1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

maybe another virus

Discussion in 'Malware and Virus Removal Archive' started by Dcmurray, 2007/08/13.

  1. 2007/08/29
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Also, what does your Aliant Security Services package include?
     
  2. 2007/08/30
    Dcmurray

    Dcmurray Well-Known Member Thread Starter

    Joined:
    2006/11/09
    Messages:
    322
    Likes Received:
    0
    Please check your email, I ran the scan and sent you the link. Also Aliant Security has anti-virus, anti-spyware, popup blocker, parental control, form filler.

    please keep in mind that I am a beginner, so some of my responses to you may not provide all the answers to the questions you send.

    Thanks again

    Dana
     

  3. to hide this advert.

  4. 2007/08/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Those test results look good. Open the Ultimate troubleshooter, click View on the menu, then select 'Log of changes you have made with TUT>View log'. If a log opens, copy it and post it here please.

    If no logs available, open the C:\Program Files\Answers That Work\Troubleshooter\backups folder and let me know what, if anything, is there.
     
    Last edited: 2007/08/30
  5. 2007/08/31
    Dcmurray

    Dcmurray Well-Known Member Thread Starter

    Joined:
    2006/11/09
    Messages:
    322
    Likes Received:
    0
    Ultimate Troubleshooter Log

    11-Apr-2007 21:55:54 Startup Disabled: Item: QuickTime Task Command: "C:\Program Files\QuickTime\qttask.exe" -atboottime Location: Registry - Machine Run
    11-Apr-2007 22:04:45 Task Ended: realsched.exe.
    11-Apr-2007 22:05:45 C:\Program Files\Common Files\Real\Update_OB\realsched.exe renamed to realsched.exe.tut1.
    11-Apr-2007 22:06:07 Startup Disabled: Item: TkBellExe Command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot Location: Registry - Machine Run
    11-Apr-2007 22:08:43 Startup Disabled: Item: IntelAudioStudio Command: "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT Location: Registry - Machine Run
    11-Apr-2007 22:08:43 Startup Disabled: Item: MSConfig Command: C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto Location: Registry - Machine Run
    11-Apr-2007 22:08:53 Startup Disabled: Item: HP Digital Imaging Monitor.lnk Command: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe Location: Startup - All Users
    11-Apr-2007 22:08:59 Startup Disabled: Item: RemoteControl Command: "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe " Location: Registry - Machine Run
    11-Apr-2007 22:09:04 Startup Disabled: Item: InCD Command: C:\Program Files\Ahead\InCD\InCD.exe Location: Registry - Machine Run
    11-Apr-2007 22:09:13 Startup Disabled: Item: RunNarrator Command: Narrator.exe Location: Registry - Default RunOnce
    11-Apr-2007 22:09:47 Startup Disabled: Item: Net Assistant.lnk Command: C:\Program Files\Aliant\Net Assistant\bin\matcli.exe Location: Startup - All Users
    11-Apr-2007 22:09:47 Startup Disabled: Item: PowerBar Command: Location: Registry - User Run
    11-Apr-2007 22:09:47 Startup Disabled: Item: SigmatelSysTrayApp Command: sttray.exe Location: Registry - Machine Run
    11-Apr-2007 22:09:47 Startup Disabled: Item: LGODDFU Command: "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun Location: Registry - Machine Run
    11-Apr-2007 22:20:12 Task Ended: hkcmd.exe.
    11-Apr-2007 22:20:21 Task Ended: hpwuSchd2.exe.
    11-Apr-2007 22:20:27 Task Ended: jusched.exe.
    11-Apr-2007 22:20:34 Task Ended: MotiveSB.exe.
    11-Apr-2007 22:20:41 Task Ended: mpbtn.exe.
    11-Apr-2007 22:20:54 Task Ended: stacsv.exe.
    11-Apr-2007 22:21:09 Task Ended: hpqtra08.exe.
    11-Apr-2007 22:21:16 Task Ended: InCD.exe.
    11-Apr-2007 22:21:23 Task Ended: InCDsrv.exe.
    11-Apr-2007 22:21:46 Task Ended: PDVDServ.exe.
    11-Apr-2007 22:22:17 Service Stopped: ALG
    11-Apr-2007 22:27:10 Startup Disabled: Item: igfxtray Command: C:\WINDOWS\system32\igfxtray.exe Location: Registry - Machine Run
    11-Apr-2007 22:27:10 Startup Disabled: Item: igfxhkcmd Command: C:\WINDOWS\system32\hkcmd.exe Location: Registry - Machine Run
    11-Apr-2007 22:27:10 Startup Disabled: Item: Motive SmartBridge Command: C:\PROGRA~1\Aliant\NETASS~1\SMARTB~1\MotiveSB.exe Location: Registry - Machine Run
    11-Apr-2007 22:27:10 Startup Disabled: Item: SunJavaUpdateSched Command: "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe " Location: Registry - Machine Run
    11-Apr-2007 22:27:10 Startup Disabled: Item: HP Software Update Command: C:\Program Files\HP\HP Software Update\HPWuSchd2.exe Location: Registry - Machine Run
    11-Apr-2007 22:27:10 Startup Disabled: Item: Microsoft Office.lnk Command: C:\Program Files\Microsoft Office\Office10\OSA.EXE Location: Startup - All Users

    End Log - 11-Apr-2007 22:27:39

    =============================================
    =============================================

    11-Apr-2007 22:40:36 Task Ended: InCDsrv.exe.
    11-Apr-2007 23:41:45 Startup Disabled: Item: Uniblue Registry Booster2 Command: C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S Location: Registry - User Run

    End Log - 11-Apr-2007 23:42:27

    =============================================
    =============================================

    13-Apr-2007 21:54:48 Startup Disabled: Item: QuickTime Task Command: "C:\Program Files\QuickTime\qttask.exe" -atboottime Location: Registry - Machine Run
    13-Apr-2007 21:54:48 Startup Disabled: Item: Uniblue Registry Booster2 Command: C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S Location: Registry - User Run
    13-Apr-2007 21:54:48 Startup Disabled: Item: 2 Command: C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S Location: Registry - User Run

    End Log - 13-Apr-2007 21:54:55

    =============================================
    =============================================

    5-Jun-2007 20:24:28 Task Ended: stacsv.exe.
    5-Jun-2007 20:28:18 Startup Disabled: Item: QuickTime Task Command: "C:\Program Files\QuickTime\qttask.exe" -atboottime Location: Registry - Machine Run
    5-Jun-2007 20:28:54 Startup Enabled: Item: IntelAudioStudio Command: "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT Location: Registry - Machine Run

    End Log - 5-Jun-2007 20:28:58

    =============================================
    =============================================

    18-Jun-2007 21:53:06 Service Started: WudfSvc
    18-Jun-2007 21:53:24 Service Started: xmlprov
    18-Jun-2007 21:53:33 Service Started: AppMgmt
    18-Jun-2007 21:53:43 Service Started: HTTPFilter
    18-Jun-2007 21:54:00 Messenger Service Set to Auto Mode.
    18-Jun-2007 21:54:08 HidServ Service Set to Auto Mode.
    18-Jun-2007 21:54:14 Service Started: Messenger
    18-Jun-2007 21:54:17 Service Started: Netlogon
    18-Jun-2007 21:54:24 Service Started: Netlogon
    18-Jun-2007 21:54:29 Netlogon Service Set to Auto Mode.
    18-Jun-2007 21:54:38 NtLmSsp Service Set to Auto Mode.
    18-Jun-2007 21:54:44 Service Started: NtmsSvc
    18-Jun-2007 21:54:50 Service Started: RasAuto
    18-Jun-2007 21:54:58 RemoteAccess Service Set to Auto Mode.
    18-Jun-2007 21:55:06 Service Started: upnphost
    18-Jun-2007 21:55:10 Service Started: RemoteAccess
    18-Jun-2007 21:55:25 Service Started: Wmi
    18-Jun-2007 21:55:31 Service Started: WudfSvc

    End Log - 18-Jun-2007 21:56:40

    =============================================
    =============================================



    Could be a problem, when I opened the Troubleshooter ( I only had 2 uses left) the lsass.exe shut down the computer, now I have used the last one. I will try to keep it open and running for now but three kids... who knows?
     
