|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Member (9 bit)
|
System possessed
My nephew was kind enough to bring over his possessed system for me to look at. I booted the system and it comes up pretty quickly, then all of a sudden all hell breaks loose... I suspect the system is trying to connect to something... The bottom line is the system is very slow, always see the hourglass on the cursor. I have run spybot, ad-aware, ran CClean to clean registry and files. Checked to see if defrag is needed, deleted a lot of junk files and I still have the same problem.
Can any of you offer any ideas as to how to tackle this problem. The XP Home software seems to work but the system is VERY VERY slow. Thanks and Happy New Year Steve |
|
|
|
|
|
#2 | |
|
Ride 'em Cowboy
Join Date: Dec 1999
Location: Dallas, Tx
Posts: 9,109
|
Quote:
__________________
Stand Up 2 Cancer - SU2C |
|
|
|
|
|
|
#3 |
|
Member (6 bit)
Join Date: Nov 2007
Location: The Earth
Posts: 57
|
Does the hdd LED glitter all the time?
|
|
|
|
|
|
#4 |
|
Member (9 bit)
|
I wish I could give you more. There is no HDD light on this system (Gateway) I don't see anything. All I can tell you is the system comes up ok at first, then 2 seconds later the cursor starts to show an hourglass as if it was doing something, I go to control panel and it can take up to 10 to 12 minutes for it to invoke. Sometimes you select a menu and it opens up... half way...
The really weird thing I have seen this morning is... in the add and remove software window the first 25 programs show up in the window and as you scroll through the window going down to the other programs it is separated by black stripes in the window. If you scroll down far enough the remaining programs installed will show... weird, I have never seen this before. The system seems really bogged down by trying to run something or something running in background. CPU Usage is low, that all looks normal. Defrag not needed... Thats all I have.. Thanks |
|
|
|
|
|
#5 |
|
Wrench Bender
Join Date: Dec 2002
Location: Plymouth,MN
Posts: 5,961
|
Would start the system up in Safe mode, then using MSCONFIG, take a look at what is in the start-up section. There is probably a lot of junk in there. Should be able to trim the programs in start-up down to about 6.
__________________
"When sliding down the banister of life; look out for splinters pointing up."
|
|
|
|
|
|
#6 | |
|
Member (9 bit)
|
Quote:
Thanks |
|
|
|
|
|
|
#7 |
|
Member (5 bit)
Join Date: Mar 2007
Posts: 31
|
Just a couple of ideas,do you know if the page file is heavily fragmented, if you open windows defragmenter and select the drive and click Analyse then click View Report then scroll down the Volume Information window, is either the Pagefile or the MFT fragmented.
Have you tried running something like F-Secure Blacklight to see if the pc has any rootkit infection. Do you have plenty of free hard drive space, how much RAM in the pc and how many sticks. |
|
|
|
|
|
#8 | |
|
Member (9 bit)
|
Quote:
The disk is ok, doesn't need to run defrag, the report was fine. I have not ran f-secure, not sure what that is but i will go research it now. I have enough hard drive space and the ram is 1 gig and room for expansion 2 sticks Thanks |
|
|
|
|
|
|
#9 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
|
What antivirus software is installed?
What antispyware software is installed? Go to the tools tab of CCleaner and in "StartUp" shut down everything except for the antivirus software. Clear all the temporary internet files using CCleaner. Does your nephew have any idea when this started to happen?, can you do a system restore back before he first noticed it? or is he clueless as to when it all started?
__________________
Niwa no niwa ni wa, niwa no niwatori wa niwaka ni wani o tabeta. |
|
|
|
|
|
#10 | |
|
Member (9 bit)
|
Quote:
I have already loaded CCleaner and cleaned everything up a few days ago... he told me it's been going on for quite some time. I went back to the last restore point but noticed he was attempting to clean the system then. I better not use that point. I did create a new restore point before I started. The last restore point goes to September 2007 so it doesn't go back far enough to a good configuration. Thanks Steve |
|
|
|
|
|
|
#11 |
|
Served with Pride
Staff
Premium Member
|
Have you tried running Hijack This! to see what is hiding in there? You've already done the prerequisites we recommend before posting a HJT log file. Might as well do that now and post it here for the rest of us to review.
Oh, and unless you have a love affair with McAfee, avoid that one just as you would Norton. |
|
|
|
|
|
#12 | |
|
Member (9 bit)
|
Quote:
No I havn't but I will tomorrow evening, I'll post it then Thanks again, Steve |
|
|
|
|
|
|
#13 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
|
If you think there are no good system restore points on that machine, switch off system restore and restart the machine. This will clear out the system restore files where a lot of this type of junk often hides, after the restart you can switch system restore back on.
|
|
|
|
|
|
#14 |
|
Member (6 bit)
Join Date: Nov 2007
Location: The Earth
Posts: 57
|
Well, I have experienced another case, the system becomes slow because the hdd transfering mode is PIO but DMA, maybe you can check that in Device Manager first.
|
|
|
|
|
|
#15 |
|
Member (5 bit)
Join Date: Mar 2007
Posts: 31
|
When you removed Norton did you use the Norton Removal Tool ? Might have nothing to do with your problem but I just wondered how you removed Norton and whether the problems were there before you removed it or are worse since you removed it.
On the hardware side a couple of things you might look at have you tried removing both ram sticks then putting just one stick back at any one time and booting up to see how it performs with one stick, also have you had a look for any bad caps on the motherboard. http://en.wikipedia.org/wiki/Capacitor_plague Have you tried F-Secure Blacklight or AVG AntiRootkit Free http://free.grisoft.com/doc/download...otkit/us/frt/0 Try running these in safe mode as well as normal and maybe try a-squared free and a-squared HiJackFree http://www.emsisoft.com/en/software/download/ |
|
|
|
|
|
#16 | |
|
Member (9 bit)
|
Quote:
Hi Panama Red, I ran Hijack This tonight and have attached the results. Thanks everyone for your help Steve |
|
|
|
|
|
|
#17 | |
|
Member (9 bit)
|
Quote:
Thanks |
|
|
|
|
|
|
#18 |
|
Served with Pride
Staff
Premium Member
|
Yup, you have company. Rather that do thru each item, here are links to two log analysers. They will tell you which items need to be removed. Feel free to post any questions here before you remove them.
http://hjt.networktechs.com/ http://www.hijackthis.de/en |
|
|
|
|
|
#19 | |
|
Member (9 bit)
|
Quote:
Thanks, I ran the log file on http://www.hijackthis.de/en[/QUOTE] and it gave me a few (6 or 7) Nasty files. This thing is not to easy to read. Do you think it's ok to kill all the nasty files first and reboot to see if it fixes anything? Then maybe look at the others flagged not so nasty? Thanks |
|
|
|
|
|
|
#20 |
|
Served with Pride
Staff
Premium Member
|
All those files that get tagged with a big yellow ? and contain nothing but consonants are all nasty too. Some files may get tagged because they are unknown. Examine them and make sure they aren't part of an application you have installed.
|
|
|
|
|
|
#21 | |
|
Member (9 bit)
|
Quote:
Steve |
|
|
|
|
|
|
#22 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
|
Each line of your log begining with 04 is a proccess that starts when Windows starts.
You have far too many, try looking through them and decide what you do and don't need to start up with Windows, a lot of the problems on that machine can not be removed until the proccess is stopped, if you can disable them to begin with it may help with the removal proccess. |
|
|
|
|
|
#23 | |
|
Member (9 bit)
|
Quote:
Your right, to many things turnd on at the start. Steve |
|
|
|
|
|
|
#24 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
|
I can see that you have a listing for AOHell and Verizon in your 04's, how do you connect to the internet? dialup, dsl, or cable and who is your service provider?
Edit.. I remember now you are cleaning this machine for your nephew, so the question should have been how does he connect to the internet? Last edited by rjfvillarosa; 01-02-2008 at 09:11 PM. |
|
|
|
|
|
#25 | |
|
Member (9 bit)
|
Quote:
They also have AOHell... I have told them to Dump it but they don't for some reason Steve |
|
|
|
|
|
|
#26 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
|
Looking through the log file makes me wonder if it would be better to backup all his personal music and picture files, then format and reinstall Windows.
There is so much junk in there you could possibly have system file damage. It's possible the reason they won't ditch AOHell is that they still have an email account with them, but I believe there are ways around that these days, if I remember correctly after ditching AOHell they keep your email active for a period of time. Personally the only contact I have ever had with AOHell was to use one of their installation disks to stop a wonky table leg moving. |
|
|
|
|
|
#27 | |
|
Member (9 bit)
|
Quote:
The kid is 16 so I am sure he has surfed every ware... and some! The music and pictures are the most important thing and yes you are right about backing them up. I asked them to get a 500 gig backup WD MyBook a few days ago if I get it on Saturday I will do just that, at least back it up. I really hate to re-load this system but it may be the thing to do. Thanks for the suggestion Steve |
|
|
|
|
|
|
#28 |
|
Served with Pride
Staff
Premium Member
|
I'm with rjf on the nuke and pave idea. Way to much stuff to spend time cleaning that machine. Good luck on either way you go.
|
|
|
|
|
|
#29 |
|
Staff
Premium Member
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,105
|
A reinstall is very easy if you do it "Lite" just load the absolute minimum to make it work, ditch all the Verizon and Printer garbage, just use the neccessary drivers ,nothing else.
|
|
|
|
|
|
#30 |
|
Member (9 bit)
|
Ok So I am reading what your asking but they have the HP all in one printer and they also have Verison. So if I ditch that stuff they will have to add it back again. How is that a good thing?
Anything I am ditching will be tempoary right now. I am going to try to get them to drop AoHell because they can use Google, Yahoo or MSN mail. So should I reformat the HD or try to re-load XP over it? Then the issue of SP2... They don't have SP2 I don't think so when I load XP can I go to MS web site and load SP2? Just want to make sure of the steps before I do it. Thanks Steve |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| System Restore, GoBack, Winternals Recovery Manager... etc | Radgam | Software Discussion & Support | 1 | 01-20-2006 09:41 AM |
| seems sketchy.. | comquter | Software Discussion & Support | 2 | 11-26-2005 09:59 AM |
| Hijack log | longrawker | Networking & Online Security | 13 | 09-12-2005 02:06 PM |
| NEW SYSTEM BUILD Ist P.O.S.T OK (now nothing) | 3DMAX | Computer Hardware | 5 | 04-04-2004 03:59 PM |