Hey .. don't worry about it. Anyway, ok, i downloaded pocket killbox and deleted the files you asked me to.
i checked Hijackthis>>Open Misc Tools>>Open Hosts File Manager but i didn't see "127.0.0.1 localhost" so i left it.
This is the fresh Findit9xme.bat log :
MBEGGR~1 DLL 227,104 03-10-05 1:15p mbeggrpid.dll
LSRAS80N DLL 227,104 03-10-05 1:15p Lsras80n.dll
DNEML DLL 227,104 03-10-05 1:15p DNEML.DLL
LAIMG80N DLL 227,104 03-10-05 1:15p Laimg80n.dll
DOD9 DLL 227,104 03-10-05 1:15p DOD9.DLL
IJFRARED DLL 227,104 03-10-05 1:15p IJFRARED.DLL
DDDIM700 DLL 227,104 03-10-05 1:15p DDDIM700.DLL
LWPCD80N DLL 227,104 03-10-05 1:15p Lwpcd80n.dll
HKDLR32 DLL 227,104 03-10-05 1:15p HKDLR32.DLL
BIWMP3 DLL 227,104 03-10-05 1:15p biwmp3.dll
SIKIT432 DLL 227,104 03-10-05 1:15p SIKIT432.DLL
CZBINET DLL 227,104 03-10-05 1:15p CZBINET.DLL
LPKODAK DLL 227,104 03-10-05 1:15p Lpkodak.dll
IRDKCS32 DLL 227,104 03-10-05 1:15p IRDKCS32.DLL
SYNTFNT DLL 227,104 03-10-05 1:15p SYntfNT.dll
PACN1111 DLL 227,104 03-10-05 1:15p PACN1111.DLL
BYSEBALL DLL 227,104 03-10-05 1:15p BYseball.dll
SNS3D630 DLL 227,104 03-10-05 1:15p sns3d630.dll
QHSF DLL 217,088 12-10-04 11:48p QHSF.DLL
MUDXMLC DLL 217,088 12-10-04 11:48p mudxmlc.dll
PGTOREC DLL 217,088 12-10-04 11:48p PGTOREC.DLL
OGE2NLS DLL 217,088 12-10-04 11:48p OGE2NLS.DLL
JSNGLE DLL 217,088 12-10-04 11:48p Jsngle.dll
WUPASF DLL 217,088 12-10-04 11:48p wupasf.dll
EIEXCH32 DLL 217,088 12-10-04 11:48p EIEXCH32.DLL
AJMUI DLL 217,088 12-10-04 11:48p AJMUI.DLL
LMBKLCNP DLL 217,088 12-10-04 11:48p lmbklcnp.dll
MZANG DLL 217,088 12-10-04 11:48p MZANG.DLL
MBIQTZ32 DLL 217,088 12-10-04 11:48p MBIQTZ32.DLL
MTDART32 DLL 217,088 12-10-04 11:48p mtdart32.dll
WTDAP32 DLL 217,088 12-10-04 11:48p WTDAP32.DLL
CSMDLG32 DLL 217,088 12-10-04 11:48p CSMDLG32.DLL
MPXML3R DLL 217,088 12-10-04 11:48p MPXML3R.DLL
ORBCCR32 DLL 217,088 12-10-04 11:48p orbccr32.dll
34 file(s) 7,561,280 bytes
0 dir(s) 7,651.05 MB free
------- Hidden Files in System Directory -------
Volume in drive C has no label
Volume Serial Number is 1546-0CF5
Directory of C:\WINDOWS\SYSTEM
VMSS <DIR> 03-07-05 7:10p vmss
WSXSVC <DIR> 03-07-05 7:10p wsxsvc
LXBKMA GID 40,613 10-20-04 10:33p lxbkma.GID
FOLDER HTT 13,122 06-23-04 1:42p folder.htt
DESKTOP INI 266 06-23-04 1:42p desktop.ini
JETERR35 GID 10,820 02-03-04 8:44p jeterr35.GID
FIZ2 1,057 01-21-04 12:32p fiz2
FIZ1 1,355 01-21-04 11:53a fiz1
KYF DAT 1,865,021 01-21-04 11:24a kyf.dat
FFASTLOG TXT 23,598 01-05-04 5:29p FFASTLOG.TXT
8 file(s) 1,955,852 bytes
2 dir(s) 7,651.04 MB free
---------------- User Agent ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{25782FD8-7F18-DFC3-CF5A-437063ED4CE2}"=""
------------------ Locate.com Results ------------------
C:\WINDOWS\SYSTEM\
mbeggr~1.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
lsras80n.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
dneml.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
laimg80n.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
dod9.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
ijfrared.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
dddim700.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
lwpcd80n.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
hkdlr32.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
biwmp3.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
sikit432.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
czbinet.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
lpkodak.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
irdkcs32.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
syntfnt.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
pacn1111.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
byseball.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
sns3d630.dll Thu Mar 10 2005 1:15:42p ..S.R 227,104 221.78 K
18 items found: 18 files, 0 directories.
Total of file sizes: 4,087,872 bytes 3.90 M
------------ Strings.exe Qoologic Results ------------
-------------- Strings.exe Aspack Results -------------
C:\WINDOWS\vsapi32.dll: ASPack 1.08.04
C:\WINDOWS\vsapi32.dll: ASPack 1.08.03
C:\WINDOWS\vsapi32.dll: ASPack 1.08.02b
C:\WINDOWS\vsapi32.dll: ASPack 1.08.01
C:\WINDOWS\vsapi32.dll: ASPack 1.08
C:\WINDOWS\vsapi32.dll: ASPack 1.07b
C:\WINDOWS\vsapi32.dll: ASPack 1.61
C:\WINDOWS\vsapi32.dll: ASPack 1.05b
C:\WINDOWS\vsapi32.dll: ASPack 1.03
C:\WINDOWS\vsapi32.dll: ASPack 1.02
C:\WINDOWS\vsapi32.dll: ASPack 1.01
C:\WINDOWS\vsapi32.dll: ASPack 1.00
C:\WINDOWS\vsapi32.dll: ASPACK EXE
C:\WINDOWS\vsapi32.dll: ASPACK2 EXE
C:\WINDOWS\SYSTEM\jesterss.dll: .aspack
C:\WINDOWS\SYSTEM\fastvideoplayer.dll: .aspack
----------------- HKLM Run Key ------------------
-------------- Strings.exe Umonitor Results -------------
C:\WINDOWS\SYSTEM\QHSF.DLL: UMonitor
C:\WINDOWS\SYSTEM\mudxmlc.dll: UMonitor
C:\WINDOWS\SYSTEM\PGTOREC.DLL: UMonitor
C:\WINDOWS\SYSTEM\OGE2NLS.DLL: UMonitor
C:\WINDOWS\SYSTEM\Jsngle.dll: UMonitor
C:\WINDOWS\SYSTEM\wupasf.dll: UMonitor
C:\WINDOWS\SYSTEM\EIEXCH32.DLL: UMonitor
C:\WINDOWS\SYSTEM\AJMUI.DLL: UMonitor
C:\WINDOWS\SYSTEM\lmbklcnp.dll: UMonitor
C:\WINDOWS\SYSTEM\MZANG.DLL: UMonitor
C:\WINDOWS\SYSTEM\MBIQTZ32.DLL: UMonitor
C:\WINDOWS\SYSTEM\mtdart32.dll: UMonitor
C:\WINDOWS\SYSTEM\WTDAP32.DLL: UMonitor
C:\WINDOWS\SYSTEM\CSMDLG32.DLL: UMonitor
C:\WINDOWS\SYSTEM\MPXML3R.DLL: UMonitor
C:\WINDOWS\SYSTEM\orbccr32.dll: UMonitor
----> i downloaded VX2 Finder.exe but couldnt run it. Something about it being only for ntsystems whatever.
And here is a fresh Hijackthis log :
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\PCCIOMON.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\PCCPFW.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ALCATEL\SPEEDTOUCH USB\DRAGDIAG.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\PCCGUIDE.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\PCCCLIENT.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\POP3TRAP.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\ELITEKBW32.EXE
C:\WINDOWS\NEWSD.EXE
C:\PROGRAM FILES\NOADS\NOADS.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2002\WEBTRAP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\IMPORTANT FILES\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by mysingtel
O1 - Hosts: 69.20.16.183 #uto.search.msn.com
O1 - Hosts: 69.20.16.183 #earch.netscape.com
O1 - Hosts: 69.20.16.183 #eautosearch
O1 - Hosts: 69.20.16.183 #uto.search.msn.com
O1 - Hosts: 69.20.16.183 #earch.netscape.com
O1 - Hosts: 69.20.16.183 #eautosearch
O1 - Hosts: 69.20.16.183 #uto.search.msn.com
O1 - Hosts: 69.20.16.183 #earch.netscape.com
O1 - Hosts: 69.20.16.183 #eautosearch
O1 - Hosts: 69.20.16.183 #uto.search.msn.com
O1 - Hosts: 69.20.16.183 #earch.netscape.com
O1 - Hosts: 69.20.16.183 #eautosearch
O1 - Hosts: 69.20.16.183 #uto.search.msn.com
O1 - Hosts: 69.20.16.183 #earch.netscape.com
O1 - Hosts: 69.20.16.183 #eautosearch
O1 - Hosts: 69.20.16.183 #uto.search.msn.com
O1 - Hosts: 69.20.16.183 #earch.netscape.com
O1 - Hosts: 69.20.16.183 #eautosearch
O1 - Hosts: 69.20.16.183 #uto.search.msn.com
O1 - Hosts: 69.20.16.183 #earch.netscape.com
O1 - Hosts: 69.20.16.183 #eautosearch
O1 - Hosts: 69.20.16.183 #uto.search.msn.com
O1 - Hosts: 69.20.16.183 #earch.netscape.com
O1 - Hosts: 69.20.16.183 #eautosearch
O1 - Hosts: 69.20.16.183 #uto.search.msn.com
O1 - Hosts: 69.20.16.183 #earch.netscape.com
O1 - Hosts: 69.20.16.183 #eautosearch
O1 - Hosts: 69.20.16.183 #uto.search.msn.com
O1 - Hosts: 69.20.16.183 #earch.netscape.com
O1 - Hosts: 69.20.16.183 #eautosearch
O1 - Hosts: 69.20.16.183 #uto.search.msn.com
O1 - Hosts: 69.20.16.183 #earch.netscape.com
O1 - Hosts: 69.20.16.183 #eautosearch
O1 - Hosts: 69.20.16.183 #uto.search.msn.com
O1 - Hosts: 69.20.16.183 #earch.netscape.com
O1 - Hosts: 69.20.16.183 #eautosearch
O2 - BHO: (no name) - {8E6354E6-9191-11D9-97A9-000C196928D0} - C:\WINDOWS\SYSTEM\BIHJ.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCIOMON.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCIOMON.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O4 - HKLM\..\Run: [antiware] C:\WINDOWS\SYSTEM\ELITEKBW32.EXE
O4 - HKLM\..\Run: [newsfeed12] C:\WINDOWS\newsd.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [PCCIOMON.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCIOMON.exe"
O4 - HKLM\..\RunServices: [PCCPFW] C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O4 - HKCU\..\Run: [NoAds] "C:\PROGRAM FILES\NOADS\NOADS.EXE"
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: STRINGS.EXE
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZCxdm410XXUSO9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system\aklsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.mysingtel.com.sg
O15 - Trusted Zone: *.iframe.biz
O15 - Trusted Zone: *.newiframe.biz
O15 - Trusted Zone: *.pizdato.biz
O15 - Trusted Zone: *.vse-moe.biz
O15 - Trusted Zone: *.sp2[censored]ed.biz
O15 - Trusted Zone: *.sp2admin.biz
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.overpro.com
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) -
http://games-dl.real.com/gameconsole/Bundl...ArcadeRdxIE.cabO16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) -
http://sc.groups.msn.com/controls/FileUC/MsnUpld.cabO16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) -
http://updates.lifescapeinc.com/installers...ll/pinstall.cabO16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) -
http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabO16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cabO16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Email Removed Attachments Control) -
http://by12fd.bay12.Email Removed.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) -
http://www.gamespot.com/KDX22/download/kdx.cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwe...etup1.0.0.8.cabO16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -
http://www.netvenda.com/sites/games-intl/sg/games3.cabO16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} (Installer Class) -
http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cabO16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) -
http://www.spywarestormer.com/files2/Install.cabO16 - DPF: {0CB2BD5A-7A80-4BA9-B49A-02DC51144BDF} (vciewer control) -
http://www.thepaymentcentre.com/build/vciewer.cabO16 - DPF: {0B682CC1-FB40-4006-A5DD-99EDD3C9095D} (vbiewer control) -
http://www.thepaymentcentre.com/build/vbiewer.cabO16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) -
http://www.errorguard.com/installation/Install.cabO16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} -
http://akamai.downloadv3.com/binaries/IA/netslv32_EN.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMesse...pDownloader.cabO16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://static.windupdates.com/cab/Download...Bridge-c135.cabO16 - DPF: {FFFFFFFF-3C18-4A7E-A29D-E24F84B79BF1} -
http://216.122.145.208/pi1_20.exeO16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) -
http://www.ysbweb.com/ist/softwares/v4.0/ysb_1002144.cabO18 - Filter: text/html - {B464E07C-8F47-11D9-97A9-000C58C7C217} - C:\WINDOWS\SYSTEM\BIHJ.DLL
O18 - Filter: text/plain - {B464E07C-8F47-11D9-97A9-000C58C7C217} - C:\WINDOWS\SYSTEM\BIHJ.DLL