Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Running slow  (Read 21700 times)

0 Members and 1 Guest are viewing this topic.

keith67

    Topic Starter


    Rookie

    Running slow
    « on: January 03, 2008, 11:26:52 AM »
    Hi i came across this forum doing a search and hopefully someone can help me out with a problem
    im running windows XP and everything was fine till the other day, my problem is when im closing a window it doesnt close straight away it starts to close from the top and slides downwards real slowly....has anyone any idea's what is causing this action ? Thanks keith

    soybean



      Genius
    • The first soybean ever to learn the computer.
    • Thanked: 469
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 10
    Re: Running slow
    « Reply #1 on: January 03, 2008, 11:31:31 AM »
    When your computer is behaving this way, open Task Manager, via Ctrl/Alt/Del and see what it shows for CPU Usage at the bottom of the panel for Processes. 

    keith67

      Topic Starter


      Rookie

      Re: Running slow
      « Reply #2 on: January 03, 2008, 11:40:42 AM »
      Hi the cpu usage ranges from 5% - 15% and there is 52 processes, some of my programmes i open, open up real slow, ive cleared my cookies and temp files to try and cure it but with no success.

      soybean



        Genius
      • The first soybean ever to learn the computer.
      • Thanked: 469
      • Computer: Specs
      • Experience: Experienced
      • OS: Windows 10
      Re: Running slow
      « Reply #3 on: January 03, 2008, 12:04:31 PM »
      Quote
      ... everything was fine till the other day ...
      What changed?  Did you install or uninstall any software or hardware?  Do you have a restore point in System Restore, prior to when this problem started, that you could go back to?
      « Last Edit: January 03, 2008, 12:33:20 PM by soybean »

      keith67

        Topic Starter


        Rookie

        Re: Running slow
        « Reply #4 on: January 03, 2008, 12:12:45 PM »
        I installed a games programme from a game website (cant remember what the game site was called) anyway all i got was a red x on the site so i uninstalled it, thats when my problem started i have tried a system restore  but all i get when it's done is "your system couldnt be restored to that date you selected" ive tried numerous dates on the restore from the day before to at least 2 weeks back and still get the same system restore message.

        patio

        • Moderator


        • Genius
        • Maud' Dib
        • Thanked: 1769
          • Yes
        • Experience: Beginner
        • OS: Windows 7
        Re: Running slow
        « Reply #5 on: January 03, 2008, 12:17:00 PM »
        Also don't neglect the regular maintenence...
        Run Disk Cleanup.
        Run Defrag.

        Clean out Temp files and free up some space on that HDD if needed.
        " Anyone who goes to a psychiatrist should have his head examined. "

        soybean



          Genius
        • The first soybean ever to learn the computer.
        • Thanked: 469
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 10
        Re: Running slow
        « Reply #6 on: January 03, 2008, 12:51:09 PM »
        I believe installing CCleaner might be advantageous here.  Go to http://www.ccleaner.com/download/builds and get the Slim version.  CCleaner is a disk cleanup utility and a registry cleaner.  Take a close look at the options for the Windows scan before running it; you might take the QuickTour for a brief introduction to it's features.  You may want to uncheck some of the options there before running a scan and deleting what CCleaner finds. 

        Be sure to run the Registry Cleaner part of CCleaner.  When prompted to backup the registry, do so, and then have CCleaner fix all items found.

        keith67

          Topic Starter


          Rookie

          Re: Running slow
          « Reply #7 on: January 03, 2008, 01:50:26 PM »
          ok done all that ive gone into the startup bit on it and there is a ctfmon.exe in there ive never seen that app before does anyone know what it is ?

          soybean



            Genius
          • The first soybean ever to learn the computer.
          • Thanked: 469
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 10
          Re: Running slow
          « Reply #8 on: January 03, 2008, 02:10:17 PM »
          Frequently asked questions about Ctfmon.exe

          So, you ran CCleaner's Windows scan and removed what it found?  And, you ran Registry cleaner and fixed all those items?  Any change in your computer's performance yet?

          keith67

            Topic Starter


            Rookie

            Re: Running slow
            « Reply #9 on: January 03, 2008, 02:55:58 PM »
            i ran it and deleted all the cookies it found seems to be doing ok at the moment, ive gone into the registry option on it and scanned for issues and it's brought up a lot of stuff to fix most i aint a clue what they are or it's stuff ive deleted and uninstalled so ive not clicked on the fix tab even that internetgamebox is in there that i think caused all the problems in the first place.

            soybean



              Genius
            • The first soybean ever to learn the computer.
            • Thanked: 469
            • Computer: Specs
            • Experience: Experienced
            • OS: Windows 10
            Re: Running slow
            « Reply #10 on: January 03, 2008, 03:16:31 PM »
            Quote
            ive gone into the registry option on it and scanned for issues and it's brought up a lot of stuff to fix most i aint a clue
            OK, sounds some real progress has been made.  CCleaner is an excellent tool to keep installed and run periodically.  So, keep it in your arsenal of PC maintenance tools.

            keith67

              Topic Starter


              Rookie

              Re: Running slow
              « Reply #11 on: January 03, 2008, 03:49:29 PM »
              yeah definatly keep that on my pc .....so do i leave all the issues unfixed then ? and thanks for all your help

              patio

              • Moderator


              • Genius
              • Maud' Dib
              • Thanked: 1769
                • Yes
              • Experience: Beginner
              • OS: Windows 7
              Re: Running slow
              « Reply #12 on: January 03, 2008, 03:56:37 PM »
              To help diagnose further please post as much info about the machine as you can after you've completed the defrag etc.
              CCleaner should have taken care of the cleanup issues...
              " Anyone who goes to a psychiatrist should have his head examined. "

              soybean



                Genius
              • The first soybean ever to learn the computer.
              • Thanked: 469
              • Computer: Specs
              • Experience: Experienced
              • OS: Windows 10
              Re: Running slow
              « Reply #13 on: January 03, 2008, 04:22:37 PM »
              yeah definatly keep that on my pc .....so do i leave all the issues unfixed then ? and thanks for all your help
              You mean the issues CCleaner found upon running the registry scan, right?  Yes, go ahead and let CCleaner fix all of them.  As I previously said, backup your registry when CCleaner prompts after you start the registry scan; just tell CCleaner you want to backup your registry and it will do it.  Also, repeat the registry scan right after the initial fixing; it sometimes finds additional issues in a subsequent scan. 

              Broni


                Mastermind
              • Kraków my love :)
              • Thanked: 614
                • Computer Help Forum
              • Computer: Specs
              • Experience: Experienced
              • OS: Windows 8
              Re: Running slow
              « Reply #14 on: January 03, 2008, 05:47:34 PM »
              Also...
              Download HijackThis:
              http://www.snapfiles.com/get/hijackthis.html
              and post its log for us to see what's running on your computer.

              keith67

                Topic Starter


                Rookie

                Re: Running slow
                « Reply #15 on: January 05, 2008, 12:02:27 PM »
                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 18:58:38, on 05/01/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                C:\WINDOWS\system32\o2flash.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\WINDOWS\RTHDCPL.EXE
                C:\WINDOWS\system32\hkcmd.exe
                C:\WINDOWS\system32\igfxpers.exe
                C:\WINDOWS\system32\WLan.exe
                C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
                C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
                C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE
                C:\Program Files\MSN Messenger\MsnMsgr.Exe
                C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                C:\Program Files\MSN Messenger\usnsvc.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://join.msn.com/?page=sitewide/worldwide
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
                O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll

                keith67

                  Topic Starter


                  Rookie

                  Re: Running slow
                  « Reply #16 on: January 05, 2008, 12:04:13 PM »
                  2nd part as it said too long for post:

                  O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                  O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                  O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                  O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                  O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                  O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                  O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [WLAN] C:\WINDOWS\system32\WLan.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
                  O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                  O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
                  O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                  O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
                  O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                  O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\keith\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                  O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
                  O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                  O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                  O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                  O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                  O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
                  O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                  O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                  O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                  O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe
                  O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                  O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                  O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                  O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                  O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                  O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

                  --
                  End of file - 10724 bytes

                  Broni


                    Mastermind
                  • Kraków my love :)
                  • Thanked: 614
                    • Computer Help Forum
                  • Computer: Specs
                  • Experience: Experienced
                  • OS: Windows 8
                  Re: Running slow
                  « Reply #17 on: January 05, 2008, 12:15:52 PM »
                  Let's eliminate some garbage, first.

                  Open HJT, and checkmark following entries:
                  - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  - O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                  - O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
                  - O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\keith\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
                  Click "Fix checked" button.

                  You also need to update your Java: http://www.java.com/en/download/index.jsp
                  From Add\Remove uninstall any older Java versions.

                  Another question. Do you use Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE?

                  Restart computer. Post new log.

                  keith67

                    Topic Starter


                    Rookie

                    Re: Running slow
                    « Reply #18 on: January 05, 2008, 01:03:34 PM »
                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 19:59:52, on 05/01/2008
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                    c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                    c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\o2flash.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                    C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                    c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\WINDOWS\RTHDCPL.EXE
                    C:\WINDOWS\system32\hkcmd.exe
                    C:\WINDOWS\system32\igfxpers.exe
                    C:\WINDOWS\system32\WLan.exe
                    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                    C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                    C:\Program Files\MSN Messenger\MsnMsgr.Exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://join.msn.com/?page=sitewide/worldwide
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                    O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
                    O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll

                    keith67

                      Topic Starter


                      Rookie

                      Re: Running slow
                      « Reply #19 on: January 05, 2008, 01:04:27 PM »
                      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                      O4 - HKLM\..\Run: [WLAN] C:\WINDOWS\system32\WLan.exe
                      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                      O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
                      O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
                      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                      O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
                      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                      O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
                      O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                      O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                      O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                      O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                      O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe
                      O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                      O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                      O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

                      --
                      End of file - 10334 bytes

                      Broni


                        Mastermind
                      • Kraków my love :)
                      • Thanked: 614
                        • Computer Help Forum
                      • Computer: Specs
                      • Experience: Experienced
                      • OS: Windows 8
                      Re: Running slow
                      « Reply #20 on: January 05, 2008, 01:12:23 PM »
                      Quote
                      Do you use Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE?

                      keith67

                        Topic Starter


                        Rookie

                        Re: Running slow
                        « Reply #21 on: January 05, 2008, 01:21:57 PM »
                        Quote
                        Do you use Microsoft's Input Message Editor (IME) for translating Japanese/Chinese text in IE?

                        Dont know what that is.....i bought this laptop new from pc world with the os already installed on it....how do i find that out , Thanks

                        Broni


                          Mastermind
                        • Kraków my love :)
                        • Thanked: 614
                          • Computer Help Forum
                        • Computer: Specs
                        • Experience: Experienced
                        • OS: Windows 8
                        Re: Running slow
                        « Reply #22 on: January 05, 2008, 01:31:32 PM »
                        It's OK. Since you don't know anything about it, you don't use it. I needed to know in order to check your startup programs.
                        Instructions in my next post.

                        Broni


                          Mastermind
                        • Kraków my love :)
                        • Thanked: 614
                          • Computer Help Forum
                        • Computer: Specs
                        • Experience: Experienced
                        • OS: Windows 8
                        Re: Running slow
                        « Reply #23 on: January 05, 2008, 02:00:05 PM »
                        Now, we are gonna eliminate some unnecessary startups. No program will be removed, some of them will be prevented from starting with your computer.

                        Open HJT, and checkmark following entries:

                        - O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

                        - O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

                        - O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

                        - O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe

                        - O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                        (unless you access your video settings few times a day; available via Start -> Settings -> Control Panel)

                        - O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                        (If you want the Ctrl+Alt+F12 or similar keypresses to access Intel's customised graphics properties, you need it, otherwise not. Can be disabled via the Display Properties in Control Panel)

                        - O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

                        - O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                        (unless you use it constantly)

                        - O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        (unless you use more, then one language in Office XP; if not, you have to manually disable it: http://support.microsoft.com/default.aspx?scid=kb;en-us;282599)

                        If you disabled the above, checkmark also:
                        - O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
                        - O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
                        - O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        - O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')


                        - O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
                        (unless you constantly use it)


                        I also don't like WLan.exe file location:
                        O4 - HKLM\..\Run: [WLAN] C:\WINDOWS\system32\WLan.exe
                        Please upload that file to:
                        http://www.virustotal.com/
                        for security check.

