|
Posted by M Trimble on April 26, 2005, 10:47 pm
If you were Registered and logged in, you could reply and use other advanced thread options On Tue, 26 Apr 2005 17:56:21 +0000, crucialware wrote:
> having serious network problems and got this as my hijack log:
>
> gfile of HijackThis v1.99.1
> Scan saved at 6:54:18 PM, on 4/26/2005 Platform: Windows XP SP2 (WinNT
> 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
>
> Running processes:
> D:\WINDOWS\System32\smss.exe
> D:\WINDOWS\system32\winlogon.exe
> D:\WINDOWS\system32\services.exe
> D:\WINDOWS\system32\lsass.exe
> D:\WINDOWS\system32\Ati2evxx.exe
> D:\WINDOWS\system32\svchost.exe
> D:\WINDOWS\System32\svchost.exe
> d:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
> D:\WINDOWS\system32\ZoneLabs\vsmon.exe
> d:\PROGRA~1\mcafee.com\vso\mcshield.exe D:\WINDOWS\system32\Ati2evxx.exe
> D:\WINDOWS\Explorer.EXE
> D:\PROGRA~1\mcafee.com\agent\mcagent.exe
> D:\PROGRA~1\mcafee.com\vso\mcvsshld.exe D:\Program Files\Zone
> Labs\ZoneAlarm\zlclient.exe d:\progra~1\mcafee.com\vso\mcvsescn.exe
> D:\Program Files\QuickTime\qttask.exe D:\WINDOWS\system32\rundll32.exe
> D:\Program Files\iNTERNET Turbo\iDetect.exe D:\Program Files\iolo\System
> Mechanic 5\StartupGuard.exe C:\program files\valve\steam\steam.exe
> D:\WINDOWS\System32\svchost.exe
> D:\Program Files\iPod\bin\iPodService.exe D:\Program Files\Internet
> Explorer\IEXPLORE.EXE D:\Program Files\Philips\PSA2\skin\qvecplsk.exe
> D:\Program Files\Common Files\Real\Update_OB\realsched.exe D:\Program
> Files\Ventrilo\Ventrilo.exe D:\Program Files\Winamp\winampa.exe
> D:\Program Files\Winamp\Winamp.exe
> D:\Program Files\Soulseek\slsk.exe
> D:\Documents and Settings\Brian\Desktop\HijackThis.exe
>
>
Uhm, no offense, but you´ve got a LOT of stuff running in background. At
a minimum, I´d kill of your Winamp (D:\Program Files\Winamp\winampa.exe
> D:\Program Files\Winamp\Winamp.exe), probably your Real ( D:\Program
> Files\Common Files\Real\Update_OB\realsched.exe) and probably your iPod
(D:\Program Files\iPod\bin\iPodService.exe) services.
Once I´d done that, I´d probably go through and find out what else is
running that isn´t essential. ZoneAlarm, McAffee and similar programs are
necessary. Ditto that for some of the Windows stuff
(d:\windows\system32\*). Everything else, unless it´s a driver, I´d kill
and remove from the startup listing.
Step three would be to reset ZoneAlarm to silently deny most of
everything.
If you do that, you should be fine, and as an added bonus, your machine
should run better/faster, etc.
HTH
M
|