Solved

kids computer runs very slow  [xp home]

Posted on 2004-08-15
5
236 Views
Last Modified: 2013-12-04
I need some help with this computer  [it barely runs]
I really don't want to strip it So I'm turning to you for help

here's a high jack this log
thanks

Logfile of HijackThis v1.97.7
Scan saved at 6:47:54 PM, on 8/15/2004
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\mfcyq.exe
C:\WINDOWS\system32\atlgw32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\atloa.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\WINDOWS\System32\hphmon03.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
C:\PROGRA~1\HEWLET~1\PHOTOS~1\HPSHAR~1\hpgs2wnf.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\WINDOWS\System32\qgkmwgei.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\System32\qttask.exe
C:\Program Files\Common files\updater\wupdater.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Linksys\WUSB11 v25 Config Utility\WUSB11Cfg.exe
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\PROGRA~1\McAfee\MCAFEE~3\CPD.EXE
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
F:\ad remover\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pupjp.dll/sp.html#22776
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://pupjp.dll/index.html#22776
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=139150
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://pupjp.dll/index.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pupjp.dll/sp.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://pupjp.dll/index.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\pupjp.dll/sp.html#22776
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = res://mshp.dll/index.html#22776
O2 - BHO: (no name) - {C396D0E0-9E0A-542C-DF8F-ADEA8A5525B8} - C:\WINDOWS\apphz32.dll
O2 - BHO: (no name) - {F7F808F0-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem218.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\ISTbar\istbar.dll (file missing)
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\System32\hphmon03.exe
O4 - HKLM\..\Run: [CXMon] "C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_Monitor.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\PhotoSmart\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScanMSC] "C:\Program Files\McAfee\McAfee VirusScan\VSStat.exe" /EMBEDDING
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [adiksaip] C:\WINDOWS\System32\qgkmwgei.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
O4 - HKLM\..\Run: [SafeSurfingUpdate] C:\WINDOWS\System32\SSUpdate.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [WebRebates] javaw -cp "C:\Program Files\WebRebates\System\Code" Main lp: "C:\Program Files\WebRebates"
O4 - HKLM\..\Run: [atlgw32.exe] C:\WINDOWS\system32\atlgw32.exe
O4 - HKLM\..\Run: [MSKExe] c:\PROGRA~1\mcafee\SPAMKI~1\spamkiller.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [areslite] "C:\Program Files\Ares Lite Edition\AresLite.exe" -h
O4 - HKLM\..\RunOnce: [sdkue.exe] C:\WINDOWS\sdkue.exe
O4 - HKLM\..\RunOnce: [msaj32.exe] C:\WINDOWS\system32\msaj32.exe
O4 - HKLM\..\RunOnce: [appmd.exe] C:\WINDOWS\system32\appmd.exe
O4 - HKLM\..\RunOnce: [apiom.exe] C:\WINDOWS\apiom.exe
O4 - HKLM\..\RunOnce: [syshd32.exe] C:\WINDOWS\syshd32.exe
O4 - HKLM\..\RunOnce: [d3jd32.exe] C:\WINDOWS\d3jd32.exe
O4 - HKLM\..\RunOnce: [javayw.exe] C:\WINDOWS\system32\javayw.exe
O4 - HKLM\..\RunOnce: [d3rp32.exe] C:\WINDOWS\system32\d3rp32.exe
O4 - HKLM\..\RunOnce: [addnz32.exe] C:\WINDOWS\addnz32.exe
O4 - HKLM\..\RunOnce: [atlkj32.exe] C:\WINDOWS\atlkj32.exe
O4 - HKLM\..\RunOnce: [d3rj.exe] C:\WINDOWS\system32\d3rj.exe
O4 - HKLM\..\RunOnce: [netnl.exe] C:\WINDOWS\system32\netnl.exe
O4 - HKLM\..\RunOnce: [crak32.exe] C:\WINDOWS\system32\crak32.exe
O4 - Global Startup: Instant Wireless Configuration Utility.lnk = ?
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab

0
Comment
Question by:roberttownsend
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 3

Expert Comment

by:4ceReconSniper
ID: 11806504
pls post the specs of the computer
0
 
LVL 3

Expert Comment

by:4ceReconSniper
ID: 11806508
as a preliminary solution look and download for a program similar or trial version to tune up utilities 2004 it really speeds up pc's
0
 

Author Comment

by:roberttownsend
ID: 11806687
800mzh p3
128 megs ram
40 gig harddrive
0
 
LVL 21

Expert Comment

by:jvuz
ID: 11807346
You can also start with doing a defrag
0
 
LVL 65

Accepted Solution

by:
SheharyaarSaahil earned 500 total points
ID: 11808384
First Download these tools and install Adaware and Spybot:
========================================================
AdAware ==> http://www.lavasoftusa.com/support/download/
SpyBot  ==> http://www.spychecker.com/program/spybot.html
CoolWebShredder ==> http://www.spychecker.com/program/coolwebshredder.html
ToolBar Cop >> http://www.mvps.org/sramesh2k/toolbarcop.htm
Stinger >> http://vil.nai.com/vil/stinger
========================================================
then TURN OFF ur System Restore and fix the following lines !!!!!

========================================================
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pupjp.dll/sp.html#22776
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://pupjp.dll/index.html#22776
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=139150
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://pupjp.dll/index.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\pupjp.dll/sp.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://pupjp.dll/index.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\pupjp.dll/sp.html#22776
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = res://mshp.dll/index.html#22776
O2 - BHO: (no name) - {C396D0E0-9E0A-542C-DF8F-ADEA8A5525B8} - C:\WINDOWS\apphz32.dll
O2 - BHO: (no name) - {F7F808F0-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem218.dll
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\ISTbar\istbar.dll (file missing)
O4 - HKLM\..\Run: [adiksaip] C:\WINDOWS\System32\qgkmwgei.exe
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
O4 - HKLM\..\Run: [SafeSurfingUpdate] C:\WINDOWS\System32\SSUpdate.exe
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [atlgw32.exe] C:\WINDOWS\system32\atlgw32.exe
O4 - HKLM\..\RunOnce: [sdkue.exe] C:\WINDOWS\sdkue.exe
O4 - HKLM\..\RunOnce: [msaj32.exe] C:\WINDOWS\system32\msaj32.exe
O4 - HKLM\..\RunOnce: [appmd.exe] C:\WINDOWS\system32\appmd.exe
O4 - HKLM\..\RunOnce: [apiom.exe] C:\WINDOWS\apiom.exe
O4 - HKLM\..\RunOnce: [syshd32.exe] C:\WINDOWS\syshd32.exe
O4 - HKLM\..\RunOnce: [d3jd32.exe] C:\WINDOWS\d3jd32.exe
O4 - HKLM\..\RunOnce: [javayw.exe] C:\WINDOWS\system32\javayw.exe
O4 - HKLM\..\RunOnce: [d3rp32.exe] C:\WINDOWS\system32\d3rp32.exe
O4 - HKLM\..\RunOnce: [addnz32.exe] C:\WINDOWS\addnz32.exe
O4 - HKLM\..\RunOnce: [atlkj32.exe] C:\WINDOWS\atlkj32.exe
O4 - HKLM\..\RunOnce: [d3rj.exe] C:\WINDOWS\system32\d3rj.exe
O4 - HKLM\..\RunOnce: [netnl.exe] C:\WINDOWS\system32\netnl.exe
O4 - HKLM\..\RunOnce: [crak32.exe] C:\WINDOWS\system32\crak32.exe
==================================================
then...... disable ur messenger service if running >> http://www.itc.virginia.edu/desktop/docs/messagepopup/

1. Restart ur machine
2. Boot into safemode and Login as Administrator
3. Run the AntiVirus tool and delete all viruses it found
4. Run the Spyware Removal tools and delete everything they detect
5. Then goto MyComputer>Tools>Folder Options>View and turn on the feature of Show Hidden Files
6. Goto C:\Documents and Settings\ur usernmae\Local Settings\Temp and delete all files present here
7. Goto C:\Documents and Settings\ur usernmae\Local Settings\Temporary Internet Files, and delete the folder of ContentIE
8. Goto C:\Documents and Settings\ur usernmae\Cookies, and delete all cookies present here.
9. Reboot back in Normal Mode and check if problems are gone
10. If YES then Great, otherwise run the Hijakcthis scan, and post the LOG file here again.

Also i will advise u to get atleast 512MB RAM,,,,, its the minimum RAM recommended for running WinXP :)
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question