Need specific Removal instructions for this log:
Logfile of HijackThis v1.99.1
Scan saved at 5:32:00 PM, on 03/23/2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon
.exe
C:\WINNT\system32\services
.exe
C:\WINNT\system32\lsass.ex
e
C:\WINNT\system32\svchost.
exe
C:\WINNT\system32\spoolsv.
exe
C:\WINNT\System32\PackethS
vc.exe
C:\Program Files\Symantec_Client_Secu
rity\Syman
tec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.
exe
D:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Symantec_Client_Secu
rity\Syman
tec AntiVirus\Rtvscan.exe
C:\WINNT\system32\regsvc.e
xe
C:\WINNT\system32\MSTask.e
xe
C:\WINNT\System32\WBEM\Win
Mgmt.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\MSWHEEL.
EXE
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
C:\WINNT\loadqm.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\winnt\system32\ttsigr.e
xe
C:\WINNT\Profiles\All Users\Application Data\msw\BMan1.exe
C:\PROGRA~1\Toolbar\TBPS.e
xe
C:\WINNT\system\bkcmmxnew.
exe
C:\WINNT\System32\sysmonnt
.exe
C:\WINNT\Profiles\Station6
\Applicati
on Data\rwun.exe
C:\WINNT\Profiles\ALLUSE~1
\APPLIC~1\
msw\BMan.e
xe
C:\WINNT\System32\j?vaw.ex
e
C:\winnt\system32\calc.exe
C:\PROGRA~1\Toolbar\PIB.ex
e
C:\Program Files\Common Files\Intuit\QuickBooks\QB
Update\qbu
pdate.exe
c:\PROGRA~1\Toolbar\radio.
exe
C:\WINNT\Profiles\Station6
\Desktop\H
JT\HijackT
his.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer,(Default) =
www.google.comR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://smbusiness-dell.excite.com/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://www.websearch.com/ie.aspx?tb_id=50220R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
www.google.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,SearchAssist
ant =
http://www.websearch.com/ie.aspx?tb_id=50220R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,CustomizeSea
rch = res://C:\PROGRA~1\Toolbar\
toolbar.dl
l/sa
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://www.websearch.com/ie.aspx?tb_id=50220R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch = res://C:\PROGRA~1\Toolbar\
toolbar.dl
l/sa
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CompuServe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3
DBE0391097
2} - C:\PROGRA~1\Toolbar\toolba
r.dll
O2 - BHO: PynixObj Class - {00000000-DD60-0064-6EC2-6
E010000000
0} - C:\WINNT\Pynix.dll
O2 - BHO: RsyncHlpr Class - {16B238D5-80DE-47CE-8F17-B
3ECE2C2248
D} - C:\WINNT\System32\rsyncmon
.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3
DBE0391097
2} - C:\PROGRA~1\Toolbar\toolba
r.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-2
9EA915965E
C} - C:\PROGRA~1\Toolbar\toolba
r.dll
O4 - HKLM\..\Run: [POINTER] C:\PROGRA~1\MSHARD~1\point
32.exe
O4 - HKLM\..\Run: [NTrtc] C:\Y2000RTC\NTRTC.EXE
O4 - HKLM\..\Run: [Norton Program Scheduler Event Checker] D:\Program Files\Norton SystemWorks\Norton Antivirus NT\NPSCHECK.EXE
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [iamapp] "D:\Program Files\Norton Personal Firewall\IAMAPP.EXE"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMAN
T~1\vptray
.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [winupdtl] C:\WINNT\System32\winupdt.
exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [farmmext] C:\WINNT\farmmext.exe
O4 - HKLM\..\Run: [ttsigr] c:\winnt\system32\ttsigr.e
xe
O4 - HKLM\..\Run: [no97iq0n] C:\Program Files\no97iq0n\no97iq0n.ex
e
O4 - HKLM\..\Run: [uFoO3tO] vdmbkup.exe
O4 - HKLM\..\Run: [BMan] C:\WINNT\Profiles\All Users\Application Data\msw\BMan1.exe
O4 - HKLM\..\Run: [RSync] C:\WINNT\System32\netsync.
exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-A
WA~2\Ad-Wa
tch.exe"
O4 - HKLM\..\Run: [etbrun] C:\winnt\system32\elitefmj
32.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.e
xe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [sysmonnt] C:\WINNT\System32\sysmonnt
O4 - HKCU\..\Run: [fo7ERjisj] skdyuv.exe
O4 - HKCU\..\Run: [Aned] C:\WINNT\Profiles\Station6
\Applicati
on Data\rwun.exe
O4 - HKCU\..\Run: [Ypiuqs] C:\WINNT\System32\j?vaw.ex
e
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QB
Update\qbu
pdate.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmse
arch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmca
che.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmtr
ans.html
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-0
0105A1B41B
8} - C:\WINNT\Downloaded Program Files\SbCIe028.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - (no file)
O12 - Plugin for .sib: C:\Program Files\Internet Explorer\PLUGINS\NPSibeliu
s.dll
O13 -
WWW. Prefix:
http://O16 - DPF: {0837121A-6472-43BD-8A40-D
9221FF1C4C
E} -
http://download.sidestep.com/get/k00719/sb028.cabO16 - DPF: {30528230-99F7-4BB4-88D8-F
A1D4F56A2A
B} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cabO16 - DPF: {50F65670-1729-11D2-A51F-0
020AFE5D50
2} (ForumChat) -
http://objects.compuserve.com/chat/RTCChat.cabO16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0
060082AA75
C} (GpcContainer Class) -
https://ecevents.webex.com/client/v_eureka-fiji/event/ieatgpc.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = saihfw.com
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = saihfw.com
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: Domain = saihfw.com
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-E
DC1B3FE100
C} - C:\PROGRA~1\Toolbar\toolba
r.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon
.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Secu
rity\Syman
tec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.
exe
O23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation - D:\Program Files\Norton Personal Firewall\NISSERV.EXE
O23 - Service: NISUM - Symantec Corporation - D:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Secu
rity\Syman
tec AntiVirus\Rtvscan.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINNT\System32\PackethS
vc.exe