Following a similar problem from another post with the same operating system I have installed and ran SpSeHjfix_, HijackThis.exe, and mwav.exe. I have saved the logs for both which are posted. I got to the the point of the HijackThis Fix and nt want to delete something in error. Any help would be appriciated. Thanks.
doLogfile of HijackThis v1.99.1
Scan saved at 5:52:39 PM, on 9/27/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - {06163FED-B021-F854-B858-3911DE5D7898} - blank (file missing)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDSG.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Search - {FFD41416-B28E-F340-79CD-9AE1E2257A50} - blank (file missing)
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKCU\..\Run: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
O4 - HKCU\..\RunServices: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
O14 - IERESET.INF: START_PAGE_URL=http://hp.my.yahoo.com
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?323
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.app.../ITDetector.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
MWAV SCAN LOG
File C:\WINDOWS\SYSTEM\dkn.exe infected by "Trojan-Downloader.Win32.Lastad.p" Virus. Action Taken: File Deleted.
File C:\WINDOWS\SYSTEM\2bundle.exe infected by "Trojan-Dropper.Win32.Agent.hl" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\b.com infected by "Trojan-Dropper.Win32.Agent.pb" Virus. Action Taken: File Deleted.
File C:\WINDOWS\Temporary Internet Files\Content.IE5\J1H11XT6\AppWrap[1].exe infected by "Trojan-Dropper.Win32.Agent.pb" Virus. Action Taken: File Deleted.
File C:\WINDOWS\Temporary Internet Files\Content.IE5\NEBZWDXI\deliver46860[1].htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\WINDOWS\Temporary Internet Files\Content.IE5\NEBZWDXI\AproposClientInstaller[1] infected by "Trojan-Downloader.Win32.Apropo.ag" Virus. Action Taken: File Deleted.
File C:\WINDOWS\Temporary Internet Files\Content.IE5\MR0L2ZEX\AppWrap[1].exe infected by "Trojan-Dropper.Win32.Agent.pb" Virus. Action Taken: File Deleted.
File C:\WINDOWS\Temporary Internet Files\Content.IE5\8LIJC563\AppWrap[1].exe infected by "Trojan-Dropper.Win32.Agent.pb" Virus. Action Taken: File Deleted.
File C:\_RESTORE\TEMP\A0055637.CPY tagged as not-a-virus:AdWare.FlashEnhancer.b. No Action Taken.
File C:\_RESTORE\TEMP\A0055638.CPY tagged as not-a-virus:AdWare.Broadcap.d. No Action Taken.
File C:\_RESTORE\TEMP\CORNSE~1.0 infected by "Trojan-Dropper.Win32.Agent.hl" Virus. Action Taken: File Deleted.
File C:\_RESTORE\TEMP\A0055666.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0055695.CPY tagged as not-a-virus:AdWare.ToolBar.ISearch.d. No Action Taken.
File C:\_RESTORE\TEMP\A0055696.CPY infected by "Trojan-Spy.Win32.VB.eh" Virus. Action Taken: File Deleted.
File C:\_RESTORE\TEMP\A0055703.CPY tagged as not-a-virus:AdWare.Adstart.i. No Action Taken.
File C:\_RESTORE\TEMP\A0055605.CPY tagged as not-a-virus:AdWare.SideSearch.i. No Action Taken.
File C:\_RESTORE\TEMP\A0055618.CPY tagged as not-a-virus:AdWare.Broadcap.d. No Action Taken.
File C:\_RESTORE\TEMP\A0055622.CPY infected by "Trojan-Downloader.Win32.PurityScan.an" Virus. Action Taken: File Deleted.
File C:\_RESTORE\TEMP\A0055714.CPY infected by "Trojan-Downloader.Win32.Agent.lg" Virus. Action Taken: File Deleted.
File C:\_RESTORE\TEMP\A0056739.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0056899.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0056925.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0055598.CPY tagged as not-a-virus:AdWare.FlashEnhancer.b. No Action Taken.
File C:\_RESTORE\TEMP\A0057114.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0057205.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0057215.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0057218.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0057222.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0057225.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0057228.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0057238.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0057244.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0057250.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0057308.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0057375.CPY tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\_RESTORE\TEMP\A0059080.CPY infected by "Trojan-Downloader.Win32.PurityScan.an" Virus. Action Taken: File Deleted.
File C:\_RESTORE\TEMP\A0059141.CPY tagged as not-a-virus:Server-Proxy.Win32.MarketScore.k. No Action Taken.
File C:\_RESTORE\TEMP\A0059185.CPY tagged as not-a-virus:AdWare.Sahat.ao. No Action Taken.
File C:\_RESTORE\TEMP\A0059230.CPY tagged as not-a-virus:AdWare.Mirar.b. No Action Taken.
File C:\_RESTORE\TEMP\A0059234.CPY tagged as not-a-virus:AdWare.Sahat.ao. No Action Taken.
File C:\_RESTORE\TEMP\A0059278.CPY tagged as not-a-virus:AdWare.Sahat.ao. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\08377A01.dll tagged as not-a-virus:AdWare.Sahat.w. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\084177F6.dll tagged as not-a-virus:AdWare.Sahat.w. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0FBE3DB9.dll tagged as not-a-virus:AdWare.Sahat.w. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2F86782C.CPY tagged as not-a-virus:AdWare.Sahat.w. No Action Taken.
File C:\Program Files\Windows Media Player\WMPLAYER.EXE tagged as not-a-virus:AdWare.Pacer.e. No Action Taken.
File C:\Program Files\Mozilla Firefox\plugins\npzango.dll tagged as not-a-virus:AdWare.WinAD.aw. No Action Taken.
File C:\Temp\Installer.exe tagged as not-a-virus:AdWare.Look2Me.ag. No Action Taken.