  6. 2007/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Dana, my recommendation would be to undo what you have done using the Ultimate Troubleshooter, based on the actions shown in the log above (disabled registry items), then reboot and uninstall the Ultimate Troubleshooter. It gave my VM machine fits when installed, and may be the source of yours as well.

    Post a new HijackThis log when done and we'll use it to deal with unwanted startup items.
     
  7. 2007/09/01
    Dcmurray

    Dcmurray Well-Known Member Thread Starter

    Joined:
    2006/11/09
    Messages:
    322
    Likes Received:
    0
    New Ultimate Log(after changes)

    11-Apr-2007 21:55:54 Startup Disabled: Item: QuickTime Task Command: "C:\Program Files\QuickTime\qttask.exe" -atboottime Location: Registry - Machine Run
    11-Apr-2007 22:04:45 Task Ended: realsched.exe.
    11-Apr-2007 22:05:45 C:\Program Files\Common Files\Real\Update_OB\realsched.exe renamed to realsched.exe.tut1.
    11-Apr-2007 22:06:07 Startup Disabled: Item: TkBellExe Command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot Location: Registry - Machine Run
    11-Apr-2007 22:08:43 Startup Disabled: Item: IntelAudioStudio Command: "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT Location: Registry - Machine Run
    11-Apr-2007 22:08:43 Startup Disabled: Item: MSConfig Command: C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto Location: Registry - Machine Run
    11-Apr-2007 22:08:53 Startup Disabled: Item: HP Digital Imaging Monitor.lnk Command: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe Location: Startup - All Users
    11-Apr-2007 22:08:59 Startup Disabled: Item: RemoteControl Command: "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe " Location: Registry - Machine Run
    11-Apr-2007 22:09:04 Startup Disabled: Item: InCD Command: C:\Program Files\Ahead\InCD\InCD.exe Location: Registry - Machine Run
    11-Apr-2007 22:09:13 Startup Disabled: Item: RunNarrator Command: Narrator.exe Location: Registry - Default RunOnce
    11-Apr-2007 22:09:47 Startup Disabled: Item: Net Assistant.lnk Command: C:\Program Files\Aliant\Net Assistant\bin\matcli.exe Location: Startup - All Users
    11-Apr-2007 22:09:47 Startup Disabled: Item: PowerBar Command: Location: Registry - User Run
    11-Apr-2007 22:09:47 Startup Disabled: Item: SigmatelSysTrayApp Command: sttray.exe Location: Registry - Machine Run
    11-Apr-2007 22:09:47 Startup Disabled: Item: LGODDFU Command: "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun Location: Registry - Machine Run
    11-Apr-2007 22:20:12 Task Ended: hkcmd.exe.
    11-Apr-2007 22:20:21 Task Ended: hpwuSchd2.exe.
    11-Apr-2007 22:20:27 Task Ended: jusched.exe.
    11-Apr-2007 22:20:34 Task Ended: MotiveSB.exe.
    11-Apr-2007 22:20:41 Task Ended: mpbtn.exe.
    11-Apr-2007 22:20:54 Task Ended: stacsv.exe.
    11-Apr-2007 22:21:09 Task Ended: hpqtra08.exe.
    11-Apr-2007 22:21:16 Task Ended: InCD.exe.
    11-Apr-2007 22:21:23 Task Ended: InCDsrv.exe.
    11-Apr-2007 22:21:46 Task Ended: PDVDServ.exe.
    11-Apr-2007 22:22:17 Service Stopped: ALG
    11-Apr-2007 22:27:10 Startup Disabled: Item: igfxtray Command: C:\WINDOWS\system32\igfxtray.exe Location: Registry - Machine Run
    11-Apr-2007 22:27:10 Startup Disabled: Item: igfxhkcmd Command: C:\WINDOWS\system32\hkcmd.exe Location: Registry - Machine Run
    11-Apr-2007 22:27:10 Startup Disabled: Item: Motive SmartBridge Command: C:\PROGRA~1\Aliant\NETASS~1\SMARTB~1\MotiveSB.exe Location: Registry - Machine Run
    11-Apr-2007 22:27:10 Startup Disabled: Item: SunJavaUpdateSched Command: "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe " Location: Registry - Machine Run
    11-Apr-2007 22:27:10 Startup Disabled: Item: HP Software Update Command: C:\Program Files\HP\HP Software Update\HPWuSchd2.exe Location: Registry - Machine Run
    11-Apr-2007 22:27:10 Startup Disabled: Item: Microsoft Office.lnk Command: C:\Program Files\Microsoft Office\Office10\OSA.EXE Location: Startup - All Users

    End Log - 11-Apr-2007 22:27:39

    =============================================
    =============================================

    11-Apr-2007 22:40:36 Task Ended: InCDsrv.exe.
    11-Apr-2007 23:41:45 Startup Disabled: Item: Uniblue Registry Booster2 Command: C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S Location: Registry - User Run

    End Log - 11-Apr-2007 23:42:27

    =============================================
    =============================================

    13-Apr-2007 21:54:48 Startup Disabled: Item: QuickTime Task Command: "C:\Program Files\QuickTime\qttask.exe" -atboottime Location: Registry - Machine Run
    13-Apr-2007 21:54:48 Startup Disabled: Item: Uniblue Registry Booster2 Command: C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S Location: Registry - User Run
    13-Apr-2007 21:54:48 Startup Disabled: Item: 2 Command: C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S Location: Registry - User Run

    End Log - 13-Apr-2007 21:54:55

    =============================================
    =============================================

    5-Jun-2007 20:24:28 Task Ended: stacsv.exe.
    5-Jun-2007 20:28:18 Startup Disabled: Item: QuickTime Task Command: "C:\Program Files\QuickTime\qttask.exe" -atboottime Location: Registry - Machine Run
    5-Jun-2007 20:28:54 Startup Enabled: Item: IntelAudioStudio Command: "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT Location: Registry - Machine Run

    End Log - 5-Jun-2007 20:28:58

    =============================================
    =============================================

    18-Jun-2007 21:53:06 Service Started: WudfSvc
    18-Jun-2007 21:53:24 Service Started: xmlprov
    18-Jun-2007 21:53:33 Service Started: AppMgmt
    18-Jun-2007 21:53:43 Service Started: HTTPFilter
    18-Jun-2007 21:54:00 Messenger Service Set to Auto Mode.
    18-Jun-2007 21:54:08 HidServ Service Set to Auto Mode.
    18-Jun-2007 21:54:14 Service Started: Messenger
    18-Jun-2007 21:54:17 Service Started: Netlogon
    18-Jun-2007 21:54:24 Service Started: Netlogon
    18-Jun-2007 21:54:29 Netlogon Service Set to Auto Mode.
    18-Jun-2007 21:54:38 NtLmSsp Service Set to Auto Mode.
    18-Jun-2007 21:54:44 Service Started: NtmsSvc
    18-Jun-2007 21:54:50 Service Started: RasAuto
    18-Jun-2007 21:54:58 RemoteAccess Service Set to Auto Mode.
    18-Jun-2007 21:55:06 Service Started: upnphost
    18-Jun-2007 21:55:10 Service Started: RemoteAccess
    18-Jun-2007 21:55:25 Service Started: Wmi
    18-Jun-2007 21:55:31 Service Started: WudfSvc

    End Log - 18-Jun-2007 21:56:40

    =============================================
    =============================================

    1-Sep-2007 12:22:13 Startup Enabled: Item: QuickTime Task Command: "C:\Program Files\QuickTime\qttask.exe" -atboottime Location: Registry - Machine Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: TkBellExe Command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot Location: Registry - Machine Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: igfxtray Command: C:\WINDOWS\system32\igfxtray.exe Location: Registry - Machine Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: igfxhkcmd Command: C:\WINDOWS\system32\hkcmd.exe Location: Registry - Machine Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: Motive SmartBridge Command: C:\PROGRA~1\Aliant\NETASS~1\SMARTB~1\MotiveSB.exe Location: Registry - Machine Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: SunJavaUpdateSched Command: "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe " Location: Registry - Machine Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: HP Software Update Command: C:\Program Files\HP\HP Software Update\HPWuSchd2.exe Location: Registry - Machine Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: Microsoft Office.lnk Command: C:\Program Files\Microsoft Office\Office10\OSA.EXE Location: Startup - All Users
    1-Sep-2007 12:22:13 Startup Enabled: Item: Net Assistant.lnk Command: C:\Program Files\Aliant\Net Assistant\bin\matcli.exe Location: Startup - All Users
    1-Sep-2007 12:22:13 Startup Enabled: Item: Uniblue Registry Booster2 Command: C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S Location: Registry - User Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: 2 Command: C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S Location: Registry - User Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: SigmatelSysTrayApp Command: sttray.exe Location: Registry - Machine Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: LGODDFU Command: "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun Location: Registry - Machine Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: RunNarrator Command: Narrator.exe Location: Registry - Default RunOnce
    1-Sep-2007 12:22:13 Startup Enabled: Item: MSConfig Command: C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto Location: Registry - Machine Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: RemoteControl Command: "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe " Location: Registry - Machine Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: InCD Command: C:\Program Files\Ahead\InCD\InCD.exe Location: Registry - Machine Run
    1-Sep-2007 12:22:13 Startup Enabled: Item: HP Digital Imaging Monitor.lnk Command: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe Location: Startup - All Users
     
  8. 2007/09/01
    Dcmurray

    Dcmurray Well-Known Member Thread Starter

    Joined:
    2006/11/09
    Messages:
    322
    Likes Received:
    0
    System Configuration Utility

    Hi Dave, After the changes to Ultimate Troubleshooter, and uninstall, I rebooted, still have the lsass.exe issue and now a message displays about the System Configuration Utility. "You have used the SCU to make changes to the way Windows starts. The SCU is currently in Diognostic or Selective Startup mode, causing thi9s message to be displayed and the Utility to run every time windows starts. Choose the normal Startup mode on the General Tab to start Windows normally and undo the changes you made using the System Configuration Utility. "

    I haven't done anything with this yet. After clicking OK the SCU General Tab came up and I just cancelled it for now. I'm assuming that I should Choose Normal Startup but wanted instructions from you first. Please advise.

    Thanks
    Dana
     
  9. 2007/09/01
    Dcmurray

    Dcmurray Well-Known Member Thread Starter

    Joined:
    2006/11/09
    Messages:
    322
    Likes Received:
    0
    New Hijackthis Log

    Logfile of HijackThis v1.99.1
    Scan saved at 12:51:38 PM, on 9/1/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\Program Files\Aliant\Aliant Security Services\fws.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Common Files\Command Software\dvpapi.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\SigmaTel\C-Major Audio\WDM\Stacsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Aliant\Servicepoint\ASA.exe
    C:\Program Files\Aliant\Aliant Security Services\Rps.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\PROGRA~1\Aliant\NETASS~1\SMARTB~1\MotiveSB.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\lg_fwupdate\fwupdate.exe
    C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Aliant\Net Assistant\bin\mpbtn.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\HJT\HijackThis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Aliant\Aliant Security Services\pkR.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Aliant\Aliant Security Services\FBHR.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [ASA.exe] "C:\Program Files\Aliant\Servicepoint\ASA.exe "
    O4 - HKLM\..\Run: [Aliant Security Services] "C:\Program Files\Aliant\Aliant Security Services\Rps.exe "
    O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Aliant\NETASS~1\SMARTB~1\MotiveSB.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe "
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
    O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe "
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
    O4 - HKCU\..\Run: [2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Net Assistant.lnk = C:\Program Files\Aliant\Net Assistant\bin\matcli.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: TruePass EPF 7,0,100,717 - https://blrscr3.egs-seg.gc.ca/applets/entrusttruepassapplet-epf.cab
    O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games "“ Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
    O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1142097753734
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
    O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} (ZPA_WheelOfFortune Object) - http://zone.msn.com/bingame/zpagames/zpa_wof.cab55579.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games "“ Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/bingame/popcaploader_v10.cab
    O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} - http://support.intel.com/design/motherbd/boardid/BoardID.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Aliant Security Services Personal Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\Aliant\Aliant Security Services\fws.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\Stacsv.exe



    Appreciate your help Dave, Thanks

    Dana
     
  10. 2007/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Scan again with HijackThis and place a check next to the following entries, then click Fix Checked.

