Home > Hijackthis Log > HijackThis Log - Csrss.exe & Generic.exe - Slow PC

HijackThis Log - Csrss.exe & Generic.exe - Slow PC

Location: : S-1-5-21-527237240-1993962763-854245398-1003\software\microsoft\mediaplayer\preferences Description : last playlist loaded in microsoft windows media player MRU List Object Recognized! OriginalFilename : IEXPLORE.EXE #:38 [realsched.exe] FilePath : C:\Program Files\Common Files\Real\Update_OB\ ProcessID : 1100 ThreadCreationTime : 12-24-2006 11:48:50 PM BasePriority : Normal FileVersion : 0.1.0.3292 ProductVersion : 0.1.0.3292 ProductName : RealPlayer (32-bit) OriginalFilename : msmsgs.exe #:25 [frameworkservice.exe] FilePath : C:\Program Files\Network Associates\Common Framework\ ProcessID : 180 ThreadCreationTime : 12-23-2006 11:48:52 PM BasePriority : Normal FileVersion : 3.1.1.184 ProductName : McAfee Common Framework CompanyName Location: : software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct X MRU List Object Recognized! check over here

All rights reserved. OriginalFilename : svchost.exe #:11 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1060 ThreadCreationTime : 12-23-2006 11:48:43 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating FileDescription : Common User Interface InternalName : UpdaterUI LegalCopyright : Copyright© 2000-2003 Networks Associates Technology, Inc. All rights reserved. https://forums.techguy.org/threads/hijackthis-log-csrss-exe-generic-exe-slow-pc-slow-ie-ie-crashes.867420/

OriginalFilename : wordpad #:36 [msnmsgr.exe] FilePath : C:\Program Files\MSN Messenger\ ProcessID : 3892 ThreadCreationTime : 12-24-2006 10:01:56 PM BasePriority : Normal FileVersion : 7.5.0299 ProductVersion : 7.5.0299 ProductName : MSN Messenger Inc.)IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local========== FireFox ==========FF - prefs.js..browser.startup.homepage: "http://www.google.com/"FF - prefs.js..extensions.enabledItems: [email protected]:1.0FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.0FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.2.20100119091315FF - prefs.js..extensions.enabledItems: {9CB58B10-BBB3-4120-9C2B-A1BCB3FEEBFB}:1.9.1FF - While the passwords may not be used as a vector on the forums, those hashed passwords should be considered compromised.

Have looked at taskmanager and searched for info on each process listed at whatprocess. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it. When posting to any other forum, do not post a HijackThis log or the post will simply be moved back to this forum for infection analysis. Location: : S-1-5-21-527237240-1993962763-854245398-1003\software\microsoft\mediaplayer\preferences Description : last playlist loaded in microsoft windows media player MRU List Object Recognized!

Location: : C:\Documents and Settings\Miss Zhen\Application Data\microsoft\office\recent Description : list of recently opened documents using microsoft office MRU List Object Recognized! All Rights Reserved. All Rights Reserved. read this post here New sub-forum for mobile tech - smartphones.

All rights reserved. Reg Problem Slow Pc Started by frankiemad , May 04 2007 08:20 AM Please log in to reply 2 replies to this topic #1 frankiemad frankiemad Members 2 posts OFFLINE avgamsvr.exe 412 AVG Alert Manager GRISOFT, s.r.o. I have searched the forum and found one possible fix for checking (enable bt.graceful shutdown).

AVG would be good enough. http://www.bleepingcomputer.com/forums/t/91038/reg-problem-slow-pc/ Logfile of HijackThis v1.99.1Scan saved at 10:30:08 PM, on 5/19/2010Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\McAfee.com\Agent\mcagent.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\WINDOWS\system32\rundll32.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\McAfee\SiteAdvisor\McSACore.exeC:\WINDOWS\system32\rundll32.exeC:\Program Files\SpywareGuard\sgmain.exeC:\PROGRA~1\McAfee\MSC\mcmscsvc.exeC:\WINDOWS\system32\regedit.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exec:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exec:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exeC:\Program Files\SpywareGuard\sgbhp.exeC:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exeC:\Program that sounds like a bus thing... Location: : S-1-5-21-527237240-1993962763-854245398-1003\software\microsoft\search assistant\acmru Description : list of recent search terms used with the search assistant MRU List Object Recognized!

OriginalFilename : mdm.exe #:31 [wdfmgr.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 604 ThreadCreationTime : 12-23-2006 11:48:59 PM BasePriority : Normal FileVersion : 5.2.3790.1230 built by: dnsrv(bld4act) ProductVersion : 5.2.3790.1230 ProductName : Microsoft® check my blog Note the file's name and save it to your root folder, such as C:\.Disconnect from the Internet and close all running programs.Temporarily disable any real-time active protection so your security program OriginalFilename : spoolsv.exe #:13 [explorer.exe] FilePath : C:\WINDOWS\ ProcessID : 1456 ThreadCreationTime : 12-25-2006 6:46:31 AM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating The page will refresh.6.

All rights reserved. Close any programs you may have running - especially your web browser.8. All rights reserved. http://splodgy.org/hijackthis-log/hijackthis-log-pc-slow.php All Rights Reserved.

Checking with real data and a situation (say copying a 4 GiB file through explorer) compared to hashing that same 4 GiB file in uT... Location: : S-1-5-21-527237240-1993962763-854245398-1003\software\realnetworks\realplayer\6.0\preferences Description : list of recent clips in realplayer MRU List Object Recognized! OriginalFilename : AIM.EXE #:24 [msmsgs.exe] FilePath : C:\Program Files\Messenger\ ProcessID : 1876 ThreadCreationTime : 12-23-2006 11:48:49 PM BasePriority : Normal FileVersion : 4.7.3001 ProductVersion : Version 4.7.3001 ProductName : Messenger CompanyName

help you see different possible problems.

OriginalFilename : naPrdMgr.exe #:31 [mdm.exe] FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\ ProcessID : 316 ThreadCreationTime : 12-25-2006 6:46:44 AM BasePriority : Normal FileVersion : 7.00.9466 ProductVersion : 7.00.9466 ProductName : Microsoft® Location: : S-1-5-21-527237240-1993962763-854245398-1003\software\microsoft\windows\currentversion\applets\wordpad\recent file list Description : list of recent files opened using wordpad MRU List Object Recognized! Site Changelog Community Forum Software by IP.Board Sign In Use Facebook Use Twitter Need an account? All rights reserved. © IDG Communications Jump to content Sign In Create Account Search Advanced Search section: This topic Forums Members Help Files Calendar View New Content Forum Rules

All rights reserved. The link is in my sig. Please post that log in your next reply.Important Note - Do not mouseclick combofix's window whilst it's running. http://splodgy.org/hijackthis-log/hijackthis-log-slow-pc.php I don't see any signs of viruses or malware in the log.

FileDescription : NAI Product Manager InternalName : Product Manager LegalCopyright : Copyright© 2000-2003 Networks Associates Technology, Inc. OriginalFilename : lsass.exe #:6 [ati2evxx.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 756 ThreadCreationTime : 12-23-2006 11:48:41 PM BasePriority : Normal #:7 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 768 ThreadCreationTime : 12-23-2006 11:48:41 All rights reserved. MMERefresh.exe 600 Digidesign MME Binder Digidesign, A Division of Avid Technology, Inc.