Can ya help me with my HijackThis List? :)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by eclayton, Jun 15, 2004.

  1. eclayton

    eclayton Sgt. Shorts-cough

    Here's my first ever Hijcack This Thread! Things are sluggish when I run IE, I have all the updates, all the patches, AVG, Ad-Aware, etc and it just isn't up to snuff. I have all the drives loaded, and still it seems to act sluggish. I just formatted and re-installed Windows XP yesterday, but I'm not happy with how it's running.

    Here 'tis...


    Logfile of HijackThis v1.97.7
    Scan saved at 2:52:33 PM, on 6/15/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\System32\vssvc.exe
    C:\WINDOWS\System32\wpabaln.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\System32\wpabaln.exe
    C:\Palm\HOTSYNC.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\Eric\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jpusa.net/
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
    O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Spam Bully for Outlook Express] "C:\Program Files\Axaware\Spam Bully 2 for OE\oespambully.exe" install
    O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38153.2688888889
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab


    Thanks for any help you can give me!!

    Eric
     
  2. Kodo

    Kodo SNATCHSQUATCH

    looks ok to me..

    can you explain which aspects of your experience are "slow"?
     
  3. cindysnoopy

    cindysnoopy Shotgun!

    Hey there Kodo, I'm answering for Eric...

    Well, when we close Outlook Express, it's really sluggish - like you wonder if you really hit the X or not, and our scrolling isn't right. It doesn't go smoothly up and down, it goes more like in a wave or something. Any ideas?
     
  4. Toucan

    Toucan Private E-2

    Hi guys. Just joined this is my first post.

    Okay, this issue was topic of discussion on another forum last week. It seems that internet browsing has been very slow for almost 3 weeks. Some one from the Northwest, I think was experiencing the same and then someone else in Florida. And we down here have also had the same problem.

    Is your experience only with IE or with other programs while not on the internet?
     
  5. cindysnoopy

    cindysnoopy Shotgun!

    We had a corrupted Windows file and had to format and reload yesterday. Our problems have only been since then. We've got a DSL connection and haven't noticed browsing being slower at all. We do use IE, but it seems like the sluggishness isn't just while we're on the internet.

    I've wondered if there's a preference that we should change with the scrolling. Can't seem to find it though...
     
  6. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    If you just re-installed it yesterday, give XP a week or so to optimize its self, XP had the routines built in that the bootvis tool just speeds up minorly, it just needs a week or so to move stuff around.

    you may want to disable a few things, Indexing Service ( slowdown and pain in the butt for starting at anytime it wants ), some of the Nvidia startups are not really needed either eg.

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit


    or for that matter if you dont need messenger all the time or use another service then this one can go

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    less things in the system tray at startup help.


    plus have you done a defrag... with all that installing of XP and soft maybe worth defragging the drive....

    then as you have no doubt popped over to BlackVipers site and turned off none essential services.
     
  7. cindysnoopy

    cindysnoopy Shotgun!

    Hey there Star, my friend! :)

    Nothing funny going on in the processes.

    As far as spambully, I've got the most recent one running, and we were having the sluggishness before I installed it, so I don't think that's it.

    Really, I think it's something to do with the scrolling. That's what's bugging Eric the most. I don't think there's really anything else wrong besides that and OE closing a little slowly.
     
  8. lostkiwi

    lostkiwi MajorGeek

    Hi Cindy, How do you know you had a corrupted windows file? I just did a post in hardware about my cd burner that I just installed, I am blaming it for the same thing, slowness! I use Opera and dsl and the pages are taking forever to load, to where you see the tags where the graphics should be. I have win2000 professional though.
     
  9. Toucan

    Toucan Private E-2

    The full initialization process takes several boots. If you do not use windows messenger you can remove it it permanently through the Control Panel\admin. tools\services.

    I only just installed Opera (latest ver) a few days ago and pages take long to open. (Note my first post.)

    Am at work, later today once i am back in my lab I will look more closely at this issue and provide better suggestions.

    Hang in there.
     
  10. eclayton

    eclayton Sgt. Shorts-cough

    Yep, did defrag yesterday, just checked startup, and turned off those things that were not needed...I had them turned off earlier, don't know why they were there again. :confused:
    Indexing servise was already off, and Messenger is off now. Still, the scrolling is just awful. A wave effect is the best way to describe it. Before we re-installed, you could scroll smoothly, and quickly. Now, if you use the scroll wheel on the mouse, it shifts very slowly, in a wavey sort of manner, and it's also slow if you click on the arrow on the scroll bar. I had wondered if it was the drivers for my Nvidia card...they seemed to have a hard time installing, I had to un-install and re-install several times. In fact, I just checked it, and it now says "This device cannot turn on, (Code 10). I think the problem is in here somewhere....

    I have an Nvidia Geforce2 MX 400. It has a nice yellow exclamation point on it, which indicates the drivers aren't right, is that correct? Well, I go to update drivers, and it says "Cannot continue the hardware update wizard, the wizard could not find a better match for your hardware than the software you have installed." Maybe I have a bad driver, I'll go look for a better one somewhere....

    Thanks again for the help guys.

    Eric
     
  11. eclayton

    eclayton Sgt. Shorts-cough

    ONe more thing, Outlook Express is also very delayed in it's responses, for example, when I delete an email, it will hesitate before it deletes it, and I'll wonder if I actually hit the X.

    Also, I just unistalled the drivers for the video card, and when I rebooted, it says it found new hardware, so I go to install the hardware automaticaly (recommended) and it says it is installing the plug and play monitor....what's that all about? I haven't unplugged the monitor or added any hardware at all.

    Once I added the "new Hardware" for the plug and play monitor, when I go to Device manager, it tells me the display adapters (the video card) are fine.

    :confused:
     
  12. Toucan

    Toucan Private E-2

    Okay cannot make anything out of your list.
    Look in properties of your vid card make a list of all driver files (nvidia). Uninstall the drivers for you vid card. reboot, when the the plug n play window pops up hold it there. Go to the folders where the driver files were and delete anyone that is still there. Then go on to the clean installation of you drivers.
     
  13. cindysnoopy

    cindysnoopy Shotgun!

    The computer was working fine when we went to bed. Woke up the next morning, and noticed that the screen was frozen. I tried restarting and got:

    Windows could not start because the following file is missing or corrupt:
    \Windows\System32\Config\System. You can attempt to repair this file by starting Windows setup using the original Setup CD-ROM. Select 'R' at the first screen to start repair.

    Not sure what happened, but we couldn't get it to repair. Called our nice tech support guy (Ken) at Gentech and he tried walking me through a couple of things. Told me that it was not repairable and that we'd have to reload Windows. We'd been talking about doing that anyway - Eric wasn't crazy about how I'd set things up.


    I think that Halo might have it right that XP just needed a little time to optimize itself, because all of a sudden, the scrolling is back to normal! Eric had tried a couple of things that he suggested, but there wasn't an immediate change or anything. Just noticed about an hour afterwards that it was scrolling like normal. OE is sometimes a little sluggish when closing, but not every time. Anyway, it's good enough that we're done complaining about it. Thanks everyone and especially Thanks Halo! :D
     
  14. alanc

    alanc MajorGeek

    Just an FYI, that's (was) a corrupt registry hive. Doesn't happen very often, but it does happen.
     
  15. Kodo

    Kodo SNATCHSQUATCH

    Sluggish PC.. makes me think CPU cycles.
    Dead hive on reboot.. makes me think along with the above:

    In the frame of mind for software related issues: VIRUS
    In the frame of mind for hardware related issues: MEMORY
     
  16. cindysnoopy

    cindysnoopy Shotgun!

    Alanc and Kodo, thanks for the info. I'm thinking it was probably a virus that got through somehow. I think we're usually on top of our updates and don't click on unknown emails, but I know that there have been some nasty trojans going around our network. One family was having trouble and our friend John checked it out for them. They didn't have any AV running and they had over 200 viruses!
     
  17. lostkiwi

    lostkiwi MajorGeek

    Thanks Cindy,
    that gives me somewhere to start. I hate having to reinstall anything, but with my luck.... oh well
    <sigh>
    Thanks
     
  18. eclayton

    eclayton Sgt. Shorts-cough

    Okay, it's doing it again. :mad: I checked Device Manager, and once again, the video card has the yellow exclamation point by it, and it says "this device cannot start (code 10).


    Should I head over to hardware and start a thread there?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds