| Answer» My machine has been SLOW and sluggish lately and my CPU Usage had been running consistently at about 50% or higher all the time. After I ran through all your steps it's now running at 1-4% Usage. Here are the requested logs.
 SUPERAntiSpyware Scan Log
 http://www.superantispyware.com
 
 Generated 11/05/2008 at 05:55 PM
 
 Application Version : 4.21.1004
 
 Core Rules Database Version : 3624
 Trace Rules Database Version: 1608
 
 Scan type   : Complete Scan
 Total Scan Time : 02:47:04
 
 Memory items scanned   : 496
 Memory threats detected : 0
 Registry items scanned  : 6790
 Registry threats detected : 0
 File items scanned    : 86137
 File threats detected  : 0
 
 -----------------------------------
 
 Malwarebytes' Anti-Malware 1.30
 Database version: 1370
 Windows 5.1.2600 Service Pack 3
 
 11/6/2008 8:56:55 AM
 mbam-log-2008-11-06 (08-56-55).txt
 
 Scan type: Quick Scan
 Objects scanned: 52044
 Time elapsed: 8 minute(s), 5 second(s)
 
 Memory Processes Infected: 0
 Memory Modules Infected: 0
 Registry Keys Infected: 0
 Registry Values Infected: 0
 Registry Data Items Infected: 0
 Folders Infected: 0
 Files Infected: 0
 
 Memory Processes Infected:
 (No malicious items detected)
 
 Memory Modules Infected:
 (No malicious items detected)
 
 Registry Keys Infected:
 (No malicious items detected)
 
 Registry Values Infected:
 (No malicious items detected)
 
 Registry Data Items Infected:
 (No malicious items detected)
 
 Folders Infected:
 (No malicious items detected)
 
 Files Infected:
 (No malicious items detected)
 
 -------------------------------------
 
 Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 9:10:01 AM, on 11/6/2008
 Platform: Windows XP SP3 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\sttray.exe
 C:\WINDOWS\system32\RUNDLL32.EXE
 C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
 C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe
 C:\Program Files\Microsoft IntelliType Pro\itype.exe
 C:\Program Files\Bonjour\mDNSResponder.exe
 C:\Program Files\Microsoft IntelliPoint\ipoint.exe
 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
 C:\WINDOWS\system32\hphmon04.exe
 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
 C:\Program Files\Hewlett-Packard\HP SOFTWARE Update\HPWuSchd.exe
 C:\PROGRA~1\AVG\AVG8\avgrsx.exe
 C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
 C:\PROGRA~1\AVG\AVG8\avgtray.exe
 C:\Program Files\Zune\ZuneLauncher.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\PROGRA~1\SecCopy\SecCopy.exe
 C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
 c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
 C:\WINDOWS\system32\STacSV.exe
 C:\WINDOWS\system32\svchost.exe
 c:\WINDOWS\system32\ZuneBusEnum.exe
 C:\PROGRA~1\AVG\AVG8\avgemc.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
 C:\WINDOWS\system32\msiexec.exe
 C:\Program Files\Java\jre6\bin\jusched.exe
 C:\Program Files\Java\jre6\bin\jqs.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Program Files\Trend Micro\HijackThis\sniper.exe
 
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
 O2 - BHO: Adobe PDF READER Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
 O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
 O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
 O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
 O2 - BHO: (no name) - {e80714f2-5cc2-3522-ceb7-5d0dc1d60bce} - (no file)
 O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
 O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe"
 O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
 O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
 O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
 O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
 O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
 O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
 O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
 O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
 O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
 O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
 O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [Second Copy] "C:\PROGRA~1\SecCopy\SecCopy.exe"
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
 O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1195229563375
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1195244036921
 O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
 O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
 O20 - AppInit_DLLs: avgrsstx.dll
 O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
 O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
 O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
 O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
 O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
 O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
 O23 - Service: DTools LANSync v5 Server (DToolsFileMgrServer) - D-Tools, Inc. - C:\Program Files\D-Tools\SI 5\Server\DToolsFileMgrServer.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
 O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
 O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
 O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe
 
 --
 End of file - 8410 bytes
 
 Maybe CCleaner did a good job because there was no malware.
 
 We can do a few things though.
 
 Download Disable/Remove Windows Messenger to the Desktop to remove Windows Messenger.
 
 Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.
 
 Unzip the file on the Desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.
 
 Exit out of MessengerDisable then delete the two files that were put on the Desktop.
 
 ----------
 
 Open HijackThis and SELECT Do a system scan only.
 
 Place a check mark next to the following entries: (if there)
 
 - O2 - BHO: (no name) - {e80714f2-5cc2-3522-ceb7-5d0dc1d60bce} - (no file)
 
 Important: Close all windows except for HijackThis and then click Fix checked.
 
 Exit HijackThis and run CCleaner then restart the computer to register the changes made by HijackThis.
 
 ----------
 
 I would also recommend that you Defrag the computer. There may be a lot of fragmented sections on the drive.
 
 You can use the built in Windows Defrag or a faster FREE program. Defraggler is very effective and easy to use. Be sure to clean out temp files and restart the computer just before using this.
 
 ----------
 
 Suggestions...
 
 Use the  Secunia Software Inspector to check for out of date software.
 
 .Click Start Now
Check the box next to Enable thorough system inspection.
Click Start
Allow the scan to finish and scroll down to see if any updates are needed.Update anything listed.
 ----------
 
 Go to Microsoft Windows Update and get all critical updates.
 
 ----------
 
 Here are some great FREE tools to help you KEEP from getting infected again. These tools use little or no resources so won't slow down your PC.
 
 Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript
 
 To prevent unknown applications from being installed on your computer install WinPatrol 2008
 *  Using Winpatrol to protect your computer from malicious software
 
 I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.
 
 SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
 * Using SpywareBlaster to protect your computer from Spyware and Malware
 * If you don't know what ActiveX controls are, see here
 
 Check out  Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.
 
 Also see  Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thank you very much for the help, it's appreciated.
 |