Here's what Ewido found:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 3:37:19 PM, 9/18/2005
+ Report-Checksum: 86313864
+ Scan result:
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0NAUOU0W\m11[1].jpg/y.bat -> Trojan.Zapchast : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.100:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Shopathomeselect : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Trafic : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Munks\Application Data\Mozilla\Firefox\Profiles\djvazmyu.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\gfhbh.exe/y.bat -> Trojan.Zapchast : Cleaned with backup
C:\WINDOWS\ra.reg -> Trojan.WinREG.LowZones.f : Cleaned with backup
C:\WINDOWS\y.bat -> Trojan.Zapchast : Cleaned with backup
::Report End
---------------------------------
I uploaded the file you told me:
Service load:
0% 100%
File: sysmanager.exe
Status:
INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 e3740152efc9ecb7b7bb839a1fb9ccae
Packers detected:
PE-CRYPT.ANTIDEB, UPX
Scanner results
AntiVir
Found Worm/SdBot.aad.175
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found Backdoor.SDBot.08D6C255
ClamAV
Found nothing
Dr.Web
Found Win32.HLLW.MyBot
F-Prot Antivirus
Found nothing
Fortinet
Found W32/SDBot.AAD-bdr
Kaspersky Anti-Virus
Found Backdoor.Win32.SdBot.aad
NOD32
Found a variant of IRC/SdBot
Norman Virus Control
Found nothing
UNA
Found nothing
VBA32
Found Backdoor.Win32.SdBot.aad
--------------------------------------
Here's a new HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 3:47:49 PM, on 9/18/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Wintab32.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
E:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\K-Lite Codec Pack\real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\sysmanager.exe
E:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
E:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Bonjour\mDNSResponder.exe
E:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\Program Files\RK Launcher\RKLauncher.exe
C:\Program Files\WinRoll\winroll.exe
C:\Program Files\YzShadow\YzShadow.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\Program Files\firefox.exe
E:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\K-Lite Codec Pack\real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [CTStartup] "C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE" /run
O4 - HKLM\..\Run: [CTSysVol] E:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] E:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [RemoteControl] "E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [RemoteCenter] E:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
O4 - HKCU\..\Run: [Active Desktop Calendar] E:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [RK Launcher] C:\Program Files\RK Launcher\RKLauncher.exe
O4 - HKCU\..\Run: [WinRoll] C:\Program Files\WinRoll\winroll.exe
O4 - HKCU\..\Run: [Yz Shadow] C:\Program Files\YzShadow\YzShadow.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1126545209156O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1126737490781O20 - Winlogon Notify: WB - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - E:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SystemManager - Unknown owner - C:\WINDOWS\sysmanager.exe
O23 - Service: Wintab32 - Unknown owner - C:\WINDOWS\System32\Wintab32.exe