Ok, i'm devoting today to sort this out. I started from scratch and followed your solution through, here are my logs.
SPSeHjFix log:
(1/1/00 00:02:07) SPSeHjFix started v1.09
(1/1/00 00:02:07) OS: WinME (4.90.73010104)
(1/1/00 00:02:07) Language: english
(1/1/00 00:02:15) Disinfect started
(1/1/00 00:02:15) Bad-Dll(IEP): (not found)
(1/1/00 00:02:15) Bad-Dll(IEP) in BHO: (not found)
(1/1/00 00:02:15) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\SYSTEM\APOA.DLL
(1/1/00 00:02:15) Searchassistant Uninstaller - Keys Deleted
(1/1/00 00:02:15) UBF: 6
(1/1/00 00:02:15) UBB: 2
(1/1/00 00:02:15) FilterKey: HKCR\text/html (deleted)
(1/1/00 00:02:15) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(1/1/00 00:02:15) FilterKey: HKCR\CLSID\{84016CF2-D8F2-4936-B9BD-7E0FDC27521E} (deleted)
(1/1/00 00:02:15) FilterKey: HKCR\text/plain (deleted)
(1/1/00 00:02:15) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(1/1/00 00:02:15) FilterKey: HKCR\CLSID\{84016CF2-D8F2-4936-B9BD-7E0FDC27521E} (error while deleting)
(1/1/00 00:02:15) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B06C80B-5774-49B8-8CCF-E2ABA6DACFFC} (deleted)
(1/1/00 00:02:15) BHO-Key: HKCR\CLSID\{5B06C80B-5774-49B8-8CCF-E2ABA6DACFFC} (deleted)
(1/1/00 00:02:15) UBR: 9
(1/1/00 00:02:15) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall (deleted)
(1/1/00 00:02:15) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Default_Page_URL: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(1/1/00 00:02:15) Stealth-String not found:
(1/1/00 00:02:15) File added to delete: c:\windows\system\apoa.dll
(1/1/00 00:02:15) File added to delete: c:\windows\system\apoa.dll
(1/1/00 00:02:15) File added to delete: c:\windows\temp\se.dll
(1/1/00 00:02:15) Reboot
(1/1/00 02:20:31) SPSeHjFix 2nd Step
(1/1/00 02:20:31) RunServicesOnce-Key: (edited)
(1/1/00 02:20:38) Cleaned
(1/1/00 00:27:45) SPSeHjFix started v1.09
(1/1/00 00:27:45) OS: WinME (4.90.73010104)
(1/1/00 00:27:45) Language: english
(1/1/00 00:59:33) SPSeHjFix started v1.09
(1/1/00 00:59:33) OS: WinME (4.90.73010104)
(1/1/00 00:59:33) Language: english
(1/1/00 00:59:35) Disinfect started
(1/1/00 00:59:35) Bad-Dll(IEP): (not found)
(1/1/00 00:59:35) Bad-Dll(IEP) in BHO: (not found)
(1/1/00 00:59:35) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\SYSTEM\APOA.DLL
(1/1/00 00:59:35) Searchassistant Uninstaller - Keys Deleted
(1/1/00 00:59:35) UBF: 4
(1/1/00 00:59:35) UBB: 1
(1/1/00 00:59:35) UBR: 8
(1/1/00 00:59:35) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Default_Page_URL: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
(1/1/00 00:59:35) Stealth-String not found:
(1/1/00 00:59:36) File added to delete: c:\windows\system\apoa.dll
(1/1/00 00:59:36) Reboot
(1/1/00 01:00:36) SPSeHjFix 2nd Step
(1/1/00 01:00:36) RunServicesOnce-Key: (edited)
(1/1/00 01:00:42) Cleaned
(1/2/80 00:02:05) SPSeHjFix started v1.09
(1/2/80 00:02:05) OS: WinME (4.90.73010104)
(1/2/80 00:02:05) Language: english
(1/2/80 00:02:19) Disinfect started
(1/2/80 00:02:19) Bad-Dll(IEP): (not found)
(1/2/80 00:02:19) Bad-Dll(IEP) in BHO: (not found)
(1/2/80 00:02:19) UBF: 4
(1/2/80 00:02:19) UBB: 1
(1/2/80 00:02:19) UBR: 9
(1/2/80 00:02:19) Bad IE-pages:
(1/2/80 00:02:19) Stealth-String not found:
(1/2/80 00:02:19) Not infected->END
(1/1/00 00:12:08) SPSeHjFix started v1.09
(1/1/00 00:12:08) OS: WinME (4.90.73010104)
(1/1/00 00:12:08) Language: english
(1/1/00 00:15:00) SPSeHjFix started v1.09
(1/1/00 00:15:00) OS: WinME (4.90.73010104)
(1/1/00 00:15:00) Language: english
(1/1/00 00:15:08) Disinfect started
(1/1/00 00:15:08) Bad-Dll(IEP): (not found)
(1/1/00 00:15:08) Bad-Dll(IEP) in BHO: (not found)
(1/1/00 00:15:08) UBF: 4
(1/1/00 00:15:08) UBB: 1
(1/1/00 00:15:08) UBR: 9
(1/1/00 00:15:08) Bad IE-pages:
(1/1/00 00:15:08) Stealth-String not found:
(1/1/00 00:15:08) Not infected->END
(1/1/00 00:02:39) SPSeHjFix started v1.09
(1/1/00 00:02:39) OS: WinME (4.90.73010104)
(1/1/00 00:02:39) Language: english
(1/1/00 00:02:56) Disinfect started
(1/1/00 00:02:56) Bad-Dll(IEP): (not found)
(1/1/00 00:02:56) Bad-Dll(IEP) in BHO: (not found)
(1/1/00 00:02:56) UBF: 4
(1/1/00 00:02:56) UBB: 1
(1/1/00 00:02:56) UBR: 9
(1/1/00 00:02:56) Bad IE-pages:
(1/1/00 00:02:56) Stealth-String not found:
(1/1/00 00:02:56) Not infected->END
Kaspersky log:
Duration of the scan process: 4615 sec
Infected Object Name - Virus Name
c:\_RESTORE\TEMP\A0178172.CPY Infected: Virus.Win9x.CIH.dam
c:\_RESTORE\TEMP\APOA.0 Infected: Trojan.Win32.StartPage.acd
c:\_RESTORE\TEMP\SE.0 Infected: Trojan.Win32.StartPage.gv
c:\WINDOWS\SYSTEM\ibm00003.exe Infected: Trojan-PSW.Win32.Agent.bu
c:\WINDOWS\SYSTEM\ibm00003.dll Infected: Trojan-PSW.Win32.Agent.bu
c:\WINDOWS\SYSTEM\ibm00002.dll Infected: Trojan-PSW.Win32.Agent.bu
c:\WINDOWS\SYSTEM\msvcrtdd.dll Infected: Trojan-PSW.Win32.Agent.bu
c:\WINDOWS\SYSTEM\ibm00004.dll Infected: Trojan-PSW.Win32.Agent.bu
c:\WINDOWS\odbs.log Infected: Trojan.VBS.Valg
c:\WINDOWS\it.bat Infected: Trojan-Clicker.Win32.Qhost.a
c:\WINDOWS\hosts.20031103-174820.backup Infected: Trojan-Clicker.Win32.Qhost.a
c:\WINDOWS\hosts.20031104-165425.backup Infected: Trojan-Clicker.Win32.Qhost.a
c:\WINDOWS\hosts.20031110-204822.backup Infected: Trojan-Clicker.Win32.Qhost.a
c:\WINDOWS\hosts.20031119-184759.backup Infected: Trojan-Clicker.Win32.Qhost.a
c:\WINDOWS\hosts.20031203-142311.backup Infected: Trojan-Clicker.Win32.Qhost.a
c:\WINDOWS\hosts.20031204-180036.backup Infected: Trojan-Clicker.Win32.Qhost.a
c:\WINDOWS\hosts.20031205-181244.backup Infected: Trojan-Clicker.Win32.Qhost.a
c:\WINDOWS\hosts.20031206-134230.backup Infected: Trojan-Clicker.Win32.Qhost.a
c:\WINDOWS\hosts.20031206-204226.backup Infected: Trojan-Clicker.Win32.Qhost.a
c:\WINDOWS\hosts.20031206-205801.backup Infected: Trojan-Clicker.Win32.Qhost.a
c:\WINDOWS\hosts.20031206-211817.backup Infected: Trojan-Clicker.Win32.Qhost.a
c:\Program Files\Kazaa\PerfectNavUninstall.exe/data0003 Infected: Trojan-Downloader.Win32.Keenval.e
c:\Program Files\Kazaa\PerfectNavUninstall.exe Infected: Trojan-Downloader.Win32.Keenval.e
c:\setup6.exe Infected: Trojan.Win32.Liech.d
c:\eied_s7.cab/eied_s7_c_52.exe Infected: Trojan-Downloader.Win32.Mediket.bb
c:\eied_s7.cab Infected: Trojan-Downloader.Win32.Mediket.bb
c:\q761596.exe Infected: Trojan-Downloader.Win32.Femad.ab
Scan process completed.
HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 02:31:20, on 01/01/2000
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\GSICON.EXE
C:\WINDOWS\SYSTEM\DSLAGENT.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\TWAIN_32\1200 UB\WATCH.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\BT BROADBAND\HELP\BIN\MPBTN.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\HJT\HIJACKTHIS.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer,Search =
http://www.puh.ru/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://www.puh.ru/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.supanet.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = ,
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = ,
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: YBIOCtrl Class - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [GSICONEXE] gsicon.exe
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [MouseDrv] C:\WINDOWS\TEMP\LINK.TXT
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [MouseDrv] C:\WINDOWS\TEMP\LINK.TXT
O4 - HKCU\..\Run: [Shell] "C:\WINDOWS\SYSTEM\ibm00003.exe"
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\1200 UB\WATCH.exe
O4 - Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe
O4 - User Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - User Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\1200 UB\WATCH.exe
O4 - User Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} -
http://www.spywarest...es2/Install.cabO16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...ebscan_ansi.cabO16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.t...all/xscan60.cabThere you go. Thankyou, you're instructions are very good.