HIJACK THIS LOG, C:\pagefile.sys?, PLEASE HELP

Discussion in 'adware, spyware & hijack cleaning' started by ReedTire, Jul 5, 2004.

Thread Status:
Not open for further replies.
  1. ReedTire

    ReedTire Registered Member

    Joined:
    Jul 5, 2004
    Posts:
    4
    I have ran both Spybot and Adaware. I followed that up by running NOD32 Anitvirus. I have also ran The Cleaner to find trojans. I find nothing, except in NOD32 I get this message: "C:\pagefile.sys - error opening (file locked) [4]". I'm not sure if that helps, but it's all I can find.

    The problems I'm having is that when I open up Internet Explorer, "about:blank" loads w/ a piss-poor search engine. Our homepage ALWAYS changes, and half the time we can't even open up normal web pages w/o getting a search engine and about 5-7 pop-ups.

    Our internet use is very important to us, as we must place orders every 15 minutes, every day. Please help us, it is hurting our business. We believe an ex-employee did something to this PC, yet we're not sure how.

    Logfile of HijackThis v1.97.7
    Scan saved at 2:51:29 PM, on 7/5/2004
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\ZoneLabs\vsmon.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Eset\nod32kui.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
    C:\WINNT\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\User\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\User\LOCALS~1\Temp\sp.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {953D407A-42E1-4B73-910E-6AE6428A54F4} - C:\WINNT\system32\gkhfa.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
    O10 - Broken Internet access because of LSP provider 'imon.dll' missing
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38091.6800694444
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{B5A71080-B03A-4610-B5E9-08C5958BE276}: NameServer = 151.164.169.201,151.164.1.8
     
  2. ReedTire

    ReedTire Registered Member

    Joined:
    Jul 5, 2004
    Posts:
    4
    PLEASE HELP!
     
  3. ReedTire

    ReedTire Registered Member

    Joined:
    Jul 5, 2004
    Posts:
    4
    I'll give it one more chance before we have to call in the specialists.

    Please, PLEASE save us the money... we sure do need it!
     
  4. ReedTire

    ReedTire Registered Member

    Joined:
    Jul 5, 2004
    Posts:
    4
    I guess I did something wrong, since it's been almost 4 weeks... CheekyMonkey, CdS, ReedTire. It only cost us $200 for a whole half hour's work of some pimply-faced 16 y/o to restart our pc in safe mode and fix it.

    Again, thanks.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.