- Joined
- Aug 30, 2007
- Messages
- 8
- Reaction score
- 0
RESPECTED ADMINISTRATOR
TWO DAYS BACK AS I WAS BROWSING I FOUND THAT MY SYSTEM IS BECOMING VERY SLOW . SO WHEN I CLICKED MY START MENU THERE WAS NO CONTROL PANEL MENU AND THEN I TRIED TO OPEN MY COMPUTER AND IN IT I CLICKED ADD OR REMOVE PROGRAM BUT I WAS DENIED ACCESS AND A MESSAGE CAME STATING THAT "THIS OPERATION HAS BEEN CANCELLED DUE TO RESTRICTIONS IN EFFECT IN THIS COMPUTER. PLEASE CONTACT YOUR SYSTEM ADMINISTRATOR".
OPERATING SYSTEM -WINDOWS XP
ANTI VIRUS SOFTWARE -AVG
ANTI SPYWARE SOFTWARE-SPYBOT
NET CONNECTION-56K
OS Name Microsoft Windows XP Professional
Version 5.1.2600 Build 2600
OS Manufacturer Microsoft Corporation
System Type X86-based PC
Processor x86 Family 6 Model 8 Stepping 1 AuthenticAMD ~1470 Mhz
BIOS Version/Date Award Software, Inc. ASUS A7N266-VM ACPI BIOS Rev 1005, 19/11/2002
SMBIOS Version 2.3
Windows Directory D:\WINDOWS
System Directory D:\WINDOWS\System32
Boot Device \Device\HarddiskVolume1
Locale United States
Hardware Abstraction Layer Version = "5.1.2600.0 (xpclient.010817-1148)"
User Name SUJITH\SUJITH M S
Time Zone India Standard Time
Total Physical Memory 128.00 MB
Available Physical Memory 10.11 MB
Total Virtual Memory 894.32 MB
Available Virtual Memory 594.27 MB
Page File Space 798.98 MB
Page File C:\pagefile.sys
AFTER THAT I RAN HIJACKTHIS ON MY COMPUTER AND THE LOG I AM POSTING BELOW.
PLEASE HELP ME SOLVE MY PROBLEM.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:45:00, on 30/08/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\Explorer.exe
D:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
D:\WINDOWS\System32\NVATray.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Google\Google Talk\googletalk.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\SUJITH M S\Desktop\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: Shell=Explorer.exe D:\WINDOWS\System32\printer.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [Microsoft Startup Manager] D:\WINDOWS\System32\sysservice.exe
O4 - HKLM\..\Run: [Easy-PrintToolBox] D:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WinAVX] D:\WINDOWS\System32\WinAvXX.exe
O4 - HKLM\..\Run: [NVIDIA nForce APU1 Utilities] NVATray.exe
O4 - HKLM\..\Run: [googletalk] D:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WinAVX] D:\WINDOWS\System32\WinAvXX.exe
O4 - Startup: system.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: autorun.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Enable / Disable Yoomba - {BAE22299-19C5-4f46-94A7-6D7A27212707} - D:\WINDOWS\System32\shdocvw.dll (HKCU)
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {EECC2B58-FDE7-4F3A-B933-B25BE90F1D37} (CTXAXSetupCtl Object) - http://download.yoomba.com/YoombaActivation.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{63656B50-9DC7-441C-8978-4A1AC0A38350}: NameServer = 218.248.255.145 218.248.240.23
O17 - HKLM\System\CS1\Services\Tcpip\..\{63656B50-9DC7-441C-8978-4A1AC0A38350}: NameServer = 218.248.255.145 218.248.240.23
O20 - AppInit_DLLs: D:\WINDOWS\System32\hadjajr.ini
O22 - SharedTaskScheduler: fagging - {94524218-9af3-4643-9687-cbc2880e54da} - (no file)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O24 - Desktop Component 0: (no name) - file:///D:/DOCUME~1/SUJITH~1/LOCALS~1/Temp/msohtml1/01/clip_image002.gif
--
End of file - 4488 bytes
TWO DAYS BACK AS I WAS BROWSING I FOUND THAT MY SYSTEM IS BECOMING VERY SLOW . SO WHEN I CLICKED MY START MENU THERE WAS NO CONTROL PANEL MENU AND THEN I TRIED TO OPEN MY COMPUTER AND IN IT I CLICKED ADD OR REMOVE PROGRAM BUT I WAS DENIED ACCESS AND A MESSAGE CAME STATING THAT "THIS OPERATION HAS BEEN CANCELLED DUE TO RESTRICTIONS IN EFFECT IN THIS COMPUTER. PLEASE CONTACT YOUR SYSTEM ADMINISTRATOR".
OPERATING SYSTEM -WINDOWS XP
ANTI VIRUS SOFTWARE -AVG
ANTI SPYWARE SOFTWARE-SPYBOT
NET CONNECTION-56K
OS Name Microsoft Windows XP Professional
Version 5.1.2600 Build 2600
OS Manufacturer Microsoft Corporation
System Type X86-based PC
Processor x86 Family 6 Model 8 Stepping 1 AuthenticAMD ~1470 Mhz
BIOS Version/Date Award Software, Inc. ASUS A7N266-VM ACPI BIOS Rev 1005, 19/11/2002
SMBIOS Version 2.3
Windows Directory D:\WINDOWS
System Directory D:\WINDOWS\System32
Boot Device \Device\HarddiskVolume1
Locale United States
Hardware Abstraction Layer Version = "5.1.2600.0 (xpclient.010817-1148)"
User Name SUJITH\SUJITH M S
Time Zone India Standard Time
Total Physical Memory 128.00 MB
Available Physical Memory 10.11 MB
Total Virtual Memory 894.32 MB
Available Virtual Memory 594.27 MB
Page File Space 798.98 MB
Page File C:\pagefile.sys
AFTER THAT I RAN HIJACKTHIS ON MY COMPUTER AND THE LOG I AM POSTING BELOW.
PLEASE HELP ME SOLVE MY PROBLEM.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:45:00, on 30/08/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\Explorer.exe
D:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
D:\WINDOWS\System32\NVATray.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Google\Google Talk\googletalk.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\SUJITH M S\Desktop\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: Shell=Explorer.exe D:\WINDOWS\System32\printer.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [Microsoft Startup Manager] D:\WINDOWS\System32\sysservice.exe
O4 - HKLM\..\Run: [Easy-PrintToolBox] D:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WinAVX] D:\WINDOWS\System32\WinAvXX.exe
O4 - HKLM\..\Run: [NVIDIA nForce APU1 Utilities] NVATray.exe
O4 - HKLM\..\Run: [googletalk] D:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WinAVX] D:\WINDOWS\System32\WinAvXX.exe
O4 - Startup: system.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: autorun.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://D:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Enable / Disable Yoomba - {BAE22299-19C5-4f46-94A7-6D7A27212707} - D:\WINDOWS\System32\shdocvw.dll (HKCU)
O12 - Plugin for .spop: D:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {EECC2B58-FDE7-4F3A-B933-B25BE90F1D37} (CTXAXSetupCtl Object) - http://download.yoomba.com/YoombaActivation.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{63656B50-9DC7-441C-8978-4A1AC0A38350}: NameServer = 218.248.255.145 218.248.240.23
O17 - HKLM\System\CS1\Services\Tcpip\..\{63656B50-9DC7-441C-8978-4A1AC0A38350}: NameServer = 218.248.255.145 218.248.240.23
O20 - AppInit_DLLs: D:\WINDOWS\System32\hadjajr.ini
O22 - SharedTaskScheduler: fagging - {94524218-9af3-4643-9687-cbc2880e54da} - (no file)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe
O24 - Desktop Component 0: (no name) - file:///D:/DOCUME~1/SUJITH~1/LOCALS~1/Temp/msohtml1/01/clip_image002.gif
--
End of file - 4488 bytes
Last edited: