Ugh Windows xp
Had to make that title an attention getter. heh, Anyway i know im not the only one expiriencing this problem. After xp gets to your desktop after starting up it will set for anywhere from 30secs to 2 mins virtually un usable and after it goes by it loads the rest of your startup programs and folding etc. Has anyone found a fix for this? I have heard sp2 cleared it up but when i installed a leak it fubared my baby so i reinstalled windows, I wasnt gonna leave any traces of it on here.
Dump the contents of your C:\windows\prefetch folder.. Delete everything in there.
//Edit done but to no avail... Anything else? Tried google and did a few things none of which worked..
That should of come before his login screen though. Or at least way before he see's the desktop.
Logfile of HijackThis v1.97.7
Scan saved at 8:41:24 AM, on 2/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\RivaTuner\RivaTuner.exe
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Silicon Image\SiISATARaid\SATARaid.exe
C:\Program Files\Folding@Home\winFAH.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\Program Files\VMware\VMware Workstation\vmware.exe
C:\Program Files\WinMX\WinMX.exe
C:\Program Files\Winamp\Winamp.exe
C:\Program Files\Folding@Home\FahCore_78.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Trevin\Local Settings\Temp\HijackThis.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400"
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner\RivaTuner.exe" /S
O4 - HKLM\..\Run: [RivaTuner] "C:\Program Files\RivaTuner\RivaTuner.exe" /T
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [AIMWDInstallFilename] C:\PROGRA~1\AIM\AIMWDI~1.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Folding@home 4.00.lnk = C:\Program Files\Folding@Home\winFAH.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: SATARaid.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Pool 2 -
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) -
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) -
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} (CTAdjust Class) -
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{CC3A4A86-BF98-4D48-9D75-090D6EDA1E4A}: NameServer =
I'd get rid of the google toolbar.
I wouldn't allow Messenger, Aim, RealPlayer, WinMX or NeroCheck to run at startup. Unless you use them constantly, they'll load fine enough from the start/programs menu. Just my personal preference.
Same with OSA.EXE, this is your MS Office. This does not need to be run at startup. Office apps load fine and with no problems through start/programs. It all comes down to available resources, the less garbage you have loading at startup, the more available you have for applications, and of course, F@H.
If you see any connections "established" using port 6666, 6667 or 6668. (And you are not running an IRC client,) then you may have a trojan.
C:\Program Files\D-Tools\daemon.exe
If you did not install this on your own (ie, to make F@H run as a service) then I'd be very suspicious.
I don't keep it running so I forgot the actual program name. Thx Thrax.
Hmmm, a bit of research found this:
Try that and see what happens.
//Edit forgot to add Sbc.. Not using that flakey sbc ie upgrade **** either.. Raspppoe...
His computers are very similar, since I gave him a list of components and he had a local company build them. The specs on his 3 desktops are:
Antec SX-635 cases w/350w Antec PSUs
MSI KT266A motherboards (one of them has RAID, the other two do not)
AMD Athlon XP 1800/1900 Palomino CPUs
512MB (1x512MB) Samsung PC2100
64MB ABIT GeForce2MX400 AGP video
onboard sound
Netgear FA310TX or FA311 NICs
Intel 56k v.90 modems (which have since been removed from two of the computers)
Maxtor D740x 60GB HDDs
16x Sony DVDs
Iomega Zip100s
24/10/40 TDK CD-RWs (one has a 32/12/40)
The problem that pcscustom is describing has happened on all three systems.
It has also happened on my computers when they've been connected directly to the DSL modem, instead of going through the router.
It's done this on my dual 2500 system, my 2.4GHz P4 laptop, and my NF7-S system.
Running windowsupdate doesn't do anything, either. I have no idea what causes it, only that it drives me insane.
Try disabling the network connection, or enter in in a static IP address temporarily, then unplug the network cable and reboot. See if your system still hangs. If so, it is a lag with your DHCP server, and the best way to avoid it is to use a router.
If the lag does not go away with that test, then disable the workstation service and try rebooting. Then let me know if those things help.
Just a few ideas.
(EDIT: Like Dex' has been saying... he he )
Did you try chagning to an internal static IP temporarily and then unplugging the network? Use
And did you try the disable workstation fix I posted? I found that in a few places, so there may be something to it.
and that is one from the annals of tech gone wrong.
There are very few services you can realisticly disable and not end up shooting your self in the foot if you network and runa wide variety of apps. And even fewer that make a differance in real life.
At least Kanez knew how to fix his problems. Most go the stupid "I had to format the whole thing...." route out of ignornace. And blame it all on "Sorry XP"
Ok my rant is over ... sorry. And no Kanez not a single line was directed at you in any way or form buddy.
I've been a big fan of Black Viper's guide since the day I found it. 90% of the changes did nothing but eliminate unecessary bloat, the other 10% (stuff I needed on that computer) were easily spotted and restored. All I did was print out a list of all of the services and mark changes with "M" for Manual or "D" for Disabled. Ten minutes of tweaking and I was done.
My advice would be that after disabling a service you should check email, Internet, print sharing, local network connections and sharing, plus try your favorite online game to be sure it connects and runs properly. 'Tain't that hard...
I almost threw up.
/me passes the barf bag to Tex
clearly a case of knowing just enough to be dangerous