UNSOLVED

kdny13

updated

19 years ago

K

kdny13

233 Posts

0

7058

May 27th, 2007 19:00

svchost...

Hello:
 
Bay Wolf suggested I contact this thread regarding the fact that my Dell Inspiron 6000d (new) laptop is running PAINFULLY slow and I notice in 'processes' that svchost is listed 7 times.  Bay Wolf suggested:

svchost.exe should not be disabled.  It is required for essential applications to work properly.
But there are trojans and virus that will install itself and use the name svchost.exe. 

Determining whether svchost.exe is a virus or a legitimate Windows process depends on the directory location it executes or runs from.

I would suggest that you visit the HijackThis group here on Dell's forum.  There you can get expert help to determine if your computer is running slow because of trojans or virus.

CAN YOU PLEASE HELP ME figure this out and why my machine is soooo slllllooooowww?  THANKS SO MUCH

KAREN

  • kdny13

    233 Posts

    418

    0

    Posted May 27th, 2007 20:00

    Hi C.G. Vet:
     
    My Dad was a U.S.C.G. Vet as well!!
     
    I am running that scan now and will post the log as you suggested.  I have Norton Internet Security Center on my laptop as well.....but it's so frustrating how slow the machine is running.  I'm hoping you can find the problem for me.
     
    Thank you for taking the time to help me.
    Karen
  • 1972vet

    3305 Posts

    418

    0

    Posted May 27th, 2007 20:00

    Perform an online scan Here.
    Scroll down and click the Scan now. Install the active X
    control needed for the scan. If a dialog box appears asking you
    if you would like to download and install the ewido anti-spyware
    online scanner please click "Yes" to allow the download.

    Once installed, click the Start Scan button. Click
    Remove Infections if found. Save the log and post it back
    on your next reply. Thanks!
  • 1972vet

    3305 Posts

    418

    0

    Posted May 27th, 2007 20:00

    Which training facility did Dad go to and when? Tell Dad I said "Semper Paratus" ...and happy Memorial Day!

    ...when you post back, also please include the last date you ran a cleanup and defrag. Thanks kiddo!
  • kdny13

    233 Posts

    418

    0

    Posted May 28th, 2007 00:00

    Dad trained at Groton, Ct.  I would give anything if I could pass your message on to him, but unfortunately that is no longer possible.  Your signoff "kiddo" made me cry and smile = that was my Dad's nickname for me!  I can't believe the coincidence!  Thanks for that - it felt good!!!!
     
    As for this darned s l o w machine --- I ran the scan you suggested and 121 infections were found.  When I clicked 'remove infections' it no longer allowed me to save the log!!  Do you want me to re-run the scan and post the log?  Please advise.
     
    Can you tell me why Norton scan did not find these 121 infections?  I'm confused by that.
     
    Do you think there's a possibility that the machine would be faster now?  Please let me know what the next steps should be to get this resolved.  Fingers crossed that you have a way to fix this issue!!
     
    (FYI, I noticed your signoff ASAP and 1st responder.  I'm not sure what that refers to but you might be interested in taking a look at my website www.readymask.com - it's a new patented product that you might find interesting.
     
    Thank you again for taking the time to help me and I look forward to hearing from you regarding all of the above.
     
    Take care,
    Karen
  • kdny13

    233 Posts

    418

    0

    Posted May 28th, 2007 02:00

    I think I forgot to mention to you that I defrag and cleanup the disc once a month - and it was actually done yesterday.
     
    Also, I just restarted the laptop, and after all I went through with earlier on this forum to get rid of the ccApp error on shutdown, it's back!!!!   I just don't know what to do anymore.......NOTHING seems to be working correctly
     
  • kdny13

    233 Posts

    419

    0

    Posted May 28th, 2007 14:00

    Ok...here's the log.  I have it open on my computer since I haven't checked anything to be deleted yet.
     
    I await your next instructions!  Thank you!
    Karen
     
    Logfile of HijackThis v1.99.1
    Scan saved at 11:36:31 AM, on 5/28/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\Raxco\PerfectDisk\PDSched.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\Program Files\Microsoft IntelliPoint\point32.exe
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe
    C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
    C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
    C:\PROGRA~1\WinFax\WFXSWTCH.exe
    C:\WINDOWS\system32\wfxsnt40.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\AOL\1172240059\ee\AOLSoftware.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\Wireless Sync\Client\Monitor.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Wireless Sync\Client\Monitor.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    E:\program files\utorrent\utorrent(2).exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Pando Networks\Pando\pando.exe
    C:\WINDOWS\system32\SearchProtocolHost.exe
    C:\hijackthis\HijackThis.exe
    C:\WINDOWS\system32\wuauclt.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
    O1 - Hosts: 64.78.21.111 EHOST011-4
    O1 - Hosts: 64.78.21.111 EHOST011-4.exch011.intermedia.net
    O1 - Hosts: 64.78.21.2 DC011.exch011.intermedia.net
    O1 - Hosts: 64.78.21.94 DC011-1.exch011.intermedia.net
    O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
    O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
    O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe" /m=0
    O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
    O4 - HKLM\..\Run: [eFax 4.2] "C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe" /R
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
    O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\WinFax\WFXSWTCH.exe
    O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1172240059\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [Startup Manager] C:\Documents and Settings\karen hollander\Application Data\Systweak\ASO 2\smstartUp manager.exe
    O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O4 - Global Startup: Wireless Sync Client.lnk = C:\Program Files\Wireless Sync\Client\Monitor.exe
    O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm103LDUS
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversFWBInitialSetup1.0.0.15.cab
    O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
    O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
    O16 - DPF: {40F8967E-34A6-474A-837A-CEC1E7DAC54C} - https://accounting.quickbooks.com/c2/v15.585/qboax9.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1180107941991
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155755403125
    O16 - DPF: {70F72504-0622-45B0-87A1-19F4C40BBBA2} (PortPingCOM Class) - https://exchange.intermedia.net/Customization/Downloads/PortPingCOM.DLL
    O16 - DPF: {843EE768-3A97-455C-9076-741BA3AD7B62} (QuickBooks Online Edition Utilities Class v10) - https://accounting.quickbooks.com/c12/v16.607/qboax10.cab
    O16 - DPF: {8AA1AE9E-9FB0-41B3-8911-89A1068A7FD1} (Installer Class) - https://www.wirelesssync.vzw.com/en/SyncInstall.cab
    O16 - DPF: {9C024426-7859-4B2D-AB4C-B1E370AE7549} - http://us.mcafee.com/Apps/WSC/en-us/WscWlanScannerCtrl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
    O23 - Service: PDScheduler (PDSched) - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDSched.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
     
  • 1972vet

    3305 Posts

    418

    0

    Posted May 28th, 2007 14:00

    Quote: Dad trained at Groton, Ct.
    Ahh...good answer lol. Many folks for whatever reason purport to be somehow affiliated with a military background. Those of us who ARE brothers in arms always make a habit of first asking where they trained. The Coast Guard is the smallest branch of the military, so there aren't many of us out here.

    Most folks who are just trying to make conversation never really seem to know where they took their training for sure lol. In those cases, we normally just let it go and chalk it up as one more well intentioned citizen. Groton, CT. is just one of only two correct answers so it can't be coincidental. I tip my hat and salute your daddy for a job welll done!


    When I clicked 'remove infections' it no longer allowed me to save the log!!
    Do you want me to re-run the scan and post the log? Please advise.
    No. It's fine.

    Can you tell me why Norton scan did not find these 121 infections? I'm confused by that
    Norton is an antivirus program. The scan I had you run online looks for various malware including viruses. Most of those infections I would surmise were probably trojans (which norton isn't going to find many of) and spyware cookies along with perhaps, just some adware. Just as a side note, you should never trust your computer's security to just one piece of protective software.

    Do you think there's a possibility that the machine would be faster now? Please let me know what the next steps should be to get this resolved. Fingers crossed that you have a way to fix this issue!!
    We will get to the bottom of it.

    I noticed your signoff ASAP and 1st responder. I'm not sure what that refers to
    A.S.A.P. stands for the Alliance of Security Analysis Professionals and 1st responder is the title I have as a staff member on the CastleCops web site (formerly ComputerCops). The first responders there are the professional security folks who are first to respond to the request for help in their HijackThis forum. Although, you do seem to be aware that the title "1st Responder" also makes reference to emergency personnel. I also happen to have been one of those in the past as well (Police Officer).

    I just restarted the laptop, and after all I went through with earlier on this forum to get rid of the ccApp error on shutdown, it's back!!!! I just don't know what to do anymore.......NOTHING seems to be working correctly
    Norton products are continuously complained of by home users all over the web...which is why I never recommend it for them. In addition, years ago I used to be a norton fan but from my own experience with it, I grew weary of uninstalling and reinstalling it just to keep it working. I unloaded it and use the freeware software now. I also find that my system now performs much faster and better.

    Let's start with a HijackThis log.

    Click HERE to download a self extractable version of hijackthis.

    Double click on the hjthis.exe then click "extract". It will be extracted automatically to it's own folder located here:
    C:\hijackthis

    This folder is where you will find the HJT logs that you save. When you use the application to remove anything, you will also find the backup copies made by HJT inside this folder.

    You can double click the icon that was placed on the Desktop to run hijackthis or you can use the icon inside the folder.

    Click Do a system scan and save a logfile. Copy and paste the contents of that log back here in this thread. Thanks!
  • 1972vet

    3305 Posts

    419

    0

    Posted May 28th, 2007 16:00

    Let's make sure you can view all files.



    Click here for information regarding the risks of using File Sharing software.



    To restart your Symantec components, please do the following:

    Click Start-->Run
    and type or copy and paste
    Services.msc
    then click "OK"

    Scroll down that list of services to locate the services named:
    Symantec Event Manager (ccEvtMgr)
    Symantec Settings Manager (ccSetMgr)
    Symantec Lic NetConnect service (CLTNetCnService)
    LiveUpdate Notice Service Ex (LiveUpdate Notice Ex)
    LiveUpdate Notice Service



    When you find them, double-click on each, one at a time, then click the Start button.

    Next, change the Startup Type to Automatic
    Apply it, OK it, and close all open windows.

    Next, please run hijackthis...
    Click "Open Misc Tools Section"



    Please uninstall the following software:
    MyWebSearch

    Click-->Start-->Control Panel-->Add/Remove Programs

    Scroll down the list to locate the program name "MyWebSearch" and click Remove. When the uninstall completes, reboot the computer.



    Please download HostsXpert 3.7 - Hosts File Manager
    formerly known as: 'Hoster'
    Unzip the file then run HostsXpert.exe

    Under Editing Tools, if the button Make Hosts Writable? appears in Red then you must click the button to enable any editing to your hosts file.

    Next, please click "Restore Microsoft'S Hosts File" then click "OK". Click the "X" to exit the program.



    Your Java application is out of date and causes a slight security risk as a result.
    Please follow these steps to remove older version Java components

    1. Close any open programs you may have running, especially your web browser.

    2. Click Start-->Control Panel-->Add or Remove Programs.
    For those just reading this thread:
    Depending on your OS, you may have to click Start-->Settings-->Control Panel-->Add or Remove Programs.


    3. Click once on any item listing Java Runtime Environment in the name (to highlight it) then click the "Remove" or "Change/Remove" button.
    Not every version of Java will begin with "Java" so be sure to read each entry in the list.
    Repeat step 3 as many times as necessary to remove all versions of Java.
    **If you are asked to reboot at any point during the uninstallations, please do so. Then go back to Add/Remove and continue with the rest of the removals...when finished uninstalling all of them, reboot the computer.

    4. Navigate to and delete:
    • C:\Program Files\ Java =this folder if found
    5. Then go to this page.
    Scroll down to where it says "Java Runtime Environment (JRE) 6u1
    The Java SE Runtime Environment (JRE) allows end-users to run Java applications."and click the "Download" button to the right.


    6. Check the box that says: "Accept License Agreement" the page will refresh and click on the link to download Windows Offline Installation with or without Multi-language. Save it to your desktop.
    Then from your desktop double-click on the executable to install the newest version. Reboot when the installation completes.



    Please visit this site. Navigate to the file indicated below in Bold and upload the file for a free scan:

    C:\WINDOWS\system32\inetsrv\ inetinfo.exe
    C:\Program Files\Raxco\PerfectDisk\ PDSched.exe

    If you're unsure how to do that, follow the instructions below:

    1. Click in the "File" box at the top of the window to put the cursor there then click the Browse button next to it.
    2. In the File Upload window that opens, click the drop down arrow in the "Look in" box and select your Local Disk.
    3. Click the "Windows" folder and click "Open", use the scroll bar to scroll across and locate the "System32" folder.
    4. Scroll across until you locate the inetsrv folder scroll across again to the inetinfo.exe file and click open.
    5. Now click the Send button. Wait for the results and copy them...then do the same for the other file listed above. Please copy the "Results" to submit with your next reply.


    6. Please run HijackThis again and check the following that may still exist:
      E:\program files\utorrent\utorrent(2).exe
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
      R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
      O1 - Hosts: 64.78.21.111 EHOST011-4
      O1 - Hosts: 64.78.21.111 EHOST011-4.exch011.intermedia.net
      O1 - Hosts: 64.78.21.2 DC011.exch011.intermedia.net
      O1 - Hosts: 64.78.21.94 DC011-1.exch011.intermedia.net
      O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
      O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
      O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
      O4 - HKLM\..\Run: "C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe" /m=0
      O4 - HKLM\..\Run: C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
      O4 - HKCU\..\Run: C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
      O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm103LDUS
      O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversFW BInitialSetup1.0.0.15.cab
      O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?


      Close all windows now except for the HijackThis application's window, then click the Fix Checked button.

      Locate and delete the following files/folders indicated in Bold text:
      C:\Program Files\ MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
      E:\program files\ utorrent\utorrent(2).exe



    Reboot the computer and post a fresh HijackThis log along with the results from your "VirusTotal" scan. Please advise how the system now performs. Thanks kiddo!
  • kdny13

    233 Posts

    419

    0

    Posted May 28th, 2007 18:00

    after following all of your instructions to the letter....(which is why it has taken me so long to reply) - it seems that this post will not let me post the logs and reply to you.  i keep getting message that our posts exceed 20000 characters.  PLEASE ADVISE HOW I CAN GET THIS POST TO YOU...
     
    THANK YOU SO MUCH
    KAREN
  • 1972vet

    3305 Posts

    147

    0

    Posted May 28th, 2007 19:00

    This forum software does behave differently than any other forum where I work and from time to time, it does some odd things.

    Dell management does take it down on occasion and performs maintenance. Perhaps it's due again soon lol.

    Just on a hunch though, open a blank notepad. Click the "Format" tab. If "Word Wrap" has a check next to it then click it to remove the check and close notepad. Next log should post ok.