1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

[Resolved] Unable to remove McAffe Virus Scanner

Discussion in 'Virus & Other Malware Removal' started by cmlyon, Feb 16, 2003.

Thread Status:
Not open for further replies.
Advertisement
  1. cmlyon

    cmlyon Thread Starter

    Joined:
    Feb 15, 2003
    Messages:
    28
    Hi,
    we installed Mcaffe virus installer many years ago and so it is now hoplessly out of date. I would like to remove it however it has no uninstall file and it cannot be removed by the windows "remove program" feature. I find it very irritating as it starts up with every session of windows. Its very annoying when a company is this aggressive/unhelp. I would like to know if anyone has any tips for safely removing the program.

    Thanks again,
    Cara
     
  2. $teve

    $teve

    Joined:
    Oct 9, 2001
    Messages:
    9,396
    hello cara.

    suposedly this is how:





    Removing McAfee

    Left click on "Start"
    Go to "Settings"
    Left click on the "Control Panel"
    Double left click on "Add/Remove Programs"
    In the new window that has opened, highlight (left click once only) "McAfee Virus Scan"
    Left click on "Add/Remove"
    A "SetupP" window will appear and you will be asked if you want to remove McAfee Virus Scan: Left click on "Yes"
    Your machine will begin to remove McAfee and in doing so will ask if you want to remove "Shared files." Click on "Yes to All"
    A window will open asking if you would like to proceed. Click "Yes".
    Click "OK" when it has completed.
    A window will now open asking if you would like to remove the McAfee directory. Click "Yes".
    Close all open windows.

    but as you say you have tried..
    .........lets see exactlywhere its starting from.
    go here:http://www.lurkhere.com/~nicefiles/
    download "startuplist"......run the program and copy/paste the generated text file in your next post here.;)
     
  3. cmlyon

    cmlyon Thread Starter

    Joined:
    Feb 15, 2003
    Messages:
    28
    Thanks for your reply and help. Yes I have tried to remove the program that way, however it simply does not appear in the list of removable programs.

    Here is my startup list:

    StartupList report, 2/16/03, 8:45:21 PM
    StartupList version: 1.51
    Started from : C:\WINDOWS\TEMP\TD_0001.DIR\STARTUPLIST.EXE
    Detected: Windows 98 Gold (Win9x 4.10.1998)
    Detected: Internet Explorer v6.00 (6.00.2600.0000)
    * Using default options
    ==================================================

    Running processes:

    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\PROGRAM FILES\NORTON SYSTEMWORKS2\NORTON CLEANSWEEP\CSINJECT.EXE
    C:\PROGRAM FILES\NORTON SYSTEMWORKS2\NORTON UTILITIES\NPROTECT.EXE
    C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\LXDBOXCP.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\CREATIVE\SHAREDLL\CTNOTIFY.EXE
    C:\PROGRAM FILES\T-MEDIA\RMTSTOCK.EXE
    C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\T-MEDIA\KBOSDCTL.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\PROGRAM FILES\T-MEDIA\CDMNG32.EXE
    C:\PROGRAM FILES\SRN MICRO\SOLOSENT.EXE
    C:\PROGRAM FILES\T-MEDIA\RMTCONVT.EXE
    C:\PROGRAM FILES\T-MEDIA\KBRMT32.EXE
    C:\PROGRAM FILES\SRN MICRO\SOLOCFG.EXE
    C:\PROGRAM FILES\T-MEDIA\DKEYBEX.EXE
    C:\PROGRAM FILES\T-MEDIA\BKGRD32.EXE
    C:\PROGRAM FILES\T-MEDIA\WHEELMNG.EXE
    C:\PROGRAM FILES\T-MEDIA\RMTSPECL.EXE
    C:\PROGRAM FILES\T-MEDIA\CALCMNG.EXE
    C:\PROGRAM FILES\T-MEDIA\RECMNG.EXE
    C:\PROGRAM FILES\CREATIVE\SHAREDLL\MEDIADET.EXE
    C:\PROGRAM FILES\T-MEDIA\KBSTATUS.EXE
    C:\PROGRAM FILES\T-MEDIA\MXRCTL32.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\WINDOWS\TEMP\TD_0001.DIR\STARTUPLIST.EXE

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\WINDOWS\Start Menu\Programs\StartUp]
    Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
    TaskMonitor = C:\WINDOWS\taskmon.exe
    SystemTray = SysTray.Exe
    LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    NewsUpd = C:\Program Files\Creative\News\NewsUpd.EXE /q
    Disc Detector = C:\Program Files\Creative\ShareDLL\CtNotify.exe
    VsecomrEXE = C:\PROGRA~1\PLUS!\Viruscan\VSECOMR.EXE
    KE9801 = C:\PROGRA~1\T-MEDIA\DriBat32.EXE DKBoot.INI
    WinampAgent = "C:\PROGRAM FILES\WINAMP\WINAMPa.exe"
    StillImageMonitor = C:\WINDOWS\SYSTEM\STIMON.EXE
    LoadQM = loadqm.exe
    SoloSentry = C:\PROGRA~1\SRNMIC~1\SOLOSENT.EXE
    SoloSchedule = C:\PROGRA~1\SRNMIC~1\SOLOCFG.EXE
    NPROTECT = C:\Program Files\Norton SystemWorks2\Norton Utilities\NPROTECT.EXE

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

    LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    SchedulingAgent = mstask.exe
    ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
    CSINJECT.EXE = C:\Program Files\Norton SystemWorks2\Norton CleanSweep\CSINJECT.EXE
    NPROTECT = C:\Program Files\Norton SystemWorks2\Norton Utilities\NPROTECT.EXE
    SymTray - Norton SystemWorks = C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"

    --------------------------------------------------

    C:\WINDOWS\WININIT.BAK listing:
    (Created 13/2/2003, 10:20:56)

    [Rename]
    NUL=C:\PROGRA~1\NORTON~1\NORTON~1\UNREGCMD.EXE

    --------------------------------------------------

    C:\AUTOEXEC.BAT listing:

    SET BLASTER=A220 I7 D3 H7 P330 T6
    SET SBPCI=C:\PROGRA~1\CREATIVE\AUDIO\DOSDRV
    C:\PROGRA~1\SRNMIC~1\SOLOLITE /HARDDISK /REPAIR /AUTO

    --------------------------------------------------


    Enumerating Browser Helper Objects:

    Yahoo! Companion BHO - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_3.DLL - {13F537F0-AF09-11d6-9029-0002B31F9E59}
    NAV Helper - C:\Program Files\Norton SystemWorks2\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}

    --------------------------------------------------

    Enumerating Task Scheduler jobs:

    Tune-up Application Start.job
    Maintenance-Clean up Start menu.job
    Maintenance-Anti-Virus.job
    Maintenance-Defragment programs.job
    Maintenance-ScanDisk.job
    Maintenance-Disk cleanup.job
    Desktop Themes.JOB
    Symantec NetDetect.job
    Norton SystemWorks One Button Checkup.job
    Norton AntiVirus - Scan my computer.job

    --------------------------------------------------

    Enumerating Download Program Files:

    [National Internet Banking Custom]
    InProcServer32 = C:\WINDOWS\SYSTEM\MSJAVA.DLL
    CODEBASE = http://www.national.com.au/rib/afs/...t/NABcustom.cab

    [National Internet Banking Images]
    InProcServer32 = C:\WINDOWS\SYSTEM\MSJAVA.DLL
    CODEBASE = http://www.national.com.au/rib/afs/...inet/images.cab

    [Shockwave Flash Object]
    InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
    CODEBASE = http://download.macromedia.com/pub/...ash/swflash.cab

    [MSN Photo Upload Tool]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MSNPUPLD.DLL
    CODEBASE = http://photos.ninemsn.com.au/r/neut....cab?5,0,1730,0

    [msichat50 Client Control]
    InProcServer32 = C:\WINDOWS\DOWNLO~1\MSICHA~1.OCX
    CODEBASE = http://www.ichat.com/custom/nativeclient/msichat.cab

    [Shockwave ActiveX Control]
    InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\SWDIR.DLL
    CODEBASE = http://download.macromedia.com/pub/...director/sw.cab

    [{F17EDBC0-3EB2-11D3-AB74-00A0C9A522F2}]
    CODEBASE = http://www.gohip.com/freevideo/download.exe

    [MS Investor Ticker]
    InProcServer32 = C:\WINDOWS\DOWNLO~1\TICKER8.OCX
    CODEBASE = http://fdl.msn.com/public/investor/v8/0326/ticker.cab

    [KX-HCM10 Control]
    InProcServer32 = C:\WINDOWS\DOWNLO~1\KXHCM10.OCX
    CODEBASE = http://northmetro.kicks-***.org:8001/kxhcm10.ocx

    [Microsoft Office Tools on the Web Control]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\OUTC.DLL
    CODEBASE = http://dgl.microsoft.com/downloads/outc.cab

    [Yahoo! Audio UI1]
    InProcServer32 = C:\PROGRAM FILES\YAHOO!\MESSENGER\YACSUI.DLL
    CODEBASE = http://chat.yahoo.com/cab/yacsui.cab

    [MSN Chat Control 4.5]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MSNCHAT45.OCX
    CODEBASE = http://fdl.msn.com/public/chat/msnchat45.cab

    [HouseCall Control]
    InProcServer32 = C:\WINDOWS\DOWNLO~1\XSCAN53.OCX
    CODEBASE = http://a840.g.akamai.net/7/840/537/...all/xscan53.cab

    [ActiveScan Installer Class]
    InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\ASINST.DLL
    CODEBASE = http://www.pandasoftware.com/activescan/as/asinst.cab

    --------------------------------------------------
    End of report, 7,585 bytes
    Report generated in 3.340 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only
     
  4. $teve

    $teve

    Joined:
    Oct 9, 2001
    Messages:
    9,396
    found it!

    can you go into regedit?
    start/run,type "regedit"(without the quotes) and make your way here:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    name VsecomrEXE

    data "C:\McAfee\VirusScan\VSECOMR.EXE"

    delete VSECOMREXE

    you can use the regedit program to look for the entry. Go to edit and find and type in VsecomrEXE into the finder. ... then delete the entry and re-boot..........problem gone;)
     
  5. $teve

    $teve

    Joined:
    Oct 9, 2001
    Messages:
    9,396
    now then........can you now go here:http://beam.to/spybotsd

    and download "spybot".....although your s.u.list is pretty clean there is one object that needs removing....."go-hip"...spyware.
    beore you run spybot hit the online tab and download the updates......then let the program fix anything highlighted in red.
     
  6. buckaroo

    buckaroo

    Joined:
    Mar 25, 2001
    Messages:
    3,334
  7. cmlyon

    cmlyon Thread Starter

    Joined:
    Feb 15, 2003
    Messages:
    28
    Legends! Thanks for your help. Problem solved. Spyware will also be removed thanks for the tip!
     
  8. $teve

    $teve

    Joined:
    Oct 9, 2001
    Messages:
    9,396
    YOUR VERY<img src=http://forums.techguy.org/attachment.php?s=&postid=731123>;)
     

    Attached Files:

  9. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/119083

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice