Extremely Slow Booting Up PC

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hurmund, Mar 10, 2006.

  1. Hurmund

    Hurmund Private E-2

    Hi all.

    Our PC has becoming extremely slow recently, sometimes taking five minutes compared to one minute a few months ago. It became notibly slower round about the time we loaded the Sony Connect software for ripping MP3 tunes. However I uninstalled that, and it is still very slow. So slow sometimes the internet freezes.

    I have tried (after live updating) Norton, Spybot, Adaware to name but a few. But it is still so slow.

    Please, please, please can someone help? It's driving us crazy!!!

    Many thanks,
    Paul

    EDIT: Inline and unrequested HiJackThis log removed
     
    Last edited by a moderator: Mar 10, 2006
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Do you have an iPod plugged into the USB port while booting? if so they are known to slow boot time down.

    Use CCleaner and clear out all the temp files you may have, aslo run its registry cleaner to tidy up the registry as old entries do slow a pc down.

    Check the amount of startup programs you have by using msconfig > startup tab ( to run msconfig click Start > Run and type msconfig > ok ) and disable all but the essential programs and reboot.. is it quicker if so then one by one add the others until you find a culprit that maybe slowing your boot time down.

    DEFRAG!!!

    are you fully upto date with all Windows Updates?

    HijackThis is an advanced tool and doesnt show all spyware/malware up so is not a definative tool to fix all issues that could cause slowdowns on a pc, its only a snall part of the steps to take to diagnose spy/malware so to that end
    and if you do suspect Malware or Spyware then please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis

    if you have any Malware or Spyware listed in the scans then please post a new thread in the Malware forum for help, remembering to attach the logs.
     
  3. tripseven

    tripseven Private First Class

    You might try Trend Micro housecall. It is free, scans your pc for all kinds of "bugs"(viruses etc...). Down side is takes about an hour. Also, you need to have java runtime environment on your pc(its free to download too).
     
  4. tripseven

    tripseven Private First Class

    I also agree with Halo. Besides what Halo says which is spot on;My answer was addressing your mention of your anti virus software. Do everything halo advises FIRST. Then explore trend micro for an extremely thorough scan of your hard drive.
     
  5. Maxwell

    Maxwell Folgers

    Firstly, you need to tell us the specification of your PC. You could try using one of the tools here (e.g.,Belarc: http://majorgeeks.com/download.php?det=1385 Everest: http://majorgeeks.com/download.php?det=4181) to tell us this.

    Secondly, I would follow some simple steps first to tidy up your computer then see if there are problems and solve these. Then finally, tune the performance of the PC.


    -------------------------------------------------------------------------
    Here are some details for these steps and I would recommend making a backup (http://forums.majorgeeks.com/showthread.php?t=27238) of your system before starting in case things go wrong.

    Step 1: Clean your computer:

    There are a number of drive cleaning tools here: http://majorgeeks.com/downloads12.html I would recommend CCleaner: http://majorgeeks.com/CCleaner_d4191.html

    Of course it may be that there is some Malware slowing your computer and following these steps should help you: http://forums.majorgeeks.com/showthread.php?t=35407

    Finally, because of your uninstall (and any other installs/uninstalls that you may have done), it may not necessarily have removed all its entries from the registry and a registry cleaner that makes a backup of your registry. I would suggest using CCleaner to scan for Issues. Examine these carefully to remove those relating to software no longer on your machine.


    Step 2: Check for problems:

    Also here are a number of diagnostic tools. However, I found that PCPitStop has a web based tool to scan and diagnose a number of problems: http://www.pcpitstop.com/ Follow the advise given by their scan tool to eliminate any problems.

    Also, take a look at your devices in the Device Manager accessible from Control Panel/System, check to see if there are any problem devices.


    Step 3: Scan and defragment your hard drive.

    Select your hard drive from My Computer and right-click and select properties. Under tools you should see scan and defragment options.


    Step 4: Fine tune the performance:

    If you are using Windows XP then you could use TuneXP to improve the boot performance: http://majorgeeks.com/download.php?det=4194
     
  6. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Good option tripseven, as its always a good step to use an online AV scan to backup your installed scanner, in case its missed something. ( as a side thought, Housecall now comes in two flavors, Java or ActiveX so if you dont want to install Java you can use the ActiveX version )
     
  7. Hurmund

    Hurmund Private E-2

    Thanks guys. I shall try some of your tips over the weekend. What do you suggest I do first?

    I did post my 'hijack this' log but someone keeps deleting it.

    For your info we are running a Compaq computer on Windows XP:-

    AMD Athlon 64 Processor
    3000+
    2.01GHz
    384 MB of RAM

    Cheers,
    Paul
     
  8. AbbySue

    AbbySue MajorGeeks Administrator

    Hurmund...moving this thread over to the malware forum. Please complete the steps given by Halo in post #2 to make sure your computer is free of malware. Once we know your system is clean, any remaining issues can be addressed in the appropriate forum.
     
  9. Hurmund

    Hurmund Private E-2

    I have ran all the steps Halo told me to referring to the 'sticky'. However my PC is still incredibly slow.

    Todays steps include:-
    0. Unchecked all items in MSCONFIG/STARTUP - still slow.
    1.Uninstalled Logitech Desktop Messenger as per your list.
    2. Ran Norton anti-virus, Ad-Aware and Spybot after updates.
    3. Disabled system restore, restart PC, enable sysyem restore.
    4. Ran malicious software scan.
    5. Ran CCleaner.
    6. Ran BitDefender (log attached).
    7. Ran Spysweeper (log attached).
    8. Ran Hijack.this (log attached).
    9. Unable to run Panda Scan as PC wouldn't download Active-X (tried five times).

    Please can you help further?

    Many thanks,
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions in step 7 of the READ & RUN ME properly. You do not have HijackThis installed correctly. And also you must not use msconfig to control startups while we are trying to resolve possible malware issues. We need to see everything. The directions explain that you must use Normal Startup.

    So install HJT properly, stop using msconfig!!! Do this now before continuing!

    Also empty all files in Norton AntiVirus Quarantine folder.
    Empty Norton Nprotect if used on your system.

    Do you like Norton??? It is a massive resource hog and has been known to cause problems like you are complaining about.

    Do you need AOL to connect to the internet? It is also a big resource hog especially if you allow it to install all of their protection stuff. Also since you already have SpySweeper, you will have extra resource conflicts and the two applications can cause problems for each other.

    Is your version of SpySweeper a paid supscription version?


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://E:\SuperCD\IntraLaunch.CAB

    After clicking Fix, exit HJT.

    Now read the information below and comment on these processes.

    Do you need the below process to load:
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    Do you need the below process to load:
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    Do you need the below process to load:
    O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
    You may want to also stop loading the below osa.exe process since it is a resource hog.
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
     
    Last edited: Mar 12, 2006
  11. Hurmund

    Hurmund Private E-2

    Hi Chaslang,

    As requested, I have stopped using MSCONFIG and returned to the normal settings. I went down this route as recommended by Halo in an earlier message in this thread.

    I have also downloaded HJT properly and have attached a log file in the correct format. I have also deleted all files in the Norton Antivirus Quarantine folder.

    I like Norton as I find it quite user friendly. I have only just bought it so I would prefer to keep it for the moment thanks.

    As far as AOL goes, we need it to connect to the internet. We use the mailbox very frequently and generally like it.

    I downloaded the trial version of Spysweeper as an extra check as part of your alternative scans http://forums.majorgeeks.com/showthread.php?t=80343 (also seeing I couldn't download Panda Active Scan).

    The four items you mention in your last reply I am not bothered about. So if it helps my PC run better, please can you tell me how to get rid of them.

    JUST TO CLARIFY.....the PC is very slow at booting up before it gets to the desktop. You know the screen with the four coloured window and when it says Windows XP and the bar with blue squares mimicking loading? Well it is that stage in particular that is incredibly slow.

    Many thanks again for all your assistance - as always.

    Cheers,
    Paul
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not fix what I gave you in my previous message yet!!! So why did you attach a new log.

    Halo was trying to give you a method to use to eliminate possible causes for your slow startup. Which can be useful as a process of elimination. But what we are now doing is trying to make sure we get rid of all malware first. To do that, we want to see everthing that could load on your system.

    I can understand that, but if what we go thru here to remove any malware and any just unnecessary processes does not help. I will be telling you to uninstall Norton (at least temporarily) to see if it makes a difference. Does your Norton stuff contain a firewall? Is it enabled? Did you disable the WinXP SP2 firewall?

    But you are also using there spyware tools etc which is going to conflict with other tools you have installed and AOL is an even bigger resource hog when you do this. And when you add this to what Norton is doing, it just compounds the problems.

    Uninstall Spy Sweeper now. Doing this will help free up some resource and speed up your startup time.

    Simple! Just have HJT fix the below lines:
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
     
  13. Hurmund

    Hurmund Private E-2

    Many apologies, I thought I had deleted all the items usinf HJT. But it looks as though I missed one. That was all wasn't it? I don't mean to annoy you by being incompetant. It's just that I'm not much of a whizz on computers - as you've probably noticed!

    I think I've done everything now. ie.. deleting all 9 of the entries you told me to on HJT. Plus uninstalling Spysweeper.

    What I shall also do is stop the antivirus software on AOL so I'm only using Norton.

    Anything else I can do? It hasn't improved much at the moment.

    Our PC did start to go slow when my fiancee loaded the Sony Connect software for her MP3 player. We heard in the press that it was causing lots of problems so we stopped using it and unistalled it. Is it possible that is still causing a problem?

    Regards,
    Paul

    Ps. New log attached.
     

    Attached Files:

  14. Hurmund

    Hurmund Private E-2

     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See the below link and make sure the Windows firewall is disabled:

    Windows Firewall

    I do not use AOL so I'm not sure how their software works but if they have learned anything in the last few years (I doubt it) there should be away to disable their security software. Otherwise we could possibly disable it manually.


    It could be! Is this a Sony PC? Do you know what the below services are for:

    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
     
    Last edited: Mar 13, 2006
  16. Hurmund

    Hurmund Private E-2

    Windows Firewall was already turned off. I guess Norton must have done it auotmatically when it was installed.

    As far as the two Sony items go, they must be something to do with the Sony MP3 Connect software which I uninstalled. (The PC is made by Compaq). I guess it should be removed. Do I remove it via HJT?

    I've turned off AOL Spy Zapper which scans the PC on connection to the internet. But for some reason it still tries to run. I've double checked but it is definitly turned off.

    I don't know if it was something you told me to do or not, but the volume buttons on the keyboard now don't work. They're not essential I know, but if you know how I could get them back it would be handy.

    Thanks for your help.

    Paul
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Special steps will be needed to remove them because they are services.

    We can probably stop some of these manually too. It's worth a try! Just let me know what you want to do.

    That was why I asked you those questions before. Remember this one:
     
  18. Hurmund

    Hurmund Private E-2

    Yes. I would definatly like to get rid of the Sony items. Please can you let me know how to do it. We have nothing on our PC to do with Sony anymore.

    Perhaps we should leave the AOL items as a last resort.

    Whoops! My mistake with the multi-media keyboard. Is there anyway to get it back?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I'll work something up for you.

    Yes! Try this. Run HijackThis and on the main screen select Open the Misc Tool section then on the next window click Backups. Locate the below in the list:

    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE

    Put a check mark on that line and then to the right side of the window click Restore.

    You are now witness to one of the reasons why we insist that HijackThis be installed properly. This way backups are created and can be used in situations like this.

    Let me know if this works okay. Meanwhile I will look at the Sony stuff.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here are the two Sony services we will be removing.
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Sony SPTI Service (if that is not found, look for the short name: SPTISRV)... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the about stop and disable for the following service: MSCSPTISRV

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    SPTISRV

    Now repeat the Delete NT Service steps for: MSCSPTISRV

    Now exit HJT but and reboot.

    After reboot just tell me if those two O23 lines for Sony are now gone.

    Also let me know how your PC is working.
     
  21. Hurmund

    Hurmund Private E-2

    Hi Chas,

    I successfully restored the HJT entry to make the volume buttons work again on my keyboard thanks. Thank God you made me install HJT properly!

    I followed your steps (nearly) to remove the service entries via services.msc. I changed the start-up type to 'DISABLED' on both entries but missed the 'STOP SERVICE' instruction (I'm really sorry - don't know how I missed it!).

    I rebooted and run HJT again (see attached) but the entries were still there. I rebooted again and looked in services.msc but the Sony entries had both dissappeared. Somehow they are still on HJT though.

    No improvement on very, very slow booting up.

    Paul
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! They are gone. The one that remains is another service I missed last time. Sorry about that!

    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to PACSPTISVR ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    PACSPTISVR

    Now exit HJT and reboot.

    After reboot just tell me the O23 lines is now gone.

    Also let me know how your PC is working.
     
  23. Hurmund

    Hurmund Private E-2

    Hi Chas,

    I've carried out your steps and can confirm that the Sony item left has been removed. Only thing is, the PC is still dead slow when booting up (at the Windows XP bit with the four coloured window panes).

    Any other ideas please?

    Paul
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said earlier! Symantec and AOL but try just fixing the below first:

    O4 - HKLM\..\RunOnce: [Pest Cleaning] "C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\ppclean.exe" "clean" "silent" "cws" "2"
     
  25. Hurmund

    Hurmund Private E-2

    I did that. But still no improvement booting-up. Also, when I connect to AOL, it automatically runs AOL Spyware Protection automatically.

    Do you think I should get rid of this one too?

    O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing).

    Ps. New HJT log attached.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That file may not really be missing and like other steps we have done the service would have to be stopped and disabled and then you could delete the NT service. Not how much help removing all AOL stuff will provide. I think you should really just bite the bullet and uninstall Norton (just for a trial) and then see how things look. You can always reinstall.

    If uninstalling Nortons and removing some other AOL items is not helping then perhaps something else is physically wrong.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds