Computer Hope

Other Pages

Home
Site map
Computer help

Dictionary
News
Q&A
What's new



Windows process and HijackThis log tool bv1.2g


Computer Hope HijackThis log tool overview (created Thu Jan 22 03:14:15 2009):
Unique found: 56 - Unknown: 1- Total: 57
Processes / services not required: 49 (that are not hardware / security: 25) - Potential threats: 15
windows xp sp3 (winnt 5.01.2600) - Windows directory: \windows\ - Detected Antivirus: AVG

PathProcessDescription
Type
Required?
Threat?
No FirewallWe could not detect a firewall process running on this computer. If no firewall is running on the computer we strongly suggest either enabling the Windows Firewall or installing another firewall.Unknown
Yes
Maybe
MissingYour Hijackthis log contains a missing file reference to: 1.exe. Although not a threat to the computer it may cause errors.Unknown
Yes
Maybe
MissingYour Hijackthis log contains a missing file reference to: yaywvuri.dll. Although not a threat to the computer it may cause errors.Unknown
Yes
Maybe
MissingYour Hijackthis log contains a missing file reference to: {2318c2b1-4965-11d4-9b18-009027a5cd4f}. Although not a threat to the computer it may cause errors.Unknown
Yes
Maybe
MissingYour Hijackthis log contains a missing file reference to: {0bf43445-2f28-4351-9252-17fe6e806aa0}. Although not a threat to the computer it may cause errors.Unknown
Yes
Maybe
MissingYour Hijackthis log contains a missing file reference to: {53e0b6e8-a51d-448b-b692-40b67b285543}. Although not a threat to the computer it may cause errors.Unknown
Yes
Maybe
MissingYour Hijackthis log contains a missing file reference to: {fa7096aa-591c-4749-8dda-92eb595622fd}. Although not a threat to the computer it may cause errors.Unknown
Yes
Maybe
MissingYour Hijackthis log contains a missing file reference to: {ca7fbe14-5973-4e41-b738-2e3b567cac4c}. Although not a threat to the computer it may cause errors.Unknown
Yes
Maybe
MissingYour Hijackthis log contains a missing file reference to: ddcdsqpq.dll. Although not a threat to the computer it may cause errors.Unknown
Yes
Maybe
UnknownAlthough unknown jbkgns.dll is suspicious since many legitimate unknown files do not run from the Windows path. Click here to open Google search for this process.Unknown
Yes
Maybe
MissingYour Hijackthis log contains a missing file reference to: desrcas.dll. Although not a threat to the computer it may cause errors.Unknown
Yes
Maybe
MissingYour Hijackthis log contains a missing file reference to: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0}. Although not a threat to the computer it may cause errors.Unknown
Yes
Maybe
MissingYour Hijackthis log contains a missing file reference to: {ef99bd32-c1fb-11d2-892f-0090271d4f88}. Although not a threat to the computer it may cause errors.Unknown
Yes
Maybe
MissingYour Hijackthis log contains a missing file reference to: desrcas.dll. Although not a threat to the computer it may cause errors.Unknown
Yes
Maybe
HijackThisIt appears you're looking at an old HijackThis log (dated: 1/3/2009) if this is your computers log we suggest re-running HijackThis and getting a more up-to-date log to look at.Application
Yes
Maybe
smss.exeMicrosoft Windows Session Manager Subsystem process that should be located in the C:\Windows\System32 directoryWindows
Yes
No
winlogon.exeMicrosoft Windows Logon Process that should be located in the C:\Windows\System32 or C:\Windows directoryWindows
Yes
No
services.exeMicrosoft Windows Service Controller that should be located in the C:\Windows\System32 directoryApplication
Yes
No
lsass.exeMicrosoft Windows security authority process that should be located in the C:\Windows\System32 directoryNetworkWindows
Yes
No
svchost.exeMicrosoft Service Host Process that should be located in the C:\Windows\System32 directoryWindows
Yes
No
explorer.exeMicrosoft Windows ExplorerWindows
Yes
No
HijackThis.exeHijackThis programSecurity
No
No
iexplore.exeMicrosoft Internet Explorer browserApplicationNetwork
Safe
No
ctfmon.exeMicrosoft Office text input process that should be located in the C:\Windows\System32 or C:\Windows directoryApplication
Safe
No
acroiehelper.dllAdobe Acrobat Internet Explorer helper DLLDLL
Safe
No
sdhelper.dllSpybot Search and Destroy DLLDLLSecurity
No
No
ssv.dllSun Java helper browser plugin DLLDLL
Safe
No
avgtoo~1.dllAVG toolbar DLLDLLSecurity
No
No
syntpenh.exeSynaptics TouchPad driverHardware
No
No
igfxtray.exeIntel Graphics driver processHardware
No
No
hkcmd.exeIntel graphics driver and hotkey keyboard hotkey processHardware
No
No
igfxpers.exeIntel video graphics processHardware
No
No
stsystra.exeSigmatel audio driverHardware
No
No
quickset.exeDell power management processHardware
No
No
dvdlauncher.exeCyberlink DVD PowerCinema processApplication
Safe
No
realplay.exeReal Player processApplicationNetwork
Safe
No
isuspm.exeMacrovision InstallShield update checker processApplicationNetwork
Safe
No
issch.exeInstallShield software update processApplicationNetwork
Safe
No
mimboot.exeMusicmatch Jukebox media player processApplication
Safe
No
aoldial.exeAOL Internet dialerApplicationNetwork
Safe
No
aolsoftware.exeAOL library processApplicationNetwork
Safe
No
dsca.exeDell Support Center processApplication
Safe
No
reader_sl.exeAdobe Acrobat Reader load time reduction processApplication
Safe
No
sprtcmd.exeDell support agent process. Also an agent file used with many different ISP software packages.Application
Safe
No
jusched.exeSun Microsystems Java Update schedulerApplicationNetwork
Safe
No
avgtray.exeAVG AntiVirus systray processSecurity
No
No
spybotsd.exeSpybot Search and Destroy (S&D) spyware applicationSecurity
No
No
netwaiting.exeInternet connection toggle process that enables you to switch between your modem connection and a voice call without breaking connectionApplicationNetwork
Safe
No
msmsgs.exeMicrosoft MSN MessengerApplicationNetwork
Safe
No
dsagnt.exeDell support and update agent processApplicationNetwork
Safe
No
teatimer.exeSpybot Search and Destroy processSecurity
No
No
excel.exeMicrosoft ExcelApplication
Safe
No
shdocvw.dllMicrosoft Windows Shell Doc Object and Control Library. Used to display folders while in Windows DLLDLLWindows
Yes
No
xpnetdiag.exeMicrosoft Windows XP network diagnostics toolApplication
Safe
No
xpsp3res.dllMicrosoft Windows XP service pack 3 (SP3) network diagnostics DLLDLL
Safe
No
facebookphotouploader3.cabFacebook.com photo uploader CABCab
Safe
No
avgpp.dllAVG Internet security DLLDLLSecurity
No
No
aolacsd.exeAOL Internet connection processApplicationNetwork
Safe
No
avgemc.exeAVG AntiVirus e-mail scannerSecurity
No
No
avgwdsvc.exeAVG watchdog security processSecurity
No
No
brsvc01a.exeSamsung printer manager that should be located in the C:\Windows\System32 directoryHardware
No
No
brkrsvc.exeDell Support serviceApplication
Safe
No
lexbces.exeLexmark printer network sharing serviceHardware
No
No
nicconfigsvc.exeDell power management processHardware
No
No
sprtsvc.exeDell Support Center serviceApplication
Safe
No
wanmpsvc.exeAOL WAN properties serviceApplicationNetwork
Safe
No
wltrysvc.exeDell wirless LAN serviceHardwareNetwork
No
No
aoltray.exeAOL Internet systray processApplication
Safe
No
easyshare.exeKodak EasyShare camera softwareApplicationHardware
No
No
kodak software updater.exeKodak digital camera software update serviceApplicationNetwork
Safe
No
osa.exeMicrosoft Office startup assistantApplication
Safe
No

Getting your system clean

Notice: This tool is currently being developed and is in the alpha stage of testing, by following these steps you agree that you're doing this at your own risk.

What to do in HijackThis

1. Open HijackThis.
2. Click Do a system scan only
3. Check the boxes that correspond to the below lines.
  • r3 - urlsearchhook: (no name) - {4d25f926-b9fe-4682-bf72-8ab8210d6d75} - c:\program files\mywaysa\srchasde\desrcas.dll (file missing)
  • r3 - urlsearchhook: yahoo! toolbar - {ef99bd32-c1fb-11d2-892f-0090271d4f88} - (no file)
  • o2 - bho: (no name) - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - (no file)
  • o2 - bho: (no name) - {4d25f921-b9fe-4682-bf72-8ab8210d6d75} - c:\program files\mywaysa\srchasde\desrcas.dll (file missing)
  • o2 - bho: {4af28625-91f9-c5f8-5d14-98b5a02c00e7} - {7e00c20a-5b89-41d5-8f5c-9f1952682fa4} - c:\windows\system32\jbkgns.dll
  • o2 - bho: (no name) - {8725e047-7220-42e0-912f-8fe0bbdbea01} - c:\windows\system32\ddcdsqpq.dll (file missing)
  • o2 - bho: (no name) - {ca7fbe14-5973-4e41-b738-2e3b567cac4c} - (no file)
  • o2 - bho: (no name) - {fa7096aa-591c-4749-8dda-92eb595622fd} - (no file)
  • o3 - toolbar: (no name) - {53e0b6e8-a51d-448b-b692-40b67b285543} - (no file)
  • o3 - toolbar: (no name) - {0bf43445-2f28-4351-9252-17fe6e806aa0} - (no file)
  • o3 - toolbar: (no name) - {2318c2b1-4965-11d4-9b18-009027a5cd4f} - (no file)
  • o20 - winlogon notify: yaywvuri - yaywvuri.dll (file missing)
  • o23 - service: mcafee application installer cleanup (0246231222493699) (0246231222493699mcinstcleanup) - unknown owner - c:\docume~1\hannah~1\locals~1\temp\024623~1.exe (file missing)
4. Once the above have been checked click the Fix checked button.
5. After fixed close Hijackthis.

Delete files

Delete the following files if found on the computer.

c:\windows\system32\jbkgns.dll *

* This file could be a legitimate file. Make sure you're positive this is not a valid file by reading the suggestions in the above chart before deleting it. If you're not comfortable deleting the file just leave it alone.
** Files not found in the Windows directory may be part of a program that can be uninstalled through the Add/Remove programs in the Control Panel.

Additional malware scans

Because potential threats were found in the HijackThis log we we also suggest you reboot the computer after completing the above steps and install and run the free Malwarebytes' Anti-Malware utility on this computer.

Verify browser plugins up-to-date

Reboot the computer into Normal Windows mode make sure you're browser has all the latest plugins installed by viewing the each of the plugins installed on your computer through our System Information tool.

Install Firewall protection

We could not detect a firewall process running on this computer. If no firewall is running on the computer we strongly suggest either enabling the Windows Firewall or installing another firewall.

After the above steps have been completed reboot the computer, let it boot as normal, and re-run HijackThis and generate a new log to be reviewed.

Main Windows process search tool page



Over 7,847,474 processes and files have been examined


A big thanks to CBMatt and Evilfantasy for their malware specialist assistance and everyone else in the Computer Hope community who has contributed to the development and testing of this tool. An ongoing discussion about this tool is found here.


Main Windows process search tool page



Over 7,847,474 processes and files have been examined


A big thanks to CBMatt and Evilfantasy for their malware specialist assistance and everyone else in the Computer Hope community who has contributed to the development and testing of this tool. An ongoing discussion about this tool is found here.

Home - Computer help - Contact - Dictionary - Links
Link to Computer Hope - Bookmark Computer Hope