PDA

View Full Version : Windows 2K Pro problem...


Dogdaysdude
01-07-2004, 11:42 PM
Hi. When I right click an icon on my desktop, it takes a good 20-25 seconds for the menu box to open. I did a de-frag and ran Spybot. Haven't ran a virus scan yet. Everything seems to be working ok other than that. No new software installed.
Any ideas on what would cause such a delay?
Thanks.

Budfred
01-08-2004, 12:01 AM
Usually it is something running in the background. A virus scan and spyware scanning would definitely be worthwhile....

Dogdaysdude
01-08-2004, 10:11 AM
Hi, Budfred...
I found after a bit more experimenting that Norton Anti-virus may possibly be the problem. (Menu items for NAV appear when most icons are right-clicked. There doesn't seem to be a delay with icons such as IE and Recovery Bin.) When I try to open NAV, it takes 20-25 seconds to respond. It's the only program acting this way. Liveupdate expired on 1/6/04 and it has been acting this way since then. I wonder if I un-install it and then re-install if that would "fix" it's delay. I'm not too worried about renewing Liveupdate until NAV is acting right. It's NAV 2003 Pro.

Paleo Pete
01-08-2004, 10:43 AM
Just out of curiosity, run Hijack This and post the log in this thread so some of the folks who know how to decipher it (I'm learning...) can have a look.

Then if nothing turns up, you might wait and update Norton again, if the last one had a bug it should be fixed fairly soon so the next update should get things back to normal...should...

Hijack This

Dogdaysdude
01-08-2004, 10:56 AM
Ok. I'd appreciate if all would look it over. I won't be able to do it until this evening sometime when I get home.

Dogdaysdude
01-08-2004, 07:35 PM
Ok, here it is...



Logfile of HijackThis v1.97.7
Scan saved at 5:35:28 PM, on 1/8/2004
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP3 (5.00.2920.0000)

Running processes:
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EX E
C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb06. exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Nikon\NkView5\NkvMon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\Webshots\WebshotsTray.exe
C:\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.excite.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CreateCD50] C:\PROGRA~1\COMMON~1\ADAPTE~1\CreateCD\CREATE~1.EX E -r
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb06. exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {28F00B0F-DC4E-11D3-ABEC-005004A44EEB} (Register Class) - http://content.hiwirenetworks.net/inbrowser/cabfiles/2.5.30/Hiwire.cab
O16 - DPF: {3C5BA506-6C30-4738-9CED-797ACADEA8DC} - http://cyberspace.com/SQLoader.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37964.8022337963
O16 - DPF: {C6B086D2-146B-47A4-A218-B82DCAF2D872} (cpbrxpie Control) - http://a19.g.akamai.net/7/19/7125/4003/ftp.coupons.com/r3120/cpbrxpie.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553528000} - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Budfred
01-08-2004, 07:48 PM
Yep, you have some garbage. Use HJT to fix these:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about :blank
O16 - DPF: {28F00B0F-DC4E-11D3-ABEC-005004A44EEB} (Register Class) - http://content.hiwirenetworks.net/i...5.30/Hiwire.cab
O16 - DPF: {3C5BA506-6C30-4738-9CED-797ACADEA8DC} - http://cyberspace.com/SQLoader.cab

If this is not your choice, fix this too:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.excite.com/

And if you don't know what this is, you may want to fix it too. It has something to do with coupons and those are often malware...

O16 - DPF: {C6B086D2-146B-47A4-A218-B82DCAF2D872} (cpbrxpie Control) - http://a19.g.akamai.net/7/19/7125/4...20/cpbrxpie.cab

You also need to get the Win2K updates to SP4. SP3 allows a number of vulnerabilities that will make it likely that you have more trouble later. It is probably also a good idea to update your IE to the latest version...

Once you are done, reboot and run HJT again. Open your browser and come back here to post the new log....