PDA

View Full Version : Trouble Shutting Windows Down


cjgriff
January 9th, 2003, 01:50 AM
I'm getting pretty desperate. I've had my computer for about a year and a half and periodically I would have trouble shutting down. Lately it's gotten alot worse. I found the info on the Windows98 "patch" in one of the forum replies and have downloaded it but it hasn't helped.

I've tried shutting down some programs manually first, like Incredimail, Netropa news but it doesn't seem to help. And when I try Ctrl+Alt+Delete I often end up with a blue screen and the message "Warning System is busy or has become unstable" . After that I often can't even get back to my desktop. I've had to use the restart button and of course get the message about properly shutting down from the Start button and then having the scan run. Then I wait awhile and try again but either it hangs up when I click for the shut down or gets to the screen that says "Windows is shutting down" which it doesn't. I'm really concerned about having to keep trying to shut down the computer and not being able to exit Windows.

Besides shutdown problems I've had problems with prgrams not responding. This morning Real One Player and yesterday Incredimail. And when I try to End Task, sometimes everything just freezes. Add to that ,my sound seems to be sporadic !
I'd be grateful for any suggestions you might have.

Info on my system-

Windows 98 2nd ed.
800MHZ CPU
128MSBDRAM
Intel Celeron Processor
Gigabyte Motherboard

I hope that the above info is helpful. This is my first post so please excuse any mistakes.

AnnMarie
January 9th, 2003, 01:55 AM
Hi cjgriff -welcome to CTH. It would be a good idea if we had a look at your startups. We may then be able to offer suggestions that might help you.

Go here (http://www.spywareinfo.com/files/startuplist.zip) and download and run Startup List. It will generate a log file. Copy the log and paste it back into this thread

cjgriff
January 9th, 2003, 02:26 AM
StartupList report, 1/9/03, 1:16:11 PM
StartupList version: 1.50
Started from : C:\UNZIPPED\STARTUPLIST\STARTUPLIST.EXE
Detected: Windows 98 SE (Win9x 4.10.2222A)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SM56HLPR.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\SPEEDKEY.EXE
C:\PROGRAM FILES\NETROPA\INTERNET RECEIVER\TRAYMON\TRAYMON.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\EVNTSVC.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\INCREDIMAIL\BIN\INCREDIMAIL.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\HOTBAR\BIN\4.1.8.0\HBINST.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\SYSTEM\E_SICN03.EXE
C:\PROGRAM FILES\WEBSHOTS\WEBSHOTSTRAY.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\HOTBAR\BIN\4.0.9.0\HBSRV.EXE
C:\UNZIPPED\STARTUPLIST\STARTUPLIST.EXE

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
Logitech Desktop Messenger.lnk = C:\Program Files\Desktop Messenger\8876480\Program\LDMConf.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
SystemTray = SysTray.Exe
SM56ACL = sm56hlpr.exe
Microsoft IntelliType Pro = "C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe"
Internet Receiver = C:\Program Files\Netropa\Internet Receiver\Traymon\Traymon.exe
IrMon = IrMon.exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
NAV Agent = C:\PROGRA~1\NORTON~1\NAVAPW32.EXE
TkBellExe = C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
QuickTime Task = C:\WINDOWS\SYSTEM\QTTASK.EXE
IncrediMail = C:\PROGRA~1\INCRED~1\bin\IncrediMail.exe /c
CriticalUpdate = C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
EM_EXEC = C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE
Hotbar = C:\PROGRAM FILES\HOTBAR\BIN\4.1.8.0\HBINST.EXE /Upgrade

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services

Machine Debug Manager = C:\WINDOWS\SYSTEM\MDM.EXE
ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = mstask.exe

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Taskbar Display Controls = RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
EPSON Stylus COLOR 480 = C:\WINDOWS\SYSTEM\E_SICN03.EXE /A "C:\WINDOWS\SYSTEM\E_S42.TMP"
Yahoo! Pager = C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {89820200-ECBD-11cf-8B85-00AA005B4383}

[>PerUser_MSN_Clean] *
StubPath = C:\WINDOWS\msnmgsr1.exe

[PerUser_LinkBar_URLs] *
StubPath = C:\WINDOWS\COMMAND\sulfnbk.exe /L

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {44BBA840-CC51-11CF-AAFA-00AA00B6015C}

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {7790769C-0471-11d2-AF11-00C04FA35D02}

[{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
StubPath = C:\WINDOWS\SYSTEM\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=
run=

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=Explorer.exe
SCRNSAVE.EXE=
drivers=mmsystem.dll power.drv

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present

--------------------------------------------------

C:\WINDOWS\WININIT.BAK listing:
(Created 6/1/2003, 16:47:46)

[rename]
NUL=C:\WINDOWS\TEMP\GLB1A2B.EXE

--------------------------------------------------

C:\AUTOEXEC.BAT listing:

LH C:\VIAUDIO\VIAFMTSR.COM
SET BLASTER=A220 I5 D0 P300
SET CLASSPATH="C:\Program Files\JavaSoft\JRE\1.3.1\lib\ext\QTJava.zip"
SET QTJAVA="C:\Program Files\JavaSoft\JRE\1.3.1\lib\ext\QTJava.zip"

--------------------------------------------------

C:\WINDOWS\DOSSTART.BAT listing:

C:\PROGRA~1\LOGITECH\MOUSEW~1\MOUSE.EXE

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Enumerating Browser Helper Objects:

(no name) - C:\WINDOWS\SYSTEM\NZDD0.DLL - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C}
Hotbar - C:\PROGRAM FILES\HOTBAR\BIN\4.0.9.0\HBHOSTIE.DLL - {B195B3B3-8A05-11D3-97A4-0004ACA6948E}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Symantec NetDetect.job
{69AF7BE0-6C50-11D6-BB46-EEB1F672A445}_My Computer.job
Synchronize.job
Windows Critical Update Notification.job

--------------------------------------------------

Enumerating Download Program Files:

[Windows Media Player]
InProcServer32 = C:\WINDOWS\SYSTEM\MSDXM.OCX
CODEBASE = http://activex.microsoft.com/activex/controls/mplayer/en/nsmp2inf.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

[YInstStarter Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YINSTHELPER.DLL
CODEBASE = http://download.yahoo.com/dl/installs/yinst.cab

[CV3 Class]
InProcServer32 = C:\WINDOWS\SYSTEM\WUV3IS.DLL
CODEBASE = http://windowsupdate.microsoft.com/R1086/V31Controls/x86/w98/en/actsetup.cab

[{D27CDB6E-AE6D-0000-0000-000000000000}]
CODEBASE = http://active.macromedia.com/flash2/cabs/swflash.cab

[PopupMenu Object]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\IEMENU.OCX
CODEBASE = http://activex.microsoft.com/activex/controls/iexplorer/x86/iemenu.cab

[AcceptLang Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\SETACCEPTLANG.DLL
CODEBASE = http://runonce.msn.com/setacceptlang.cab

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\SWDIR.DLL
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

[Live365Player Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\PLAY365.DLL
CODEBASE = http://www.live365.com/players/play365.cab

[{41F17733-B041-4099-A042-B518BB6A408C}]
CODEBASE = http://a1540.g.akamai.net/7/1540/52/20020323/qtinstall.info.apple.com/qt505/us/win/QuickTimeInstaller.exe

[QuickTime Object]
InProcServer32 = C:\WINDOWS\SYSTEM\QTPLUGIN.OCX
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[iPIX ActiveX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\IPIXX.OCX
CODEBASE = http://www.ipix.com/download/ipixx.cab

[HbInstObj Class]
InProcServer32 = C:\PROGRAM FILES\HOTBAR\BIN\4.0.9.0\HBINSTIE.DLL
CODEBASE = http://installs.hotbar.com/installs/hotbar/programs/hotbar.cab

[WebEyeControl]
InProcServer32 = C:\WINDOWS\DOWNLO~1\WEBEYE.OCX
CODEBASE = http://207.168.91.4/kotelcam/wg_webeye.cab

[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37596.8972916667

[{D14D6793-9B65-11D3-80B6-00500487BDBA}]
CODEBASE = http://files.cc.cometsystems.com/cc2/release/bin/platform-4-3-330-NoAdZap.cab

--------------------------------------------------
End of report, 9,776 bytes
Report generated in 4.367 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Hope this is what you need.

AnnMarie
January 9th, 2003, 02:44 AM
Hi cjgriff - you have some spyware on your PC that could possibly be causing problems.

Download Spybot - Search & Destroy from

http://beam.to/spybotsd

After installing, go to the Online tab, and search for and install all updates.

Next, go to the Settings tab > File Sets, and uncheck 'System Internals' and 'Tracks' .
These aren't needed for our present purpose, and you can always experiment with them later on.

Finally, after closing down Internet Explorer, hit 'Check for Problems', and have SpyBot remove all it finds.

NOTE: SSD will sometimes not be able to remove all active components in the first 'run'.
In that case you will get a dialog asking you to run SSD at next start.
Click yes and reboot.
Subsequently SSD will come up before the system puts these components 'in use', and it will then be able to 'fix' the rest.


After running spybot, run startuplist again and copy and paste the results

cjgriff
January 9th, 2003, 03:12 AM
Maybe it's me but I couldn't download after I used your link.
Could you check to see if things are all right at the spybot site?

Sorry for the trouble.

AnnMarie
January 9th, 2003, 03:37 AM
Hi cjgriff - its no problem. Try this link http://www.pc-xpress.ca/spybot/ I checked it, the download starts.

wllwnn
January 9th, 2003, 05:56 AM
Thank u AnnMarie been searchin for that link. Stupid delete button/sleepyness:D

Now the last thing i need to do is update norten and im done a full system cleaning!!

wllwnn
January 9th, 2003, 05:59 AM
do i delete all found stuff on the list or no?

[edit]nvm i just awnsered my question:( thank god for system restore. It thought IE was a spyware and thouse deleted it:confused:

I hate that thing screwed the whole comp up. (Again thanks system restore) I will only delete file that are metioned to me

AnnMarie
January 9th, 2003, 06:35 AM
wllwnn - did you follow the instructions for using Spybot that I posted?

cjgriff
January 9th, 2003, 09:36 AM
AnnMarie - sorry for the delay. Downloaded Spybot and ran a scan. I wasn't sure about some of the things listed like IE so I left them alone. Please let me know if there are some left that I should have checked.

I did successfully shut down with a minor hitch. I got the same message when things hung up and I did Ctrl+Alt+Delete ( forgot to mention it before, said "Notification Wnd for RNAdmin".) but this time I was able to End Task and the Shut down process was successful.

I've run the startuplist when I came back on and am listing the results.

StartupList report, 1/9/03, 8:07:17 PM
StartupList version: 1.50
Started from : C:\UNZIPPED\STARTUPLIST\STARTUPLIST.EXE
Detected: Windows 98 SE (Win9x 4.10.2222A)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SM56HLPR.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\KEYBOARD\SPEEDKEY.EXE
C:\PROGRAM FILES\NETROPA\INTERNET RECEIVER\TRAYMON\TRAYMON.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\EVNTSVC.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\INCREDIMAIL\BIN\INCREDIMAIL.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\SYSTEM\E_SICN03.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\WEBSHOTS\WEBSHOTSTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\UNZIPPED\STARTUPLIST\STARTUPLIST.EXE

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
Logitech Desktop Messenger.lnk = C:\Program Files\Desktop Messenger\8876480\Program\LDMConf.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
SystemTray = SysTray.Exe
SM56ACL = sm56hlpr.exe
Microsoft IntelliType Pro = "C:\Program Files\Microsoft Hardware\Keyboard\speedkey.exe"
Internet Receiver = C:\Program Files\Netropa\Internet Receiver\Traymon\Traymon.exe
IrMon = IrMon.exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
NAV Agent = C:\PROGRA~1\NORTON~1\NAVAPW32.EXE
TkBellExe = C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
QuickTime Task = C:\WINDOWS\SYSTEM\QTTASK.EXE
IncrediMail = C:\PROGRA~1\INCRED~1\bin\IncrediMail.exe /c
CriticalUpdate = C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
EM_EXEC = C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services

Machine Debug Manager = C:\WINDOWS\SYSTEM\MDM.EXE
ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = mstask.exe

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Taskbar Display Controls = RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
EPSON Stylus COLOR 480 = C:\WINDOWS\SYSTEM\E_SICN03.EXE /A "C:\WINDOWS\SYSTEM\E_S42.TMP"
Yahoo! Pager = C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {89820200-ECBD-11cf-8B85-00AA005B4383}

[>PerUser_MSN_Clean] *
StubPath = C:\WINDOWS\msnmgsr1.exe

[PerUser_LinkBar_URLs] *
StubPath = C:\WINDOWS\COMMAND\sulfnbk.exe /L

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {44BBA840-CC51-11CF-AAFA-00AA00B6015C}

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {7790769C-0471-11d2-AF11-00C04FA35D02}

[{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
StubPath = C:\WINDOWS\SYSTEM\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=
run=

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=Explorer.exe
SCRNSAVE.EXE=
drivers=mmsystem.dll power.drv

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present

--------------------------------------------------

C:\WINDOWS\WININIT.BAK listing:
(Created 6/1/2003, 16:47:46)

[rename]
NUL=C:\WINDOWS\TEMP\GLB1A2B.EXE

--------------------------------------------------

C:\AUTOEXEC.BAT listing:

LH C:\VIAUDIO\VIAFMTSR.COM
SET BLASTER=A220 I5 D0 P300
SET CLASSPATH="C:\Program Files\JavaSoft\JRE\1.3.1\lib\ext\QTJava.zip"
SET QTJAVA="C:\Program Files\JavaSoft\JRE\1.3.1\lib\ext\QTJava.zip"

--------------------------------------------------

C:\WINDOWS\DOSSTART.BAT listing:

C:\PROGRA~1\LOGITECH\MOUSEW~1\MOUSE.EXE

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Enumerating Browser Helper Objects:

(no name) - C:\WINDOWS\SYSTEM\NZDD0.DLL - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Symantec NetDetect.job
{69AF7BE0-6C50-11D6-BB46-EEB1F672A445}_My Computer.job
Synchronize.job
Windows Critical Update Notification.job

--------------------------------------------------

Enumerating Download Program Files:

[Windows Media Player]
InProcServer32 = C:\WINDOWS\SYSTEM\MSDXM.OCX
CODEBASE = http://activex.microsoft.com/activex/controls/mplayer/en/nsmp2inf.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

[YInstStarter Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YINSTHELPER.DLL
CODEBASE = http://download.yahoo.com/dl/installs/yinst.cab

[CV3 Class]
InProcServer32 = C:\WINDOWS\SYSTEM\WUV3IS.DLL
CODEBASE = http://windowsupdate.microsoft.com/R1086/V31Controls/x86/w98/en/actsetup.cab

[{D27CDB6E-AE6D-0000-0000-000000000000}]
CODEBASE = http://active.macromedia.com/flash2/cabs/swflash.cab

[PopupMenu Object]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\IEMENU.OCX
CODEBASE = http://activex.microsoft.com/activex/controls/iexplorer/x86/iemenu.cab

[AcceptLang Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\SETACCEPTLANG.DLL
CODEBASE = http://runonce.msn.com/setacceptlang.cab

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\SWDIR.DLL
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

[Live365Player Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\PLAY365.DLL
CODEBASE = http://www.live365.com/players/play365.cab

[{41F17733-B041-4099-A042-B518BB6A408C}]
CODEBASE = http://a1540.g.akamai.net/7/1540/52/20020323/qtinstall.info.apple.com/qt505/us/win/QuickTimeInstaller.exe

[QuickTime Object]
InProcServer32 = C:\WINDOWS\SYSTEM\QTPLUGIN.OCX
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[iPIX ActiveX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\IPIXX.OCX
CODEBASE = http://www.ipix.com/download/ipixx.cab

[WebEyeControl]
InProcServer32 = C:\WINDOWS\DOWNLO~1\WEBEYE.OCX
CODEBASE = http://207.168.91.4/kotelcam/wg_webeye.cab

[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37596.8972916667

--------------------------------------------------
End of report, 9,169 bytes
Report generated in 1.593 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

AnnMarie
January 9th, 2003, 09:18 PM
Hi cjgriff - I'll bet that Real Player is the culprit. Go to Start > Run and type

msconfig

then OK. Click on the Startup tab and uncheck TKBellExe. Reboot your PC when asked and then run a search for evntsvc.exe and delete it. How is your shutdown now?

wllwnn
January 9th, 2003, 09:48 PM
Originally posted by AnnMarie
wllwnn - did you follow the instructions for using Spybot that I posted?

*levels himself with a 2X4* nope

cjgriff
January 10th, 2003, 04:49 AM
Hi AnnMarie - Thank you, thank you, thank you. It worked !!
Actually, I thought that something was wrong with my speakers as I couldn't get anything with RealPlayer or Windows Media Player lately. So not only did the shut down go smoothly, but Real Player and WMPlayer are working now too. You're a wonder!! I'm so glad that CTH is out there.
Take care and have a great weekend.

AnnMarie
January 10th, 2003, 04:53 AM
Thats great news cjgriff. You are very welcome for the help and I hope that you have an enjoyable weekend too :D