                        When you're done, restart your computer, and post new HJT log.

                        keith67

                          Topic Starter


                          Rookie

                          Re: Running slow
                          « Reply #24 on: January 05, 2008, 02:11:18 PM »
                          I also don't like WLan.exe file location:
                          O4 - HKLM\..\Run: [WLAN] C:\WINDOWS\system32\WLan.exe
                          Please upload that file to:
                          http://www.virustotal.com/
                          for security check.

                          Do i check this with the other's you suggested ? also how do i upload it to the sicht you gave me ?

                          keith67

                            Topic Starter


                            Rookie

                            Re: Running slow
                            « Reply #25 on: January 05, 2008, 02:26:40 PM »
                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 21:23:55, on 05/01/2008
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                            C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                            C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                            C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                            C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                            C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                            c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                            c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                            C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                            C:\WINDOWS\system32\o2flash.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                            C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                            c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                            C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\WINDOWS\RTHDCPL.EXE
                            C:\WINDOWS\system32\WLan.exe
                            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                            C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
                            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                            C:\Program Files\MSN Messenger\MsnMsgr.Exe
                            C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                            C:\Program Files\MSN Messenger\usnsvc.exe
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                            C:\Program Files\Messenger\msmsgs.exe

                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://join.msn.com/?page=sitewide/worldwide
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                            O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                            O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                            O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
                            O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                            O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                            O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
                            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                            O4 - HKLM\..\Run: [WLAN] C:\WINDOWS\system32\WLan.exe
                            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                            O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
                            O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                            O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
                            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                            O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                            O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
                            O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                            O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                            O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                            O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
                            O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                            O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                            O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                            O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                            O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe
                            O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                            O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                            O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                            O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

                            --
                            End of file - 9302 bytes

                            keith67

                              Topic Starter


                              Rookie

                              Re: Running slow
                              « Reply #26 on: January 05, 2008, 02:29:09 PM »
                              Also i keep getting web pages pop up from celldorado.com any ideas on that too ?

                              Broni


                                Mastermind
                              • Kraków my love :)
                              • Thanked: 614
                                • Computer Help Forum
                              • Computer: Specs
                              • Experience: Experienced
                              • OS: Windows 8
                              Re: Running slow
                              « Reply #27 on: January 05, 2008, 02:42:25 PM »
                              Quote
                              Do i check this with the other's you suggested ?
                              Not yet.
                              First:
                              Quote
                              how do i upload it to the sicht you gave me ?
                              Go to that web site, click on Browse button, and navigate to:
                              C:\WINDOWS\system32\WLan.exe

                              At the same time, I'll check your new HJT log.

                              Broni


                                Mastermind
                              • Kraków my love :)
                              • Thanked: 614
                                • Computer Help Forum
                              • Computer: Specs
                              • Experience: Experienced
                              • OS: Windows 8
                              Re: Running slow
                              « Reply #28 on: January 05, 2008, 02:49:38 PM »
                              When you're done with Virustotal...

                              Download, and install AutoRuns: http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx
                              Open it, go to Logon tab, and uncheck the following items:
                              - MSN Messenger
                              - Yahoo! Pager

                              Restart your computer, provide info from Virustotal, and new HJT log.

                              keith67

                                Topic Starter


                                Rookie

                                Re: Running slow
                                « Reply #29 on: January 05, 2008, 02:54:37 PM »
                                Prevx1    -    -    Win32.Malware.gen .......... thats all i get from the Virustotal .....now going to do what you told me to do

                                keith67

                                  Topic Starter


                                  Rookie

                                  Re: Running slow
                                  « Reply #30 on: January 05, 2008, 03:07:53 PM »
                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 22:06:03, on 05/01/2008
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                                  C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                                  C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                  C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                                  C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                                  C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                  c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                                  c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                                  C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                                  C:\WINDOWS\system32\o2flash.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                                  C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                                  c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                                  C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                  C:\WINDOWS\RTHDCPL.EXE
                                  C:\WINDOWS\system32\WLan.exe
                                  C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                                  C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
                                  C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                  C:\WINDOWS\system32\wuauclt.exe
                                  C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                  C:\Program Files\Messenger\msmsgs.exe

                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://join.msn.com/?page=sitewide/worldwide
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                                  O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                                  O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                  O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
                                  O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                                  O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                  O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
                                  O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                  O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                  O4 - HKLM\..\Run: [WLAN] C:\WINDOWS\system32\WLan.exe
                                  O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                  O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
                                  O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
                                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                  O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                                  O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
                                  O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                                  O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                                  O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                                  O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                                  O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
                                  O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                  O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                  O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                                  O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                                  O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe
                                  O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                                  O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                                  O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                                  O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                  O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                                  O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

                                  --
                                  End of file - 9001 bytes

                                  Broni


                                    Mastermind
                                  • Kraków my love :)
                                  • Thanked: 614
                                    • Computer Help Forum
                                  • Computer: Specs
                                  • Experience: Experienced
                                  • OS: Windows 8
                                  Re: Running slow
                                  « Reply #31 on: January 05, 2008, 03:28:08 PM »
                                  Quote
                                  Prevx1    -    -    Win32.Malware.gen .......... thats all i get from the Virustotal
                                  I knew, I didn't like that location.

                                  1. Print this post out, since you won't have an access to it, at some point.

                                  2. Close all windows, except for HijackThis.

                                  3. Put a checkmark next to the following HijackThis entries:

                                  - O4 - HKLM\..\Run: [WLAN] C:\WINDOWS\system32\WLan.exe

                                  4. Click on "Fix checked" button.

                                  5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

                                  6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

                                  7. Delete following files/folders (if present):

                                  - WLan.exe file from C:\WINDOWS\system32

                                  8. Turn off System Restore:

                                  - Windows XP:
                                     1. Click Start.
                                     2. Right-click the My Computer icon, and then click Properties.
                                     3. Click the System Restore tab.
                                     4. Check "Turn off System Restore".
                                     5. Click Apply.   
                                     6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
                                     7. Click OK.
                                  - Windows Vista:
                                     1. Click Start.
                                     2. Right-click the Computer icon, and then click Properties.
                                     3. Click on System Protection under the Tasks column on the left side
                                     4. Click on Continue on the "User Account Control" window that pops up
                                     5. Under the System Protection tab, find Available Disks
                                     6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                                     7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                                     8. Click OK

                                  9. Restart in Normal Mode.

                                  10. Turn System Restore on.

                                  11. Run HijackThis again, and post back its log back here.

                                  keith67

                                    Topic Starter


                                    Rookie

                                    Re: Running slow
                                    « Reply #32 on: January 05, 2008, 03:57:06 PM »
                                    Just a quick question about this WLan.exe isnt this somthing to do with my laptop with it being a wireless enabled one ? and also do i do the safe mode with networking or not ? Thanks

                                    Broni


                                      Mastermind
                                    • Kraków my love :)
                                    • Thanked: 614
                                      • Computer Help Forum
                                    • Computer: Specs
                                    • Experience: Experienced
                                    • OS: Windows 8
                                    Re: Running slow
                                    « Reply #33 on: January 05, 2008, 04:04:19 PM »
                                    Quote
                                    this WLan.exe isnt this somthing to do with my laptop with it being a wireless enabled one
                                    That's why I missed it, first time around. But apparently, even if it looks legit, it's not, as Virustotal confirmed.
                                    In any case HJT makes its own backup in case something goes wrong, so you can always go back.

                                    Quote
                                    do i do the safe mode with networking or not ?
                                    Read, and print my last instructions. It says at what point you enter Safe Mode.

                                    keith67

                                      Topic Starter


                                      Rookie

                                      Re: Running slow
                                      « Reply #34 on: January 05, 2008, 04:22:36 PM »
                                      Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 23:21:12, on 05/01/2008
                                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                                      C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                                      C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                      C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                                      C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                                      C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                      c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                                      c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                                      C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                                      C:\WINDOWS\system32\o2flash.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                                      C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                                      c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                                      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                      C:\WINDOWS\RTHDCPL.EXE
                                      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                                      C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
                                      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                      C:\Program Files\MSN Messenger\msnmsgr.exe
                                      C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                                      C:\Program Files\Messenger\msmsgs.exe
                                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://join.msn.com/?page=sitewide/worldwide
                                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                      O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                                      O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                                      O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                      O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
                                      O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                                      O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                      O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
                                      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                      O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
                                      O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
                                      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                                      O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
                                      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                                      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                                      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                                      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                                      O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
                                      O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                      O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                      O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                                      O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                                      O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe
                                      O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                                      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                                      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                                      O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                                      O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

                                      --
                                      End of file - 9013 bytes

                                      keith67

                                        Topic Starter


                                        Rookie

                                        Re: Running slow
                                        « Reply #35 on: January 08, 2008, 03:25:34 PM »
                                        Hi my system still running slow anyone else any ideas ? its driving me nuts now keep getting unwanted internet pop - up's too

                                        Broni


                                          Mastermind
                                        • Kraków my love :)
                                        • Thanked: 614
                                          • Computer Help Forum
                                        • Computer: Specs
                                        • Experience: Experienced
                                        • OS: Windows 8
                                        Re: Running slow
                                        « Reply #36 on: January 08, 2008, 03:48:35 PM »
                                        I'm sorry for late response, but apparently, I didn't receive any email notification about your previous post.
                                        Anyway, your HJT log is clean, but to be on safe side...

                                        1. Run free ESET Online Scanner at: http://www.eset.com/onlinescan/
                                        Note: This Scanner is for Internet Explorer Only
                                           1.  You will notice that the "Start" button is grayed out. Place a check mark at "Yes, I accept the Terms of use". The "Start" button will become visible. Click on it.
                                           2. If it wants to install an ActiveX component allow it
                                           3. You will be asked to install an ActiveX, click the "Install" button (Note: If you have a Firewall install you may have to approve the installation)
                                           4. Once ActiveX control is installed click on the "Start" button to initialize the scanner
                                           5. After initialization is complete uncheck\untick "Remove found threats"
                                           6. Check\tick "Scan unwanted applications"
                                           7. Click the "Scan" button
                                           8. Once the scan is done, you will find a log in C:\Program Files\esetonlinescanner\log.txt
                                        Post ESET's log.

                                        2. Download SUPERAntiSpyware Free for Home Users:
                                        http://www.superantispyware.com/

                                        Print these instructions out.

                                            * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
                                            * An icon will be created on your desktop. Double-click that icon to launch the program.
                                            * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
                                            * Close SUPERAntiSpyware.

                                        Restart computer in Safe Mode.
                                        To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen

                                            * Open SUPERAntiSpyware.
                                            * Under "Configuration and Preferences", click the Preferences button.
                                            * Click the Scanning Control tab.
                                            * Under Scanner Options make sure the following are checked (leave all others unchecked):
                                                  o Close browsers before scanning.
                                                  o Scan for tracking cookies.
                                                  o Terminate memory threats before quarantining.
                                            * Click the "Close" button to leave the control center screen.
                                            * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
                                            * On the left, make sure you check C:\Fixed Drive.
                                            * On the right, under "Complete Scan", choose Perform Complete Scan.
                                            * Click "Next" to start the scan. Please be patient while it scans your computer.
                                            * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
                                            * Make sure everything has a checkmark next to it and click "Next".
                                            * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
                                            * If asked if you want to reboot, click "Yes".
                                            * To retrieve the removal information after reboot, launch SUPERAntispyware again.
                                                  o Click Preferences, then click the Statistics/Logs tab.
                                                  o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
                                                  o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
                                                  o Please copy and paste the Scan Log results in your next reply with a new HijackThis log.
                                            * Click Close to exit the program.
                                        Post SUPERAntiSpyware log.

                                        keith67

                                          Topic Starter


                                          Rookie

                                          Re: Running slow
                                          « Reply #37 on: January 09, 2008, 06:10:19 AM »
                                          Nothing cane up on the ESET online scanner......this is the log of the SAS scan
                                          SUPERAntiSpyware Scan Log
                                          http://www.superantispyware.com

                                          Generated 01/09/2008 at 04:05 AM

                                          Application Version : 3.9.1008

                                          Core Rules Database Version : 3376
                                          Trace Rules Database Version: 1370

                                          Scan type       : Complete Scan
                                          Total Scan Time : 02:21:30

                                          Memory items scanned      : 156
                                          Memory threats detected   : 0
                                          Registry items scanned    : 5330
                                          Registry threats detected : 0
                                          File items scanned        : 55265
                                          File threats detected     : 21

                                          Adware.Tracking Cookie
                                             C:\Documents and Settings\keith\Cookies\keith@hitbox[2].txt
                                             C:\Documents and Settings\keith\Cookies\keith@adrevolver[3].txt
                                             C:\Documents and Settings\keith\Cookies\[email protected][1].txt
                                             C:\Documents and Settings\keith\Cookies\keith@serving-sys[1].txt
                                             C:\Documents and Settings\keith\Cookies\[email protected][1].txt
                                             C:\Documents and Settings\keith\Cookies\keith@advertising[1].txt
                                             C:\Documents and Settings\keith\Cookies\keith@adrevolver[2].txt
                                             C:\Documents and Settings\keith\Cookies\keith@mediaplex[1].txt
                                             C:\Documents and Settings\keith\Cookies\keith@atdmt[2].txt
                                             C:\Documents and Settings\keith\Cookies\keith@cgi-bin[2].txt
                                             C:\Documents and Settings\keith\Cookies\keith@tradedoubler[2].txt
                                             C:\Documents and Settings\keith\Cookies\[email protected][2].txt
                                             C:\Documents and Settings\keith\Cookies\[email protected][2].txt
                                             C:\Documents and Settings\keith\Cookies\[email protected][1].txt
                                             C:\Documents and Settings\keith\Cookies\keith@2o7[2].txt
                                             C:\Documents and Settings\keith\Cookies\keith@adinterax[1].txt
                                             C:\Documents and Settings\keith\Cookies\keith@doubleclick[1].txt
                                             C:\Documents and Settings\keith\Cookies\[email protected][1].txt
                                             C:\Documents and Settings\keith\Cookies\[email protected][2].txt
                                             C:\Documents and Settings\keith\Cookies\[email protected][2].txt
                                             C:\Documents and Settings\keith\Cookies\keith@apmebf[2].txt

                                          keith67

                                            Topic Starter


                                            Rookie

                                            Re: Running slow
                                            « Reply #38 on: January 09, 2008, 06:12:35 AM »
                                            Logfile of Trend Micro HijackThis v2.0.2
                                            Scan saved at 13:10:56, on 09/01/2008
                                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                                            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                            Boot mode: Normal

                                            Running processes:
                                            C:\WINDOWS\System32\smss.exe
                                            C:\WINDOWS\system32\winlogon.exe
                                            C:\WINDOWS\system32\services.exe
                                            C:\WINDOWS\system32\lsass.exe
                                            C:\WINDOWS\system32\svchost.exe
                                            C:\WINDOWS\System32\svchost.exe
                                            C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                                            C:\WINDOWS\Explorer.EXE
                                            C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                                            C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                                            C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                            C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                                            C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                                            C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                            C:\WINDOWS\system32\spoolsv.exe
                                            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                            c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                                            c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                                            C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                                            C:\WINDOWS\system32\o2flash.exe
                                            C:\WINDOWS\system32\svchost.exe
                                            C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                                            C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                                            c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                                            C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                            C:\WINDOWS\RTHDCPL.EXE
                                            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                                            C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
                                            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                            C:\Program Files\MSN Messenger\msnmsgr.exe
                                            C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                            C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
                                            C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                                            C:\WINDOWS\system32\wuauclt.exe
                                            C:\Program Files\MSN Messenger\usnsvc.exe
                                            C:\Program Files\Internet Explorer\iexplore.exe
                                            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                            C:\Program Files\Messenger\msmsgs.exe
                                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
                                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
                                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm
                                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://join.msn.com/?page=sitewide/worldwide
                                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
                                            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                            O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                                            O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                                            O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                            O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
                                            O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                                            O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                            O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-gb\msntb.dll
                                            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                            O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
                                            O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                            O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
                                            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                                            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                            O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
                                            O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
                                            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

                                            keith67

                                              Topic Starter


                                              Rookie

                                              Re: Running slow
                                              « Reply #39 on: January 09, 2008, 06:13:03 AM »
                                              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                              O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                                              O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
                                              O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                                              O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                                              O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                                              O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                                              O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
                                              O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
                                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                              O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                              O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                                              O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
                                              O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe
                                              O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                                              O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                                              O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                                              O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                              O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                                              O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

                                              --
                                              End of file - 9704 bytes

                                              keith67

                                                Topic Starter


                                                Rookie

                                                Re: Running slow
                                                « Reply #40 on: January 09, 2008, 06:15:46 AM »
                                                Sorry about this Broni i understand you are very busy .... im still getting internet pop ups from sites called
                                                fp.pc-on-internet.com and celldorado & a couple of others too and they all start with "~http//" hope my logs can explain this.

                                                Broni


                                                  Mastermind
                                                • Kraków my love :)
                                                • Thanked: 614
                                                  • Computer Help Forum
                                                • Computer: Specs
                                                • Experience: Experienced
                                                • OS: Windows 8
                                                Re: Running slow
                                                « Reply #41 on: January 09, 2008, 08:24:28 PM »
                                                Your log is totally clean.
                                                I assume, you're using Internet Explorer?
                                                Is pop-up blocker enabled?
                                                How about upgrading to ver. 7?

                                                I'd like you also to....
                                                1. Download, and install CCleaner: http://www.ccleaner.com/
                                                2. Read CCleaner instruction from here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner

                                                keith67

                                                  Topic Starter


                                                  Rookie

                                                  Re: Running slow
                                                  « Reply #42 on: January 10, 2008, 02:03:13 AM »
                                                  Hi Broni yes my pop up blocker is Enabled and i get pop ups on both internet Explorer & mozilla firefox, i just cant understand whats going on with this laptop as it's still running slow and freezes from time to time too, ive already installed CCleaner as you said in a previuos post, also im not sure wether this problem started after i upgraded to ie7 or not..... looks like im going to have to do a system recovery and reset to factory setting's if this carries on for much longer  :'(

                                                  Broni


                                                    Mastermind
                                                  • Kraków my love :)
                                                  • Thanked: 614
                                                    • Computer Help Forum
                                                  • Computer: Specs
                                                  • Experience: Experienced
                                                  • OS: Windows 8
                                                  Re: Running slow
                                                  « Reply #43 on: January 10, 2008, 06:44:48 PM »
                                                  You sure, those pop-up windows are browser windows, i.e. have a title Internet Explorer, or Firefox?

                                                  keith67

                                                    Topic Starter


                                                    Rookie

                                                    Re: Running slow
                                                    « Reply #44 on: January 11, 2008, 11:49:32 AM »
                                                    Hi Broni thanks for all your help in trying to resolve this matter, but it got the better of me and i ended up doing a system recovery and resetting it all to when i bought it.... i have another problem though with my main pc do i put up a new post ? Thanks

                                                    Broni


                                                      Mastermind
                                                    • Kraków my love :)
                                                    • Thanked: 614
                                                      • Computer Help Forum
                                                    • Computer: Specs
                                                    • Experience: Experienced
                                                    • OS: Windows 8
                                                    Re: Running slow
                                                    « Reply #45 on: January 11, 2008, 01:08:35 PM »
                                                    Quote
                                                    i have another problem though with my main pc do i put up a new post ?
                                                    Yes, please.