This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Having Computer Problems

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello! Whenever I am going on the Internet, it always starts to slow down & then all of a sudden, it just starts going normal again. I had downloaded the newset version of Norton AntiVirus a couple of weeks ago. I think this is causing me this problem. I already used Ad-Aware & Spybot to scan for virus, but they came up clean. I would like some immediate help hopefully. Here is my HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 12:50:56 PM, on 7/1/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKCU\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
Your HijackThis log is clean, I suggest you ask your ISP for some help, they may be able to pinpoint the problem, or discuss it with Norton to see what they say. Thanks…pskelley TomCoyote forum Slyware Warrior
Pskelley, I've been trying to get some help from another forum as well about this. Thank you for responding. I am still having Internet problems. I'll see what I can do in calling about Comcast. Also, I think that my HJT log is now screwed up. Can you check it out for me please? Here it is:

Logfile of HijackThis v1.99.1
Scan saved at 6:03:08 PM, on 7/5/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MANAGER\VIEWMGR.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKCU\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundl…ArcadeRdxIE.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
The log is still clean but I do see a new program:
C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MANAGER\VIEWMGR.EXE

Did you install this? It usually gets installed by aol along with stuff like AIM. aol installs it without your knowledge and without asking. I would suggest you go to Add Remove programs and uninstall it.

Also, I think that my HJT log is now screwed up. Can you check it out for me please? Here it is:

What makes you think your log is "skrewed up?" Is something happening, error messages, symptoms other that ISP issues.? I suggest you try these two programs: http://tomcoyote.org/aawsb.php If you wish to take a look for something that HJT could not see, try this scan:
http://www.windowsecurity.com/trojanscan/ or here is a free trial period download: http://www.misec.net/trojanhunter/
I also wish to say that this is not the first time I have heard of problems occuring right after a Norton download. You might want to turn the Norton off to see if the problem goes away. If you need a free antivirus program or firewall, let me know. I will give you this information now in the event something in it will help you:
Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

I hope this helps
Thanks…pskelley
TomCoyote forum
Slyware Warrior
Pskelley, I have uninstalled Viewpoint. As for the files, whenever I tried to delete the Viewpoint file in my Program Files folder, I get an error message that says "Cannot delete AxMetaStream_0302021C: Access is denied." Is there anything that I can do about this? Now, about my HijackThis log, I reason that I thought it was screwed up because it doesn't mention the ScanRegistry file. Is there any way that I can get ScanRegistry back? BTW, it isn't in one of my folders. Finally, how do you get rid of that TKBellExe thing? Please respond back.
Hello gshowman18 :) Let's see what I can do with your questions.

Pskelley, I have uninstalled Viewpoint. As for the files, whenever I tried to delete the Viewpoint file in my Program Files folder, I get an error message that says "Cannot delete AxMetaStream_0302021C: Access is denied." Is there anything that I can do about this?

Use the following instructions to take your computer into Safe Mode:
http://www.bleepingcomputer.com/forums/tutorial61.html
Once there click RIGHT on Start then Explore. Navigate to the folder: C:\PROGRAM FILES\VIEWPOINT\ >>> folder and delete the folder, that should take care of Viewpoint and all Viewpoint messages. Read the EULA agreements carefully as many "free" programs will bundle junk and malware with the download and they must give you that information in the EULA agreement. If they tell you about a lot of stuff that you will get with the "free" software and do not give you the choice of rejecting the junk, then my advice is to avoid that software completely. Much adware and spyware is downloaded in this way.

Jumping to this question while I have you in Safe Mode and in Windows Explorer:
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
read this: http://castlecops.com/startuplist-9746.html review all the information. As you can see you can disable this item from within the software, if you want it gone and do not use the RealPlayer (I don't see it in the log) then remove the item from here:
C:\Program Files\Common Files\Real\Update_OB\realsched.exe. You will have to choose what you want removed, if you remove the folder highlited in red all will be gone including the RealPlayer. This also will need to be done in Safe Mode.

Now, about my HijackThis log, I reason that I thought it was screwed up because it doesn't mention the ScanRegistry file.

I am on a WindowsXp machine and rather than boot my Windows 98 SE machine I believe I will be right if I suggest to you that you would only see your ScanRegistry if it was running at the time you created the HJT log. I am 99% (without testing it out) that Registry Checker runs when you start up and I am not sure if it would be visible in the log once it has completed it's function. Here is some additional information:
http://www.microsoft.com/resources/documen…rt6/wrkc31.mspx

I hope this helps…Phil
Pskelley, I was told that there was a way to get back ScanRegistry though. Also, how do you turn off Norton Antivirus? I can probably confirm that this is what's causing my Internet problems. Please respond back.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI