![]() |
| ||
| Please can someone help me :sad: Please can some one help me, my computer is only 6mths old and its started running slow and even though I have pop up stoppers on I still get loads. This makes my computer screen freeze up I have added my hijack this scan. Klaura Logfile of HijackThis v1.99.0 Scan saved at 14:58:40, on 29/05/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe c:\APPS\HIDSERVICE\HIDSERVICE.exe c:\progra~1\mcafee\mcafee antispyware\massrv.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe c:\APPS\Powercinema\Kernel\TV\CLSched.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe C:\Apps\Powercinema\PCMService.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\Internet Explorer\iexplore.exe C:\progra~1\mcafee\MCAFEE~1\masalert.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\vsnpstd2.exe C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe C:\Program Files\VoyagerTest\fts.exe C:\Program Files\Common Files\AOL\ACS\AOLDial.exe C:\Program Files\Common Files\AOL\1146088720\ee\AOLSoftware.exe C:\PROGRA~1\MSNMES~1\msnmsgr.exe C:\Program Files\AOL\Broadband CheckUp\bin\mpbtn.exe c:\program files\common files\aol\1146088720\ee\services\antiSpywareApp\ver2_0_27_1\AOLSP Scheduler.exe c:\program files\common files\aol\1146088720\ee\aolsoftware.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\AOL 9.0a\waol.exe C:\Program Files\AOL 9.0a\shellmon.exe C:\Program Files\Common Files\AOL\aoltpspd.exe C:\WINDOWS\system32\msiexec.exe D:\DOCUME~1\Kaye\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://as.starware.com/dp/search?x=w...ry4QJ5kwl9g/w= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R3 - URLSearchHook: (no name) - - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {16F01245-8B34-2A47-DAB1-915ACB189B3C} - D:\DOCUME~1\Kaye\APPLIC~1\SURFBE~1\WAITNOUN.exe (file missing) O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [SemanticInsight] C:\Program Files\RXToolBar\Semantic Insight\SemanticInsight.exe O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [this heart bags skip] D:\Documents and Settings\All Users\Application Data\rect extra this heart\wait support.exe O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe" O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1146088720\ee\AOLSoftware.exe O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe" O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe" O4 - HKLM\..\RunOnce: [eISS_licreg] "C:\Program Files\CA\eTrust Internet Security Suite\licreg.exe" /s O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ActiveBase] D:\DOCUME~1\Kaye\APPLIC~1\DUPEFL~1\Cake Third.exe O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [Skype] "c:\apps\skype\phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0a\aoltray.exe O4 - Global Startup: AOL Broadband Check-Up.lnk = C:\Program Files\AOL\Broadband CheckUp\bin\matcli.exe O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm O16 - DPF: {0835BC90-6ABC-4F52-A103-4FC3A61F2C33} (A18X Control) - http://www.albatross18.com/cabs/A18X.ocx O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab O16 - DPF: {20D70B3E-1D58-4729-9608-FA8D742711C7} (BTAPI.XMLReader) - http://ecdl.canterbury.ac.uk/activlite/BTEngine.cab O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/comput...up/qdiagcc.cab O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/sof...iveXPlugin.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/amp...1.11_en_dl.cab O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game01.zylom.com/activex/zylomgamesplayer.cab O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite...ITDetector.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...99/mcfscan.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{5B05B66B-D653-469F-A3A8-467C148C0BC2}: NameServer = 205.188.146.145 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O18 - Filter: text/html - (no CLSID) - (no file) O23 - Service: AOL Connectivity Service - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: Bonjour Service - Unknown - C:\Program Files\Bonjour\mDNSResponder.exe (file missing) O23 - Service: CyberLink Background Capture Service (CBCS) - Unknown - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) - Unknown - c:\APPS\Powercinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: Generic Service for HID Keyboard Input Collections - Unknown - c:\APPS\HIDSERVICE\HIDSERVICE.exe O23 - Service: InstallDriver Table Manager - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe O23 - Service: McAfee WSC Integration - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee Task Scheduler - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: SmartLinkService - - slserv.exe O23 - Service: Ulead Burning Helper - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe |
| ||
| Re: Please can someone help me have u tried running the DISK CLEANUP, and DISK DEFRAGMENTER tools?, u can find them on: C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools try runing them in the order i gave u, this tools will delete all ur cookies, temp internet files, etc, just check the box of the type of file that u want to be deleted (i check them all), the second one will arrange ur cd space and make ur comp faster. |
| ||
| Re: Please can someone help me oh, and if u have mcafee, in my opinion i dont like it, try trend micro pc-cillin internet security |
| ||
| Re: Please can someone help me Thanks but its still happening is there anything in my hijack this scan |
| ||
| Re: Please can someone help me well i tried to check it out but i still dont see anything, but i do see that u are using aol, that could be the cause too, i had it for about 3 months and my computer was as slow as a turtle, and it didnt matter how many tools i used it was still slow, when i unisntalled aol my comp got faster, and i think u can get a great deal out of SBC Yahoo DSL for around $15 a month. Sorry but thats all i can think of AOL and McKafee |
| ||
| Re: Please can someone help me Quote:
|
| ||
| Re: Please can someone help me Hi klaura, All kidding aside (and I was just kidding, cubanforever), there definitely are infections indicated in your log; please do the following: 1. D:\DOCUME~1\Kaye\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe The log entry above indicates that you have not yet unzipped the hijackthis.exe program file from within the downloaded hijackthis.zip archive file. You are also running HijackThis from within a Temp/Temporary folder, which you should not do. To remedy this, follow these steps before running HijackThis again: * Create a separate, new folder for HJT outside of any Temp/Temporary folders. A folder such such as C:\HijackThis or C:\Spyware Tools\HijackThis will do. * Right-click on the HijackThis.zip folder that you downloadd and choose "Extract All.." from the resulting context menu. This will open the file extraction wizard. * When the wizard presents you with the option of choosing the location into which the extracted hijackthis.exe file will be placed, browse to and select the new folder you created. * When the extraction is complete, an Explorer window will appear showing the newly-extracted HijackThis.exe file; double-click on that file to run the program. 2. C:\Program Files\Internet Explorer\iexplore.exe The log entry above indicates that you had at least 1 instance of Internet Explorer running when you ran HijackThis. Before fixing problems with HijackThis, you must make sure to close/quit ALL instances of your web browser! HijackThis cannot fully perform its fixes while browsers are running. ------------------------------------------------------------------------------------------------------------------- Once you have remedied the two issues above: You will need to close/quit all web browser programs and disconnect from the Internet for much of the following, so you should print out these instructions or save them into a text file with Notepad. * Open your Add/Remove Programs control panel and uninstall the following software if you find it listed there: RXToolBar/SemanticInsight Need2Find * Download and install the following utilities: Windows Defender - http://www.microsoft.com/downloads/d...displaylang=en CCleaner - www.ccleaner.com ewido Anti-malware - http://www.ewido.net/en/download/ * When installing ewido, under "Additional Options" uncheck..
ewido manual updates Don't run a scan with ewido yet; just close the program once the updates are installed. * Open your antivirus program and check for/install the most current updates. Again- don't run a scan with it; just close the program once the updates are installed. * Close all open programs, especially Internet Explorer. * Run HijackThis again, put a check mark in the box to the left of the following entries, and then click the "Fix checked" button. Close HJT after the fixes complete: R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://as.starware.com/dp/search?x=w...ry4QJ5kwl9g/w= R3 - URLSearchHook: (no name) - - (no file) O2 - BHO: (no name) - {16F01245-8B34-2A47-DAB1-915ACB189B3C} - D:\DOCUME~1\Kaye\APPLIC~1\SURFBE~1\WAITNOUN.exe (file missing) O4 - HKLM\..\Run: [SemanticInsight] C:\Program Files\RXToolBar\Semantic Insight\SemanticInsight.exe O4 - HKLM\..\Run: [this heart bags skip] D:\Documents and Settings\All Users\Application Data\rect extra this heart\wait support.exe O4 - HKCU\..\Run: [ActiveBase] D:\DOCUME~1\Kaye\APPLIC~1\DUPEFL~1\Cake Third.exe O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL O18 - Filter: text/html - (no CLSID) - (no file) * Reboot into safe mode (you get to the safe mode boot option by hitting the F8 key as your computer is starting up) and: * Open Windows Explorer, and in the Folder Options->View settings under the Tools menu, select "show hidden files and folders", and uncheck "Hide protected operating system files" and "Hide extentions for known file types". * Run CCleaner. - Go to Options-> Advanced: Uncheck "Only delete files in Windows Temp folders older than 48 hours" - Go to Options>CustomFolders>Add Folder>Navigate to these folders (click on bold file once and hit OK) : * C:\Windows\Temp * C:\Windows\Prefetch * C:\Documents and Settings\<Your Profile>\Local Settings\Temporary Internet Files\ (This will delete all your cached internet content including cookies.) * C:\Documents and Settings\<Your Profile>\Local Settings\Temp * C:\Documents and Settings\<any other user's Profile>\Local Settings\Temporary Internet Files * C:\Documents and Settings\<Any other user's Profile>\Local Settings\Temp * C:\Documents and Settings\<Your Profile>\Cookies * C:\Documents and Settings\<Any other users Profile>\Cookies Hit OK - In left pane, scroll down to "Advanced, Custom Folders", put a check in Custom Folders - Click on Run Cleaner. It may take a while for the program to perform its cleaning, so be patient. Close the program when it has finished. * Run full system scans with your antivirus program, Windows Defender, and ewido; have the programs fix all malicious items they find. When ewido finds the first malicious object on your system, it will ask you if it should clean it. When it asks this, put a checkmark in the lower left corner of the box that says "Perform action on all infections", then choose clean and click OK. Save the log file that ewido will create after it finishes scanning; you'll be including that log in your next post here. * Open Windows Explorer again. Locate and delete the following folders entirely. Note that two of the folder names have been shortened by HijackThis, so I can't tell you the exact names. However, the true names will begin with the letters given in the names below, but will consists of additional characters after that instead of the "~1" characters : \Documents and Settings\Kaye\Application Data\SURFBE~1 \Documents and Settings\All Users\Application Data\rect extra this heart \Documents and Settings\Kaye\Application Data\DUPEFL~1 \Program Files\RXToolBar * Empty your Recycle Bin, reboot normally, run HijackThis again, and post the new log. Also post the log that ewido generated. - |
| All times are GMT -4. The time now is 1:33 pm. |
Forum system based on vBulletin Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
©2003 - 2009 DaniWeb® LLC