Thanks for looking over my introduction. Here is the latest HJT log on the Barton:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 6:53:36 AM, on 1/12/2007
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
Boot mode: Safe mode with network support
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\dmadmin.exe
D:\WINDOWS\Explorer.EXE
D:\Documents and Settings\Administrator.TEMP-7KNDXUB9ET\Desktop\HiJackThis_v2.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [EPoXUSDM] "C:\Program files\EPoX\USDM\USDM.EXE" "5000"
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [ShutdownEventCheck] %systemroot%\system32\dumprep 0 -s
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O15 - ESC Trusted Zone:
http://www.0spam.comO15 - ESC Trusted Zone:
http://forums.######.comO15 - ESC Trusted Zone:
http://www.andale.comO15 - ESC Trusted Zone:
http://www.download.comO15 - ESC Trusted Zone:
http://www.dsldepot.comO15 - ESC Trusted Zone:
http://support.gateway.comO15 - ESC Trusted Zone:
http://search.irs.govO15 - ESC Trusted Zone:
http://www.irs.govO15 - ESC Trusted Zone:
http://www.learnflash.comO15 - ESC Trusted Zone:
http://www.learnoffice2003.comO15 - ESC Trusted Zone:
http://www.learnsqlserver.comO15 - ESC Trusted Zone:
http://www.learnwebdevelopment.comO15 - ESC Trusted Zone:
http://www.learnwindowsserver.comO15 - ESC Trusted Zone:
http://mail01.mail.comO15 - ESC Trusted Zone:
http://auto.search.msn.comO15 - ESC Trusted Zone:
http://by101fd.bay101.Email Removed.msn.com
O15 - ESC Trusted Zone:
http://by24fd.bay24.Email Removed.msn.com
O15 - ESC Trusted Zone:
http://by2fd.bay2.Email Removed.msn.com
O15 - ESC Trusted Zone:
http://runonce.msn.comO15 - ESC Trusted Zone:
http://webmailb.netzero.netO15 - ESC Trusted Zone:
http://loginnet.passport.comO15 - ESC Trusted Zone:
http://login.passport.netO15 - ESC Trusted Zone:
http://www.tax.state.ny.usO15 - ESC Trusted Zone:
http://*.windowsupdate.comO15 - ESC Trusted Zone:
http://www.zinncycles.comO15 - ESC Trusted Zone:
http://runonce.msn.com (HKLM)
O15 - ESC Trusted Zone:
http://*.windowsupdate.com (HKLM)
O15 - ESC Trusted IP range: 192.168.0.1
O15 - ESC Trusted IP range:
http://192.168.1.1O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
--
End of file - 4170 bytes
I've made some progress but CWShredder informed me that I had a Coolweb variant and started with a random text. I also have rootcheck and other logs in the event you want to take this on.