Hi - thanks for the advice. I was able to get on-line after removing NewDotNet. I then did the following:
1. Removed both windb32.exe and digtizer.exe as well as all the files I listed except for msvcp71.dll.
2. Scanned Trend Micro, which found 9 things that it was able to remove successfully.
3. Scanned using the Panda site, which found over 40 objects - removed what I could; some I couldn't find (see below, after HJT Log)
4. Removed some of the obvious bad things from HJT, including Media Access and NewDotNet.
5. Rebooted
6. Spybot immediately asks me if I would allow c:\wnlogon.exe, media access, & adtool's values to be deleted from System Startup global entry; I say yes
7. I run HJT, the log file is below
8. I run Spybot; it finds DSOExploit and advertising.com, which it fixes. (But it re-finds something everytime I go through this cycle.)
9. Panda ActiveScan still finds the same virus as the earlier scan (see below, after HJT). I was unable to delete some of the files/folders in part because it appears that they're somehow read-only: I change the properties panel to turn off the read-only but it seems to have no effect. Also, the recycle bin has disappeared and I am unable to delete the folder under C:\RECYCLER.
I can't seem to get rid of all the malware but at least the popups are not happening anymore and I'm on the internet so thanks so much!
Is there something else I can/should do? Thanks!
===================== HJT log
Logfile of HijackThis v1.99.1
Scan saved at 12:54:31 AM, on 4/3/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\WISPTIS.EXE
C:\WINDOWS\System32\tabbtnu.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Fujitsu\Utils\fjevents.exe
C:\Program Files\Fujitsu\Utils\FjDspMon.exe
C:\Program Files\Fujitsu\Utils\FjMnuIco.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\igfxext.exe
C:\PROGRA~1\Zinio\ZDLM.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\microsoft shared\ink\TPA.exe
C:\Program Files\Linksys\Bluetooth Utility\BTTray.exe
C:\Program Files\AXMA\Fax-Internet\faxtray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\OpenOffice.org1.1.4\program\soffice.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Apache Group\Apache\Apache.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Apache Group\Apache\Apache.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Linksys\Bluetooth Utility\bin\btwdins.exe
C:\mysql\bin\mysqld.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Tablet.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\hjt\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/stuff/web/BoxOfCrap/index.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.fujitsupc.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [TabletTip] "C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe" /resume
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [FjEvents] c:\Program Files\Fujitsu\Utils\fjevents.exe
O4 - HKLM\..\Run: [FjDspMon] c:\Program Files\Fujitsu\Utils\FjDspMon.exe
O4 - HKLM\..\Run: [Fujitsu Menu] c:\Program Files\Fujitsu\Utils\FjMnuIco.exe
O4 - HKLM\..\Run: [LoadBtnHnd] C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\RunServices: [Microsoft Update] Isass.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Zinio DLM] C:\PROGRA~1\Zinio\ZDLM.exe /hide
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: OpenOffice.org 1.1.4.lnk = C:\Program Files\OpenOffice.org1.1.4\program\quickstart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = C:\Program Files\Linksys\Bluetooth Utility\BTTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: systray for fax applications.lnk = C:\Program Files\AXMA\Fax-Internet\faxtray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Linksys\Bluetooth Utility\btsendto_ie.htm
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {10000000-1000-0000-1000-000000000000} -
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: loginkey - C:\WINDOWS\SYSTEM32\LoginKey.dll
O20 - Winlogon Notify: TabBtnWL - C:\WINDOWS\SYSTEM32\TabBtnWL.dll
O20 - Winlogon Notify: tpgwlnotify - C:\WINDOWS\SYSTEM32\tpgwlnot.dll
O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe" --ntservice (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Linksys\Bluetooth Utility\bin\btwdins.exe
