Solved

Slow computer...

Posted on 2011-09-24
18
327 Views
Last Modified: 2012-05-12
I am working on a client’s computer that is very slow.  I have reinstalled IE, run Malwarebytes – it found Trojan.Vundo and lots of adware - ran Hitman Pro, CCleaner, got rid of troublesome programs, ran Glarysoft Disk Speedup to defrag, and went through startup and services.  Anything else you might recommend?
mbam-log-2011-09-24--00-14-20-.txt
Hitman-Pro-log.xml
0
Comment
Question by:MagsMcKinley14
  • 7
  • 4
  • 3
  • +4
18 Comments
 
LVL 13

Expert Comment

by:themrrobert
ID: 36594182
combofix works well on xp in my experience.

http://www.bleepingcomputer.com/download/anti-virus/combofix
0
 

Expert Comment

by:Osram34
ID: 36594189
After eVeRything you have dOne to bring this unit back with no luck. I would recommend doing a fresh install of your O.S. This will be the only way to bring this computer back into it's best possible speed. Once you have a fresh install look into upgrading the ram and tweaking the O.S. EX.
deactivating the indexing on your hard drive
0
 

Author Comment

by:MagsMcKinley14
ID: 36594222
themrrobert I've only used combofix a couple of times.  There are so many warnings about using it, it makes me nervous that it might cause problems.  How safe for guided use is it?  Does it need the internet to fully run?

Things are running faster...he has 2 g ram, lots for XP.  I don't have access to the internet right now on his computer so can't do a full test on all I have done.  I’ll know more on Monday.  I agree, if this doesn't take care of it a fresh install will be necessary.
0
 
LVL 66

Accepted Solution

by:
johnb6767 earned 200 total points
ID: 36594370
Need clarification....  

How was the performance immediately before the virus infection?

I would do a Read Only CHKDSK inside windows....

start>run>cmd

chkdsk

If it reports there are errors, or that it cannot continue, select "chkdsk /f /r", hit Y, and reboot. The results are in the Application Log, source Winlogon.

Also, run through this.....

How to check your DMA status & reset it if necessary
http://forum.digital-digest.com/showthread.php?t=61905

Now here is another possibility to isolate purely a HW problem or a SW problem. Build your choice of the following 3 standalone CD based OS'es, and run some of the stress testing utilities on it. If it is slow still, I would suggest hardware.

What is the Ultimate Boot CD for Windows?
http://www.ubcd4win.com/

Bart's Preinstalled Environment (BartPE) bootable live windows CD/DVD
http://www.nu2.nu/pebuilder/

KNOPPIX - Live Linux Filesystem On CD-
http://www.knoppix.org/
 

0
 
LVL 4

Expert Comment

by:lordrt
ID: 36597416
may be run a registry defragmentation, and if possible, ask the client to add more RAM to the machine
0
 
LVL 91

Assisted Solution

by:nobus
nobus earned 300 total points
ID: 36597467
>>  a client’s computer that is very slow  <<   thsi has many possible causes:
-malware, as you already looked into
-specs : cpu too slow for xp sp3, too little ram, disk full  --> post cpu, ram spec and disk size + free space
-software : OS corrupted, programs running in background (eg daily AV scan)
-hardware  : bad disk sectors, file table corrupted

as for now - i suggest to run a LONG disk diag; if that comes back OK, run chkdsk on it, and a defragmentation, that should take care of most problems
find here all disk diags : http://www.tacktech.com/display.cfm?ttid=287      
pick the one for your disk brand
0
 
LVL 2

Expert Comment

by:karanprabham
ID: 36597491
go to device manager
expand - IDE ATA/ATAPI Controllers
delete primary IDE channel and Secondary IDE Channel.
Reboot

Because due to disk error sometimes it goes into PIO Mode instead of DMA mode.
0
 

Author Comment

by:MagsMcKinley14
ID: 36602113
Hey John...I'm not sure when I got the virus, he didn't even know he had one since Norton did not find it.  I ran chkdsk.  looked good when I ran it...where do I find Application Log, source Winlogon?

When I checked the DMA there are 2 primary and 2 secondary IDE Channels...1 set looks set correctly.

I have a UBCD Disk...so much on it not sure what to run.

nobus
CPU - Intel Core2 6300 @1.86 GHz
1.59 GHz, 1.99 GB of RAM
HDD 289 GB with 238 GB of free space

Need to run a disk diag
0
 
LVL 66

Assisted Solution

by:johnb6767
johnb6767 earned 200 total points
ID: 36602140
" I ran chkdsk.  looked good when I ran it...where do I find Application Log, source Winlogon?"

start>run>eventvwr.msc

Application Log, and click the top of the SOURCE column, and it will sort the events for you...... Then just find Winlogon....
0
Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

 

Author Comment

by:MagsMcKinley14
ID: 36602326
Here is the log John
Checking-file-system-on-C.doc
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 36685595
No bad sectors, that was good... I would expect a little improvement as it did make some corrections?
0
 

Author Comment

by:MagsMcKinley14
ID: 36700136
Things are loading faster.  Not like new but we would probably need to do a fresh install for that.  Would you still recommend a Disk Diag or does the chkdsk do much of the same?  Should I run some from the UBCD disk?  Favorite tests?

What about the DMA?

Thanks for the learning lessons!
0
 
LVL 91

Assisted Solution

by:nobus
nobus earned 300 total points
ID: 36707838
run from UBCD - long test - pick the one for your disk brand, eg seagate for seagate disk
it won't harm anything - and it is better than chkdsk (which checks the file system)
0
 

Author Comment

by:MagsMcKinley14
ID: 36710725
nobus...that is what I thought after I thought about it for a minute...thanks for clarifing.  Went to run the long test...said to make sure files are backed up...exited to run back up.  Client says his files are backed up but I would rather error on the safe side and do a quick back up.

Is this over kill or a good practice when working on a clients computer?
0
 
LVL 91

Assisted Solution

by:nobus
nobus earned 300 total points
ID: 36711038
a backup is NEVER overkill; better have 2 than 1 which proves corrupt when you want to restore it...
0
 

Author Comment

by:MagsMcKinley14
ID: 36711527
Help!!  .Net Framework was corrupt so I uninstalled and reinstalled (per another EE solution) the version that was corrupt.  Now Media Center will not open, saying it needs an older version to run.  Is there any issue in installing that version as well...I was under the impress that the newer version was sufficient.
0
 

Author Comment

by:MagsMcKinley14
ID: 36714251
Computer up and running as well as possible without a fresh install.  HDD error free.  Thanks guys!
0
 
LVL 91

Expert Comment

by:nobus
ID: 36714818
tx for feedback, and good luck with it
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

You cannot be 100% sure that you can protect your organization against crypto ransomware but you can lower down the risk and impact of the infection.
This story has been written with permission from the scammed victim, a valued client of mine – identity protected by request.
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now