Hi. I've found out I've got CWS.hiddendll (a variant of CoolWebSearch's really piss annoying hijacker). It's the one that changes the homepage to about:blank, an annoying web search and also prompts pop-ups all the time, which really piss you off.
Hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 10:03:33 PM, on 5/5/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\PCCIOMON.EXE
C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\PCCPFW.EXE
C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\TMPROXY.EXE
C:\PROGRAM FILES\MESSENGERPLUS! 3\MSGPLUS.EXE
C:\WINDOWS\SYSTEM\SPOOLSRV32.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\WINDOWS\SYSTEM32\DRIVERS\KODAKCCS.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\PCCGUIDE.EXE
C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\PCCLIENT.EXE
C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\TMOAGENT.EXE
C:\PROGRAM FILES\THOMSON\SPEEDTOUCH USB\DRAGDIAG.EXE
C:\PROGRAM FILES\TELSTRA\TOOLBAR\BPUMTRAY.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\RK.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\COMMON FILES\GMT\GMT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\PROFILES\DANIEL\DESKTOP\DANIEL\DOWNLOADS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/spage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.bigpond.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/spage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {B2281DC6-BDA4-11D9-B4CB-000A40EEC41E} - C:\WINDOWS\SYSTEM\NLPJ.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O3 - Toolbar: BigPond Toolbar - {7A431EC4-CC21-4DF7-9DB1-A2CF74C4CC98} - C:\PROGRAM FILES\TELSTRA\TOOLBAR\BPUMTOOLBAND.DLL
O3 - Toolbar: DashBar Toolbar - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - C:\PROGRAM FILES\DASHBAR\DASHBAR21.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [LVCOMS] C:\WINDOWS\SYSTEM\LVCOMS.EXE
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [KodakCCS] C:\WINDOWS\System32\Drivers\KodakCCS.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MsnExplorer] C:\WINDOWS\shch.exe /i
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
O4 - HKLM\..\Run: [PCCIOMON.exe] "C:\Program Files\Trend Micro\Internet Security\PCCIOMON.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [BigPond Toolbar] "C:\Program Files\Telstra\Toolbar\bpumTray.exe"
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe C:\PROGRA~1\WILDTA~1\APPS\CDA\CDAENG~1.DLL,cdaEngineMain
O4 - HKLM\..\Run: [AQ3HelperStartUp] C:\PROGRAM FILES\AQUATICA WATERWORLDS\AQ3HELPER.EXE /partner AQ3
O4 - HKLM\..\Run: [OSS] c:\windows\system\rk.exe -boot
O4 - HKLM\..\Run: [saap] c:\program files\180solutions inc\sa\81\saap.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [PCCIOMON.exe] "C:\Program Files\Trend Micro\Internet Security\PCCIOMON.exe"
O4 - HKLM\..\RunServices: [PccPfw] C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
O4 - HKLM\..\RunServices: [tmproxy] C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
O4 - HKLM\..\RunServices: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\RunServices: [Srv32 spool service] C:\WINDOWS\System\spoolsrv32.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - HKCU\..\RunServices: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\RunServices: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\RunServices: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mid%20: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.bigpond.com/
O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} -
http://www.addictivetechnologies.net/DM0/cab/m0h54e.cabO16 - DPF: Yahoo! Chess -
http://download.games.yahoo.com/games/clients/y/ct2_x.cabO16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) -
http://chat.yahoo.com/cab/yacsui.cabO16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) -
http://us.chat1.yimg.com/us.yimg.com/i/cha...v45/yacscom.cabO16 - DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} (SOESysInfo Control) -
http://everquest2.station.sony.com/systemscan/soesysinfo.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cabO16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
http://fdl.msn.com/zone/datafiles/heartbeat.cabO16 - DPF: Yahoo! Cribbage -
http://download.games.yahoo.com/games/clients/y/it1_x.cabO16 - DPF: Yahoo! Canasta -
http://download.games.yahoo.com/games/clients/y/yt1_x.cabO16 - DPF: Yahoo! Blackjack -
http://download.games.yahoo.com/games/clients/y/jt0_x.cabO16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/games/clients/y/pote_x.cabO16 - DPF: Yahoo! Dice -
http://download.games.yahoo.com/games/clients/y/dct4_x.cabO16 - DPF: Toki Toki Boom -
http://download.games.yahoo.com/games/clients/y/vto_x.cabO16 - DPF: Yahoo! Gin -
http://download.games.yahoo.com/games/clients/y/nt1_x.cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwe...up1.0.0.8-2.cabO16 - DPF: Yahoo! Euchre -
http://download.games.yahoo.com/games/clients/y/et1_x.cabO16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) -
http://zone.msn.com/bingame/rtlw/default/R...bGameLoader.cabO16 - DPF: Video Poker -
http://download.games.yahoo.com/games/clients/y/vpt0_x.cabO16 - DPF: Yahoo! Bridge -
http://download.games.yahoo.com/games/clients/y/bt1_x.cabO16 - DPF: Tornado 21 -
http://download.games.yahoo.com/games/clients/y/t21t0_x.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMesse...pDownloader.cabO16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/...nst_current.cabO16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cabO16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Email Removed Attachments Control) -
http://by17fd.bay17.Email Removed.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = qld.bigpond.net.au
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = qld.bigpond.net.au
O18 - Filter: text/html - {B2281DC5-BDA4-11D9-B4CB-000AB03C5A69} - C:\WINDOWS\SYSTEM\NLPJ.DLL
O18 - Filter: text/plain - {B2281DC5-BDA4-11D9-B4CB-000AB03C5A69} - C:\WINDOWS\SYSTEM\NLPJ.DLL
* HERE IS THE DLLCOMPARE LOG*
* DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
O^E says: "There were no files found

http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\'

\' />"
________________________________________________
862 items found: 862 files, 0 directories.
Total of file sizes: 175,266,558 bytes 167.14 M
--------------------End log---------------------
* HERE IS THE START DRECK LOG*
- note, this one is finding: run keys, browser help objects, run processes
StartDreck (build 2.1.7 public stable) - 2005-05-06 @ 21:16:26 (GMT +10:00)
Platform: Windows 98 SE (Win 4.10.2222 A)
Internet Explorer: 6.0.2800.1106
Logged in as Daniel at EDMUNDS
»Registry
»Run Keys
»Current User
»Run
*Taskbar Display Controls=RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
*MessengerPlus3="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
*msnmsgr="C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
»RunOnce
»Default User
»Run
*Taskbar Display Controls=RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
*MessengerPlus3="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
*MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
»RunOnce
»Local Machine
»Run
*ScanRegistry=C:\WINDOWS\scanregw.exe /autorun
*TaskMonitor=C:\WINDOWS\taskmon.exe
*SystemTray=SysTray.Exe
*LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
*SoundMan=SOUNDMAN.EXE
*ATIPTA=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
*LVCOMS=C:\WINDOWS\SYSTEM\LVCOMS.EXE
*DXM6Patch_981116=C:\WINDOWS\p_981116.exe /Q:A
*KodakCCS=C:\WINDOWS\System32\Drivers\KodakCCS.exe
*StillImageMonitor=C:\WINDOWS\SYSTEM\STIMON.EXE
*LoadQM=loadqm.exe
*MsnExplorer=C:\WINDOWS\shch.exe /i
*pccguide.exe="C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
*PCCIOMON.exe="C:\Program Files\Trend Micro\Internet Security\PCCIOMON.exe"
*PCClient.exe="C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
*TM Outbreak Agent="C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
*SpeedTouch USB Diagnostics="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
*BigPond Toolbar="C:\Program Files\Telstra\Toolbar\bpumTray.exe"
*WildTangent CDA=RUNDLL32.exe C:\PROGRA~1\WILDTA~1\APPS\CDA\CDAENG~1.DLL,cdaEngineMain
*AQ3HelperStartUp=C:\PROGRAM FILES\AQUATICA WATERWORLDS\AQ3HELPER.EXE /partner AQ3
*sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
»RunOnce
»RunServices
*LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
*SchedulingAgent=mstask.exe
*PCCIOMON.exe="C:\Program Files\Trend Micro\Internet Security\PCCIOMON.exe"
*PccPfw=C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
*tmproxy=C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
*MessengerPlus3="C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
*Srv32 spool service=C:\WINDOWS\System\spoolsrv32.exe
»RunServicesOnce
**c=rundll32 C:\WINDOWS\WIN3H6.SWP,DllGetClassObject
»RunOnceEx
»RunServicesOnceEx
»Browser Helper Objects (LM)
*{78FC9FC7-BE60-11D9-B4CB-000AC4DBFB1E}
`InprocServer32=C:\WINDOWS\SYSTEM\NLPJ.DLL
»Files
»System/Drivers
»Running Processes
+FFCE6845=C:\WINDOWS\SYSTEM\KERNEL32.DLL
+FFFFB3ED=C:\WINDOWS\SYSTEM\MSGSRV32.EXE
+FFFFAD7D=C:\WINDOWS\SYSTEM\MPREXE.EXE
+FFFF2101=C:\WINDOWS\SYSTEM\MSTASK.EXE
+FFFF71B5=C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\PCCIOMON.EXE
+FFFF600D=C:\WINDOWS\RUNDLL32.EXE
+FFFF7179=C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\PCCPFW.EXE
+FFFCBA79=C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\TMPROXY.EXE
+FFFF6369=C:\PROGRAM FILES\MESSENGERPLUS! 3\MSGPLUS.EXE
+FFFF2ECD=C:\WINDOWS\SYSTEM\SPOOLSRV32.EXE
+FFFC260D=C:\WINDOWS\SYSTEM\mmtask.tsk
+FFFDE811=C:\WINDOWS\EXPLORER.EXE
+FFF2FECD=C:\WINDOWS\TASKMON.EXE
+FFF2E88D=C:\WINDOWS\SYSTEM\SYSTRAY.EXE
+FFF226D9=C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
+FFF24EF9=C:\WINDOWS\SYSTEM\LVCOMS.EXE
+FFF3ACDD=C:\WINDOWS\SYSTEM32\DRIVERS\KODAKCCS.EXE
+FFF38641=C:\WINDOWS\SYSTEM\STIMON.EXE
+FFF3BC09=C:\WINDOWS\LOADQM.EXE
+FFF27EFD=C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\PCCGUIDE.EXE
+FFF3B9A5=C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\PCCLIENT.EXE
+FFF30B09=C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY\TMOAGENT.EXE
+FFF37329=C:\PROGRAM FILES\THOMSON\SPEEDTOUCH USB\DRAGDIAG.EXE
+FFF36CB5=C:\PROGRAM FILES\TELSTRA\TOOLBAR\BPUMTRAY.EXE
+FFF33931=C:\WINDOWS\RUNDLL32.EXE
+FFF0F46D=C:\WINDOWS\RUNDLL32.EXE
+FFF00B61=C:\WINDOWS\RunDLL.exe
+FFF1EB8D=C:\WINDOWS\SYSTEM\DDHELP.EXE
+FFF69019=C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
+FFF634E9=C:\WINDOWS\SYSTEM\WMIEXE.EXE
+FFF77FC1=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
+FFF74311=C:\WINDOWS\SYSTEM\PSTORES.EXE
+FFF47F3D=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
+FFF53D29=C:\WINDOWS\PROFILES\DANIEL\DESKTOP\START DRECK\STARTDRECK.EXE
»Application specific
THANKS HEAPS! hopefully all the logs i posted will help in some way.