Windows XP Start up problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by compnewbie, Jan 9, 2005.

  1. compnewbie

    compnewbie Private E-2

    Windows XP
    256mb ram
    Athalon 2100

    Hi. I hope I'm in the right place for this. I'm having some XP problems. When I start up the computer it takes a while for the screen to come up to enter a password to log onto XP. Then several more moments go by before my desktop loads. My start button and task bar no longer load up automatically, and I no longer have a button to do a system restore and my volume is gone as well. After I run and load some programs they turn off. I hope someone can help me out. I've read some other threads and tried some things listed but nothing is working. Thanks!

    Geoff
     
  2. ASUS

    ASUS MajorGeek

    Get any errors?
    When's the last time, you had all your missing stuff?
    Have you tryed Advanced start up options, F8, try system restore there, safe mode?



    If you dont have any important stuff on that PC, there is always the option of a complete reinstall of windows, but before you do that wait and see if any one has any advice.
     
  3. Robert

    Robert Sergeant

    If there are no error msgs with XP I'd look at what's loading in the background when you startup. Could be a whole heap of programs taking up memory which you don't know about.
    Could also be a whole heap of unnecessary CRAP on your hard drive plus a pressing need for a defrag.
    Download and run crapcleaner (available feeware this site) reboot in safe mode and do a defrag. Hopefully that may solve your probs - but look very carefully at the programs that are loading at Startup - you should only allow the one that you need - the others can always be called at at your command not when some programmer out there has insisted that it should be in the program queue.
    Cheers
    Robert
     
  4. Turcoloco

    Turcoloco MajorGeek

    As an addition to other fellas, to see what services/programs loading up at Windows startup, do this:

    START > RUN > msconfig > OK

    Check the 'Startup' tab. Before disabling any of the entries but unchecking the boxes next to them write down its name and the location of the executables that you don't know or look suspicious and post the list here. This could be another infection case, so let us know.
     
  5. compnewbie

    compnewbie Private E-2

    Thanks guys, I have done a last known good start up from F8 still no task bar or start button, and no audio controls Here is the list of items running from MSCONFIG:
    vptray C: Program Files\NavNt\vptray.exe
    svJ C:program Files\documents and settings\owner\local settings\temp\svJ.exe
    sgtray C: Program Files\Veritas Software\Update Manager\
    ps2 C:Windows\system32\ps2.exe
    RUNDLL32 RUNDLL32.EXE NvQTwk,NvCPLDaemon initialize
    ntdv C: Windows\system32\ntdv.exe
    m C: Program Files\documents and settings\owner\local settings\temp\m.exe
    idctup20 C: WINDOWS\system32\idctup20.exe
    igfxtray C: WINDOWS\system32\igfxtray.exe
    hpsysdrv C:\windows\system\hpsysdrv.exe
    hpztsb05 C: WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
    HPWuschd C:\Program Files\Hewlett-Packard\HP Software\update\HPWuschd.
    hpcmpmgr C: Program Files\HP\hpcoretech\hpcmpmgr.exe
    hkcmd C: WINDOWS\System32\hkcmd.exe
    uwrhhn C: WINDOWS\System32\uwrhhn.exe
    dllhostxp dllhostxp.exe
    tfswctrl C: WINDOWS\system32\dla\tfswctrl.exe
    clfmon clfmon.exe
    ct C: program files\HPselect\Frontend\ct.exe
    hpqcmon C: Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.
    apptz32 C: WINDOWS\system32\apptz.exe
    ADUserMon C: Program Files\Iomega\AutoDisk\ADUserMon.exe
    zzb C: WINDOWS\System32\zzb.exe
    Adobe Gamma Loader.exe C: Progra~1\COMMON~1\Adobe\CALIBR~1\
    ADOBEG~1.exe
    Datviz Messenger C: \WINDOWS\DVZCOM~1\DvzMsgr
    hp center UI C:pROGRA~1\HPCENT~1\137903\Shadow\SHADOW~1.EXE-STARTUP
    RealDownload C: PROGRA~1\Real\REALDO~!\REALDO~1.EXE-hidden
    Power Reg Scheduler C: Documents and Settings\Owner\Start Menu\Programs
    \Startup\Power Reg Scheduler.exe

    Let me know if you need anything else. Again thanks for looking at this.

    Geoff
     
  6. KIHERBERTK

    KIHERBERTK Private E-2

    Quickest Solution,which`s Worked4me.
    Try Loading In Safe Mode& See If Loads,if No Try2 Back Up All Your Stuff I.e Slave The Drive On Another Pc,
    Then Load Another Win-xp.
    Or.
    Load Xp On Another Folder I.e Windows.001.

    It `always Works4me
    Goodluck. Am At>kiherbertk@yahoo.com>
     
  7. Phatsta

    Phatsta Corporal

    well that'll work, but you'll end up having two and with time maybe three and four installations..? wouldn't recommend that.

    windows does this with time. it's all natural due to it's crappy way of keeping the registryfile clean when you install/uninstall programs, spyware etc which btw may very well be your problem.

    anyway, if you really need the files on the computer, you can always start up in safe mode as kiherbert says, then back it all up to another drive, or partition a part of your drive for it, then make a complete reinstall. that would be the best. or if you wanna try getting it to work without reinstalling it, start up in safe mode and run adaware or another spyware search program. clean up your computer with disk cleanup. also uninstall any programs you don't use with add/remove programs. at least then you've made sure there's no applications in the background sucking up your system resources.
     
  8. Turcoloco

    Turcoloco MajorGeek

    Your system seems to be infected with some sort of malicioud software (malware). I will inform Chaslang or PhilliePhan to take a look as well but before continuing any further please do READ and FOLLOW the instructions on this thread, ok?
     
  9. Markelvis

    Markelvis Private E-2

    I have a HP computer. When I turn it on, it does not chose which microsoft software to use on the computer. It doesn't even count down. I have to turn it on again and then it choses the correct one and starts up. What causes it and how could I fix it. Any help is appreciated.
     
  10. Phatsta

    Phatsta Corporal

    the only suspect thing here is this: m C: Program Files\documents and settings\owner\local settings\temp\m.exe
     
  11. Turcoloco

    Turcoloco MajorGeek

    CompNewbie, prior to reading the thread I posted do this to have a bit more workable/stable system, ok?

    1. Open 'msconfig' / Startup tab and uncheck these entries that are possibly malware related:

    svJ C:program Files\documents and settings\owner\local settings\temp\svJ.exe
    ps2 C:Windows\system32\ps2.exe
    RUNDLL32 RUNDLL32.EXE NvQTwk,NvCPLDaemon initialize
    ntdv C: Windows\system32\ntdv.exe

    m C: Program Files\documents and settings\owner\local settings\temp\m.exe << Are you sure this is the correct path? Usually it is either C:\Program Files\... or C:\Documents and Settings\username\...

    idctup20 C: WINDOWS\system32\idctup20.exe
    igfxtray C: WINDOWS\system32\igfxtray.exe
    uwrhhn C: WINDOWS\System32\uwrhhn.exe
    dllhostxp dllhostxp.exe
    tfswctrl C: WINDOWS\system32\dla\tfswctrl.exe
    apptz32 C: WINDOWS\system32\apptz.exe
    zzb C: WINDOWS\System32\zzb.exe


    ~ Uncheck these entries that are not/may not be malware related but not needed anyhow, it should also improve performance and startup time:

    sgtray C: Program Files\Veritas Software\Update Manager\
    ct C: program files\HPselect\Frontend\ct.exe
    HPWuschd C:\Program Files\Hewlett-Packard\HP Software\update\HPWuschd.
    hpqcmon C: Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.
    ADUserMon C: Program Files\Iomega\AutoDisk\ADUserMon.exe
    Adobe Gamma Loader.exe C: Progra~1\COMMON~1\Adobe\CALIBR~1\
    ADOBEG~1.exe
    Datviz Messenger C: \WINDOWS\DVZCOM~1\DvzMsgr
    hp center UI C:pROGRA~1\HPCENT~1\137903\Shadow\SHADOW~1.EXE-STARTUP
    RealDownload C: PROGRA~1\Real\REALDO~!\REALDO~1.EXE-hidden
    Power Reg Scheduler C: Documents and Settings\Owner\Start Menu\Programs
    \Startup\Power Reg Scheduler.exe

    Afterwards, click on START > Control Panel > Folder Options > View
    make sure the 'show hidden files and folders' option is selected.
    Then open Windows Explorer and browse to:
    C:\Documents and Settings\username\local settings\temp &
    C:\Documents and Settings\username\local settings\Temporary Internet Files
    C:\Windows\Prefetch

    DELETE EVERYTHING in these 3 folders (not the folders)!

    Reboot and follow the instructions on the thread, ok?
    Repost please if you have any questions.
     
  12. compnewbie

    compnewbie Private E-2

    Thanks for the suggestions. I did what you guys said to do going into safe mode etc. and still no luck except that my machine seems cleaner! Maybe this will help to.. I was reading a thread on getting rid of viruses and going through the steps and got to the part about going into services.msc and disabling the RPC I did that as well as how disable and enable system restore. I did those things but now I can't enable the system restore. The tab button for it is gone. I have gone into safemode and tried from there and no luck either. Another thing I noticed on msconfig when I clicked on the services tab, I noticed most of the items under status are stopped. Could this be the problem too? A lot of my programs will not run correctly either or either shut down after loading. Sorry I have so many questions. Again thanks for the help.

    Geoff
     
  13. Turcoloco

    Turcoloco MajorGeek

    Geoff read my previous post and do that first....then read the thread thoroughly before doing anything else. Also do not enable/disable any services when you are in 'Safe Mode', as certain services can not even be started in 'Safe Mode'.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are several processes that I see that would indicate that you have an HSA hijack going on.

    The ntdv.exe and apptz.exe processes are two examples.

    Have you run the steps from the READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal sticky thread. You should do that. Make sure you look for those 3 services (mentioned in step 2 of Getting Prepared) and disable them if found. Also, make sure you look for the In particular make sure you run HSremove and about:Buster.

    After doing ALL of the above if you still have a problem:

    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT


    NOTE: I'm also moving this to the Spyware Forum where it belongs.
     
  15. compnewbie

    compnewbie Private E-2

    Hi again.. I did the steps mentioned in the read me first before asking thread on basic spyware trojan and spyware removal and that is where my problems seemed to start. After turning off the RPC in the Services.msc area, and when I disabled my system restore, I couldn't go back in and enable the system restore. The tab for it is gone. I noticed in the msconfig on the Services tab that almost all of the functions listed on there are stopped. I can't copy and paste anything, I can't use instant messenger, I can't print anything etc. I'm really confused as to what I may have done. Again, any help would be appreciated... Thanks!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You believe that you did not follow the directions properly. It only states the any of the below three services need to be stopped and disabled:
    • Network Security Service
    • Workstation Netlogon Service
    • Remote Procedure Call (RPC) Helper
    No others! And I quote from the READ ME:

    Sounds like you disabled Remote Procedure Call (RPC) not Remote Procedure Call (RPC) Helper. Is that what you did? If so, you need to Start it again and make it Automatic.

    You may find the below links to be of use here just in case you run into problems:
    http://support.microsoft.com/default.aspx?scid=kb;en-us;838428
    http://support.microsoft.com/default.aspx?scid=kb;en-us;241584

    Once you get the "real" RPC running again, post a HJT log and let's see what you have still got in your system.
     
    Last edited: Jan 11, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds