An icon labeled TAG (TagASaurus) appeared on my desktop. Since then, I have lost my internet access, my browser home page seems to get re-directed and all of my bookmarks have been changed to the same re-direct. I downloaded, installed and ran HijackThis and my log is as follows (any help would be appreciated):
Logfile of HijackThis v1.99.1
Scan saved at 1:16:07 PM, on 5/8/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\FSI\F-Prot\fpavupdm.exe
C:\WINNT\System32\llssrv.exe
C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\50\bin\OWSTIMER.EXE
C:\WINNT\nhvqvhx.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\Explorer.EXE
C:\Program Files\FSI\F-Prot\F-Sched.exe
C:\Program Files\FSI\F-Prot\F-StopW.EXE
C:\windows\mousepad17.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\nhvqvhxA.exe
C:\winnt\system32\fthot.exe
C:\WINNT\system32\logon.exe
C:\Program Files\VIA Technologies, Inc\VIA Audio Driver Setup Program\AudioDeck\AudioDeck.exe
C:\WINNT\System32\svchost.exe
C:\Install\HijackThis\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://fast-finder.com/searchresults.asp?si=20061&k=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://fast-finder.com/searchresults.asp?si=20061&k=
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_22.dll
O2 - BHO: (no name) - {B86C63AF-1916-4B1E-9165-9A70208935C6} - C:\Program Files\Internet Explorer\horec.dll
O2 - BHO: SDWin32 Class - {BB18E44E-A622-411E-81C3-EFC23BD0CFB6} - C:\WINNT\system32\zexgp.dll
O2 - BHO: SDWin32 Class - {E939BDAB-6802-44A8-9C1A-E630A560522A} - C:\WINNT\system32\xtgvw.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [FRISK FP-Scheduler] C:\Program Files\FSI\F-Prot\F-Sched.exe STARTUP
O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
O4 - HKLM\..\Run: [F-StopW] C:\Program Files\FSI\F-Prot\F-StopW.EXE
O4 - HKLM\..\Run: [Microsoft (R) Windows Update Manager] C:\WINNT\system32\ppvypqv.exe
O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard17.exe
O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad17.exe
O4 - HKLM\..\Run: [newname] C:\windows\newname17.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [nhvqvhxA] C:\WINNT\nhvqvhxA.exe
O4 - HKLM\..\Run: [lstat] c:\winnt\system32\fthot.exe
O4 - HKLM\..\Run: [xtgvwc] C:\WINNT\system32\xtgvwc.exe
O4 - HKLM\..\Run: [zexgpc] C:\WINNT\system32\zexgpc.exe
O4 - HKLM\..\Run: [Windows Logon Application] C:\WINNT\system32\logon.exe
O4 - HKCU\..\Run: [kmir] C:\Program Files\Common Files\kmir\kmirm.exe
O4 - Global Startup: AudioDeck.lnk = C:\Program Files\VIA Technologies, Inc\VIA Audio Driver Setup Program\AudioDeck\AudioDeck.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O13 - WWW. Prefix: http://
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138297860078
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138306460203
O17 - HKLM\System\CCS\Services\Tcpip\..\{75E483E7-DDDE-4EEE-A0B5-BD31656151B6}: NameServer = 64.105.189.26,64.105.179.138
O20 - Winlogon Notify: App Management - C:\WINNT\system32\tafaux.dll (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: F-Prot Antivirus Update Monitor - FRISK Software - C:\Program Files\FSI\F-Prot\fpavupdm.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Windows Update Manager (UpdateManager) - Unknown owner - C:\WINNT\system32\ppvypqv.exe (file missing)
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINNT\nhvqvhx.exe