Results from analyzer:


THESE ITEMS ARE EITHER HARMFULL OR A SECURITY RISK
WE STRONGLY RECOMMEND TO FIX THEM :

\program files\istsvc\istsvc.exe
r1 - hkcu\software\microsoft\internet explorer\search
r0 - hklm\software\microsoft\internet explorer\search
searchassistant = about:blank
r1 - hkcu\software\microsoft\internet connection wizard
o2 - bho: (no name) - {7a572048-141f-47e8-9d05-39cfb479caf2} - c:\windows\system32\egoc.dll (file missing)
o2 - bho: (no name) - {c7cb7747-b60a-21fe-33c9-e3e479112a67} - (no file)
o4 - hklm..\run: [ist service] c:\program files\istsvc\istsvc.exe
o4 - hklm..\run: [power scan] c:\program files\power scan\powerscan.exe
o15 - trusted zone: *.awmdabest.com
o15 - trusted zone: *.c4tdownload.com
o15 - trusted zone: *.clickspring.net
o15 - trusted zone: *.iframe.biz
o15 - trusted zone: *.mt-download.com
o15 - trusted zone: *.newiframe.biz
o15 - trusted zone: *.overpro.com
o15 - trusted zone: *.pizdato.biz
o15 - trusted zone: *.slotch.com
o15 - trusted zone: *.sp2admin.biz
o15 - trusted zone: *.sp2fucked.biz
o15 - trusted zone: *.vse-moe.biz
o15 - trusted zone: *.windupdates.com
o15 - trusted zone: *.xxxtoolbar.com
o15 - trusted zone: *.ysbweb.com
o16 - dpf: {42f2c9ba-614f-47c0-b3e3-ecfd34eed658} (installer class) - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
o23 - service: xcikbwpspvot (faddwtbp6) - unknown owner - c:\windows\system32\skmozzlj6.exe (file missing)
o23 - service: x10 device network service (x10nets) - unknown owner - c:\progra~1\atimul~1\remctrl\x10nets.exe (file missing)


HARMFULL ITEMS IN THE DOCUMENTS AND SETTINGS FOLDER(S) :

Nothing found.


THE FOLLOWING ITEMS ARE NOT NEEDED TO LOAD
AT BOOTTIME FOR THE SYSTEM TO WORK PROPERLY :

o4 - global startup: corecenter.lnk = c:\program files\msi\core center\corecenter.exe

btw, it's still taunting me w/ that "Is your computer infect with spyware?" message that only gives me a 'yes' or 'no' answer. no way to delete or close it unless i can figure out which task to end. ARGH plz help!!

This sounds like adware to me, click on the link in Eddy’s signature (See a post by eddy above) and follow the malware removal instructions.

After that redo the hijackthis log and post back here please.

–lee