
Sorry it took so long to reply. I have a lot of files on my PC.
Here is what I did.
Ran Malwarebytes in Safemode with full scan ( takes a longtime to boot in safemode

, never had that before ).

Again found nothing.
Malwarebytes' Anti-Malware 1.36
Database version: 1970
Windows 5.1.2600 Service Pack 3
4/12/2009 4:46:02 PM
mbam-log-2009-04-12 (16-46-02).txt
Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|)
Objects scanned: 182041
Time elapsed: 1 hour(s), 7 minute(s), 59 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
***************************************************************

Went back to Normal boot & ran SmitfraudFix
here is my report :
SmitFraudFix v2.408
Scan done at 12:57:06.23, Sun 04/12/2009
Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\readericon45G.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\StopSign\POPUPB~1\sspopupblockerctrl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
C:\Program Files\eAcceleration\OnAccess\onaccess.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe
C:\PROGRA~1\AVANQU~1\Fix-It\MXTask.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe
C:\Program Files\eAcceleration\Firewall\FWService.exe
C:\PROGRA~1\AVANQU~1\Fix-It\mxtask.exe
C:\Program Files\eAcceleration\Station\station_bk.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Owner\LOCALS~1\Temp
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Owner\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
C:\Program Files\Google\googletoolbar1.dll FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» o4Patch
!!!Attention, following keys are not inevitably infected!!!
o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
!!!Attention, following keys are not inevitably infected!!!
Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, following keys are not inevitably infected!!!
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\Userinit.exe"
»»»»»»»»»»»»»»»»»»»»»»»» RK
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: NVIDIA nForce Networking Controller - Packet Scheduler Miniport
DNS Server Search Order: 192.168.2.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{C4A7BF59-6F26-4320-8889-C47E55060BA5}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{C4A7BF59-6F26-4320-8889-C47E55060BA5}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{C4A7BF59-6F26-4320-8889-C47E55060BA5}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
******************************************************************
Went back to Safemode & ran ATF-Cleaner.
Then I just checked marked
Close browsers before scanning.
Scan for tracking cookies.
Terminate memory threats before quarantining.
Then I ran SAS in Safemode (Full Scan) ( Scanned C :& D:)

found nothing.
here is my report :
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 04/12/2009 at 11:17 PM
Application Version : 4.26.1000
Core Rules Database Version : 3839
Trace Rules Database Version: 1795
Scan type : Complete Scan
Total Scan Time : 05:50:24
Memory items scanned : 232
Memory threats detected : 0
Registry items scanned : 5070
Registry threats detected : 0
File items scanned : 108837
File threats detected : 0
********************************************************************
Went to Event Viewer
here are my errors :
Event Type: Error
Event Source: SecurityCenter
Event Category: None
Event ID: 1804
Date: 4/13/2009
Time: 05:58:37
User: N/A
Computer: YOUR-D5CB4B4C7B
Description:
The Windows Security Center Service was unable to load instances of AntiVirusProduct from WMI.For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 13 10 04 80
*************************************************************
Event Type: Error
Event Source: WinMgmt
Event Category: None
Event ID: 10
Date: 4/13/2009
Time: 05:58:33
User: N/A
Computer: YOUR-D5CB4B4C7B
Description:
Event filter with query "SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct'
OR TargetInstance ISA 'FirewallProduct'" could not be (re)activated in namespace "//./ROOT/SecurityCenter" because of error 0x80042002.
Events may not be delivered through this filter until the problem is corrected.For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
******************************************
Event Type: Error
Event Source: Application Hang
Event Category: (101)
Event ID: 1002
Date: 4/12/2009
Time: 17:11:41
User: N/A
Computer: YOUR-D5CB4B4C7B
Description:
Hanging application SUPERAntiSpyware.exe, version 4.26.0.1000, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 48 61 6e 67 ion Hang
0010: 20 20 53 55 50 45 52 41 SUPERA
0018: 6e 74 69 53 70 79 77 61 ntiSpywa
0020: 72 65 2e 65 78 65 20 34 re.exe 4
0028: 2e 32 36 2e 30 2e 31 30 .26.0.10
0030: 30 30 20 69 6e 20 68 75 00 in hu
0038: 6e 67 61 70 70 20 30 2e ngapp 0.
0040: 30 2e 30 2e 30 20 61 74 0.0.0 at
0048: 20 6f 66 66 73 65 74 20 offset
0050: 30 30 30 30 30 30 30 30 00000000
******************************************************
Event Type: Error
Event Source: SecurityCenter
Event Category: None
Event ID: 1804
Date: 4/12/2009
Time: 16:56:26
User: N/A
Computer: YOUR-D5CB4B4C7B
Description:
The Windows Security Center Service was unable to load instances of AntiVirusProduct from WMI.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 13 10 04 80
********************************************************
Discovered & Removed the following with Ad-Aware
Win32.TrojanSpy
Win32FraudToolVirusRanger
Win32AdwareSearchit
PC acting a little better
Still think there is more bugs on my PC though.
Edited by koolkat, 13 April 2009 - 01:41 PM.