Jump to content


Photo

pc troubleshoot


  • This topic is locked This topic is locked
2 replies to this topic

#1 pc87

pc87

    Member

  • Full Member
  • Pip
  • 2 posts

Posted 16 July 2004 - 10:02 AM

Hi,
Whenever I log on to windows, my computer just hangs for a short period of time, showing me the hanged desktop for a few minutes and then everything's normal. Take a look at my HJT log :

Logfile of HijackThis v1.97.7
Scan saved at 7:04:25 PM, on 7/16/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\crypserv.exe
D:\Program Files\Norton Antivirus\navapsvc.exe
D:\Program Files\Norton Internet Security\NISUM.EXE
D:\Program Files\Norton Internet Security\NISSERV.EXE
D:\Program Files\Norton Internet Security\SymProxySvc.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\System32\hkcmd.exe
D:\Program Files\Norton Internet Security\IAMAPP.EXE
D:\PROGRA~1\NORTON~1\navapw32.exe
D:\Program Files\Messenger Plus! 3\MsgPlus.exe
D:\PROGRA~1\INTERN~2\inetmgr.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\WINDOWS\System32\svohost.exe
D:\PROGRA~1\INTERN~2\inetsvc.exe
D:\Documents and Settings\Administrator\Desktop\HijackThis.exe

F0 - system.ini: Shell=explorer.exe D:\WINDOWS\System32\svohost.exe
F2 - REG:system.ini: Shell=explorer.exe D:\WINDOWS\System32\svohost.exe
O2 - BHO: (no name) - {046D6EA4-15E3-4b27-8010-45BD78A9219E} - D:\PROGRA~1\INTERN~2\inetkw.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] D:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] D:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [iamapp] D:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NAV Agent] D:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [MessengerPlus3] "D:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [load32] D:\WINDOWS\System32\swchost.exe
O4 - HKLM\..\Run: [inetmgr] D:\PROGRA~1\INTERN~2\inetmgr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: svchost.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = D:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Download with &DAP - D:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - D:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: ICQ Lite (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .pdf: D:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...ry/msgrchkr.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macr...director/sw.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...StatsClient.cab
O16 - DPF: {9D614E8E-03AA-11D3-90FC-0040C7157029} (PDMSInstallerCtl Class) - http://www.pakdata.c...MSInstaller.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-downlo...tsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...8154.4968287037
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {CAAE28D1-ADCC-11D1-BD4D-004845401881} (Urdu98 Control) - http://www.pakdata.c.../urduplugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/p...t/msnchat45.cab

Plz reply quickly
pc87

#2 Master Green

Master Green

    Member

  • Full Member
  • Pip
  • 41 posts

Posted 16 July 2004 - 10:27 AM

Hi,
One trick I can offer as a suggestion that may not be is, while it's hanging, press the "Esc" key (top left side of your keyboard). If your Norton Virus Protection (which I beleive your computer has from what I can decipher from the log) is the reason, it will display the Norton thing as soon as you press it. If it does not then it's on too plan B...If it does then you need to re-configure how Norton starts up.

#3 dave38

dave38

    Devout Murphyite!

  • Emeritus
  • PipPipPipPipPip
  • 8,508 posts

Posted 16 July 2004 - 02:43 PM

Have Hijack This fix all of the following by placing a check in the appropriate boxes and hitting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.

F0 - system.ini: Shell=explorer.exe D:\WINDOWS\System32\svohost.exe
F2 - REG:system.ini: Shell=explorer.exe D:\WINDOWS\System32\svohost.exe
O2 - BHO: (no name) - {046D6EA4-15E3-4b27-8010-45BD78A9219E} - D:\PROGRA~1\INTERN~2\inetkw.dll

O4 - HKLM\..\Run: [load32] D:\WINDOWS\System32\swchost.exe
O4 - HKLM\..\Run: [inetmgr] D:\PROGRA~1\INTERN~2\inetmgr.exe
O4 - Startup: svchost.exe

O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-downlo...tsInstaller.cab

Reboot and delete

files
D:\WINDOWS\System32\svohost.exe
D:\WINDOWS\System32\swchost.exe

folders
D:\PROGRA~1\INTERN~2

These may be hidden files. See HERE for how to show hidden files.

Please post a followup Hijack this log, and say if your problems persist.
Be wary of strong drink. It may make you shoot at tax collectors, and miss!
Please support SWI forum




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button