HiJackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 1:31:05 PM, on 7/20/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\INETCNTRL\INETCNTRL.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YMSGR_TRAY.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [InetCntrl] C:\WINDOWS\SYSTEM\INETCNTRL\INETCNTRL.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRAM FILES\YAHOO!\MESSENGER\ypager.exe -quiet
O4 - Startup: PowerReg Scheduler V3.exe
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - http://www.streamaud...d/ccpm_0237.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.app.../ITDetector.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-17.cab
O16 - DPF: {5D8844F9-1CB8-11D2-A0A0-00600859EB9F} (PatchCtl Class) - file://C:\Games\Fifa2004\update.1.1\patchx2.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.game...outLauncher.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalci...illama/ampx.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spys...rCabInstall.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
ActiveScan log:
Incident Status Location
Adware:adware/portalscan No disinfected C:\WINDOWS\SYSTEM\winupdt.bin
Adware:adware/searchforit No disinfected C:\WINDOWS\SYSTEM\SYSsfitb.dll
Adware:adware/sqwire No disinfected C:\WINDOWS\SYSTEM\tsuninst.exe
Adware:adware/ncase No disinfected C:\TEMP\salm_kyf.dat
Adware:adware/bookedspace No disinfected C:\WINDOWS\cfgmgr52.ini
Spyware:spyware/dyfuca No disinfected C:\WINDOWS\nem220.dll
Adware:adware/wupd No disinfected C:\PROGRAM FILES\AdTools Service
Adware:adware/fizzle No disinfected C:\PROGRAM FILES\FwBarTemp
Adware:adware/oemji No disinfected C:\PROGRAM FILES\Oemji
Adware:adware/sahagent No disinfected C:\WINDOWS\SYSTEM\SahImages
Adware:adware/wintools No disinfected HKEY_CLASSES_ROOT\PROTOCOLS\NAME-SPACE HANDLER\RES
Adware:adware/elitebar No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS\USER AGENT\POST PLATFORM\IEBAR
Spyware:spyware/virtumonde No disinfected HKEY_CLASSES_ROOT\Interface\{05080e6b-a88a-4cfd-8c3d-9b2557670b6e}
Adware:Adware/Searchforit No disinfected C:\WINDOWS\SYSTEM\SYSsfitb.dll
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\SYSTEM\tsuninst.exe
Adware:Adware/ClkOptimizer No disinfected C:\WINDOWS\TEMP\pav196.TMP
Adware:Adware/ClkOptimizer No disinfected C:\WINDOWS\TEMP\pav5345.TMP
Adware:Adware/PortalScan No disinfected C:\WINDOWS\Helper101.dll
Adware:Adware/BookedSpace No disinfected C:\WINDOWS\dldhrthn.exe
Adware:Adware/ClkOptimizer No disinfected C:\WINDOWS\khks.dll
Adware:Adware/ClkOptimizer No disinfected C:\WINDOWS\eaea.dll
Adware:Adware/Oemji No disinfected C:\Program Files\Common Files\Oem Common\robj1.dll
Adware:Adware/Oemji No disinfected C:\Program Files\Common Files\Oem Common\bayesobj.dll
Adware:Adware/Sqwire No disinfected C:\Program Files\Common Files\omof\omofd\omofc.dll
Adware:Adware/SideFind No disinfected C:\Program Files\Common Files\omof\omofp.exe
Adware:Adware/WUpd No disinfected C:\Program Files\AdTools Service\AdTools.exe
Adware:Adware/eZula No disinfected C:\Program Files\sf\sf.exe
Adware:Adware/Oemji No disinfected C:\Program Files\Oemji\OemjiSearchPlus\OemjiPls.dll
Adware:Adware/Oemji No disinfected C:\Program Files\Oemji\Toolbar\OemjiSrc.dll
Adware:Adware/Oemji No disinfected C:\Program Files\Oemji\Toolbar\WebPoi.dll
Adware:Adware/Adshooter No disinfected C:\Hijackthis\backups\backup-20050720-095224-841.dll
Adware:Adware/BookedSpace No disinfected C:\Hijackthis\backups\backup-20050720-095224-228.dll
Thanks!