Re: HELP!!!! need help with hijack log results

From: M Trimble (user_at_127.0.0.1)
Date: 04/27/05


Date: Tue, 26 Apr 2005 22:47:55 -0500

On Tue, 26 Apr 2005 17:56:21 +0000, crucialware wrote:

> having serious network problems and got this as my hijack log:
>
> gfile of HijackThis v1.99.1
> Scan saved at 6:54:18 PM, on 4/26/2005 Platform: Windows XP SP2 (WinNT
> 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
>
> Running processes:
> D:\WINDOWS\System32\smss.exe
> D:\WINDOWS\system32\winlogon.exe
> D:\WINDOWS\system32\services.exe
> D:\WINDOWS\system32\lsass.exe
> D:\WINDOWS\system32\Ati2evxx.exe
> D:\WINDOWS\system32\svchost.exe
> D:\WINDOWS\System32\svchost.exe
> d:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
> D:\WINDOWS\system32\ZoneLabs\vsmon.exe
> d:\PROGRA~1\mcafee.com\vso\mcshield.exe D:\WINDOWS\system32\Ati2evxx.exe
> D:\WINDOWS\Explorer.EXE
> D:\PROGRA~1\mcafee.com\agent\mcagent.exe
> D:\PROGRA~1\mcafee.com\vso\mcvsshld.exe D:\Program Files\Zone
> Labs\ZoneAlarm\zlclient.exe d:\progra~1\mcafee.com\vso\mcvsescn.exe
> D:\Program Files\QuickTime\qttask.exe D:\WINDOWS\system32\rundll32.exe
> D:\Program Files\iNTERNET Turbo\iDetect.exe D:\Program Files\iolo\System
> Mechanic 5\StartupGuard.exe C:\program files\valve\steam\steam.exe
> D:\WINDOWS\System32\svchost.exe
> D:\Program Files\iPod\bin\iPodService.exe D:\Program Files\Internet
> Explorer\IEXPLORE.EXE D:\Program Files\Philips\PSA2\skin\qvecplsk.exe
> D:\Program Files\Common Files\Real\Update_OB\realsched.exe D:\Program
> Files\Ventrilo\Ventrilo.exe D:\Program Files\Winamp\winampa.exe
> D:\Program Files\Winamp\Winamp.exe
> D:\Program Files\Soulseek\slsk.exe
> D:\Documents and Settings\Brian\Desktop\HijackThis.exe
>
>
Uhm, no offense, but you´ve got a LOT of stuff running in background. At
a minimum, I´d kill of your Winamp (D:\Program Files\Winamp\winampa.exe
> D:\Program Files\Winamp\Winamp.exe), probably your Real ( D:\Program
> Files\Common Files\Real\Update_OB\realsched.exe) and probably your iPod
(D:\Program Files\iPod\bin\iPodService.exe) services.

Once I´d done that, I´d probably go through and find out what else is
running that isn´t essential. ZoneAlarm, McAffee and similar programs are
necessary. Ditto that for some of the Windows stuff
(d:\windows\system32\*). Everything else, unless it´s a driver, I´d kill
and remove from the startup listing.

Step three would be to reset ZoneAlarm to silently deny most of
everything.

If you do that, you should be fine, and as an added bonus, your machine
should run better/faster, etc.

HTH
M



Relevant Pages

  • RE: IE default Page
    ... trojan, per housecall.antivirus.com's virus scanner. ... kill off those services (regedit and delete the references after you ... run hijackthis and kill whatever you see that doesn't belong ... threads and/or system services that watch the system processes and ...
    (Incidents)
  • Re: Restarting the computer programmatically
    ... As far as I know, if You wanted a guaranteed reboot, the only approach ... is load all the current running processes that are running and start ... always request the customer to restart the machine carefully. ... If you want code for get all the processes and kill them one after ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: Shutdown Problems
    ... running processes in addition to anything on the applications tab. ... repeat the process and kill a few more. ... I have serious problems shutting down my Windows XP Home pc with Service ...
    (microsoft.public.windowsxp.basics)
  • Re: How to kill hidden winlogon processes
    ... Do you know of a third party tool ... | that shows ALL the running processes and allows me to kill which ones ... yet require a ustility to kill an undefinded Winlogon Process. ... in a virtual machine: ...
    (microsoft.public.windowsxp.general)
  • Re: top command question
    ... Right now I'm trying to find all running processes in 'top' by command ... 'iperf', I have an iperf daemon running and I need to find the PID for ... it in the list so I can kill it with. ...
    (Ubuntu)