Cannot Terminate Default Browser AND smhost.exe

Discussion in 'Windows - Virus and spyware problems' started by bmmiller, Jul 30, 2006.

  1. bmmiller

    bmmiller Member

    Joined:
    Jul 30, 2006
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    11
    I'd really appreciate any input and/or help with my issue. Thanks in advance.

    I was having a problem with a couple things recently. First of all, whenever I reboot I get the following that shows up in the upper left hand corner every time, I tried googling smhost.exe with very little results.

    [​IMG]

    Occationally, my computer will hang up recently and I would like to think this is part of the problem. Would anyone know what is going on with this? Seen it before? Know what to try? I've looked in and out o safe mode and cannot find smhost.exe within the Windows directory. I do however see a smhost w/o extention and a smhost value in the prefetch folder. I tried deleting those with little change in my hang ups. Here is also my hijackthis log:

    Logfile of HijackThis v1.99.1
    Scan saved at 4:03:03 AM, on 7/30/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5450.0004)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Eset\nod32kui.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Active SMART\ActiveSMART.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Kerio\Personal Firewall\persfw.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    C:\Files\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.xbox-scene.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=33568
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - Startup: Active SMART.lnk = C:\Program Files\Active SMART\ActiveSMART.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148921058570
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe
    O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

    Everything looked fine to me. I'm also having an issue with the default browser. I use Firefox 1.5.0.5 and IE7 beta, and each will do the following error. When I boot up at first there is about a ~3k in resources process running of the default browser whether I have it running or not. If I do start up the default browser it will create a second instance that runs normal. If the ~3k instance is ever terminated it comes right back. I had a temporary fix where I tricked it into not having a default browser, but that really doesn't solve the underlying problem. I was wondering if there is a relation to these two, or if anyone had experienced one of the single issues on their own.

    To sum up, my current situation is a hang up every so often, and an extra instance of the deault browser. I have ran AdAware, Spyware Doctor, and NOD32 all in and out of safe mode all come up empty and all have latest defitions and versions.

    It would be very great if someone could help me out.
     
  2. bmmiller

    bmmiller Member

    Joined:
    Jul 30, 2006
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    11
    I also should note I have next to nothing in my startup. Neither problem is not a process I can just remove w/ msconfig settings.

    I also realised that I should point out that when I deleted the smhost w/o extention and the value in the prefetch folder, I still received the image I posted when I boot up or logon.
     
  3. Niobis

    Niobis Active member

    Joined:
    Jan 30, 2005
    Messages:
    2,326
    Likes Received:
    0
    Trophy Points:
    66
    The image doesn't work. Can you please repost another?
     
  4. The_Fiend

    The_Fiend Guest

    It would have been better of you posted this in the Anti virus/anti spyware forum, the guys there know their stuff when it comes to windows processes and hijackthis.
    I'll ask the moderators to move this for you.
     
  5. bmmiller

    bmmiller Member

    Joined:
    Jul 30, 2006
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    11
  6. Nephilim

    Nephilim Moderator Staff Member

    Joined:
    Feb 13, 2003
    Messages:
    13,161
    Likes Received:
    1
    Trophy Points:
    116
    Teleported :)
     
  7. bmmiller

    bmmiller Member

    Joined:
    Jul 30, 2006
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    11
    I fixed it, I had asked this on another bored for Firefox actually since at first I was under the suspesion that it was a Firefox issue, I'm not sure if I can post the link to those forums, so I'm going to qutoe myself from those forums, just incase others need help with this issue. I was one of many who had this isssue on those forums :-/

     

Share This Page