This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My computer is running slow, can you help?

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My desktop computer is running slow when I am browsing the internet. I don't know what is causing this problem. Can you help?
Hi cafenoir:

First, please copy and paste this text into a Notepad file and place it on your desktop, to review as you work. Please read this entire text, before beginning and ask any questions you may have about the following.

Please download Hijack This from here:
http://radiosplace.com

Or from here:

http://www.spywareinfo.com/~merijn/files/hijackthis.zip

133060


Next:
Your copy of HijackThis needs to be in a folder of it's own. When HJT fixes anything, it makes backups of the original files in the folder it is in. For this reason it cannot be run from a Zip file or from Temporary folders because the backups will be deleted. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!

1. Please go to you're 'My Documents' folder, right-click and select 'New > Folder' then name the folder 'HJT'.

2. Copy and paste HijackThis.exe to the new folder.

An HJT update:
You need to Update HiJackThis. Do the following:
1. Open HiJackThis, click on the Config button (bottom right corner)
2. Click on Misc. Tools (button at the top)
3. Click on *Check for online Update*
4. Check for updates often (weekly is recommended) or just before scanning.

Also, if you have any Startup items disabled in Msconfig, uncheck those items, reboot, then post a fresh log. Hijack This can not "see" disabled items in Startup.

Next:
Close all other Windows and Browsers, leaving only Hijack This open.

Double-click "HijackThis.exe" and Press "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Click: "Save Log" (generates: "hijackthis.log")
Copy and Paste the entire log,including the header, into this topic.

Please use the [external image: Posted Image] button to reply.

Note: Do not change anything in the new log. We need to see the entire log with no revisions.:


Hint: after posting your log click "Track this topic" at the top of the page, this way you will be notified (email) when a response is made to your post.

Please, do not post a Startup list, unless requested to do so.
Logfile of HijackThis v1.99.1
Scan saved at 10:39:53 PM, on 9/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\PASSWO~1\tlpd.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\PROGRA~1\efriendsi\taskmgr.exe
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\PROGRA~1\PASSWO~1\tlpd.exe
C:\PROGRA~1\myLinker\myLinker.exe
C:\Program Files\torang\Torang.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\NATEON\BIN\NATEONMain.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\conime.exe
C:\PROGRA~1\efriendsi\ENOTICE.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\efriendsi\EMESSAGE.EXE
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Hyo P. Kim\My Documents\hjt\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: asetapp Class - {73289162-036F-467D-921C-8DDC081693A5} - C:\WINDOWS\SYSTEM32\appset.dll
O3 - Toolbar: AICA·≫Ai - {26DFF40F-9082-4BDE-A703-D994E345C704} - C:\PROGRA~1\EFRIEN~1\efriends.dll
O3 - Toolbar: AICA·≫Ai(°E≫o/AO¼O) - {4E1377C1-3F95-4F90-976C-148BF6DB11B3} - C:\PROGRA~1\EFRIEN~1\efasbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Password Door Loader] C:\PROGRA~1\PASSWO~1\tlpd.exe /boot
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [eUpdate] "C:\PROGRA~1\efriendsi\patch.exe"
O4 - HKLM\..\Run: [EMESSAGE] "C:\PROGRA~1\efriendsi\taskmgr.exe"
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [InCD] C:\Documents and Settings\Hyo P. Kim\Desktop\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [spynet] C:\Program Files\SpyNet\SpyNet.exe -bg
O4 - HKLM\..\Run: [myLinker] C:\PROGRA~1\myLinker\myLinker.exe /B
O4 - HKLM\..\Run: [Torang] C:\Program Files\torang\Torang.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NATEON] C:\Program Files\NATEON\BIN\NATEON.exe -as
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O16 - DPF: {00001024-B831-448B-9ABD-3D3DF187F359} (DaumGameStarter24 Class) - http://download.netmarble.com/web/nmstarte…meStarter24.cab
O16 - DPF: {04E7BADF-F3B9-420D-B82D-8D8CADEFE4F9} (CyImage2Ctl Class) - http://cyimg6.cyworld.nate.com/ImageUpload…mageUpload2.cab
O16 - DPF: {916465E2-F906-4A14-9A91-261BA17CA6A1} - http://stop.co.kr/program/install/actstop.cab
O16 - DPF: {D3A3737D-21EE-43DB-9F6A-32B220B706EE} (FREEPOPLauncher.Launch) - http://club.freepop.co.kr/fpop/service/FREEPOPLauncher.CAB
O16 - DPF: {E8FB2BD7-3703-483A-8EC1-43DADAFC7668} (ELauncher Control) - http://update.folderplus.com/eWebLink/eLauncher.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InCD Helper (InCDsrv) - Unknown owner - C:\Documents and Settings\Hyo P. Kim\Desktop\InCD\InCDsrv.exe (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hi cafenoir:

Please print, or copy and paste this text into a Notepad file and place it on your desktop, to review as you work. Please proceed with this fix in the order provided below. Please read this text before beginning, so you will know what to expect.

I do not see a FIREWALL ,or an Anti-Virus on your PC, both of which are absolutely essential for any PC that is on the Internet. If you do not have either of those, it is essential that you download and install one of each, without delay. Failure to do this can nullify any good we are able to do.

Below you will find a link to Zone Alarm, which has a good free firewall for personal use, another for kerio (free for personal use) and a link to sygate. Note that it is not recommended to run two firewalls simultaneously, not even along with the new Microsoft firewall, which is not recommended.
http://www.zonelabs.com/store/content/cata…sku_list_za.jsp
http://www.kerio.com/us/kpf_home.html
http://smb.sygate.com/products/spf_pro.htm

Then:
To disable the XP firewall: Control Panel > Internet Options > Connections > Settings > Properties > Advanced…. Remove the check mark from the "Internet Connection Firewall" box and click "OK." Now, install your new firewall, without any further delay and certainly before going onto the internet.

Here is a link for a free AVG ANTI-VIRUS:

http://free.grisoft.com/freeweb.php/doc/1/lng/us/tpl/v5

Next:
Use ctl/alt/del to get into Task Manager and hilight the following, if found.
Then, click on END PROCESS.

SearchNugget Toolbar
EFRIEN~1
efriendsi
SpyNet
myLinker
AICA
EMESSAGE

The following is optional
AWS\WEATHE~1

The following could not be positively identified, so must be your option
torang
NATEON


Then, exit Task Manager.


Next:

Go to Start -> Settings -> Control Panel -> Add/Remove Programs. If found remove the program(s).
SearchNugget Toolbar
EFRIEN~1
efriendsi
SpyNet
myLinker
AICA
EMESSAGE

The following is optional
AWS\WEATHE~1

The following could not be positively identified, so must be your option
torang
NATEON


Next:
Please set your system to show all files; please see here if you're unsure how to do this.

Close all windows and browsers, leaving only HijackThis running.

Place a check beside each of these entries listed below, if still present.

O2 - BHO: asetapp Class - {73289162-036F-467D-921C-8DDC081693A5} - C:\WINDOWS\SYSTEM32\appset.dll
O3 - Toolbar: AICA·»Ai - {26DFF40F-9082-4BDE-A703-D994E345C704} - C:\PROGRA~1\EFRIEN~1\efriends.dll
O3 - Toolbar: AICA·»Ai(°E»o/AO¼O) - {4E1377C1-3F95-4F90-976C-148BF6DB11B3} - C:\PROGRA~1\EFRIEN~1\efasbar.dll
O4 - HKLM\..\Run: [eUpdate] "C:\PROGRA~1\efriendsi\patch.exe"
O4 - HKLM\..\Run: [EMESSAGE] "C:\PROGRA~1\efriendsi\taskmgr.exe"
O4 - HKLM\..\Run: [spynet] C:\Program Files\SpyNet\SpyNet.exe -bg
O4 - HKLM\..\Run: [myLinker] C:\PROGRA~1\myLinker\myLinker.exe /B
O16 - DPF: {00001024-B831-448B-9ABD-3D3DF187F359} (DaumGameStarter24 Class) - http://download.netmarble.com/web/nmstarte…meStarter24.cab
O16 - DPF: {04E7BADF-F3B9-420D-B82D-8D8CADEFE4F9} (CyImage2Ctl Class) - http://cyimg6.cyworld.nate.com/ImageUpload…mageUpload2.cab
O16 - DPF: {916465E2-F906-4A14-9A91-261BA17CA6A1} - http://stop.co.kr/program/install/actstop.cab
O16 - DPF: {D3A3737D-21EE-43DB-9F6A-32B220B706EE} (FREEPOPLauncher.Launch) - http://club.freepop.co.kr/fpop/service/FREEPOPLauncher.CAB
O16 - DPF: {E8FB2BD7-3703-483A-8EC1-43DADAFC7668} (ELauncher Control) - http://update.folderplus.com/eWebLink/eLauncher.cab

The following are recommended/optional fixes:

O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1

The following two, could not be positively identified.

O4 - HKLM\..\Run: [Torang] C:\Program Files\torang\Torang.exe

O4 - HKCU\..\Run: [NATEON] C:\Program Files\NATEON\BIN\NATEON.exe -as

Click on Fix Checked when finished and exit HijackThis.


[*]Reboot into Safe Mode: see here if you are not sure how to do this.


Using Windows Explorer, locate the following files/folders shown DARK and delete them, if still present:

C:\WINDOWS\SYSTEM32\appset.dll

C:\PROGRA~1\EFRIEN~1\efriends.dll
C:\PROGRA~1\EFRIEN~1\efasbar.dll
C:\PROGRA~1\efriendsi\patch.exe
C:\PROGRA~1\efriendsi\taskmgr.exe
C:\Program Files\SpyNet\SpyNet.exe -bg
C:\PROGRA~1\myLinker\myLinker.exe /B

The following is optional.

