Laptop running slow, spyware?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wackyjacky, Oct 8, 2005.

  1. wackyjacky

    wackyjacky Private E-2

    Hi,

    I posted this on another forum but no-one could help so putting it on here to see if anyone on here can help. Don't know if Spyware is the problem but please read and see if you can advise on the problem.

    My laptop is running really slow, particularly on the web, even though I have 2mb broadband. Most applications I try to open take up to 2 minutes to open and the mouse pointer appears to freeze. Not just the mouse but the laptop and any application running can freeze but when you move the mouse pointer it starts up again from where it left off. I.e it's like a pause button. This is the same whether or not I use the internal mouse or an external one.
    I've ran loads of antivirus and spyware including:-
    Lavasoft Adaware, Spyware Blaster, RegistryFix, PCBugDoctor, Avast Antivirus, Xoftspy, CC Cleaner, Spybot and AOLs own virus scan. I've also ran TrendMicro and Panda Software on-line virus scans. Only the odd small thing showed up which I've removed/fixed.
    I guess I may have too many processes running but don't know which ones I don't need or how to turn them off so they only run when needed.
    I've downloaded AIDA32 as recommended on this site but don't know what information to post. This is the system info for my pc

    OS Name Microsoft Windows XP Home Edition
    Version 5.1.2600 Service Pack 2 Build 2600
    OS Manufacturer Microsoft Corporation
    System Name DAVID_WILSON
    System Manufacturer MEDIONNB
    System Model FID2130
    System Type X86-based PC
    Processor x86 Family 15 Model 2 Stepping 9 GenuineIntel ~3200 Mhz
    Processor x86 Family 15 Model 2 Stepping 9 GenuineIntel ~3200 Mhz
    BIOS Version/Date Phoenix Technologies LTD 4.06, 23/02/2004
    SMBIOS Version 2.31
    Windows Directory C:\WINDOWS
    System Directory C:\WINDOWS\system32
    Boot Device \Device\HarddiskVolume1
    Locale United States
    Hardware Abstraction Layer Version = "5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)"
    User Name DAVID_WILSON\David
    Time Zone GMT Daylight Time
    Total Physical Memory 512.00 MB
    Available Physical Memory 48.47 MB
    Total Virtual Memory 2.00 GB
    Available Virtual Memory 1.96 GB
    Page File Space 1.38 GB
    Page File C:\pagefile.sys

    Hopefully someone on here can help, thanks in advance

    Dave
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please work thru our standard cleaning procedures below even if you have done them before. Make sure you check to see that you have the versions that are links indicate and make sure you have checked for detections/reference file updates. Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    .
     
  3. wackyjacky

    wackyjacky Private E-2

    Hi,

    I've followed all your instructions and the following things happened.

    Bitdefender = nothing untoward found
    RavAntivirus = nothing untoward found
    Trend Micro = nothing untoward found

    CC Cleaner = cleaned up a few files
    Ad-Aware = fixed 4 things found
    Spybot = couldn't update because of bad checksum then fixed something from New.New
    Microsoft Antispyware = removed Blazefinder and two others
    CWShredder = found nothing
    Kill2Me = found nothing

    All of these were run in Safe Mode.

    The pc is still really slow (although was quicker on Safe mode) so I've followed the HijackThis instructions and have posted the log (see attached).

    Thanks for you help so far and for the future, hopefully!!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have more than one antivirus application installed. You should only use one. Choose the one you prefer and uninstall the other.

    When you get checksum errors trying to get updates to Spybot, all you typically must do is change the download site source. Choose another from the pull down list.

    Personally I do not recommend using Spybot's Teatimer as it often can be a resource hog. Also it typically needs to be disabled to remove malware because it will block changes trying to be made by us.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    The only item in your log that I would have HJT fix is the below:

    O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab

    Other than that, perhaps your laptop is running slow because of all the items loading. Disabling Teatimer will help. And using only one antivirus application will help alot.

    Also since you have McAfee's Firewall installed, did you disable the firewall in Win XP SP2? If not, you need to!
     
  5. wackyjacky

    wackyjacky Private E-2

    Hi,

    Which two antivirus are installed? I thought I only had Avast installed, didn't realise there was another unless you mean the Windows one. I've uninstalled the Windows firewall, should I uninstall their antivirus too as I prefer the Avast one.
    I've done the other things you suggested and already seen an improvement, thanks very much.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have both Avast and McAfee installed! As I mentioned in my previous message you have McAfee's firewall too! If you uninstall McAfee, you will need to install another firewall. This may not be a bad choice though because McAfee is very resource hungry.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wait!!!! Perhaps you only have McAfee's Firewall installed and I just assumed you also had the antivirus installed. Is that what you did?

    This is part of McAfee's Internet Security Suite to protect agains worms, viruses and trojans and still may be a problem with resource hogging.
     
  8. wackyjacky

    wackyjacky Private E-2


    All I did was uninstall Microsofts firewall, nothing else. As far as I know McAfee is just a Firewall, not antivirus. I'm willing to do what you recommend?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well let's ignore it for now. Did you disable Teatimer?

    Do you use the old Windows Messenger :
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    Most people do not and it has been known as a source of popups.

    You may want to consider dumping the AOL Spyware stuff and keeping MS Antispyware. Have two full blown blockers running simultaneously could be part of the reason your PC is slow.
     
  10. wackyjacky

    wackyjacky Private E-2

    I've disabled Teatimer and don't use Messenger so will get HJT to fix this. I'll dump the AOL cos I like the look of the Microsoft spyware.
    Any other changes you can recommend?

    Thanks and Happy Birthday, I noticed it on the front page!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not need to load the below at startup either:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    With all these changes let me know if things seem to working any faster.

    Thanks for the BD wishes!
     
  12. wackyjacky

    wackyjacky Private E-2

    How do i stop things running on startup such as qttask.exe? I've done all the other changes and things are running faster.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just have HJT fix the below line:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
     
  14. wackyjacky

    wackyjacky Private E-2

    Thanks, I've done all those and its running better.

    If you think of other things I can stop I'd appreciate it but thanks for the help and guidance so far. I'll keep checking back in case you think of anything else to change.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's a matter of personal preference and what you use/need. Only you really know that. You can search for your processes on www.google.com and then make your decisions on some of the processes show in the lines below from your log:

    O4 - HKLM\..\Run: [Dimension4] C:\Program Files\D4\D4.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
     
  16. wackyjacky

    wackyjacky Private E-2

    For some reason my laptop has slowed right up again, particularly the internet, pages are taking 30 secs to load even though I have 2mb broadband. It was fine before and I haven't changed anything and i'm accessing the same sites. My connection via a router has a strong signal strength and the other pc in the house which runs from the same router is fine.
    What is going on with this laptop! argghh!!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well something must be different if it was fine before and slow now.

    Bring your laptop right near the wireless router and see if it works better.

    You could also try some of the Alternative Scans in the new READ ME FIRST. See step 8!
     
  18. wackyjacky

    wackyjacky Private E-2

    It's really weird, it went really slow for about 30 mins and when I looked at my internet connections there was one called Gateway which was connected. My wireless connection said connected as did 1394 connection! I re-booted and disabled the Gateway connection and everything seems fine again. Really can't understand this and why it had connected.
    So currently it's ok with 1394 connection connected and my wireless connection connected.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  20. wackyjacky

    wackyjacky Private E-2


    I'll maybe look at it over the next few days cos it's slowed right up again and i've had enough for one day! Thanks very much for all your help.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds