HijackThis log file - problem accessing internet pages

  1. #1
    nono81 is offline Newbie

    Post HijackThis log file - problem accessing internet pages

    Hi
    I can really appreciate any help re a browser issue still active after several virus and spam cleanup performed on a computer.
    As a result of the issue, no internet pages are reachable.

    Logfile of HijackThis v1.99.1
    Scan saved at 18.15.01, on 16/03/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\drivers\CDAC11BA.EXE
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    C:\WINDOWS\System32\nvsvc32.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\ICO.EXE
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\WHEELM~1\wh_exec.exe
    C:\Programmi\Creative\Mouse Optical\mouse_2k.exe
    C:\Programmi\iTunes\iTunesHelper.exe
    C:\Programmi\QuickTime\qttask.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Programmi\BullsEye Network\bin\bargains.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\programmi\180solutions\sais.exe
    C:\WINDOWS\system32\nvscv32.exe
    C:\WINDOWS\system32\winIogon.exe
    C:\Programmi\Messenger\msmsgs.exe
    C:\Programmi\iPod\bin\iPodService.exe
    C:\Programmi\Alice ti aiuta\bin\mpbtn.exe
    c:\progra~1\mcafee.com\vso\mcvsftsn.exe
    C:\Programmi\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\windrives.exe
    C:\WINDOWS\system32\windrives.exe
    C:\WINDOWS\system32\windrives.exe
    C:\WINDOWS\System32\windrives.exe
    C:\DOCUME~1\chantal\IMPOST~1\Temp\Directory temporanea 4 per hijackthis.zip\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.club-vaio.sony-europe.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.sony-europe.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    O4 - HKLM\..\Run: [Apoint] C:\Programmi\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [WheelMouse] C:\WHEELM~1\wh_exec.exe
    O4 - HKLM\..\Run: [CreativeMouse ] C:\Programmi\Creative\Mouse Optical\mouse_2k.exe
    O4 - HKLM\..\Run: [iTunesHelper] C:\Programmi\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Programmi\Aethra\ADSL EB1070 USB\CnxTrApp.dll",AppEntry -REG "Aethra\ADSL EB1070 USB"
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [BullsEye Network] C:\Programmi\BullsEye Network\bin\bargains.exe
    O4 - HKLM\..\Run: [sais] c:\programmi\180solutions\sais.exe
    O4 - HKLM\..\Run: [FireWire Service] nvscv32.exe
    O4 - HKLM\..\Run: [gN9g] C:\WINDOWS\okascfqn.exe
    O4 - HKLM\..\Run: [Windows Servlce] winIogon.exe
    O4 - HKLM\..\Run: [Windows Services] Spool32x.exe
    O4 - HKLM\..\Run: [WebRebates0] "C:\Programmi\Web_Rebates\WebRebates0.exe"
    O4 - HKLM\..\Run: [Systems Backups] windrives.exe
    O4 - HKLM\..\Run: [zsh] C:\WINDOWS\zsh.exe
    O4 - HKLM\..\RunServices: [Windows Servlce] winIogon.exe
    O4 - HKLM\..\RunServices: [Systems Backups] windrives.exe
    O4 - HKLM\..\RunServices: [System32] nah.exe
    O4 - HKLM\..\RunServices: [FireWire Service] nvscv32.exe
    O4 - HKLM\..\RunServices: [Windows Services] Spool32x.exe
    O4 - HKLM\..\RunOnce: [Windows Servlce] winIogon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Machine Debug Manager] mdm.exe
    O4 - HKCU\..\Run: [Windows Servlce] winIogon.exe
    O4 - HKCU\..\Run: [Windows Services] Spool32x.exe
    O4 - HKCU\..\RunOnce: [Windows Servlce] winIogon.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = ?
    O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: Web Rebates - file://C:\Programmi\Web_Rebates\Sy1150\Tp1150\scri1150a.h tm
    O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Programmi\SideFind\sidefind.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.sony-europe.com/
    O15 - Trusted Zone: *.sony-europe.com
    O15 - Trusted Zone: *.sonystyle-europe.com
    O15 - Trusted Zone: *.vaio-link.com
    O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Programmi\AutoCAD 2002\AcDcToday.ocx
    O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Programmi\AutoCAD 2002\InstBanr.ocx
    O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Programmi\AutoCAD 2002\InstFred.ocx
    O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Programmi\AutoCAD 2002\AcPreview.ocx
    O17 - HKLM\System\CCS\Services\Tcpip\..\{73ED9D66-3372-4302-8ACE-E515C0F5C013}: NameServer = 151.99.125.1,151.99.125.2
    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
    O23 - Service: Servizio iPod (iPodService) - Apple Computer, Inc. - C:\Programmi\iPod\bin\iPodService.exe
    O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Systems Backups (Restoreds) - Unknown owner - C:\WINDOWS\System32\windrives.exe" -service (file missing)
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FILECO~1\SONYSH~1\AVLib\Sptisrv.exe

    Attached the log file
    Thanks
    Attached Files
    Last edited by owen; 17-03-2005 at 10:43 PM.


  2. #2
    owen is offline D-A-L Team Member (UK)
    Close all browser windows, restart Hijack This and put a checkmark next to the following entries:

    O4 - HKLM\..\Run: [BullsEye Network] C:\Programmi\BullsEye Network\bin\bargains.exe
    O4 - HKLM\..\Run: [sais] c:\programmi\180solutions\sais.exe
    O4 - HKLM\..\Run: [FireWire Service] nvscv32.exe
    O4 - HKLM\..\Run: [gN9g] C:\WINDOWS\okascfqn.exe
    O4 - HKLM\..\Run: [Windows Servlce] winIogon.exe
    O4 - HKLM\..\Run: [Windows Services] Spool32x.exe
    O4 - HKLM\..\Run: [WebRebates0] "C:\Programmi\Web_Rebates\WebRebates0.exe"
    O4 - HKLM\..\Run: [Systems Backups] windrives.exe
    O4 - HKLM\..\Run: [zsh] C:\WINDOWS\zsh.exe
    O4 - HKLM\..\RunServices: [Windows Servlce] winIogon.exe
    O4 - HKLM\..\RunServices: [Systems Backups] windrives.exe
    O4 - HKLM\..\RunServices: [System32] nah.exe
    O4 - HKLM\..\RunServices: [FireWire Service] nvscv32.exe
    O4 - HKLM\..\RunServices: [Windows Services] Spool32x.exe
    O4 - HKLM\..\RunOnce: [Windows Servlce] winIogon.exe
    O4 - HKCU\..\Run: [Machine Debug Manager] mdm.exe
    O4 - HKCU\..\Run: [Windows Servlce] winIogon.exe
    O4 - HKCU\..\Run: [Windows Services] Spool32x.exe
    O4 - HKCU\..\RunOnce: [Windows Servlce] winIogon.exe
    O8 - Extra context menu item: Web Rebates - file://C:\Programmi\Web_Rebates\Sy1150\Tp1150\scri1150a.h tm
    O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Programmi\SideFind\sidefind.dll
    O15 - Trusted Zone: *.sony-europe.com
    O15 - Trusted Zone: *.sonystyle-europe.com
    O15 - Trusted Zone: *.vaio-link.com
    O23 - Service: Systems Backups (Restoreds) - Unknown owner - C:\WINDOWS\System32\windrives.exe" -service (file missing)

    Click Fix Checked

    Then boot into Safe Mode and ensure that you are showing Hidden Files and Folders.

    Delete the following files and folders:
    C:\Programmi\BullsEye Network
    c:\programmi\180solutions
    C:\WINDOWS\system32\nvscv32.exe
    C:\WINDOWS\system32\winIogon.exe
    C:\WINDOWS\System32\windrives.exe
    :\Programmi\Web_Rebates
    C:\Programmi\SideFind
    C:\WINDOWS\zsh.exe
    C:\WINDOWS\okascfqn.exe

    Reboot and post a fresh log

  3. #3
    nono81 is offline Newbie
    owen
    thanks everything's fine now.

  4. #4
    owen is offline D-A-L Team Member (UK)
    Save 20% on AVG Internet Security 2012 Suite!
    I suggest posting a fresh log for a final checkup.

+ Reply to Thread