PDA

View Full Version : Versy slow computer overheating then switching off



sg1974
2008-06-29, 14:47
Hi,

Our computer has gotten very slow recently; the hard drive appears to be working hard when nothing is obviously happening and it is becoming almost unusable. Sometimes the simplest of actions (e.g. opening "My Computer") can take 20-60 seconds to process. All the while the computer is on, the fan is going full pelt and the unit gets extremely hot. Then, after a while, the computer switches itself off. Indeed, I cannot succesfully run the Spybot S&D check without it crashing the computer halfway through.

Also, Internet Explorer is very slow and frequently locks for minutes at a time - the blue bar at top says "not responding" and then the "e" icon goes blank. I've got broadband but some webpages take a minute or two to load.

Thanks for your help.

James

(PS I think we have a custom IP blocker - a list of addresses in a notepad which a friend created ages ago saying it would protect us. Is that why we have some dodgy web addresses in this log?)

Hijack This log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:31:22, on 29/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Dell\AccessDirect\DadTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\ntl\ntl Netguard\RPS.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Safer Networking\RunAlyzer\RunAlyzer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0
O1 - Hosts: 127.0.01 virtumonde.com
O1 - Hosts: 27.0.0.1 www.visitfind.net#end of lines added by WinHelp2002.0.0.1 clit16.sextracker.com127.0.0.1 elite.sextracker.com127.0.0.1 graphics1.sextracker.com127.0.0.1 graphics2.sextracker.com127.0.0.1 hosting.sextracker.com127.0.0.1 links.sextracker.com127.0.0.1 mau.sextracker.com127.0.0.1 moneytree.sextracker.com127.0.0.1 ranks.sextracker.com127.0.0.1 stat1.sextracker.com127.0.0.1 start.sextracker.com127.0.0.1 stx.sextracker.com127.0.0.1 stx1.sextracker.com127.0.0.1 stx2.sextracker.com127.0.0.1 stx3.sextracker.com127.0.0.1 stx4.sextracker.com127.0.0.1 stx5.sextracker.com127.0.0.1 stx6.sextracker.com127.0.0.1 stx7.sextracker.com127.0.0.1 stx8.sextracker.com127.0.0.1 stx9.sextracker.com127.0.0.1 stx10.sextracker.com127.0.0.1 stx11.sextracker.com127.0.0.1 stx12.sextracker.com127.0.0.1 stx13.sextracker.com127.0.0.1 stx14.sextracker.com127.0.0.1 stx15.sextracker.com127.0.0.1 stxbans.sextracker.com127.0.0.1 webmasters.sextracker.com127.0.0.1 stx.banners.sextracker.com127.0.0.1 wm.banners.sextracker.com127.0
O1 - Hosts: neoffers.com #[Trojan-Downloader.Win32com127.0.0.1 www.customersupporthelp.com127.0.0.1 secure6.platinumbucks.com127.0.0.1 www.platinumbucks.com127.0.0.1 www.searchexpert.com127.0.0.1 www.sexfind.com127.0.0.1 searchforit.com #[eTrust.AdShooter.SearchForIt]127.0.0.1 dl.searchforit.com #[SunBelt.SearchForIt.AdShooter]127.0.0.1 www.searchforit.com #[Adware.Searchforit]127.0.0.1 surfenhance.com127.0.0.1 dl.surfenhance.com #[IE-SpyAd]127.0.0.1 www.surfenhance.com# [Monteg Inc]127.0.0.1 www.thumbsearcher.net #[klikfeed.com]127.0.0.1 www.toolbar4cash.com# [Netdreams P/L]127.0.0.1 www.egoog.com #[IE-SpyAd]127.0.0.1 www.escortsindex.com127.0.0.1 free-popup-killer.com #[TrojanClicker.Win32.VB.bn]127.0.0.1 www.internetpeace.com #[eTrust.Free Popup Killer]# [PayCounter.com, Inc]127.0.0.1 paycounter.com #[Ad-Aware.Tracking Cookie]127.0.0.1 count.paycounter.com #[IE-SpyAd]127.0.0.1 images1.paycounter.com127.0.0.1 in.paycounter.com127.0.0.1 stats.paycounter.com127.0.0.1 www.paycounter.com127.0.0.1 sort.trafficju
O1 - Hosts: .0.0.1 clit16.sextracker.com
O1 - Hosts: 127.0.
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [ntl Netguard] "C:\Program Files\ntl\ntl Netguard\RPS.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [IndexCleaner] "C:\Program Files\ntl\ntl Netguard\IdxClnR.exe"
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Sarah Oliver"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\ntl\ntl Netguard\IdxClnR.exe"
O4 - HKCU\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/download/scanner/wlscbase5059.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124098858156
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 11073 bytes

Blade81
2008-07-03, 10:20
Hi

Have you cleaned dust inside computer recently? If not, might be one reason for heating.


