wcw7398 Posted January 29, 2004 Report Share Posted January 29, 2004 I use Windows ME and recently spent quite a lot of time removing viruses, and adware from my computer. Everything seemes fine execpt now my curser is jerky and the little hour glass flashes constatly, indicating that the processor is working or busy. I wonder if maybe something got deleted that shouldn't have in my "cleanup" effort. Thanks in advance for any help you can offer. Quote Link to comment Share on other sites More sharing options...
nellie2 Posted January 29, 2004 Report Share Posted January 29, 2004 what tools did you use to do your clean up?? If your mouse is lagging that could be a sign that something is working overtime, what programs have you got running in task manager? Quote Link to comment Share on other sites More sharing options...
wcw7398 Posted January 29, 2004 Author Report Share Posted January 29, 2004 I used bazooka adware scanner and then followed the intructions for removing the offending material. I also am using Norton Antivirus. Norton is the only thing running. I used regcleaner to clean up my register. Something is obviously working my little machine harder than it was. Its an older laptop with a pentium ll processor. Maybe norton has it bogged down? Quote Link to comment Share on other sites More sharing options...
nellie2 Posted January 29, 2004 Report Share Posted January 29, 2004 Well Norton is a little heavy on the resources.... You can download hijackthis if you like and post a log. We can look at your running processes and also see if there is anything left after your cleanup that shouldn't be there.http://www.windowsforum.org/support/forum/...?showtopic=6901 Quote Link to comment Share on other sites More sharing options...
wcw7398 Posted January 29, 2004 Author Report Share Posted January 29, 2004 Here's the log from hijack this. Thanks for all your help, I really appreciate it!Logfile of HijackThis v1.97.7Scan saved at 5:23:50 PM, on 1/29/2004Platform: Windows ME (Win9x 4.90.3000)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\SYSTEM\MPREXE.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXEC:\WINDOWS\SYSTEM\MSTASK.EXEC:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXEC:\WINDOWS\SYSTEM\SPOOL32.EXEC:\WINDOWS\EXPLORER.EXEC:\WINDOWS\SYSTEM\PSTORES.EXEC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\WINDOWS\SYSTEM\WMIEXE.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXEC:\PROGRAM FILES\WINZIP\WINZIP32.EXEC:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXER1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Yahoo!R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = ,R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = ,R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = ,R3 - URLSearchHook: (no name) - _{FD9BC004-8331-4457-B830-4759FF704C22} - (no file)R3 - URLSearchHook: (no name) - _{30192F8D-0958-44E6-B54D-331FD39AC959} - (no file)R3 - URLSearchHook: (no name) - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLLO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)O2 - BHO: (no name) - {CDEB2648-1E33-4E66-BC20-72F6618D1B91} - (no file)O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: (no name) - {D5F82809-C7E5-46D5-8BB5-3CC2BBCFC273} - (no file)O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCXO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dllO4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorunO4 - HKLM\..\Run: [systemTray] SysTray.ExeO4 - HKLM\..\Run: [symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe startO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\RunServices: [scriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -regO4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"O4 - HKLM\..\RunServices: [schedulingAgent] mstask.exeO9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)O9 - Extra button: Sidesearch (HKLM)O13 - WWW. Prefix: http://ehttp.cc/?O14 - IERESET.INF: START_PAGE_URL=http://www.yahoo.comO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cabO16 - DPF: {78A730D4-0DF3-4B65-8DD2-BFCD433CEE30} - http://www.surfsecret.com/inst/DVInstaller.exeO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...7864.3507407407O16 - DPF: {f760cb9e-c60f-4a89-890e-fae8b849493e} - O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} (EPlugin Control) - http://66.230.146.125/EPlugin.cabO16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cabO16 - DPF: {FE1A240F-B247-4E06-A600-30E28F5AF3A0} - http://toolbar2.i-lookup.com/toolbar2/windec32.cabO16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinstc.cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...etup1.0.0.6.cab Quote Link to comment Share on other sites More sharing options...
nellie2 Posted January 29, 2004 Report Share Posted January 29, 2004 I'm afraid you did have some bad stuff left :( Make sure all browsers and windows are closed except for hijackthis, put a check against the following and click 'fix checked'R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = ,R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = ,R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = ,R3 - URLSearchHook: (no name) - _{FD9BC004-8331-4457-B830-4759FF704C22} - (no file)R3 - URLSearchHook: (no name) - _{30192F8D-0958-44E6-B54D-331FD39AC959} - (no file)R3 - URLSearchHook: (no name) - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)O2 - BHO: (no name) - {CDEB2648-1E33-4E66-BC20-72F6618D1B91} - (no file)O3 - Toolbar: (no name) - {D5F82809-C7E5-46D5-8BB5-3CC2BBCFC273} - (no file)O9 - Extra button: Sidesearch (HKLM)O13 - WWW. Prefix: http://ehttp.cc/?O16 - DPF: {f760cb9e-c60f-4a89-890e-fae8b849493e} - O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} (EPlugin Control) - http://66.230.146.125/EPlugin.cabO16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cabO16 - DPF: {FE1A240F-B247-4E06-A600-30E28F5AF3A0} - http://toolbar2.i-lookup.com/toolbar2/windec32.cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...etup1.0.0.6.cabReboot and post a fresh log for a check over, I have to go now but if no one else gets to it first I will give your new log a check over tomorrow!!Bye for now and :welcome: Quote Link to comment Share on other sites More sharing options...
wcw7398 Posted January 30, 2004 Author Report Share Posted January 30, 2004 This is the log after fixing the items you suggested. It should be noted that I had to do it twice. After the first "fix" nothing changed, that is to say all of the lines were still there when I scanned it afterwards. Any my cursor is still herky-jerky, and yes, I have disabled the Norton program. I should mention that when I first boot my machine it behaves just fine for a few minutes, but then goes sour after say, mmmmmmmm about 3 or 4 minutes. Veerrry frustrating indeed!C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\MPREXE.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXEC:\WINDOWS\SYSTEM\MSTASK.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXEC:\WINDOWS\EXPLORER.EXEC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXEC:\WINDOWS\SYSTEM\WMIEXE.EXEC:\WINDOWS\PROFILES\JAYHAWK\DESKTOP\HIJACKTHIS.EXER1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Yahoo!O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLLO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCXO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dllO4 - HKLM\..\Run: [scanRegistry] C:\WINDOWS\scanregw.exe /autorunO4 - HKLM\..\Run: [systemTray] SysTray.ExeO4 - HKLM\..\Run: [symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe startO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\RunServices: [scriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -regO4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"O4 - HKLM\..\RunServices: [schedulingAgent] mstask.exeO9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)O14 - IERESET.INF: START_PAGE_URL=http://www.yahoo.comO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cabO16 - DPF: {78A730D4-0DF3-4B65-8DD2-BFCD433CEE30} - http://www.surfsecret.com/inst/DVInstaller.exeO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...7864.3507407407O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinstc.cab Quote Link to comment Share on other sites More sharing options...
mark2 Posted January 30, 2004 Report Share Posted January 30, 2004 You can have Hijackthis fix this last one, but I doubt it is causing you problems now.After your clean up have you defragged or run disc clean up ?What do you have disabled using msconfig ?Did you have Norton prior to the slowdown ? Quote Link to comment Share on other sites More sharing options...
wcw7398 Posted January 30, 2004 Author Report Share Posted January 30, 2004 In your post you said I can have Hijack fix this one. What specifically?Disabled with msconfig are the following: SchedulingAgent, LoadPowerProfile, *Statemgr, (what is this?), Microsoft Office Start Up, run= (this points to win.ini scvinit.exe)I did not have Norton prior to slowdown, however many things where changed and or deleted after I got Norton, so the addition of Norton is certainly not conclusively the cause. In addition Norton is disabled and the still the problem persists.I have run defrag within the last day or so. Not familiar with “disc clean up”. Quote Link to comment Share on other sites More sharing options...
Guest Lived Backwards Posted January 30, 2004 Report Share Posted January 30, 2004 Disc Clean Up....Start>All Programs>Accessories>System Tools>disc Cleanup. Quote Link to comment Share on other sites More sharing options...
nellie2 Posted January 30, 2004 Report Share Posted January 30, 2004 *Statemgr is the Windows ME default for System Restore. I suggest you re-enable that one ASAP!!!Also I think it would be a good idea to uninstall Norton and use a nice free antivirus.Why not go here and have a look at the free AV mentioned, either Avast or AVG are just as good as each other and don't hog your resources like Norton does.http://www.windowsforum.org/support/forum/...?showtopic=3702Dunno what Mark2 was on about :huh: perhaps he forgot his marbles or something!!!! :D :D Quote Link to comment Share on other sites More sharing options...
mark2 Posted January 30, 2004 Report Share Posted January 30, 2004 Should have put this in my post ! :D :D O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)I was just about to leave when I posted (without checking, short of time) Quote Link to comment Share on other sites More sharing options...
wcw7398 Posted January 30, 2004 Author Report Share Posted January 30, 2004 All done, same crap.... Gettin' bored, need a paperweight? Quote Link to comment Share on other sites More sharing options...
mark2 Posted January 30, 2004 Report Share Posted January 30, 2004 Nothing obvious shows in your log now, it MAY be worth trying Process Explorer fromhttp://www.sysinternals.com/ntw2k/freeware/procexp.shtml to identify the processes using up the CPU and resources Quote Link to comment Share on other sites More sharing options...
wcw7398 Posted January 30, 2004 Author Report Share Posted January 30, 2004 Avast found wuauboot.exe but it isn't apparent how I get rid of it. I don't see any options or tools within the program to do this. Am I just missing it? Quote Link to comment Share on other sites More sharing options...
mark2 Posted January 30, 2004 Report Share Posted January 30, 2004 Windows Update Critical Update Notification. This will appear in your Task List if you did a Windows Update at some stage and installed the "Critical Update Notification" component. Do not walk, run to your "Add/Remove Programs" icon in the Control Panel and immediately uninstall Microsoft Windows Critical Updates Notification. Recommendation : It is best that you simply do a Windows Update once every two or three months, say, and only at times when you do not require your PC urgently in the following 24 hours! Finally, quite aside from the above, WUCRTUPD is also sometimes responsible for illegal operations, 3-seconds mouse freezes, WULOADER error messages, and Invalid Page Faults in KERNEL32. Have we said enoughDoes the above look familiar ??from a reply at http://www.annoyances.org/exec/forum/winme/t1045326829a link to http://www.answersthatwork.com/Tasklist_pages/tasklist.htm Quote Link to comment Share on other sites More sharing options...
wcw7398 Posted January 30, 2004 Author Report Share Posted January 30, 2004 Luckily, I don't show window critical updates as an option for removal. I know the dang thing is hidding in there somewhere, but I can't find it. Quote Link to comment Share on other sites More sharing options...
wcw7398 Posted January 30, 2004 Author Report Share Posted January 30, 2004 I may have found it! It seems to be behaving, at least for the moment. Thanks for all your help. You guys are lifesavers. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.