Hiyas again Rob,
my first hijackthis log is as follows:
Logfile of HijackThis v1.98.0
Scan saved at 10:51:45 AM, on 8/3/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINNTSystem32smss.exe
C:WINNTsystem32winlogon.exe
C:WINNTsystem32services.exe
C:WINNTsystem32lsass.exe
C:WINNTsystem32svchost.exe
C:WINNTsystem32spoolsv.exe
C:WINNTSystem32msdtc.exe
C:WINNTSystem32svchost.exe
C:WINNTSystem32
vsvc32.exe
C:WINNTsystem32egsvc.exe
C:WINNTsystem32MSTask.exe
C:WINNTSystem32 cpsvcs.exe
C:WINNTSystem32snmp.exe
C:WINNTSystem32WBEMWinMgmt.exe
C:WINNTsystem32mspmspsv.exe
C:WINNTsystem32svchost.exe
C:WINNTSystem32inetsrvinetinfo.exe
C:WINNTSystem32mqsvc.exe
C:WINNTExplorer.EXE
C:WINNTSystem32svchost.exe
C:Program FilesCommon FilesRealUpdate_OBealsched.exe
C:WINNTsystem32mdnp.exe
C:WINNTsystem32wuauclt.exe
C:Program FilesInternet Exploreriexplore.exe
C:Documents and SettingsdodiMy DocumentsDowloaded_execsHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet Explorer,SearchURL =
http://searchmiracle.com/sp.phpR1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = file://C:DOCUME~1dodiLOCALS~1Tempsp.html
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = file://C:DOCUME~1dodiLOCALS~1Tempsp.html
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = file://C:DOCUME~1dodiLOCALS~1Tempsp.html
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = file://C:DOCUME~1dodiLOCALS~1Tempsp.html
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = file://C:DOCUME~1dodiLOCALS~1Tempsp.html
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = file://C:DOCUME~1dodiLOCALS~1Tempsp.html
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak =
http://www.google.ca/R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = about:blank
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81C3A} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: (no name) - {93E58BBE-A93D-486A-9018-6044FA5EEE4B} - C:WINNTsystem32msdoh.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA880F} - C:WINNTEliteBarEliteBar version 35.dll
O4 - HKLM..Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINNTSystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [TkBellExe] "C:Program FilesCommon FilesRealUpdate_OBealsched.exe" -osboot
O4 - HKCU..Run: [Cwoqwt] C:WINNTsystem32mdnp.exe
O4 - Startup: PalNetaware.lnk = C:Program FilesPaltalkpnetaware.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:program filesgoogleGoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:program filesgoogleGoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:program filesgoogleGoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~3Office10EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:program filesgoogleGoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:program filesgoogleGoogleToolbar1.dll/cmtrans.html
O16 - DPF: v2cab -
http://searchmiracle.com/cab/v2cab.cabO16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) -
http://fr.encyclopedia.yahoo.com/rsc/tdserver.cabO17 - HKLMSystemCCSServicesTcpip..{E5453779-B2A4-4FE5-AF01-3D152E756DB2}: NameServer = 198.235.216.134,198.235.216.135
O18 - Filter: text/html - {519BDAEF-A6D1-4613-9F21-746AE4623A1B} - C:WINNTsystem32msdoh.dll
O18 - Filter: text/plain - {519BDAEF-A6D1-4613-9F21-746AE4623A1B} - C:WINNTsystem32msdoh.dll