Computing.Net > Forums > Security and Virus > Strange Behaviour

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Click here to start participating now! Also, check out the New User Guide.

Strange Behaviour

Reply to Message Icon

Name: hugh90
Date: December 30, 2003 at 03:20:23 Pacific
OS: Windows XP
CPU/Ram: Althlon 1800/512Meg
Comment:

Hi guys, I have run into a bit of a brick wall with some problems with both Explorer and Internet Explorer.

When I go to start, search, all files and folders nothing happens, and explorer sometimes locks up and has to be restarted.

In Internet Explorer I can't use the 'Open in new window' function. This results in an IE lockup and occasionally svchost.exe going a bit mad with the CPU. I can shut them both down then start again etc.

I am running the latest McAfee which finds nothing. I have run Spybot search and destroy and Hijack this and removed anything suspect.

I have tried turning off my firewall but to no avail.

My most recent step was to repair my XP installation from the CD, but the problem still remains. Any advice would be appreciated.

Logfile of HijackThis v1.97.7
Scan saved at 11:12:02, on 30/12/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINDOWS\System32\CTSvcCDA.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\runservice.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\WINDOWS\system32\ZoneLabs\minilog.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Creative\Audio2K\PROGRAM\CTMIX32.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\McAfee\McAfee VirusScan\AlogServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Hugh\Desktop\hijackthis\HijackThis.exe

N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.google.com"); (C:\Documents and Settings\Hugh\Application Data\Mozilla\Profiles\default\gkqbxgiw.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_02.src"); (C:\Documents and Settings\Hugh\Application Data\Mozilla\Profiles\default\gkqbxgiw.slt\prefs.js)
O2 - BHO: (no name) - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - C:\Program Files\DAP\DAPIEBar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar.dll
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\Program Files\McAfee\McAfee VirusScan\VSCShellExtension.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [CreativeMixer] C:\Program Files\Creative\Audio2K\PROGRAM\CTMIX32.exe /t
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\GoogleToolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\GoogleToolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\GoogleToolbar.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\GoogleToolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page - res://C:\WINDOWS\GoogleToolbar.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020124/qtinstall.info.apple.com/qt505/uk/win/QuickTimeInstaller.exe
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{96B49296-0DB2-468B-B15D-8EA7A7DBDEC5}: NameServer = 213.208.106.212 213.208.106.213
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = tay.ac.uk
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = tay.ac.uk
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = tay.ac.uk




Sponsored Link
Ads by Google

Response Number 1
Name: hacad
Date: December 30, 2003 at 06:12:45 Pacific
Reply:

C:\Program Files\Internet Explorer\iexplore.exe
iexplorer is not a typical startup program unless you want it to open at startup. Usually a line that is added via a virus or spyware.

Other than that I do not see anything maybe someone else will notice something.

Looks like Netscape is your default browser (my preference) although I do not have the N3 Lines as you do.

could try you tweaking your network connections as your on a satellite network?
I removed the QoS Packet Scheduler from my Internet connections and seemed to speed things up a bit.

Also try running DrWatson while you open I.E. and see if it comes up with anything.



0

Response Number 2
Name: hugh90
Date: December 30, 2003 at 06:44:40 Pacific
Reply:

Slightly bizarre development in that the problems mentioned appear to have disappeared even though I haven't performed any additional fixes. Not sure exactly what to make of that.

Will see how things go in the meantime.


0

Response Number 3
Name: iceblue
Date: December 30, 2003 at 20:39:04 Pacific
Reply:

It does sound like conflict rather than hijack.
Download Accelerator Plus can go on the strength of this link;
http://www.safersite.com/PestInfo/d/download_accelerator_plus.asp

Have HijackThis fix checked that one item:
O2 - BHO: (no name) - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - C:\Program Files\DAP\DAPIEBar.dll

One definite item is to update your windows and IE from windowsupdates. No point having a system that is underprotected - too many serious problems out there.

hth
iceblue


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


VX2/? What is this? Am I ... Need Help Spybot B&K



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Strange Behaviour

Trojan? Help.. Strange Behaviour www.computing.net/answers/security/trojan-help-strange-behaviour/8208.html

VERY annoying virus/malware www.computing.net/answers/security/very-annoying-virusmalware/19512.html

text fields get filled with xxxxx www.computing.net/answers/security/text-fields-get-filled-with-xxxxx/1596.html