Hi.New member here,since this is the third time I got the sh*t!
Read that I can post my log here and you help me out,so…can U help me out…?
How do I upload the log,as a Txt. or plain text here…?
Thanx
A swede that still learning
Here`s my startup log. =)
Mozilla firefox as web-browser….
StartupList report, 19/11/2006, 18:36:56
StartupList version: 1.52.2
Started from : C:\Program Files\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Unable to get Internet Explorer version!
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\WINDOWS\system32\isnotify.exe
C:\WINDOWS\system32\issearch.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\loadqm.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Common
Files\{F0B7B6D0-0AE9-2057-0814-03071904002c}\Update.exe
C:\PROGRA~1\MSNMES~1\msnmsgr.exe
C:\Documents and Settings\Administrator\Start
Menu\Programs\Startup\iexplore.exe
C:\Program Files\SpeedFan\speedfan.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Creative Professional\Digital Audio System\E-MU
PatchMix DSP\EmuPatchMixDSP.exe
C:\WINDOWS\System32\svchost.exe
D:\PROGRAM\MOZILL~1\FIREFOX.EXE
C:\PROGRA~1\ICROSO~1.NET\chkntfs.exe
C:\Program Files\Common Files\S?mantec\m?hta.exe
C:\Program Files\HijackThis\HijackThis.exe
————————————————–
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\Administrator\Start
Menu\Programs\Startup]
iexplore.exe
SpeedFan.lnk = C:\Program Files\SpeedFan\speedfan.exe
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Acrobat Speed Launcher.lnk = ?
————————————————–
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DiskeeperSystray = "C:\Program Files\Diskeeper
Corporation\Diskeeper\DkIcon.exe"
IntelliPoint = "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
{0228e555-4f9c-4e35-a3ec-b109a192b4c2} = C:\Program
Files\Google\Gmail Notifier\gnotify.exe
Acrobat Assistant 7.0 = "C:\Program Files\Adobe\Acrobat
7.0\Distillr\Acrotray.exe"
CTHelper = CTHELPER.EXE
UpdReg = C:\WINDOWS\UpdReg.EXE
LoadQM = loadqm.exe
MessengerPlus3 = "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
SunJavaUpdateSched = "C:\Program
Files\Java\jre1.5.0_09\bin\jusched.exe"
NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe
Ad-Aware = "C:\Program Files\AdAware\Ad-Aware.exe" +c
MULTIMEDIA KEYBOARD = C:\Program Files\Netropa\Multimedia
Keyboard\MMKeybd.exe
CTDrive = rundll32.exe C:\WINDOWS\system32\drvwur.dll,startup
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
CTFMON.EXE = C:\WINDOWS\system32\CTFMON.EXE
SetDefaultMIDI = MIDIDef.exe
MessengerPlus3 = "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
/WinStart
msnmsgr = "C:\PROGRA~1\MSNMES~1\msnmsgr.exe" /background
HijackThis startup scan = C:\Program Files\HijackThis\HijackThis.exe
/startupscan
Rnnw = "C:\PROGRA~1\ICROSO~1.NET\chkntfs.exe" -vt yazb
Vadn = C:\Program Files\Common Files\S?mantec\m?hta.exe
————————————————–
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
————————————————–
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations:
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mshtml2.exe
————————————————–
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
SysTray: C:\WINDOWS\system32\stobject.dll
cussers: C:\WINDOWS\system32\cfltygd.dll
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Ru
n
{F0B7B6D0-0AE9-2057-0814-03071904002c} = "C:\Program
Files\Common
Files\{F0B7B6D0-0AE9-2057-0814-03071904002c}\Update.exe"
mc-110-12-0000272
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Ru
n
ishost.exe = ishost.exe
kernel32.dll = C:\WINDOWS\system32\isnotify.exe
issearch.exe = issearch.exe
————————————————–
End of report, 6,362 bytes
Report generated in 0.031 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of
platform
/history - to list version history only
So….nobody wants to give me a hand here…?
/M@