Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

MSN Virus, Cannot access Task Manager


  • Please log in to reply

#1
Akanah Pell

Akanah Pell

    New Member

  • Member
  • Pip
  • 7 posts
I did something stupid and I opened a file over my Messenger and it gave me a virus. I quickly closed the program and went to my task manager, but I can't access it. I can't click on the button because it's not highlighted. I ran a few virus scans and anti-spyware programs and it came up with nothing, yet this stupid virus will keep messaging everyone on my contact list every 5 mins. I don't know how to find out what the .exe file is that is the virus so I can delete it if I can't open my task manager! I've also tried to see if working in safe mode changes anything, but it doesn't. HELP!!!

Logfile of HijackThis v1.99.1
Scan saved at 8:29:22 AM, on 5/1/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\msnisjeeet21.exe
C:\WINNT\system32\atiptaxx.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\system32\mskev.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINNT\system32\mskev.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\My Documents\My Received Files\HijackThis.exe

R3 - Default URLSearchHook is missing
F3 - REG:win.ini: load=C:\\msnisjeeet21.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Lysqhzma] C:\Program Files\Vuabk\Dllzb.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Windows kev Messenger] mskev.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunServices: [Windows kev Messenger] mskev.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] \WkDetect.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
O4 - HKCU\..\Run: [Windows kev Messenger] mskev.exe
O4 - HKCU\..\RunServices: [Windows kev Messenger] mskev.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z....iTunesSetup.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} - http://www.ysbweb.co...ysb_1002245.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zone...ctor/WebAAS.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?326
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

Edited by Akanah Pell, 01 May 2005 - 09:29 AM.

  • 0

Advertisements


#2
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Hey there Akanah Pell and Welcome to G2G!!!

Lets see cant we get a handle on this bugger!!!

Open HijackThis and put a check by these but DO NOT hit the Fix Checked button yet!

R3 - Default URLSearchHook is missing

F3 - REG:win.ini: load=C:\\msnisjeeet21.exe

O4 - HKLM\..\Run: [Lysqhzma] C:\Program Files\Vuabk\Dllzb.exe<< Unless you know where this came from!

O4 - HKLM\..\Run: [Windows kev Messenger] mskev.exe

O4 - HKLM\..\RunServices: [Windows kev Messenger] mskev.exe

O4 - HKCU\..\Run: [Windows kev Messenger] mskev.exe

O4 - HKCU\..\RunServices: [Windows kev Messenger] mskev.exe

O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} - http://www.ysbweb.co...ysb_1002245.cab

O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) -

O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx

O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab

O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab

O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?326

Now Make sure ALL WINDOWS and BROWSERS are CLOSED and hit the Fix Checked Button!!

Reboot into SAFE MODE(Tap F8 when restarting)
Here is a link on how to boot into Safe Mode:
http://service1.syma...src=sec_doc_nam

After restarting in Safe Mode,Configure Windows to Show All Hidden Files and Folders,this must be done after restarting in Safe Mode!!
Here is a link to help with that:
http://www.bleepingc...showtutorial=62

Locate and Delete:

C:\msnisjeeet21.exe<< File Only!

C:\WINNT\system32\mskev.exeC:\Program Files\Vuabk

C:\Program Files\Vuabk<< The Entire Vuabk Folder,unless you know where this came from!
If that folder will not delete,open it up and Remove every file and folder until it is empty,then delete the folder!

Please keep a list of any files\folder that you could not locate or could not delete,I will need that info in the next post!

Still in Safe Mode,Run MSCONFIG and enable everything in the startup area. To get to MSCONFIG, click on Start -> Run -> type in MSCONFIG -> click OK!

Make Sure Normal Startup is Checked!!

Select the tab labeled Startup and put a Check by every box there!!

Click Apply>>OK>>Follow the Prompts to Restart!!

Once Restart in Normal Mode and Using Internet Explorer Only,Have the PC Scanned here:
http://www.pandasoft...n_principal.htm

Save the Report from that Scan and Post it with a fresh HijackThis log!!
  • 0

#3
Akanah Pell

Akanah Pell

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
When I looked for "C:\Program Files\Vuabk" it wasn't there. and when I tried to run MSCONFIG it said that it cannot find the file!

I'm still not able to access my task manager. Geez what a pain. Thanks for helping me, I really appreciate it!

Logfile of HijackThis v1.99.1
Scan saved at 12:06:13 PM, on 5/1/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\atiptaxx.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\My Documents\My Received Files\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [Microsoft Works Update Detection] \WkDetect.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z....iTunesSetup.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
  • 0

#4
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Lets see what the Scan from Panda reveals!!!

Exactly how do you access the Task Manager?
  • 0

#5
Akanah Pell

Akanah Pell

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
I access my task Manager by pressing CTRL+ALT+DELETE

This is what the Panda Scan came up with:
Incident Status Location
Adware:Adware/nCase No disinfected C:\WINNT\msbb*

Spyware:Spyware/Dyfuca No disinfected Windows Registry

Spyware:Spyware/ISTbar No disinfected C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Shortcuts.txt

Adware:Adware/PowerScan No disinfected Windows Registry

Virus:W32/Gaobot.batch Disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\r.bat
Adware:Adware/nCase No disinfected C:\WINNT\msbb.exe Virus:W32/Gaobot.batch Disinfected C:\WINNT\Temp\r.bat

And even after that, I STILL can't open my task manager!

Edited by Akanah Pell, 01 May 2005 - 10:44 PM.

  • 0

#6
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
OK,lets download 2 Temp File Cleaning Utilities:

CCleaner:
http://www.filehippo...d_ccleaner.html
This is to help keep those Temporary Files Cleaned Up,all you will want to use on this is the Opening Page(Windows Tab)Just Click Run Cleaner and let it do its thing!

CleanUp! 4.0:
http://cleanup.stevengould.org/
Just Scroll through the Page and locate this Line:
So download CleanUp! now and reap the benefits of a clean machine.
If that Link doesnt work,just go to Google.com and Search for CleanUp!
It should be the First Return!!
Once Installed,Open and Click CleanUp! and When Prompted to Log Off,do so!

When Cleanup prompts you to Log off,just restart in Safe mode!

In Safe Mode,locate and delete:

C:\WINNT\msbb.exe<< File only!

C:\Documents and Settings\Administrator\Local Settings\Temp\Shortcuts.txt<< Make sure that is gone and that Temp folder is empty!

C:\Documents and Settings\Administrator\Local Settings\Temp\r.bat << Make sure that is gone and that Temp folder is empty!

C:\WINNT\Temp\r.bat << Make sure that is gone and that Temp folder is empty!

Once Complete,Restart Normal and Right Click the Taskbar near the Clock,See if the Task Manager Selection is available,is so,click it and see if the Task Manager opens!!

Post back and let me know how it goes!
  • 0

#7
Akanah Pell

Akanah Pell

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Sorry it took me a while to post back, it's been a hectic week!

I did everything you suggested. The virus is gone, but I'm still not able to access my task manager. I guess the virus deleted an important file for me to access it. At least the virus is gone and my hard drive is all clean! Thanks again for you help! But I don't have a clue as to how to open my task manager.
  • 0

#8
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
OK,please go to C:\WINNT\system32

Once there,locate all Instances of Taskmgr and Taskman,post back and tell me what you find!!!

Please Download F-Secure Blacklight:
http://www.f-secure....light/try.shtml
Please download this to the same folder HijackThis is in!!

Once at the page,Click "I Accept"

Then Click Download,which sits right under "Graphical user interface version:"

Once Downloaded,Double Click blbeta.exe to Start it,then Click "I accept the agreement" and click "Next"

Now Click "Expert Mode" and then"Scan" and let it do its thing,if it finds anything,it will automatically tell you and go to Step 2 to begin the cleaning process,if not post back and let me know ASAP!!


If all went well,look back in the folder that blbeta.exe resides in,there you should see "fsbl.log"

If Blacklight identified anything,it will be in that log,I will need to see those Results!

Once all is complete,post both logs back here!!
  • 0

#9
Akanah Pell

Akanah Pell

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Ok, so I checked my C:\WINNT\system32 file folder and found taskman.exe and taskmgr, but when I clicked on taskmgr, it says it has been disabled by the administrator, but I didn't. I hove no idea how to undo that either.
Then I did the blacklight scan and it said there were no hidden files:

05/07/05 08:51:27 [Info]: *** F-Secure BlackLight Beta 1.4.1003 started
05/07/05 08:51:27 [Info]: OS version: 5.0 build 2195 (Service Pack 4)
05/07/05 08:51:34 [Info]: User initiated system scan
05/07/05 08:51:34 [Info]: Process scan started
05/07/05 08:51:35 [Info]: Process scan done
05/07/05 08:51:35 [Info]: Filesystem scan started
05/07/05 08:51:35 [Info]: Filesystem scan engine version: 1.7 (build 1006)
05/07/05 08:51:35 [Note]: Running expert mode scan
05/07/05 08:51:35 [Info]: Scanning drive C:\
05/07/05 08:51:36 [Note]: FS type NTFS
05/07/05 08:53:46 [Info]: Done scanning drive C:\
05/07/05 08:53:46 [Info]: Filesystem scan completed
05/07/05 08:55:35 [Info]: *** F-Secure BlackLight Beta 1.4.1003 stopped

Pretty frustrating!
  • 0

#10
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Allright,thats what I needed to know!!!

I will post back as soon as I gather the info for the Taskmanager!!
  • 0

#11
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
See if these 2 links dont help ya out!!!

http://www.windowsne...indows2000.html

http://www.infopacke...2000_and_xp.htm

Please let me know what you find out!!!
  • 0

#12
Akanah Pell

Akanah Pell

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
YAY!!!! It worked!!! The second link really helped. I really appreciate all the help you've given me! This one was a frustrating one. Thanks again!
  • 0

#13
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Sorry for the delay bud,but work carried me out of town for a week!!

Glas to hear that something worked,Update me,how is the PC acting?
  • 0

#14
Akanah Pell

Akanah Pell

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
My computer is running great except for the fact that it needs more hard drive space and ram, but hey, it's the best I can do for now! Once I get the funds, this will all be remedied! Thank you again for your help!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP