PDA

View Full Version : Windows 2000 Professional problem?


ditmx6
07-12-2002, 09:19 PM
Hi I'm having a problem with my Windows 2000 Professional computer. It used to be that when I started my computer up (or rebooted) that my firewall (Zonealarm Pro) and my virus detection software (AVG) would automatically start up. This had worked fine for about 2 months or so. Anyway now when I start up the computer or even try to start those two programs manually they try to start but do not last more then a few seconds. I can see the icons in the system tray right after I manually try to start them but a few seconds later they dissapear. I also checked in the task manager and was not able to see the proscesses listed running after the icons dissapeared in the system tray. Any help would be greatly appreciated.

Thanks,
ditmx6

ditmx6
07-12-2002, 09:49 PM
One other thing that I forgot to mention. I ran a complete test to see if there were any viruses with the AVG program and found none. Also in the Event Viewer I have the following errors:

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 7/12/2002
Time: 8:22:29 PM
User: N/A
Computer: MASTERPC
Description:
The ASCTRM service failed to start due to the following error:
The system cannot find the file specified.

and

Event Type: Error
Event Source: True Vector Engine
Event Category: None
Event ID: 1
Date: 7/12/2002
Time: 10:38:03 AM
User: N/A
Computer: MASTERPC
Description:
The description for Event ID ( 1 ) in Source ( True Vector Engine ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The following information is part of the event: .
Data:
0000: 44 61 74 61 62 61 73 65 Database
0008: 20 66 69 6c 65 20 43 3a file C:
0010: 5c 57 49 4e 44 4f 57 53 \WINDOWS
0018: 5c 49 6e 74 65 72 6e 65 \Interne
0020: 74 20 4c 6f 67 73 5c 49 t Logs\I
0028: 41 4d 44 42 2e 52 44 42 AMDB.RDB
0030: 20 77 61 73 20 69 6d 70 was imp
0038: 72 6f 70 65 72 6c 79 20 roperly
0040: 73 68 75 74 20 64 6f 77 shut dow
0048: 6e 2e 20 20 52 65 73 74 n. Rest
0050: 6f 72 69 6e 67 20 62 61 oring ba
0058: 63 6b 75 70 20 72 75 6c ckup rul
0060: 65 73 20 64 61 74 61 62 es datab
0068: 61 73 65 3a 20 43 3a 5c ase: C:\
0070: 57 49 4e 44 4f 57 53 5c WINDOWS\
0078: 49 6e 74 65 72 6e 65 74 Internet
0080: 20 4c 6f 67 73 5c 42 41 Logs\BA
0088: 43 4b 55 50 2e 52 44 42 CKUP.RDB
0090: 00 .

The first error was in the System log and the second was in the Application log.

Hope this helps,
ditmx6

iisbob
07-13-2002, 01:56 AM
try re-installing the application's, sounds like they've become corrupted.

ditmx6
07-13-2002, 07:34 AM
Just so everyone knows the problem that I had was actually caused by some kind of trojan called Net Devil. I think that I got it from a file that I downloaded from Kazaa. The program that controlled the virus was called NETAPI.EXE. The way that I found out about this is because my firewall asked me if I wanted to allow NETAPI.EXE to access some unknown ip address. I then denied it and then it terminated my firewall. I then went into my task manager in the processes section, and found that the NETAPI.EXE process was running. Then after searching the internet (Google) for NETAPI.EXE, I found a website that contained information about this trojan. They actually have a website designed to distribute this trojan. It allows hackers to remotely controll your computer (similar to PCANYWHERE). On the site it has screen shots of their victims desktops (which they refer to as vics on their message boards). After going through the site I finally started to search my hard drive for NETAPI.EXE. I found it in my system or system32 folder ( I can't remember which). I then deleted it and searched the registry for the same string. I then came across a key that contained the NETAPI name which I deleted. After deleting these files I rebooted and have been fine since. No more errors during boot up or anytime after. Please note that the trojan is called NETAPI.EXE not Netapa32.dll or anything else that ends with the .dll extension. I think that those files are supposed to be in the system and system32 files. Anyway this virus actually would cause my firewall and my virus detector to fail during their initialization. Spread the word. This could become a big problem.

ditmx6

Paul Komski
07-13-2002, 09:20 AM
I suspect the problem lies with Kazaa and not with NetDevil/NETAPI.EXE per se.

Usability and privacy: a study of Kazaa P2P file-sharing (http://www.hpl.hp.com/techreports/2002/HPL-2002-163.html)

"By providing several different locations and interfaces to
manage file sharing and not connecting their information,
users are not made aware of what files are being offered
for others to download and are not able to determine how
to successfully share and stop sharing files." ... is in the conclusion of the full abstract (http://www.hpl.hp.com/techreports/2002/HPL-2002-163.pdf).