ComputerForum.com ComputerForum.com  
TigerDirect
 
Go Back   Computer Forum > Computer Systems > Desktop Computers

Reply
 
LinkBack Thread Tools Display Modes
Old 10-26-2005, 02:47 AM   #11 (permalink)
VIP Member
 
Trizoy's Avatar
 
Join Date: Apr 2005
Location: Campbell, Ca
Posts: 4,647
Default

What it is..
http://www.tomcoyote.org/hjt/#Top

Where to get it...
http://tomcoyote.org/hjt//HijackThis.exe

What is does- scans the current processes, registry and EVERYTHING for spyware. Just post the log here.. When it is done.
Trizoy is offline   Reply With Quote


Old 10-26-2005, 03:02 AM   #12 (permalink)
Diamond Member
 
Camper's Avatar
 
Join Date: Mar 2005
Location: /dev/null
Age: 22
Posts: 1,227
Default

Hijackthis Logs
__________________
Dell Inspiron 530
Q6600 Quad
3gb RAM
Nvidia 8600 GT
500GB HD
Camper is offline   Reply With Quote
Old 10-26-2005, 03:54 AM   #13 (permalink)
Bronze Member
 
Join Date: Oct 2005
Posts: 28
Default

log file here
dorkins is offline   Reply With Quote
Old 10-26-2005, 07:33 AM   #14 (permalink)
Platinum Member
 
vortmax's Avatar
 
Join Date: Sep 2004
Age: 26
Posts: 619
Default

your problem is 512 meg of ram and norton IS. I ran NIS for a while and it killed my system. It is the biggest resource hog ever.

I run mcafee enterprise which eats almost no resources yet is very robust. That with microsoft anti-spyware, occasional spybot scans and the intelligence to recognize i really won't win an i-pod if I can whack the monkey has kept my system problem free for years. Just try uninstalling Norton (unplug your net connection if you're paranoid) and see how it runs.
__________________
Asus A7N8x delux Nforce 2
AMD Athlon 2800+ (barton core)
512 meg Corsair DDR 400
Gainward G-force FX 5200

Dell 6000i
Intel Pentium M 725 (1.60 GHz/2MB Cache/400MHz FSB)
ATI MOBILITY RADEON X300 64MB HyperMemory
1 gig DDR2 PC2-3200

Music server:
AMD K6 500 MHz
128 Meg RAM

Onkyo HT-R520 Reciever
6.1 DTS ES & Dolby Digital EX
vortmax is offline   Reply With Quote
Old 10-26-2005, 08:09 AM   #15 (permalink)
banned
 
Join Date: Feb 2005
Posts: 1,486
Default

Quote:
Originally Posted by vortmax
your problem is 512 meg of ram and norton IS. I ran NIS for a while and it killed my system. It is the biggest resource hog ever.
I quite doubt it I run norton2005 and it uses about 8mb of ram unless I am doing a scan!

Your hijack this log does not look bad except for weather bug and a couple of unnecessary processes running in the background!

Uninstall weather bug and then open hijack this and do a system scan only and check the following entry!

O4 - Global Startup: SpySubtract.lnk = C:\Program

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)

Close all open windows and browsers, and hit "Fix Checked".

I know spysubtract was bundles software but get rid of it, it might conflict with norton!

Download ad-aware and spybot search and destroy along with ewido for your spyware protection arsenal!

Then lets check your operating system, type in sfc /scannow in your run box and see if it comes up with anything.

I have the compaq sr1220nx and it runs like a raped ape, I up graded to 1mb of ram and a stand alone video card because it was not powerful enough for video editing but before I did that it could do just about anything like burning a cd and downloading songs and surfing the web at same time without any issues and I only had 512mb of ram and ran norton in the back ground!

This is going to be a step by step process so try not to get fusterated, we are just going to start with the easy stuff first but we will get to the bottem of it!

After you do the steps above download ewido you may have a trojan, http://www.ewido.net/en/ update ewido defenitions reboot in safe mode do a complete system scan and fix what it finds and then post back and tell us how your computer is running and we will go from there!

Last edited by cell4me; 10-26-2005 at 08:33 AM.
cell4me is offline   Reply With Quote


Old 10-26-2005, 02:09 PM   #16 (permalink)
Bronze Member
 
Join Date: Oct 2005
Posts: 28
Default

i will get this done when i get home from school, but just fyi, i have experimented with disabling norton, with no luck...

so, i dont think its norton
dorkins is offline   Reply With Quote
Old 10-26-2005, 06:27 PM   #17 (permalink)
banned
 
Join Date: Feb 2005
Posts: 1,486
Default

Quote:
Originally Posted by dorkins
i will get this done when i get home from school, but just fyi, i have experimented with disabling norton, with no luck...

so, i dont think its norton
Its not norton, my computer runs just as fast with it on as when its off!
cell4me is offline   Reply With Quote
Old 10-26-2005, 08:13 PM   #18 (permalink)
Bronze Member
 
Join Date: Oct 2005
Posts: 28
Default

sfc /scannow
test run, no results displayed

all programs downloaded and quick run, deep scan in process now...

so far, not much change
dorkins is offline   Reply With Quote
Old 10-26-2005, 08:57 PM   #19 (permalink)
Bronze Member
 
Curt's Avatar
 
Join Date: Aug 2005
Location: Illinois
Age: 23
Posts: 74
Default

Quote:
Originally Posted by cell4me
Its not norton, my computer runs just as fast with it on as when its off!
Not that I think it's the problem in this case (because I don't) But Norton 2005 and NIS are two different things and NIS tends to cause a lot of issues with some peoples computers. We get issues in my shop all the time with NIS causing issues with other programs. The problem is, it's too secure in some areas and not secure enough in others.
I am not a big fan of Norton either way. Much better antivirus programs out there for free rather than wasting money on Norton.

Sorry for being off topic.
__________________
Computer Forums #1 Metalhead
Curt is offline   Reply With Quote
Old 10-26-2005, 09:54 PM   #20 (permalink)
Bronze Member
 
Join Date: Oct 2005
Posts: 28
Default

new log file...

Logfile of HijackThis v1.99.1
Scan saved at 4:53:23 PM, on 10/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Norton Internet Security\ISSVC.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY... io&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY... io&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY... io&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing) (HKCU)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1129235463484
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
dorkins is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 11:10 AM.


Powered by: vBulletin Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.1.0 ©2007, Crawlability, Inc.
Copyright © 2002-2007 Computer Forum and Web Design Forum