Freezing PC

View previous topic View next topic Go down

Freezing PC

Post by edgaraaa on 19th July 2009, 8:26 pm

My PC (Win Vista) started freezing yesterday. Nod 32 has not found anything. I am almost sure that the freezing is caused by my messing up with the registry, but I want to make it clear that my PC is clean. I am sending my hijackthis log file. Thank you. :smile2:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:15:26, on 19. 7. 2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Volumouse\volumouse.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\Explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\PROGRA~1\IDM\QUICKF~1\PlugIns\IEHelp.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ESET GUI] C:\Program Files\ESET\ESET Smart Security\egui.exe
O4 - HKLM\..\Run: [TOSHIBA Power Saver] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
O4 - HKLM\..\Run: [TfcRst ????—???] C:\Program Files\Toshiba\FlashCards\TfcRst.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Synaptics TouchPad Enhancements] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKCU\..\Run: [HotStartOn] C:\Program Files\Toshiba\TBS\HSON.exe
O4 - HKCU\..\Run: [$Volumouse$] "C:\Program Files\Volumouse\volumouse.exe" /nodlg
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService) - Unknown owner - C:\Program Files\Macrium\Reflect\ReflectService.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe

--
End of file - 4266 bytes

edgaraaa
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-04-03
Gender Gender : Male
Points Points : 28108
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Freezing PC

Post by Origin on 20th July 2009, 3:37 pm

Hello edgaraaa,

Welcome to Geek Police, my name is Origin and I will be helping you today. Please keep the following in mind:

  • If you do not get a reply from me or another helper within 2 days, please reply to your topic with the phrase BUMP
  • If you have any cracked/pirated software in your computer delete them or we will not help you.
  • Only follow advise from Geek Police Staff and not a regular member.
  • Do NOT run any tool without Geek Police supervision as it could hinder your system useless.



Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31503
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Freezing PC

Post by edgaraaa on 21st July 2009, 8:44 am

Hello, Origin. I followed your instuctions and here is the MBAM Log (PC is still freezing):

Malwarebytes' Anti-Malware 1.39
Database version: 2467
Windows 6.0.6002 Service Pack 2

20. 7. 2009 19:52:24
mbam-log-2009-07-20 (19-52-24).txt

Scan type: Quick Scan
Objects scanned: 84454
Time elapsed: 21 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Miracle (Rogue.PerfectOptimizer) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

edgaraaa
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-04-03
Gender Gender : Male
Points Points : 28108
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Freezing PC

Post by Origin on 22nd July 2009, 3:51 pm


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31503
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Freezing PC

Post by edgaraaa on 23rd July 2009, 2:11 pm

I downloaded DDS.scr to my desktop and I ran it, but it did not work:

[You must be registered and logged in to see this link.]

edgaraaa
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-04-03
Gender Gender : Male
Points Points : 28108
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Freezing PC

Post by Origin on 24th July 2009, 7:00 pm

I see, please do the following:

1. If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

2. During the download, rename Combofix to Combo-Fix as follows:





3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.

  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouse click combofix's window whilst it's running. That may cause it to stall.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31503
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Freezing PC

Post by edgaraaa on 26th July 2009, 3:11 pm

I ran ComboFix and here is the log:(it found enabled real-time protection of Spybot Search and Destroy which I uninstalled about 2 months ago)

ComboFix 09-07-25.06 - Peter . 07. 2009 16:16.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1250.421.1051.18.2046.1399 [GMT 2:00]
Running from: c:\users\Peter\Desktop\Combo-Fix.exe
SP: BitDefender Antispyware *disabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Internet Explorer.lnk
c:\windows\system32\mfc45.dll

.
((((((((((((((((((((((((( Files Created from 2009-06-26 to 2009-07-26 )))))))))))))))))))))))))))))))
.

2009-07-26 14:46 . 2009-07-26 14:47 -------- d-----w- c:\users\Peter\AppData\Local\temp
2009-07-26 14:46 . 2009-07-26 14:46 -------- d-----w- c:\users\Ja\AppData\Local\temp
2009-07-23 09:10 . 2009-07-23 09:10 -------- d-----w- c:\program files\MSXML 4.0
2009-07-22 19:53 . 2009-07-22 19:53 -------- d-----w- c:\users\Ja\AppData\Roaming\PC Suite
2009-07-22 19:20 . 2009-07-22 19:20 -------- d-sh--w- c:\users\Peter\Phone Browser
2009-07-22 15:14 . 2009-07-22 15:15 -------- d-----w- c:\users\Ja\AppData\Roaming\Nokia
2009-07-22 15:05 . 2009-07-22 15:05 -------- d-----w- c:\programdata\Nokia
2009-07-22 15:03 . 2009-07-22 14:58 24549792 ----a-w- c:\programdata\Installations\{9F59C3AE-81B0-4EF6-9762-D674BB079705}\NokiaSoftwareUpdaterSetup_sk.exe
2009-07-22 15:03 . 2009-07-22 15:03 3351812 ----a-w- c:\programdata\Installations\{9F59C3AE-81B0-4EF6-9762-D674BB079705}\Installer\CommonCustomActions\msxml6Exec.exe
2009-07-22 15:03 . 2009-07-22 15:03 36864 ----a-w- c:\programdata\Installations\{9F59C3AE-81B0-4EF6-9762-D674BB079705}\Installer\CommonCustomActions\Sleep.exe
2009-07-22 15:03 . 2009-07-22 15:03 3181612 ----a-w- c:\programdata\Installations\{9F59C3AE-81B0-4EF6-9762-D674BB079705}\Installer\CommonCustomActions\vcredistExec.exe
2009-07-22 12:11 . 2009-07-22 12:25 680 ----a-w- c:\users\Peter\AppData\Local\d3d9caps.dat
2009-07-22 10:33 . 2009-07-22 10:33 -------- d-----w- c:\program files\Common Files\PCSuite
2009-07-22 10:32 . 2009-07-24 09:18 -------- d-----w- c:\program files\Common Files\Nokia
2009-07-22 10:30 . 2008-08-26 08:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-07-22 10:30 . 2009-07-22 10:30 -------- d-----w- c:\program files\PC Connectivity Solution
2009-07-22 10:28 . 2009-07-22 10:08 33911376 ----a-w- c:\programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_slk_web.exe
2009-07-22 10:28 . 2009-07-22 10:28 95232 ----a-w- c:\programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-07-22 10:28 . 2009-07-22 10:28 8192 ----a-w- c:\programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-07-22 10:28 . 2009-07-22 10:28 61440 ----a-w- c:\programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-07-22 10:28 . 2009-07-22 10:28 10240 ----a-w- c:\programdata\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-07-21 16:05 . 2009-07-21 16:33 -------- d-----w- c:\users\Peter\AppData\Roaming\PC Suite
2009-07-21 16:05 . 2009-07-21 16:53 -------- d-----w- c:\users\Peter\AppData\Roaming\Nokia
2009-07-21 16:05 . 2009-07-21 16:12 -------- d-----w- c:\programdata\PC Suite
2009-07-21 15:59 . 2009-07-22 10:30 -------- d-----w- c:\program files\DIFX
2009-07-21 15:58 . 2009-07-22 10:30 -------- dc----w- c:\windows\system32\DRVSTORE
2009-07-21 15:53 . 2009-02-09 06:37 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-07-21 15:53 . 2009-07-24 09:18 -------- d-----w- c:\program files\Nokia
2009-07-21 15:51 . 2009-01-01 10:00 52048144 --s-a-w- c:\programdata\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\PC-Suite.exe
2009-07-21 15:50 . 2009-07-21 15:50 8192 ----a-w- c:\programdata\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-07-21 15:50 . 2009-07-21 15:50 61440 ----a-w- c:\programdata\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-07-21 15:50 . 2009-07-21 15:50 10240 ----a-w- c:\programdata\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-07-21 15:49 . 2009-07-22 15:02 -------- d-----w- c:\programdata\Installations
2009-07-21 11:11 . 2007-10-23 07:27 110592 ----a-w- c:\users\Peter\AppData\Roaming\U3\temp\cleanup.exe
2009-07-20 18:21 . 2009-07-20 18:21 -------- d-----w- c:\programdata\McAfee
2009-07-20 18:16 . 2008-05-02 08:41 3493888 ---ha-w- c:\users\Peter\AppData\Roaming\U3\temp\Launchpad Removal.exe
2009-07-20 17:58 . 2009-07-24 16:36 -------- d-----w- c:\users\Peter\AppData\Roaming\U3
2009-07-20 17:24 . 2009-07-20 17:24 -------- d-----w- c:\users\Peter\AppData\Roaming\Malwarebytes
2009-07-20 17:24 . 2009-07-13 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-20 17:24 . 2009-07-20 17:24 -------- d-----w- c:\programdata\Malwarebytes
2009-07-20 17:24 . 2009-07-13 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-20 17:24 . 2009-07-20 17:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-19 20:04 . 2009-07-19 20:04 -------- d-----w- c:\program files\Trend Micro
2009-07-19 19:39 . 2009-07-19 19:39 -------- d-----w- c:\programdata\abelhadigital.com
2009-07-19 12:44 . 2009-07-19 12:44 -------- d-----w- c:\users\Ja\AppData\Local\OziExplorer
2009-07-18 10:00 . 2009-07-18 10:08 -------- d-----w- c:\users\Peter\AppData\Local\TempImages
2009-07-16 16:06 . 2009-07-16 16:06 -------- d-----w- c:\users\Peter\AppData\Roaming\DAEMON Tools Lite
2009-07-16 16:06 . 2009-07-16 16:06 -------- d-----w- c:\users\Peter\AppData\Roaming\DAEMON Tools
2009-07-16 16:05 . 2009-07-16 16:06 -------- d-----w- c:\users\Peter\AppData\Roaming\DAEMON Tools Pro
2009-07-16 16:00 . 2009-07-16 16:00 -------- d-----w- c:\programdata\Macrium
2009-07-16 16:00 . 2009-07-16 16:00 43646 ----a-r- c:\users\Peter\AppData\Roaming\Microsoft\Installer\{3BAD2D97-4900-4014-A2F5-B549802CEEE2}\_E3296CA52D73B98AE9B5F9.exe
2009-07-16 16:00 . 2009-07-16 16:00 43646 ----a-r- c:\users\Peter\AppData\Roaming\Microsoft\Installer\{3BAD2D97-4900-4014-A2F5-B549802CEEE2}\_D707CE1C009F1381803C2C.exe
2009-07-16 16:00 . 2009-07-16 16:00 43646 ----a-r- c:\users\Peter\AppData\Roaming\Microsoft\Installer\{3BAD2D97-4900-4014-A2F5-B549802CEEE2}\_BBCA226959C1D3D63C885B.exe
2009-07-16 16:00 . 2009-07-16 16:00 43646 ----a-r- c:\users\Peter\AppData\Roaming\Microsoft\Installer\{3BAD2D97-4900-4014-A2F5-B549802CEEE2}\_21F3885A18D238E15AAE81.exe
2009-07-16 16:00 . 2009-07-16 16:00 29926 ----a-r- c:\users\Peter\AppData\Roaming\Microsoft\Installer\{3BAD2D97-4900-4014-A2F5-B549802CEEE2}\_EDC08689E679B6EDDC26F8.exe
2009-07-16 16:00 . 2009-07-16 16:00 109534 ----a-r- c:\users\Peter\AppData\Roaming\Microsoft\Installer\{3BAD2D97-4900-4014-A2F5-B549802CEEE2}\_6FEFF9B68218417F98F549.exe
2009-07-16 16:00 . 2009-07-16 16:00 -------- d-----w- c:\program files\Macrium
2009-07-16 12:03 . 2009-07-16 12:03 -------- d-----w- c:\users\Peter\AppData\Roaming\VistaCodecs
2009-07-16 11:26 . 2009-07-16 12:03 -------- d-----w- c:\programdata\VistaCodecs
2009-07-16 09:19 . 2009-07-16 09:23 -------- d-----w- c:\users\Peter\AppData\Roaming\GlarySoft
2009-07-16 08:03 . 2009-07-16 08:03 -------- d-----w- c:\program files\Glary Utilities
2009-07-15 16:42 . 2009-07-15 16:42 -------- d-----w- c:\users\Peter\AppData\Roaming\IObit
2009-07-15 16:42 . 2009-07-15 16:42 -------- d-----w- c:\program files\IObit
2009-07-15 08:14 . 2009-07-15 08:17 -------- d-----w- c:\program files\Shutdown Command
2009-07-15 06:38 . 2009-06-15 14:53 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-07-15 06:38 . 2009-06-15 14:52 23552 ----a-w- c:\windows\system32\lpk.dll
2009-07-15 06:38 . 2009-06-15 14:52 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-07-15 06:38 . 2009-06-15 14:51 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-07-15 06:38 . 2009-06-15 12:42 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-07-14 18:27 . 2007-06-05 09:26 56496 ----a-w- c:\windows\system32\wbhelp2.dll
2009-07-14 08:21 . 2009-07-14 08:21 -------- d-----w- c:\users\Peter\AppData\Roaming\KoshyJohn.com
2009-07-14 08:21 . 2009-07-14 08:19 771469 ----a-w- c:\users\Peter\AppData\Roaming\KoshyJohn.com\DiskMax\DiskMax.exe
2009-07-11 01:51 . 2009-07-11 01:51 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-07-10 13:44 . 2009-07-10 13:44 -------- d-----w- c:\users\Peter\AppData\Local\Help
2009-07-08 10:15 . 2009-07-08 10:15 -------- d-----w- c:\program files\uTorrent
2009-07-08 10:14 . 2009-07-24 16:36 -------- d-----w- c:\users\Peter\AppData\Roaming\uTorrent
2009-07-08 08:47 . 2009-07-08 08:47 -------- d-----w- c:\users\Peter\AppData\Roaming\vlc
2009-07-07 13:05 . 2009-07-07 13:05 -------- d-----w- c:\users\Peter\AppData\Roaming\ATI
2009-07-07 13:05 . 2009-07-07 13:05 -------- d-----w- c:\users\Peter\AppData\Local\ATI
2009-07-07 10:44 . 2009-07-07 10:44 -------- d-----w- c:\users\Peter\AppData\Local\ESET
2009-07-07 10:26 . 2009-07-16 11:27 -------- d-----w- c:\program files\VistaCodecPack
2009-07-06 16:18 . 2009-07-06 16:18 -------- d-----w- c:\users\Ja\AppData\Local\Adobe
2009-07-06 13:19 . 2009-07-24 14:59 -------- d-----w- c:\users\Peter\AppData\Local\MyDownloader
2009-07-06 10:21 . 2009-07-06 10:21 1003520 ----a-w- c:\windows\system32\VSFilter.dll
2009-07-06 08:59 . 2009-07-06 09:00 -------- d-----w- c:\users\Peter\AppData\Local\Adobe
2009-07-03 15:44 . 2009-07-03 15:44 -------- d-----w- c:\users\Peter\AppData\Roaming\ICQ
2009-07-03 15:44 . 2009-07-09 10:28 -------- d-----w- c:\users\Peter\AppData\Roaming\Skype
2009-07-03 13:45 . 2009-07-03 13:45 -------- d-----w- c:\program files\Common Files\Nitro PDF
2009-07-03 13:45 . 2009-07-03 13:45 -------- d-----w- c:\program files\Common Files\BCL Technologies
2009-07-03 13:37 . 2009-07-03 13:37 -------- d-----w- c:\users\Peter\AppData\Local\Toshiba
2009-07-03 12:50 . 2009-07-03 12:50 -------- d-----w- c:\users\Peter\AppData\Roaming\toshiba
2009-07-03 11:23 . 2009-07-03 11:23 -------- d-----w- c:\users\Peter\AppData\Local\lpd
2009-07-03 11:23 . 2009-07-03 11:23 -------- d-----w- c:\users\Peter\AppData\Roaming\lpd
2009-07-03 11:23 . 2009-07-05 14:05 -------- d-----w- c:\users\Peter\AppData\Roaming\LangSoft
2009-07-03 11:23 . 2009-07-03 11:23 -------- d-----w- c:\users\Peter\AppData\Roaming\TheSage
2009-07-03 11:22 . 2009-07-03 11:23 -------- d-----w- c:\users\Peter\AppData\Roaming\oald7
2009-07-03 11:22 . 2009-07-05 14:14 -------- d-----w- c:\users\Peter\AppData\Roaming\cald3
2009-07-03 11:22 . 2009-07-03 11:22 -------- d-----w- c:\users\Peter\AppData\Local\cald3
2009-07-03 11:10 . 2009-07-03 11:10 -------- d-----w- c:\users\Peter\AppData\Roaming\Nitro PDF
2009-07-03 10:46 . 2009-07-03 10:46 -------- d-----w- c:\users\Peter\AppData\Local\Mozilla
2009-07-01 19:49 . 2009-07-02 09:30 81984 ----a-w- c:\windows\system32\bdod.bin
2009-07-01 08:47 . 2009-07-01 08:48 -------- d-----w- c:\windows\system32\ca-ES
2009-07-01 08:47 . 2009-07-01 08:48 -------- d-----w- c:\windows\system32\eu-ES
2009-07-01 08:46 . 2009-07-01 08:47 -------- d-----w- c:\windows\system32\vi-VN
2009-07-01 08:26 . 2009-07-01 08:26 -------- d-----w- c:\windows\system32\EventProviders
2009-07-01 08:20 . 2009-04-11 06:28 203264 ----a-w- c:\windows\system32\uDWM.dll
2009-07-01 08:19 . 2009-04-11 06:28 60416 ----a-w- c:\windows\system32\msscntrs.dll
2009-07-01 08:18 . 2009-04-11 06:28 85504 ----a-w- c:\windows\system32\msctfui.dll
2009-07-01 08:17 . 2009-04-11 06:28 218624 ----a-w- c:\windows\system32\wdscore.dll
2009-07-01 08:17 . 2009-04-11 06:27 130560 ----a-w- c:\windows\system32\PkgMgr.exe
2009-07-01 08:17 . 2009-04-11 06:28 247808 ----a-w- c:\windows\system32\drvstore.dll
2009-06-28 14:41 . 2009-06-28 14:45 -------- d-----w- c:\programdata\Apple Computer
2009-06-28 14:28 . 2009-06-28 14:28 -------- d-----w- c:\program files\Oxford
2009-06-26 18:08 . 2009-06-26 18:08 -------- d-----w- c:\programdata\Nitro PDF
2009-06-26 17:54 . 2009-04-24 02:55 176235 ----a-w- c:\windows\system32\Primomonnt.dll
2009-06-26 17:54 . 2009-07-23 16:33 -------- d-----w- c:\program files\Nitro PDF

.

edgaraaa
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-04-03
Gender Gender : Male
Points Points : 28108
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Freezing PC

Post by edgaraaa on 26th July 2009, 3:12 pm

Second part of the log:

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-26 14:17 . 2009-04-04 14:38 42110 ----a-w- c:\windows\system32\perfh01B.dat
2009-07-26 14:17 . 2009-04-04 14:38 12532 ----a-w- c:\windows\system32\perfc01B.dat
2009-07-26 13:31 . 2009-05-16 11:27 -------- d-----w- c:\users\Ja\AppData\Roaming\Skype
2009-07-26 11:30 . 2009-05-16 11:27 -------- d-----w- c:\users\Ja\AppData\Roaming\skypePM
2009-07-24 15:01 . 2009-05-13 21:22 -------- d-----w- c:\program files\P o r t a b l e p r o g r a m y
2009-07-22 10:48 . 2009-07-22 10:48 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2009-07-21 16:12 . 2009-07-21 16:12 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_05_00.Wdf
2009-07-21 14:52 . 2009-07-21 14:52 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-07-19 14:56 . 2009-06-01 20:51 -------- d-----w- c:\users\Ja\AppData\Roaming\uTorrent
2009-07-18 12:41 . 2009-05-11 22:08 71608 ----a-w- c:\users\Ja\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-17 16:54 . 2009-07-03 10:16 71608 ----a-w- c:\users\Peter\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-17 16:42 . 2009-04-05 13:42 -------- d-----w- c:\programdata\Microsoft Help
2009-07-10 10:56 . 2009-05-02 15:30 -------- d-----w- c:\program files\Longman
2009-07-08 19:22 . 2009-04-11 09:50 -------- d-----w- c:\program files\QuickTime
2009-07-08 13:29 . 2008-03-17 14:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-08 12:47 . 2008-03-17 14:56 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-07 15:22 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-07-07 08:10 . 2008-03-17 14:47 -------- d-----w- c:\program files\Java
2009-07-06 08:59 . 2008-03-17 15:20 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-01 08:48 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-07-01 08:48 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-01 08:48 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-07-01 08:48 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-07-01 08:48 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-07-01 08:46 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-07-01 08:39 . 2006-11-02 12:37 37665 ----a-w- c:\windows\Fonts\GlobalUserInterface.CompositeFont
2009-06-21 15:28 . 2008-03-17 14:52 -------- d-----w- c:\program files\CONEXANT
2009-06-21 15:26 . 2008-10-28 14:49 188416 ----a-w- c:\windows\system32\drivers\CHDRT32.sys
2009-06-21 15:26 . 2008-07-29 23:26 249856 ----a-w- c:\windows\system32\UCI32A34.dll
2009-06-18 14:40 . 2009-06-18 14:40 -------- d-----w- c:\users\Ja\AppData\Roaming\LangSoft
2009-06-13 13:52 . 2009-06-13 13:52 -------- d-----w- c:\users\Ja\AppData\Roaming\KoshyJohn.com
2009-06-13 10:50 . 2009-04-25 14:00 -------- d-----w- c:\windows\Fonts\DoulosSIL
2009-06-10 20:04 . 2009-06-10 20:04 -------- d-----w- c:\program files\Total Video Converter
2009-06-10 10:32 . 2009-06-10 10:32 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_Apfiltr_01005.Wdf
2009-06-09 18:11 . 2009-05-26 11:15 -------- d-----w- c:\program files\Volumouse
2009-06-05 18:10 . 2009-06-13 13:52 771469 ----a-w- c:\users\Ja\AppData\Roaming\KoshyJohn.com\DiskMax\DiskMax.exe
2009-06-02 21:28 . 2009-06-02 21:13 88 --sh--r- c:\programdata\01AC8953C7.sys
