republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
page: 1 · 2 · 3
AuthorAll Replies


keith2468
Premium,MVM
join:2001-02-03
Winnipeg, MB

reply to madpiano

Re: sudden slow browsing - CPU flat out

I think JVM is onto something. You should skip my suggestion, unless it turns out that it isn't a NAV issue.


sonofjay
Mission Accomplished - Bush May 1, 2003
Premium,MVM
join:2001-05-14
North Attleboro, MA
kudos:1
Reviews:
·Earthlink Cable ..

Well add me to the list of people seeing symproxysvc.exe chew up 100% CPU and cause really slow browsing.

I'm running NIS 2002 on WinXP. Anyone have any definitive information as to what the problem is or if it will be fixed?

Thanks!
-S
--
The war is over??



jvmorris
I Am The Man Who Was Not There.
Premium,MVM
join:2001-04-03
Reston, VA

said by sonofjay:
Well add me to the list of people seeing symproxysvc.exe chew up 100% CPU and cause really slow browsing.

I'm running NIS 2002 on WinXP. Anyone have any definitive information as to what the problem is or if it will be fixed?
See »Re: There are times in life when . . . .

If you're going to try it, it would be interesting to know what a File | Find ... on SYM*.* yields both before and after the LiveUpdate, especially files with new dates.
--
Regards, Joseph V. Morris


sonofjay
Mission Accomplished - Bush May 1, 2003
Premium,MVM
join:2001-05-14
North Attleboro, MA
kudos:1
Reviews:
·Earthlink Cable ..

There are no LUs available. I have already applied both and the symproxysvc.exe is still chewing up 97-100% CPU.

Has anyone gotten any info from Symantec or found a way to manually correct this? Web browsing in this current state is not bearable.

Thanks!
--
The war is over??



jvmorris
I Am The Man Who Was Not There.
Premium,MVM
join:2001-04-03
Reston, VA

Okay, let me rephrase prior query:

It would be interesting to know what a File | Find ... on SYM*.* yields for File Created and File Last Modified dates, also same information for SNDMON.EXE .(There are others who've indicated that LiveUpdate found nothing waiting, so it's sort of important to know what you've got at the moment.)
--
Regards, Joseph V. Morris



sonofjay
Mission Accomplished - Bush May 1, 2003
Premium,MVM
join:2001-05-14
North Attleboro, MA
kudos:1
Reviews:
·Earthlink Cable ..

Sorry, I misunderstood what you were asking for .

Here's what I have:

SYMDATASVC.DLL, Norton Internet Security 4.0.3.104, 63144 bytes
2002-02-18 13:06:06, SHA1: B6FA7C39FA4E72046B7D59330E60D1EC9307B860

SYMICONV.DLL, Norton Internet Security 4.0.3.104, 607912 bytes
2002-02-18 13:07:02, SHA1: 6F4B846006FDB06A6031CCFDCCB445AC4E12D7BA

SYMPROXY.DLL, Norton Internet Security 4.0.3.104, 104104 bytes
2002-02-18 13:06:12, SHA1: 5003CAB20F5707BFD929C688A80F430B3C140F22

SYMPROXYALERT.DLL, Norton Internet Security 4.0.3.104, 71336 bytes
2002-02-18 13:06:18, SHA1: 0BA248AE572E232BD8659AAEF510250D40C31246

SYMPROXYSVC.EXE, Norton Internet Security 4.0.3.104, 54952 bytes
2002-02-18 13:02:46, SHA1: 54964A03DC8A420501B764CAF0F211BC3EC025AE

SYMURL.DLL, Norton Internet Security 4.0.3.105, 124584 bytes
2002-03-01 11:20:10, SHA1: 86FD41963EB464B5CAA0C3488F645775BE301C1C

SYMWBWND.DLL, Norton Internet Security 4.0.3.104, 145064 bytes
2002-02-18 13:06:28, SHA1: FF981BFF79D53C64965251C7CEBE6FB867ECE039

Sndmon.exe
location C:\Program Files\Symantec\LiveUpdate
85.1 KB (87,184 bytes)
Sunday, May 23, 2004, 12:32:52 PM
Friday, May 21, 2004, 2:59:46 PM
--
The war is over??



jvmorris
I Am The Man Who Was Not There.
Premium,MVM
join:2001-04-03
Reston, VA

Something is missing! Where's the famous SYMDNS.* file? (That's purportedly what started all this nonsense.)
--
Regards, Joseph V. Morris



sonofjay
Mission Accomplished - Bush May 1, 2003
Premium,MVM
join:2001-05-14
North Attleboro, MA
kudos:1
Reviews:
·Earthlink Cable ..

