Forum Home
Press F1
 
Thread ID: 63683 2005-11-19 09:32:00 NEED HELP WITH PC !! tion (9265) Press F1
Post ID Timestamp Content User
405514 2005-11-19 19:27:00 you can never have too much ram ;) Prescott (11)
405515 2005-11-19 19:28:00 It's not the CPU that decides how much memory it can handle.

Its the motherboard. If the mobo supports up to 2-3 gb, 1.18 shouldnt be a prob.
Speedy Gonzales (78)
405516 2005-11-19 19:58:00 so wats wrong with my pc then ??
if its not the ram and it has no viruses,spyware,adware or trojans then wat else cud it be ??

im stuck for ideas my old pc was just about the same specs but with less ram and that ran faster than my new 1 helppp sum111
tion (9265)
405517 2005-11-19 20:06:00 well you still havent posted a hijack this log.

do it now.

80.237.140.193
Prescott (11)
405518 2005-11-19 20:09:00 Get Hijackthis (www.merijn.org)

As someone said in a previous post. Unzip it first into its own folder. Then run it scan and copy and paste the log here.

It'll show us, whether anything nasty, maybe in the system, or running on bootup/startup.
Speedy Gonzales (78)
405519 2005-11-19 20:25:00 right done that here is the log

Logfile of HijackThis v1 . 99 . 1
Scan saved at 20:23:41, on 19/11/2005
Platform: Windows XP SP2 (WinNT 5 . 01 . 2600)
MSIE: Internet Explorer v6 . 00 SP2 (6 . 00 . 2900 . 2180)

Running processes:
C:\WINDOWS\System32\smss . exe
C:\WINDOWS\system32\winlogon . exe
C:\WINDOWS\system32\services . exe
C:\WINDOWS\system32\lsass . exe
C:\WINDOWS\system32\svchost . exe
C:\WINDOWS\System32\svchost . exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr . exe
C:\WINDOWS\Explorer . EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr . exe
C:\Program Files\Common Files\Symantec Shared\ccProxy . exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc . exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc . exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc . exe
C:\WINDOWS\system32\spoolsv . exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc . exe
c:\APPS\Powercinema\Kernel\TV\CLSched . exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer . exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService . exe
c:\APPS\HIDSERVICE\HIDSERVICE . exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc . exe
C:\WINDOWS\system32\slserv . exe
C:\WINDOWS\SOUNDMAN . EXE
C:\Program Files\Java\j2re1 . 4 . 2_05\bin\jusched . exe
C:\Apps\Powercinema\PCMService . exe
C:\Program Files\Mouse\MouseDrv . exe
C:\Program Files\Common Files\Symantec Shared\ccApp . exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S 2 . EXE
C:\Program Files\Multimedia Keyboard\Multimedia Keyboard\mm2000 . exe
C:\WINDOWS\system32\sistray . exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE . EXE
C:\Program Files\Windows Media Player\wmplayer . exe
C:\Program Files\Internet Explorer\iexplore . exe
C:\Program Files\MSN Messenger\msnmsgr . exe
C:\Program Files\Messenger\msmsgs . exe
C:\Documents and Settings\Tion\My Documents\hijackthis_199\HijackThis . exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = . packardbell . com/cgi-bin/redirect/?country=UK&range=AD&phase=6&key=SEARCH" target="_blank">format . packardbell . com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk . htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6 . 0\Reader\ActiveX\AcroIEHelper . dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt . dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt . dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt . dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt . dll
O4 - HKLM\ . . \Run: [IMJPMIG8 . 1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG . EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\ . . \Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP . EXE /SYNC
O4 - HKLM\ . . \Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP . EXE /IMEName
O4 - HKLM\ . . \Run: [SoundMan] SOUNDMAN . EXE
O4 - HKLM\ . . \Run: [SiSPower] Rundll32 . exe SiSPower . dll,ModeAgent
O4 - HKLM\ . . \Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1 . 4 . 2_05\bin\jusched . exe
O4 - HKLM\ . . \Run: [PCMService] "c:\Apps\Powercinema\PCMService . exe"
O4 - HKLM\ . . \Run: [DeluxMouse] C:\Program Files\Mouse\MouseDrv . exe
O4 - HKLM\ . . \Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp . exe"
O4 - HKLM\ . . \Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S 2 . EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66"
O4 - HKCU\ . . \Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs . exe" /background
O4 - Global Startup: Multimedia Keyboard . lnk = C:\Program Files\Multimedia Keyboard\Multimedia Keyboard\mm2000 . exe
O4 - Global Startup: Utility Tray . lnk = C:\WINDOWS\system32\sistray . exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL . EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1 . 4 . 2_05\bin\npjpi142_05 . dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1 . 4 . 2_05\bin\npjpi142_05 . dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR . DLL
O9 - Extra button: Real . com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw . dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs . exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs . exe
O14 - IERESET . INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk . htm
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - . symantec . com/techsupp/asa/ctrl/tgctlsi . cab" target="_blank">www . symantec . com
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - . symantec . com/techsupp/asa/ctrl/tgctlsr . cab" target="_blank">www . symantec . com
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - . symantec . com/techsupp/asa/ctrl/LSSupCtl . cab" target="_blank">www . symantec . com
O16 - DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} (Seekford Solutions, Inc . 's ssiPictureUploader Control) - . funtigo . com/images/uploader/ssiPictureUploader . cab" target="_blank">img . funtigo . com
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - . msn . com/download/MsnMessengerSetupDownloader . cab" target="_blank">messenger . msn . com
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp . dll" (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr . exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc . exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy . exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr . exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc . exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched . exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost . exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer . exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE . exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc . exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE . EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan . exe



plz help me now !!
tion (9265)
405520 2005-11-19 20:38:00 Boot into safe mode. Turn system restore off.

Run hijackthis again. And tick these entries. Then tick fix checked. Then reboot.

HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = format.packardbell.com

O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm

Do you have a SIS videocard on this system?? Do you know?
Speedy Gonzales (78)
405521 2005-11-19 20:39:00 Did you do a complete format and install or a simple non-destructive recovery?

The latter wont nesercerally correct a munted XP.

And there wont be anyway a better video card would slow down your PC unless you munted teh driver install.
Metla (12)
405522 2005-11-19 20:48:00 Did you do a complete format and install or a simple non-destructive recovery?

The latter wont nesercerally correct a munted XP.

And there wont be anyway a better video card would slow down your PC unless you munted teh driver install.

i did a destructive recovery so it wiped everything from the harddrive and reinstalled xp for me
tion (9265)
405523 2005-11-19 20:50:00 Boot into safe mode. Turn system restore off.

Run hijackthis again. And tick these entries. Then tick fix checked. Then reboot.

HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = format.packardbell.com

O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm

Do you have a SIS videocard on this system?? Do you know?


can i just ask what this does by ticking these entries ?? wil it brake anything ?? is it completely safe ??

as for your question erm....yes its a sis videocard because it onboard graphics 64mb i think
tion (9265)
1 2 3 4 5