1
   

my c still freezez

 
 
Ulitk-
 
Reply Thu 1 Jul, 2004 10:32 am
hey

i updated my AV ran it, didnt find anything.
ran ad aware and spybot - cleaned some things but still everytime i ran them they find more and more...

my pc still freezez after 10 mins...
plz help.

log:

Logfile of HijackThis v1.98.0
Scan saved at 7:30:19 PM, on 7/1/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Barak013\fts.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\SpyKiller\spykiller.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\Microsoft Office\Office10\POWERPNT.EXE
C:\Program Files\Barak013\FWPortal.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Inna Miznikov\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bgu.ac.il/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.bgu.ac.il/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [%FP%Barak013 fts.exe] "C:\Program Files\Barak013\fts.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\RunServices: [RDLL] RunDll16.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {8FE29136-4B85-4991-B55B-18B1B07B1DCA} (DragDropUploadPictor.UploadCtl) - http://www.pictor.co.il/Upload/DragDropUploadPictor.CAB
O16 - DPF: {BDD2F926-8158-4F62-9E0D-B3B75FD1F07F} (McObjectFactory Class) - http://download.mcafee.com/molbin/shared/McMySec/en-us/1,0,0,2/mcmysec.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.pic.co.il/XUpload.ocx
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4371/mcfscan.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5BFECE84-18B5-47AE-87E6-673BC03AA17C}: NameServer = 212.150.49.10 206.49.94.234
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 695 • Replies: 1
No top replies

 
Craven de Kere
 
  1  
Reply Thu 1 Jul, 2004 12:21 pm
Re: my c still freezez
1) Uninstall any junk you have that you are able to uninstall. By this I mean silly programs that you don't really need (freeware).

2) Follow these instructions. If I tell you to delete feel free to make a backup on removeable media in case I am wrong.

Ulitk@ wrote:

C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe


I do not recognize but it looks fishy. Investigate (see if it's something you know you installed, run it and see what happens...)

If unecessary uninstall or if that'snot possible kill the process and delete the file.

Quote:
C:\Program Files\Barak013\fts.exe


kill and delete

Quote:
C:\Program Files\Microsoft Office\Office10\POWERPNT.EXE


Dude, when you post these logs close all programs you can (that you know are good).

Quote:
C:\Program Files\Barak013\FWPortal.exe


Kill and delete, tell us what else is in that folder.

Quote:
C:\Program Files\ICQLite\ICQLite.exe


If this is something you want then get it off before posting logs, otherwise you make us investigate needlessly.

Quote:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bgu.ac.il/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.bgu.ac.il/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,


Fix

Quote:
O4 - HKLM\..\Run: [%FP%Barak013 fts.exe] "C:\Program Files\Barak013\fts.exe"


Fix and delete the exe file


Quote:
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup


Fix and delete the exe file

Quote:
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start


Fix, I'd delete as well.

Quote:
O4 - HKLM\..\RunServices: [RDLL] RunDll16.exe


Fix and delete

This is the same file as contained in a virus that allows hackers to control your computer through IRC.

More on the virus:

http://www.symantec.com/avcenter/venc/data/backdoor.sdbot.f.html

What IRC clients do you have? The ICQ you had now sounds like an even better idea to uninstall (especially if it has IRC, I will not be installing just to find out for you).


Quote:
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup


I just point and laugh, so many of the logs I help people with contain this useless software.

Quote:
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot


Fix at least, look into uninstalling and/or deleting.

Quote:
O16 - DPF: {8FE29136-4B85-4991-B55B-18B1B07B1DCA} (DragDropUploadPictor.UploadCtl) - http://www.pictor.co.il/Upload/DragDropUploadPictor.CAB


Fix


Quote:
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://www.pic.co.il/XUpload.ocx


Fix


Quote:

O17 - HKLM\System\CCS\Services\Tcpip\..\{5BFECE84-18B5-47AE-87E6-673BC03AA17C}: NameServer = 212.150.49.10 206.49.94.234


Fix



3) when you are done, reboot and tell us what happens.
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » my c still freezez
Copyright © 2025 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.03 seconds on 12/23/2025 at 04:10:16