<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: HJT Log System Slow Disk Busy in Security Cleanup</title>
<link>http://www.dslreports.com/forum/r20309919</link>
<description></description>
<language>en</language>
<pubDate>Fri, 05 Dec 2008 11:41:33 EDT</pubDate>
<lastBuildDate>Fri, 05 Dec 2008 11:41:33 EDT</lastBuildDate>

<item>
<title>Re: HJT Log System Slow Disk Busy</title>
<link>http://www.dslreports.com/forum/remark,20334715</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Glad to hear you found the problem :)<br><br>And I'm glad your system isn't infected too! ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20334715</guid>
<pubDate>Mon, 14 Apr 2008 21:22:01 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log System Slow Disk Busy</title>
<link>http://www.dslreports.com/forum/remark,20317057</link>
<description><![CDATA[<A HREF="/useremail/u/1110454"><b>RJHere</b></A> : Thanks for the help on this problem.<br><br>I was stupid, I should have checked the hardware first.<br>The problem is that there is a bad block on the hard drive.  As you stated at the top "No hiding infection there :)".  This made me think about the problem and look a little deeper, but I should have done this first.<br><br>I do very much appreciate the time you took with this problem.  I will also take advantage of the suggestions for updating the java runtime.  <br><br>Thanks again, problem fixed.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20317057</guid>
<pubDate>Fri, 11 Apr 2008 09:19:56 EDT</pubDate>
</item>

<item>
<title>Re: HJT Log System Slow Disk Busy</title>
<link>http://www.dslreports.com/forum/remark,20309919</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : No hiding infection there :)<br><br>The MyWebSearch mostly likely came pre-installed on your Dell computer.  It is best removed via the Control Panel under Add/Remove programs - although it is not harmful really,nor the cause of your symptoms.  But the scanners did not completely remove it (possibly because you may have had your browser open during scanning).  And some do not detect it because it is not harmful or malicious.<br><br>See if this is listed in your Add/Remove programs and remove it from there (with all browsed closed)<br><b>MYWEBSEARCH BAR</b><br><br>Then reboot the PC<br><br>After reboot, scan with HijackThis and if the following entries are still present, you can checkmark these two and press the *fix checked* button. <br><br><b>O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br><br>O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S</b><br><br>Subsequently delete the following folder, if found:<br><br>C:\PROGRAM FILES\<b>MYWEBSEARCH BAR</b><br><br>...........<br>And on a side note (not related at to your problem) is that your Sun Java is very outdated and security risk.<br><br>Old versions left on your pc, even after updating can be vulnerable to malware exploit. Go to Start / Control Panel and look in Add/Remove programs. <b>Remove all old versions of Sun Java</b>. <br>They will appear in the "J's" something similar to:<br><br>j2re1.4.2_05 or<br><br>JAVA 2 RUNTIME ENVIROMENT SE V1.4.2_03<br><br>JAVA 2 RUNTIME ENVIROMENT SE V.14.2_06<br><br>(or similar, and there may be more than one. Remove them all)<br><br>Then go get the latest up to date version here:<br><A HREF="http://www.java.com/en/download/manual.jsp">http://www.java.com/en/download/manual.jsp</a><br><br>Here's why removing old versions of Sun Java is important:<br>Potential Vulnerability with Sun Java auto update<br><A HREF="http://www.dslreports.com/forum/remark,14738046">http://www.dslreports.com/forum/remark,14738046</a><br><br>This is a vulnerability in that Sun Java new updated versions do not remove prior vulnerable versions.  You will have to remember to do that manually whenever you update your Sun Java.<br>............<br>We could take a little deeper look to ensure there is nothing hiding with this free tool.  Please post the logs it makes back here for review:<br><br>Download Deckard's System Scanner (DSS)<br><br><textarea name="code" class="text" cols=50 rows=10> &#012;http://www.techsupportforum.com/sectools/Deckard/dss.exe&#012; &#012;</textarea><!--end code block--><br>Save the file to your <b>Desktop</b>.<br><br>Note: You must be logged onto an account with administrator privileges.<br><br>[*]<b>Close</b> all applications and windows.<br>[*]<b>Double-click</b> on <b>dss.exe</b> to run it, and follow the prompts.<br>[*]When the scan is complete, two text files will open - <b>main.txt</b> [color=Red]extra.txt</b>[color=Red](Ctrl+A then Ctrl+C)</b> and paste <b>(Ctrl+V)</b> the contents of <b>main.txt</b> and the extra.txt to your post. in your reply</ol><br><small>--<br>It takes a disaster to make a woman out of a female<br>Microsoft MVP/Windows Security 2003-2008<br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </a> (Alliance of Security Analysis Professionals)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20309919</guid>
<pubDate>Wed, 09 Apr 2008 18:13:04 EDT</pubDate>
</item>

<item>
<title>HJT Log System Slow Disk Busy</title>
<link>http://www.dslreports.com/forum/remark,20306918</link>
<description><![CDATA[<A HREF="/useremail/u/1110454"><b>RJHere</b></A> : My laptop started to suddenly run slow.  When it is slow the disk light is on constantly.  I used the task manager utility to check the processed when this is happening.  There is no process using very much CPU only the disk is busy and using task manager I am not able to find a process that is making the disk busy.<br><br>I have Symantec antivirus install and I ran a scan but found nothing.  I ran Spybot S&D and it found DoubleClick, FunWeb, FunWebProducts, MyWay.MyWebSearch, MyWebSearch, Web Trends Live and Wild Tangent.  I uninstalled Wild Tangent and let Spybot fix the other problems.  I then ran Ad-Aware se and it found MyWebSearch and I had it fix that.<br><br>Then I ran the web-based McAfee antivirus and it found nothing.  I ran the web-based Trendmicro Housecall and it found cookies and nothing elese.  Then I ran CWShredder and nothing was found.<br><br>The problem persists so I ran HJT and this is the log that it produced.<br><br>Logfile of Trend Micro HijackThis v2.0.2<br>Scan saved at 8:17:29 AM, on 4/9/2008<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br>Boot mode: Normal<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\Program Files\Windows Defender\MsMpEng.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE<br>C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br>C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe<br>C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br>C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe<br>C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>C:\WINDOWS\system32\fxssvc.exe<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\WINDOWS\system32\Ati2evxx.exe<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\system32\wuauclt.exe<br>C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe<br>C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe<br>C:\WINDOWS\stsystra.exe<br>C:\Program Files\Dell\QuickSet\quickset.exe<br>C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\Program Files\Dell\Media Experience\PCMService.exe<br>C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe<br>C:\WINDOWS\system32\dla\tfswctrl.exe<br>C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe<br>C:\Program Files\Logitech\SetPoint\LBTWiz.exe<br>C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe<br>C:\Program Files\Qurb\QSP-3.0.311.7\QOELoader.exe<br>C:\Program Files\Windows Defender\MSASCui.exe<br>C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe<br>C:\Program Files\NetWaiting\netWaiting.exe<br>C:\Program Files\DellSupport\DSAgnt.exe<br>C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe<br>C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe<br>C:\Program Files\Digital Line Detect\DLG.exe<br>C:\Program Files\Logitech\SetPoint\SetPoint.exe<br>C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE<br>C:\Program Files\ATI Technologies\ATI.ACE\cli.exe<br>C:\Program Files\Internet Explorer\iexplore.exe<br>C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<br><br>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us<br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &raquo;<A HREF="http://www.dell.com" >www.dell.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html" >us.rd.yahoo.com/customize/ie/def&middot;&middot;&middot;rch.html</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &raquo;<A HREF="http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com" >us.rd.yahoo.com/customize/ie/def&middot;&middot;&middot;ahoo.com</A><br>R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.dell.com" >www.dell.com</A><br>R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us<br>O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)<br>O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll<br>O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll<br>O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"<br>O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless<br>O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe<br>O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe<br>O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe<br>O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay<br>O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"<br>O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"<br>O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe<br>O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup<br>O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start<br>O4 - HKLM\..\Run: [Logitech BT Wizard] LBTWiz.exe -silent<br>O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE<br>O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\Qurb\QSP-3.0.311.7\QOELoader.exe"<br>O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime<br>O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide<br>O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S<br>O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe<br>O4 - HKLM\..\Run: [DLCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16<br>O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe<br>O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background<br>O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup<br>O4 - HKCU\..\Run: [DellTransferAgent] "C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe"<br>O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')<br>O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')<br>O4 - Global Startup: Bluetooth.lnk = ?<br>O4 - Global Startup: Digital Line Detect.lnk = ?<br>O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe<br>O8 - Extra context menu item: &Search - ?p=ZU<br>O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll<br>O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll<br>O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br>O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm<br>O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll<br>O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - &raquo;<A HREF="http://wwws.musicmatch.com/mmz/openWebRadio.html" >wwws.musicmatch.com/mmz/openWebRadio.html</A> (file missing)<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe<br>O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - &raquo;<A HREF="http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab" >www.kaspersky.com/kos/eng/partne&middot;&middot;&middot;code.cab</A><br>O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - &raquo;<A HREF="http://go.microsoft.com/fwlink/?linkid=39204" >go.microsoft.com/fwlink/?linkid=39204</A><br>O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll<br>O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - &raquo;<A HREF="http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1155746690671" >update.microsoft.com/windowsupda&middot;&middot;&middot;46690671</A><br>O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe<br>O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe<br>O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe<br>O23 - Service: dlcf_device -   - C:\WINDOWS\system32\dlcfcoms.exe<br>O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe<br>O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE<br>O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe<br>O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe<br>O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe<br>O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe<br>O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe<br><br>--<br>End of file - 9445 bytes<br><br>I hope that this information is helpful for solving my problem.<br><br>Thanks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20306918</guid>
<pubDate>Wed, 09 Apr 2008 08:51:54 EDT</pubDate>
</item>

</channel>
</rss>
