Guestolo,
I followed your instructions, the "EVNTSVC.EXE" was not found on the task manager. In the add remove programs listing I found "REALONE PLAYER" and removed it. In windows the folder C:\Progra, Files\Comet was not present. Following are the Hijackthis and Panda reports:
Logfile of HijackThis v1.99.1
Scan saved at 6:27:06 PM, on 5/15/06
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\LINKSYS WIRELESS-G PCI ADAPTER\WMP54GV4.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\OPLIMIT\OCRAWARE.EXE
C:\OPLIMIT\OCRAWR32.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\E_S4I2S1.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.enter.net/F1 - win.ini: load=C:\OPLIMIT\ocraware.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_5_7_1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_5_7_1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\SYSTEM\E_S4I2S1.EXE /P23 "EPSON Stylus C66 Series" /O7 "EPUSB1:" /M "Stylus C66"
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [WMP54Gv4] C:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O8 - Extra context menu item: AltaVista Home -
http://jump.altavista.com/avie5/homeO8 - Extra context menu item: AV Search This Term -
http://jump.altavista.com/avie5/searchO8 - Extra context menu item: AV Translate this Web Page -
http://jump.altavista.com/avie5/babelfishO8 - Extra context menu item: AV Translate Selection -
http://jump.altavista.com/avie5/babelfishO9 - Extra button: (no name) - {06FE5D00-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/home (file missing)
O9 - Extra 'Tools' menuitem: &AltaVista Home - {06FE5D00-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/home (file missing)
O9 - Extra button: Translate - {06FE5D05-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/babelfish (file missing)
O9 - Extra 'Tools' menuitem: AV &Translate - {06FE5D05-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/babelfish (file missing)
O9 - Extra button: (no name) - {06FE5D02-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/linksearch (file missing)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL - {06FE5D02-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/linksearch (file missing)
O9 - Extra button: (no name) - {06FE5D03-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/hostsearch (file missing)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host - {06FE5D03-8F11-11d2-804F-00105A133818} -
http://jump.altavista.com/avie5/hostsearch (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O16 - DPF: Serome Web2Phone -
http://www.dialpad.com/applet/vscp.cabO16 - DPF: {4226E9B7-D637-40E8-893A-13298AB41477} (CWDL_DownLoadControl Class) -
http://www.callwave.com/include/cab/CWDL_DownLoad.CABO16 - DPF: {7BA7BCE2-D359-4407-82D9-CDF9A74C487A} (DownLoadStub Class) -
http://www.hpphoto.com/downloads/DownloadPhotos.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabIncident Status Location
Adware:adware/comet Not disinfected Windows Registry
Adware:Adware/Comet Not disinfected C:\WINDOWS\TEMP\ccu\comet.cab[csbho.dll]
Adware:Adware/Comet Not disinfected C:\WINDOWS\TEMP\ccu\csbho.dll
Spyware:Cookie/LinkExchange Not disinfected C:\WINDOWS\Cookies\default@linkexchange[1].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\default@go[2].txt
Spyware:Cookie/Preferences Not disinfected C:\WINDOWS\Cookies\default@preferences[2].txt
Spyware:Cookie/Preferences Not disinfected C:\WINDOWS\Cookies\default@preferences[1].txt
Spyware:Cookie/Kount Not disinfected C:\WINDOWS\Cookies\anyuser@kount[1].txt
Spyware:Cookie/LinkExchange Not disinfected C:\WINDOWS\Cookies\default@linkexchange[2].txt
Spyware:Cookie/Belnk Not disinfected C:\WINDOWS\Cookies\
[email protected][2].txt
Spyware:Cookie/LinkExchange Not disinfected C:\WINDOWS\Cookies\default@linkexchange[3].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\default@go[1].txt
Spyware:Cookie/LinkExchange Not disinfected C:\WINDOWS\Cookies\default@linkexchange[4].txt
Spyware:Cookie/Preferences Not disinfected C:\WINDOWS\Cookies\default@preferences[4].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\default@go[3].txt
Spyware:Cookie/Atwola Not disinfected C:\WINDOWS\Cookies\default@atwola[2].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\WINDOWS\Cookies\
[email protected][1].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\default@go[4].txt
Spyware:Cookie/YieldManager Not disinfected C:\WINDOWS\Cookies\
[email protected][1].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\WINDOWS\Cookies\
[email protected][3].txt
Spyware:Cookie/Affiliate fuel Not disinfected C:\WINDOWS\Cookies\
[email protected][2].txt
Spyware:Cookie/Com.com Not disinfected C:\WINDOWS\Cookies\default@com[1].txt
Spyware:Cookie/Apmebf Not disinfected C:\WINDOWS\Cookies\default@apmebf[2].txt
Spyware:Cookie/Overture Not disinfected C:\WINDOWS\Cookies\
[email protected][1].txt
Spyware:Cookie/Com.com Not disinfected C:\WINDOWS\Cookies\default@com[2].txt
Spyware:Cookie/Atwola Not disinfected C:\WINDOWS\Cookies\default@atwola[1].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\default@go[5].txt
Spyware:Cookie/Belnk Not disinfected C:\WINDOWS\Cookies\
[email protected][2].txt
Spyware:Cookie/Go Not disinfected C:\WINDOWS\Cookies\default@go[6].txt
Spyware:Cookie/Kount Not disinfected C:\WINDOWS\Cookies\default@kount[1].txt