#1
Posted 01 July 2009 - 11:24 PM
I was wondering if someone could take a look at my autoruns and let me know what I could weed out. What would be the best way to attach this? Thanks in advance to any advice
Avira Antivir Personal and MBAM Pro
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
#2
Posted 01 July 2009 - 11:58 PM
Please post the reason why you would want someone to read the logs in Autoruns, what are the issues. You can download it from here: http://technet.microsoft.com/en-us/sysinte...s/bb963902.aspx
Save it to your Desktop, then run the Program, Depending on the instructions you receive from an admin. or someone who will read this from the HiJackLog forum.
As soon as you start the program, press the Esc. key to stop it. In the menu bar of the program go to Options and drop down to "Verify Code Signatures" place a check there.
Then Press F5 to start the program again. When its Finished scanning, Go to File, Save. and save it to the desktop. it will be saved as an .am file Then zip the the file up, (since there over 5MB+) and attach it to your post.
note: unless you were sent here? I would contact an admin like: AdvancedSetup via PM.
one reason is my instructions above may need to be changed? Its not up to me! regards (any questions?)
Save it to your Desktop, then run the Program, Depending on the instructions you receive from an admin. or someone who will read this from the HiJackLog forum.
As soon as you start the program, press the Esc. key to stop it. In the menu bar of the program go to Options and drop down to "Verify Code Signatures" place a check there.
Then Press F5 to start the program again. When its Finished scanning, Go to File, Save. and save it to the desktop. it will be saved as an .am file Then zip the the file up, (since there over 5MB+) and attach it to your post.
note: unless you were sent here? I would contact an admin like: AdvancedSetup via PM.
one reason is my instructions above may need to be changed? Its not up to me! regards (any questions?)

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
http://www.tentrexindustries.com/
#3
Posted 02 July 2009 - 12:19 AM
A more efficient approach for non malware problems is to use a simpler program to get started
Please download and run Processexplorer
http://technet.microsoft.com/en-us/sysinte...s/bb896653.aspx
Under file and save as, create a log and post here
copy and paste into a reply
Please download and run Processexplorer
http://technet.microsoft.com/en-us/sysinte...s/bb896653.aspx
Under file and save as, create a log and post here
copy and paste into a reply
Regards
Chewy the wild wookie
Chewy the wild wookie
#4
Posted 02 July 2009 - 12:29 AM
DaChew, on Jul 1 2009, 07:19 PM, said:
A more efficient approach for non malware problems is to use a simpler program to get started
Please download and run Processexplorer
http://technet.microsoft.com/en-us/sysinte...s/bb896653.aspx
Under file and save as, create a log and post here
copy and paste into a reply
Please download and run Processexplorer
http://technet.microsoft.com/en-us/sysinte...s/bb896653.aspx
Under file and save as, create a log and post here
copy and paste into a reply
Thanks. Advanced setup had told me that I could probably weed out some things on startup when he was looking at my logs for malware in the HJT forum (no malware was found). Just trying to trim some stuff down. Here is the log you requested. Thanks for the help!
Process PID CPU Description Company Name
System Idle Process 0 95.05
Interrupts n/a 1.98 Hardware Interrupts
DPCs n/a 0.99 Deferred Procedure Calls
System 4
smss.exe 612 Windows NT Session Manager Microsoft Corporation
csrss.exe 676 Client Server Runtime Process Microsoft Corporation
winlogon.exe 700 Windows NT Logon Application Microsoft Corporation
services.exe 744 0.99 Services and Controller app Microsoft Corporation
ibmpmsvc.exe 932 ThinkPad Power Management Service Lenovo
ati2evxx.exe 964 ATI External Event Utility EXE Module ATI Technologies Inc.
svchost.exe 984 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1048 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1144 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1216 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1284 Generic Host Process for Win32 Services Microsoft Corporation
spoolsv.exe 1768 Spooler SubSystem App Microsoft Corporation
sched.exe 1820 Antivirus Scheduler Avira GmbH
svchost.exe 1916 Generic Host Process for Win32 Services Microsoft Corporation
acs.exe 596 ACS Atheros
DiskMonitorService.exe 672 Active@ Disk Monitor Service LSoft Technologies Inc
avguard.exe 660 Antivirus On-Access Service Avira GmbH
BcmSqlStartupSvc.exe 880 BCM SQL Startup Service Microsoft Corporation
jqs.exe 1108 Java Quick Starter Service Sun Microsystems, Inc.
mdm.exe 1168 Machine Debug Manager Microsoft Corporation
QCONSVC.EXE 1236
SbieSvc.exe 1596 Sandboxie Service tzuk
sqlbrowser.exe 1740 SQL Browser Service EXE Microsoft Corporation
sqlwriter.exe 1876 SQL Server VSS Writer Microsoft Corporation
wdfmgr.exe 2012 Windows User Mode Driver Manager Microsoft Corporation
sqlservr.exe 516 SQL Server Windows NT Microsoft Corporation
alg.exe 1620 Application Layer Gateway Service Microsoft Corporation
lsass.exe 756 LSA Shell (Export Version) Microsoft Corporation
explorer.exe 3056 Windows Explorer Microsoft Corporation
rundll32.exe 3212 Run a DLL as an App Microsoft Corporation
jusched.exe 3312 Java Platform SE binary Sun Microsystems, Inc.
avgnt.exe 3332 Antivirus System Tray Tool Avira GmbH
IObit SmartDefrag.exe 3344 Smart Defrag IObit
ctfmon.exe 3364 CTF Loader Microsoft Corporation
SUPERANTISPYWARE.EXE 3376 0.99 SUPERAntiSpyware Application SUPERAntiSpyware.com
ISUSPM.exe 3384 Macrovision Software Manager Macrovision Corporation
DiskMonitor.exe 3428 Active@ Hard Disk Monitor LSoft Technologies Inc
DiskMonitor.exe 3520 Active@ Hard Disk Monitor LSoft Technologies Inc
SbieCtrl.exe 3548 Sandboxie Control tzuk
procexp.exe 1096 Sysinternals Process Explorer Sysinternals - www.sysinternals.com
Avira Antivir Personal and MBAM Pro
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
#5
Posted 02 July 2009 - 12:33 AM
Quote
Well from what I can tell there does not appear to be any infection. You do have a few programs that do a lot of Input/Output to the hard drive and its possible that maybe they can cause a minor slowdown or mini freeze from time to time.
I would get a program like AutoRuns from Microsoft and weed down some of the programs that are not absolutely needed to run during startup.
Uninstall those that you also no longer want or use
I would get a program like AutoRuns from Microsoft and weed down some of the programs that are not absolutely needed to run during startup.
Uninstall those that you also no longer want or use
Above is what Advanced setup said, if that helps any. Thanks!
Avira Antivir Personal and MBAM Pro
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
#6
Posted 02 July 2009 - 12:38 AM
@ prairie dog ok very well, if AdvancedSetup said post an autoruns log here. very good. You may want to save the autoruns instructions above. I can't get in the middle btw. DaChew & AdvanedSetup. cya later regards....

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
http://www.tentrexindustries.com/
#7
Posted 02 July 2009 - 01:36 AM
@yardbird don't worry
how much ram does this thinkpad have?
how much ram does this thinkpad have?
Regards
Chewy the wild wookie
Chewy the wild wookie
#8
Posted 02 July 2009 - 01:58 AM
1GB of Ram
Avira Antivir Personal and MBAM Pro
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
#9
Posted 02 July 2009 - 02:19 AM
You should still post the autoruns, I see a lot of stuff that could go, Advanced gave you good advice on that.
Ram only helps so much, still a heavy load for an old laptop with slow cpu and hard drive
Ram only helps so much, still a heavy load for an old laptop with slow cpu and hard drive
Regards
Chewy the wild wookie
Chewy the wild wookie
#10
Posted 02 July 2009 - 02:23 AM
should I just copy and paste like the last one? Thanks
Avira Antivir Personal and MBAM Pro
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
#11
Posted 02 July 2009 - 02:31 AM
No please not the autoruns! Follow my Install instructions above & where to download it, after its done & on your desktop, then zip it and attach it here! you now how to attach it? (use the browse, then upload) if you need help...post back... regards