Sorry, maybe there is an easier way to get the file info but I just used the NisSettings.exe and manually got the info for SNDMon.exe. Here's the info on SYMDNS.* (I only found one)

symdns.sys
version 5.3.1.54
location C:\WINDOWS\system32\drivers
10.7 KB (11,008 bytes)
Thursday, May 13, 2004, 9:25:08 PM
Thursday, May 13, 2004, 9:25:08 PM

Sndmon.exe
version 5.3.1.9
location C:\Program Files\Symantec\LiveUpdate
85.1 KB (87,184 bytes)
Sunday, May 23, 2004, 12:32:52 PM
Friday, May 21, 2004, 2:59:46 PM
--
The war is over??



jvmorris
I Am The Man Who Was Not There.
Premium,MVM
join:2001-04-03
Reston, VA

Okay, your sndmon.exe file is the same as people who have NIS/NPF 2002 working, so that doesn't seem to be the problem (same situation in a different thread at Wilders, incidentally).

I'm sorry, I'm getting confused between what's posted in what thread, so I didn't give you sufficient instructions last time.

We are fairly certain that, whatever is causing the problem, it is some file not routinely found by NIS Settings. If you check you'll notice that all the files you listed are quite old and that's what other people who've now resolved the problem have also noted. So, it's located in some other obscure Norton or Symantec directory (of which you've probably got about half a dozen scattered around your C: drive). As a working hypothesis, the next thing is to find a file, probably SYM*.*, located somewhere on the drive that shows a Date Modified after 1 May 2004 (but presumably before 24 May 2004). The way to find these files is to use Start | File | Find ... or Start | Search | Files ... , depending on your OS, and then search for the wildcard filename SYM*.* . You should find a lot of files, some of which you've already displayed above and have date modified information well before the most recent LiveUpdates -- so you can ignore those. Specifically, we're probably looking for something with a 2004 date. If you find such files, we need to know • the FileName, • the FileSize (to the BYTE, not the number expressed in KB), • the FileCreated date, • the FileModified date, and • FileVersion information (off the second tab) for each such file. You get this by right-clicking on the file(s) listed in the search/find display and then selected Properties in the pop-up menu that then appears. You're going to have to write it down, because it doesn't copy and paste easily -- be careful, every digit is important.

We can then check what you find against what someone else has and possibly identify the source of the problem.

Unfortunately probably is the operative word here; it may turn out to be some other obscure Symantec/Norton file that does not begin with SYM; Symantec is not saying and we're still looking for the source of the problem.
--
Regards, Joseph V. Morris



blkkat
Live On
Premium
join:2002-11-20
Juneau, AK

JV Morris I do not hve NIS or NPF but I am having the same problem. Panda and Nav both show me virus free and I am sitting behind a Internet Sharing Box with NAT enabled.I am also running NSW 2003.Any idea's?
--



jvmorris
I Am The Man Who Was Not There.
Premium,MVM
join:2001-04-03
Reston, VA

That one is beyond me. I would strongly recommend that you start a new thread for NSW 2003, identify the OS you're using, and detail the precise symptoms that you are experiencing.

However, are you sure that your problems are not related to the DDos Attacks currently ongoing against a number of HTML-based security forums?

I haven't even had a chance to check out »www.incidents.org so far today, so I have to admit I'm not uptodate on what may be happening out there in general.
--
Regards, Joseph V. Morris



sonofjay
Mission Accomplished - Bush May 1, 2003
Premium,MVM
join:2001-05-14
North Attleboro, MA
kudos:1
Reviews:
·Earthlink Cable ..

Thanks jvmorris!

Do you have a link to the other forum that covers this problem? I'd like to read up on it too.

SymantecRootInstaller.exe
2.0.39.0
C:\Program Files\Symantec\LiveUpdate
197 KB (201,880 bytes)
Saturday, May 17, 2003, 10:27:23 PM
Friday, January 02, 2004, 3:20:24 PM

SymantecRootInstaller.log
C:\Program Files\Symantec\LiveUpdate
42 bytes (42 bytes)
Monday, January 19, 2004, 10:33:39 PM
Monday, January 19, 2004, 10:33:39 PM

symaveng.cat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub
7.94 KB (8,137 bytes)
Tuesday, April 13, 2004, 4:00:00 AM
Tuesday, April 13, 2004, 4:00:00 AM

symaveng.inf
C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub
899 bytes (899 bytes)
Tuesday, April 13, 2004, 4:00:00 AM
Tuesday, April 13, 2004, 4:00:00 AM

