
how-to block ads
|
|
Share Topic  |
 |
|
|
|
 keith2468Premium,MVM join:2001-02-03 Winnipeg, MB | reply to madpiano
Re: sudden slow browsing - CPU flat out I think JVM is onto something. You should skip my suggestion, unless it turns out that it isn't a NAV issue. | |  sonofjayMission Accomplished - Bush May 1, 2003Premium,MVM join:2001-05-14 North Attleboro, MA kudos:1 Reviews:
·Earthlink Cable ..
| Well add me to the list of people seeing symproxysvc.exe chew up 100% CPU and cause really slow browsing.
I'm running NIS 2002 on WinXP. Anyone have any definitive information as to what the problem is or if it will be fixed?
Thanks! -S -- The war is over?? | |  jvmorrisI Am The Man Who Was Not There.Premium,MVM join:2001-04-03 Reston, VA | said by sonofjay: Well add me to the list of people seeing symproxysvc.exe chew up 100% CPU and cause really slow browsing.
I'm running NIS 2002 on WinXP. Anyone have any definitive information as to what the problem is or if it will be fixed?
See »Re: There are times in life when . . . .
If you're going to try it, it would be interesting to know what a File | Find ... on SYM*.* yields both before and after the LiveUpdate, especially files with new dates. -- Regards, Joseph V. Morris | |  sonofjayMission Accomplished - Bush May 1, 2003Premium,MVM join:2001-05-14 North Attleboro, MA kudos:1 Reviews:
·Earthlink Cable ..
| There are no LUs available. I have already applied both and the symproxysvc.exe is still chewing up 97-100% CPU.
Has anyone gotten any info from Symantec or found a way to manually correct this? Web browsing in this current state is not bearable.
Thanks! -- The war is over?? | |  jvmorrisI Am The Man Who Was Not There.Premium,MVM join:2001-04-03 Reston, VA | Okay, let me rephrase prior query:
It would be interesting to know what a File | Find ... on SYM*.* yields for File Created and File Last Modified dates, also same information for SNDMON.EXE .(There are others who've indicated that LiveUpdate found nothing waiting, so it's sort of important to know what you've got at the moment.) -- Regards, Joseph V. Morris | |  sonofjayMission Accomplished - Bush May 1, 2003Premium,MVM join:2001-05-14 North Attleboro, MA kudos:1 Reviews:
·Earthlink Cable ..
| Sorry, I misunderstood what you were asking for .
Here's what I have:
SYMDATASVC.DLL, Norton Internet Security 4.0.3.104, 63144 bytes 2002-02-18 13:06:06, SHA1: B6FA7C39FA4E72046B7D59330E60D1EC9307B860
SYMICONV.DLL, Norton Internet Security 4.0.3.104, 607912 bytes 2002-02-18 13:07:02, SHA1: 6F4B846006FDB06A6031CCFDCCB445AC4E12D7BA
SYMPROXY.DLL, Norton Internet Security 4.0.3.104, 104104 bytes 2002-02-18 13:06:12, SHA1: 5003CAB20F5707BFD929C688A80F430B3C140F22
SYMPROXYALERT.DLL, Norton Internet Security 4.0.3.104, 71336 bytes 2002-02-18 13:06:18, SHA1: 0BA248AE572E232BD8659AAEF510250D40C31246
SYMPROXYSVC.EXE, Norton Internet Security 4.0.3.104, 54952 bytes 2002-02-18 13:02:46, SHA1: 54964A03DC8A420501B764CAF0F211BC3EC025AE
SYMURL.DLL, Norton Internet Security 4.0.3.105, 124584 bytes 2002-03-01 11:20:10, SHA1: 86FD41963EB464B5CAA0C3488F645775BE301C1C
SYMWBWND.DLL, Norton Internet Security 4.0.3.104, 145064 bytes 2002-02-18 13:06:28, SHA1: FF981BFF79D53C64965251C7CEBE6FB867ECE039
Sndmon.exe location C:\Program Files\Symantec\LiveUpdate 85.1 KB (87,184 bytes) Sunday, May 23, 2004, 12:32:52 PM Friday, May 21, 2004, 2:59:46 PM -- The war is over?? | |  jvmorrisI Am The Man Who Was Not There.Premium,MVM join:2001-04-03 Reston, VA | Something is missing! Where's the famous SYMDNS.* file? (That's purportedly what started all this nonsense.) -- Regards, Joseph V. Morris | |  sonofjayMission Accomplished - Bush May 1, 2003Premium,MVM join:2001-05-14 North Attleboro, MA kudos:1 Reviews:
·Earthlink Cable ..
| Sorry, maybe there is an easier way to get the file info but I just used the NisSettings.exe and manually got the info for SNDMon.exe. Here's the info on SYMDNS.* (I only found one)
symdns.sys version 5.3.1.54 location C:\WINDOWS\system32\drivers 10.7 KB (11,008 bytes) Thursday, May 13, 2004, 9:25:08 PM Thursday, May 13, 2004, 9:25:08 PM
Sndmon.exe version 5.3.1.9 location C:\Program Files\Symantec\LiveUpdate 85.1 KB (87,184 bytes) Sunday, May 23, 2004, 12:32:52 PM Friday, May 21, 2004, 2:59:46 PM -- The war is over?? | | |
|  jvmorrisI Am The Man Who Was Not There.Premium,MVM join:2001-04-03 Reston, VA | Okay, your sndmon.exe file is the same as people who have NIS/NPF 2002 working, so that doesn't seem to be the problem (same situation in a different thread at Wilders, incidentally).
I'm sorry, I'm getting confused between what's posted in what thread, so I didn't give you sufficient instructions last time.
We are fairly certain that, whatever is causing the problem, it is some file not routinely found by NIS Settings. If you check you'll notice that all the files you listed are quite old and that's what other people who've now resolved the problem have also noted. So, it's located in some other obscure Norton or Symantec directory (of which you've probably got about half a dozen scattered around your C: drive). As a working hypothesis, the next thing is to find a file, probably SYM*.*, located somewhere on the drive that shows a Date Modified after 1 May 2004 (but presumably before 24 May 2004). The way to find these files is to use Start | File | Find ... or Start | Search | Files ... , depending on your OS, and then search for the wildcard filename SYM*.* . You should find a lot of files, some of which you've already displayed above and have date modified information well before the most recent LiveUpdates -- so you can ignore those. Specifically, we're probably looking for something with a 2004 date. If you find such files, we need to know • the FileName, • the FileSize (to the BYTE, not the number expressed in KB), • the FileCreated date, • the FileModified date, and • FileVersion information (off the second tab) for each such file. You get this by right-clicking on the file(s) listed in the search/find display and then selected Properties in the pop-up menu that then appears. You're going to have to write it down, because it doesn't copy and paste easily -- be careful, every digit is important.
We can then check what you find against what someone else has and possibly identify the source of the problem.
Unfortunately probably is the operative word here; it may turn out to be some other obscure Symantec/Norton file that does not begin with SYM; Symantec is not saying and we're still looking for the source of the problem. -- Regards, Joseph V. Morris | |  blkkatLive OnPremium join:2002-11-20 Juneau, AK | JV Morris I do not hve NIS or NPF but I am having the same problem. Panda and Nav both show me virus free and I am sitting behind a Internet Sharing Box with NAT enabled.I am also running NSW 2003.Any idea's? --
| |  jvmorrisI Am The Man Who Was Not There.Premium,MVM join:2001-04-03 Reston, VA | That one is beyond me. I would strongly recommend that you start a new thread for NSW 2003, identify the OS you're using, and detail the precise symptoms that you are experiencing.
However, are you sure that your problems are not related to the DDos Attacks currently ongoing against a number of HTML-based security forums?
I haven't even had a chance to check out »www.incidents.org so far today, so I have to admit I'm not uptodate on what may be happening out there in general. -- Regards, Joseph V. Morris | |  sonofjayMission Accomplished - Bush May 1, 2003Premium,MVM join:2001-05-14 North Attleboro, MA kudos:1 Reviews:
·Earthlink Cable ..
| Thanks jvmorris!
Do you have a link to the other forum that covers this problem? I'd like to read up on it too.
