![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Aug 2009
Posts: 2
OS: xp
|
My Computer Running Slow Please Help
I ran hijack this and made log file. Please help me figure out whats wrong.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 오전 10:04:14, on 2009-08-11 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\AhnLab\V3Lite\V3LTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\drivers\CDAC11BA.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\Naver\NaverPCGreen\Nsavsvc.npc C:\Program Files\Naver\NaverPCGreen\Nsvmon.npc C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe C:\ugs\license\lmgrd.exe C:\ugs\license\lmgrd.exe C:\Program Files\AhnLab\V3Lite\V3LSvc.exe C:\ugs\license\ugslmd.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\Naver\NaverPCGreen\NPCGreenAgent.npc C:\WINDOWS\system32\SearchProtocolHost.exe C:\Program Files\AhnLab\SiteGuard\SGsvc.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe O2 - BHO: Site Gaurd - {19217B99-F935-4A39-B857-A68A68D5BEBB} - C:\Program Files\AhnLab\SiteGuard\SGAgenti.dll O2 - BHO: Mplus Reward Class - {4465BF12-801F-449c-AA43-B01FCA95B830} - C:\PROGRA~1\Mplus\MG_RWD~1.DLL O2 - BHO: 탭브라우저 - {4864C73D-A2A9-42E7-B840-21306C7F87FD} - C:\PROGRA~1\ktoolbar\TABBRO~1.DLL O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Mplus Search Class - {8EA9A253-227C-4b03-9DD7-A138E8600430} - C:\Program Files\Mplus\mg_src_1f.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: 탭브라우저 - {4864C73D-A2A9-42E7-B840-21306C7F87FD} - C:\PROGRA~1\ktoolbar\TABBRO~1.DLL O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Korean IME Migration] C:\PROGRA~1\COMMON~1\MICROS~1\IME12\IMEKR\IMKRMIG.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [NaverPCGreen] "C:\Program Files\Naver\NaverPCGreen\NPCGreenUpgrader.exe" /reboot O4 - HKLM\..\Run: [HncUpdate] C:\WINDOWS\system32\HncUpdate.exe /A O4 - HKLM\..\Run: [KSignSWATCheck] C:\Program Files\KSign\KSignSWAT\SWATCheck.exe O4 - HKLM\..\Run: [AhnLab V3Lite Tray Process] "C:\Program Files\AhnLab\V3Lite\V3LTray.exe" /logon O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [\\HYUNJOO\EPSON Stylus Photo 1390 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBXP.EXE /FU "C:\WINDOWS\TEMP\E_SBA.tmp" /EF "HKCU" O4 - HKCU\..\Run: [\\B\EPSON Stylus Photo 1390 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBXP.EXE /FU "C:\DOCUME~1\YK\LOCALS~1\Temp\E_S57.tmp" /EF "HKCU" O4 - HKCU\..\Run: [\\SERVER\EPSON Stylus Photo 1390 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBXP.EXE /FU "C:\DOCUME~1\YK\LOCALS~1\Temp\E_S2EF.tmp" /EF "HKCU" O4 - HKCU\..\Run: [\\B\EPSON Stylus Photo 1390 Series(1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBXP.EXE /FU "C:\DOCUME~1\YK\LOCALS~1\Temp\E_S57.tmp" /EF "HKCU" O4 - HKCU\..\Run: [\\HYUNJOO\EPSON Stylus Photo 1390 Series(1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBXP.EXE /FU "C:\WINDOWS\TEMP\E_SBA.tmp" /EF "HKCU" O4 - HKCU\..\Run: [\\SERVER\EPSON Stylus Photo 1390 Series(1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBXP.EXE /FU "C:\DOCUME~1\YK\LOCALS~1\Temp\E_S2EF.tmp" /EF "HKCU" O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] ctfmon.exe (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] ctfmon.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] ctfmon.exe (User 'Default user') O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: *.acegolf.com O15 - Trusted Zone: *.americanexpress.co.kr O15 - Trusted Zone: http://*.artreon.co.kr O15 - Trusted Zone: creative365.cafe24.com O15 - Trusted Zone: *.mpi.dacom.net O15 - Trusted Zone: *.hometax.go.kr O15 - Trusted Zone: *.kumhoresort.co.kr O15 - Trusted Zone: *.lotte.com O15 - Trusted Zone: http://*.lottecard.co.kr O15 - Trusted Zone: *.lottecardflower.co.kr O15 - Trusted Zone: *.lottetown.com O15 - ESC Trusted Zone: http://*.update.microsoft.com O16 - DPF: {0349EF81-B9C1-4B97-86F7-7B931D0E2532} (NowStarter2 Control) - http://sticube.clubbox.co.kr/sticube...owStarter2.cab O16 - DPF: {0A4E624A-F7EA-4313-B721-C5669E0C6266} (TrustSiteAuction Control) - http://download.auction.co.kr/active...uctionCtrl.cab O16 - DPF: {1A29905C-C082-11D4-9376-00AA00BFFB71} (checkVerX Control) - http://download.hts.nefficient.co.kr...b/checkVer.cab O16 - DPF: {1A6B7867-9062-4B2F-BD76-AD4653FF480E} (GameLamp Update Control) - http://www.gamelamp.com/etc/activex/GameLampCtrl.cab O16 - DPF: {2022EE84-1E1F-45B0-8D35-FF9DA75366BC} (ExpressViewer Class) - http://download.softforum.co.kr/Publ...i_install2.cab O16 - DPF: {20BBA18F-5BC8-47B5-8FC9-5DFCA8E56A4B} (XacsPop Control) - https://mpi.dacom.net/XMPI/js/xmpi2007.cab O16 - DPF: {286A75C3-11FB-4FB4-AC4A-4DD1B0750050} (INISAFEWeb6 V6 Class) - http://www.citibank.co.kr/initech/plugin/INIS60.cab O16 - DPF: {2A6EA6C1-4F09-4CE0-8E2B-95A4D7205B32} (SmartOnForm Control) - http://imgcdn.pandora.tv/static/smarton/smarton.cab O16 - DPF: {3777C31D-20BE-4D86-A566-E63D37BD2798} (Kdisk File Control1) - http://kdisk.co.kr/mmsv/KdiskWebControl.CAB O16 - DPF: {39461460-2552-4D51-A062-3AB6A7B902E9} (INISAFE Updater Control) - http://www.citibank.co.kr/shttp/inst...ie8/INIS70.cab O16 - DPF: {39FC0CF9-86F3-4502-B773-D16706EDEC83} (SCSK Control) - http://www.citibank.co.kr/js/kor/ie8/SCSK4.cab O16 - DPF: {4ABB12B3-8A8B-481D-874A-93E16F930A8B} (CKKeyPro Crypto support Class (CKNhnInst)) - http://www.hangame.com/common/CKKeyProInst.cab O16 - DPF: {57979411-BD4D-4896-9A89-415A902430B6} (eKSys SmartMapGX SDK 4.0) - http://map.roadi.com/SmartMapGXW.cab O16 - DPF: {5797A411-BD4D-4896-9A89-415A902430B6} (eKSys SmartMapGX SDK 3.0) - http://map.roadi.com/bin/SmartMapGX.cab O16 - DPF: {59A5D6BC-0C36-4EB1-89B0-54857023687A} (BoxView Control) - http://www.modenbox.com/BoxProject/test/BoxView.CAB O16 - DPF: {5B28FBF2-8EA7-4EEE-BA15-BFD1608C783B} (GoodFileDownLoad Control) - http://goodfile.net/downloder/GoodFileDownLoadProj.cab O16 - DPF: {6368221B-31D9-4BE6-8937-B4F37B3930B8} (NpZoneMgr Control) - http://update.nprotect.net/npzone/lo.../npZoneMgr.cab O16 - DPF: {6531D99C-0D0E-4293-B3CB-A3E1D0D41847} (AhnASP Control) - http://ahnlabdownload.nefficient.co....cab/AhnASP.cab O16 - DPF: {6687DEFA-B8AB-4895-B3BD-68DBEEF569DC} (WebSecurer Class) - http://softcamp.nefficient.co.kr/KCB/scwebsc.cab O16 - DPF: {6CE20149-ABE3-462E-A1B4-5B549971AA38} (XecureCKKB Class) - https://npg.tgcorp.com/dlp/js/CKKeyPro/CKKeyPro.cab O16 - DPF: {6FE760D3-7851-4879-8838-62D9881D7177} (IniMasHandler Class) - http://www.bccard.com/service/indivi...iMasPlugin.cab O16 - DPF: {7392F578-42CF-4A94-BB71-83B871BB3A6B} (CYBERMAP_ASP_POST Control) - http://www.cybermap.co.kr/cm2000/com...P_ASP_POST.cab O16 - DPF: {7513B187-5954-4C64-ABF4-E652FE899F24} (Wedisk Control) - http://wedisk.co.kr/app/WeDisk.cab O16 - DPF: {78E27FE2-EB04-4008-9979-F7AB2751F7C2} - https://updates.nprotect.net/nprotec.../nPCom_new.cab O16 - DPF: {7E9FDB80-5316-11D4-B02C-00C04F0CD404} (XecureWeb 4.0 Client Control) - http://download.softforum.co.kr/Publ...xw_install.cab O16 - DPF: {97533519-FBD3-42D5-BB07-C49F022B39EE} (MAWS_NTS Class) - http://download.hts.nefficient.co.kr...AOnFPS_NTS.cab O16 - DPF: {99C709C7-4F58-46C1-855B-90213C760395} (v3d Class) - https://v3d.kcp.co.kr/file/kcp_ansimclick.cab O16 - DPF: {9B75502C-BBED-4BBD-8FE2-822E5E0AD32C} (MagicLockOCX Control) - http://www.tvcf.co.kr/activx/Down_YZ...gicLockOCX.cab O16 - DPF: {9CDD57AC-CA86-464C-B920-3228A388CC78} (NaverFileControl Control) - http://file.naver.com/activex/NaverFile.cab O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} (Kdfense8 Control) - http://kings.nefficient.co.kr/kings/...1/kdfense8.cab O16 - DPF: {A9F090E5-FC80-4772-AFEE-D102AB6E77D6} (IssacWebProCMS Class) - http://pgdownload.lgdacom.net/dacom/..._6_8_DACOM.cab O16 - DPF: {B0A75875-3622-48BA-B5FF-45AD77AC2D0E} (BankPayEFTCtrl Control) - http://download.auction.co.kr/active...BankPayEFT.cab O16 - DPF: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} (Daum ActiveX manager Class) - http://cafeimg.hanmail.net/cto/1_2_3...ab?ver=1,2,3,5 O16 - DPF: {BD6BB450-7C69-43B8-96F3-689CAE57AB51} - O16 - DPF: {C021A4D6-173F-4BF4-B38C-B12CAA20E518} (Mgoon Launcher Control) - http://www.mgoon.com/launcher.cab O16 - DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} (HanSetupCtrl1010 Class) - http://id.hangame.com/common/HanSetup1020.cab O16 - DPF: {C1143E84-B2B1-473B-9F20-E62DD754FCAF} (VineTransfer Control) - https://vbv.shinhancard.com/infovine/VineTransfer.cab O16 - DPF: {C854C4D1-ED53-4B1F-AA45-783B3CF3315C} (DacomUpload Control) - http://program.webhard.co.kr/Plus/ac...acomUpload.cab O16 - DPF: {CB5C683C-416A-4701-B018-0F1B21D64D6B} (SKCInst1 Class) - http://cyimg7.cyworld.com/cymusic/package/skcinst.cab O16 - DPF: {CF392830-663F-11D5-89EE-000086551DF6} (PS_NTSATL Class) - http://download.hts.nefficient.co.kr...one_crypto.cab O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://n-protect.kbstar.com/nprotect/module/npx.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} - http://update.nprotect.net/keycrypt/cans21/npkcx.cab O16 - DPF: {D912AABC-6CB0-416F-85B6-CABBB86FD558} (INIwallet60 Control) - https://plugin.inicis.com/wallet60_i...NIwallet60.cab O16 - DPF: {D96D2F74-0B74-47D2-964F-B67E9F69F1CD} (CongnamulMap4Asp Control) - http://mapsvc.samsung.co.kr/ActiveX/...ap4Asp_V29.cab O16 - DPF: {DC4207CE-C03E-4449-ACB1-032CA4137053} - http://update.nprotect.net/nprotect2006/lotte/npz.cab O16 - DPF: {E0BF7A2B-2F7C-497A-B50F-292D3F317965} (CongnamulMap Control) - http://www.congnamul.com/ActiveX/Rel...mulMap_V21.cab O16 - DPF: {E2A96175-32D0-4651-B228-B474C2408346} (DacomDownload Control) - http://program.webhard.co.kr/Plus/ac...omDownload.cab O16 - DPF: {E3FA6DAA-04BF-4AEF-9612-341B2B7A25FC} - http://pay.kcp.co.kr/plugin/file/payplus.cab O16 - DPF: {E78928A6-3D2A-4BF7-A100-F3FBAA351B49} (KvpIspCtlD Control) - https://www.vpay.co.kr/kvpfiles/KVPISPCTLD.cab O16 - DPF: {E831AA9C-C980-4F16-B252-09AAF40D0E9B} (Kdfense9 Control) - http://k-defence.kbstar.com/kdfx218/kbstar/kdfense9.cab O16 - DPF: {F1149E8A-79EB-4859-835E-95432B72FEA2} (AnycallLAND_DownCheck Control) - http://img.anycall.com/anycall/suppo...CheckProj1.cab O16 - DPF: {F1F07506-6CB4-44AC-8615-66D1234EFD05} (WebCtl Class) - https://www.shinhancard.com/initech4...gin/INIS50.cab O16 - DPF: {F326007F-DD23-4724-BAFC-B1C97FC18794} (CAxSWATAgent Class) - http://www.yebigun1.mil.kr/homepage/...T(2.0.3.5).cab O16 - DPF: {FE342FC7-4374-4EBE-86DB-D73AE861F779} (NaverAXGuide Class) - http://file.naver.com/activex/test/NaverAXGuide.cab O16 - DPF: {FFD77E35-1C34-4EAC-B5A7-414CC5D007DA} (AnsimPlugin Class) - https://www.isaackorea.net/update/ansim/ilkactx.cab O18 - Protocol: s-http - {D37E6C5F-1C0F-47C0-A3B6-403EEC555402} - C:\Program Files\Initech\SHTTP\InitechSHTTPInterface.10115.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AhnLab Log Service - Unknown owner - C:\Program Files\Common Files\AhnLab\ACA\ACALS.exe (file missing) O23 - Service: Apple 모바일 장비 (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: Bonjour 서비스 (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod 서비스 (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Naver Anti-virus Realtime Monitor (Nsavsvc) - Unknown owner - C:\Program.exe (file missing) O23 - Service: Naver Anti-virus Scan Service (nsvmon) - Unknown owner - C:\Program.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: AhnLab SiteGuard Service (SGsvc) - AhnLab, Inc. - C:\Program Files\AhnLab\SiteGuard\SGsvc.exe O23 - Service: UGS License Server (ugslmd) - Macrovision Corporation - C:\ugs\license\lmgrd.exe O23 - Service: V3 Lite Service - AhnLab, Inc. - C:\Program Files\AhnLab\V3Lite\V3LSvc.exe -- End of file - 15759 bytes |
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
![]() |
| Thread Tools | |
|
|