Thanks
Windows XP start up slow
#1
Posted 27 November 2006 - 10:25 PM
Thanks
#2
Posted 27 November 2006 - 11:45 PM
click Start-
click run
type: msconfig
uncheck things that you dont need at start up and it should make the boot up process faster
#3
Posted 28 November 2006 - 10:36 PM
Look them up here
http://www.sysinfo.org/startuplist.php
#4
Posted 30 November 2006 - 09:30 PM
#5
Guest_rushin1nd_*
Posted 30 November 2006 - 09:42 PM
#6
Posted 02 December 2006 - 06:49 AM
#7
Posted 03 December 2006 - 03:06 PM
I just deleted it off the add\remove software on the control panel. I didnt run the uninstall like I should. When I run spybot it finds it in the registry but cant delete it. Whenever I start up my pc windows keeps trying to install it again and I have to keep deleting the intallation window. It just gets annoying is all.what steps did you take to remove spyware remover
#8
Guest_rushin1nd_*
Posted 03 December 2006 - 05:36 PM
before you begin to navigate to spyware program in the registry make a back-up first
start>>regedit>>ok
create back-up>>>click on file when registry opens
click export
when you have option to save name as reg2006
save to my documents...click save
---------------------------------------------------------------------------------------------------
if something goes wrong then you can use reg2006 to merge back in as backup
now if your still in the registry then navigate to the following and delete the spyware remover folder
if your not in registry then from start>>type in regedit>>click ok
---------------------------------------------------------------------------------------------------
go to HKEY_CURRENT_USER/Software
look for spyware remover folder then delete
----------------------------------------------------
then look in HKEY_LOCAL_MACHINE/SOFTWARE
look for spyware folder and then delete
--------------------------------------------------------
then look in HKEY_USERS/S-1-5-21-4089584507-2448793096-2622062187-1009
then look for spyware folder and delete
-----------------------------------------------------
after your done all of that ..only takes a few minutes
then open my computer and look in c:drive open it and look in program files look to see if spyware remover has a folder if it does the delete it
to double check to see if spyware remover is uninstall or removed then do a search from your start >>search>>all files and folders>>type in spyware remover ...if any shows up then try to open where it is
if you cant just delete right there
=====================================================================================================================================
This a method i use to remove drive cleaner from registry
drive cleaner is nothing but popups bad malware
+++++++++++++++++++++++++++++++++++++++
it will work for removing your spyware program from registry
Edited by rushin1nd, 03 December 2006 - 05:38 PM.
#9
Posted 05 December 2006 - 10:29 AM
Microsoft.Windows.Security.InternetExplorer: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1065397860-3967216430-2567981340-1005\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\iexplore.exe!=W=1
BPS Spyware Remover: Shared DLL (1 apps) (Registry value, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\BulletProofSoft.com\SpywareRemover\Spyware.exe
BPS Spyware Remover: Shared DLL (1 apps) (Registry value, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\BulletProofSoft.com\SpywareRemover\scripten-WIN2000.exe
BPS Spyware Remover: Shared DLL (1 apps) (Registry value, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\BulletProofSoft.com\SpywareRemover\scr56en-Win98-me-nt4.exe
BPS Spyware Remover: Shared DLL (1 apps) (Registry value, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\PopUpWatch.exe
This is what comes up when I run spybot. Ive gone to the registry and deleted it but it returns every time I reboot. I cant find it anywhere else. Any ideas?
Thanks
REMOVING SPYWARE REMOVER FROM THE REGISTRY
before you begin to navigate to spyware program in the registry make a back-up first
start>>regedit>>ok
create back-up>>>click on file when registry opens
click export
when you have option to save name as reg2006
save to my documents...click save
---------------------------------------------------------------------------------------------------
if something goes wrong then you can use reg2006 to merge back in as backup
now if your still in the registry then navigate to the following and delete the spyware remover folder
if your not in registry then from start>>type in regedit>>click ok
---------------------------------------------------------------------------------------------------
go to HKEY_CURRENT_USER/Software
look for spyware remover folder then delete
----------------------------------------------------
then look in HKEY_LOCAL_MACHINE/SOFTWARE
look for spyware folder and then delete
--------------------------------------------------------
then look in HKEY_USERS/S-1-5-21-4089584507-2448793096-2622062187-1009
then look for spyware folder and delete
-----------------------------------------------------
after your done all of that ..only takes a few minutes
then open my computer and look in c:drive open it and look in program files look to see if spyware remover has a folder if it does the delete it
to double check to see if spyware remover is uninstall or removed then do a search from your start >>search>>all files and folders>>type in spyware remover ...if any shows up then try to open where it is
if you cant just delete right there
=====================================================================================================================================
This a method i use to remove drive cleaner from registry
drive cleaner is nothing but popups bad malware
+++++++++++++++++++++++++++++++++++++++
it will work for removing your spyware program from registry
#10
Guest_rushin1nd_*
Posted 05 December 2006 - 10:33 AM
#11
Posted 05 December 2006 - 10:47 AM
did you or can you navigate your way to the registry to locate spyware remover
Yes, what I posted in Hkey\local machine is what I have deleted in the past and it just comes back every time I reboot.
#12
Guest_rushin1nd_*
Posted 05 December 2006 - 10:49 AM
look in program files for spyware remover folder delete it
recheck your registry go back to hKEY_LOCAL_MACHINE.. it may have reattach itself you may have missed something its a simple thing but im going ask for help
Make sure Read only mode is disabled in Options menu.
that may have something to do with it
also check HKEY_CURRENT_USERS
HKEY_USERS
#13
Guest_rushin1nd_*
Posted 05 December 2006 - 12:25 PM
i dont believe its malware
but it does manage your bho>>===> BROWSER HELPER OBJECTS
Features:
Friendly interface allows to perform the following operations:
Scans for almost all SpyWare components out there today!
Easy to use (just one click of a mouse)
Scans Running processes (Memory), Registry, Fixed, and removable drives.
Backup and restore removed items.
Multi-Language Support
Ignore List (Found items can be ignored)
Also features BHO Manager
Also features Startup Manager
Registered users get at least 1 year of free upgrades.
What's New in the last version ?
The fastest scanning techniques in the market.
New amazing easy-to-navigate interface
New results design shows all properties of each detected threat.
A wide range of actions to perform with detected threats.
Manage the infected lists so you can take an action later without performing
a new scan.
Quarantine and restore detected spyware.
A set of scan options so you can highly customize the program.
Instant description (help) for each item in the program. .
A System-Wide Real-time system protection.
Stops spyware programs before they can run.
Monitors the favorite's items and blocks any unwanted additions.
Shreds the detected spyware threats files and folders.
Scans all user accounts.
Protects the Hosts file from modifications
Protects the system from malicious LSP Modules
Monitors the running services
Monitors the ActiveX Installations in Microsoft® Internet Explorer®
Monitors the IE toolbars installations
Manages the LSP modules installed in your system
Manages the startup entries in your system.
Manages the Browser Helper Objects in your system
Manages the Hosts file entries
Manages IE Toolbars
Immediately suspend the detected malicious processes
if it shows then we will try one more way to remove without using highjack tool
#14
Posted 05 December 2006 - 12:36 PM
Logfile of HijackThis v1.99.1
Scan saved at 10:34:47 AM, on 12/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Zoom\Modem Status\ZoomCableModemStatus.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\Explorer.EXE
C:\unzipped\hijackthis[1]\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Zoom Cable Monitor.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....015/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1158880257328
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15021/CTPID.cab
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.c.../zoomify305.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe
can you post a hijack log
i dont believe its malware
but it does manage your bho>>===> BROWSER HELPER OBJECTS
Features:
Friendly interface allows to perform the following operations:
Scans for almost all SpyWare components out there today!
Easy to use (just one click of a mouse)
Scans Running processes (Memory), Registry, Fixed, and removable drives.
Backup and restore removed items.
Multi-Language Support
Ignore List (Found items can be ignored)
Also features BHO Manager
Also features Startup Manager
Registered users get at least 1 year of free upgrades.
What's New in the last version ?
The fastest scanning techniques in the market.
New amazing easy-to-navigate interface
New results design shows all properties of each detected threat.
A wide range of actions to perform with detected threats.
Manage the infected lists so you can take an action later without performing
a new scan.
Quarantine and restore detected spyware.
A set of scan options so you can highly customize the program.
Instant description (help) for each item in the program. .
A System-Wide Real-time system protection.
Stops spyware programs before they can run.
Monitors the favorite's items and blocks any unwanted additions.
Shreds the detected spyware threats files and folders.
Scans all user accounts.
Protects the Hosts file from modifications
Protects the system from malicious LSP Modules
Monitors the running services
Monitors the ActiveX Installations in Microsoft® Internet Explorer®
Monitors the IE toolbars installations
Manages the LSP modules installed in your system
Manages the startup entries in your system.
Manages the Browser Helper Objects in your system
Manages the Hosts file entries
Manages IE Toolbars
Immediately suspend the detected malicious processes
if it shows then we will try one more way to remove without using highjack tool
#15
Posted 05 December 2006 - 01:02 PM
Similar Topics
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users