Logfile of HijackThis v1.97.7
Scan saved at 4:59:19 AM, on 5/13/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\System32\Ati2ev
xx.exe
E:\Program Files\Diskeeper\DkService.
exe
E:\PROGRA~1\new\NORTON~2\G
HOSTS~2.EX
E
E:\Program files\new\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\INTEL\DSLSetup\ProDs
l.exe
C:\WINDOWS\system32\ZONELA
BS\vsmon.e
xe
C:\Program Files\Logitech\iTouch\iTou
ch.exe
C:\PROGRA~1\PESTPA~1\PPMem
Check.exe
C:\WINDOWS\System32\sstray
.exe
E:\Program files\AnalogX\CookieWall\c
ookie.exe
E:\Program files\Ahead InCd packet writer\InCD.exe
E:\PROGRA~1\ZONELA~1\ZONEA
L~1\zlclie
nt.exe
E:\Program files\new\Norton Utilities\SYSDOC32.EXE
C:\Program Files\Internet Explorer\iexplore.exe
E:\Program Files\Microsoft Office\Office\WINWORD.EXE
E:\PROGRA~1\PASSWO~1\PWAGE
NT.EXE
E:\Program files\PC_Cillin 2004 w security\tmproxy.exe
E:\Program files\PC_Cillin 2004 w security\PccPfw.exe
E:\Program files\PC_Cillin 2004 w security\Tmntsrv.exe
E:\Program files\PC_Cillin 2004 w security\PCClient.EXE
E:\Program files\PC_Cillin 2004 w security\PCCGUIDE.EXE
E:\Program files\PC_Cillin 2004 w security\TMOAgent.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\rundll
32.exe
E:\Program files\Download U Meter\DUMeter.exe
E:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
E:\PROGRA~1\new\NORTON~3\Q
DCSFS.EXE
P:\Program Storage main\data, file recovery progs\HijackThis 1.97.7\HijackThis.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://my.myway.com/R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page = c:\WINDOWS\PCHEALTH\HELPCT
R\System\p
anels\blan
k.htm
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - E:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDs
l.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTou
ch.exe
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMem
Check.exe
O4 - HKLM\..\Run: [KeyPatrol] c:\PROGRA~1\PESTPA~1\KeyPa
trol.exe
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCh
eck.exe
O4 - HKLM\..\Run: [CookieWall] E:\Program files\AnalogX\CookieWall\c
ookie.exe
O4 - HKLM\..\Run: [InCD] E:\Program files\Ahead InCd packet writer\InCD.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\
drivers\w3
2x86\3\hpz
tsb04.exe
O4 - HKLM\..\Run: [pccguide.exe] "E:\Program files\PC_Cillin 2004 w security\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "E:\Program files\PC_Cillin 2004 w security\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "E:\Program files\PC_Cillin 2004 w security\TMOAgent.exe" /run
O4 - HKLM\..\Run: [Zone Labs Client] E:\PROGRA~1\ZONELA~1\ZONEA
L~1\zlclie
nt.exe
O4 - HKLM\..\Run: [QD FastAndSafe] E:\PROGRA~1\new\NORTON~3\Q
DCSFS.exe /scheduler
O4 - HKLM\..\Run: [DU Meter] E:\Program files\Download U Meter\DUMeter.exe
O4 - HKLM\..\RunOnce: [Q828026] "C:\WINDOWS\INF\unregmp2.e
xe" /UpdateWMP
O4 - Startup: Norton System Doctor.LNK = E:\Program files\new\Norton Utilities\SYSDOC32.EXE
O4 - Global Startup: CleanSweep Smart Sweep-Internet Sweep.LNK = E:\Program files\new\Norton CleanSweep\csinsmnt.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmse
arch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmca
che.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmtr
ans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.
dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-0
0105AA9B6A
E} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cabO16 - DPF: {2FC9A21E-2069-4E47-8235-3
6318989DB1
3} (PPSDKActiveXScanner.MainS
creen) -
http://www.pestscan.com/scanner/axscanner.cabO16 - DPF: {3E68E405-C6DE-49FF-83AE-4
1EE9F4C36C
E} (Office Update Installation Engine) -
http://office.microsoft.com/officeupdate/content/opuc.cabO16 - DPF: {56336BCB-3D8A-11D6-A00B-0
050DA18DE7
1} (RdxIE Class) -
http://software-dl.real.com/066c489dc13b0ce2a521/netzip/RdxIE601.cabO16 - DPF: {638AF6A2-81A1-4655-9FFA-9
FC09CDE22C
F} (CScanner Object) -
http://www.pestscan.com/scanner/ppctlcab.cabO16 - DPF: {90C9629E-CD32-11D3-BBFB-0
0105A1F0D6
8} (InstallShield International Setup Player) -
http://www.installengine.com/engine/isetup.cabO16 - DPF: {9EB320CE-BE1D-4304-A081-4
B4665414BE
F} (MediaTicketsInstaller Control) -
http://www.mt-download.com/MediaTicketsInstaller.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-4
7A8489BB47
F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38010.1882523148O16 - DPF: {A8658086-E6AC-4957-BC8E-7
D54A7E8A78
E} (SassCln Object) -
http://www.microsoft.com/security/controls/Sasser/20/SassCln.CABO16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-0
0105AA9B6A
E} (Symantec RuFSI Registry Information Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {C8FDFFC4-0FCA-4FC0-8D9F-6
297479D680
E} (iolo.SR.RescueWizard.Test
Drive) -
http://www.iolo.com/sr/ocx/reswiz.ocxO16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0
F47A330807
8} (ActiveDataInfo Class) -
https://www-secure.symantec.com/techsupp/activedata/SymAData.dllO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {E77C0D62-882A-456F-AD8F-7
C6C9569B8C
7} (ActiveDataObj Class) -
https://www-secure.symantec.com/techsupp/activedata/ActiveData.cabO17 - HKLM\System\CCS\Services\T
cpip\..\{8
4FC8B7C-DE
78-42E5-9F
E8-F89279D
BA20E}: NameServer = 216.87.64.2,166.90.152.35