WIndows starting boot up is extremely slow.
Also the computer functions very very slow when 3-4 windows/operation are OPEN.
Its pathetically slow....drags most of the times
RAM-128
celeron 533
10 Gb HDD - 1.5 GB FREE
HEre's
1)hijack log.
2)Start up log fileyo man
Logfile of HijackThis v1.98.2
Scan saved at 4:38:10 PM, on 10/9/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
d:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
d:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\Explorer.EXE
C:\Documents and Settings\Bhaumik\Desktop\msnmsgr.exe
C:\Documents and Settings\Bhaumik\Desktop\FreeRAM XP Pro 1.40.exe
D:\Program Files\IceXpress\icexpress.exe
D:\Program Files\YahooPOPs\YahooPOPs.exe
C:\WINNT\System32\svchost.exe
D:\Program Files\IceNet Dialer\DialIce.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
D:\Downloads\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sify.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\msdownld.tmp\AS604C34.tmp\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = http=127.0.0.1:5400
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.d ll
O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - D:\Program Files\IceXpress\PBHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.d ll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [msnmsgr] "C:\Documents and Settings\Bhaumik\Desktop\msnmsgr.exe" /background
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Documents and Settings\Bhaumik\Desktop\FreeRAM XP Pro 1.40.exe" -win
O4 - Startup: YahooPOPs.lnk = D:\Program Files\YahooPOPs\YahooPOPs.exe
O4 - Global Startup: IceXpress-5 times faster Internet.lnk = D:\Program Files\IceXpress\icexpress.exe
O8 - Extra context menu item: Download using LeechGet - file://D:\LeechGet 2003\\AddUrl.html
O8 - Extra context menu item: Download using LeechGet Wizard - file://D:\LeechGet 2003\\Wizard.html
O8 - Extra context menu item: Parse with LeechGet - file://D:\LeechGet 2003\\Parser.html
O8 - Extra context menu item: Show All Original Images - res://D:\Program Files\IceXpress\icexpress.exe/250
O8 - Extra context menu item: Show Original Image - res://D:\Program Files\IceXpress\icexpress.exe/227
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yaho...st20040510.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EFA05038-1363-4861-8244-2B32F5A27BD1}: NameServer = 203.88.128.250 203.88.135.250
**********************
StartupList report, 3/1/1999, 1:33:34 AM
StartupList version: 1.52.2
Started from : D:\Downloads\hijackthis.EXE
Detected: Windows 2000 SP4 (WinNT 5.00.2195)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
d:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
d:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\Explorer.EXE
C:\Documents and Settings\Bhaumik\Desktop\msnmsgr.exe
C:\Documents and Settings\Bhaumik\Desktop\FreeRAM XP Pro 1.40.exe
D:\Program Files\IceXpress\icexpress.exe
D:\Program Files\YahooPOPs\YahooPOPs.exe
D:\Program Files\IceNet Dialer\DialIce.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\Program Files\Opera7.1\opera.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\NOTEPAD.EXE
D:\Downloads\hijackthis.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\Bhaumik\Start Menu\Programs\Startup]
YahooPOPs.lnk = D:\Program Files\YahooPOPs\YahooPOPs.exe
Shell folders Common Startup:
[C:\Documents and Settings\All Users.WINNT\Start Menu\Programs\Startup]
IceXpress-5 times faster Internet.lnk = D:\Program Files\IceXpress\icexpress.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINNT\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Synchronization Manager = mobsync.exe /logon
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
msnmsgr = "C:\Documents and Settings\Bhaumik\Desktop\msnmsgr.exe" /background
FreeRAM XP = "C:\Documents and Settings\Bhaumik\Desktop\FreeRAM XP Pro 1.40.exe" -win
--------------------------------------------------
Shell & screensaver key from C:\WINNT\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINNT\system32\ssstars.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_5_0.d ll - {02478D38-C3F9-4efb-9B51-7695ECA05670}
(no name) - D:\Program Files\IceXpress\PBHelper.dll - {4115122B-85FF-4DD3-9515-F075BEDE5EB5}
--------------------------------------------------
Enumerating Download Program Files:
[YInstStarter Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\yinsthelper.dll
CODEBASE = http://us.dl1.yimg.com/download.yaho...st20040510.cab
[HouseCall Control]
InProcServer32 = C:\WINNT\DOWNLO~1\xscan53.ocx
CODEBASE = http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
[Update Class]
InProcServer32 = C:\WINNT\System32\iuctl.dll
CODEBASE = http://v4.windowsupdate.microsoft.co...8121.907974537
[Shockwave Flash Object]
InProcServer32 = C:\WINNT\system32\Flash.ocx
CODEBASE = http://download.macromedia.com/pub/s...sh/swflash.cab
--------------------------------------------------
Enumerating Winsock LSP files:
Protocol #1: D:\PROGRA~1\ICEXPR~1\sliplsp.dll
Protocol #2: D:\PROGRA~1\ICEXPR~1\sliplsp.dll
Protocol #3: D:\PROGRA~1\ICEXPR~1\sliplsp.dll
Protocol #17: D:\PROGRA~1\ICEXPR~1\sliplsp.dll
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
Network.ConnectionTray: C:\WINNT\system32\NETSHELL.dll
WebCheck: C:\WINNT\system32\webcheck.dll
SysTray: stobject.dll
--------------------------------------------------
End of report, 5,209 bytes
Report generated in 3.435 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
HEre's 1)hijack log. 2)Start up log file


