Solved

Dell Dimension 3000 slow. Hard drive light on a lot!

Posted on 2009-06-27
18
863 Views
Last Modified: 2012-05-07
I have a DELL Dimension 3000 that my wife uses. It is really getting slow and I have checked somewhat extensively for adware, virii, etc. Defragged.

The noticeable symmpton is that I frequently get a LONG period of time with the HD ligh mainly on (occasionally off). When it goes off (often 10 minutes after logging in!) the machine performance is only marginally slower than back in the day.
Hijack log follows

Thnaks for any ideas...
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:51:14 PM, on 6/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\American Express Online Assistant\OnlineAssistant.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Online Assistant - {465E08E7-F005-4389-980F-1D8764B3486C} - C:\Program Files\American Express Online Assistant\ietoolbar.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: Online Assistant - {6ADB0F93-1AA5-4BCF-9DF4-CEA689A3C111} - C:\Program Files\American Express Online Assistant\ietoolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Online Assistant.lnk = C:\Program Files\American Express Online Assistant\OnlineAssistant.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUman000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Online Assistant - {97ED3A9F-CD6F-473A-8FE1-7505C1B844C3} - C:\Program Files\American Express Online Assistant\ietoolbar.dll (HKCU)
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {00C0A1F2-D492-4DBA-A8E2-76CB1B791724} (TNPLDownloader Control) - https://dtwx2.accuweather.com/tnpl_awda/client/download/TNPLDownloader.cab
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/latest/PlaxoInstall.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/243c3f728f9e8dd49123/netzip/RdxIE601.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1227806229796
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamemanager/DIGGameManager.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 8665 bytes
0
Comment
Question by:lrplinker
  • 5
  • 5
  • 2
  • +4
18 Comments
 
LVL 23

Expert Comment

by:ComputerTechie
ID: 24730273
what are the syste spec and i would click on run and type msconfig

and then click on start up tap and uncheck some of the programs you do not need and reboot the compuer.

if the computer has a low amount of ram like 1 gig adding another stick of ram should increase speed.

CT
0
 
LVL 2

Expert Comment

by:matholland
ID: 24730487
seems like a virus.  try running malwarebytes.
0
 
LVL 91

Expert Comment

by:nobus
ID: 24730749
remove thois at least :
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUman000     The entry &Search has been identified as nasty.
0
 

Author Comment

by:lrplinker
ID: 24731272
COmputerTechie: I assume that more RAM being a solution to the constantly on hard drive assumes a lot of VM use? I am pretty sure that isnt it. But more RAM is cheap so I will try.

MATHOLLAND: No love on that idea. Like I said in the post I have (and often do) remove adware/malware. FWIW malwarebytes didnt get anything AVG and adaware hadnt already gotten

NOBUS: my wbsearch doesnt show up in add/remove programs. i removed it in "hijack this" but it comes back. more odeas on that specifically?
0
 
LVL 5

Expert Comment

by:KETTANEH
ID: 24731287
ensure that your machine is clean from viruses & you have enough RAM.
what is the CPU usage ??


use this tool : COMBOFIX
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

it's really helpfull
0
 
LVL 13

Expert Comment

by:JeremySBrown
ID: 24731565
Try scanning with Dr. Web Anti-Virus too.
http://www.freedrweb.com/
0
 
LVL 91

Expert Comment

by:nobus
ID: 24731752
i recommend running these :
     Spybot :        http://www.download.com/3000-8022-10122137.html
http://housecall.trendmicro.com/                                                               online scan for trojans
http://www.malwarebytes.org/mbam.php                         MBAM
0
 

Author Comment

by:lrplinker
ID: 24732127
No luck on freedrweb, spybot or housecall either. I can say this for malwarebytes---it runs a loooong time. 2 hrs 49 minutes on my machine.  

Basically i dont think this is a malware/trojan issue. surely there is something else that makes this hd spin a long time (light on) when i log in or crank up a new app...or just in the middle of something. then again, maybe not.....

i sort of hope the ram thing fixes it as i have ordered 4x the current memory
0
 
LVL 13

Expert Comment

by:JeremySBrown
ID: 24732171
If there's programs installed on the computer that you don't use...I suggest the you uninstall them to speed up your system a bit. You may want to scan the registry for any errors using something like Eusing Free Registry Cleaner. http://www.eusing.com/free_registry_cleaner/registry_cleaner.htm
If none of the above seem to work...you'll might to backup everything...format and reinstall Windows.

0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 2

Expert Comment

by:ilnyc
ID: 24732994
Couple of suggestions:

1. to see if virtual memory is causing the slow down, go to task manager, performance, and see whether peak commit charge is higher than total physical RAM.

2. make sure there is no hardware failures--check even log for warnings (yellow) and errors (red).

3. run some HD diagnostics. There is freeware called HDTune. And if you have a Seagate drive in your PC, you can download free seatools.
0
 
LVL 23

Expert Comment

by:ComputerTechie
ID: 24733004
you can use spinrite to refresh the drive. http://www.grc.com/sr/spinrite.htm

CT
0
 
LVL 23

Expert Comment

by:ComputerTechie
ID: 24733010
0
 
LVL 23

Expert Comment

by:ComputerTechie
ID: 24733015
make sure you have admin access and reboot computer.

CT
0
 

Author Comment

by:lrplinker
ID: 24733089
Maybe ilnyc is one to something. My "commit charge" is 435884 and Total is 421792 (moves around)....The "Limit" is 2060836 .....i dont even know what those mean, but do they suggest something to do?

exactly what is the "even log for warnings (yellow) and errors (red)" I am suppose to check  --- how do I do that. I will run HDTUNE.

ComputerTechie : I do not have aol. I do not understand the context of "make sure you have admin access and reboot computer." as I do that pretty regularly.
0
 
LVL 2

Accepted Solution

by:
ilnyc earned 500 total points
ID: 24733166
" My "commit charge" is 435884 and Total is 421792 (moves around)....The "Limit" is 2060836 .."

It means your memory usage is about  a little over 400MB. Did you say you have 1GB of physical RAM? If so RAM is not the problem.  You limit of 2GB is your physical and virtual memory combined.

"exactly what is the "even log for warnings (yellow) and errors (red)" I am suppose to check  --- how do I do that."

right click my computer-->manage, opens computer management window. Click event viewer under System Tools.

Here is another angle:

Since you mentioned the HD light comes up and computer slow down shortly after startup, it looks very much like AV scan.  From your hijackthis log I see that you use AVG as your AV.  You may want to try something different.

Since you can only use one AV at a time, you must completely uninstall AVG.   I recommend the follow 3 commercial AV programs which are known not to bog down your PC a lot:  ESET Nod32, kaspersky, and Norton AV 2009.   I am aware of a full trial version of Kaspersky, which allows you to try it before paying for it.
0
 

Author Closing Comment

by:lrplinker
ID: 31597641
I will test the additional RAM recommendation since I only have 512. I will go to 2.0. If that doesnt work I will replace avg,

Thanks
0
 
LVL 23

Expert Comment

by:ComputerTechie
ID: 24733208
OPs wrong post. what is ilnyc?

CT
0
 

Author Comment

by:lrplinker
ID: 24733448
"OPs wrong post. what is ilnyc?"

more like Who is? see name of prior poster.


0

Featured Post

Network it in WD Red

There's an industry-leading WD Red drive for every compatible NAS system to help fulfill your data storage needs. With drives up to 8TB, WD Red offers a wide array of solutions for customers looking to build the biggest, best-performing NAS storage solution.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You have seen this as an option on your internet browser before or it may be completely new to you.  But what does this mean and why would I use this?
I use more than 1 computer in my office for various reasons. Multiple keyboards and mice take up more than just extra space, they make working a little more complicated. Using one mouse and keyboard for all of my computers makes life easier. This co…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

28 Experts available now in Live!

Get 1:1 Help Now