Help - Search - Members - Calendar
Full Version: Blue Screen Error
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
mokonaku
The past few days every time i close my World of Warcraft game my computer would show up a blue screen saying there's some error and it's forcing me to shutdown or restart... I have been playing the game for months and there wasn't any problem till few days ago. Also, I've tried to install norton internet security 2005, but my computer crashed mid way and the installation did not complete. Now I've installed other antivirus/firewall programs so I don't need norton anymore, so I go to Add/Remove programs section in control paneland try to remove it, however nothing happens when i press the remove button.

Here is my hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 2:36:42 AM, on 03/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
D:\HijackThis\hijackthis.exe

O1 - Hosts: 218.83.153.2 bt.greedland.net
O1 - Hosts: 218.83.153.3 tk.greedland.net
O1 - Hosts: 218.83.153.4 bt1.greedland.net
O1 - Hosts: 218.83.153.4 bbs.greedland.net
O1 - Hosts: 218.83.153.4 bbs.greedland.com
O1 - Hosts: 218.109.14.144 www.greedland.net
O1 - Hosts: 218.83.153.2 www.greedland.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\GENIUS~1\mouseElf.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [C-Media Echo Control] C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download the file(s) in D.S.Code - D:\DSLite2\dl_text.html
O8 - Extra context menu item: &Download the file(s) in D.S.Code-File - D:\DSLite2\dl_url.html
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: 下載編碼內容(&D.S.Lite) - D:\DSLite2\dl_text.html
O8 - Extra context menu item: 下載編碼檔案內容(&D.S.Lite) - D:\DSLite2\dl_url.html
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: D.S.Lite - {F8475519-8412-4D40-A46E-692D9D04DF7F} - D:\DSLite2\DSLite.exe
O9 - Extra 'Tools' menuitem: &D.S.Lite - {F8475519-8412-4D40-A46E-692D9D04DF7F} - D:\DSLite2\DSLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Spelldown - http://download.games.yahoo.com/games/clients/y/sdt1_x.cab
O16 - DPF: Yahoo! Word Racer - http://download.games.yahoo.com/games/clients/y/wt1_x.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033...all/xscan53.cab
O16 - DPF: {7BA7BCE2-D359-4407-82D9-CDF9A74C487A} (DownLoadStub Class) - http://www.hpphoto.com/downloads/DownloadPhotos.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Thanks for the help!
Bobbi Flekman
Hi mokonaku,

QUOTE
The past few days every time i close my World of Warcraft game my computer would show up a blue screen saying there's some error and it's forcing me to shutdown or restart... I have been playing the game for months and there wasn't any problem till few days ago. Also, I've tried to install norton internet security 2005, but my computer crashed mid way and the installation did not complete. Now I've installed other antivirus/firewall programs so I don't need norton anymore, so I go to Add/Remove programs section in control paneland try to remove it, however nothing happens when i press the remove button.
Can you be more specific about the error because your HijackThis log is clean.

For Norton I need more info. Launch Notepad, and copy/paste the box below into a new text file. Save it as Options.txt on your Desktop.

QUOTE
RegSearch Options File

[Search]
Norton
[Exclude]

[Options]
Filter=KVDLU


Download Registry Search and extract it. Doubleclick the icon to run and click on "Import...". Select the file you created above. Click "OK" and Registry Search will search the Registry and report what it finds. Post that here.
mokonaku
This is what the blue screen says:

QUOTE
A problem has been detected and windows has been shut down to prevent damage to your computer.

The problem seems to be caused by the following file: nv4_disp.dll

PAGE_FALT_IN_NONPAGED_AREA

If this is the first time you've seen this Stop error screen, restart your computer.  If this is a new installation, ask your hardware or software manufacturer.

If problems continue, disable or remove any newly installed hardwarer or software.  Disable BIOS memory options such as caching or shadowing.  If you need to use Safe Mode to remove or disable components, restart your computer, press F8 to select Advanced Startup Options, and then select Safe Mode.

Technical information:

*** STOP: 0x00000050 (0xE58B1DC24, 0x00000000, 0xBFA8C558, 0x00000001)

*** nv4_disp.dll - Address BFA8C558 base at BF9D3000, Datestamp 00000000

Beginning dump of physical memory
Physical memory dump complete.
Contact your system administrator or technical support group for further assistance.


and this is what i got from RegSearch:
QUOTE
REGEDIT4

; Registry Search by Bobbi Flekman
; Version: 1.0.2.1

; Results at 03/08/2005 8:55:07 PM for strings:
;  'norton'
; Strings excluded from search:
;  (None)
; Search in:
;  Registry Keys  Registry Values  Registry Data
;  HKEY_LOCAL_MACHINE  HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37611656-A7F6-4581-A1AE-9DB4E1442BB2}\InprocServer32]
@="C:\\Program Files\\Norton Internet Security\\nislcom.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\41858184422Aa74418AD17DB0285E0B1]
"ProductName"="Norton Internet Security"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6350C2CFC3850c6448A426ECAC0EF122]
"ProductName"="Norton Internet Security"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\CD5DA6254CFCa2f448248CC49CD1C6F7]
"ProductName"="Norton Internet Security"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1505EC1C-E9F6-4BF5-A4ED-6A3F74E1D6C2}\1.0\0\win32]
@="C:\\Program Files\\Norton Internet Security\\nislcom.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1505EC1C-E9F6-4BF5-A4ED-6A3F74E1D6C2}\1.0\HELPDIR]
@="C:\\Program Files\\Norton Internet Security\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\Compatibility\NortonSystemInfo]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\024EC3F90C2DE7C4FB1FFB4F5F332623]
"41858184422Aa74418AD17DB0285E0B1"="C:\\Program Files\\Norton Internet Security\\CfgWiz.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\044E7B0C1B06EC14E92B7D5969253EC2]
"CD5DA6254CFCa2f448248CC49CD1C6F7"="C:\\Program Files\\Norton Internet Security\\ccALE.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2D40DF4A1B79BC94B8BB811C21CDB9F3]
"41858184422Aa74418AD17DB0285E0B1"="C:\\Program Files\\Norton Internet Security\\ActRes.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3B2D8CCBDF636154CA11562FA1985814]
"CD5DA6254CFCa2f448248CC49CD1C6F7"="C:\\Program Files\\Norton Internet Security\\FRERules.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E63A1A0FC3E1F24BB302AC419D4841C]
"41858184422Aa74418AD17DB0285E0B1"="C:\\Program Files\\Norton Internet Security\\LRSend.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F6D8AFF8D16BA4CAC3521092CC436F]
"6350C2CFC3850c6448A426ECAC0EF122"="C:\\Program Files\\Norton Internet Security\\FREPrvcy.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\580295135EF16E045BF5AB6DB99820D8]
"CD5DA6254CFCa2f448248CC49CD1C6F7"="C:\\Program Files\\Norton Internet Security\\FRESettg.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6175647594900AC4AB89DA41EC22BDCA]
"41858184422Aa74418AD17DB0285E0B1"="C:\\Program Files\\Norton Internet Security\\SymLCUI.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\714B9864220447F45BBDCCAA49DF3D03]
"CD5DA6254CFCa2f448248CC49CD1C6F7"="C:\\Program Files\\Norton Internet Security\\TLData.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B555CBEE5D5DC34DA22C85A114E44D6]
"CD5DA6254CFCa2f448248CC49CD1C6F7"="C:\\Program Files\\Norton Internet Security\\ccRuleIO.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B508B6DAB8B7964E8AD0D371CF29B5C]
"41858184422Aa74418AD17DB0285E0B1"="C:\\Program Files\\Norton Internet Security\\DJSAlert.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A31A16C69A2D4F40B30BC92212E9182]
"CD5DA6254CFCa2f448248CC49CD1C6F7"="C:\\Program Files\\Norton Internet Security\\ccFWSetg.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9B86277100D8422439997954E0A5EF56]
"CD5DA6254CFCa2f448248CC49CD1C6F7"="C:\\Program Files\\Norton Internet Security\\HNetWiz.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D485B77AAFBE7FE4EB02F19B1C742D99]
"41858184422Aa74418AD17DB0285E0B1"="C:\\Program Files\\Norton Internet Security\\SymUIHlp.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F297450C80AA7B44CAC9B12C24BFA5C5]
"41858184422Aa74418AD17DB0285E0B1"="C:\\Program Files\\Norton Internet Security\\LtChkRes.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\41858184422Aa74418AD17DB0285E0B1\InstallProperties]
"DisplayName"="Norton Internet Security"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6350C2CFC3850c6448A426ECAC0EF122\InstallProperties]
"DisplayName"="Norton Internet Security"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CD5DA6254CFCa2f448248CC49CD1C6F7\InstallProperties]
"DisplayName"="Norton Internet Security"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SymSetupTemp.{A93C9E60-29B6-49da-BA21-F70AC6AADE20}]
"InstallLocation"="C:\\Program Files\\Norton Internet Security"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SymSetupTemp.{A93C9E60-29B6-49da-BA21-F70AC6AADE20}]
"DisplayName"="Norton Internet Security 2005"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{48185814-A224-447a-81DA-71BD20580E1B}]
"DisplayName"="Norton Internet Security"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F}]
"DisplayName"="Norton Internet Security"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FC2C0536-583C-46c0-844A-62CECAE01F22}]
"DisplayName"="Norton Internet Security"

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\CCPD\SuiteOwners\{257BBC47-1B26-432e-9F84-188603799DD3}]
"ActivationDirectory"="C:\\Program Files\\Norton Internet Security\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\InstalledApps]
"SSINSTALLDIR"="C:\\Program Files\\Norton Internet Security\\Norton AntiVirus"

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\InstalledApps]
"SS_NIS_INSTALLDIR"="C:\\Program Files\\Norton Internet Security"

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Norton AntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\SymSetup\Internet SecurityTemp]
"ShortcutPath"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Norton Internet Security\\"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup]
"Norton AntiVirus Defs"=hex(7):43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,\

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\BackupRestore\KeysNotToRestore]
"Norton AntiVirus Defs"=hex(7):48,4b,45,59,5f,4c,4f,43,41,4c,5f,4d,41,43,48,49,\

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NAVAPSVC\0000]
"DeviceDesc"="Norton AntiVirus Auto Protect Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\navapsvc]
"EventMessageFile"="C:\\PROGRA~1\\NORTON~1\\navapsvc.exe"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\navapsvc]
"DisplayName"="Norton AntiVirus Auto Protect Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\navapsvc]
"Description"="Handles Norton AntiVirus Auto-Protect events."

[HKEY_USERS\S-1-5-21-1606980848-117609710-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Norton AntiVirus]

; End Of The Log...


Thanks for the help!
mokonaku
I think I found out what caused my blue error screen.... I insalled one of the addons called RangeSwitch for my hunter character in World of Warcraft few days ago, and it is at the same time I started having blue screen error. I've just uninstalled it and I can exit the game with no problems. It was this addon that caused the problem. http://www.curse-gaming.com/mod.php?addid=662
Bobbi Flekman
Hi mokonaku,

Am I to understand that everything is clear?
mokonaku
the blue screen error is, but not the norton internet security part... still can't delete it
Bobbi Flekman
Hi mokonaku,

Ok... Before I tackle the log from RegSearch... Do you have any Norton programs that you want to keep? Because that determines what I will do.
mokonaku
nope, i don't want anymore norton programs on my computer
Bobbi Flekman
Hi mokonaku,

Launch Notepad, and copy/paste the box below into a new text file. Save it as fixme.reg and save it on your Desktop.

QUOTE
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37611656-A7F6-4581-A1AE-9DB4E1442BB2}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\41858184422Aa74418AD17DB0285E0B1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\6350C2CFC3850c6448A426ECAC0EF122]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\CD5DA6254CFCa2f448248CC49CD1C6F7]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1505EC1C-E9F6-4BF5-A4ED-6A3F74E1D6C2}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Program Files\\Norton Internet Security\\"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\024EC3F90C2DE7C4FB1FFB4F5F332623]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\044E7B0C1B06EC14E92B7D5969253EC2]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2D40DF4A1B79BC94B8BB811C21CDB9F3]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3B2D8CCBDF636154CA11562FA1985814]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E63A1A0FC3E1F24BB302AC419D4841C]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53F6D8AFF8D16BA4CAC3521092CC436F]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\580295135EF16E045BF5AB6DB99820D8]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6175647594900AC4AB89DA41EC22BDCA]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\714B9864220447F45BBDCCAA49DF3D03]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B555CBEE5D5DC34DA22C85A114E44D6]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B508B6DAB8B7964E8AD0D371CF29B5C]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A31A16C69A2D4F40B30BC92212E9182]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9B86277100D8422439997954E0A5EF56]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D485B77AAFBE7FE4EB02F19B1C742D99]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F297450C80AA7B44CAC9B12C24BFA5C5]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\41858184422Aa74418AD17DB0285E0B1]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\6350C2CFC3850c6448A426ECAC0EF122]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\CD5DA6254CFCa2f448248CC49CD1C6F7]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SymSetupTemp.{A93C9E60-29B6-49da-BA21-F70AC6AADE20}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SymSetupTemp.{A93C9E60-29B6-49da-BA21-F70AC6AADE20}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{48185814-A224-447a-81DA-71BD20580E1B}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FC2C0536-583C-46c0-844A-62CECAE01F22}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Symantec]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NAVAPSVC\0000]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\navapsvc]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\navapsvc]

[-HKEY_USERS\S-1-5-21-1606980848-117609710-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Norton AntiVirus]
Locate fixme.reg on your Desktop and double-click on it.
You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer "Yes" and wait for a message to appear similar to "Merged Successfully".

The above Registry file was written specifically for this infection on this person's computer. It is NOT to be used on another computer, as it may cause damage that could result in a format!

Afterwards you can delete the folders from you harddisc.
mokonaku
i did the steps above and it's fine now, thanks lot for the help!
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.