Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
1)Every time i boot winxp-pro a program requests to dial up my internet connection to connect angelfire.com. At this instant the system performance is terribly bad for 5-10 minutes after i cancel the connection or end the rasautou.exe process in taskmgr(so bad that the windows booting tone comes only after these 10 mins)
2)Also initially norton antivirus autoprotect gets automatically disabled every time i boot , though the option "Start Autoprotect when windows starts" is checked ON
3)I ran my virus (Norton 2003 updated 7th jan 2004) protection as well as
SPYBOT 1.1 and it fixed a few things. But the problem is not yet solved
4) Now after spybot etc. 2 moer programs hav started connecting crl.verisign.com and icq.com they appear only 1 at a time (both same as above ie at boot)
5) i hav checked startup options thru msconfig.exe but didnt find any such programs
5) Except this (at startup) pc runs normal ten mins after boot
6)I hv also run hijack-this and saved the log
i wud really appreciate if someone cud PLEASE check the following log
how do i get rid of this problem?Thank you
Logfile of HijackThis v1.97.7
Scan saved at 1:06:05 PM, on 1/13/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\WINDOWS\Explorer.exe
D:\WINDOWS\unin0686.exe
D:\Program Files\Winamp\Winampa.exe
D:\WINDOWS\sm56hlpr.exe
D:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\FreeMem Professional\Fmempro.exe
D:\WINDOWS\System32\ctfmon.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\System32\cisvc.exe
D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\WINDOWS\System32\wbem\wmiapsrv.exe
D:\WINDOWS\system32\NOTEPAD.exe
D:\Program Files\Messenger\msmsgs.exe
D:\PROGRA~1\WINZIP\winzip32.exe
D:\Documents and Settings\amogh\Local Settings\Temp\HijackThis.exeO2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Common\ycomp5_1_3_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Common\ycomp5_1_3_0.dll
O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)
O4 - HKLM\..\Run: [WinampAgent] "D:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [TkBellExe] D:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [ccRegVfy] D:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [ccApp] D:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [COM Services] unin0686.exe
O4 - HKLM\..\Run: [svchost] D:\WINDOWS\SVCHOST .exe
O4 - HKCU\..\Run: [FreeMem Pro] "C:\FreeMem Professional\Fmempro.exe" Startup
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [svchost] D:\WINDOWS\SVCHOST .exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.exe
O8 - Extra context menu item: &Download with &DAP - D:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - D:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXC EL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa ve/cabs/flash/swflash.cab

Read these please
http://www.computing.net/windowsxp/wwwboard/forum/87147.html
http://www.computing.net/security/wwwboard/forum/6433.html
Good luck
V...

Start=>run=> type regedit
Then look in the menu above for "search".
Type "dailer", in the result delete the one or two "rasauto.exe"strings.
Close , run "search and destroy" in advanced mode, reboot and normally the probem is solved.
greetzz

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |