Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

It Killed Panda and svchost !


  • Please log in to reply

#31
Blender

Blender

    Malware Expert

  • Member
  • PipPipPip
  • 187 posts
  • MVP
Hi

Sorry for delay. I missed my topic reply notice.

Good plan to be careful with editing registry. I kinda compare editing the registry to someone playing with my brain.

Tool we can use to help us find Norton stuff. It won't clean every trace but should show me a good portion.

Download Bobbi Flekman's RegSearch from
http://www.xs4all.nl...s/regsearch.zip

Create a folder for RegSearch on the C: drive called C:\RegSearch. You can do this by going to My Computer then double click on C: then right click and select New then Folder and name it RegSearch. Extract all the files from the zip archive into that folder.

Open the RegSearch folder and double-click the icon for RegSearch.exe to launch the program.
Copy / Paste the following line into the Search Box:

Symantec

On the next line type Norton

then hit Ok

After completion Notepad will be opened with all the found instances of the string. The resulting file is saved in the same location as RegSearch.exe.

Please post the results.
I suspect log will be kinda big so you can attach it please.

Please don't be tempted to delete what you see in the log as some results may not be related to your old Norton install.

Those ?? you see in your bootlog are normal. Not sure why the "reloads" yet.
Hopefully cleaning some leftover norton stuff helps some.

Thanks :blink:

ps. If I don't reply within say 24 hours...give the topic a 'bump'.
that *should* wake me up. :whistling:
  • 0

Advertisements


#32
steveAA

steveAA

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
Thanks a bunch Blender. I'm leavingon a trip, so I can't do anything on my computer until about this thursday night. I'll have to wait until then to respond, but here's the Regsearch listing.

Edited by steveAA, 19 February 2007 - 01:22 PM.

  • 0

#33
steveAA

steveAA

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
OPPS Here's the attachment. There's a lot of Symnatec there.

Attached Files


  • 0

#34
Blender

Blender

    Malware Expert

  • Member
  • PipPipPip
  • 187 posts
  • MVP
Hi

Hope the trip goes well.

Thanks for the regsearch log. Great! :blink:
I kinda figured there would be a few leftovers.

Warning!! This fix is intended for this user only!!. Anyone else running this fix can do irreparible damage to their system!

Scared yet? :whistling:
That was just so others wouldn't use it. OK on here because we intend to remove Norton remains.

Download this zip:

http://p-nand-q.com/.../supershell.zip

Save the file and unzip it to its own folder. It must be in its own folder to work right cus there are several files involved.
Carefull with this tool please. It is quite powerful.

Attached to my post is fixit.zip
Download it> save it> unzip it.
Once unzipped you should have fixit.reg

Close other running programs cus I will get you to reboot shortly.

Open supershell folder and double click supershell.exe.
A cmd window should open.

type: regedit and hit enter.

Registry editor will open.
Careful in here please. Regedit is now running as SYSTEM account so is much more powerful.

Click "registry" menu, then "import registry file"
Navigate to fixit.reg you saved earlier and click open

You should get a prompt asking if you want to add contents of "fixit.reg" to the registry.

Answer yes.
You should get success message.

Ok the message
Exit regedit
Type exit in the cmd window & hit enter.

Reboot.

Once restarted please run regsearch again using the same search strings as before.

If any results please post or attach the regsearch.txt.

Let me know how machine is running.

Attached Files


  • 0

#35
steveAA

steveAA

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
Hi Blender. Back after a long, long drive. Did everything as stated. I restarted several times and the eectrl error is gone. I reran the registry search and it's almost all gone. Here's what's left.

; Results at 07-02-22 00:01:59 for strings:
; 'symantec'
; Strings excluded from search:
; 'norton'
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SPBBCDrv\Parameters]
"Configuration"="C:\\Program Files\\Common Files\\Symantec Shared\\SPBBC\\2006-11-14-0c12.kc"

; End Of The Log

Everything related to this seems OK.
When I started back up once, it was as if windows was slow and several drivers didn't load. I copied the event note.
...The following boot-start or system-start driver(s) failed to load:
APPFLT
DSAFLT
eeCtrl
FNETMON
IDSFLT
SASDIFSV
SASKUTIL
ShldDrv
SMSFLT
WNMFLT

Several things were funny. Panda was partially disabled, and the desktop acted funny. I opened in safe mode and couldn't seem to find any problems and it it even acted funny in safe mode. The event viewer wouldn't display the faults for example and wouldn't close unless you closed the properties page which didn't exist! , but it said to restart,,, I did, and it seems OK now, but I think something still isn't right. BUT, we are worlds better tahn when we started! :whistling:
  • 0

#36
steveAA

steveAA

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
OPPS. The sequence where the eeCtrl showed up on the Event viewer and the drivers not loading,,, were BEFORE I finished the Norton registry fixit. Nothing has shown up since we did the registry fixit. Sorry to have maybe confused the sequence of events.
  • 0

#37
Blender

Blender

    Malware Expert

  • Member
  • PipPipPip
  • 187 posts
  • MVP
Hi

Sounds like things are getting better. That app sure worked sweet. :blink:

Looks like I missed one registry key too. No biggy. I can't get it all on the first shot now can I! :whistling:

You can delete your current fixit.reg and its zip.
I will be attaching another.

Same procedure as before.
Attached is Fix.zip.
Download it> save it> unzip it.
You should now have fix.reg.

Open supershell.exe
Type regedit in the open cmd box and hit enter.
Regedit should open.

Click "registry" menu, then "import registry file"
Navigate to fix.reg you saved earlier and click open

You should get a prompt asking if you want to add contents of "fix.reg" to the registry.

Answer yes.
You should get success message.

Ok the message
Exit regedit
Type exit in the cmd window & hit enter.

Reboot.

If this folder is present go ahead and delete it:

C:\Program Files\Common Files\Symantec Shared

Let me know if you have troubles deleting this folder.

Please run regsearch again using the same search strings as before.

If any results please post or attach the regsearch.txt.

Let me know how machine is running. Any more Panda errors?

Thanks :help:

Attached Files

  • Attached File  fix.zip   225bytes   126 downloads

  • 0

#38
steveAA

steveAA

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
WORKED like a Champ! Registry is Clean as whistle !
Panda seems to be working good now. Basically, all seems OK. THE BIG PLUS is that I'm clean and far better protected with better AV and AS systems than ever before. Several of the tools and suggestions along the way have done great and I learned like from a Professor! Great job. :whistling:
I still have some registry concerns, but we can wait to see how they work out. Registry Mechanic says I have 65 errors and one of the other free scans said about 300!
  • 0

#39
Blender

Blender

    Malware Expert

  • Member
  • PipPipPip
  • 187 posts
  • MVP
Hi

Good to hear! :whistling:

Does registry Mechanic keep a log of what it finds even though you didn't let it clean? Yeah...it must!
What about that other registry program? The one that shows 300 errors. <-- which program is this by the way?

If you can find the logs I'd like to see em. I'm willing to bet most of the "errors" are a result of "most recently used" references.

Registry Mechanic logs *should* be here:

C:\Program Files\Registry Mechanic\log

And Here:

C:\Program Files\Registry Mechanic\Data

You can zip up both the Log & Data folders and upload them to me?
Best zip em since the logs can be quite large.

Since I don't know what the free registry tool you scanned with is....I don't have a clue how to find the logs.
likely in its program file folder someplace.
Zipping up the "logs or log" folder and uploading should get me what I need.

Thanks!
  • 0

#40
steveAA

steveAA

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
Here's the Registry Mechanic Log zipped up.
I'll try to find the other program and attach it. :whistling:

The other program was RegCure and it was 645 errors not 300.
I couldn't copy a log to show what's up, but here's the listing. I suspect the empty keys may not be hurting me unless they should have something in them. I may have deleted some in the past, but I believe I was selective.

282 Empty Registry Keys
314 File path references
13 shortcuts
5 Windows start up items
30 Com/ActiveX entries.

I have notice a difference in that the system runs better. :blink: A funny part about IE though. I remember that all you had to do was click on any window and it would come to the front immediately. Now, after everything, you have to click on that window, and go back to click on the existing open window before the one you wanted opens? After the first time of clicking, then the windows will change as soon as you click, but they don't the first time. ???? I can live with it, but I did notice that difference and thought I'd mention it.

Attached Files


Edited by steveAA, 22 February 2007 - 08:48 PM.

  • 0

Advertisements


#41
Blender

Blender

    Malware Expert

  • Member
  • PipPipPip
  • 187 posts
  • MVP
Hi

Thanks for the log.

I do have to say though that RegCure scares me.
I am not one for registry cleaners simply because I have seen first hand the damage many can do.
I did try a couple well trusted ones a few years back. Installed the program, ran it as most people would do and let it "fix" what it found.
One machine I ended up formatting.
The other System restore got me back up and running.
I have also had to fix many computers that have had reg cleaners run through them...
Some turned out OK, others not so well.

Just reading some comments people have had in regards to RegCure.
http://forums.techgu...ed-regcure.html
http://www.pcreview....ead-2544189.php
http://forums.cnet.c...m...09&start=60
http://ph.answers.ya...12072920AA79qAF

Seems to be alot of lack of support, things flagged not being removed/fixed, unable to get refunds, etc...

In short I dont think I would let that program touch my computer with a 10 foot pole.
Call me paranoid but I dont like programs messing in my registry.

Registry Mechanic log...

Did you uninstall CCleaner? (crap cleaner)
Quicktime?
Eazy CD Creator 5?

Since I don't run registry mechanic...I'm just trying to get what these entries all mean.
They are showing as references pointing to no longer existing programs?

The MRU items are safe to fix. Like items under:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU

Program I have used that will totally back up the registry and also optimize it if you want.

http://www.larsheder...nline.de/erunt/

It is free.

DEtailed info:
http://www.larsheder...erunt/erunt.txt

Optimizer detaild info:
http://www.larsheder...nt/ntregopt.txt

I have not used the Optimize myself so I don't know how much difference it does make. I just set erunt up to do its regular backups.

-------------------------------

I had to install RegCure. I was curious...

Wow....... :whistling:

Once I did the scan and hit the "results" button at left...
I could expand the results.

Alot of the "empty registry keys" referenced were put there by Windows itself and several other programs.
Just nothing was written to those keys yet because I have not set up the referenced "features" in windows or referenced programs.
Unless it is pointing to a program you can positively ID as one you removed....these are best left alone.
If its empty--its doing nothing anyway but it is there when the program or OS that put it there needs it.
Someone purchasing this program and letting all these keys be removed.....could end up with a broken windows.

Alot of the "file path references" are pulled from items from temp files/folders used at one time or another when setting up programs, windows updates, etc.
Best left alone. Problem I see here is they are all by default checked to fix. Even though the program itself says most are better left alone. See above.

"Program shortcuts"...
Most of mine in list were stuff in my "recent" folder that pointed to stuff that no longer existed.
A couple broken shortcuts I knew I had.
Most of these are Ok to fix.

COM/ActiveX references...
I only had one but didn't investigate what it was. Having 30...
Problem here I see is it does not actually show you the file that is referenced by the AppID or CLSID that it is flagging.
Unless you searched these yourself....you dunno what it wants to remove.

Startup references...
Are yours pointing to programs you no longer have?
  • 0

#42
steveAA

steveAA

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
I read the posts on RegCure also and I agree,,, so I've uninstalled it. Along the posts though, "Advanced Windows Care" was recommended. I downloaded it and I really likethe way it looks and works because it looks at many of the things that concerned me. IE settings, system settings , etc. The program looks pretty good. It does show a gazillion registry errors, but I've elected to not get let it mess with it for now. I did let it "Fix" some of the Windows settings and I'll have to see how they work.
I've ERUNT and have used it for the restore points as you had said. I had downloaded it very early in our discussion as a life preserver.
CCleaner I reinstalled after seeing the hiccup. I had moved it to a different file and I think the links didn't follow.
I did uninstall Quicktime and CD Creator but there's a ton of registry errors left over from them that I need to address. Can you help with that?

By the way, do you know how to view those AOL E Mail media files that come through as Winmail.dat ? Windows media can't play them, and I thought it was because the were sent through Outlook to AOL and changing to HTML or Text format would do it. Frankly, I've read about it and made several setting changes and have yet to get it to work.

Edited by steveAA, 23 February 2007 - 01:45 PM.

  • 0

#43
Blender

Blender

    Malware Expert

  • Member
  • PipPipPip
  • 187 posts
  • MVP
Hi

I didn't have a chancwe to look at Windows Advanced Care but it does seem to be listed on several trusted sites.
As with any new program do make sure to back up before letting it do too much.

winmail.dat....

Couple documents on this one. Seems you are right how they are created. :whistling:

http://www.gpc.edu/~...rce/winmail.htm

Program they mention to open these things..:

http://www.biblet.freeserve.co.uk/

I'm not sure if you can download another copy and use it after this one expires or they mean you need to buy it after.
For 10 bucks though if it works as expected....pretty cheap.
Otherwise I think you would need to keep uninstalling/re-installing each time it expires.

----------------------

Quicktime & Easy CD Creator...

Quicktime shouldn't be hard but it will take me some looking around on Easy CD.
There are a couple registry entries if missed will end up messing with how windows loads drivers for your CD Rom drive(s) and it won't show up in "my computer".

Quicktime...

Lets search for it's references.

Start regsearch you downloaded earlier.
On first line type quicktime

On the second line type itunes

Hit OK

When search is done please post the results or attach the log.

Thanks :blink:

I'll do some research on Easy CD before we tackle that one.
  • 0

#44
Blender

Blender

    Malware Expert

  • Member
  • PipPipPip
  • 187 posts
  • MVP
Me again....

If you have not done the first regsearch already...

You can add these 2 strings to the 3rd & 4th line respectively:

Adeptec
Roxio

So in short....

Open regsearch

Line 1 type: Quicktime
Line 2 type: itunes
Line 3 type: Adaptec
Line 4 type: Roxio

Hit OK...
Let search finish...
Attach results of regsearch.txt that is located in regsearch folder.

Thanks :whistling:
  • 0

#45
steveAA

steveAA

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
Here's the log,,,, LOT'S of stuff!

Attached Files


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP