StartupList report, 2/8/03, 3:37:06 PM
StartupList version: 1.51
Started from : C:\WINDOWS\TEMP\STARTUPLIST.EXE
Detected: Windows 98 SE (Win9x 4.10.2222A)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINJECT.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\LXSUPMON.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE
C:\PROGRAM FILES\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINSM32.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\FINDFAST.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OSA.EXE
C:\PROGRAM FILES\MSWORKS\CALENDAR\WKCALREM.EXE
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Monwow.exe
C:\WINDOWS\TEMP\INS7.TMP\DLGLI.EXE
C:\WINDOWS\DRWATSON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\GETRIGHT\GETRIGHT.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\WINDOWS\TEMP\STARTUPLIST.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\CSINSM32.EXE
Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\FINDFAST.EXE
Office Startup.lnk = C:\Program Files\Microsoft Office\OSA.EXE
Microsoft Works Calendar Reminders.lnk = C:\Program Files\MSWorks\Calendar\WKCALREM.EXE
Data LifeGuard LifeLine Lite installer.lnk = C:\WINDOWS\TEMP\ins7.TMP\DLGLI.EXE
Drwatson.lnk = C:\WINDOWS\DRWATSON.EXE
Shell folders Common Startup:
[C:\WINDOWS\All Users\Start Menu\Programs\StartUp]
ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
EnsoniqMixer = starter.exe
NPROTECT = C:\Program Files\Norton SystemWorks\Norton Utilities\nprotect.exe
QD FastAndSafe = C:\Program Files\Norton SystemWorks\Norton CleanSweep\QDCSFS.exe /startup
StillImageMonitor = C:\WINDOWS\SYSTEM\STIMON.EXE
POINTER = C:\Program Files\Microsoft Hardware\Mouse\point32.exe
CriticalUpdate = C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
WinHacker = rundll32.exe C:\PROGRA~1\WEDGES~1\WINHAC~1.0\wh95.dll,HackMe
LexStart = Lexstart.exe
LexmarkPrinTray = PrinTray.exe
LXSUPMON = C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
Welcome = C:\WINDOWS\Welcome.exe /R
ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
NAV Agent = C:\PROGRA~1\NORTON~1\NORTON~1\NAVAPW32.EXE
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
SymTray - Norton SystemWorks = C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
TrueVector = C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = C:\WINDOWS\SYSTEM\mstask.exe
NPROTECT = C:\Program Files\Norton SystemWorks\Norton Utilities\nprotect.exe
CSINJECT.EXE = C:\Program Files\Norton SystemWorks\Norton CleanSweep\CSINJECT.EXE
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Yahoo! Pager = C:\PROGRAM FILES\YAHOO!\MESSENGER\ypager.exe -quiet
--------------------------------------------------
C:\WINDOWS\WININIT.BAK listing:
(Created 8/2/2003, 11:27:30)
[Rename]
C:\PROGRA~1\NORTON~1\NORTON~1\SCANMGR.DLL=C:\PROGRA~1\NORTON~1\NORTON~1\SCA11A1.TMP
--------------------------------------------------
C:\AUTOEXEC.BAT listing:
SET BLASTER=A220 I7 D1 T2
SET SNDSCAPE=C:\WINDOWS
SET CLASSPATH=C:\PROGRA~1\PHOTOD~1.1\ADOBEC~1
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\WINDOWS\DOWNLOADED PROGRAM FILES\YCOMP5_1_1_0.DLL - {02478D38-C3F9-4efb-9B51-7695ECA05670}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Tune-up Application Start.job
Symantec NetDetect.job
Windows Critical Update Notification.job
Desktop Themes.job
--------------------------------------------------
Enumerating Download Program Files:
[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE =
http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37652.0609606481
[Yahoo! Companion]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YCOMP5_1_1_0.DLL
CODEBASE =
http://us.dl1.yimg.com/download.yahoo.com/dl/toolbar/yiebio5_1_1_0.cab
[YInstStarter Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YINSTHELPER.DLL
CODEBASE =
http://download.yahoo.com/dl/installs/yinst.cab
[YahooYMailTo Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YMMAPI.DLL
CODEBASE =
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/essentials/ymmapi_0727.dll
--------------------------------------------------
End of report, 6,545 bytes
Report generated in 0.458 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
----------------------------------------------------------------------
I ran the SpyBot 3 times and still it found the same error about something called 'BackWeb'. I am still getting the same error for when I am trying to download my email. Nothing is stalled as far as the listing in 'close program' (ctrl, alt, del) yet my pc is barely able to shut down.
any suggestions besides throwing my pc out the window? lol
deb