Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Browser Troubles


  • Please log in to reply
26 replies to this topic

#1 ZeYusAngelBee

ZeYusAngelBee

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Location:Fresno, California
  • Local time:08:20 AM

Posted 29 April 2004 - 07:59 PM

I am just very irritated with my browsers. I have 3 of them: IE6, YAHOO DSL Browser and Mozilla.

I don't run them all at once. I just reformatted my Windows 98SE and updated all the latest critical patches.

I empty my cookies and TIFs, so what gives? Why is every one of them slower than molasses in January?

I have DSL, I have all the latest anti-viral, anti-hijack and other software offered on this board and have run all of them. Squeaky clean system.

My father tweaked out the RAM and I have been told it is up to snuff and i have enough. I also have 83% of my total disc space free.

I am at the end of my rope. It not only runs slow, it hangs or refuses to take me to the other websites clicked either in Bookmarked pages or when using the <--BACK key.

In Mozilla, I thought I found the answer, NOW it's starting to slow down. HELP PLEASE.

ZeYusBee
~~ZeYusAngelBee~~

BC AdBot (Login to Remove)

 


#2 Bluie

Bluie

  • Members
  • 160 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Here OR there
  • Local time:08:20 AM

Posted 29 April 2004 - 08:45 PM

Well, yesterday, that is Wed April 28 from about 4pm through the rest of the evening it was the internet itself. And weekends are getting to be a real pain. If you have Verizon in Portland Or then maybe we could blame it on our server. First I blamed it on 98, changed to XP, that helped some. Then I blamed it on dialup connection, changed to DSL, that helped some. My theory is that we are just plain maxing the web system out. Oh yes and that is with all three of my browzers.

But that is not what you want to hear. All I can offer is sympathy because it sounds as if you have pretty well covered all the bases. Hopefully one of the real experts here will have some suggestions for you.

Edited by Bluie, 29 April 2004 - 08:46 PM.


#3 ZeYusAngelBee

ZeYusAngelBee
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Location:Fresno, California
  • Local time:08:20 AM

Posted 29 April 2004 - 09:52 PM

Well friend, I certainly feel better now. I thought it was happening to only me.

Considering this had 11 views, I think it's one of those things as you said. It is nothing more than a maxed out Internet.

I think in the world of Internet where nearly everyone around the globe is online, I guess it was bound to happen sooner or later.......doesn't help waiting forever for the stupid website though :thumbsup:
~~ZeYusAngelBee~~

#4 Bluie

Bluie

  • Members
  • 160 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Here OR there
  • Local time:08:20 AM

Posted 29 April 2004 - 10:27 PM

How is it tonight? No problems for me.

#5 Guest_MrSnausage_*

Guest_MrSnausage_*

  • Guests
  • OFFLINE
  •  

Posted 29 April 2004 - 11:02 PM

Yeah last night was creeping for me too here in New York City on road runner.

If you want to post a hijackthis log, i would be more than happy to tell you if i see something weird, but that would affect IE and not the other browsers.

#6 ZeYusAngelBee

ZeYusAngelBee
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Location:Fresno, California

Posted 29 April 2004 - 11:12 PM

Hello to the both of you :thumbsup:.

It is bad tonight too. Creeping last night to almost a stop and I was ready to throw out my computer.


When you say "fix this or fix that," please explain what you mean, ok? I am very new at this.

Thanks

My Hijack this log:

Logfile of HijackThis v1.97.7
Scan saved at 9:08:40 PM, on 4/29/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SA3DSRV.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\WINDOWS\CPQDIAG\CPQDFWAG.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\COMPAQ\INTERNET\ISDBDC.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\WEBSCANX.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\CPQS\BWTOOLS\SCCENTER.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\MOTIVE\MOTIVEASSISTANT\MOTMON.EXE
C:\PROGRAM FILES\YAHOO!\BROWSER\YBRWICON.EXE
C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
C:\PROGRAM FILES\YAHOO!\BROWSER\YCOMMON.EXE
C:\PROGRAM FILES\SUPPORT.COM\BIN\TGCMD.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGEMC.EXE
C:\PROGRAM FILES\MICROSOFT MONEY\SYSTEM\REMINDER.EXE
C:\PROGRAM FILES\MOZILLA.ORG\MOZILLA\MOZILLA.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\SBC\CONNECTION MANAGER\CMANAGER.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\BROADJUMP\CORRECTCONNECT ENGINE\CCD.EXE
C:\PROGRAM FILES\EFFICIENT NETWORKS\ENTERNET 300\APP\ENTERNET.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O2 - BHO: (no name) - {074E3AA7-7718-4404-B3F8-FF8FB5414E0E} - (no file)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [Aureal A3D Interactive Audio Init] A3dInit.exe
O4 - HKLM\..\Run: [Service Connection] c:\cpqs\bwtools\sccenter.exe
O4 - HKLM\..\Run: [AvconsoleEXE] C:\Program Files\Network Associates\McAfee VirusScan\avconsol.exe /minimize
O4 - HKLM\..\Run: [VsecomrEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSECOMR.EXE
O4 - HKLM\..\Run: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\Run: [VsStatEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSSTAT.EXE /SHOWWARNING
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [3dfx Tools] rundll32.exe 3dfxCmn.dll,UpdateRegSettings
O4 - HKLM\..\Run: [McAfeeWebScanX] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\WebScanX.Exe
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [System DLF] C:\WINDOWS\Cpqdiag\Cpqdiaga.exe -S -PC:\WINDOWS\Cpqdiag\
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\MotiveAssistant\motmon.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVG7\AVGEMC.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Aureal A3D Interactive Audio] sa3dsrv.exe
O4 - HKLM\..\RunServices: [CPQInet Runtime Service] c:\compaq\CPQInet\CpqInet.exe
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\WINDOWS\cpqdiag\CpqDfwAg.exe
O4 - HKLM\..\RunServices: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\RunServices: [isdbdc] c:\compaq\internet\isdbdc.exe
O4 - HKLM\..\RunServices: [HC Reminder] hc.exe
O4 - HKLM\..\RunServices: [McAfeeWebScanX] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\WebScanX.Exe /RUNSERVICES
O4 - HKLM\..\RunServices: [avgamsvr.exe] C:\PROGRA~1\GRISOFT\AVG7\AVGAMSVR.EXE
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft Money\System\reminder.exe
O4 - HKCU\..\Run: [SpyKiller] c:\program files\spykiller\spykiller.exe /startup
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\mozilla.org\Mozilla\Mozilla.exe" -turbo
O4 - Startup: Connection Manager.lnk = C:\Program Files\SBC\Connection Manager\CManager.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: AltaVista Home - http://jump.altavista.com/avie5/home
O8 - Extra context menu item: AV Search This Term - http://jump.altavista.com/avie5/search
O8 - Extra context menu item: AV Translate this Web Page - http://jump.altavista.com/avie5/babelfish
O8 - Extra context menu item: AV Translate Selection - http://jump.altavista.com/avie5/babelfish
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra 'Tools' menuitem: &AltaVista Home (HKLM)
O9 - Extra button: Translate (HKLM)
O9 - Extra 'Tools' menuitem: AV &Translate (HKLM)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL (HKLM)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Yahoo! Login (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://download.yahoo.com/dl/installs/yab_af.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...8103.7076041667
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033...all/xscan53.cab
~~ZeYusAngelBee~~

#7 Guest_MrSnausage_*

Guest_MrSnausage_*

  • Guests
  • OFFLINE
  •  

Posted 29 April 2004 - 11:37 PM

Well you have a very clean log Spyware wise. There are two things that bother me about how the computer is setup though.

The first is it seem you have both AVG and McAfee Virusscan running at the same time. You should only use one virusscan at a time as that can really bring down the performance of your computer. You should picjk the virusscan you want to use and uninstall the other.

Do you use Spykiller? Unless you pay for it tends to be useless so your better off without it. If you have never paid for it, uninstall it.

