Author Topic: does the very slow window boot-up means i have malware?  (Read 21048 times)

0 Members and 2 Guests are viewing this topic.

bijspace

  • Guest
does the very slow window boot-up means i have malware?
« on: October 19, 2010, 03:05:14 PM »
hey,i have avast Pro version for a year,and for nearly six months i have been facing this problem.it takes so long for windows to load.i downloaded the MBAM software,it caught 10 infected files,and that is after i had run a full scan with Avast!5 pro version.
but,the problem is still there,the windows takes alot of time to load.
there's another problem,when i try to play two or more programs,they won't run smoothly.for example if I'm running iTunes and start internet explorer,the music would start cracking.
 i have done defragmentation,checkdisk,had run avast so many times,got the registry cleaned up(which now ive read,i shouldn't have),and latest is the MBAM software...but the problem is still there.Help!!

CharleyO

  • Guest
Re: does the very slow window boot-up means i have malware?
« Reply #1 on: October 19, 2010, 06:44:36 PM »
***

Give us the specifications of your computer.


***

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: does the very slow window boot-up means i have malware?
« Reply #2 on: October 19, 2010, 06:48:17 PM »
Quote
downloaded the MBAM software,it caught 10 infected files
can you post the log ?

bijspace

  • Guest
Re: does the very slow window boot-up means i have malware?
« Reply #3 on: October 19, 2010, 07:21:41 PM »
i have attached the log file.
the specifications are:
 Windows xp professional,512RAM..and what else should i tell?

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: does the very slow window boot-up means i have malware?
« Reply #4 on: October 19, 2010, 07:33:15 PM »
adware potato?rofl ;D
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: does the very slow window boot-up means i have malware?
« Reply #5 on: October 19, 2010, 07:43:16 PM »
your log say " NO ACTION TAKEN " did you click the " remove selected " button after the scan ?
also did you update Malwarebytes before you scanned ?
your log say you scanned yesterday with database  4862, this is older then one day.....latest now is 4882
« Last Edit: October 19, 2010, 07:45:55 PM by Pondus »

bijspace

  • Guest
Re: does the very slow window boot-up means i have malware?
« Reply #6 on: October 19, 2010, 07:51:42 PM »
adware potato?rofl ;D
this was this program for free online series and sitcoms ::),i had removed it(even though i didn't know it was hosting viruses too)
but the problem with windows bootup has nothing to do with it,cuz i have been facing the problem for a long time but had downloaded the click potato program only recently

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: does the very slow window boot-up means i have malware?
« Reply #7 on: October 19, 2010, 08:02:12 PM »
adware potato?rofl ;D
this was this program for free online series and sitcoms ::),i had removed it(even though i didn't know it was hosting viruses too)
but the problem with windows bootup has nothing to do with it,cuz i have been facing the problem for a long time but had downloaded the click potato program only recently

mm
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

bijspace

  • Guest
Re: does the very slow window boot-up means i have malware?
« Reply #8 on: October 19, 2010, 08:20:54 PM »
your log say " NO ACTION TAKEN " did you click the " remove selected " button after the scan ?
also did you update Malwarebytes before you scanned ?
your log say you scanned yesterday with database  4862, this is older then one day.....latest now is 4882

i did click "remove selected" after the scan
and i updated Malwarebytes today and i scanned my computer after that.there are zero infected files.
in the task manager,there is a list of processes,i saw 4 of 5 SVCHOST.EXE processes which are always running.do you think these are viruses?should i "End Process"?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: does the very slow window boot-up means i have malware?
« Reply #9 on: October 19, 2010, 08:44:40 PM »
Follow this guide form our expert malware remover Essexboy and post the log`s here
http://forum.avast.com/index.php?topic=53253.0

To avoid using multiple post with copy and paste you have to attach the log`s
Lower left corner: Additional Options > Attach ( OTL.Txt and Extras.Txt.)

He enters the forum soon so if you hurry.....

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: does the very slow window boot-up means i have malware?
« Reply #10 on: October 19, 2010, 10:52:31 PM »
Could just be a tad of TLC required but lets have a look

Download OTS to your Desktop and double-click on it to run it
  • Make sure you close all other programs and don't use the PC while the scan runs.
  • Select All Users
  • Under additional scans select the following
Reg - NetSvcs
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check
File - Purity Scan


  • Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Please attach the log in your next post.

bijspace

  • Guest
Re: does the very slow window boot-up means i have malware?
« Reply #11 on: October 20, 2010, 10:28:23 AM »
i have attached the log file.should i remove the OTS program now?
« Last Edit: October 20, 2010, 10:33:48 AM by bijspace »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: does the very slow window boot-up means i have malware?
« Reply #12 on: October 20, 2010, 09:31:52 PM »
I will tidy the programmes up when we are finished  ;D

Nothing major apparent there so I will remove some junk entries and empty your temporary files etc...
Then we will defragment the drive and see if that makes any improvement

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

Quote
[Unregister Dlls]
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {02478D38-C3F9-4efb-9B51-7695ECA05670} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "Adobe Reader Speed Launcher" -> C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"]
YN -> "TkBellExe" -> C:\Program Files\Common Files\Real\Update_OB\realsched.exe ["C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot]
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\
YN -> {FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> Reg Error: Value error. [Button: Messenger]
YN -> {FB5F1910-F110-11d2-BB9E-00C04F795683}:Reg Error: Value error. [HKLM] -> Reg Error: Value error. [Menu: Windows Messenger]
< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> [Messenger]
< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> [Messenger]
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-1078081533-854245398-839522115-1003\] > -> HKEY_USERS\S-1-5-21-1078081533-854245398-839522115-1003\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> [Reg Error: Value error.]
YN -> CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> [Messenger]
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List
YN -> "C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)]
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
[ClearAllRestorePoints]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix.  Post that information back here

I will review the information when it comes back in.

Download and run Puran Disc Defragmenter
For the first run use the boot time defrag with checkdisc


bijspace

  • Guest
Re: does the very slow window boot-up means i have malware?
« Reply #13 on: October 20, 2010, 09:50:35 PM »
i have attached the file you asked for.i did the defragmentation and deletion of temporary files before too and it hadn't helped at all.but i'm still gonna try the steps you're telling me :D

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: does the very slow window boot-up means i have malware?
« Reply #14 on: October 20, 2010, 10:03:20 PM »
Quote
Total Files Cleaned = 792.00 mb
Once you defrag after clearing this it may well be better.  But, your RAM is very tight