Flamejanes Posted June 7, 2005 Posted June 7, 2005 I have winxp and I was wondering if someone could help me fix a problem? When I open "Msconfig" I see that there are like "20 something plain square boxes" in my startup list, located in (software\microsoft\windows nt\currentversion\windows)I don't know if that's (HKLM or HKCU or what) thats the only location description it shows. How do I find it & delete it? Any help would be deeply appreciated Here is my HJT LogLogfile of HijackThis v1.99.0Scan saved at 9:17:41 AM, on 6/7/2005Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Norton AntiVirus\navapsvc.exeC:\Program Files\Norton AntiVirus\IWP\NPFMntor.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeC:\WINDOWS\Explorer.exeC:\Program Files\Yahoo!\browser\ybrwicon.exeC:\HP\KBD\KBD.EXEC:\windows\system\hpsysdrv.exeC:\WINDOWS\System32\hkcmd.exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CMPDPSRV.EXEC:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\Program Files\interMute\SpamSubtract\SpamSub.exeC:\PROGRA~1\Yahoo!\browser\ycommon.exeC:\WINDOWS\System32\msiexec.exeC:\Program Files\Yahoo!\browser\YBrowser.exeC:\Program Files\Yahoo!\Messenger\YPAGER.EXEC:\Program Files\Messenger\msmsgs.exeC:\Program Files\hijackthis.exeF2 - REG:system.ini: Shell=C:\WINDOWS\Explorer.exeO4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exeO4 - HKLM\..\Run: [VTTimer] VTTimer.exeO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [iPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exeO4 - HKLM\..\Run: [CMPDPSRV] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\CMPDPSRV.EXEO4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exeO4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /ConsumerO4 - HKLM\..\Run: [sSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exeO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exeO16 - DPF: {4EC8E993-32C1-47F5-A07A-5B0574655AD4} (WXcom Class) - http://us.dl1.yimg.com/download.yahoo.com/...ntr_current.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{851FA0D9-8763-4662-83EA-DCB1C7FEEFBC}: NameServer = 69.50.166.94 69.31.80.244O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeO23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exeO23 - Service: Norton AntiVirus Firewall Monitor Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exeO23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exeO23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exeO23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exeO23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exeO23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Tarun Posted June 7, 2005 Posted June 7, 2005 Looks completely clean. Is HijackThis reporting the blank checkmarks? Also, do they display as the following:[x] (No information follows)If so, they are safe to remove/delete.
Flamejanes Posted June 8, 2005 Author Posted June 8, 2005 Thanks alot Tarun for your help and NO HJT doesn't report the square boxes that's in msconfig....Yes they look like this ( [] [] [] [] [] [] [] [] [].....) msconfig reports the location as (software\microsoft\windows nt\currentversion\windows)but I dont know where that is in regedit No HKLM or HKCU \ software.... like it should be
Tarun Posted June 8, 2005 Posted June 8, 2005 Thanks alot Tarun for your help and NO HJT doesn't report the square boxes that's in msconfig....Yes they look like this ( [] [] [] [] [] [] [] [] [].....) msconfig reports the location as (software\microsoft\windows nt\currentversion\windows)but I dont know where that is in regedit No HKLM or HKCU \ software.... like it should be<{POST_SNAPBACK}>Always be careful when editing the registry!Go to Start, Run... and type in regeditNow check the following keys:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnceHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceExHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesIf you have CCleaner, you may also be able to remove them using the Tools -> Startup Programs section of CCleaner.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now