I'm on my dad's machine at the moment. He has something nasty on here. It seems obvious that some bugger is using the machine to attack others, because as stated in the topic description, he has 8,589,936,267 packets sent and counting, with 106,000 some odd received. No joke. I've followed the steps in the sticky topic before posting my HJT log. Check out all those processes - randomly generated exe reaking havoc, need help! Here it is!
==================================================
Logfile of HijackThis v1.99.1
Scan saved at 9:14:04 AM, on 6/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Plaxo\2.1.0.80\InstallStub.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\p0i70g.exe
C:\Program Files\Real\RealPlayer\rphelperapp.exe
C:\Program Files\Real\RealPlayer\rphelperapp.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\u2aj36p.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\system32\p0i70g.exe
C:\WINDOWS\system32\p0i70g.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\p0i70g.exe
C:\Documents and Settings\Censored\My Documents\Downloads\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.geekstogo.com/
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4A25D449-2BAA-4426-A992-D18CA70CF5A9} - C:\WINDOWS\system32\p5pxrz.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [Tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe /server"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [_Cat3] C:\WINDOWS\msmsgrxp.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.Exe -boot
O4 - HKLM\..\RunOnce: [e0u8ff.exe] C:\WINDOWS\system32\e0u8ff.exe /k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.1.0.80\InstallStub.exe -a
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ppctlcab - http://www.pestscan....er/ppctlcab.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zone...ctor/WebAAS.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
==================================================
Thanks so much.