| Forum |
|
|||||||
| QnA (read only) Mods please help transfer the contents of this forum to proper sections. :) |
|
|
LinkBack | Thread Tools | Search this Thread | Display Modes |
|
|
#1 (permalink) |
|
Right Off the Assembly Line
Join Date: Mar 2004
Location: Mumbai
Posts: 38
|
I need help to clean my desktop. I've Uninstalled all unnecessary softwares from my box but still comp takes time to boot. Because several programmes runniong in the background. I'll be thankful if anyone explain me which programmes are these like SVCHOST.exe and how to clear them. ![]() Waiting for reply.....
__________________
Vickymustdie..... Believe me, I\'m Improving..... |
|
|
| Advertisements. Register and be a member of the community to get rid of them. | |
|
Advertisement
|
|
|
|
#2 (permalink) |
|
Human Spambot
Join Date: Mar 2004
Location: India
Posts: 2,033
|
You have some Spyware processes running in the background (like 180Searchassistant). Download HijackThis and unzip it to dedicated folder (like C:\HijackThisFolder\hijackthis.exe).
Then run it and click the button Do a System scan and save log file. HijackThis will perform a scan and saves the log file as hijackthis.log in the same folder where it is installed and it also opens the file automatically. Copy the entire contents of the file and post it here.
__________________
http://swatrant.blogspot.com/ |
|
|
|
|
#3 (permalink) | |
|
I am Optimus Prime
Join Date: Feb 2005
Location: Delhi, India
Posts: 1,919
|
Quote:
|
|
|
|
|
|
#4 (permalink) |
|
Right Off the Assembly Line
Join Date: Mar 2004
Location: Mumbai
Posts: 38
|
Thanks for replying Swatkat...
I've performed the steps you suggested and this is what i came with.... =============================================== Logfile of HijackThis v1.99.1 Scan saved at 6:01:31 PM, on 5/5/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE C:\WINDOWS\system32\lvhidsvc.exe C:\Program Files\Alias\Maya6.5\docs\wrapper.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE C:\Program Files\Alias\Maya6.5\docs\jre\bin\java.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\sstray.exe C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\system32\PV92Tray.exe C:\PROGRA~1\KEMailKb\KEMailKb.EXE C:\Program Files\TVR\RecSche.exe F:\oracle\ora90\BIN\TNSLSNR.exe C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\ISTsvc\istsvc.exe C:\WINDOWS\vtktard.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Media Access\MediaAccK.exe C:\Program Files\Media Access\MediaAccess.exe C:\windows\180ax.exe C:\WINDOWS\system32\rundll32.exe f:\oracle\ora90\bin\ORACLE.EXE C:\WINDOWS\system32\P2P Networking\P2P Networking.exe C:\program files\altnet\points manager\points manager.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\Macromedia\Flash MX 2004\Flash.exe C:\DOCUME~1\owner\LOCALS~1\Temp\~e5d141.tmp C:\DOCUME~1\owner\LOCALS~1\Temp\~e5d141.tmp C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\FlashGet\flashget.exe C:\PROGRA~1\WINZIP\winzip32.exe C:\Documents and Settings\owner\Local Settings\Temp\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://surfunion.com/forum/index.php? O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll O2 - BHO: InstaFinderK - {4E7BD74F-2B8D-469E-90F0-F66AB581A933} - C:\PROGRA~1\INSTAF~1\INSTAF~1.DLL O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: NavHelper Class - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHelper.dll O2 - BHO: Saristar - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE50} - C:\WINDOWS\system32\saristar.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [PV92TRAY] PV92Tray.exe O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE O4 - HKLM\..\Run: [KEMailKb] C:\PROGRA~1\KEMailKb\KEMailKb.EXE O4 - HKLM\..\Run: [ScanRegistry] C:\W O4 - HKLM\..\Run: [RecSche] "C:\Program Files\TVR\RecSche.exe" O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [MimBoot] C:\Program Files\Musicmatch\Musicmatch Jukebox\mimboot.exe O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe O4 - HKLM\..\Run: [Ayi96aG] C:\WINDOWS\vtktard.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe O4 - HKLM\..\Run: [180ax] c:\windows\180ax.exe O4 - HKLM\..\Run: [sixtysix] C:\WINDOWS\sixtypopsix.exe O4 - HKLM\..\Run: [ynqd] C:\WINDOWS\ynqd.exe O4 - HKLM\..\Run: [Ã?³#Â*L"h'þ9Óœð3rÃ…WC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\vtktard.exe O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\system32\P2P Networking\P2P Networking.exe /AUTOSTART O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.ht m (file missing) (HKCU) O9 - Extra button: Ebates - {7F241C00-DAB6-11d5-AAA8-0001028DF1BC} - file://C:\Program Files\EbatesMoeMoneyMaker\System\Temp\ebates_scrip t0.htm (file missing) (HKCU) O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O15 - Trusted Zone: *.media-motor.net O15 - Trusted Zone: *.musicmatch.com O15 - Trusted Zone: *.popuppers.com O15 - Trusted Zone: *.musicmatch.com (HKLM) O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Do...ridge-c293.cab O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) - O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.com/ist/softwares/...sb_regular.cab O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - http://www.xxxtoolbar.com/ist/softwa...06_regular.cab O16 - DPF: {858B4F85-E945-4F0C-AF65-059E0AD9EEC0} (IntraLaunch.MainControl) - file://H:\Interface\IntraLaunch.CAB O16 - DPF: {AD0B8220-7DA4-4C0A-8532-B25A9F631D3D} (VacPro.internazionale_ver10) - http://advnt01.com/dialer/internazionale_ver10.CAB O16 - DPF: {D19781C5-2051-44F8-8445-DDC82933C191} (VacPro.internazionale_ver11) - http://advnt01.com/dialer/internazionale_ver11.CAB O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/diamond.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{50B67F39-18C1-4A9F-85A2-E8C35EC1DE75}: NameServer = 203.197.38.2 203.197.38.3 O17 - HKLM\System\CCS\Services\Tcpip\..\{87F3CD8D-8CE5-441D-8FD8-D2478ADDE0E5}: NameServer = 203.197.38.2,203.197.38.3 O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: LifeView HID Service (LvHidSvc) - Animation Technologies Inc. - C:\WINDOWS\system32\lvhidsvc.exe O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: Maya 6.5 Documentation Server (maya65docserver) - Unknown owner - C:\Program Files\Alias\Maya6.5\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya6.5\docs\Wrapper.conf (file missing) O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE O23 - Service: Oracle OLAP 9.0.1.0.1 (OLAPServer) - Oracle Corporation - F:\oracle\ora90\bin\xsolap.exe O23 - Service: Oracle OLAP Agent - Unknown owner - F:\oracle\ora90\bin\xsaagent.exe O23 - Service: OracleOraHome90Agent - Oracle Corporation - F:\oracle\ora90\bin\agntsrvc.exe O23 - Service: OracleOraHome90ClientCache - Unknown owner - F:\oracle\ora90\BIN\ONRSD.EXE O23 - Service: OracleOraHome90HTTPServer - Unknown owner - F:\oracle\ora90\Apache\Apache\Apache.exe O23 - Service: OracleOraHome90PagingServer - Unknown owner - F:\oracle\ora90/bin/pagntsrv.exe O23 - Service: OracleOraHome90SNMPPeerEncapsulator - Unknown owner - F:\oracle\ora90\BIN\ENCSVC.EXE O23 - Service: OracleOraHome90SNMPPeerMasterAgent - Unknown owner - F:\oracle\ora90\BIN\AGNTSVC.EXE O23 - Service: OracleOraHome90TNSListener - Unknown owner - F:\oracle\ora90\BIN\TNSLSNR.exe O23 - Service: OracleServiceANIL - Oracle Corporation - f:\oracle\ora90\bin\ORACLE.EXE O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Visibroker Smart Agent (xsSmartAgent) - Unknown owner - F:\oracle\ora90\bin\osagent.exe =============================================== Waiting for more suggestions.....
__________________
Vickymustdie..... Believe me, I\'m Improving..... |
|
|
|
|
#5 (permalink) |
|
Distinguished Member
Join Date: Mar 2005
Location: Pune
Posts: 3,783
|
you seem to have lots of spyware, like newdotnet, 180, etc.
run microsoft antispyware, adaware and spybot or spyware doctor. you may habe to uninstall your p2p kazaa. then download and install WinPatrol. from it control/remove your start-ups, services, BHO's etc. you dont really need that many startups. i have only : igfxtray.exe, hkcmd.exe and ctfmon.exe. and my winxp sp1 works just fine. u decide what u need. u will find a marked difference in your startup time and performance. also use ccleaner or ace utilities or tune-up utilities to clear junk and optimize you pc. also check out in the tutorial section : how to reduce startup/shutdown time in winxp.
__________________
> www.TheWindowsClub.com < = www.WinVistaClub.com = Microsoft® MVP |
|
|
|
|
#6 (permalink) | ||
|
Certified Nutz
Join Date: Jan 2004
Location: The 3rd rock from the sun
Posts: 310
|
Quote:
entries in orange r not spywares, but can be fixed. and i see many processes which u can eliminate during startup. go to run, type msconfig and press enter. go to the startup tab and uncheck the following entries: Quote:
btw, if u have doubts on processes, check these sites: http://www.liutilities.com/products/...rocesslibrary/ http://www.windowsstartup.com/wso/browse.php http://www.neuber.com/taskmanager/process/ these three sites are among the best, and can offer accurate basic information regarding processes. moreover and its easy to browse these sites rather than browse spyware related forums which takes a lot of time. * regarding these two processes: C:\DOCUME~1\owner\LOCALS~1\Temp\~e5d141.tmp C:\DOCUME~1\owner\LOCALS~1\Temp\~e5d141.tmp they r safe and should not be considered as rogue processes. they r required by macromedia softwares. read here: http://spywareblog.com/index.php/200...ous_e5d141_tmp
__________________
"Don't take life too seriously. You'll never get out alive!" - Bugs Bunny |
||
|
|
|
|
#7 (permalink) |
|
Human Spambot
Join Date: Mar 2004
Location: India
Posts: 2,033
|
Download CCleaner,AdAware, SpyBot SnD, TrojanHunter Trial and SpywareBlaster.
Boot in safe mode. Go to Control Panel> Add/Remove Programs, and unisntall these tools if you find them:- 1] NavPoint ToolBar or NavExcel Toolbor or NavHelper 2] ISTBar 3] WindUpdates or MediaAccess 4] New.Net or New Dot Net 5] P2P Networking 6] 180 Search Assistant 7] EBates MoneyMaker 8] Altnet Points Manager 9] Internet Optimizer 10] Kazaa (it's better to uninstall this) Then run HijackThis and click "Do only a system scan". Then put a check mark against the below entries:- O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll O2 - BHO: InstaFinderK - {4E7BD74F-2B8D-469E-90F0-F66AB581A933} - C:\PROGRA~1\INSTAF~1\INSTAF~1.DLL O2 - BHO: NavHelper Class - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHelper.dll O2 - BHO: Saristar - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE50} - C:\WINDOWS\system32\saristar.dll O4 - HKLM\..\Run: [ScanRegistry] C:\W O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe O4 - HKLM\..\Run: [Ayi96aG] C:\WINDOWS\vtktard.exe O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe O4 - HKLM\..\Run: [180ax] c:\windows\180ax.exe O4 - HKLM\..\Run: [sixtysix] C:\WINDOWS\sixtypopsix.exe O4 - HKLM\..\Run: [ynqd] C:\WINDOWS\ynqd.exe O4 - HKLM\..\Run: [Ã?³#Â*L"h'þ9Ӝð3rÃ…WC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\vtktard.exe O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\system32\P2P Networking\P2P Networking.exe /AUTOSTART O4 - HKLM\..\Run: [KAZAA] C:\Program Files\Kazaa\kazaa.exe /SYSTRAY O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.ht m (file missing)(HKCU) O9 - Extra button: Ebates - {7F241C00-DAB6-11d5-AAA8-0001028DF1BC} - file://C:\Program Files\EbatesMoeMoneyMaker\System\Temp\ebates_scrip t0.htm (file missing) (HKCU) O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O15 - Trusted Zone: *.media-motor.net O15 - Trusted Zone: *.musicmatch.com O15 - Trusted Zone: *.popuppers.com O15 - Trusted Zone: *.musicmatch.com (HKLM) O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Do...ridge-c293.cab O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) - O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.com/ist/softwares/...sb_regular.cab O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - http://www.xxxtoolbar.com/ist/softwa...06_regular.cab O16 - DPF: {858B4F85-E945-4F0C-AF65-059E0AD9EEC0} (IntraLaunch.MainControl) - file://H:\Interface\IntraLaunch.CAB O16 - DPF: {AD0B8220-7DA4-4C0A-8532-B25A9F631D3D} (VacPro.internazionale_ver10) - http://advnt01.com/dialer/internazionale_ver10.CAB O16 - DPF: {D19781C5-2051-44F8-8445-DDC82933C191} (VacPro.internazionale_ver11) - http://advnt01.com/dialer/internazionale_ver11.CAB O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/diamond.cab Close all other programs and click "Fix Checked" in HijackThis. Exit from HijackThis and then delete these files:- C:\Program Files\NewDotNet\newdotnet6_38.dll C:\PROGRA~1\INSTAF~1\INSTAF~1.DLL C:\Program Files\NavExcel\NavHelper\v2.0.4d\NHelper.dll C:\WINDOWS\system32\saristar.dll C:\Program Files\ISTsvc\istsvc.exe C:\WINDOWS\vtktard.exe C:\Program Files\Media Access\MediaAccK.exe c:\windows\180ax.exe C:\WINDOWS\sixtypopsix.exe C:\WINDOWS\ynqd.exe C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL C:\WINDOWS\system32\P2P Networking\P2P Networking.exe c:\program files\altnet\points manager\points manager.exe C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm C:\Program Files\EbatesMoeMoneyMaker\System\Temp\ebates_script0.htm C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe C:\Program Files\ISTsvc\istsvc.exe H:\Interface\IntraLaunch.CAB c:\w And delete these Folders:- C:\Program Files\NewDotNet C:\PROGRA~1\INSTAF~1 C:\Program Files\NavExcel C:\Program Files\ISTsvc C:\Program Files\Media Access C:\WINDOWS\system32\P2P Networking c:\program files\altnet C:\Program Files\Ebates_MoeMoneyMaker Run these Tools:- CCleaner --> Click "Options" button and here go to "Settings" tab and uncheck the option "Only delete files in Windows Temp folder older than 48 hours". Click OK to exit from the Options. Finally click "Run Cleaner" AdAware --> Click "Scan Now" button in the left pane and select the radio button "Perform full system scan" and click "Start" SpyBot SnD --> Go to "Mode" menu and click "Advanced". Then "Settings" tab in the left pane, and click "File Sets" and here select the file set named "Usage Tracking" and "Tracks.uti". Then click "SpyBot S&D" button in the left pane and click "Check For Problems" TrojanHunter --> Select all the Hard Disk partitions and click "Full Scan" SpywareBlaster --> Run it, and click "Enable All Protection". Reboot to Normal Mode. Go to Command Prompt and type this command netsh winsock reset and press ENTER. Run HijackThis again, and post a fresh HijackThis log. Kazaa is (in)famous for spywares, you can use P2P tool like Shareaza, which is free of any spyware.
__________________
http://swatrant.blogspot.com/ |
|
|
|
|
#8 (permalink) | |
|
Human Spambot
Join Date: Mar 2004
Location: India
Posts: 2,033
|
@sree,
Explorer.exe will be in Windows folder only and you missed these things:- Quote:
__________________
http://swatrant.blogspot.com/ |
|
|
|
|
|
#9 (permalink) |
|
Right Off the Assembly Line
Join Date: Mar 2004
Location: Mumbai
Posts: 38
|
Thats a fantastic feedback...
Thanks anandk, navjotjsingh, sreevirus and swatkat for you reply. Thanks for going through each and every line and providing me the solutions. I'll perform all the steps as mentioned. Thanks again.... Note : (
__________________
Vickymustdie..... Believe me, I\'m Improving..... |
|
|
|
|
#11 (permalink) | |
|
Distinguished Member
Join Date: Mar 2005
Location: Pune
Posts: 3,783
|
Quote:
BUT THEN, I AM ALSO NOT GREAT WHEN IT COMES TO 'IT' TOO...!
__________________
> www.TheWindowsClub.com < = www.WinVistaClub.com = Microsoft® MVP |
|
|
|
|
|
#13 (permalink) |
|
Certified Nutz
Join Date: Jan 2004
Location: The 3rd rock from the sun
Posts: 310
|
@ swat, i was mistaken about the location of explorer.
but i'm not sure about this one's legitimacy. if u notice, windows xp would never have a file named Explorer.exe (ie with a capital E). it should be explorer.exe normally (unless i'm mistaken again) thats what made me think about it. anyway vicky, please update ur AV and scan Explorer.exe once. if nothing shows, then i'm sorry for the inconvenience. anyway, i inferred this site: http://www.neuber.com/taskmanager/pr...lorer.exe.html seems like even neuber is mistaken.
__________________
"Don't take life too seriously. You'll never get out alive!" - Bugs Bunny |
|
|
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|