1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Must restart with Last Known Good Config

Discussion in 'Windows XP' started by respun, 2007/07/27.

  1. 2007/07/30
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    The fact that stands out from those event messages is that you apparently have Symantec (Norton) installed - is Norton running? If it is there is likely to be a conflict between that and WindowsOneCare. WOC provides antivirus and firewall as does Norton, depending on what version you may have running. Running 2 firewalls and 2 antivirus programs is courting potential problems. Would you clarify this point please.

    Also seems to be a problem with Webroot Spy Sweeper - I would reinstall.

    There is still a reference to Kaazaa lurking somewhere ....
    Wait for advice from Dave before running that command.
    This is really harmless, but can be resolved by applying the UHPClean patch.

    If the WindowsOneCare firewall is off the native Windows Firewall should be switched on - if you have no firewall there would be a warning from Security Centre in the Notification Area.

    You may need to reinstall WOC.

    It's not clear if any of the above are the direct cause of the BSOD's, etc, but worth fixing them - particularly the Norton/WOC question.
     
  2. 2007/07/30
    respun

    respun Inactive Thread Starter

    Joined:
    2007/07/27
    Messages:
    23
    Likes Received:
    0
    Dear Pete -- I uninstalled Norton some years ago. I replaced it with Webroot which I also uninstalled more than a year ago. I replaced Webroot with AOL security suite on the advice of a computer repairman. Within the last few months, I turned off AOL security center but I didn't unintall it. I have been using Windows Live OneCare, based on internet reviews.

    Just this morning, I used the Norton Removal Tool, but the Norton remnants linger. I would like no more Norton stuff, no more Kazaa, no more Webroot. I am also ready to uninstall all AOL security and spyware stuff. But geesh. My how do I get the Windows Live OneCare to work again? Thanks for all your help. :confused:
     

  3. to hide this advert.

  4. 2007/07/30
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Ok - you may be able to hide the remnants of Norton and Webroot - the Services that they installed are still apparently present ....

    Right Click My Computer icon > Manage > Services & Applications > Services.

    Scroll down the list and if you find Symantec Core LC listed double click on it and set Startup type to Disabled.

    Do the same for Webroot Spy Sweeper Engine if present.
    I am not familiar with WindowsOneCare, but my first reaction would be to uninstall it, reboot and reinstall it - http://help.msn.com/(bWt0PWVuLVVTJn...&querytype=topic&query=PROC_hdi_reinstall.htm
     
  5. 2007/07/30
    respun

    respun Inactive Thread Starter

    Joined:
    2007/07/27
    Messages:
    23
    Likes Received:
    0
    Dear Pete --

    Thank you. I just disabled Symantec Core LC. Webroot was already disabled earlier today by me (and that setting is still valid). So strange to me how these pieces follow your computer around long after you've tried to properly banish them. I am now about to uninstall all of my old AOL security stuff. And then I will work on your Windows Live OneCare suggestion. Thanks again. :)
     
  6. 2007/07/30
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
  7. 2007/07/30
    respun

    respun Inactive Thread Starter

    Joined:
    2007/07/27
    Messages:
    23
    Likes Received:
    0
    AOL is the CULPRIT

    Unbelievable. I have now removed AOL Security and Spyware. Using Uninstall AOL in the Add/Remove control panel. My system is working normally. No blue screens. No Last Known Good Configuration. I was even able to set a System Restore point just now. AOLLLLLLLLL! Urgh. I find it shocking that they don't send out an email to all subscribers when they cause a systemwide problem. They are very able to send out mass emails asking us whether we want AOL Visa cards. Harumph.

    I still can't get my Windows OneCare to work. Possible coincidence. Their web site says that they are experiencing technical difficulties. In any event, I uninstalled this. I will reinstall when their web site is back up. Unless this forum tells me not to and to install other, better firewall, AV, and spyware products. I do like having all embedded in one suite -- other better suites?

    Thanks again to everyone. :eek:
     
  8. 2007/07/30
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Damned AOL again - I detest that setup - AOHell - as no doubt you have seen. Well done anyway :)

    I must be honest and say that WindowsOneCare does not rate highly in any tests . My choice would be - and this is obviously what I use and sleep well at night :) is ....

    Comodo firewall - free

    NOD32 AV - pay , but one of, if not the best.

    Antispyware - my choice ....

    Sunbelt Counterspy - pay, Windows Defender a free option coupled with ....

    SpywareBlaster - permanent protection against a range of nasties - free

    Spybot Search and Destroy - with the immunise feature enabled - manual scan occasionally - free

    AdAware 2007 - manual scan occasionally as backup to above - free

    IeSpyads - IE restricted Zone addons - free

    Custom Hosts file - mvps.org - free

    See my article for more detail and links ....

    Keep your Computer free from Viruses, Trojans, Spyware and other Malware

    The problem with security suites is that you do not get the best individual components - one component may well be good, the others mediocre.
     
  9. 2007/07/30
    respun

    respun Inactive Thread Starter

    Joined:
    2007/07/27
    Messages:
    23
    Likes Received:
    0
    Dear Pete --

    I have printed out your recommendations and your article. Many thanks. I only wish that my solution (easy) could get out to all those who are in my same boat. I can see from doing a Google search on AOL and Command Services that there are lots of similarly troubled computers...
    :D
     
  10. 2007/07/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi respun,

    Happy to hear the BSODs have stopped :D

    Suggest you run the Norton Removal Tool to clean up leftovers.

    Kazaa ........ I'm quite surprised there are still some remnants left. Suggest you get RegSeeker and do a Find in registry search for Kazaa. When the search is complete, please click Select>Select All, then click Action>Export selected items. It will default to the RegSeeker\Backup folder as a registry file. Right click that file and select edit to open it in notepad. Copy the contents and post it here, unless you feel comfortable just deleting whatever is found.
     
  11. 2007/07/30
    Bursley

    Bursley Well-Known Member Alumni

    Joined:
    2001/12/29
    Messages:
    462
    Likes Received:
    2
    by unchecking the auto-restart option, your system should display a blue screen of death (BSOD), and wait for you to hard reset your system prior to rebooting. this should allow you to capture the screen, which may tell us additional information.
     
  12. 2007/07/30
    respun

    respun Inactive Thread Starter

    Joined:
    2007/07/27
    Messages:
    23
    Likes Received:
    0
    Dear Noah and Eric --

    1. Norton Removal Tool. I have now used Norton Removal Tool twice today. Hmm. Not sure at all that it actually does what it promises to do.

    2. Kazaa. I installed and ran a RegSeeker search on Kazaa. I have posted the resultant registry file at the end of this post.

    3. BSoD. A thing of my past! Eric, see my post #17 in this thread, and the subsequent posts, to get the capture information that you were looking for on the hard restart (which happened earlier today). You will also learn that AOL security was the problem. Once that was removed, I have returned to normal operation, but see...

    4. Slow as Molasses. I have installed the recommended AV program (Kaspersky) and the recommended Firewall (Comodo). My internet surfing is akin to watching paint dry. I used to zip along. Have I bogged myself down? Should I remove these and try less demanding options?

    Respun :confused:

    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603]
    "002 "= "kazaa "
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\kazaa-lite.ws]
    "* "=dword:00000004
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1]
    "3 "=hex:46,00,31,00,00,00,00,00,5D,31,C6,9E,10,00,4B,41,5A,41,41,42,7E,31,00,00,2E,00,\
    03,00,04,00,EF,BE,5D,31,C6,9E,5D,31,C6,9E,14,00,00,00,6B,00,61,00,7A,00,61,\
    00,61,00,62,00,65,00,67,00,6F,00,6E,00,65,00,00,00,18,00,00,00
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\0]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\1]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\10]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\11]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\12]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\13]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\14]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\15]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\16]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\17]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\18]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\19]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\2]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\20]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\21]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\22]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\1\1\23]
     
  13. 2007/07/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Run that RegSeeker search again and click the following entry to select it.

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\kazaa-lite.ws]

    Then right click and select Open in regedit. In the left pane, click on the kazaa-lite.ws key (folder icon), then right click on it and select delete. Close the registry editor. In Regseeker, click Select>Select All, then click Action>Delete selected items.

    I'm still not convinced that was what we were looking for RE:Kazaa either. Check the event viewer over the next couple of days and let me know if that error resurfaces. Meantime, I'll do some research on it.

    If you want, we can make sure that at least the Norton Services are gone, although that removal tool generally does a good job. To check the services, download WinPFind3U.exe by OldTimer to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.

    Close out all other programs and windows. Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
    • In the Processes group click None
    • In the Win32 Services group click All
    • In the Driver Services group click None
    • In the Registry group click None
    • In the Files Created Within group select None
    • In the Files Modified Within group select None
    • In the File String Search group select None
    • In the Additional scans section to the right, uncheck the box
    Now click the Run Scan button on the toolbar.

    Let it run unhindered until it finishes.

    When the scan is complete Notepad will open with the report file loaded in it.
    Save that notepad file and post the results here. The log might be quite large and require more than one post to get it all.
     
  14. 2007/07/31
    respun

    respun Inactive Thread Starter

    Joined:
    2007/07/27
    Messages:
    23
    Likes Received:
    0
    Dear Noah --

    Last things first. Here is WinPFind3U Log:

    WinPFind3 logfile created on: 7/30/2007 10:00:39 PM
    WinPFind3U by OldTimer - Version 1.0.39 Folder = C:\Documents and Settings\[my name]\My Documents\My Downloads\WinPFind3u\
    Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
    Internet Explorer (Version = 7.0.5730.11)

    509.98 Mb Total Physical Memory | 296.57 Mb Available Physical Memory | 58.15% Memory free
    1.22 Gb Paging File | 0.97 Gb Available in Paging File | 79.35% Paging File free
    Paging file location(s): C:\pagefile.sys 768 1536;

    %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
    Drive C: | 35.89 Gb Total Space | 9.58 Gb Free Space | 26.68% Space Free
    D: Drive not present or media not loaded
    E: Drive not present or media not loaded
    F: Drive not present or media not loaded

    Computer Name: [my name]
    Current User Name: [my name]
    Logged in as Administrator.
    Current Boot Mode: Normal


    [Win32 Services - All]
    (Alerter) Alerter [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (ALG) Application Layer Gateway Service [Win32_Own | On_Demand | Running] -> %System32%\alg.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 44544 bytes | Modified Date = 8/4/2004 12:56:48 AM | Attr = ]
    (AOL ACS) AOL Connectivity Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\AOL\ACS\AOLacsd.exe -> AOL LLC [Ver = 4.6.1.2 | Size = 46640 bytes | Modified Date = 10/23/2006 5:50:36 AM | Attr = R ]
    (AOL TopSpeedMonitor) AOL TopSpeed Monitor [Win32_Own | Auto | Running] -> %CommonProgramFiles%\AOL\TopSpeed\2.0\aoltsmon.exe -> America Online, Inc [Ver = 2, 0, 0, 0 | Size = 100016 bytes | Modified Date = 10/15/2004 1:54:14 PM | Attr = ]
    (AppMgmt) Application Management [Win32_Shared | On_Demand | Stopped] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> Microsoft Corporation [Ver = 2.0.50727.832 (QFE.050727-8300) | Size = 33632 bytes | Modified Date = 4/13/2007 3:20:52 AM | Attr = ]
    (AudioSrv) Windows Audio [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (AVP) Kaspersky Anti-Virus 6.0 [Win32_Own | Auto | Running] -> %ProgramFiles%\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe -> Kaspersky Lab [Ver = 6.0.2.621 | Size = 200768 bytes | Modified Date = 3/9/2007 7:50:58 PM | Attr = ]
    (BITS) Background Intelligent Transfer Service [Win32_Shared | On_Demand | Stopped] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (Browser) Computer Browser [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (cisvc) Indexing Service [Win32_Shared | On_Demand | Stopped] -> %System32%\cisvc.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 5632 bytes | Modified Date = 8/4/2004 12:56:48 AM | Attr = ]
    (ClipSrv) ClipBook [Win32_Own | Disabled | Stopped] -> %System32%\clipsrv.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 33280 bytes | Modified Date = 8/4/2004 12:56:48 AM | Attr = ]
    (clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> Microsoft Corporation [Ver = 2.0.50727.832 (QFE.050727-8300) | Size = 68952 bytes | Modified Date = 4/13/2007 3:21:18 AM | Attr = ]
    (CmdAgent) Comodo Application Agent [Win32_Own | Auto | Running] -> %ProgramFiles%\Comodo\Firewall\cmdagent.exe -> COMODO [Ver = 2.4.0.20 | Size = 361040 bytes | Modified Date = 7/30/2007 5:43:44 PM | Attr = ]
    (COMSysApp) COM+ System Application [Win32_Own | On_Demand | Stopped] -> %System32%\dllhost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 5120 bytes | Modified Date = 8/4/2004 12:56:48 AM | Attr = ]
    (CryptSvc) Cryptographic Services [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (DcomLaunch) DCOM Server Process Launcher [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (Dhcp) DHCP Client [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 12:56:48 AM | Attr = ]
    (dmserver) Logical Disk Manager [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (Dnscache) DNS Client [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (ERSvc) Error Reporting Service [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (Eventlog) Event Log [Win32_Shared | Auto | Running] -> %System32%\services.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 108032 bytes | Modified Date = 8/4/2004 12:56:56 AM | Attr = ]
    (EventSystem) COM+ Event System [Win32_Shared | On_Demand | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (FastUserSwitchingCompatibility) Fast User Switching Compatibility [Win32_Shared | On_Demand | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.0.734.29932.beta | Size = 138168 bytes | Modified Date = 2/3/2007 8:39:04 AM | Attr = ]
    (helpsvc) Help and Support [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (HidServ) HID Input Service [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (HTTPFilter) HTTP SSL [Win32_Shared | On_Demand | Stopped] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 1:41:10 AM | Attr = ]
    (ImapiService) IMAPI CD-Burning COM Service [Win32_Own | On_Demand | Stopped] -> %System32%\imapi.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 150016 bytes | Modified Date = 8/4/2004 12:56:50 AM | Attr = ]
    (iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.1.1.5 | Size = 500800 bytes | Modified Date = 3/14/2007 7:05:42 PM | Attr = ]
    (lanmanserver) Server [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (lanmanworkstation) Workstation [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (LmHosts) TCP/IP NetBIOS Helper [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (LPDSVC) TCP/IP Print Server [Win32_Shared | On_Demand | Stopped] -> %System32%\tcpsvcs.exe -> Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 19456 bytes | Modified Date = 8/18/2001 6:00:00 AM | Attr = ]
    (MDM) Machine Debug Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Microsoft Shared\VS7Debug\mdm.exe -> Microsoft Corporation [Ver = 7.00.9466 | Size = 322120 bytes | Modified Date = 6/19/2003 11:25:00 PM | Attr = ]
    (Messenger) Messenger [Win32_Shared | Disabled | Stopped] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (mnmsrvc) NetMeeting Remote Desktop Sharing [Win32_Own | On_Demand | Stopped] -> %System32%\mnmsrvc.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 | Size = 32768 bytes | Modified Date = 8/4/2004 12:56:52 AM | Attr = ]
    (MSDTC) Distributed Transaction Coordinator [Win32_Own | On_Demand | Stopped] -> %System32%\msdtc.exe -> Microsoft Corporation [Ver = 2001.12.4414.258 | Size = 6144 bytes | Modified Date = 8/4/2004 12:56:54 AM | Attr = ]
    (MSIServer) Windows Installer [Win32_Shared | On_Demand | Stopped] -> %System32%\msiexec.exe -> Microsoft Corporation [Ver = 3.1.4000.1823 | Size = 78848 bytes | Modified Date = 3/21/2005 3:00:22 PM | Attr = ]
    (NetDDE) Network DDE [Win32_Shared | Disabled | Stopped] -> %System32%\netdde.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 111104 bytes | Modified Date = 8/4/2004 12:56:54 AM | Attr = ]
    (NetDDEdsdm) Network DDE DSDM [Win32_Shared | Disabled | Stopped] -> %System32%\netdde.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 111104 bytes | Modified Date = 8/4/2004 12:56:54 AM | Attr = ]
    (Netlogon) Net Logon [Win32_Shared | On_Demand | Stopped] -> %System32%\lsass.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Modified Date = 8/4/2004 12:56:50 AM | Attr = ]
    (Netman) Network Connections [Win32_Shared | On_Demand | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (Nla) Network Location Awareness (NLA) [Win32_Shared | On_Demand | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (NMSSvc) Intel(R) NMS [Win32_Own | Auto | Stopped] -> %System32%\NMSSvc.Exe -> Intel Corporation [Ver = 2.2.9.0 | Size = 1118208 bytes | Modified Date = 5/3/2002 1:36:24 PM | Attr = ]
    (NtLmSsp) NT LM Security Support Provider [Win32_Shared | On_Demand | Stopped] -> %System32%\lsass.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Modified Date = 8/4/2004 12:56:50 AM | Attr = ]
    (NtmsSvc) Removable Storage [Win32_Shared | On_Demand | Stopped] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (PlugPlay) Plug and Play [Win32_Shared | Auto | Running] -> %System32%\services.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 108032 bytes | Modified Date = 8/4/2004 12:56:56 AM | Attr = ]
    (PolicyAgent) IPSEC Services [Win32_Shared | Auto | Running] -> %System32%\lsass.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Modified Date = 8/4/2004 12:56:50 AM | Attr = ]
    (ProtectedStorage) Protected Storage [Win32_Shared | Auto | Running] -> %System32%\lsass.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Modified Date = 8/4/2004 12:56:50 AM | Attr = ]
    (RasAuto) Remote Access Auto Connection Manager [Win32_Shared | On_Demand | Stopped] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (RasMan) Remote Access Connection Manager [Win32_Shared | On_Demand | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (RDSessMgr) Remote Desktop Help Session Manager [Win32_Own | On_Demand | Stopped] -> %System32%\sessmgr.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 140800 bytes | Modified Date = 8/4/2004 12:56:56 AM | Attr = ]
    (RemoteAccess) Routing and Remote Access [Win32_Shared | Disabled | Stopped] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (RemoteRegistry) Remote Registry [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (RpcLocator) Remote Procedure Call (RPC) Locator [Win32_Own | On_Demand | Stopped] -> %System32%\locator.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 75264 bytes | Modified Date = 8/4/2004 12:56:50 AM | Attr = ]
    (RpcSs) Remote Procedure Call (RPC) [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (RSVP) QoS RSVP [Win32_Own | On_Demand | Stopped] -> %System32%\rsvp.exe -> Microsoft Corporation [Ver = 5.1.2600.0 (xpclient.010817-1148) | Size = 132608 bytes | Modified Date = 8/18/2001 6:00:00 AM | Attr = ]
    (SamSs) Security Accounts Manager [Win32_Shared | Auto | Running] -> %System32%\lsass.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 13312 bytes | Modified Date = 8/4/2004 12:56:50 AM | Attr = ]
    (SCardSvr) Smart Card [Win32_Shared | On_Demand | Stopped] -> %System32%\scardsvr.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 95744 bytes | Modified Date = 8/4/2004 12:56:56 AM | Attr = ]
    (Schedule) Task Scheduler [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (seclogon) Secondary Logon [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (SENS) System Event Notification [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (SharedAccess) Windows Firewall/Internet Connection Sharing (ICS) [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (ShellHWDetection) Shell Hardware Detection [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (SNMP) SNMP Service [Win32_Own | Auto | Running] -> %System32%\snmp.exe -> Microsoft Corporation [Ver = 5.1.2600.3038 (xpsp_sp2_gdr.061119-2303) | Size = 33280 bytes | Modified Date = 11/20/2006 1:42:46 AM | Attr = ]
    (SNMPTRAP) SNMP Trap Service [Win32_Own | On_Demand | Stopped] -> %System32%\snmptrap.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 8704 bytes | Modified Date = 8/4/2004 12:56:56 AM | Attr = ]
    (Spooler) Print Spooler [Win32_Own | Auto | Running] -> %System32%\spoolsv.exe -> Microsoft Corporation [Ver = 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) | Size = 57856 bytes | Modified Date = 6/10/2005 4:53:32 PM | Attr = ]
    (srservice) System Restore Service [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (SSDPSRV) SSDP Discovery Service [Win32_Shared | On_Demand | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (stisvc) Windows Image Acquisition (WIA) [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (SwPrv) MS Software Shadow Copy Provider [Win32_Own | On_Demand | Stopped] -> %System32%\dllhost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 5120 bytes | Modified Date = 8/4/2004 12:56:48 AM | Attr = ]
    (Symantec Core LC) Symantec Core LC [Win32_Own | Disabled | Stopped] -> %CommonProgramFiles%\Symantec Shared\CCPD-LC\symlcsvc.exe -> File not found
    (SysmonLog) Performance Logs and Alerts [Win32_Own | On_Demand | Stopped] -> %System32%\smlogsvc.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 89600 bytes | Modified Date = 8/4/2004 12:56:56 AM | Attr = ]
    (TapiSrv) Telephony [Win32_Shared | On_Demand | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (TermService) Terminal Services [Win32_Shared | On_Demand | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (Themes) Themes [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (TlntSvr) Telnet [Win32_Own | On_Demand | Stopped] -> %System32%\tlntsvr.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 73216 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (TrkWks) Distributed Link Tracking Client [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (UMWdf) Windows User Mode Driver Framework [Win32_Own | Auto | Running] -> %System32%\wdfmgr.exe -> Microsoft Corporation [Ver = 5.2.3790.1230 built by: dnsrv(bld4act) | Size = 38912 bytes | Modified Date = 1/28/2005 2:44:28 PM | Attr = ]
    (UPHClean) User Profile Hive Cleanup [Win32_Own | Auto | Running] -> %ProgramFiles%\UPHClean\uphclean.exe -> Microsoft Corporation [Ver = 1.6.30.0 | Size = 241725 bytes | Modified Date = 4/27/2005 2:59:24 PM | Attr = ]
    (upnphost) Universal Plug and Play Device Host [Win32_Shared | On_Demand | Stopped] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (UPS) Uninterruptible Power Supply [Win32_Own | On_Demand | Stopped] -> %System32%\ups.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 18432 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (VSS) Volume Shadow Copy [Win32_Own | On_Demand | Stopped] -> %System32%\vssvc.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 289792 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (W32Time) Windows Time [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (WANMiniportService) WAN Miniport (ATW) Service [Win32_Own | Auto | Running] -> %SystemRoot%\wanmpsvc.exe -> America Online, Inc. [Ver = 9, 0, 0, 0 | Size = 65536 bytes | Modified Date = 8/27/2003 10:29:46 AM | Attr = ]
    (WebClient) WebClient [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (WebrootSpySweeperService) Webroot Spy Sweeper Engine [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\Webroot\Spy Sweeper\SpySweeper.exe -> File not found
    (winmgmt) Windows Management Instrumentation [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (winss) Windows Live OneCare [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Microsoft Windows OneCare Live\winss.exe -> File not found
    (WmdmPmSN) Portable Media Serial Number Service [Win32_Shared | On_Demand | Stopped] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (Wmi) Windows Management Instrumentation Driver Extensions [Win32_Shared | On_Demand | Stopped] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (WmiApSrv) WMI Performance Adapter [Win32_Own | On_Demand | Stopped] -> %System32%\wbem\wmiapsrv.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 126464 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (wscsvc) Security Center [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (wuauserv) Automatic Updates [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (WZCSVC) Wireless Zero Configuration [Win32_Shared | Auto | Running] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]
    (xmlprov) Network Provisioning Service [Win32_Shared | On_Demand | Stopped] -> %System32%\svchost.exe -> Microsoft Corporation [Ver = 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) | Size = 14336 bytes | Modified Date = 8/4/2004 12:56:58 AM | Attr = ]

    < End of report >
     
  15. 2007/07/31
    respun

    respun Inactive Thread Starter

    Joined:
    2007/07/27
    Messages:
    23
    Likes Received:
    0
    Dear Noah --

    Did the RegSeeker steps to delete Kazaa stuff. Not sure I did it right as the entries weren't identical to those in the log that I earlier posted. But, oh what the heck. They all said Kazaa and they are all deleted. Thank you. I'll let you know if anything zany happens. Respun;)
     
  16. 2007/07/31
    Rockster2U

    Rockster2U Geek Member

    Joined:
    2002/04/01
    Messages:
    3,181
    Likes Received:
    9
    Question of respun and Dave ..........
    It appears that AOL connectivity service is in play here - would it be smart to investigate this further?

    ;)
     
  17. 2007/07/31
    respun

    respun Inactive Thread Starter

    Joined:
    2007/07/27
    Messages:
    23
    Likes Received:
    0
    Dear Rockster --

    Thanks for your question. A reboot cured me of the slows. I'm operating just fine on all counts. I don't know what caused it. Here is all that shows up in my Event Viewer. These same two entries show up multiple times but not since the last occasion identified with the time stamps below.

    Respun:)

    Event Type: Warning
    Event Source: EvntAgnt
    Event Category: None
    Event ID: 1015
    Date: 7/30/2007
    Time: 8:13:51 PM
    Description: TraceLevel parameter not located in registry; Default trace level used is 32.

    Event Type: Warning
    Event Source: EvntAgnt
    Event Category: None
    Event ID: 1003
    Date: 7/30/2007
    Time: 8:13:51 PM
    Description: TraceFileName parameter not located in registry; Default trace file used is .
     
  18. 2007/07/31
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi respun,

    Just one Symantec entry left, and three AOLs. Click Start>Run and type (or paste) the following commands, one at a time, hitting enter after each to remove them.

    sc stop AOL ACS
    sc delete AOL ACS
    sc stop AOL TopSpeedMonitor
    sc delete AOL TopSpeedMonitor
    sc stop WANMiniportService
    sc delete WANMiniportService
    sc stop Symantec Core LC
    sc delete Symantec Core LC


    Good to hear a reboot cured the molasses effect too. :D

    Post back if that Kazaa error continues.
     
  19. 2007/07/31
    respun

    respun Inactive Thread Starter

    Joined:
    2007/07/27
    Messages:
    23
    Likes Received:
    0
    Dear Noah -- I executed on the two Run instructions in re Symantec. I am still using AOL so I didn't remove the other items. I will post back if the Kazaa error repeats. Should I be worried about the two other items from the Event Viewer (see my post to Rockster, right before your last post)? These two do continue to occur...

    Respun:)
     
  20. 2007/07/31
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
  21. 2007/08/01
    respun

    respun Inactive Thread Starter

    Joined:
    2007/07/27
    Messages:
    23
    Likes Received:
    0
    Wow. My errors are so normal, yet seemingly so worrisome. I did not fix these as you offered because I was scared off by the Microsoft warnings. Chicken, I know. Just don't want any trouble now that I've had one day of smooth sailing. Thanks again.

    Respun:eek:
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.