Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

a slow pc very slow


  • Please log in to reply

#16
MrCharlie

MrCharlie

    Visiting Staff

  • Visiting Consultant
  • 170 posts
That's good news.

Just a little bit more to do....

Run HJT > Misc Tools > Delete a NT Service > we want to delete this one only!!!
Network DDE Client (NetDDEclnt)

When that's done, hit back and scan ........
Close ALL programs down, leaving ONLY HijackThis running.
Place a check against the following items:

O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O4 - Global Startup: BlueSoleil.lnk = ?
O23 - Service: Network DDE Client (NetDDEclnt) - Unknown owner - D:\WINDOWS\System32\netddeclnt.exe (file missing)

Click on Fix Checked and exit HijackThis.

Reboot and post a fresh HijackThis log and we'll take another look. MrC

  • 0

Advertisements


#17
toutou21

toutou21

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
hi
i don't know how to delete the network dde client in hijackthis ????
  • 0

#18
MrCharlie

MrCharlie

    Visiting Staff

  • Visiting Consultant
  • 170 posts
OK, lets do this...

Download the Registry Search Tool at this link:

http://www.billsway.com/vbspage/ (it's about halfway down)

Unzip it and run it. (If your antivirus inteferes you may have to disable script blocking in the antivirus.)

Copy and paste the following in the search box and hit OK.

NetDDEclnt

Post the results.

Thanks, MrC

  • 0

#19
toutou21

toutou21

    Member

  • Topic Starter
  • Member
  • PipPip
  • 18 posts
hi, i do what you told me , this is the startup log :

StartupList report, 25/08/2000, 16:33:14
StartupList version: 1.52.2
Started from : D:\HTJ\hijackthis\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================

Running processes:

D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\netdde.exe
D:\WINDOWS\system32\cisvc.exe
D:\WINDOWS\System32\imapi.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\vssvc.exe
D:\WINDOWS\System32\wbem\wmiapsrv.exe
D:\WINDOWS\System32\dmadmin.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
D:\WINDOWS\system32\cidaemon.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\HTJ\hijackthis\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Common Startup:
[D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage]
BlueSoleil.lnk = ?

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = D:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Shell & screensaver key from D:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=explorer.exe
SCRNSAVE.EXE=D:\WINDOWS\MAERSK~1.SCR
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - (no file) - {A5366673-E8CA-11D3-9CD9-0090271D075B}

--------------------------------------------------

Enumerating Task Scheduler jobs:

XoftSpy.job

--------------------------------------------------

Enumerating Download Program Files:

[{41564D57-9980-0010-8000-00AA00389B71}]
CODEBASE = http://download.micr...01F/wmvadvd.cab

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: D:\WINDOWS\system32\SHELL32.dll
CDBurn: D:\WINDOWS\system32\SHELL32.dll
WebCheck: *Registry key not found*
SysTray: D:\WINDOWS\System32\stobject.dll

--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

Spool Service = t.exe

--------------------------------------------------

End of report, 3 556 bytes
Report generated in 0,521 seconds

And this is my new htjthis log :

Logfile of HijackThis v1.99.1
Scan saved at 19:25:50, on 28/08/2000
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\netdde.exe
D:\WINDOWS\system32\cisvc.exe
D:\WINDOWS\System32\imapi.exe
D:\WINDOWS\system32\sessmgr.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\vssvc.exe
D:\WINDOWS\System32\wbem\wmiapsrv.exe
D:\WINDOWS\System32\dmadmin.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\WINDOWS\notepad.exe
D:\HTJ\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:1030
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;cgi*.ebay.com;disney.go.com;msa_e1.ebay.com;rhapsody_app*.listen.com;<local>
O4 - Global Startup: BlueSoleil.lnk = ?
O8 - Extra context menu item: Download All by FlashGet - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - D:\Program Files\FlashGet\jc_link.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{A760F5A3-BB80-4D42-862C-AB65B3D2B149}: NameServer = 10.10.1.202 192.168.20.5
O23 - Service: Network DDE Client (NetDDEclnt) - Unknown owner - D:\WINDOWS\System32\netddeclnt.exe (file missing)

so what do you think .....
  • 0

#20
MrCharlie

MrCharlie

    Visiting Staff

  • Visiting Consultant
  • 170 posts
That's not what I wanted.

Please print this out so you can refer to it.

This is the entry in the HJT log that we want to delete:

O23 - Service: Network DDE Client (NetDDEclnt) - Unknown owner - D:\WINDOWS\System32\netddeclnt.exe (file missing)

Here's what I want you to do:

Double click on the HijackThis.exe (it's in D:\HTJ\hijackthis\HijackThis.exe)

Now on the first page that comes up you'll see Open the Misc. Tools Section, it's the forth one down on the list.
Click on it

Under System Tools, click on Delete an NT service, it's the forth one down


In the window that pops up,
Copy and past this in NetDDEclnt and click on OK

That should delete the HJT entry

Reboot and post a fresh HJT log, MrC

  • 0

#21
MrCharlie

MrCharlie

    Visiting Staff

  • Visiting Consultant
  • 170 posts
toutou21 are you still with us??

If there's something about my instructions you don't understand - please let me know, I'm trying to have you delete that entry the easiest way possible.
We're here to help you.
With that entry deleted your log will be clean, I don't want to leave you with the possibility of malware still being on the system.
Please let me know, Thanks, MrC

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP