PDA

View Full Version : Can someone help me, please?


moochey
05-19-2004, 08:53 AM
My system seems to be alot slower than previously. I have ran "HiJack This" and I will post the log. If anyone has suggestions, I would appreciate your help! Thank You

Logfile of HijackThis v1.97.7
Scan saved at 9:51:42 AM, on 5/19/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Netropa\Internet Receiver\Traymon\Traymon.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\PROGRA~1\MAGICF~1\MulMouse.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\PCPhone\PCPhone.exe
C:\Program Files\Message Away\MessageAway.exe
C:\PROGRA~1\NORTON~1\NORTON~3\GHOSTS~2.EXE
C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\OPScan.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Greg\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=%tb_id
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: C:\Program Files\Norton Internet Security Professional\UrlLstCk.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~2\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [ICQ Net] C:\I386\winlogon.exe -stealth
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Internet Receiver] C:\Program Files\Netropa\Internet Receiver\Traymon\Traymon.exe
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [Versato] C:\PROGRA~1\MAGICF~1\MulMouse.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Startup: Message Away Real-time Protector.lnk = C:\Program Files\Message Away\MessageAway.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: PCPhone.lnk = C:\Program Files\PCPhone\PCPhone.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O9 - Extra 'Tools' menuitem: &Ad Blocker (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O9 - Extra button: WeatherBug (HKCU)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - [url]http://www.comcastsupport.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1076464758046
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinstc.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/0823bd6363e0d198a019/netzip/RdxIE601.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9184D21C-9835-42C5-A883-EA8BE7FC048D} (Downloader Class) - http://www.shop.intuit.com/commerce/account/downloads/executables/ie/IDA.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/gs/install/guidedsolutions.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37953.6377083333
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78D} (DoomCln Object) - http://www.microsoft.com/security/controls/DoomCln.CAB
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/controls/SassCln.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-44455354FFFF} - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F76DF680-EC17-4272-B1C7-CDB2641FA20B} (KB836528 Object) - http://microsoft.com/security/controls/DoomChk.CAB

Jason
05-19-2004, 09:46 AM
When a system suddenly seems slower the first thing you want to ask yourself is "what have I recently done?"

Installed any programs?
Installed any hardware?
New drivers?
Crash or incorrect shut down before the slowdown?
Changed bios settings?
Visited any weird IE sites?

Do a control+alt+del once and see whats running in the background and check the cpu utilization for high usage.

Disconnect from the internet and shut down all unnecessary tray software and see if its still slow.

Also are we speaking of IE thats slow or just the computer in general?

System stats?

Jason

moochey
05-19-2004, 09:59 AM
I recently downloaded DirectX upgrade. But the system was slow before that.
I installed a new driver for my HP Officejet K80 printer, from the HP website. But I think it was running OK after that.
No new hardware
No weird websites
It appears only to slow down when I run IE

The CPU usage flucuates between 5% and 100%.
The "processes" tab shows about 45 - 50 items running, the largest being CCPROXY.exe SYSTEM at 118,820


Thank you

Jason
05-19-2004, 10:24 AM
First off the system being slow in IE means nothing about the entire system being slow. Most likely your internet connection is just sucky right now. Are you Cable or 56K or DSL?

Secondly is there a specific reason you are running symantec network proxy service? (CCPROXY)

moochey
05-19-2004, 10:39 AM
I don't know of any .. I don't know what symantec network proxy service does.. so I don't know a specific reason.
Should I be?

I am on cable

Jason
05-19-2004, 10:49 AM
Well two things.

First are you serving the internet to anyone else, meaning another machine?

Secondly if you are on cable then welcome to the network my friend, your internet is shared with everyone else on your node and you could be going slower because a few new people signed up on your node and so your bandwidth is split.

If your not serving internet access to another separate machine then theres no reason for you to have CCproxy on your machine. That could be slowing you down, its also eating up massive ammounts of your ram at close to 115 meg. Freeing up this ram will definitely give you a speed increase.

Jason
05-19-2004, 10:50 AM
Did you install the symantec CC proxy software? Did you install norton suite or something?

Jason
05-19-2004, 10:53 AM
If you dont need the full norton suite I suggest you only install the antivirus and uninstall the rest. Norton is the most intrusive software I know of as your finding out.

moochey
05-19-2004, 10:54 AM
1st - I only have this PC so I don't want to be sharing with anyone. I did install Norton Internet Security Professional some time ago.
How do I get rid of the proxy??

and again... thank you for your help

Jason
05-19-2004, 11:42 AM
I would suggest uninstalling the entire suite from the add/remove control panel. Then re-install just the antivirus portion of the software. Its all you really need.

Prometheus
05-19-2004, 12:51 PM
Woah jason triple post!

Looks like a lot of spyware in hijack this

Run adaware and spybot etc

Jason425
05-19-2004, 07:37 PM
easy fix.. start, run, type msconfig, go to startup, and uncheck EVERYTHING.. you'll be happy....

Jason
05-19-2004, 08:17 PM
Jason if your going to give advice please know the full story. There are certain items that may be in his msconfig that he needs or wants. Unchecking everything could lead to an unstable system.

Please use the uninstall in the control panel to remove unneeded items

Jason

Jason425
05-19-2004, 08:34 PM
I know... he knows what he wants and he can keep those.. 90% of those nobody uses.. I know the story...

Jason
05-20-2004, 07:08 AM
Judging by his lack of familiarity with the threads and programs running on his system and his overall inability to solve this problem I wouldnt conclude he knows enough to not take what you said literally.

And no offense to you moochey, we all were at that point at some time. Well maybe not Jason425, I think he popped into this world with an Intel inside sticker on his ass.

moochey
05-20-2004, 07:45 AM
No offense taken... I am VERY unfamilar with this. I tried what Jason425 suggested and nothing loaded, so I reversed the changes.
I tried spy-bot and it doesn't seem to be any better.

I tried to remove Norton Internet Security Professional, but it says I need to contact them to do it. But I had it before and this was working good.

Where I really notice the difference is when I click on icons .. theres several seconds before the program is activated. It used to be immediate.

I certainly appreciate all the help. And again, I am ignorant when it comes to this stuff, so it's not insulting.

Jason
05-20-2004, 08:13 AM
Were this my machine I would suggest you simply reformat and re-install. However what you need to do is get a hold of a friend whom you trust and is good with computers to help you. Do you have the original Windows XP disk with cd key? DO you have a Cd burner and blank disk for backup of your data?

If so then we might be in business.

Please give me a rundown of the stats of this machine including:

CPU
Ram
Motherboard if you know it
Custom machine or dell, compaq etc?
Graphics card
Sound
Lan card
Any additional peripherals
Any additional software CD's

moochey
05-20-2004, 08:44 AM
It's a Dell 4500s

Pentium 4 1.8 ghz
512 RAM
XP Home Edition
I have HP K80 "all in one" printer
I have a CD burner
I have a wireless keyboard and mouse
Soundmax Audio
Cnet Pro200wl card
Intel 82845G Graphics
Conexant HSF V96 56K data fax MCI modem
I also have a logitech video cam
I use outlook express email

The OS was intalled by Dell. I have a CD, but I don't have the key

I did finally manage to get Norton Security Professional off and it seems to be a little better. But now I have to get another unintrusive virus and internet protection program .. any suggestions?

I had this problem about 1 year ago and after posting the "hijack this" log, I was instructed to remove some of the programs listed and it was fixed.

Thank you

Jason
05-20-2004, 09:09 AM
More than likely you can use the same CD that the norton security professional came from and simply select the components you want installed. In which case make certain that the only thing being installed is the antivirus.

A few areas to note:

If you are cable modem connected, then you don't need the 56K modem and may uninstall this. May free up IRQ's and CPU cycles.

If your Printer is USB as well as the CAM then you may diable all serial ports and Parallel port in the Bios (if you don't know how to do this I don't suggest trying to change anything in the bios)

Try making certain that all device drivers and latest patches are installed. Check the microsoft updates site.

Call Dell for the CD key for your CD as you should have gotten it.

Jason425's advice is correct to a degree in that you should try to uninstall if possible or disable all background services that you can. The problem is in determining what you can turn off and what you shouldnt. This is difficult for us to help you with. Here is where a computer savy friend is helpful.

Clean out your internet temp files and history. This could be taking up valuable space and contributing to your delay's. Open I.E. go to tools/internet options/ delete files (including offline files)/ then clear history

then

Perform a a diskcleanup and defrag on your HD. Right click C drive/properties/disk cleanup (check all boxes, may take a while depending on size of drive and amount to clean)
Then right click C/properties/tools/disk defrag (may take hours, depending on fragmentation (advice it to let it run overnight and not use the computer while its running the defrag)

Dragon
05-20-2004, 09:24 AM
my internet gets slow all the time as a result of about 150 meg in the temp internet files... i clean those out daily; i know this is an obvious thought but - did you try it?

likin the new avatar pro

Jason
05-20-2004, 09:31 AM
Hey what about my avatar?

And yes Temp files can kill you. If you havent cleaned them out in a while it could be gigs of info there.

moochey
05-20-2004, 09:35 AM
I go into the "My Computer" go to the Temporay internet and temp files and delete them quite often. Thanks for the suggestion though.

I have reloaded the virus portion only now. I will clean out all temp files and the do a defrag. It appears to be getting better though.

Thanks

Jason
05-20-2004, 09:45 AM
Good. There are,however, several directories that the computer uses to store temp files in. Some of which cannot be seen even if you have show hidden files and folders turned on. The I.E. 5 folder being such a folder. In XP I believe the default directory is

C:/DOcuments andsettings/(username)/local settings/history/I.E. 5

I may be wrong. from the Local settings folder you will have access to the Temp and Temporary internet files folders as well.

moochey
05-20-2004, 12:58 PM
OK .. I've done everything and it seems to BE BETTER than ever!!!!

Thank you VERY MUCH. I really appreciate your help!

Jason
05-20-2004, 01:23 PM
Glad to be of help. Now go learn about computers and stay here at TWL.

Xerxies
06-21-2004, 09:27 PM
Old thread, but I myself like having NSW installed. All you have todo to disable ccproxy is run regedit and goto HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ccProxy and goto the start entry. Change its value from 2 to 0 and restart. ccProxy will no longer load and it doesnt effect your norton installation.

Jason
06-22-2004, 10:08 AM
excellent reply Xerxies, thanks for the info.