OK, finished all of it and we seem to be making some progress. I was able to locate shell.dll in the system32 folder so that is OK. I did everything else as per your instructions and here are the loffiles you requested.
Logfile of HijackThis v1.99.1
Scan saved at 11:52:59 PM, on 12/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\HJT\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.comO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 11:18:43 PM, 12/14/2005
+ Report-Checksum: 840EB18
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{07FF232E-41D0-38A2-6073-6847AD3E6453} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5345A51F-E5D0-5A0D-1418-A1C95C417E3C} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Cleaned with backup
C:\WINDOWS\addwg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appqn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\imsins.BAK:pspbi -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\javari.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syspy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysqv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apihd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\dial32.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\WINDOWS\system32\iesr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieze.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ldr105.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr114.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr136.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr177.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr192.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr242.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr404.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr405.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr412.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr5.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr500.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr516.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr652.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\ldr905.dll -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\mfcba.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcjy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntfe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\oleext.dll -> Trojan.Small.ev : Cleaned with backup
C:\WINDOWS\system32\run597.exe -> Downloader.Small.cat : Cleaned with backup
C:\WINDOWS\system32\sdfdil.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\WINDOWS\system32\srpcsrv32.dll -> Downloader.Adload.g : Cleaned with backup
C:\WINDOWS\system32\txfdb32.dll -> Downloader.Adload.g : Cleaned with backup
C:\WINDOWS\system32\upd370.exe -> Downloader.Small.bpz : Cleaned with backup
C:\WINDOWS\system32\upd440.exe -> Downloader.Small.bpz : Cleaned with backup
C:\WINDOWS\system32\upd773.exe -> Dropper.Agent.ii : Cleaned with backup
C:\WINDOWS\system32\upd865.exe -> Downloader.Small.bpz : Cleaned with backup
C:\WINDOWS\system32\upd984.exe -> Dropper.Agent.ii : Cleaned with backup
C:\WINDOWS\system32\winctrl64.exe -> Downloader.Small.awa : Cleaned with backup
C:\WINDOWS\sysxw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\warnhp.html:gcxti -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\winjf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\WMSysPrx.prx:tlkjy -> Downloader.Agent.td : Cleaned with backup
C:\WINDOWS\{EAD46DB3-72B0-4394-9F4B-3272587729F5}.dat:sznmk -> Downloader.WinShow.bg : Cleaned with backup
::Report End
AboutBuster 5.1, reference file 33
Scan started on [12/14/2005] at [10:18:20 PM]
------------------------------------------------
No Ads Found!
------------------------------------------------
No Files Found!
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 10:20:04 PM
AboutBuster 5.1, reference file 33
Scan started on [12/14/2005] at [10:20:53 PM]
------------------------------------------------
No Ads Found!
------------------------------------------------
No Files Found!
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 10:22:26 PM
Things seem to be running a lot better than they were, at least so far.