This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

In over my head

42 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:blink: Curses Foiled AGAIN!

Well I was awfully dang optimistic… and that's my fault. I should know by now when I am feeling good something is going to come and kick me in the jimmy. This morning I was pleased to see the system up and running fine when I came in. The AVG had scanned my backup drive with a clean scan. Yipee!

Okay so lets start now with the bad news…. Hmmm well It seems that Windows had to increase the virtual memory because system resources were low… This was/is a tad vexing to me as,
  • I had recently doubled the amount of RAM
  • The only things I had up and running were AVG and background functions.
So I bring up TASKMANGER and sure enough over 50% of my physical memory is in use. Now that would mean that if I hadn't just doubled it all would be gone. What in the SAM HADES is using it all. Well I didn't get the chance to write it all down because the system was acting a tad cranky and I foolishly thought maybe a restart would fix it… But I do seem to recall that whole bunch of the big users had CC as a part of their name. That's right Virginia there is a memory hogging satan.. and his name is Norton. Oh! And this was with NORTON OFF!! I've had it shut down since I started this fix.

Well fine.. I know I have the total suite of Norton paid up for another 137 days but I'll uninstall it and go with AVG and the rest of the programs recommended. Well So I shut AVG down and open up the Norton console to see if it has it's own method of uninstall. Not finding it.. Go to ADD/REMOVE. Click on NORTON SYSTEMS WORKS. *REBOOT VIA POWERCYCLE* WEEEeeeeeeeee.!! :weee:
Come back up to LogIn… Try again Oh and Now though disabled NORTON is up and running in semi-full force. Start->Settings->REBOOT! :scratch:
LOGIN->REBOOT :huh:
LOGIN->ACTIVE DESKTOP RECOVERY->BLUESCREEN!

:(

" Stop: 0x0000001E (0xC0000005, 0x804B45F, 0x00000000, 0x0000005B)
Kmode_Exception_Not_Handled *Address 804B485F base @ 80400000 Datestamp 45069e6e - notoskrnl.exe.

If this is the first time you've seen this Stop error screen, restart your computer.


(So I set the hammer down)

If this screen appears again, follow these steps:

Check to be sure you have adequate Disk Space. If a driver is identified in the Stop Message, disable the Driver or check with the manufacturer for Driver Updates. Try changing the Video Adapters.

Check with your Hardware Vendor for any BIOS updates. Disable Memory options such as Caching or Shadowing. If you need to use SAFEMODE to remove or disable components, RESTART your computer, PRESS F8 to select ADVANCED STARTUP OPTIONS, and then select SAFEMODE.

Refer to your GETTING STARTED MANUAL for more information trouble shooting Stop errors
."

(Notice that they failed to mention the hammer a most negligent omission to be sure.)



Well I am proceeding with the rec's given and really look forward to hearing any and all advice. If this has become an off topic post just give me a nudge on how to remove it to the appropriate forum.


Thankyou again for all your help both past and future.

~Po.

UPDATE: Tried to reboot via Powercyle… It hung at the gray WINDOWS IS STARTING SCREEN… Turned off MAXTOR.. TURNED OFF COMPUTER… Trying to get it up in SAFEMODE.
Well Bummer… You can't get rid of Norton in SAFEMODE it seems… at least not via the ADD/REMOVE console. And I didn't see an obvious uninstall icon. It wants me to start up in normal mode so I guess. Looking to see my Disk space etc…. Noticed that the USB problem device is back can't seem to find the correct drivers. Could that be because I have the MAXTOR off? Don't know. OK Disk Space "should" be fine… I have 24.9 GB of 37.2 GB available Was in C:->Properties *clicked* the Norton TAB and Windows Explorer Generated an error and had to quit. System Properties->Advanced->Performance Options: Optimize performance for Applications. Wondering if this should be set to Background Services. Virtual Memory: Total Paging file size for all drives @ 384MB change? no clue. Startup & Recovery: Default Operating System : "Microsoft Windows 2000 Professional" /fastdetect Check - on Display list of operating systems for -30- seconds. System Failure: Check - Write an event to the system log Check - Send and administrative alert NOCheck- Automatically reboot Write Debugging Information -Small Memory Dump (64 KB) Small Dump Directory: -%SystemRoot%\Minidump Check (but grayed out) Overwrite any existing file Trying a restart. After I find a prayer candle.
Hmmmmm Just read this post…. Wonder if that effected me?

WARNING-Combofix

Please Do Not use Combofix and delete Combofix from your computer!

Malware has recently been created and identified that will cause ComboFix to delete normal files and adversely affect your computer.

  • If you have run ComboFix in the past and did not suffer any adverse affects do not worry, but please delete ComboFix now.
  • You must have the specific malware infection present on your system to cause ComboFix to delete the normal files, but as safety precaution you need to delete ComboFix now!


Wonder what the specific infection is…
Guess I will delete as LDtate said to ditch what ever he'd have me installed.
OH DANGNATION!!


Up in desktop recovery mode*. Printed the instructions to uninstall Norton… looked on laptop to see if there were any replies… Came back to trouble system and it's frozen…

Update 1: Up in DRM* Following Norton instructions to uninstall as it's hogging my memory now and making all other fixes next to impossible. START->SETTINGS->CONTOL PANEL->ADD/REMOVE->Norton SystemWorks-> REBOOT! :wavey:

God Bless America ain't this fun.




Update 2: Back in DRM* AVG and Norton Suite both loaded… Shut AVG down, Start to shut Norton down… Then to proceed with Uninstall.. Yeah it freezes. :weee: Weeeeeee.


Update 3:Back in DRM* Restore Active Desktop, Close AVG, Close Norton GO BACK, Open Norton Systems Work Panel to try to close it. No dice, can't find the exit program function. Curse my poor memory… That's personal not RAM…Close the Norton window… Gonna try making it to the Task Manager… Foolish mortal… System Freeze… NO SOUP FOR YOU!. REBOOT! It's a muddy road ahead.

Think I'll drive down to the Druid City and find me a psychiatrist maybe that'll help. :blink:

Update 4: More trouble… *sings* If it weren't for bad luck I'd have no luck at all… Pain, despair, and agony on me…" Seem the dang cursor locked up before I even got through the CTRL ALT DEL screen that helps keep my password secure… This is about to insist on my taking a break from all of this as the hammer and woodchipper are looking mighty good right now.
Update 6: NOTE TO SELF: DO NOT TRY TO BOOT INTO DEBUGGING MODE THOU DOST NOT KNOW ENOUGH TO USE IT. ALL I GOT was a blank desktop with a start bar and no cursor… Rebooting last try to get anything done. Before I have to run for a few hours to keep my sanity. Up in DRM* START->SETTINGS->ADD/REMOVE-> NORTON SYSTEMWORKS 2006->REMOVE->UNINSTALLATION IN PROCESS->GET DOWN ON MY KNEES AND PRAY.-> Partway through I saw something about Beavcom. Then got to a Software KEY and froze. Key: SOFTWARE\CLASSES\CLSID\{B27AF784-C7FB-11D1-B535-0060085C418E}\InprocServer32, Name:T… That's as far as I can read and the only thing to do is Powercycle. I am getting the flock out of here for a bit before the folks in this office see a grown man cry. :wavey:
Run system file checker again.

You can use windows sfc (system file checker) You'd need your XP CD to make this work.
Click Start> Run> type sfc /scannow Note the space.
(Note that there is a space between sfc and /scannow)
I assume you meant win2k. So that's what I used. I do have xp cd's this is actually the only system still on WIN2kPRO. You don't figure that the fact that the WIN2KPRO Operating systems disk's being SP-1 could cause any issues what with the system itself now being on SP-4. Also it (SFC) has run is it supposed to generate a report or anything? As far as I can tell it just runs and closes.
Well I ran SFC… Got some cursor & or systems locks… No I didn't click on the window whilst it was running. The SFC actually seemed to run fine. Tried to Uninstall Norton Systems Works 2006 got some errors with the uninstall posssibly the result of the 'first' attempt that froze 1/3 way through. Indicated I needed to go to the website. So reboot via advised restart. Try again… Hoping to maybe at least get the message again now that I have the system back online. Bluescreen

*** STOP: 0x0000007F (0x0000000D,0x00000000,0x00000000,0x00000000)
UNEXPECTED_KERNEL_MODE_TRAP

Beginning dump of physical memory
Physical memory dump complete. Contact your system administrator or technical support group.

