Tech Support Guy banner

hijack this any body see anything ??

687 Views 0 Replies 1 Participant Last post by  dimmie
ogfile of HijackThis v1.97.7
Scan saved at 10:49:28 PM, on 3/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
C:\WINDOWS\System32\A0L.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\unzipped\hijackthis[1]\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.comcast.net/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AOL Messengar] A0L.EXE
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [AOL Messengar] A0L.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O9 - Extra button: ComcastHSI (HKCU)
O9 - Extra button: Help (HKCU)
O9 - Extra button: Support (HKCU)
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: MobRegCtrl - http://wfp.microsoft.com/register/MobRegCtrl.cab
O16 - DPF: Yahoo! NBA StatTracker - http://aud7.sports.yahoo.com/java/y/nbast8264_x.cab
O16 - DPF: Yahoo! NFL GameChannel StatTracker - http://aud15.sports.sc5.yahoo.com/java/y/nflgcst1010_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://www.comcastsupport.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {01FE8D0A-51AD-459B-B62B-85E135128B32} (DD_v4.DDv4) - http://www.drivershq.com/DD_v4.CAB
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/12119/CTSUEng.cab
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {11004D63-D403-4128-BE38-BA8035F01AE4} (csCAM.csAccountManager) - https://www.centershift.com/store31/x/csConsolidatedAccountManager.CAB
O16 - DPF: {1178E4A2-86B4-11D5-89FA-00C04F2FABD2} (STANPin.clsPins) - https://www.centershift.com/store31/x/STANPin.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {16FAC6F5-C570-4E77-9187-7ED6C9D6451C} (CXPlugin.CXMovein) - https://www.centershift.com/store31/x/csCXPlugIn.CAB
O16 - DPF: {18B01F09-2965-11D3-9461-00A0C9B1E042} (FunnyVoiceCtl Class) - http://www.kiddonet.com/kiddonet/luvclicks2/FunnyVoice.ocx
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/downl...-a3de-373c3e5552fc/msSecAdv.cab?1075962483655
O16 - DPF: {22CF1688-43B2-4BE6-AD4F-0BED3D188416} (BatchPaymentOCX.ctlBPay) - https://www.centershift.com/store31/x/BatchPaymentOCX.CAB
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {306A3A9D-5711-468C-89E1-08B53607ADEC} (Centershift_ClientManager.CS_CCManager) - https://www.centershift.com/store31/x/Centershift_ClientManager31.CAB
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://host.cycore.net/Cult.cab
O16 - DPF: {35A07B73-808D-409F-B12E-8EAE82154C78} (MessagePolling.ctlMsgPolling) - https://www.centershift.com/store31/x/msgPolling.CAB
O16 - DPF: {35D8C241-C955-49C1-8995-7B08DB1D089E} (Lookups.LookupAdmin) - https://www.centershift.com/store31/x/LookupProj.CAB
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {3FC76754-41A5-11D2-9370-00A0C9B1E042} (ColoringCtl Class) - http://www.kiddonet.com/lapware/actmenu/coloring/Coloring.ocx
O16 - DPF: {41A7F6B3-95E6-4E01-B370-DED12CA827B7} (csPrint.Receipt) - https://www.centershift.com/store31/x/csPrint31.CAB
O16 - DPF: {4799588E-BE7E-4C70-A99B-91F5E85C903A} (csPrint.PrintMoveOut) - https://www.centershift.com/store31/x/csPrint31.CAB
O16 - DPF: {4DA69678-F10F-430A-BC87-ED40B89F5875} (hKey.Current_user) - https://www.centershift.com/csweb/components/hkey.CAB
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) - http://www.gamehouse.com/ghdlctl.cab
O16 - DPF: {52EEED38-6E2F-4B1D-AE39-99FBB56CF8B1} (CSPayment.clsPayment) - https://www.centershift.com/store31/x/CSPayment.CAB
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.gocyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: {6B42B55C-583F-480C-861D-CED3FCAD3512} (csAuctionAdmin.ctlAuctionAdmin) - https://www.centershift.com/store31/x/csAuctionAdmin.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {846D1B10-EC6B-4334-9FFA-EABEC4E8F025} (csPopUpCalendar.csCal) - https://www.centershift.com/csweb/components/csCal.CAB
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs7b.instantservice.com/jars/customerxsigned33.cab
O16 - DPF: {9B1CF940-520E-48FA-B2E3-26DACF117FF9} (csPrint.smReceipt) - https://www.centershift.com/store31/x/csPrint31.CAB
O16 - DPF: {9C2FC5A6-1D2B-434D-82D8-38652C74F43A} (CSFSO.FileSystemObject) - https://www.centershift.com/store31/x/CSFSO.CAB
O16 - DPF: {9E84AFC0-6C29-43FE-8AB5-3A9701CBAB01} (Gate31.Controller) - https://www.centershift.com/store31/x/Gate31.CAB
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38021.7504976852
O16 - DPF: {A5741E90-2468-4444-96A1-507095977D40} (csReportView.csReportViewer) - https://www.centershift.com/csds22/csReportViewer.CAB
O16 - DPF: {A5F9D5D3-5A9E-40B5-8E5C-9CFAE21AF0DF} (CSInstallPak3.CSInstaller30) - https://www.centershift.com/store31/x/CSinstall30.CAB
O16 - DPF: {A61C74D0-3876-4CBD-9B75-61EC04FE31EE} (Navigator3.CS_Navigator3) - https://www.centershift.com/store31/x/csNavigator3.CAB
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
O16 - DPF: {AEABC324-386F-4CB6-94C2-45A35DA56B20} (csPrint.Lease) - https://www.centershift.com/store31/x/csPrint31.CAB
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {C96327C6-E2AD-49FB-AC10-6077B3BE3C42} (csPrint.PrintTrans) - https://www.centershift.com/store31/x/csPrint31.CAB
O16 - DPF: {C9BADB23-839E-48C7-BA37-4E1433F15E1C} (STANChangeAddress.clsChangeAddress) - https://www.centershift.com/store31/x/STANChangeAddress.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D313EAB1-0C96-4DFC-BE1D-447662CC0BA1} (csSearch.searchUserControl) - https://www.centershift.com/store31/x/csSearch.CAB
O16 - DPF: {DF6A0F17-0B1E-11D4-829D-00C04F6843FE} (Microsoft Office Tools on the Web Control) - http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab
O16 - DPF: {EF783396-97FB-400B-A6B0-2AC5A74D65DF} (CentershiftMap.csMap) - https://www.centershift.com/store31/x/csMap30.CAB
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/yiebio5_1_4_0.cab
O16 - DPF: {F187501F-293B-4E88-93E5-E8A536FAB937} (CSFSO.FileSystemObject) - https://www.centershift.com/csweb/components/CSFSO.CAB
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/12119/CTPID.cab
O16 - DPF: {F7A34E78-9C47-4B32-A425-4FF7B0E5F77F} (STANsearchControl.STANuserControl) - https://www.centershift.com/store31/x/csSearch.CAB
O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (Tukati Launcher) - http://http.gamezone.tukati.com/tukati/1.7.20.20/tukati.cab
See less See more
Status
Not open for further replies.
1 - 1 of 1 Posts
1 - 1 of 1 Posts
Status
Not open for further replies.
Top