    O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
    O4 - HKCU\..\Run: [2] C:\Program Files\Uniblue\RegistryBooster2\RegistryBooster.exe /S
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    Close HijackThis.

    Let's get rid of the leftover Symantec service. Highlight and copy the following bolded command.

    sc stop CLTNetCnService

    Click Start>Run then paste the command in and hit enter.
    Now copy and paste the next command then hit enter.

    sc delete CLTNetCnService

    Now, with the Run dialog still open, type services.msc and hit enter to open the Services configuration applet.

    Scroll down the list to the Messenger entry and double click it. If service status is 'running', click Stop. When it has stopped, or if it wasn't running, set the startup type to Disabled, click Apply and then OK.

    Now scroll to Netlogon, stop and set to Manual.
    Scroll to NtLmSsp, stop and set to Manual.
    Close the Services applet and reboot.
    Create a fresh HijackThis log and post it please.
     
  11. 2007/09/01
    Dcmurray

    Dcmurray Well-Known Member Thread Starter

    Joined:
    2006/11/09
    Messages:
    322
    Likes Received:
    0
    New Hijackthis Log

    Logfile of HijackThis v1.99.1
    Scan saved at 1:34:27 PM, on 9/1/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\Program Files\Aliant\Aliant Security Services\fws.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Common Files\Command Software\dvpapi.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\SigmaTel\C-Major Audio\WDM\Stacsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Aliant\Servicepoint\ASA.exe
    C:\Program Files\Aliant\Aliant Security Services\Rps.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\PROGRA~1\Aliant\NETASS~1\SMARTB~1\MotiveSB.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Aliant\Net Assistant\bin\mpbtn.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\HJT\HijackThis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Aliant\Aliant Security Services\pkR.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Aliant\Aliant Security Services\FBHR.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [ASA.exe] "C:\Program Files\Aliant\Servicepoint\ASA.exe "
    O4 - HKLM\..\Run: [Aliant Security Services] "C:\Program Files\Aliant\Aliant Security Services\Rps.exe "
    O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Aliant\NETASS~1\SMARTB~1\MotiveSB.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe "
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe "
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Net Assistant.lnk = C:\Program Files\Aliant\Net Assistant\bin\matcli.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: TruePass EPF 7,0,100,717 - https://blrscr3.egs-seg.gc.ca/applets/entrusttruepassapplet-epf.cab
    O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games "“ Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
    O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1142097753734
    O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
    O16 - DPF: {8C279F4E-917E-4CD2-8DF0-D9C73C0CE763} (ZPA_WheelOfFortune Object) - http://zone.msn.com/bingame/zpagames/zpa_wof.cab55579.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games "“ Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/bingame/popcaploader_v10.cab
    O16 - DPF: {E5ABEB00-B357-4884-9949-77B2C71A7EE3} - http://support.intel.com/design/motherbd/boardid/BoardID.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Aliant Security Services Personal Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\Aliant\Aliant Security Services\fws.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\Stacsv.exe



    Wow!!!

    lsass.exe is no longer showing up! Aliant Security Services startup is much faster too. Seems we are heading in the right direction!!

    Appreciation is growing at a tremendous rate.

    Thanks

    Dana
     
  12. 2007/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Browse around for a while, run some programs, etc. Let me know if you get any more lsass errors. ;)
     
  13. 2007/09/01
    Dcmurray

    Dcmurray Well-Known Member Thread Starter

    Joined:
    2006/11/09
    Messages:
    322
    Likes Received:
    0
    Still Not right

    Hi Dave,

    Still having problems with audio and gaming as before and when shutting down internet I still get "program not responding ".

    I think we are close but not there yet.

    Dana
     
  14. 2007/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Right click My Computer and select Properties. Click the Hardware tab, then Device Manager. Look for errors (will be a yellow warning triangle) and let me know if there are any, and what has it.

    Please describe the problems for me again, in detail.
     
  15. 2007/09/01
    Dcmurray

    Dcmurray Well-Known Member Thread Starter

    Joined:
    2006/11/09
    Messages:
    322
    Likes Received:
    0
    Maybe Something?

    Under Other Devices>Unknown Device at location: onIntel(R)82801GH(1CH7DH) LPC Interface - Drivers not installed (code28). Device Instance ID
    ACPI\AWY0001\4&3036D68D&0

    This is showing as a yellow question mark.

    When playing WMP songs, the audio becomes very intermittent stopping and starting quickly, sounds like an audio CD that is skipping. If I choose 4 -5 songs to play, the first one or 2 will play as normal and then the "skipping" will start and become so bad that you are unable to even determine what is playing.

    Insofar as gaming, we don't play much (except online gaming etc. Runescape) but I do have Zuma installed and as with Media Player, the first couple of minutes of game play will act as normal, however, after a few minutes, it too becomes intermittent with both game play and audio again to a point that it becomes impossible to play the game and audio skips.

    The internet, zuma, Outlook and WMP is generally the most common uses on this system. Outlook Express seems to be running normally, Zuma and WMP as described above, and Internet loads slower than normal, but when opened, runs normally until shutting it down, then it will not shut down properly (Program not responding). This happens every time when closing the internet. Beyond that, I haven't noticed any other issues yet.

    Thank You

    Dana
     
  16. 2007/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Have you got the cds that came with the computer, in particularly, one labled Drivers? If you do, recommend you right click that device and select Uninstall, then reboot. You may be prompted for the location of driver files if/when the Add Hardware Wizard opens. Insert the cd and make sure 'Removable media' is one of the options selected in places to search.

    Have you cleaned the inside of the computer? Do you have compressed air?
     
  17. 2007/09/01
    Dcmurray

    Dcmurray Well-Known Member Thread Starter

    Joined:
    2006/11/09
    Messages:
    322
    Likes Received:
    0
    Drivers

    This is the list of CDs that I have

    ACer Monitor
    Intel Desktop Utilities
    Microsoft Keyboard Software
    HP Photosmart (Printer)
    Intel Express Installer Driver CD
    Microsoft Windows XP Pro Includes Service pack 2 Version 2002
    LG DVD Writer Solution ( Power DVD/Power Producer/Nero express/IN CD Acrobat Reader/Drive Manual
    and a very small CD - Card Reader Ver2.02

    I am assuming the drivers are on the Windows XP disc but want to clarify first.

    Computer was cleaned about 3 weeks ago (inside)

    Dana
     
  18. 2007/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Should be the Intel Express Installer Driver CD, but have the XP disc handy anyway. ;)

    The gaming and sound problem suggest a possible bandwidth problem. Low bandwidth would cause the computer to process information faster than it could be downloaded (streamed), thereby forcing the information to be buffered (collected and saved for a short period before resuming play) which means pausing at random intervals. You can test your bandwidth (speed test) at the following link.

    http://www.speakeasy.net/speedtest/
     
  19. 2007/09/01
    Dcmurray

    Dcmurray Well-Known Member Thread Starter

    Joined:
    2006/11/09
    Messages:
    322
    Likes Received:
    0
    Speed test

    Download Speed: 570 kbps (71.3KB/sec transfer rate)
    Upload Speed: 247 kbps (30.9 KB/sec transfer rate)
     
  20. 2007/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    That download speed is considerably low for gaming and streaming audio/video. What type of internet service do you have?
     
  21. 2007/09/01
    Dcmurray

    Dcmurray Well-Known Member Thread Starter

    Joined:
    2006/11/09
    Messages:
    322
    Likes Received:
    0
    Don't really know. Aliant (telephone company) High Speed. I use a telephone jack but I know it isn't dialup and always on. I think it is DSL because the router I use has Power,Ethernet,Wireless,DSL, Internet green Lights on and a USB light that is off.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.