PDA

View Full Version : xp machine very slow can't update



brianp
2010-07-26, 15:36
This is my dad's computer, he uses it to surf, read the local paper, email, and play solitaire. It's an old laptop that was never really used. It's XP and I am unable to update the service packs. When I try to open IE, it's VERY slow and usually ends up just closing after a few minutes. Here are the log files.

DDS (Ver_10-03-17.01) - FAT32x86
Run by Sharon at 8:04:47.03 on Mon 07/26/2010
Internet Explorer: 6.0.2800.1106
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.247.55 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
SVCHOST.EXE
SVCHOST.EXE
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\WgaTray.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\techbox\techbox.exe
C:\WINDOWS\System32\wltray.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PVSW\Bin\w3dbsmgr.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\msiexec.exe
F:\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.tribtown.com/
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\System32\browseui.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [MMTray] c:\program files\musicmatch\musicmatch jukebox\mm_tray.exe
mRun: [Tech-In-A-Box] c:\techbox\techbox.exe
mRun: [wltray.exe] c:\windows\system32\wltray.exe
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [gowukirem] Rundll32.exe "c:\windows\system32\dahogemu.dll",a
mRun: [Realtime Monitor] c:\progra~1\ca\etrust~1\realmon.exe -s
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~2.lnk - c:\msoffice\office\FASTBOOT.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pervas~1.lnk - c:\pvsw\bin\w3dbsmgr.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\MSMSGS.EXE
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {32505657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: igfxcui - igfxsrvc.dll
SSODL: yodukereg - {8f8d109b-5365-43a1-bf01-15ba8431b6a9} - c:\windows\system32\dahogemu.dll
STS: jugezatag: {8f8d109b-5365-43a1-bf01-15ba8431b6a9} - c:\windows\system32\dahogemu.dll
LSA: Notification Packages = scecli nobajanu.dll

============= SERVICES / DRIVERS ===============

R3 {5C8B2B62-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-A;c:\windows\system32\drivers\a311.sys [2003-8-23 31287]
R3 {5C8B2B65-A385-11d5-A78B-00104B672758};AIM 3.0 Part 01 Codec Driver CH-7017-B;c:\windows\system32\drivers\a310.sys [2003-8-23 33335]
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;c:\windows\system32\drivers\DP83815.sys [2003-2-12 18392]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [2008-7-7 20480]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [2008-5-9 174336]

=============== Created Last 30 ================

2010-07-23 12:31:03 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-07-23 12:31:03 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-07-22 18:41:05 19776 ----a-w- c:\windows\system32\drivers\ino_flpy.sys
2010-07-22 18:41:05 113728 ----a-w- c:\windows\system32\drivers\ino_fltr.sys
2010-07-22 18:40:47 102 ----a-w- C:\Platform.ini
2010-07-22 18:31:42 0 d-----w- c:\program files\Trend Micro
2010-07-15 16:58:42 71170 ----a-w- c:\docume~1\alluse~1\applic~1\P3W4mp5f.exe
2010-07-15 16:55:25 122880 ----a-w- c:\windows\system32\7YNhX2t1.dll
2010-07-15 16:55:24 112 ----a-w- c:\docume~1\alluse~1\applic~1\hg6DQc4b.dat
2010-07-15 12:29:26 47616 ----a-w- c:\windows\system32\bootopen.dll
2010-07-13 23:27:12 53248 ----a-w- c:\windows\system32\6to4v32.dll

==================== Find3M ====================

2010-07-15 16:52:24 36864 ----a-w- c:\windows\fonts\C5B88.com
2010-06-10 20:01:38 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2010-06-10 20:01:28 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-03-08 13:07:38 99328 --sha-w- c:\windows\system32\ronuruso.dll
2010-02-27 19:31:16 71168 --sha-w- c:\windows\system32\danuzihi.dll
2010-03-07 11:12:52 99328 --sha-w- c:\windows\system32\vidasasa.dll
2010-02-27 19:30:34 71168 --sha-w- c:\windows\system32\wemipipo.dll
2010-03-21 16:05:32 99328 --sha-w- c:\windows\system32\tadagagu.dll
2010-03-22 11:21:36 99840 --sha-w- c:\windows\system32\huverego.dll
2010-03-25 11:35:18 99840 --sha-w- c:\windows\system32\yuhituka.dll
2010-03-28 11:58:26 99328 --sha-w- c:\windows\system32\sohibesi.dll
2010-04-15 11:42:28 100352 --sha-w- c:\windows\system32\dahogemu.dll
2010-04-19 12:06:36 99840 --sha-w- c:\windows\system32\zojoludi.dll
2010-04-20 19:01:58 99840 --sha-w- c:\windows\system32\mavubayi.dll
2010-04-22 15:02:26 99840 --sha-w- c:\windows\system32\jatipife.dll

============= FINISH: 8:06:00.93 ===============

Boot Device: \Device\HarddiskVolume1
Install Date: 12/31/2003 8:00:00 AM
System Uptime: 7/26/2010 8:02:24 AM (0 hours ago)

Motherboard: | |
Processor: Intel(R) Pentium(R) 4 CPU 2.66GHz | CPU 1 | 2664/133mhz

==== Disk Partitions =========================

C: is FIXED (FAT32) - 32 GiB total, 21.173 GiB free.
D: is FIXED (FAT32) - 6 GiB total, 4.206 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 1394 Net Adapter
Device ID: V1394\NIC1394\75514FD130D49
Manufacturer: Microsoft
Name: 1394 Net Adapter
PNP Device ID: V1394\NIC1394\75514FD130D49
Service: NIC1394

==== System Restore Points ===================

RP329: 4/26/2010 7:59:39 AM - System Checkpoint
RP330: 4/28/2010 9:37:08 AM - System Checkpoint
RP331: 4/29/2010 1:00:54 PM - System Checkpoint
RP332: 5/4/2010 8:03:41 AM - System Checkpoint
RP333: 5/5/2010 10:33:24 AM - System Checkpoint
RP334: 5/6/2010 10:37:17 AM - System Checkpoint
RP335: 5/10/2010 11:56:06 AM - System Checkpoint
RP336: 5/12/2010 7:26:59 AM - System Checkpoint
RP337: 5/13/2010 1:27:02 PM - System Checkpoint
RP338: 5/19/2010 12:41:13 PM - System Checkpoint
RP339: 5/20/2010 2:33:40 PM - System Checkpoint
RP340: 5/25/2010 1:45:20 PM - System Checkpoint
RP341: 6/2/2010 7:03:24 AM - System Checkpoint
RP342: 6/4/2010 11:56:19 AM - System Checkpoint
RP343: 6/7/2010 8:39:03 AM - System Checkpoint
RP344: 6/9/2010 6:37:40 AM - System Checkpoint
RP345: 6/9/2010 9:30:13 AM - Software Distribution Service 3.0
RP346: 6/10/2010 9:45:36 AM - System Checkpoint
RP347: 6/10/2010 2:56:55 PM - Installed Windows Installer KB893803v2.
RP348: 6/10/2010 2:57:30 PM - Removed MSXML 6.0 Parser
RP349: 6/10/2010 2:59:32 PM - Removed Microsoft IntelliPoint 6.1
RP350: 6/10/2010 3:01:06 PM - Installed Windows XP Wdf01005.
RP351: 6/14/2010 8:07:12 AM - System Checkpoint
RP352: 6/17/2010 7:41:38 AM - System Checkpoint
RP353: 6/18/2010 11:35:35 AM - System Checkpoint
RP354: 6/22/2010 11:49:28 AM - System Checkpoint
RP355: 6/23/2010 12:04:39 PM - System Checkpoint
RP356: 6/24/2010 12:36:01 PM - System Checkpoint
RP357: 6/25/2010 12:48:10 PM - System Checkpoint
RP358: 6/28/2010 1:53:07 PM - System Checkpoint
RP359: 7/6/2010 7:47:41 AM - System Checkpoint
RP360: 7/8/2010 10:05:31 AM - System Checkpoint
RP361: 7/16/2010 11:54:08 AM - System Checkpoint
RP362: 7/22/2010 1:31:34 PM - Installed HiJackThis
RP363: 7/23/2010 1:34:00 PM - System Checkpoint
RP364: 7/26/2010 7:47:52 AM - System Checkpoint

==== Installed Programs ======================

Adobe Flash Player 10 ActiveX
Adobe Reader 6.0
Belkin Wireless Utility
BusinessWorks Gold - Standard
CA eTrust Antivirus
DP8381x 10/100 PCI Network Adapter Driver
HiJackThis
Intel(R) Extreme Graphics Driver
iPod for Windows User Guide
iPod System Software Updater 2.0.1
Lexmark 640 Series
Microsoft .NET Framework 2.0
Microsoft Application Error Reporting
Microsoft IntelliPoint 7.1
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Office 2000 Professional
Mobile Broadband Generic Drivers
Motorola Handset USB Driver
MSXML 6.0 Parser (KB933579)
MUSICMATCH iPod Plug-in
MUSICMATCH® Jukebox
Pervasive.SQL Workgroup v8.10
Photo Explosion Special Edition
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905495)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB914798)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924496)
Smart Link 56K Modem
Update for Windows XP (KB835409)
Update for Windows XP (KB898461)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
VIA Audio Driver Setup Program
VZAccess Manager for Novatel
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Installer 3.1 (KB893803)
Windows Media Player Hotfix [See wm828026 for more information]
Windows XP Hotfix - KB810217
Windows XP Hotfix - KB821557
Windows XP Hotfix - KB823182
Windows XP Hotfix - KB824105
Windows XP Hotfix - KB824141
Windows XP Hotfix - KB824146
Windows XP Hotfix - KB825119
Windows XP Hotfix - KB828035
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB842773
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892944
Windows XP Hotfix - KB911567
Windows XP Hotfix - KB918439
Windows XP Hotfix - KB918899
Windows XP Hotfix - KB925486

==== Event Viewer Messages From Past Week ========

7/26/2010 3:04:52 AM, error: Service Control Manager [7016] - The SmartLinkService service has reported an invalid current state 0.
7/19/2010 8:47:35 AM, error: Service Control Manager [7000] - The wscsvc service failed to start due to the following error: The executable program that this service is configured to run in does not implement the service.
7/19/2010 8:46:51 AM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
7/19/2010 8:46:51 AM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.

==== End Of File ===========================


Thank you!

Blade81
2010-08-01, 18:06
Hi,

If you still need help with this do the following:

Download GMER (http://www.gmer.net) here by clicking download exe -button and then saving it your desktop:
Double-click .exe that you downloaded
Click rootkit-tab, uncheck files option and then click scan.
Don't check
Show All
box while scanning in progress!
When scanning is ready, click Copy.
This copies log to clipboard
Post log (if the log is long, archive it into a zip file and attach instead of posting) in your reply. Post a fresh dds.txt contents too.

Blade81
2010-08-07, 08:06
Due to inactivity, this thread will now be closed.

Note:If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh DDS log and a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

If it has been less than three days since your last response and you need the thread re-opened, please send me or other MOD a private message (pm). A valid, working link to the closed topic is required.