Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] laptop was slow

[Fixed] Hijackthis! Logs - [Resolved] laptop was slow posted in the Security & Safety forums; I am trying to fix a friends laptop and have completed all the prework. I am attaching the ewido logs and HJT logs. can someone check them through and see ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 05-25-2006
spellbyte's Avatar
Elite Member
My PC
 
Join Date: Nov 2004
Location: Top Secret... really
Posts: 527
spellbyte - See this Members User comments on their Profile page
Send a message via MSN to spellbyte Send a message via Skype™ to spellbyte
Default [Resolved] laptop was slow

I am trying to fix a friends laptop and have completed all the prework.

I am attaching the ewido logs and HJT logs. can someone check them through and see if there is anything left on there,

the laptop is a Packard Bell Easynote W3301 and as usual there is a load of unnecessary software loaded up onto the system, so could someone also point out which is safe to remove and which should be kept on there for the system to function properly?


  #2  
Old 05-25-2006
spellbyte's Avatar
Elite Member
My PC
 
Join Date: Nov 2004
Location: Top Secret... really
Posts: 527
spellbyte - See this Members User comments on their Profile page
Send a message via MSN to spellbyte Send a message via Skype™ to spellbyte
Default

my mistake, sorry guys i forgot to post the all important logs
Attached Files
File Type: log hijackthis.log (7.2 KB, 2 views)
File Type: txt ewido report.txt (1.2 KB, 2 views)


  #3  
Old 05-26-2006
spellbyte's Avatar
Elite Member
My PC
 
Join Date: Nov 2004
Location: Top Secret... really
Posts: 527
spellbyte - See this Members User comments on their Profile page
Send a message via MSN to spellbyte Send a message via Skype™ to spellbyte
Default

has anyone had a chance to look at those logs yet


  #4  
Old 05-26-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Nope , not untill now.

Unless he uses the Powercinema and Cyberlink software then these can be fixed with hjt , if he does use those then remove them from the list:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
Use start/run/services.msc to disable the 023 entry's:

Click Start>Run and type in: services.msc
Click OK
In the Services window find: The Service Name of the 023's
Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK


And do you/he know what these are?

O4 - HKLM\..\Run: [RMC] C:\WINDOWS\system32\drivers\RMC.exe
O4 - HKLM\..\Run: [ms1src] c:\program files\common files\system\ms1src.exe /install

If not then upload them to this site and report back the scan results please:

http://www.virustotal.com/en/indexf.html


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 05-27-2006
spellbyte's Avatar
Elite Member
My PC
 
Join Date: Nov 2004
Location: Top Secret... really
Posts: 527
spellbyte - See this Members User comments on their Profile page
Send a message via MSN to spellbyte Send a message via Skype™ to spellbyte
Default

I haven't got a clue what those last ones are and i'm pretty sure that she doesn't. the laptop has been used to look at risky sites so she says so it could be anything. i'll ask her to bring it back round so i can do the nessecary removals

thanks for the reply joe,

who knows this could be my last post on here from the UK


  #6  
Old 05-27-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Im pretty sure the ms1src.exe is some sort of malware , im not sure about the RMC.exe one. Lets see what the online scan results at that site will be.


PS , how come the last post from the UK? Are you moving?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 03:09 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top