well im at my friends house and his computer is running really slow. i have tried many things but when he does anything on his computer it takes forever. if you could please take a look. here is the log
Logfile of HijackThis v1.98.2
Scan saved at 6:15:42 PM, on 3/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Registration\mainap.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iPod\bin\iPodManager.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Bradly Benditz\Desktop\HijackThis.exe

R3 - URLSearchHook: (no name) - _{6E6DD93E-1FC3-4F43-8AFB-1B7B90C9D3EB} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CATLEvents Object - {68132581-10F2-416E-B188-4E648075325A} - C:\DOCUME~1\BRADLY~1\LOCALS~1\Temp\litulru.dat
O2 - BHO: CATLEvents Object - {D487068E-9B04-4FE5-8A83-08344F800BF5} - C:\DOCUME~1\BRADLY~1\LOCALS~1\Temp\ofnisnd.dat
O2 - BHO: CATLEvents Object - {FF4D5071-EE0E-4DCA-BC1C-D776B0F2276E} - C:\DOCUME~1\BRADLY~1\LOCALS~1\Temp\paniam.dat
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [iPodManager] C:\Program Files\iPod\bin\iPodManager.exe
O4 - HKLM\..\Run: [jpegurl] C:\WINDOWS\repair\jpegurl.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [*drvutil] C:\WINDOWS\system\drvutil.exe
O4 - HKLM\..\Run: [*abrap] C:\WINDOWS\Config\abrap.exe
O4 - HKLM\..\Run: [*unjpeg] C:\WINDOWS\system\unjpeg.exe
O4 - HKLM\..\Run: [*mfcras] C:\WINDOWS\Fonts\mfcras.exe
O4 - HKLM\..\Run: [*runbin] C:\WINDOWS\Registration\runbin.exe
O4 - HKLM\..\Run: [*taskweb] C:\WINDOWS\Web\taskweb.exe
O4 - HKLM\..\Run: [*runun] C:\WINDOWS\Cursors\runun.exe
O4 - HKLM\..\Run: [*smfc] C:\WINDOWS\Microsoft.NET\smfc.exe
O4 - HKLM\..\Run: [*dvdnut] C:\WINDOWS\Microsoft.NET\dvdnut.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [*dvdav] C:\WINDOWS\msagent\dvdav.exe
O4 - HKLM\..\Run: [*imgurl] C:\WINDOWS\inf\imgurl.exe
O4 - HKLM\..\Run: [*dnsftp] C:\WINDOWS\Help\dnsftp.exe
O4 - HKLM\..\Run: [*eulatask] C:\WINDOWS\assembly\temp\KRW28EJPU0\eulatask.exe
O4 - HKLM\..\Run: [*astcp] C:\WINDOWS\security\Database\astcp.exe
O4 - HKLM\..\Run: [*kbfax] C:\WINDOWS\system\kbfax.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunOnce: [*mainap] C:\WINDOWS\Registration\mainap.exe rerun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [ifmon] C:\WINDOWS\System32\ifmon.exe
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\Steam.exe -silent
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSxmb016
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{252F36BB-1546-44D1-85D7-4B86A9175068}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{FA87C927-0875-4D9F-ABE9-96581B1A6ED2}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{252F36BB-1546-44D1-85D7-4B86A9175068}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{252F36BB-1546-44D1-85D7-4B86A9175068}: NameServer = 192.168.1.1

Recommended Answers

All 3 Replies

Looks like your friends computer is running too many processes. It would be best to shut most of them down by pressing alt+ctrl+delete and shut off the programs you dont need to use. Or you can simply just close programs that slow down your computer such as messengers and other things. I've had this problem too and if you run too many processes (such as programs) you can find your computer running slow. Hope this helps. Anybody feel free to correct me if I'm wrong, I'm still just a n00b.

That log does indicate some cleaning is necessary, but before you fix anything with hijackthis, it needs to be in it's own folder. To do this, right-click on the desktop, select New, Folder; give the new folder a name of your choosing (something like HJT or HijackThis would be good), and then drag the hijackthis.exe icon that is on the desktop into this new folder.

Now, after you've moved it, close all browser windows, scan with HJT, and post a new log please.

That log does indicate some cleaning is necessary

"Some" cleaning? That would be an understatement, Danny.... Yuck!

ineedshelp,

Aside from some pretty nasty infestation, the log also indicates that your friend is running a rather old version (1.98.2) of HijackThis. Please download the lastest version (1.99.1), follow dlh6213's instructions above, and post the fresh log.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.