didnt see anything, I always check the event logs.
i attached a small clip of the event log from last weekend.
when i open the event log error it says "End Backup: E: Warnings or errors were encountered consult backup log"
which says E: is not a valid drive, or you do not have access.
dvr 0 Junior Poster
no nothing that changes drive letters.
i haven't tried accessing it, because it usually starts the full backup around 2am.
however i have signed in and made sure that all the drives are connected.
when this first started happening i rebooted the server every saturday and that seemed to fix it.
now it started doing it again and i still reboot the server.
frustrating dealing with backup issues.
dvr 0 Junior Poster
i am attaching my backup batch file
::This batch job will stop Timberline Document Management service and
::backup DM to the NAS.
E:\applications\TSDV\hub_service -stop
E:\applications\TSDV\db_prog.exe -start_offline_dump
robocopy e:\applications\TSDV \\nas\backups\TimberlineDMbackup\TSDV /e /copyall /V /NFL /NDL /w:1 /r:0 /np
robocopy "c:\documents and settings\all users\application data\sage" \\nas\backups\TimberlineDMbackup\sage /e /copyall /V /NFL /NDL /w:1 /r:0 /np
::Now robocopy to the secondaryserver
robocopy e: \\secondaryserver\e$ /e /copyall /XD "E:\System Volume Information" /V /NFL /NDL /w:1 /r:0 /np
E:\applications\TSDV\db_prog.exe -cancel_offline_dump
net start cypress
echo on
for /f "tokens=1-4 delims=/ " %%a in ('date /t') do (
set yyyymmdd=%%d_%%b_%%c
set dd=%%c
set dow=%%a
)
echo %yyyymmdd%
echo %dd%
set btype=Incremental
if "%dow%"=="Sat" set btype=Normal
::Backup of File Server
C:\WINDOWS\system32\ntbackup.exe backup "@C:\Documents and Settings\NTBackup\Local Settings\Application Data\Microsoft\Windows NT\NTBackup\data\DailyBackup.bks" /F \\nas\backups\FileServerBackups\BACKUP_%dd%.bkf /m %btype% /v:no /j "Backup.job" /l:s
for /f "tokens=2 delims=]" %%a in ('dir /o:-d /b c:\"Documents and Settings\NTBackup\Local Settings\Application Data\Microsoft\Windows NT\NTBackup\data\backup*.log" ^| find /i /n "backup" ^| find /i "[1]"') do set mylog=%%a
find /i /v "backup" "c:\Documents and Settings\NTBackup\Local Settings\Application Data\Microsoft\Windows NT\NTBackup\data\%mylog%" | find /i /v "Media name" >>c:\batch\backupsummary.log
::Now Mail Backup Result to Administrators.
::This line mails the File Server backup log.
smtpsend -fxxxx@*****.com -tme@*****.com -s File Server Backup Result. -hmail.*****.com -iC:\Documents and Settings\NTBackup\Local Settings\Application Data\Microsoft\Windows NT\NTBackup\data\%mylog%
::This line mails the Document Management backup log.
smtpsend -fxxxx@*****.com -tme@*****.com -s DM Backup Result. -hmail.*****.com -ic:\batch\dailybackup.txt
dvr 0 Junior Poster
No time restrictions, this also was working fine for about a year
dvr 0 Junior Poster
Hi All
I am sure this has been discussed multiple times.
I have searched the forum and found nothing like my problem.
I have windows server 2003 it runs a incremental backup everyday.
but on saturday it runs a normal(full) backup. during the week it runs fine.
on the weekend it fails and gives me the E: is not a valid drive, or you do not have access.
I have checked security and NTBackup user has all the permissions for drive E:
and so does Backup Operators also. any ideas what else i should check?
Thanks
dvr 0 Junior Poster
Can you show me the link you get from the dell websites? Thanks:)
Sorry I cant find the link. but if you open your PC and look at the card and if you see no battery that is why, if you see a battery replace it.
best help I can give you.
dvr 0 Junior Poster
hi
I have a dell t7400. during boot it says
"your battery is either charging, bad or missing, and you have VDs configured
for write-back mode. Because the batteryis not currently usable, these VDs
wil actually run in write-through mode untilthe battery is fully charged or
replaced if it is bad or missing."the computer has been running for a week straight and still says the same.
any ideas?
found the answer on dells site.
my cards dont have batteries.:$ should of opened the case first.
dvr 0 Junior Poster
hi
I have a dell t7400. during boot it says
"your battery is either charging, bad or missing, and you have VDs configured
for write-back mode. Because the batteryis not currently usable, these VDs
wil actually run in write-through mode untilthe battery is fully charged or
replaced if it is bad or missing."
the computer has been running for a week straight and still says the same.
any ideas?
dvr 0 Junior Poster
If you company uses OWA exposed to the internet then you can get a program called Touchdown for the Android phones.
thanks but my company doesn't allow OWA only inside the company.
I talked to one of are IT guys and he is going to try and build another exchange server just for mobile devices.
dvr 0 Junior Poster
not sure if I'am in the right area but here it goes.
is it possible to have a exchange server like a blackberry server for the droid x?
meaning my company does not want to open up ports for our exchange server to the internet.
but if there is a way to have a sub-server like the blackberry server.
if that made any sense please let me know. my boss and I want either a Iphone or droid x.
dvr 0 Junior Poster
dvr 0 Junior Poster
that is the port forwarding on the router.
thats where I have forwarded out all my other ports from.
dvr 0 Junior Poster
here is a screen shot of my firewall port forwarding
dvr 0 Junior Poster
I have a firebox edge router, which I forward out other ports already.
I just can't figure out how to redirect say port 81 to the webserver which is port 80.
dvr 0 Junior Poster
I have a webserver that uses port 80 and the port cannot be changed.
is there a way to redirect another port to it?
or a program that can run on a pc that will redirect to the webserver?
my ISP blocks 80 of course, I have 4 webservers that all use port 80 and I
can't change that. they are stand alone units(not computers).
dvr 0 Junior Poster
I ran avg, spybot, adaware, kaspersky and bitdefender.
here are the logs
Kaspersky
Total number of scanned objects 64892
Number of viruses found 0
Number of infected objects 0
Number of suspicious objects 0
Duration of the scan process 00:47:38
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\ph Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\ACS\1.0\variable Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstderr.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aolstdout.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\aoltsmon.lock Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\cache.db Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\TopSpeed\2.0\server.lock Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\BOPDATA\_Date-20070911_Time-100233734_EnterceptExceptions.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\BOPDATA\_Date-20070911_Time-100233734_EnterceptRules.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\mcafee.com personal firewall\data\IpRules.xdb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\mcafee.com personal firewall\data\log.edb Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat …
dvr 0 Junior Poster
a couple of questions
after creating a new connection you get the network icon back or nothing?
what OS?
have you started in safe mode and tried to get rid of the virus?
dvr 0 Junior Poster
thanx I tried that also. I don't understand what happened.
everything worked fine, then 2 days later everything does not.
grrr.
dvr 0 Junior Poster
ok I have unplugged everything and plugged back in.
reshared folders restarted all machines and switches.
shut down win xp pro firewalls.
and now I can see computers, but can only access certain ones.
I have searched google and google groups. some people have the same problems but no soluitions yet.
dvr 0 Junior Poster
tried that, still the same problem.
dvr 0 Junior Poster
I have been having network problems. I checked my event viewer and it shows me alot of errors in system log. this is a windows 2000 pro sp4 system. I have a list of commands that have errors, here they are.
the at9.job command failed to start due to the following error:
General access denied error.
it has a list at1-9 and at17-24
all have the same event id: 7901
dvr 0 Junior Poster
ok everything was fine last week when I was transfering files between computers. but today I tried to transfer some pictures between them and could not get to any computers on my network.
I am running win 2000 pro on 3 computers and 2 have xp pro for a total of five. I can ping them all, I can search for them, but I only find 2, one win 2000 and one xp. I thought it might be something with my router, so I plugged them into a switch still the same thing.
when you click on workgroup it says workgroup is not accessible
the specified server cannot perform the requested operation.
I can surf the internet fine. any ideas??
dvr 0 Junior Poster
sorry if this is in the wrong place.
is it possible to forward port say 81 from one pc to port 80 on another webserver? here is my problem I have 4 webservers that use port 80 and my ISP blocks port 80, and I cannot change the ports on the webservers. so I would like to open ports 81,82,83 and 84 and send them to the IP's of those webservers. my router is a firebox edge, which I haven't installed yet, but will be shortly.
dvr 0 Junior Poster
same thing just clicked on button rebuild icon cache.
dvr 0 Junior Poster
thanks I got it fixed I had to download activicon and that had a simple way to rebuild the icon cache.
dvr 0 Junior Poster
thanks I will try the tweakui. nothing else seems to work.
dvr 0 Junior Poster
it opens the programs that are under the recycle bin, but its hard to make out the icons under the recycle bin icons.
dvr 0 Junior Poster
I have a windows 2000 pc and all the icons are covered up by recycle bin icons. I ran ewido,adaware, spybot s&d and avg they found nothing.
sorry if this is in the wrong forum, but it doesn't appear to be a virus to me since all the scans came up with nothing. any ideas?
dvr 0 Junior Poster
I just installed windows 2003 server r2 for the first time.
when I put in the disk for the motherboard it started and loaded the chipset and restarted then it went to install the audio and that failed and the video failed then the NIC took for ever after an hour I stopped the program and restarted the computer. I tried putting the driver disk back in and it wont auto run any more. the mother board is a intel D945gnt.
I ran the audio setup and that installed. I tried the video setup file and it will not load, it says"an unknown error occured setup will exit.", the NIC loaded. the video folder says intel R graphics media accelerator. I looked on intels site for drivers for the video card and could not find anything on windows 2003 server. what can I do?
dvr 0 Junior Poster
does anyone know if Dynamic C is the same as visual c+?
also I am trying to find or make a simple program of a time clock like this for controlling outside lights.
[IMG]timeclock.jpg[/IMG]
does anyone know where to find a site for help on this?
dvr 0 Junior Poster
maybe someone can help me out.
I want to install some relays on some outside lights. I would like to know if there is a program that can turn them on and off at different hours and days. plus be able to over ride and turn them on.
I imagine I will need some sort of I/O device to do this.
any ideas??
dvr 0 Junior Poster
nevermind I remembered had to change it to windows login
dvr 0 Junior Poster
how can I get rid of the win 98 login?
I used to be able to boot right into the desktop with out login in. its been a long time since I used win 98.
dvr 0 Junior Poster
I downloaded spydoctor and ran it. it scanned my computer and found 55 infections. of course after the scan it said to clean please register which cost $$ :( but I saved the log.
and was wondering if that is a good spyware remover? here is the log.
<?xml version="1.0"?>
<data>
<scan>
<scanstart>3/4/2006 12:43:39 AM</scanstart>
<timestamp>3/4/2006 5:42:53 AM</timestamp>
<item>
<name>Trojan.Downloader.Small.AIQ</name>
<type>general malware</type>
<location>multiple</location>
<risk>High</risk>
<description>Trojan.Downloader.Small.AIQ runs as a process in memory and periodically contacts servers for malicious files to download.</description>
<tool>genscanner.dll</tool>
</item>
<item>
<name>SpyAxe</name>
<type>Processes</type>
<location>Explorer.EXE (C:\WINNT\system32\dxmpp.dll)</location>
<risk>Elevated</risk>
<description>SpyAxe is a Rogue Anti-Spyware product which comes bundled along with a malicious downloader. It is downloaded and installed without the users consent.</description>
<tool>pscanner.dll</tool>
</item>
<item>
<name>Trojan.Dropper.Small.OI</name>
<type>Registry</type>
<location>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler##{5FFD4A60-C328-128D-44EB-21D258091D15}</location>
<risk>High</risk>
<description>Trojan.Dropper.Small.OI silently hides itself inside explorer. Running in stealth mode the Trojan will silently try to download additional malware from remote servers over the internet. More to that it will hijack your homepage to www.searchzoommer.com.</description>
<tool>StartupScanner.dll</tool>
</item>
<item>
<name>Windows AdControl</name>
<type>Registry</type>
<location>HKCR\WinServAdX.Installer</location>
<risk>Elevated</risk>
<description>Windows AdControl tracks a users browsing habits and distributes the data to remote servers to produce pop-up advertisements, mainly of pornographic nature.</description>
<tool>regscanner.dll</tool>
</item>
<item>
<name>Windows AdControl</name>
<type>Registry</type>
<location>HKCR\WinServAdX.Installer##</location>
<risk>Elevated</risk>
<description>Windows AdControl tracks a users browsing habits and distributes the data to remote …
dvr 0 Junior Poster
Logfile of HijackThis v1.99.1
Scan saved at 1:20:53 AM, on 3/4/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\userinit.exe
C:\WINNT\Explorer.EXE
C:\WINNT\explorer.exe
C:\Documents and Settings\pbmp3\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = www.google.com
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v6.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 …
dvr 0 Junior Poster
I have an infection and can't get rid of it.
I tried adaware,spybot,avg,ewido and the online scans and nothing gets rid of it. spyfalcon and a globe that looks like windows update but it changes to a red circle with a X in the center and then back to the globe here is my hijack this log I will post my winpfind log next
Logfile of HijackThis v1.99.1
Scan saved at 12:03:19 AM, on 3/4/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SpyFalcon\SpyFalcon.exe
C:\Program Files\SpyFalcon\SpyFalcon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\explorer.exe
C:\Documents and Settings\pbmp3\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = [url]www.google.com[/url]
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
O2 - BHO: (no name) - {FA93E44F-B026-4E28-89BF-33986035EFAD} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - [url]http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab[/url]
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - [url]http://download.games.yahoo.com/games/popcap/zuma/popcaploader_v6.cab[/url]
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe …
dvr 0 Junior Poster
yeah I tried that already and the files weren't there. but everytime I reboot they are back? if I goto my processes there are three CLI.exe files running if I end them then those files disappear. I just want to make sure this isn't one of those new trojans out now.
dvr 0 Junior Poster
xp crashed and I found these files after reboot in my temp folder and cannot delete them. it says they are being used by another user or program.
Perflib_Perfdata_1a8.dat
Perflib_Perfdata_c68.dat
Perflib_Perfdata_c5c.dat
Perflib_Perfdata_a74.dat
dvr 0 Junior Poster
I am looking for a free parental control for win xp for a lady at my work.
I just finished building her new pc and she is looking for a parental control for her kids, to block unwanted sites. is there a good free one or should she just go and by one or is there a way to have XP home block stuff? I don't have kids and never looked for stuff like this before.
thanks in advanced
dvr 0 Junior Poster
when I open word and excel they both have errors. this is a fresh install on a laptop( a dell latitude).with windows 2000.
ok word comes with this error "compile error in hidden module AutoExec"
and when you close it it has the same error.
on excel it says "compile error in hidden module AutoExecNew" when you start the program and when you close it says "compile error in hidden module Distmon"
what can I do to stop this?
dvr 0 Junior Poster
new hijackthis log after above fixes you gave me
Logfile of HijackThis v1.99.1
Scan saved at 12:17:29 AM, on 8/20/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\pbmp3\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = www.google.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {FA93E44F-B026-4E28-89BF-33986035EFAD} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program …
dvr 0 Junior Poster
ok its long here it is
WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.
If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.
»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows 2000 Current Build: Service Pack 4 Current Build Number: 2195
Internet Explorer Version: 5.00.3700.1000
»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»
Checking %SystemDrive% folder...
Checking %ProgramFilesDir% folder...
Checking %WinDir% folder...
Checking %System% folder...
Umonitor 6/19/2003 1:05:04 PM 529168 C:\WINNT\SYSTEM32\RASDLG.DLL
winsync 5/8/2001 8:00:00 AM 1309184 C:\WINNT\SYSTEM32\wbdbase.deu
UPX! 1/9/2005 1:37:44 AM 65536 C:\WINNT\SYSTEM32\wined.dll
Checking %System%\Drivers folder and sub-folders...
UPX! 7/24/2005 12:52:54 AM 668704 C:\WINNT\SYSTEM32\drivers\avg7core.sys
FSG! 7/24/2005 12:52:54 AM 668704 C:\WINNT\SYSTEM32\drivers\avg7core.sys
aspack 7/24/2005 12:52:54 AM 668704 C:\WINNT\SYSTEM32\drivers\avg7core.sys
Items found in C:\WINNT\SYSTEM32\drivers\etc\hosts
Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
H 8/13/2005 2:16:28 PM 920876 C:\WINNT\ShellIconCache
H 8/7/2005 10:00:58 AM 2015744 C:\WINNT\w74ca5e40.tmp
S 8/13/2005 5:16:38 PM 64 C:\WINNT\CSC\00000001
S 8/13/2005 2:08:58 PM 64 C:\WINNT\CSC\00000002
S 8/13/2005 1:06:36 AM 64 C:\WINNT\CSC\csc1.tmp
SH 7/30/2005 2:53:36 PM 10022 C:\WINNT\system32\KGyGaAvL.sys
H 8/13/2005 5:16:40 PM 890 C:\WINNT\system32\vsconfig.xml
H 7/13/2005 10:35:32 PM 4212 C:\WINNT\system32\zllictbl.dat
H 8/13/2005 5:18:14 PM 1024 C:\WINNT\system32\config\default.LOG
H 8/13/2005 5:16:38 PM 1024 C:\WINNT\system32\config\SAM.LOG
H 8/13/2005 5:17:22 PM 1024 C:\WINNT\system32\config\SECURITY.LOG
H 8/13/2005 5:21:50 PM 1024 C:\WINNT\system32\config\software.LOG
H 8/13/2005 5:16:26 PM 6 C:\WINNT\Tasks\SA.DAT
Checking for CPL …
dvr 0 Junior Poster
here is the new log sorry for the old one.
I also scanned with the panda one online and it deleted the wininet.dll I couldn't use adaware and spybot and internet explorer. but I fixed that already.
Logfile of HijackThis v1.99.1
Scan saved at 2:11:42 PM, on 8/13/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\pbmp3\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = www.google.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {FA93E44F-B026-4E28-89BF-33986035EFAD} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O15 - Trusted IP range: 206.161.125.149
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AVG7 Alert Manager …
dvr 0 Junior Poster
here is my hijack this logLogfile of HijackThis v1.97.7
Scan saved at 11:45:45 PM, on 8/12/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\pbmp3\Desktop\hijackthis\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {FA93E44F-B026-4E28-89BF-33986035EFAD} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
dvr 0 Junior Poster
I cant get rid of these programs they keep coming back.
I did what swatkat said
Open NotePad, and copy the contents of the below "Quote" box:-
Quote:
cd %windir%
attrib -s -r -h ALCMTR.EXE
del ALCMTR.EXE
cd system32
attrib -s -r -h install32m.exe
attrib -s -r -h intel32.exe
attrib -s -r -h msnethlp32.exe
attrib -s -r -h Oeoepi32.exe
attrib -s -r -h paytime.exe
attrib -s -r -h Lgjopdch.dll
del Lgjopdch.dll
del install32m.exe
del intel32.exe
del Oeoepi32.exe
del msnethlp32.exe
del paytime.exe
Go to File Menu > Save As, and save the file with the name Test.bat and exit from NotePad.
Download Ewido and install it. Then run, you will receive a warning message saying "Database not found", click "OK" for this. Next in the main screen, click "Update" and click "Start Update". After the update process, exit from Ewido.
Download CCleaner and CWShredder.
and then this
Double-Click on the file Test.bat, a small DOS type window should open and close immediately.
Delete this folder ( and all the files inside it ):-
C:\Program Files\PSGuard
Search for this file and delete it:-
msnethlp32.dll
Run CCleaner, click "Options" button and here go to "Settings" tab and uncheck the option "Only delete files in Windows Temp folder older than 48 hours". Click OK to exit from the Options. Finally …
dvr 0 Junior Poster
Download Ewido and install it. click "Update" and click "Start Update". After the update process, exit from Ewido.
Download CCleaner and install it.
Run CCleaner, click "Options" button and here go to "Advanced" tab and uncheck the option "Only delete files in Windows Temp folder older than 48 hours". Click OK to exit from the Options. click "Run Cleaner" and choose "Yes" to continue cleaning.
Run Ewido, click on the "Scanner" button in the left menu, then click on the "Start" button.
If ewido finds anything, it will pop up a notification. select "Clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
also you can download AVG antivirus it is free and updates are free as well.
personally I think its better than norton and mcaffee it finds viruses that they don't.
dvr 0 Junior Poster
where are you MartyMcFly I need your help here.
dvr 0 Junior Poster
sounds like your power supply. when you plug it in do you hear anything sometimes a fan will start for a split second.