This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] svchost errors - driving me crazy please help

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Superanti-spyway scan (new):

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 02/16/2009 at 05:42 PM

Application Version : 4.25.1012

Core Rules Database Version : 3761
Trace Rules Database Version: 1723

Scan type : Quick Scan
Total Scan Time : 01:51:19

Memory items scanned : 391
Memory threats detected : 0
Registry items scanned : 472
Registry threats detected : 0
File items scanned : 10205
File threats detected : 2

Adware.Vundo/Variant-S129
C:\WINDOWS\SYSTEM32\PHNFOKTD.DLL

Adware.Vundo/Variant
C:\WINDOWS\SYSTEM32\RTSRVW.DLL
Hi,

Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :services
    Aiangvcs

    :reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
    "Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00

    :files
    c:\windows\system32\perfmon.exe
    C:\WINDOWS\system32\mwhsnr.dll
    c:\windows\system32\cbXqPFVm
    c:\windows\system32\phnfoktd.dll
    c:\windows\system32\rtsrvw.dll

    :Commands
    [emptytemp]
    [Reboot]

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Also, please give a detailed description of how your computer is running and behaving at the moment, listing any remaining problems. Please post a new DDS log in your next reply.

Thanks.
it asked me to reboot, so i did, then it had me run the program before windows started, so i hit run. Then it popped up the notecard with this: ========== SERVICES/DRIVERS ========== Service Aiangvcs stopped successfully. Service Aiangvcs deleted successfully. ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}\\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}\\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}\\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\"Authentication Packages"|hex(7):6d,73,76,31,5f,30,00,00 /E : value set successfully! ========== FILES ========== c:\windows\system32\perfmon.exe moved successfully. File/Folder C:\WINDOWS\system32\mwhsnr.dll not found. File/Folder c:\windows\system32\cbXqPFVm not found. File/Folder c:\windows\system32\phnfoktd.dll not found. File/Folder c:\windows\system32\rtsrvw.dll not found. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Jennifer\LOCALS~1\Temp\~efd6aa\~df394b.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jennifer\LOCALS~1\Temp\~efd6aa\~efe2.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jennifer\LOCALS~1\Temp\~efc90d\~debe26.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jennifer\LOCALS~1\Temp\~efc90d\~df394b.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jennifer\LOCALS~1\Temp\~efc90d\~efe2.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jennifer\LOCALS~1\Temp\etilqs_h3W4baRTj9pn5pECflss scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jennifer\LOCALS~1\Temp\flaED.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jennifer\LOCALS~1\Temp\Photoshop Temp4756862 scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\Jennifer\LOCALS~1\Temp\~e5d141.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Jennifer\Local Settings\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jennifer\Local Settings\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jennifer\Local Settings\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jennifer\Local Settings\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jennifer\Local Settings\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Jennifer\Local Settings\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02172009_160117 Files moved on Reboot… C:\DOCUME~1\Jennifer\LOCALS~1\Temp\~efd6aa\~df394b.tmp moved successfully. C:\DOCUME~1\Jennifer\LOCALS~1\Temp\~efd6aa\~efe2.tmp moved successfully. File C:\DOCUME~1\Jennifer\LOCALS~1\Temp\~efc90d\~debe26.tmp not found! File C:\DOCUME~1\Jennifer\LOCALS~1\Temp\~efc90d\~df394b.tmp not found! File C:\DOCUME~1\Jennifer\LOCALS~1\Temp\~efc90d\~efe2.tmp not found! File C:\DOCUME~1\Jennifer\LOCALS~1\Temp\etilqs_h3W4baRTj9pn5pECflss not found! File C:\DOCUME~1\Jennifer\LOCALS~1\Temp\flaED.tmp not found! File C:\DOCUME~1\Jennifer\LOCALS~1\Temp\Photoshop Temp4756862 not found! C:\DOCUME~1\Jennifer\LOCALS~1\Temp\~e5d141.tmp moved successfully. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. C:\Documents and Settings\Jennifer\Local Settings\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Jennifer\Local Settings\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Jennifer\Local Settings\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Jennifer\Local Settings\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Jennifer\Local Settings\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\Jennifer\Local Settings\Application Data\Mozilla\Firefox\Profiles\s6y15soe.default\XUL.mfl moved successfully.
I am gonna run kaspersky but i have incredible windows lag, all my programs freeze, everything runs sluggish and very slow firefox crashed too with a windows error something is very wrong :|
Hi,

Hold off on the scan if it is still causing problems, I've had a couple of other users having problems with Kaspersky as well.

We need to restore something. Please open OTMoveIt3. Click Restore. There should be a file called:
02172009_160117.res
Please open it. Place a check-mark next to the entry that says:
To: C:\WINDOWS\system32\perfmon.exe
and then click Restore.

Please reboot your machine after this, and then run DDS again and post the first log it gives (DDS.txt).

Let's try a different scan:

Run Eset NOD32 Online AntiVirus
http://www.eset.eu/online-scanner
Note: You will need to use Internet Explorer for this scan.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your current Antivirus software. You can usually do this with its Notfication Tray icon near the clock.
  • Click Start
  • Make sure that the option "Remove found threats" is Un-checked, and the option "Scan unwanted applications" is checked
  • Click Scan
  • Wait for the scan to finish
  • Re-enable your Anvirisus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please include this on your post.
Thanks.
i used the restore it, my computer rebooted then windows crashed continously. I restarted in safe mode, then rebooted again and there was no windows crashing :| Havent done the online scan yet, but here is new DDS report: DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 15:23:04.07 on Wed 02/18/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.563 [GMT -5:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe C:\WINDOWS\system32\wscntfy.exe E:\Winamp\winampa.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\ctfmon.exe E:\SUPERAntiSpyware.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\Logitech\SetPoint\KEM.exe C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE C:\Program Files\Linksys\WUSB100\WUSB100.exe E:\SecondLifeReleaseCandidate\SecondLifeReleaseCandidate.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Documents and Settings\Jennifer\Desktop\dds.scr C:\Program Files\Mozilla Firefox\firefox.exe ============== Pseudo HJT Report =============== uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - e:\spybot~1\SDHelper.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [SUPERAntiSpyware] E:\SUPERAntiSpyware.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [WinampAgent] e:\winamp\winampa.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [nwiz] nwiz.exe /install mRun: [SoundMan] SOUNDMAN.EXE mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\KEM.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\documents and settings\all users\start menu\programs\startup\Syncura Document Sharing Service.lnk.disabled StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\program files\linksys\wusb100\WUSB100.exe uPolicies-explorer: NoViewOnDrive = 0 (0x0) IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - e:\spybot~1\SDHelper.dll DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab DPF: {6715D12F-213F-4C6E-ACE1-8A363F550B96} - hxxp://aolsvc.aol.com/onlinegames/free-trial-doggie-dash/DoggieDash.1.0.0.6.cab DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - E:\SASWINLO.dll AppInit_DLLs: mwhsnr.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - E:\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\jennifer\applic~1\mozilla\firefox\profiles\s6y15soe.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-amo&p= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&vernum=1.0&uid=&did=f8d4a70c-98e2-4081-901d-01bf93043ede&q= FF - plugin: c:\documents and settings\jennifer\application data\mozilla\firefox\profiles\s6y15soe.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp07051001.dll FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPAdbESD.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll FF - plugin: e:\divx web player\divx\divx content uploader\npUpload.dll FF - plugin: e:\divx web player\divx\divx player\npDivxPlayerPlugin.dll FF - plugin: e:\divx web player\divx\divx web player\npdivx32.dll ============= SERVICES / DRIVERS =============== R1 SASDIFSV;SASDIFSV;E:\sasdifsv.sys [2009-1-15 8944] R1 SASKUTIL;SASKUTIL;E:\SASKUTIL.SYS [2009-1-15 55024] R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\firebird\firebird_1_5\bin\fbguard.exe -s –> c:\program files\firebird\firebird_1_5\bin\fbguard.exe -s [?] R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\firebird\firebird_1_5\bin\fbserver.exe -s –> c:\program files\firebird\firebird_1_5\bin\fbserver.exe -s [?] R3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2007-7-28 517632] R3 SASENUM;SASENUM;E:\SASENUM.SYS [2009-1-15 7408] S2 PostgreSQL;PostgreSQL Database Server;"c:\program files\postgresql\8.0-beta2-dev3\bin\pg_ctl.exe" runservice -n "postgresql" -d "c:\program files\postgresql\8.0-beta2-dev3\data\" –> c:\program files\postgresql\8.0-beta2-dev3\bin\pg_ctl.exe [?] S3 Aegiscso;Aegiscso; [x] S3 GETNDIS;VIA Networking Velocity Family Giga-bit Ethernet Adapter Driver;c:\windows\system32\drivers\getnd5b.sys [2005-2-24 44544] S3 SandraAgentSrv;SiSoftware Deployment Agent Service;e:\sisoftware sandra lite 2009.sp2\RpcAgentSrv.exe [2009-2-15 98488] =============== Created Last 30 ================ 2009-02-17 16:01 –d—– C:\_OTMoveIt 2009-02-16 14:30 250 a——- c:\windows\gmer.ini 2009-02-16 02:27 –d—– c:\docume~1\jennifer\applic~1\SUPERAntiSpyware.com 2009-02-09 07:30 54,156 a—h— c:\windows\QTFont.qfn 2009-02-09 07:30 1,409 a——- c:\windows\QTFont.for 2009-02-07 16:06 206,793 a——- c:\windows\system32\nvapps.nvb 2009-02-03 18:41 459,264 -c—— c:\windows\system32\dllcache\msfeeds.dll 2009-02-03 18:41 52,224 -c—— c:\windows\system32\dllcache\msfeedsbs.dll 2009-02-03 18:41 267,776 -c—— c:\windows\system32\dllcache\iertutil.dll 2009-02-03 18:41 63,488 -c—— c:\windows\system32\dllcache\icardie.dll 2009-02-03 18:41 13,824 -c—— c:\windows\system32\dllcache\ieudinit.exe 2009-02-03 18:41 383,488 -c—— c:\windows\system32\dllcache\ieapfltr.dll 2009-02-03 18:41 2,455,488 -c—— c:\windows\system32\dllcache\ieapfltr.dat 2009-02-03 18:41 991,232 -c—— c:\windows\system32\dllcache\ieframe.dll.mui 2009-02-03 18:41 6,066,176 -c—— c:\windows\system32\dllcache\ieframe.dll 2009-02-03 18:41 633,632 -c—— c:\windows\system32\dllcache\iexplore.exe 2009-02-03 15:35 –d—– c:\program files\Linksys 2009-02-03 15:29 16,512 a——- c:\windows\system32\drivers\RAPIProtocol.sys 2009-02-03 15:29 21,361 a——- c:\windows\system32\drivers\AegisP.sys 2009-02-03 15:22 –d—– C:\Linksys Driver 2009-02-03 14:46 4,490,712 a——- C:\WindowsUpdateAgent20-x86.exe 2009-02-03 14:46 1,266,056 a——- C:\WindowsXP-KB927891.exe 2009-02-03 10:23 –d—– c:\program files\Realtek AC97 2009-02-03 10:14 –d—– c:\docume~1\alluse~1\applic~1\Norton 2009-02-03 10:14 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller 2009-02-02 12:27 200,411 a——- c:\windows\system32\nvapps.xml 2009-02-02 12:27 –d—– c:\windows\nview 2009-02-02 10:46 453,152 a——- c:\windows\system32\nvudisp.exe 2009-02-02 10:46 18,725 a——- c:\windows\system32\nvdisp.nvu 2009-02-02 10:46 453,152 a——- c:\windows\system32\NVUNINST.EXE 2009-02-02 10:45 –d—– C:\NVIDIA 2009-02-02 10:42 552 a——- c:\windows\system32\d3d8caps.dat 2009-02-02 10:41 –d—– c:\program files\SystemRequirementsLab 2009-02-01 15:48 1,645,320 a——- c:\windows\system32\gdiplus.dll 2009-01-30 22:17 –d—– c:\windows\Logs 2009-01-30 15:49 –d—– c:\windows\system32\NtmsData 2009-01-30 03:31 23 a–sh— c:\windows\system32\feba1_g.dll 2009-01-30 03:31 23 a——- c:\windows\system32\cccfffec3_g.ocx 2009-01-30 02:31 –d—– c:\documents and settings\jennifer\Tracing 2009-01-30 02:30 –d—– c:\program files\Microsoft 2009-01-30 02:29 –d—– c:\program files\Windows Live SkyDrive 2009-01-30 02:21 –d—– c:\program files\common files\Windows Live 2009-01-29 17:29 –d—– c:\documents and settings\jennifer\.housecall6.6 2009-01-29 13:39 101,888 ac—— c:\windows\system32\dllcache\adpu160m.sys 2009-01-29 13:39 46,112 ac—— c:\windows\system32\dllcache\adptsf50.sys 2009-01-29 13:29 66,048 ac—— c:\windows\system32\dllcache\s3legacy.dll 2009-01-29 09:36 –d—– c:\docume~1\alluse~1\applic~1\PC Drivers HeadQuarters 2009-01-29 09:35 –d—– c:\windows\system32\CatRoot_bak 2009-01-28 02:17 1,324 a——- c:\windows\system32\d3d9caps.dat 2009-01-28 01:58 0 a——- c:\windows\ativpsrm.bin ==================== Find3M ==================== 2009-02-11 10:19 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-11 10:19 15,504 a——- c:\windows\system32\drivers\mbam.sys 2008-12-09 15:43 388,608 a——- c:\windows\system32\CF24313.exe 2008-12-09 03:18 410,984 a——- c:\windows\system32\deploytk.dll 2008-12-04 10:36 3,396 a–sh— c:\windows\system32\dllcache\winsvcmgmnt.dll 2008-12-02 22:37 49,480 a——- c:\windows\system32\sirenacm.dll 2008-12-01 14:53 45,056 a——- c:\windows\system32\amdcalrt.dll 2008-12-01 14:53 45,056 a——- c:\windows\system32\amdcalcl.dll 2008-12-01 14:50 3,252,224 a——- c:\windows\system32\Amdcaldd.dll 2006-08-14 22:28 24,096 ac—— c:\docume~1\jennifer\applic~1\GDIPFONTCACHEV1.DAT 2008-01-15 09:13 861 a–sh— c:\windows\system32\dllcache\aamonit.dll 2008-01-15 09:13 847,872 a–shr– c:\windows\system32\dllcache\libeay32.dll 2008-01-15 09:13 159,744 a–shr– c:\windows\system32\dllcache\ssleay32.dll 2008-01-15 09:13 64,000 a–shr– c:\windows\system32\dllcache\syschk32.dll 2008-01-15 09:13 488 a–shr– c:\windows\system32\dllcache\winsvcf.dll 2008-01-15 09:13 895 a–shr– c:\windows\system32\dllcache\winsvcn.dll 2007-07-31 17:42 55,296 ac-shr– c:\windows\system32\spool\drivers\raddrv.dll ============= FINISH: 15:25:18.39 ===============
Hmm, this is all a bit odd. Let's have a non-invasive look at some things.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :service
    Aegiscso
    
    :file
    C:\WINDOWS\system32\mwhsnr.dll
    C:\WINDOWS\system32\perfmon.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found at on your Desktop entitled SystemLook.txt

Let me know if you get any more errors or crashing. Can you run DDS and post the 2nd log (Attach.txt) that it generates? That usually gives some information about recent errors/problems.

Thanks.
SystemLook v1.0 by jpshortstuff (11.02.09) Log created at 18:13 on 18/02/2009 by Kishkoway (Administrator - Elevation successful) ========== service ========== Aegiscso Aegiscso (No Description) Current Status: Stopped Startup Type: Demand Error Control: Critical Binary: Group: Base SafeBoot: Minimal(Group) Network(Group) Dependencies: (none) Dependant Services: (none) ========== file ========== C:\WINDOWS\system32\mwhsnr.dll - Unable to find/read file. C:\WINDOWS\system32\perfmon.exe - File found and opened. MD5: 230F51F2E4D9C7590F8E1DD76A627143 Created at 12:00 on 23/08/2001 Modified at 05:56 on 04/08/2004 Size: 15872 bytes Attributes: –a— FileDescription: Performance Monitor Command Line Shell FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion: 5.1.2600.2180 OriginalFilename: PERFMON.EXE InternalName: PERFMON.EXE ProductName: Microsoft® Windows® Operating System CompanyName: Microsoft Corporation LegalCopyright: © Microsoft Corporation. All rights reserved. -=End Of File=-
Hi,

Have you had any more crashes or have things settled down a bit? The error log mentioned a problem with a device, could have a been an one off hardware issue…


Please run SystemLook again with this input:
:filefind
mwhsnr.dll

:reg
HKLM\SYSTEM\CurrentControlSet\Services\Aegiscso /s
And post the log file.

Thanks.
i woke up this morning to my computer frozen up, so i rebooted 2 svchost errors, clicked ok to terminate, couldn't get online (wireless intneret) wouldn't connect restarted in safe mode then restarted again normal and no errors and it booted ok and got connected to intenret I get these svchost errors all the time :|
Hi,

Are these the same errors that you were getting before you started this topic, or are they new/different? Can you see what they say?

Do you have a Windows XP Installation Disk?

If you can, please try the SystemLook step from my last post.


Also, let's try this.

Please click Start >> Run. Type (or copy/paste):
Chkdsk /r
into the Run box. Make sure all Windows and Browsers are closed and then press Enter. This will now scan your harddisk for errors, please be patient while it runs as sometimes it can take a long time.

Thanks.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI