HiJack Startups

Discussion in 'Software' started by Greyhound, Jan 13, 2004.

  1. Greyhound

    Greyhound Sergeant

    I noticed some slow down and things that have been changing every now and again. Not new to PCs but also not up with some of the latest fixes. Here is a list of my Hijack log. Is there anything in this that is hurting me?
    and here is my sysinfo.
    OS Name Microsoft Windows
    Version 4.90.3000 Build 3000
    OS Manufacturer Microsoft Corporation
    System Name P0V3P7
    System Manufacturer Dell Computer Corporation
    System Model Inspiron 8000
    System Type X86-based PC
    Processor Pentium(r) III processor GenuineIntel ~900 Mhz
    BIOS Version Phoenix ROM BIOS PLUS Version 1.10 A10
    Windows Directory C:\WINDOWS
    Locale United States
    Time Zone Pacific Standard Time
    Total Physical Memory 255.43 MB
    Available Physical Memory 54.70 MB
    Total Virtual Memory 2.00 GB
    Available Virtual Memory 1.67 GB
    Page File Space 1.75 GB
    ---------------------------------------------------------------------
    Logfile of HijackThis v1.97.7
    Scan saved at 11:08:53 AM, on 1/13/2004
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\DELL\ACCESSDIRECT\DADAPP.EXE
    C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\WINDOWS\DOCKAPP.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
    C:\WINDOWS\RUNDLL32.EXE
    C:\WINDOWS\SYSTEM\INETCNTRL\INETCNTRL.EXE
    C:\WINDOWS\SYSTEM\CTFMON.EXE
    C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
    C:\SIERRA\PLANNER\PLNRNOTE.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myafo.net/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50046
    R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [DadApp] C:\Program Files\DELL\AccessDirect\dadapp.exe
    O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
    O4 - HKLM\..\Run: [BayMgr] DockApp.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
    O4 - HKLM\..\Run: [NVQuickTweak] RUNDLL32.EXE NVQTWK.DLL,NvTaskbarInit
    O4 - HKLM\..\Run: [InetCntrl] C:\WINDOWS\SYSTEM\InetCntrl\InetCntrl.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
    O4 - Startup: Event Planner Reminders Tray Icon.lnk = C:\Sierra\Planner\PLNRnote.exe
    O4 - Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM\E_SRCV02.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE10\EXCEL.EXE/3000
    O8 - Extra context menu item: Download using Download &Express - file://C:\Program Files\Download Express\Add_Url.htm
    O10 - Broken Internet access because of LSP provider 'inetcntrl.dll' missing
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37870.8717361111
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
    O16 - DPF: {B160422D-0A48-11D4-BD9B-00A0C9B0AB7B} (Download Class) - http://expressit.broderbund.com/plugin/Download.cab
    O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.dell.com/us/en/systemprofiler/SysProfLCD.CAB
    O16 - DPF: msvcp71 - http://download.pestpatrol.com/Downloads/Components/msvcp71.cab
    O16 - DPF: msvcr71 - http://download.pestpatrol.com/Downloads/Components/msvcr71.cab
    O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MT...sarwatches.com/Collections/SC1_TechGear2.aspx
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/d052c1d7d32ead/housecall.antivirus.com/housecall/xscan53.cab
     
  2. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

    i dont see anything hurtful there i personally would not have all those programs running at start-up but its all about personal preferences
    but it wouldnt hurt to have a look here for a description of each one to see if you need them auto running or not
    http://www.pacs-portal.co.uk/startup_pages/startup_full.php

    also i prefer to check for windows updates manually but again its a personal choice

    you mentioned a few problems maybe you could give some details and someone here may be able to help you out

    might help to check out this
    http://www.majorgeeks.com/vb/showthread.php?p=293084#post293084
    sorry MA i replied to this before you posted in the tips tricks forum
     
    Last edited: Jan 13, 2004
    1 person likes this.
  3. Greyhound

    Greyhound Sergeant

    Thanks, for the help, I did stop 4 of them from running, but didn't see many more that I could. Also saw that one of them wasn't even listed ie: InetCntrl
     
  4. jujet84

    jujet84 Master Sergeant

    Well one you missed---- that you can uncheck is O4 - HKLM\..\Run: [LoadQM] loadqm.exe "Note"
    Loadqm.exe is used by MSN Messenger in MSN Explorer to transmit data. It queues up the instant messages in Messenger,
    and its one big resource hog.Unchecking this will result in more speed,loading up.
     
  5. Greyhound

    Greyhound Sergeant

    Thanks, I had already done that plus BayMgr, Ctfmon, and SchedulingAgent. Still have found no answer for the InetCntrl though. :)
     
  6. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

    hi there as far as im aware INET CTRL is linking to some form of internet filtering so if you use this kind of software to filter what your kids are doing then this would be the reason and obviously you wouldnt want to stop this service running although i believe most of this kind of software cant be stopped just by disabling it at start-up that would just be too easy for most pc savvy kids :p
     
  7. Greyhound

    Greyhound Sergeant

    I found out that InetCntrl is a filter that my ISP uses, and if I take it out, I won't be able to get online. Thanks one and all, now if I knew how to close this thread I would be doing great. :) :) :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds