I'm having a few problems. I get intermittent freeze up runing Win ME. Also when I shutdown I freeze, forcing me to press power button. What seems to worry me the most is sometimes when I shutdown, I get a dialog box stating a program is not responding and then gives me the option to end task or wait, but there isn't any program name on the title bar. I'm concerned if this is viral behavior. I have not read any other post on this.
Here is my startuplist that everyone else seem to be fond of but i haven't a clue what most of these entries are. Much appreciated for any help.
StartupList report, 1/27/2003, 11:12:54 PM
StartupList version: 1.51
Started from : F:\INCOMING\STARTUPLIST.EXE
Detected: Windows ME (Win9x 4.90.3000)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\ADAPTEC\GOBACK\GBPOLL.EXE
C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\EXECUTIVE SOFTWARE\DISKEEPERWORKSTATION\DKSERVICE.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\BCMDMMSG.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\POPROXY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\VERIZON ONLINE\WINPOET\WINPPPOVERETHERNET.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\ICSMGR.EXE
C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\LOGITECH\DESKTOP MESSENGER\8876480\PROGRAM\BACKWEB-8876480.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZAPRO.EXE
C:\WEBSHOTZ\WEBSHOTS\WEBSHOTSTRAY.EXE
E:\ACROBAT\DISTILLR\ACROTRAY.EXE
F:\INCOMING\STARTUPLIST.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM\E_SRCV02.EXE
Webshots.lnk = C:\webshotz\Webshots\WebshotsTray.exe
Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
Acrobat Assistant.lnk = E:\acrobat\Distillr\AcroTray.exe
Shell folders Common Startup:
[C:\WINDOWS\All Users\Start Menu\Programs\StartUp]
ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
TaskMonitor = C:\WINDOWS\taskmon.exe
SystemTray = SysTray.Exe
Norton Auto-Protect = C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
NAV DefAlert = C:\PROGRA~1\NORTON~1\DEFALERT.EXE
Norton eMail Protect = C:\Program Files\Norton AntiVirus\POPROXY.EXE
Tweak UI = RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\SYSTEM\\NVCpl.dll,NvStartup
a-winpoet-service = "C:\Program Files\Verizon Online\WinPoET\winpppoverethernet.exe"
ICSMGR = ICSMGR.EXE
EM_EXEC = C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE
devldr16.exe = C:\WINDOWS\SYSTEM\devldr16.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*StateMgr = C:\WINDOWS\System\Restore\StateMgr.exe
GoBack Polling Service = C:\Program Files\Adaptec\GoBack\GBPoll.exe
SAgent2ExePath = C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
TrueVector = C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
SchedulingAgent = mstask.exe
DkService = C:\Program Files\Executive Software\DiskeeperWorkstation\DkService.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
LDM = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
Microsoft Works Update Detection = C:\Program Files\Microsoft Works\WkDetect.exe
--------------------------------------------------
C:\WINDOWS\WININIT.BAK listing:
(Created 25/1/2003, 23:44:20)
[rename]
nul=C:\WINDOWS\TEMP\~f51e43.tmp
nul=C:\WINDOWS\TEMP\~f51e43.tmp
--------------------------------------------------
C:\AUTOEXEC.BAT listing:
SET windir=C:\WINDOWS
SET winbootdir=C:\WINDOWS
SET COMSPEC=C:\WINDOWS\COMMAND.COM
SET PATH=C:\WINDOWS;C:\WINDOWS\COMMAND;E:\ULTRAE~1
SET PROMPT=$p$g
SET TEMP=C:\WINDOWS\TEMP
SET TMP=C:\WINDOWS\TEMP
--------------------------------------------------
C:\WINDOWS\WINSTART.BAT listing:
C:\WINDOWS\tmpcpyis.bat
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\PROGRA~1\SURFSA~1\SURFSA~1.DLL (file missing) - {CBB0A6A0-8430-11D4-814D-0050047090B1}
(no name) - c:\windows\downloaded program files\googletoolbar_en_1.1.66-deleon.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - E:\ACROBAT\ACROBAT\ACTIVEX\ACROIEHELPER.OCX - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Tune-up Application Start.job
PCHealth Scheduler for Data Collection.job
Symantec NetDetect.job
Maintenance-Defragment programs.job
Maintenance-ScanDisk.job
Maintenance-Disk cleanup.job
weekly virus scan.job
daily live update check.job
--------------------------------------------------
Enumerating Download Program Files:
[{11111111-1111-1111-1111-111111111111}]
CODEBASE = http://canderp1.nocreditcard.net/download/newdial-erp/975/dialer.exe
[MSNBC News Menu Control 3.01]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\NEWSM301.OCX
CODEBASE = http://www.msnbc.com/download/nr1228.cab
[IPIX ActiveX Control]
InProcServer32 = C:\WINDOWS\OCCACHE\IPIXX.OCX
CODEBASE = http://www.ipix.com/viewers/ipixx.cab
[CfgAOL Class 2]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\NSCFGAOL.DLL
CODEBASE = https://www.netsetter.com/r/ns/config/nscfgaol.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
[GigexCtrl ActiveX]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\GIGEXAGENT.DLL
CODEBASE = http://www.gigex.com/tv/igor/gigexagent.dll
[{41F17733-B041-4099-A042-B518BB6A408C}]
CODEBASE = http://a224.g.akamai.net/7/224/52/2...apple.com/qt502/us/win/QuickTimeInstaller.exe
[MailConfigure Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MAILCFG.DLL
CODEBASE = http://supportservices.msn.com/us/oeconfig/MailCfg.cab
[Symantec RuFSI Registry Information Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\RUFSI.DLL
CODEBASE = http://security1.norton.com/us/sa/common/common/bin/cabsa.cab
[CV3 Class]
InProcServer32 = C:\WINDOWS\SYSTEM\WUV3IS.DLL
CODEBASE = http://windowsupdate.microsoft.com/R1024/V31Controls/x86/mil/en/actsetup.cab
[Symantec AntiVirus scanner]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\AVSNIFF.DLL
CODEBASE = http://security1.norton.com/SSC/SharedContent/vc/bin/AvSniff.cab
[Download.Complete]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\DOWNLOAD.OCX
CODEBASE = http://www.measureup.com/test/controls/SelectPlace.CAB
[AV Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\PAV.DLL
CODEBASE = http://pcpitstop.com/antivirus/PCPAV.CAB
[QuickTime Object]
InProcServer32 = C:\WINDOWS\SYSTEM\QTPLUGIN.OCX
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab
[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37594.828125
--------------------------------------------------
Enumerating Winsock LSP files:
Protocol #1: csloa2.dll (file MISSING)
--------------------------------------------------
End of report, 8,307 bytes
Report generated in 0.607 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Here is my startuplist that everyone else seem to be fond of but i haven't a clue what most of these entries are. Much appreciated for any help.
StartupList report, 1/27/2003, 11:12:54 PM
StartupList version: 1.51
Started from : F:\INCOMING\STARTUPLIST.EXE
Detected: Windows ME (Win9x 4.90.3000)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\ADAPTEC\GOBACK\GBPOLL.EXE
C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\EXECUTIVE SOFTWARE\DISKEEPERWORKSTATION\DKSERVICE.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\BCMDMMSG.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\POPROXY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\VERIZON ONLINE\WINPOET\WINPPPOVERETHERNET.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\ICSMGR.EXE
C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\LOGITECH\DESKTOP MESSENGER\8876480\PROGRAM\BACKWEB-8876480.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZAPRO.EXE
C:\WEBSHOTZ\WEBSHOTS\WEBSHOTSTRAY.EXE
E:\ACROBAT\DISTILLR\ACROTRAY.EXE
F:\INCOMING\STARTUPLIST.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM\E_SRCV02.EXE
Webshots.lnk = C:\webshotz\Webshots\WebshotsTray.exe
Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
Acrobat Assistant.lnk = E:\acrobat\Distillr\AcroTray.exe
Shell folders Common Startup:
[C:\WINDOWS\All Users\Start Menu\Programs\StartUp]
ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
TaskMonitor = C:\WINDOWS\taskmon.exe
SystemTray = SysTray.Exe
Norton Auto-Protect = C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
NAV DefAlert = C:\PROGRA~1\NORTON~1\DEFALERT.EXE
Norton eMail Protect = C:\Program Files\Norton AntiVirus\POPROXY.EXE
Tweak UI = RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\SYSTEM\\NVCpl.dll,NvStartup
a-winpoet-service = "C:\Program Files\Verizon Online\WinPoET\winpppoverethernet.exe"
ICSMGR = ICSMGR.EXE
EM_EXEC = C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE
devldr16.exe = C:\WINDOWS\SYSTEM\devldr16.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*StateMgr = C:\WINDOWS\System\Restore\StateMgr.exe
GoBack Polling Service = C:\Program Files\Adaptec\GoBack\GBPoll.exe
SAgent2ExePath = C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
TrueVector = C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
SchedulingAgent = mstask.exe
DkService = C:\Program Files\Executive Software\DiskeeperWorkstation\DkService.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
LDM = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
Microsoft Works Update Detection = C:\Program Files\Microsoft Works\WkDetect.exe
--------------------------------------------------
C:\WINDOWS\WININIT.BAK listing:
(Created 25/1/2003, 23:44:20)
[rename]
nul=C:\WINDOWS\TEMP\~f51e43.tmp
nul=C:\WINDOWS\TEMP\~f51e43.tmp
--------------------------------------------------
C:\AUTOEXEC.BAT listing:
SET windir=C:\WINDOWS
SET winbootdir=C:\WINDOWS
SET COMSPEC=C:\WINDOWS\COMMAND.COM
SET PATH=C:\WINDOWS;C:\WINDOWS\COMMAND;E:\ULTRAE~1
SET PROMPT=$p$g
SET TEMP=C:\WINDOWS\TEMP
SET TMP=C:\WINDOWS\TEMP
--------------------------------------------------
C:\WINDOWS\WINSTART.BAT listing:
C:\WINDOWS\tmpcpyis.bat
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\PROGRA~1\SURFSA~1\SURFSA~1.DLL (file missing) - {CBB0A6A0-8430-11D4-814D-0050047090B1}
(no name) - c:\windows\downloaded program files\googletoolbar_en_1.1.66-deleon.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - E:\ACROBAT\ACROBAT\ACTIVEX\ACROIEHELPER.OCX - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Tune-up Application Start.job
PCHealth Scheduler for Data Collection.job
Symantec NetDetect.job
Maintenance-Defragment programs.job
Maintenance-ScanDisk.job
Maintenance-Disk cleanup.job
weekly virus scan.job
daily live update check.job
--------------------------------------------------
Enumerating Download Program Files:
[{11111111-1111-1111-1111-111111111111}]
CODEBASE = http://canderp1.nocreditcard.net/download/newdial-erp/975/dialer.exe
[MSNBC News Menu Control 3.01]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\NEWSM301.OCX
CODEBASE = http://www.msnbc.com/download/nr1228.cab
[IPIX ActiveX Control]
InProcServer32 = C:\WINDOWS\OCCACHE\IPIXX.OCX
CODEBASE = http://www.ipix.com/viewers/ipixx.cab
[CfgAOL Class 2]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\NSCFGAOL.DLL
CODEBASE = https://www.netsetter.com/r/ns/config/nscfgaol.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
[GigexCtrl ActiveX]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\GIGEXAGENT.DLL
CODEBASE = http://www.gigex.com/tv/igor/gigexagent.dll
[{41F17733-B041-4099-A042-B518BB6A408C}]
CODEBASE = http://a224.g.akamai.net/7/224/52/2...apple.com/qt502/us/win/QuickTimeInstaller.exe
[MailConfigure Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MAILCFG.DLL
CODEBASE = http://supportservices.msn.com/us/oeconfig/MailCfg.cab
[Symantec RuFSI Registry Information Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\RUFSI.DLL
CODEBASE = http://security1.norton.com/us/sa/common/common/bin/cabsa.cab
[CV3 Class]
InProcServer32 = C:\WINDOWS\SYSTEM\WUV3IS.DLL
CODEBASE = http://windowsupdate.microsoft.com/R1024/V31Controls/x86/mil/en/actsetup.cab
[Symantec AntiVirus scanner]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\AVSNIFF.DLL
CODEBASE = http://security1.norton.com/SSC/SharedContent/vc/bin/AvSniff.cab
[Download.Complete]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\DOWNLOAD.OCX
CODEBASE = http://www.measureup.com/test/controls/SelectPlace.CAB
[AV Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\PAV.DLL
CODEBASE = http://pcpitstop.com/antivirus/PCPAV.CAB
[QuickTime Object]
InProcServer32 = C:\WINDOWS\SYSTEM\QTPLUGIN.OCX
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab
[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37594.828125
--------------------------------------------------
Enumerating Winsock LSP files:
Protocol #1: csloa2.dll (file MISSING)
--------------------------------------------------
End of report, 8,307 bytes
Report generated in 0.607 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only