SymantecRootInstaller.exe 2.0.39.0 C:\Program Files\Symantec\LiveUpdate 197 KB (201,880 bytes) Saturday, May 17, 2003, 10:27:23 PM Friday, January 02, 2004, 3:20:24 PM
SymantecRootInstaller.log C:\Program Files\Symantec\LiveUpdate 42 bytes (42 bytes) Monday, January 19, 2004, 10:33:39 PM Monday, January 19, 2004, 10:33:39 PM
symaveng.cat C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub 7.94 KB (8,137 bytes) Tuesday, April 13, 2004, 4:00:00 AM Tuesday, April 13, 2004, 4:00:00 AM
symaveng.inf C:\Program Files\Common Files\Symantec Shared\VirusDefs\BinHub 899 bytes (899 bytes) Tuesday, April 13, 2004, 4:00:00 AM Tuesday, April 13, 2004, 4:00:00 AM
SymRedir.cat C:\WINDOWS\system32\drivers 20 bytes (20 bytes) Thursday, May 13, 2004, 9:14:24 PM Thursday, May 13, 2004, 9:14:24 PM
SymRedir.inf C:\WINDOWS\system32\drivers 1.10 KB (1,133 bytes) Thursday, May 13, 2004, 9:14:24 PM Thursday, May 13, 2004, 9:14:24 PM
symdns.sys 5.3.1.54 C:\WINDOWS\system32\drivers 10.7 KB (11,008 bytes) Thursday, May 13, 2004, 9:25:08 PM Thursday, May 13, 2004, 9:25:08 PM
symndis.sys 5.3.1.54 C:\WINDOWS\system32\drivers 50.3 KB (51,552 bytes) Thursday, May 13, 2004, 9:25:12 PM Thursday, May 13, 2004, 9:25:12 PM
SymIDSCo.sys 5.3.1.54 C:\WINDOWS\system32\drivers 166 KB (170,208 bytes) Thursday, May 13, 2004, 9:25:16 PM Thursday, May 13, 2004, 9:25:16 PM
symredrv.sys 5.3.1.54 C:\WINDOWS\system32\drivers 15.9 KB (16,288 bytes) Thursday, May 13, 2004, 9:25:16 PM Thursday, May 13, 2004, 9:25:16 PM
symtdi.sys 5.3.1.54 C:\WINDOWS\system32\drivers 257 KB (263,744 bytes) Thursday, May 13, 2004, 9:25:18 PM Thursday, May 13, 2004, 9:25:18 PM
SymRedir.dll 5.3.1.54 C:\WINDOWS\system32 113 KB (115,936 bytes) Thursday, May 13, 2004, 9:25:20 PM Thursday, May 13, 2004, 9:25:20 PM
SymNeti.dll 5.3.1.54 C:\WINDOWS\system32 493 KB (505,056 bytes) Thursday, May 13, 2004, 9:25:22 PM Thursday, May 13, 2004, 9:25:22 PM
SymFW.sys 5.3.1.55 C:\WINDOWS\system32\drivers 162 KB (166,048 bytes) Sunday, May 23, 2004, 2:23:10 PM Tuesday, May 18, 2004, 1:01:28 AM
SYMAVENG.CAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20040518.032 7.94 KB (8,137 bytes) Tuesday, May 18, 2004, 6:03:22 PM Tuesday, May 18, 2004, 4:00:00 AM
SYMAVENG.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20040518.032 900 bytes (900 bytes) Tuesday, May 18, 2004, 6:03:22 PM Tuesday, May 18, 2004, 4:00:00 AM
SYMAVENG.CAT C:\Program Files\Common Files\Symantec Shared\VirusDefs\20040519.021 7.94 KB (8,137 bytes) Sunday, May 23, 2004, 12:34:14 PM Wednesday, May 19, 2004, 4:00:00 AM
SYMAVENG.INF C:\Program Files\Common Files\Symantec Shared\VirusDefs\20040519.021 900 bytes (900 bytes) Sunday, May 23, 2004, 12:34:14 PM Wednesday, May 19, 2004, 4:00:00 AM
symaveng.cat C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmpD0.tmp 7.94 KB (8,137 bytes) Sunday, May 23, 2004, 12:34:12 PM Wednesday, May 19, 2004, 4:00:00 AM
symaveng.inf C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmpD0.tmp 900 bytes (900 bytes) Sunday, May 23, 2004, 12:34:12 PM Wednesday, May 19, 2004, 4:00:00 AM
SYMAVENG.985 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmpCF.tmp 1.39 KB (1,425 bytes) Sunday, May 23, 2004, 12:33:42 PM Wednesday, May 19, 2004, 10:53:48 AM
SYMAVENG.984 C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmpCF.tmp 104 bytes (104 bytes) Sunday, May 23, 2004, 12:33:42 PM Wednesday, May 19, 2004, 10:53:50 AM -- The war is over?? | |  sonofjayMission Accomplished - Bush May 1, 2003Premium,MVM join:2001-05-14 North Attleboro, MA kudos:1 Reviews:
·Earthlink Cable ..
