QUOTE(SkittlesPC @ Jul 29 2006, 07:44 AM)

Do you have the latest HJT build?
I am assuming you have used hjt before? So you know how it works, correct?
Yes and Yes! I uninstalled and reinstalled my HJT and it's now giving a log file. I will post it in a new window.
Now, for the continuing adventures of...
Last night I tried a new program that I have seen around but never had tried it. It's called XoftSpy.
That little program found stuff that not 1 of my other programs found. I ran it over night last night.
This is what it found:
Starting to Quarantine 11 Items
FunWebProducts
IBIS/Hunt Toolbar
Medload
CWS.Homepage
Yazzle Cowabanga
Trojan/CWS Combo
Iopus Starr Pro Key Logger
statcounter cookie
================
I thought that all was well untill I rebooted, and the very 1st website that I hit, one of my programs blocked access to SMART-SECURITY.BIZ and HERE4SEARCH.BIZ over and over, 3-4 times each,
each time.
I then new my day once again was shot
I went into safe mode and ran Spybot S&D, it found a few more items, then the STUFF hit the fan
I clicked "fix".
Almost forgot this..
While I was in safe mode I adjusted Ad-watch.
I rebooted xp in normal mode. ad-watch started going nutz!!!
This is just a piece of the file below. I don't know if what I did in S&D?! Fix something in xp or I made things worse.
I WAS able to boot, so far (fingers xxxed) I am on line and on my IE and NO weird messages,
my desktop looked a bit different from before I did the safe mode, so I know some things corrected
themselves, I feel like I am navigating faster too.
anyway here is a partail log from ad-watch:
OH BTW I unclicked ad-watch as it is still trying to change my machine
HELP! Do I accept this or reject it??? Right now I am rejecting everything!!!!!!! HELP! shoot dernit why did I open it?

7/29/2006 5:10:30 PM> Registry modification detected
7/29/2006 5:10:30 PM>
7/29/2006 5:10:30 PM> Root:HKEY_LOCAL_MACHINE
7/29/2006 5:10:30 PM> Key:Software\Microsoft\Windows\CurrentVersion\Policies\System
7/29/2006 5:10:30 PM> Value:DisableTaskMgr
7/29/2006 5:10:30 PM> Data:
7/29/2006 5:10:30 PM> New Data:0
7/29/2006 5:10:30 PM>
7/29/2006 5:10:42 PM> Registry modification detected
7/29/2006 5:10:42 PM>
7/29/2006 5:10:42 PM> Root:HKEY_CURRENT_USER
7/29/2006 5:10:42 PM> Key:Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
7/29/2006 5:10:42 PM> Value:NoActiveDesktop
7/29/2006 5:10:42 PM> Data:
7/29/2006 5:10:42 PM> New Data:0
7/29/2006 5:10:42 PM>
7/29/2006 5:10:49 PM> Registry modification detected
7/29/2006 5:10:49 PM>
7/29/2006 5:10:49 PM> Root:HKEY_LOCAL_MACHINE
7/29/2006 5:10:49 PM> Key:Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
7/29/2006 5:10:49 PM> Value:NoSetHomePage
7/29/2006 5:10:49 PM> Data:
7/29/2006 5:10:49 PM> New Data:1
7/29/2006 5:10:49 PM>
7/29/2006 5:11:28 PM> Registry modification detected
7/29/2006 5:11:28 PM>
7/29/2006 5:11:28 PM> Root:HKEY_LOCAL_MACHINE
7/29/2006 5:11:28 PM> Key:Software\Microsoft\Windows\CurrentVersion\Run
7/29/2006 5:11:28 PM> Value:SpySweeper
7/29/2006 5:11:28 PM> Data:
7/29/2006 5:11:28 PM> New Data:"C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
7/29/2006 5:11:28 PM>
7/29/2006 5:11:31 PM> Registry modification detected
7/29/2006 5:11:31 PM>
7/29/2006 5:11:31 PM> Root:HKEY_CURRENT_USER
7/29/2006 5:11:31 PM> Key:Software\Microsoft\Windows\CurrentVersion\RunOnce
7/29/2006 5:11:31 PM> Value:The Bat!
7/29/2006 5:11:31 PM> Data:C:\Program Files\The Bat!\thebat.exe
7/29/2006 5:11:31 PM> New Data:
7/29/2006 5:11:31 PM>
7/29/2006 5:11:38 PM> Registry modification detected
7/29/2006 5:11:38 PM>
7/29/2006 5:11:38 PM> Root:HKEY_LOCAL_MACHINE
7/29/2006 5:11:38 PM> Key:Software\Microsoft\Windows\CurrentVersion\Run
7/29/2006 5:11:38 PM> Value:Symantec NetDriver Monitor
7/29/2006 5:11:38 PM> Data:C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
7/29/2006 5:11:38 PM> New Data:
7/29/2006 5:11:38 PM>
7/29/2006 5:11:44 PM> Registry modification detected
AND IT CONTINUES!
I will post my HJT in a new window. Thanks again all!