Second is that you seem to have a bunch of programs starting automatically which we will try to trim down the ones you do not need.

Fix these:

Does not hurt to fix this and cleans it up
R3 - Default URLSearchHook is missing

Stray registry entry because file is missing so we clean it up
O2 - BHO: (no name) - {074E3AA7-7718-4404-B3F8-FF8FB5414E0E} - (no file)

This is a compuler for help files that does not need to run automatically
O4 - HKLM\..\RunServices: [HC Reminder] hc.exe

This is the winzip icon in your systemtray that is unneeded and uses resources
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

Repost a new log after you fix these and figure out spykiller/virusscan

#8 ZeYusAngelBee

ZeYusAngelBee
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Location:Fresno, California
  • Local time:08:20 AM

Posted 29 April 2004 - 11:55 PM

Fixed. Trouble with McAfee, it came with the CD and I cannot uninstall it without my computer crashing. I don't want McAfee. I want AVG Anti-virus.

Here is the new log:

Logfile of HijackThis v1.97.7
Scan saved at 9:49:49 PM, on 4/29/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SA3DSRV.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\WINDOWS\CPQDIAG\CPQDFWAG.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\COMPAQ\INTERNET\ISDBDC.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\WEBSCANX.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\CPQS\BWTOOLS\SCCENTER.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\MOTIVE\MOTIVEASSISTANT\MOTMON.EXE
C:\PROGRAM FILES\YAHOO!\BROWSER\YBRWICON.EXE
C:\PROGRAM FILES\BROADJUMP\CLIENT FOUNDATION\CFD.EXE
C:\PROGRAM FILES\YAHOO!\BROWSER\YCOMMON.EXE
C:\PROGRAM FILES\SUPPORT.COM\BIN\TGCMD.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG7\AVGEMC.EXE
C:\PROGRAM FILES\MICROSOFT MONEY\SYSTEM\REMINDER.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\SBC\CONNECTION MANAGER\CMANAGER.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\BROADJUMP\CORRECTCONNECT ENGINE\CCD.EXE
C:\PROGRAM FILES\EFFICIENT NETWORKS\ENTERNET 300\APP\ENTERNET.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE
C:\PROGRAM FILES\MOZILLA.ORG\MOZILLA\MOZILLA.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [Aureal A3D Interactive Audio Init] A3dInit.exe
O4 - HKLM\..\Run: [Service Connection] c:\cpqs\bwtools\sccenter.exe
O4 - HKLM\..\Run: [AvconsoleEXE] C:\Program Files\Network Associates\McAfee VirusScan\avconsol.exe /minimize
O4 - HKLM\..\Run: [VsecomrEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSECOMR.EXE
O4 - HKLM\..\Run: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\Run: [VsStatEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSSTAT.EXE /SHOWWARNING
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [3dfx Tools] rundll32.exe 3dfxCmn.dll,UpdateRegSettings
O4 - HKLM\..\Run: [McAfeeWebScanX] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\WebScanX.Exe
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [System DLF] C:\WINDOWS\Cpqdiag\Cpqdiaga.exe -S -PC:\WINDOWS\Cpqdiag\
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\MotiveAssistant\motmon.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [tgcmdprovidersbc] "c:\program files\support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVG7\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVG7\AVGEMC.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Aureal A3D Interactive Audio] sa3dsrv.exe
O4 - HKLM\..\RunServices: [CPQInet Runtime Service] c:\compaq\CPQInet\CpqInet.exe
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\WINDOWS\cpqdiag\CpqDfwAg.exe
O4 - HKLM\..\RunServices: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\RunServices: [isdbdc] c:\compaq\internet\isdbdc.exe
O4 - HKLM\..\RunServices: [McAfeeWebScanX] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\WebScanX.Exe /RUNSERVICES
O4 - HKLM\..\RunServices: [avgamsvr.exe] C:\PROGRA~1\GRISOFT\AVG7\AVGAMSVR.EXE
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft Money\System\reminder.exe
O4 - HKCU\..\Run: [SpyKiller] c:\program files\spykiller\spykiller.exe /startup
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\mozilla.org\Mozilla\Mozilla.exe" -turbo
O4 - Startup: Connection Manager.lnk = C:\Program Files\SBC\Connection Manager\CManager.exe
O8 - Extra context menu item: AltaVista Home - http://jump.altavista.com/avie5/home
O8 - Extra context menu item: AV Search This Term - http://jump.altavista.com/avie5/search
O8 - Extra context menu item: AV Translate this Web Page - http://jump.altavista.com/avie5/babelfish
O8 - Extra context menu item: AV Translate Selection - http://jump.altavista.com/avie5/babelfish
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra 'Tools' menuitem: &AltaVista Home (HKLM)
O9 - Extra button: Translate (HKLM)
O9 - Extra 'Tools' menuitem: AV &Translate (HKLM)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL (HKLM)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Yahoo! Login (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/.../ymmapi_416.dll
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://download.yahoo.com/dl/installs/yab_af.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...8103.7076041667
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033...all/xscan53.cab
~~ZeYusAngelBee~~

