Welcome! Register for a free account (or login) > How does it work?
|
|


Jul 2 2009, 04:41 PM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 18-May 04 Member No.: 7,082 |
It takes about 5 minutes to get the computer to a state where I can use it after I turn it on. Here is the HIJACKTHIS outcome and the STARTUP outcome. Please help...!
Regards, Bill
HJTLog.txt ( 7.84K )
Number of downloads: 4StartupList report, 7/2/2009, 2:12:29 PM StartupList version: 1.52.2 Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE Detected: Windows XP SP3 (WinNT 5.01.2600) Detected: Internet Explorer v7.00 (7.00.6000.16850) * Using default options ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\Nhksrv.exe C:\WINDOWS\System32\drivers\CDAC11BA.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe C:\WINDOWS\system32\LXSUPMON.EXE C:\WINDOWS\DELLMMKB.EXE C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Netropa\OSD.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\UNINST.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE -------------------------------------------------- Listing of startup folders: Shell folders Common Startup: [C:\Documents and Settings\All Users\Start Menu\Programs\Startup] Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run LXSUPMON = C:\WINDOWS\system32\LXSUPMON.EXE RUN DellTouch = C:\WINDOWS\DELLMMKB.EXE AdaptecDirectCD = "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" SunJavaUpdateSched = "C:\Program Files\Java\jre6\bin\jusched.exe" TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background MoneyStartUp = C:\Program Files\Microsoft Money\System\Money Startup.exe ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe swg = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\Run [OptionalComponents] = -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=explorer.exe SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry value not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Enumerating Browser Helper Objects: (no name) - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} SpywareGuard Download Protection - C:\Program Files\ComputerStuff\SpywareGuard\dlprotect.dll - {4A368E80-174F-4872-96B5-0B27DDD11DB2} (no name) - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7} (no name) - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} (no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9} JQSIEStartDetectorImpl - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -------------------------------------------------- Enumerating Download Program Files: [symsupportutil] CODEBASE = https://www-secure.symantec.com/techsupp/ac...supportutil.CAB OSD = C:\WINDOWS\Downloaded Program Files\OSD4A.OSD [SysProWmi Class] InProcServer32 = C:\WINDOWS\System32\Dell\SystemProfiler\SysPro.ocx CODEBASE = http://support.dell.com/us/en/systemprofiler/SysPro.CAB [Windows Genuine Advantage Validation Tool] InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll CODEBASE = http://download.microsoft.com/download/3/9...heckControl.cab [Office Update Installation Engine] InProcServer32 = C:\WINDOWS\opuc.dll CODEBASE = http://office.microsoft.com/officeupdate/content/opuc.cab [WUWebControl Class] InProcServer32 = C:\WINDOWS\system32\wuweb.dll CODEBASE = http://update.microsoft.com/windowsupdate/...b?1120916851465 [Symantec Download Manager] InProcServer32 = C:\WINDOWS\Downloaded Program Files\symdlmgr.dll CODEBASE = https://webdl.symantec.com/activex/symdlmgr.cab [MUWebControl Class] InProcServer32 = C:\WINDOWS\system32\muweb.dll CODEBASE = http://update.microsoft.com/microsoftupdat...b?1126293569703 [{74C861A1-D548-4916-BC8A-FDE92EDFF62C}] CODEBASE = http://mediaplayer.walmart.com/installer/install.cab [{9F1C11AA-197B-4942-BA54-47A8489BB47F}] CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/...7635.7755671296 [Shockwave Flash Object] InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx CODEBASE = http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab -------------------------------------------------- Enumerating Windows NT logon/logoff scripts: *No scripts set to run* Windows NT checkdisk command: BootExecute = autocheck autochk * Windows NT 'Wininit.ini': PendingFileRenameOperations: C:\Config.Msi\18f2cf.rbf||C:\Config.Msi\18f2d0.rbf||C:\Config.Msi\18f2d1.rbf||C:\Config.Msi\18f2d2.rbf||C:\Config.Msi\18f2d4.rbf -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\system32\webcheck.dll SysTray: C:\WINDOWS\System32\stobject.dll WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll -------------------------------------------------- End of report, 7,825 bytes Report generated in 0.170 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only This post has been edited by appleoddity: Jul 2 2009, 06:30 PM
Reason for edit: Removed HJT - see attached.
|
|
|
|
![]() |
Jul 2 2009, 06:34 PM
Post
#2
|
|
![]() SuperMember Group: Tech Team Posts: 1,941 Joined: 7-January 09 From: Flint, Michigan Member No.: 83,485 Operating System: Windows XP, Server 2003/2008, Linux |
Hi Krbybng.
I have removed your main HiJackThis log and have rolled it up as an attachment. We don't usually use, nor request HJT logs in the Windows support forum. Instead, we leave these up to the malware removal experts to analyze. If we do need or want anything from HiJackThis we will request it from you. And, even then, it must always be an attachment and not a copy and paste to the forum. We don't want google indexing hijackthis logs in the windows support forum because it is primarily a malware removal tool and is used only in the malware removal forum. Please do not post any more HJT logs unless requested to do so by a helper. We have many other tools at our disposal that usually provide comparable or better information for us to offer you quality assistance. Thanks, and good luck with getting your issue resolved. |
|
|
|
krbybng Dreadfully Slow Startup Jul 2 2009, 04:41 PM
maco Hello There. You could try this to aid with faster... Jul 11 2009, 10:31 AM
Ztruker Delays of that magnitude are almost always network... Jul 11 2009, 08:51 PM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
13 | Amebeo | 206 | Yesterday, 08:39 PM Last post by: inzanity |
|||
![]() |
0 | Sparkey2372 | 22 | Yesterday, 02:13 PM Last post by: Sparkey2372 |
|||
![]() |
17 | mojomojo | 311 | Yesterday, 10:28 AM Last post by: ken545 |
|||
![]() |
0 | thunder420 | 19 | Yesterday, 08:54 AM Last post by: thunder420 |
|||
|
Time is now: 19th March 2010 - 05:36 AM |