I ran StartUp list and following are the process running:
StartupList report, 7/10/05, 1:20:20 PM
StartupList version: 1.52
Started from : C:\WINDOWS\TEMP\STARTUPLIST.EXE
Detected: Windows 98 SE (Win9x 4.10.2222A)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\WINNB32.EXE
C:\WINDOWS\SYSTEM\MSGLOOP.EXE
C:\WINDOWS\SYSTEM\MSG32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\USBMMKBD.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SOFTWARE UPDATE\HPWUSCHD2.EXE
C:\WINDOWS\SYSTEM\APIXY.EXE
C:\PROGRAM FILES\ZONEALARM FIREWALL\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\SYSTEM\UJOWKUG.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MANAGER\VIEWMGR.EXE
C:\WINDOWS\HMHRNA.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\LAVASOFT\AD-AWARE SE PLUS\AD-WATCH.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERMUTE\SPYSUBTRACT\SPYSUB.EXE
C:\WINDOWS\SYSTEM\CFGWIZ32.EXE
C:\PROGRAM FILES\YAHOO!\BROWSER\YBROWSER.EXE
C:\PROGRAM FILES\YAHOO!\BROWSER\YCOMMON.EXE
C:\PROGRAM FILES\YAHOO!\BROWSER\YBRWICON.EXE
C:\WINDOWS\BZSDLCRB.EXE
C:\WINDOWS\REGEDIT.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
C:\WINDOWS\TEMP\STARTUPLIST.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SPYSUB.EXE
rtrn.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
ccRegVfy = "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
CriticalUpdate = c:\windows\SYSTEM\wucrtupd.exe -startup
USBMMKBD = usbmmkbd.exe
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
QuickTime Task = "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
HP Software Update = C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
APIXY.EXE = C:\WINDOWS\SYSTEM\APIXY.EXE
Zone Labs Client = C:\Program Files\ZoneAlarm Firewall\ZoneAlarm\zlclient.exe
ujowkug = c:\windows\system\ujowkug.exe
cfgmgr52 = RunDLL32.EXE C:\WINDOWS\CFGMGR52.DLL,DllRun
AUNPS2 = RUNDLL32 AUNPS2.DLL,_Run@16
autoupdate = rundll32 C:\WINDOWS\SYSTEM\SUPDATE.DLL,SHStart
ViewMgr = C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
WinTask driver = C:\WINDOWS\SYSTEM\wintask.exe
exp.exe = C:\WINDOWS\SYSTEM\exp.exe
KavSvc = C:\WINDOWS\hmhrna.exe reg_run
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
ccEvtMgr = "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
Hidserv = Hidserv.exe run
SchedulingAgent = mstask.exe
TrueVector = C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
KB891711 = c:\windows\SYSTEM\KB891711\KB891711.EXE
WINNB32.EXE = C:\WINDOWS\WINNB32.EXE /s
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Taskbar Display Controls = RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
AWMON = "C:\PROGRAM FILES\LAVASOFT\AD-AWARE SE PLUS\AD-WATCH.EXE"
--------------------------------------------------
C:\WINDOWS\WININIT.BAK listing:
(Created 10/7/2005, 9:44:48)
[RENAME]
NUL=C:\WINDOWS\TEMP\TP7543.EXE
NUL=C:\WINDOWS\UNUVMZ.EXE
NUL=C:\WINDOWS\OGOZHXX.DLL
NUL=C:\WINDOWS\STARTM~1\PROGRAMS\STARTUP\RTRN.EXE
NUL=C:\WINDOWS\SYSTEM\BROWSEUI.DLL
C:\WINDOWS\SYSTEM\BROWSEUI.DLL=C:\WINDOWS\SYSTEM\SETC2E4.TMP
NUL=C:\WINDOWS\SYSTEM\IEPEERS.DLL
C:\WINDOWS\SYSTEM\IEPEERS.DLL=C:\WINDOWS\SYSTEM\SETC2F1.TMP
NUL=C:\WINDOWS\SYSTEM\MSHTML.DLL
C:\WINDOWS\SYSTEM\MSHTML.DLL=C:\WINDOWS\SYSTEM\SETC2F4.TMP
NUL=C:\WINDOWS\SYSTEM\SHDOCVW.DLL
C:\WINDOWS\SYSTEM\SHDOCVW.DLL=C:\WINDOWS\SYSTEM\SETC302.TMP
NUL=C:\WINDOWS\SYSTEM\SHLWAPI.DLL
C:\WINDOWS\SYSTEM\SHLWAPI.DLL=C:\WINDOWS\SYSTEM\SETC305.TMP
NUL=C:\WINDOWS\SYSTEM\URLMON.DLL
C:\WINDOWS\SYSTEM\URLMON.DLL=C:\WINDOWS\SYSTEM\SETC310.TMP
NUL=C:\WINDOWS\SYSTEM\WININET.DLL
C:\WINDOWS\SYSTEM\WININET.DLL=C:\WINDOWS\SYSTEM\SETC313.TMP
--------------------------------------------------
C:\AUTOEXEC.BAT listing:
C:\PROGRA~1\NORTON~1\NAVDX.EXE /startup
SET SBPCI=C:\SBPCI
path C:\WINDOWS;C:\WINDOWS\COMMAND
call c:\dosboot\sPower
SET BLASTER=A220 I7 D1 H7 P330 T6
call c:\dosboot\drivers.bat
Set tvdumpflags=10
Set tvdumpflags=10
Set tvdumpflags=10
Set tvdumpflags=10
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
(no name) - c:\program files\google\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\WINDOWS\ATLKB32.DLL - {97FD03BF-2223-5BCC-0213-A97E0706011D}
