Derek, I unzipped it all and ran it and it came up as Computer clean, it found nothing, not even the 5 things Spybot always finds

Items in Startup Item in msconfig, in the System Configuration Utility/Startup

When I turn off the computer two things always say they are closing and then needs me to click close:
rundll32.exe

and TaskPanel   maybe not panel, some other word, 

I know something is going on down there, anyway, here are what may be suspicious clicked Startup Items
these are the sTARTUP iTEM AND cOMMANd:
tovebogi  Rundll32.exe"c:\windows2\system32\tovebogi.dll",a
totitiga  Rundll32.exe"C:\WINDOWS2\SYSTEM32\totitiga.dll",S
tovebogi  Rundll32.exe"c:\windows2\system32\tovebogi.dll",a
vapuhonu  rundll32.exe"C:\WINDOWS2\system32\vapuhonu.dll",b
totitiga  Rundll32.exe"C:\WINDOWS2\system32\totitiga.dll,s

Every other choice on the list begins with C:\ most with C:\Program Files

Putting 2 and 2 together, since that rundll.exe comes up every time and since it looks to me like totitiga (with two keys, two HKLM \ connections) and vapuhonu which go directly to this satellite, parasite.....

And what is WINDOWS2, in explore it seems to be a duplicate windows folder. If this is what this might be, if I go in there now and find these files, wahat if I search those 3 "words"?

hmmm

I will turn these off now as well as two that show nothing, no text, except the reg keys, what is that about?

I now have to remember to save this Notepad so I can email it later

Also another 3 hour Spybot scan in case those 4 do get removed temporarily and might be triggers. What is an include?  What is that?????

I can do Adaware back online again but why bother

What is wkfud.exe ? in Microsoft woks  I am also turning off AAWService.exe, some Adaware thing that's too active.

There are no dll files I can find with those names, tovebogi, totitiga, vapuhonu



I can't get the acual key from System Config Utility, it all just has ...\CurrenbtVersion\Run  at the end, they all read he same


It didn't work, when one clicks on Normal start up in the System config, all the boxes become checked again including all those non C:\ rundll files, start up commands, and if I try to keep them from happening, it opens up in diagnostic but maybe still launched them.

I will try again with safeboot when theyd on't open anyway...so I guess nothing canm be done at all but go after 
Win32.sdbot.aad
Hupigon13
ProGroup.Prorat
Virtumonde.prx
Vundo Variant.bho

and if the following is an actual name of a malware:
Microsoft.WindowsSecurityCenter_disabled

I am going to ftp these so I can read them at library and print out possibly what to remove and where, what maybe I can use against this stuff. I need to find this stuff and stop it, it got crazy last time when it hijacked the firewall, turning the Spygate icon black with a star flashing in the center and launching 29 IE windows going nuts and when spygate came back on it was still rising and it said it waas blocking IE. Yipes. So I will download any devices at library and emaail them to me, I think it can't go nuts if no browser is opened...  If no virus is found as it hasn't been, this is quite a worm, it is worse than a virus....

Each time I uncheck the rndll start up boxes, less come back checked, the problem is none of them go away as a choice so when normal is set they all come back

Do you think there is a way through DOS?

HKLM
HKCU  in Location in Startup in System Configuration Utility