No pagefile and can not create one

  1. #11
    Bobarb9 is offline Newbie

    Re: No pagefile and can not create one

    Stinger did not complete - machine rebooted. SilentRunner ran (very quickly, it seems). Following is the log.

    I think I can run Spybot to completion. Would you like for me to run that again?

    Thanks for your persistence!

    Bob G.

    "Silent Runners.vbs", revision R50, http://www.silentrunners.org/
    Operating System: Windows XP SP2
    Output limited to non-default values, except where indicated by "{++}"


    Startup items buried in registry:
    ---------------------------------

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run \ {++}
    "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
    "QAGENT" = "C:\QUICKENW\QAGENT.EXE" [empty string]
    "MsnMsgr" = ""C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background" [MS]
    "MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]
    "MoneyAgent" = ""C:\Program Files\Microsoft Money\System\Money Express.exe"" [MS]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run \ {++}
    "HPDJ Taskbar Utility" = "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb 05.exe" ["HP"]
    "ccApp" = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" ["Symantec Corporation"]
    "WorksFUD" = "C:\Program Files\Microsoft Works\Wkfud.exe" ["Microsoft® Corporation"]
    "POINTER" = "point32.exe" [MS]
    "osCheck" = ""C:\Program Files\Norton AntiVirus\osCheck.exe"" ["Symantec Corporation"]
    "NvCplDaemon" = "RUNDLL32.EXE NvQTwk,NvCplDaemon initialize" [MS]
    "Microsoft Works Update Detection" = "C:\Program Files\Microsoft Works\WkDetect.exe" ["Microsoft® Corporation"]
    "Microsoft Works Portfolio" = "C:\Program Files\Microsoft Works\WksSb.exe /AllUsers" ["Microsoft® Corporation"]
    "DellTouch" = "C:\WINDOWS\DELLMMKB.EXE" ["Netropa Corp."]
    "AdaptecDirectCD" = ""C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"" ["Roxio"]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "AcroIEHlprObj Class"
    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string]
    {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" ["Safer Networking Limited"]

    HKLM\Software\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved\
    "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
    -> {HKLM...CLSID} = "Display Panning CPL Extension"
    \InProcServer32\(Default) = "deskpan.dll" [file not found]
    "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
    -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
    "{5E44E225-A408-11CF-B581-008029601108}" = "Adaptec DirectCD Shell Extension"
    -> {HKLM...CLSID} = "Adaptec DirectCD Shell Extension"
    \InProcServer32\(Default) = "C:\PROGRA~1\Adaptec\EASYCD~1\DirectCD\Shellex.dll " ["Roxio"]
    "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
    -> {HKLM...CLSID} = "Outlook File Icon Extension"
    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL" [MS]
    "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
    "{e57ce731-33e8-4c51-8354-bb4de9d215d1}" = "Universal Plug and Play Devices"
    -> {HKLM...CLSID} = "Universal Plug and Play Devices"
    \InProcServer32\(Default) = "C:\WINDOWS\system32\upnpui.dll" [MS]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks\
    <<!>> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5"
    -> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" ["Anti-Malware Development a.s."]

    HKLM\Software\Classes\*\shellex\ContextMenuHandler s\
    AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
    -> {HKLM...CLSID} = "CContextScan Object"
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]
    Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"
    -> {HKLM...CLSID} = "IEContextMenu Class"
    \InProcServer32\(Default) = "C:\PROGRA~1\NORTON~1\NavShExt.dll" ["Symantec Corporation"]

    HKLM\Software\Classes\Directory\shellex\ContextMen uHandlers\
    AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
    -> {HKLM...CLSID} = "CContextScan Object"
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]

    HKLM\Software\Classes\Folder\shellex\ContextMenuHa ndlers\
    Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"
    -> {HKLM...CLSID} = "IEContextMenu Class"
    \InProcServer32\(Default) = "C:\PROGRA~1\NORTON~1\NavShExt.dll" ["Symantec Corporation"]


    Group Policies {policy setting}:
    --------------------------------

    Note: detected settings may not have any effect.

    HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System\

    "DisableRegistryTools" = (REG_DWORD) hex:0x00000000
    {Prevent access to registry editing tools}

    HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\

    "GeneralTab" = (REG_DWORD) hex:0x00000000
    {Disable the General page}

    "SecurityTab" = (REG_DWORD) hex:0x00000000
    {Disable the Security page}

    "ConnectionsTab" = (REG_DWORD) hex:0x00000000
    {Disable the Connections page}

    "ProgramsTab" = (REG_DWORD) hex:0x00000000
    {unrecognized setting}

    "PrivacyTab" = (REG_DWORD) hex:0x00000000
    {Disable the Privacy page}

    "AdvancedTab" = (REG_DWORD) hex:0x00000000
    {Disable the Advanced page}

    "ResetWebSettings" = (REG_DWORD) hex:0x00000000
    {Disable the Reset Web Settings feature}

    "Settings" = (REG_DWORD) hex:0x00000000
    {Prevent the deletion of temporary Internet files and cookies}

    "CertifPers" = (REG_DWORD) hex:0x00000000
    {unrecognized setting}

    "CertifSite" = (REG_DWORD) hex:0x00000000
    {unrecognized setting}

    "CertifPub" = (REG_DWORD) hex:0x00000000
    {unrecognized setting}

    "Profiles" = (REG_DWORD) hex:0x00000000
    {unrecognized setting}

    "FormSuggest" = (REG_DWORD) hex:0x00000000
    {unrecognized setting}

    "Ratings" = (REG_DWORD) hex:0x00000000
    {unrecognized setting}

    "ConnWiz Admin Lock" = (REG_DWORD) hex:0x00000000
    {unrecognized setting}

    HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\

    "NoBrowserOptions" = (REG_DWORD) hex:0x00000000
    {Tools menu: Disable Internet Options... menu option}

    HKLM\Software\Microsoft\Windows\CurrentVersion\Pol icies\System\

    "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
    {Shutdown: Allow system to be shut down without having to log on}

    "undockwithoutlogon" = (REG_DWORD) hex:0x00000001
    {Devices: Allow undock without having to log on}


    Active Desktop and Wallpaper:
    -----------------------------

    Active Desktop may be disabled at this entry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellState


    Startup items in "Bob Golder" & "All Users" startup folders:
    ------------------------------------------------------------

    C:\Documents and Settings\Bob Golder\Start Menu\Programs\Startup
    "Microsoft Greetings Reminders" -> shortcut to: "C:\Program Files\Microsoft Home Publishing\MHPRMIND.EXE" [MS]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    "Billminder" -> shortcut to: "C:\QUICKENW\BILLMIND.EXE" ["Intuit"]
    "Camio Viewer 2000" -> shortcut to: "C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe -s" ["Sierra Imaging"]
    "CorrectConnect" -> shortcut to: "C:\Program Files\CConnect\CConnect.exe" ["BroadJump"]
    "Event Reminder" -> shortcut to: "C:\Program Files\PrintMaster 16\pmremind.exe" ["Broderbund Properties LLC"]
    "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office10\OSA.EXE -b -l" [MS]
    "Microsoft Works Calendar Reminders" -> shortcut to: "C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe" ["Microsoft® Corporation"]
    "Quicken Startup" -> shortcut to: "C:\QUICKENW\QWDLLS.EXE" ["Intuit"]


    Enabled Scheduled Tasks:
    ------------------------

    "Norton AntiVirus - Run Full System Scan - Bob Golder" -> launches: "C:\Program Files\Norton AntiVirus\Navw32.exe /TASK:"C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\mycomp.sca"" ["Symantec Corporation"]


    Winsock2 Service Provider DLLs:
    -------------------------------

    Namespace Service Providers

    HKLM\System\CurrentControlSet\Services\Winsock2\Pa rameters\NameSpace_Catalog5\Catalog_Entries\ {++}
    000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
    000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
    000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

    Transport Service Providers

    HKLM\System\CurrentControlSet\Services\Winsock2\Pa rameters\Protocol_Catalog9\Catalog_Entries\ {++}
    0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
    %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
    %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


    Toolbars, Explorer Bars, Extensions:
    ------------------------------------

    Toolbars

    HKLM\Software\Microsoft\Internet Explorer\Toolbar\
    "{327C2873-E90D-4C37-AA9D-10AC9BABA46C}" = "Easy-WebPrint"
    -> {HKLM...CLSID} = "Easy-WebPrint"
    \InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]

    Explorer Bars

    HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\

    HKLM\Software\Classes\CLSID\{03C1C47F-0538-4645-8372-D3109B9FC636}\(Default) = "Easy-WebPrint"
    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
    InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]

    Extensions (Tools menu items, main toolbar menu buttons)

    HKLM\Software\Microsoft\Internet Explorer\Extensions\
    {2FDEF853-0759-11D4-A92E-006097DBED37}\
    "ButtonText" = "Encarta Encyclopedia"
    "MenuText" = "Encarta Encyclopedia"
    "Script" = "C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM" [null data]

    {5DA9DE80-097A-11D4-A92E-006097DBED37}\
    "ButtonText" = "Define"
    "MenuText" = "Define"
    "Script" = "C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM" [null data]

    {E2E2DD38-D088-4134-82B7-F2BA38496583}\
    "MenuText" = "@xpsp3res.dll,-20001"
    "Exec" = "%windir%\Network Diagnostic\xpnetdiag.exe" [MS]

    {FB5F1910-F110-11D2-BB9E-00C04F795683}\
    "ButtonText" = "Messenger"
    "MenuText" = "Windows Messenger"
    "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


    Running Services (Display Name, Service Name, Path {Service DLL}):
    ------------------------------------------------------------------

    Automatic LiveUpdate Scheduler, Automatic LiveUpdate Scheduler, ""C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"" ["Symantec Corporation"]
    AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe" ["Anti-Malware Development a.s."]
    Netropa NHK Server, Nhksrv, "C:\WINDOWS\Nhksrv.exe" [null data]
    NVIDIA Driver Helper Service, NVSvc, "C:\WINDOWS\System32\nvsvc32.exe" ["NVIDIA Corporation"]
    Symantec AppCore Service, SymAppCore, ""C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe"" ["Symantec Corporation"]
    Symantec Core LC, Symantec Core LC, ""C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe"" ["Symantec Corporation"]
    Symantec Event Manager, ccEvtMgr, ""C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon" ["Symantec Corporation"]
    Symantec Lic NetConnect service, CLTNetCnService, ""C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon" ["Symantec Corporation"]
    Symantec Settings Manager, ccSetMgr, ""C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon" ["Symantec Corporation"]


    Keyboard Driver Filters:
    ------------------------

    HKLM\System\CurrentControlSet\Control\Class\{4D36E 96B-E325-11CE-BFC1-08002BE10318}\
    "UpperFilters" = <<!>> "msikbd2k" ["Netropa Corporation"]


    Print Monitors:
    ---------------

    HKLM\System\CurrentControlSet\Control\Print\Monito rs\
    Canon BJ Language Monitor iP1600\Driver = "CNMLM75.DLL" ["CANON INC."]


    ----------
    <<!>>: Suspicious data at a malware launch point.

    + This report excludes default entries except where indicated.
    + To see *everywhere* the script checks and *everything* it finds,
    launch it from a command prompt or a shortcut with the -all parameter.
    + The search for DESKTOP.INI DLL launch points on all local fixed drives
    took 72 seconds.
    ---------- (total run time: 156 seconds)

  2. #12
    Neal is offline Dedicated Member
    I think you need to look in different directions to solve your problem.

    Silentrunners was clean.

    Have you read this:

    http://support.microsoft.com/kb/315270


    suggest you go to xp help section and see if they can help you.

  3. #13
    Bobarb9 is offline Newbie
    Thanks for working with us so hard! I'll follow your suggestion and post a new thread on the XP forum. Thanks again! (Yes, I had read and tried 315270, among others. Sigh! )

  4. #14
    Neal is offline Dedicated Member
    Save 20% on AVG Internet Security 2012 Suite!
    Good luck hope you get it sorted out.

+ Reply to Thread
Page 2 of 2 FirstFirst 1 2