Wow, that ActiveScan thing took a while. Anyway, here is my HiJack log again and my ActiveScan log. Somewhat discouraging, lol. Thanks again for your help
Logfile of HijackThis v1.99.1
Scan saved at 3:29:49 PM, on 10/15/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Rainlendar\Rainlendar.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_1_0_0_44.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1124813266875O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
Incident Status Location
Spyware:spyware/dyfuca No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\cfout.txt
Adware:adware/alwaysupdatednewsNo disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\toc_0036.exe
Adware:adware/sqwire No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\ts_8_new.exe
Adware:adware/portalscan No disinfected C:\WINDOWS\SYSTEM32\AUNPS2.dll
Adware:adware/elitebar No disinfected C:\WINDOWS\SYSTEM32\eliteicj32.exe
Adware:adware/searchforit No disinfected C:\WINDOWS\SYSTEM32\SYSsfitb.dll
Adware:adware/bookedspace No disinfected C:\WINDOWS\cfgmgr52.dll
Adware:adware/apropos No disinfected Windows Registry
Adware:Adware/Adtomi No disinfected C:\Documents and Settings\Administrator\Desktop\backups\backup-20051015-105010-636.dll
Virus:Trj/Delf.JS Disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\atiupdate.exe
Spyware:Spyware/Dyfuca No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\cfin[cfin]
Spyware:Spyware/Dyfuca No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\cfout.txt
Adware:Adware/IST.ISTBar No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\GLF6GLF6.EXE
Adware:Adware/eZula No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\GLF7GLF7.EXE
Adware:Adware/eZula No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\GLF99GLF99.EXE
Adware:Adware/eZula No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\GLF9GLF9.EXE
Adware:Adware/eZula No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\GLFAGLFA.EXE
Adware:Adware/IST.ISTBar No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\GLFEGLFE.EXE
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\temp.exe
Adware:Adware/AlwaysupdatednewsNo disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\toc_0036.exe
Adware:Adware/eZula No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\ts_8_new.exe
Adware:Adware/Adtomi No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\y2t4.sys
Virus:Trj/PWSteal.H No disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\29SV2H25\mm[1].jpg[muma.exe]
Virus:Trj/PWSteal.H Disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\8HEN05AR\[bleep]snow[1].exe
Virus:Trj/Downloader.DGM Disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\HFZB9T4E\sia[1].txt
Virus:Exploit/Codebase.AL No disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OHAN0HUB\help[1].txt[#.htm]
Virus:Trj/PWSteal.H No disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\OHAN0HUB\help[1].txt[[bleep]snow.exe]
Virus:Trj/PWSteal.H Disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\SPSFKR87\muma[1].exe
Virus:Trj/PWSteal.H No disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WX6ZWXMN\mm[1].jpg[muma.exe]
Virus:Trj/PWSteal.H Disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\WXYZKTI3\muma[1].exe
Adware:Adware/BookedSpace No disinfected C:\WINDOWS\cfgmgr52.dll
Adware:Adware/PortalScan No disinfected C:\WINDOWS\Helper101.dll
Adware:Adware/Transponder No disinfected C:\WINDOWS\khhqhj.exe
Adware:Adware/BookedSpace No disinfected C:\WINDOWS\lomyjhme.exe
Adware:Adware/Favadd No disinfected C:\WINDOWS\sfita.exe
Virus:Trj/Clicker.DJ Disinfected C:\WINDOWS\system32\AUNPS2.dll
Adware:Adware/HuntBar No disinfected C:\WINDOWS\system32\Cache\EDow_AS2.exe
Virus:Trj/Delf.EB Disinfected C:\WINDOWS\system32\Cache\HelperInstall.exe
Adware:Adware/PortalScan No disinfected C:\WINDOWS\system32\Cache\InstallAPS.exe
Spyware:Spyware/Dyfuca No disinfected C:\WINDOWS\system32\Cache\optimize.exe
Spyware:Spyware/SurfSideKick No disinfected C:\WINDOWS\system32\Cache\SSK3_B5 Advagency.exe
Adware:Adware/IST.ISTBar No disinfected C:\WINDOWS\system32\Cache\ven_d1.exe
Adware:Adware/IST.ISTBar No disinfected C:\WINDOWS\system32\Cache\ven_d2.exe
Adware:Adware/EliteBar No disinfected C:\WINDOWS\system32\eliteicj32.exe
Adware:Adware/Searchforit No disinfected C:\WINDOWS\system32\SYSsfitb.dll
Adware:Adware/IST.ISTBar No disinfected C:\WINDOWS\system32\tsuninst.exe
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\system32\xmltok.dll
Adware:Adware/Adtomi No disinfected C:\WINDOWS\system32\y2t4.sys
Adware:Adware/Adtomi No disinfected C:\WINDOWS\system32\ypnq.dll
Adware:Adware/Adtomi No disinfected C:\WINDOWS\system32\z0c7hwz.exe
Adware:Adware/Adtomi No disinfected C:\WINDOWS\y2t4.sys