1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Hijack this Log After Fixing Log On Log Off Loop

Discussion in 'Windows XP' started by devnj, Oct 8, 2009.

Thread Status:
Not open for further replies.
Advertisement
  1. devnj

    devnj Thread Starter

    Joined:
    Oct 8, 2009
    Messages:
    8
    Hey everyone i was reading an old thread about the log on log off loop because my computer was expirencing the same difficulties, i managed to fix the promblem and log back on, but the end of the old thread i was reading(expired now) said to run hijack this and to send in the log file, so im sending mine now to avoid this promblem in the future,can someone tell me if there is still something wrong with my computer, thanks!
    oh and i have a dell inspiron 1100 sp3. and the person that helped me on the thread i was reading was mosiac1

    this is my log:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:02:11 AM, on 10/8/2009
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\System32\igfxtray.exe
    C:\Program Files\NETGEAR\WPN511\Utility\WPN511.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Documents and Settings\Owner\Application Data\U3\35155111AD82C629\LaunchPad.exe
    F:\Blow your mind\HijackThis.exe
    C:\Documents and Settings\Owner\Application Data\U3\35155111AD82C629\285E6953-BF3C-4445-9376-3FE5D7F645B2\Exec\bin\SignupShield.exe
    C:\WINDOWS\System32\wuauclt.exe
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [AS00_WPN511] C:\Program Files\NETGEAR\WPN511\Utility\WPN511.exe -hide
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
    --
    End of file - 2272 bytes
     
  2. Sponsor

  3. Phantom010

    Phantom010 Trusted Advisor

    Joined:
    Mar 9, 2009
    Messages:
    34,753
    Well, yes, there is a problem. XP SP1!!! .

    We're at SP3. At least update to SP2! Also update to IE7 and please get yourself an antivirus.

    Or is this a very old HijackThis log? You should always post a fresh log.
     
  4. devnj

    devnj Thread Starter

    Joined:
    Oct 8, 2009
    Messages:
    8
    i have the sp3 update on my computer but i had to use my sp1 cd when i fixed my problem..im installing sp3 now
     
  5. Phantom010

    Phantom010 Trusted Advisor

    Joined:
    Mar 9, 2009
    Messages:
    34,753
  6. devnj

    devnj Thread Starter

    Joined:
    Oct 8, 2009
    Messages:
    8
    ok here it is again updated
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:02:58 AM, on 10/8/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\NETGEAR\WPN511\Utility\WPN511.exe
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Documents and Settings\Owner\Application Data\U3\35155111AD82C629\LaunchPad.exe
    C:\Documents and Settings\Owner\Application Data\U3\35155111AD82C629\285E6953-BF3C-4445-9376-3FE5D7F645B2\Exec\bin\SignupShield.exe
    F:\Blow your mind\HijackThis.exe
    \?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [AS00_WPN511] C:\Program Files\NETGEAR\WPN511\Utility\WPN511.exe -hide
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
    --
    End of file - 2000 bytes
     
  7. Phantom010

    Phantom010 Trusted Advisor

    Joined:
    Mar 9, 2009
    Messages:
    34,753
    So far, nothing special about it. You'll have to reinstall your regular software, especially an antivirus and a firewall. With a fresh XP install, no need to post your HijackThis log.

    I would update to IE7 though...
     
  8. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    77,415
    First Name:
    Frank
    Install HijackThis 2.0.2 properly.

    Download it from here, close all open windows, then install it in its default location: C:\Program Files\Trend Micro\HijackThis.

    Run a scan, then post that new log here.

    ---------------------------------------------------------------
     
  9. devnj

    devnj Thread Starter

    Joined:
    Oct 8, 2009
    Messages:
    8
    here is the new one and im downloading ie7
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:09:22 AM, on 10/8/2009
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\NETGEAR\WPN511\Utility\WPN511.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [AS00_WPN511] C:\Program Files\NETGEAR\WPN511\Utility\WPN511.exe -hide
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
    --
    End of file - 2156 bytes
     
  10. devnj

    devnj Thread Starter

    Joined:
    Oct 8, 2009
    Messages:
    8
    my computer messed up again and i had to do a system restore
    it put me back at sp1 im going to download a fresh sp3
     
  11. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    77,415
    First Name:
    Frank
  12. devnj

    devnj Thread Starter

    Joined:
    Oct 8, 2009
    Messages:
    8
    ok more problems again upgraded from my sp1 to my fresh sp3 now this cmd promt looking box with dots flashing all in pops up and another box saying 16 bit ms-dos subsystem dl.ex on top of that my ie icon is gone and it just looks like an unknown file or something, now my internet is back to not working right so i ran hijack this again then i ran ad aware i can send that scan log if u want, thanks
    here is hijack this
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:15:00 PM, on 10/8/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\NETGEAR\WPN511\Utility\WPN511.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Documents and Settings\Owner\Application Data\U3\35155111AD82C629\LaunchPad.exe
    C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
    C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\regedit.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\SoftwareDistribution\Download\Install\windows-kb890830-v2.14.exe
    c:\4fc52b9267edc1849a08061429ac6c20\mrtstub.exe
    C:\WINDOWS\system32\MRT.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [AS00_WPN511] C:\Program Files\NETGEAR\WPN511\Utility\WPN511.exe -hide
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
    --
    End of file - 2279 bytes
     
  13. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    77,415
    First Name:
    Frank
    If you're doing a hard drive format, then doing a fresh install of XP SP1, then doing a SP3 upgrade, you're pretty much starting out with a pristine clean computer. I can't understand how you're running into problems so quickly. :confused:

    And I can't understand why your HijackThis log is so small. It should have a lot more entries than that.

    ---------------------------------------------------------------
     
  14. devnj

    devnj Thread Starter

    Joined:
    Oct 8, 2009
    Messages:
    8
    i don kno either wen i ran ad adware its said i had piarate and tenga even tho erased the whole thing and put sp1 on
     
  15. flavallee

    flavallee Trusted Advisor

    Joined:
    May 12, 2002
    Messages:
    77,415
    First Name:
    Frank
    I googled "tenga" and that name is associated with adult sex toys. :rolleyes:

    I googled "piarate" and came up empty. Did you misspell it?

    -----------------------------------------------------------------
     
  16. devnj

    devnj Thread Starter

    Joined:
    Oct 8, 2009
    Messages:
    8
    i might hav imma run it again
     
  17. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/867000

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice