guestolo,
I started to carryout the instructions you sent me and ran in to some problems. I downloaded the softwares and restarted in safe mode. I went to the task manager to look for the programs you listed but none of those were running. I then found all the dll and exe files you listed and deleted them. Idid another scan with hijackthis and found that all the R0 items had a file jpwmo.dll instead of the kylww.dll listed in the previous log and so I did not "fix check" them but did "fix check the renaining ones.Still in safe mode I ran "about:buster" saved the log and exit.
I ran CWSSchredder and used the fix button.
Then I rebooted in normal mode and in the process recieved an error "While initializing device IOS" "error:real mode memeroy allocation failed". I had that happen to me one time in the past and the manufacturer directed to do a "system files restore", which cleared the error. I repeated this restore operation, and the error cleared and I was able to restart in normal mode.
Once rebooted I ran another about:buster log.
I ran Hoster and restored the original hosts.
I reset the web settings as you directed.
I found the shell.dll file it was in my system folder.
When shut down and restarted my computer, I was unable to access the internet. So I decided to re-install my PCI card and dsl modem, but this has not resolved my problem. I am posting to you from another computer which has internet access. Another problem also developed in that when I do a normal shut down, the shut down starts normally but then freezes when it gets to the windows "shutting down screen" and then the only way I could finish the shut down process is to hold the power button in for 5 seconds.
Here is latest hijackthis log and the safe mode and normal mode about:buster logs:
Logfile of HijackThis v1.99.1
Scan saved at 3:49:16 PM, on 03/11/2005
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ABCD.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM32\DRIVERS\KODAKCCS.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\KODAK\KODAK EASYSHARE SOFTWARE\BIN\EASYSHARE.EXE
C:\VSTASCAN\VSACCESS.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system\jpwmo.dll/sp.html#28129
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http:/www2.enter.net
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: {0000031A-0000-0000-C000-000000000046} - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Dcfssvc] C:\Program Files\Common Files\KODAK\HYDRA_DR\dcfssvc.exe --pdr: "C:\Program Files\Common Files\KODAK\HYDRA_DR\dcmnter.pdr"
O4 - HKLM\..\Run: [KodakCCS] C:\WINDOWS\System32\Drivers\KodakCCS.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [ADDZT32.EXE] C:\WINDOWS\ADDZT32.EXE
O4 - HKLM\..\RunServices: [MSKV.EXE] C:\WINDOWS\SYSTEM\MSKV.EXE
O4 - HKLM\..\RunServices: [D3BJ32.EXE] C:\WINDOWS\SYSTEM\D3BJ32.EXE
O4 - HKLM\..\RunServices: [SDKBF32.EXE] C:\WINDOWS\SYSTEM\SDKBF32.EXE
O4 - HKLM\..\RunServices: [ADDNL32.EXE] C:\WINDOWS\SYSTEM\ADDNL32.EXE
O4 - HKLM\..\RunServices: [SYSOE.EXE] C:\WINDOWS\SYSTEM\SYSOE.EXE
O4 - HKLM\..\RunServices: [ADDTQ32.EXE] C:\WINDOWS\ADDTQ32.EXE
O4 - Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Startup: UMAX VistaAccess.lnk = C:\VSTASCAN\vsaccess.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: Serome Web2Phone -
http://www.dialpad.com/applet/vscp.cabO16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) -
http://activex.microgaming.com/DLhelper/ve...n7/dlhelper.cabScanned at: 2:55:48 PM on: 03/10/2005
-- Scan 1 ---------------------------
About:Buster Version 4.0
Reference List : 25
ADS not scanned System(FAT)
Removed! : C:\WINDOWS\addzt32.exe
Removed! : C:\WINDOWS\addna32.exe
Removed! : C:\WINDOWS\d3lj32.exe
Removed! : C:\WINDOWS\crtu.exe
Removed! : C:\WINDOWS\d3dm32.exe
Removed! : C:\WINDOWS\ieze32.exe
Removed! : C:\WINDOWS\d3rk.exe
Removed! : C:\WINDOWS\netwm32.exe
Removed! : C:\WINDOWS\SYSTEM\d3su.exe
Removed! : C:\WINDOWS\SYSTEM\addwg32.exe
Removed! : C:\WINDOWS\SYSTEM\atltk.exe
Removed! : C:\WINDOWS\SYSTEM\addil.exe
Removed! : C:\WINDOWS\SYSTEM\javaml.exe
Attempted Clean Of Temp folder.
Removed Uninstall Key (HSA)
Removed Uninstall Key (SE)
Removed Uninstall Key (SW)
Pages Reset... Done!
-- Scan 2 ---------------------------
About:Buster Version 4.0
Reference List : 25
ADS not scanned System(FAT)
Attempted Clean Of Temp folder.
Pages Reset... Done!
Scanned at: 3:22:57 PM on: 03/10/2005
-- Scan 1 ---------------------------
About:Buster Version 4.0
Reference List : 25
ADS not scanned System(FAT)
Attempted Clean Of Temp folder.
Pages Reset... Done!
-- Scan 2 ---------------------------
About:Buster Version 4.0
Reference List : 25
ADS not scanned System(FAT)
Attempted Clean Of Temp folder.
Pages Reset... Done!
Once again thanks for your help, can you help me resolve these newest problems.