This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

In over my head

42 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Okay I got all the CD's that came with this unit and plus those that came with other machines just in case. I assume that the one I need to use is the COMPAQ - Operating System CD W2K with SP-1 (Only for use with COMPAQ Restore CD) N.B. There is also a COMPAQ Restore CD - Copaq Deskpro EXS Series Version 1.4 (Requires the Compaq Operating System CD) I apologize for getting such a late start but either all the computer work, or that peach flavored moonshine has given me one hell of a headache. And the System keep rebooting.
So I am running the the Windows File Protection Scan… ..and it got me to wondering what will the result be since the system and therefore the restore disk shipped WIN2K SP-1 and now on WIN2K SP-4 Should be fun finding out. Sure that Chinese gentleman "blessed me " to live in interesting times… but how was I to know she was his niece.
5th try today to get the scan to run… Keeps locking up. Currently trying to run it in safe mode… Because standard seems to unstable, thinking that it won't run in safe mode though… Hmmm May try safe mode with networking? Not sure what day it is, still plenty of water and mangoes, though powder for my fowling piece and pistol is becoming scarce.
Alright Amybe this will stay up long enough to post…
Logfile of HijackThis v1.99.1
Scan saved at 1:01:00 PM, on 2/14/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
C:\Program Files\Maxtor\OneTouch\utils\mspm.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/slv/ycheck/as/*http://…/search/ie.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: del.icio.us Toolbar Helper - {7AA07AE6-01EF-44EC-93CA-9D7CD41CCDB6} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: del.icio.us - {981FE6A8-260C-4930-960F-C3BC82746CB0} - C:\Program Files\del.icio.us\Internet Explorer Buttons\dlcsIE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
O4 - HKLM\..\Run: [mspm] C:\Program Files\Maxtor\OneTouch\utils\mspm.exe
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {352797A0-EFD0-4FA6-B229-145120EA4B8A} (Walt Disney Internet Group Hardware Control) - https://disneyblast.go.com/v3/setup/activex…wareControl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.yahoo.com/…/yiebio4028.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1904A8F5-780E-4D9E-8722-2B42466BD072}: NameServer = 12.127.16.68,12.127.17.72
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Unknown owner - C:\Program Files\Symantec\pcAnywhere\awhost32.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Now shutting down browser and attempting to run svc
UPDATE No dice on the attempted run lockup almost immediately…. Rebooted and now running the AA followed by AVG and ATF in order to get a more stable system in which to run the SFC scan… (Oh and in past post when I said I was trying to run SVC i meant SFC…)
Update 2 AA ran and detected 4 critical and 9 negligible deleted… also noticed that under ADS it was set to ignore CA_INOCULATEIT. Is this a normal part of the program so that it doesn't detect it's own protection? Rerunning AA then moving to AVG. 2nd AA scan came up clean.
Running AVG now. N.B. I am doing all of the above unplugged from net as my paranoia forces me to think I am getting intruded upon.
AA & AVG RAN followed with HJT Still have system off line. Logs posted below in order of their running Ad-Aware SE Build 1.06r1 Logfile Created on:Wednesday, February 14, 2007 1:43:19 PM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R152 13.02.2007 ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª References detected during the scan: ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª None ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª Definition File: ========================= Definitions File Loaded: Reference Number : SE1R152 13.02.2007 Internal build : 192 File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref File size : 1009235 Bytes Total size : 3289774 Bytes Signature data size : 3242355 Bytes Reference data size : 46907 Bytes Signatures total : 86954 CSI Fingerprints total : 5964 CSI data size : 286876 Bytes Target categories : 15 Target families : 1048 Memory + processor status: ========================== Number of processors : 1 Processor architecture : Intel Pentium III Memory available:54 % Total physical memory:523696 kb Available physical memory:280524 kb Total page file size:883236 kb Available on page file:646888 kb Total virtual memory:2097024 kb Available virtual memory:2018480 kb OS:Microsoft Windows 2000 Professional Service Pack 4 (Build 2195) Ad-Aware SE Settings =========================== Set : Search for negligible risk entries Set : Search for low-risk threats Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan within archives Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 2-14-2007 1:43:19 PM - Scan started. (Full System Scan) Listing running processes ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª #:1 [smss.exe] FilePath : \SystemRoot\System32\ ProcessID : 168 ThreadCreationTime : 2-14-2007 7:10:20 PM BasePriority : Normal #:2 [csrss.exe] FilePath : \??\C:\WINNT\system32\ ProcessID : 196 ThreadCreationTime : 2-14-2007 7:10:35 PM BasePriority : Normal #:3 [winlogon.exe] FilePath : \??\C:\WINNT\system32\ ProcessID : 216 ThreadCreationTime : 2-14-2007 7:10:40 PM BasePriority : High #:4 [services.exe] FilePath : C:\WINNT\system32\ ProcessID : 244 ThreadCreationTime : 2-14-2007 7:10:42 PM BasePriority : Normal FileVersion : 5.00.2195.7035 ProductVersion : 5.00.2195.7035 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : services.exe #:5 [lsass.exe] FilePath : C:\WINNT\system32\ ProcessID : 256 ThreadCreationTime : 2-14-2007 7:10:42 PM BasePriority : Normal FileVersion : 5.00.2195.7011 ProductVersion : 5.00.2195.7011 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : LSA Executable and Server DLL (Export Version) InternalName : lsasrv.dll and lsass.exe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : lsasrv.dll and lsass.exe #:6 [svchost.exe] FilePath : C:\WINNT\system32\ ProcessID : 444 ThreadCreationTime : 2-14-2007 7:10:47 PM BasePriority : Normal FileVersion : 5.00.2134.1 ProductVersion : 5.00.2134.1 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : svchost.exe #:7 [spoolsv.exe] FilePath : C:\WINNT\system32\ ProcessID : 468 ThreadCreationTime : 2-14-2007 7:10:48 PM BasePriority : Normal FileVersion : 5.00.2195.7059 ProductVersion : 5.00.2195.7059 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolss.exe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : spoolss.exe #:8 [aluschedulersvc.exe] FilePath : C:\Program Files\Symantec\LiveUpdate\ ProcessID : 496 ThreadCreationTime : 2-14-2007 7:10:48 PM BasePriority : Normal FileVersion : 3.0.0.160 ProductVersion : 3.0.0.160 ProductName : LiveUpdate CompanyName : Symantec Corporation FileDescription : Automatic LiveUpdate Scheduler Service InternalName : Automatic LiveUpdate Scheduler Service LegalCopyright : Copyright © 1996-2005 Symantec Corporation OriginalFilename : ALUSchedulerSvc.exe #:9 [guard.exe] FilePath : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\ ProcessID : 524 ThreadCreationTime : 2-14-2007 7:10:49 PM BasePriority : Normal FileVersion : 7, 5, 0, 47 ProductVersion : 7, 5, 0, 47 ProductName : AVG Anti-Spyware CompanyName : Anti-Malware Development a.s. FileDescription : AVG Anti-Spyware guard InternalName : AVG Anti-Spyware guard LegalCopyright : Copyright © 2006 Anti-Malware Development a.s. OriginalFilename : guard.exe #:10 [ccsetmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 536 ThreadCreationTime : 2-14-2007 7:10:49 PM BasePriority : Normal FileVersion : 104.0.14.2 ProductVersion : 104.0.14.2 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Settings Manager Service InternalName : ccSetMgr LegalCopyright : Copyright © 2000-2005 Symantec Corporation. All rights reserved. OriginalFilename : ccSetMgr.exe #:11 [svchost.exe] FilePath : C:\WINNT\System32\ ProcessID : 560 ThreadCreationTime : 2-14-2007 7:10:51 PM BasePriority : Normal FileVersion : 5.00.2134.1 ProductVersion : 5.00.2134.1 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : svchost.exe #:12 [gbpoll.exe] FilePath : C:\Program Files\Norton SystemWorks\Norton GoBack\ ProcessID : 596 ThreadCreationTime : 2-14-2007 7:10:55 PM BasePriority : Normal #:13 [maxbackserviceint.exe] FilePath : C:\Program Files\Maxtor\Maxtor Backup\ ProcessID : 620 ThreadCreationTime : 2-14-2007 7:10:58 PM BasePriority : Normal FileVersion : 1, 0, 0, 3 ProductVersion : 1, 0, 0, 3 ProductName : MaxBackServiceInt Module FileDescription : MaxBackServiceInt Module InternalName : MaxBackServiceInt LegalCopyright : Copyright 2005 OriginalFilename : MaxBackServiceInt.EXE #:14 [npfmntor.exe] FilePath : C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\ ProcessID : 688 ThreadCreationTime : 2-14-2007 7:11:02 PM BasePriority : Normal FileVersion : 12.6.0.1 ProductVersion : 12.6.0 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Firewall Install Monitor InternalName : NPFMonitor LegalCopyright : Norton AntiVirus 2006 for Windows 2000/XP Copyright © 2005 Symantec Corporation. All rights reserved. OriginalFilename : NPFMonitor.EXE #:15 [nprotect.exe] FilePath : C:\PROGRA~1\NORTON~1\NORTON~3\ ProcessID : 708 ThreadCreationTime : 2-14-2007 7:11:03 PM BasePriority : Normal FileVersion : 19.0.0.48 ProductVersion : 19.0.0.48 ProductName : Norton Utilities CompanyName : Symantec Corporation FileDescription : Norton Protection Status InternalName : NPROTECT LegalCopyright : Copyright © 1997-2005 Symantec Corporation LegalTrademarks : Norton UtilitiesÆ and UnEraseÆ are registered trademarks of Symantec Corporation. OriginalFilename : NPROTECT.EXE #:16 [syncservices.exe] FilePath : C:\Program Files\Maxtor\OneTouch\Utils\ ProcessID : 792 ThreadCreationTime : 2-14-2007 7:11:07 PM BasePriority : Normal FileVersion : 1, 0, 0, 1 ProductVersion : 1, 0, 0, 1 ProductName : SyncServices FileDescription : SyncServices InternalName : SyncServices LegalCopyright : Copyright © 2005 OriginalFilename : SyncServices.exe #:17 [nvsvc32.exe] FilePath : C:\WINNT\System32\ ProcessID : 808 ThreadCreationTime : 2-14-2007 7:11:08 PM BasePriority : Normal FileVersion : 6.13.10.2942 ProductVersion : 6.13.10.2942 ProductName : NVIDIA Driver Helper Service, Version 29.42 CompanyName : NVIDIA Corporation FileDescription : NVIDIA Driver Helper Service, Version 29.42 InternalName : NVSVC LegalCopyright : © NVIDIA Corporation. All rights reserved. OriginalFilename : nvsvc32.exe #:18 [regsvc.exe] FilePath : C:\WINNT\system32\ ProcessID : 840 ThreadCreationTime : 2-14-2007 7:11:08 PM BasePriority : Normal FileVersion : 5.00.2195.6701 ProductVersion : 5.00.2195.6701 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Remote Registry Service InternalName : regsvc LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : REGSVC.EXE #:19 [mstask.exe] FilePath : C:\WINNT\system32\ ProcessID : 844 ThreadCreationTime : 2-14-2007 7:11:09 PM BasePriority : Normal FileVersion : 4.71.2195.6972 ProductVersion : 4.71.2195.6972 ProductName : MicrosoftÆ WindowsÆ Task Scheduler CompanyName : Microsoft Corporation FileDescription : Task Scheduler Engine InternalName : TaskScheduler LegalCopyright : Copyright © Microsoft Corp. 1997 OriginalFilename : mstask.exe #:20 [sndsrvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 876 ThreadCreationTime : 2-14-2007 7:11:10 PM BasePriority : Normal FileVersion : 6.0.4.402 ProductVersion : 6.0 ProductName : Symantec Security Drivers CompanyName : Symantec Corporation FileDescription : Network Driver Service InternalName : SndSrvc LegalCopyright : Copyright 2002 - 2006 Symantec Corporation OriginalFilename : SndSrvc.exe #:21 [spbbcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\SPBBC\ ProcessID : 920 ThreadCreationTime : 2-14-2007 7:11:10 PM BasePriority : Normal FileVersion : 2.1.0.4 ProductVersion : 2.1.0.4 ProductName : SPBBC CompanyName : Symantec Corporation FileDescription : SPBBC Service InternalName : SPBBCSvc LegalCopyright : Copyright © 2004, 2005 Symantec Corporation. All rights reserved. OriginalFilename : SPBBCSvc.exe #:22 [nopdb.exe] FilePath : C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\ ProcessID : 944 ThreadCreationTime : 2-14-2007 7:11:12 PM BasePriority : Normal FileVersion : 7.00.0.24 ProductVersion : 7.00.0.24 ProductName : Norton Speed Disk CompanyName : Symantec Corporation FileDescription : NOPDB InternalName : NOPDB LegalCopyright : Copyright © 1997-2005 Symantec Corporation OriginalFilename : NOPDB.dll #:23 [symlcsvc.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\ ProcessID : 960 ThreadCreationTime : 2-14-2007 7:11:13 PM BasePriority : Normal FileVersion : 1.9.1.1080 ProductVersion : 1.9.1.1080 ProductName : Symantec Core Component CompanyName : Symantec Corporation FileDescription : Symantec Core Component InternalName : symlcsvc LegalCopyright : Copyright © 2003 OriginalFilename : symlcsvc.exe #:24 [winmgmt.exe] FilePath : C:\WINNT\System32\WBEM\ ProcessID : 980 ThreadCreationTime : 2-14-2007 7:11:15 PM BasePriority : Normal FileVersion : 1.50.1085.0100 ProductVersion : 1.50.1085.0100 ProductName : Windows Management Instrumentation CompanyName : Microsoft Corporation FileDescription : Windows Management Instrumentation InternalName : WINMGMT LegalCopyright : Copyright © Microsoft Corp. 1995-1999 #:25 [mspmspsv.exe] FilePath : C:\WINNT\system32\ ProcessID : 1008 ThreadCreationTime : 2-14-2007 7:11:17 PM BasePriority : Normal FileVersion : 7.10.00.3068 ProductVersion : 7.10.00.3068 ProductName : Microsoft ® DRM CompanyName : Microsoft Corporation FileDescription : WMDM PMSP Service InternalName : MSPMSPSV.EXE LegalCopyright : Copyright © Microsoft Corp. 1981-2000 OriginalFilename : MSPMSPSV.EXE #:26 [svchost.exe] FilePath : C:\WINNT\system32\ ProcessID : 1020 ThreadCreationTime : 2-14-2007 7:11:17 PM BasePriority : Normal FileVersion : 5.00.2134.1 ProductVersion : 5.00.2134.1 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : svchost.exe #:27 [ccevtmgr.exe] FilePath : C:\Program Files\Common Files\Symantec Shared\ ProcessID : 1048 ThreadCreationTime : 2-14-2007 7:11:20 PM BasePriority : Normal FileVersion : 104.0.14.2 ProductVersion : 104.0.14.2 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Event Manager Service InternalName : ccEvtMgr LegalCopyright : Copyright © 2000-2005 Symantec Corporation. All rights reserved. OriginalFilename : ccEvtMgr.exe #:28 [explorer.exe] FilePath : C:\WINNT\ ProcessID : 312 ThreadCreationTime : 2-14-2007 7:22:53 PM BasePriority : Normal FileVersion : 5.00.3700.6690 ProductVersion : 5.00.3700.6690 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : EXPLORER.EXE #:29 [hpztsb04.exe] FilePath : C:\WINNT\system32\spool\drivers\w32x86\3\ ProcessID : 1420 ThreadCreationTime : 2-14-2007 7:23:06 PM BasePriority : Normal FileVersion : 2,75,0,0 ProductVersion : 2,75,0,0 ProductName : HP DeskJet CompanyName : HP LegalCopyright : Copyright © Hewlett-Packard Company 1999-2001 #:30 [onetouch.exe] FilePath : C:\Program Files\Maxtor\OneTouch\utils\ ProcessID : 924 ThreadCreationTime : 2-14-2007 7:23:07 PM BasePriority : Normal FileVersion : 4, 0, 1, 0 ProductVersion : 4, 0, 1, 0 ProductName : Maxtor OneTouch II CompanyName : Maxtor Corporation FileDescription : Maxtor OneTouch Detection InternalName : OneTouch LegalCopyright : Copyright © 2004-2005 OriginalFilename : OneTouch.EXE #:31 [mspm.exe] FilePath : C:\Program Files\Maxtor\OneTouch\utils\ ProcessID : 1276 ThreadCreationTime : 2-14-2007 7:23:08 PM BasePriority : Normal FileVersion : 0, 0, 0, 1 ProductVersion : 0, 0, 0, 1 ProductName : MSPM Application CompanyName : Maxtor Corp. FileDescription : MSPM MFC Application InternalName : MSPM LegalCopyright : Copyright © 2005 OriginalFilename : MSPM.EXE Comments : MSPM Scheduler #:32 [maxmenumgr.exe] FilePath : C:\Program Files\Maxtor\OneTouch Status\ ProcessID : 1424 ThreadCreationTime : 2-14-2007 7:23:08 PM BasePriority : Normal FileVersion : 1, 0, 1, 12 ProductVersion : 1, 0, 1, 12 ProductName : MSS & OneTouchô Application CompanyName : Maxtor Corp. FileDescription : MSS & OneTouchô MFC Application InternalName : MaxMenuMgr LegalCopyright : Copyright © 2005 OriginalFilename : MaxMenuMgr.EXE #:33 [avgas.exe] FilePath : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\ ProcessID : 1452 ThreadCreationTime : 2-14-2007 7:23:14 PM BasePriority : Normal FileVersion : 7, 5, 0, 50 ProductVersion : 7, 5, 0, 50 ProductName : AVG Anti-Spyware CompanyName : Anti-Malware Development a.s. FileDescription : AVG Anti-Spyware InternalName : AVG Anti-Spyware LegalCopyright : Copyright © 2006 Anti-Malware Development a.s. OriginalFilename : avgas.exe #:34 [googletoolbarnotifier.exe] FilePath : C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\ ProcessID : 1460 ThreadCreationTime : 2-14-2007 7:23:15 PM BasePriority : Normal FileVersion : 1, 2, 1128, 5462 ProductVersion : 1, 2, 1128, 5462 ProductName : GoogleToolbarNotifier CompanyName : Google Inc. FileDescription : GoogleToolbarNotifier LegalCopyright : Copyright © 2005-2006 OriginalFilename : GoogleToolbarNotifier.exe #:35 [gbtray.exe] FilePath : C:\Program Files\Norton SystemWorks\Norton GoBack\ ProcessID : 1492 ThreadCreationTime : 2-14-2007 7:23:17 PM BasePriority : Normal #:36 [ad-aware.exe] FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\ ProcessID : 648 ThreadCreationTime : 2-14-2007 7:23:53 PM BasePriority : Normal FileVersion : 6.2.0.236 ProductVersion : SE 106 ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft AB Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª New critical objects: 0 Objects found so far: 0 Started registry scan ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª Registry Scan result: ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª New critical objects: 0 Objects found so far: 0 Started deep registry scan ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª Deep registry scan result: ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª New critical objects: 0 Objects found so far: 0 Started Tracking Cookie scan ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª Tracking cookie scan result: ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª New critical objects: 0 Objects found so far: 0 Disk Scan Result for C:\ ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª New critical objects: 0 Objects found so far: 0 Scanning Hosts file…… Hosts file location:"C:\WINNT\system32\drivers\etc\hosts". ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª Hosts file scan result: ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª 4 entries scanned. New critical objects:0 Objects found so far: 0 1:52:29 PM Scan Complete Summary Of This Scan ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª Total scanning time:00:09:09.516 Objects scanned:103150 Objects identified:0 Objects ignored:0 New critical objects:0 ________________________________________________________________________ ArchiveData(auto-quarantine- 2007-02-14 13-35-19.bckp) Referencefile : SE1R152 13.02.2007 ====================================================== MRU LIST ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª obj[0]=MRU FileReference : C:\Documents and Settings\Administrator\recent\Adaware log Feb1307 1049.txt.lnk obj[1]=MRU FileReference : C:\Documents and Settings\Administrator\recent\Adaware log Feb1307 0930.txt.lnk obj[2]=MRU FileReference : C:\Documents and Settings\Administrator\recent\AdbeRdr80_DLM_en_US.exe.lnk obj[3]=MRU FileReference : C:\Documents and Settings\Administrator\recent\Admin.hlp.lnk obj[4]=MRU FileReference : C:\Documents and Settings\Administrator\recent\ATF-Cleaner.exe.lnk obj[5]=MRU FileReference : C:\Documents and Settings\Administrator\recent\combofix.exe.lnk obj[6]=MRU RegReference : S-1-5-21-1262643047-251222768-1713184818-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\* obj[7]=MRU RegReference : S-1-5-21-1262643047-251222768-1713184818-500\software\microsoft\windows\currentversion\explorer\recentdocs\.exe obj[8]=MRU RegReference : S-1-5-21-1262643047-251222768-1713184818-500\software\microsoft\windows\currentversion\explorer\recentdocs\.hlp obj[9]=MRU RegReference : S-1-5-21-1262643047-251222768-1713184818-500\software\microsoft\windows\currentversion\explorer\recentdocs\.log obj[10]=MRU RegReference : S-1-5-21-1262643047-251222768-1713184818-500\software\microsoft\windows\currentversion\explorer\recentdocs\.rtf obj[11]=MRU RegReference : S-1-5-21-1262643047-251222768-1713184818-500\software\microsoft\windows\currentversion\explorer\recentdocs\.txt obj[12]=MRU RegReference : S-1-5-21-1262643047-251222768-1713184818-500\software\microsoft\windows\currentversion\explorer\recentdocs\Folder obj[13]=MRU FileReference : C:\Documents and Settings\Administrator\recent\Report-Scan-20070213-112342.txt.lnk obj[14]=MRU RegReference : S-1-5-21-1262643047-251222768-1713184818-500\software\microsoft\windows\currentversion\explorer\runmru obj[15]=MRU FileReference : C:\Documents and Settings\Administrator\recent\Report-Scan-20070213-115505.txt.lnk obj[16]=MRU FileReference : C:\Documents and Settings\Administrator\recent\Report-Scan-20070213-135304.txt.lnk obj[17]=MRU FileReference : C:\Documents and Settings\Administrator\recent\ReportingEvents.log.lnk obj[18]=MRU FileReference : C:\Documents and Settings\Administrator\recent\SmitfraudFix.exe.lnk obj[19]=MRU FileReference : C:\Documents and Settings\Administrator\recent\SoftwareDistribution.lnk obj[20]=MRU FileReference : C:\Documents and Settings\Administrator\recent\Spybot Log 20070213-1158.txt.lnk obj[21]=MRU FileReference : C:\Documents and Settings\Administrator\recent\spybotsd14.exe.lnk obj[22]=MRU FileReference : C:\Documents and Settings\Administrator\recent\ST5UNST.EXE.lnk obj[23]=MRU FileReference : C:\Documents and Settings\Administrator\recent\TRIPS TECH TOOLS.lnk obj[24]=MRU FileReference : C:\Documents and Settings\Administrator\recent\WINNT.lnk obj[26]=MRU RegReference : software\microsoft\directdraw\mostrecentapplication name obj[27]=MRU RegReference : S-1-5-21-1262643047-251222768-1713184818-500\software\microsoft\microsoft management console\recent file list obj[28]=MRU RegReference : S-1-5-21-1262643047-251222768-1713184818-500\software\microsoft\windows\currentversion\applets\regedit lastkey obj[29]=MRU RegReference : S-1-5-21-1262643047-251222768-1713184818-500\software\microsoft\windows\currentversion\applets\wordpad\recent file list obj[30]=MRU RegReference : S-1-5-21-1262643047-251222768-1713184818-500\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru TRACKING COOKIE ªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªªª obj[9]=IECache Entry : Cookie:[removed]/ obj[10]=IECache Entry : Cookie:[removed]/ obj[11]=IECache Entry : Cookie:[removed]/ obj[12]=IECache Entry : Cookie:[removed]/ __________________________________________________________________________________ - Proceeding with ATF-CLEANER FOLLOWED BY SFC Attempt number 4 or 5
Well SFC ran… I am unsure of the results but I can say I didn't lock up yet. That's a big check in the plus column right there. WOOHOOO!! No Windows installer error on deleting the Kodak!!! Plus Just got shed of the PC Anywhere & Real Player which granted I once put on myself but given the problems I am trying to get this down as simple and secure as possible.

Would love to hear any and all advice on what else I can get rid of and/or do to optimize & secure this system as well as test it before plugging it back in.


Update ADOBE Reader just installed so that's another problem fixed… Wondering if I should now uninstall the Adobe Download Manager or is it fine… Also noted that I have 2 copies of HJT due to problems installing the first time. Unsure if I install one if I will lose both and as a result my logs etc.
Sounds like there were some corrupt windows files.

You can uninstall and remove any programs I had you install.


1.Do one of the following:
In Windows 98/Me/2000, on the Windows desktop, double-click the My Computer

icon.
In Windows XP, on the taskbar, click Start > My Computer.

2.Do one of the following:
In Windows 98, on the View menu, click Folder Options.
In Windows Me/2000/XP, on the Tools menu, click Folder Options.
On the View tab, check Hide file extensions for known file types.

3.Do one of the following:
In Windows 98, in the Advanced Settings box, under the "Hidden files" folder,

unclick Show all files.
In Windows Me/2000/XP, check Hide protected operating system files. Then, under

the "Hidden files" folder, unclick Show hidden files and folders.
If you see a warning message, click Yes.
Click Apply.
Click OK.



If you dont have any programs like these, I would recommend that you get them.
Spywareblaster,
Spywareguard.


Also get a FREE FIREWALL and FREE ANTI VIRUS if you need one.

Only run one Anti-Virus and Firewall program.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Do not use Ad-aware if you have McAfee's VirusScan and AntiSpyware


Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
So I am proceeding with what you just posted and thought I'd put up some screen shots of some of the main files just so you could take a look and see if anything popped out at you before I plugged it back in.

[external image: Posted Image]

[external image: Posted Image]

[external image: Posted Image]

[external image: Posted Image]

I also have images of everything in the WINNT Folder that I could post. If I am just being paranoid and need to except that this is fixed I will do so.


Oh and as far as making sure my drivers are correct for running the USB Backup and all what's the best way? Or should I repost that under a different topic?
found.000 <-These were the corrupt files. You can remove it.

Oh and as far as making sure my drivers are correct for running the USB Backup and all what's the best way?

The usb backup isn't working? Is this a external hard drive you're using for the backup?
Yes it is a Maxtor one touch III USB 2.0 My installing a new USB/Firewire card a USB Hub and the Backup unit is how I got involved with this problem… Also was wondering where I should read or inquire on how to best setup the security and permissions on the system so that other users cannot undo the work I have done with your most generous guidance.
Security settings: Be sure to make notes of what settings you change in case you need to change them back.
http://labmice.techtarget.com/articles/securingwin2000.htm

Maxtor one touch III USB 2.0 My installing a new USB/Firewire card a USB Hub and the Backup unit

OK. So if I understand the problem, you installed USB/Firewire card a USB Hub and attached the drive but it doesn't reconize if? Have you tried their support forum?
http://www.seagate.com/www/en-us/support/i…nal_servers/ot3
When I had tried to backup before it failed. seemed to be because of bad USB Controllers… Running AVG on the backup now. Will jump back on this come tomorrow cause if I don't leave now and go see a young lady on this St. Valentines day I will be in much trouble.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI