Okay, this is all way over my head, but here's the information you requested. Thanks for your patience:
My HJT log (note that the UTHM area.exe is back):
Logfile of HijackThis v1.99.1
Scan saved at 10:12:53 PM, on 8/29/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 SP1 (5.50.4134.0600)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\DELAYRUN.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\WINDOWS\SYSTEM\USBMMKBD.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\@HOME\TIOGA\BIN\TGCMD.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
C:\PROGRAM FILES\SONY CORPORATION\IMAGE TRANSFER\SONYTRAY.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\PROGRAM FILES\UTHM\AREA.EXE
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\WINDOWS\DESKTOP\PROTECTION\HIJACKTHIS-1.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by @Home
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [DJRegFix] regedit /s c:\hp\djregfix.reg
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Delay] C:\WINDOWS\delayrun.exe
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [USBMMKBD] usbmmkbd.exe
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\Program Files\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [TgAddServer] "c:\@Home\tioga\bin\tgfix" /fds "
http://www/download/tioga"
O4 - HKLM\..\Run: [Tgcmd] "c:\@Home\tioga\bin\tgcmd.exe" /server /nosystray
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [Keyboard Manager] c:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - HKCU\..\Run: [Uate] C:\Program Files\uthm\area.exe
O4 - Startup: Image Transfer.lnk = C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
And here is the log.txt from RunThis.bat:
Log of L2M9XFix v1
************
Running from directory:
C:\WINDOWS\Desktop\l2m9xfix
************
Files found:
C:\WINDOWS\system\BFOWSEUI.DLL
C:\WINDOWS\system\BFOWSEUI.DLL
C:\WINDOWS\system\BFOWSEUI.DLL
C:\WINDOWS\system\BFOWSEUI.DLL
C:\WINDOWS\system\DCNPUT.DLL
C:\WINDOWS\system\DCNPUT.DLL
C:\WINDOWS\system\DCNPUT.DLL
C:\WINDOWS\system\DCNPUT.DLL
C:\WINDOWS\system\DCSPEX.DLL
C:\WINDOWS\system\DCSPEX.DLL
C:\WINDOWS\system\DCSPEX.DLL
C:\WINDOWS\system\DCSPEX.DLL
C:\WINDOWS\system\IIM32.DLL
C:\WINDOWS\system\IIM32.DLL
C:\WINDOWS\system\IIM32.DLL
C:\WINDOWS\system\IIM32.DLL
C:\WINDOWS\system\IP_NDI.DLL
C:\WINDOWS\system\IP_NDI.DLL
C:\WINDOWS\system\IP_NDI.DLL
C:\WINDOWS\system\IP_NDI.DLL
C:\WINDOWS\system\ldimg11n.dll
C:\WINDOWS\system\ldimg11n.dll
C:\WINDOWS\system\ldimg11n.dll
C:\WINDOWS\system\ldimg11n.dll
C:\WINDOWS\system\LYDIS12n.DLL
C:\WINDOWS\system\LYDIS12n.DLL
C:\WINDOWS\system\LYDIS12n.DLL
C:\WINDOWS\system\LYDIS12n.DLL
C:\WINDOWS\system\MBOTHUNK.DLL
C:\WINDOWS\system\MBOTHUNK.DLL
C:\WINDOWS\system\MBOTHUNK.DLL
C:\WINDOWS\system\MBOTHUNK.DLL
C:\WINDOWS\system\mgiosd32.dll
C:\WINDOWS\system\mgiosd32.dll
C:\WINDOWS\system\mgiosd32.dll
C:\WINDOWS\system\mgiosd32.dll
C:\WINDOWS\system\MIVFW32.DLL
C:\WINDOWS\system\MIVFW32.DLL
C:\WINDOWS\system\MIVFW32.DLL
C:\WINDOWS\system\MIVFW32.DLL
C:\WINDOWS\system\mjhp.dll
C:\WINDOWS\system\mjhp.dll
C:\WINDOWS\system\mjhp.dll
C:\WINDOWS\system\mjhp.dll
C:\WINDOWS\system\mjikbdfr.dll
C:\WINDOWS\system\mjikbdfr.dll
C:\WINDOWS\system\mjikbdfr.dll
C:\WINDOWS\system\mjikbdfr.dll
C:\WINDOWS\system\MOMFCNT.DLL
C:\WINDOWS\system\MOMFCNT.DLL
C:\WINDOWS\system\MOMFCNT.DLL
C:\WINDOWS\system\MOMFCNT.DLL
C:\WINDOWS\system\mruni10.dll
C:\WINDOWS\system\mruni10.dll
C:\WINDOWS\system\mruni10.dll
C:\WINDOWS\system\mruni10.dll
C:\WINDOWS\system\MWPMSP.DLL
C:\WINDOWS\system\MWPMSP.DLL
C:\WINDOWS\system\MWPMSP.DLL
C:\WINDOWS\system\MWPMSP.DLL
C:\WINDOWS\system\NKCPL.DLL
C:\WINDOWS\system\NKCPL.DLL
C:\WINDOWS\system\NKCPL.DLL
C:\WINDOWS\system\NKCPL.DLL
C:\WINDOWS\system\NNNDS.DLL
C:\WINDOWS\system\NNNDS.DLL
C:\WINDOWS\system\NNNDS.DLL
C:\WINDOWS\system\NNNDS.DLL
C:\WINDOWS\system\NQDLL.DLL
C:\WINDOWS\system\NQDLL.DLL
C:\WINDOWS\system\NQDLL.DLL
C:\WINDOWS\system\NQDLL.DLL
C:\WINDOWS\system\OCENGL32.DLL
C:\WINDOWS\system\OCENGL32.DLL
C:\WINDOWS\system\OCENGL32.DLL
C:\WINDOWS\system\OCENGL32.DLL
C:\WINDOWS\system\ONBC32.DLL
C:\WINDOWS\system\ONBC32.DLL
C:\WINDOWS\system\ONBC32.DLL
C:\WINDOWS\system\ONBC32.DLL
C:\WINDOWS\system\OWECNV32.DLL
C:\WINDOWS\system\OWECNV32.DLL
C:\WINDOWS\system\OWECNV32.DLL
C:\WINDOWS\system\OWECNV32.DLL
C:\WINDOWS\system\PASPL.DLL
C:\WINDOWS\system\PASPL.DLL
C:\WINDOWS\system\PASPL.DLL
C:\WINDOWS\system\PASPL.DLL
C:\WINDOWS\system\pomas.dll
C:\WINDOWS\system\pomas.dll
C:\WINDOWS\system\pomas.dll
C:\WINDOWS\system\pomas.dll
C:\WINDOWS\system\pudx5016.dll
C:\WINDOWS\system\pudx5016.dll
C:\WINDOWS\system\pudx5016.dll
C:\WINDOWS\system\pudx5016.dll
C:\WINDOWS\system\PYUSTAB.DLL
C:\WINDOWS\system\PYUSTAB.DLL
C:\WINDOWS\system\PYUSTAB.DLL
C:\WINDOWS\system\PYUSTAB.DLL
C:\WINDOWS\system\RBAPH.DLL
C:\WINDOWS\system\RBAPH.DLL
C:\WINDOWS\system\RBAPH.DLL
C:\WINDOWS\system\RBAPH.DLL
C:\WINDOWS\system\RRR20.DLL
C:\WINDOWS\system\RRR20.DLL
C:\WINDOWS\system\RRR20.DLL
C:\WINDOWS\system\RRR20.DLL
C:\WINDOWS\system\SSRRUN.DLL
C:\WINDOWS\system\SSRRUN.DLL
C:\WINDOWS\system\SSRRUN.DLL
C:\WINDOWS\system\SSRRUN.DLL
C:\WINDOWS\system\Utderwater.dll
C:\WINDOWS\system\Utderwater.dll
C:\WINDOWS\system\Utderwater.dll
