I have the same problem that I have seen on another thread: task manager and regedit quickly disappearing. Both are OK in Safe mode. I have checked for Nullbot.exe, Netstatt.exe, and have tried the scripts from kellys-korner-xp. I also have run Spybot Search and Rescue, Lavasoft, and Norton. I am getting tied of trying to solve this everynight with no luck. Can you help? Thanks in advance, Mark
Here is the Highjack this log file:
Logfile of HijackThis v1.99.0
Scan saved at 10

44 PM, on 2/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\xl.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Picasa\PicasaMediaDetector.exe
C:\PROGRA~1\Dantz\RETROS~1\ComboButton.exe
C:\WINDOWS\MXOaldr.exe
C:\documents and settings\tricia\local settings\temp\1v2j.exe
C:\WINDOWS\system32\MSGINAV.EXE
C:\documents and settings\tricia\local settings\temp\nPYqZvQ.exe
C:\documents and settings\tricia\local settings\temp\ZmP4HjY.exe
C:\WINDOWS\System32\Roboex32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\documents and settings\tricia\local settings\temp\fhZZp.exe
C:\documents and settings\tricia\local settings\temp\Ysu.exe
C:\WINDOWS\Xhrmy.exe
C:\windows\system32\yA8B9tvj3.exe
C:\windows\system32\Mrz.exe
C:\documents and settings\tricia\local settings\temp\1v2j.exe
C:\documents and settings\tricia\local settings\temp\nPYqZvQ.exe
C:\documents and settings\tricia\local settings\temp\ZmP4HjY.exe
C:\documents and settings\tricia\local settings\temp\fhZZp.exe
C:\windows\system32\yA8B9tvj3.exe
C:\documents and settings\tricia\local settings\temp\Ysu.exe
C:\documents and settings\tricia\local settings\temp\RE6.exe
C:\documents and settings\tricia\local settings\temp\l5BwVdp.exe
C:\WINDOWS\SYSTEM32\tbctray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Documents and Settings\Tricia\Application Data\athb.exe
C:\WINDOWS\system32\w?auboot.exe
C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
C:\QUICKENW\QWDLLS.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\SYSTEM32\Mrz.exe
C:\Program Files\Hijack this\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32\SearchBar.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.comcast.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AD57691A-86A6-CE0F-D34A-861D8A181891} - C:\WINDOWS\system32\iiwxnkgb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Tricia\Local Settings\Temp\6T.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [MaxtorCombo] "C:\PROGRA~1\Dantz\RETROS~1\ComboButton.exe"
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOaldr.exe
O4 - HKLM\..\Run: [1v2j] C:\documents and settings\tricia\local settings\temp\1v2j.exe
O4 - HKLM\..\Run: [AOL Instant Messenger] MSGINAV.EXE
O4 - HKLM\..\Run: [nPYqZvQ] C:\documents and settings\tricia\local settings\temp\nPYqZvQ.exe
O4 - HKLM\..\Run: [ZmP4HjY] C:\documents and settings\tricia\local settings\temp\ZmP4HjY.exe
O4 - HKLM\..\Run: [0b377fa7f456] C:\WINDOWS\System32\Roboex32.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [fhZZp] C:\documents and settings\tricia\local settings\temp\fhZZp.exe
O4 - HKLM\..\Run: [RE6] C:\documents and settings\tricia\local settings\temp\RE6.exe
O4 - HKLM\..\Run: [l5BwVdp] C:\documents and settings\tricia\local settings\temp\l5BwVdp.exe
O4 - HKLM\..\Run: [Ysu] C:\documents and settings\tricia\local settings\temp\Ysu.exe
O4 - HKLM\..\Run: [xhrmy] C:\WINDOWS\Xhrmy.exe
O4 - HKLM\..\Run: [yA8B9tvj3] C:\windows\system32\yA8B9tvj3.exe
O4 - HKLM\..\Run: [Mrz.exe] c:\windows\system32\Mrz.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [1v2j.exe] C:\documents and settings\tricia\local settings\temp\1v2j.exe
O4 - HKLM\..\Run: [nPYqZvQ.exe] C:\documents and settings\tricia\local settings\temp\nPYqZvQ.exe
O4 - HKLM\..\Run: [ZmP4HjY.exe] C:\documents and settings\tricia\local settings\temp\ZmP4HjY.exe
O4 - HKLM\..\Run: [fhZZp.exe] C:\documents and settings\tricia\local settings\temp\fhZZp.exe
O4 - HKLM\..\Run: [yA8B9tvj3.exe] C:\windows\system32\yA8B9tvj3.exe
O4 - HKLM\..\Run: [Ysu.exe] C:\documents and settings\tricia\local settings\temp\Ysu.exe
O4 - HKLM\..\Run: [RE6.exe] C:\documents and settings\tricia\local settings\temp\RE6.exe
O4 - HKLM\..\Run: [l5BwVdp.exe] C:\documents and settings\tricia\local settings\temp\l5BwVdp.exe
O4 - HKLM\..\Run: [TraySantaCruz] C:\WINDOWS\SYSTEM32\tbctray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Csia] C:\Documents and Settings\Tricia\Application Data\athb.exe
O4 - HKCU\..\Run: [Urgueqf] C:\WINDOWS\system32\w?auboot.exe
O4 - HKCU\..\RunOnce: [AOL Instant Messenger] MSGINAV.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Global Startup: TrueSync Launcher.lnk = C:\Program Files\Starfish\TrueSync\tstool.exe
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Weekly Compass.lnk = C:\Program Files\Franklin Covey\Planner\Compass.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Franklin Covey\Planner\Palm\HotSync.exe
O4 - Global Startup: PowerReg SchedulerV2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\maxspeed.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: ComcastHSI - {19C1A7AA-59F3-49BE-B371-6C5387022546} -
http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {3847F310-26A7-4A84-AC4C-51F2DF340436} -
http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Dell Home - {DE9F7D9E-71AE-44E3-8DE5-D741FBFD7B86} -
http://www.dellnet.com/ (file missing) (HKCU)
O9 - Extra button: Support - {FB707759-B40D-4E76-92AB-CFF212D29B2B} -
http://www.comcastsupport.com (file missing) (HKCU)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O21 - SSODL: Microsoft DirectXb - {79FEACFF-FFCE-815E-A900-316290B5B738} - C:\WINDOWS\System32\Jkkagchd.dll (file missing)
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: XtreamLok License Manager - Unknown - C:\WINDOWS\System32\xl.exe