Couldn't use the link you provided, got there using 216.180.233.153
CWShredder found the problem and fixed it, but on opening IE the problem returned!!
Logfile of HijackThis v1.97.7
Scan saved at 00:45:33, on 04/02/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Windows\system\time.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Keith Bonney\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://magicsearch.ws/?q=R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://magicsearch.ws/?q=R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://magicsearch.ws/?q=R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://magicsearch.wsR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://magicsearch.wsR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://magicsearch.ws/?q=R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://magicsearch.ws/?q=R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://magicsearch.ws/?q=R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://magicsearch.wsR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://magicsearch.ws/?q=R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://magicsearch.ws/?q=R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://magicsearch.wsR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://magicsearch.ws/?q=R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://magicsearch.ws/?q=R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://magicsearch.ws/?q=R1 - HKCU\Software\Microsoft\Internet Explorer,Search =
http://magicsearch.ws/?q=R1 - HKLM\Software\Microsoft\Internet Explorer,Search =
http://magicsearch.ws/?q=O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
O4 - HKLM\..\Run: [AGNTDK] C:\WINDOWS\AGNTDK.exe
O4 - HKLM\..\Run: [Belt] C:\WINDOWS\Belt.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM\..\Run: [MicrosoftWindows] C:\Windows\system\time.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MicrosoftWindows] C:\Windows\system\time.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O9 - Extra button: AOL Instant Messenger (TM) (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - DefaultPrefix:
http://magicsearch.ws/?q=O13 - WWW Prefix:
http://magicsearch.ws/?q=O16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/games/clients/y/potc_x.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {E8EDB60C-951E-4130-93DC-FAF1AD25F8E7} -
http://cdn.climaxbucks.com/internet-optimizer/080703/UniDistIOcrack.CABO17 - HKLM\System\CCS\Services\Tcpip\..\{A3E5D502-5A05-42A8-96BB-2C5A03CF24D7}: NameServer = 193.38.113.3 194.117.157.4