Hi again Bob4bob,
I am really shocked that anything could get in given your protection. It is possible that you are having some conflict with your anti-spyware programs, but that seems unlikely to be the cause of your symptoms.
Let's start here, and if I have missed anything our Senior Security Analyst will be along soon and can add to the fix.
First, can you please make sure that you have disabled your System Restore, and have all files and folders showing. Can you please download CCleaner and RegSupremePro from my signature. Then can you please download and run Housecall, also from my signature. Let it fix anything that it finds.
Now make sure that Spy Sweeper and ewido are completely updated, then boot into Safe Mode, stay there until you have finished these instructions.
Install and run CCleaner, choose all options including Advanced, answer OK to all warnings. Click on Analyze, then Click on Run Cleaner. Exit CCleaner.
Run a full system scan with Spy Sweeper, make sure all Sweep Options are selected EXCEPT Do Not Sweep System Restore Folders. Quarantine everything that it finds.
Now run an ewido scan, allow it to fix all that it finds. Save the log so that you can post it back here.
Now run HijackThis! and fix the following;Then delete the items in Bold.
Note, the R0 & R1 entries are for clarification sake, they are not virus' just seem to be conflicting.
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http:\\www.MSN.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O4 - Startup: Starter.lnk.disabled
O4 - Global Startup: Kaspersky Anti-Hacker.lnk = ?
O17 - HKLM\System\CCS\Services\Tcpip\..\{9132BD3D-F434-4D51-A6D4-B79CD2415026}: NameServer = 10.2.0.2,10.2.0.1 This entry refers to the ISP IANA see info here, are you familiar with it? If not then fix it, otherwise leave it.
O18 - Protocol: mmdtp - {E62C17EA-223C-4022-881D-2796CCD31CA6} - f:\Program Files\??????? ????\mmdtp.dll
Now run CCleaner again and boot back into regular mode. Install and run RegSupremePro, it will want to make a back up of your cache, let it. Then click on Registry Cleaner, choose Aggressive. Let it run. When it has finished, click on Select, choose All. Click on Fix. Let it fix everything that it finds.
Run
HJT one more time and post the new log along with the ewido log back here. Look forward to your response.
TTFN
LGW