Go Back   Cyber Tech Help Support Forums > Operating Systems > Older Windows Versions > Windows ME

Notices

Reply
 
Topic Tools
  #1  
Old May 2nd, 2003, 08:25 PM
jmpsilva jmpsilva is offline
New Member
 
Join Date: Apr 2003
Posts: 4
Start up the PC

When I start the PC finishing the boot, appear the "Maneger Conections" screen.
Hoew can I fixed?
Reply With Quote
  #2  
Old May 3rd, 2003, 01:54 PM
tb525 tb525 is offline
Hijack Advisor
 
Join Date: Sep 2002
O/S: Windows Vista
Posts: 3,132
Let's see what is loading at startup, Go here and download, unzip and run StartupList. It will create a log file, Copy the log and paste it in a reply.

http://www.lurkhere.com/~nicefiles/index.html
Reply With Quote
  #3  
Old May 4th, 2003, 01:28 AM
jmpsilva jmpsilva is offline
New Member
 
Join Date: Apr 2003
Posts: 4
StartupList report, 3/5/2003, 19:09:35
StartupList version: 1.52
Started from : C:\WINDOWS\DESKTOP\STARTUPLIST.EXE
Detected: Windows ME (Win9x 4.90.3000)
Detected: Internet Explorer v6.00 (6.00.2600.0000)
* Using default options
==================================================

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\ARQUIVOS DE PROGRAMAS\ROXIO\GOBACK\GBPOLL.EXE
C:\ARQUIVOS DE PROGRAMAS\ARQUIVOS COMUNS\SYMANTEC SHARED\CCEVTMGR.EXE
C:\ARQUIVOS DE PROGRAMAS\ARQUIVOS COMUNS\SYMANTEC SHARED\SYMTRAY.EXE
C:\ARQUIVOS DE PROGRAMAS\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE
C:\ARQUIVOS DE PROGRAMAS\NORTON PERSONAL FIREWALL\NISUM.EXE
C:\ARQUIVOS DE PROGRAMAS\NORTON PERSONAL FIREWALL\CCPXYSVC.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SM56HLPR.EXE
C:\WINDOWS\SYSTEM\HPZTSB03.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\LOADQM.EXE
C:\ARQUIVOS DE PROGRAMAS\KAZAA\KAZAA.EXE
C:\ARQUIVOS DE PROGRAMAS\DOWNLOADWARE\DW.EXE
C:\ARQUIVOS DE PROGRAMAS\ARQUIVOS COMUNS\SYMANTEC SHARED\CCAPP.EXE
C:\ARQUIVOS DE PROGRAMAS\WINAMP3\WINAMPA.EXE
C:\WINDOWS\RunDLL.exe
C:\ARQUIVOS DE PROGRAMAS\ROXIO\GOBACK\GBTRAY.EXE
C:\ARQUIVOS DE PROGRAMAS\WINZIP\WZQKPICK.EXE
C:\ARQUIVOS DE PROGRAMAS\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINSM32.EXE
C:\ARQUIVOS DE PROGRAMAS\INS\VITALAGENT\PROGRAM\VTLAGENT.EXE
C:\Arquivos de programas\Norton SystemWorks\Norton CleanSweep\Monwow.exe
C:\WINDOWS\DESKTOP\STARTUPLIST.EXE

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\WINDOWS\Menu Iniciar\Programas\Iniciar]
Microsoft Office.lnk = C:\Aplicativos\Office2000\Office\OSA9.EXE
WinZip Quick Pick.lnk = C:\Arquivos de programas\WinZip\WZQKPICK.EXE
CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Arquivos de programas\Norton SystemWorks\Norton CleanSweep\csinsm32.exe
MyVitalAgent.lnk = C:\Arquivos de programas\INS\VitalAgent\Program\VtlAgent.exe

Shell folders Common Startup:
[C:\WINDOWS\All Users\Menu Iniciar\Programas\Iniciar]
GoBack.lnk = C:\Arquivos de programas\Roxio\GoBack\GBTray.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\TASKMON.EXE
PCHealth = C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE -s
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SMSERIAL = sm56hlpr.exe
HPDJ Taskbar Utility = C:\WINDOWS\SYSTEM\hpztsb03.exe
Horas = C:\WINDOWS\SYSTEM\horas.exe
Mirabilis ICQ = C:\Meus documentos\Mauricio\Arquivos de programas\Symantec\LiveUpdate\NDETECT.EXE
DXM6Patch_981116 = C:\WINDOWS\p_981116.exe /Q:A
LVComs = C:\WINDOWS\SYSTEM\LVComS.exe
LoadQM = loadqm.exe
WinStart = C:\WINDOWS\System\WinStart.exe -boot
KAZAA = C:\ARQUIVOS DE PROGRAMAS\KAZAA\KAZAA.EXE /SYSTRAY
MediaLoads Installer = "C:\Arquivos de programas\DownloadWare\dw.exe" /H
ccApp = C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccApp.exe
ccRegVfy = "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccRegVfy.exe"
QD FastAndSafe =
NPROTECT = C:\Arquivos de programas\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
WinampAgent = "C:\Arquivos de programas\Winamp3\winampa.exe"

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services

LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
*StateMgr = C:\WINDOWS\System\Restore\StateMgr.exe
Machine Debug Manager = C:\WINDOWS\SYSTEM\MDM.EXE
SchedulingAgent = mstask.exe
GoBack Polling Service = C:\Arquivos de programas\Roxio\GoBack\GBPoll.exe
ccEvtMgr = C:\Arquivos de programas\Arquivos comuns\Symantec Shared\ccEvtMgr.exe
ScriptBlocking = "C:\Arquivos de programas\Arquivos comuns\Symantec Shared\Script Blocking\SBServ.exe" -reg
SymTray - Norton SystemWorks = C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SymTray.exe "Norton SystemWorks"
NPROTECT = C:\Arquivos de programas\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
Nisum = C:\Arquivos de programas\Norton Personal Firewall\NISUM.EXE
ccPxySvc = C:\ARQUIV~1\NORTON~2\CCPXYSVC.EXE

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Taskbar Display Controls = RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
msnmsgr = ;"C:\ARQUIVOS DE PROGRAMAS\MSN MESSENGER\MSNMSGR.EXE" /background

--------------------------------------------------

C:\WINDOWS\WININIT.BAK listing:
(Created 1/5/2003, 22:38:18)

[Rename]
C:\ARQUIV~1\ARQUIV~1\SYMANT~1\SEVINST.EXE=C:\ARQUI V~1\ARQUIV~1\SYMANT~1\SEVINST.EX1

--------------------------------------------------

C:\AUTOEXEC.BAT listing:

SET windir=C:\WINDOWS
SET winbootdir=C:\WINDOWS
SET COMSPEC=C:\WINDOWS\COMMAND.COM
SET PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
SET PROMPT=$p$g
SET TEMP=C:\WINDOWS\TEMP
SET TMP=C:\WINDOWS\TEMP

--------------------------------------------------

C:\WINDOWS\WINSTART.BAT listing:

C:\WINDOWS\tmpcpyis.bat

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\WINDOWS\TEMP\pft335~TMP\Reader\ActiveX\AcroIEHe lper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - (no file) - {7EEF1E3D-FD97-4401-BCDB-5827F2D11709}
(no name) - C:\WINDOWS\IPINSIGT.DLL - {000004CC-E4FF-4F2C-BC30-DBEF0B983BC9}
(no name) - C:\WINDOWS\SYSTEM\BHO.DLL - {730F2451-A3FE-4A72-938C-FC8A74F15978}
Url Catcher - (no file) - {CE31A1F7-3D90-4874-8FBE-A5D97F8BC8F1}
(no name) - C:\Arquivos de programas\NewDotNet\newdotnet4_50.dll - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E}
NAV Helper - C:\Arquivos de programas\Norton SystemWorks\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
(no name) - (no file) - {2662BDD7-05D6-408F-B241-FF98FACE6054}
MediaLoads Enhanced - C:\ARQUIVOS DE PROGRAMAS\MEDIALOADS ENHANCED\ME1.DLL - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Agendador do PCHealth para coleta de dados.job
Symantec NetDetect.job
Norton SystemWorks One Button Checkup.job
Norton AntiVirus - Scan my computer.job

--------------------------------------------------

Enumerating Download Program Files:

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/s...sh/swflash.cab

[AInst Class]
InProcServer32 = C:\WINDOWS\DOWNLO~1\ACTIVE~1.DLL
CODEBASE = http://cnt.rapidblaster.com/install/activeinstaller.dll

[MSN Chat Control 4.5]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MSNCHAT45.OCX
CODEBASE = http://fdl.msn.com/public/chat/msnchat45.cab

[MoneyTree Dialer]
InProcServer32 = C:\WINDOWS\DOWNLO~1\UNIDIST.OCX
CODEBASE = http://xbscc1.mtree.com/mt/dialers/fc/UniDist.CAB

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #2: C:\Arquivos de programas\NewDotNet\newdotnet4_50.dll
Protocol #1: C:\ARQUIVOS DE PROGRAMAS\NEWDOTNET\NEWDOTNET4_50.DLL
Protocol #2: C:\ARQUIVOS DE PROGRAMAS\NEWDOTNET\NEWDOTNET4_50.DLL
Protocol #9: C:\ARQUIVOS DE PROGRAMAS\NEWDOTNET\NEWDOTNET4_50.DLL
Protocol #10: C:\ARQUIVOS DE PROGRAMAS\NEWDOTNET\NEWDOTNET4_50.DLL

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
AUHook: C:\WINDOWS\SYSTEM\AUHOOK.DLL

--------------------------------------------------
End of report, 8.668 bytes
Report generated in 0,794 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Reply With Quote
  #4  
Old May 4th, 2003, 01:45 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
MVP
 
Join Date: Oct 2001
Location: Netherlands
Posts: 289
You have some spyware.

Download Spybot - Search & Destroy

After installing, first press Online, and search for, put a check mark at, and install all updates.

Next, close all Internet Explorer windows, hit 'Check for Problems', and have SpyBot remove all it finds.

NOTE: SSD will sometimes not be able to remove all active components in the first 'run'.
In that case you will get a dialog asking you to run SSD at next start.
Click yes and reboot.
Subsequently SSD will come up before the system puts these components 'in use', and it will then be able to 'fix' the rest.

When you've done all that, test your system, and see whether your problem is gone.

If no joy, please repost, and we'll look further.
__________________
Tony < - > CLSID List
Reply With Quote
  #5  
Old May 4th, 2003, 04:33 PM
jmpsilva jmpsilva is offline
New Member
 
Join Date: Apr 2003
Posts: 4
The program is cmstp.exe appear ? desktop
Could sameone help me??
Reply With Quote
  #6  
Old May 4th, 2003, 04:46 PM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
MVP
 
Join Date: Oct 2001
Location: Netherlands
Posts: 289
Although it could be the legitimate MS Connection Manager installer, it could also point to a virus infection.

Run an online virus scan at Trend Micro HouseCall or Panda Active Scan, and see what that turns up.

Did you already run SpyBot??
__________________
Tony < - > CLSID List
Reply With Quote
Reply

Bookmarks

Topic Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 06:46 PM.

[ RSS ]