Forum Home
Press F1
 
Thread ID: 70767 2006-07-15 10:34:00 HJT Help Please (...again) roddy_boy (4115) Press F1
Post ID Timestamp Content User
471114 2006-07-15 10:34:00 Hai all,

Trying to sort out my parent's computer, it's constantly running slowly, and freezes up sometimes. I've just taken off Norton IS '06, and installed NOD32, but this hasn't helped much so far. Don't know what else to do to speed things up, it may just be because they only have 256MB of RAM and are running XP.
If someone could take a look at the HJT log and tell me what I can safely kill without losing functionality on the printer, etc, it would be much appreciated.

Cheers,

roddy

Logfile of HijackThis v1.99.1
Scan saved at 9:26:57 p.m., on 15/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\WINDOWS\SYSTEM32\Brmfrmps.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Eset\nod32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\Roderick\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [SA] C:\Program Files\Logitech\QuickCam\SA3.EXE
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - housecall60.trendmicro.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - go.microsoft.com
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\SYSTEM32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
roddy_boy (4115)
471115 2006-07-15 18:58:00 Im not sure about HJT I cant see anything in there although speedy seems very good and would spot things I won't, but I am not surprised it runs slowly with only 256 ram and all the processes running. My pc uses more then that at idle with all the security and junk we like in our taskbars :) MORE RAM!!!!!! ram is cheap and an effective way to speed up the pc
(that doesnt mean you shouldnt be doing disk cleanup and defrag tho)

in re processes, I would be looking at getting skype, paper port I dont know about dlg tho
straitjacket (9698)
471116 2006-07-15 21:06:00 Hmm yup, log looks ok to me.

Some more ram would definitely help.

And some kind of firewall besides XP's.

And a defrag, if u havent defragged recently.
Speedy Gonzales (78)
471117 2006-07-15 21:26:00 looks clean to me also
Just one comment I would stop skype from running at startup, when you need it use the desktop shortcut.
Check msconfig (startup tab) for un-needed startup items, also start >> programs >> startup folder

Also right click on My Computer choose properties choose advanced tab click on settings under the performance heading select option "adjust for best performance"You will lose some visual effects using this.

You could also reduce the hardware accelation in the video card properties to free up some ram but this is a desperate measure.
beama (111)
471118 2006-07-16 07:42:00 Cheers guys, it's my old lady's computer so leaving skype running at startup so i can get in touch with her more easily :p
I'll get some more RAM for it next time I'm up north, and yes I have defragged it recently.

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
Is apparently some HP thing, anyone know what it's for.

Cheers for the help everyone :)
roddy_boy (4115)
471119 2006-07-16 07:47:00 Cheers guys, it's my old lady's computer so leaving skype running at startup so i can get in touch with her more easily :p
I'll get some more RAM for it next time I'm up north, and yes I have defragged it recently.

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
Is apparently some HP thing, anyone know what it's for.

Cheers for the help everyone :)

It's something to do with the cd burning software.

It may not work, if u delete this entry.
Speedy Gonzales (78)
1