C:\WINDOWS\system\Utderwater.dll
C:\WINDOWS\system\wgidx.dll
C:\WINDOWS\system\wgidx.dll
C:\WINDOWS\system\wgidx.dll
C:\WINDOWS\system\wgidx.dll
C:\WINDOWS\system\WII.DLL
C:\WINDOWS\system\WII.DLL
C:\WINDOWS\system\WII.DLL
C:\WINDOWS\system\WII.DLL
************
Registry entries found:
[HKEY_CLASSES_ROOT\CLSID\{DC6C76DB-7762-46E3-A2A1-F4B58B611D55}\InprocServer32]
@="C:\\WINDOWS\\system\\DCSPEX.DLL"
[HKEY_CLASSES_ROOT\CLSID\{DC6C76DB-7762-46E3-A2A1-F4B58B611D55}\InprocServer32]
@="C:\\WINDOWS\\system\\DCSPEX.DLL"
[HKEY_CLASSES_ROOT\CLSID\{DC6C76DB-7762-46E3-A2A1-F4B58B611D55}\InprocServer32]
@="C:\\WINDOWS\\system\\DCSPEX.DLL"
[HKEY_CLASSES_ROOT\CLSID\{DC6C76DB-7762-46E3-A2A1-F4B58B611D55}\InprocServer32]
@="C:\\WINDOWS\\system\\DCSPEX.DLL"
[HKEY_CLASSES_ROOT\CLSID\{4A126662-22C1-4163-A462-A1395C2FDD76}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\MOMFCNT.DLL"
[HKEY_CLASSES_ROOT\CLSID\{4A126662-22C1-4163-A462-A1395C2FDD76}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\MOMFCNT.DLL"
[HKEY_CLASSES_ROOT\CLSID\{4A126662-22C1-4163-A462-A1395C2FDD76}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\MOMFCNT.DLL"
[HKEY_CLASSES_ROOT\CLSID\{4A126662-22C1-4163-A462-A1395C2FDD76}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\MOMFCNT.DLL"
[HKEY_CLASSES_ROOT\CLSID\{3D08DC1B-15E1-4E8C-80B5-BEDDB9F845E1}\InprocServer32]
@="C:\\WINDOWS\\system\\NNNDS.DLL"
[HKEY_CLASSES_ROOT\CLSID\{3D08DC1B-15E1-4E8C-80B5-BEDDB9F845E1}\InprocServer32]
@="C:\\WINDOWS\\system\\NNNDS.DLL"
[HKEY_CLASSES_ROOT\CLSID\{3D08DC1B-15E1-4E8C-80B5-BEDDB9F845E1}\InprocServer32]
@="C:\\WINDOWS\\system\\NNNDS.DLL"
[HKEY_CLASSES_ROOT\CLSID\{3D08DC1B-15E1-4E8C-80B5-BEDDB9F845E1}\InprocServer32]
@="C:\\WINDOWS\\system\\NNNDS.DLL"
[HKEY_CLASSES_ROOT\CLSID\{2CAECBAA-7F92-499F-8D7D-05FCF155E96F}\InprocServer32]
@="C:\\WINDOWS\\system\\Utderwater.dll"
[HKEY_CLASSES_ROOT\CLSID\{2CAECBAA-7F92-499F-8D7D-05FCF155E96F}\InprocServer32]
@="C:\\WINDOWS\\system\\Utderwater.dll"
[HKEY_CLASSES_ROOT\CLSID\{2CAECBAA-7F92-499F-8D7D-05FCF155E96F}\InprocServer32]
@="C:\\WINDOWS\\system\\Utderwater.dll"
[HKEY_CLASSES_ROOT\CLSID\{2CAECBAA-7F92-499F-8D7D-05FCF155E96F}\InprocServer32]
@="C:\\WINDOWS\\system\\Utderwater.dll"
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{28F92EF3-90A6-656B-CDAA-787B64405FB9}"=""
************
Killing Explorer
Done!
Killing Rundll32
Done!
Removing malicious CLSID(s)
Done!
Restarting Explorer
Done!
Deleting malicious files
Done!
Finished!
That is the end of the log.txt from RunThis.bat.
Thanks again for all the assistance. These browser hijackings and popups are driving me nuts.
Ed