Well unfortunately for the poor sods who need the computational device the former is me so I've been contacted… Maybe they'll have better luck out of their technical support group which would be you fine folks.

This all just makes me so warm and fuzzy inside.
I think I might get an abacus.
Man this is kicking my tuckus. Spontaneous reboots. Locks up everytime I try to uninstall Norton.. Processor maxed doing sweet F.A. cursor freeze. Not sure where to go from here.
In order to completely uninstall Symantec AntiVirus and all related components you need to follow these instructions.
Note: This procedure will remove all Symantec products, not just Symantec AntiVirus.

1.Click on Start | Settings | Control Panel
2.In the control panel double-click on Add / Remove Programs
3.Look through the list of installed programs for any item that says either "Norton" or "Symantec" or "LiveUpdate". (for example "Symantec AntiVirus Corporate Edition" or "Norton AntiVirus 2000")
4.For each "Norton", "Symantec", or "LiveUpdate" item, select the item and click Add / Remove. Follow the instructions, and click Yes or Yes to all when prompted.
When you are done there should be no items in the list that say "Norton", "Symantec", or "LiveUpdate".
5.Click OK to close the Add / Remove Programs window.
6.Reboot your computer if it hasn't already automatically rebooted.
7.Delete the c:\Program Files\Symantec AntiVirus (or c:\Program Files\Norton) folder.
8.Delete the c:\Program Files\Symantec folder.
9.Delete the c:\Program Files\Common Files\Symantec Shared folder.



If uninstalling Symantec AntiVirus using Add / Remove Programs does not work, you can use the directions on this Symantec website to manually remove all elements of Symantec Antivirus from your computer.
http://service1.symantec.com/SUPPORT/ent-s…src=bar_sch_nam
I may try the manual way here shortly the problem I am having getting it done is the system keeps freezing mid process. I 'think' this is due in part from Norton hogging the systems resources… so I would need to boot up/ control startup in such a way that it didn't load. And/or there are bad mouse drivers or something…. Did you take a look at that Stop error I posted?

*** STOP: 0x0000007F (0x0000000D,0x00000000,0x00000000,0x00000000)
UNEXPECTED_KERNEL_MODE_TRAP


Not sure if that is indicative of what sort of problem I am having.

Okay so it could be software or hardware…. Got the same tried replacing the memory before I ever came on to this forum. Don't really have a 'Spare' motherboard lying about. Tried to run the Memory diagnostics tool from MICROSOFT. As I didn't have much luck finding it on the two Compaq disk I looked at. TRied with floppy and got disk I/O error. Could these trouble be explained by I/O conflicts that somehow the machine doesn't flag? I did not I have multiple entries for some controllers particularly in the USB area. Also it seemed like there were a number of disparate devices using the same IRQ's? Any hint's on what to look for? I am trying to make a cd version of the Microsoft Memory Diagnostics tool now. *DISCLAIMER* I just barely know enough to get myself in trouble with the I/O IRQ stuff.
So I didn't have much luck with the CD version of the Memory diagnostic. It just booted right past it.
Suppose I am grasping at straws now.
Here is the Hijack This Startup log.

StartupList report, 2/16/2007, 6:23:30 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Hijackthis\HijackThis.EXE
Detected: Windows 2000 SP4 (WinNT 5.00.2195)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
* Including empty and uninteresting sections
==================================================

Running processes:

C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Program Files\Maxtor\OneTouch\utils\mspm.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe

————————————————–

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Administrator\Start Menu\Programs\Startup]
*No files*

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINNT\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

NvCplDaemon = RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
nwiz = nwiz.exe /install
Synchronization Manager = mobsync.exe /logon
HPDJ Taskbar Utility = C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
MaxtorOneTouch = C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
mspm = C:\Program Files\Maxtor\OneTouch\utils\mspm.exe
mxomssmenu = "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
!AVG Anti-Spyware = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

KillWelcomeScreen = E:\TOOLS\notwell.exe

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

swg = C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
*No values found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

————————————————–

File association entry for .HTA:
*Registry value not found*

————————————————–

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

————————————————–

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

————————————————–

Load/Run keys from C:\WINNT\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

————————————————–

Shell & screensaver key from C:\WINNT\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6}
NAV Helper - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD}
(no name) - c:\program files\google\googletoolbar4.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}

————————————————–

Enumerating Task Scheduler jobs:

Norton AntiVirus - Run Full System Scan - Administrator.job
Norton AntiVirus - Run Norton QuickScan - Administrator.job
Symantec Drmc.job

————————————————–

Enumerating Download Program Files:

[DirectAnimation Java Classes]
CODEBASE = file://C:\WINNT\Java\classes\dajava.cab
OSD = C:\WINNT\Downloaded Program Files\DirectAnimation Java Classes.osd

[Microsoft XML Parser for Java]
CODEBASE = file://C:\WINNT\Java\classes\xmldso.cab
OSD = C:\WINNT\Downloaded Program Files\Microsoft XML Parser for Java.osd

[{00000075-0000-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.microsoft.com/codecs/i386/voxmsdec.CAB

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINNT\system32\LegitCheckControl.DLL
CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

[Symantec AntiVirus scanner]
InProcServer32 = C:\WINNT\Downloaded Program Files\avsniff.dll
CODEBASE = http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab

[{31564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.microsoft.com/codecs/i386/wmvax.cab

[{32564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.microsoft.com/codecs/i386/wmv8ax.cab

[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB

[Walt Disney Internet Group Hardware Control]
InProcServer32 = C:\WINNT\DOWNLO~1\DIGHAR~1.OCX
CODEBASE = https://disneyblast.go.com/v3/setup/activex…wareControl.cab

[Symantec RuFSI Utility Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\rufsi.dll
CODEBASE = http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab

[Update Class]
InProcServer32 = C:\WINNT\system32\iuctl.dll
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/…9106.6022916667

[Crucial cpcScan]
InProcServer32 = C:\WINNT\Downloaded Program Files\cpcScan.dll
CODEBASE = http://www.crucial.com/controls/cpcScanner.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINNT\system32\Macromed\Flash\Flash9b.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa…ash/swflash.cab

[{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/…/yiebio4028.cab

————————————————–

Enumerating Winsock LSP files:

NameSpace #1: C:\WINNT\System32\rnr20.dll
NameSpace #2: C:\WINNT\System32\winrnr.dll
Protocol #1: C:\WINNT\system32\msafd.dll
Protocol #2: C:\WINNT\system32\msafd.dll
Protocol #3: C:\WINNT\system32\msafd.dll
Protocol #4: C:\WINNT\system32\rsvpsp.dll
Protocol #5: C:\WINNT\system32\rsvpsp.dll
Protocol #6: C:\WINNT\system32\msafd.dll
Protocol #7: C:\WINNT\system32\msafd.dll
Protocol #8: C:\WINNT\system32\msafd.dll
Protocol #9: C:\WINNT\system32\msafd.dll
Protocol #10: C:\WINNT\system32\msafd.dll
Protocol #11: C:\WINNT\system32\msafd.dll

————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

Network.ConnectionTray: C:\WINNT\system32\netshell.dll
WebCheck: C:\WINNT\system32\webcheck.dll
SysTray: stobject.dll

————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

————————————————–

End of report, 17,025 bytes
Report generated in 0.094 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI