Content Top
DAL Computer Help » Internet Security Help » Spyware, Adware, Viruses and HijackThis Logs » Computer is EXTREMELY SLOW unless in safe mode

Recommended Fix

Click here to fix Windows Errors and Optimize Windows Performance

Need Computer Help?
Register Now for FREE

Computer is EXTREMELY SLOW unless in safe mode

Reply
Thread Tools
Spyware, Adware, Viruses and HijackThis Logs
  #1 (permalink)  
Old 22-12-2004, 06:37 AM
Newbie
D-A-L Newbie
 
Join Date: Dec 2004
Posts: 7
mattmew Is a beginner here at D-A-L
Question Computer is EXTREMELY SLOW unless in safe mode

My computer has began running EXTREMELY SLOW. The only way I can get around is by booting in safe mode. I followed all of Owen's instructions by running the appropriate software. I downloaded the hijackthis and here is the log:

Logfile of HijackThis v1.99.0
Scan saved at 9:09:41 PM, on 12/21/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Aladdin Systems\StuffIt\stuffit.exe
C:\Documents and Settings\Matthew\Application Data\Aladdin Systems\StuffIt\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *r1.attbi.com
O2 - BHO: MySearch - {4E7BD74F-2B8D-469E-A0E8-F76FA694BF2E} - C:\WINDOWS\DOWNLO~1\searchv2.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MySearch - {4E7BD74F-2B8D-469E-A0E8-F76FA694BF2E} - C:\WINDOWS\DOWNLO~1\searchv2.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Realtime Monitor] "C:\Program Files\CA\eTrust\Antivirus\realmon.exe"
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Help - {C9CC262B-3947-42AF-A867-E240088CFBAD} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {EAC05624-28BD-48EC-ABFC-732A8EA9C801} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {EED2483F-74A8-46B3-ABA9-14A521D87E34} - http://www.comcast.net (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {4E7BD74F-2B8D-469E-A0E8-F76FA694BF2E} (MySearch) - http://toolbar.push.com/searchv2.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...4/mcinsctl.cab
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs7b.instantservice.com/jars/...rxsigned33.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://webchat.dell.com/Media/Visit.../TLIEFlash.CAB
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/pro...tor/WebSWK.cab
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com/components/ocx/...or/Outside.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...21/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...71/mcfscan.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: eTrust Antivirus RPC Server - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\Antivirus\InoTask.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Can someone please help me? I am anxious to learn what I should have done to make sure this doesn't happen.

Let me know.

Thanks!!!!
Matt
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 22-12-2004, 01:03 PM
Newbie
D-A-L Newbie
 
Join Date: Dec 2004
Posts: 12
ziggy Is a beginner here at D-A-L
Re: Computer is EXTREMELY SLOW unless in safe mode

Use Hijack This to remove the following:

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe

O16 - DPF: {4E7BD74F-2B8D-469E-A0E8-F76FA694BF2E} (MySearch) - http://toolbar.push.com/searchv2.cab

O9 - Extra button: ComcastHSI - {EED2483F-74A8-46B3-ABA9-14A521D87E34} - http://www.comcast.net (file missing) (HKCU)

O9 - Extra button: Support - {EAC05624-28BD-48EC-ABFC-732A8EA9C801} - http://www.comcastsupport.com (file missing) (HKCU)

O9 - Extra button: ComcastHSI - {EED2483F-74A8-46B3-ABA9-14A521D87E34} - http://www.comcast.net (file missing) (HKCU)

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

O3 - Toolbar: MySearch - {4E7BD74F-2B8D-469E-A0E8-F76FA694BF2E} - C:\WINDOWS\DOWNLO~1\searchv2.dll

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll

O2 - BHO: MySearch - {4E7BD74F-2B8D-469E-A0E8-F76FA694BF2E} - C:\WINDOWS\DOWNLO~1\searchv2.dll
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 23-12-2004, 03:36 AM
Newbie
D-A-L Newbie
 
Join Date: Dec 2004
Posts: 7
mattmew Is a beginner here at D-A-L
Re: Computer is EXTREMELY SLOW unless in safe mode

Thanks Ziggy, but the problem still persists after I restart and allow normal startup. My desktop won't even load for a LLLLOONNNGG time. Any other ideas on how to fix this issue.

Thanks,
Matt
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 23-12-2004, 03:38 AM
Newbie
D-A-L Newbie
 
Join Date: Dec 2004
Posts: 7
mattmew Is a beginner here at D-A-L
Unhappy Re: Computer is EXTREMELY SLOW unless in safe mode

I did the things Ziggy said, but the problem still persists. Any other ideas????

Thanks,
Matt
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 23-12-2004, 10:54 AM
HJM's Avatar
HJM HJM is offline
Valued Member
New Recruit
 
Join Date: Dec 2004
Posts: 115
HJM Is a beginner here at D-A-L
Re: Computer is EXTREMELY SLOW unless in safe mode

Mattmew, you're very low on running processes in your log which leads me to believe you've generated it while in Safe Mode. We need to see everything.

Please do the following:

Click Start > Run and type in msconfig to open the System Configuration Utility.
On the Startup Tab, make sure that all the processes have a checkmark in the box beside them.

Then post a new HijackThis log while running in normal mode.

I'll run through your log this evening after work.

Last edited by HJM; 23-12-2004 at 11:14 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 24-12-2004, 04:04 AM
Newbie
D-A-L Newbie
 
Join Date: Dec 2004
Posts: 7
mattmew Is a beginner here at D-A-L
Re: Computer is EXTREMELY SLOW unless in safe mode

Quote:
Originally Posted by HJM
Mattmew, you're very low on running processes in your log which leads me to believe you've generated it while in Safe Mode. We need to see everything.

Please do the following:

Click Start > Run and type in msconfig to open the System Configuration Utility.
On the Startup Tab, make sure that all the processes have a checkmark in the box beside them.

Then post a new HijackThis log while running in normal mode.

I'll run through your log this evening after work.
HJM, When I try to startup in normal mode it will not even get past the welcome "loading your personal settings" screen. One time it did and only half my desktop icons loading and I can't click on anything it just sits there. My mouse still moves, but no results from clicking. It seems like I am stuck with safe mode for now. When I click on the start button there is no "run" option.
Let me know what I should do. I REALLY appreciate your help.
Thanks,
Mattmew
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 24-12-2004, 06:02 PM
Newbie
D-A-L Newbie
 
Join Date: Dec 2004
Posts: 7
mattmew Is a beginner here at D-A-L
Re: Computer is EXTREMELY SLOW unless in safe mode

When I try to startup in normal mode it will not even get past the welcome "loading your personal settings" screen. One time it did and only half my desktop icons loading and I can't click on anything it just sits there. My mouse still moves, but no results from clicking. It seems like I am stuck with safe mode for now. When I click on the start button there is no "run" option.
Let me know what I should do. I REALLY appreciate your help.
Thanks,
Mattmew
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 24-12-2004, 10:07 PM
HJM's Avatar
HJM HJM is offline
Valued Member
New Recruit
 
Join Date: Dec 2004
Posts: 115
HJM Is a beginner here at D-A-L
Re: Computer is EXTREMELY SLOW unless in safe mode

We'll have to work in Safe Mode for the time being then. Print these instructions out or copy them to notepad. It's not a good idea to go online while in Safe Mode so try not to do it unless really necessary.

To add the 'Run Command' to your Start menu, right click on the 'Start' button and select 'Properties'. On the 'Startup' tab, click on 'Customize' and then the 'Advanced' tab. Scroll down the 'Start menu items' list and checkmark the box next to 'Run Command', click OK.

Now Click Start > Run and type in msconfig to open the System Configuration Utility.
On the Startup Tab, make sure that all the processes have a checkmark in the box beside them.


You're running HJT from a Temp folder. HJT makes backups which can be accidently removed when running from a Temp folder. This would be a problem if you ever need to roll back a HJT Fix.

Create a folder on the C: drive called C:\HJT
Go to My Computer (Windows key+e)
Double click on C:
then right click and select New > Folder
Name it HJT and unzip your copy of HJT to it for future use.


If you haven't got Ad-Aware SE, please download, configure and scan as per the Ad-Aware Tutorial link in my signature. (disconnect from the net when you've finished the configuration).


Close all windows and browsers, run HJT again and check mark the following:-

O2 - BHO: MySearch - {4E7BD74F-2B8D-469E-A0E8-F76FA694BF2E} - C:\WINDOWS\DOWNLO~1\searchv2.dll
O3 - Toolbar: MySearch - {4E7BD74F-2B8D-469E-A0E8-F76FA694BF2E} - C:\WINDOWS\DOWNLO~1\searchv2.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Help - {C9CC262B-3947-42AF-A867-E240088CFBAD} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {EAC05624-28BD-48EC-ABFC-732A8EA9C801} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {EED2483F-74A8-46B3-ABA9-14A521D87E34} - http://www.comcast.net (file missing) (HKCU)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe
O16 - DPF: {4E7BD74F-2B8D-469E-A0E8-F76FA694BF2E} (MySearch) - http://toolbar.push.com/searchv2.cab
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs7b.instantservice.com/jars...erxsigned33.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://webchat.dell.com/Media/Visi...t/TLIEFlash.CAB
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab



Click FIX CHECKED



Set Windows to 'Show all files & folders'.
Click Start > My Computer> Tools> Folder Options>
On the View tab make sure that you:-
Select 'Show Hidden Files & Folders'
Uncheck 'Hide file extensions for known file types'.
Uncheck 'Hide protected operating system files'.
Click OK.


Go to C:\WINDOWS\DOWNLO~1 and delete searchv2.dll.

Go to C:\Program Files and delete Viewpoint <---Folder



Clean out temporary files:
* Go to Start | Run | type cleanmgr | OK
* Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are checked.
* Let it scan your system for files to remove.
* Press OK to remove them.



Reboot into normal mode (if you can) and post a fresh log letting me know how things are running.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 25-12-2004, 03:58 AM
Newbie
D-A-L Newbie
 
Join Date: Dec 2004
Posts: 7
mattmew Is a beginner here at D-A-L
Red face Re: Computer is EXTREMELY SLOW unless in safe mode

HJM, I did as you said in your reply and the Run Command to start menu was already checked. I checked to see if I missed it for some reason and it again was not in the start menu. I unchecked and rechecked. For some reason it is not there. I am running in Safe Mode with Networking. Does this option have anything to do with it?
Sorry this is being so difficult! I am anxious to do the things you are saying, but not able to get past the run portion.
Let me know.
Thank you,
Mattmew
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 25-12-2004, 07:34 AM
Newbie
D-A-L Newbie
 
Join Date: Dec 2004
Posts: 7
mattmew Is a beginner here at D-A-L
Re: Computer is EXTREMELY SLOW unless in safe mode

So, I was able to log into the normal mode while waiting about 15 minutes between each move. I was able to open the run mode and msconfig and made sure everything was running. Other than that it froze again. So, knowing that everything was running, I started back up in safe mode and did all that you asked. A few of the things you asked for me to delete in the Highjackthis.log were not present. I was unable to delete the download~ file. So, I ran the Highjackthis.log again and this is what I came up with.

THANK YOU VERY MUCH FOR YOUR HELP, I REALLY APPRECIATE IT!!!!

Logfile of HijackThis v1.99.0
Scan saved at 10:25:32 PM, on 12/24/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Matthew\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *r1.attbi.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Realtime Monitor] "C:\Program Files\CA\eTrust\Antivirus\realmon.exe"
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...4/mcinsctl.cab
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/pro...tor/WebSWK.cab
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com/components/ocx/...or/Outside.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...21/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...71/mcfscan.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O23 - Service: eTrust Antivirus RPC Server - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\Antivirus\InoTask.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Extremely slow computer! (hjt log) PeaTear Spyware, Adware, Viruses and HijackThis Logs 4 29-01-2007 08:33 PM
My computer extremely slow (hjt log) KoZu Spyware, Adware, Viruses and HijackThis Logs 1 23-04-2006 04:42 AM
I can only use my computer in safe mode mugsi Windows XP Help 3 11-01-2006 08:14 PM
Computer Extremely slow on boot up lyn_78 General Hardware Issues 3 26-02-2005 08:29 PM
Please help with extremely slow computer... grodriguezjr Windows XP Help 3 07-12-2004 01:55 PM


All times are GMT +1. The time now is 12:27 AM.

Bottom Corner