Computer Hope

Microsoft => Microsoft Windows => Windows XP => Topic started by: squirrel on July 26, 2006, 02:11:05 PM

Title: PC running slow, malware scans show nothing
Post by: squirrel on July 26, 2006, 02:11:05 PM
Windows XP Dell GX240 tower machine is running slow.  Programs do not respond as well or as fast.  I am having to end-task programs more often.  Really bad since colleague accidentally tripped circuit and power to machine was cut while machine was on.  It ran fine before I put SpyBot and AdAware on it.  Could they be killing the PC?

Please help, it is company computer.

Additional info:  I have run every scan (Virusscan, spybot, adaware) I could think of, as well as defragmenting the HD and checking the disk for errors.  HD properties says the disk is only half full.  

Did the power thing do something?  Are my anti-malware programs infected with viruses?  Do I need to reimage PC and start over? Is the computer FUBAR?

Please help, it is company computer.[highlight][/highlight]
Title: Re: PC running slow, malware scans show nothing
Post by: ale52 on July 26, 2006, 03:10:43 PM
Try running chkdsk.  It may just be that the tripped-power damaged the hard drive.

Alan <><  ;)
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 26, 2006, 03:11:45 PM
Already tried. showed nothing. :-? :-? :-? :-? :-?

HELP!!!
Title: Re: PC running slow, malware scans show nothing
Post by: Fed on July 26, 2006, 03:13:55 PM
Online Virus Scan and Spyware Scan
http://www.pandasoftware.com/products/activescan.htm

Online Malware Scan
http://www.ewido.net/en/

If Panda gives you a report, save it & come back here.
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 26, 2006, 03:15:14 PM
Except that my browser programs are some of the ones that keep freezing and i have to end-task them.
Title: Re: PC running slow, malware scans show nothing
Post by: Fed on July 26, 2006, 03:22:53 PM
Try safe mode + networking.
I noticed you said it was a company computer, are you allowed to fix it or should you be contacting your IT people?
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 26, 2006, 03:25:44 PM
IT people? They're all otherwise occupied. I'm all there is.  What is safemode+networking? I know about safemode, but "+networking?" How to boot XP machine in safe mode?
Title: Re: PC running slow, malware scans show nothing
Post by: GX1_Man on July 26, 2006, 03:44:52 PM
Try Task Manager (Ctl+Alt+Del) to see what processes are running that could be using your processor power.

If no joy there, you can run Hijack This and post a log file here for our resident experts to analyze. It will take several posts to get it all and the whole thing must be here.

http://www.majorgeeks.com/download3155.html
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 26, 2006, 03:48:00 PM
Quote
Try Task Manager (Ctl+Alt+Del) to see what processes are running that could be using your processor power.

If no joy there, you can run Hijack This and post a log file here for our resident experts to analyze. It will take several posts to get it all and the whole thing must be here.

http://www.majorgeeks.com/download3155.html

Well, what processes should I be looking for?  One person at work told me to just wipe the stupid thing and start over.

Also, as I said above, the web browsers are among the programs that are affected by the problem.  I don't trust them.
Title: Re: PC running slow, malware scans show nothing
Post by: johnchain on July 26, 2006, 04:17:45 PM
Safe mode+networking....

When computer boots up, right when it shows the computer comapnies name (before the Windows XP loading screen) start tapping the F8 key.

You will arrive at a menu that will have optins including
"start windows in safe mode with networking"

Try out all your programs, if the same performance continues, you have a hardware issue. Otherwise, it's some program on the computer.
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 26, 2006, 04:19:55 PM
okay, i got into safe mode with networking. . .attempting suggestion. . .
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 26, 2006, 04:25:30 PM
i foud the panda thing.  scanning now. . .
Title: Re: PC running slow, malware scans show nothing
Post by: GX1_Man on July 26, 2006, 04:37:04 PM
Quote
 One person at work told me to just wipe the stupid thing and start over.

A good format and reinstall solves all Windows problems, for a while. Do you have a real Windows CD or what?
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 26, 2006, 04:42:06 PM
ran faster in safe mode. . .running panda scan now.
Title: Re: PC running slow, malware scans show nothing
Post by: Fed on July 26, 2006, 04:58:19 PM
Don't forget Ewido when Panda is finished. ;)
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 26, 2006, 05:11:51 PM
Okay. . .

Panda found some stuff.

9 spyware things were found.

What now?
Title: Re: PC running slow, malware scans show nothing
Post by: Fed on July 26, 2006, 05:21:07 PM
Quote
If Panda gives you a report, save it & come back here.
If Panda did not correct the 9 spyware things then it would have made a report for you to save.
Copy & paste that report in here.
Run Ewido too.
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 06:50:43 AM
It listed all the things as cookies.  I understand from a co-worker that deleting all the cookies can have a negative effect?

Running ewido now. . .
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 08:23:23 AM
Okay, guys. . .

Panda found only cookies.  Ewido found some adware stuff and I removed it.  Adaware keeps finding something called dataminer.
Title: Re: PC running slow, malware scans show nothing
Post by: panboy on July 27, 2006, 08:36:12 AM
Data Miners are a type of Adware, they Send your info like websites you visit and personal Info , to company to do market Research, there annoying little Pricks if you ask me , but having a few like 3 or 4 shouldn't Kill the Computer,

maybe you could Try CCleaner as Well

And you Still have not posted your "Hijack this" log file, it's likely that it could help
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 08:37:35 AM
PC does not have HiJack this.
Title: Re: PC running slow, malware scans show nothing
Post by: panboy on July 27, 2006, 08:39:20 AM
you can get it here

http://www.majorgeeks.com/download3155.html

as GX1_man Posted
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 08:40:49 AM
okay, let me log onto computer hope on the other PC. be right back.
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 08:49:23 AM
here is HijackThis log.

Logfile of HijackThis v1.99.1
Scan saved at 10:47:16 AM, on 7/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Viewpoint\Viewpoint Toolbar V35\FotomatDeviceConnect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\taskmgr.exeC:\DOCUME~1\ADMINI~1.MCP\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mcps.k12.md.us/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeO4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [ViewpointPhotosDeviceConnect] C:\Program Files\Viewpoint\Viewpoint Toolbar V35\FotomatDeviceConnect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E822D072-1DF4-4EB3-8498-8756684C7E46}: NameServer = 205.222.5.22,205.222.5.23
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 08:49:52 AM
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NAV Alert - Symantec Corporation - C:\PROGRA~1\Navnt\alertsvc.exe
O23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
O23 - Service: Norton Program Scheduler - Symantec Corporation - C:\PROGRA~1\Navnt\npssvc.exe

Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 08:53:38 AM
oh, and a process in my task manager called svchost.exe is listed several times for the same user (system) and only one of them is using up a lot of memory.

Title: Re: PC running slow, malware scans show nothing
Post by: panboy on July 27, 2006, 09:00:43 AM
Im not an Expet in hijack this logs, but i noticed you seem to have 3 Anti virus Scaners Running.
Norton, McAffee, And AVG

Its not a Good idea to Run so many, and can Cause alot of Slow down.

O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

O23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 09:03:53 AM
norton's won't let me uninstall it!!!!  
Title: Re: PC running slow, malware scans show nothing
Post by: panboy on July 27, 2006, 09:11:04 AM
And Now Can you UnderStand Why people dislike it so, there is a detailed Help file on how to dispose of it. hmm GX1_man keeps posting links to it, ill go find one
Title: Re: PC running slow, malware scans show nothing
Post by: panboy on July 27, 2006, 09:25:08 AM
Try Ask Dave, i see this around quite Often , and people have giving it a pretty Positive response

http://www.askdavetaylor.com/how_can_i_fully_remove_norton_antivirus_from_my_system.html
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 09:30:17 AM
I get an error message that says the log file is not vcalid or the data has been corrupted. uninstallation will not continue.
Title: Re: PC running slow, malware scans show nothing
Post by: panboy on July 27, 2006, 09:34:45 AM
Is that The Error the Uninstaller is Giving you, if so i think you should try removing it trough the Registry, the Dave Taylor site Gives you the Info you need for that i believe
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 09:40:12 AM
problem is that add/remove programs (like it says on the website) gives the error message.  anything else in my hijack this log that needs my attention?
Title: Re: PC running slow, malware scans show nothing
Post by: panboy on July 27, 2006, 01:33:01 PM
Have a look here they went trought the Norton Process just last week ^.^

http://www.computerhope.com/cgi-bin/yabb/YaBB.cgi?num=1152742462/0

Sorry, im not that Good with Hijack This logs, i think DL65 is ok

Beg him to look :)
Title: Re: PC running slow, malware scans show nothing
Post by: Fed on July 27, 2006, 02:57:44 PM
Norton will plague you forever, do a clean install of your OS plus AVG, Spybot with resident teatimer & a firewall.
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 02:58:53 PM
anything else in my hijack this log? :-? :-? :-? :-? :-/
Title: Re: PC running slow, malware scans show nothing
Post by: Fed on July 27, 2006, 03:02:40 PM
Get rid of Norton and other antivirus programs until you are left with AVG only for antivirus.
Have one antispyware program.
Install a firewall, Sygate is good.
I'd remove all the viewpoint junk too.
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 03:03:00 PM
Quote
Try Task Manager (Ctl+Alt+Del) to see what processes are running that could be using your processor power.


What processes should i be looking for?

What is svchost.exe and why does the amount of memory it is using keep increasing?
Title: Re: PC running slow, malware scans show nothing
Post by: GX1_Man on July 27, 2006, 03:14:10 PM
Here you go:

http://www.google.com/search?hl=en&q=svchost.exe+


<---------
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 03:17:24 PM
but the one svchost.exe keeps on taking up more and more memory--but no processor time.
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 03:47:21 PM
okay. I deleted the viewpoint stuff and the norton stuff that hijack this found.  computer running better, but anything else i should do? how to keep viewpoint from reinstalling itself?  why does the amt of memory svchost.exe is using keep increasing?  and what other processes should i look for?
Title: Re: PC running slow, malware scans show nothing
Post by: GX1_Man on July 27, 2006, 04:13:30 PM
Have a read:

http://www.2-spyware.com/remove-viewpoint-media-player.html

and then here:

http://www.computerhope.com/cgi-bin/yabb/YaBB.cgi?num=1149948530


Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 04:24:11 PM
Quote
 why does the amt of memory svchost.exe is using keep increasing?  and what other processes should i look for?

I have still not received an answer to these two questions? :'( :'( :'( :'( :-/ :-?
Title: Re: PC running slow, malware scans show nothing
Post by: GX1_Man on July 27, 2006, 04:32:03 PM
And what did your reading and Google searches show you so far?

There were 3,290,000 hits for svchost.exe !  :o :o :o :o
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 27, 2006, 04:34:00 PM
google just showed me what the svchost.exe was. it didn't tell me why it is eating the memory.

It isn't eating cpu time, just memory.  and i saw nothing about processes to be alert for.

Title: Re: PC running slow, malware scans show nothing
Post by: dl65 on July 27, 2006, 05:06:13 PM
squirrel......  I just got back , how about posting a new hijackthis logfile .........as the old one has now changed .......


dl65  ::)
Title: Re: PC running slow, malware scans show nothing
Post by: Neil on July 28, 2006, 10:02:59 AM
svchost.exe is normal to appear several times. My largest one takes up 21,640kb. Unless it is more than that, not a problem.

It sounds like the best thing to do is to format the harddrive. This will lose all data on the harddrive, so make sure you back it up on CD or other computer. You'll need a legal Windows XP disk (or whatever OS you are using) and the drivers disk which you should have been given with your computer, but you might be able to download these. Formatting can be hard because you'll lose the data, but it will have 95% chance of fixing this problem. Because everything goes, including the bad stuff. We can then help you install Windows the "proper" way to minimize the risk of this happening again. (But if this is your only Interent computer, let us give you the instructions first of course!)

But if you want to keep on trying for the moment to fix it, on the task manager processes list list for us all the processes which use lots of memory, or anything you think looks suspicious (or the whole list if you have time). We can then see if it has anything suspect in it.

Have you ran checkdisk and defragmented the drive? I haven't read all of this thread.
Title: Re: PC running slow, malware scans show nothing
Post by: panboy on July 28, 2006, 10:27:40 AM
Quote
Have you ran checkdisk and defragmented the drive? I haven't read all of this thread.

You really Should Read the Entire Tread First, if you had you'd know Squirrel does not want to Format and Has Run scan Disk and Defrag.

And the computer is not So craped out that a Format is Necessary, its only got a Few bug's they just seem to big of the Big slow Verity
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 28, 2006, 11:26:56 AM
running much better since i deleted viewpoint. going to run hijack this, be right back.
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 28, 2006, 11:29:49 AM
here it is. . .if there's anything else i need to delete?  BTW, managed to erase norton's completely ;D

Logfile of HijackThis v1.99.1
Scan saved at 1:27:47 PM, on 7/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Adobe\Acrobat 6.0\Acrobat\Acrobat.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mcps.k12.md.us/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 28, 2006, 11:30:14 AM
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E822D072-1DF4-4EB3-8498-8756684C7E46}: NameServer = 205.222.5.22,205.222.5.23
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe

Title: Re: PC running slow, malware scans show nothing
Post by: dl65 on July 28, 2006, 01:19:24 PM
Hi Squirel.......  Ok , heres what I see.........
You arent running any firewall , which is ok ........ and not causing any issue ......   but , I'm seeing referance to 2 differant AV scanners running ...AVG  and some active virus scanner from McAfee ........ Really you only be running one ...... Anti virus application ........... it's ok to have a second one installed , but it shouldnt be active .......

Now on to the log file .........

I would mark for removal , the following :
  
O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)

now then please check these items and only leave them if you know what they are and trust them ..........

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} -   [highlight]appears to be a active X item ...... if you dont know and trust it remove it .[/highlight]

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -       [highlight]Same comment as above [/highlight]

O17 - HKLM\System\CCS\Services\Tcpip\..\{E822D072-1DF4-4EB3-8498-8756684C7E46}: NameServer = 205.222.5.22,205.222.5.23      [highlight]Is this address part of your ISP or do you know it to be safe ?[/highlight]

that IP address appears to be ........ part of ...... Montgomery County Public Schools     [highlight]Does that sound right to you ? [/highlight]

let us know about those questionable entries ..........

dl65  ::)
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 28, 2006, 01:34:56 PM
Quote
Hi Squirel.......  Ok , heres what I see.........
You arent running any firewall , which is ok ........ and not causing any issue ......   but , I'm seeing referance to 2 differant AV scanners running ...AVG  and some active virus scanner from McAfee ........ Really you only be running one ...... Anti virus application ........... it's ok to have a second one installed , but it shouldnt be active .......

Now on to the log file .........

I would mark for removal , the following :
  
O2 - BHO: (no name) - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - (no file)

okay. . .

Quote
now then please check these items and only leave them if you know what they are and trust them ..........

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} -   [highlight]appears to be a active X item ...... if you dont know and trust it remove it .[/highlight]

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -       [highlight]Same comment as above [/highlight]

is active x bad? how do i know company doesn't need it there?

Quote
O17 - HKLM\System\CCS\Services\Tcpip\..\{E822D072-1DF4-4EB3-8498-8756684C7E46}: NameServer = 205.222.5.22,205.222.5.23      [highlight]Is this address part of your ISP or do you know it to be safe ?[/highlight]

that IP address appears to be ........ part of ...... Montgomery County Public Schools     [highlight]Does that sound right to you ? [/highlight]
Yes. that's the company.--HEY!!! HOW DID YOU FIND THAT OUT? DOES IT SAY THAT, TOO????? :-?
Title: Re: PC running slow, malware scans show nothing
Post by: dl65 on July 28, 2006, 01:54:27 PM
 squirrel.......  I just did a little research on that ip address nd there is a whack of info available , but thats all I showed ........
so this is a work machine then ...and not your personel home machine then ?

Active X can be a problem , but in your case it may be ok .

dl65  ::)
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 28, 2006, 01:55:27 PM
yeah. earlier in the thread i think i mentioned that.  ::) 8-)
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 28, 2006, 02:09:56 PM
here is yet another hijackthis log file. . .if ya need it. :)

Logfile of HijackThis v1.99.1
Scan saved at 4:07:52 PM, on 7/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Adobe\Acrobat 6.0\Acrobat\Acrobat.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mcps.k12.md.us/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 28, 2006, 02:10:15 PM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E822D072-1DF4-4EB3-8498-8756684C7E46}: NameServer = 205.222.5.22,205.222.5.23
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe

Title: Re: PC running slow, malware scans show nothing
Post by: dl65 on July 28, 2006, 02:47:04 PM
 squirrel........ Your hijackthis logfile looks ok ........ except , I still referances to more than 1 av ........

How is the machine running now ?     The lack of co-operation between the differant AV scanners may be causing some lag ....... ( but only you would know that)    
The only other thing I can suggest would be a clean install , which you dont want to do .

dl65  ::)
Title: Re: PC running slow, malware scans show nothing
Post by: squirrel on July 28, 2006, 02:48:06 PM
running much much much much much much mucxh much much better!!!!!!  :) :) :) :) :) ;D ;D ;D 8-) ;D ;D ;D 8-) 8-) 8-) 8-) 8-) 8-) ;D ;D ;D ;D

[highlight]THANX[/highlight]
Title: Re: PC running slow, malware scans show nothing
Post by: dl65 on July 28, 2006, 04:14:15 PM
The issue appears to have been resolved  
[size=16] this topic is closed [/size]


dl65  ::)