Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

IE opening VERY SLOW

Posted on 2004-09-05
5
Medium Priority
?
930 Views
Last Modified: 2010-08-05
I have ran CWshredder, ad-ware and spybot in the Safe Mode.   They have found items and they have been deleted but the slow reaction of the IE opening is rediculaously slow.  All other operations of the computer seems to be fine.  PLease provide some advice.  I am running XP Home, and the restore is turned off.

Rick

0
Comment
Question by:rsaintonge
  • 2
  • 2
5 Comments
 
LVL 65

Accepted Solution

by:
SheharyaarSaahil earned 1200 total points
ID: 11986512
Hello rsaintonge =)

Have u yet tried emptying Temporary Internet Files and Cookies of IE ??
and when u goto Tools>Internet Options>Advanced adn untick Enable Third Party browser extenions
close and reopen IE.... same problem ??

if NO, then there is still soemthing bad sticked to IE, just Download HijackThis v1.98.2, run it, Save the LOG file and Post it here:
http://tools.radiosplace.com/HijackThis.exe

and if YES, then u may need to repair ur IE,,,, what OS are u using ??

Repair or Reinstall Internet Explorer in Windows XP:
http://www.theeldergeek.com/repair_ie6.htm
(First run the SFC scan, and then reinstall using ie.inf method)

if still no luck, then try running this tool(for Win2k\XP)
http://www.mvps.org/sramesh2k/IEFIX.htm

For NON-XP Based Systems:
http://support.earthlink.net/mu/1/psc/img/walkthroughs/windows_9x_nt/browsers/ie_6.0/8458.psc.html

!! GOOD LUCK !!
0
 

Author Comment

by:rsaintonge
ID: 11986620
Completed the first paragraph with no better result (Cookies and temp Files had already been done) dowloaded highkack this and here is my log file. OS is MS Windows XP Home Edition. Version 2002 Service pack 1.

 Logfile of HijackThis v1.98.2
Scan saved at 5:49:10 PM, on 9/5/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\pctspk.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Star Mortgage\Application Data\omts.exe
C:\WINDOWS\System32\rmnryhs.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Documents and Settings\All Star Mortgage\My Documents\Spy Ware Tools\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\adobe\acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6EAC6879-E336-05C6-8756-175578AE2330} - C:\WINDOWS\System32\hkemzvrc.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {E434D3C7-A673-4100-8140-79C020945017} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {53829F91-1B06-4DB9-B13E-812A986169F9} - (no file)
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKLM\..\Run: [Ad-watch] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Taeu] C:\Documents and Settings\All Star Mortgage\Application Data\omts.exe
O4 - HKCU\..\Run: [Ubsflwwl] C:\WINDOWS\System32\rmnryhs.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net

0
 
LVL 49

Assisted Solution

by:sunray_2003
sunray_2003 earned 800 total points
ID: 11986700
Hi rsaintonge,

Remove these

C:\WINDOWS\System32\rmnryhs.exe
O2 - BHO: (no name) - {6EAC6879-E336-05C6-8756-175578AE2330} - C:\WINDOWS\System32\hkemzvrc.dll
O2 - BHO: (no name) - {E434D3C7-A673-4100-8140-79C020945017} - (no file)
O4 - HKCU\..\Run: [Ubsflwwl] C:\WINDOWS\System32\rmnryhs.exe

Not sure why this has to run
O4 - HKCU\..\Run: [Taeu] C:\Documents and Settings\All Star Mortgage\Application Data\omts.exe

If you have not put restrictions , remove these
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present


SR..
0
 
LVL 49

Assisted Solution

by:sunray_2003
sunray_2003 earned 800 total points
ID: 11986702
Try doing all the latest updates for IE going to http://windowsupdate.microsoft.com and check if that would help

You may want to try IEFIX given in the first suggestion and see if that would help

SR
0
 
LVL 65

Assisted Solution

by:SheharyaarSaahil
SheharyaarSaahil earned 1200 total points
ID: 11988904
and include this line also aling with the lines sunray gave u....

>> O3 - Toolbar: (no name) - {53829F91-1B06-4DB9-B13E-812A986169F9} - (no file)

and dont forget to delete these two files in safemode, after fixing the lines in hijakcthis as they are unknown files, to me atleast, :)

hkemzvrc.dll(if its present) from C:\WINDOWS\System32 folder
rmnryhs.exe from C:\WINDOWS\System32 folder
omts.exe from C:\Documents and Settings\All Star Mortgage\Application Data folder

u have already emptied the Temp Internet Files and Cookies....
but u can also goto C:\Documents and Settings\username\Local Settings\TEMP
and can delete the junk present here,,,, this folder is the Home of many junk items from internet =\

Also empty the C:\Windows\TEMP folder... and if possible run some spyware and antivirus scans in safemode, to ensure ur system is really clean after deleting the junk with hijakchtis :)

and if still u get the same slowness problem, then a SFC scan is a must thing for u, run it and check if u can get the problem sorted or not, post back the results =)
0

Featured Post

Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This story has been written with permission from the scammed victim, a valued client of mine – identity protected by request.
Phishing emails are a popular malware delivery vehicle for attack.  While there are many ways for an attacker to increase the chances of success for their phishing emails, one of the most effective methods involves spoofing the message to appear to …
Please read the paragraph below before following the instructions in the video — there are important caveats in the paragraph that I did not mention in the video. If your PaperPort 12 or PaperPort 14 is failing to start, or crashing, or hanging, …
Look below the covers at a subform control , and the form that is inside it. Explore properties and see how easy it is to aggregate, get statistics, and synchronize results for your data. A Microsoft Access subform is used to show relevant calcul…

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question