I executed HijackThis and got the following log in return.
Since this counts as another question I thought I would post it as such.
special thanks to war1
Here is the hijackthis log:
Logfile of HijackThis v1.97.6
Scan saved at 3:43:30 PM, on 11/12/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc3
2.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.e
xe
C:\WINDOWS\System32\devldr
32.exe
C:\WINDOWS\System32\spool\
drivers\w3
2x86\3\hpz
tsb05.exe
C:\WINDOWS\System32\hphmon
04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\MESSEN~1\msmsg
s.exe
C:\WINDOWS\System32\ctfmon
.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\System32\HPHipm
11.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SYSTEM32\cmd.ex
e
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip3
2.exe
C:\Documents and Settings\All Users\Desktop\Download\Hij
ackThis.ex
e
R1 - HKCU\Software\Microsoft\In
ternet Explorer,SearchURL =
http://www.spidersearch.com/frame_results.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://www.spidersearch.com/frame_results.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://www.spidersearch.com/frame_results.phpR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.cnn.com/R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://www.spidersearch.com/frame_results.phpR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Microsoft Internet Explorer provided by AT&T WorldNet Service
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.ht
m
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH
elper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0
B5F309A0E6
4} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: ineb Helper - {753AA023-02D1-447D-8B55-5
3A91A5ABF1
8} - C:\WINDOWS\System32\bmeb.d
ll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
09B6AD74AC
C} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: SpiderSearch.com Bar - {0AAF602E-72A1-45FE-BAB1-0
6971E07EAA
2} - C:\WINDOWS\System32\bmeb.d
ll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [MadExe] C:\PROGRAM FILES\DELL\RESOLUTION ASSISTANT\COMMON\BIN\Launc
hRA.exe -boot
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.e
xe"
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\
drivers\w3
2x86\3\hpz
tsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon
04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hph
upd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\PROGRA~1\MESSEN~1\msms
gs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE10\
EXCEL.EXE/
3000
O9 - Extra button: Web Entry (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O9 - Extra button: Dell Home (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {072D3F2E-5FB6-11D3-B461-0
0C04FA35A2
1} (CFForm Runtime) -
http://www.pbcprc.com/CFIDE/classes/CFJava.cabO16 - DPF: {7519DB27-0B01-4B3C-AB05-4
981200A8B0
B} (CyberClassRoomActiveX.Cyb
erCActiveX
) - file://C:\Program Files\PTG Interactive\htdocs\0176s4\
CyberCActi
veX.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37862.8701736111O16 - DPF: {BD419ACD-B41C-49D9-8ADF-C
CA15905251
5} (Inst Class) -
http://traffichog.com/toolbar/bmeb.cabO16 - DPF: {D1E7CBDA-E60E-4970-A01C-3
7301EF7BF9
8} (Measurement Service Client v.3) -
http://ccon.madonion.com/global/msc3.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {DC765522-D5BE-49C9-AF5F-8
C715A44BA2
8} (MS Investor Ticker) -
http://fdl.msn.com/public/investor/v9.5/ticker.cab