Have used Norton Anti-Virus, SBC Yahoo ant-Spy, and Spybot to clean computer.
I have run Hijack This and pasted my log below:
Logfile of HijackThis v1.99.1
Scan saved at 8:41:20 AM, on 8/9/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\WINDOWS\netps.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\d3wx32.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\MsgSys.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Mike\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\zpquw.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\zpquw.dll/sp.html#93256
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gem.jsu.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\zpquw.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\zpquw.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\zpquw.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\zpquw.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\zpquw.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
O1 - Hosts: 69.31.81.22 www.google.ae www.google.am www.google.as www.google.at www.google.az www.google.be www.google.bi
O1 - Hosts: 69.31.81.22 www.google.ca www.google.cd www.google.cg www.google.ch www.google.ci www.google.cl www.google.co.cr
O1 - Hosts: 69.31.81.22 www.google.co.hu www.google.co.il www.google.co.in www.google.co.je www.google.co.jp www.google.co.ke www.google.co.kr
O1 - Hosts: 69.31.81.22 www.google.co.ls www.google.co.nz www.google.co.th www.google.co.ug www.google.co.uk www.google.co.ve www.google.com
O1 - Hosts: 69.31.81.22 www.google.com.ag www.google.com.ar www.google.com.au www.google.com.br www.google.com.co www.google.com.cu www.google.com.do
O1 - Hosts: 69.31.81.22 www.google.com.ec www.google.com.fj www.google.com.gi www.google.com.gr www.google.com.gt www.google.com.hk www.google.com.ly
O1 - Hosts: 69.31.81.22 www.google.com.mt www.google.com.mx www.google.com.my www.google.com.na www.google.com.nf www.google.com.ni www.google.com.np
O1 - Hosts: 69.31.81.22 www.google.com.pa www.google.com.pe www.google.com.ph www.google.com.pk www.google.com.pr www.google.com.py www.google.com.sa
O1 - Hosts: 69.31.81.22 www.google.com.sg www.google.com.sv www.google.com.tr www.google.com.tw www.google.com.ua www.google.com.uy www.google.com.vc
O1 - Hosts: 69.31.81.22 www.google.com.vn www.google.de www.google.dj www.google.dk www.google.es www.google.fi www.google.fm
O1 - Hosts: 69.31.81.22 www.google.fr www.google.gg www.google.gl www.google.gm www.google.hn www.google.ie www.google.it
O1 - Hosts: 69.31.81.22 www.google.kz www.google.li www.google.lt www.google.lu www.google.lv www.google.mn www.google.ms
O1 - Hosts: 69.31.81.22 www.google.mu www.google.mw www.google.nl www.google.no www.google.off.ai www.google.pl www.google.pn
O1 - Hosts: 69.31.81.22 www.google.pt www.google.ro www.google.ru www.google.rw www.google.se www.google.sh www.google.sk
O1 - Hosts: 69.31.81.22 www.google.sm www.google.td www.google.tm www.google.tt www.google.uz www.google.vg google.ae
O1 - Hosts: 69.31.81.22 google.am google.as google.at google.az google.be google.bi google.ca
O1 - Hosts: 69.31.81.22 google.cd google.cg google.ch google.ci google.cl google.co.cr google.co.hu
O1 - Hosts: 69.31.81.22 google.co.il google.co.in google.co.je google.co.jp google.co.ke google.co.kr google.co.ls
O1 - Hosts: 69.31.81.22 google.co.nz google.co.th google.co.ug google.co.uk google.co.ve google.com google.com.ag
O1 - Hosts: 69.31.81.22 google.com.ar google.com.au google.com.br google.com.co google.com.cu google.com.do google.com.ec
O1 - Hosts: 69.31.81.22 google.com.fj google.com.gi google.com.gr google.com.gt google.com.hk google.com.ly google.com.mt
O1 - Hosts: 69.31.81.22 google.com.mx google.com.my google.com.na google.com.nf google.com.ni google.com.np google.com.pa
O1 - Hosts: 69.31.81.22 google.com.pe google.com.ph google.com.pk google.com.pr google.com.py google.com.sa google.com.sg
O1 - Hosts: 69.31.81.22 google.com.sv google.com.tr google.com.tw google.com.ua google.com.uy google.com.vc google.com.vn
O1 - Hosts: 69.31.81.22 google.de google.dj google.dk google.es google.fi google.fm google.fr
O1 - Hosts: 69.31.81.22 google.gg google.gl google.gm google.hn google.ie google.it google.kz
O1 - Hosts: 69.31.81.22 google.li google.lt google.lu google.lv google.mn google.ms google.mu
O1 - Hosts: 69.31.81.22 google.mw google.nl google.no google.off.ai google.pl google.pn google.pt
O1 - Hosts: 69.31.81.22 google.ro google.ru google.rw google.se google.sh google.sk google.sm
O1 - Hosts: 69.31.81.22 google.td google.tm google.tt google.uz google.vg search.yahoo.com ar.search.yahoo.com
O1 - Hosts: 69.31.81.22 br.search.yahoo.com ca.search.yahoo.com cf.search.yahoo.com mx.search.yahoo.com espanol.search.yahoo.com au.search.yahoo.com ct.search.yahoo.com
O1 - Hosts: 69.31.81.22 fr.search.yahoo.com de.search.yahoo.com it.search.yahoo.com uk.search.yahoo.com search.msn.com search.msn.at search.sympatico.msn.ca
O1 - Hosts: 69.31.81.22 search.msn.co.za search.ninemsn.com.au search.xtramsn.co.nz search.msn.co.uk search.msn.be search.msn.dk search.msn.fi
O1 - Hosts: 69.31.81.22 search.msn.fr search.msn.de search.msn.it search.msn.nl search.msn.no search.msn.es uk.search.msn.com
O1 - Hosts: 69.31.81.22 search.msn.se search.msn.ch search.msn.co.in search.msn.com.sg toolbar.search.msn.com beta.search.msn.com beta.search.msn.at
O1 - Hosts: 69.31.81.22 beta.search.sympatico.msn.ca beta.search.msn.co.za beta.search.ninemsn.com.au beta.search.xtramsn.co.nz beta.search.msn.co.uk beta.search.msn.be beta.search.msn.dk
O1 - Hosts: 69.31.81.22 beta.search.msn.fi beta.search.msn.fr beta.search.msn.de beta.search.msn.it beta.search.msn.nl beta.search.msn.no beta.search.msn.es
O1 - Hosts: 69.31.81.22 beta.search.msn.se beta.search.msn.ch beta.search.msn.co.in beta.search.msn.com.sg auto.search.msn.com www.alexa.com alexa.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Class - {FD61B84C-0010-955A-086A-0FC97935B74A} - C:\WINDOWS\sysen.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [addpt.exe] C:\WINDOWS\system32\addpt.exe
O4 - HKLM\..\Run: [netps.exe] C:\WINDOWS\netps.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] 1
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: Yahoo! Poker - http://download.game...nts/y/pt3_x.cab
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\rmeecccv.exe
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://dl.ad-ware.cc...m::/on-line.exe
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!http://69.50.166.213...hm::/update.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - http://files.member....s/sbc/yinst.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z....iTunesSetup.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1102791895983
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart...ploadClient.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo....plorer1_9us.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\d3wx32.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
Thank you much.
-Mike D