SymRedir.cat
C:\WINDOWS\system32\drivers
20 bytes (20 bytes)
Thursday, May 13, 2004, 9:14:24 PM
Thursday, May 13, 2004, 9:14:24 PM

SymRedir.inf
C:\WINDOWS\system32\drivers
1.10 KB (1,133 bytes)
Thursday, May 13, 2004, 9:14:24 PM
Thursday, May 13, 2004, 9:14:24 PM

symdns.sys
5.3.1.54
C:\WINDOWS\system32\drivers
10.7 KB (11,008 bytes)
Thursday, May 13, 2004, 9:25:08 PM
Thursday, May 13, 2004, 9:25:08 PM

symndis.sys
5.3.1.54
C:\WINDOWS\system32\drivers
50.3 KB (51,552 bytes)
Thursday, May 13, 2004, 9:25:12 PM
Thursday, May 13, 2004, 9:25:12 PM

SymIDSCo.sys
5.3.1.54
C:\WINDOWS\system32\drivers
166 KB (170,208 bytes)
Thursday, May 13, 2004, 9:25:16 PM
Thursday, May 13, 2004, 9:25:16 PM

symredrv.sys
5.3.1.54
C:\WINDOWS\system32\drivers
15.9 KB (16,288 bytes)
Thursday, May 13, 2004, 9:25:16 PM
Thursday, May 13, 2004, 9:25:16 PM

symtdi.sys
5.3.1.54
C:\WINDOWS\system32\drivers
257 KB (263,744 bytes)
Thursday, May 13, 2004, 9:25:18 PM
Thursday, May 13, 2004, 9:25:18 PM

SymRedir.dll
5.3.1.54
C:\WINDOWS\system32
113 KB (115,936 bytes)
Thursday, May 13, 2004, 9:25:20 PM
Thursday, May 13, 2004, 9:25:20 PM

SymNeti.dll
5.3.1.54
C:\WINDOWS\system32
493 KB (505,056 bytes)
Thursday, May 13, 2004, 9:25:22 PM
Thursday, May 13, 2004, 9:25:22 PM

SymFW.sys
5.3.1.55
C:\WINDOWS\system32\drivers
162 KB (166,048 bytes)
Sunday, May 23, 2004, 2:23:10 PM
Tuesday, May 18, 2004, 1:01:28 AM

SYMAVENG.CAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20040518.032
7.94 KB (8,137 bytes)
Tuesday, May 18, 2004, 6:03:22 PM
Tuesday, May 18, 2004, 4:00:00 AM

SYMAVENG.INF
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20040518.032
900 bytes (900 bytes)
Tuesday, May 18, 2004, 6:03:22 PM
Tuesday, May 18, 2004, 4:00:00 AM

SYMAVENG.CAT
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20040519.021
7.94 KB (8,137 bytes)
Sunday, May 23, 2004, 12:34:14 PM
Wednesday, May 19, 2004, 4:00:00 AM

SYMAVENG.INF
C:\Program Files\Common Files\Symantec Shared\VirusDefs\20040519.021
900 bytes (900 bytes)
Sunday, May 23, 2004, 12:34:14 PM
Wednesday, May 19, 2004, 4:00:00 AM

symaveng.cat
C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmpD0.tmp
7.94 KB (8,137 bytes)
Sunday, May 23, 2004, 12:34:12 PM
Wednesday, May 19, 2004, 4:00:00 AM

symaveng.inf
C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmpD0.tmp
900 bytes (900 bytes)
Sunday, May 23, 2004, 12:34:12 PM
Wednesday, May 19, 2004, 4:00:00 AM

SYMAVENG.985
C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmpCF.tmp
1.39 KB (1,425 bytes)
Sunday, May 23, 2004, 12:33:42 PM
Wednesday, May 19, 2004, 10:53:48 AM

SYMAVENG.984
C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmpCF.tmp
104 bytes (104 bytes)
Sunday, May 23, 2004, 12:33:42 PM
Wednesday, May 19, 2004, 10:53:50 AM
--
The war is over??



sonofjay
Mission Accomplished - Bush May 1, 2003
Premium,MVM
join:2001-05-14
North Attleboro, MA
kudos:1
Reviews:
·Earthlink Cable ..

1 edit


service
For what its worth. I am able to temporarily surf normally after I disabled the Proxy service.
--
The war is over??


jvmorris
I Am The Man Who Was Not There.
Premium,MVM
join:2001-04-03
Reston, VA

reply to sonofjay
Okay, thanks, scratching down here.
Randy, I could use a bit of help regarding his NAV entries.

said by sonofjay:
...Do you have a link to the other forum that covers this problem? I'd like to read up on it too.
Back with those shortly, unless you already know how to access the NNTP newsgroup at grc.security.
quote:
SymantecRootInstaller.exe 2.0.39.0 too old. . . .
SymantecRootInstaller.log LOG File ...
symaveng.cat NAV file ...
symaveng.inf Ditto ...
Some of the following look more promising.
quote:
SymRedir.cat
C:\WINDOWS\system32\drivers
20 bytes (20 bytes)
Thursday, May 13, 2004, 9:14:24 PM
Thursday, May 13, 2004, 9:14:24 PM

SymRedir.inf
C:\WINDOWS\system32\drivers
1.10 KB (1,133 bytes)
Thursday, May 13, 2004, 9:14:24 PM
Thursday, May 13, 2004, 9:14:24 PM

symdns.sys
5.3.1.54
C:\WINDOWS\system32\drivers
10.7 KB (11,008 bytes)
Thursday, May 13, 2004, 9:25:08 PM
Thursday, May 13, 2004, 9:25:08 PM

symndis.sys
5.3.1.54
C:\WINDOWS\system32\drivers
50.3 KB (51,552 bytes)
Thursday, May 13, 2004, 9:25:12 PM
Thursday, May 13, 2004, 9:25:12 PM

SymIDSCo.sys
5.3.1.54
C:\WINDOWS\system32\drivers
166 KB (170,208 bytes)
Thursday, May 13, 2004, 9:25:16 PM
Thursday, May 13, 2004, 9:25:16 PM

symredrv.sys
5.3.1.54
C:\WINDOWS\system32\drivers
15.9 KB (16,288 bytes)
Thursday, May 13, 2004, 9:25:16 PM
Thursday, May 13, 2004, 9:25:16 PM

symtdi.sys
5.3.1.54
C:\WINDOWS\system32\drivers
257 KB (263,744 bytes)
Thursday, May 13, 2004, 9:25:18 PM
Thursday, May 13, 2004, 9:25:18 PM

SymRedir.dll
5.3.1.54
C:\WINDOWS\system32
113 KB (115,936 bytes)
Thursday, May 13, 2004, 9:25:20 PM
Thursday, May 13, 2004, 9:25:20 PM

SymNeti.dll
5.3.1.54
C:\WINDOWS\system32
493 KB (505,056 bytes)
Thursday, May 13, 2004, 9:25:22 PM
Thursday, May 13, 2004, 9:25:22 PM
The above are all interesting because they post-date the 12 May LiveUpdate. On the other hand, I find it curious that the DateCreated and DateModified information is identical.

Need to have someone with a working copy of NIS/NPF 2002 review those.
quote:
SymFW.sys
5.3.1.55
C:\WINDOWS\system32\drivers
162 KB (166,048 bytes)
Sunday, May 23, 2004, 2:23:10 PM
Tuesday, May 18, 2004, 1:01:28 AM
The above is very interesting; it's a newer build than I've seen anyone else reference, last modified on 18 May and it certainly looks like you got blessed with it as a consequence of the LiveUpdate released last weekend.
quote:
SYMAVENG.CAT NAV File...
SYMAVENG.INF ditto...
SYMAVENG.CAT ditto...
SYMAVENG.INF ditto...
symaveng.cat ditto...
symaveng.inf ditto...
SYMAVENG.985 ditto...
SYMAVENG.984 ditto...

Okay, let me go back and see what's still of interest . . .
--
Regards, Joseph V. Morris


sonofjay
Mission Accomplished - Bush May 1, 2003
Premium,MVM
join:2001-05-14
North Attleboro, MA
kudos:1

Thanks!

Also, I just went back and confirmed that the create date and modified date were indeed the same on the files that had the two dates as being identical
--
The war is over??



jvmorris
I Am The Man Who Was Not There.
Premium,MVM
join:2001-04-03
Reston, VA

reply to sonofjay

said by sonofjay:
For what its worth. I am able to temporarily surf normally after I disabled the Proxy service.
Okay, that's also interesting. I've heard of that before. Need to haul someone in here (probably kicking and screaming).
--
Regards, Joseph V. Morris


jvmorris
I Am The Man Who Was Not There.
Premium,MVM
join:2001-04-03
Reston, VA

reply to sonofjay
Okay, back to the compressed list of other sites:

At Wilders, check the "Other Firewalls" forum after 13 May at »www.wilderssecurity.com/forumdis···php?f=31 .

At Computer Cops, check the "Symantec General" forum at »www.computercops.biz/forum82.html .

At Gladiator Security Forum, see the thread at »forum.gladiator-antivirus.com/in···4759&hl= .

There are multiple threads at Wilders and Computer Cops, only one (I believe) at Gladiator.

I have a problem in referencing threads in the NNTP newsgroups. The one most relevant is at nntp://news.grc.com/grc.security (hope I typed that correctly) and starts with a thread title of "AtGuard Vulnerable?" That's the one that lists the specific threads in the various HTML-based forums, which I really should consolidate and bring back here, also.
--
Regards, Joseph V. Morris



jvmorris
I Am The Man Who Was Not There.
Premium,MVM
join:2001-04-03
Reston, VA

reply to sonofjay
You might also want to start monitoring the thread at »computercops.biz/postx41991-0-0.html ,
especially the recent postings by Troy_McClure.

You guys show different results on SYMFW.SYS and I'm not sure why (but that may be about to change, based on his last post).
--
Regards, Joseph V. Morris



Randy Bell
Premium
join:2002-02-24
Santa Clara, CA

reply to jvmorris

said by jvmorris:
.. I could use a bit of help regarding his NAV entries.
My son is using his computer but I have access through the local network. I mapped his C: Drive to a network Z: drive, so I'll copy and paste some directory contents to compare. Here is the first one:

Directory of Z:\Program Files\Symantec\LiveUpdate

01/02/2004 02:20 PM 278 LUInit.ini
01/02/2004 02:20 PM 79,000 LUInit.exe
01/02/2004 02:20 PM 1,549,464 LUALL.EXE
01/02/2004 02:20 PM 152,728 S32LUWI1.DLL
01/02/2004 02:20 PM 181,400 S32LIVE1.DLL
01/02/2004 02:20 PM 99,480 S32LUIS1.DLL
01/02/2004 02:20 PM 115,864 S32LUCP1.CPL
01/02/2004 02:20 PM 1,746,072 LuComServer.EXE
01/02/2004 02:20 PM 287,896 LuComServerPS.DLL
01/02/2004 02:20 PM 21,810 README.TXT
01/02/2004 02:20 PM 283,800 LUINSDLL.DLL
02/19/1998 05:43 PM 264 RESET_NU.REG
01/02/2004 02:20 PM 205,976 ProductRegCom.DLL
05/25/2004 05:54 PM 57 ludirloc.dat
01/02/2004 02:20 PM 79,000 LSETUP.EXE
01/02/2004 02:20 PM 757 LUINFO.INF
01/02/2004 02:20 PM 111,768 NDETECT.EXE
01/02/2004 02:20 PM 259,224 AUPDATE.EXE
01/02/2004 02:20 PM 152,728 NetDetectController.DLL
01/02/2004 02:20 PM 83,096 Luupdate.exe
01/02/2004 02:20 PM 201,880 SymantecRootInstaller.exe
01/02/2004 02:21 PM 3,980,888 Lusetup.exe
01/02/2004 02:20 PM 79,000 ProductRegComPS.DLL
01/02/2004 02:20 PM 54,424 ALUNOTIFY.EXE
01/02/2004 02:20 PM 230,552 LuPreCon.DLL
01/06/2004 11:24 PM 73 LuResult.txt
08/07/2002 09:04 AM 1,202 1.Settings.Default.LiveUpdate
01/02/2004 02:20 PM 1,041,560 LUSESAIntegration.dll
01/02/2004 02:20 PM 1,399 Settings.Default.LiveUpdate
01/02/2004 02:20 PM 151,552 pegclient.DLL
01/02/2004 02:20 PM 618,496 pegcommon.DLL
01/02/2004 02:20 PM 335,292 luproviderinst.jar
01/02/2004 02:20 PM 39,489 providerInst.jar
01/06/2004 11:24 PM 42 SymantecRootInstaller.log
05/21/2004 02:59 PM 87,184 SNDMon.EXE
--
"But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13)


Randy Bell
Premium
join:2002-02-24
Santa Clara, CA


Contents of Z:\Program Files\Symantec
Here is the Z:\Program Files\Symantec directory. {C: drive mapped to Z:} -- ScreenShot Above ..

Sunday, 27-May 08:00:24 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics