Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Now this is very strange....drive and file I've never seen before.

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU
 
woo me with science Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Aug-14-10 11:58 AM
Original message
Now this is very strange....drive and file I've never seen before.
Can anyone explain what might be going on?

Background....The computer started moving very slowly and acting strangely. I ran Superantispyware and Malwarebytes and got rid of a bunch of cookies but that's all. Hijack This and Combofix only deleted an instant messaging program.

Still slow.

I went to All Programs - Accessories - System Tools - Defragmenter and saw a drive I have never seen before. In addition to my main C drive, there was a "B" drive listed as a floppy drive. I explored, and there was an executable on it, password(something).exe.

I am kicking myself for not remembering the name exactly, but it was something like passwordmanagement.exe or passwordcontrol.exe. I didn't write it down, because I thought I could go back and look at it again.

Then I had to do some other things and got distracted.

When I got back to the computer, I forgot all about the B drive and program. I got busy doing Ccleaner scans, including their registry fix. The computer was still going slow but I thought it seemed a tiny bit better.

I convinced myself without evidence that I was dealing with drive issues and not malware, so I put in my operating system CD and did a repair of the existing Windows installation. I am not talking about Recovery Console or the full reinstall. I did the option where you get new system files but don't lose your documents or programs. When it finished I had Service Pack 2 instead of Service Pack 3, and I had to download a bunch of old security updates again. It hung reinstalling SP3, so I am still on SP2 as I type.

I thought having Service Pack 2 automatically after the repair was strange, because the last time I used the "repair an existing Windows installation" option, it made me reinstall Service Pack 2 during the process from a disk. So the process was slightly different than I remembered it.

The computer was still acting slow, but better than at the outset.

Then I remembered about the B drive and tried to go back to look at the program again. However, when I go to All Programs - Accessories - System Tools _Defrag now, I get a message that "MMC cannot open the file...This may be because the file does not exist, is not an MMC console, or was created by a later version of MMC. This may also be because you do not have sufficient access rights to the file."

I can get into the defragmenter by another route: Control Panel - Administrative Tools - Computer Management. However, when I open it, it doesn't show any B drive at all anymore, only the C.

I can't open Local Security Policy. I receive the same error message about MMC that I get when I try to open Defrag from the Start menu.

Finally, please humor my paranoia for this last question. The other thing I noticed is that when I open Computer Management -Shared Folders - Shares and click on the Admin$, C$ or IPC$ entries, I get a message that the share permissions and security cannot be set, and there are comments inside about "remote admin" and "remote IPC." My computer is set to disallow file sharing, so I would just like reassurance that these are normal entries.


So anyway....I think I will end up reinstalling my OS from scratch. But I am wondering what the heck was this B drive I saw with a password program, and why don't I see it anymore? Did it disappear because I did the Windows Repair, or is this something more sinister and it's just not visible opening from somewhere else? When I click on My Computer, there is no sign of any B floppy drive, and I don't remember EVER having seen it before.

Also, why am I unable to open Defrag from the Start Menu, or Security Policies from anywhere?

My fear has to do with a quick Google search I did on some strange log entries in my event log ("A provider, RSOP Planning Mode Provider has been registered in the WMI namespace...to be run using the LocalSystem account." There were similar entries for Providers named "OffProv11" and "CMDTRiggerConsumer." The Google search led me to very scary pages talking about rootkits that may stay on the computer even after reinstallation by using a partition to reinfect the computer. Do I have to worry about this given the mysterious B drive I saw????


Does any of this make any sense? Can anyone give some insight? I don't want to do a clean reinstall until I have figured out if there is something else (like finding and cleaning a partition) that I need to do first.

Thanks in advance for any help or advice you can give.
Refresh | 0 Recommendations Printer Friendly | Permalink | Reply | Top
blogslut Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Aug-14-10 01:44 PM
Response to Original message
1. Hell if I know
I hate to admit this but Microsoft Security Essentials is a fairly decent anti-virus checker/killer as well as firewall and anti-spyware suite:

http://www.microsoft.com/security_essentials/

If that doesn't fix things, and you have an OS install disk, back up important files to removable media, wipe the drive and re-install. Here's a great program for zapping everything:

http://www.killdisk.com/

When you re-install Windows the software partitions the drive for you. The default settings are usually just fine.

Good luck.
Printer Friendly | Permalink | Reply | Top
 
woo me with science Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Aug-15-10 07:14 AM
Response to Reply #1
2. Thank you.
If anyone is surveilling me, they will be sorely disappointed at how boring my life actually is.
Printer Friendly | Permalink | Reply | Top
 
canetoad Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Aug-15-10 01:47 PM
Response to Reply #2
3. Quick question, wmws
Did you download a weight loss hypnosis CD?

Have a look at this http://www.download3k.com/Antivirus-Report-Hypnosis-CD-Weight-Loss.html
I wonder if it mounts the CD on a virtual drive of it's own creation. :shrug:
Printer Friendly | Permalink | Reply | Top
 
woo me with science Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Aug-15-10 10:44 PM
Response to Reply #3
5. No, I didn't, but
it's a refurbished computer. I wonder if something like that could survive a reformat?

Thank you very much. Maybe this will give me some ideas about what to do next.
Printer Friendly | Permalink | Reply | Top
 
struggle4progress Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Aug-15-10 02:27 PM
Response to Original message
4. You might try googling: "Password*.exe" (with quotes and *)
See if anything looks familiar

Printer Friendly | Permalink | Reply | Top
 
woo me with science Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Aug-15-10 10:46 PM
Response to Reply #4
6. Thanks for the idea. nt
Printer Friendly | Permalink | Reply | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu May 02nd 2024, 05:59 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC