Cretemonster,
Please find attached all logs and let me know what you think about them.
SpSeHjFix Logs(4/13/05 8:23:44 AM) SPSeHjFix started v1.09
(4/13/05 8:23:44 AM) OS: WinME (4.90.73010104)
(4/13/05 8:23:44 AM) Language: english
(4/13/05 8:23:51 AM) Disinfect started
(4/13/05 8:23:51 AM) Bad-Dll(IEP): (not found)
(4/13/05 8:23:51 AM) Bad-Dll(IEP) in BHO: (not found)
(4/13/05 8:23:51 AM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\SYSTEM\MNAIDAA.DLL
4/13/05 8:23:51 AM) Searchassistant Uninstaller - Keys Deleted
(4/13/05 8:23:51 AM) UBF: 6
(4/13/05 8:23:51 AM) UBB: 0
(4/13/05 8:23:51 AM) UBR: 22
(4/13/05 8:23:51 AM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall (deleted)
(4/13/05 8:23:51 AM) Bad IE-pages:
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
(4/13/05 8:23:51 AM) Stealth-String found: C:\WINDOWS\HLPMD.GIF
(4/13/05 8:23:51 AM) File added to delete: c:\windows\system\mnaidaa.dll
4/13/05 8:23:51 AM) File added to delete: c:\windows\temp\se.dll
(4/13/05 8:23:51 AM) File added to delete: c:\windows\hlpmd.gif
(4/13/05 8:23:51 AM) Reboot
(4/13/05 8:25:07 AM) SPSeHjFix 2nd Step
(4/13/05 8:25:07 AM) RunServicesOnce-Key: (alex)
(4/13/05 8:26:02 AM) Cleaned
*******************************************************************]
HijackThis LogLogfile of HijackThis v1.99.1
Scan saved at 8:29:01 AM, on 13/04/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\THOMSON\SPEEDTOUCH USB\DRAGDIAG.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\PROGRAM FILES\EXIF LAUNCHER\QUICKDCF.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\PROGRAM FILES\ACCESSORIES\WORDPAD.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\MY DOWNLOAD FILES\HIJACKTHIS\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) =
http://www.google.co.uk/R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) =
http://www.google.co.uk/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Wanadoo
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [LexStart] lexstart.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPFMonitor] C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe
O4 - Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cabO16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) -
http://support.f-sec...m/ols/fscax.cab********************************************************************
Startdreck LogsStartDreck (build 2.1.7 public stable) - 2005-04-13 @ 08:29:46 (GMT +01:00)
Platform: Windows ME (Win 4.90.3000 )
Internet Explorer: 6.0.2800.1106
Logged in as default at TINY-BMWCZOTZ
»Registry
»Run Keys
»Current User
»Run
*MsnMsgr="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
*NVIEW=rundll32.exe nview.dll,nViewLoadHook
»RunOnce
»Default User
»Run
*MsnMsgr="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
*NVIEW=rundll32.exe nview.dll,nViewLoadHook
»RunOnce
»Local Machine
»Run
*TaskMonitor=C:\WINDOWS\taskmon.exe
*SystemTray=SysTray.Exe
*CountrySelection=pctptt.exe
*PCTVOICE=pctvoice.exe
*LoadQM=loadqm.exe
*LexStart=lexstart.exe
*SpeedTouch USB Diagnostics="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
*QuickTime Task="C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
*TkBellExe="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
*Symantec Core LC=C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
*ccApp="C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
*Symantec NetDriver Monitor=C:\PROGRA~1\SYMNET~1\SNDMON.EXE
*sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
+OptionalComponents
+MSFS
*Installed=1
+MAPI
*Installed=1
*NoChange=1
+MAPI
*Installed=1
*NoChange=1
»RunOnce
»RunServices
*SchedulingAgent=mstask.exe
*StillImageMonitor=C:\WINDOWS\SYSTEM\STIMON.EXE
**StateMgr=C:\WINDOWS\System\Restore\StateMgr.exe
*ccEvtMgr="C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
*ccSetMgr="C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
*NPFMonitor=C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
*ScriptBlocking="C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
»RunServicesOnce
**xxv=rundll32 C:\WINDOWS\HLPMD.GIF,DllGetClassObject
»RunOnceEx
»RunServicesOnceEx
»Browser Helper Objects (LM)
*Navbho.CNavExtBho.1/{BDF3E430-B101-42AD-A544-FADC6B084872}
`InprocServer32=C:\Program Files\Norton AntiVirus\NavShExt.dll
»Files
»System/Drivers
»Running Processes
+FFCF6319=C:\WINDOWS\SYSTEM\KERNEL32.DLL
+FFFFA5B1=C:\WINDOWS\SYSTEM\MSGSRV32.EXE
+FFFFC54D=C:\WINDOWS\SYSTEM\mmtask.tsk
+FFFFCF81=C:\WINDOWS\SYSTEM\MPREXE.EXE
+FFFE06D1=C:\WINDOWS\SYSTEM\MSTASK.EXE
+FFFE6099=C:\WINDOWS\SYSTEM\STIMON.EXE
+FFFE4079=C:\WINDOWS\RUNDLL32.EXE
+FFFEEB3D=C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
+FFFECD15=C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
+FFFD53A9=C:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
+FFFCBA19=C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
+FFFE10C1=C:\WINDOWS\EXPLORER.EXE
+FFFC8459=C:\WINDOWS\TASKMON.EXE
+FFFB31F5=C:\WINDOWS\SYSTEM\SYSTRAY.EXE
+FFFB7801=C:\WINDOWS\PCTVOICE.EXE
+FFFB5BB9=C:\WINDOWS\LOADQM.EXE
+FFFBA845=C:\PROGRAM FILES\THOMSON\SPEEDTOUCH USB\DRAGDIAG.EXE
+FFFBB3BD=C:\WINDOWS\SYSTEM\WMIEXE.EXE
+FFFA3901=C:\WINDOWS\SYSTEM\LEXBCES.EXE
+FFFBF69D=C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
+FFFA23B5=C:\WINDOWS\SYSTEM\RPCSS.EXE
+FFFA245D=C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
+FFFA69E9=C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
+FFF937E1=C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
+FFF9AC91=C:\WINDOWS\SYSTEM\DDHELP.EXE
+FFF9F795=C:\WINDOWS\SYSTEM\LEXPPS.EXE
+FFF951E5=C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
+FFF83BBD=C:\PROGRAM FILES\EXIF LAUNCHER\QUICKDCF.EXE
+FFF8DFF9=C:\WINDOWS\RUNDLL32.EXE
+FFF76FCD=C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
+FFF50785=C:\PROGRAM FILES\ACCESSORIES\WORDPAD.EXE
+FFF930ED=C:\WINDOWS\SYSTEM\SPOOL32.EXE
+FFF30BFD=C:\WINDOWS\NOTEPAD.EXE
+FFF4D761=C:\MY DOWNLOAD FILES\STARTDRECK217\STARTDRECK.EXE
»Application specific
Thnak You Again for your help!