Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Windows XP start up slow


  • Please log in to reply

#1
sg555

sg555

    Member

  • Member
  • PipPip
  • 52 posts
My PC is booting up very slow. Im running Windows XP and dont think I have a malware problem. Ive run all the precautions. I did unintstall bps spyware remover some time ago and everytime I boot the pc it keeps trying to re-install it. I cant seem to get rid of it. Im posting a hijack this log and hope someone sees something I dont.
Thanks
  • 0

Advertisements


#2
ultimateslacker2

ultimateslacker2

    Member 1K

  • Retired Staff
  • 1,581 posts
Try doing this

click Start-
click run
type: msconfig
uncheck things that you dont need at start up and it should make the boot up process faster
  • 0

#3
Jack Hackett

Jack Hackett

    Member

  • Member
  • PipPip
  • 39 posts
When you look at whats listed in the Startup list of msconfig you may find it useful to look up what the processes are before making the decision to remove any entries.

Look them up here
http://www.sysinfo.org/startuplist.php
  • 0

#4
sg555

sg555

    Member

  • Topic Starter
  • Member
  • PipPip
  • 52 posts
Thanks for the help. It did speed things up
  • 0

#5
Guest_rushin1nd_*

Guest_rushin1nd_*
  • Guest
what steps did you take to remove spyware remover
  • 0

#6
zbd

zbd

    Member

  • Member
  • PipPipPip
  • 271 posts
This site is great for speeding up your computer. It worked for me. Especially the second group of suggestions. http://computercleanup.blogspot.com/
  • 0

#7
sg555

sg555

    Member

  • Topic Starter
  • Member
  • PipPip
  • 52 posts

what steps did you take to remove spyware remover

I just deleted it off the add\remove software on the control panel. I didnt run the uninstall like I should. When I run spybot it finds it in the registry but cant delete it. Whenever I start up my pc windows keeps trying to install it again and I have to keep deleting the intallation window. It just gets annoying is all.
  • 0

#8
Guest_rushin1nd_*

Guest_rushin1nd_*
  • Guest
REMOVING SPYWARE REMOVER FROM THE REGISTRY

before you begin to navigate to spyware program in the registry make a back-up first

start>>regedit>>ok
create back-up>>>click on file when registry opens
click export
when you have option to save name as reg2006
save to my documents...click save


---------------------------------------------------------------------------------------------------
if something goes wrong then you can use reg2006 to merge back in as backup

now if your still in the registry then navigate to the following and delete the spyware remover folder

if your not in registry then from start>>type in regedit>>click ok
---------------------------------------------------------------------------------------------------

go to HKEY_CURRENT_USER/Software

look for spyware remover folder then delete
----------------------------------------------------
then look in HKEY_LOCAL_MACHINE/SOFTWARE

look for spyware folder and then delete
--------------------------------------------------------
then look in HKEY_USERS/S-1-5-21-4089584507-2448793096-2622062187-1009

then look for spyware folder and delete

-----------------------------------------------------
after your done all of that ..only takes a few minutes

then open my computer and look in c:drive open it and look in program files look to see if spyware remover has a folder if it does the delete it

to double check to see if spyware remover is uninstall or removed then do a search from your start >>search>>all files and folders>>type in spyware remover ...if any shows up then try to open where it is
if you cant just delete right there

=====================================================================================================================================


This a method i use to remove drive cleaner from registry

drive cleaner is nothing but popups bad malware

+++++++++++++++++++++++++++++++++++++++

it will work for removing your spyware program from registry

Edited by rushin1nd, 03 December 2006 - 05:38 PM.

  • 0

#9
sg555

sg555

    Member

  • Topic Starter
  • Member
  • PipPip
  • 52 posts
Hi, The only place I find it is here:
Microsoft.Windows.Security.InternetExplorer: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-1065397860-3967216430-2567981340-1005\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\iexplore.exe!=W=1

BPS Spyware Remover: Shared DLL (1 apps) (Registry value, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\BulletProofSoft.com\SpywareRemover\Spyware.exe

BPS Spyware Remover: Shared DLL (1 apps) (Registry value, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\BulletProofSoft.com\SpywareRemover\scripten-WIN2000.exe

BPS Spyware Remover: Shared DLL (1 apps) (Registry value, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\BulletProofSoft.com\SpywareRemover\scr56en-Win98-me-nt4.exe

BPS Spyware Remover: Shared DLL (1 apps) (Registry value, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\BulletProofSoft.com\SpywareRemover\popup-watch\PopUpWatch.exe
This is what comes up when I run spybot. Ive gone to the registry and deleted it but it returns every time I reboot. I cant find it anywhere else. Any ideas?
Thanks

REMOVING SPYWARE REMOVER FROM THE REGISTRY

before you begin to navigate to spyware program in the registry make a back-up first

start>>regedit>>ok
create back-up>>>click on file when registry opens
click export
when you have option to save name as reg2006
save to my documents...click save


---------------------------------------------------------------------------------------------------
if something goes wrong then you can use reg2006 to merge back in as backup

now if your still in the registry then navigate to the following and delete the spyware remover folder

if your not in registry then from start>>type in regedit>>click ok
---------------------------------------------------------------------------------------------------

go to HKEY_CURRENT_USER/Software

look for spyware remover folder then delete
----------------------------------------------------
then look in HKEY_LOCAL_MACHINE/SOFTWARE

look for spyware folder and then delete
--------------------------------------------------------
then look in HKEY_USERS/S-1-5-21-4089584507-2448793096-2622062187-1009

then look for spyware folder and delete

-----------------------------------------------------
after your done all of that ..only takes a few minutes

then open my computer and look in c:drive open it and look in program files look to see if spyware remover has a folder if it does the delete it

to double check to see if spyware remover is uninstall or removed then do a search from your start >>search>>all files and folders>>type in spyware remover ...if any shows up then try to open where it is
if you cant just delete right there

=====================================================================================================================================


This a method i use to remove drive cleaner from registry

drive cleaner is nothing but popups bad malware

+++++++++++++++++++++++++++++++++++++++

it will work for removing your spyware program from registry


  • 0

#10
Guest_rushin1nd_*

Guest_rushin1nd_*
  • Guest
did you or can you navigate your way to the registry to locate spyware remover
  • 0

Advertisements


#11
sg555

sg555

    Member

  • Topic Starter
  • Member
  • PipPip
  • 52 posts

did you or can you navigate your way to the registry to locate spyware remover


Yes, what I posted in Hkey\local machine is what I have deleted in the past and it just comes back every time I reboot.
  • 0

#12
Guest_rushin1nd_*

Guest_rushin1nd_*
  • Guest
open my computer and open c:drive

look in program files for spyware remover folder delete it

recheck your registry go back to hKEY_LOCAL_MACHINE.. it may have reattach itself you may have missed something its a simple thing but im going ask for help

Make sure Read only mode is disabled in Options menu.

that may have something to do with it

also check HKEY_CURRENT_USERS

HKEY_USERS
  • 0

#13
Guest_rushin1nd_*

Guest_rushin1nd_*
  • Guest
can you post a hijack log

i dont believe its malware

but it does manage your bho>>===> BROWSER HELPER OBJECTS

Features:
Friendly interface allows to perform the following operations:
Scans for almost all SpyWare components out there today!
Easy to use (just one click of a mouse)
Scans Running processes (Memory), Registry, Fixed, and removable drives.
Backup and restore removed items.
Multi-Language Support
Ignore List (Found items can be ignored)
Also features BHO Manager
Also features Startup Manager
Registered users get at least 1 year of free upgrades.

What's New in the last version ?

The fastest scanning techniques in the market.
New amazing easy-to-navigate interface
New results design shows all properties of each detected threat.
A wide range of actions to perform with detected threats.
Manage the infected lists so you can take an action later without performing
a new scan.
Quarantine and restore detected spyware.
A set of scan options so you can highly customize the program.
Instant description (help) for each item in the program. .
A System-Wide Real-time system protection.
Stops spyware programs before they can run.
Monitors the favorite's items and blocks any unwanted additions.
Shreds the detected spyware threats files and folders.
Scans all user accounts.
Protects the Hosts file from modifications
Protects the system from malicious LSP Modules
Monitors the running services
Monitors the ActiveX Installations in Microsoft® Internet Explorer®
Monitors the IE toolbars installations
Manages the LSP modules installed in your system
Manages the startup entries in your system.
Manages the Browser Helper Objects in your system
Manages the Hosts file entries
Manages IE Toolbars

Immediately suspend the detected malicious processes

if it shows then we will try one more way to remove without using highjack tool
  • 0

#14
sg555

sg555

    Member

  • Topic Starter
  • Member
  • PipPip
  • 52 posts
Here is my logfile. I looked every place you suggested and there is no evidence of this other than what I posted earlier.

Logfile of HijackThis v1.99.1
Scan saved at 10:34:47 AM, on 12/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Zoom\Modem Status\ZoomCableModemStatus.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\Explorer.EXE
C:\unzipped\hijackthis[1]\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Zoom Cable Monitor.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....015/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1158880257328
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15021/CTPID.cab
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.c.../zoomify305.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe


can you post a hijack log

i dont believe its malware

but it does manage your bho>>===> BROWSER HELPER OBJECTS

Features:
Friendly interface allows to perform the following operations:
Scans for almost all SpyWare components out there today!
Easy to use (just one click of a mouse)
Scans Running processes (Memory), Registry, Fixed, and removable drives.
Backup and restore removed items.
Multi-Language Support
Ignore List (Found items can be ignored)
Also features BHO Manager
Also features Startup Manager
Registered users get at least 1 year of free upgrades.

What's New in the last version ?

The fastest scanning techniques in the market.
New amazing easy-to-navigate interface
New results design shows all properties of each detected threat.
A wide range of actions to perform with detected threats.
Manage the infected lists so you can take an action later without performing
a new scan.
Quarantine and restore detected spyware.
A set of scan options so you can highly customize the program.
Instant description (help) for each item in the program. .
A System-Wide Real-time system protection.
Stops spyware programs before they can run.
Monitors the favorite's items and blocks any unwanted additions.
Shreds the detected spyware threats files and folders.
Scans all user accounts.
Protects the Hosts file from modifications
Protects the system from malicious LSP Modules
Monitors the running services
Monitors the ActiveX Installations in Microsoft® Internet Explorer®
Monitors the IE toolbars installations
Manages the LSP modules installed in your system
Manages the startup entries in your system.
Manages the Browser Helper Objects in your system
Manages the Hosts file entries
Manages IE Toolbars

Immediately suspend the detected malicious processes

if it shows then we will try one more way to remove without using highjack tool


  • 0

#15
The Skeptic

The Skeptic

    Trusted Tech

  • Technician
  • 4,075 posts
Download Killbox and/or Unlocker. Reinstall the program you want to remove. Use these software removal tools to remove it.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP