Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Is this A Virus? Or is My Comp Just Being Mean?


  • Please log in to reply

#31
noahdfear

noahdfear

    Malware Expert

  • Expert
  • 1,316 posts
  • MVP
Delete the following files in bold.

C:\WINDOWS\System32\70TOVMTO.INI
C:\WINDOWS\System32\BLN02NQV.INI
C:\WINDOWS\System32\GAH95ON6.INI
C:\WINDOWS\tasks\Symantec NetDetect.job

If you don't see the .job, open a command window by clicking Start>run and typing cmd, hit enter. Type or copy and paste the following line.

attrib -r -h -s C:\WINDOWS\tasks\*.*

Hit enter. Refresh the C:\Windows\tasks folder and you should now see it.

We're going to shut down some un-needed services and disable them from starting up.
Click Start>run and type services.msc then hit enter. In the services window, locate each of the following services, right click and choose properties. If started, click stop and when stopped, set to disabled, then click apply and ok. If not running, set to disabled and apply.

Fast User Switching Compatibility
Super Ad Blocker Service
Task Scheduler
Wireless Zero Configuration


The Super Ad Blocker Service is missing a filepath so it won't work anyway. We're going to delete that one. Click Start>run and type or paste the following command.

sc delete SABSVC

Hit enter.

Reboot and see how things are.

If still slow, did you notice if it slowed after the installation of some software, such as Zone Alarm?

I would also like you to copy the command (including quotes) below and paste it to the run box, then hit enter.

regedit.exe /e c:\policies.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall"

Open C:\policies.txt and post it's contents.
  • 0

Advertisements


#32
Omnifire

Omnifire

    Member

  • Topic Starter
  • Member
  • PipPip
  • 38 posts
I did notice that it started after ZoneAlarm, or perhaps Thunderbird... anyway, i cna't find policies.txt (even using search funtcion) is this my fault?
  • 0

#33
noahdfear

noahdfear

    Malware Expert

  • Expert
  • 1,316 posts
  • MVP
The inability to find policies.txt suggests the registry key does not exist. Nothing you're doing wrong. I was looking for it as a possible reason for some services being disabled that really shouldn't be. Please go back into services.msc and set the startup type of the following three services to Automatic, click apply and OK. Reboot and post a new getservices log please (delete the previous log before running).

You can certainly try uninstalling Zone Alarm to see if it is the slow boot cause, but until we know that the XP firewall is working, I suggest some extra precautions be taken should you decide to uninstall it. Download another firewall, such as Sygate or Kerio. Available here. Physically disconnect your computer from it's internet connection, then uninstall ZA. Reboot and install the new firewall, reboot and re-connect to the internet.
  • 0

#34
Omnifire

Omnifire

    Member

  • Topic Starter
  • Member
  • PipPip
  • 38 posts
Well, Zone Alarm was innocnet, as was firebird, as was an abundance of roms i have hoarded over the years. I was at my wit's end long ago, don't tell me you're stumped!!
  • 0

#35
noahdfear

noahdfear

    Malware Expert

  • Expert
  • 1,316 posts
  • MVP
Sorry for the delay......have had a very busy few days.

Locate the file C:\Windows\Ntbtlog.txt and delete it. Click Start\run and type msconfig then hit enter. On the boot.ini tab, check the box next to /bootlog. Click OK and allow you computer to restart. Open Ntbtlog.txt and post it's contents. You can uncheck /bootlog now.

I would also like for you to scan with Panda ActiveScan, save the report and post it here.

Is slow booting the only issue?
  • 0

#36
Omnifire

Omnifire

    Member

  • Topic Starter
  • Member
  • PipPip
  • 38 posts
Here it is. The panda scan won't give me a log, it's just stuck on the 100% downloaded stage..advice?

Service Pack 2 8 10 2005 18:27:27.500
Loaded driver \WINDOWS\system32\ntoskrnl.exe
Loaded driver \WINDOWS\system32\hal.dll
Loaded driver \WINDOWS\system32\KDCOM.DLL
Loaded driver \WINDOWS\system32\BOOTVID.dll
Loaded driver ACPI.sys
Loaded driver \WINDOWS\System32\DRIVERS\WMILIB.SYS
Loaded driver pci.sys
Loaded driver isapnp.sys
Loaded driver pciide.sys
Loaded driver \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
Loaded driver MountMgr.sys
Loaded driver ftdisk.sys
Loaded driver PartMgr.sys
Loaded driver VolSnap.sys
Loaded driver atapi.sys
Loaded driver disk.sys
Loaded driver \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
Loaded driver sr.sys
Loaded driver PxHelp20.sys
Loaded driver drvmcdb.sys
Loaded driver KSecDD.sys
Loaded driver Ntfs.sys
Loaded driver NDIS.sys
Loaded driver Mup.sys
Loaded driver \SystemRoot\System32\DRIVERS\processr.sys
Loaded driver \SystemRoot\System32\DRIVERS\ialmnt5.sys
Loaded driver \SystemRoot\System32\DRIVERS\usbuhci.sys
Loaded driver \SystemRoot\System32\DRIVERS\usbehci.sys
Loaded driver \SystemRoot\System32\DRIVERS\HSFHWBS2.sys
Loaded driver \SystemRoot\System32\DRIVERS\HSF_DP.sys
Loaded driver \SystemRoot\System32\DRIVERS\HSF_CNXT.sys
Loaded driver \SystemRoot\System32\Drivers\Modem.SYS
Loaded driver \SystemRoot\System32\DRIVERS\bcm4sbxp.sys
Loaded driver \SystemRoot\System32\DRIVERS\fdc.sys
Loaded driver \SystemRoot\System32\DRIVERS\i8042prt.sys
Loaded driver \SystemRoot\System32\DRIVERS\kbdclass.sys
Loaded driver \SystemRoot\System32\DRIVERS\L8042mou.Sys
Loaded driver \SystemRoot\System32\DRIVERS\LMouKE.Sys
Loaded driver \SystemRoot\System32\DRIVERS\mouclass.sys
Loaded driver \SystemRoot\System32\DRIVERS\serial.sys
Loaded driver \SystemRoot\System32\DRIVERS\serenum.sys
Loaded driver \SystemRoot\System32\DRIVERS\parport.sys
Loaded driver \SystemRoot\System32\Drivers\cdrbsvsd.SYS
Loaded driver \SystemRoot\System32\DRIVERS\imapi.sys
Loaded driver \SystemRoot\system32\drivers\sscdbhk5.sys
Loaded driver \SystemRoot\System32\Drivers\MxlW2k.SYS
Loaded driver \SystemRoot\System32\DRIVERS\cdrom.sys
Loaded driver \SystemRoot\System32\DRIVERS\redbook.sys
Loaded driver \SystemRoot\system32\drivers\smwdm.sys
Loaded driver \SystemRoot\system32\drivers\aeaudio.sys
Loaded driver \SystemRoot\System32\DRIVERS\audstub.sys
Loaded driver \SystemRoot\System32\DRIVERS\rasl2tp.sys
Loaded driver \SystemRoot\System32\DRIVERS\ndistapi.sys
Loaded driver \SystemRoot\System32\DRIVERS\ndiswan.sys
Loaded driver \SystemRoot\System32\DRIVERS\raspppoe.sys
Loaded driver \SystemRoot\System32\DRIVERS\raspptp.sys
Loaded driver \SystemRoot\System32\DRIVERS\msgpc.sys
Loaded driver \SystemRoot\System32\DRIVERS\psched.sys
Loaded driver \SystemRoot\System32\DRIVERS\ptilink.sys
Loaded driver \SystemRoot\System32\DRIVERS\raspti.sys
Loaded driver \SystemRoot\System32\DRIVERS\termdd.sys
Loaded driver \SystemRoot\System32\DRIVERS\swenum.sys
Loaded driver \SystemRoot\System32\DRIVERS\update.sys
Loaded driver \SystemRoot\System32\DRIVERS\omci.sys
Did not load driver \SystemRoot\System32\DRIVERS\mssmbios.sys
Loaded driver \SystemRoot\System32\Drivers\NDProxy.SYS
Did not load driver \SystemRoot\System32\Drivers\NDProxy.SYS
Loaded driver \SystemRoot\system32\drivers\ialmkchw.sys
Loaded driver \SystemRoot\system32\drivers\ialmsbw.sys
Loaded driver \SystemRoot\System32\DRIVERS\usbhub.sys
Did not load driver \SystemRoot\System32\Drivers\lbrtfdc.SYS
Did not load driver \SystemRoot\System32\Drivers\Sfloppy.SYS
Loaded driver \SystemRoot\System32\Drivers\i2omgmt.SYS
Did not load driver \SystemRoot\System32\Drivers\Changer.SYS
Did not load driver \SystemRoot\System32\Drivers\Cdaudio.SYS
Loaded driver \SystemRoot\System32\Drivers\Fs_Rec.SYS
Loaded driver \SystemRoot\System32\Drivers\Null.SYS
Loaded driver \SystemRoot\System32\Drivers\Beep.SYS
Loaded driver \SystemRoot\system32\drivers\ssrtln.sys
Loaded driver \SystemRoot\System32\drivers\vga.sys
Loaded driver \SystemRoot\System32\Drivers\mnmdd.SYS
Loaded driver \SystemRoot\System32\DRIVERS\RDPCDD.sys
Loaded driver \SystemRoot\system32\drivers\fwdrv.sys
Loaded driver \SystemRoot\System32\Drivers\Msfs.SYS
Loaded driver \SystemRoot\System32\Drivers\Npfs.SYS
Loaded driver \SystemRoot\System32\DRIVERS\rasacd.sys
Loaded driver \SystemRoot\System32\DRIVERS\ipsec.sys
Loaded driver \SystemRoot\System32\DRIVERS\tcpip.sys
Loaded driver \SystemRoot\System32\DRIVERS\netbt.sys
Loaded driver \SystemRoot\System32\drivers\afd.sys
Loaded driver \SystemRoot\System32\DRIVERS\netbios.sys
Did not load driver \SystemRoot\System32\DRIVERS\p3.sys
Did not load driver \SystemRoot\System32\Drivers\PCIDump.SYS
Loaded driver \SystemRoot\System32\DRIVERS\rdbss.sys
Loaded driver \SystemRoot\System32\DRIVERS\mrxsmb.sys
Loaded driver \SystemRoot\system32\drivers\khips.sys
Loaded driver \SystemRoot\System32\Drivers\Fips.SYS
Loaded driver \SystemRoot\System32\DRIVERS\NetMotCM.sys
Loaded driver \SystemRoot\System32\Drivers\Cdfs.SYS
Loaded driver \SystemRoot\system32\drivers\drvnddm.sys
Loaded driver \SystemRoot\system32\dla\tfsndres.sys
Loaded driver \SystemRoot\system32\dla\tfsnifs.sys
Loaded driver \SystemRoot\system32\dla\tfsnopio.sys
Loaded driver \SystemRoot\system32\dla\tfsnpool.sys
Loaded driver \SystemRoot\system32\dla\tfsnboio.sys
Loaded driver \SystemRoot\system32\dla\tfsncofs.sys
Loaded driver \SystemRoot\system32\dla\tfsndrct.sys
Loaded driver \SystemRoot\system32\dla\tfsnudf.sys
Loaded driver \SystemRoot\system32\dla\tfsnudfa.sys
Loaded driver \SystemRoot\System32\DRIVERS\wanarp.sys
Did not load driver \SystemRoot\System32\DRIVERS\rdbss.sys
Did not load driver \SystemRoot\System32\DRIVERS\mrxsmb.sys
Loaded driver \SystemRoot\System32\DRIVERS\mrxdav.sys
Loaded driver \SystemRoot\System32\Drivers\ParVdm.SYS
Loaded driver \SystemRoot\System32\DRIVERS\mdmxsdk.sys
Loaded driver \SystemRoot\System32\DRIVERS\secdrv.sys
Loaded driver \??\C:\WINDOWS\System32\SVKP.sys
Loaded driver \SystemRoot\System32\DRIVERS\srv.sys
Loaded driver \??\C:\Program Files\AVPersonal\AVGNTDW.SYS
Loaded driver \SystemRoot\system32\drivers\sysaudio.sys
Loaded driver \SystemRoot\system32\drivers\splitter.sys
Loaded driver \SystemRoot\system32\drivers\aec.sys
Loaded driver \SystemRoot\system32\drivers\swmidi.sys
Loaded driver \SystemRoot\system32\drivers\DMusic.sys
Loaded driver \SystemRoot\system32\drivers\kmixer.sys
Loaded driver \SystemRoot\system32\drivers\drmkaud.sys
Loaded driver \SystemRoot\system32\drivers\wdmaud.sys
Did not load driver \SystemRoot\System32\Drivers\HTTP.sys
Loaded driver \??\C:\DOCUME~1\Zak\LOCALS~1\Temp\mc27.tmp
Loaded driver \SystemRoot\system32\drivers\kmixer.sys
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP