Boot in Safe Mode.
Switch System restore OFF.
Press Ctrl/Alt/Del simultaneously, select Taskmanager/Processes, select the process (if there), click "End Process" for:
scrsvc.exe
bootpd.exe
000StTHK.exe
Next, run HJT on its own and let it 'fix' if there:
C:\WINNT\System32\
scrsvc.exe
C:\WINNT\System32\
bootpd.exe
C:\WINNT\System32\bootpd.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\sp.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 196.10.0.2:80
ALL lines starting with:
O1 - Hosts:
O2 - BHO: (no name) - {3E438185-C3E0-44E2-AF74-B1FF62C48FD5} - C:\WINNT\System32\
agko.dll
O2 - BHO: (no name) - {5483427F-93B8-1470-5A89-E6B56484CDB2} - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winawckebqd.dll
O4 - HKLM\..\Run: [000StTHK]
000StTHK.exe
O4 - HKLM\..\Run: [scrsvc] C:\WINNT\System32\scrsvc.exe
O4 - HKLM\..\Run: [bootpd.exe] C:\WINNT\System32\bootpd.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://
C:\foo.mht!
http://82.179.166.68/4NrsNfdKk-7TM6Uo.chm::/on-line.exe
O18 - Filter: text/html - {E3BC895D-872D-465E-9B8D-D4EB9BF8D0B0} - C:\WINNT\System32\agko.dll
O18 - Filter: text/plain - {E3BC895D-872D-465E-9B8D-D4EB9BF8D0B0} - C:\WINNT\System32\agko.dll
When done, delete the highlighted
bold files.
Delete ALL files and/or subdirectories from: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
Boot normal. When all OK, switch System Restore back on.
You should then consider installing XP-SP1, and probably a whole load more web-updates.
Do NOT install SP2 if you don't have any good backup-strategy.