hijack this log, help please

Status
Not open for further replies.

techno-dodo

Beta member
Messages
1
Hello,
I have been having nothing but trouble with a refurbished hard drive I now own. I'm not sure what is wrong, and have run many different kinds of anti-virus and anti-spyware programs on it. Right now there is AVG antivirus, adaware, Zone Alarm and Hijack This on it. Previously I had Spybot S and D, All-In-One Secretmaker, and Norton Antivirus 2004 (Had to remove it today because it said everything was tampered with) plus others, if I remember correctly-too many to remember!. This thing has been reformatted and had a complete uninstall and reinstall of Windows XP.
Something I noticed when I used to run Spybot when I first got the hard drive was that there were TONS of pornographic sites listed as well as diallers, trojans, etc., etc.
Sometimes it won't let me into some sites, for example Yahoo! Mail, it tells me it won't accept cookies, and sometimes it has a "system shutdown" where my computer shuts itself down and restarts on its own. In addition one particular page keeps coming up, but it is not a page I have ever been to myself or bookmarked, and it still comes up even though I have put it on my list of restricted sites. I also was having problems with the computer dropping the connection to the server, although that seems to be ok this past day or two.
I've included a log from Hijack This that I did today, if anyone would be so kind as to have a look at it for me.
Many thanks,
Techno-dodo
**********************


Logfile of HijackThis v1.99.1
Scan saved at 12:58:05 PM, on 4/6/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\airftp.exe
C:\WINDOWS\System32\msnsvc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Grisoft\AVG Free\avgcc.exe
C:\Program Files\Grisoft\AVG Free\avgemc.exe
C:\Documents and Settings\user\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\Documents and Settings\user\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...l]http://www.yahoo.com/ext/search/search.html[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...l]http://www.yahoo.com/ext/search/search.html[/url]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/*[url]http://www.yahoo.com[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*[url]http://www.yahoo.com[/url]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Sympatico
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ethernet] airftp.exe
O4 - HKLM\..\Run: [msn] msnsvc.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\RunServices: [ethernet] airftp.exe
O4 - HKLM\..\RunServices: [Disk Manager] diskver.exe
O4 - HKLM\..\RunServices: [Windows Compliant] vuhpfb.exe
O4 - HKLM\..\RunServices: [Microsoft Development Debugger] C:\WINDOWS\system32\msdev.exe
O4 - HKLM\..\RunServices: [Windows update 2005] ulyprvzmx.exe
O4 - HKLM\..\RunServices: [msn] msnsvc.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1112307796037
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AB7C9A4A-6B42-4256-8B66-4A73E4C19CBF}: NameServer = 206.47.244.50 206.47.244.79
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 
Remove entries at your own risk


R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) Should be fixed.

O15 - Trusted Zone: http://ny.contentmatch.net (HKLM) If you did not add these pages to your trusted pages, they should be fixed.
 
Status
Not open for further replies.
Back
Top Bottom