mystree911 Posted January 15, 2009 Report Share Posted January 15, 2009 Please review this and see if anything is obviously wrong. My PC has drastically slowed during gaming and I am not sure why.ThanksLogfile of Trend Micro HijackThis v2.0.2Scan saved at 9:02:05 AM, on 1/15/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16762)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exeC:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exeC:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exeC:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exeC:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeC:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\CTHELPER.EXEC:\Program Files\AGEIA Technologies\bin\TrayIcon.exeC:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exeC:\Program Files\CAT\cat.exeC:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exeC:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exeC:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Plaxo\3.13.1.2\PlaxoHelper_en.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\CA\CA Internet Security Suite\ccprovsp.exeC:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exeC:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\wuauclt.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com/browsers/redirect/?b=RRH...RR&d=homerrR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/browsers/redirect/?b=RRH...RR&d=homerrR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com/browsers/redirect/?b=RRH...RR&d=homerrR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/browsers/redirect/?b=RRH...RR&d=homerrR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Road Runner High Speed OnlineR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localO2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {8151A608-00FB-4D5C-8B8D-40E239E32A42} - (no file)O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXEO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exeO4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exeO4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\bin\TrayIcon.exeO4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"O4 - HKLM\..\Run: [cat] C:\Program Files\CAT\cat.exeO4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -clO4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exeO4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exeO4 - HKLM\..\Run: [cafw] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -clO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\3.13.1.2\PlaxoHelper_en.exe -aO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.13.1.2\PlaxoSysTray.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: Aces Up! by pogo - http://game3.pogo.com/v/9.1.1.8/applet/aces/aces-en_US.cabO16 - DPF: Addiction by pogo - http://game3.pogo.com/v/9.1.1.8/applet/add...ction-en_US.cabO16 - DPF: Alibaba Slots - http://game3.pogo.com/v/9.1.2.3/applet/ali...ibaba-en_US.cabO16 - DPF: Blackjack by pogo - http://game3.pogo.com/v/9.1.1.8/applet/bla...kjack-en_US.cabO16 - DPF: Blooop by pogo - http://game3.pogo.com/v/9.1.3.19/applet/ca...scade-en_US.cabO16 - DPF: Crazy Cakes by pogo - http://game3.pogo.com/v/9.0.3.19/applet/pl...inner-en_US.cabO16 - DPF: Dice Derby by pogo - http://game3.pogo.com/v/9.1.1.1/applet/che...dflag-en_US.cabO16 - DPF: First Class Solitaire by pogo - http://game3.pogo.com/v/9.1.3.19/applet/fi...lass2-en_US.cabO16 - DPF: Fortune Bingo by pogo - http://game3.pogo.com/v/9.1.1.1/applet/sup...bingo-en_US.cabO16 - DPF: Harvest Mania by pogo - http://game3.pogo.com/v/9.1.3.19/applet/ha...rvest-en_US.cabO16 - DPF: Jigsaw Treasure Hunter - http://game3.pogo.com/v/9.1.2.19/applet/jth/jth-en_US.cabO16 - DPF: Jungle Gin by pogo - http://game3.pogo.com/v/9.1.1.1/applet/gin2/gin2-en_US.cabO16 - DPF: Mah Jong Garden by pogo - http://game3.pogo.com/v/9.1.1.1/applet/mah...jong2-en_US.cabO16 - DPF: Mahjong Safari by Pogo - http://game3.pogo.com/v/9.1.4.5/applet/saf...afari-en_US.cabO16 - DPF: Makeover Madness by pogo - http://game3.pogo.com/v/9.1.3.19/applet/sh...shoes-en_US.cabO16 - DPF: Monopoly by pogo - http://game3.pogo.com/v/9.1.4.9/applet/mon...opoly-en_US.cabO16 - DPF: Perfect Pair Solitaire by pogo - http://game3.pogo.com/v/9.1.1.1/applet/wat...wheel-en_US.cabO16 - DPF: Poppit by pogo - http://game3.pogo.com/v/9.1.3.19/applet/po...ppit2-en_US.cabO16 - DPF: Quick Quack by pogo - http://game3.pogo.com/v/9.0.9.8/applet/hot...treak-en_US.cabO16 - DPF: QWERTY by pogo - http://game3.pogo.com/v/9.0.5.4/applet/squ...uares-en_US.cabO16 - DPF: SciFi Slots by pogo - http://game3.pogo.com/v/9.1.1.1/applet/slots/scifi-en_US.cabO16 - DPF: Scrabble by pogo - http://game3.pogo.com/v/9.0.9.8/applet/scr...abble-en_US.cabO16 - DPF: Showbiz Slots by pogo - http://game3.pogo.com/v/9.1.3.19/applet/sl...owbiz-en_US.cabO16 - DPF: Squelchies by pogo - http://game3.pogo.com/v/9.0.8.20/applet/sq...chies-en_US.cabO16 - DPF: Sweet Tooth 2 by Pogo - http://game3.pogo.com/v/9.0.1.7/applet/swe...ooth2-en_US.cabO16 - DPF: Team Bingo by Pogo - http://game3.pogo.com/v/9.1.3.19/applet/te...bingo-en_US.cabO16 - DPF: Thousand Island Solitaire by pogo - http://game3.pogo.com/v/9.0.9.8/applet/mil...lbrae-en_US.cabO16 - DPF: Tri-Peaks by pogo - http://game3.pogo.com/v/9.1.1.1/applet/peaks/peaks-en_US.cabO16 - DPF: Trivial Pursuit by pogo - http://game3.pogo.com/v/9.1.3.32/applet/tr...ivial-en_US.cabO16 - DPF: Tumble Bees by pogo - http://game3.pogo.com/v/9.0.8.20/applet/tu...mbee2-en_US.cabO16 - DPF: Vaults of Atlantis Slots by pogo - http://game3.pogo.com/v/9.0.5.4/applet/mls...slots-en_US.cabO16 - DPF: Wonderland Memories by pogo - http://game3.pogo.com/v/9.0.8.20/applet/me...ories-en_US.cabO16 - DPF: Word Craft by pogo - http://game3.pogo.com/v/9.1.3.19/applet/ba...abble-en_US.cabO16 - DPF: Word Whomp by pogo - http://game3.pogo.com/v/9.0.9.8/applet/wor...homp2-en_US.cabO16 - DPF: Word Whomp Whackdown by pogo - http://game3.pogo.com/v/9.0.1.7/applet/wha...kdown-en_US.cabO16 - DPF: WordJong by pogo - http://game3.pogo.com/v/9.0.1.7/applet/wor...djong-en_US.cabO16 - DPF: World Class Solitaire by pogo - http://game3.pogo.com/v/9.1.8.1/applet/wor...class-en_US.cabO16 - DPF: {0713E8D2-850A-101B-AFC0-4210102A8DA7} (Microsoft ProgressBar Control, version 5.0 (SP2)) - http://download.mcafee.com/molbin/Shared/C...22/ComCtl32.cabO16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/download...ne_Inst_Win.cabO16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://www.pogo.com/cdl/launcher/PogoWebLa...erInstaller.CABO16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc...OnlineGames.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1152756474671O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/webgames/popcaploader_v10.cabO16 - DPF: {F10C33E8-4EC0-4369-B365-730450CF5A09} (CPlayFirstDDTumsControl Object) - http://www.gamehouse.com/realarcade-webgam...nerDashTums.cabO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exeO23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exeO23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exeO23 - Service: Sony SPTI Service for DVE (ICDSPTSV) - Sony Corporation - C:\WINDOWS\system32\IcdSptSv.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: InCD Helper (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe (file missing)O23 - Service: InCD Helper (read only) (InCDsrvR) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe (file missing)O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exeO23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exeO23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exeO23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exeO23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exeO23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe--End of file - 13349 bytes Link to post Share on other sites
Andro1d Posted January 18, 2009 Report Share Posted January 18, 2009 Hello and Welcome to the forums. I am MoNsTeReNeRgY22 and I will be assisting you with your computer problem today. Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.Please re-open HijackThis and scan. Check the boxes next to all the entries listed below. O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXEO4 - HKLM\..\Run: [cat] C:\Program Files\CAT\cat.exeNow close all windows other than Hijackthis, then click Fix Checked. Close HijackThis. Reboot into safe mode.Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.Please enter Safe Mode by using the Arrow Keys and then hit Enter.Please go to Start > Control Panel > Add or Remove Programs and remove the following (if present):CATPlease note any other programs that you dont recognize in that list in your next responseUsing Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these folders (if present):C:\Program Files\CATAfter that, Reboot to Normal Mode.Please post a fresh HJT log when you are done.Also, have you upgraded any drivers on your computer lately? Link to post Share on other sites
Andro1d Posted February 3, 2009 Report Share Posted February 3, 2009 Inactive topic...If you still need help on this problem, contact me or one of the Moderators to re-open this up.Topic closed. Link to post Share on other sites
Recommended Posts