Here is my Hijack This log can someone please help me. Thak You.
Logfile of HijackThis v1.97.7
Scan saved at 11:27:35 AM, on 6/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\System32\driver
s\CDAC11BA
.EXE
C:\WINDOWS\system32\driver
s\KodakCCS
.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTO
N~2\NPROTE
CT.EXE
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\WINDOWS\System32\ScsiAc
cess.EXE
C:\PROGRA~1\NORTON~1\NORTO
N~2\SPEEDD
~1\NOPDB.E
XE
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\posaszsll.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\WINDOWS\ukyzx.exe
C:\Compaq\eakdrv\STARTDRV.
exe
C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\CMP
DPSRV.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\yaxtlzao.exe
C:\Compaq\eakdrv\EAKDRV.ex
e
C:\Program Files\webHancer\Programs\w
hAgent.exe
C:\WINDOWS\System32\SahAge
nt.exe
C:\Program Files\AWS\WeatherBug\Weath
er.exe
C:\WINDOWS\System32\ctfmon
.exe
C:\Compaq\eakdrv\EAUSBKBD.
EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\smith family\Local Settings\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.
exe
C:\Program Files\Messenger\msmsgs.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page_bak =
http://www.yahoo.com/R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-E
A101271BC2
5} - C:\Program Files\TV Media\TvmBho.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\System
32\Userini
t.exe
O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-2
16055BF991
8} - (no file)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {c900b400-cdfe-11d3-976a-0
0e02913a9e
0} - C:\Program Files\webHancer\programs\w
hiehlpr.dl
l
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E
1B4C16F92E
B} - (no file)
O3 - Toolbar: (no name) - {BDF6CE3D-F5C5-4462-9814-3
C8EAC330CA
8} - (no file)
O4 - HKLM\..\Run: [vptg] C:\WINDOWS\posaszsll.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Smiley Faces For AIM] C:\Program Files\Smiley Faces\smiley_demo.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [ongpyb] C:\WINDOWS\ongpyb.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [mmcjleve] C:\WINDOWS\ukyzx.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.
exe
O4 - HKLM\..\Run: [fyvgvmj] C:\WINDOWS\fyvgvmj.exe
O4 - HKLM\..\Run: [dnvkrc] C:\WINDOWS\System32\qpdjrl
.exe
O4 - HKLM\..\Run: [Desksite CMA] c:\program files\desksite\bin\cma.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Compaq\eakdrv\STARTDRV.
exe
O4 - HKLM\..\Run: [CMPDPSRV] C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\CMP
DPSRV.EXE
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ahif] C:\WINDOWS\ahif.exe
O4 - HKLM\..\Run: [AdRoarUpdate] C:\WINDOWS\ARUpdate.exe
O4 - HKLM\..\Run: [hbstzuke] C:\WINDOWS\yaxtlzao.exe
O4 - HKLM\..\Run: [webHancer Agent] "C:\Program Files\webHancer\Programs\w
hAgent.exe
"
O4 - HKLM\..\Run: [SAHAgent] C:\WINDOWS\System32\SahAge
nt.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weath
er.exe 1
O4 - HKCU\..\Run: [Forbes] C:\Program Files\Forbes\ForbesAlerts.
exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
.exe
O4 - HKLM\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\RunOnce: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\6.1.4.37-7
288971L\Pr
ogram\runn
er.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar
2.dll/cmse
arch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar
2.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar
2.dll/cmca
che.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar
2.dll/cmsi
milar.html
O8 - Extra context menu item: Translate Page - res://C:\Program Files\Google\GoogleToolbar
2.dll/cmtr
ans.html
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\WebRebates\System\Te
mp\topr115
0_script0.
htm
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O9 - Extra button: WeatherBug (HKCU)
O9 - Extra button: Support (HKCU)
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.d
ll
O14 - IERESET.INF: START_PAGE_URL=
http://www.comcast.netO16 - DPF: {02BF25D5-8C17-4B23-BC80-D
3488ABDDC6
B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cabO16 - DPF: {11260943-421B-11D0-8EAC-0
000C07D88C
F} (iPIX ActiveX Control) -
http://www.ipix.com/viewers/ipixx.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-4
4455354000
0} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1
E41684E07B
B} -
http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.5.cabO16 - DPF: {2B96D5CC-C5B5-49A5-A69D-C
C0A30F9028
C} (MiniBugTransporterX Class) -
http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?rand=200341212O16 - DPF: {30528230-99F7-4BB4-88D8-F
A1D4F56A2A
B} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cabO16 - DPF: {33564D57-0000-0010-8000-0
0AA00389B7
1} -
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CABO16 - DPF: {41F17733-B041-4099-A042-B
518BB6A408
C} -
http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exeO16 - DPF: {56336BCB-3D8A-11D6-A00B-0
050DA18DE7
1} (RdxIE Class) -
http://207.188.7.150/25a84382ccc28c62c416/netzip/RdxIE601.cabO16 - DPF: {6A060448-60F9-11D5-A6CD-0
002B31F745
5} (ExentInf Class) -
http://us.games2.yimg.com/download.games.yahoo.com/games/play/client/exentctl_0_0_0_0.ocxO16 - DPF: {90C9629E-CD32-11D3-BBFB-0
0105A1F0D6
8} (InstallShield International Setup Player) -
http://www.napster.com/client/isetup.cabO16 - DPF: {917623D1-D8E5-11D2-BE8B-0
0104B06BDE
3} (CamImage Class) -
http://24.234.255.102/activex/AxisCamControl.cabO16 - DPF: {A031D222-B496-11D2-9CC8-0
0105A10AAF
6} (WONWebLauncher Class) -
http://www.virtualvegas.com/cab/WONWebLauncherControl.cabO16 - DPF: {A17E30C4-A9BA-11D4-8673-6
0DB54C1000
0} (YahooYMailTo Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dllO16 - DPF: {AED98630-0251-4E83-917D-4
3A23D66D50
7} (WebHandler Class) -
http://activex.microgaming.com/DLhelper/version6/dlhelper.cabO16 - DPF: {B942A249-D1E7-4C11-98AE-F
CB76B08747
F} (RealArcadeRdxIE Class) -
http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cabO16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-0
0105AA9B6A
E} (Symantec RuFSI Registry Information Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} -
http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_2_3_0.cabStart Free Trial