Nice try Spike, but by no means complete.
Ivan Moore,
It is incredible how INFESTED your PC is! Every single O4 is another virus/trojan/you name it!
Go to my post here and follow it EXACTLY, and I mean EXACTLY
How to remove Begin2Search / Coolwebsearch
After you have installed/updated/done everything there,
Boot in Safe Mode
Uninstall anything to do with:
C:\Program Files\DeskAd Service
C:\PROGRA~1\COMMON~1\WinTools
C:\Program Files\Common Files\eAcceleration\
Run HJT on its own and let it "fix" (whatever is left over after the first post above):
C:\Program Files\DeskAd Service\DeskAdServ.exe
C:\WINDOWS\Help\SBSI\svrhard.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = C:\WINDOWS\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://default.home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://default.home
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: DOMP Class - {4C1B116F-2860-46db-8E6C-B4BFC4DFD683} - C:\WINDOWS\ietlbass32.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [logsys32host] C:\WINDOWS\System32\diagsmss32.exe
O4 - HKLM\..\Run: [dirhostrun] C:\WINDOWS\System32\spooldirhost.exe
O4 - HKLM\..\Run: [sysdisc] C:\WINDOWS\System32\smss32.exe
O4 - HKLM\..\Run: [wersds.exe] C:\WINDOWS\System32\doriot.exe
O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe
O4 - HKLM\..\Run: [*javadoc] C:\WINDOWS\msagent\javadoc.exe
O4 - HKLM\..\Run: [*acweb] C:\WINDOWS\Tasks\acweb.exe
O4 - HKLM\..\Run: [StopSignStatus] Rundll32.exe "C:\Program Files\Common Files\eAcceleration\Installer\stopsinfo.dll",VerifyStatus
O4 - HKLM\..\Run: [smss32x] C:\WINDOWS\System32\spool32win.exe %srun%
O4 - HKLM\..\Run: [DeskAd Service] C:\Program Files\DeskAd Service\DeskAdServ.exe
O4 - HKCU\..\Run: [hostdirdisc] C:\WINDOWS\System32\diagsmss32.exe
O4 - HKCU\..\Run: [cryptrun] C:\WINDOWS\System32\spooldirhost.exe
O4 - HKCU\..\Run: [crypt] C:\WINDOWS\System32\smss32.exe
O4 - HKCU\..\Run: [wersds.exe] C:\WINDOWS\System32\doriot.exe
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe
O4 - HKCU\..\Run: [logexpolerx] C:\WINDOWS\System32\spool32win.exe %srun%
O4 - HKCU\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKCU\..\RunOnce: [*WinLogon] C:\WINDOWS\Help\SBSI\svrhard.exe ren time:1104653397
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O13 - WWW. Prefix:
http://ehttp.cc/?
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {14578416-1111-1111-1111-111111411123} - file://C:\Documents and Settings\Ivan Moore\Desktop\1\calc.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab28177.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} -
http://download.websearch.com/Dnl/T_50138/QDow_AS2.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) -
http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) -
http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
http://fdl.msn.com/zone/datafiles/heartbeat.cab
O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe (file missing)
Reboot again in Safe mode. Make a new HJT-log and post it here as a .txt file