here ya go...
Logfile of HijackThis v1.97.7
Scan saved at 12:51:27 AM, on 4/5/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\PROGRAM FILES\COMPAQ\DIGITAL DASHBOARD\DEVGULP.EXE
C:\CPQS\BWTOOLS\SCCENTER.EXE
C:\WINDOWS\ptsnoop.exe
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\SCANSOFT\TEXTBRIDGE PLUS\BIN\INSTANTACCESS.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\EAUSBKBD.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\PROGRAM FILES\SCANSOFT\TEXTBRIDGE PLUS\EREG\REMIND32.EXE
C:\WINDOWS\SYSTEM\CMMON32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\MY DOCUMENTS\MONET'S\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://desktop.presario.net/scripts/...nsumer&LC=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://search.presario.net/scripts/r...rchbar&LC=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\PROGRAM FILES\MYWAY\SRCHASTT\1.BIN\MYSRCHAS.DLL (file missing)
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [CPQInet] c:\compaq\CPQInet\CpqInet.exe
O4 - HKLM\..\Run: [Digital Dashboard] C:\Program Files\Compaq\Digital Dashboard\DevGulp.exe
O4 - HKLM\..\Run: [Service Connection] c:\cpqs\bwtools\sccenter.exe
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [LexStart] Lexstart.exe
O4 - HKLM\..\Run: [LexmarkPrinTray] PrinTray.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [AvconsoleEXE] C:\Program Files\Network Associates\McAfee VirusScan\avconsol.exe /minimize
O4 - HKLM\..\Run: [VsecomrEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSEcomR.EXE
O4 - HKLM\..\Run: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\Run: [VsStatEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSSTAT.EXE /SHOWWARNING
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\SCANSOFT\TEXTBR~1\BIN\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [LIU] C:\PROGRAM FILES\LOGITECH\QUICKCAM\RUBICON.EXE
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [LVComs] c:\windows\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\DOWNLOADED PROGRAM FILES\BRIDGE.DLL",Load
O4 - HKLM\..\Run: [SOUNDD] C:\WINDOWS\SYSTEM\SOUNDD.exe
O4 - HKLM\..\Run: [I3KY1Q03.EXE] C:\WINDOWS\I3KY1Q03.EXE /dk
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Hidserv] Hidserv.exe run
O4 - HKLM\..\RunServices: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [MsnMsgr] "c:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [I3KY1Q03.EXE] C:\WINDOWS\I3KY1Q03.EXE /dk
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: MSN Quick View.lnk = C:\Program Files\Online Services\MSN50\MSNDC.EXE
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: reminder-ScanSoft Product Registration.lnk = C:\Program Files\ScanSoft\TextBridge Plus\Ereg\REMIND32.EXE
O4 - Startup: MORZE5.lnk.disabled
O4 - Startup: J635CGRL.lnk.disabled
O4 - Startup: OX3L9L80.lnk.disabled
O4 - Startup: IE0AV37Z.lnk.disabled
O4 - Startup: XRZX60G7.lnk.disabled
O4 - Startup: MORZE1.lnk.disabled
O4 - Startup: WYQ70XWE.lnk.disabled
O4 - Startup: XDYL8O08.lnk.disabled
O4 - Startup: D382KJDP.lnk.disabled
O4 - Startup: B49IHXT1.lnk.disabled
O4 - Startup: 7K0MN61J.lnk.disabled
O4 - Startup: GRM8QKT4.lnk.disabled
O4 - Startup: 9A7TNCNH.lnk.disabled
O4 - Startup: FMZGYVLP.lnk.disabled
O4 - Startup: 6DPUI0AD.lnk.disabled
O4 - Startup: 6ZUELDYV.lnk.disabled
O4 - Startup: YKWUHMRL.lnk.disabled
O4 - Startup: QOC1DTAG.lnk.disabled
O4 - Startup: RAB3XFXU.lnk.disabled
O4 - Startup: G7QKVIRH.lnk.disabled
O4 - Startup: D5WAL0A4.lnk.disabled
O4 - Startup: EE8FBV7T.lnk.disabled
O4 - Startup: ELR03ZHU.lnk.disabled
O4 - Startup: QAYFRXNN.lnk.disabled
O4 - Startup: MUPULJ08.lnk.disabled
O4 - Startup: UOZQIM5T.lnk.disabled
O4 - Startup: 6HB07R50.lnk.disabled
O4 - Startup: FFPDJIGU.lnk.disabled
O4 - Startup: 5BEU3YG8.lnk.disabled
O4 - Startup: PF8D0XQ6.lnk.disabled
O4 - Startup: WPTOHVTM.lnk.disabled
O4 - Startup: 6TN47D1C.lnk.disabled
O4 - Startup: 9PRF9DYQ.lnk.disabled
O4 - Startup: 3TGTYLZZ.lnk.disabled
O4 - Startup: 106YZGMZ.lnk.disabled
O4 - Startup: 7RMHOUG2.lnk.disabled
O4 - Startup: 556DQX7A.lnk.disabled
O4 - Startup: AKAQLPZ3.lnk.disabled
O4 - Startup: RIZ6792K.lnk.disabled
O4 - Startup: GLJEHB27.lnk.disabled
O4 - Startup: 2IH7TJ8Y.lnk.disabled
O4 - Startup: H8IE077I.lnk.disabled
O4 - Startup: BK05ZC5E.lnk.disabled
O4 - Startup: 6OV8V52Q.lnk.disabled
O4 - Startup: Y90IY7HN.lnk.disabled
O4 - Startup: QK3M7B8Y.lnk.disabled
O4 - Startup: 0BGTYPZN.lnk.disabled
O4 - Startup: WH06KMP4.lnk.disabled
O4 - Startup: J1I5783O.lnk.disabled
O4 - Startup: XVZP5H1T.lnk.disabled
O4 - Startup: 5M83F3VU.lnk.disabled
O4 - Startup: 3X23GLJ3.lnk.disabled
O4 - Startup: 4FT20M4B.lnk.disabled
O4 - Startup: NBJIKK9X.lnk.disabled
O4 - Global Startup: 4FT20M4B.lnk.disabled
O4 - Global Startup: J635CGRL.lnk.disabled
O4 - Global Startup: OX3L9L80.lnk.disabled
O4 - Global Startup: 5M83F3VU.lnk.disabled
O4 - Global Startup: XVZP5H1T.lnk.disabled
O4 - Global Startup: XRZX60G7.lnk.disabled
O4 - Global Startup: J1I5783O.lnk.disabled
O4 - Global Startup: WYQ70XWE.lnk.disabled
O4 - Global Startup: XDYL8O08.lnk.disabled
O4 - Global Startup: 0BGTYPZN.lnk.disabled
O4 - Global Startup: QK3M7B8Y.lnk.disabled
O4 - Global Startup: B49IHXT1.lnk.disabled
O4 - Global Startup: GRM8QKT4.lnk.disabled
O4 - Global Startup: BK05ZC5E.lnk.disabled
O4 - Global Startup: 7K0MN61J.lnk.disabled
O4 - Global Startup: 9A7TNCNH.lnk.disabled
O4 - Global Startup: FMZGYVLP.lnk.disabled
O4 - Global Startup: 2IH7TJ8Y.lnk.disabled
O4 - Global Startup: GLJEHB27.lnk.disabled
O4 - Global Startup: 6ZUELDYV.lnk.disabled
O4 - Global Startup: YKWUHMRL.lnk.disabled
O4 - Global Startup: RAB3XFXU.lnk.disabled
O4 - Global Startup: AKAQLPZ3.lnk.disabled
O4 - Global Startup: 556DQX7A.lnk.disabled
O4 - Global Startup: 7RMHOUG2.lnk.disabled
O4 - Global Startup: D5WAL0A4.lnk.disabled
O4 - Global Startup: EE8FBV7T.lnk.disabled
O4 - Global Startup: 3TGTYLZZ.lnk.disabled
O4 - Global Startup: 9PRF9DYQ.lnk.disabled
O4 - Global Startup: QAYFRXNN.lnk.disabled
O4 - Global Startup: MUPULJ08.lnk.disabled
O4 - Global Startup: WPTOHVTM.lnk.disabled
O4 - Global Startup: PF8D0XQ6.lnk.disabled
O4 - Global Startup: 6HB07R50.lnk.disabled
O4 - Global Startup: FFPDJIGU.lnk.disabled
O4 - Global Startup: MORZE5.lnk.disabled
O4 - Global Startup: NBJIKK9X.lnk.disabled
O4 - Global Startup: 3X23GLJ3.lnk.disabled
O4 - Global Startup: IE0AV37Z.lnk.disabled
O4 - Global Startup: MORZE1.lnk.disabled
O4 - Global Startup: WH06KMP4.lnk.disabled
O4 - Global Startup: D382KJDP.lnk.disabled
O4 - Global Startup: Y90IY7HN.lnk.disabled
O4 - Global Startup: 6OV8V52Q.lnk.disabled
O4 - Global Startup: H8IE077I.lnk.disabled
O4 - Global Startup: 6DPUI0AD.lnk.disabled
O4 - Global Startup: QOC1DTAG.lnk.disabled
O4 - Global Startup: RIZ6792K.lnk.disabled
O4 - Global Startup: G7QKVIRH.lnk.disabled
O4 - Global Startup: 106YZGMZ.lnk.disabled
O4 - Global Startup: ELR03ZHU.lnk.disabled
O4 - Global Startup: 6TN47D1C.lnk.disabled
O4 - Global Startup: UOZQIM5T.lnk.disabled
O4 - Global Startup: 5BEU3YG8.lnk.disabled
O9 - Extra button: Translate (HKLM)
O9 - Extra 'Tools' menuitem: AV &Translate (HKLM)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL (HKLM)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host (HKLM)
O9 - Extra 'Tools' menuitem: AV Home (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: MSN (HKCU)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yaho.../yinst0401.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
http://us.dl1.yimg.com/download.yaho...ymmapi_416.dll
O16 - DPF: Yahoo! Literati -
http://download.games.yahoo.com/game...ts/y/tt1_x.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/game...s/y/potc_x.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) -
http://launch.gamespyarcade.com/soft...ch/alaunch.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) -
http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} (CRegistryDownload Class) -
http://download.paltalk.com/download/0.x/regdload.cab
O16 - DPF: Yahoo! MahJong Solitaire -
http://download.games.yahoo.com/game.../y/mjst3_x.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) -
http://us.dl1.yimg.com/download.yaho...opper1_1us.cab
O16 - DPF: Yahoo! Chess -
http://download.games.yahoo.com/game...ts/y/ct1_x.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/06869d73...p/RdxIE601.cab
O16 - DPF: Yahoo! Checkers -
http://download.games.yahoo.com/game...ts/y/kt3_x.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab