i never do a serious maintenance, i have good reasons:
1)im lazy
2)have alot of things to do like play games , sleeping, and eating
3) dont know how to do it
i have done with the defrag
i cant remove NORTON beacuse i cant go to the add/remove program in the Control Panel
i go to Start > All Programs > Accessories > System Tools > System restore then a message said c:\window\system32\Restore\rstrui.exe is unkpwn appication or dameaged,also my AVG is only trail version only have 57 days left
for your question
Quote:
|
Judging by this scan I'm very surprised you could even log on to this machine.
|
because i care about mine pc alot, i take care of it with mine heart, o and also mine pc is the best that why i can still log in.
that the hijack report after i delete the thing i only delete the 02-BHO with no name, also if i start mine pc next time will those 02 BHO be on list the hijack again?
Logfile of HijackThis v1.99.1
Scan saved at 2:47:34 AM, on 8/19/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\server.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\TT\TTraveler.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\Internet Explorer\Connection Wizard\icwx25b.dun
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\English\Desktop\hijackthis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: xBarHelper.MoveCatchPic - {0CF098A0-CBAC-4EFB-8451-3AFC201C7222} - (no file)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\cnshook.dll
O2 - BHO: Windows Shell - {D22B05B5-457C-4FC6-8562-190B7615ADCC} - (no file)
O2 - BHO: Windows Shell - {D2362775-D2A7-4CA0-A206-9CA0919BDFAE} - (no file)
O2 - BHO: Windows Shell - {D243AFD0-16D4-40AF-9DDC-587F155B937D} - (no file)
O2 - BHO: Windows Shell - {D306FE0F-DFBA-4AE4-99C0-16A7E7A7A241} - (no file)
O2 - BHO: Windows Shell - {D3850FEA-99A7-4F96-8128-E216A6D59800} - (no file)
O2 - BHO: Windows Shell - {D456C230-86AB-41D0-A260-F32B660C8CBF} - (no file)
O2 - BHO: Windows Shell - {D52F83C6-FC85-482E-BFE4-BCF22CE70404} - (no file)
O2 - BHO: Windows Shell - {D72664D7-4DF8-409A-9F64-89A3AB9E0E7D} - (no file)
O2 - BHO: Windows Shell - {D72EDF1A-670A-4884-9461-867AADFE3ACF} - (no file)
O2 - BHO: Windows Shell - {D757F2A1-8FE1-4AED-B9D7-7033B6AD8C41} - (no file)
O2 - BHO: Windows Shell - {D7F4EF0B-3601-40A4-8B76-D45B27499916} - (no file)
O2 - BHO: Windows Shell - {D7FC60F9-8A46-4AA4-B9ED-1A9A33476053} - (no file)
O2 - BHO: Windows Shell - {D8983120-24D1-4156-A232-1B770D614AC5} - (no file)
O2 - BHO: Windows Shell - {D9A8BE2A-F4F5-42E0-B409-9427466064B4} - (no file)
O2 - BHO: Windows Shell - {D9F1A7E9-74E7-40D5-8D8B-2E51F55F19C9} - (no file)
O2 - BHO: Windows Shell - {DA62FAE5-F641-4365-9F6A-6FED5FD41A09} - (no file)
O2 - BHO: Windows Shell - {DA700AA1-FCE2-433B-9385-ADC98C965454} - (no file)
O2 - BHO: Windows Shell - {DB75A0D1-56DA-4057-9F9B-B313BE22FD22} - (no file)
O2 - BHO: Windows Shell - {DCB52CB2-76A9-465F-BB77-FCDAA351D995} - (no file)
O2 - BHO: Windows Shell - {DD78921B-1C80-4B88-AEE4-29382BF42E3C} - (no file)
O2 - BHO: Csyshelper Object - {E16BB625-16F1-4338-AA38-098F6873AC24} - C:\WINDOWS\system32\syshelper.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - (no file)
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SecurePCSolutionsBootCheck] C:\Program Files\Secure PC Solutions\1 Click Fixer PLUS\BootCheck.exe
O4 - HKLM\..\Run: [1ClickFixerPlus] C:\Program Files\Secure PC Solutions\1 Click Fixer PLUS\1ClickFixerPlus.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\..\RunOnce: [CnsHook.dll] regsvr32 /s C:\WINDOWS\downlo~1\CnsHook.dll
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2006\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\QQ2004\AddToNetDisk.htm
O8 - Extra context menu item: 使用Web迅雷下载 - C:\Program Files\Thunder Network\WebThunder\GetUrl.htm
O8 - Extra context menu item: 使用Web迅雷下载全部链接 - C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\QQ2004\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\QQ2004\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\QQ2004\SendMMS.htm
O9 - Extra button: Yahoo 1G mail - {507F9113-CD77-4866-BA92-0E86DA3D0B97} -
ÑÅ»¢ÖúÊÖ (file missing)
O9 - Extra button: E bazar - {59BC54A2-56B3-44a0-93E5-432D58746E26} -
http://adtaobao.allyes.com/main/adfc...allyesPara=816 (file missing)
O9 - Extra button: Yahoo Assistant - {5D73EE86-05F1-49ed-B850-E423120EC338} -
ÑÅ»¢ÖúÊÖ (file missing)
O9 - Extra button: (no name) - {6354ABE6-05F1-49ed-B850-E423120EC338} -
Yahoo!Widget_Ê×Ò³ (file missing)
O9 - Extra button: Instant Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -
ÑÅ»¢ÖúÊÖ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -
ÑÅ»¢ÖúÊÖ (file missing)
O9 - Extra 'Tools' menuitem: Repair Browser - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -
ÑÅ»¢ÖúÊÖ (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
ÑÅ»¢ÖúÊÖ (file missing)
O9 - Extra 'Tools' menuitem: Clean Internet access record - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
ÑÅ»¢ÖúÊÖ (file missing)
O11 - Options group: [!CNS] Chinese keywords
O11 - Options group: [!IESearch] ??¨′?¨¨???????¨|??
O11 - Options group: [CDNCLIENT] ?D??¨|?¨a?
O16 - DPF: Yahoo! Go -
http://download.games.yahoo.com/game...ts/y/gt2_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} -
http://www3.ca.com/securityadvisor/p...n/pestscan.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsof...?1097698886951
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
http://aolsvc.aol.com/onlinegames/be...ploader_v7.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O20 - Winlogon Notify: windows - windows.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)