# Look at this Hijack This Log?

**URL:** <https://boards.straightdope.com/t/look-at-this-hijack-this-log/513590>\
**Category:** Factual Questions\
**Created:** [October 12, 2009, 9:56pm UTC](https://boards.straightdope.com/t/look-at-this-hijack-this-log/513590 "2009-10-12T21:56:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![treis](https://avatars.discourse-cdn.com/v4/letter/t/bc79bd/32.png) [@treis](https://boards.straightdope.com/u/treis)\
**Post date:** [October 12, 2009, 9:56pm UTC](https://boards.straightdope.com/t/look-at-this-hijack-this-log/513590/1 "2009-10-12T21:56:07Z")

</div>

Logfile of Trend Micro HijackThis v2.0.2  
Scan saved at 4:15:08 PM, on 10/12/2009  
Platform: Windows XP SP3 (WinNT 5.01.2600)  
MSIE: Internet Explorer v8.00 (8.00.6001.18702)  
Boot mode: Normal

Running processes:  
C:\WINDOWS\System32\smss.exe  
C:\WINDOWS\system32\winlogon.exe  
C:\WINDOWS\system32\services.exe  
C:\WINDOWS\system32\lsass.exe  
C:\WINDOWS\system32\svchost.exe  
C:\WINDOWS\System32\svchost.exe  
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe  
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe  
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe  
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe  
C:\WINDOWS\Explorer.EXE  
C:\WINDOWS\system32\ZoneLabs\vsmon.exe  
C:\WINDOWS\system32\spoolsv.exe  
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe  
C:\Program Files\AskBarDis\bar\bin\AskService.exe  
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe  
C:\Program Files\Bonjour\mDNSResponder.exe  
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe  
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdrserv.exe  
C:\WINDOWS\system32\lxdrcoms.exe  
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe  
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe  
C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe  
C:\Program Files\Dell Support Center\bin\sprtsvc.exe  
C:\WINDOWS\system32\svchost.exe  
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe  
C:\Program Files\Apoint\Apoint.exe  
C:\WINDOWS\system32\hkcmd.exe  
C:\WINDOWS\system32\igfxpers.exe  
C:\Program Files\Java\j2re1.4.2\_03\bin\jusched.exe  
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe  
C:\WINDOWS\system32\igfxsrvc.exe  
C:\Program Files\Dell\Media Experience\PCMService.exe  
C:\WINDOWS\system32\dla fswctrl.exe  
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe  
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe  
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E\_FATI9FA.EXE  
C:\Program Files\Picasa2\PicasaMediaDetector.exe  
C:\Program Files\Dell Support Center\bin\sprtcmd.exe  
C:\WINDOWS\System32\svchost.exe  
C:\Program Files\Lexmark 4900 Series\lxdrmon.exe  
C:\Program Files\Apoint\Apntex.exe  
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe  
C:\Program Files\Lexmark 4900 Series\lxdrMsdMon.exe  
C:\Program Files\iTunes\iTunesHelper.exe  
C:\Program Files\DellSupport\DSAgnt.exe  
C:\WINDOWS\system32\ctfmon.exe  
C:\Program Files\Digital Line Detect\DLG.exe  
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe  
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe  
C:\Program Files\Mozilla Firefox\firefox.exe  
C:\WINDOWS\system32\wuauclt.exe  
C:\Program Files\iPod\bin\iPodService.exe  
C:\WINDOWS\system32\msiexec.exe  
C:\Documents and Settings\Mary Reistetter\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default\_Page\_URL = [Computers, Monitors & Technology Solutions | Dell USA](http://www.dell4me.com/myway)  
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE](http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE)  
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Computers, Monitors & Technology Solutions | Dell USA](http://www.dell4me.com/myway)  
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default\_Page\_URL = [MSN](http://go.microsoft.com/fwlink/?LinkId=69157)  
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default\_Search\_URL = [Bing](http://go.microsoft.com/fwlink/?LinkId=54896)  
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Bing](http://go.microsoft.com/fwlink/?LinkId=54896)  
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [MSN](http://go.microsoft.com/fwlink/?LinkId=69157)  
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = \*.local  
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll  
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll  
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll  
O2 - BHO: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar oolband.dll  
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll  
O2 - BHO: [WormRadar.com](http://WormRadar.com) IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll  
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll  
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla fswshx.dll  
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll  
O2 - BHO: Lexmark Printable Web - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll  
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar oolband.dll  
O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll  
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll  
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe  
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe  
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe  
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe  
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2\_03\bin\jusched.exe  
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless  
O4 - HKLM..\Run: [PCMService] “C:\Program Files\Dell\Media Experience\PCMService.exe”  
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla fswctrl.exe  
O4 - HKLM..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup  
O4 - HKLM..\Run: [ISUSScheduler] “C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” -start  
O4 - HKLM..\Run: [RemoteControl] “C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe”  
O4 - HKLM..\Run: [EPSON Stylus Photo R320 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E\_FATI9FA.EXE /P30 “EPSON Stylus Photo R320 Series” /O6 “USB002” /M “Stylus Photo R320”  
O4 - HKLM..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe  
O4 - HKLM..\Run: [dscactivate] “C:\Program Files\Dell Support Center\gs\_agent\custom\dsca.exe”  
O4 - HKLM..\Run: [DellSupportCenter] “C:\Program Files\Dell Support Center\bin\sprtcmd.exe” /P DellSupportCenter  
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 8.0\Reader\Reader\_sl.exe”  
O4 - HKLM..\Run: [lxdrmon.exe] “C:\Program Files\Lexmark 4900 Series\lxdrmon.exe”  
O4 - HKLM..\Run: [lxdramon] “C:\Program Files\Lexmark 4900 Series\lxdramon.exe”  
O4 - HKLM..\Run: [FaxCenterServer] “C:\Program Files\Lexmark Fax Solutions\fm3032.exe” /s  
O4 - HKLM..\Run: [ZoneAlarm Client] “C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe”  
O4 - HKLM..\Run: [QuickTime Task] “C:\Program Files\QuickTime\QTTask.exe” -atboottime  
O4 - HKLM..\Run: [iTunesHelper] “C:\Program Files\iTunes\iTunesHelper.exe”  
O4 - HKCU..\Run: [DellSupport] “C:\Program Files\DellSupport\DSAgnt.exe” /startup  
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe  
O4 - HKCU..\Run: [DellSupportCenter] “C:\Program Files\Dell Support Center\bin\sprtcmd.exe” /P DellSupportCenter  
O4 - Global Startup: Digital Line Detect.lnk = ?  
O4 - Global Startup: hpoddt01.exe.lnk = ?  
O4 - Global Startup: McAfee Security Scan.lnk = ?  
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000  
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\_03\bin  
pjpi142\_03.dll  
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\_03\bin  
pjpi142\_03.dll  
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL  
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL  
O9 - Extra button: [Real.com](http://Real.com) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll  
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - [http://wwws.musicmatch.com/mmz/openWebRadio.html](http://wwws.musicmatch.com/mmz/openWebRadio.html) (file missing)  
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe  
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe  
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe  
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe  
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - [http://go.microsoft.com/fwlink/?linkid=39204](http://go.microsoft.com/fwlink/?linkid=39204)  
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll  
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe  
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe  
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe  
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe  
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe  
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe  
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe  
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe  
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe  
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe  
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe  
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe  
O23 - Service: lxdrCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdrserv.exe  
O23 - Service: lxdr\_device - - C:\WINDOWS\system32\lxdrcoms.exe  
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe  
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe  
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe  
O23 - Service: SlingAgentService - Sling Media Inc. - C:\Program Files\Sling Media\SlingAgent\SlingAgentService.exe  
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc\_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe  
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe  
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–  
End of file - 11740 bytes

This is my mom’s laptop that is reportedly running slow. I think there is just a bunch of crap running in the background. I stopped a bunch of stuff from starting up at startup and I think its running a little bit quicker. It only has 512mb of ram which is a contributing factor, so I think I am going to upgrade that. If anyone has other suggestions I would be open.

---

<div class="post-metadata">

**Author:** ![Intergalactic\_Gladiator](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/intergalactic_gladiator/32/112_2.png) [@Intergalactic\_Gladiator](https://boards.straightdope.com/u/Intergalactic_Gladiator)\
**Post date:** [October 12, 2009, 10:01pm UTC](https://boards.straightdope.com/t/look-at-this-hijack-this-log/513590/2 "2009-10-12T22:01:57Z")

</div>

Even without looking at the log, I’d say that you definitely want to up the RAM to (at least) 1 or 2 GB.

If you can set up a 2nd user account, you should go in as that and delete all her cookies, temp files, and temp Internet files. That seems to me a lot more thorough than disk cleanup, but that’s an option as well.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [October 12, 2009, 10:51pm UTC](https://boards.straightdope.com/t/look-at-this-hijack-this-log/513590/3 "2009-10-12T22:51:48Z")

</div>

AskBar and MyWaySA are spyware, I believe

Adobe speed launcher and all the Apple/itunes stuff can be quite resource-hungry - although you might just have to live with this if you need either of them specifically.

Same probably goes for all the ‘Dell media experience’ and ‘Dell Support’ stuff - most likely sitting there chewing up resources all the time.

---

<div class="post-metadata">

**Author:** ![yoyodyne](https://avatars.discourse-cdn.com/v4/letter/y/a9a28c/32.png) [@yoyodyne](https://boards.straightdope.com/u/yoyodyne)\
**Post date:** [October 12, 2009, 11:10pm UTC](https://boards.straightdope.com/t/look-at-this-hijack-this-log/513590/4 "2009-10-12T23:10:50Z")

</div>

I would:

uninstall ZoneAlarm, AVG, McAfee Security Scan  
uninstall the Ask toolbar  
if she’s not using QuickBooks or Quicken uninstall them  
uninstall all Sling software  
uninstall all Dell support software, MyWay Search Assistant  
uninstall digital line detect  
uninstall Acrobat reader 8  
uninstall any unsued printer software

stop C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup from starting  
stop [ISUSScheduler] “C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” -start from starting  
stop PCMService from starting  
stop dla from starting

update Picasa to V3  
install Acrobat reader 9 and update  
install [Microsoft Security Essentials](http://www.microsoft.com/security_essentials/?mkt=en-us)  
install 1GB RAM

---

<div class="post-metadata">

**Author:** ![strqwert44](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@strqwert44](https://boards.straightdope.com/u/strqwert44)\
**Post date:** [October 12, 2009, 11:19pm UTC](https://boards.straightdope.com/t/look-at-this-hijack-this-log/513590/5 "2009-10-12T23:19:06Z")

</div>

download…

> **[CCleaner Makes Your Computer Faster & More Secure | Official Website](https://www.ccleaner.com/)**
>
> CCleaner is the number-one tool for cleaning your PC. It protects your privacy and makes your computer faster and more secure! Download it FREE today.

uninstall all the programs mentioned by the posts above…

google “wise registry cleaner free version” and download that

also take a look at the following website and apply to the computer.

[http://www.speedyvista.com/services.php](http://www.speedyvista.com/services.php)

---

<div class="post-metadata">

**Author:** ![strqwert44](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@strqwert44](https://boards.straightdope.com/u/strqwert44)\
**Post date:** [October 12, 2009, 11:26pm UTC](https://boards.straightdope.com/t/look-at-this-hijack-this-log/513590/6 "2009-10-12T23:26:46Z")

</div>

addendum…

as the computer is XP, check out the following site and apply for the computer.

[http://www.beemerworld.com/tips/servicesxp.htm](http://www.beemerworld.com/tips/servicesxp.htm)

as for additional memory, one good site is [www.crucial.com](http://www.crucial.com)