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
http://www.tentrexindustries.com/
#12
Posted 02 July 2009 - 02:49 AM
@yardbird. HA! that would be a pretty long copy/paste. Sorry about that
Attached is the zipped autoruns. Thanks!
Attached is the zipped autoruns. Thanks!
Avira Antivir Personal and MBAM Pro
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
#13
Posted 02 July 2009 - 02:51 AM
Great! nice work... its a good program...
EDIT: ok its just a matter of time, depending on how busy AdvancedSetup is?
You can read the top 3 pinned topics in this forum: http://www.malwareby...php?showforum=7
It may be done tonight or a day from now.... will cya out there on ther board..
EDIT: ok its just a matter of time, depending on how busy AdvancedSetup is?
You can read the top 3 pinned topics in this forum: http://www.malwareby...php?showforum=7
It may be done tonight or a day from now.... will cya out there on ther board..

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
http://www.tentrexindustries.com/
#14
Posted 02 July 2009 - 03:00 AM
Thanks for the help Yardbird. I'll wait for DaChew to go over the log?
Avira Antivir Personal and MBAM Pro
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
#15
Posted 02 July 2009 - 03:03 AM
very good whatever you had agreed to... ... all I did was get you to autoruns & the rest you did! see you out on the forums

No trees were harmed in the posting of this message...however an extraordinarily large number of electrons were horribly inconvenienced.
http://www.tentrexindustries.com/
#16
Posted 02 July 2009 - 06:56 AM
@prairie dog: I just took a look at your Autoruns file, looks like you forgot to refresh and let it scan again after checking the entry for verify code signatures. Please post another per the instructions below:
Please download Sysinternals Autoruns from here.
Thanks
.
Please download Sysinternals Autoruns from here.
- Save Autoruns.exe to your desktop and double-click it to run it.
- Once it starts, please press the Esc key on your keyboard.
- Now that scanning is stopped, click on the Options button at the top of the program and select Verify Code Signatures
- Once that's done press the F5 key on your keyboard, this will start the scan again, this time let it finish.
- When it's finished, please click on the File button at the top of the program and select Save and save the Autoruns.arn file to your desktop.
- Now right-click on the Autoruns.arn file located on your desktop and highlight Send To and select Compressed (zipped) Folder
- Please attach the Autoruns.zip file you just created to your next post.
Thanks
#18
Posted 02 July 2009 - 09:30 AM
Yeah, I'm at work, no IM's here unfortunately (I don't like to install software on the work PC since it's against policy, even though I could get away with it
).
#19
Posted 02 July 2009 - 05:57 PM
exile360, on Jul 2 2009, 01:56 AM, said:
@prairie dog: I just took a look at your Autoruns file, looks like you forgot to refresh and let it scan again after checking the entry for verify code signatures. Please post another per the instructions below:
Please download Sysinternals Autoruns from here.
Sorry about that. I thought I had sent the right one. Here is the new autoruns log. Thanks again!
Thanks
.
Please download Sysinternals Autoruns from here.
- Save Autoruns.exe to your desktop and double-click it to run it.
- Once it starts, please press the Esc key on your keyboard.
- Now that scanning is stopped, click on the Options button at the top of the program and select Verify Code Signatures
- Once that's done press the F5 key on your keyboard, this will start the scan again, this time let it finish.
- When it's finished, please click on the File button at the top of the program and select Save and save the Autoruns.arn file to your desktop.
- Now right-click on the Autoruns.arn file located on your desktop and highlight Send To and select Compressed (zipped) Folder
- Please attach the Autoruns.zip file you just created to your next post.
Sorry about that. I thought I had sent the right one. Here is the new autoruns log. Thanks again!
Thanks
Avira Antivir Personal and MBAM Pro
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
On demand: SAS and Hitman Pro
Firewall-Online Armor Premium
FF3-adblock plus, noscript, betterprivacy, WOT, Keyscrambler, TrackMeNot
Sandboxie
ONE DAY AT A TIME!
#20
Posted 02 July 2009 - 11:21 PM
Do you run disk cleanup and keep at least 20% free space on your hard drive?
Do you see the same problems when sandbox is disabled?
Do you see the same problems when sandbox is disabled?
Regards
Chewy the wild wookie
Chewy the wild wookie
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
Sign In
Create Account

Back to top










