1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Internet Connection box appears on boot-up

Discussion in 'Virus & Other Malware Removal' started by firefly260, Feb 19, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. firefly260

    firefly260 Thread Starter

    Joined:
    Dec 4, 2001
    Messages:
    71
    Hi, probably a simple answer to this, when I boot-up, my internet conection box appears without opening IE or Outlook Express, anyone anyt clues as to why?

    Have posted list from Startuplist below.
    Thanks

    StartupList report, 19/02/2003, 10:18:54
    StartupList version: 1.51
    Started from : G:\STARTUPLIST.EXE
    Detected: Windows 98 Gold (Win9x 4.10.1998)
    Detected: Internet Explorer v6.00 (6.00.2600.0000)
    * Using default options
    ==================================================

    Running processes:

    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
    C:\PROGRAM FILES\AVGSERV9.EXE
    C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\RPCSS.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\SYSTEM\ATIPTAAA.EXE
    C:\WINDOWS\SYSTEM\LVCOMS.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\AVGCC32.EXE
    C:\PROGRAM FILES\WINPORTRAIT\WPCTRL95.EXE
    C:\PROGRAM FILES\WINAMP3\WINAMPA.EXE
    C:\WINDOWS\STARTER.EXE
    C:\PROGRAM FILES\MCAFEE\QUICKCLEAN\PLGUNI.EXE
    C:\PROGRAM FILES\WINPORTRAIT\WPWATCHD.EXE
    C:\PROGRAM FILES\DIRECTCD.EXE
    C:\WINDOWS\RunDLL.exe
    D:\PROGRAM FILES\DESKTOP_ARCHITECT\DATRAY.EXE
    C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED COMPONENTS\INSTANT UPDATER\RULAUNCH.EXE
    C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE
    D:\PROGRAM FILES\SEC\NATURAL COLOR\NATURALCOLORLOAD.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    G:\STARTUPLIST.EXE

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\WINDOWS\Start Menu\Programs\StartUp]
    Microsoft Office.lnk = D:\office\Office10\OSA.EXE
    NaturalColorLoad.lnk = D:\Program Files\SEC\Natural Color\NaturalColorLoad.exe
    PowerReg Scheduler.exe
    EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM\E_SRCV02.EXE

    Shell folders Common Startup:
    [C:\WINDOWS\All Users\Start Menu\Programs\StartUp]
    .lnk = C:\Program Files\Microsoft NetShow\Tools\nsppthlp.exe
    ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
    TaskMonitor = C:\WINDOWS\taskmon.exe
    SystemTray = SysTray.Exe
    PowerQuest Startup Utility = C:\Program Files\PowerQuest\PartitionMagic4\UTILITY\MMOVER32\PQINIT.EXE
    Tweak UI = RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
    ATIGART = c:\ati\gart\atigart.exe
    AtiPTA = Atiptaaa.exe
    AtiCwd32 = Aticwd32.exe
    AtiQiPcl = AtiQiPcl.exe
    Netline User = C:\netchk.exe
    DXM6Patch_981116 = C:\WINDOWS\p_981116.exe /Q:A
    LVComs = C:\WINDOWS\SYSTEM\LVComS.exe
    StillImageMonitor = C:\WINDOWS\SYSTEM\STIMON.EXE
    AVG_CC = C:\PROGRA~1\avgcc32.exe /STARTUP
    Desktop Architect =
    wpctrl95 = "C:\Program Files\WinPortrait\wpctrl95.exe"
    WinampAgent = "C:\Program Files\Winamp3\winampa.exe"
    LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    EnsoniqMixer = starter.exe
    Imonitor = "C:\Program Files\McAfee\QuickClean\Plguni.exe" /START
    Adaptec DirectCD = c:\program files\DIRECTCD.EXE

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

    McAfeeWebScanX = C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE OFFICE\MCAFEE VIRUSSCAN\WebScanX.Exe /RUNSERVICES
    SAgent2ExePath = C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    Avgserv9.exe = C:\PROGRA~1\Avgserv9.exe
    MiniLog = C:\WINDOWS\SYSTEM\ZONELABS\MINILOG.EXE -service
    LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    SchedulingAgent = C:\WINDOWS\SYSTEM\mstask.exe
    TrueVector = C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    Taskbar Display Controls = RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
    Desktop Architect = "D:\PROGRAM FILES\DESKTOP_ARCHITECT\DATRAY.EXE" -S
    McAfee.InstantUpdate.Monitor = "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    [DSS]
    = C:\WINDOWS\\BBStore\DSS\dssagent.exe

    [OptionalComponents]
    *No values found*

    --------------------------------------------------

    C:\WINDOWS\WININIT.BAK listing:
    (Created 16/2/2003, 20:6:20)

    [rename]
    NUL=C:\WINDOWS\TEMP\GLB1A2B.EXE
    NUL=F:\PROGRA~1\ZONEAL~1\ZAUNINST.EXE

    --------------------------------------------------

    C:\AUTOEXEC.BAT listing:

    C:\PROGRA~1\bootup.exe
    IF ERRORLEVEL 1 PAUSE
    PROMPT $P$G
    PATH C:\WINDOWS;C:\WINDOWS\COMMAND;D:\OFFICE\OFFICE;C:\DOS;0;C:\PROGRA~1;C:\PROGRA~1\COMMON~1\FOLIOS~1
    SET TEMP=C:\DOS
    SET PATH=%PATH%;e:\MACAFEE\OFFICE\MCAFEE~1;0;C:\PROGRA~1\COMMON~1\FOLIOS~1
    mode con codepage prepare=((850) C:\WINDOWS\COMMAND\ega.cpi)
    mode con codepage select=850
    keyb uk,,C:\WINDOWS\COMMAND\keyboard.sys

    --------------------------------------------------


    Enumerating Browser Helper Objects:

    (no name) - D:\PROGRAM FILES\ADOBE\READER\ACTIVEX\ACROIEHELPER.OCX - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

    --------------------------------------------------

    Enumerating Task Scheduler jobs:

    Tune-up Application Start.job

    --------------------------------------------------

    Enumerating Download Program Files:

    [Shockwave Flash Object]
    InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    [Ikonic Button Control]
    InProcServer32 = C:\WINDOWS\DOWNLO~1\CONFLICT.1\IKBUTTON.OCX
    CODEBASE = http://cookiecentral.com/activex/ikcntrls.cab

    [BtnMenu Object]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\BTNMENU.OCX
    CODEBASE = http://activex.microsoft.com/controls/iexplorer/x86/btnmenu.cab

    [BrowseFolderPopup Class]
    InProcServer32 = C:\WINDOWS\MCBIN\SHARED\MGBRWFLD.DLL
    CODEBASE = http://download.mcafee.com/molbin/Shared/MGBrwFld.cab

    [Label Object]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\IELABEL.OCX
    CODEBASE = http://activex.microsoft.com/controls/iexplorer/x86/ielabel.cab

    [McAfee Clinic AV Installer Control]
    InProcServer32 = C:\WINDOWS\MCBIN\AV\MGAVINST.DLL
    CODEBASE = http://download.mcafee.com/molbin/clinic/virusscan/mgavinst.cab

    [HouseCall Control]
    InProcServer32 = C:\WINDOWS\DOWNLO~1\XSCAN53.OCX
    CODEBASE = http://a840.g.akamai.net/7/840/537/2003012801/housecall.antivirus.com/housecall/xscan53.cab

    [PWMediaSendControl Class]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\PWACTIVEXIMGCTL.DLL
    CODEBASE = http://216.249.24.142/code/PWActiveXImgCtl.CAB

    [IntraLaunch.MainControl]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\INTRALAUNCH.OCX
    CODEBASE = file://H:\SuperCD\IntraLaunch.CAB

    --------------------------------------------------
    End of report, 7,747 bytes
    Report generated in 0.159 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only

    Incedently can anyone tell me how to remove the entries for Mcafee office, I deleted the programme ages ago.
     
  2. $teve

    $teve

    Joined:
    Oct 9, 2001
    Messages:
    9,396
    tool/internet options/connections.........check "never dial a connection"
    it should now only dial when you tell it to.

    your startuplist looks fine.;)
     
  3. firefly260

    firefly260 Thread Starter

    Joined:
    Dec 4, 2001
    Messages:
    71
    Thanks for that $teve, thought it would be something simple, just had a brain fade though. Cured the problem, though how it changed I have no idea.

    Keith
     
  4. TOGG

    TOGG

    Joined:
    Apr 2, 2002
    Messages:
    5,899
    firefly260,

    Some versions of Zone Alarm cause your browser to auto start on bootup so don't be surprised if your problem comes back!

    Zonelabs are supposed to be fixing this with the next version.
     
  5. firefly260

    firefly260 Thread Starter

    Joined:
    Dec 4, 2001
    Messages:
    71
    Hi Togg, thanks for that, it was after I reloaded ZA that I started having the problem, now I do not get the connection box on opening IE or OE, have to connect via Dial Up Connections.

    Cheers
    Keith
     
  6. Byteman

    Byteman Gone but Never Forgotten

    Joined:
    Jan 24, 2002
    Messages:
    17,742
  7. Del

    Del

    Joined:
    Aug 31, 2001
    Messages:
    3,452
    I'd run the spybot and get rid of what you don't want.
     
  8. firefly260

    firefly260 Thread Starter

    Joined:
    Dec 4, 2001
    Messages:
    71
    Thanks Byteman & Del, have tried spybot but it has not picked DSS agent up. Can I manually delete it from

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    [DSS]
    = C:\WINDOWS\\BBStore\DSS\dssagent.exe

    Thanks again
    Keith
     
  9. Byteman

    Byteman Gone but Never Forgotten

    Joined:
    Jan 24, 2002
    Messages:
    17,742
    Hi,

    Here is an automatic removal tool- I cannot say how well it works. Since it is from Mattel, whose software was bundled at one point with Broderbund components, chances are it does the job. Interesting to find out about.
    http://www.generation.net/~hleboeuf/spyware.htm
    It's at the end of that page in it's own section. There is also a link to Microsoft info about DSS, msconfig entry, etc.

    OR::
    Follow this. http://www.cexx.org/startup.htm#registry
    have you checked Online in SpyBot for updates?
    AdAware 6.0, the NEW version, is good to use along with SpyBot, they do detect some different, as well as ovelapping, things.
    Haven't run into DSS in a while- does it have any entry in msconfig which you can turn off?
    SpyBot has to be updated, run, remove things, reboot, run again for complete removal of certain things, like files in use.
    Manual deletion, as you thought, is possible; sounds like you know what you are doing in Registry.
    Pays to cross check the steps.
     
  10. firefly260

    firefly260 Thread Starter

    Joined:
    Dec 4, 2001
    Messages:
    71
    Thanks again Byteman, have already tried cleanbc.exe to no avail, tried updating spybot but got an error retrieving the files and no download. Have manually deleted the entry, so will see what happens now.

    Thanks
    Keith
     
  11. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/119665

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice