i never do a serious maintenance, i have good reasons:
1)im lazy
2)have a lot of things to do like play games , sleeping, and eating
3) don't know how to do it
i have done with the defrag
i can't remove NORTON because i can't go to the add/remove program in the Control Panel
i go to Start > All Programs > Accessories > System Tools > System restore then a message said c:\window\system32\Restore\rstrui.exe is unkpwn appication or dameaged,also my AVG is only trail version only have 57 days left
for your question
Judging by this scan I'm very surprised you could even log on to this machine.
because i care about mine PC a lot, i take care of it with mine heart, o and also mine PC is the best that why i can still log in. :)
that the hijack report after i delete the thing i only delete the 02-BHO with no name, also if i start mine PC next time will those 02 BHO be on list the hijack again?:confused:
Logfile of HijackThis v1.99.1
Scan saved at 2:47:34 AM, on 8/19/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\server.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\TT\TTraveler.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\Internet Explorer\Connection Wizard\icwx25b.dun
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\English\Desktop\hijackthis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: xBarHelper.MoveCatchPic - {0CF098A0-CBAC-4EFB-8451-3AFC201C7222} - (no file)
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\cnshook.dll
O2 - BHO: Windows Shell - {D22B05B5-457C-4FC6-8562-190B7615ADCC} - (no file)
O2 - BHO: Windows Shell - {D2362775-D2A7-4CA0-A206-9CA0919BDFAE} - (no file)
O2 - BHO: Windows Shell - {D243AFD0-16D4-40AF-9DDC-587F155B937D} - (no file)
O2 - BHO: Windows Shell - {D306FE0F-DFBA-4AE4-99C0-16A7E7A7A241} - (no file)
O2 - BHO: Windows Shell - {D3850FEA-99A7-4F96-8128-E216A6D59800} - (no file)
O2 - BHO: Windows Shell - {D456C230-86AB-41D0-A260-F32B660C8CBF} - (no file)
O2 - BHO: Windows Shell - {D52F83C6-FC85-482E-BFE4-BCF22CE70404} - (no file)
O2 - BHO: Windows Shell - {D72664D7-4DF8-409A-9F64-89A3AB9E0E7D} - (no file)
O2 - BHO: Windows Shell - {D72EDF1A-670A-4884-9461-867AADFE3ACF} - (no file)
O2 - BHO: Windows Shell - {D757F2A1-8FE1-4AED-B9D7-7033B6AD8C41} - (no file)
O2 - BHO: Windows Shell - {D7F4EF0B-3601-40A4-8B76-D45B27499916} - (no file)
O2 - BHO: Windows Shell - {D7FC60F9-8A46-4AA4-B9ED-1A9A33476053} - (no file)
O2 - BHO: Windows Shell - {D8983120-24D1-4156-A232-1B770D614AC5} - (no file)
O2 - BHO: Windows Shell - {D9A8BE2A-F4F5-42E0-B409-9427466064B4} - (no file)
O2 - BHO: Windows Shell - {D9F1A7E9-74E7-40D5-8D8B-2E51F55F19C9} - (no file)
O2 - BHO: Windows Shell - {DA62FAE5-F641-4365-9F6A-6FED5FD41A09} - (no file)
O2 - BHO: Windows Shell - {DA700AA1-FCE2-433B-9385-ADC98C965454} - (no file)
O2 - BHO: Windows Shell - {DB75A0D1-56DA-4057-9F9B-B313BE22FD22} - (no file)
O2 - BHO: Windows Shell - {DCB52CB2-76A9-465F-BB77-FCDAA351D995} - (no file)
O2 - BHO: Windows Shell - {DD78921B-1C80-4B88-AEE4-29382BF42E3C} - (no file)
O2 - BHO: Csyshelper Object - {E16BB625-16F1-4338-AA38-098F6873AC24} - C:\WINDOWS\system32\syshelper.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: (no name) - {406F94F0-504F-4a40-8DFD-58B0666ABEBD} - (no file)
O4 - HKLM\.. \Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\.. \Run: [SecurePCSolutionsBootCheck] C:\Program Files\Secure PC Solutions\1 Click Fixer PLUS\BootCheck.exe
O4 - HKLM\.. \Run: [1ClickFixerPlus] C:\Program Files\Secure PC Solutions\1 Click Fixer PLUS\1ClickFixerPlus.exe
O4 - HKLM\.. \Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\.. \Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\.. \Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32
O4 - HKLM\.. \RunOnce: [CnsHook.dll] regsvr32 /s C:\WINDOWS\downlo~1\CnsHook.dll
O4 - HKCU\.. \Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2006\MemOptimizer.exe" autostart
O4 - HKCU\.. \Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\QQ2004\AddToNetDisk.htm
O8 - Extra context menu item: 使用Web迅雷下载 - C:\Program Files\Thunder Network\WebThunder\GetUrl.htm
O8 - Extra context menu item: 使用Web迅雷下载全部链接 - C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\QQ2004\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\QQ2004\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\QQ2004\SendMMS.htm
O9 - Extra button: Yahoo 1G mail - {507F9113-CD77-4866-BA92-0E86DA3D0B97} -
ÑÅ»¢ÖúÊÖ (file missing)
O9 - Extra button: E bazar - {59BC54A2-56B3-44a0-93E5-432D58746E26} -
http://adtaobao.allyes.com/main/adfc...allyesPara=816 (file missing)
O9 - Extra button: Yahoo Assistant - {5D73EE86-05F1-49ed-B850-E423120EC338} -
ÑÅ»¢ÖúÊÖ (file missing)
O9 - Extra button: (no name) - {6354ABE6-05F1-49ed-B850-E423120EC338} -
Yahoo!Widget_Ê×Ò³ (file missing)
O9 - Extra button: Instant Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -
ÑÅ»¢ÖúÊÖ (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -
ÑÅ»¢ÖúÊÖ (file missing)
O9 - Extra 'Tools' menuitem: Repair Browser - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -
ÑÅ»¢ÖúÊÖ (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
ÑÅ»¢ÖúÊÖ (file missing)
O9 - Extra 'Tools' menuitem: Clean Internet access record - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
ÑÅ»¢ÖúÊÖ (file missing)
O11 - Options group: [!CNS] Chinese keywords
O11 - Options group: [!IESearch]? ¨′?¨¨?? ¨|?
O11 - Options group: [CDNCLIENT] ?D? ¨|?¨a?
O16 - DPF: Yahoo! Go -
http://download.games.yahoo.com/game...ts/y/gt2_x.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} -
http://www3.ca.com/securityadvisor/p...n/pestscan.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsof...?1097698886951
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
http://aolsvc.aol.com/onlinegames/be...ploader_v7.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O20 - Winlogon Notify: windows - windows.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: avast! IAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)