pc gone like a snail !!!! can anyone help?

Discussion in 'Malware Help (A Specialist Will Reply)' started by lord lucan, Jul 12, 2005.

  1. lord lucan

    lord lucan Private First Class

    hi my friend has recomended this site , my pc is running very slow all of a sudden , ive done the basics as required in your thread i have norton virus, spyblaster, adaware se , spyblaster search and destroy , my pc uses xp home.
    ive down loaded the hijack this log attatched here

    thanks for your time
     
  2. lord lucan

    lord lucan Private First Class

    sorry here
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post HijackThis logs unless they are requested.
    Your log does not show any signs of having run the online scanners from the READ ME FIRST. Did you skip them? Did you skip any other steps?

    You should not be running more than one antivirus application. You have both AVG and Norton/Symantec installed. Pick the one you prefer and uninstall the other. If you are having a problem with your PC being slow, uninstalling Norton would be the best choice.


    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to System Startup Service or SvcProc Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    SvcProc

    You may be told to reboot at this point. Do not reboot just exit HijackThis and we will be restarting it with different options in a moment.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: Shell=
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe (file missing) <-- this may be gone already due to above steps


    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete (if found):
    C:\WINDOWS\svcproc.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.


    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  4. lord lucan

    lord lucan Private First Class

    done all that ,still seems a bit slow to be honest ,i get a box come up when i booted into normal at the end "runner error invalid backweb application id 137903" ?
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Backweb stuff is there because you installed all the crap from HP with their printer. Most people treat backweb as mild malware. You can just have HJT kill the below process:

    C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe

    And then have HJT fix the below line in your log:


    O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe

    If you want to speed things up you have to look at all the unnecessary items that you are loading and decide whether you really require them or not (but they are not malware. They are just things you don't need ware!). Some examples:

    4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe
    O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe
    O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe <--- many people do not use this
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE <-- you probably do not need this
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

    Again these are not malware. You are the one that must decide whether you need them or not. Some of these may be useful to you and some may not be.

    Also, do you use Windows Messenger? It's running: C:\Program Files\Messenger\msmsgs.exe
     
  6. lord lucan

    lord lucan Private First Class

    i do use messenger i downloaded the new version 7 is msn messenger the same as microsoft messenger?
    so if i get rid of that with hjt the backweb thing i mean will it stop my printer working?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    MSN Messenger and Windows Messenger are two different programs? Most people never use the built in Windows Messenger and it is quite often a cause of popups.

    Removing the Backweb process will not affect your printer. Read the below:
    ( http://www.liutilities.com/products/wintaskspro/processlibrary/backweb-137903/
     
  8. lord lucan

    lord lucan Private First Class

    ok thanks alot ,just out of interest the other things you suggested i could remove, i havent really got a clue what they are or if i use them ,can you expand at all?

    cheers again
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Read about them a little with the info I give below. And you decide if you want them or not. You can also use a program like Startup CPL to stop them from loading at startup temporarily to see if they affect anything you need. Also this will let you know if they are slowing your PC down. If you find out you need the process to run, you can then re-enable them.

    c:\windows\system\hpsysdrv.exe - http://www.liutilities.com/products/wintaskspro/processlibrary/hpsysdrv/

    C:\WINDOWS\System32\hkcmd.exe - http://www.liutilities.com/products/wintaskspro/processlibrary/hkcmd/

    C:\Windows\system32\HpSrvUI.exe - No one is really sure what this HP Printer service does. It could be needed.

    c:\hp\drivers\scanners\scannerfb.exe - related to HP scanner. Not sure what it's purpose is.

    c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe - http://www.liutilities.com/products/wintaskspro/processlibrary/hpqcmon/

    c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe - http://www.liutilities.com/products/wintaskspro/processlibrary/hpgs2wnd/


    C:\HP\KBD\KBD.EXE - http://www.liutilities.com/products/wintaskspro/processlibrary/kbd/

    also see this: http://support.microsoft.com/default.aspx?scid=kb;en-us;812337


    C:\Windows\Creator\Remind_XP.exe - http://www.liutilities.com/products/wintaskspro/processlibrary/Remind_XP/

    ALCXMNTR.EXE - http://castlecops.com/s180-Alcxmntr_exe.html
     
  10. lord lucan

    lord lucan Private First Class

    thanks for help ,ive had a quick fiddle nothing seems to have improved greatly , its at it slowest when i say , open up control panel from desktop or try to move about the pc ,thinks like mozilla dont open up quickly , i have to wait to the point where i wonder if i double clicked properly , it takes an age to do anything ,not so much internet.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is the speed and processor type in your PC and how much memory do you have installed?

    When is the last time you did a defrag?
     
  12. lord lucan

    lord lucan Private First Class

    defrag 2 days ago ( do it daily usually ) 2.3 intel processor , 512 mb , 40gb hd only 25% full
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does it seem slow in safe mode too?

    If you do not have a connection (physically unplug the cable) to the internet in normal boot mode and all browser windows are closed, does it also seem slow?
     
  14. lord lucan

    lord lucan Private First Class

    seems bit better in safe mode, it seems smae unplugged in normal as you asked.

    also how do i stop windows updates ?? i run sp2 i turn it off but it constantly says turn it on etc really annoying these updates slow things even more , is there a way of stopping them ,ive diabled them but it just keeps annoying me
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you right click on MyComputer and select Automatic Updates and then select Turn off Automatic Updates?

    Take a look at your HijackThis log from a safe mode boot and compare it to a normal mode boot. See what additional processes are running in normal boot mode. And then try killing those processes when in normal boot mode. Does it help the speed problem?
     
  16. lord lucan

    lord lucan Private First Class

    yes i disabled it like that , it still pesters me all the time though
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many people run into problems stopping this. It is really a discussion that belongs in the Software Forum.

    Another way to stop it is for you to run services.msc and disable the Automatic Updates service. You will have to re-enable again yourself if you ever want them back on again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds