Hi Siggyx, I ran the programs that you told me to and here are the logs you requested. Again thank you for you patience with me and my computer.
Logfile of HijackThis v1.99.1
Scan saved at 5:35:47 PM, on 12/01/2006
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\DMI\BIN\WIN32SL.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\DMI\BIN\DELLDMI.EXE
C:\DMI\BIN\MONITOR.EXE
C:\DMI\BIN\NIC.EXE
C:\DMI\BIN\COO.EXE
C:\DMI\BIN\DNAR.EXE
C:\DMI\BIN\NODEMNGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
C:\WINDOWS\SYSTEM\SXGTKBAR.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\WEBROOT\SHREDDER\SPSHREDDER.EXE
C:\PROGRAM FILES\WEBROOT\POPUPWASHER\POPUPWASHER.EXE
C:\PROGRAM FILES\WEBROOT\WASHER\WWDISP.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\MY DOCUMENTS\MY RECEIVED FILES\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.dell.com/search/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Popup Killer - {4A3A071E-F913-4eee-AE15-AEFFA16FB6BC} - C:\WINDOWS\POPUPW~1.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YT.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [Disknag] C:\DELL\DISKNAG.EXE
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.EXE -off
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [PCHealth] c:\windows\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Symantec Core LC] "C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe" start
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\RunServices: [3Com DMI Agent] C:\WINDOWS\SYSTEM\3com_dmi\3CDMINIC.EXE
O4 - HKLM\..\RunServices: [DMILDR] C:\DMI\bin\dmildr.exe
O4 - HKLM\..\RunServices: [Win32SL] C:\DMI\BIN\Win32sl.EXE -i -p -r
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [ccEvtMgr] "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPFMonitor] c:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Spam Shredder] C:\Program Files\Webroot\Shredder\spshredder.exe -tray
O4 - HKCU\..\Run: [PopUpWasher] C:\Program Files\Webroot\PopUpWasher\PopUpWasher.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\WINDOWS\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\WINDOWS\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: Dell Home - {9210B580-05E1-11DA-8A8D-00B0D0604B78} -
http://www.dellnet.com (file missing) (HKCU)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...ebscan_ansi.cab
This is the kaspersky log.
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Thursday, January 12, 2006 00:40:47
Operating System: Microsoft Windows Millennium Edition
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 12/01/2006
Kaspersky Anti-Virus database records: 170652
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
a:\
c:\
d:\
Scan Statistics:
Total number of scanned objects: 19349
Number of viruses found: 10
Number of infected objects: 45
Number of suspicious objects: 2
Duration of the scan process: 2550 sec
Infected Object Name - Virus Name
c:\_RESTORE\ARCHIVE\FS72.CAB/A-1030056402.CPY Infected: not-a-virus:AdWare.Win32.NewDotNet.e
c:\_RESTORE\ARCHIVE\FS72.CAB/A-1030056397.CPY Infected: not-a-virus:AdWare.Win32.NewDotNet.e
c:\_RESTORE\ARCHIVE\FS72.CAB/A-1030056392.CPY Infected: not-a-virus:AdWare.Win32.NewDotNet
c:\_RESTORE\ARCHIVE\FS72.CAB/A-1030056387.CPY Infected: not-a-virus:AdWare.Win32.NewDotNet.e
c:\_RESTORE\ARCHIVE\FS72.CAB Infected: not-a-virus:AdWare.Win32.NewDotNet.e
c:\_RESTORE\ARCHIVE\FS71.CAB/A-1030057415.CPY Infected: not-a-virus:AdWare.Win32.NewDotNet
c:\_RESTORE\ARCHIVE\FS71.CAB/A-1030057414.CPY Infected: not-a-virus:AdWare.Win32.Maxifiles.o
c:\_RESTORE\ARCHIVE\FS71.CAB Infected: not-a-virus:AdWare.Win32.Maxifiles.o
