I know I have Spyware/Adware, need help finding and removing.
Windows XP SP2, on SBS Domain with Barracuda Web Filter and Spam Filter. Here's my HiJack This Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:57:33 PM, on 3/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
C:\Program Files\Broadcom\ASFIPMon\As
fIpMon.exe
C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe
C:\Program Files\Wireless-G Portable USB Adapter\WUSB54GP.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\All Users\Application Data\zktynktc\hctwdoxi.exe
C:\Program Files\Java\jre1.6.0_03\bin
\jusched.e
xe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.e
xe
C:\Program Files\CyberLink\PowerDVD\D
VDLauncher
.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System32\DLA\DL
ACTRLW.EXE
C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Google\GoogleToolbar
Notifier\G
oogleToolb
arNotifier
.exe
C:\WINDOWS\system32\bilolg
lu.exe
C:\Program Files\3M\PSN2Lite\Psn2Lite
.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\Program Files\Microsoft Office\Office12\ONENOTEM.E
XE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.
exe
C:\PROGRA~1\3M\PSN2Lite\PS
NGive.exe
C:\Program Files\iPod\bin\iPodService
.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.
exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.e
xe
C:\WINDOWS\system32\wscntf
y.exe
C:\DOCUME~1\RODTAK~1\LOCAL
S~1\Temp\S
D.TMP\axsc
an.exe
C:\Program Files\Java\jre1.6.0_03\bin
\jucheck.e
xe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://companywebR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://companywebR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Search,Default_Pa
ge_URL =
www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070704O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
0123456789
0} - C:\WINDOWS\System32\DLA\DL
ASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - C:\Program Files\Java\jre1.6.0_03\bin
\ssv.dll
O2 - BHO: GNX Bingo - {903AD98D-8A91-4FBB-B5E1-4
FFCA9003E6
A} - C:\WINDOWS\kdftlboeorn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
E66B5AD205
D} - C:\Program Files\Google\GoogleToolbar
Notifier\2
.0.301.716
4\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A
07C3DB8F77
7} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O3 - Toolbar: qvdntlmw - {19188BC4-4E06-48E6-9C54-8
E94425AEF0
2} - C:\WINDOWS\qvdntlmw.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin
\jusched.e
xe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.e
xe" runtime -Delay
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\D
VDLauncher
.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DL
ACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTA
L~1\UPDATE
~1\ISUSPM.
exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update
Service\is
sch.exe" -start
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobs
ync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe
" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
Notifier\G
oogleToolb
arNotifier
.exe
O4 - HKCU\..\Run: [EPSON PictureMate PM 200] C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\E_F
ATIBBA.EXE
/FU "C:\WINDOWS\TEMP\E_S1BB.tm
p" /EF "HKCU"
O4 - HKCU\..\Run: [EPSON PictureMate PM 200 (from RODDYS-TOSHIBA)] C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\E_F
ATIBBA.EXE
/FU "C:\WINDOWS\TEMP\E_S22A.tm
p" /EF "HKCU"
O4 - HKCU\..\Run: [jqbypcrm] C:\WINDOWS\system32\bilolg
lu.exe
O4 - HKLM\..\Policies\Explorer\
Run: [MC7d7gCj2Z] C:\Documents and Settings\All Users\Application Data\zktynktc\hctwdoxi.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.E
XE
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSN2Lite\Psn2Lite
.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office12\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_03\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_03\bin
\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MICROS~2\Offic
e12\ONBttn
IE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5
663EE0C6C4
9} - C:\PROGRA~1\MICROS~2\Offic
e12\ONBttn
IE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MI05E6~1\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprov
au.dll
O16 - DPF: {0BCADE60-1E93-11D8-ABDA-0
004759647B
3} (FastBid1 Class) -
http://www.bxwa.com/fastbid/fastbidx1.cabO16 - DPF: {32322460-3E7D-11D7-ABD8-0
001029A9BA
6} (FastBid2 Class) -
http://www.bxwa.com/fastbid/fastbidx2.cabO16 - DPF: {485D813E-EE26-4DF8-9FAF-D
EDF2885306
E} (NSHelp Class) -
http://pe-main/connectcomputer/nshelp.dllO16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1193677709328O16 - DPF: {708C978C-BBF5-4038-8DC1-6
4FF22BCFFB
6} (AXScan Control) -
https://192.168.1.2/cleanup/tool/BarracudaSpyRemoval.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = pe.local
O17 - HKLM\Software\..\Telephony
: DomainName = pe.local
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = pe.local
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~
1\GOEC62~1
.DLL
O21 - SSODL: yYiqglkRjSO - {E496A03D-4E3C-0A97-F98D-E
C0ABBE152F
0} - C:\WINDOWS\system32\fdef.d
ll
O21 - SSODL: vbgtorfd - {F3900FCA-0A16-41AA-BC5C-C
0406D83EC3
5} - C:\WINDOWS\vbgtorfd.dll
O21 - SSODL: dwnrpofk - {94BB7032-AE9E-4BF1-ADA4-3
E3217037D7
9} - C:\WINDOWS\dwnrpofk.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: Broadcom ASF IP Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\As
fIpMon.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
xx.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManage
r.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: WUSB54GPSVC - GEMTEKS - C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe
--
End of file - 9556 bytes