I’ve been trying to help colleague at work with her PC which won’t start properly.
The PC is an Acer Aspire T510 (AMD Sempron) with XP Home Edition, SP2, and Norton / Symantec PC security suite 9.1.
It gets to the login screen just fine, but freezes shortly after you log in. The mouse pointer freezes with an hour-glass beside it, and the PC locks solid. Sometimes you get to see the desktop and then it freezes, but not usually. This happens across all users, both admin and restricted. Waiting does not help.
It loads just fine in Safe Mode, but the wireless adapter software doesn’t work in safe mode with networking. The PC has an onboard NIC but there is no wired connection.
A scan with Malware Bytes picked up the usual adware & tracking cookies, plus there was a registry entry identified as being for Vundo, but Vundo did not appear to be present, and the behaviour is not consistent with Vundo anyway.
The initial line of investigation was some software her bank’s website had asked her to download - always a red flag - but we talked to the bank and it was legit and the software failed to install anyway.
There is nothing useful in the Event Viewer - the only red entries are when I boot into Safe Mode and from those that fail in Safe Mode (e.g. DCOM)
I’ve scanned through the HDD visually and nothing immediately stood out. There’s plenty of HDD space. I’ve done a CHKDSK.
I tried two system restores - one to a week ago, and another to 3 weeks ago - without success. I did a virus scan after each, of course, re-removing the errant registry entries.
I’ve been thoroughly through disabling startup items in MSConfig. I’ve tried disabling Symantec via Computer Administration, Services. I’ve tried disabling the network cards in Device Manager.
I’ve tried creating a new user, with no success.
I tried to remove Symantec but it will not allow uninstallation in Safe Mode, and my removal tool cannot cope with the latest version.
She has no backup, so I’ve recommended she purchase a USB drive and do a backup from Safe Mode.
All that took me 3 hours.
I can’t help feeling I’m missing something very simple.