Slow Start up and program initiation

edited November 2009 in Spyware & Virus Removal
Windows XP, I have been experiencing slow start up and program initiation. Unsure if it is due to Secunia PSI is activated and checking for updates.

Comments

  • edited October 2009
    actually i have the same problem with my laptop and PC both have Windows XP and office
  • edited November 2009
    Hello, sorry for the late reply.

    If you still need help,
    A few things before we start....
    1. Please Read All Instructions Carefully.
    2. If you don't understand something, stop and ask! Don't keep going on.
    3. Please do not run any other tools or scans whilst I am helping you.
    4. If you have to go away for an extended period of time, let me know.
    5. Please continue to respond until I give you the "All Clear".
    (Just because you can't see a problem doesn't mean it isn't there)



    Please download Malwarebytes' Anti-Malware by clicking the link below:
    Malwarebytes Anti-Malware - Reviews and free Malwarebytes Anti-Malware downloads at Download.com

    Double Click mbam-setup.exe to install the application.

    * Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select "Perform Quick Scan", then click Scan.
    * The scan may take some time to finish,so please be patient.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Make sure that everything is checked, and click Remove Selected.
    * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    * You'll be required to post the contents of this log later.

    Please Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.



    Next let's have you download ComboFix.exe. Please visit this webpage for downloading and instructions for running the tool:

    Go here ======> A guide and tutorial on using ComboFix <====== Go here

    Please ensure you read this guide carefully and install the Recovery Console first.This applies to XP Pro and XP Home users only.If you have SP3 installed you will need to use the download meant for SP2.

    The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    Once installed, you should get a prompt that says:

    The Recovery Console was successfully installed.

    Please continue as follows:

    (1) Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    (2) Click Yes to allow ComboFix to continue scanning for malware.

    When the tool is finished, it will produce a report for you.


    Please include MBAM log and C:\ComboFix.txt for further review, so that we may continue cleansing the system.


    Caution: Never run and remove files with Combofix unless supervised by a qualified security analyst who is experienced in the use of Combofix. Misuse can cause serious computer problems.
  • edited November 2009
    Hi

    I could get combofix torun on my laptop but it didnt appear to run on my tower. downloded ok began but never scanned.

    here is the log for my laptop

    Malwarebytes' Anti-Malware 1.40
    Database version: 2551
    Windows 5.1.2600 Service Pack 3
    20/10/2009 4:57:35 PM
    mbam-log-2009-10-20 (16-57-34).txt
    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 185944
    Time elapsed: 1 hour(s), 30 minute(s), 22 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    (No malicious items detected)
    Registry Values Infected:
    (No malicious items detected)
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    (No malicious items detected)

    ComboFix 09-11-01.04 - Kevin 02/11/2009 21:35.1.1 - FAT32x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.212 [GMT 10.5:30]
    Running from: c:\documents and settings\Kevin\Desktop\ComboFix.exe
    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
    .
    ((((((((((((((((((((((((( Files Created from 2009-10-02 to 2009-11-02 )))))))))))))))))))))))))))))))
    .
    2009-10-23 07:48 . 2009-10-23 07:48
    d
    w- c:\program files\CCleaner
    2009-10-19 11:41 . 2009-10-19 11:41
    d
    w- c:\documents and settings\Ellen\Application Data\Malwarebytes
    2009-10-19 11:31 . 2009-10-19 11:31
    d-sh--w- c:\documents and settings\Ellen\IECompatCache
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-10-17 23:20 . 2008-02-15 06:01 65040 ----a-w- c:\documents and settings\Ellen\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-09-11 14:18 . 2004-08-03 18:30 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-04 21:03 . 2004-08-03 18:30 58880 ----a-w- c:\windows\system32\msasn1.dll
    2009-09-02 07:29 . 2009-08-02 08:24 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2009-08-29 08:08 . 2004-08-03 18:30 916480 ----a-w- c:\windows\system32\wininet.dll
    2009-08-26 08:00 . 2004-08-03 18:30 247326
    w- c:\windows\system32\strmdll.dll
    2009-08-25 08:42 . 2006-09-21 21:35 65040 ----a-w- c:\documents and settings\Jade\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-08-23 03:21 . 2009-05-18 10:42 11952 ----a-w- c:\windows\system32\avgrsstx.dll
    2009-08-23 03:21 . 2009-05-18 10:42 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
    2009-08-23 03:20 . 2009-05-18 10:42 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2009-08-18 09:50 . 2008-12-30 12:13 411368 ----a-w- c:\windows\system32\deploytk.dll
    2009-08-06 08:54 . 2004-08-03 18:30 327896 ----a-w- c:\windows\system32\wucltui.dll
    2009-08-06 08:54 . 2004-08-03 18:30 209632 ----a-w- c:\windows\system32\wuweb.dll
    2009-08-06 08:54 . 2005-05-25 17:46 44768 ----a-w- c:\windows\system32\wups2.dll
    2009-08-06 08:54 . 2004-08-03 18:30 35552 ----a-w- c:\windows\system32\wups.dll
    2009-08-06 08:54 . 2004-08-03 18:30 53472 ----a-w- c:\windows\system32\wuauclt.exe
    2009-08-06 08:54 . 2004-08-03 18:30 96480 ----a-w- c:\windows\system32\cdm.dll
    2009-08-06 08:53 . 2004-08-03 18:30 575704 ----a-w- c:\windows\system32\wuapi.dll
    2009-08-06 08:53 . 2006-11-20 00:35 274288 ----a-w- c:\windows\system32\mucltui.dll
    2009-08-06 08:53 . 2005-05-25 17:49 215920 ----a-w- c:\windows\system32\muweb.dll
    2009-08-06 08:53 . 2004-08-03 18:30 1929952 ----a-w- c:\windows\system32\wuaueng.dll
    2009-08-05 08:01 . 2004-08-03 18:30 204800
    w- c:\windows\system32\mswebdvd.dll
    2009-08-04 14:20 . 2004-08-03 18:30 2066048
    w- c:\windows\system32\ntkrnlpa.exe
    2007-07-08 03:53 . 2007-07-08 03:53 5 --sha-w- c:\windows\system32\cbdbad6_g.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-14 68856]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "preload"="c:\windows\RUNXMLPL.exe" [2005-05-19 32768]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-04 102490]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-04 708698]
    "EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-10-26 212992]
    "ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-10-26 2889728]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
    "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
    "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
    "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
    "PCMService"="c:\program files\Arcade\PCMService.exe" [2005-03-09 49152]
    "LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
    "PowerKey"="c:\program files\Launch Manager\PowerKey.exe" [2002-08-30 94208]
    "LManager"="c:\program files\Launch Manager\HotkeyApp.exe" [2005-06-06 69632]
    "CtrlVol"="c:\program files\Launch Manager\CtrlVol.exe" [2003-09-16 20480]
    "LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2005-07-25 241664]
    "Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2005-07-25 81920]
    "eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2005-10-31 385024]
    "AirPort Base Station Agent"="c:\program files\AirPort\APAgent.exe" [2008-05-20 737280]
    "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-19 2025752]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-18 149280]
    "SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2007-04-16 577536]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
    2009-08-23 03:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
    @=&quot;"
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
    @=&quot;"
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "d:\\Swimming\\Meet Manager\\SwimMM2.exe"=
    "c:\\WINDOWS\\System32\\ftp.exe"=
    "c:\\Program Files\\AirPort\\APAgent.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "5353:UDP"= 5353:UDP:Bonjour
    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2/08/2009 6:54 PM 206256]
    R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2/08/2009 8:36 PM 51488]
    R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2/08/2009 8:36 PM 39200]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [18/05/2009 9:12 PM 335240]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [18/05/2009 9:12 PM 108552]
    R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2/08/2009 6:54 PM 159600]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [18/05/2009 9:12 PM 297752]
    R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [16/05/2009 2:31 PM 55152]
    R3 POWERKEY;POWERKEY;c:\program files\Launch Manager\POWERKEY.SYS [16/09/2006 1:39 PM 2343]
    S1 mailKmd;mailKmd; [x]
    S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [6/02/2009 6:08 PM 533360]
    S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2/08/2009 6:53 PM 64392]
    S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2/08/2009 6:53 PM 348752]
    S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2/08/2009 8:36 PM 33056]
    S3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]
    --- Other Services/Drivers In Memory ---
    *NewlyCreated* - INT15.SYS
    *NewlyCreated* - MBR
    *NewlyCreated* - PROCEXP113
    *Deregistered* - mbr
    *Deregistered* - PROCEXP113
    .
    Contents of the 'Scheduled Tasks' folder
    2009-11-02 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-07-14 23:18]
    2009-05-28 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:04]
    .
    .
    Supplementary Scan
    .
    uStart Page = hxxp://www.google.com.au/
    uInternet Settings,ProxyOverride = *.local
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
    FF - ProfilePath - c:\documents and settings\Kevin\Application Data\Mozilla\Firefox\Profiles\jgckhx8o.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.foxsports.com.au/
    FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
    FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
    FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
    FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
    FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
    FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
    FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    .
    - - - - ORPHANS REMOVED - - - -
    URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
    Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)

    **************************************************************************
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-11-02 21:44
    Windows 5.1.2600 Service Pack 3 FAT NTAPI
    scanning hidden processes ...
    scanning hidden autostart entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    .
    DLLs Loaded Under Running Processes
    - - - - - - - > 'lsass.exe'(620)
    c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
    - - - - - - - > 'explorer.exe'(428)
    c:\windows\system32\WININET.dll
    c:\program files\CyberLink\Shared Files\CLRCEngine.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    c:\program files\Malwarebytes' Anti-Malware\mbamext.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
    c:\progra~1\MICROS~2\OFFICE11\MCPS.DLL
    .
    Completion time: 2009-11-02 21:46
    ComboFix-quarantined-files.txt 2009-11-02 11:16
    Pre-Run: 3,000,614,912 bytes free
    Post-Run: 3,384,262,656 bytes free
    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect
    - - End Of File - - 9799ACD26FF25CC04ECB03C341151A96
  • edited November 2009
    Please visit Virustotal
    • Click the Browse.. button
    • Navigate to the file c:\windows\system32\cbdbad6_g.dll
    • Click the Open button
    • Click the Send button
    • Copy and paste the results into a new reply in this thread please.
    If VirusTotal is busy please use Jotti
  • edited November 2009
    Problem, Cant find any cbd file
  • edited November 2009
    Follow the instructions here to show all hidden files and folders:
    http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/tips/hiddenfiles.mspx

    Then locate the cbdbad6_g.dll file again and upload it to VirusTotal/Jotti.
  • edited November 2009
    Tried that and still no show, any other suggestions?
  • edited November 2009
    OK let's have you go HERE to run Panda ActiveScan 2.0
    • Click the big green Scan now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • Once the scan is completed, please hit the notepad icon next to the text Export to:
    • Save it to a convenient location such as your Desktop
    • Post the contents of the ActiveScan.txt in your next reply, along with a new ComboFix log.
  • edited November 2009
    Will do
  • edited November 2009
    Now i have a major problem - ran the panda and then the combofix. now on start up it just keeps rebooting and wont go any further than the black startup screens.
This discussion has been closed.