Computer ForumsComputers  

Go Back   Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection > HijackThis Logs (finished)

 
 
LinkBack Thread Tools Display Modes
Old 12-29-2004, 07:38 PM   #1 (permalink)
Newb Techie
 
Join Date: Dec 2004
Posts: 1
Default Need help, tried all. No Acces to ebay, Hotmail and Microsoft

Im having a problem accessing ebay.com; ebay.ch (Switzerland) but i can the homepage of ebay.com.au (Australia)

I have no chance to access hotmail.com and microsoft.com
All other sides work fine.

I was having the problem, but ment having solved it by adjusting MTU value from 1500 to 576.

After 2 days the problem was back !!!!('')
mad

Serched again and used Spyware Doctor. The problem was solved, but was back again within 4hours.

I do not know any more!!!! Help!!

Thanks for your help!!

Here is my log file: I tired to eliminate all firewall und other things!



Logfile of HijackThis v1.99.0
Scan saved at 02:14:30, on 30.12.2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
D:\Program Files\AVPersonal\AVGUARD.EXE
D:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINNT\System32\svchost.exe
d:\program files\devnz\gbpvr\gbpvrrecordingservice.exe
D:\Program Files\Ahead\InCD\InCDsrv.exe
c:\WINDOWS\system32\MSSvc.EXE
c:\WINDOWS\system32\runbatch.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\wupdated.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
D:\Program Files\AVPersonal\AVGNT.EXE
D:\Program Files\Spyware Doctor\spydoctor.exe
D:\program files\WinTV\Ir.exe
D:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
D:\program files\Nikon\NkView4\NkVwMon.exe
D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINNT\system32\HPZipm12.exe
D:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Documents and Settings\sri1.SRI\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bluewin.ch/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.co.jp/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.jp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bluewin.ch/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.co.jp/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.co.jp/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.bluewin.ch/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = http://proxy-mssbzhh.bluewin.ch/:80
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVGCtrl] D:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\RunServices: [Microsoft Services] lsrv.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINNT\system32\mstask.exe
O4 - HKLM\..\RunServices: [NvCPL32] nvcplc32.exe
O4 - HKLM\..\RunServices: [Synchronization huome lokd] h1m5w4s.exe
O4 - HKCU\..\Run: [Spyware Doctor] "D:\Program Files\Spyware Doctor\spydoctor.exe" /Q
O4 - Global Startup: AutoStart IR.lnk = D:\program files\WinTV\Ir.exe
O4 - Global Startup: hp psc 2000 Series.lnk = D:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: NkVwMon.exe.lnk = D:\program files\Nikon\NkView4\NkVwMon.exe
O4 - Global Startup: officejet 6100.lnk = D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Mobilen Favoriten erstellen - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{0398498F-25D5-4AF8-AC5C-36407A780FDA}: NameServer = 195.186.1.108 195.186.4.109
O17 - HKLM\System\CS1\Services\Tcpip\..\{0398498F-25D5-4AF8-AC5C-36407A780FDA}: NameServer = 195.186.1.108 195.186.4.109
O23 - Service: AntiVir Service - H+BEDV Datentechnik GmbH - D:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update - H+BEDV Datentechnik GmbH, Germany - D:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare NT Utilities 2.6 - Unknown - C:\WINNT\SYSTEM32\DNTUS26.EXE (file missing)
O23 - Service: GB-PVR Recording Service - - d:\program files\devnz\gbpvr\gbpvrrecordingservice.exe
O23 - Service: InCD Helper - Ahead Software AG - D:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: ISEXEng - Unknown - C:\WINNT\system32\angelex.exe (file missing)
O23 - Service: Microsoft NetWork FireWall Services - Unknown - NetServices.exe (file missing)
O23 - Service: MSSvc msnet - Unknown - c:\WINDOWS\system32\MSSvc.EXE
O23 - Service: Intel NCS NetService - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: MSSvc runbatch - Unknown - c:\WINDOWS\system32\MSSvc.EXE
O23 - Service: Sagate Security Firewall - Unknown - C:\WINNT\system32\sagate.exe (file missing)
O23 - Service: SBHookSvc - Unknown - D:\PROGRA~2\Bluewin\QUICKH~1\SMARTB~1\SBHookSvc.ex e (file missing)
O23 - Service: SoundMAX Agent Service - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Windows Management NetWork Service Extensions - Unknown - NetManager.exe (file missing)
O23 - Service: Windows Update - Unknown - C:\WINNT\system32\vcvhost.exe (file missing)
O23 - Service: ZESOFT - Unknown - C:\WINNT\zeta.exe (file missing)


storchenegger is offline  
Old 02-23-2005, 05:47 AM   #2 (permalink)
Newb Techie
 
Join Date: Feb 2005
Posts: 1
Default me too

its crazy. ive got a similar problem.. i have reloaded xp 3 times now.. even today i did a full reload with FULL format.. still cannot access hotmail, myebay, yahoo mail or any sites that seem to need to transfer files etc. what the **** is causing this problem? ive noticed a few other people have the same or simlilar issues.. there is NO spyware on my system.. even with a clean load of XP, (no sp2 no other programs ) i still couldnt access these sites.. ive tried a proxy server..nothing.. its not a ISP problem as i can use my laptop thru my same network with no problems.. does anyone have any ideas here?
castigan is offline  
Old 02-23-2005, 11:08 AM   #3 (permalink)
Wizard Techie
 
Join Date: Jul 2003
Posts: 3,940
Default

Moved to proper forum and left redirect in previous forum

ekÆsine
Tech Forums Super Moderator
ekÆsine is offline  
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 11:46 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0