Re: hijackthis log help

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Jupiter Jones [MVP] (jones_jupiter_at_hotnomail.com)
Date: 10/20/04


Date: Wed, 20 Oct 2004 17:13:24 -0600

See the lower part of the yellow section on this link for a more
appropriate place to post this:
http://www3.telus.net/dandemar/slowcom.htm

-- 
Jupiter Jones  [MVP]
http://www3.telus.net/dandemar/
"Kellipurr" <Kellipurr@discussions.microsoft.com> wrote in message 
news:FB7406A2-EA40-4DF8-BD6D-E7750F803603@microsoft.com...
> My pc has been freezing a lot but only seems to when plugged in 
> between 83%
> and up and over on ac power (laptop).. Just wondering if someone can 
> just
> check to see if anything strange is in my hijack this log...Logfile 
> of
> HijackThis v1.98.0
> Scan saved at 9:26:06 PM, on 10/16/2004
> Platform: Windows XP SP1 (WinNT 5.01.2600)
> MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
>
> Running processes:
> C:\WINDOWS\System32\smss.exe
> C:\WINDOWS\system32\winlogon.exe
> C:\WINDOWS\system32\services.exe
> C:\WINDOWS\system32\lsass.exe
> C:\WINDOWS\system32\svchost.exe
> C:\WINDOWS\System32\svchost.exe
> C:\WINDOWS\system32\spoolsv.exe
> C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
> C:\Program Files\Norton AntiVirus\navapsvc.exe
> C:\WINDOWS\system32\slserv.exe
> C:\WINDOWS\System32\wuauclt.exe
> C:\WINDOWS\Explorer.EXE
> C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
> C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
> C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
> C:\Program Files\Common Files\Symantec Shared\ccApp.exe
> C:\Program Files\Messenger\msmsgs.exe
> C:\Program Files\AIM\aim.exe
> C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
> C:\WINDOWS\slrundll.exe
> C:\WINDOWS\System32\wuauclt.exe
> C:\Program Files\Internet Explorer\IEXPLORE.EXE
> C:\Documents and Settings\fhkhfhsfds\Local Settings\Temporary 
> Internet
> Files\Content.IE5\DGKKBZ7W\HijackThis[1].exe
>
> R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
> http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
> R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
> http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
> R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
> http://www.yahoo.com/
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL 
> =
> http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
> R1 - HKLM\Software\Microsoft\Internet 
> Explorer\Main,Default_Search_URL =
> http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
> http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
> http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http://www.yahoo.com
> R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
> http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
> R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
> http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
> R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
> http://windowsupdate.microsoft.com/
> F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
> O2 - BHO: Yahoo! Companion BHO - 
> {02478D38-C3F9-4efb-9B51-7695ECA05670} -
> C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_5_0.dll
> O2 - BHO: AcroIEHlprObj Class - 
> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
> C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
> O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
> C:\PROGRA~1\SPYBOT~1\SDHelper.dll
> O2 - BHO: CNavExtBho Class - 
> {BDF3E430-B101-42AD-A544-FADC6B084872} -
> C:\Program Files\Norton AntiVirus\NavShExt.dll
> O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
> C:\WINDOWS\System32\msdxm.ocx
> O3 - Toolbar: Norton AntiVirus - 
> {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
> C:\Program Files\Norton AntiVirus\NavShExt.dll
> O3 - Toolbar: Yahoo! Toolbar - 
> {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
> C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_5_0.dll
> O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD 
> Creator
> 5\DirectCD\DirectCD.exe"
> O4 - HKLM\..\Run: [SynTPLpr] C:\Program 
> Files\Synaptics\SynTP\SynTPLpr.exe
> O4 - HKLM\..\Run: [SynTPEnh] C:\Program 
> Files\Synaptics\SynTP\SynTPEnh.exe
> O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec
> Shared\ccRegVfy.exe"
> O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
> Shared\ccApp.exe"
> O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program
> Files\Yahoo!\Messenger\ypager.exe -quiet
> O4 - HKCU\..\Run: [avtapi] C:\WINDOWS\System32\avtapi.exe
> O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" 
> /background
> O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
> O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions 
> present
> O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control 
> Panel present
> O9 - Extra button: Messenger - 
> {4528BBE0-4E08-11D5-AD55-00010333D0AD} -
> C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
> O9 - Extra 'Tools' menuitem: Yahoo! Messenger -
> {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program
> Files\Yahoo!\Messenger\yhexbmes0411.dll
> O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - 
> C:\Program
> Files\AIM\aim.exe
> O9 - Extra button: Real.com - 
> {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
> C:\WINDOWS\System32\Shdocvw.dll
> O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} -
> http://www.spywarestormer.com/files2/Install.cab
> O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter 
> Class) -
> http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
> O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} 
> (QDiagAOLCCUpdateObj
> Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
> O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall 
> Control) -
> http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
> O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo 
> Class) -
> http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
> O17 -
> HKLM\System\CCS\Services\Tcpip\..\{D0C6FC13-8E6E-46C5-B742-0164394D2B1E}:
> NameServer = 204.127.160.4 12.102.240.2
>
> *note* I now have service pack 2 in which finally dl and 
> installed...but the
> same exact problem is still happening... pc freezing and slooooow 
> opening of
> web pages.. 


Relevant Pages

  • Re: The Page Cannot Be Displayed Error
    ... Nil Carborundum Illegitemi ... Please read http://dts-l.org/goodpost.htm on how to post messages to NG's ... > Here is also a log from Hijack this! ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Agnostic Creation
    ... proffsl wrote: ... It's a claim, not a truth. ... What created the creator? ... them to hijack it only limits one's own ability to understand their ...
    (talk.atheism)
  • Computer Freezes, no idea why
    ... Logfile of HijackThis v1.99.1 ... Windows 98 Gold ... Creator 5\DirectCD\DirectCD.exe" ... It started freezing yesterday, please respond ASAP ...
    (comp.security.firewalls)
  • Re: Home Page Hijinks
    ... There are many Forums that offer Free "Hijack This" log review. ... > Logfile of HijackThis v1.97.7 ... > Explorer\Control Panel present ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: need hijackthis log analysis
    ... I'm not an expert on your hijack logfile but I do have a suggestion: ... Try it and then run hijack this and compare the two log files and see what's ... Microsoft Internet Explorer provided by AT&T WorldNet Service ... Creator 5\DirectCD\DirectCD.exe" ...
    (microsoft.public.security.virus)