Please, starting with Windows XP, I have experienced some difficulties. This, below, is a content of the log file, from Hijackthis. This entries are well?
Workstation(no network - single machine) with AMD Duron 1.6mhz. with 512mb RAM. and 40mb. IDE/HD.
----- start log
Logfile of HijackThis v1.99.1
Scan saved at 08:59:06, on 5/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\ARQUIV~1\ALWILS~1\Avast4\ashDisp.exe
C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Arquivos de programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashServ.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Arquivos de programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Arquivos de programas\Opera\Opera.exe
C:\hijack\HijackThis.exe
Thank you for help me.
I think that yes, however I cannot guarantee. I do not have much experience with the hijackthis.
The machine breaks constantly, when initiating (?).
Thanks and best regards,
off topic -If you don’t use these a lot, you might want to consider removing these from starting up every time you turn on your PC. Really not needed and might speed up your boot up.
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Arquivos de programas\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
Hijackthis is searching for ‘C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe" /service’ (including double quotes and ‘/service’ parameter) as a file, this causes ‘file missing’, because only present is ‘C:\Arquivos de programas\Alwil Software\Avast4\ashMaiSv.exe’.
Hi druzilla, you appear to missing the 02 entries whilst it is not beyond possibility that you have none it is also a sign of malware intrusion. So I would suggest you rename HJT to somthing else e.g. Gotcha and then re-run it and see if you get any 02 entries appearing. If you do it may be a sign of a Virtumondo infection