Runtime error 9, Subscript out of range

Discussion in 'other security issues & news' started by gcshaw, Oct 24, 2004.

Thread Status:
Not open for further replies.
  1. gcshaw

    gcshaw Registered Member

    Joined:
    Oct 24, 2004
    Posts:
    1
    I am getting the above error message everytime that I start or restart my computer. Any ideas about how to get rid of it. It seems that when it started, some webpages loaded much more slowly.
     
  2. kwinkle

    kwinkle Registered Member

    Joined:
    Nov 7, 2004
    Posts:
    7
    I also have started getting this error when XP starts - I did a through cleaning of spyware and still get the error - did you get an answer or solution?
     
  3. javacool

    javacool BrightFort Moderator

    Joined:
    Feb 10, 2002
    Posts:
    3,997
    Hi,

    Are either of you using SpywareGuard and/or SpywareBlaster? (Please specify one or the other, or both - thanks!)

    Best regards,

    -Javacool
     
  4. kwinkle

    kwinkle Registered Member

    Joined:
    Nov 7, 2004
    Posts:
    7
    No, I am not. I am using GIANT Antispyware and Norton antivirus. I have done what I believe to be a good cleaning of the system. Defrag, temp files, Virus scan, spyware scan - but nothing has helped. In my case it seemed to have started after I uninstalled (using control panel) a program called Ringtone Convertor. I had used it before when I had Win98. I now have XP. The trial version does have adware but is supossed to remove it all when you uninstall. I have tried the support on the site but no avail. I removed it because it was not compatible with my new phone. Anyway, this is definately something that is trying to start when windows starts but I can not determine what it is. It is not something I put in the start menu and Ringtone convertor did not start up with windows start. On another tech page someone said it was a problem in the registry and although I am pretty PC savvy I do not mess with the registry unless I have someone that really knows what they are doing - so I am dead in the water there. It closes right away and does not seem to affect performance and I have not found any programs (yet) that are not functioning but it is irritating enough that I am ready to do a recover and be done with it! Thanks for replying Karen
     
  5. Bubba

    Bubba Updates Team

    Joined:
    Apr 15, 2002
    Posts:
    11,271
    Hey kwinkle and gcshaw,

    Would you Please download the below item to a temp folder....uncompress the file....run the executable and copy\paste all the notepad info it displays into a new post here.

    We will then determine what further course of action\recommendation to suggest.

    This file---> StartupList :
     
  6. kwinkle

    kwinkle Registered Member

    Joined:
    Nov 7, 2004
    Posts:
    7
    Thanks SO much for helping! here is mine...

    I think I see the problems - it is:

    C:\documents and settings\karen winkle\local settings\temp\flsvTt.exe
    C:\DOCUME~1\KARENW~1\LOCALS~1\Temp\searchbarcash.exe

    Right? But the Spyware remover and Norton said they deleted these so now what?

    -------------------------------------------------------------


    StartupList report, 11/7/2004, 10:03:57 AM
    StartupList version: 1.52
    Started from : C:\Documents and Settings\Karen Winkle\Local Settings\Temp\Temporary Directory 1 for startuplist.zip\StartupList.EXE
    Detected: Windows XP SP1 (WinNT 5.01.2600)
    Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    * Using default options
    ==================================================

    Running processes:

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\MySQL\bin\mysqld-max-nt.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\documents and settings\karen winkle\local settings\temp\flsvTt.exe
    C:\DOCUME~1\KARENW~1\LOCALS~1\Temp\searchbarcash.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\GIANT Company Software\GIANT AntiSpyware\gcasServ.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\BigFix\BigFix.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\WINDOWS\System32\HPZipm12.exe
    C:\Program Files\GIANT Company Software\GIANT AntiSpyware\gcasDtServ.exe
    C:\Program Files\SpamBuster\spamBuster.exe
    C:\Program Files\Netscape\Netscape 6\Netscp.exe
    C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    C:\Program Files\Desktop Alert\desktopalert_174817.exe
    C:\Program Files\Norton AntiVirus\OPScan.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Documents and Settings\Karen Winkle\Local Settings\Temp\Temporary Directory 1 for startuplist.zip\StartupList.exe

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\Documents and Settings\Karen Winkle\Start Menu\Programs\Startup]
    Desktop Alert.lnk = C:\Program Files\Desktop Alert\desktopalert_174817.exe

    Shell folders Common Startup:
    [C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
    BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
    HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    Microsoft Works Calendar Reminders.lnk = ?

    --------------------------------------------------

    Checking Windows NT UserInit:

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    UserInit = C:\WINDOWS\system32\userinit.exe,

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    PrinTray = C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
    WorksFUD = C:\Program Files\Microsoft Works\wkfud.exe
    Microsoft Works Portfolio = C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
    Microsoft Works Update Detection = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    MoneyStartUp10.0 = "C:\Program Files\Microsoft Money\System\Activation.exe"
    NeroCheck = C:\WINDOWS\system32\NeroCheck.exe
    SunJavaUpdateSched = C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
    IgfxTray = C:\WINDOWS\System32\igfxtray.exe
    HotKeysCmds = C:\WINDOWS\System32\hkcmd.exe
    HP Component Manager = "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    HP Software Update = "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    flsvTt.exe = C:\documents and settings\karen winkle\local settings\temp\flsvTt.exe
    mswspl = C:\DOCUME~1\KARENW~1\LOCALS~1\Temp\searchbarcash.exe
    X4HcklHTr.exe = C:\documents and settings\karen winkle\local settings\temp\X4HcklHTr.exe
    7936b70cc708 = C:\WINDOWS\System32\aclui153.exe
    ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    SSC_UserPrompt = C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    gcasServ = "C:\Program Files\GIANT Company Software\GIANT AntiSpyware\gcasServ.exe"

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    ctfmon.exe = C:\WINDOWS\System32\ctfmon.exe

    --------------------------------------------------

    Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

    Shell=*INI section not found*
    SCRNSAVE.EXE=*INI section not found*
    drivers=*INI section not found*

    Shell & screensaver key from Registry:

    Shell=Explorer.exe
    SCRNSAVE.EXE=*Registry value not found*
    drivers=*Registry value not found*

    Policies Shell key:

    HKCU\..\Policies: Shell=*Registry value not found*
    HKLM\..\Policies: Shell=*Registry value not found*

    --------------------------------------------------


    Enumerating Browser Helper Objects:

    (no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
    (no name) - C:\WINDOWS\System32\prjsn.dll (file missing) - {3CA96051-C232-0EC2-D459-65557EF67A1C}
    NAV Helper - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
    (no name) - C:\Program Files\Microsoft Money\System\mnyviewer.dll - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC}

    --------------------------------------------------

    Enumerating Task Scheduler jobs:

    Symantec NetDetect.job

    --------------------------------------------------

    Enumerating Download Program Files:

    [Symantec AntiVirus scanner]
    InProcServer32 = C:\WINDOWS\Downloaded Program Files\avsniff.dll
    CODEBASE = http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab

    [Office Update Installation Engine]
    InProcServer32 = C:\WINDOWS\opuc.dll
    CODEBASE = http://office.microsoft.com/officeupdate/content/opuc.cab

    [Symantec RuFSI Utility Class]
    InProcServer32 = C:\WINDOWS\Downloaded Program Files\rufsi.dll
    CODEBASE = http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

    [Shockwave Flash Object]
    InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
    CODEBASE = https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    [Secure Delivery]
    CODEBASE = http://www.gamespot.com/KDX22/download/kdx.cab

    --------------------------------------------------

    Enumerating ShellServiceObjectDelayLoad items:

    PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
    CDBurn: C:\WINDOWS\system32\SHELL32.dll
    WebCheck: C:\WINDOWS\System32\webcheck.dll
    SysTray: C:\WINDOWS\System32\stobject.dll

    --------------------------------------------------
    End of report, 7,813 bytes
    Report generated in 0.203 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only
     
  7. Bubba

    Bubba Updates Team

    Joined:
    Apr 15, 2002
    Posts:
    11,271
    Exactly....among a couple more....which confirmed my suspicion. Unfortunately....Wilders no longer offers one-on-one system cleaning services....BUT....if you follow the below suggestions you stand a good chance of ridding yourself of this highjacker.

    My suggestion is to follow one of the following:

    1) GENERAL Virus and Trojan removal Instructions.

    2)Visit one of the below sites and follow their Forum procedures for posting a HighJackThis log. The experts there will then advise you on what action to take.

    How to remove spyware or a hijacker

    Hijackthis - Spyware, Viruses, Worms, Trojans Oh My!
     
  8. still_longhorn

    still_longhorn Registered Member

    Joined:
    Oct 3, 2004
    Posts:
    256
  9. kwinkle

    kwinkle Registered Member

    Joined:
    Nov 7, 2004
    Posts:
    7
    Thank you I will - i posted my Hijack this report on one of the pages you suggested but have not received an answer yet - I will let you know - i can see the files in the report but i just do not know enough to feel confidente in deleteing them

    Link: http://www.spywareinfoforum.com/index.php?showtopic=33750
     
    Last edited by a moderator: Nov 8, 2004
  10. Bubba

    Bubba Updates Team

    Joined:
    Apr 15, 2002
    Posts:
    11,271
    Please be patient with which ever Forum you posted to. Those great folks out there are working their behinds off attempting to clean hundreds of PC's a day from infected users.

    While it is not an exact science....it is no longer like the days of old where we simply suggested to a user change their Home page back to what they wanted. These days the scum bags of the world are almost making it so difficult that a re-format is the only choice.

    Anyway....Good Luck and have patience....They will fix your problem :)
     
  11. kwinkle

    kwinkle Registered Member

    Joined:
    Nov 7, 2004
    Posts:
    7
    Oh i know and thank you! I always wonder about folks who sit around and create these kind of programs that play havoc with someones PC - don't they have better things to do? I really do appreciate the help!
     
  12. kwinkle

    kwinkle Registered Member

    Joined:
    Nov 7, 2004
    Posts:
    7
    Well - someone answered me and I seem to have a clean PC now!!!!!! No more runtime error!!! What a relief!!!

    Thanks so much for all your help! I know you took some time from your day to work on this as well and I do appreciate it!

    Karen
     
  13. Yama

    Yama Registered Member

    Joined:
    Dec 1, 2004
    Posts:
    2
    Dear All,

    I have the same problem (got the "Runtime error 9, Subscript out of range"). Please someone help me. Below please find my startup list:

    StartupList report, 01/12/2004, 16:18:49
    StartupList version: 1.52
    Started from : C:\Documents and Settings\uhsih.JAKARTA\Desktop\Temporary\StartupList.EXE
    Detected: Windows 2000 SP4 (WinNT 5.00.2195)
    Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    * Using default options
    ==================================================

    Running processes:

    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\WINNT\System32\svchost.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\System32\igfxtray.exe
    C:\WINNT\System32\hkcmd.exe
    C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
    C:\DOCUME~1\UHSIH~1.JAK\LOCALS~1\Temp\searchbarcash.exe
    C:\documents and settings\uhsih.jakarta\local settings\temp\9tikpXxNz.exe
    C:\documents and settings\uhsih.jakarta\local settings\temp\H77SgTQh.exe
    C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
    C:\WINNT\system32\internat.exe
    C:\Documents and Settings\uhsih.JAKARTA\Application Data\w??q.exe
    C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\WINNT\system32\wisptis.exe
    C:\WINNT\System32\svchost.exe
    C:\Documents and Settings\uhsih.JAKARTA\Desktop\Temporary\StartupList.exe

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Common Startup:
    [C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
    Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
    WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

    --------------------------------------------------

    Checking Windows NT UserInit:

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    UserInit = C:\WINNT\system32\userinit.exe,

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    Synchronization Manager = mobsync.exe /logon
    IgfxTray = C:\WINNT\System32\igfxtray.exe
    HotKeysCmds = C:\WINNT\System32\hkcmd.exe
    Smapp = C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    DrvLsnr = C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
    vptray = C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    HP Software Update = C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    HPDJ Taskbar Utility = C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb08.exe
    DeviceDiscovery = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    (Default) =
    StatusClient = C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
    TomcatStartup = C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
    mswspl = C:\DOCUME~1\UHSIH~1.JAK\LOCALS~1\Temp\searchbarcash.exe
    9tikpXxNz = C:\documents and settings\uhsih.jakarta\local settings\temp\9tikpXxNz.exe
    rCPIR = C:\documents and settings\uhsih.jakarta\local settings\temp\rCPIR.exe
    ad9d969589e1 = C:\WINNT\system32\cnbjmon6.exe
    H77SgTQh = C:\documents and settings\uhsih.jakarta\local settings\temp\H77SgTQh.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    internat.exe = internat.exe
    Oacc = C:\Documents and Settings\uhsih.JAKARTA\Application Data\w??q.exe

    --------------------------------------------------

    Shell & screensaver key from C:\WINNT\SYSTEM.INI:

    Shell=*INI section not found*
    SCRNSAVE.EXE=*INI section not found*
    drivers=*INI section not found*

    Shell & screensaver key from Registry:

    Shell=Explorer.exe
    SCRNSAVE.EXE=C:\WINNT\LIVING~1.SCR
    drivers=*Registry value not found*

    Policies Shell key:

    HKCU\..\Policies: Shell=*Registry key not found*
    HKLM\..\Policies: Shell=*Registry value not found*

    --------------------------------------------------


    Enumerating Browser Helper Objects:

    (no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
    Search Help - C:\Documents and Settings\uhsih.JAKARTA\Local Settings\Temp\lq2n.dll - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841}

    --------------------------------------------------

    Enumerating Download Program Files:

    [Shockwave Flash Object]
    InProcServer32 = C:\WINNT\system32\Macromed\Flash\Flash.ocx
    CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    --------------------------------------------------

    Enumerating ShellServiceObjectDelayLoad items:

    Network.ConnectionTray: C:\WINNT\system32\NETSHELL.dll
    WebCheck: C:\WINNT\System32\webcheck.dll
    SysTray: stobject.dll

    --------------------------------------------------
    End of report, 6,152 bytes
    Report generated in 0.250 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only


    Thank you,

    Yama
     
  14. kwinkle

    kwinkle Registered Member

    Joined:
    Nov 7, 2004
    Posts:
    7
    i can see in your list that you have some of the same spyware i did - I am not a tech so can not help you but here is the link to the thread that i posted and got a solution with the help of this board and the board i was referred to - but make sure you post as well and do not try just to use the same solution as mine - it might not be what you need

    http://www.spywareinfoforum.com/index.php?showtopic=33750&hl=
     
  15. Yama

    Yama Registered Member

    Joined:
    Dec 1, 2004
    Posts:
    2
    Hi kwinkle, the URL that you gave cannot be found, the error message was:

    The error returned was:
    Sorry, the link that brought you to this page seems to be out of date or broken.

    Can you just copy and paste the information in this thread?

    Thanks,

    Yama
     
Loading...
Thread Status:
Not open for further replies.