phpBB Forum
 
It is currently Wed Mar 25, 2020 3:40 pm




Post new topic Reply to topic  [ 11 posts ]  Go to page 1, 2  Next
HijackThis - Help with Log. 
Author Message
HH Donor
HH Donor
User avatar

Joined: Tue Apr 01, 2008 7:16 pm
Posts: 1185
Location: England
STEAM_0:0:7517399
MCID: SpineJ
Post HijackThis - Help with Log.
(Before you ask: HijackThis, sometimes abbreviated HJT, is a freeware spyware-removal tool.) Info and Download here: http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis

Now I need someone whose good at telling what is running on computers. Some of this stuff I can recognize, but just in case I thought I'd double check with someone on the HH forums.

Running processes:
C:\WINDOWS1\System32\smss.exe
C:\WINDOWS1\system32\winlogon.exe
C:\WINDOWS1\system32\services.exe
C:\WINDOWS1\system32\lsass.exe
C:\WINDOWS1\system32\Ati2evxx.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS1\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS1\system32\dlbtcoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS1\system32\PnkBstrA.exe
C:\WINDOWS1\system32\PnkBstrB.exe
C:\WINDOWS1\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS1\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS1\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /QS
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS1\system32\ctfmon.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-U ... E_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crl ... crlocx.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS1\system32\NavLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS1\system32\WPDShServiceObj.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS1\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS1\system32\ati2sgag.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: dlbt_device - - C:\WINDOWS1\system32\dlbtcoms.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS1\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS1\system32\PnkBstrB.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

Now your probably saying, "No good throwing this at me because I don't know what you want running."
So let me put this simply: I just wanna play TF2.
So If I was playing TF2, what from this list would slow me down dramatically?
Anything like MSN doesn't count, because thats just what I had running at the time.
Thanks guys. =)

_________________
Extra_Cold wrote:
The Adroit Discourse Of Extra_Cold Cannot Be Contained In 255 Characters.


Fri Sep 05, 2008 3:41 pm
Profile E-mail
HH Donor
HH Donor

Joined: Sat May 31, 2008 7:07 pm
Posts: 3624
STEAM_0:0:10872863
MCID: FluffyMeowington
BattleTag: FluffyM#2320
Post Re: HijackThis - Help with Log.
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS1\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16 - unknown process, possibly nasty

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime - unnecessary, take out of autostart

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" - unnecessary, take out of autostart


Rest looks fine.

For future research: http://www.hijackthis.de/ ;)

_________________
"They jumped out of the 9/11" -Agent, 2016


Fri Sep 05, 2008 3:53 pm
Profile
HH Donor
HH Donor
User avatar

Joined: Tue Apr 01, 2008 7:16 pm
Posts: 1185
Location: England
STEAM_0:0:7517399
MCID: SpineJ
Post Re: HijackThis - Help with Log.
Fluffy wrote:
O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS1\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16 - unknown process, possibly nasty

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime - unnecessary, take out of autostart

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" - unnecessary, take out of autostart


Rest looks fine.

For future research: http://www.hijackthis.de/ ;)

Thanks buddy.


Fri Sep 05, 2008 4:03 pm
Profile E-mail
HH Donor
HH Donor
User avatar

Joined: Sun May 25, 2008 8:20 pm
Posts: 5490
Location: nextdoor
STEAM_0:1:12422276
MCID: bomaster
Post Re: HijackThis - Help with Log.
this is only a rough guide btw but if its system/local service/network service, dont touch it. if its svchost.exe, dont touch it. anything else remove/delete and see what crashes and what doesn't, restart strike it off the list, it fairly long and unorthodox but it works.
the only things on my pc that take up mem (when nothing running) is explorer.exe, svchost.exe
cpu = system idle process, nothing should drain cpu when nothing is running

_________________
But PGT's the musical one, and he's got poobrain!!

|H|H| PotentGermanThunder: yoooo peej your mustache arrived
|H|H| PotentGermanThunder: thanks ma

|H|H| PotentGermanThunder: evolution didn't bring freud anywhere, he still died
|H|H| Bomaster: i think you're confused with darwin

|H|H| PotentGermanThunder: how about fuck you that's shit go eat a bag of dicks euclid

|H|H| PotentGermanThunder: bon jovi is as good as van halen


Fri Sep 05, 2008 5:12 pm
Profile E-mail
HH Donor
HH Donor
User avatar

Joined: Sun Jan 06, 2008 8:04 pm
Posts: 2815
STEAM_0:0:5277183
Post Re: HijackThis - Help with Log.
One way to speed this up is to stop all unnecesary processes before they start, go to run, type msconfig and go to startup tab, uncheck what you dont need.

qtttask
Itunes helper

can both be safely unchecked, as can 90% of the other stuff (i only have 4/30 checked just to give you an idea the only ones i have running are:

ashdisp (avast)
Teatimer (Spybot S&D)
RTHDCPL (sound thing, because i have a lot of inputs and outputs running in parralel)
CTFMON (neccesary process)
WMPNSCFG (so i can network to my xbox))

Following that go to services tab, check HIDE ALL MICROSOFT SERVICES, and uncheck the remaining services as appropriate, stuff like live messenger setup can be disabled as they arnt needed till you start msn messenger at which point they start themselves IPOD service and apple and bonjour can also all be stopped

BE CAREFUL unchecking an important entry like a windows service can screw up your startup DO NOT UNCHECK IF YOUR NOT SURE, google the process before unchecking it (<process name> process library) and check it out before hand

_________________


Fri Sep 05, 2008 7:10 pm
Profile E-mail
HH Donor
HH Donor
User avatar

Joined: Mon Dec 31, 2007 11:54 am
Posts: 2703
Location: Yorkshire
STEAM_0:1:16793612
MCID: EnKaRn
Post Re: HijackThis - Help with Log.
Reinstall windows and dont install all the crap simple as :P

Its obvious which stuff yo dont need as they are Apps you installed, jsut disable them on startup and be carful when touchung processes you dont know i.e. google them simple and mostly tells you what a process does

C:\WINDOWS1\system32\PnkBstrA.exe
C:\WINDOWS1\system32\PnkBstrB.exe
You dont need them running if you only play tf2 as they are Anitcheat for games liek BF Tf2 uses Valve Anticheat :P which is frankly a laod of turd


Fri Sep 05, 2008 9:45 pm
Profile E-mail
HH Donor
HH Donor

Joined: Sat May 31, 2008 7:07 pm
Posts: 3624
STEAM_0:0:10872863
MCID: FluffyMeowington
BattleTag: FluffyM#2320
Post Re: HijackThis - Help with Log.
lol so is punkbuster unfortunately


Sat Sep 06, 2008 7:03 am
Profile
HH Donor
HH Donor
User avatar

Joined: Sun May 25, 2008 8:20 pm
Posts: 5490
Location: nextdoor
STEAM_0:1:12422276
MCID: bomaster
Post Re: HijackThis - Help with Log.
i dug out cod 2 for old times sake and now i cant get rid of fkin pnkbstr. bstrds


Sun Sep 07, 2008 1:37 am
Profile E-mail
HH Donor
HH Donor
User avatar

Joined: Sun Jan 06, 2008 8:04 pm
Posts: 2815
STEAM_0:0:5277183
Post Re: HijackThis - Help with Log.
Fluffy wrote:
lol so is punkbuster unfortunately


Disable it then until you run a game that needs it you can safely turn it of in msconfig, where you can leave it until you need it (then recheck it and restart) 90% of the time its not needed...


Sun Sep 07, 2008 12:08 pm
Profile E-mail
HH Member
HH Member
User avatar

Joined: Fri May 09, 2008 11:06 pm
Posts: 1383
Location: Nowhere
STEAM_0:0:14333246
MCID: Kbramman
Post Re: HijackThis - Help with Log.
Bomaster, go here and run the pbsvc program, this has an option to remove punkbuster completely...


Sun Sep 07, 2008 6:32 pm
Profile E-mail
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 11 posts ]  Go to page 1, 2  Next


Who is online

Users browsing this forum: No registered users and 6 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © phpBB Group.
Designed by Vjacheslav Trushkin for Free Forum/DivisionCore.