Welcome! Register for a free account (or login) > How does it work?
|
|
![]() ![]() |
Jul 2 2009, 04:41 PM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 18-May 04 Member No.: 7,082 |
Regards, Bill
HJTLog.txt ( 7.84K )
Number of downloads: 4StartupList report, 7/2/2009, 2:12:29 PM StartupList version: 1.52.2 Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE Detected: Windows XP SP3 (WinNT 5.01.2600) Detected: Internet Explorer v7.00 (7.00.6000.16850) * Using default options ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\Nhksrv.exe C:\WINDOWS\System32\drivers\CDAC11BA.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe C:\WINDOWS\system32\LXSUPMON.EXE C:\WINDOWS\DELLMMKB.EXE C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Netropa\OSD.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\UNINST.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE -------------------------------------------------- Listing of startup folders: Shell folders Common Startup: [C:\Documents and Settings\All Users\Start Menu\Programs\Startup] Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run LXSUPMON = C:\WINDOWS\system32\LXSUPMON.EXE RUN DellTouch = C:\WINDOWS\DELLMMKB.EXE AdaptecDirectCD = "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" SunJavaUpdateSched = "C:\Program Files\Java\jre6\bin\jusched.exe" TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background MoneyStartUp = C:\Program Files\Microsoft Money\System\Money Startup.exe ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe swg = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\Run [OptionalComponents] = -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=explorer.exe SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry value not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Enumerating Browser Helper Objects: (no name) - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} SpywareGuard Download Protection - C:\Program Files\ComputerStuff\SpywareGuard\dlprotect.dll - {4A368E80-174F-4872-96B5-0B27DDD11DB2} (no name) - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7} (no name) - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} (no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9} JQSIEStartDetectorImpl - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -------------------------------------------------- Enumerating Download Program Files: [symsupportutil] CODEBASE = https://www-secure.symantec.com/techsupp/ac...supportutil.CAB OSD = C:\WINDOWS\Downloaded Program Files\OSD4A.OSD [SysProWmi Class] InProcServer32 = C:\WINDOWS\System32\Dell\SystemProfiler\SysPro.ocx CODEBASE = http://support.dell.com/us/en/systemprofiler/SysPro.CAB [Windows Genuine Advantage Validation Tool] InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll CODEBASE = http://download.microsoft.com/download/3/9...heckControl.cab [Office Update Installation Engine] InProcServer32 = C:\WINDOWS\opuc.dll CODEBASE = http://office.microsoft.com/officeupdate/content/opuc.cab [WUWebControl Class] InProcServer32 = C:\WINDOWS\system32\wuweb.dll CODEBASE = http://update.microsoft.com/windowsupdate/...b?1120916851465 [Symantec Download Manager] InProcServer32 = C:\WINDOWS\Downloaded Program Files\symdlmgr.dll CODEBASE = https://webdl.symantec.com/activex/symdlmgr.cab [MUWebControl Class] InProcServer32 = C:\WINDOWS\system32\muweb.dll CODEBASE = http://update.microsoft.com/microsoftupdat...b?1126293569703 [{74C861A1-D548-4916-BC8A-FDE92EDFF62C}] CODEBASE = http://mediaplayer.walmart.com/installer/install.cab [{9F1C11AA-197B-4942-BA54-47A8489BB47F}] CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/...7635.7755671296 [Shockwave Flash Object] InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx CODEBASE = http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab -------------------------------------------------- Enumerating Windows NT logon/logoff scripts: *No scripts set to run* Windows NT checkdisk command: BootExecute = autocheck autochk * Windows NT 'Wininit.ini': PendingFileRenameOperations: C:\Config.Msi\18f2cf.rbf||C:\Config.Msi\18f2d0.rbf||C:\Config.Msi\18f2d1.rbf||C:\Config.Msi\18f2d2.rbf||C:\Config.Msi\18f2d4.rbf -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\system32\webcheck.dll SysTray: C:\WINDOWS\System32\stobject.dll WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll -------------------------------------------------- End of report, 7,825 bytes Report generated in 0.170 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only This post has been edited by appleoddity: Jul 2 2009, 06:30 PM
Reason for edit: Removed HJT - see attached.
|
|
|
|
Jul 2 2009, 06:34 PM
Post
#2
|
|
![]() SuperMember Group: Tech Team Posts: 1,941 Joined: 7-January 09 From: Flint, Michigan Member No.: 83,485 Operating System: Windows XP, Server 2003/2008, Linux |
Hi Krbybng.
I have removed your main HiJackThis log and have rolled it up as an attachment. We don't usually use, nor request HJT logs in the Windows support forum. Instead, we leave these up to the malware removal experts to analyze. If we do need or want anything from HiJackThis we will request it from you. And, even then, it must always be an attachment and not a copy and paste to the forum. We don't want google indexing hijackthis logs in the windows support forum because it is primarily a malware removal tool and is used only in the malware removal forum. Please do not post any more HJT logs unless requested to do so by a helper. We have many other tools at our disposal that usually provide comparable or better information for us to offer you quality assistance. Thanks, and good luck with getting your issue resolved. |
|
|
|
Jul 11 2009, 10:31 AM
Post
#3
|
|
![]() Authentic Member ![]() ![]() Group: Authentic Member Posts: 34 Joined: 29-June 09 Member No.: 86,465 Operating System: windows vista |
Hello There. You could try this to aid with faster start up.
http://www.windowsstartup.com/download.php http://www.auslogics.com/en/software/disk-defrag/download I could give you a link for a good registry defragger which would also help but there seems to be a bit of confusion by the moderators between a defragger and a registry cleaner. |
|
|
|
Jul 11 2009, 08:51 PM
Post
#4
|
|
![]() WTT Tech Group: Tech Team Posts: 2,976 Joined: 6-August 05 From: Central Florida Member No.: 37,720 Operating System: Windows 7 Pro, Windows XP Pro and Ubuntu Linux |
Delays of that magnitude are almost always network related.
First, check to see if Remote Procedure Call (RPC) Locator is started in Services. If yes, is the Startup type set to Manual? If it's Automatic, double click on it and change it to Manual. That way it will only start if needed. Now do the following:
|
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
16 | mojomojo | 229 | Today, 07:11 AM Last post by: ken545 |
|||
![]() |
6 | Amebeo | 91 | Yesterday, 12:27 PM Last post by: Amebeo |
|||
![]() |
10 | narao | 186 | 12th March 2010 - 06:52 AM Last post by: CatByte |
|||
![]() |
24 | Guyl | 330 | 12th March 2010 - 06:49 AM Last post by: CatByte |
|||
|
Time is now: 14th March 2010 - 10:33 AM |