questions about TCP optimizer

General discussion related to Cable Modems, DSL, Wireless, Fiber, Mobile Networks, Wireless ISPs, Satellite, or any other type of high-speed Internet connection, general issues and questions here. Review and discuss ISPs as well (AT&T / SBC, BellSouth, Bright House, CableOne, Charter, Comcast, Covad, Cox, Cablevision / Optimum Online, TMobile, Verizon FIOS, Shaw, Telus, Starlink, etc.)
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

questions about TCP optimizer

Post by Brave_heart »

sorry if this is the wrong forum, if so please move.

ok so i have been having ping problems in online games, so i installed TCP optimizer, but i dont know what to do with it, will it even work with vista 64? what do i set the settings to? and how do i know if i am "capped" or not?

also: Image so as you can see i have no problem with my internet speed, theres just something wrong with my ping...so what ever i can do to improve my ping would be great.
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Vista is auto-tuning and cannot be tweaked.

Check signal quality.

Do a tracert to http://www.yahoo.com and post.
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

what do you mean Vista is auto tweaked?

that was the first thing i did

what is a tracert?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Brave_heart wrote:what do you mean Vista is auto tweaked?

that was the first thing i did

what is a tracert?
Vista will adjust RWIN automatically to suit the latency of your connections. Thus, you cannot set a static value for it.

To do a tracert, click 'Start' and then 'Run'. Type "cmd" into the box and click 'ok'.

A DOS black screen will appear. Type after the C:\>

tracert http://www.yahoo.com

and press enter key

When test is completed, move mouse cursor to the DOS black screen, click right and choose 'select all'.

Move mouse cursor to the Quick Reply box of this forum, click right and 'paste'.
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

trogers wrote:Vista will adjust RWIN automatically to suit the latency of your connections. Thus, you cannot set a static value for it.

To do a tracert, click 'Start' and then 'Run'. Type "cmd" into the box and click 'ok'.

A DOS black screen will appear. Type after the C:\>

tracert http://www.yahoo.com

and press enter key

When test is completed, move mouse cursor to the DOS black screen, click right and choose 'select all'.

Move mouse cursor to the Quick Reply box of this forum, click right and 'paste'.
click start? dude, what does that mean? click what start?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
YARDofSTUF
Posts: 70006
Joined: Sat Nov 11, 2000 12:00 am
Location: USA

Post by YARDofSTUF »

Brave_heart wrote:click start? dude, what does that mean? click what start?
Windows vista picture at the bottom left of the screen.
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

YARDofSTUF wrote:Windows vista picture at the bottom left of the screen.
gotcha, the word start can mean plenty of things, i thought he was talking about some program.

ok here it is: Microsoft Windows [Version 6.0.6001]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.

C:\Users\Luke>tracert http://www.yahoo.com

Tracing route to http://www.yahoo-ht3.akadns.net [209.131.36.158]
over a maximum of 30 hops:

1 1 ms 1 ms <1 ms 192.168.1.1
2 13 ms 12 ms 11 ms ip24-251-120-1.ph.ph.cox.net [24.251.120.1]
3 14 ms 13 ms 12 ms 68.2.9.17
4 13 ms 33 ms 12 ms 68.2.12.166
5 11 ms 11 ms 13 ms 68.2.12.30
6 23 ms 17 ms 8 ms chnddsrj02-ae1.0.rd.ph.cox.net [68.2.14.13]
7 34 ms 26 ms 33 ms langbbr01-ae0.r2.la.cox.net [68.1.0.232]
8 33 ms 35 ms 55 ms ge-1-3-4-p143.pat1.pao.yahoo.com [216.115.96.46]

9 50 ms 48 ms 43 ms g-0-0-0-p161.msr1.sp1.yahoo.com [216.115.107.59]

10 35 ms 46 ms 50 ms te-9-1.bas-a1.sp1.yahoo.com [209.131.32.21]
11 37 ms 38 ms 36 ms f1.http://www.vip.sp1.yahoo.com [209.131.36.158]

Trace complete.

C:\Users\Luke>
what does it mean?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Brave_heart wrote: Tracing route to http://www.yahoo-ht3.akadns.net [209.131.36.158]
over a maximum of 30 hops:

1 1 ms 1 ms <1 ms 192.168.1.1
2 13 ms 12 ms 11 ms ip24-251-xxx-xxx.ph.ph.cox.net [24.251.xxx.xxx]
3 14 ms 13 ms 12 ms 68.2.9.17
4 13 ms 33 ms 12 ms 68.2.12.166
5 11 ms 11 ms 13 ms 68.2.12.30
6 23 ms 17 ms 8 ms chnddsrj02-ae1.0.rd.ph.cox.net [68.2.14.13]
7 34 ms 26 ms 33 ms langbbr01-ae0.r2.la.cox.net [68.1.0.232]
8 33 ms 35 ms 55 ms ge-1-3-4-p143.pat1.pao.yahoo.com [216.115.96.46]
9 50 ms 48 ms 43 ms g-0-0-0-p161.msr1.sp1.yahoo.com [216.115.107.59]
10 35 ms 46 ms 50 ms te-9-1.bas-a1.sp1.yahoo.com [209.131.32.21]
11 37 ms 38 ms 36 ms f1.http://www.vip.sp1.yahoo.com [209.131.36.158]

Trace complete.

C:\Users\Luke>
what does it mean?
Slight irregular ping times at the modem in hop 2 that cascade down to later hops (4,6,7).

Your modem is probably being affected by electromagnetic interference from some nearby device.

Turn off power to the modem and relocate it to a place a few feet away from ALL other electrical devices, including away from the router.
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

trogers wrote:Slight irregular ping times at the modem in hop 2 that cascade down to later hops (4,6,7).

Your modem is probably being affected by electromagnetic interference from some nearby device.

Turn off power to the modem and relocate it to a place a few feet away from ALL other electrical devices, including away from the router.
really? ok i turned it off and moved it far away from the computer and the router(it was right next to the computer) and then i tested it again:

Microsoft Windows [Version 6.0.6001]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.

C:\Users\Luke>tracert http://www.yahoo.com

Tracing route to http://www.yahoo-ht3.akadns.net [209.131.36.158]
over a maximum of 30 hops:

1 1 ms 1 ms <1 ms 192.168.1.1
2 13 ms 12 ms 11 ms ip24-251-120-1.ph.ph.cox.net [24.251.120.1]
3 14 ms 13 ms 12 ms 68.2.9.17
4 13 ms 33 ms 12 ms 68.2.12.166
5 11 ms 11 ms 13 ms 68.2.12.30
6 23 ms 17 ms 8 ms chnddsrj02-ae1.0.rd.ph.cox.net [68.2.14.13]
7 34 ms 26 ms 33 ms langbbr01-ae0.r2.la.cox.net [68.1.0.232]
8 33 ms 35 ms 55 ms ge-1-3-4-p143.pat1.pao.yahoo.com [216.115.96.46]

9 50 ms 48 ms 43 ms g-0-0-0-p161.msr1.sp1.yahoo.com [216.115.107.59]

10 35 ms 46 ms 50 ms te-9-1.bas-a1.sp1.yahoo.com [209.131.32.21]
11 37 ms 38 ms 36 ms f1.http://www.vip.sp1.yahoo.com [209.131.36.158]

Trace complete.

C:\Users\Luke>

is that better?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

I think this is the previous tracert.

Do a fresh one and post.
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
ejack681

Post by ejack681 »

hey. i have the same prob but totally the same. but when i tried the optimizer, my connection didnt change, i think it slowed it down.. idk.. im confused.. i have a router. should i take my router out to see the effect?
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

ejack681 wrote:hey. i have the same prob but totally the same. but when i tried the optimizer, my connection didnt change, i think it slowed it down.. idk.. im confused.. i have a router. should i take my router out to see the effect?
Start a new thread. Tell us what speed you paid to get and post your TCP Analyzer report.
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

ejack681 wrote:hey. i have the same prob but totally the same. but when i tried the optimizer, my connection didnt change, i think it slowed it down.. idk.. im confused.. i have a router. should i take my router out to see the effect?
my thread, make your own please ;)

ok I'll try it again:
Microsoft Windows [Version 6.0.6001]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.

C:\Users\Luke>tracert http://www.yahoo.com

Tracing route to http://www.yahoo-ht3.akadns.net [209.131.36.158]
over a maximum of 30 hops:

1 2 ms 1 ms <1 ms 192.168.1.1
2 12 ms 12 ms 13 ms ip24-251-120-1.ph.ph.cox.net [24.251.120.1]
3 13 ms 73 ms 59 ms 68.2.9.17
4 11 ms 12 ms 16 ms 68.2.12.166
5 12 ms 18 ms 13 ms 68.2.12.30
6 37 ms 24 ms 13 ms chnddsrj01-ae1.0.rd.ph.cox.net [68.2.14.1]
7 27 ms 20 ms 25 ms langbbr01-ae0.r2.la.cox.net [68.1.0.232]
8 33 ms 44 ms 35 ms ge-1-3-4-p143.pat1.pao.yahoo.com [216.115.96.46]

9 37 ms 35 ms 43 ms g-0-0-0-p171.msr2.sp1.yahoo.com [216.115.107.83]

10 30 ms 58 ms 36 ms te-9-1.bas-a1.sp1.yahoo.com [209.131.32.21]
11 72 ms 39 ms 41 ms f1.http://www.vip.sp1.yahoo.com [209.131.36.158]

Trace complete.

C:\Users\Luke>

is that better?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Brave_heart wrote: 1 2 ms 1 ms <1 ms 192.168.1.1
2 12 ms 12 ms 13 ms ip24-251-xxx-xxx.ph.ph.cox.net [24.251.xxx.xxx] <= X out for security reason
3 13 ms 73 ms 59 ms 68.2.9.17
4 11 ms 12 ms 16 ms 68.2.12.166
5 12 ms 18 ms 13 ms 68.2.12.30
Check and make sure the cable connecting the modem to the wall socket are not coiled or twisted and not damaged. Check and ensure all connectors are tightly seated.

Do you have any large electrical equipment placed nearby, eg. guitar amp or sub-woofer?
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

trogers wrote:Check and make sure the cable connecting the modem to the wall socket are not coiled or twisted and not damaged. Check and ensure all connectors are tightly seated.

Do you have any large electrical equipment placed nearby, eg. guitar amp or sub-woofer?
ok, and no i dont have anything like that.
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Brave_heart wrote:ok, and no i dont have anything like that.
The you need to get your ISP tech to check out the connection line, that connects your modem to their switch.
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

ok, oh and there might be a cut in my ethernet cord...would that be helping make these problems?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Brave_heart wrote:ok, oh and there might be a cut in my ethernet cord...would that be helping make these problems?
Replace the damaged ethernet cord.
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

trogers wrote:Replace the damaged ethernet cord.
i ordered one from newegg, oh and i chatted with cox support today, they said it was my routers fault :irate:
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

installed new cat6 cable, straightened out all kinks and twists that i could find in any of the cables.

Microsoft Windows [Version 6.0.6001]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.

C:\Users\Luke>tracert http://www.yahoo.com

Tracing route to http://www.yahoo-ht3.akadns.net [209.191.93.52]
over a maximum of 30 hops:

1 2 ms <1 ms 1 ms 192.168.1.1
2 15 ms 28 ms 32 ms ip24-251-120-1.ph.ph.cox.net [24.251.120.1]
3 96 ms 29 ms 21 ms 68.2.9.17
4 18 ms 20 ms 105 ms 68.2.12.166
5 12 ms 16 ms 20 ms 68.2.12.30
6 13 ms 80 ms 21 ms chnddsrj02-ae1.0.rd.ph.cox.net [68.2.14.13]
7 46 ms 29 ms 39 ms langbbr01-ae0.r2.la.cox.net [68.1.0.232]
8 55 ms 54 ms 82 ms ge-1-3-4-p144.pat1.pao.yahoo.com [216.115.96.50]

9 55 ms * 76 ms ge-0-1-0-p100.msr1.mud.yahoo.com [216.115.104.97
]
10 49 ms 62 ms 116 ms te-8-1.bas-c1.mud.yahoo.com [68.142.193.5]
11 61 ms 80 ms 50 ms f1.http://www.vip.mud.yahoo.com [209.191.93.52]

Trace complete.

C:\Users\Luke>

is that better? also, i was installing UT3 in the back....would that affect it?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Post a hijackthis log.
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

trogers wrote:Post a hijackthis log.
i am a n00b with networking and this forum....please explain what you mean :)
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Brave_heart wrote:i am a n00b with networking and this forum....please explain what you mean :)
Go to this link and download and run Hijackthis. Then post the log:

http://www.download.com/Trend-Micro-Hij ... 27353.html
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

ok, here it is:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:34:13 PM, on 4/22/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe
C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files (x86)\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razertra.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerofa.exe
C:\Program Files (x86)\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files (x86)\EasyCal -- 1\ZSMVGDP.EXE
C:\Program Files (x86)\Xfire\xfire.exe
C:\Program Files (x86)\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Diamondback] "C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files (x86)\OpenOffice.org 2.4\program\quickstart.exe
O4 - Startup: Xfire.lnk = C:\Program Files (x86)\Xfire\xfire.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files (x86)\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 6706 bytes

what does it mean?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Brave_heart wrote:ok, here it is:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:34:13 PM, on 4/22/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe
C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files (x86)\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razertra.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerofa.exe
C:\Program Files (x86)\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files (x86)\EasyCal -- 1\ZSMVGDP.EXE
C:\Program Files (x86)\Xfire\xfire.exe
C:\Program Files (x86)\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Diamondback] "C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files (x86)\OpenOffice.org 2.4\program\quickstart.exe
O4 - Startup: Xfire.lnk = C:\Program Files (x86)\Xfire\xfire.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files (x86)\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)


--
End of file - 6706 bytes

what does it mean?
Your comp has been hijacked. See this: http://www.fileresearchcenter.com/U/USE ... -9993.html

I have list the suspicious items in red, especially those of 'unknown owner' and (file missing).

Follow the guide of Mnosteele52 at this thread to weed out the infection:

http://forums.speedguide.net/showthread.php?t=240054
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

ok, i am following that guide, but i am not sure what settings i should run crap cleaner at...theres tons of little things to check off, can someone tell me which to pick?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Brave_heart wrote:ok, i am following that guide, but i am not sure what settings i should run crap cleaner at...theres tons of little things to check off, can someone tell me which to pick?
The only thing I exclude is 'installer' under Registry. All else are cleaned or fixed.
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

got it, thanks.
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

i have done steps 1 thru 7 but ad aware and AVG are not working...when i start AVG this error message comes up: Image
what do i do?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Do not install AVG antivirus. Step 7 ask you to download and install AVG antispyware, and then update it and do a complete scan of your comp.

I think the link has to be updated:

http://free.grisoft.com/doc/download-free-anti-spyware/
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

ok, so i am on step 8 (been taking all day because i am a teen with school and a life) and i installed and ran autruns, now what do i do with it?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

windows defender does not support vista, what is a good alternative? or is it alright to skip that step?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

I think you can skip steps 8 and 9.

After scanning and cleaning comp with AVG antispyware, reboot comp and post a new Hijackthis log.
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

ok, i did everything that i could, heres the result:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:34:13 PM, on 4/22/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe
C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files (x86)\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razertra.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerofa.exe
C:\Program Files (x86)\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files (x86)\EasyCal -- 1\ZSMVGDP.EXE
C:\Program Files (x86)\Xfire\xfire.exe
C:\Program Files (x86)\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Diamondback] "C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files (x86)\OpenOffice.org 2.4\program\quickstart.exe
O4 - Startup: Xfire.lnk = C:\Program Files (x86)\Xfire\xfire.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files (x86)\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 6706 bytes

i still see the "unknown owner" in there...can you highlight what i need to "fix" with highjackthis?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
mccoffee
Posts: 13365
Joined: Sat Nov 03, 2001 12:00 pm
Location: Cleveland, Ohio, United States

Post by mccoffee »

O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)


Thease look fishy since it's unknown owner file missing also try downloading and running cccleaner it's a free app it also fixes registry essues as well http://www.ccleaner.com/
Comptia a+ n+
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Brave Heart, are you using a genuine copy of Vista?
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

mccoffee wrote:O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)


Thease look fishy since it's unknown owner file missing also try downloading and running cccleaner it's a free app it also fixes registry essues as well http://www.ccleaner.com/
i have crap cleaner and i have used it many times.

@ trogers, yes, it's an genuine OEM 64bit home premium from ClubIT.com
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:34:13 PM, on 4/22/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe
C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files (x86)\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razertra.exe
C:\Program Files (x86)\Razer\Diamondback 3G\razerofa.exe
C:\Program Files (x86)\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files (x86)\EasyCal -- 1\ZSMVGDP.EXE
C:\Program Files (x86)\Xfire\xfire.exe
C:\Program Files (x86)\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Diamondback] "C:\Program Files (x86)\Razer\Diamondback 3G\razerhid.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files (x86)\OpenOffice.org 2.4\program\quickstart.exe
O4 - Startup: Xfire.lnk = C:\Program Files (x86)\Xfire\xfire.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files (x86)\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 6706 bytes

:irate: :wth: :cry: :mad: :( :confused: it's still there, i have done everything...i really need your help guys.
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

I am not well verse in the correct Hijack log of Vista. Perhaps someone else can give guidance.
"Contentment is not the fulfillment of what you want, but is the realisation of how much you already have" - anon
User avatar
Brave_heart
Member
Posts: 64
Joined: Fri Apr 18, 2008 8:05 pm

Post by Brave_heart »

trogers wrote:I am not well verse in the correct Hijack log of Vista. Perhaps someone else can give guidance.
ok, thanks for all the help man.


anyone else? it's still there, am i missing something?
512MB 8800 GTS|AMD athlon 6000 X2|4GB OCZ platinum 800|700W OCZ gamexstream|gigabyte MA770|modded coolermaster mystique|250GB barracuda|razer diamondback| vista 64 HP
Post Reply