Unsolved

This post is more than 5 years old

17 Posts

379

October 1st, 2004 00:00

Computer running slowly ... can anyone help?

Hello,

My computer is running slowly, and has issues with freezing frequently.  I have posted my hijackthis log below.  I would greatly appreciate any help you guys may have.

Logfile of HijackThis v1.98.2
Scan saved at 9:28:10 PM, on 9/30/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSDTCW.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\WINDOWS\OPTIONS\CABS\LOGITECH\HP_FINDER.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\TPPALDR.EXE
C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
C:\WINDOWS\TEMP\X3.EXE
C:\WINDOWS\SYSTEM32\PCS\PCSVC.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\TPPSTRAY.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\HPRTRY09.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\PROGRAM FILES\BACKWEB\BACKWEB\PROGRAM\BACKWEB.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\DELAYRUN.EXE
C:\WINDOWS\OPTIONS\CABS\LOGITECH\HP_FINDER.EXE
C:\WINDOWS\TEMP\X3.EXE
C:\WINDOWS\SYSTEM\LZEI32.EXE
C:\WINDOWS\SYSTEM\BCNPVKR.EXE
C:\WINDOWS\SYSTEM\YATIOY8.EXE
C:\WINDOWS\SYSTEM\RYEO82.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\GLARKXAZ\HIJACKTHIS[1].EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O2 - BHO: NavErrRedir Class - {0199DF25-9820-4bd5-9FEE-5A765AB4371E} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Delay] C:\WINDOWS\delayrun.exe
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [mgavrtclexe] C:\WINDOWS\MCBin\AV\Rt\mgavrtcl.exe
O4 - HKLM\..\Run: [HPLogiFinder] \WINDOWS\OPTIONS\CABS\LOGITECH\HP_FINDER.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [X3] C:\WINDOWS\TEMP\X3.EXE
O4 - HKLM\..\Run: [Bakra] C:\WINDOWS\SYSTEM\IEHost.exe
O4 - HKLM\..\Run: [4THQMFQ5XMTXYD] C:\WINDOWS\SYSTEM\Bnqw5T.exe
O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pcsvc.exe
O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [MSDTC] msdtcw -start
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Uate] C:\WINDOWS\Application Data\oocs.exe
O4 - HKCU\..\Run: [ClockSync] C:\PROGRA~1\CLOCKS~1\Sync.exe /q
O4 - HKCU\..\Run: [b9v7RWbnh] LZEI32.EXE
O4 - HKCU\..\Run: [Rxyb] C:\WINDOWS\SYSTEM\bcnpvkr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msmc] C:\WINDOWS\SYSTEM\msmc.exe
O4 - Startup: HP 2000C Taskbar Icon.lnk = C:\WINDOWS\SYSTEM\HPRTRY09.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\SYSTEM\ms.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\SYSTEM\ms.exe
O14 - IERESET.INF: START_PAGE_URL=http://hp.my.yahoo.com

 

2 Intern

 • 

860 Posts

October 1st, 2004 16:00

If the above fixes fail you would need to run hijackthis
Here are some sites where you can receive help analyzing your HijackThis log from trained experts. Note that the sites require registration before you will be able to post.
 Include your Hijackthis log in the post while explaining your problem at the same time.
http://radiosplace.com/
http://tomcoyote.com/hjt/#copyandpaste


Online Tools Resources
You can find almost everything here :) http://forums.subratam.org/index.php?showtopic=43
http://computercops.biz/downloads-cat-14.html
http://encyclopedia.thefreedictionary.com/Online%20Tools%20Resources
http://www.geekstogo.com/forum/index.php?showtopic=38
http://www.windowsbbs.com/showthread.php?t=31695
http://aumha.org/secure.htm

Kill Spyware Forums
http://forums.subratam.org/index.php?showforum=7
tools needed to get help http://forums.subratam.org/index.php?showtopic=7
Forum Led by: Forum Moderators,subratam,baskar1234(DELL REGULAR),efwis,Metallica,psyne, SpyDie, normmork, Admin,chrisRLG(DELL REGULAR)

http://www.bleepingcomputer.com/forums/forum22.html
Our Tutorials
http://www.bleepingcomputer.com/forums/forum6.html
How to submit a Hijackthis Log
http://www.bleepingcomputer.com/forums/topict956.html
HijackThis Tutorial - How to use HijackThis to remove Browser Hijackers & Spyware
http://www.bleepingcomputer.com/forums/tutorial42.html

Forum Led by: Moderators, Global Moderator, groovicus,Grinler(DELL REGULAR),harrywaldron,Papakid,


http://forums.net-integration.net/index.php?showforum=32
Forum Led by: Global Moderator, Administrators, Technical Experts, Technical Assistant, Team Spybot S&D, Technical Guide
TonyKlein,Eagle1,Galadriel,tashi,Archon_Wing,
Spybot Search & Destroy 1.X OFFICIAL FORUM
http://forums.net-integration.net/index.php?showforum=28

lavasoftsupport
http://www.lavasoftsupport.com/index.php?showforum=44
Forum Led by: SpyDie, Lavasoft Admins, Moderators
Newbies
http://www.lavasoftsupport.com/index.php?showforum=34


http://forum.gladiator-antivirus.com/index.php?showforum=170
Forum Led by: CalamityJane, LoPhatPhuud, FatsGordon,Hunter,TheSentinel,
Guidelines for Posting in This Forum, READ THIS FIRST PLEASE
http://forum.gladiator-antivirus.com/index.php?showtopic=10517
How to Stop Hijackers & Spyware Infections, And other malware too!
http://forum.gladiator-antivirus.com/index.php?showtopic=9857

For immediate help or advice on hijackthis for further solutions before proceeding you could also visit the online experts on the chat
There may or may not be experts in the chat rooms depending on the time you log into those chat rooms

http://chat.skads.org/applet/
http://chat.subratam.org/
http://tech-touch.net/temp/indexold.php
http://www1.spywareinfo.com/chat/#chat
You will get a security warning click yes if you get it. IF you cant log in Press F5 on your keyboard to allow the page to refresh then try and connect also click on joine and in the name type #killspyware
http://www.net-integration.net/chat1.html

No Events found!

Top