Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 30

Thread: Infected or malware--slow startup, System Restore inoperative

  1. #11
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    It looks like you have these items disabled or unchecked in msconfig

    msconfig\startupreg\hpqSRMon]
    You might try checking it and see if its related to the printer error your seeing.


    Enable this one also and see if it helps your connection
    msconfig\startupreg\Broadcom Wireless Manager UI
    How Can I Reduce My Risk?

  2. #12
    Junior Member
    Join Date
    Jun 2013
    Posts
    19

    Default

    Quote Originally Posted by shelf life View Post
    It looks like you have these items disabled or unchecked in msconfig

    msconfig\startupreg\hpqSRMon]
    You might try checking it and see if its related to the printer error your seeing.


    Enable this one also and see if it helps your connection
    msconfig\startupreg\Broadcom Wireless Manager UI
    Okay, here's what's happening. I entered msconfig and checked the hpq box. When I hit "Okay" I got a message that access was denied, because I don't have administrator privileges. My friend who helped me earlier said I shouldn't be getting this command, that it might be malware wanting to prevent my accessing msconfig. However, when I rebooted the item remained checked.

    I couldn't find the Broadcom Wireless Manager n the startup list. I use XP, if that's any help to locate it.

    Startup remains about 5 minutes long. However, I have three users listed, and if I stay on the user screen for a minute the icons come up much faster, but the wireless and cable connection icons still take about two minutes.

    Sorry to be such a bother! Dan

  3. #13
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    Malwarebytes will fix things malware might do like a disabled task manager or being unable to make registry changes. Not seeing any malware. Lets get another download which is similar to adwcleaner. Make sure all the toolbar garbage is gone. You might also try resetting IE back to its defaults. IE>tools>Internet Options>Advanced tab> Reset.

    Download RogueKiller.exe
    Quit all programs that you may have started.
    Please disconnect any USB or external drives from the computer before you run this scan!
    For Vista or Windows 7, right-click and select "Run as Administrator to start"
    For Windows XP, double-click to start.
    Wait until the Prescan has finished
    Then Click on "Scan" button
    Wait until the Status box shows "Scan Finished"
    click on "delete"
    Wait until the Status box shows "Deleting Finished"
    Click on "Report" and copy/paste the content of the Notepad into your next reply.
    The log should be found in RKreport[1].txt on your Desktop
    Exit by File>Quit

    long time for the internet icon
    Is this the MS network icon or some other softwares icon like your wireless card?
    How Can I Reduce My Risk?

  4. #14
    Junior Member
    Join Date
    Jun 2013
    Posts
    19

    Default RogueKiller Log 3-16-13

    RogueKiller V8.5.2 [Mar 9 2013] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : http://www.geekstogo.com/forum/files...3-roguekiller/
    Website : http://tigzy.geekstogo.com/roguekiller.php
    Blog : http://tigzyrk.blogspot.com/

    Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
    Started in : Normal mode
    User : Dan Kamin [Admin rights]
    Mode : Remove -- Date : 07/10/2013 22:10:33
    | ARK || FAK || MBR |

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 4 ¤¤¤
    [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> DELETED
    [HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
    [HJ DESK] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [LOADED] ¤¤¤
    SSDT[12] : NtAlertResumeThread @ 0x805D4C0C -> HOOKED (Unknown @ 0x8A3A0530)
    SSDT[13] : NtAlertThread @ 0x805D4BBC -> HOOKED (Unknown @ 0x8A1FBD68)
    SSDT[17] : NtAllocateVirtualMemory @ 0x805A8AEE -> HOOKED (Unknown @ 0x89F8B270)
    SSDT[19] : NtAssignProcessToJobObject @ 0x805D66D0 -> HOOKED (Unknown @ 0x8A5DB5C8)
    SSDT[31] : NtConnectPort @ 0x805A4604 -> HOOKED (Unknown @ 0x8A33C098)
    SSDT[43] : NtCreateMutant @ 0x80617822 -> HOOKED (Unknown @ 0x8A297630)
    SSDT[52] : NtCreateSymbolicLinkObject @ 0x805C3A2E -> HOOKED (Unknown @ 0x8A3C6418)
    SSDT[53] : NtCreateThread @ 0x805D1068 -> HOOKED (Unknown @ 0x89FB54B8)
    SSDT[57] : NtDebugActiveProcess @ 0x80643CB2 -> HOOKED (Unknown @ 0x89E50750)
    SSDT[68] : NtDuplicateObject @ 0x805BE03C -> HOOKED (Unknown @ 0x89F91268)
    SSDT[83] : NtFreeVirtualMemory @ 0x805B2FE6 -> HOOKED (Unknown @ 0x8A1E7538)
    SSDT[89] : NtImpersonateAnonymousToken @ 0x805F9362 -> HOOKED (Unknown @ 0x8A1B6B60)
    SSDT[91] : NtImpersonateThread @ 0x805D7890 -> HOOKED (Unknown @ 0x89E82A88)
    SSDT[97] : NtLoadDriver @ 0x80584172 -> HOOKED (Unknown @ 0x8A369108)
    SSDT[108] : NtMapViewOfSection @ 0x805B206E -> HOOKED (Unknown @ 0x8A2DC590)
    SSDT[114] : NtOpenEvent @ 0x8060F1E0 -> HOOKED (Unknown @ 0x8A1FD2D0)
    SSDT[122] : NtOpenProcess @ 0x805CB486 -> HOOKED (Unknown @ 0x8A1EFA38)
    SSDT[123] : NtOpenProcessToken @ 0x805EE030 -> HOOKED (Unknown @ 0x8A219260)
    SSDT[125] : NtOpenSection @ 0x805AA420 -> HOOKED (Unknown @ 0x8A03DD20)
    SSDT[128] : NtOpenThread @ 0x805CB712 -> HOOKED (Unknown @ 0x8A1EF9F0)
    SSDT[137] : NtProtectVirtualMemory @ 0x805B8452 -> HOOKED (Unknown @ 0x8A5DB4F8)
    SSDT[206] : NtResumeThread @ 0x805D4A48 -> HOOKED (Unknown @ 0x89FFD1D8)
    SSDT[213] : NtSetContextThread @ 0x805D2C4A -> HOOKED (Unknown @ 0x89F8F288)
    SSDT[228] : NtSetInformationProcess @ 0x805CDED0 -> HOOKED (Unknown @ 0x8A25A278)
    SSDT[240] : NtSetSystemInformation @ 0x8060FE98 -> HOOKED (Unknown @ 0x8A189D08)
    SSDT[253] : NtSuspendProcess @ 0x805D4B10 -> HOOKED (Unknown @ 0x8A1FD1F0)
    SSDT[254] : NtSuspendThread @ 0x805D4982 -> HOOKED (Unknown @ 0x89FFD298)
    SSDT[257] : NtTerminateProcess @ 0x805D2308 -> HOOKED (Unknown @ 0x89EF6208)
    SSDT[258] : NtTerminateThread @ 0x805D2502 -> HOOKED (Unknown @ 0x8A19DE10)
    SSDT[267] : NtUnmapViewOfSection @ 0x805B2E7C -> HOOKED (Unknown @ 0x89F8C2D0)
    SSDT[277] : NtWriteVirtualMemory @ 0x805B4400 -> HOOKED (Unknown @ 0x8A2367B0)
    S_SSDT[307] : NtUserAttachThreadInput -> HOOKED (Unknown @ 0x8A3CCBF8)
    S_SSDT[383] : NtUserGetAsyncKeyState -> HOOKED (Unknown @ 0x8A3C5200)
    S_SSDT[414] : NtUserGetKeyboardState -> HOOKED (Unknown @ 0x8A3C6950)
    S_SSDT[416] : NtUserGetKeyState -> HOOKED (Unknown @ 0x8A3C2598)
    S_SSDT[428] : NtUserGetRawInputData -> HOOKED (Unknown @ 0x8A3E0E38)
    S_SSDT[460] : NtUserMessageCall -> HOOKED (Unknown @ 0x8A188778)
    S_SSDT[475] : NtUserPostMessage -> HOOKED (Unknown @ 0x8A3E4618)
    S_SSDT[476] : NtUserPostThreadMessage -> HOOKED (Unknown @ 0x8A293850)
    S_SSDT[549] : NtUserSetWindowsHookEx -> HOOKED (Unknown @ 0x8A3CFA60)
    S_SSDT[552] : NtUserSetWinEventHook -> HOOKED (Unknown @ 0x8A369AC8)

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\WINDOWS\system32\drivers\etc\hosts

    127.0.0.1 localhost


    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: ST9160314AS +++++
    --- User ---
    [MBR] 735558283eb882d10429f4baef6de194
    [BSP] 2f3e1d68fd4dad25f7b87b4131285341 : Windows XP MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 152625 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[2]_D_07102013_02d2210.txt >>
    RKreport[1]_S_07102013_02d2209.txt ; RKreport[2]_D_07102013_02d2210.txt

  5. #15
    Junior Member
    Join Date
    Jun 2013
    Posts
    19

    Default

    Is this the MS network icon or some other softwares icon like your wireless card?[/QUOTE]

    It's the two computer screen icons, one for the Wireless Network Connection and one for Local Area Connection/Network Cable (I use Verizon Wifi and not cable plug in at home)

  6. #16
    Junior Member
    Join Date
    Jun 2013
    Posts
    19

    Default Docking station

    By the way, I usually dock my computer and use external keyboard and screen at home. I took it out for this cleanup. Let me know if you'd like me to keep it out during any of the procedures we are doing. Thanks, Dan

  7. #17
    Junior Member
    Join Date
    Jun 2013
    Posts
    19

    Default msconfig

    Just tried changing an item on the msconfigure startup tab and got the same Access denied message. However, as I mentioned, it did let me check the HP Printer item before, and retains that change.

  8. #18
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    Try booting into safe mode and chose the option: safe mode with networking.
    to reach safe mode tap the f8 key during a computer restart, chose the safe mode with networking option. Log into your normal account.
    See if the networking services start up faster in safe mode then they do in normal mode. To get back to normal mode just reboot your machine like you normally would. You can keep the laptop out of the docking station.
    How Can I Reduce My Risk?

  9. #19
    Junior Member
    Join Date
    Jun 2013
    Posts
    19

    Default

    Quote Originally Posted by shelf life View Post
    Try booting into safe mode and chose the option: safe mode with networking.
    to reach safe mode tap the f8 key during a computer restart, chose the safe mode with networking option. Log into your normal account.
    See if the networking services start up faster in safe mode then they do in normal mode. To get back to normal mode just reboot your machine like you normally would. You can keep the laptop out of the docking station.
    Okay, this might have given us some clues. Here's what happened.

    1) All desktop icons came up quickly
    2) All my quick launch icons on the left of the toolbar came up quickly as well, but NONE of the icons on the right side of the taskbar came up--neither of the network icons, the indexing icon, the volume icon, the remove hardware icon, or the Norton icon;
    3) Nevertheless, when I started Firefox, my default browser, it came right up and connected to the internet
    4) Microsoft Outlet came up much more quickly than it usually does; HOWEVER, a second screen labelled Office 2010 came up on top, and a message saying that it was making connections or something--sorry, can't remember, FOLLOWED BY an error message saying that I it couldn't find a license for Office 2010, that the repair was cancelled by the user or the program, and that it was going to shut down the program. I use Office 2000 however, and this has never come up before when I open Outlook 2010. My copies of Outlook and Office are legal. I wonder if an incompatibility between the programs is causing the delayed startup.

  10. #20
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    Your #4 observation is possible. Also I would make sure you have the latest driver for your NIC, based on the make and model of your machine. You only want to get it from the HP website, no where else. HP site also has good troubleshooting sections for various problems.

    I want to check out the items under the driver section of Roguekiller. It dosnt mean malware, could be your AV. We will get a tool from Malwarebytes to use as one more check.

    Download the beta version of Malwarebytes Anti-rootkit to your desktop.
    Read the Disclaimer since this is a Beta version

    http://www.malwarebytes.org/products/mbar/

    Download Malwarebytes Anti-Rootkit from the link to the right.
    Unzip the contents to a folder in a convenient location.
    Open the folder where the contents were unzipped and run mbar.exe
    Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
    Click on the Cleanup button to remove any threats and reboot if prompted to do so.
    Wait while the system shuts down and the cleanup process is performed.
    Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
    If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:

    Internet access
    Windows Update
    Windows Firewall

    If there are additional problems with your system, such as any of those listed above or other system issues, then run the 'fixdamage' tool included with Malwarebytes Anti-Rootkit and reboot.
    Verify that your system is now functioning normally.

    Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
    Copy and paste the contents of these two log files in your next reply.
    How Can I Reduce My Risk?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •