Went thru the list...no spyware or anti virus scans will not execute...IE has been taken over, multiple popups, missing files or corrupt files. Please help.
Logfile of HijackThis v1.99.1
Scan saved at 8:39:36 PM, on 06/07/2005
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\INET20037\SERVICES.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\WINOA386.MOD
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/spage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/spage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.oemji.com/side_search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
F1 - win.ini: run=C:\WINDOWS\INET20037\SERVICES.EXE
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.netscape.com"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\1zmvc408.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRAM%20FILES%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\1zmvc408.slt\prefs.js)
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: Cls - {CF021F40-3E14-23A5-CBA2-717765728274} - C:\WINDOWS\SYSTEM\WER8274.DLL
O2 - BHO: (no name) - {505E5FC1-C9EB-11D9-AC4C-008061C7CF9F} - C:\WINDOWS\SYSTEM\ANFL.DLL
O2 - BHO: BHOmodObj Class - {7F6828CA-9E42-462C-BC60-418C8144012C} - C:\WINDOWS\SYSTEM\BHOMOD.DLL
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\CERES.DLL
O2 - BHO: PBHelper - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\PROGRAM FILES\OEMJI\TOOLBAR\POPUPBLOCKER\PBHELPER.DLL
O2 - BHO: OemjiSearchPlus - {D240DC29-C093-4388-B71F-A7103C796B0C} - C:\PROGRAM FILES\OEMJI\OEMJISEARCHPLUS\OEMJIPLS.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: AdwareFilter - {1028F737-81E7-452B-A860-E50CAD90A08C} - C:\PROGRAM FILES\ADWAREFILTERTOOLBAR\ADWAREFILTER.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Oemji - {804DB5C7-31E6-4885-850A-F1941B58A4C7} - C:\PROGRAM FILES\OEMJI\TOOLBAR\OEMJISRC.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\INET20037\SERVICES.EXE
O4 - HKLM\..\Run: [eumpap] c:\windows\system\eumpap.exe
O4 - HKLM\..\Run: [SpySpotter] C:\PROGRAM FILES\SPYSPOTTER\SpySpotter.exe -onreboot
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Srv32 spool service] C:\WINDOWS\System\spoolsrv32.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\INET20037\SERVICES.EXE
O4 - Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\UOWS\PldReminder.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Microsoft AntiSpyware helper - {AE0807C0-9C32-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {AE0807C0-9C32-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {101D4EE0-9C3B-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {101D4EE0-9C3B-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {71E64AC0-9C43-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {71E64AC0-9C43-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {D4264B60-9C4B-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D4264B60-9C4B-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {36E36B40-9C54-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {36E36B40-9C54-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {98EF8AA0-9C5C-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {98EF8AA0-9C5C-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {FE754060-9C64-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {FE754060-9C64-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {60A47820-9C6D-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {60A47820-9C6D-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {C2F3BB00-9C75-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {C2F3BB00-9C75-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {337E4AA0-9C7D-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {337E4AA0-9C7D-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {4132A3E0-9DCB-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {4132A3E0-9DCB-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {A381E6C0-9DD3-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {A381E6C0-9DD3-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {05A055A0-9DDC-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {05A055A0-9DDC-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {22F91800-A1DB-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {22F91800-A1DB-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {850E5F20-A1E3-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {850E5F20-A1E3-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {E6D8E1A0-A1EB-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {E6D8E1A0-A1EB-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {CEC13B80-D1BB-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {CEC13B80-D1BB-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {3C2B9920-D2A4-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {3C2B9920-D2A4-11D9-AC4C-0080C8F8AAE5} - (no file) (HKCU)
O16 - DPF: SEAGULL J Walk Java Client 3_1C1 -
http://12.14.82.69/jwalk/jwalk_ie.cabO16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} -
http://download.spys...rCabInstall.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = jots
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 151.164.1.8,151.164.11.201
O18 - Filter: text/html - {2237E4C0-D208-11D9-AC4C-0080965CE1E3} - C:\WINDOWS\SYSTEM\ANFL.DLL
O18 - Filter: text/plain - {2237E4C0-D208-11D9-AC4C-0080965CE1E3} - C:\WINDOWS\SYSTEM\ANFL.DLL
I have merged your two topics together. Please keep all questions/comments/replies about this issue in THIS thread!
Edited by ~Kat~, 07 June 2005 - 07:44 PM.