Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Thorough Scan Disc


  • Please log in to reply

#1
Joan A

Joan A

    Member

  • Member
  • PipPip
  • 48 posts
I have Win98SE and usually run scan disc and defrag once a month. I also have AVG Free, AdAware and Spybot which I run weekly. Lately, I've noticed that the hard drive is always 'working'. Last week, a thorough scan disc took over 48 hours (the contents kept changing, so it kept restarting) and it found no errors. Yesterday, I did a regular scan disc and defrag, which took the normal time, but a through scan disc was taking forever, so I restarted in safe mode and did a thorough scan disc. After 8 hours of "contents changed, restarting", I stopped it.

I have just run Cleanup, updated AdAware and Spybot then ran them, nothing was found. Ran Shredder, Panda online scan, Trojan Hunter. Updated and run AVG. According to everything, my system is clean. My HiJack this log is below.

Something is running, and I haven't a clue what. Any help will be greatly appreciated.

Logfile of HijackThis v1.99.1
Scan saved at 5:13:00 PM, on 10/4/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ADSUBTRACT\ADSUB.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\NETSCAPE\NETSCAPE\NETSCP.EXE
C:\DOWNLOADS\EXE FILES\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=AdSubtract:4444
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://my.netscape.com"); (C:\Program Files\Netscape\Users\jarbuthnot\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - Startup: AdSubtract.lnk = C:\Program Files\AdSubtract\adsub.exe
O16 - DPF: {8FBFE5FF-5E98-11D3-80AF-00C04FCFBC72} (SurveyCtl35 Class) - http://activex.micro...izards/sw35.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab

Edited by Joan A, 04 October 2005 - 03:28 PM.

  • 0

Advertisements


#2
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
Nothing wrong at first sight in your log.
Before we start digging, one question if I may:

Have you tried doing the ScanDisc in safe mode?

If not try that please and let us know how it goes.

Regards,
  • 0

#3
Joan A

Joan A

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
Metallica

Glad to know all looks ok. As I said in my post above, the last try with scan disc was in safe mode and I stopped it after 8 hours.

Joan A
  • 0

#4
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
Oops I missed that part about safe mode. :tazz:

Can you make a HijackThis log in safe mode so I can see what's running?

Regards,
  • 0

#5
Joan A

Joan A

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
Pieter

Here it is in safe mode

Logfile of HijackThis v1.99.1
Scan saved at 11:51:06 AM, on 10/8/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\DOWNLOADS\EXE FILES\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://my.netscape.com"); (C:\Program Files\Netscape\Users\jarbuthnot\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - Startup: AdSubtract.lnk = C:\Program Files\AdSubtract\adsub.exe
O16 - DPF: {8FBFE5FF-5E98-11D3-80AF-00C04FCFBC72} (SurveyCtl35 Class) - http://activex.micro...izards/sw35.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab

Joan A
  • 0

#6
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
That isn't much and should not be the cause.

Two thing you can try.

- In safe mode) use the DiskCleanup Tool to empty all your Temp folders. Also get rid of everything else you don't need anymore.

- Download SmartClose here: http://i.domaindlx.c...close/index.htm
Read the description before using it.

Regards,
  • 0

#7
Joan A

Joan A

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
Pieter

Did Disc Cleanup and it didn't find much.

Got SmartClose and found out it won't operate in Safe Mode. Eventually got it running and had it stop everything but Zone Alarm (I'm on wireless, so didn't want to disable that). Then tried scan disc in normal mode and got "contents changing, restarting" for both standard and thorough modes. Now what? Should I really address this in another forum?

Really appreciate all your help.

Joan A

Edited by Joan A, 09 October 2005 - 12:50 PM.

  • 0

#8
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
Hi Joan,

You may indeed get better help posting a follow-up in the Windows 98 forums:
http://www.geekstogo...5-98-ME-f3.html

If you want to link to this topic for background information, you can use this link:
http://www.geekstogo...showtopic=68475

rEGARDS,
  • 0

#9
Joan A

Joan A

    Member

  • Topic Starter
  • Member
  • PipPip
  • 48 posts
Pieter

Will do. Thanks for the help.

Joan A
  • 0

#10
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 33,101 posts
No problem. :tazz:

Let me know if you think I can be of assistance.

Regards,
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP