|
Answer» Hi, newbie here - hope you can help. My PC has suddenly and for no apparent reason decided to slow down to a near crawl. I have tried a system restore - no good. I have tried defragmenting - got to 3% after 36 hours so I stopped it. I ran Spybot - it found some bogeys - but would not fix thme - said some dll file was missing? Now i cannot even start it up. It gets as far as my wallpaper and the start button and thats it - after about 8 hours. I'm assuming this is malware-related but i really don't know. Any help would be much appreciated.Well, if you can not start the computer, then your best THOUGHT would be to reformat....
[glb]Flame[/glb]Yeah - but i was hoping to avoid this in order to avoid losing all the data. The problem seems to be progressive - at first it was slow to boot up, but did and I was able to connect to the Internet, now it is just freezing.Have tried safe mode? Run spybot and your AV from there.Do you have a CD burner? You can SAVE all your data to a CD in safe mode and then erase if you can not fix it...
[glb]Flame[/glb]Thanks - Gonna try that when I get home - wasnt SURE whether spybot would work in safe mode. I know its hard to tell but is it possible it's a hardware problem? thats another reason I don't want to reformat - I'd hate to erase all taht data and then find out it's the CPU or something.Yeah - i have a CD burner. Thanks I'll try this.Actually, many people do not know this, but you SHOULD run system restores, etc. in safe mode for the best results... Suprising eh? Give us a shout when you get a chance to try these suggestions...
[glb]Flame[/glb]AVG Free -- Anti virus scanner Adaware SE Personal -- Anti spyware scanner Microsoft Antispyware -- Anti spyware scanner. Windows XP Home and Professional only. Spybot Search & Destroy -- Anti spyware scanner ZoneAlarm Free -- Free firewall - more user friendly Sygate Personal -- Free firewall - more configuration options
Download, install and configure these programs. Apply them in safe mode.Have most of those on the PC.
Tried running Spybot in safe mode. Safe Mode took about 20 minutes to boot up. Spybot ran ok and found a number of problems - however, when I tried to fix the problems it came up with various errors. One said a dll file was not a valid windows image. Another said a dll file (wbtengine.dll) could not be found. You should use a registry cleaner first.Where will i get a registry cleaner? I can't connect to the Internet in Safe mode. When I try to boot up normally it just freezes.If you are using Windows XP, you should select safe mode with NETWORK support
Or copy the data ONTO a medium.
Easy Cleaners -- Freeware registry scanner Registrar Lite -- Excellent replacement for Windows Regedit Crap Cleaner -- Freeware registry scanner/history cleaner
(Does anyone have any recommendations?)I recommend that we first try and figure out what the OS is. It's a waste of time trying to clean it up while restore is running.HJT LOG
Part 1:
Logfile of HijackThis v1.99.1 Scan saved at 17:45:38, on 08/07/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\System32\cisvc.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\System32\sistray.EXE C:\WINDOWS\System32\khooker.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe C:\Program Files\AIM\aim.exe C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe C:\Program Files\OpenOffice.org1.1.0\program\soffice.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Colin Shaw\Desktop\HJT\hijackthis1991.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.co.uk R3 - URLSearchHook: (no name) - {34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file) O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe" O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe" O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - Startup: OpenOffice.org 1.1.0.lnk = C:\Program Files\OpenOffice.org1.1.0\program\quickstart.exe O4 - Global Startup: Image Transfer.lnk = ?
|