Unsolved
This post is more than 5 years old
7 Posts
0
1191
February 5th, 2007 23:00
Help: 100% CPU Usage. Is my Laptop junk?
The following is a post from October (with no replies!).
Since then, I have totally formated my system and reinstalled everything and now the problem is back. This makes about the 5th time since October I have had to format, install, format install etc. The laptop works great for awhile then either 1) being caused by software that i re-install or 2) some kind of virus?
I could really use some help with this. I am at my wits end and am considering just junking the whole machine.
Also something curious I found was when I was locking up at 100% usage I could open notebook(not word, or anything else) and the time and date will continue to scroll across the blank page in notebook without typing.
thanks!
_______________________________________________________________________________
Hello,
I have a bug on my laptop. I will turn on PC, it might go 15 minutes then all of a sudden it starts slowing down locking up. I goto Task manager and see that Taskmgr.exe and firefox.exe (sometimes also lsass.exe is clocking too)is continuously running from 0 to 100 and so on. CPU usage stays clocked at 100%. End process and then it comes back in like 5 minutes. If i have firefox open it will reload the page over and over. If i click on my desktop, all my icons will flicker.
I can hit escape key and it goes away for like 60 seconds.
If have to do a hard shutdown, then the comp starts beeping when it comes back on for about 10 seconds before it boots up.
I have ran every virus scanner/spyware I could find. I took MCafee off and put on Trend. Ran Adaware, Spybot S & D, CWShredder etc, and found nothing but cookies. Even defrag/clean with Fix-it 6!
I havent installed any hardware or any software recently.
I have a Dell Inspiron 5100 xp service pack2 home edition
Pentium 4 CPU 2.66 GHZ 768 MB RAM
the following is my hijackthis log, any help would be appreciated greatly!:
Logfile of HijackThis v1.99.1
Scan saved at 10:41:53 PM, on 10/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Rob\Desktop\HijackThis_v1.99.1.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts file is located at: C:\WINDOWS\System32\drivers\etc\hosts
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\VCOM\Fix-It\MemCheck.exe
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Palo Alto Software Update Manager 8.0.lnk = C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1158720873766
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1158720862139
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Fix-It Task Manager - Avanquest Publishing USA, Inc. - C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
I have a bug on my laptop. I will turn on PC, it might go 15 minutes then all of a sudden it starts slowing down locking up. I goto Task manager and see that Taskmgr.exe and firefox.exe (sometimes also lsass.exe is clocking too)is continuously running from 0 to 100 and so on. CPU usage stays clocked at 100%. End process and then it comes back in like 5 minutes. If i have firefox open it will reload the page over and over. If i click on my desktop, all my icons will flicker.
I can hit escape key and it goes away for like 60 seconds.
If have to do a hard shutdown, then the comp starts beeping when it comes back on for about 10 seconds before it boots up.
I have ran every virus scanner/spyware I could find. I took MCafee off and put on Trend. Ran Adaware, Spybot S & D, CWShredder etc, and found nothing but cookies. Even defrag/clean with Fix-it 6!
I havent installed any hardware or any software recently.
I have a Dell Inspiron 5100 xp service pack2 home edition
Pentium 4 CPU 2.66 GHZ 768 MB RAM
the following is my hijackthis log, any help would be appreciated greatly!:
Logfile of HijackThis v1.99.1
Scan saved at 10:41:53 PM, on 10/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Rob\Desktop\HijackThis_v1.99.1.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts file is located at: C:\WINDOWS\System32\drivers\etc\hosts
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Fix-It AV] C:\PROGRA~1\VCOM\Fix-It\MemCheck.exe
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Palo Alto Software Update Manager 8.0.lnk = C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1158720873766
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1158720862139
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Fix-It Task Manager - Avanquest Publishing USA, Inc. - C:\PROGRA~1\VCOM\Fix-It\mxtask.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
No Events found!


bamajim
10.4K Posts
0
February 6th, 2007 01:00
2. Things:
If your CPU is at 100%, please open Taskmanger and in your reply indicate what processes are shwoing the most CPU usasge.
Next Go HERE and Download System Repair Engine by smallfrogs
Rt Click sreng2.zip->>Extract all->>Extract it to your desktop
Open the sreng folder
Double click SREng->>Click Run
At the main Window, in the left Pane,Select Smart Scan
At the next window make sure all of the boxes are checked and Select Scan
When the scan is complete Select Save reports
Save it to your desktop and Close the tool
Double Click SREngLog.txt copy and paste that log as a reply to this thread
Do not run any other options with this tool unless instructed to do so.
roburanus
7 Posts
0
February 10th, 2007 01:00
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
Winsock Provider
MC_LAYERED MSAFD Tcpip [TCP/IP]
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
MC_LAYERED MSAFD Tcpip [UDP/IP]
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
MC_LAYERED MSAFD Tcpip [RAW/IP]
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
MC_LAYERED RSVP UDP Service Provider
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
MC_LAYERED RSVP TCP Service Provider
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{1AB5D4E6-F759-4943-BF84-1E3B789F4610}] SEQPACKET 3
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{1AB5D4E6-F759-4943-BF84-1E3B789F4610}] DATAGRAM 3
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{CD2051BF-89F3-4267-9668-CD67A6CF3E50}] SEQPACKET 0
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{CD2051BF-89F3-4267-9668-CD67A6CF3E50}] DATAGRAM 0
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{89F31D57-6E4E-42F0-B44E-367DA1A742C2}] SEQPACKET 1
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{89F31D57-6E4E-42F0-B44E-367DA1A742C2}] DATAGRAM 1
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{0EBB7CA5-BE1E-459D-829C-0C4060629787}] SEQPACKET 2
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
MC_LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{0EBB7CA5-BE1E-459D-829C-0C4060629787}] DATAGRAM 2
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
McAfee.com Layered Provider
C:\WINDOWS\System32\mclsp.dll(McAfee, Inc., McAfee Layered Service Provider)
Autorun.Inf
N/A
HOSTS File
127.0.0.1 localhost
API HOOK
N/A
[/CODE]
roburanus
7 Posts
0
February 10th, 2007 01:00
[PID: 600][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 668][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 692][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 752][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 764][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\mclsp.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\mclsphlr\gdlsphlr.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\system32\McRtl32.dll] [McAfee, Inc., 8.0.0.149]
[PID: 936][C:\WINDOWS\System32\Ati2evxx.exe] [N/A, N/A]
[PID: 948][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1032][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\mclsp.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\mclsphlr\gdlsphlr.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\system32\McRtl32.dll] [McAfee, Inc., 8.0.0.149]
[PID: 1136][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\mclsp.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\mclsphlr\gdlsphlr.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\McRtl32.dll] [McAfee, Inc., 8.0.0.149]
[PID: 1184][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\mclsp.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\mclsphlr\gdlsphlr.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\McRtl32.dll] [McAfee, Inc., 8.0.0.149]
[PID: 1392][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\mclsp.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\mclsphlr\gdlsphlr.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\McRtl32.dll] [McAfee, Inc., 8.0.0.149]
[PID: 1508][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[PID: 1684][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\System32\AdobePDF.dll] [Adobe Systems Incorporated., 7.0.0.00]
[C:\Program Files\Adobe\Acrobat 7.0\Distillr\adistres.dll] [Adobe Systems Incorporated., 7.0.7.2006011200]
[PID: 1856][c:\program files\mcafee.com\agent\mcdetect.exe] [McAfee, Inc, 6, 0, 0, 7]
[PID: 1872][c:\PROGRA~1\mcafee.com\vso\mcshield.exe] [McAfee Inc., 11.0.0.151]
[c:\PROGRA~1\mcafee.com\vso\RES00\McShield.DLL] [McAfee Inc., 11.0.0.141]
[c:\PROGRA~1\mcafee.com\vso\FTL.Dll] [McAfee Inc., 11.0.0.151]
[c:\PROGRA~1\mcafee.com\vso\naiann.dll] [McAfee, Inc., 10, 0, 0, 21]
[c:\PROGRA~1\mcafee.com\vso\mytilus.dll] [McAfee Inc., 11.0.0.151]
[C:\Program Files\McAfee.com\VSO\MCSCAN32.DLL] [McAfee, Inc., 4.4.00]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\naiannps.dll] [McAfee, Inc, 10, 0, 0, 0]
[PID: 1904][c:\PROGRA~1\mcafee.com\agent\mctskshd.exe] [McAfee, Inc, 6, 0, 0, 9]
[PID: 2032][c:\PROGRA~1\mcafee.com\vso\OasClnt.exe] [McAfee, Inc., 10, 0, 0, 24]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\naiannps.dll] [McAfee, Inc, 10, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\mcvsps.dll] [McAfee, Inc, 10, 0, 0, 17]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[PID: 296][c:\program files\mcafee.com\vso\mcvsshld.exe] [McAfee, Inc., 10, 0, 0, 22]
[C:\Program Files\McAfee.com\VSO\VsCfgW32.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\program files\mcafee.com\vso\ashldres.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\program files\mcafee.com\agent\submgr\6,0,0,3\mcsubmgr.dll] [McAfee, Inc, 6, 0, 0, 3]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\mcvsps.dll] [McAfee, Inc, 10, 0, 0, 17]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[PID: 316][c:\program files\mcafee.com\agent\mcagent.exe] [McAfee, Inc, 6, 0, 0, 3]
[c:\program files\mcafee.com\agent\SCRes.dll] [McAfee, Inc, 6, 0, 0, 7]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[PID: 388][c:\progra~1\mcafee.com\vso\mcvsescn.exe] [McAfee, Inc., 10, 0, 0, 20]
[c:\progra~1\mcafee.com\vso\ashldres.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\progra~1\mcafee.com\vso\EmScnRes.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\program files\mcafee.com\vso\vsoupd.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\progra~1\mcafee.com\vso\McVsWorm.dll] [McAfee, Inc., 10, 0, 0, 19]
[C:\Program Files\McAfee.com\VSO\VsCfgW32.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\progra~1\mcafee.com\vso\WormRes.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[PID: 540][C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe] [McAfee Corporation, 7.0.0.152]
[C:\WINDOWS\system32\MPFAPI.dll] [McAfee, 7.0.0.152]
[C:\WINDOWS\System32\mclsp.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\mclsphlr\gdlsphlr.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\system32\McRtl32.dll] [McAfee, Inc., 8.0.0.149]
[PID: 568][C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe] [McAfee Inc., 7.0.1.3]
[C:\PROGRA~1\McAfee\SPAMKI~1\borlndmm.dll] [Borland Software Corporation, 6.0.6.163]
[C:\PROGRA~1\McAfee\SPAMKI~1\MskRescs.dll] [McAfee, Inc., 7.0.1.3]
[C:\PROGRA~1\McAfee\SPAMKI~1\McAbImp.dll] [McAfee, Inc., 7.0.1.4]
[c:\program files\mcafee.com\agent\submgr\6,0,0,3\mcsubmgr.dll] [McAfee, Inc, 6, 0, 0, 3]
[C:\WINDOWS\System32\mclsp.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\mclsphlr\gdlsphlr.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\system32\McRtl32.dll] [McAfee, Inc., 8.0.0.149]
[PID: 652][C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe] [ATI Technologies, Inc., 6.14.10.5028]
[C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATRPUIXX.ENU] [ATI Technologies, Inc., 6.14.10.5028]
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdsxx.dll] [ATI Technologies, Inc., 6.14.10.5028]
[C:\Program Files\ATI Technologies\ATI Control Panel\atipdxxx.dll] [ATI Technologies, Inc., 6.14.10.5028]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[PID: 712][C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe] [, 2, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[PID: 992][C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe] [McAfee Security, 7.0.0.153]
[C:\PROGRA~1\McAfee.com\PERSON~1\Localized.DLL] [McAfee Security, 7.0.0.152]
[C:\WINDOWS\system32\MPFAPI.dll] [McAfee, 7.0.0.152]
[c:\program files\mcafee.com\agent\submgr\6,0,0,3\mcsubmgr.dll] [McAfee, Inc, 6, 0, 0, 3]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[C:\WINDOWS\System32\mclsp.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\mclsphlr\gdlsphlr.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\system32\McRtl32.dll] [McAfee, Inc., 8.0.0.149]
[PID: 1012][C:\PROGRA~1\mcafee.com\mps\mscifapp.exe] [McAfee, Inc., 8.0.0.149]
[C:\PROGRA~1\mcafee.com\mps\MPSRES.DLL] [McAfee, Inc., 8.0.0.149]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[C:\PROGRA~1\mcafee.com\mps\msccfg.dll] [McAfee, Inc., 8.0.0.149]
[c:\program files\mcafee.com\shared\Dunzip32.dll] [Inner Media, Inc., 3.00.14]
[C:\PROGRA~1\mcafee.com\mps\monitors.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\system32\McRtl32.dll] [McAfee, Inc., 8.0.0.149]
[C:\PROGRA~1\mcafee.com\agent\mcuilib.dll] [McAfee, Inc, 6, 0, 0, 5]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[PID: 1100][C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe] [McAfee Inc., 7.0.1.3]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[PID: 1160][C:\WINDOWS\BCMSMMSG.exe] [Broadcom Corporation, 3.5.25 08/27/2003 20:04:35]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[PID: 1172][C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe] [Sun Microsystems, Inc., 5.0.90.1]
[PID: 1196][C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe] [Adobe Systems Inc., 7.0.7.2006011200]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[PID: 1408][C:\Program Files\WinZip\WZQKPICK.EXE] [WinZip Computing LP, 1.0 (32-bit)]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[PID: 1628][C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe] [McAfee Security, 7.0.0.152]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[C:\PROGRA~1\McAfee.com\PERSON~1\Localized.DLL] [McAfee Security, 7.0.0.152]
[c:\program files\mcafee.com\agent\mcagntps.dll] [McAfee, Inc, 5, 0, 0, 0]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[c:\program files\mcafee.com\agent\submgr\6,0,0,3\mcsubmgr.dll] [McAfee, Inc, 6, 0, 0, 3]
[PID: 1092][C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe] [Rocket Division Software, 2.6.1 Build 0x20050401]
[C:\WINDOWS\System32\mclsp.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\mclsphlr\gdlsphlr.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\system32\McRtl32.dll] [McAfee, Inc., 8.0.0.149]
[PID: 1500][C:\WINDOWS\System32\wltrysvc.exe] [N/A, N/A]
[PID: 2076][C:\WINDOWS\System32\bcmwltry.exe] [Belkin Corporation, 3.50.21.12]
[C:\WINDOWS\System32\AegisE5.dll] [Meetinghouse Data Communications, 1, 8, 0, 23]
[C:\WINDOWS\System32\SSLEAY32.dll] [N/A, N/A]
[C:\WINDOWS\System32\LIBEAY32.dll] [N/A, N/A]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[PID: 3056][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\System32\mclsp.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\mclsphlr\gdlsphlr.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\McRtl32.dll] [McAfee, Inc., 8.0.0.149]
[PID: 2632][C:\WINDOWS\system32\wuauclt.exe] [Microsoft Corporation, 5.8.0.2469 built by: lab01_n(wmbla)]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[PID: 2208][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll] [Adobe Systems Incorporated, 7.0.5.2005092300]
[C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll] [Yahoo! Inc., 2006, 9, 7, 1]
[C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTabBar.dll] [Yahoo!, 2006.07.05.1]
[C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 7.0.7.2006011200]
[c:\program files\mcafee.com\mps\mcbrhlpr.dll] [McAfee, Inc., 8.0.0.149]
[c:\program files\mcafee\spamkiller\mcapfbho.dll] [McAfee, Inc., 7.0.1.3]
[C:\Program Files\Yahoo!\Common\yiesrvc.dll] [Yahoo! Inc., 2006, 7, 31, 1]
[C:\Program Files\Yahoo!\Common\YIeTagBm.dll] [Yahoo! Inc., 2006, 7, 28, 1]
[C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll] [Sun Microsystems, Inc., 5.0.90.1]
[c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1020, 2544]
[C:\WINDOWS\System32\mclsp.dll] [McAfee, Inc., 8.0.0.149]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[C:\WINDOWS\System32\mclsphlr\gdlsphlr.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\system32\McRtl32.dll] [McAfee, Inc., 8.0.0.149]
[C:\Program Files\Yahoo!\Companion\Installs\cpn0\pubmod.dll] [Yahoo! Inc., 2005, 12, 16, 1]
[C:\Program Files\Yahoo!\Companion\Installs\cpn0\ypubc.dll] [Yahoo! Inc., 2006.1.25.01]
[C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTAntiSpy.dll] [Yahoo!, Inc., 2006, 06, 27, 01]
[C:\Program Files\Yahoo!\Companion\Installs\cpn0\YMERemote.dll] [Yahoo! Inc., 2006, 7, 27, 1]
[C:\Program Files\Yahoo!\Messenger\ypagerps.dll] [N/A, 1, 0, 0, 1]
[C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx] [Adobe Systems, Inc., 9,0,28,0]
[C:\Program Files\Yahoo!\Common\Yshortcut.dll] [Yahoo! Inc., 2006, 6, 5, 1]
[PID: 380][C:\WINDOWS\system32\notepad.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[PID: 3332][C:\Program Files\WinRAR\WinRAR.exe] [N/A, N/A]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[PID: 888][C:\DOCUME~1\ROB~1.ROB\LOCALS~1\Temp\Rar$EX05.318\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[C:\PROGRA~1\McAfee\SPAMKI~1\mskoeplg.dll] [McAfee Inc., 7.0.1.3]
[c:\progra~1\mcafee.com\vso\McVSSkt.dll] [McAfee, Inc., 10, 0, 0, 19]
[C:\WINDOWS\System32\mclsp.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\System32\mclsphlr\gdlsphlr.dll] [McAfee, Inc., 8.0.0.149]
[C:\WINDOWS\system32\McRtl32.dll] [McAfee, Inc., 8.0.0.149]
roburanus
7 Posts
0
February 10th, 2007 01:00
its taskmgr.exe clocking from 0 to 99 and back and IE explorer turning over but not as fast.
8:43 PM 2/9/2007
8:43 PM 2/9/2007
Smallfrogs ( http://www.KZTechs.com)
- Administrative User - Completed Functions Allowed
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Runing Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet> [(Verified)Yahoo! Inc.]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
[(Verified)ATI Technologies, Inc.]
[ATI Technologies, Inc.]
[]
<"C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask> [McAfee, Inc.]
[McAfee, Inc.]
[McAfee, Inc.]
[McAfee, Inc]
[McAfee, Inc]
[McAfee Security]
[McAfee, Inc.]
[McAfee Inc.]
[McAfee, Inc.]
[(Verified)Broadcom Corporation]
<"C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"> [Sun Microsystems, Inc.]
<"C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"> [Adobe Systems Inc.]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[(Verified)Microsoft Corporation]
[(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[(Verified)Microsoft Corporation]
Startup Folders
[Adobe Acrobat Speed Launcher]
C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [N/A]>
[Adobe Gamma Loader]
C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [Adobe Systems, Inc.]>
[WinZip Quick Pick]
C:\PROGRA~1\WinZip\WZQKPICK.EXE [WinZip Computing LP]>
Services
[Application Management / AppMgmt][Stopped/Disabled]
%SystemRoot%\System32\appmgmts.dll>
[Ati HotKey Poller / Ati HotKey Poller][Running/Auto Start]
[Human Interface Device Access / HidServ][Stopped/Disabled]
%SystemRoot%\System32\hidserv.dll>
[McAfee WSC Integration / McDetect.exe][Running/Auto Start]
[McAfee.com McShield / McShield][Running/Auto Start]
[McAfee Task Scheduler / McTskshd.exe][Running/Auto Start]
[McAfee SecurityCenter Update Manager / mcupdmgr.exe][Stopped/Manual Start]
[McAfee Personal Firewall Service / MpfService][Running/Auto Start]
[McAfee SpamKiller Server / MskService][Running/Auto Start]
[StarWind iSCSI Service / StarWindService][Running/Auto Start]
[WLTRYSVC / WLTRYSVC][Running/Auto Start]
Drivers
[ati2mtag / ati2mtag][Running/Manual Start]
[BCM 802.11b Network Adapter Driver / BCM43XX][Running/Manual Start]
[BCM V.92 56K Modem / BCMModem][Running/Manual Start]
[AEGIS Protocol (IEEE 802.1x) v2.3.0.0 / MDC8021X][Running/Auto Start]
[MPFIREWL / MPFIREWL][Running/System Start]
[NaiAvFilter1 / NaiAvFilter1][Running/Manual Start]
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
[Secdrv / Secdrv][Stopped/Manual Start]
[sptd / sptd][Running/Boot Start]
<\SystemRoot\System32\Drivers\sptd.sys>
[Audio Driver (WDM) - SigmaTel CODEC / STAC97][Running/Manual Start]
[vaxscsi / vaxscsi][Running/Manual Start]
<\SystemRoot\System32\Drivers\vaxscsi.sys>
Browser Add-ons
[Yahoo! Toolbar Helper]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
[McBrwHelper Class]
{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}
[McAfee Privacy Service Popup Blocker]
{3EC8255F-E043-4cae-8B3B-B191550C2A22}
[McAfee Anti-Phishing Filter]
{41D68ED8-4CFF-4115-88A6-6EBB8AF19000}
[Yahoo! IE Services Button]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
[SSVHelper Class]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7}
[Adobe PDF Conversion Toolbar Helper]
{AE7CD045-E861-484f-8273-0445EE161910}
[Java Plug-in 1.5.0_09]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
[MyCfgDlgCmdTarget Class]
{39FD89BF-D3F1-45b6-BB56-3582CCF489E1}
[Yahoo! IE Services Button]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
[&Research]
{92780B25-18CC-41C8-B9BE-3C9C571A8263}
[Yahoo! Messenger]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683}
[McAfee VirusScan]
{BA52B914-B692-46c4-B683-905236F6F655}
[Yahoo! Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
[Adobe PDF]
{47833539-D0C5-4125-9FA8-0819E2EAAC93}
[Java Plug-in 1.5.0_09]
{8AD9C840-044E-11D1-B3E9-00805F499D93}
[Java Plug-in 1.5.0_09]
{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}
[Java Plug-in 1.5.0_09]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000}
[Yahoo! Toolbar Helper]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[Adobe PDF Reader Link Helper]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
[McBrwHelper Class]
{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A}
[McAfee Privacy Service Popup Blocker]
{3EC8255F-E043-4CAE-8B3B-B191550C2A22}
[McAfee Anti-Phishing Filter]
{41D68ED8-4CFF-4115-88A6-6EBB8AF19000}
[Adobe PDF]
{47833539-D0C5-4125-9FA8-0819E2EAAC93}
[Yahoo! IE Services Button]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
[SSVHelper Class]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7}
[Adobe PDF Conversion Toolbar Helper]
{AE7CD045-E861-484F-8273-0445EE161910}
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000}
[Messenger Class]
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} <, N/A>
[Yahoo! Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[&Yahoo! Search]
< file:///C:\Program Files\Yahoo!\Common/ycsrch.htm, N/A>
[Convert link target to Adobe PDF]
[Convert link target to existing PDF]
[Convert selected links to Adobe PDF]
[Convert selected links to existing PDF]
[Convert selection to Adobe PDF]
[Convert selection to existing PDF]
[Convert to Adobe PDF]
[Convert to existing PDF]
[E&xport to Microsoft Excel]
[Yahoo! &Dictionary]
< file:///C:\Program Files\Yahoo!\Common/ycdict.htm, N/A>
[Yahoo! &Maps]
< file:///C:\Program Files\Yahoo!\Common/ycmap.htm, N/A>
[Yahoo! &SMS]
< file:///C:\Program Files\Yahoo!\Common/ycsms.htm, N/A>
bamajim
10.4K Posts
0
February 10th, 2007 01:00
roburanus
7 Posts
0
February 11th, 2007 05:00
roburanus
7 Posts
0
February 11th, 2007 05:00
now like before even after i reformatted, usually when i try to type anything while ie is open ie will start flashing and trying to refresh. if i try to type in notepad. the date keeps popping up every other word. below i have attached the hijack log from tonight after reformat, and i have also attached the sreng2 report.
Taskmgr.exe and IE were still clocking earlier at 100% when i noticed that my pc was acting up. sometimes it seems to go away but it usually comes back and gets worse then might go away for a while. i really appreciate the help on this.
Scan saved at 1:02:21 AM, on 2/11/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Rob\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Smallfrogs ( http://www.KZTechs.com)
- Administrative User - Completed Functions Allowed
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Runing Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[(Verified)Microsoft Corporation]
[(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
[(Verified)Microsoft Corporation]
Startup Folders
N/A
Services
[Application Management / AppMgmt][Stopped/Disabled]
%SystemRoot%\System32\appmgmts.dll>
[Human Interface Device Access / HidServ][Stopped/Disabled]
%SystemRoot%\System32\hidserv.dll>
[WLTRYSVC / WLTRYSVC][Running/Auto Start]
Drivers
[BCM 802.11b Network Adapter Driver / BCM43XX][Running/Manual Start]
[AEGIS Protocol (IEEE 802.1x) v2.3.0.0 / MDC8021X][Running/Auto Start]
[OMCI / OMCI][Running/System Start]
<\SystemRoot\SYSTEM32\DRIVERS\OMCI.SYS>
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
[Secdrv / Secdrv][Stopped/Manual Start]
Browser Add-ons
[@shdoclc.dll,-866]
{c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A>
[&Radio]
{8E718888-423F-11D2-876E-00A0C9082467}
Running Processes
[PID: 524][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 592][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 616][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 660][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 672][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 844][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 924][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1148][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1248][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1280][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[PID: 1484][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[PID: 1704][C:\WINDOWS\System32\wltrysvc.exe] [N/A, N/A]
[PID: 1812][C:\WINDOWS\System32\bcmwltry.exe] [Belkin Corporation, 3.50.21.12]
[C:\WINDOWS\System32\AegisE5.dll] [Meetinghouse Data Communications, 1, 8, 0, 23]
[C:\WINDOWS\System32\SSLEAY32.dll] [N/A, N/A]
[C:\WINDOWS\System32\LIBEAY32.dll] [N/A, N/A]
[PID: 1404][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\macromed\flash\swflash.ocx] [Macromedia, Inc., 5,0,44,0]
[PID: 1668][C:\WINDOWS\System32\wuauclt.exe] [Microsoft Corporation, 5.4.3630.1106 (xpsp1.020828-1920)]
[PID: 348][C:\Documents and Settings\Rob\Local Settings\Temp\Temporary Directory 1 for sreng2.zip\SREng.EXE] [Smallfrogs Studio, 2.3.13.690]
[PID: 1228][C:\WINDOWS\System32\wbem\wmiprvse.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
File Associations
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
Winsock Provider
N/A
Autorun.Inf
N/A
HOSTS File
127.0.0.1 localhost
API HOOK
N/A
bamajim
10.4K Posts
0
February 11th, 2007 23:00