spyware issues

Status
Not open for further replies.

krisjr

In the zone
hi guys,
i ran hijack this and this is wat i came across.

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe

the info in hijackthis says its suspected spyware,adware etc..but it might be some system files.since this involves registry i wanted some expert opinions from u guys..can i safely del these items etc..

do let me know
tx
 

swatkat

Technomancer
krisjr said:
hi guys,
i ran hijack this and this is wat i came across.

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe

the info in hijackthis says its suspected spyware,adware etc..but it might be some system files.since this involves registry i wanted some expert opinions from u guys..can i safely del these items etc..

do let me know
tx
these r not adwares/spywares...these r system files and some of them r of Norton, dont delete them.....
also, this is not a complete HijackThis log file, post the complete log file!!
 

Nemesis

Wise Old Owl
the only thing that's suspicious on this list is the webshots thing...but other than that, everything is safe...and like swat said, post the complete file...
 
OP
K

krisjr

In the zone
hi guys,well this is the complete file mate....rest wer spywares so i deleted them..webshots is my screensavers and wallpaper stuff..wat exactly u mean by complete log file..let me know plz.
tx
 

swatkat

Technomancer
When u run a latest version of HijackThis (1.99), u get an option screen with some buttons like "Do a System scan and save log file" , "Do a System scan only" etc.....here u click "Do a System scan and save log file", it then scans ur system and opens a "Save" dialog box, and here u click "Save", after this the log file is opened automatically in NotePad, u copy the entire content of Log file and Paste it in ur post here...

if u r not getting the Option screen as above, u click the button "Scan" in the HijackThis, and after the scan, click the button "Save Log" and rest of the process is same.....
 
Status
Not open for further replies.
Top Bottom