Let's clean your log a bit. Some entries are probably there by that custom IP blocker you meantioned. Anyway, better clean those and get MVPS Hosts file here (http://www.mvps.org/winhelp2002/hosts.htm) (but don't install it just yet) :)


We have to uninstall Spybot first to make sure TeaTimer won't interfere fixing. I'll let you know when it can be reinstalled.


Start hjt, do a system scan, check:
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: 127.0.01 virtumonde.com
O1 - Hosts: 27.0.0.1 www.visitfind.net#end of lines added by WinHelp2002.0.0.1 clit16.sextracker.com127.0.0.1 elite.sextracker.com127.0.0.1 graphics1.sextracker.com127.0.0.1 graphics2.sextracker.com127.0.0.1 hosting.sextracker.com127.0.0.1 links.sextracker.com127.0.0.1 mau.sextracker.com127.0.0.1 moneytree.sextracker.com127.0.0.1 ranks.sextracker.com127.0.0.1 stat1.sextracker.com127.0.0.1 start.sextracker.com127.0.0.1 stx.sextracker.com127.0.0.1 stx1.sextracker.com127.0.0.1 stx2.sextracker.com127.0.0.1 stx3.sextracker.com127.0.0.1 stx4.sextracker.com127.0.0.1 stx5.sextracker.com127.0.0.1 stx6.sextracker.com127.0.0.1 stx7.sextracker.com127.0.0.1 stx8.sextracker.com127.0.0.1 stx9.sextracker.com127.0.0.1 stx10.sextracker.com127.0.0.1 stx11.sextracker.com127.0.0.1 stx12.sextracker.com127.0.0.1 stx13.sextracker.com127.0.0.1 stx14.sextracker.com127.0.0.1 stx15.sextracker.com127.0.0.1 stxbans.sextracker.com127.0.0.1 webmasters.sextracker.com127.0.0.1 stx.banners.sextracker.com127.0.0.1 wm.banners.sextracker.com127.0
O1 - Hosts: neoffers.com #[Trojan-Downloader.Win32com127.0.0.1 www.customersupporthelp.com127.0.0.1 secure6.platinumbucks.com127.0.0.1 www.platinumbucks.com127.0.0.1 www.searchexpert.com127.0.0.1 www.sexfind.com127.0.0.1 searchforit.com #[eTrust.AdShooter.SearchForIt]127.0.0.1 dl.searchforit.com #[SunBelt.SearchForIt.AdShooter]127.0.0.1 www.searchforit.com #[Adware.Searchforit]127.0.0.1 surfenhance.com127.0.0.1 dl.surfenhance.com #[IE-SpyAd]127.0.0.1 www.surfenhance.com# [Monteg Inc]127.0.0.1 www.thumbsearcher.net #[klikfeed.com]127.0.0.1 www.toolbar4cash.com# [Netdreams P/L]127.0.0.1 www.egoog.com #[IE-SpyAd]127.0.0.1 www.escortsindex.com127.0.0.1 free-popup-killer.com #[TrojanClicker.Win32.VB.bn]127.0.0.1 www.internetpeace.com #[eTrust.Free Popup Killer]# [PayCounter.com, Inc]127.0.0.1 paycounter.com #[Ad-Aware.Tracking Cookie]127.0.0.1 count.paycounter.com #[IE-SpyAd]127.0.0.1 images1.paycounter.com127.0.0.1 in.paycounter.com127.0.0.1 stats.paycounter.com127.0.0.1 www.paycounter.com127.0.0.1 sort.trafficju
O1 - Hosts: .0.0.1 clit16.sextracker.com
O1 - Hosts: 127.0.
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

Close browsers and fix checked. At this point you can install MVPS Hosts file meantioned above if you like.


You're using vulnerable Microsoft Java. Since Microsoft doesn't provide security patches to it it's recommended to remove it and install Sun Java. Instructions here (http://www.helpwithwindows.com/WindowsXP/howto-21.html).


After those steps done, reboot and post a fresh hjt log.

Blade81
2008-07-11, 19:24
Due to inactivity, this thread will now be closed.

Note:If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.