This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Computer is very very slow

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm trying to help a neighbor figure out why their PC is so slow on boot up and when trying to open applications, etc. I installed and ran Malwarebytes and Spybot, both cleaned up some stuff, but not that much. This is a WinXP/SP2 machine, has a 2 Ghz cpu and a gig of memory. I'm not sure if there is more malware that the above mentioned programs haven't found or if there is another problem. I'm including the DDS log and the attach file, I also have a Hijackthis log if needed. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 15:38:33.81 on Mon 08/24/2009 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.647 [GMT -4:00] AV: avast! antivirus 4.8.1351 [VPS 090824-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} ============== Running Processes =============== C:\WINNT\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\WINNT\system32\svchost.exe -k netsvcs C:\WINNT\system32\svchost.exe -k WudfServiceGroup C:\WINNT\Explorer.EXE svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINNT\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Motive\McciCMService.exe C:\WINNT\System32\NMSSvc.exe C:\WINNT\System32\svchost.exe -k imgsvc C:\WINNT\system32\SK9910DM.EXE C:\WINNT\GWMDMMSG.exe C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\Program Files\Messenger\msmsgs.exe C:\WINNT\system32\ctfmon.exe C:\Program Files\NetZero\exec.exe C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe C:\Program Files\NetZero\exec.exe C:\WINNT\system32\wscntfy.exe C:\Documents and Settings\Owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.verizon.net/central/vzc.portal uSearch Page = hxxp://my.netzero.net/s/search?r=minisearch uSearch Bar = hxxp://my.netzero.net/s/search?r=minisearch mDefault_Search_URL = hxxp://my.netzero.net/s/search?r=minisearch mSearch Page = hxxp://my.netzero.net/s/search?r=minisearch uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch mSearchAssistant = hxxp://my.netzero.net/s/search?r=minisearch uURLSearchHooks: URLSearchHook Class: {37d2cdbf-2af4-44aa-8113-bd0d2da3c2b8} - c:\program files\netzero\SearchEnh1.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx BHO: {243b17de-77c7-46bf-b94b-0b5f309a0e64} - c:\program files\microsoft money\system\mnyside.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File TB: ZeroBar: {f0f8ecbe-d460-4b34-b007-56a92e8f84a7} - c:\program files\netzero\Toolbar.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\winnt\system32\Shdocvw.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\winnt\system32\ctfmon.exe uRun: [NetZero_uoltray] c:\program files\netzero\exec.exe regrun uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe" mRun: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE mRun: [GWMDMMSG] GWMDMMSG.exe mRun: [IgfxTray] c:\winnt\system32\igfxtray.exe mRun: [HotKeysCmds] c:\winnt\system32\hkcmd.exe mRun: [Keyboard Preload Check] c:\oemdrvrs\keyb\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check" mRun: [GWMDMpi] c:\winnt\GWMDMpi.exe mRun: [AdaptecDirectCD] "c:\program files\roxio\easy cd creator 5\directcd\DirectCD.exe" mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe mRun: [HPDJ Taskbar Utility] c:\winnt\system32\spool\drivers\w32x86\3\hpztsb04.exe mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [COMODO Firewall Pro] "c:\program files\comodo\firewall\cfp.exe" -h mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h mRunOnce: [OOBEDDDemise] cmd /x /c erase c:\winnt\system32\oobe\msoobe.exe StartupFolder: c:\documents and settings\owner\start menu\programs\startup\PowerReg Scheduler V3.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wincin~1.lnk - c:\program files\sandisk\common\bin\WinCinemaMgr.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\winnt\system32\Shdocvw.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll IE: {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - {DD6687B5-CB43-4211-BFC9-2942CCBDCB3E} - c:\program files\microsoft money\system\mnyside.dll DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab DPF: Yahoo! Spades - hxxp://download2.games.yahoo.com/games/clients/y/st3_x.cab DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemyfios.verizon.net/sdcCommon/download/FIOS/Verizon%20FiOS%20Installer.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://support.gateway.com/support/profiler/PCPitStop.CAB DPF: {0F04992B-E661-4DB9-B223-903AB628225D} - file://c:\program files\gateway\do more\DoMoreRunExe.CAB DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,64/mcinsctl.cab DPF: {511073AD-BE56-4D43-AE68-93390514385E} - hcp://system/TechTools.CAB DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1143324825062 DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} - hcp://system/RunExeActiveX.CAB DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} - hcp://system/StartFirstControl.CAB DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37934.6622106481 DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,13/mcgdmgr.cab Notify: igfxcui - igfxsrvc.dll AppInit_DLLs: c:\winnt\system32\guard32.