1 edit |  service |
For what its worth. I am able to temporarily surf normally after I disabled the Proxy service. -- The war is over?? | |  jvmorrisI Am The Man Who Was Not There.Premium,MVM join:2001-04-03 Reston, VA | reply to sonofjay Okay, thanks, scratching down here. Randy, I could use a bit of help regarding his NAV entries. said by sonofjay: ...Do you have a link to the other forum that covers this problem? I'd like to read up on it too.
Back with those shortly, unless you already know how to access the NNTP newsgroup at grc.security. quote: SymantecRootInstaller.exe 2.0.39.0 too old. . . .
SymantecRootInstaller.log LOG File ...
symaveng.cat NAV file ...
symaveng.inf Ditto ...
Some of the following look more promising. quote: SymRedir.cat C:\WINDOWS\system32\drivers 20 bytes (20 bytes) Thursday, May 13, 2004, 9:14:24 PM Thursday, May 13, 2004, 9:14:24 PM
SymRedir.inf C:\WINDOWS\system32\drivers 1.10 KB (1,133 bytes) Thursday, May 13, 2004, 9:14:24 PM Thursday, May 13, 2004, 9:14:24 PM
symdns.sys 5.3.1.54 C:\WINDOWS\system32\drivers 10.7 KB (11,008 bytes) Thursday, May 13, 2004, 9:25:08 PM Thursday, May 13, 2004, 9:25:08 PM
symndis.sys 5.3.1.54 C:\WINDOWS\system32\drivers 50.3 KB (51,552 bytes) Thursday, May 13, 2004, 9:25:12 PM Thursday, May 13, 2004, 9:25:12 PM
SymIDSCo.sys 5.3.1.54 C:\WINDOWS\system32\drivers 166 KB (170,208 bytes) Thursday, May 13, 2004, 9:25:16 PM Thursday, May 13, 2004, 9:25:16 PM
symredrv.sys 5.3.1.54 C:\WINDOWS\system32\drivers 15.9 KB (16,288 bytes) Thursday, May 13, 2004, 9:25:16 PM Thursday, May 13, 2004, 9:25:16 PM
symtdi.sys 5.3.1.54 C:\WINDOWS\system32\drivers 257 KB (263,744 bytes) Thursday, May 13, 2004, 9:25:18 PM Thursday, May 13, 2004, 9:25:18 PM
SymRedir.dll 5.3.1.54 C:\WINDOWS\system32 113 KB (115,936 bytes) Thursday, May 13, 2004, 9:25:20 PM Thursday, May 13, 2004, 9:25:20 PM
SymNeti.dll 5.3.1.54 C:\WINDOWS\system32 493 KB (505,056 bytes) Thursday, May 13, 2004, 9:25:22 PM Thursday, May 13, 2004, 9:25:22 PM
The above are all interesting because they post-date the 12 May LiveUpdate. On the other hand, I find it curious that the DateCreated and DateModified information is identical.
Need to have someone with a working copy of NIS/NPF 2002 review those. quote: SymFW.sys 5.3.1.55 C:\WINDOWS\system32\drivers 162 KB (166,048 bytes) Sunday, May 23, 2004, 2:23:10 PM Tuesday, May 18, 2004, 1:01:28 AM
The above is very interesting; it's a newer build than I've seen anyone else reference, last modified on 18 May and it certainly looks like you got blessed with it as a consequence of the LiveUpdate released last weekend. quote: SYMAVENG.CAT NAV File...
SYMAVENG.INF ditto...
SYMAVENG.CAT ditto...
SYMAVENG.INF ditto...
symaveng.cat ditto...
symaveng.inf ditto...
SYMAVENG.985 ditto...
SYMAVENG.984 ditto...
Okay, let me go back and see what's still of interest . . . -- Regards, Joseph V. Morris | |  sonofjayMission Accomplished - Bush May 1, 2003Premium,MVM join:2001-05-14 North Attleboro, MA kudos:1 | Thanks!
Also, I just went back and confirmed that the create date and modified date were indeed the same on the files that had the two dates as being identical -- The war is over?? | |  jvmorrisI Am The Man Who Was Not There.Premium,MVM join:2001-04-03 Reston, VA | reply to sonofjay said by sonofjay: For what its worth. I am able to temporarily surf normally after I disabled the Proxy service.
Okay, that's also interesting. I've heard of that before. Need to haul someone in here (probably kicking and screaming). -- Regards, Joseph V. Morris | |  jvmorrisI Am The Man Who Was Not There.Premium,MVM join:2001-04-03 Reston, VA | reply to sonofjay Okay, back to the compressed list of other sites:
At Wilders, check the "Other Firewalls" forum after 13 May at »www.wilderssecurity.com/forumdis···php?f=31 .
At Computer Cops, check the "Symantec General" forum at »www.computercops.biz/forum82.html .
At Gladiator Security Forum, see the thread at »forum.gladiator-antivirus.com/in···4759&hl= .
There are multiple threads at Wilders and Computer Cops, only one (I believe) at Gladiator.
I have a problem in referencing threads in the NNTP newsgroups. The one most relevant is at nntp://news.grc.com/grc.security (hope I typed that correctly) and starts with a thread title of "AtGuard Vulnerable?" That's the one that lists the specific threads in the various HTML-based forums, which I really should consolidate and bring back here, also. -- Regards, Joseph V. Morris | |  jvmorrisI Am The Man Who Was Not There.Premium,MVM join:2001-04-03 Reston, VA | reply to sonofjay You might also want to start monitoring the thread at »computercops.biz/postx41991-0-0.html , especially the recent postings by Troy_McClure.
You guys show different results on SYMFW.SYS and I'm not sure why (but that may be about to change, based on his last post). -- Regards, Joseph V. Morris | |  | reply to jvmorris said by jvmorris: .. I could use a bit of help regarding his NAV entries.
My son is using his computer but I have access through the local network. I mapped his C: Drive to a network Z: drive, so I'll copy and paste some directory contents to compare. Here is the first one:
Directory of Z:\Program Files\Symantec\LiveUpdate
01/02/2004 02:20 PM 278 LUInit.ini 01/02/2004 02:20 PM 79,000 LUInit.exe 01/02/2004 02:20 PM 1,549,464 LUALL.EXE 01/02/2004 02:20 PM 152,728 S32LUWI1.DLL 01/02/2004 02:20 PM 181,400 S32LIVE1.DLL 01/02/2004 02:20 PM 99,480 S32LUIS1.DLL 01/02/2004 02:20 PM 115,864 S32LUCP1.CPL 01/02/2004 02:20 PM 1,746,072 LuComServer.EXE 01/02/2004 02:20 PM 287,896 LuComServerPS.DLL 01/02/2004 02:20 PM 21,810 README.TXT 01/02/2004 02:20 PM 283,800 LUINSDLL.DLL 02/19/1998 05:43 PM 264 RESET_NU.REG 01/02/2004 02:20 PM 205,976 ProductRegCom.DLL 05/25/2004 05:54 PM 57 ludirloc.dat 01/02/2004 02:20 PM 79,000 LSETUP.EXE 01/02/2004 02:20 PM 757 LUINFO.INF 01/02/2004 02:20 PM 111,768 NDETECT.EXE 01/02/2004 02:20 PM 259,224 AUPDATE.EXE 01/02/2004 02:20 PM 152,728 NetDetectController.DLL 01/02/2004 02:20 PM 83,096 Luupdate.exe 01/02/2004 02:20 PM 201,880 SymantecRootInstaller.exe 01/02/2004 02:21 PM 3,980,888 Lusetup.exe 01/02/2004 02:20 PM 79,000 ProductRegComPS.DLL 01/02/2004 02:20 PM 54,424 ALUNOTIFY.EXE 01/02/2004 02:20 PM 230,552 LuPreCon.DLL 01/06/2004 11:24 PM 73 LuResult.txt 08/07/2002 09:04 AM 1,202 1.Settings.Default.LiveUpdate 01/02/2004 02:20 PM 1,041,560 LUSESAIntegration.dll 01/02/2004 02:20 PM 1,399 Settings.Default.LiveUpdate 01/02/2004 02:20 PM 151,552 pegclient.DLL 01/02/2004 02:20 PM 618,496 pegcommon.DLL 01/02/2004 02:20 PM 335,292 luproviderinst.jar 01/02/2004 02:20 PM 39,489 providerInst.jar 01/06/2004 11:24 PM 42 SymantecRootInstaller.log 05/21/2004 02:59 PM 87,184 SNDMon.EXE -- "But now abide faith, hope, love, these three; but the greatest of these is love." (1 Cor. 13:13) | |  |  Contents of Z:\Program Files\Symantec |
Here is the Z:\Program Files\Symantec directory. {C: drive mapped to Z:} -- ScreenShot Above .. | |
|