#9 Guest_MrSnausage_*

Guest_MrSnausage_*

  • Guests
  • OFFLINE
  •  

Posted 30 April 2004 - 08:05 AM

What about spykiller? Did you pay for that or is it the free trial?

When you say Mcafee crashes when you uninstall what exactly happens? Is this when you try it through the add/remove programs?

I can make it so it does not load up automatically but it will still be on your computer if you wish.

#10 ZeYusAngelBee

ZeYusAngelBee
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Location:Fresno, California

Posted 30 April 2004 - 09:34 AM

What about spykiller? Did you pay for that or is it the free trial?

When you say Mcafee crashes when you uninstall what exactly happens? Is this when you try it through the add/remove programs?

I can make it so it does not load up automatically but it will still be on your computer if you wish.

I did not know I still had SpyKiller. Free trial my *&^%^&! It's worthless unless you buy the license. It found files but, you couldn't clean them (which is stupid)I thought I had uninstalled it (I even ran RegCleaner).

I will go through computer files and delete it manually as it's no longer listed in ADD/REMOVE or in my PROGRAMS folder.

I have disabled McAfee it in msconfig but no matter how careful I am, it crashes my computer if I uninstall it either through the ADD/REMOVE utility or by manually removing the files. What's worse, there IS NO uninstall for this program, meaning, it isn't supposed to be removed.

They did that on purpose so that you HAD to purchase the license to activate it passed the expiration date just to be able to uninstall it. I have scoured their website looking for the uninstall program there and I cannot even access anything because I haven't purchased it.

I even thought I could use the trial ware (they have none) and uninstall that way. No such luck.

By crash I mean, I get the dreaded blue screen with an error message from HELL itself (something about not being able to find a certain very needed Windows DLL file or two) locking me out of everything. I cannot even access Windows through SAFE mode when that happens.

Did the log look better?

ZeYusBee
~~ZeYusAngelBee~~

#11 Guest_MrSnausage_*

Guest_MrSnausage_*

  • Guests
  • OFFLINE
  •  

Posted 30 April 2004 - 09:40 AM

Log looks fine. If you want we can try to manually disable mcafee from starting if your willing to take that risk. I do not see why disabling the mcafee stuff from startup should cause a problem.

Your call though.

#12 Bluie

Bluie

  • Members
  • 160 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Here OR there
  • Local time:08:20 AM

Posted 30 April 2004 - 10:19 AM

When you do tne uninstall does it ask you about deleting shared files? Tell it NO.

Which DLL file does it say is missing? Perhaps you could make a duplicate of that file and replace it after you get rid of McAfee.

#13 ZeYusAngelBee

ZeYusAngelBee
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Location:Fresno, California

Posted 30 April 2004 - 01:45 PM

You know, I have truly tried that, but it doesn't work.

I have a website that has every imagineable DLL or driver you can think of, and I have downloaded them but it still crashes my system.

I have said NO to shared files......it doesn't matter it seems.
~~ZeYusAngelBee~~

#14 ZeYusAngelBee

ZeYusAngelBee
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Location:Fresno, California
  • Local time:08:20 AM

Posted 30 April 2004 - 01:51 PM

BTW, I have disabled it from Start up. At this point I am leary of messing with trying to remove it. I cannot tell you how many system crashes I have had with this stupid program :trumpet: :thumbsup: :flowers:

The only one that knows the hell i have been through with my system is Papakid.

He's pulled my arse out of many a mess! So I really don't want to mess up anything unless there is a sure fire way to irraticate the darned program without destroying my system in the process (or forcing me to do another reformat).

Anyways.......that's my story and I am sticking to it :inlove:
~~ZeYusAngelBee~~

#15 Papakid

Papakid

    Guru at being a Newbie


  • Malware Response Team
  • 6,663 posts
  • ONLINE
  •  
  • Gender:Male

Posted 30 April 2004 - 03:05 PM

Hi Deb,

He's pulled my arse out of many a mess!

:thumbsup:
I don't recall that. Honestly I don't.
Anyway I wrote the following while you were posting your last two. After exchanging PM's with Mr.Snausage.
-----------------------------------------------------------------
Let's try a few things.

There should be a way to uninstall McAfee and what Bluie recommends about leaving any shared dll files behind could well be what the problem is--and it is important to know what exactly the blue screen is complaining about. But let's try disabling those McAfee startups first.


1. Download & install System Security Suite (3S).
2. Open the MS Configuration Utility. I know you know how to do this, but for the benefit of others--START>Run>type in MSCONFIG>OK.
3. In the Startup tab, make sure all McAfee entries are checked. Let me know if those entries had checks by them when you first look at the screen--some items, like qttask, will recheck themselves--but I want you to make sure the McAfee Items are checked. Also uncheck the startup entries associated with AVG. NOTE: This all should be done while offline & disconnected from DSL.
4. Click OK, Close MSCONFIG & reboot.
5. Open 3S and click on the AutoRun Tasks tab.
6. Put a check by all of the McAfee startup entries.
7. Click the "Lock" Checked button.
8. Close 3S and reboot.
9. If you get a blue screen on restart, write down all the details & post it back here. Then follow the above steps in reverse order to reverse what you just did and we'll try something else.

If you don't have a blue screen or any other problems running your OS or any offline programs, before going online again, do this:

10. Open MSCONFIG again & recheck the AVG startups. (AVGCC.EXE & AVGEMC.EXE) And check to see if McAfee has rechecked itself.

Let us know how that goes. If we can't figure out a way to unistall McAfee or if you just want to play it safe & this works for you, then at least you won't have two AV's running at the same time.

There are a couple of other things that concern me when looking at your log. So I want you to do this:

1. Scan with HijackThis again. Put a check by the following after ensuring all other windows are closed.:
O4 - HKCU\..\Run: [SpyKiller] c:\program files\spykiller\spykiller.exe /startup

2. Click the Fix Checked button & reboot.
3. In Windows Explorer, navigate to the Program Files folder & delete the entire Spykiller directory. Be sure the Recycle Bin is configured so that files remain there until you empty the bin. Because you want to leave them in there for a while to be sure no problems arise from their removal. You can empty the bin later if you feel it's safe.

The other item: After fixing with HT the BHO for Yahoo Companion appeared with a file missing. Is your toolbar misbehaving? I believe (but don't know for sure) that the missing URL searchhook should not have been fixed, that's what affected your BHO. MrSnausage thought he saw a file missing there. So let's try restoring that item with HijackThis.

1. Please review this section of our HijackThis tutorial. I've not done a restore, but it should be pretty easy. When you get to the point where you see the screen as it appears in the tute's screenshot, select "Default URLSearchHook" (probably a check box) & click Restore.
2. Reboot, & let us know if there is any change in behavior.

Let's see how that goes. There are some other things that may need attention or if you get stuck somewhere let us know that too.

Edited by Papakid, 30 April 2004 - 03:14 PM.

We always did feel the same

We just started from a different point of view

Tangled up in blue--Bob Dylan





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users