2009-06-02 21:28 . 2009-06-02 21:13 88 --sh--r- c:\programdata\01AC8953C7.sys
2009-06-02 18:06 . 2008-03-17 15:16 -------- d-----w- c:\programdata\Toshiba
2009-05-31 20:08 . 2009-05-11 22:51 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-05-31 20:08 . 2009-05-06 19:18 -------- d-----w- c:\program files\Common Files\Stardock
2009-05-31 20:08 . 2009-04-09 08:35 -------- d-----w- c:\program files\DesiatimiPrstami
2009-05-31 20:08 . 2009-04-05 10:38 -------- d-----w- c:\program files\Common Files\Skype
2009-05-31 20:08 . 2009-04-04 10:56 -------- d-----w- c:\program files\Camera Assistant Software for Toshiba
2009-05-31 20:07 . 2009-05-28 14:43 -------- d-----w- c:\program files\Microsoft Works
2009-05-31 20:07 . 2009-04-05 10:04 -------- d-----w- c:\program files\ICQ6.5
2009-05-30 19:22 . 2009-04-11 09:50 -------- d-----w- c:\programdata\QuickTime
2009-05-29 14:52 . 2009-05-29 14:52 204800 ----a-w- c:\windows\system32\xvidvfw.dll
2009-05-29 14:47 . 2009-05-29 14:47 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-05-28 16:19 . 2008-03-17 15:02 -------- d-----w- c:\program files\Toshiba
2009-05-28 14:42 . 2009-05-28 14:42 -------- d-----w- c:\program files\Microsoft.NET
2009-05-28 12:36 . 2008-03-17 13:02 2125312 ----a-w- c:\windows\system32\CnxtAp32.dll
2009-05-26 14:31 . 2009-05-26 14:31 23 --sha-w- c:\windows\system32\edacded0.dat
2009-05-26 11:15 . 2009-05-26 11:15 39424 ----a-w- c:\windows\zipinst.exe
2009-05-25 20:04 . 2009-05-25 20:04 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-05-21 09:33 . 2009-04-04 11:08 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-20 00:02 . 2009-04-13 22:24 299008 ----a-w- c:\programdata\LangSoft\TrnWord.dll
2009-05-14 13:49 . 2009-05-14 13:49 38240 ----a-w- c:\windows\system32\drivers\epfwwfp.sys
2009-05-14 13:49 . 2009-05-14 13:49 33096 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2009-05-14 13:49 . 2009-05-14 13:49 133000 ----a-w- c:\windows\system32\drivers\epfw.sys
2009-05-14 13:41 . 2009-05-14 13:41 114472 ----a-w- c:\windows\system32\drivers\eamon.sys
2009-05-11 20:36 . 2009-04-05 15:45 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-05-11 10:47 . 2009-05-11 10:47 1302600 ----a-w- c:\windows\system32\WUDFUpdate_01007.dll
2009-05-09 05:50 . 2009-06-10 10:09 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-10 10:09 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-05-06 19:04 . 2009-05-06 19:04 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-07-17 06:48 . 2009-04-04 15:25 137208 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"Synaptics TouchPad Enhancements"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416]
"HotStartOn"="c:\program files\Toshiba\TBS\HSON.exe" [2007-10-31 54608]
"$Volumouse$"="c:\program files\Volumouse\volumouse.exe" [2009-03-15 31744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TfcRst ????—???"="c:\program files\Toshiba\FlashCards\TfcRst.exe" [?]
"TOSHIBA Power Saver"="c:\program files\Toshiba\Power Saver\TPwrMain.exe" [2008-01-17 431456]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-05-14 2029640]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 2 (0x2)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRealMode"= 0 (0x0)
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):e8,28,01,88,29,fa,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1770975144-4268453387-985056479-1000]
"EnableNotificationsRef"=dword:00000002

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1770975144-4268453387-985056479-1001]
"EnableNotificationsRef"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-350281380-233495102-1455855570-1000]
"EnableNotificationsRef"=dword:0000000b

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-350281380-233495102-1455855570-1001]
"EnableNotificationsRef"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-350281380-233495102-1455855570-1004]
"EnableNotificationsRef"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-350281380-233495102-1455855570-1009]
"EnableNotificationsRef"=dword:00000003

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{93F08813-CA83-4B8D-81D5-5E0D293B58EF}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{35B69D28-54AF-4B50-82BF-FB5A21C8B399}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{1FC463B9-3605-41BF-B3E8-FC3F84CD533C}"= c:\program files\Skype\Phone\Skype.exe:Skype

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 pssnap;Paramount Software Snapshot Filter;c:\windows\System32\drivers\pssnap.sys [20. 5. 2008 8:32 15328]
R1 ElRawDisk;ElRawDisk;c:\windows\System32\drivers\elrawdsk.sys [23. 5. 2009 22:11 20392]
R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\System32\drivers\RtlProt.sys [4. 4. 2009 13:17 25896]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [14. 5. 2009 15:47 731840]
R2 epfwwfp;epfwwfp;c:\windows\System32\drivers\epfwwfp.sys [14. 5. 2009 15:49 38240]
R2 ReflectService;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [6. 8. 2008 11:34 216032]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\Toshiba\SMARTLogService\TosIPCSrv.exe [3. 12. 2007 17:03 126976]
R3 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [15. 1. 2008 11:34 48472]
R3 QIOMem;Generic IO & Memory Access;c:\windows\System32\drivers\QIOMem.sys [9. 4. 2007 17:13 8192]
R3 RTL8187B;Sieťový adaptér bezdrôtového pripojenia RTL8187B Wireless 802.11b/g 54Mbps USB 2.0;c:\windows\System32\drivers\rtl8187B.sys [4. 4. 2009 13:01 290304]
S4 DrWebEngine;Dr.Web Scanning Engine (DrWebEngine);"c:\program files\Common Files\Doctor Web\Scanning Engine\dwengine.exe" --> c:\program files\Common Files\Doctor Web\Scanning Engine\dwengine.exe [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Nitro PDF Professional]
cscript //B "c:\program files\Nitro PDF\Professional\RemoveOldAddins.vbs"
.
Contents of the 'Scheduled Tasks' folder

2009-07-23 c:\windows\Tasks\At1.job
- c:\windows\system32\shutdown.exe [2009-04-04 07:33]

2009-07-26 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-07-16 14:55]

2009-07-25 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-07-15 07:22]

2009-07-26 c:\windows\Tasks\User_Feed_Synchronization-{B2CC1751-A132-4EA2-B5EE-3EEC03061991}.job
- c:\windows\system32\msfeedssync.exe [2009-05-08 11:31]
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)


.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-07-26 16:47
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-07-26 17:01
ComboFix-quarantined-files.txt 2009-07-26 15:00

Pre-Run: 43 909 324 800 bytes free
Post-Run: 43 872 997 376 bytes free

312 --- E O F --- 2009-07-24 14:11

edgaraaa
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-04-03
Gender Gender : Male
Points Points : 28108
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Freezing PC

Post by Belahzur on 26th July 2009, 5:57 pm

Hello.
Please post a new Hijack This log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Freezing PC

Post by edgaraaa on 26th July 2009, 7:08 pm

Hello, here is that log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:05:48, on 26. 7. 2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Volumouse\volumouse.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Windows\system32\conime.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\PROGRA~1\IDM\QUICKF~1\PlugIns\IEHelp.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [TOSHIBA Power Saver] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
O4 - HKLM\..\Run: [TfcRst ????—???] C:\Program Files\Toshiba\FlashCards\TfcRst.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Synaptics TouchPad Enhancements] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKCU\..\Run: [HotStartOn] C:\Program Files\Toshiba\TBS\HSON.exe
O4 - HKCU\..\Run: [$Volumouse$] "C:\Program Files\Volumouse\volumouse.exe" /nodlg
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
O23 - Service: Macrium Reflect Image Mounting Service (ReflectService) - Unknown owner - C:\Program Files\Macrium\Reflect\ReflectService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe

--
End of file - 4262 bytes

edgaraaa
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-04-03
Gender Gender : Male
Points Points : 28108
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Freezing PC

Post by Belahzur on 26th July 2009, 8:50 pm

Hello.
Lets stop some things that aren't really needed from running.

Do you use Volumemouse? it is set for running on startup and isn't really needed for that. You can start it manually via the start menu

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe


  • Press "Fix Checked"
  • Close Hijack This.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Freezing PC

Post by edgaraaa on 26th July 2009, 9:07 pm

Hello. I use Volumouse and therefore it's on the startup list. I fixed those two things.

edgaraaa
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-04-03
Gender Gender : Male
Points Points : 28108
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Freezing PC

Post by edgaraaa on 26th July 2009, 9:32 pm

Hello, Origin, it's me again. As I first wrote in this post, I wanted to make sure that my computer isn't infected with a virus causing it to work slower. So if you can assure me that there is now no infection in my PC, I think there's no point in trying to make my computer work better by applying tweaks such as removing unneeded startup entries. I have tried many tweaks and registry cleaners before and I think some of them made damage to my registry and this causes the freezing. What do you think about it? I know that you are far more experienced in these things than I am Let me think

edgaraaa
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-04-03
Gender Gender : Male
Points Points : 28108
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Freezing PC

Post by Belahzur on 27th July 2009, 9:25 pm

Hello.
The logs look fine, no outstanding problems.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Freezing PC

Post by edgaraaa on 28th July 2009, 9:34 am

Okay then. I'm gonna reinstall Windows because it's making me mad. Thank you for your help and your time. Thank You!

edgaraaa
Novice
Novice

Posts Posts : 15
Joined Joined : 2009-04-03
Gender Gender : Male
Points Points : 28108
# Likes # Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum