NightBadger 0 Newbie Poster

Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
PC: Fujitsu Siemens Scenic

I can log onto Internet no probs, browse away for approx one minute, then get "The page cannot be displayed" error, all/any webpage. I'm pretty sure malware is involved. No new installs or anything. This post is from a different PC, different location.

I have tried IE Repair, reinstalling IE, virus scans, other threads, etc. I could really do with help interpeting my HijackThis log.

I have had problems of late with Backdoor spyware:
"Backdoor.Win32.Rbot.gen",
"Backdoor.Win32.sdbot.ZG", &
"Backdoor.Win32.sdbot.gen!A".

I have run HijackThis (v1.99.1), read and followed all preliminaries. Here is my log. Please help if you can. Thank you...

ps I have also posted to techsupportforum, I will update here/there with progress

Dani AI

Generated

— Focus on containment first and then on offline removal. Isolate the machine from networks to stop any remote callbacks. From a clean computer, build bootable rescue media from a reputable antivirus vendor and run a full, signature-updated offline scan; offline tools have the best chance of detecting kernel/MBR-resident components that in-OS scanners miss.

After offline scanning, perform targeted in-OS checks while in a limited boot state. Use Sysinternals Autoruns to inspect and disable unknown startup items and drivers, and use Process Explorer to examine running processes and their network endpoints; search any unfamiliar filenames from a clean machine before deleting. Verify the hosts file at %SystemRoot%\system32\drivers\etc\hosts, confirm there are no unexpected proxy/LAN settings in the browser, review scheduled tasks and nonstandard services, and consider reinstalling NIC drivers or using vendor network-repair tools if the stack appears corrupted.

If a stealth component cannot be confidently removed, back up personal data (scan that backup on a clean machine) and perform a clean OS reinstall. After recovery, change all account passwords from a known-good device and retain copies of logs for later review. For anyone analyzing logs, the raw text of the attached log plus notes about whether Safe Mode scans changed behavior makes targeted guidance possible.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.