Post your hijack this log.
Also Start->Run->MSCONFIG and remove all items from startup tab...
Main Topics
Browse All TopicsDear Experts,
My PC, after my dad used it, suddenly takes 3-4 minutes to complete the boot up. The logon screen comes up immediately, but as soon as i log in under my name it brings up my desktop but slows to a crawl (the Norton Firewall, and Internet connectivity icons take forever to show up). This last step of the boot up takes 3-4 minutes.
I know that my dad's use of the internet has installed some rogue program because the same thing happened on his computer. My computer was working fine until he used it to do some internet browsing.
The start up folder is empty. I have run highjackthis, and spybot but nothing jumps out at me as the problem.
Can someone please advise me? I will happily post logs for you to review and help me find this pesky rogue program that is slowing down my start up.
I have a P4, 1.5mghz, 512 Gigs of RAM, with Windows XP home edition (with latest patches).
Very frustrated.
Please help.
David
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Logfile of HijackThis v1.97.6
Scan saved at 12:31:37 PM, on 1/13/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\System32\Ati2ev
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\system32\Ati2ev
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.e
C:\WINDOWS\System32\spool\
C:\WINDOWS\System32\hphmon
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\MESSEN~1\msmsg
C:\WINDOWS\System32\ctfmon
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\System32\devldr
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\HPHipm
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\All Users\Desktop\Download\Hij
R0 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-F
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.e
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hph
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\PROGRA~1\MESSEN~1\msms
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: Web Entry (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O9 - Extra button: Dell Home (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
O16 - DPF: {072D3F2E-5FB6-11D3-B461-0
O16 - DPF: {7519DB27-0B01-4B3C-AB05-4
O16 - DPF: {94B82441-A413-4E43-8422-D
O16 - DPF: {9F1C11AA-197B-4942-BA54-4
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0
O16 - DPF: {072D3F2E-5FB6-11D3-B461-0
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0
cyberactivex is used in on-line classes...
Java 2 Cyber Classroom, 3rd Edition (Deitel)
Internet & WWW Programming Cyber Classroom, 1st Edition (Deitel)
C++ Cyber Classroom, 3rd Edition (Deitel)
XML Programming Cyber Classroom (Deitel)
e-Business & e-Commerce Programming Cyber Classroom (Deitel)
Perl Cyber Classroom (Deitel)
UML Cyber Classroom (Booch)
Linux Shell Programming Cyber Classroom (Hawkins)
Web Server Cyber Classroom (Stephens & Larson)
Web Design Cyber Classroom (Hubbell, et. al.)
TCP/IP Cyber Classroom (Comer)
SQL Queries Cyber Classroom (Hernandez & Viescas)
from http://ptgtraining.com/
ieatgpc is part of a control used in on-line meetings
cfjava is used by the on-line claim form helper if you have leaky plastic pipes...
To remove entries from your registry startup:
Start/Run/Regedit - navigate to HKEY_Local_Machine\Softwar
With Run highlighted, click File/Export and save this file somewhere on your desktop (run.reg) (this saves a copy)
Once saved remove unneeded/unwanted items by right-clicking and clicking delete...
I am worried about removing everything from start up because I am thinking if i remove the wrong thing then I will not be able to undo the removal. Is there a way to incrementally one by one remove programs from start up (and re-include them in start up if they are not the source of problem) till i find the rogue program?
I did notice that the ATI (video driver icon) appears right away, then the 3-4 minute delay occurs, then after the delay the windows logon sound is played, followed by the remaining icons (Norton antivirus, firewall, windows messenger).
I removed some obvious stuff from start up (epson printer, ms works, and quicktime stuff) becuase i dont use any of those programs anymore. I restarted but still the same problem with the slow start up.
The cyberclassroom is for my java online class (this was on before the problem started), and the webex program (was also on before the problem started).
Tx for all of your help.... I hope we can track this problem down.
For determining what startup programs are needed:
This page has an alphabetical list of many, many, programs that have been found in the startup list in Msconfig of Windows computers. It is very long, and if you have a regular dialup modem, it will take some time to load (even with my DSL connection, it takes almost half a minute to load.) As explained on the page, you can browse through the different alphabetical sections, or you can do a "Find" on any name you choose to inquire about. It will tell you with a code about the program whether it is necessary or not for Windows running:
"Y" - Normally leave to run at start-up
"N" - Not required - typically infrequently used tasks that can be started manually if necessary
"U" - User's choice - depends whether a user deems it necessary
"X" - Definitely not required - typically viruses, spyware, adware and "resource hogs"
http://www.pacs-portal.co.
Here are some other websites where you can track down info about startup programs:
http://www.3feetunder.com/
http://www.answersthatwork
http://www2.whidbey.net/dj
I have removed the Nvidia drivers from start up. I have removed SysTray.exe (but it keeps reappearing). I am still going through the list of required programs but I still can not solve the problem. When i remove systray.exe from the computer boots quickly but the systray.exe reappears after reboot. ?
Well if anyone spots anything or has any other ideas i would love to hear them. In the meantime I am going to parse through the startup list to see what is required and what can be removed.
Thanks for the help.
Business Accounts
Answer for Membership
by: sirbountyPosted on 2004-01-13 at 09:26:05ID: 10105891
Check for Spyware: uide.com/s pyware.htm spyware.ht ml om/program /hijackthi s.html king.org/ .htm com/~merij n/ cwschron icles.html #cwshredde r ort/spywar e.shtml (common Spyware removal programs) om/overtur e/index.ht ml m/overture .php ut.com/lib rary/blfre espyware.h tm
om/sscv6/d efault.asp ? productid =symhome&l angid=ie&v enid=sym .com/house call/start _corp.asp /scan/lice nce.php m/scan/ om/actives can/ mfs/defaul t.asp emotevirus chk.html
All inclusive Spyware Protection and Removal --> links:http://www.firewallg
Spyware defined --> http://www.spychecker.com/
HijackThis -->http://www.spychecker.c
Spybot-S&D -->http://www.safer-networ
Adware --> http://www.cexx.org/adware
Web Shredder -->http://www.spywareinfo.
PC Hell --> http://www.pchell.com/supp
Spyware BeGone! --> http://www.spywarebegone.c
Spyware Nuker! --> http://www.spywarenuker.co
Ad-Aware --> http://www.netsecurity.abo
Check for Viruses with online scanners:
Norton/Symantec --> http://security.symantec.c
Trend Micro --> http://housecall.antivirus
BitDefender --> http://www.bitdefender.com
RAV Antivirus --> http://www.ravantivirus.co
Panda ActiveScan --> http://www.pandasoftware.c
McAfee Security --> http://us.mcafee.com/root/
Individual File Scanner --> http://www.kaspersky.com/r