PDA

View Full Version : Computer very slow to boot



Planes
2011-12-05, 04:37
My computer Panasonic Tough book with windows xp and sp3 is very slow to boot up and when clicking on the task bar takes forever to react

The problem began when I had trouble downloading AVG updates once I got the update to down load the machine has been slow to respond to clicks

The machine runs fine in SAFE Mode

I have run MALWAREBYTES and CClesaner I have also Run defrag also HIJack This has been run I could not find any thing susspisous all before finding Spybot which has been downloaded and run which Identerfied some Threats
which spybot say have been removed
.

DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.6001.18702
Run by Administrator at 12:01:02 on 2011-12-05
.
============== Running Processes ===============
.
C:\Program Files\Panasonic\HPLSMAN\hplsman.exe
C:\Program Files\Panasonic\Disprot\IDRot.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Administrator\Desktop\dds.scr
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot - search & destroy\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {CCAC5586-44D7-4c43-B64A-F042461A97D2} - No File
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [PRONoMgr.exe] c:\program files\intel\prosetwireless\ncs\proset\PRONoMgr.exe
mRun: [NeroCheck.exe] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [NBHGui.exe] c:\program files\nero\nero 7\incd\NBHGui.exe
mRun: [Ltmoh.exe] c:\program files\ltmoh\Ltmoh.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [InCD.exe] c:\program files\nero\nero 7\incd\InCD.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [htcUPCTLoader.exe] "c:\program files\htc\htc sync 3.0\htcUPCTLoader.exe" -startup
mRun: [HPlsKey] c:\program files\panasonic\hplsman\hplskey.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot - search & destroy\SDHelper.dll
Trusted Zone: facebook.com\login
DPF: {304171C0-65EA-4B51-B5D9-93A311E26EB1} - hxxp://123.209.185.222/cgi-bin/MxPEG_ActiveX.cab?dummy=3298460
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 10.129.38.173 10.129.39.177 10.129.39.5
TCP: Interfaces\{55BDAC71-BD37-4C77-901E-317D59951E0A} : DhcpNameServer = 10.129.38.173 10.129.39.177 10.129.39.5
TCP: Interfaces\{678A381A-874C-4E85-B671-DD37BFC9BB01} : DhcpNameServer = 192.168.100.254
TCP: Interfaces\{AEDF0D7A-A885-405A-8D46-76D8811B5B6E} : DhcpNameServer = 192.168.42.129
Notify: HPLSNTF - HPLSNtf.dll
Notify: igfxcui - igfxsrvc.dll
Notify: Sebring - c:\windows\system32\LgNotify.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R? aswFsBlk;aswFsBlk
R? aswSnx;aswSnx
R? aswSP;aswSP
R? avast! Antivirus;avast! Antivirus
R? brecal;Panasonic Battery Recalibration Driver
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? cpudrv;cpudrv
R? cvhsvc;Client Virtualization Handler
R? evserial;Virtual Serial Ports Driver (Eltima Softwate)
R? evserial7;Virtual Serial Ports Driver 7 (Eltima Softwate)
R? FreewavePollingService;FreeWave Polling Service
R? fssfltr;fssfltr
R? fsssvc;Windows Live Family Safety Service
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? HTCAND32;HTC Device Driver
R? htcnprot;HTC NDIS Protocol Driver
R? HW_VSP3s_Service;HW Virtual Serial Port (single)
R? MatSvc;Microsoft Automated Troubleshooting Service
R? MOSUMAC;USB-Ethernet Driver
R? MSSQL$APEX2005;SQL Server (APEX2005)
R? NitroReaderDriverReadSpool;NitroPDFReaderDriverCreatorReadSpool
R? osppsvc;Office Software Protection Platform
R? PassThru Service;Internet Pass-Through Service
R? pcinfo;Panasonic PC Info. Viewer Driver
R? RICOH SmartCard Reader;RICOH SmartCard Reader
R? Sftfs;Sftfs
R? sftlist;Application Virtualization Client
R? Sftplay;Sftplay
R? Sftredir;Sftredir
R? Sftvol;Sftvol
R? sftvsa;Application Virtualization Service Agent
R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0
R? zgwhsdiag;ZTE WCDMA Handset Diagnostic Port
R? zgwhsmdm;ZTE WCDMA Handset USB Modem
R? zgwhsnmea;WCDMA Handset NMEA Port
S? FIDMOU;Fujitsu Takamisawa touchpad
S? HTKPLUS;Panasonic Hotkey PLUS Driver
S? VSBC;Virtual Serial Bus Enumerator (Eltima Software)
S? VSBC7;Virtual Serial Bus Enumerator 7 (Eltima Software)
.
=============== Created Last 30 ================
.
2011-12-04 03:58:09 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-12-04 03:58:09 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-12-03 05:48:19 -------- d-----w- c:\documents and settings\administrator\application data\Windows Search
2011-12-02 05:09:04 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-12-02 05:08:53 41184 ----a-w- c:\windows\avastSS.scr
2011-12-02 05:08:37 -------- d-----w- c:\program files\AVAST Software
2011-12-02 05:08:37 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2011-12-01 06:06:15 22 --sha-w- c:\documents and settings\administrator\application data\Sys2662.Config.Repository.bin
2011-12-01 05:58:07 -------- d-----w- c:\program files\jv16 PowerTools 2011
2011-11-30 22:50:02 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-30 22:50:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-30 10:32:25 -------- d-----w- c:\windows\pss
2011-11-22 01:37:15 -------- d-----w- C:\Koree card
2011-11-15 04:16:49 -------- d-----w- C:\flash drive
2011-11-09 22:57:37 -------- d-----w- c:\windows\system32\cache
.
==================== Find3M ====================
.
2011-12-01 05:27:36 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-01 05:25:37 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-12-01 05:25:37 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 12:42:05 629760 ------w- c:\windows\system32\wpd_ci.dll
2011-09-28 12:42:04 356352 ------w- c:\windows\system32\wpdsp.dll
2011-09-28 12:42:03 38400 ------w- c:\windows\system32\wpdshextres.dll
2011-09-28 12:42:03 17408 ------w- c:\windows\system32\wpdshextautoplay.exe
2011-09-28 12:42:02 63488 ------w- c:\windows\system32\wpdmtpus.dll
2011-09-28 12:42:02 154624 ------w- c:\windows\system32\wpdmtp.dll
2011-09-28 12:42:01 656896 ------w- c:\windows\system32\WMVXENCD.dll
2011-09-28 12:42:01 35840 ------w- c:\windows\system32\wpdconns.dll
2011-09-28 12:42:00 767488 ------w- c:\windows\system32\WMVSENCD.dll
2011-09-28 12:39:48 4096 ------w- c:\windows\system32\MPG4DMOD.dll
2011-09-28 12:24:43 2603008 ------w- c:\windows\system32\WpdShext.dll
2011-09-28 12:24:43 133632 ------w- c:\windows\system32\WPDShServiceObj.dll
2011-09-28 12:24:41 8231936 ----a-w- c:\windows\system32\wmploc.dll
2011-09-28 12:24:39 222208 ----a-w- c:\windows\system32\WMASF.dll
2011-09-28 12:24:38 757248 ----a-w- c:\windows\system32\WMADMOD.dll
2011-09-28 12:24:38 712704 ------w- c:\windows\system32\windowscodecs.dll
2011-09-28 12:24:35 254976 ------w- c:\windows\system32\PortableDeviceApi.dll
2011-09-28 12:24:35 166912 ------w- c:\windows\system32\PortableDeviceTypes.dll
2011-09-28 12:24:30 212992 ------w- c:\windows\system32\MFPLAT.dll
2011-09-28 12:22:29 35328 ----a-w- c:\windows\system32\drivers\pcntpci5.sys
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-28 04:44:31 276992 ------w- c:\windows\system32\audiodev.dll
2011-09-26 01:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 01:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 01:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20:51 1858944 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 12:04:10.86 ===============



I will be very happy for any assistance I can get
Thanks
:confused:

ken545
2011-12-14, 01:12
:snwelcome:


Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.

Until we deem your system clean I am going to ask you not to install or uninstall any software or hardware except for the programs we may run.

Running programs with Vista or Windows 7 , you need to Right Click on the program and select RUN AS ADMINISTATOR


Not sure if your problem is malware related, your talking about AVG updates but I see Avast installed, can you clearify this ?

ken545
2011-12-18, 12:37
Still with us ?

ken545
2011-12-20, 11:15
Due to inactivity, this thread will now be closed.

If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a new DDS log with a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.