XP slow start-up

Discussion in 'Malware Help (A Specialist Will Reply)' started by mqw1968, Aug 25, 2009.

  1. mqw1968

    mqw1968 Private E-2

    I have a friend's PC which has been running poorly for a while now. Have solved various problems relating to fragmentation and did a SpyBot run which unearthed only a MegaUpload toolbar issue, which i "fixed".

    Have just carried out all the scans prescribed for malware removal and logs are attached

    Would be grateful if someone could check these over and advise

    I have also discovered that despite the default account (with admininstrator privileges) being "Sara", the related user folder in C:\Documents and Settings appears to have been renamed to "bethan!". Yes, that's "bethan" plus "!" rolleyes.

    My friend (Sara) recalls that "something went wrong" when her daughter, Bethan, attempted to create her own separate XP account. There is no "Sara" folder in Documents and Settings. Would this have any effect on the start-up?

    Added to that, i can see that the daughter has also installed Windows Live Messenger Plus and some optional skins for this program. I get the impression that this is not a good idea.

    The PC as it stands actually runs reasonably well - apart from the irritatingly long start-up. I'm not aware of issues with web-browsing or running applications. Any help would be gratefully received

    MarkW.

    PS Will attach last scan log to additional post
     

    Attached Files:

  2. mqw1968

    mqw1968 Private E-2

    Here's the MG Tools log relating to my post above

    MarkW.
     

    Attached Files:

  3. mqw1968

    mqw1968 Private E-2

    Just realised that i ought to have posted the questions about user folder being renamed and other non-malware stuff in a different forum.....this i will do now

    MarkW.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome. :)

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. This takes some time so your patience is appreciated.

    * In the meantime, I would like to point out to you that the version of SUPERantispyware that you have installed on this machine is very out of date. Please refer to the below to correct this:

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log into your next post here.
     
  5. mqw1968

    mqw1968 Private E-2

    Kestrel,
    Thanks for the response. I thought that i'd updated SAS online, but i will follow your instructions as soon as i can get back to the PC in question. It's currently back with the owner and I won't get a chance to do anything until next Tuesday. I will tell the owner not to install/uninstall anything. As far as I'm aware, anything that the scans discovered has only been quarantined and not removed as yet.

    Thanks again for your time. Much appreciated

    MarkW.
     
    Last edited by a moderator: Aug 28, 2009
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem, I shall be here waiting :)
     
  7. mqw1968

    mqw1968 Private E-2

    Hi Kestrel,
    Finally i managed to get access to the problem PC again and have followed your instructions for updating SAS.

    The scan results are attached. Thanks for your patience. I'd be happy to hear your recommendations whenever you have the time to deal with this.

    Regards
    MarkW.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your logs are clean :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. mqw1968

    mqw1968 Private E-2

    Thanks for your swift reply, Kestrel.

    Have done the final clean up as recommended. I assume that it's sensible to remove the items quarantined by SAS and Malwarebytes?

    MarkW.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are welcome . And yes you can remove the quarantined items :)

    Safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds