1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Resolved Need help w/ reducing XP startup

Discussion in 'Windows XP' started by chas berlin, 2010/03/10.

  1. 2010/03/10
    chas berlin

    chas berlin Inactive Thread Starter

    Joined:
    2008/06/03
    Messages:
    1,578
    Likes Received:
    2
    Here's the Hijack log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:47:55 PM, on 3/10/2010
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\COMODO\Firewall\cmdagent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
    C:\WINDOWS\system32\acs.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Microsoft LifeCam\MSCamS32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
    C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
    C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\COMODO\Firewall\cfp.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\iTunes\iTunes.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Vuze\Azureus.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
    O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
    O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe "
    O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6796.cab
    O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1232051400706
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su/ocx/15111/CTPID.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0AC63FC9-2CD2-490E-BF41-FF1BC08EB0BB}: NameServer = 68.94.156.1,68.94.157.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{EE03ECD5-7F5E-4951-9473-40F69AD18F62}: NameServer = 68.94.156.1,68.94.157.1
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0AC63FC9-2CD2-490E-BF41-FF1BC08EB0BB}: NameServer = 68.94.156.1,68.94.157.1
    O17 - HKLM\System\CS3\Services\Tcpip\..\{0AC63FC9-2CD2-490E-BF41-FF1BC08EB0BB}: NameServer = 68.94.156.1,68.94.157.1
    O17 - HKLM\System\CS4\Services\Tcpip\..\{0AC63FC9-2CD2-490E-BF41-FF1BC08EB0BB}: NameServer = 68.94.156.1,68.94.157.1
    O17 - HKLM\System\CS5\Services\Tcpip\..\{0AC63FC9-2CD2-490E-BF41-FF1BC08EB0BB}: NameServer = 68.94.156.1,68.94.157.1
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: c:\windows\system32\guard32.dll C:\WINDOWS\system32\guard32.dll
    O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\
    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
    O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Avira Upgrade Service (AntiVirUpgradeService) - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\AVSETUP_4a01d5f8\basic\avupgsvc.exe (file missing)
    O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
    O23 - Service: Ocster Backup Service (ocsterBackupDaemon) - Unknown owner - c:\Program Files\Ocster Backup\bin\backupDaemon.exe
    O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

    --
    End of file - 7937 bytes


    I've deleted Nokia - so not sure why it shows up.
    Ocster Backup has been downloaded, but not used, and don't need it to jump start.
    I don't have an iPod, so not sure if that's necessary.

    I have two drives and this one takes much more memory than the other, and I'd like to put it on a diet.
     
    Last edited: 2010/03/10
  2. 2010/03/10
    chas berlin

    chas berlin Inactive Thread Starter

    Joined:
    2008/06/03
    Messages:
    1,578
    Likes Received:
    2
    Also, have Seagate discwizard, but don't see why it needs to load. Rarely use it.
    Google? Why load this?
     

  3. to hide this advert.

  4. 2010/03/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Chas
    I don't see any unnecessary startups.

    As for:
    Go Start>Run, type in:
    services.msc
    Click OK.

    New window will open.
    Find:
    ServiceLayer
    Ocster Backup Service

    In each case, right click on the service, click "Properties "
    Under "Startup type" select "Disable" fro drop-down menu.
    Restart computer.

    You have to explain this better:
    because I don't understand what you're saying.
    What are the issues to start with?
     
  5. 2010/03/10
    chas berlin

    chas berlin Inactive Thread Starter

    Joined:
    2008/06/03
    Messages:
    1,578
    Likes Received:
    2
    Thx Broni. I'd do that in a moment.

    Drive A starts up and Task Mgr shows 280000K avail memory. The other drive were now looking at on has 250000- 260000K avil.
     
  6. 2010/03/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    What do you mean by "drive "? A computer? Two different computers?

    How much RAM do you have?
     
  7. 2010/03/10
    chas berlin

    chas berlin Inactive Thread Starter

    Joined:
    2008/06/03
    Messages:
    1,578
    Likes Received:
    2
    Right.
    3GB's RAM
    One machine w/ one drive A and a 2nd (external drive B). If I hook up drive B (removing the cabling for drive A) it gets better memory numbers than A.

    (B is also the drive I spent the last 2 days on, but couldn't get a sound driver to load. Had the sound worked that would be my main drive. It has a new XP install). Both are XP Pro (SP2)
     
  8. 2010/03/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Do you have Windows installed on both drives. I'm not sure what kind of configuration it is.

    Then what? Is the computer slow, or...?
    You're not saying what the issues are.
     
  9. 2010/03/11
    chas berlin

    chas berlin Inactive Thread Starter

    Joined:
    2008/06/03
    Messages:
    1,578
    Likes Received:
    2
    Sorry Broni.
    Yes, XP is on both drives, and the drives are identical Seagate 750GB.
    The issue is just wanting to free up more memory, so the cache doesn't have to be cleared as often. Make sense?
     
  10. 2010/03/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Chas
    What are the computer issues?
    What's wrong with it?
    What cache are you talking about?
     
  11. 2010/03/11
    chas berlin

    chas berlin Inactive Thread Starter

    Joined:
    2008/06/03
    Messages:
    1,578
    Likes Received:
    2
    Can't really explain that one Broni. I've always read that the box needs a restart every few days to clear the cache. I tend to watch my memory usage in Task Mgr and when it gets around 180000-200000 avail I restart to clear the cache. Any other issues we've (on this bbs) been unable to resolve, though as it turns out SFC won't run on the new install either. Go figure!
    Oh and after the changes you had me make memory went up to 270000, so no complaints bud. :)
     
  12. 2010/03/11
    chas berlin

    chas berlin Inactive Thread Starter

    Joined:
    2008/06/03
    Messages:
    1,578
    Likes Received:
    2
    Broni, where'd you get off to?
     
  13. 2010/03/11
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    An exercise in futility. You aren't going to notice anything different if you have 15-20MB more free memory available (on your total of around 240-250 MB free).
     
  14. 2010/03/11
    chas berlin

    chas berlin Inactive Thread Starter

    Joined:
    2008/06/03
    Messages:
    1,578
    Likes Received:
    2
    What causes memory to drop from say 240000 to 210000 overnight, when the computer is just sitting idle?
    At what point is it good to restart to clear the cache?
     
  15. 2010/03/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    .....
     
  16. 2010/03/11
    chas berlin

    chas berlin Inactive Thread Starter

    Joined:
    2008/06/03
    Messages:
    1,578
    Likes Received:
    2
    Broni, I did my best to answer in post #10. SFC won't run, and when I safely remove a flash drive I get a message saying "an exception occurred" there's more to the message, but it flashes so quickly I can't read the rest. Otherwise the box is fine.
     
  17. 2010/03/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    If so, either fresh install went wrong, your Windows CD has problems, or you have some hardware problem.
     
  18. 2010/03/11
    chas berlin

    chas berlin Inactive Thread Starter

    Joined:
    2008/06/03
    Messages:
    1,578
    Likes Received:
    2
    Good pts Broni.
    It's unlikely both drives have a problem (though it's possible), and the new install was done twice (to try and overcome the driver/machine not recognising the sound card), so I have to question the CD I have. Got it four yrs ago, so I doubt there's anything I can do about it, or do you know of something? I don't imagine MS being willing to address an old OS, do you?
     
  19. 2010/03/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I doubt.
     
  20. 2010/03/11
    chas berlin

    chas berlin Inactive Thread Starter

    Joined:
    2008/06/03
    Messages:
    1,578
    Likes Received:
    2
    That's what I thought.
    That's not a major issue, and it is doing better since the changes you had me make, so I'm happy.
    Thx again for your help bud. :)
     
  21. 2010/03/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Sure thing :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.