FatalFake 0 Newbie Poster

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:41:55 AM, on 10/18/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16757)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\rundll32.exe
C:\Windows.old\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\System32\taskmgr.exe
C:\Windows\system32\mmc.exe
C:\Windows.old\Users\Anon\Downloads\WLinstaller.exe
C:\Program Files\Windows Live\installer\Dashboard.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [msnmsgr] "C:\Windows.old\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DEEF4F7A-7A2E-495D-852D-0F040EBA0BD2}: NameServer = ,,,,,,,,,,
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\MabinogiNA\npkcmsvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 2812 bytes


http://www.daniweb.com/forums/thread151861.html

I stated in that thread that the problem was a seemingly random freezing of the computer every few minutes.

Dani AI

Generated

The log points to two separate, plausible causes for the frequent, short freezes: (1) a software/driver conflict or leftover executables from an earlier installation/upgrade, and (2) network-level DNS changes or malware that can affect browsing and system behavior. Treat the problem as both a local stability issue and a possible compromise — back up important data first, then proceed with the triage below.

Recommended triage (in order): boot to Safe Mode and note whether freezes continue; run a Clean Boot (disable non‑Microsoft services/startups) to isolate third‑party software; check Event Viewer (System and Application) for errors around the freeze times; verify disk health and file integrity with chkdsk and SFC; test memory with a bootable memory test. If network/DNS behavior looks abnormal, disconnect the machine from the network while investigating so a possible redirector can’t interfere.

Useful commands and quick actions (run from an elevated command prompt, then reboot after the resets):

ipconfig /all > C:\ipconfig_before.txt
netsh int ip reset resetlog.txt
netsh winsock reset
ipconfig /flushdns
sfc /scannow
chkdsk C: /f /r

Also capture any recurring Event Viewer error IDs and save them for analysis.

Follow‑ups and cautions: use Sysinternals Autoruns to inspect and safely disable suspicious startup entries rather than deleting registry keys directly. Confirm the publisher/signature on any odd services or executables (drivers from audio/codecs are common culprits). Run a current anti‑malware scan (signature‑based + on‑demand scanner) and a reputable rootkit check if DNS or network entries remain suspicious. Avoid running aggressive removal tools (ComboFix etc.) without guidance; clean reinstall is a last resort if stability cannot be restored. Notes for : leftover executables or an autorun entry from a previous install can freeze a system repeatedly — isolating by Safe Mode / Clean Boot will quickly tell whether the cause is software or hardware/network related.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.