1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Anyone able to help with this HIJACK THIS

Discussion in 'Security and Privacy' started by Frank Williams, 2004/03/18.

Thread Status:
Not open for further replies.
  1. 2004/03/18
    Frank Williams

    Frank Williams Inactive Thread Starter

    Joined:
    2004/03/18
    Messages:
    3
    Likes Received:
    0
    Can anyone help me find why my computer is "bogging down" regularly from the hijack log? TIA.

    The mouse "hangs" and is sporadic indicating something is dominating the processor - MAYBE?

    Logfile of HijackThis v1.97.7
    Scan saved at 3:35:14 PM, on 3/18/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\Atiptaxx.exe
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\BHODemon\BHODemon.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\System32\gearsec.exe
    C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
    C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\ntvdm.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Documents and Settings\Main\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.thedaily.com/overlook.html
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [PRONoMgrWired] c:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: BHODemon.lnk = C:\Program Files\BHODemon\BHODemon.exe
    O4 - Global Startup: HP OfficeJet Series 500 Startup.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet Series 500\Bin\HPOstr05.exe
    O8 - Extra context menu item: &Copy Location - C:\WINDOWS\WEB\graburl.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra 'Tools' menuitem: Add to R&estricted Zone (HKLM)
    O9 - Extra 'Tools' menuitem: Add to Tr&usted Zone (HKLM)
    O9 - Extra button: Offline (HKLM)
    O15 - Trusted Zone: http://www.aamu.edu
    O15 - Trusted Zone: http://*.chordfind.com
    O15 - Trusted Zone: http://www.dealcatcher.com
    O15 - Trusted Zone: http://cgi.ebay.com
    O15 - Trusted Zone: http://half.ebay.com
    O15 - Trusted Zone: http://pages.ebay.com
    O15 - Trusted Zone: http://signin.ebay.com
    O15 - Trusted Zone: http://www.ebay.com
    O15 - Trusted Zone: http://www.guitaradoptions.com.
    O15 - Trusted Zone: http://acapella.harmony-central.com
    O15 - Trusted Zone: http://www.paypal.com
    O15 - Trusted Zone: http://community.sparedollar.com
    O15 - Trusted Zone: http://www.sparedollar.com
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup144.cab
    O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.sparedollar.com/sdImage/XUpload.ocx
     
  2. 2004/03/18
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Not an 'expert', but that looks pretty clean for the most part. I would fix these;

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.thedaily.com/overlook.html
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    Uninstall Windows Messenger.

    Info on O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    Open task manager to performance page and try to keep an eye on CPU usage when mouse hangs.

    EDIT
    Welcome to WindowsBBS! :D
     
    Last edited: 2004/03/18

  3. to hide this advert.

  4. 2004/03/18
    Frank Williams

    Frank Williams Inactive Thread Starter

    Joined:
    2004/03/18
    Messages:
    3
    Likes Received:
    0
    Thanks for your welcome

    I deleted Windows Messenger - THANK YOU! I had tried to delete it previously and wasnt able to do it because of the IRON FIST of Microsoft (I supposed).

    I fixed your 4 recommendations too.

    When my system gets slowed, the CPU usage is spiking up to anywhere from 30 to 60% - normal?

    I don't know of any reason for it to be doing such a spike however...

    On my running processes, I recognize most but there are several I dont:
    lsass.exe
    csrss.exe
    smss.exe
    gearsec.exe
    System ; AND
    System Idle Process

    There are also two hp prefix .exe files that I am suspicious. They are the Hewlett Packard printer management programs and have never worked correctly in years of trying to use them. Each and every time I turn my PC on it has to go through the "Found Hardware" wizard. I have an All-in-one HP OfficeJet 500 and if there were a generic software driver I would use it if it would operate my HP.


    Again, THANK YOU for your response. There are so many helpful people here

    Is there anything that can be done, governmentally speaking, with all the hackers, spyers, wormers, infecters? They cost billions of dollars of lost productivity to millions of users - and frankly, I would be ready to throw them UNDER THE JAIL.. and I am serious.
     
  5. 2004/03/18
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    lsass.exe
    csrss.exe
    smss.exe
    gearsec.exe
    System ; AND
    System Idle Process

    Gearsec is a burning application and need niot run at startup. It may be part of ITunes. The others are needed windows processes.

    Go into admin tools\services and disable or set to manual those services you do not need running. Esp 3rd party stuff like iPod service. see www.blkviper.com for services guides and use the "safe" config.
     
  6. 2004/03/18
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Frank

    You Might keep an eye out for new proccess's and post another log if something starts without your starting it

    Lonny
     
  7. 2004/03/18
    Frank Williams

    Frank Williams Inactive Thread Starter

    Joined:
    2004/03/18
    Messages:
    3
    Likes Received:
    0
    I found the problem

    First, thanks to all who responded - this board is GREAT!

    Now, the unusual discovery.

    I kept watching all the things mentioned here to no avail. The problem was getting worse - hanging mouse, I even started getting ding dong tones from my machine....

    I eventually suspected a faulty mouse and plugged in a cheapie Dell mouse I had hidden away in a drawer. PROBLEM SOLVED! I am now going online to get another 5 button optical mouse (the simple 2 and 3 button ones dont satisfy me any more). I have had the faulty mouse (Microsoft 5 button USB intellimouse) for around five years of very heavy usage and it finally failed. Sorry for the wild mouse chase...

    At least I learned a little more from this website. And there is at least one data point about how long optical mouses last..

    Again, THANK YOU!
     
  8. 2004/03/18
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Good to hear, and you are welcome. :)
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.