*** Is Windows firewall on?

*** You need to update your Java:
http://java.sun.com/javase/downloads/index.jsp
Java Runtime Environment (JRE) 6 Update 6
Uninstall all previous versions of Java through Add\Remove.

*** Disable TeaTimer, as it'll interfere with the cleaning process:
Right click Spybot's TeaTimer System Tray Icon.
Click Exit Spybot-S&D Resident.
TeaTimer closes.

1. Print this post out, since you won't have an access to it, at some point.

2. Close all windows, except for HijackThis.

3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

- O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
- O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
- O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
- O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
- O2 - BHO: (no name) - {5DF4E179-1574-41FA-95BC-5DB5797509CA} - (no file)
- O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
- O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
- O2 - BHO: StFlex IE Helper - {8334A30C-49E5-489a-B63D-5B927C1EF46E} - C:\Program Files\QdrDrive\QdrDrive15.dll (file missing)
- O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
- O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
- O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
- O2 - BHO: (no name) - {E6BE4D59-51BA-4E3C-86EC-BB858BD5B0DC} - C:\WINDOWS\system32\wvUnLBSK.dll (file missing)
- O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
- O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
- O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
- *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
- O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
- O4 - HKLM\..\Run: [advap32] C:\WINDOWS\TEMP\3323.tmp/r
- O4 - HKLM\..\RunOnce: [SpybotDeletingA2964] command /c del "C:\WINDOWS\stcloader.exe"
- O4 - HKLM\..\RunOnce: [SpybotDeletingC9082] cmd /c del "C:\WINDOWS\stcloader.exe"
- O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
- O4 - HKCU\..\RunOnce: [SpybotDeletingB73] command /c del "C:\WINDOWS\stcloader.exe"
- O4 - HKCU\..\RunOnce: [SpybotDeletingD5154] cmd /c del "C:\WINDOWS\stcloader.exe"
- *O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
- O4 - Global Startup: VPN Client.lnk = ?
- O14 - IERESET.INF: START_PAGE_URL=http://graco
- if you don't know msp.graco.com, checkmark all nine O17 entries



4. Click on Fix checked button.

5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

7. Delete following files/folders (if present):

- spools.exe file from C:\WINDOWS\system32\drivers
- 3323.tmp file from C:\WINDOWS\TEMP
- stcloader.exe file from C:\WINDOWS

8. Restart in Normal Mode.

9. Post new HijackThis log.