Recently, Ive been noticing some spyware toolbars on one of my other computers. Here is the log from Hijack this: If you can tell me which processses I should delete, it would be a big help
unning processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Picasa\PicasaMediaDe
tector.exe
C:\Program Files\Support.com\bin\tgcm
d.exe
C:\Program Files\PhoneTools\CapFax.EX
E
C:\Program Files\Hewlett-Packard\Tool
box2.0\Apa
che Tomcat 4.0\webapps\Toolbox\Status
Client\Sta
tusClient.
exe
C:\Program Files\Real\RealPlayer\Real
Play.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\Program Files\Altnet\Points Manager\Points Manager.exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Common files\updmgr\updmgr.exe
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\WINDOWS\System32\ctfmon
.exe
C:\PROGRA~1\AIM\aim.exe
C:\WINDOWS\System32\RUNDLL
32.EXE
C:\Program Files\Netscape\Netscape\Ne
tscp.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\America Online 9.0a\aoltray.exe
C:\Program Files\Common Files\GMT\GMT.exe
C:\WINDOWS\system32\ntvdm.
exe
C:\PROGRA~1\Altnet\DOWNLO~
1\asm.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\Hewlett-Packard\Tool
box2.0\Jav
asoft\JRE\
1.3.1\bin\
javaw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINDOWS\System32\gearse
c.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\nvsvc3
2.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\iPod\bin\iPodService
.exe
C:\WINDOWS\System32\MsgSys
.EXE
C:\PROGRA~1\WINZIP\winzip3
2.exe
C:\unzipped\hijackthis\Hij
ackThis.ex
e
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.comcast.netR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - URLSearchHook: PerfectNavBHO Class - {00D6A7E7-4A97-456f-848A-3
B75BF7554D
7} - C:\PROGRA~1\PERFEC~1\BHO\P
ERFEC~1.DL
L
N3 - Netscape 7: user_pref("browser.search.
defaulteng
ine", "engine://C%3A%5CProgram%2
0Files%5CN
etscape%5C
Netscape%5
Csearchplu
gins%5CSBW
eb_01.src"
); (C:\Documents and Settings\Charlene\Applicat
ion Data\Mozilla\Profiles\defa
ult\cqufgw
xo.slt\pre
fs.js)
O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3
B75BF7554D
7} - C:\PROGRA~1\PERFEC~1\BHO\P
ERFEC~1.DL
L
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEH
elper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDe
tector.exe
O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgki
ll.exe /cleaneahtioga /start
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CapFax] C:\Program Files\PhoneTools\CapFax.EX
E
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Tool
box2.0\Apa
che Tomcat 4.0\webapps\Toolbox\Status
Client\Sta
tusClient.
exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Tool
box2.0\hpb
psttp.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\Real
Play.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.
exe
O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\w
hSurvey.ex
e"
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [AltnetPointsManager] C:\Program Files\Altnet\Points Manager\Points Manager.exe -s
O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTR
AY.DLL,NvT
askbarInit
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Ne
tscp.exe" -turbo
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
obe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0a\aoltray.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
2.dll/cmse
arch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar
2.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar
2.dll/cmca
che.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar
2.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
2.dll/cmtr
ans.html
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O9 - Extra button: ComcastHSI (HKCU)
O9 - Extra button: Support (HKCU)
O9 - Extra button: Help (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.d
ll
O14 - IERESET.INF: START_PAGE_URL=
http://www.comcast.netO16 - DPF: Squelchies by pogo -
http://squelchies.pogo.com/applet-5.8.1.28/squelchies/squelchies-ob-assets.cabO16 - DPF: {02BCC737-B171-4746-94C9-0
D8A0B2C008
9} (Microsoft Office Template and Media Control) -
http://office.microsoft.com/templates/ieawsdc.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-4
4455354000
0} (Shockwave ActiveX Control) -
http://active.macromedia.com/director/cabs/sw.cabO16 - DPF: {1D6711C8-7154-40BB-8380-3
DEA45B69CB
F} (Web P2P Installer) -
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-C
C0A30F9028
C} (MiniBugTransporterX Class) -
http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8
DC6B52AB35
B} (QDiagAOLCCUpdateObj Class) -
http://aolcc.aol.com/computercheckup/qdiagcc.cabO16 - DPF: {739E8D90-2F4C-43AD-A1B8-6
6C356FCEA3
5} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX
.CAB
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D
18220D90AD
1} (StartFirstControl.CheckFi
rst) - hcp://system/StartFirstCon
trol.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {DF6A0F17-0B1E-11D4-829D-0
0C04F6843F
E} (Microsoft Office Tools on the Web Control) -
http://dgl.microsoft.com/downloads/outc.cabO16 - DPF: {F54C1137-5E34-4B95-95A5-B
A56D4D8D74
3} (Secure Delivery) -
http://moviefone.kontiki.com/securedelivery/main/kdx.cabThanks!