Thanks for the procedure. Completed although the folder program files\vbouncer was not there. loadingwebsite.com opening spam pages throughout this procedure.
Files from panda scan and HJT below:
Incident Status Location
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CZLENG.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MMPI32.DLL
Adware:Adware/SaveNow No disinfected C:\WINDOWS\All Users\Application Data\wsxs
Spyware:Spyware/Aveo-Attune No disinfected C:\Program Files\Aveo
Spyware:Spyware/AdClicker No disinfected Windows Registry
Adware:Adware/AdDestroyer No disinfected C:\WINDOWS\Start Menu\Programs\AdDestroyer
Adware:Adware/DelFinMedia No disinfected C:\keys.ini
Adware:Adware/ISearch No disinfected C:\WINDOWS\isrvs
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\UpdInstall.exe
Adware:Adware/Transponder No disinfected C:\WINDOWS\inf\dlmax.inf
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\TKPI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MSSLGN32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WLAVUSD.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SZDPAPI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\AHDENC32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\NYARCH16.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\UYLMON.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\JFPL400.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WBOCK32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OZFOX32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ISGSHL.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WNNNET16.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\hlztbi08.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mWpi32x.dll
Spyware:Spyware/Virtumonde No disinfected C:\WINDOWS\SYSTEM\akcore.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IHM32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\wxsdmoe.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MITCP.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OEBCCP32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\QVVD.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\PSPD.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\EKABLE3.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SXLWAPI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\NYDLL.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ALMUI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DQ3J.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\PLSPL.DLL
Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe
Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM\nsvsvc\nsvs.dll
Adware:Adware/DelFinMedia No disinfected C:\WINDOWS\SYSTEM\nsvsvc\nsv.ocx
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\smnscfg.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MVCUIW32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DA7VB.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WDAUPD98.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DQCNDI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DNNMPNTW.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DNDRM.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MWVCRT.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\NGDLL.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MKRLE32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DO3J.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\II41_QCX.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CZOL.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\Syace.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CzlEng.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SVORAGE.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mjisip.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\huinv.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WJI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mpvidctl.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mMpi32.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MHJAVA.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WPPLENC.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MTWEBDVD.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CQMDLG32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MGDVDOPT.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\QDDWIPES.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\TDPI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IB1XCG9X.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\UpdInstall.exe
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\AHHOOK.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IKDKCS32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\EDIFLN62.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MDUTILSE.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RGR20.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OWTWA400.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mtnetobj.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MJCD30.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\FO20.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IQS.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OEE32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DZSKCP16.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SLORAGE.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WHBVW.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\AAYCFILT.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OEGFS400.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mbndex.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\LQRT.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RQRC32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\EJIFLN62.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IVIRCL.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\JCMD400.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IQ41_QCX.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\hginv.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CQBINET.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MCEXCL40.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\EYH4E0M2.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\Opbcint.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DOCNDI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\QMVD.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MKMFCNT.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WRWIZDLL.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DTTACLEN.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\avferror.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\AKV01W9X.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RYOCURS.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IN1XGDEV.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\lwflt09.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\hhzcon08.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\hyzstsin.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\wzvdmod.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OOE32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MOSYSTEM.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\eecapi.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MERECR40.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WPAUPD98.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DZDIM700.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MDSIGN32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\wgstream.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\HYINK.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IO1XGDEV.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\HTINK.DLL
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\INF\CERES.INF
Adware:Adware/Transponder No disinfected C:\WINDOWS\INF\PYNIX.INF
Adware:Adware/Transponder No disinfected C:\WINDOWS\INF\DLMAX.INF
Adware:Adware/StartPage.EL No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.1\dbaccess.exe
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts
Adware:Adware/IESearchBar No disinfected C:\WINDOWS\isrvs\mfiltis.dll
Adware:Adware/ISearch No disinfected C:\WINDOWS\isrvs\isearch.xpi
Adware:Adware/ISearch No disinfected C:\WINDOWS\isrvs\isearch.xpi[isearch.jar][isearch.js]
Adware:Adware/ISearch No disinfected C:\WINDOWS\deskbar.ini
Adware:Adware/ISearch No disinfected C:\WINDOWS\delprot.ini
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\Buddy.exe
Adware:Adware/VirtualBouncer No disinfected C:\Program Files\Common Files\SYSTEM\Mapi\1033\95\WrapperOuter.exe
Adware:Adware/DelFinMedia No disinfected C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe
Adware:Adware/ISearch No disinfected C:\Program Files\Mozilla Firefox\extensions\{2bafa858-4ff3-4207-822e-ef46d1b431de}\chrome\isearch.jar[isearch.js]
Adware:Adware/DelFinMedia No disinfected C:\keys.ini
Adware:Adware/VirtualBouncer No disinfected C:\WrapperOuter.exe
Logfile of HijackThis v1.99.1
Scan saved at 00:21:16, on 18/05/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HJT\HIJACKTHIS.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://bt.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [MSConfigReminder] C:\WINDOWS\SYSTEM\msconfig.exe /reminder
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVG7\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O12 - Plugin for .hpb: C:\PROGRA~1\INTERN~1\PLUGINS\nphpipb.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .WAV: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://bt.yahoo.com
O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) -
http://register.btin...bcontrol023.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cab