I hope I've posted this in the right place. I keep getting redirected to a couple of sites...one is "AllFreeStuff"...one asks to download cookies from "gl0ck.9.net", and the other generates a popup with "Sitebar! You sitebar is ready to be downloaded". I've tried and tried to get rid of it, but so far, no spyware has been able to find it and get rid of it, including AdAware, Spybot, etc.
My internet connection arbitrarily decides it's not connected when it is, and requires my completing shutting down my system and the doing a cold reboot to get it up again.
Can you help me?
Logfile of HijackThis v1.99.0
Scan saved at 5:12:34 AM, on 3/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\MSSQL\MSSQL\Binn\sqlservr.exe
C:\PROGRA~1\PANALI~1\F6statmn.exe
C:\WINDOWS\System32\dnsrslve.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Hijack This\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [PMS Status Monitor] C:\PROGRA~1\PANALI~1\F6statmn.exe
O4 - HKLM\..\Run: [Dns Resolver] dnsrslve.exe
O4 - HKLM\..\RunServices: [Dns Resolver] dnsrslve.exe
O4 - HKCU\..\Run: [Dns Resolver] dnsrslve.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: startdb.lnk = C:\MSSQL\DATA\startdb.vbs
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.1.3.21/mahjong/mahjong-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo - http://game1.pogo.com/applet-6.1.3.21/waterwheel/waterwheel-ob-assets.cab
O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.1.5.21/peaks/peaks-ob-assets.cab
O16 - DPF: Turbo 21 TM by pogo - http://game1.pogo.com/applet-6.1.3.21/turbo21/turbo21-ob-assets.cab
O16 - DPF: WebConnect Pro 5.1.7 - https://s1web4.casecorp.com/WebConnectDU.cab
O16 - DPF: {1C1F0DCD-9910-11D3-A7DB-0060083317AA} (ReaderX Class) - http://65.168.240.130/jrx/readerx-1-0-0-63.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{03262926-C495-46C5-A6D6-689E65FB8C4F}: NameServer = 208.231.96.12 209.16.64.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{03262926-C495-46C5-A6D6-689E65FB8C4F}: NameServer = 208.231.96.12 209.16.64.2