Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Another Ctrl>Alt>Del issue


  • Please log in to reply

#1
vsalzman

vsalzman

    Member

  • Member
  • PipPip
  • 37 posts
I've posted this issue before with the instructions to try everything in all other posts....I have done that several time....yes, EVERYTHING! Including the Brute Force Uninstaller suggested by "Metallica" with no luck what so ever. I have tried running registry cleaners as well. I have this issue on five PCs, all running Win2k. I am desperate, does anyone have ANY other suggestions? Below is the latest HJT log from one of the PCs and all others are exactly the same. Thanks.

Logfile of HijackThis v1.99.1
Scan saved at 2:17:19 PM, on 9/12/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Lanovation\PrismXL\ChannelDeploy.sys
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\ePOAgent\naimas32.exe
c:\oracle\Ora92\bin\omtsreco.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\SOUNDMAN3D.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\VERITAS\Backup Exec\RANT\beremote.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Prism Deploy\Client\PTClient.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ePOAgent\naimag32.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\explorer.exe
C:\HIjackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.isgs.uiuc.edu/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Prism Deploy Client] "C:\Program Files\Prism Deploy\Client\PTClient.exe" /Subscriber
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NaimAgent_UI] C:\Program Files\ePOAgent\naimag32.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = isgs.uiuc.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{0424F1AB-A0AB-405D-A3DE-0E3494262935}: NameServer = 128.174.175.102,128.174.175.115,128.174.5.102
O17 - HKLM\System\CCS\Services\Tcpip\..\{0A61313B-B99B-47F6-A7F3-42B0441FA624}: NameServer = 128.174.175.102,128.174.175.115,128.174.5.102
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D60FB7F-38A2-45E0-857B-ABC447EC0B2F}: NameServer = 128.174.185.102,128.174.175.115,128.174.5.102
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = isgs.uiuc.edu
O17 - HKLM\System\CS1\Services\Tcpip\..\{0424F1AB-A0AB-405D-A3DE-0E3494262935}: NameServer = 128.174.175.102,128.174.175.115,128.174.5.102
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = isgs.uiuc.edu
O17 - HKLM\System\CS2\Services\Tcpip\..\{0424F1AB-A0AB-405D-A3DE-0E3494262935}: NameServer = 128.174.175.102,128.174.175.115,128.174.5.102
O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerator) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\RANT\beremote.exe
O23 - Service: Channel Deployer - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\ChannelDeploy.sys
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NAI ePolicy Orchestrator Agent (NAIMAGENT32) - Network Associates, Inc. - C:\Program Files\ePOAgent\naimas32.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - c:\oracle\Ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome81ClientCache - Unknown owner - C:\Oracle\Ora81\BIN\ONRSD.EXE
O23 - Service: OracleOraHome92ClientCache - Unknown owner - c:\oracle\Ora92\BIN\ONRSD.EXE
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: 3D Sound (SoundDrv) - Unknown owner - C:\WINNT\SOUNDMAN3D.exe
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP