PDA

View Full Version : Tell me whats wrong.


V
01-08-2009, 08:29 PM
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:10:25 PM, on 1/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\mHotkey.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 7.exe
C:\WINDOWS\system32\hphmon04.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Styler\Styler.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 7.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - Startup: Styler.lnk = ?
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1227391021202
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

--
End of file - 4611 bytes


GO!

Sargeant27
01-08-2009, 08:36 PM
Logfile of Trend Micro HijackThis v2.02
0.2
--
End of file - 4611 bytes


GO!

Could that have something to do with it? o_o

wut
01-08-2009, 08:48 PM
Could that have something to do with it? o_o

Hijackthis is an anti-malware program.

>_>

brohana
01-09-2009, 01:41 AM
C:\WINDOWS\mHotkey.exe



Only thing I saw that i wasnt sure what it was.

EDIT: Disregard, it is a simple keyboard process


Other then that, I didn't see anything wrong with it

Cobra
01-09-2009, 02:16 AM
I have to agree w/ Bro on this one, i dont see anything wronge/out of the ordinary....

V
01-09-2009, 02:57 AM
Then 'splain why it randomly logs me off/shuts down my computer.

Cobra
01-09-2009, 03:36 AM
Then 'splain why it randomly logs me off/shuts down my computer.

GEE THANKS FOR EXPLAINING YOUR ISSUE IN THE FIRST POST
Now, on to your issue, fill this out

Computer(brand/model):
OS (if you use multiple then list both):
Laptop/Desktop:
Internet Connection (do you have a router? if so what):
Display type(what is your screen/how big):
Graphics/Video Card:

Eiliosdraye
01-09-2009, 10:01 AM
Gto, that can be contributed to Windows Updates. They're real pains in the...

V
01-09-2009, 03:35 PM
Well, the computer that is having the problems... is

an Emachines T2200

Xp Home Edition, SP3

Linksys Router, WEP Protected.

Amd Athlon XP 2200+ 1.79ghz, 512MB

Monitors and Graphics Card are completely irrelevant.

I have automatic windows updates turned off.

V
01-09-2009, 11:39 PM
Problem persists, think I didn't think of that?

wut
01-09-2009, 11:48 PM
This looks fishy.

O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe

arabftw123
01-10-2009, 02:14 AM
This looks fishy.

O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe

Nothing malicious about it. A process run by HP, my guess would be his printer?

And V, I'm assuming you've already tried reinstalling?

V
01-10-2009, 02:54 AM
Reinstalling what........

If you mean reformatting/reinstalling my os, then yes. I have.

Possibly just a hardware failure, don't really wanna put money into a new computer right now, but chances are that I might.

brohana
01-10-2009, 04:55 AM
I'm actually thinking it could be a hardware problem, my old laptop overheated often and randomly crashed/restarted.

I would invest in a new computer, cause you have a *gag* emachine.

zenga
01-10-2009, 04:59 AM
I'm actually thinking it could be a hardware problem, my old laptop overheated often and randomly crashed/restarted.

I would invest in a new computer, cause you have a *gag* emachine.

lol i would check with the Cobra he seems really hight tech.

Eiliosdraye
01-10-2009, 11:29 AM
lol i would check with the Cobra he seems really hight tech.
No, Cobra is still learning.



V, drop us a Dxdiag report here, I might be able to compare it to some other stuff and check if your computer hardware is to blame.

Cobra
01-10-2009, 01:42 PM
-OFFSUBJECT- >.>

No, Cobra is still learning.


o.O i'm still learning some of teh programing languages i'm good w/ fixing computers

-ONSUBJECT-

o.O you could be having the same issue i had with my old Desktop, it whould randomly shut off and log on due to the video card getting overheated (why it restarted if its over heated idk) but it would do that so we replaced the video card and smooth sailing after taht for about 2 weeks then the screen went out -.-" (it was a built together cpu & moniter) so now it sits in the dinning room :D and we all have new laptops

^^^see graphics card ISNT IRRELIVANT THATS WHY I WAS ASKING^^^ -.-" :D

V
01-10-2009, 08:54 PM
It is irrelevant.

Period.

The computer is quite old.

If you didn't date it when I said 1.79 mhz, then... well you fail.

*sigh*

*goes to buy new computer*

=\