re: Multiple illegal operation errors on startup
Friday, May 20, 2005 at 5:01 pm Windows 98 Annoyances Discussion Forum
Posted by weeian
(5 messages posted)
Carol,
Heres my startup log from HJT. Look forward to hearing from you with any further
advice as I'm really strugglin now, having trouble even gettin through startup! Computer
just keeps freezing on startup, took me about 7/8 goes to get on tonight, losing
the will to hit the power button at times lol!!
As per my earlier post, do you know if I can get online in safe mose with win98 as
this seems the only way I will be able to run the virus scan you suggested?
--------------------------------------------------------------------
StartupList report, 20/05/05, 18:56:17
StartupList version: 1.52.2
Started from : C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE
Detected: Windows 98 SE (Win9x 4.10.2222A)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
* Showing rarely important sections
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
TaskMonitor = c:\windows\taskmon.exe
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
ATIGART = c:\ati\gart\atigart.exe
EnsoniqMixer = starter.exe
Internet Registration = c:\program files\internet explorer\connection wizard\netcheck.exe
StillImageMonitor = C:\WINDOWS\SYSTEM\STIMON.EXE
LoadQM = loadqm.exe
ScanRegistry = c:\windows\scanregw.exe /autorun
THGuard = "C:\PROGRAM FILES\TROJANHUNTER 4.2\THGUARD.EXE"
Desktop Search = C:\WINDOWS\isrvs\desktop.exe
ffis = C:\WINDOWS\isrvs\ffisearch.exe
IST Service = \ISTsvc\istsvc.exe
KAVPersonal50 = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe"
/minimize
RegistryMechanic = C:\Program Files\Registry Mechanic\RegMech.exe /QS
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = mstask.exe
kavsvc = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe"
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Taskbar Display Controls = RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
MsnMsgr = "c:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
ICC2000 = C:\PROGRAM FILES\INTERNET\ICC\icc2000.exe
--------------------------------------------------
File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command
(Default) = c:\windows\NOTEPAD.EXE %1
--------------------------------------------------
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)
[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {89820200-ECBD-11cf-8B85-00AA005B4383}
[>PerUser_MSN_Clean] *
StubPath = c:\windows\msnmgsr1.exe
[MmoptPreferredAudioDevices] *
StubPath = rundll32.exe shell32.dll,Control_RunDLL mmsys.cpl,@0,SUSB\VID_0546&PID_3155&MI_02\2USB&VID_0546&PID_3155&INST_0
[PerUser_LinkBar_URLs] *
StubPath = c:\windows\COMMAND\sulfnbk.exe /L
[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {44BBA840-CC51-11CF-AAFA-00AA00B6015C}
[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {7790769C-0471-11d2-AF11-00C04FA35D02}
[>IEPerUser] *
StubPath = RUNDLL32.EXE IEDKCS32.DLL,BrandIE4 SIGNUP
[{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
StubPath = C:\WINDOWS\SYSTEM\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl
--------------------------------------------------
Load/Run keys from C:\WINDOWS\WIN.INI:
load=C:\WINDOWS\PTSNOOP.EXE
run=
--------------------------------------------------
Checking for EXPLORER.EXE instances:
C:\WINDOWS\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present
--------------------------------------------------
C:\WINDOWS\WININIT.BAK listing:
(Created 18/5/2005, 23:11:38)
[rename]
C:\WINDOWS\SYSTEM\IoSubSys\SmartVSD.VxD=C:\WINDOWS\SYSTEM\SmartVSD.VxD
--------------------------------------------------
C:\AUTOEXEC.BAT listing:
CALL C:\WINDOWS\RECOVERY\CHECK.BAT
LH C:\WINDOWS\COMMAND\MOUSE
LH keyb uk,,c:\windows\COMMAND\keyboard.sys
SET BLASTER=A220 I7 D1 T2
SET SNDSCAPE=C:\WINDOWS
C:\PROGRA~1\CREATIVE\CTSND\DOSDRV\APINIT.COM
--------------------------------------------------
C:\CONFIG.SYS listing:
DEVICE=C:\WINDOWS\HIMEM.SYS
DEVICE=C:\WINDOWS\EMM386.EXE NOEMS
DOS=HIGH,UMB
DEVICEHIGH=C:\WINDOWS\COMMAND\VIDE-CDD.SYS /D:CD-ROM
COUNTRY=044,850,C:\WINDOWS\COMMAND\COUNTRY.SYS
--------------------------------------------------
C:\WINDOWS\DOSSTART.BAT listing:
C:\PROGRA~1\CREATIVE\CTSND\DOSDRV\APINIT
LH C:\WINDOWS\COMMAND\MSCDEX.EXE /D:CD-ROM /M:10
echo.
cls
--------------------------------------------------
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
--------------------------------------------------
Enumerating Browser Helper Objects:
IE Update Class - C:\WINDOWS\isrvs\sysupd.dll (file missing) - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993}
(no name) - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Tune-up Application Start.job
609BFCEA6E7C5235.job
EBF8AC596E9B9DCA.job
A57C84616E7D204E.job
4A156C176E7DA174.job
7ED0CF226E7C409F.job
2ED9F1CF6E7CD83C.job
4C0D7046918B160D.job
--------------------------------------------------
Enumerating Download Program Files:
[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\SHOCKWAVE 10\DOWNLOAD.DLL
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38485.4072916667
[WScanCtl Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.1\WEBSCAN.DLL
CODEBASE = http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
--------------------------------------------------
End of report, 7,704 bytes
Report generated in 0.310 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
|
All messages in this thread [show all]
 |  |  |  |  |  |  |  | re: Multiple illegal operation errors on startup (weeian: Fri, May 20, 2005, 5:01 pm) |
| |
| |
Return to the Windows 98 Discussion Forum
|
|