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winnt\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\winnt\system32\drivers\aswSP.sys [2009-4-29 114768] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\winnt\system32\drivers\cmdguard.sys [2009-8-23 132040] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\winnt\system32\drivers\cmdhlp.sys [2009-8-23 25160] R2 aswFsBlk;aswFsBlk;c:\winnt\system32\drivers\aswFsBlk.sys [2009-4-29 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-4-29 138680] R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2009-8-23 707152] R2 RioPNP;RioPNP;c:\winnt\system32\drivers\RioPnP.sys [2002-11-8 6736] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-4-29 254040] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-4-29 352920] S3 PCDRDRV;Pcdr Helper Driver;\??\c:\atf\qctest\pcdoc\pcdrdrv.sys –> c:\atf\qctest\pcdoc\PCDRDRV.sys [?] =============== Created Last 30 ================ 2009-08-24 15:08 –d—– C:\HJT 2009-08-23 19:00 179,792 a——- c:\winnt\system32\guard32.dll 2009-08-23 19:00 132,040 a——- c:\winnt\system32\drivers\cmdguard.sys 2009-08-23 19:00 25,160 a——- c:\winnt\system32\drivers\cmdhlp.sys 2009-08-23 14:34 91 a——- c:\winnt\wininit.ini 2009-08-23 12:42 –d—– c:\program files\Spybot - Search & Destroy 2009-08-23 12:42 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-08-23 12:41 –d—– c:\docume~1\owner\applic~1\Malwarebytes 2009-08-23 12:41 19,096 a——- c:\winnt\system32\drivers\mbam.sys 2009-08-23 12:41 38,160 a——- c:\winnt\system32\drivers\mbamswissarmy.sys 2009-08-23 12:41 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-23 12:41 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-23 12:40 –d—– c:\program files\SpywareBlaster 2009-08-23 12:38 –d—– C:\tmp 2009-08-20 00:05 –d—– C:\36927068b1187e1437cd0153f00e96 2009-08-17 01:03 1,871,872 ——– c:\winnt\system32\dllcache\mstscax.dll 2009-08-17 01:03 128,512 ——– c:\winnt\system32\dllcache\dhtmled.ocx 2009-08-05 05:11 204,800 ——– c:\winnt\system32\dllcache\mswebdvd.dll ==================== Find3M ==================== 2009-08-05 05:11 204,800 a——- c:\winnt\system32\mswebdvd.dll 2009-07-19 09:33 3,597,824 a——- c:\winnt\system32\dllcache\mshtml.dll 2009-07-19 09:32 6,067,200 ——– c:\winnt\system32\dllcache\ieframe.dll 2009-07-17 14:55 58,880 a——- c:\winnt\system32\atl.dll 2009-07-17 14:55 58,880 ——– c:\winnt\system32\dllcache\atl.dll 2009-07-13 23:43 10,841,088 a——- c:\winnt\system32\dllcache\wmp.dll 2009-07-13 23:43 286,208 a——- c:\winnt\system32\wmpdxm.dll 2009-07-13 23:43 286,208 a——- c:\winnt\system32\dllcache\wmpdxm.dll 2009-07-10 09:42 1,315,328 ——– c:\winnt\system32\dllcache\msoe.dll 2009-06-29 07:07 13,824 ——– c:\winnt\system32\dllcache\ieudinit.exe 2009-06-29 07:07 70,656 ——– c:\winnt\system32\dllcache\ie4uinit.exe 2009-06-29 04:35 634,632 ——– c:\winnt\system32\dllcache\iexplore.exe 2009-06-29 04:33 2,452,872 ——– c:\winnt\system32\dllcache\ieapfltr.dat 2009-06-29 04:33 161,792 a——- c:\winnt\system32\dllcache\ieakui.dll 2009-06-25 04:44 724,480 a——- c:\winnt\system32\lsasrv.dll 2009-06-25 04:44 298,496 a——- c:\winnt\system32\kerberos.dll 2009-06-25 04:44 168,448 a——- c:\winnt\system32\schannel.dll 2009-06-25 04:44 133,632 a——- c:\winnt\system32\msv1_0.dll 2009-06-25 04:44 59,392 a——- c:\winnt\system32\wdigest.dll 2009-06-25 04:44 56,320 a——- c:\winnt\system32\secur32.dll 2009-06-25 04:44 724,480 ——– c:\winnt\system32\dllcache\lsasrv.dll 2009-06-25 04:44 298,496 ——– c:\winnt\system32\dllcache\kerberos.dll 2009-06-25 04:44 168,448 ——– c:\winnt\system32\dllcache\schannel.dll 2009-06-25 04:44 133,632 ——– c:\winnt\system32\dllcache\msv1_0.dll 2009-06-25 04:44 59,392 ——– c:\winnt\system32\dllcache\wdigest.dll 2009-06-25 04:44 56,320 ——– c:\winnt\system32\dllcache\secur32.dll 2009-06-22 07:34 92,544 ——– c:\winnt\system32\dllcache\ksecdd.sys 2009-06-16 10:55 119,808 a——- c:\winnt\system32\t2embed.dll 2009-06-16 10:55 82,432 a——- c:\winnt\system32\fontsub.dll 2009-06-16 10:55 82,432 a——- c:\winnt\system32\dllcache\fontsub.dll 2009-06-16 10:55 119,808 ——– c:\winnt\system32\dllcache\t2embed.dll 2009-06-12 07:50 76,288 a——- c:\winnt\system32\telnet.exe 2009-06-12 07:50 76,288 ——– c:\winnt\system32\dllcache\telnet.exe 2009-06-10 10:21 84,992 a——- c:\winnt\system32\avifil32.dll 2009-06-10 10:21 84,992 ——– c:\winnt\system32\dllcache\avifil32.dll 2009-06-10 02:32 132,096 a——- c:\winnt\system32\wkssvc.dll 2009-06-10 02:32 132,096 ——– c:\winnt\system32\dllcache\wkssvc.dll 2009-06-09 11:06 1,871,872 a——- c:\winnt\system32\mstscax.dll 2009-06-03 15:27 1,290,752 a——- c:\winnt\system32\quartz.dll 2009-06-03 15:27 1,290,752 ——– c:\winnt\system32\dllcache\quartz.dll 2009-05-09 19:07 79,832 a——- c:\docume~1\owner\applic~1\GDIPFONTCACHEV1.DAT ============= FINISH: 15:40:28.52 ===============

Attachments:

As requested, this thread has been closed. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI