PDA

View Full Version : winxp prof. errors that never go away


bigheadgun
February 14th, 2003, 06:26 AM
i don't know if this is a hardware or software problem but for some reason when i close most of my large programs or almost any program
in windows xp professional it always bring up an error about not being able to read memory instruction and a whole lot of numbers.
and i close it and it just goes on close the program. i had the memory checked and it tested good and i can't even think about putting my ddr mem in my system want even boot!

AnnMarie
February 14th, 2003, 11:12 PM
Hi bigheadgun - this message seems to occur for a variety of reasons. We can look at your startups for you and see if we can find an obvious conflict.

Go here (http://www.spywareinfo.com/files/startuplist.zip) and download and run Startup List. It will generate a log file. Copy the log and paste it back into this thread

bigheadgun
February 14th, 2003, 11:34 PM
hey um before i download that software how do uninstall that spyware or limit it to the start up.

AnnMarie
February 14th, 2003, 11:58 PM
What spyware are you referring to bigheadgun?

bigheadgun
February 15th, 2003, 12:24 AM
isn't that link for the word here a spyware program i mean thats what it said when i started to download it.

AnnMarie
February 15th, 2003, 12:35 AM
Nope, its the link for Startup List from www.spywareinfo.com.

bigheadgun
February 15th, 2003, 12:37 AM
what do i do with the notepad document it made

AnnMarie
February 15th, 2003, 12:47 AM
Go to Edit > Select All and then Edit > Copy and then when you come back here, after clicking on Post Reply, rightclick in the reply box and choose Paste and the contents will be pasted into this thread.

bigheadgun
February 15th, 2003, 01:15 AM
StartupList report, 2/14/2003, 7:00:27 PM
StartupList version: 1.51
Started from : C:\Documents and Settings\Administrator\Local Settings\Temp\StartupList.EXE
Detected: Windows XP (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 (6.00.2600.0000)
* Using default options
==================================================

Running processes:

C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINNT\System32\DRIVERS\CDANTSRV.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\wanmpsvc.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe
C:\WINNT\System32\SoundMan.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\Common Files\Mediafour\MACVNTFY.EXE
C:\Program Files\Mediafour\XPlay\1033\XPLAYMD5.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Say the Time\SayTime.exe
C:\PROGRA~1\INSTAN~1\INSTAN~1\IWCTRL.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\System32\ctfmon.exe
C:\PROGRA~1\AIM95\aim.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C:\Program Files\Keyspan\Digital Media Remote 2.0\KDMRdmn.exe
C:\Program Files\SBC\Connection Manager\CManager.exe
C:\WINNT\System32\rundll32.exe
C:\PROGRA~1\BROADJ~1\CORREC~1\CCD.exe
C:\Program Files\Yahoo!\browser\YBrowser.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\StartupList.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Administrator\Start Menu\Programs\Startup]
Connection Manager.lnk = C:\Program Files\SBC\Connection Manager\CManager.exe

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0c\aoltray.exe
Keyspan Digital Media Remote.lnk = C:\Program Files\Keyspan\Digital Media Remote 2.0\KDMRdmn.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINNT\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Synchronization Manager = mobsync.exe /logon
NvCplDaemon = RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
SiSSoundMan = C:\WINNT\System32\SoundMan.exe
SiSSetCDfmt = C:\WINNT\System32\SetCDfmt.exe
nwiz = nwiz.exe /install
Alogserv = C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
Mediafour Mac Volume Notifications = "C:\Program Files\Common Files\Mediafour\MACVNTFY.EXE" /auto
XPLAYMD5.EXE.1033 = C:\Program Files\Mediafour\XPlay\1033\XPLAYMD5.EXE
MediaLoads Installer = "C:\Program Files\DownloadWare\dw.exe" /H
IPInSightMonitor 01 = "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
BJCFD = C:\Program Files\BroadJump\Client Foundation\CFD.exe
tgcmdprovidersbc = "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor /deaf /nosystray
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run Once

SpyBotSnD = C:\Program Files\Spybot - Search & Destroy 1.1\SpybotSD.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services

RNBOStart = C:\WINNT\SYSTEM\RNBOSENT\SENTSTRT.EXE
1A:Stardock TrayMonitor =

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background
ATI Launchpad =
ctfmon.exe = C:\WINNT\System32\ctfmon.exe
AIM = C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
Yahoo! Pager = C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

[nView]
NVIEW = rundll32.exe nview.dll,nViewLoadHook

--------------------------------------------------


Enumerating Browser Helper Objects:

Yahoo! Companion BHO - C:\Program Files\Yahoo!\Common\ycomp5,0,8,0.dll - {13F537F0-AF09-11d6-9029-0002B31F9E59}
MediaLoads Enhanced - C:\Program Files\MediaLoads Enhanced\ME1.DLL (file missing) - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E}

--------------------------------------------------

Enumerating Download Program Files:

[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[{359F7E49-1EA0-4671-92E9-61E32FE25C5E}]
CODEBASE = http://69.0.137.190/version3/Netster.dll

[{41F17733-B041-4099-A042-B518BB6A408C}]
CODEBASE = http://apple.speedera.net/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe

[GSDACtl Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\gsda.dll
CODEBASE = http://launch.gamespyarcade.com/software/launch/alaunch.cab

[AcDcToday Control]
InProcServer32 = C:\WINNT\DOWNLO~1\ACDCTO~1.OCX
CODEBASE = file://C:\Program Files\AutoCAD 2000i\AcDcToday.ocx

[{82202BE7-C56A-487E-9E55-D84BDC1A5776}]
CODEBASE = http://install.anark.com/client/version1/windows-ie/en/AMClient.cab

[RegConfig Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\yregcfg.dll
CODEBASE = http://download.yahoo.com/dl/installs/bkm/prod/yregcfg.cab

[Update Class]
InProcServer32 = C:\WINNT\System32\iuctl.dll
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37317.8250578704

[YahooYMailTo Class]
InProcServer32 = C:\WINNT\Downloaded Program Files\ymmapi.dll
CODEBASE = http://download.yahoo.com/dl/installs/ymail/ymmapi.dll

[HeartbeatCtl Class]
InProcServer32 = C:\WINNT\DOWNLO~1\hrtbeat.ocx
CODEBASE = http://fdl.msn.com/zone/datafiles/heartbeat.cab

[InstaFred Control]
InProcServer32 = C:\WINNT\DOWNLO~1\InstFred.ocx
CODEBASE = file://C:\Program Files\AutoCAD 2000i\InstFred.ocx

[Shockwave Flash Object]
InProcServer32 = C:\WINNT\System32\macromed\flash\Flash.ocx
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

[AcPreview Control]
InProcServer32 = C:\WINNT\DOWNLO~1\ACPREV~1.OCX
CODEBASE = file://C:\Program Files\AutoCAD 2000i\AcPreview.ocx

[WildTangent Control]
InProcServer32 = C:\WINNT\wt\webdriver\webdriver.dll
CODEBASE = http://www.wildtangent.com/install/wdriver/racing/dodgespeedway/microsoft/wtinst.cab

--------------------------------------------------

Enumerating Winsock LSP files:

Protocol #1: C:\WINNT\System32\CSLSP.DLL
Protocol #2: C:\WINNT\System32\CSLSP.DLL
Protocol #3: C:\WINNT\System32\CSLSP.DLL
Protocol #4: C:\WINNT\System32\CSLSP.DLL
Protocol #5: C:\WINNT\System32\CSLSP.DLL
Protocol #6: C:\WINNT\System32\CSLSP.DLL
Protocol #7: C:\WINNT\System32\CSLSP.DLL
Protocol #8: C:\WINNT\System32\CSLSP.DLL
Protocol #9: C:\WINNT\System32\CSLSP.DLL
Protocol #10: C:\WINNT\System32\CSLSP.DLL
Protocol #11: C:\WINNT\System32\CSLSP.DLL
Protocol #12: C:\WINNT\System32\CSLSP.DLL
Protocol #13: C:\WINNT\System32\CSLSP.DLL
Protocol #14: C:\WINNT\System32\CSLSP.DLL
Protocol #15: C:\WINNT\System32\CSLSP.DLL
Protocol #16: C:\WINNT\System32\CSLSP.DLL
Protocol #17: C:\WINNT\System32\CSLSP.DLL
Protocol #23: C:\WINNT\System32\CSLSP.DLL

--------------------------------------------------
End of report, 8,712 bytes
Report generated in 0.140 seconds

bigheadgun
February 15th, 2003, 01:18 AM
hey does anyone know how to remove bde projector completely out of your system without removing the program it's in. i removed everything but the folder directory it want leave for some reason.

AnnMarie
February 15th, 2003, 01:47 AM
Hi bigheadgun - BDE projector is not running in your startups so you should be able to just delete the directory however more information for you here (http://www.doxdesk.com/parasite/BDE.html). You do however have DownloadWare (http://www.doxdesk.com/parasite/DownloadWare.html) running. Try removing it from Add/Remove Programs and then update Spybot and run it again.

Now open your browser and go to Tools > Internet Options and click on the General Tab. Click on Settings (next to Temporary Internet Files) and then click on View Objects. Rightclick on each of the following entries and delete them:

[{359F7E49-1EA0-4671-92E9-61E32FE25C5E}]
CODEBASE = http://69.0.137.190/version3/Netster.dll

[WildTangent Control]
InProcServer32 = C:\WINNT\wt\webdriver\webdriver.dll
CODEBASE = http://www.wildtangent.com/install/...soft/wtinst.cab

If there are any damaged controls there, delete those also.

Let us know if this helps.

wllwnn
February 15th, 2003, 02:07 AM
Note that the Wild Tanget web driver is for there games.

If u delete that you will have too redownload it. (from what i know there is no spyware on it)