(no name) - C:\WINDOWS\SYSTEM\IPKP.DLL - {AB6EDD85-AE4D-654F-6EE9-1EAD4CDD4057}
(no name) - C:\WINDOWS\CFGMGR52.DLL - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Symantec NetDetect.job
Norton AntiVirus - Scan my computer.job
Windows Critical Update Notification.job
--------------------------------------------------
Enumerating Download Program Files:
[ForumChat]
InProcServer32 = C:\WINDOWS\SYSTEM\MSJAVA.DLL
CODEBASE = http://objects.compu...hat/RTCChat.cab
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\SWDIR.DLL
CODEBASE = http://download.macr.../swdir8d196.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macr...ash/swflash.cab
[GifViewerX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\GIFVIE~1.OCX
CODEBASE = http://www.chatbox.c.../GifViewerX.cab
[{2C38A62E-D257-40E8-8BB7-5624E38FEB0A}]
CODEBASE = http://www.britney-s...om/lsdialer.cab
[plug Class]
InProcServer32 = C:\WINDOWS\DOWNLO~1\CHARGI~1.DLL
CODEBASE = http://dist02.chargi...chargitplug.dll
[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE = http://v4.windowsupd...7873.6702893519
[iNotes Class]
InProcServer32 = C:\WINDOWS\DOWNLO~1\INOTES.DLL
CODEBASE = https://mail101a.urs....com/iNotes.cab
[YInstStarter Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YINSTHELPER1.DLL
CODEBASE = http://us.dl1.yimg.c...s/yinst0401.cab
[YahooYMailTo Class]
InProcServer32 = C:\PROGRAM FILES\YAHOO!\COMMON\YMMAPI.DLL
CODEBASE = http://download.yaho...mail/ymmapi.dll
[PhotosCtrl Class]
InProcServer32 = C:\PROGRAM FILES\YAHOO!\COMMON\YPHOTOS.DLL
CODEBASE = http://photos.yahoo....plorer1_9us.cab
[YAddBook Class]
InProcServer32 = C:\PROGRA~1\YAHOO!\COMMON\YADDBOOK.DLL
CODEBASE = http://download.yaho...alls/yab_af.cab
[WSDownloader Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\WSDOWN~1.OCX
CODEBASE = http://www.webshots....SDownloader.ocx
[RegConfig Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YREGCFG.DLL
CODEBASE = http://download.yaho...rod/yregcfg.cab
[YPCXWizard Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.1\YPCXWIZARD_DLL.DLL
CODEBASE = http://download.yaho...d2003080601.cab
[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.micr...922/wmv9VCM.CAB
[QuickTime Object]
InProcServer32 = C:\WINDOWS\SYSTEM\QTPLUGIN.OCX
CODEBASE = http://www.apple.com...ex/qtplugin.cab
[HouseCall Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\XSCAN53.OCX
CODEBASE = http://a840.g.akamai...all/xscan53.cab
[IncrediMail]
CODEBASE = http://www2.incredim...p1/imloader.cab
[Shutterfly Picture Upload Plugin]
InProcServer32 = C:\WINDOWS\DOWNLO~1\SFUPLO~1.OCX
CODEBASE = http://web1.shutterf...ds/Uploader.cab
[Wwlaunch Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\WWLAUNCH.OCX
CODEBASE = http://www.worldwinn...ed/wwlaunch.cab
[Chess Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\CHESS.OCX
CODEBASE = http://www.worldwinn...chess/chess.cab
[MetaStreamCtl Class]
InProcServer32 = C:\PROGRAM FILES\VIEWPOINT\VIEWPOINT MEDIA PLAYER\AXMETASTREAM_03000F10.DLL
CODEBASE = https://components.v...1_Arctura2.aspx
[InstallX Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\INST2.DLL
CODEBASE = http://www.20x2p.com...38deb/enter.cab
[MeadCo ScriptX]
InProcServer32 = C:\WINDOWS\SYSTEM\MCSCRIPX.DLL
CODEBASE = https://www.cmsins.com/cms/ScriptX.cab
OSD = C:\WINDOWS\Downloaded Program Files\ScriptX.osd
[cpbrkpie Control]
InProcServer32 = C:\WINDOWS\CPBRKPIE.OCX
CODEBASE = http://a19.g.akamai....23/cpbrkpie.cab
[Anonymizer Anti-Spyware Scanner]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\WEBAAS.DLL
CODEBASE = http://download.zone...ctor/WebAAS.cab
[Yahoo! Webcam Viewer Wrapper]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YVWRCTL.DLL
CODEBASE = http://chat.yahoo.com/cab/yvwrctl.cab
[ActiveX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\ACTIVEX.OCX
CODEBASE = http://www.icannnews.../ST/ActiveX.ocx
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
--------------------------------------------------
End of report, 11,474 bytes
Report generated in 1.392 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
------------------------------------------------------
Can you tell me how to proceed fixing my system?
Thank you,
Debbie