Hi, tried both methods. The command prompt route gave me a load of error
messages after i typed ntsd explorer, including:
Loaded dbghelp extension DLL
The call to LoadLibrary(ext) failed with error 2.
Please check your debugger configuration and/or network access
The same for "LoadLibrary(uext)"
and then:
Symbol search path is: ***Invalid*** : Verify _NT_SYMBOL_PATH setting
followed by a lot of numbers.
after hitting 'g' it did came up with a lot of numbers and text and then the
final message:
Program too big to fit in memory
I also tried asviewer and it gave me the following results:
DiamondCS Autostart Viewer (
www.diamondcs.com.au) - Report for USER@SANJ,
10-30-2005
c:\windows\system32\autoexec.nt
C:\WINDOWS\system32\mscdexnt.exe
C:\WINDOWS\system32\redir.exe
C:\WINDOWS\system32\dosx.exe
c:\windows\system32\config.nt
C:\WINDOWS\system32\himem.sys
c:\windows\system.ini [drivers]
timer=timer.drv
c:\windows\system.ini [boot]\shell
C:\WINDOWS\Explorer.exe
c:\windows\system.ini [boot]\scrnsave.exe
C:\WINDOWS\system32\sspipes.scr
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
C:\WINDOWS\Explorer.exe
HKCU\Control Panel\Desktop\scrnsave.exe
C:\WINDOWS\system32\sspipes.scr
HKCR\vbsfile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\vbefile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\jsfile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\jsefile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\wshfile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKCR\wsffile\shell\open\command\
C:\WINDOWS\System32\WScript.exe "%1" %*
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\TkBellExe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NAV CfgWiz
C:\PROGRA~1\NORTON~1\NORTON~1\Cfgwiz.exe /R
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NAV Agent
C:\PROGRA~1\NORTON~1\NORTON~1\Navapw32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\BootWarn
C:\Program Files\Norton SystemWorks\Norton AntiVirus\BootWarn.exe /a
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Symantec NetDriver Monitor
C:\PROGRA~1\SYMNET~1\SNDMon.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MSConfig
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\*Restore
C:\WINDOWS\system32\restore\rstrui.exe -c
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\CTFMON.EXE
C:\WINDOWS\system32\ctfmon.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\NAVCFG
C:\Program Files\Norton SystemWorks\Norton AntiVirus\CfgWiz.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\NSWCfg.exe
C:\Program Files\Norton SystemWorks\NSWCfg.exe
HKU\.Default\Software\Microsoft\Windows\CurrentVersion\Run\CTFMON.EXE
C:\WINDOWS\system32\CTFMON.EXE
HKU\.Default\Software\Microsoft\Windows\CurrentVersion\Run\AVG7_Run
C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\webcheck.dll
C:\WINDOWS\system32\stobject.dll
C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job
C:\Program Files\Common Files\Symantec Shared\NMain.exe
C:\WINDOWS\Tasks\Symantec NetDetect.job
C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
autocheck autochk *
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
C:\WINDOWS\system32\userinit.exe
HKLM\System\CurrentControlSet\Control\WOW\cmdline
C:\WINDOWS\system32\ntvdm.exe
HKLM\System\CurrentControlSet\Control\WOW\wowcmdline
C:\WINDOWS\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\rsvpsp.dll
Thanks everyone.
:
Try typing in a command prompt
ntsd explorer
After it loads it will break before running - type g (for go) to start it.
This may (and may means may not will) give a hint.
--
--------------------------------------------------------------------------------------------------
Read David defending the concept of violence.
http://margokingston.typepad.com/harry_version_2/2005/10/entering_the_ga.html#more
=================================================
If starting in Safe Mode made no difference then we definitely have a
problem. Because booting in that manner should not have allowed anything to
start that was not necessary for Windows to run. That means our issue is
not in the HKLM\...\Run key but in another place likely under the WinLogon
key in the registry. Safe Mode should not have allowed any thing started
with the shell to run except that which is necessary for Windows to start.
So you need a different app:
http://www.diamondcs.com.au/index.php?page=asviewer
File | Save it after you run it and post the result here.
--
George Hester
_________________________________
Yeah, i was running media player when i made the log - should i not have
done
that? Messenger plus is an add-on for messenger, just gives a lot of
extra
features. I've had that installed for ages, has never caused me any
problems
before.
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe
bthprops.cpl,,BluetoothAuthenticationAgent
This is a programme for moving files between my phone and computer using
bluetooth.
Couldn't find rundll32.exe in my task manager, but have noticed it in the
past.
I only installed the norton antivirus after this problem started, so i'm
not
sure if that could be causing the problem.
I will also stop running limewire and itunes on booting up.
I tried to run things on safemode, but it didn't make a difference
unfortunately.
Is there anything else i need to be doing?
Cheers...
:
Turn off one of the Anti Virus programs.
Were you running Windows Media Player when you made this log?
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
is Real Player but you should be OK. You caanot remove this.
Stop LimeWire from starting at boot
What is this?
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
Oh Ok that is your Acrobat plugin. That's fine.
What is this?
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe
bthprops.cpl,,BluetoothAuthenticationAgent
You do NOT need to run a cpl at every boot.. If you do that is bad
engineering and the application which is doing it should be removed if
you
can.
I do not like this:
O23 - Service: SmartLinkService (SLService) - Smart Link -
Try booting in Safe Mode and tell me if you get the same behavior.
rundll32.exe should not always be running. Try shutting that down in
Task
Manager and tell me what happens. If nothing try a New task there
type in
explorer and say OK.
Why do you need iTunes firing at every boot.
What you want is as little as possible in HKLM\..\Run key. Becuase
you
have
Norton installed it will always be full of stuff. But as little as
possible
in there is what you want to shoot for.
Please answer my very first question that could be most important.
Did you have this issue before you installed Messenger Plus? And
actually
what is that? Messenger is free why do you need a plus?