dvr 0 Junior Poster

didnt see anything, I always check the event logs.
i attached a small clip of the event log from last weekend.
when i open the event log error it says "End Backup: E: Warnings or errors were encountered consult backup log"
which says E: is not a valid drive, or you do not have access.

dvr 0 Junior Poster

no nothing that changes drive letters.
i haven't tried accessing it, because it usually starts the full backup around 2am.
however i have signed in and made sure that all the drives are connected.
when this first started happening i rebooted the server every saturday and that seemed to fix it.
now it started doing it again and i still reboot the server.
frustrating dealing with backup issues.

dvr 0 Junior Poster

i am attaching my backup batch file

dvr 0 Junior Poster

local disk

dvr 0 Junior Poster

No time restrictions, this also was working fine for about a year

dvr 0 Junior Poster

Hi All

I am sure this has been discussed multiple times.
I have searched the forum and found nothing like my problem.
I have windows server 2003 it runs a incremental backup everyday.
but on saturday it runs a normal(full) backup. during the week it runs fine.
on the weekend it fails and gives me the E: is not a valid drive, or you do not have access.
I have checked security and NTBackup user has all the permissions for drive E:
and so does Backup Operators also. any ideas what else i should check?

Thanks

dvr 0 Junior Poster

Can you show me the link you get from the dell websites? Thanks:)

Sorry I cant find the link. but if you open your PC and look at the card and if you see no battery that is why, if you see a battery replace it.
best help I can give you.

dvr 0 Junior Poster

hi
I have a dell t7400. during boot it says
"your battery is either charging, bad or missing, and you have VDs configured
for write-back mode. Because the batteryis not currently usable, these VDs
wil actually run in write-through mode untilthe battery is fully charged or
replaced if it is bad or missing."

the computer has been running for a week straight and still says the same.
any ideas?

found the answer on dells site.
my cards dont have batteries.:$ should of opened the case first.

dvr 0 Junior Poster

hi
I have a dell t7400. during boot it says
"your battery is either charging, bad or missing, and you have VDs configured
for write-back mode. Because the batteryis not currently usable, these VDs
wil actually run in write-through mode untilthe battery is fully charged or
replaced if it is bad or missing."

the computer has been running for a week straight and still says the same.
any ideas?

dvr 0 Junior Poster

If you company uses OWA exposed to the internet then you can get a program called Touchdown for the Android phones.

thanks but my company doesn't allow OWA only inside the company.
I talked to one of are IT guys and he is going to try and build another exchange server just for mobile devices.

dvr 0 Junior Poster

not sure if I'am in the right area but here it goes.
is it possible to have a exchange server like a blackberry server for the droid x?
meaning my company does not want to open up ports for our exchange server to the internet.
but if there is a way to have a sub-server like the blackberry server.
if that made any sense please let me know. my boss and I want either a Iphone or droid x.

dvr 0 Junior Poster
dvr 0 Junior Poster

that is the port forwarding on the router.
thats where I have forwarded out all my other ports from.

dvr 0 Junior Poster

here is a screen shot of my firewall port forwarding

dvr 0 Junior Poster

I have a firebox edge router, which I forward out other ports already.
I just can't figure out how to redirect say port 81 to the webserver which is port 80.

dvr 0 Junior Poster

I have a webserver that uses port 80 and the port cannot be changed.
is there a way to redirect another port to it?
or a program that can run on a pc that will redirect to the webserver?
my ISP blocks 80 of course, I have 4 webservers that all use port 80 and I
can't change that. they are stand alone units(not computers).

dvr 0 Junior Poster

I ran avg, spybot, adaware, kaspersky and bitdefender.
here are the logs
Kaspersky

Total number of scanned objects 64892
Number of viruses found 0
Number of infected objects 0
Number of suspicious objects 0
Duration of the scan process 00:47:38

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstderr.txt Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstdout.txt Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aoltsmon.lock Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\cache.db Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\server.lock Object is locked skipped

C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Application Data\McAfee\BOPDATA\_Date-20070911_Time-100233734_EnterceptExceptions.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\McAfee\BOPDATA\_Date-20070911_Time-100233734_EnterceptRules.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\mcafee.com personal firewall\data\IpRules.xdb Object is locked skipped

C:\Documents and Settings\All Users\Application Data\mcafee.com personal firewall\data\log.edb Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat …

dvr 0 Junior Poster

a couple of questions
after creating a new connection you get the network icon back or nothing?
what OS?
have you started in safe mode and tried to get rid of the virus?

dvr 0 Junior Poster

thanx I tried that also. I don't understand what happened.
everything worked fine, then 2 days later everything does not.
grrr.

dvr 0 Junior Poster

ok I have unplugged everything and plugged back in.
reshared folders restarted all machines and switches.
shut down win xp pro firewalls.
and now I can see computers, but can only access certain ones.
I have searched google and google groups. some people have the same problems but no soluitions yet.

dvr 0 Junior Poster

tried that, still the same problem.

dvr 0 Junior Poster

I have been having network problems. I checked my event viewer and it shows me alot of errors in system log. this is a windows 2000 pro sp4 system. I have a list of commands that have errors, here they are.

the at9.job command failed to start due to the following error:
General access denied error.

it has a list at1-9 and at17-24
all have the same event id: 7901

dvr 0 Junior Poster

ok everything was fine last week when I was transfering files between computers. but today I tried to transfer some pictures between them and could not get to any computers on my network.
I am running win 2000 pro on 3 computers and 2 have xp pro for a total of five. I can ping them all, I can search for them, but I only find 2, one win 2000 and one xp. I thought it might be something with my router, so I plugged them into a switch still the same thing.
when you click on workgroup it says workgroup is not accessible
the specified server cannot perform the requested operation.
I can surf the internet fine. any ideas??

dvr 0 Junior Poster

sorry if this is in the wrong place.
is it possible to forward port say 81 from one pc to port 80 on another webserver? here is my problem I have 4 webservers that use port 80 and my ISP blocks port 80, and I cannot change the ports on the webservers. so I would like to open ports 81,82,83 and 84 and send them to the IP's of those webservers. my router is a firebox edge, which I haven't installed yet, but will be shortly.

dvr 0 Junior Poster

same thing just clicked on button rebuild icon cache.

dvr 0 Junior Poster

thanks I got it fixed I had to download activicon and that had a simple way to rebuild the icon cache.

dvr 0 Junior Poster

thanks I will try the tweakui. nothing else seems to work.

dvr 0 Junior Poster

it opens the programs that are under the recycle bin, but its hard to make out the icons under the recycle bin icons.

dvr 0 Junior Poster

I have a windows 2000 pc and all the icons are covered up by recycle bin icons. I ran ewido,adaware, spybot s&d and avg they found nothing.
sorry if this is in the wrong forum, but it doesn't appear to be a virus to me since all the scans came up with nothing. any ideas?

dvr 0 Junior Poster

I just installed windows 2003 server r2 for the first time.
when I put in the disk for the motherboard it started and loaded the chipset and restarted then it went to install the audio and that failed and the video failed then the NIC took for ever after an hour I stopped the program and restarted the computer. I tried putting the driver disk back in and it wont auto run any more. the mother board is a intel D945gnt.
I ran the audio setup and that installed. I tried the video setup file and it will not load, it says"an unknown error occured setup will exit.", the NIC loaded. the video folder says intel R graphics media accelerator. I looked on intels site for drivers for the video card and could not find anything on windows 2003 server. what can I do?

dvr 0 Junior Poster

does anyone know if Dynamic C is the same as visual c+?
also I am trying to find or make a simple program of a time clock like this for controlling outside lights.

[IMG]timeclock.jpg[/IMG]


does anyone know where to find a site for help on this?

dvr 0 Junior Poster

maybe someone can help me out.
I want to install some relays on some outside lights. I would like to know if there is a program that can turn them on and off at different hours and days. plus be able to over ride and turn them on.
I imagine I will need some sort of I/O device to do this.
any ideas??

dvr 0 Junior Poster

nevermind I remembered had to change it to windows login

dvr 0 Junior Poster

how can I get rid of the win 98 login?
I used to be able to boot right into the desktop with out login in. its been a long time since I used win 98.

dvr 0 Junior Poster

yes its on the same computer

dvr 0 Junior Poster

I downloaded spydoctor and ran it. it scanned my computer and found 55 infections. of course after the scan it said to clean please register which cost $$ :( but I saved the log.
and was wondering if that is a good spyware remover? here is the log.


<?xml version="1.0"?>
<data>
<scan>
<scanstart>3/4/2006 12:43:39 AM</scanstart>
<timestamp>3/4/2006 5:42:53 AM</timestamp>
<item>
<name>Trojan.Downloader.Small.AIQ</name>
<type>general malware</type>
<location>multiple</location>
<risk>High</risk>
<description>Trojan.Downloader.Small.AIQ runs as a process in memory and periodically contacts servers for malicious files to download.</description>
<tool>genscanner.dll</tool>
</item>
<item>
<name>SpyAxe</name>
<type>Processes</type>
<location>Explorer.EXE (C:\WINNT\system32\dxmpp.dll)</location>
<risk>Elevated</risk>
<description>SpyAxe is a Rogue Anti-Spyware product which comes bundled along with a malicious downloader. It is downloaded and installed without the users consent.</description>
<tool>pscanner.dll</tool>
</item>
<item>
<name>Trojan.Dropper.Small.OI</name>
<type>Registry</type>
<location>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler##{5FFD4A60-C328-128D-44EB-21D258091D15}</location>
<risk>High</risk>
<description>Trojan.Dropper.Small.OI silently hides itself inside explorer. Running in stealth mode the Trojan will silently try to download additional malware from remote servers over the internet. More to that it will hijack your homepage to www.searchzoommer.com.</description>
<tool>StartupScanner.dll</tool>
</item>
<item>
<name>Windows AdControl</name>
<type>Registry</type>
<location>HKCR\WinServAdX.Installer</location>
<risk>Elevated</risk>
<description>Windows AdControl tracks a users browsing habits and distributes the data to remote servers to produce pop-up advertisements, mainly of pornographic nature.</description>
<tool>regscanner.dll</tool>
</item>
<item>
<name>Windows AdControl</name>
<type>Registry</type>
<location>HKCR\WinServAdX.Installer##</location>
<risk>Elevated</risk>
<description>Windows AdControl tracks a users browsing habits and distributes the data to remote …

dvr 0 Junior Poster

Logfile of HijackThis v1.99.1
Scan saved at 1:20:53 AM, on 3/4/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\userinit.exe
C:\WINNT\Explorer.EXE
C:\WINNT\explorer.exe
C:\Documents and Settings\pbmp3\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = www.google.com
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v6.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 …

dvr 0 Junior Poster

I have an infection and can't get rid of it.
I tried adaware,spybot,avg,ewido and the online scans and nothing gets rid of it. spyfalcon and a globe that looks like windows update but it changes to a red circle with a X in the center and then back to the globe here is my hijack this log I will post my winpfind log next

Logfile of HijackThis v1.99.1
Scan saved at 12:03:19 AM, on 3/4/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SpyFalcon\SpyFalcon.exe
C:\Program Files\SpyFalcon\SpyFalcon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\explorer.exe
C:\Documents and Settings\pbmp3\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = [url]www.google.com[/url]
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
O2 - BHO: (no name) - {FA93E44F-B026-4E28-89BF-33986035EFAD} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - [url]http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab[/url]
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - [url]http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v6.cab[/url]
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe …
dvr 0 Junior Poster

yeah I tried that already and the files weren't there. but everytime I reboot they are back? if I goto my processes there are three CLI.exe files running if I end them then those files disappear. I just want to make sure this isn't one of those new trojans out now.

dvr 0 Junior Poster

xp crashed and I found these files after reboot in my temp folder and cannot delete them. it says they are being used by another user or program.

Perflib_Perfdata_1a8.dat
Perflib_Perfdata_c68.dat
Perflib_Perfdata_c5c.dat
Perflib_Perfdata_a74.dat

dvr 0 Junior Poster

I am looking for a free parental control for win xp for a lady at my work.
I just finished building her new pc and she is looking for a parental control for her kids, to block unwanted sites. is there a good free one or should she just go and by one or is there a way to have XP home block stuff? I don't have kids and never looked for stuff like this before.
thanks in advanced

dvr 0 Junior Poster

when I open word and excel they both have errors. this is a fresh install on a laptop( a dell latitude).with windows 2000.
ok word comes with this error "compile error in hidden module AutoExec"
and when you close it it has the same error.

on excel it says "compile error in hidden module AutoExecNew" when you start the program and when you close it says "compile error in hidden module Distmon"

what can I do to stop this?

dvr 0 Junior Poster

new hijackthis log after above fixes you gave me

Logfile of HijackThis v1.99.1
Scan saved at 12:17:29 AM, on 8/20/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\pbmp3\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = www.google.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {FA93E44F-B026-4E28-89BF-33986035EFAD} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program …

dvr 0 Junior Poster

ok its long here it is

WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.


If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.


»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows 2000    Current Build: Service Pack 4    Current Build Number: 2195
Internet Explorer Version: 5.00.3700.1000


»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»


Checking %SystemDrive% folder...


Checking %ProgramFilesDir% folder...


Checking %WinDir% folder...


Checking %System% folder...
Umonitor             6/19/2003 1:05:04 PM   529168     C:\WINNT\SYSTEM32\RASDLG.DLL
winsync              5/8/2001 8:00:00 AM    1309184    C:\WINNT\SYSTEM32\wbdbase.deu
UPX!                 1/9/2005 1:37:44 AM    65536      C:\WINNT\SYSTEM32\wined.dll


Checking %System%\Drivers folder and sub-folders...
UPX!                 7/24/2005 12:52:54 AM  668704     C:\WINNT\SYSTEM32\drivers\avg7core.sys
FSG!                 7/24/2005 12:52:54 AM  668704     C:\WINNT\SYSTEM32\drivers\avg7core.sys
aspack               7/24/2005 12:52:54 AM  668704     C:\WINNT\SYSTEM32\drivers\avg7core.sys


Items found in C:\WINNT\SYSTEM32\drivers\etc\hosts



Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
H                    8/13/2005 2:16:28 PM   920876     C:\WINNT\ShellIconCache
H                    8/7/2005 10:00:58 AM   2015744    C:\WINNT\w74ca5e40.tmp
S                    8/13/2005 5:16:38 PM   64         C:\WINNT\CSC\00000001
S                    8/13/2005 2:08:58 PM   64         C:\WINNT\CSC\00000002
S                    8/13/2005 1:06:36 AM   64         C:\WINNT\CSC\csc1.tmp
SH                   7/30/2005 2:53:36 PM   10022      C:\WINNT\system32\KGyGaAvL.sys
H                    8/13/2005 5:16:40 PM   890        C:\WINNT\system32\vsconfig.xml
H                    7/13/2005 10:35:32 PM  4212       C:\WINNT\system32\zllictbl.dat
H                    8/13/2005 5:18:14 PM   1024       C:\WINNT\system32\config\default.LOG
H                    8/13/2005 5:16:38 PM   1024       C:\WINNT\system32\config\SAM.LOG
H                    8/13/2005 5:17:22 PM   1024       C:\WINNT\system32\config\SECURITY.LOG
H                    8/13/2005 5:21:50 PM   1024       C:\WINNT\system32\config\software.LOG
H                    8/13/2005 5:16:26 PM   6          C:\WINNT\Tasks\SA.DAT


Checking for CPL …
dvr 0 Junior Poster

here is the new log sorry for the old one.
I also scanned with the panda one online and it deleted the wininet.dll I couldn't use adaware and spybot and internet explorer. but I fixed that already.


Logfile of HijackThis v1.99.1
Scan saved at 2:11:42 PM, on 8/13/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\pbmp3\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = www.google.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {FA93E44F-B026-4E28-89BF-33986035EFAD} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O15 - Trusted IP range: 206.161.125.149
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AVG7 Alert Manager …

dvr 0 Junior Poster

here is my hijack this logLogfile of HijackThis v1.97.7
Scan saved at 11:45:45 PM, on 8/12/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\pbmp3\Desktop\hijackthis\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {FA93E44F-B026-4E28-89BF-33986035EFAD} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

dvr 0 Junior Poster

I cant get rid of these programs they keep coming back.
I did what swatkat said
Open NotePad, and copy the contents of the below "Quote" box:-

Quote:
cd %windir%
attrib -s -r -h ALCMTR.EXE
del ALCMTR.EXE
cd system32
attrib -s -r -h install32m.exe
attrib -s -r -h intel32.exe
attrib -s -r -h msnethlp32.exe
attrib -s -r -h Oeoepi32.exe
attrib -s -r -h paytime.exe
attrib -s -r -h Lgjopdch.dll
del Lgjopdch.dll
del install32m.exe
del intel32.exe
del Oeoepi32.exe
del msnethlp32.exe
del paytime.exe


Go to File Menu > Save As, and save the file with the name Test.bat and exit from NotePad.
Download Ewido and install it. Then run, you will receive a warning message saying "Database not found", click "OK" for this. Next in the main screen, click "Update" and click "Start Update". After the update process, exit from Ewido.

Download CCleaner and CWShredder.

and then this


Double-Click on the file Test.bat, a small DOS type window should open and close immediately.

Delete this folder ( and all the files inside it ):-
C:\Program Files\PSGuard

Search for this file and delete it:-
msnethlp32.dll


Run CCleaner, click "Options" button and here go to "Settings" tab and uncheck the option "Only delete files in Windows Temp folder older than 48 hours". Click OK to exit from the Options. Finally …

dvr 0 Junior Poster

Download Ewido and install it. click "Update" and click "Start Update". After the update process, exit from Ewido.

Download CCleaner and install it.

Run CCleaner, click "Options" button and here go to "Advanced" tab and uncheck the option "Only delete files in Windows Temp folder older than 48 hours". Click OK to exit from the Options. click "Run Cleaner" and choose "Yes" to continue cleaning.

Run Ewido, click on the "Scanner" button in the left menu, then click on the "Start" button.
If ewido finds anything, it will pop up a notification. select "Clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.

also you can download AVG antivirus it is free and updates are free as well.
personally I think its better than norton and mcaffee it finds viruses that they don't.

dvr 0 Junior Poster

where are you MartyMcFly I need your help here.

dvr 0 Junior Poster

sounds like your power supply. when you plug it in do you hear anything sometimes a fan will start for a split second.