View Full Version : Slowll-l-y
Raiders
06-30-2004, 07:10 PM
I have Windows XP Pro on my other PC and i have a 80GB hard drive split it into 2 Partitions and it turns out that its is moving slowly i cleared it Fornat the PC b4 i went on Holiday so its just moving slowly when i scroll up and down a webpage or a window it waits 1 second then it scrolls down or either way i go like a replay on the TV (football match) Can sumone help to solve the problem.
Cheers Raiders
Variable
06-30-2004, 09:46 PM
how much RAM and what kind of CPU do you have?
Raiders
07-01-2004, 07:06 AM
RAM is 256MB
AMD Athlon 2200XP+
1.81Ghz
pave_spectre
07-01-2004, 07:35 AM
Your RAM is about the minimum needed for XP to run decently.
You may want to look into what programs or services are running in the background.
Variable
07-01-2004, 10:18 AM
Yea, that's enough RAM to run fine as long as you don't have a dozen odd apps running in the background. If you do CTR-ALT-DLT, click Task Manager, you will have the answers to your problem at hand. First look at the Performance tab and look down and see how much Physical memory you have available, CPU usage is top left, should be under 5 percent if you have nothing open. Now click Processes, these are all the processes running on your machine.The System Idle Process should be between 95 and 99. If you look down and see one Image Name running really high you have found your culprit. If you have a lot of spyware running on your system that could also be your problem. XP is a resource hog and you are on the edge of enough resources while still having enough for applications. Do you have a firewall,AV and spyware checker?
You could also run a sysofts Sandra and see if it is a hardware problem, cpu functioning below normal for example. I think they have a freeware version.
Raiders
07-01-2004, 11:28 AM
i only have Photoshop CS and Yahoo Messenger on the machine im about to buy a Anti-virus and Norton Personal Firewall i hear NPFW(Norton Personal FireWall) is the best one around. Is there any other ones u can recomend me?
Variable
07-01-2004, 01:18 PM
The newer versions of Norton Firewall may be more customizable but, the one I have can be more of a pain than a help. Especially if you like to tweak things. For the average user I recommend the Norton personal firewall and AV all the time. It's a good basic firewall. But , I don't have it installed. I use sygate for gaming and my own firewall for surfing. If you look at the Application and Utility forum, under Windows here at PCGuide you will notice a section on all the security apps, links to free ones and such. Lots of folks use zone alarm.
anyway, did you do the ctrl alt del thing I talked about and if so do you notice anything hogging CPU cycles? How much free physical memory do you have?
V
Raiders
07-01-2004, 02:49 PM
Nothings Hoging the CPU Cycle
Pyiscal Memory is 261616k
Steve
07-01-2004, 03:16 PM
im about to buy a Anti-virus and Norton Personal Firewall
If you've been online without an A/V program and a firewall, it might be a good idea to post a HJT log. You can download it Here (http://www.download.com/3000-2144-10227352.html) . Install it in a permanent folder, scan your computer, save the log and copy and paste it here.
At least we can decide if it is or isn't malware that is causing your problem.
:)
Raiders
07-01-2004, 03:26 PM
i haven't got anyfin else on it apart from Yahoo and Photoshop Cs
Variable
07-01-2004, 09:52 PM
You may want to try downloading Sandra and running it? If you do not have any spyware or virii then it could be a hardware problem. Are you on dial up or high speed?
Sandra
Link (http://www.sisoftware.net/index.html?dir=dload&location=sware_dl_x86&langx=en&a=)
Paleo Pete
07-02-2004, 02:03 AM
If you have had this PC on the internet with no firewall or antivirus, DEFINITELY run some spyware and antivirus scans SOON. The internet is not safe without them any more. At default XP settings, 45 minutes online and I would almost bet you have at least 4 spyware applications hogging resources, 2 weeks and you're almost sure to have at least one virus, probably 3 or 4. You should see the computers I clean up that DO have antivirus and firewall...Do yourself a favor and keep everything updated.
Look Here (http://www.pcguide.com/vb/showthread.php?s=&threadid=26244) for some good free spyware scanning/removal applications, Hijack This has already mentioned and I would recommend Adaware before running it. This Thread (http://www.pcguide.com/vb/showthread.php?s=&threadid=15179) has links to some good antivirus/anti trojan stuff, including a couple of good online virus scans. Also in the Applications and Security section look for one of Budfred's posts, he has currently good links in his signature if those posted above aren't working, I think Whyzman does too.
Download Hijack This to its own folder, NOT the desktop, and run it from there. That makes things a lot cleaner for your desktop and easier to handle if a restore is needed. Always save the log to the same folder. I always create a Hijack This folder on C drive and use that. Easy to find and identify.
Raiders
07-02-2004, 11:29 AM
I'm on High Speed Broadband
classicsoftware
07-02-2004, 11:41 AM
Broadband Cable internet access w/o a AV or firewall. You either brave or stupid, I'm not sure which.
Get yourself an antivirus program now:
Avast (http://www.avast.com/eng/products/free_software/avast_4_home/free_antivirus_softw.html) and AVG (http://www.grisoft.com/us/us_dwnl_free.php) are free
Then update and perform a full system scan. After that,
Perform and on line scan here (http://housecall.trendmicro.com/)
As instructed previously download, install and update Adaware (http://www.lavasoftusa.com/). Perform an indepth scan and fix everything it finds
Then after all is said and done download Hijackthis (http://www.spywareinfo.com/~merijn/downloads.html)
run it, but don't fix anything. Post your log back here.
There are some very bright people who have given yoiu some good advice (Steve and Paleo Pete) Do what they say. I'll bet you a jelly doughnut your system is infected with spyware and or a virus/trojan horse.
Variable
07-02-2004, 11:51 AM
I was working on a new machine recently and was installing the internal DSL modem, I connected it to the web to verify it would work and decided to update the virus scan real quick. The machine was infected with LSASS in less than 30 seconds. The Nortom wizard was not even done polling for available updates. He has to have at least the XP firewall running and must have up to date OS, otherwise he would be infected by several nasty exploits. He would also probably be also hosting several warez sites :p
V
Raiders
07-02-2004, 12:33 PM
I will post my HIJThis ASAP
Raiders
07-02-2004, 01:20 PM
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\gaamsf.exe
C:\Program Files\WindowsSA\omniscient.exe
C:\WINDOWS\System32\Adstartup.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\PicoZip\PicoZipTray.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\WINDOWS\twain_32\AVISION\AV260C\SCANER32.EXE
C:\PROGRA~1\PicoZip\PicoZip.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\PicoZip\PicoZip.exe
C:\DOCUME~1\MCCONN~1.FAM\LOCALS~1\Temp\zf_6.tmp\Hi jackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://broadband.blueyonder.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem219.dll (file missing)
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_ 12_0.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: (no name) - {0B90AA1B-F649-44C3-9FD3-736C332CBBCF} - C:\WINDOWS\System32\IEEnhancer.dll
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper\CCHelper.dll
O2 - BHO: (no name) - {9E992732-295F-4987-8BE3-16FAC1639198} - C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.d ll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_ 12_0.dll
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: (no name) - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - (no file)
O3 - Toolbar: Pa&nicware Pop-Up Stopper - {7E82235C-F31E-46CB-AF9F-1ADD94C585FF} - C:\Program Files\Panicware\Pop-Up Stopper\pstopper.dll
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - HKLM\..\Run: [vxribktkgk] C:\WINDOWS\System32\gaamsf.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [dmzoxqd] C:\WINDOWS\dmzoxqd.exe
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
O4 - HKLM\..\Run: [pyj] C:\WINDOWS\pyj.exe
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\Adstartup.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
Raiders
07-02-2004, 01:22 PM
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.e xe
O4 - HKCU\..\Run: [PicoZip] C:\PROGRA~1\PicoZip\PicoZipTray.exe
O4 - Startup: Avision Scanner Utilities.lnk = C:\WINDOWS\twain_32\AVISION\AV260C\SCANER32.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm414
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
I have a RUNDLL Problem with Birdge.dll
Steve
07-02-2004, 07:37 PM
Hi Raiders,
First go to Control Panel > Add/Remove programs and uninstall My Way, My Web Search and any other "MY" programs that are there. This is often considered an optional fix and I have included it in the following fix. If for some reason you want this program, just omit it from the fix. I recommend getting rid of it.
Here are the things I see that you can fix with HJT:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://broadband.blueyonder.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem219.dll (file missing)
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: (no name) - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - (no file)
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - HKLM\..\Run: [vxribktkgk] C:\WINDOWS\System32\gaamsf.exe
O4 - HKLM\..\Run: [dmzoxqd] C:\WINDOWS\dmzoxqd.exe
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
O4 - HKLM\..\Run: [pyj] C:\WINDOWS\pyj.exe
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\Adstartup.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm414
Then boot into safe mode and find and delete:
gaamsf.exe
dmzoxqd.exe
omniscient.exe
pyj.exe
Adstartup.exe
Then reboot. Run HJT again and post a follow up log.
:)
Raiders
07-03-2004, 03:37 PM
new Hijack after above as requested
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\PicoZip\PicoZipTray.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\WINDOWS\twain_32\AVISION\AV260C\SCANER32.EXE
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\PicoZip\PicoZip.exe
C:\DOCUME~1\MCCONN~1.FAM\LOCALS~1\Temp\zf_4.tmp\Hi jackThis.exe
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {0B90AA1B-F649-44C3-9FD3-736C332CBBCF} - C:\WINDOWS\System32\IEEnhancer.dll
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper\CCHelper.dll
O2 - BHO: (no name) - {9E992732-295F-4987-8BE3-16FAC1639198} - C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.d ll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_ 12_0.dll
O3 - Toolbar: (no name) - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - (no file)
O3 - Toolbar: Pa&nicware Pop-Up Stopper - {7E82235C-F31E-46CB-AF9F-1ADD94C585FF} - C:\Program Files\Panicware\Pop-Up Stopper\pstopper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
Raiders
07-03-2004, 03:38 PM
O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.e xe
O4 - HKCU\..\Run: [PicoZip] C:\PROGRA~1\PicoZip\PicoZipTray.exe
O4 - Startup: Avision Scanner Utilities.lnk = C:\WINDOWS\twain_32\AVISION\AV260C\SCANER32.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Its still going slow.
Steve
07-03-2004, 04:58 PM
Hi Raiders,
I see you have chosen to keep the "MY" programs. You take a little performance hit with these programs, but not to bad. I'm glad to see you now have an A/V program and firewall.
You really should have HJT fix the following item:
O3 - Toolbar: (no name) - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - (no file)
And here are some things you can use HJT to fix. This will not delete or effect the programs except to stop them from starting up when you boot the computer, saving you some memory:
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.e xe
O4 - HKCU\..\Run: [PicoZip] C:\PROGRA~1\PicoZip\PicoZipTray.exe
O4 - Startup: Avision Scanner Utilities.lnk = C:\WINDOWS\twain_32\AVISION\AV260C\SCANER32.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
BTW, you have this program on the computer:
IE Enhancer
Do you know what it is? I can't find any solid info on it.
See if that helps.
:)
Raiders
07-03-2004, 05:17 PM
I don't know what IE Enchance is don't even know where it came from or where its is
PrntRhd
07-03-2004, 05:23 PM
I did a Google search for IE Enhancer, it came up as a toolbar. I would remove it, if Steve concurs.
Raiders
07-03-2004, 05:37 PM
I have decide to keep 'MY' stuff cos i use the funny faces thing from SmileyCentral.com
new HJT:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\PicoZip\PicoZipTray.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\WINDOWS\twain_32\AVISION\AV260C\SCANER32.EXE
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Movie Maker\moviemk.exe
C:\PROGRA~1\PicoZip\PicoZip.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\DOCUME~1\MCCONN~1.FAM\LOCALS~1\Temp\zf_314.tmp\ HijackThis.exe
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper\CCHelper.dll
O2 - BHO: (no name) - {9E992732-295F-4987-8BE3-16FAC1639198} - C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.d ll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_ 12_0.dll
O3 - Toolbar: Pa&nicware Pop-Up Stopper - {7E82235C-F31E-46CB-AF9F-1ADD94C585FF} - C:\Program Files\Panicware\Pop-Up Stopper\pstopper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\Adstartup.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralInitialSetup1.0.0.8.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Steve
07-03-2004, 05:52 PM
OK. I agree with PrntRhd. Let's do alittle more cleanup. Keep in mind, if you fix all the 04 items I mentioned in the last post you will not loose the programs and the computer will run a little faster.
Fix the following with HJT:
O2 - BHO: (no name) - {0B90AA1B-F649-44C3-9FD3-736C332CBBCF} - C:\WINDOWS\System32\IEEnhancer.dll
O2 - BHO: (no name) - {9E992732-295F-4987-8BE3-16FAC1639198} - C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.d ll
O3 - Toolbar: (no name) - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - (no file)
O4 - HKCU\..\Run: [\IEService.exe] C:\DOCUME~1\ALLUSE~1\APPLIC~1\IESERV~1\IEService.e xe
Then find and delete:
C:\WINDOWS\System32\IEEnhancer.dll
IEService.dll
IEService.exe
Then clean out your history, temp and tif folders. Reboot and see if things are faster.
david eaton
07-03-2004, 06:54 PM
Also fix this one: -
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\Adstartup.exe
Delete the file C:\WINDOWS\System32\Adstartup.exe after rebooting.
Popup ad generator!
Raiders
07-03-2004, 06:59 PM
I have done that....
Its still slow!
Raiders
07-04-2004, 07:46 AM
I fixed it the problem was The Acceleration under advanced in the Desktop Settings.
But i have a problem i can't get rid of XXXtoolbar in my Control Panel>Add and Remove Programs.
Can anyone help?
Cheers for ur help guys
P.S.Help on the other fing it was just a last min thing that popped into my head what i learned from my Course HNC Computing!!
vBulletin v3.6.1, Copyright ©2000-2012, Jelsoft Enterprises Ltd.