HELP ME WITH THE LOGFILE PLS... :?:

Logfile of HijackThis v1.99.0
Scan saved at 10:45:12 PM, on 2/19/2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\snmp.exe
C:\Program Files\UWIN\usr\etc\ums.exe
C:\Program Files\UWIN\usr\etc\init.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mqsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\UWIN\usr\etc\inetd.exe
C:\Program Files\UWIN\usr\lib\cs\tcp\at\at.svc
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\System32\taskmgr.exe
D:\COMMON\Install\HijackThis_ver1.99.1.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.smh.com.au/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: YBIOCtrl Class - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: YBIOCtrl Class - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .pdf: C:\PROGRA~1\Plus!\MICROS~1\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - WWW. Prefix: http://
O16 - DPF: Yahoo! Chess -
O17 - HKLM\System\CCS\Services\Tcpip\..\{BFE566ED-E110-4732-972C-10D09195F8AD}: NameServer =
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Kerio Personal Firewall - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe
O23 - Service: Uwin Master - Unknown - C:\Program Files\UWIN\usr\etc\ums.exe

Dani AI

Generated

Short expert summary and safe workflow. As noted, getting Windows 2000 up to Service Pack 4 is an important hardening step; however, cleanup should follow a safe sequence: make a complete system-state backup / Emergency Repair Disk and export the registry, place HijackThis.exe in a permanent folder so its own backups are kept, then proceed with targeted removals and scans. Windows 2000’s recovery model relies on ERD/system-state backups rather than the System Restore feature found in later Windows releases, so preserve those backups before editing the registry or fixing entries. (helpwithwindows.com)

Browser Helper Objects and toolbars: identify orphaned BHOs before removal. Look up each BHO’s CLSID in the registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects and then check the corresponding HKCR\CLSID{…}\InprocServer32 value to find the DLL path. If the in‑process DLL file is missing (or clearly part of uninstalled software), the registry entry is an orphan and is generally safe to remove with HijackThis — but if the DLL exists, research the filename/digital signer first. Use HijackThis’s built-in backup/restore (View Backups) so any mistaken fixes can be undone. ()

Network/DNS checks: the log contains a custom NameServer entry. Verify actual client DNS with ipconfig /all, compare those addresses to the ISP/router defaults, and inspect the local Hosts file for redirects. If DNS has been hijacked, reset the adapter to obtain DNS automatically (or set trusted DNS addresses), then flush the resolver cache (ipconfig /flushdns) and re-check connectivity. These steps will reveal whether the change is local, router-level, or caused by malware. (learn.microsoft.com)

Cleanup and follow-up: run full AV and an up‑to‑date anti‑spyware/rootkit scan in Safe Mode (or from offline rescue media) until no “delete on reboot” items remain. After a verified clean state, apply Service Pack 4 and related updates, then re-scan and save a fresh HijackThis log for comparison. This sequence preserves rollback options and reduces the chance of breaking a working system while removing unwanted entries. (helpwithwindows.com)

You urgently require service pack 4 for Windows 2000!!
http://windowsupdate.microsoft.com/

Scan with hijackthis and tick the boxes next to all the following entries, then close all browser and explorer windows, and hit the "Fix checked" button.

O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: YBIOCtrl Class - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: YBIOCtrl Class - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.