----a-w C:\WINDOWS\system32\nvwrsru.dll
2007-04-19 17:26:00 315,392 ----a-w C:\WINDOWS\system32\nvwrshu.dll
2007-04-19 17:26:00 311,296 ----a-w C:\WINDOWS\system32\nvwrsde.dll
2007-04-19 17:26:00 311,296 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-04-19 17:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrstr.dll
2007-04-19 17:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrssl.dll
2007-04-19 17:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrsfi.dll
2007-04-19 17:26:00 3,203,072 ----a-w C:\WINDOWS\system32\nvgamesr.dll
2007-04-19 17:26:00 3,035,136 ----a-w C:\WINDOWS\system32\nvgames.dll
2007-04-19 17:26:00 299,008 ----a-w C:\WINDOWS\system32\nvwrssk.dll
2007-04-19 17:26:00 299,008 ----a-w C:\WINDOWS\system32\nvwrsno.dll
2007-04-19 17:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrssv.dll
2007-04-19 17:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrspl.dll
2007-04-19 17:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrsda.dll
2007-04-19 17:26:00 286,720 ----a-w C:\WINDOWS\system32\nvwrseng.dll
2007-04-19 17:26:00 286,720 ----a-w C:\WINDOWS\system32\nvwrscs.dll
2007-04-19 17:26:00 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-04-19 17:26:00 282,624 ----a-w C:\WINDOWS\system32\nvwrsar.dll
2007-04-19 17:26:00 278,528 ----a-w C:\WINDOWS\system32\nvwrshe.dll
2007-04-19 17:26:00 278,528 ----a-w C:\WINDOWS\system32\nvrsfr.dll
2007-04-19 17:26:00 274,432 ----a-w C:\WINDOWS\system32\nvrsit.dll
2007-04-19 17:26:00 274,432 ----a-w C:\WINDOWS\system32\nvrses.dll
2007-04-19 17:26:00 274,432 ----a-w C:\WINDOWS\system32\nvrsel.dll
2007-04-19 17:26:00 270,336 ----a-w C:\WINDOWS\system32\nvrsde.dll
2007-04-19 17:26:00 266,240 ----a-w C:\WINDOWS\system32\nvrspt.dll
2007-04-19 17:26:00 266,240 ----a-w C:\WINDOWS\system32\nvrsnl.dll
2007-04-19 17:26:00 266,240 ----a-w C:\WINDOWS\system32\nvrsesm.dll
2007-04-19 17:26:00 262,144 ----a-w C:\WINDOWS\system32\nvrsru.dll
2007-04-19 17:26:00 262,144 ----a-w C:\WINDOWS\system32\nvrsptb.dll
2007-04-19 17:26:00 262,144 ----a-w C:\WINDOWS\system32\nvrsja.dll
2007-04-19 17:26:00 258,048 ----a-w C:\WINDOWS\system32\nvrsko.dll
2007-04-19 17:26:00 253,952 ----a-w C:\WINDOWS\system32\nvrshu.dll
2007-04-19 17:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrstr.dll
2007-04-19 17:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrssl.dll
2007-04-19 17:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrssk.dll
2007-04-19 17:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrspl.dll
2007-04-19 17:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrsno.dll
2007-04-19 17:26:00 245,760 ----a-w C:\WINDOWS\system32\nvrssv.dll
2007-04-19 17:26:00 245,760 ----a-w C:\WINDOWS\system32\nvrsda.dll
2007-04-19 17:26:00 241,664 ----a-w C:\WINDOWS\system32\nvrsfi.dll
2007-04-19 17:26:00 241,664 ----a-w C:\WINDOWS\system32\nvrseng.dll
2007-04-19 17:26:00 241,664 ----a-w C:\WINDOWS\system32\nvrscs.dll
2007-04-19 17:26:00 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll
2007-04-19 17:26:00 221,184 ----a-w C:\WINDOWS\system32\nvrszhc.dll
2007-04-19 17:26:00 212,992 ----a-w C:\WINDOWS\system32\nvwrsja.dll
2007-04-19 17:26:00 212,992 ----a-w C:\WINDOWS\system32\nvapi.dll
2007-04-19 17:26:00 2,973,696 ----a-w C:\WINDOWS\system32\nvvitvsr.dll
2007-04-19 17:26:00 2,924,544 ----a-w C:\WINDOWS\system32\nvvitvs.dll
2007-02-23 07:57:59 88 --sh--r C:\WINDOWS\system32\4BFB238848.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 11:28]
{4A168249-1BF9-4A1D-965C-3EC04A69736B}=C:\Program Files\Windows NT\mewofyn83122.dll [2007-06-18 14:59]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}=C:\Program Files\Yahoo!\Common\yiesrvc.dll [2006-10-31 16:29]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 16:21]
{9A9C9B69-F908-4AAB-8D0C-10EA8997F37E}=C:\WINDOWS\system32\WinNB58.dll []
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar2.dll [2007-01-19 23:55]
{DC192567-65F9-4AB6-ADB7-E13575F81726}=C:\WINDOWS\system32\opnmlmm.dll [2007-06-25 20:15]
{E62D925C-87E0-41DB-8EAF-4019C079FD96}=C:\WINDOWS\system32\jkhfe.dll []
{f692398e-2c9c-4a4d-96e8-b1520eeac2c8}=C:\WINDOWS\system32\bxvymww.dll [2007-06-25 20:15]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\Program Files\NavNT\vptray.exe" [2001-09-24 07:59]
"nwiz"="nwiz.exe" [2007-04-19 13:26 C:\WINDOWS\system32\nwiz.exe]
"Logitech Hardware Abstraction Layer"="C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE" []
"ViewMgr"="C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" []
"Cmaudio"="cmicnfg.cpl" []
"@"="" []
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" []
"atwtusb"="atwtusb.exe" [2005-02-03 10:37 C:\WINDOWS\system32\atwtusb.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 16:07]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 16:57]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpData"="C:\WINDOWS\system32\svch0st.exe" []
"igndlm.exe"="C:\Program Files\IGN\Download Manager\DLM.exe" [2006-11-07 18:22]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 06:48]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:54]
"Steam"="" []
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-01-19 13:49]
"Outerinfo"="C:\Program Files\Outerinfo\Outerinfo.exe" []
"OuterinfoUpdate"="C:\Program Files\Outerinfo\OuterinfoUpdate.exe" []
"WinPop"="C:\Program Files\WinPop\winpop.exe" [2007-06-25 20:18]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-06-25 20:30]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\Internet Explorer\rteremejyfs.html
FriendlyName=
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 10:13]
"{DC192567-65F9-4AB6-ADB7-E13575F81726}"="C:\WINDOWS\system32\opnmlmm.dll" [2007-06-25 20:15]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnmlmm]
opnmlmm.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2a15a5a0-aa57-11db-a05a-9ccc57198468}]
AutoRun\command- F:\LaunchU3.exe -a
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-25 23:21:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-25 23:23:21 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-25 23:23
--- E O F ---
Sadly, Mirar and all it's little pop-up pals are still bugging me almost constantly, but there is definitely a change in performance so far.