1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

My Computer was very fast,Now it's too slow?

Discussion in 'Malware and Virus Removal Archive' started by Newbie24, 2004/10/28.

Thread Status:
Not open for further replies.
  1. 2004/10/28
    Newbie24

    Newbie24 Banned Thread Starter

    Joined:
    2004/10/23
    Messages:
    19
    Likes Received:
    0
    I was wondering if someone can be of assistance?.
    I recently bought a brand new P4 3Ghz system with 512 mb 400 mhz ram and a 160Gb wd Hdd.Everything was fine I was able to use the Internet fast and everything.But now it is too slow when trying to pull up a web site or even to connect to the internet?.I don't know much about all this stuff and I have High Speed Internet.Sometimes when I try and hit the start or close a page it takes forever to pull up.Not sure how to use Task manager,is it processes hanging causing this cuz this end now box appears when I try to restart my computer.And there are severall of the same Ybrowser processes running when I pull up taskmgr?.What should I do I know it's a dumb thing to ask but you got to learn some where. :p
     
  2. 2004/10/28
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Not a simple problem at all. If it were, you would have a half-dozen answers by now.

    Is Internet Explorer / web pages the only thing on the PC that is giving you trouble?

    What version of XP and since this is in the SP2 section I'll assume you have that loaded - did the problem start immediately after you installed SP2?

    edit note: I just read your Task Manager thread and notice that you have Kazaa and Gator loaded. Yuck. Bad idea. May well be causing your problem and even if not, Yuck, bad idea. I'm moving this thread to the spyware section since that's the best place to discuss some cleanup things you will need to do.
     
    Newt,
    #2

  3. to hide this advert.

  4. 2004/10/28
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Since Newt mentioned Kazaa, you're going to get the standard Kazaa speech for starters. ;)

    You are or were using Kazaa. This is not technically malware by itself, but it installs malware in order to run properly and it opens the door for every other nasty program you can think of. I strongly recommend that you remove it. Read this article for alternatives that will provide some of the same function without the garbage: http://www.spywareinfo.com/articles/p2p/ If you opt to remove it, first use Add/Remove Program to remove it and any reference to Altnet and P2P Networking. Go to your control panel, then to add/remove programs...uninstall P2P networking...If/when asked whether you also want to remove Altnet components, say 'Yes'.
    P2P Networking is a totally useless Kazaa add-on, and it's been reported to be responsible for serious system slowdowns. You may also want to run KazaaBegone to completely purge it from the system. Make sure to get the available LSPFix, just in case. Additionally, there is another new 'nasty' virus using P2P networks to spread itself. More here.

    WinMX seems to be a popular alternative. :)

    When done with that, download, install and update the latest versions of both Spybot and Ad-aware. Run Spybot and fix all problems found that are prechecked for removal. Run Ad-aware in full scan mode and delete all it finds. Then reboot. If things are still slugish, download HijackThis.exe from here. Save it to a permanent folder (I create a new folder in C:\ named HJT). Open and click scan, then save log. Once it is saved it will open in notepad. Select all from the edit button, copy and paste the results here. Don't fix anything with it yet! Someone experienced with the logs will advise you.
     
  5. 2004/10/31
    Newbie24

    Newbie24 Banned Thread Starter

    Joined:
    2004/10/23
    Messages:
    19
    Likes Received:
    0
    Computer slow

    thanks for getting back.Before I heard about all this I removed kazaa,p2p components,and anything to do with alnet.I also got norton anti virus 2005,installed and it detected 2 p2p infected files?.Then I went to Lavasoft.com and got Adaware and then Spy Bot.I did a full system scan with adaware and lots of detections were found,I ended up fixing them myself and i was carefull on what i did.I know you mention get help with that but i didn't read this posting until I already did this.I didn't do the HijackThis yet though.I'm very new to all this so thanks for bearing with me.And what is CWshredder for exactly,I only know briefly.Should I use this or the HijackThis.exe option as well considering my situation?.I also didn't know anything untill today about the Kazaabegone down load.Should I use this and get that fix they mentioned first just incase I loose my Internet connection from that bug it mentions.?The good thing is that my computer is no longer slow anymore but things don't seem right yet?.Do you think this might have something to do with why I can never copy and paste like I used to be able too?I can't even copy and paste a pic.Uninstall SP2??.or is it the spyware adware doing this to me?. :confused:
     
  6. 2004/10/31
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Yes, please post a HijackThis log. Please describe what other problems you are having. Is copy/paste working at all, or is it just pics that won't c/p?
     
  7. 2004/10/31
    Newbie24

    Newbie24 Banned Thread Starter

    Joined:
    2004/10/23
    Messages:
    19
    Likes Received:
    0
    CW Shredder and HijackThis

    I used to be able to copy and paste pic's(Jpeg)and now for some reason,everytime I try to paste it in say my pictures folder the paste button is greyed out,won't work?.But I just copied and pasted a (GIF)pic and it worked fine.What is going on here?.I don't know much about this stuff but I read the posts about people having problems not being able to copy and paste?.Is this some kind of virus not detected?,I have Norton Anti Virus 2005 installed.I ran Adaware and Spy Bot and got rid of Kazaa and p2p from my system.I have not ran CWShredeer yet.I'm asking if I should run CWShredder before attempting to do HijackThis and post the log??.I was able to copy and paste a pic in here,I tested this and it worked a(GIF)image.And certain sites like rogers will let you because I tried copying and Pasting a pic from there into my pictures folder and it worked and when I clicked over the pick to copy it a lining appeared around the pic letting me copy/paste it.So why I am I unable to Copy and Paste any other pics that I was before?.I even went back to the same sites I got them from and it won't let me,only able to to it in the folder making a duplicate pic?. :confused:
     
  8. 2004/10/31
    Newbie24

    Newbie24 Banned Thread Starter

    Joined:
    2004/10/23
    Messages:
    19
    Likes Received:
    0
    HijackThis Log

    I still can't seem to copy and paste jpeg images to my pictures,which I used to be able to do.I didn't use CWShredder yet or Kazaa be gone with the fix.I just have Adaware and Spy Bot.along with Norton anti Virus 2005,and Zone alarm's Fire wall, Since I am temporarily on the free trial of Norton Anti Virus from Symantec do I need,Norton Internet Security too?. Here is my HijackThis Log:

    Logfile of HijackThis v1.98.2
    Scan saved at 3:16:21 PM, on 10/31/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\SM1BG.EXE
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\Program Files\Yahoo!\Messenger\YPAGER.EXE
    C:\Program Files\Yahoo!\browser\ybrwicon.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\Program Files\Common Files\Copy of HijackThis.exe
    C:\WINDOWS\system32\wuauclt.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ca.red.clientapps.yahoo.com/customize/rogers/defaults/sb/*http://www.yahoo.com/search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ca.red.clientapps.yahoo.com/customize/rogers/defaults/sp/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rogers.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rogers.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ca.red.clientapps.yahoo.com/customize/rogers/defaults/su/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ca.red.clientapps.yahoo.com/customize/rogers/defaults/sb/*http://www.yahoo.com/search/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ca.red.clientapps.yahoo.com/customize/rogers/defaults/sp/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rogers.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ca.red.clientapps.yahoo.com/customize/rogers/defaults/su/*http://www.yahoo.com
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_20_0.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: IYBookmarkHO Class - {8B11A219-80C8-4B42-B558-B8C14D1AA8C4} - C:\Program Files\Yahoo!\browser\ybmho.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_20_0.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKCU\..\Run: [RHSI SHS] "C:\Program Files\Rogers\SelfHealing\SHS.exe" /background
    O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll
    O9 - Extra button: Rogers Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C:\Program Files\Yahoo!\browser\ysidebarIE.dll
    O9 - Extra 'Tools' menuitem: Rogers &Yahoo! Sidebar - {51085E3D-A958-42A2-A6BE-A6A9B0BAF276} - C:\Program Files\Yahoo!\browser\ysidebarIE.dll
    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.mdg.ca
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
     
  9. 2004/11/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Scan again with HijackThis and check the following entries. Close all other windows and click fix. The green are optional, although hijacks of the Windows default settings, most likely by your ISP software.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ca.red.clientapps.yahoo.com/.../search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ca.red.clientapps.yahoo.com/...//www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://rogers.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rogers.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ca.red.clientapps.yahoo.com/...//www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ca.red.clientapps.yahoo.com/.../search/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ca.red.clientapps.yahoo.com/...//www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rogers.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ca.red.clientapps.yahoo.com/...//www.yahoo.com

    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
    O14 - IERESET.INF: START_PAGE_URL=http://www.mdg.ca


    You should visit the Sun Java website and update your JRE runtime to 1.4.2_06

    See nothing wrong with the apps you are currently running; Norton, ZA firewall. At this point, I also see no reason to run CWShredder and/or Kazaabegone.

    What does happen when you try to copy/paste jpegs? Error messages? Have you noticed anything else not behaving?
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.