Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » rediculously slow computer

[Fixed] Hijackthis! Logs - rediculously slow computer posted in the Security & Safety forums; Just recently my computer started running rediculously slow for about an hour after I start i up each morning. I've followed the instructions on using the other tools provided, and ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 02-08-2008
Bronze Member
My PC
 
Join Date: Feb 2008
Posts: 6
PC Experience: Experienced
pungkow - See this Members User comments on their Profile page
Default rediculously slow computer

Just recently my computer started running rediculously slow for about an hour after I start i up each morning. I've followed the instructions on using the other tools provided, and this is after already running multiple other optimization programs. Here's my log:

Logfile of HijackThis v1.99.1
Scan saved at 7:20:17 PM, on 2/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\hijackthis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

Any input would be appreciated.


  #2  
Old 02-09-2008
Bronze Member
My PC
 
Join Date: Feb 2008
Posts: 6
PC Experience: Experienced
pungkow - See this Members User comments on their Profile page
Default Re: rediculously slow computer

Still awaiting a reply on this. The problem is still there, and I'm sure there's something in there that needs to be done away with.


  #3  
Old 02-09-2008
ih8bills's Avatar
Tech Team Leader
My PC
 
Join Date: Feb 2006
Location: coastal Rhode Island
Posts: 4,317
PC Experience: More Stubborn than any PC
ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page ih8bills - See this Members User comments on their Profile page
Default Re: rediculously slow computer

Sorry for the delay I will PM some of the security team for you.
They have been "swamped" lately.


__________________


Without music, life would be a mistake
Friedrich Nietzsche
  #4  
Old 02-10-2008
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 547
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: rediculously slow computer

Please uninstall the version of HijackThis that you are using. Download the newest version from here.

Please download Combofix from one of these locations:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Take note that the links are case sensitive

Save ComboFix to the desktop.
Note: It is important that it is saved directly to, and run from your desktop.
In the event you already have Combofix, please delete it as this is a new version.
  • Close any open browsers.
  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix.
1. Double click on combo.exe & follow the prompts.
2. When finished, it will produce a logfile located at C:\ComboFix.txt.
3. Post the contents of that log in your next reply with a new hijackthis log.
Note: Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang. Do not proceed with the rest of the fix if you fail to run combofix


__________________
Steve

Last edited by dahli; 02-10-2008 at 09:57 PM.
  #5  
Old 02-11-2008
Bronze Member
My PC
 
Join Date: Feb 2008
Posts: 6
PC Experience: Experienced
pungkow - See this Members User comments on their Profile page
Default Re: rediculously slow computer

Ok, I've followed your instructions, and here's the logs. First the combofix log:

ComboFix 08-02.05.3 - paul 2008-02-10 17:27:24.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.639 [GMT -5:00]
Running from: C:\Documents and Settings\paul\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\paul\Application Data\macromedia\Flash Player\#SharedObjects\2K2ZNNRL\Broadcaster.com | Home | Viral Video Clips, Live Community, News, Software, Movies, Music, Games, Mobile Media & More
C:\Documents and Settings\paul\Application Data\macromedia\Flash Player\#SharedObjects\2K2ZNNRL\www.broadcaster.com\played_list.sol
C:\Documents and Settings\paul\Application Data\macromedia\Flash Player\#SharedObjects\2K2ZNNRL\www.broadcaster.com\video_queue.sol
C:\Documents and Settings\paul\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#Broadcaster.com | Home | Viral Video Clips, Live Community, News, Software, Movies, Music, Games, Mobile Media & More
C:\Documents and Settings\paul\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
----- BITS: Possible infected sites -----
hxxp://www.spiralfrog.com
.
((((((((((((((((((((((((( Files Created from 2008-01-10 to 2008-02-10 )))))))))))))))))))))))))))))))
.
2008-02-10 17:18 . 2008-02-10 17:18 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-07 08:55 . 2008-02-07 08:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-07 08:46 . 2006-09-05 11:03 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-06 12:41 . 2008-02-06 12:41 <DIR> d-------- C:\Program Files\GraphicsGale FreeEdition
2008-02-06 12:41 . 2008-02-06 12:41 <DIR> d-------- C:\Documents and Settings\paul\Application Data\Humanbalance
2008-02-05 20:30 . 2008-02-06 08:26 <DIR> d-------- C:\Program Files\DVD Decrypter
2008-02-05 20:19 . 2008-02-06 08:26 <DIR> d-------- C:\Program Files\DVD Shrink
2008-02-05 20:19 . 2008-02-05 20:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-02-02 13:51 . 2008-02-06 08:26 <DIR> d-------- C:\Program Files\CDBurnerXP
2008-01-31 14:31 . 2008-01-31 14:33 <DIR> d-------- C:\Documents and Settings\paul\Application Data\SecondLife
2008-01-31 14:30 . 2008-01-31 14:35 <DIR> d-------- C:\Program Files\SecondLife
2008-01-28 22:57 . 2008-01-28 22:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spiralfrog
2008-01-28 22:20 . 2008-01-28 22:20 <DIR> d--hs---- C:\Documents and Settings\All Users\DRM
2008-01-28 22:17 . 2008-02-06 08:43 <DIR> d-------- C:\Program Files\SpiralFrog
2008-01-28 21:53 . 2008-01-28 21:57 <DIR> d-------- C:\Documents and Settings\paul\Application Data\Ahead
2008-01-28 21:53 . 2008-01-28 21:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-01-28 21:49 . 2008-01-28 21:49 <DIR> d-------- C:\Program Files\Nero
2008-01-28 21:49 . 2008-01-28 21:52 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-01-28 21:49 . 2008-01-28 21:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-01-13 15:59 . 2008-02-07 20:39 <DIR> d-------- C:\Program Files\Savage 2 - A Tortured Soul
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-02-06 14:31 --------- d-----w C:\Documents and Settings\paul\Application Data\DNA
2008-02-06 14:28 --------- d-----w C:\Program Files\Download Manager
2008-02-06 13:26 --------- d-----w C:\Documents and Settings\paul\Application Data\uTorrent
2008-02-06 13:26 --------- d-----w C:\Documents and Settings\paul\Application Data\BitTorrent
2008-02-06 01:27 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-05 01:03 --------- d-----w C:\Documents and Settings\paul\Application Data\Skype
2008-01-26 01:14 --------- d-----w C:\Program Files\World of Warcraft
2008-01-05 17:07 --------- d-----w C:\Program Files\m
2008-01-05 02:19 --------- d-----w C:\Program Files\Steam
2008-01-05 00:35 --------- d-----w C:\Program Files\DNA
2008-01-05 00:35 --------- d-----w C:\Program Files\BitTorrent
2008-01-03 02:51 --------- d-----w C:\Program Files\Creative
2008-01-03 02:50 --------- d-----w C:\Program Files\WarRock
2008-01-03 02:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-02 19:37 --------- d-----w C:\Program Files\Canon
2008-01-02 19:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-01-02 19:12 --------- d-----w C:\Program Files\Common Files\Canon
2008-01-01 00:26 --------- d-----w C:\Program Files\Ventrilo
2008-01-01 00:25 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-01 00:24 2,732,032 ----a-w C:\Program Files\ventrilo-3.0.1-Windows-i386.exe
2007-12-30 01:17 --------- d-----w C:\Program Files\Common Files\HP
2007-12-30 01:17 --------- d-----w C:\Documents and Settings\paul\Application Data\Printer Info Cache
2007-12-30 01:17 --------- d-----w C:\Documents and Settings\paul\Application Data\Image Zone Express
2007-12-29 20:46 --------- d-----w C:\Documents and Settings\paul\Application Data\HP
2007-12-29 20:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2007-12-29 20:37 --------- d-----w C:\Program Files\HP
2007-12-29 20:34 --------- d-----w C:\Program Files\Hewlett-Packard
2007-12-29 20:32 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2007-12-29 01:57 --------- d-----w C:\Program Files\Java
2007-12-27 20:17 --------- d--h--r C:\Documents and Settings\paul\Application Data\SecuROM
2007-12-27 20:01 --------- d-----w C:\Program Files\EA Games
2007-12-27 01:19 --------- d-----w C:\Program Files\Guild Wars
2007-12-21 17:43 --------- d-----w C:\Program Files\AGEIA Technologies
2007-12-21 14:02 --------- d-----w C:\Program Files\Sony
2007-12-21 14:02 --------- d-----w C:\Program Files\Flying Lab Software
2007-12-21 13:44 --------- d-----w C:\Documents and Settings\paul\Application Data\IGN_DLM
2007-12-15 01:20 --------- d-----w C:\Program Files\Warcraft III
2007-12-13 01:25 --------- d-----w C:\Program Files\Mp3 My Mp3 2.0
2007-08-31 12:56 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2006-09-08 18:59 65,536 ----a-w C:\Program Files\silverback.exe
2006-09-08 18:59 65,536 ----a-w C:\Program Files\savage.exe
2006-09-08 04:45 1,060,864 ----a-w C:\Program Files\silverback2.exe
2006-03-05 01:50 880,128 ----a-w C:\Program Files\WinRAR.exe
2006-03-01 05:11 27 ----a-w C:\Program Files\titanium.bat
2006-02-07 23:47 25 ----a-w C:\Program Files\graveyard.bat
2005-05-08 22:56 55,808 ----a-w C:\Program Files\zlib1.dll
2005-05-08 22:55 203,264 ----a-w C:\Program Files\libpng13.dll
2004-10-18 18:04 161,280 ----a-w C:\Program Files\fmod.dll
2004-09-02 03:05 4 ----a-w C:\Program Files\locale.msg
2004-07-14 03:07 13 ----a-w C:\Program Files\locale.dzn
2004-07-01 03:31 147,456 ----a-w C:\Program Files\Lokalizator.dll
2004-03-19 00:36 401,484 ----a-w C:\Program Files\msvcrtd.dll
2004-01-16 05:43 188,495 ----a-w C:\Program Files\libcurl.dll
2003-08-01 16:51 46,553 ----a-w C:\Program Files\licenses.txt
2003-07-16 04:00 53,248 ----a-w C:\Program Files\zlib.dll
2003-06-20 10:16 843,776 ----a-w C:\Program Files\libeay32.dll
2003-06-20 10:16 159,744 ----a-w C:\Program Files\ssleay32.dll
2003-04-23 04:59 843,776 ----a-w C:\Program Files\iconv.dll
2003-04-23 04:59 506,486 ----a-w C:\Program Files\libglib-2.0-0.dll
2003-04-23 04:59 47,027 ----a-w C:\Program Files\libintl-1.dll
2003-04-23 04:59 32,644 ----a-w C:\Program Files\libgthread-2.0-0.dll
2003-04-23 04:59 23,284 ----a-w C:\Program Files\libgmodule-2.0-0.dll
2003-02-21 19:42 348,160 ----a-w C:\Program Files\msvcr71.dll
2007-08-05 23:33 56 --sh--r C:\WINDOWS\system32\4DCE451F62.sys
2007-08-05 23:33 952 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2008-02-07 08:47 6731312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\RunOnce]
"WIAWizardMenu"="C:\WINDOWS\system32\sti_ci.dl l" [2004-08-04 00:56 136704]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2005-04-25 13:45 36040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\WINDOWS\\system32\\logonuiX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^paul^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\paul\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^paul^Start Menu^Programs^Startup^Neverwinter Nights_ Platinum Edition Registration.lnk]
path=C:\Documents and Settings\paul\Start Menu\Programs\Startup\Neverwinter Nights_ Platinum Edition Registration.lnk
backup=C:\WINDOWS\pss\Neverwinter Nights_ Platinum Edition Registration.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^paul^Start Menu^Programs^Startup^OpenOffice.org 2.0.lnk]
path=C:\Documents and Settings\paul\Start Menu\Programs\Startup\OpenOffice.org 2.0.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.0.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^paul^Start Menu^Programs^Startup^WindowBlinds.lnk]
path=C:\Documents and Settings\paul\Start Menu\Programs\Startup\WindowBlinds.lnk
backup=C:\WINDOWS\pss\WindowBlinds.lnkStartup
[HKLM\~\startupfolder\^AdobeFnt10.lst]
path=\AdobeFnt10.lst
backup=C:\WINDOWS\pss\AdobeFnt10.lstCommon Startup
[HKLM\~\startupfolder\^hs_err_pid3404.log]
path=\hs_err_pid3404.log
backup=C:\WINDOWS\pss\hs_err_pid3404.logCommon Startup
[HKLM\~\startupfolder\^hs_err_pid3888.log]
path=\hs_err_pid3888.log
backup=C:\WINDOWS\pss\hs_err_pid3888.logCommon Startup
[HKLM\~\startupfolder\^ntuser.dat]
path=\ntuser.dat
backup=C:\WINDOWS\pss\ntuser.datCommon Startup
[HKLM\~\startupfolder\^ntuser.dat.LOG]
path=\ntuser.dat.LOG
backup=C:\WINDOWS\pss\ntuser.dat.LOGCommon Startup
[HKLM\~\startupfolder\^ntuser.ini]
path=\ntuser.ini
backup=C:\WINDOWS\pss\ntuser.iniCommon Startup
[HKLM\~\startupfolder\^Start Menu.rar]
path=\Start Menu.rar
backup=C:\WINDOWS\pss\Start Menu.rarCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
--a------ 2006-08-01 15:35 67112 C:\PROGRA~1\AIM\aim.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
C:\Program Files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Probe]
--a------ 2002-12-06 16:07 617984 C:\Program Files\ASUS\Probe\AsusProb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-01 10:21 153136 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2008-01-04 19:35 290112 C:\Program Files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
--------- 2004-12-02 17:23 102400 C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMOFFICE4DMOUSE]
C:\Program Files\Labtec\Desktop\V5.1\moffice.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
--a------ 2007-03-05 16:57 1103480 C:\Program Files\Download Manager\DLM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogonStudio]
C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 11:54 5674352 C:\Program Files\MSN Messenger\MsnMsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OFFICEKB]
C:\Program Files\Labtec\Desktop\V5.1\kbdap32a.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-12-08 23:06 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
--a------ 2006-12-18 17:32 25365032 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpiralFrog]
--a------ 2007-12-18 11:10 163128 C:\Program Files\SpiralFrog\Spiralfrog.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-12-13 22:36 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
--a------ 2004-11-10 23:15 111816 C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2004-12-20 13:41 33792 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WmdmPmSp"=2 (0x2)
"uploadmgr"=2 (0x2)
"SCardDrv"=3 (0x3)
"TlntSvr"=3 (0x3)
"Netlogon"=3 (0x3)
"Messenger"=2 (0x2)
"WMP54GXSVC"=2 (0x2)
"MDM"=2 (0x2)
"SSDPSRV"=3 (0x3)
"upnphost"=3 (0x3)
"Adobe LM Service"=3 (0x3)
R0 d344bus;d344bus;C:\WINDOWS\system32\DRIVERS\d344bu s.sys [2003-12-27 20:42]
R0 d344prt;d344prt;C:\WINDOWS\system32\Drivers\d344pr t.sys [2003-12-27 02:38]
S1 FG;FG;C:\WINDOWS\SYSTEM32\DRIVERS\FG.SYS []
S2 Ca533av;Icatch(IV) Video Camera Device;C:\WINDOWS\system32\Drivers\Ca533av.sys []
S3 Dual Modeual Mode Video Capture;C:\WINDOWS\system32\DRIVERS\CoachVc.sys [2002-10-09 20:24]
S3 samhid;samhid;C:\WINDOWS\system32\drivers\samhid.s ys []
S3 USBCamera;Icatch(IV) Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk533.sys []
S3 XDva011;XDva011;C:\WINDOWS\system32\XDva011.sys []
S3 XDva014;XDva014;C:\WINDOWS\system32\XDva014.sys []
S3 XDva015;XDva015;C:\WINDOWS\system32\XDva015.sys []
S3 XDva024;XDva024;C:\WINDOWS\system32\XDva024.sys []
S4 WMP54GXSVC;WMP54GXSVC;"C:\Program Files\Linksys Wireless-G PCI Adapter with SRX\WLService.exe" "WMP54GX.exe" []
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{aeb65dcd-f66d-11da-9df1-00121768086d}]
\Shell\AutoRun\command - G:\autoverify.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-02-04 18:47:00 C:\WINDOWS\Tasks\Disk Cleanup.job"
- C:\WINDOWS\system32\cleanmgr.exe
"2008-02-10 19:00:01 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-02-08 20:00:00 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
************************************************** ************************
disk not found C:\
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
disk not found C:\
************************************************** ************************
.
Completion time: 2008-02-10 17:37:20
ComboFix-quarantined-files.txt 2008-02-10 22:36:28
.
2007-11-29 13:22:42 --- E O F ---




now the Hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:56:51 PM, on 2/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe " -t (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 3860 bytes


  #6  
Old 02-11-2008
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 547
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: rediculously slow computer

Please perform this online scan: F-Secure Online Scanner The online scanner is on the bottom right of the page. Follow the directions in the F-Secure page for proper Installation.
  • You may receive an alert on the address bar at this point to install the ActiveX control.
  • Click on that alert and then click "Install ActiveX component".
  • Read the license agreement and click "Accept".
  • Click "Full System Scan" to download the scanning components and begin scan and cleaning.
  • When the scan completes, click the "I want to decide item by item" button.
  • For each item found, Select "Disinfect" and click "Next".
  • When done, click the "Show Report" button, then copy and paste the entire report into your next reply.


__________________
Steve

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Very slow computer - HJT log. caxis [Fixed] Hijackthis! Logs 3 02-01-2008 02:09 AM
Norton refues to give tech support without additional fees !!! synthetic144 Anti-Virus (AV) 6 01-20-2008 01:54 AM
Please help! My desktop has been alter, my IE shuts down, and my computer is slow sjwalla3 [Fixed] Hijackthis! Logs 1 11-04-2007 12:06 AM
[Resolved] Really Slow Computer, seems like HD or RAM haptic Windows Vista 8 08-24-2007 03:33 AM
[Fixed] Spyware and slow computer! Jimmyb30 [Fixed] Hijackthis! Logs 12 09-24-2006 10:10 PM


All times are GMT +1. The time now is 06:06 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
Credit Report
Get your free credit report and score online.

Loans
Loans information and advice from money expert.

New York Hotel
New York hotel information and advice.