I recently was invaded by CWS. I think all the problem is fixed since I ran CWShredder, but my system is running slower than before. Maybe something got missed.
I am attaching the Hijackthis log file hoping someone will let me know if everything is OK.
Logfile of HijackThis v1.97.7
Scan saved at 8:19:27 PM, on 4/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCE
S.EXE
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\system32\LEXPPS
.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\PGPsdk
Serv.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Toshiba\Network Device Switch 3\NDSTray.exe
C:\Program Files\Yahoo!\browser\ybrwi
con.exe
C:\WINDOWS\System32\TPWRTR
AY.EXE
C:\Program Files\TOSHIBA\TouchED\Touc
hED.Exe
C:\WINDOWS\System32\TFNF5.
exe
C:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe
C:\PROGRA~1\NORTON~1\navap
w32.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\WINDOWS\System32\00THot
key.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\HistoryKill\histkill
.exe
C:\Program Files\ClipCache\clipc.exe
C:\PROGRA~1\Greatis\REGRUN
~1\WatchDo
g.exe
C:\PROGRA~1\Yahoo!\browser
\ycommon.e
xe
C:\Program Files\RFA\rfagent.exe
C:\Program Files\HistoryKill\hkPopupK
iller.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.e
xe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\MultiMacro\multimac.
exe
C:\Program Files\PGP Corporation\PGP for Windows XP\PGPtray.exe
C:\Program Files\MemTurbo\MemTurbo.ex
e
C:\Documents and Settings\Ron\Desktop\Clean
Up Programs\hijackthis\Hijack
This.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://dsl.sbc.yahoo.com/R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://yahoo.sbc.com/dslR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://yahoo.sbc.com/dslR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page = c:\WINDOWS\PCHEALTH\HELPCT
R\System\p
anels\blan
k.htm
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIE
Helper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - c:\DOCUME~1\Ron\Desktop\CL
EANU~1\SPY
BOT~1\SPYB
OT~1.1\SDH
elper.dll
O2 - BHO: (no name) - {56B38F40-4E70-11d4-A076-0
080AD86BA2
F} - C:\Program Files\Larson Software Technology\Larson WebView CGM\cgmopenbho.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-0
0400523e39
a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0
090271D075
B} - C:\PROGRA~1\FlashGet\jccat
ch.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-F
ADC6B08487
2} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
859DF00B1D
6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0
050BA6940E
3} - C:\PROGRA~1\FlashGet\fgieb
ar.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-0
0400523e39
a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\Toshiba\Network Device Switch 3\NDSTray.exe"
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwi
con.exe
O4 - HKLM\..\Run: [TSysSMon] c:\toshiba\sysstability\ts
yssmon.exe
/detect
O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\Touc
hED.Exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TFncKy] c:\Program Files\Toshiba\TOSHIBA Controls\TFncKy.exe /Type 20
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [NAV Agent] c:\PROGRA~1\NORTON~1\navap
w32.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THot
key.exe
O4 - HKLM\..\Run: [RegRun WinBait] C:\WINDOWS\winbait.exe
O4 - HKLM\..\Run: [@RegRunOnSecure] C:\PROGRA~1\Greatis\REGRUN
~1\OnSecur
e.exe
O4 - HKLM\..\Run: [PDF Converter Registry Controller] "C:\Program Files\ScanSoft\PDF Converter\RegistryControll
er.exe"
O4 - HKLM\..\Run: [PDFConverterReminder] "C:\PROGRA~1\ScanSoft\PDFC
ON~1\EReg\
EReg.exe" -r "C:\PROGRA~1\ScanSoft\PDFC
ON~1\EReg\
ereg.ini"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe
O4 - HKCU\..\Run: [HistoryKill] C:\Program Files\HistoryKill\histkill
.exe /startup
O4 - HKCU\..\Run: [ClipCache] C:\Program Files\ClipCache\clipc.exe /wait 3
O4 - HKCU\..\Run: [Regrun2] C:\PROGRA~1\Greatis\REGRUN
~1\WatchDo
g.exe
O4 - HKCU\..\Run: [RFAgent] C:\Program Files\RFA\rfagent.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.e
xe"
O4 - Startup: MemTurbo.lnk = C:\Program Files\MemTurbo\MemTurbo.ex
e
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: MultiMacro.lnk = C:\Program Files\MultiMacro\multimac.
exe
O4 - Global Startup: PGPtray.lnk = ?
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: Customize Menu &4 - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustom
izeIEMenu.
html
O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1\FlashGet\jc_al
l.htm
O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1\FlashGet\jc_li
nk.htm
O8 - Extra context menu item: Fill Forms &] - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillFo
rms.html
O8 - Extra context menu item: Open PDF in Word - res://C:\Program Files\ScanSoft\PDF Converter\IEShellExt.dll /100
O8 - Extra context menu item: Save Forms &[ - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePa
ss.html
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict
.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch
.htm
O9 - Extra button: Yahoo! Login (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM)
O9 - Extra button: Fill Forms (HKLM)
O9 - Extra 'Tools' menuitem: Fill Forms &] (HKLM)
O9 - Extra button: Save (HKLM)
O9 - Extra 'Tools' menuitem: Save Forms &[ (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: RoboForm (HKLM)
O9 - Extra 'Tools' menuitem: RF Toolbar &2 (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugi
n2.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {2B323CD9-50E3-11D3-9466-0
0A0C970049
8} (Yahoo! Audio Conferencing) -
http://us.i1.yimg.com/us.yimg.com/i/chat/a...v45/yacscom.cabO16 - DPF: {556DDE35-E955-11D0-A707-0
0000052195
7} -
http://www.xblock.com/download/xclean_micro.exeO16 - DPF: {5B2B8121-7216-11D5-9A00-0
0000000000
0} (IRARO.IRAROConf) -
http://www.technalink.com/vdist/iraro/IRARO.CABO16 - DPF: {74FFE28D-2378-11D5-990C-0
0609423508
4} (IBM Access Support) -
https://www-3.ibm.com/pc/support/access/sdc...en/IbmEgath.cabO16 - DPF: {9CF28A69-7659-4C51-BFD5-9
ADE19E19EC
3} (RegConfig Class) -
http://download.yahoo.com/dl/installs/bkm/prod/yregcfg.cabO16 - DPF: {A17E30C4-A9BA-11D4-8673-6
0DB54C1000
0} (YahooYMailTo Class) -
http://download.yahoo.com/dl/installs/ymail/ymmapi.dllO16 - DPF: {A3009861-330C-4E10-822B-3
9D16EC8829
D} (CRAVOnline Object) -
http://www.ravantivirus.com/scan/ravonline.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwa...ash/swflash.cabO16 - DPF: {DF6A0F17-0B1E-11D4-829D-0
0C04F6843F
E} (Microsoft Office Tools on the Web Control) -
http://officeupdate.microsoft.com/Template...nloads/outc.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-F
B9E207A39E
6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/...239/mcfscan.cabO16 - DPF: {F54C1137-5E34-4B95-95A5-B
A56D4D8D74
3} (Secure Delivery) -
http://content.kontiki.com/kdx/v2.20/konti...current/kdx.cab