Help - Search - Members
Full Version: Just a scan.
Piriform Community Forums > Computer Help and Discussion > Spyware Hell
par0x
Hey could somebody check this log and see if theres anything thats needed or not needed as in the (file missing) options.

And my pc has been running slow these few days..

Logfile of HijackThis v1.99.1
Scan saved at 14:39:51, on 18/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
E:\Program Files\Microsoft AntiSpyware\gcasServ.exe
E:\Program Files\MessengerPlus! 3\MsgPlus.exe
E:\Program Files\Unlocker\UnlockerAssistant.exe
E:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\atwtusb.exe
C:\WINDOWS\system32\CTFMON.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\TBLMOUSE.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
E:\Program Files\Firefox\firefox.exe
E:\Setups\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "E:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "e:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "E:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKCU\..\Run: [MessengerPlus3] "e:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst20040510.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://pcpitstop.com/pestscan/pestscan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1136737662906
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1127423373718
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by101fd.bay101.hotmail.msn.com/activex/HMAtchmt.ocx
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: interceptor.dll,wbsys.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Windows Media Connect (WMC) (WmcCds) - Unknown owner - c:\program files\windows media connect\mswmccds.exe (file missing)
O23 - Service: Windows Media Connect (WMC) Helper (WmcCdsLs) - Unknown owner - C:\Program Files\Windows Media Connect\mswmcls.exe (file missing)

AndyManchesta
Hi par0x

Thats a clean log but there is a couple of entries that can be fixed, Regarding the (file missing) lines, its best you search for the files first to be sure they do not exist then they can be fixed using Hijack This if the files cannot be found.

Run Hijack This and choose Do A System Scan then place a check next to any of these entries you want to fix, Close all open browser and other windows except for Hijack This and press the Fix Checked button

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

Checks for updates to Java but its not required to run everytime you start up the pc, you can either update Java using the Control Panel Java icon or visit Sun's website Here to keep Java up-to-date.


O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

Application which launches common MS Office components to help speed up the launch of Office programs. It's somewhat of a resource hog, and some users claim there's no difference with or without it. Note - if you make use of the Microsoft Office Shortcut Bar outside an office program this application will need to be enabled for it to show


O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

This restriction can be used by some malware to prevent you from changing settings like your homepage. It can also be set by you (using programs like Spybot:S&D) to prevent malware changing your settings or by a System Administrator to prevent users changing settings. If you or a system administrator didn't set that restriction then it can be fixed using Hijack This. If in doubt then leave it in place as there is no indication thats its been added by malware.


O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

This entry is from Webroot's SpySweeper, if you have removed SpySweeper from the pc then it can be fixed.


O23 - Service: Windows Media Connect (WMC) (WmcCds) - Unknown owner - c:\program files\windows media connect\mswmccds.exe (file missing)
O23 - Service: Windows Media Connect (WMC) Helper (WmcCdsLs) - Unknown owner - C:\Program Files\Windows Media Connect\mswmcls.exe (file missing)


Its worth checking if these files exist on the pc then the entries can be fixed if the files cannot be found.

Goto Start Menu > Search > Click All Files and Folders, scroll down to the More Advanced Options which is the last option, click that and then make sure there is a check next to Search System Folders, Search Hidden Files and Folders & Search Subfolders

Once they are enabled scroll back up to the All or part of the filename: area and enter this

mswmccds.exe

Press Search and see if it finds the file in the Windows Media Connect folder then search for this file:

mswmcls.exe

If the files are not found in the Windows Media Connect folder then both entries can be fixed using Hijack This which will set the services to disabled.

Let us know if you have any problems,

Regards

Andy
par0x
only the mswmcls.exe was found not the other one.
thanks mate.

i also have another problem, http://img127.imageshack.us/img127/5805/hlp2oq.jpg how can i fix this back to the normal icons there?
AndyManchesta
Hi par0x

What part did you want to return to normal ?, If its the lack of icons on the top bar click View then Toolbars and place a check next to Standard Buttons. If Its another area let me know and I will help if I can.
par0x
Hey, yeah, well in my documents it was hard to navigate, it's fixed now thankyou.

also when i double click a folder it opens in a new window and it says in the options open folder in same window
AndyManchesta
If you open a new folder then it will always open into a New Window, If that folder contains a second folder then that is the one that will open in the same window if you have it set to that option,

You can test that by Right clicking the Desktop or C:\Drive and choose New > Folder , name it Folder Test . Open Folder Test and then create another folder inside it called Folder Test 2.

If you open the Folder Test Folder it should open into a new window but if you open the second folder (Folder Test 2) it should open into the same window without creating the second window. If you goto Folder Options and set the Browse Folder option to Open each folder in it's own window then Folder Test will open a new window and Folder Test 2 will open a second window.

If it is opening new windows even though its not set that way It might be best to use the Restore Defaults button on the Folder Options and View tab.

Click Start. Goto MyComputer then c:\drive

Select the Tools menu from the top bar and click Folder Options.

Press the Restore Defaults button on the Folder Options tab and the View tab then press Apply and OK to exit the options screen.

Let me know if the problem continues

Cheers

Andy
par0x
1
IPB Image
2(i closed the thing on the left)
IPB Image
3(opens a new window with the same thing on the left)
IPB Image

it's annoying.

:@
can i add you to msn?
AndyManchesta
Thanks for the pics, I get what you mean now but Im not sure what's causing it, try clicking the Restore Defaults button on the Folder Options and View tab and also click the Reset All Folders button on the view tab to see if it fixes the problem,

You can add me but I hardly ever sign into MSN except for checking emails so contacting me on the forum would probably be quicker as its set to notify me if there's any replies.
par0x
Hey, ok thanks anyway, just that this is sort of annoyin' tho'.

Thanks for the help.
krit86lr
Hi. I can't see your pictures. Is this the problem that you're having? If so, Post #16 is the solution.

* Copy and paste everything in the Code box to Notepad.
* Save it as (anything).reg
* Double click the file to add it to the registry


If this isn't your problem I will see what else I can find out. smile.gif
par0x
well sort of but its not on the desktop, in my documents ect but its the folders view
when i close it and open a folder itopens with a new folder in a new window and shows the folders view over and over, lol.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.