Here is the new hijack this:
Logfile of HijackThis v1.99.1
Scan saved at 6:55:40 PM, on 12/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Alias\Maya7.0\docs\wrapper.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Alias\Maya7.0\docs\jre\bin\java.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Toolbar V35\FotomatDeviceConnect.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Adam Bierman\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe" -autorun
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ViewpointPhotosDeviceConnect] C:\Program Files\Viewpoint\Viewpoint Toolbar V35\FotomatDeviceConnect.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\RunOnce: [AOLRebootNeeded] regsvr32.exe /s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter: text/plain - (no CLSID) - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Maya 7.0 Documentation Server (maya70docserver) - Unknown owner - C:\Program Files\Alias\Maya7.0\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya7.0\docs\Wrapper.conf (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Ewido Log:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 5:42:23 PM, 12/28/2005
+ Report-Checksum: 71CF233F
+ Scan result:
C:\Documents and Settings\Adam Bierman\Cookies\adam
bierman@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Adam Bierman\Cookies\adam
bierman@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Adam Bierman\Cookies\adam
bierman@partygaming.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.dll -> Trojan.Agent.bu : Cleaned with backup
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.dll -> Trojan.Agent.bu : Cleaned with backup
C:\WINDOWS\system32\002k0cho.dll -> Adware.Sud : Cleaned with backup
C:\WINDOWS\system32\azesearch4.ocx -> Spyware.AzSearch : Cleaned with backup
C:\WINDOWS\system32\iasada.dll_tobedeleted -> Spyware.AzSearch : Cleaned with backup
C:\WINDOWS\system32\service\explorer.exe -> Logger.Agent.ew : Cleaned with backup
C:\WINDOWS\system32\spoolsrv32.exe -> Spyware.FindSpy : Cleaned with backup
C:\WINDOWS\system32\ssldr32.dll -> Proxy.Agent.hs : Cleaned with backup
::Report End
Kasperskt Scan:
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, December 28, 2005 18:53:47
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 29/12/2005
Kaspersky Anti-Virus database records: 168091
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 46972
Number of viruses found: 19
Number of infected objects: 33
Number of suspicious objects: 1
Duration of the scan process: 3322 sec
Infected Object Name - Virus Name
C:\Program Files\BitComet\Downloads\Mathematica.v5.2\Keymaker.exe Suspicious: Type_Win32
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\586C2DBB.exe Infected: Trojan-PSW.Win32.Agent.bu
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP35\A0003142.exe Infected: Trojan-Downloader.Win32.Adload.l
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP35\A0003158.exe Infected: Trojan-Downloader.Win32.Qoologic.at
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP35\A0003159.exe Infected: Packed.Win32.Klone.b
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP35\A0003160.exe Infected: Packed.Win32.Klone.b
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP35\A0003161.exe Infected: Packed.Win32.Klone.b
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP35\A0003162.exe Infected: Packed.Win32.Klone.b
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP35\A0003163.exe Infected: Packed.Win32.Klone.b
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP35\A0003164.exe Infected: Trojan-Clicker.Win32.VB.kc
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP35\A0003229.exe Infected: Trojan-Downloader.Win32.Small.cam
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP36\A0003420.exe Infected: not-virus:Hoax.Win32.Renos.aj
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP36\A0003421.exe Infected: not-virus:Hoax.Win32.Renos.aj
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP40\A0003524.dll Infected: not-a-virus:AdWare.Win32.AzSearch.b
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003544.exe Infected: Trojan-PSW.Win32.Agent.bu
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003551.exe Infected: Trojan-PSW.Win32.Agent.bu
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003552.exe Infected: Trojan-Downloader.Win32.Harnig.ax
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003553.exe Infected: Trojan-Downloader.Win32.Tiny.al
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003554.exe Infected: Trojan-Dropper.Win32.Small.zp
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003555.exe Infected: Trojan-Downloader.Win32.Adload.j
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003557.exe Infected: not-virus:Hoax.Win32.Renos.aj
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003564.exe Infected: Trojan-Downloader.Win32.Adload.j
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003565.exe Infected: Trojan.Win32.StartPage.agp
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003574.exe Infected: Trojan-Downloader.Win32.Qoologic.at
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003576.exe Infected: Trojan-Downloader.Win32.Small.cam
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003634.dll Infected: Trojan-PSW.Win32.Agent.bu
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003635.dll Infected: Trojan-PSW.Win32.Agent.bu
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003636.dll Infected: not-a-virus:AdWare.Win32.Sud.a
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003637.ocx Infected: not-a-virus:AdWare.Win32.AzSearch.b
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003638.exe Infected: Trojan-Spy.Win32.Agent.ew
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003639.exe Infected: not-a-virus:AdWare.Win32.FindSpy.e
C:\System Volume Information\_restore{71B66B0C-02BE-465E-8FF4-8ABFC577DF54}\RP41\A0003640.dll Infected: Trojan-Proxy.Win32.Agent.hs
C:\WINDOWS\system32\srpcsrv32.dll Infected: Trojan-Downloader.Win32.Agent.rm
C:\WINDOWS\system32\txfdb32.dll Infected: Trojan-Downloader.Win32.Agent.rm
Scan process completed.
Smitfiles.txt log:
smitRem © log file
version 2.8
by noahdfear
Microsoft Windows XP [Version 5.1.2600]
The current date is: Wed 12/28/2005
The current time is: 16:32:27.28
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
checking for ShudderLTD key
ShudderLTD key not present!
checking for PSGuard.com key
PSGuard.com key not present!
checking for WinHound.com key
WinHound.com key not present!
spyaxe uninstaller NOT present
Winhound uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Existing Pre-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
Install.dat
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Craig.Peacock@beyondlogic.org
Killing PID 840 'explorer.exe'
Killing PID 840 'explorer.exe'
Starting registry repairs
Deleting files
Remaining Post-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~ Wininet.dll ~~~
CLEAN!
