Jump to content

i got delay everytime when i click taskbar icon...


Recommended Posts

@moogly thx a lot mate

i will make it and post all info in some min.

ok guys here is it


Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 18:28 ч., on 9.12.2008 г.

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

Running processes:






C:\Program Files\ESET\ESET Smart Security\egui.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Internet Download Manager\IDMan.exe

C:\Program Files\Xfire\xfire.exe

C:\Program Files\Raxco\PerfectDisk2008\PD91AgentS1.exe


C:\Program Files\Internet Download Manager\IEMonitor.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O1 - Hosts: dekaronpatch.gametribe.com

O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll

O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dll

O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dll

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NodLogin] C:\Program Files\ESET\ESET Smart Security\nodlogin.exe

O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [iDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe

O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm

O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm

O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm

O9 - Extra button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~1\NUCLEA~1\VideoGet\Plugins\VIDEOG~1.DLL

O9 - Extra 'Tools' menuitem: Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\PROGRA~1\NUCLEA~1\VideoGet\Plugins\VIDEOG~1.DLL

O13 - Gopher Prefix:

O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_srl.cab

O16 - DPF: {45FE4418-F85F-45F0-BCAA-68C334FA6E08} (Sipd Control) - file:///C:/Users/Matau/AppData/Local/Microsoft/Windows%20Sidebar/Gadgets/(EPIDEM.RU)%20AGEphoneGadget.gadget/sipd.ocx

O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://disteng.nefficient.com/disteng/neffy/NeffyLauncher.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{91FCA6DE-FC00-4901-93B3-80E5FBF142D5}: NameServer =,

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe

O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe

O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe

O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe

O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe

O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe

O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe


End of file - 6289 bytes

and Utorrent process

Process PID CPU Description Company Name

System Idle Process 0 39.84

Interrupts n/a 0.78 Hardware Interrupts

DPCs n/a 2.34 Deferred Procedure Calls

System 4

smss.exe 532 Windows Session Manager Microsoft Corporation

csrss.exe 664 Client Server Runtime Process Microsoft Corporation

wininit.exe 716 Windows Start-Up Application Microsoft Corporation

services.exe 760 Services and Controller app Microsoft Corporation

svchost.exe 956 Host Process for Windows Services Microsoft Corporation

unsecapp.exe 1312 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation

WmiPrvSE.exe 1320 WMI Provider Host Microsoft Corporation

nvvsvc.exe 1008 NVIDIA Driver Helper Service, Version 175.19 NVIDIA Corporation

rundll32.exe 1604 Windows host process (Rundll32) Microsoft Corporation

svchost.exe 1036 Host Process for Windows Services Microsoft Corporation

svchost.exe 1076 Host Process for Windows Services Microsoft Corporation

svchost.exe 1156 Host Process for Windows Services Microsoft Corporation

audiodg.exe 1344 Windows Audio Device Graph Isolation Microsoft Corporation

svchost.exe 1204 Host Process for Windows Services Microsoft Corporation

dwm.exe 352 Desktop Window Manager Microsoft Corporation

svchost.exe 1236 Host Process for Windows Services Microsoft Corporation

taskeng.exe 220 Task Scheduler Engine Microsoft Corporation

taskeng.exe 2068 Task Scheduler Engine Microsoft Corporation

svchost.exe 1372 Host Process for Windows Services Microsoft Corporation

SLsvc.exe 1416 Microsoft Software Licensing Service Microsoft Corporation

svchost.exe 1444 Host Process for Windows Services Microsoft Corporation

svchost.exe 1668 Host Process for Windows Services Microsoft Corporation

spoolsv.exe 1928 Spooler SubSystem App Microsoft Corporation

svchost.exe 1952 Host Process for Windows Services Microsoft Corporation

mDNSResponder.exe 2924 Bonjour Service Apple Computer, Inc.

ekrn.exe 2948 25.00 Eset Service ESET

PD91Agent.exe 3068 PD91Agent Module Raxco Software, Inc.

PD91AgentS1.exe 2064 PD91AgentS1 Module Raxco Software, Inc.

PnkBstrA.exe 3160

PsiService_2.exe 3184 PsiService PsiService Protexis Inc.

svchost.exe 3204 Host Process for Windows Services Microsoft Corporation

TUProgSt.exe 3232 TuneUp Program Statistics Service TuneUp Software

svchost.exe 3260 7.03 Host Process for Windows Services Microsoft Corporation

SDWinSec.exe 3360 Spybot-S&D Security Center integration Safer Networking Ltd.

lsass.exe 776 Local Security Authority Process Microsoft Corporation

lsm.exe 784 Local Session Manager Service Microsoft Corporation

csrss.exe 728 Client Server Runtime Process Microsoft Corporation

winlogon.exe 860 Windows Logon Application Microsoft Corporation

explorer.exe 552 Windows Explorer Microsoft Corporation

RtHDVCpl.exe 2152 HD Audio Control Panel Realtek Semiconductor

rundll32.exe 2184 Windows host process (Rundll32) Microsoft Corporation

egui.exe 2208 Eset GUI ESET

Skype.exe 2256 Skype Skype Technologies S.A.

IDMan.exe 2264 Internet Download Manager (IDM) Tonec Inc.

IEMonitor.exe 1564 Internet Download Manager agent for click monitoring in IE-based browsers Tonec Inc.

xfire.exe 2284 Xfire Xfire Inc.

uTorrent.exe 2764 24.22 µTorrent BitTorrent, Inc.

firefox.exe 1740 Firefox Mozilla Corporation

procexp.exe 2648 0.78 Sysinternals Process Explorer Sysinternals - www.sysinternals.com

Process: uTorrent.exe Pid: 2764

Name Description Company Name Version

ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.00.6001.18000

ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0000


CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.6931.18000

COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.6001.18000

comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.6001.18000

dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.00.6001.18000

dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.00.6001.18000

DnsApi.dll DNS Client API DLL Microsoft Corporation 6.00.6001.18000

FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.00.6001.18000

GDI32.dll GDI Client DLL Microsoft Corporation 6.00.6001.18023

GPAPI.dll Group Policy Client API Microsoft Corporation 6.00.6001.18000

hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 6.00.6001.18000

idmmkb.dll Internet Download Manager module Tonec Inc. 4.00.0000.0001

IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.00.6001.18000

Iphlpapi.dll IP Helper API Microsoft Corporation 6.00.6001.18000

kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.00.6001.18000



LPK.DLL Language Pack Microsoft Corporation 6.00.6001.18000

mdnsNSP.dll Bonjour Namespace Provider Apple Computer, Inc. 1.00.0003.0001

MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.00.6001.18000

MSIMG32.dll GDIEXT Client DLL Microsoft Corporation 6.00.6000.16386

MSVCR71.DLL Microsoft® C Runtime Library Microsoft Corporation 7.10.3052.0004

msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.6001.18000

mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.00.6001.18000

napinsp.dll E-mail Naming Shim Provider Microsoft Corporation 6.00.6001.18000

NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.00.6001.18000

npmproxy.dll Network List Manager Proxy Microsoft Corporation 6.00.6000.16386

NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.00.6001.18000

ntdll.dll NT Layer DLL Microsoft Corporation 6.00.6001.18000

ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.00.6001.18000

OLEACC.dll Active Accessibility Core Component Microsoft Corporation 4.02.5406.0000

oleaccrc.dll Active Accessibility Resource DLL Microsoft Corporation 4.02.5406.0000

oleaut32.dll Microsoft Corporation 6.00.6001.18000

pnrpnsp.dll PNRP Name Space Provider Microsoft Corporation 6.00.6001.18000

PSAPI.DLL Process Status Helper Microsoft Corporation 6.00.6000.16386

rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.00.6000.16386

RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.00.6001.18051

rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.00.6001.18000

Secur32.dll Security Support Provider Interface Microsoft Corporation 6.00.6001.18000

SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.6001.18062

shfolder.dll Shell Folder Service Microsoft Corporation 6.00.6000.16386

SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.6001.18000

slc.dll Software Licensing Client Dll Microsoft Corporation 6.00.6001.18000

SSDPAPI.dll SSDP Client API DLL Microsoft Corporation 6.00.6000.16386

SXS.DLL Fusion 2.5 Microsoft Corporation 6.00.6001.18000

upnp.dll UPnP Control Point API Microsoft Corporation 6.00.6001.18000

USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.00.6001.18000

USERENV.dll Userenv Microsoft Corporation 6.00.6001.18000

USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.6001.18000

uTorrent.exe µTorrent BitTorrent, Inc. 1.09.0000.13583

uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.6001.18000

VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.00.6001.18000

WINHTTP.dll Windows HTTP Services Microsoft Corporation 6.00.6001.18000

WINMM.dll MCI API DLL Microsoft Corporation 6.00.6001.18000

WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.00.6001.18000

winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.00.6000.16386

WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.00.6001.18000

WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.00.6001.18000

wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.00.6001.18000

wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.00.6001.18000

WSOCK32.dll Windows Socket 32-Bit DLL Microsoft Corporation 6.00.6001.18000

xfire_toucan_35044.dll Xfire Toucan DLL Xfire Inc. 1.00.0000.35044

Link to comment
Share on other sites


This topic is now archived and is closed to further replies.

  • Create New...