O23 - Service: Digitizer Service (Digitizer) - Unknown owner - C:\WINDOWS\System32\digtizer.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MySQL - Unknown owner - C:\mysql\bin\mysqld.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\System32\Tablet.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
================= Panda Activescan Log
(Lines beginning with * I removed, ? I couldn't find, the rest I wasn't able to get to)
Incident Status Location
* Spyware:Spyware/New.net No disinfected C:\WINDOWS\NDNuninstall*.exe
* Adware:Adware/nCase No disinfected C:\Temp\salm_*.dat
Adware:Adware/DownloadWare No disinfected Windows Registry
* Adware:Adware/SAHAgent No disinfected C:\WINDOWS\System32\q17i9a4j.exe
Adware:Adware/WUpd No disinfected Windows Registry
?Adware:Adware/EliteBar No disinfected C:\Documents and Settings\Administrator\Favorites\Finances & Business
Adware:Adware/TopConvert No disinfected Windows Registry
?Spyware:Spyware/SurfSideKick No disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Ssk.log
Adware:Adware/Minibug No disinfected C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll
Adware:Adware/EliteBar No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4007.tmp\v3cab.inf
Adware:Adware/EliteBar No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4008.tmp\v3cab.inf
Adware:Adware/NavHelper No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4035.fr1D8B\NavHelper\v2.0.4c\NHelper.dll
Adware:Adware/NavHelper No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4035.fr1D8B\NavHelper\v2.0.4c\NHUninstaller.exe
Adware:Adware/NavHelper No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4035.fr1D8B\NavHelper\v2.0.4c\NHUpdater.exe
Adware:Adware/NavHelper No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4035.fr1D8B\NavHelper\v2.0.4c\v2.0.4c.cab
Adware:Adware/NavHelper No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4035.fr1D8B\NavHelper\v2.0.4c\v2.0.4c.cab[NHelper.dll]
Adware:Adware/NavHelper No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4035.fr1D8B\NavHelper\v2.0.4c\v2.0.4c.cab[NHUninstaller.exe]
Adware:Adware/NavHelper No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4035.fr1D8B\NavHelper\v2.0.4c\v2.0.4c.cab[NHUpdater.exe]
Adware:Adware/EliteBar No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4038.fr2047\EliteToolBar version 60.dll
Adware:Adware/WUpd No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4179\op[1].htm
Adware:Adware/WinAD No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4181\d56[1].exe
Adware:Adware/Medload No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4212\v1\ML.exe
Adware:Adware/Ucmore No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4213\IUCmore.dll
Adware:Adware/Ucmore No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4213\UCMTSAIE.dll
Adware:Adware/WinAD No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4218.exe
Adware:Adware/WinAD No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4219.exe
Adware:Adware/WinAD No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4220.exe
Spyware:Spyware/ISTbar No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4221.zip[InstallerApplet.class]
Adware:Adware/WUpd No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4222.exe
Adware:Adware/WUpd No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4223.dll
Adware:Adware/Minibug No disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4224.EXE
Adware:Adware/BrilliantDigitalNo disinfected C:\RECYCLER\S-1-5-21-233559411-1967630633-991910116-500\Dc4239\S-1-5-21-233559411-1967630633-991910116-500\Dc4225.dll
* Adware:Adware/SAHAgent No disinfected C:\WINDOWS\70tovmto.exe
?Spyware:Spyware/New.net No disinfected C:\WINDOWS\NDNuninstall6_38.exe
* Adware:Adware/WUpd No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ELXOG3KV\AdTools[1].exe
* Adware:Adware/WinAD No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ELXOG3KV\d56[1].exe
* Adware:Adware/WUpd No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\PMSFYZ5B\AdToolsComm[1].dll
* Adware:Adware/WUpd No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\VBJKWDOO\AdToolsKeep[1].exe
?Adware:Adware/SAHAgent No disinfected C:\WINDOWS\system32\q17i9a4j.exe
* Adware:Adware/Ucmore No disinfected C:\WINDOWS\ucmoreiex.exe