c:\_RESTORE\ARCHIVE\FS66.CAB/A-1030060464.CPY Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\_RESTORE\ARCHIVE\FS66.CAB/A-1030060461.CPY Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\_RESTORE\ARCHIVE\FS66.CAB/A-1030060460.CPY Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\_RESTORE\ARCHIVE\FS66.CAB/A-1030060458.CPY Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\_RESTORE\ARCHIVE\FS66.CAB/A-1030060457.CPY Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\_RESTORE\ARCHIVE\FS66.CAB Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\_RESTORE\ARCHIVE\FS101.CAB/A-1030047370.CPY Infected: not-a-virus:AdWare.Win32.MyWebSearch.i
c:\_RESTORE\ARCHIVE\FS101.CAB/A-1030047369.CPY Infected: not-a-virus:AdWare.Win32.MySearch.g
c:\_RESTORE\ARCHIVE\FS101.CAB/A-1030047368.CPY Infected: not-a-virus:AdWare.Win32.MyWebSearch.l
c:\_RESTORE\ARCHIVE\FS101.CAB/A-1030047362.CPY Infected: not-a-virus:AdWare.Win32.MyWebSearch.ae
c:\_RESTORE\ARCHIVE\FS101.CAB/A-1030047321.CPY/EXE-file/WISE0012.BIN Infected: not-a-virus:AdWare.Win32.MyWebSearch.ae
c:\_RESTORE\ARCHIVE\FS101.CAB/A-1030047321.CPY/EXE-file Infected: not-a-virus:AdWare.Win32.MyWebSearch.ae
c:\_RESTORE\ARCHIVE\FS101.CAB/A-1030047321.CPY Infected: not-a-virus:AdWare.Win32.MyWebSearch.ae
c:\_RESTORE\ARCHIVE\FS101.CAB Infected: not-a-virus:AdWare.Win32.MyWebSearch.ae
c:\_RESTORE\ARCHIVE\FS114.CAB/A-1030038307.CPY Infected: Trojan.Win32.Autoit.h
c:\_RESTORE\ARCHIVE\FS114.CAB/A-1030038305.CPY Infected: not-a-virus:AdWare.Win32.MyWebSearch.i
c:\_RESTORE\ARCHIVE\FS114.CAB Infected: not-a-virus:AdWare.Win32.MyWebSearch.i
c:\WINDOWS\All Users\Application Data\Spybot - Search & Destroy\Recovery\RegistryCleaner.zip/SOPROC.EXE Suspicious: Password-protected-EXE
c:\WINDOWS\All Users\Application Data\Spybot - Search & Destroy\Recovery\RegistryCleaner.zip Suspicious: Password-protected-EXE
c:\WINDOWS\.housecall\Quarantine\freeprodtb.exe.bac_a91083 Infected: not-a-virus:AdWare.Win32.Maxifiles.o
c:\WINDOWS\.housecall\Quarantine\A-1030060457.CPY.bac_a91083 Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\WINDOWS\.housecall\Quarantine\A-1030060460.CPY.bac_a91083 Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\WINDOWS\.housecall\Quarantine\FS66.CAB.bac_a67277/A-1030060464.CPY Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\WINDOWS\.housecall\Quarantine\FS66.CAB.bac_a67277/A-1030060461.CPY Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\WINDOWS\.housecall\Quarantine\FS66.CAB.bac_a67277/A-1030060460.CPY Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\WINDOWS\.housecall\Quarantine\FS66.CAB.bac_a67277/A-1030060458.CPY Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\WINDOWS\.housecall\Quarantine\FS66.CAB.bac_a67277/A-1030060457.CPY Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\WINDOWS\.housecall\Quarantine\FS66.CAB.bac_a67277 Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\WINDOWS\.housecall\Quarantine\FS71.CAB.bac_a67277/A-1030057415.CPY Infected: not-a-virus:AdWare.Win32.NewDotNet
c:\WINDOWS\.housecall\Quarantine\FS71.CAB.bac_a67277/A-1030057414.CPY Infected: not-a-virus:AdWare.Win32.Maxifiles.o
c:\WINDOWS\.housecall\Quarantine\FS71.CAB.bac_a67277 Infected: not-a-virus:AdWare.Win32.Maxifiles.o
c:\WINDOWS\.housecall\Quarantine\FS72.CAB.bac_a67277/A-1030056402.CPY Infected: not-a-virus:AdWare.Win32.NewDotNet.e
c:\WINDOWS\.housecall\Quarantine\FS72.CAB.bac_a67277/A-1030056397.CPY Infected: not-a-virus:AdWare.Win32.NewDotNet.e
c:\WINDOWS\.housecall\Quarantine\FS72.CAB.bac_a67277/A-1030056392.CPY Infected: not-a-virus:AdWare.Win32.NewDotNet
c:\WINDOWS\.housecall\Quarantine\FS72.CAB.bac_a67277/A-1030056387.CPY Infected: not-a-virus:AdWare.Win32.NewDotNet.e
c:\WINDOWS\.housecall\Quarantine\FS72.CAB.bac_a67277 Infected: not-a-virus:AdWare.Win32.NewDotNet.e
c:\Program Files\Norton AntiVirus\Quarantine\2F06513F.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.u
c:\!KillBox\mc-110-12-0000133.exe Infected: Trojan.Win32.Autoit.h
c:\!KillBox\NPMySrch.dll Infected: not-a-virus:AdWare.Win32.MyWebSearch.i
Scan process completed.