C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1


The two following two could not be positively identified.

C:\Program Files\torang\Torang.exe


C:\Program Files\NATEON\BIN\NATEON.exe -as


Exit Explorer, enable hidden files and reboot.

If you were unable to delete any of the files, then please follow these additional instructions:
Download Pocket Killbox and unzip it; save it to your Desktop.
Run it, and click the radio button that says Delete a file on reboot. For each of the files you could not delete, paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.
The program will ask you if you want to reboot; say No each time until the last one has been pasted in whereupon you should answer Yes.
Let the system reboot.

Updating Java
  • Download the latest version of Java Runtime Environment (JRE) 5.0 Update 8.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-1_5_0_08-windowsi586-p.exe to install the newest version.
Please run Hijack This again. Scan and copy the log, then post it into this topic.

Please advise if any problems remain.

Please use the [external image: Posted Image] button to reply.
Thank you for your help!



Logfile of HijackThis v1.99.1
Scan saved at 4:34:01 PM, on 9/30/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\GRETECH\GOMPLA~1\GOM.exe
C:\Program Files\FolderPlus\FolderPlus Browser 4.exe
C:\Documents and Settings\Hyo P. Kim\My Documents\hjt\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InCD Helper (InCDsrv) - Unknown owner - C:\Documents and Settings\Hyo P. Kim\Desktop\InCD\InCDsrv.exe (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
Hi cafenoir. You're welcome.

Your Hijack This log looks clean, with the possible exception of the two Programs that follow.
Do you know what these are and if so do you trust them ? Please advise.

C:\PROGRA~1\GRETECH\GOMPLA~1\GOM.exe
C:\Program Files\FolderPlus\FolderPlus Browser 4.exe


Also, please advise if your PC is running normally, with no problems.

Please use the [external image: Posted Image] button to reply.
Thank you once again for replying.. one is called a gom player which plays .avi files and the other is a download site for software.. My computer seems to be improved but still not running as smooth as it did before..
Hi cafenoir. You're welcome.

Well, lets run some programs and scanners to see if anything can be found that could cause the "smoothness" difficulties.

Please install, update, then configure Ad-Aware SE to the following directions. If you already have Ad-Aware SE, be sure to first update it , configure it to do a full systems scan, then run it and let it remove anything it asks about.
Install and how to use Ad-aware SE
http://www.bleepingcomputer.com/forums/ind…showtutorial=48

After using Ad-Aware SE, please reboot to allow it to finish.


Please use the following links to run two, or more of these online Virus Scanners and let them fix whatever they find.

When using Trend Micro, be sure and put a check in the box by "Auto Clean" before you do the scan. If it finds anything that it cannot clean have it delete it or make a note of the file location, so you can delete it yourself.


TrendMicro HouseCall
http://www.kaspersky.com/virusscanner
http://www.kaspersky.co.uk/news.html?id=146100010
Bitdefender and let it delete everything it finds.
eTrust AntiVirus Web Scanner
Panda ActiveScan
Note any thing that can't be fixed.

Please reboot when finished.

Then, lets run Ewido.


First, lets do a bit of cleaning, to make the Ewido report managable.

Clean your Cache and Cookies in IE:
  • Close all instances of Outlook Express and Internet Explorer
  • Go to Control Panel > Internet Options > General tab
  • Click the "Delete Cookies" button
  • Next to it, Click the "Delete Files" button
  • When prompted, place a check in: "Delete all offline content", click OK
Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
  • Go to Tools > Options.
  • Click Privacy in the menu on the left side of the Options window.
  • Click the Clear button located to the right of each option (History, Cookies, Cache).
  • Click OK to close the Options window
    Alternatively, you can clear all information stored while browsing by clicking Clear All.
    A confirmation dialog box will be shown before clearing the information.
Clean other Temporary files + Recycle bin
  • Go to start > run and type: cleanmgr and click ok.
  • Let it scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
  • Press OK to remove them.

    Please Note: This is a new version of Ewido Anti-Malware. It has a new set of setup and running instructions. Please delete any other versions and use the setup and usage directions shown below.

    Download ewido anti-spyware from HERE and save that file to your desktop.
    This is a 30 day trial of the program
    • Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
    • Once the setup is complete you will need run ewido and update the definition files.
    • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
    Close ewido anti-spyware, Do Not run a scan at this time.

    Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:
    • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
    • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    • ewido will now begin the scanning process, be patient this may take a little time.
      Once the scan is complete do the following:
    • If you have any infections you will prompted, then select "Apply all actions"
    • Next select the "Reports" icon at the top.
    • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important). I suggest saving it to your desktop.
    Close ewido and reboot your system back into Normal Mode.

    Then post the results of the ewido report scan into this topic, along with a fresh Hijack This log.

    Please use the [external image: Posted Image] button to reply.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI