KB890830

G

Guest

I downloaded the KB890830 (Malicious Tool) Critical Update tonight and when I
did the RUN "for notepage %windir%\debug\mrt.log," I got the following:
===================================
Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Tue Jun 12 19:24:35 2007
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:464 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:128 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Tue Jun 12
19:25:38 2007
=========================================
I manually went to: Winint/system32/mrt.exe
and clicked on that and it only stated: "No malicious software was detected."

(Last month I had approximately the same results, which were:
May 2007 Microsoft Windows Malicious Software Removal Tool v1.29, May 2007
Started On Tue May 08 19:57:36 2007
->Scan ERROR: resource process://pid:976 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
Results Summary: ---------------- No infection found.
Return code: 0 Microsoft Windows Malicious Software Removal Tool Finished
On Tue May 08 19:58:34 2007 -

I posted a similar note last month, but actually forgot about the answers
until this recent download.)
============================
I don't notice any problems while running my laptop (WinXPsp2/IE6/AOL9 VR)
and wonder if these "Scan Errors" are very, very dangerous? I really can't
afford to buy another computer.
Can anyone help please?
Alice
 
M

MowGreen [MVP]

Those errors may be related to the 'Iomega Activity Disk2'
To determine if that's the case, disconnect it from the system and then
manually start the MRT by going to Start > Run > and type in

mrt.exe

Click OK or press Enter
The Malicious Software Removal Tool window will appear
It should show June 2007 at the very top
If so, click Next
Put a tick next to ' Full scan '
Click Next
When the scan is done a new page will open with the result

If nothing is detected then open the mrt.log once more.
Do the errors still appear ?

As stated in the prior thread covering this :

Windows Error 0x0000054F - 1359
The security account database contains an internal inconsistency.
ERROR_INTERNAL_ERROR

To determine just which programs are pid 212, 464, and 128 are, you can
download and SAVE Process Explorer :
http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/ProcessExplorer.mspx

*Instructions for it's use are on that web page*
The download is in a .zip format
You MUST first extract or decompress the .zip file
Suggest you do so to the My Documents folder

There IS one more error showing in this log then the one you posted last
month and the PIDs differ. That is not a good sign. The MRT does not
target all malware and the system *may* be compromised.

If this is too difficult, then STRONGLY SUGGEST you either bring the
system to a reputable PC tech or have a technically adept acquaintance
check it.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============
 
G

Guest

Thanks for the help. I did run the full scan and nothing was detected.
I looked at the log and it did show different PIDs = 168 and 440. I then
opened the Process Explorer and saw that both were related to:
168 vsmon.exe True Vector Service Zone Labs
440 zlclient.exe True Vector Service Zone Labs

The previous PIDs were not listed (but think maybe they were also related to
ZA.)

I am using ZoneAlarm, and wonder if ZA is causing these "scan ERRORs."
I ran AdAware and nothing showing. I am hoping my computer is not
"compromised."

Living on small monthly income and, as I said, cannot afford any unnecessary
expenses.

Alice



=================
MowGreen said:
Those errors may be related to the 'Iomega Activity Disk2'
To determine if that's the case, disconnect it from the system and then
manually start the MRT by going to Start > Run > and type in

mrt.exe

Click OK or press Enter
The Malicious Software Removal Tool window will appear
It should show June 2007 at the very top
If so, click Next
Put a tick next to ' Full scan '
Click Next
When the scan is done a new page will open with the result

If nothing is detected then open the mrt.log once more.
Do the errors still appear ?

As stated in the prior thread covering this :

Windows Error 0x0000054F - 1359
The security account database contains an internal inconsistency.
ERROR_INTERNAL_ERROR

To determine just which programs are pid 212, 464, and 128 are, you can
download and SAVE Process Explorer :
http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/ProcessExplorer.mspx

*Instructions for it's use are on that web page*
The download is in a .zip format
You MUST first extract or decompress the .zip file
Suggest you do so to the My Documents folder

There IS one more error showing in this log then the one you posted last
month and the PIDs differ. That is not a good sign. The MRT does not
target all malware and the system *may* be compromised.

If this is too difficult, then STRONGLY SUGGEST you either bring the
system to a reputable PC tech or have a technically adept acquaintance
check it.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============


I downloaded the KB890830 (Malicious Tool) Critical Update tonight and when I
did the RUN "for notepage %windir%\debug\mrt.log," I got the following:
===================================
Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Tue Jun 12 19:24:35 2007
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:464 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:128 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Tue Jun 12
19:25:38 2007
=========================================
I manually went to: Winint/system32/mrt.exe
and clicked on that and it only stated: "No malicious software was detected."

(Last month I had approximately the same results, which were:
May 2007 Microsoft Windows Malicious Software Removal Tool v1.29, May 2007
Started On Tue May 08 19:57:36 2007
->Scan ERROR: resource process://pid:976 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
Results Summary: ---------------- No infection found.
Return code: 0 Microsoft Windows Malicious Software Removal Tool Finished
On Tue May 08 19:58:34 2007 -

I posted a similar note last month, but actually forgot about the answers
until this recent download.)
============================
I don't notice any problems while running my laptop (WinXPsp2/IE6/AOL9 VR)
and wonder if these "Scan Errors" are very, very dangerous? I really can't
afford to buy another computer.
Can anyone help please?
Alice
 
G

Guest

Just an add-on to my previous post. My son just paid a visit and brought
along a sheet of paper he printed out after he ran the Kb890830 Malicious
tool on his computer and then looking at the mrt.log. This is what he shows
(all of the pid refer to Symantec (Norton), which he has on his computer.
Does anyone know what is going on?...


---------------------------------------------------------------------------------------

Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Wed Jun 13 21:49:40 2007
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2504 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Wed Jun 13
21:50:26 2007




AliceZ said:
Thanks for the help. I did run the full scan and nothing was detected.
I looked at the log and it did show different PIDs = 168 and 440. I then
opened the Process Explorer and saw that both were related to:
168 vsmon.exe True Vector Service Zone Labs
440 zlclient.exe True Vector Service Zone Labs

The previous PIDs were not listed (but think maybe they were also related to
ZA.)

I am using ZoneAlarm, and wonder if ZA is causing these "scan ERRORs."
I ran AdAware and nothing showing. I am hoping my computer is not
"compromised."

Living on small monthly income and, as I said, cannot afford any unnecessary
expenses.

Alice



=================
MowGreen said:
Those errors may be related to the 'Iomega Activity Disk2'
To determine if that's the case, disconnect it from the system and then
manually start the MRT by going to Start > Run > and type in

mrt.exe

Click OK or press Enter
The Malicious Software Removal Tool window will appear
It should show June 2007 at the very top
If so, click Next
Put a tick next to ' Full scan '
Click Next
When the scan is done a new page will open with the result

If nothing is detected then open the mrt.log once more.
Do the errors still appear ?

As stated in the prior thread covering this :

Windows Error 0x0000054F - 1359
The security account database contains an internal inconsistency.
ERROR_INTERNAL_ERROR

To determine just which programs are pid 212, 464, and 128 are, you can
download and SAVE Process Explorer :
http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/ProcessExplorer.mspx

*Instructions for it's use are on that web page*
The download is in a .zip format
You MUST first extract or decompress the .zip file
Suggest you do so to the My Documents folder

There IS one more error showing in this log then the one you posted last
month and the PIDs differ. That is not a good sign. The MRT does not
target all malware and the system *may* be compromised.

If this is too difficult, then STRONGLY SUGGEST you either bring the
system to a reputable PC tech or have a technically adept acquaintance
check it.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============


I downloaded the KB890830 (Malicious Tool) Critical Update tonight and when I
did the RUN "for notepage %windir%\debug\mrt.log," I got the following:
===================================
Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Tue Jun 12 19:24:35 2007
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:464 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:128 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Tue Jun 12
19:25:38 2007
=========================================
I manually went to: Winint/system32/mrt.exe
and clicked on that and it only stated: "No malicious software was detected."

(Last month I had approximately the same results, which were:
May 2007 Microsoft Windows Malicious Software Removal Tool v1.29, May 2007
Started On Tue May 08 19:57:36 2007
->Scan ERROR: resource process://pid:976 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
Results Summary: ---------------- No infection found.
Return code: 0 Microsoft Windows Malicious Software Removal Tool Finished
On Tue May 08 19:58:34 2007 -

I posted a similar note last month, but actually forgot about the answers
until this recent download.)
============================
I don't notice any problems while running my laptop (WinXPsp2/IE6/AOL9 VR)
and wonder if these "Scan Errors" are very, very dangerous? I really can't
afford to buy another computer.
Can anyone help please?
Alice
 
M

MowGreen [MVP]

I'd bet that those errors contained in both logs indicate that Symantec
[Norton] and ZoneAlarm are the cause.
For your system you could try Enabling the native XP Firewall from
within the Control Panel and then Disable ZA
Then do a scan with the MRT and check for further errors

Your son can temporarily disable whichever Norton software is installed
by, hopefully, reading the Help file for directions to do so .
If it's a security suite and includes a Firewall then have him Enable
the native XP one before Disabling Norton's.
Then scan with MRT, check for any errors

BTW, one can just type in
mrt
in the Run line, click OK, and it will open.

I'd be curious to see the MRT log with the system booted to Safe Mode.
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx


MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============


Just an add-on to my previous post. My son just paid a visit and brought
along a sheet of paper he printed out after he ran the Kb890830 Malicious
tool on his computer and then looking at the mrt.log. This is what he shows
(all of the pid refer to Symantec (Norton), which he has on his computer.
Does anyone know what is going on?...


---------------------------------------------------------------------------------------

Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Wed Jun 13 21:49:40 2007
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2504 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Wed Jun 13
21:50:26 2007




:

Thanks for the help. I did run the full scan and nothing was detected.
I looked at the log and it did show different PIDs = 168 and 440. I then
opened the Process Explorer and saw that both were related to:
168 vsmon.exe True Vector Service Zone Labs
440 zlclient.exe True Vector Service Zone Labs

The previous PIDs were not listed (but think maybe they were also related to
ZA.)

I am using ZoneAlarm, and wonder if ZA is causing these "scan ERRORs."
I ran AdAware and nothing showing. I am hoping my computer is not
"compromised."

Living on small monthly income and, as I said, cannot afford any unnecessary
expenses.

Alice



=================
:

Those errors may be related to the 'Iomega Activity Disk2'
To determine if that's the case, disconnect it from the system and then
manually start the MRT by going to Start > Run > and type in

mrt.exe

Click OK or press Enter
The Malicious Software Removal Tool window will appear
It should show June 2007 at the very top
If so, click Next
Put a tick next to ' Full scan '
Click Next
When the scan is done a new page will open with the result

If nothing is detected then open the mrt.log once more.
Do the errors still appear ?

As stated in the prior thread covering this :

Windows Error 0x0000054F - 1359
The security account database contains an internal inconsistency.
ERROR_INTERNAL_ERROR

To determine just which programs are pid 212, 464, and 128 are, you can
download and SAVE Process Explorer :
http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/ProcessExplorer.mspx

*Instructions for it's use are on that web page*
The download is in a .zip format
You MUST first extract or decompress the .zip file
Suggest you do so to the My Documents folder

There IS one more error showing in this log then the one you posted last
month and the PIDs differ. That is not a good sign. The MRT does not
target all malware and the system *may* be compromised.

If this is too difficult, then STRONGLY SUGGEST you either bring the
system to a reputable PC tech or have a technically adept acquaintance
check it.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============



AliceZ wrote:


I downloaded the KB890830 (Malicious Tool) Critical Update tonight and when I
did the RUN "for notepage %windir%\debug\mrt.log," I got the following:
===================================
Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Tue Jun 12 19:24:35 2007
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:464 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:128 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Tue Jun 12
19:25:38 2007
=========================================
I manually went to: Winint/system32/mrt.exe
and clicked on that and it only stated: "No malicious software was detected."

(Last month I had approximately the same results, which were:
May 2007 Microsoft Windows Malicious Software Removal Tool v1.29, May 2007
Started On Tue May 08 19:57:36 2007
->Scan ERROR: resource process://pid:976 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
Results Summary: ---------------- No infection found.
Return code: 0 Microsoft Windows Malicious Software Removal Tool Finished
On Tue May 08 19:58:34 2007 -

I posted a similar note last month, but actually forgot about the answers
until this recent download.)
============================
I don't notice any problems while running my laptop (WinXPsp2/IE6/AOL9 VR)
and wonder if these "Scan Errors" are very, very dangerous? I really can't
afford to buy another computer.
Can anyone help please?
Alice
 
G

Guest

Thanks.
Funny thing. My son said he forgot to look at the mrt.log and did a
CCleaner, and when he tried to look at the log (notepad
%\windir%\debug\mrt.log), it said it was not availabe (having been deleted by
CCleaner). When he remembered, he ran the mrt.exe and then looked at the
mrt.log and he saw all those PIDs (error scans) related to NAV.
For an experiment, we went to my neighbor and had them download the KB890830
and when that finished, the mrt.log only said "no infection found." However,
we did a CCleaner on that machine and then tried to look at the mrt.log, it
reported it could not be found (having been deleted by the CCleaner - same as
happned to my son's computer).
When we then ran the mrt.exe and looked at the log (on my neighbor's
computer), it not only reported "no infection found," but also reported the
'identical' PIDs errors that were reported on my son's mrt.log (after he ran
it after the CCleaner deleted original mrt.log).
Does any of this son make sense? It seems that if we look at the log right
after we log off from the web, we get "no infection found." But, if we run
the CCleaner BEFORE looking at the log and then run mrt.exe and look at the
log, it prints all those NAV PIDs.
(By the way the original laptop we used has gone BSOD. I had gotten the BSOD
a few times in the past months, so it wasn't a big surprise. That is the one
with ZA. My son is letting me use his laptop which has NAV.)
Alice
=============
MowGreen said:
I'd bet that those errors contained in both logs indicate that Symantec
[Norton] and ZoneAlarm are the cause.
For your system you could try Enabling the native XP Firewall from
within the Control Panel and then Disable ZA
Then do a scan with the MRT and check for further errors

Your son can temporarily disable whichever Norton software is installed
by, hopefully, reading the Help file for directions to do so .
If it's a security suite and includes a Firewall then have him Enable
the native XP one before Disabling Norton's.
Then scan with MRT, check for any errors

BTW, one can just type in
mrt
in the Run line, click OK, and it will open.

I'd be curious to see the MRT log with the system booted to Safe Mode.
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx


MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============


Just an add-on to my previous post. My son just paid a visit and brought
along a sheet of paper he printed out after he ran the Kb890830 Malicious
tool on his computer and then looking at the mrt.log. This is what he shows
(all of the pid refer to Symantec (Norton), which he has on his computer.
Does anyone know what is going on?...


---------------------------------------------------------------------------------------

Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Wed Jun 13 21:49:40 2007
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2504 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Wed Jun 13
21:50:26 2007




:

Thanks for the help. I did run the full scan and nothing was detected.
I looked at the log and it did show different PIDs = 168 and 440. I then
opened the Process Explorer and saw that both were related to:
168 vsmon.exe True Vector Service Zone Labs
440 zlclient.exe True Vector Service Zone Labs

The previous PIDs were not listed (but think maybe they were also related to
ZA.)

I am using ZoneAlarm, and wonder if ZA is causing these "scan ERRORs."
I ran AdAware and nothing showing. I am hoping my computer is not
"compromised."

Living on small monthly income and, as I said, cannot afford any unnecessary
expenses.

Alice



=================
:


Those errors may be related to the 'Iomega Activity Disk2'
To determine if that's the case, disconnect it from the system and then
manually start the MRT by going to Start > Run > and type in

mrt.exe

Click OK or press Enter
The Malicious Software Removal Tool window will appear
It should show June 2007 at the very top
If so, click Next
Put a tick next to ' Full scan '
Click Next
When the scan is done a new page will open with the result

If nothing is detected then open the mrt.log once more.
Do the errors still appear ?

As stated in the prior thread covering this :

Windows Error 0x0000054F - 1359
The security account database contains an internal inconsistency.
ERROR_INTERNAL_ERROR

To determine just which programs are pid 212, 464, and 128 are, you can
download and SAVE Process Explorer :
http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/ProcessExplorer.mspx

*Instructions for it's use are on that web page*
The download is in a .zip format
You MUST first extract or decompress the .zip file
Suggest you do so to the My Documents folder

There IS one more error showing in this log then the one you posted last
month and the PIDs differ. That is not a good sign. The MRT does not
target all malware and the system *may* be compromised.

If this is too difficult, then STRONGLY SUGGEST you either bring the
system to a reputable PC tech or have a technically adept acquaintance
check it.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============



AliceZ wrote:


I downloaded the KB890830 (Malicious Tool) Critical Update tonight and when I
did the RUN "for notepage %windir%\debug\mrt.log," I got the following:
===================================
Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Tue Jun 12 19:24:35 2007
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:464 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:128 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Tue Jun 12
19:25:38 2007
=========================================
I manually went to: Winint/system32/mrt.exe
and clicked on that and it only stated: "No malicious software was detected."

(Last month I had approximately the same results, which were:
May 2007 Microsoft Windows Malicious Software Removal Tool v1.29, May 2007
Started On Tue May 08 19:57:36 2007
->Scan ERROR: resource process://pid:976 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
Results Summary: ---------------- No infection found.
Return code: 0 Microsoft Windows Malicious Software Removal Tool Finished
On Tue May 08 19:58:34 2007 -

I posted a similar note last month, but actually forgot about the answers
until this recent download.)
============================
I don't notice any problems while running my laptop (WinXPsp2/IE6/AOL9 VR)
and wonder if these "Scan Errors" are very, very dangerous? I really can't
afford to buy another computer.
Can anyone help please?
Alice
 
M

MowGreen

Perhaps CCleaner is the cause for the PIDs showing. It would be wise to
set CCleaner to NOT delete the mrt.log. Then you can see if the PIDs
show up again.
BSODs *may* be related to malware but usually are caused by drivers or
failing hardware, Alice. Suggest you check the Event Viewer.
*Right* click My Computer either on the Desktop or on the Start Menu and
choose Manage
Click the plus sign next to Event Viewer and then click on System
Look for Error in the right frame
Double click on any Error listed for a more detailed view and check to
see if any are related to the display adapter or other hardware
If there are none, then I'd suspect that there may be some well hidden
malware resident on the system.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============


Thanks.
Funny thing. My son said he forgot to look at the mrt.log and did a
CCleaner, and when he tried to look at the log (notepad
%\windir%\debug\mrt.log), it said it was not availabe (having been deleted by
CCleaner). When he remembered, he ran the mrt.exe and then looked at the
mrt.log and he saw all those PIDs (error scans) related to NAV.
For an experiment, we went to my neighbor and had them download the KB890830
and when that finished, the mrt.log only said "no infection found." However,
we did a CCleaner on that machine and then tried to look at the mrt.log, it
reported it could not be found (having been deleted by the CCleaner - same as
happned to my son's computer).
When we then ran the mrt.exe and looked at the log (on my neighbor's
computer), it not only reported "no infection found," but also reported the
'identical' PIDs errors that were reported on my son's mrt.log (after he ran
it after the CCleaner deleted original mrt.log).
Does any of this son make sense? It seems that if we look at the log right
after we log off from the web, we get "no infection found." But, if we run
the CCleaner BEFORE looking at the log and then run mrt.exe and look at the
log, it prints all those NAV PIDs.
(By the way the original laptop we used has gone BSOD. I had gotten the BSOD
a few times in the past months, so it wasn't a big surprise. That is the one
with ZA. My son is letting me use his laptop which has NAV.)
Alice
=============
MowGreen said:
I'd bet that those errors contained in both logs indicate that Symantec
[Norton] and ZoneAlarm are the cause.
For your system you could try Enabling the native XP Firewall from
within the Control Panel and then Disable ZA
Then do a scan with the MRT and check for further errors

Your son can temporarily disable whichever Norton software is installed
by, hopefully, reading the Help file for directions to do so .
If it's a security suite and includes a Firewall then have him Enable
the native XP one before Disabling Norton's.
Then scan with MRT, check for any errors

BTW, one can just type in
mrt
in the Run line, click OK, and it will open.

I'd be curious to see the MRT log with the system booted to Safe Mode.
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx


MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============


Just an add-on to my previous post. My son just paid a visit and brought
along a sheet of paper he printed out after he ran the Kb890830 Malicious
tool on his computer and then looking at the mrt.log. This is what he shows
(all of the pid refer to Symantec (Norton), which he has on his computer.
Does anyone know what is going on?...


---------------------------------------------------------------------------------------

Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Wed Jun 13 21:49:40 2007
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2504 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Wed Jun 13
21:50:26 2007




:


Thanks for the help. I did run the full scan and nothing was detected.
I looked at the log and it did show different PIDs = 168 and 440. I then
opened the Process Explorer and saw that both were related to:
168 vsmon.exe True Vector Service Zone Labs
440 zlclient.exe True Vector Service Zone Labs

The previous PIDs were not listed (but think maybe they were also related to
ZA.)

I am using ZoneAlarm, and wonder if ZA is causing these "scan ERRORs."
I ran AdAware and nothing showing. I am hoping my computer is not
"compromised."

Living on small monthly income and, as I said, cannot afford any unnecessary
expenses.

Alice



=================
:


Those errors may be related to the 'Iomega Activity Disk2'
To determine if that's the case, disconnect it from the system and then
manually start the MRT by going to Start > Run > and type in

mrt.exe

Click OK or press Enter
The Malicious Software Removal Tool window will appear
It should show June 2007 at the very top
If so, click Next
Put a tick next to ' Full scan '
Click Next
When the scan is done a new page will open with the result

If nothing is detected then open the mrt.log once more.
Do the errors still appear ?

As stated in the prior thread covering this :

Windows Error 0x0000054F - 1359
The security account database contains an internal inconsistency.
ERROR_INTERNAL_ERROR

To determine just which programs are pid 212, 464, and 128 are, you can
download and SAVE Process Explorer :
http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/ProcessExplorer.mspx

*Instructions for it's use are on that web page*
The download is in a .zip format
You MUST first extract or decompress the .zip file
Suggest you do so to the My Documents folder

There IS one more error showing in this log then the one you posted last
month and the PIDs differ. That is not a good sign. The MRT does not
target all malware and the system *may* be compromised.

If this is too difficult, then STRONGLY SUGGEST you either bring the
system to a reputable PC tech or have a technically adept acquaintance
check it.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============



AliceZ wrote:


I downloaded the KB890830 (Malicious Tool) Critical Update tonight and when I
did the RUN "for notepage %windir%\debug\mrt.log," I got the following:
===================================
Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Tue Jun 12 19:24:35 2007
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:464 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:128 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Tue Jun 12
19:25:38 2007
=========================================
I manually went to: Winint/system32/mrt.exe
and clicked on that and it only stated: "No malicious software was detected."

(Last month I had approximately the same results, which were:
May 2007 Microsoft Windows Malicious Software Removal Tool v1.29, May 2007
Started On Tue May 08 19:57:36 2007
->Scan ERROR: resource process://pid:976 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
Results Summary: ---------------- No infection found.
Return code: 0 Microsoft Windows Malicious Software Removal Tool Finished
On Tue May 08 19:58:34 2007 -

I posted a similar note last month, but actually forgot about the answers
until this recent download.)
============================
I don't notice any problems while running my laptop (WinXPsp2/IE6/AOL9 VR)
and wonder if these "Scan Errors" are very, very dangerous? I really can't
afford to buy another computer.
Can anyone help please?
Alice
 
G

Guest

Thanks. Our old laptop (BSOD) cannot even be started. We turn it on and it
runs for a few seconds and then the BSOD; so I have given up on in.
#1- You mention to sent the CCleaner not to delete the "mrt.log." I don't
think there is any way to do that.
Should I post the following as a separate question?
#2- I'm at my son's house using his laptop. But when he turned on his
desktop (he had 512MB ran, but installed another 512MB about 2 months ago)
and got a small pop-up while he was offline saying something about Virtual
Memory being low and being adjusted. He looked in the System Advanced VM and
saw:
Page file size for selected drive (C:)
Drive: C
Space available: 179034MB
Custom size (checked)
Initial size (MB) 756
Maximum size (MB) 1512

System managed site (not checked)
No paging file (not checked)

Total paging file size for all drives
Minimum allowed: 2 MB
Recommended: 1519 MB
Currently allocated: 756 MB

Do you think anything should be changed (or was something changed
automatically)? We don't know anything about this. (Neighbor said we should
check System Managed Site, but we don't want to do anything that might
screw-up the computer.)
Thanks again,
Alice

=====
MowGreen said:
Perhaps CCleaner is the cause for the PIDs showing. It would be wise to
set CCleaner to NOT delete the mrt.log. Then you can see if the PIDs
show up again.
BSODs *may* be related to malware but usually are caused by drivers or
failing hardware, Alice. Suggest you check the Event Viewer.
*Right* click My Computer either on the Desktop or on the Start Menu and
choose Manage
Click the plus sign next to Event Viewer and then click on System
Look for Error in the right frame
Double click on any Error listed for a more detailed view and check to
see if any are related to the display adapter or other hardware
If there are none, then I'd suspect that there may be some well hidden
malware resident on the system.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============


Thanks.
Funny thing. My son said he forgot to look at the mrt.log and did a
CCleaner, and when he tried to look at the log (notepad
%\windir%\debug\mrt.log), it said it was not availabe (having been deleted by
CCleaner). When he remembered, he ran the mrt.exe and then looked at the
mrt.log and he saw all those PIDs (error scans) related to NAV.
For an experiment, we went to my neighbor and had them download the KB890830
and when that finished, the mrt.log only said "no infection found." However,
we did a CCleaner on that machine and then tried to look at the mrt.log, it
reported it could not be found (having been deleted by the CCleaner - same as
happned to my son's computer).
When we then ran the mrt.exe and looked at the log (on my neighbor's
computer), it not only reported "no infection found," but also reported the
'identical' PIDs errors that were reported on my son's mrt.log (after he ran
it after the CCleaner deleted original mrt.log).
Does any of this son make sense? It seems that if we look at the log right
after we log off from the web, we get "no infection found." But, if we run
the CCleaner BEFORE looking at the log and then run mrt.exe and look at the
log, it prints all those NAV PIDs.
(By the way the original laptop we used has gone BSOD. I had gotten the BSOD
a few times in the past months, so it wasn't a big surprise. That is the one
with ZA. My son is letting me use his laptop which has NAV.)
Alice
=============
MowGreen said:
I'd bet that those errors contained in both logs indicate that Symantec
[Norton] and ZoneAlarm are the cause.
For your system you could try Enabling the native XP Firewall from
within the Control Panel and then Disable ZA
Then do a scan with the MRT and check for further errors

Your son can temporarily disable whichever Norton software is installed
by, hopefully, reading the Help file for directions to do so .
If it's a security suite and includes a Firewall then have him Enable
the native XP one before Disabling Norton's.
Then scan with MRT, check for any errors

BTW, one can just type in
mrt
in the Run line, click OK, and it will open.

I'd be curious to see the MRT log with the system booted to Safe Mode.
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx


MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============



AliceZ wrote:

Just an add-on to my previous post. My son just paid a visit and brought
along a sheet of paper he printed out after he ran the Kb890830 Malicious
tool on his computer and then looking at the mrt.log. This is what he shows
(all of the pid refer to Symantec (Norton), which he has on his computer.
Does anyone know what is going on?...


---------------------------------------------------------------------------------------

Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Wed Jun 13 21:49:40 2007
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2504 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Wed Jun 13
21:50:26 2007




:


Thanks for the help. I did run the full scan and nothing was detected.
I looked at the log and it did show different PIDs = 168 and 440. I then
opened the Process Explorer and saw that both were related to:
168 vsmon.exe True Vector Service Zone Labs
440 zlclient.exe True Vector Service Zone Labs

The previous PIDs were not listed (but think maybe they were also related to
ZA.)

I am using ZoneAlarm, and wonder if ZA is causing these "scan ERRORs."
I ran AdAware and nothing showing. I am hoping my computer is not
"compromised."

Living on small monthly income and, as I said, cannot afford any unnecessary
expenses.

Alice



=================
:


Those errors may be related to the 'Iomega Activity Disk2'
To determine if that's the case, disconnect it from the system and then
manually start the MRT by going to Start > Run > and type in

mrt.exe

Click OK or press Enter
The Malicious Software Removal Tool window will appear
It should show June 2007 at the very top
If so, click Next
Put a tick next to ' Full scan '
Click Next
When the scan is done a new page will open with the result

If nothing is detected then open the mrt.log once more.
Do the errors still appear ?

As stated in the prior thread covering this :

Windows Error 0x0000054F - 1359
The security account database contains an internal inconsistency.
ERROR_INTERNAL_ERROR

To determine just which programs are pid 212, 464, and 128 are, you can
download and SAVE Process Explorer :
http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/ProcessExplorer.mspx

*Instructions for it's use are on that web page*
The download is in a .zip format
You MUST first extract or decompress the .zip file
Suggest you do so to the My Documents folder

There IS one more error showing in this log then the one you posted last
month and the PIDs differ. That is not a good sign. The MRT does not
target all malware and the system *may* be compromised.

If this is too difficult, then STRONGLY SUGGEST you either bring the
system to a reputable PC tech or have a technically adept acquaintance
check it.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============



AliceZ wrote:


I downloaded the KB890830 (Malicious Tool) Critical Update tonight and when I
did the RUN "for notepage %windir%\debug\mrt.log," I got the following:
===================================
Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Tue Jun 12 19:24:35 2007
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:464 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:128 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Tue Jun 12
19:25:38 2007
=========================================
I manually went to: Winint/system32/mrt.exe
and clicked on that and it only stated: "No malicious software was detected."

(Last month I had approximately the same results, which were:
May 2007 Microsoft Windows Malicious Software Removal Tool v1.29, May 2007
Started On Tue May 08 19:57:36 2007
->Scan ERROR: resource process://pid:976 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
Results Summary: ---------------- No infection found.
Return code: 0 Microsoft Windows Malicious Software Removal Tool Finished
On Tue May 08 19:58:34 2007 -

I posted a similar note last month, but actually forgot about the answers
until this recent download.)
============================
I don't notice any problems while running my laptop (WinXPsp2/IE6/AOL9 VR)
and wonder if these "Scan Errors" are very, very dangerous? I really can't
afford to buy another computer.
Can anyone help please?
Alice
 
M

MowGreen [MVP]

So many questions, so little time ...

Inline -
Thanks. Our old laptop (BSOD) cannot even be started. We turn it on and it
runs for a few seconds and then the BSOD; so I have given up on in.
#1- You mention to sent the CCleaner not to delete the "mrt.log." I don't
think there is any way to do that.

Dunno. You'll have to consult CCleaner's FAQs or the Help file to learn
how to configure it. If it's that much of an issue then perhaps you
should uninstall it and manually clean out Temp locations ?
Should I post the following as a separate question?
#2- I'm at my son's house using his laptop. But when he turned on his
desktop (he had 512MB ran, but installed another 512MB about 2 months ago)
and got a small pop-up while he was offline saying something about Virtual
Memory being low and being adjusted. He looked in the System Advanced VM and
saw:
Page file size for selected drive (C:)
Drive: C
Space available: 179034MB
Custom size (checked)
Initial size (MB) 756
Maximum size (MB) 1512

System managed site (not checked)
No paging file (not checked)

Total paging file size for all drives
Minimum allowed: 2 MB
Recommended: 1519 MB
Currently allocated: 756 MB

Do you think anything should be changed (or was something changed
automatically)? We don't know anything about this. (Neighbor said we should
check System Managed Site, but we don't want to do anything that might
screw-up the computer.)
Thanks again,
Alice

Are you referring to System Properties > Advanced > Performance> Advanced ?
The OS sets these parameters, unless there are 3rd party software that
*may* change the Duh-fault settings.
On a 512 MB RAM XP Pro OS, the settings here are:

Initial size: 384
Maximum size : 768

Total paging file size for all drives
Minimum allowed: 2 MB
Recommended: 766 MB
Currently allocated: 384 MB

YMMV

MG

=====
:

Perhaps CCleaner is the cause for the PIDs showing. It would be wise to
set CCleaner to NOT delete the mrt.log. Then you can see if the PIDs
show up again.
BSODs *may* be related to malware but usually are caused by drivers or
failing hardware, Alice. Suggest you check the Event Viewer.
*Right* click My Computer either on the Desktop or on the Start Menu and
choose Manage
Click the plus sign next to Event Viewer and then click on System
Look for Error in the right frame
Double click on any Error listed for a more detailed view and check to
see if any are related to the display adapter or other hardware
If there are none, then I'd suspect that there may be some well hidden
malware resident on the system.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============


Thanks.
Funny thing. My son said he forgot to look at the mrt.log and did a
CCleaner, and when he tried to look at the log (notepad
%\windir%\debug\mrt.log), it said it was not availabe (having been deleted by
CCleaner). When he remembered, he ran the mrt.exe and then looked at the
mrt.log and he saw all those PIDs (error scans) related to NAV.
For an experiment, we went to my neighbor and had them download the KB890830
and when that finished, the mrt.log only said "no infection found." However,
we did a CCleaner on that machine and then tried to look at the mrt.log, it
reported it could not be found (having been deleted by the CCleaner - same as
happned to my son's computer).
When we then ran the mrt.exe and looked at the log (on my neighbor's
computer), it not only reported "no infection found," but also reported the
'identical' PIDs errors that were reported on my son's mrt.log (after he ran
it after the CCleaner deleted original mrt.log).
Does any of this son make sense? It seems that if we look at the log right
after we log off from the web, we get "no infection found." But, if we run
the CCleaner BEFORE looking at the log and then run mrt.exe and look at the
log, it prints all those NAV PIDs.
(By the way the original laptop we used has gone BSOD. I had gotten the BSOD
a few times in the past months, so it wasn't a big surprise. That is the one
with ZA. My son is letting me use his laptop which has NAV.)
Alice
=============
:


I'd bet that those errors contained in both logs indicate that Symantec
[Norton] and ZoneAlarm are the cause.
For your system you could try Enabling the native XP Firewall from
within the Control Panel and then Disable ZA
Then do a scan with the MRT and check for further errors

Your son can temporarily disable whichever Norton software is installed
by, hopefully, reading the Help file for directions to do so .
If it's a security suite and includes a Firewall then have him Enable
the native XP one before Disabling Norton's.
Then scan with MRT, check for any errors

BTW, one can just type in
mrt
in the Run line, click OK, and it will open.

I'd be curious to see the MRT log with the system booted to Safe Mode.
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx


MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============



AliceZ wrote:


Just an add-on to my previous post. My son just paid a visit and brought
along a sheet of paper he printed out after he ran the Kb890830 Malicious
tool on his computer and then looking at the mrt.log. This is what he shows
(all of the pid refer to Symantec (Norton), which he has on his computer.
Does anyone know what is going on?...


---------------------------------------------------------------------------------------

Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Wed Jun 13 21:49:40 2007
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2504 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Wed Jun 13
21:50:26 2007




:



Thanks for the help. I did run the full scan and nothing was detected.
I looked at the log and it did show different PIDs = 168 and 440. I then
opened the Process Explorer and saw that both were related to:
168 vsmon.exe True Vector Service Zone Labs
440 zlclient.exe True Vector Service Zone Labs

The previous PIDs were not listed (but think maybe they were also related to
ZA.)

I am using ZoneAlarm, and wonder if ZA is causing these "scan ERRORs."
I ran AdAware and nothing showing. I am hoping my computer is not
"compromised."

Living on small monthly income and, as I said, cannot afford any unnecessary
expenses.

Alice



=================
:



Those errors may be related to the 'Iomega Activity Disk2'
To determine if that's the case, disconnect it from the system and then
manually start the MRT by going to Start > Run > and type in

mrt.exe

Click OK or press Enter
The Malicious Software Removal Tool window will appear
It should show June 2007 at the very top
If so, click Next
Put a tick next to ' Full scan '
Click Next
When the scan is done a new page will open with the result

If nothing is detected then open the mrt.log once more.
Do the errors still appear ?

As stated in the prior thread covering this :

Windows Error 0x0000054F - 1359
The security account database contains an internal inconsistency.
ERROR_INTERNAL_ERROR

To determine just which programs are pid 212, 464, and 128 are, you can
download and SAVE Process Explorer :
http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/ProcessExplorer.mspx

*Instructions for it's use are on that web page*
The download is in a .zip format
You MUST first extract or decompress the .zip file
Suggest you do so to the My Documents folder

There IS one more error showing in this log then the one you posted last
month and the PIDs differ. That is not a good sign. The MRT does not
target all malware and the system *may* be compromised.

If this is too difficult, then STRONGLY SUGGEST you either bring the
system to a reputable PC tech or have a technically adept acquaintance
check it.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============



AliceZ wrote:



I downloaded the KB890830 (Malicious Tool) Critical Update tonight and when I
did the RUN "for notepage %windir%\debug\mrt.log," I got the following:
===================================
Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Tue Jun 12 19:24:35 2007
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:464 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:128 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Tue Jun 12
19:25:38 2007
=========================================
I manually went to: Winint/system32/mrt.exe
and clicked on that and it only stated: "No malicious software was detected."

(Last month I had approximately the same results, which were:
May 2007 Microsoft Windows Malicious Software Removal Tool v1.29, May 2007
Started On Tue May 08 19:57:36 2007
->Scan ERROR: resource process://pid:976 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
Results Summary: ---------------- No infection found.
Return code: 0 Microsoft Windows Malicious Software Removal Tool Finished
On Tue May 08 19:58:34 2007 -

I posted a similar note last month, but actually forgot about the answers
until this recent download.)
============================
I don't notice any problems while running my laptop (WinXPsp2/IE6/AOL9 VR)
and wonder if these "Scan Errors" are very, very dangerous? I really can't
afford to buy another computer.
Can anyone help please?
Alice
 
G

Guest

Yes, that is what I was referring to. As I said, it now shows:
Initial size (MB) 756
Maximum size (MB) 1512

System managed site (not checked)
No paging file (not checked)

Total paging file size for all drives
Minimum allowed: 2 MB
Recommended: 1519 MB
Currently allocated: 756 MB
We were told that if he increased the original 512MB by another 512MB, then
the
(original, now showing)
Initial size (MB) 756
should be changed to 1536 MB (which is 1.5 x 1GB (1024 MB).
That is what we were trying to confirm.
What we should change the Initial Size to
and what we should change the Maximum Size to

===
Thanks. Our old laptop (BSOD) cannot even be started. We turn it on and it
runs for a few seconds and then the BSOD; so I have given up on in.
#1- You mention to sent the CCleaner not to delete the "mrt.log." I don't
think there is any way to do that.

Dunno. You'll have to consult CCleaner's FAQs or the Help file to learn
how to configure it. If it's that much of an issue then perhaps you
should uninstall it and manually clean out Temp locations ?
Should I post the following as a separate question?
#2- I'm at my son's house using his laptop. But when he turned on his
desktop (he had 512MB ran, but installed another 512MB about 2 months ago)
and got a small pop-up while he was offline saying something about Virtual
Memory being low and being adjusted. He looked in the System Advanced VM and
saw:
Page file size for selected drive (C:)
Drive: C
Space available: 179034MB
Custom size (checked)
Initial size (MB) 756
Maximum size (MB) 1512

System managed site (not checked)
No paging file (not checked)

Total paging file size for all drives
Minimum allowed: 2 MB
Recommended: 1519 MB
Currently allocated: 756 MB

Do you think anything should be changed (or was something changed
automatically)? We don't know anything about this. (Neighbor said we should
check System Managed Site, but we don't want to do anything that might
screw-up the computer.)
Thanks again,
Alice

Are you referring to System Properties > Advanced > Performance> Advanced ?
The OS sets these parameters, unless there are 3rd party software that
*may* change the Duh-fault settings.
On a 512 MB RAM XP Pro OS, the settings here are:

Initial size: 384
Maximum size : 768

Total paging file size for all drives
Minimum allowed: 2 MB
Recommended: 766 MB
Currently allocated: 384 MB

YMMV

MG

=====
:

Perhaps CCleaner is the cause for the PIDs showing. It would be wise to
set CCleaner to NOT delete the mrt.log. Then you can see if the PIDs
show up again.
BSODs *may* be related to malware but usually are caused by drivers or
failing hardware, Alice. Suggest you check the Event Viewer.
*Right* click My Computer either on the Desktop or on the Start Menu and
choose Manage
Click the plus sign next to Event Viewer and then click on System
Look for Error in the right frame
Double click on any Error listed for a more detailed view and check to
see if any are related to the display adapter or other hardware
If there are none, then I'd suspect that there may be some well hidden
malware resident on the system.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============



AliceZ wrote:

Thanks.
Funny thing. My son said he forgot to look at the mrt.log and did a
CCleaner, and when he tried to look at the log (notepad
%\windir%\debug\mrt.log), it said it was not availabe (having been deleted by
CCleaner). When he remembered, he ran the mrt.exe and then looked at the
mrt.log and he saw all those PIDs (error scans) related to NAV.
For an experiment, we went to my neighbor and had them download the KB890830
and when that finished, the mrt.log only said "no infection found." However,
we did a CCleaner on that machine and then tried to look at the mrt.log, it
reported it could not be found (having been deleted by the CCleaner - same as
happned to my son's computer).
When we then ran the mrt.exe and looked at the log (on my neighbor's
computer), it not only reported "no infection found," but also reported the
'identical' PIDs errors that were reported on my son's mrt.log (after he ran
it after the CCleaner deleted original mrt.log).
Does any of this son make sense? It seems that if we look at the log right
after we log off from the web, we get "no infection found." But, if we run
the CCleaner BEFORE looking at the log and then run mrt.exe and look at the
log, it prints all those NAV PIDs.
(By the way the original laptop we used has gone BSOD. I had gotten the BSOD
a few times in the past months, so it wasn't a big surprise. That is the one
with ZA. My son is letting me use his laptop which has NAV.)
Alice
=============
:


I'd bet that those errors contained in both logs indicate that Symantec
[Norton] and ZoneAlarm are the cause.
For your system you could try Enabling the native XP Firewall from
within the Control Panel and then Disable ZA
Then do a scan with the MRT and check for further errors

Your son can temporarily disable whichever Norton software is installed
by, hopefully, reading the Help file for directions to do so .
If it's a security suite and includes a Firewall then have him Enable
the native XP one before Disabling Norton's.
Then scan with MRT, check for any errors

BTW, one can just type in
mrt
in the Run line, click OK, and it will open.

I'd be curious to see the MRT log with the system booted to Safe Mode.
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx


MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============



AliceZ wrote:


Just an add-on to my previous post. My son just paid a visit and brought
along a sheet of paper he printed out after he ran the Kb890830 Malicious
tool on his computer and then looking at the mrt.log. This is what he shows
(all of the pid refer to Symantec (Norton), which he has on his computer.
Does anyone know what is going on?...


---------------------------------------------------------------------------------------

Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Wed Jun 13 21:49:40 2007
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2504 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Wed Jun 13
21:50:26 2007




:



Thanks for the help. I did run the full scan and nothing was detected.
I looked at the log and it did show different PIDs = 168 and 440. I then
opened the Process Explorer and saw that both were related to:
168 vsmon.exe True Vector Service Zone Labs
440 zlclient.exe True Vector Service Zone Labs

The previous PIDs were not listed (but think maybe they were also related to
ZA.)

I am using ZoneAlarm, and wonder if ZA is causing these "scan ERRORs."
I ran AdAware and nothing showing. I am hoping my computer is not
"compromised."

Living on small monthly income and, as I said, cannot afford any unnecessary
expenses.

Alice



=================
:



Those errors may be related to the 'Iomega Activity Disk2'
To determine if that's the case, disconnect it from the system and then
manually start the MRT by going to Start > Run > and type in

mrt.exe

Click OK or press Enter
The Malicious Software Removal Tool window will appear
It should show June 2007 at the very top
If so, click Next
Put a tick next to ' Full scan '
Click Next
When the scan is done a new page will open with the result

If nothing is detected then open the mrt.log once more.
Do the errors still appear ?

As stated in the prior thread covering this :

Windows Error 0x0000054F - 1359
The security account database contains an internal inconsistency.
ERROR_INTERNAL_ERROR

To determine just which programs are pid 212, 464, and 128 are, you can
download and SAVE Process Explorer :
http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/ProcessExplorer.mspx

*Instructions for it's use are on that web page*
The download is in a .zip format
You MUST first extract or decompress the .zip file
Suggest you do so to the My Documents folder

There IS one more error showing in this log then the one you posted last
month and the PIDs differ. That is not a good sign. The MRT does not
target all malware and the system *may* be compromised.

If this is too difficult, then STRONGLY SUGGEST you either bring the
system to a reputable PC tech or have a technically adept acquaintance
check it.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============



AliceZ wrote:



I downloaded the KB890830 (Malicious Tool) Critical Update tonight and when I
did the RUN "for notepage %windir%\debug\mrt.log," I got the following:
===================================
Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Tue Jun 12 19:24:35 2007
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:464 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:128 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Tue Jun 12
19:25:38 2007
=========================================
I manually went to: Winint/system32/mrt.exe
and clicked on that and it only stated: "No malicious software was detected."

(Last month I had approximately the same results, which were:
May 2007 Microsoft Windows Malicious Software Removal Tool v1.29, May 2007
Started On Tue May 08 19:57:36 2007
->Scan ERROR: resource process://pid:976 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
 
M

MowGreen [MVP]

I allow Windows to manage those settings, Alice. Have never had any
issues, so far.
Perhaps someone else can assist you in regards to custom tweaking:
XP Configuration and Management
http://www.microsoft.com/communitie...291-cdf9-431a-8374-a8037de637eb&lang=en&cr=US

XP General
http://www.microsoft.com/communitie...a1e-b269-4291-b6b4-dc2d504ce9ef&lang=en&cr=US

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============

Yes, that is what I was referring to. As I said, it now shows:
Initial size (MB) 756
Maximum size (MB) 1512

System managed site (not checked)
No paging file (not checked)

Total paging file size for all drives
Minimum allowed: 2 MB
Recommended: 1519 MB
Currently allocated: 756 MB
We were told that if he increased the original 512MB by another 512MB, then
the
(original, now showing)
Initial size (MB) 756
should be changed to 1536 MB (which is 1.5 x 1GB (1024 MB).
That is what we were trying to confirm.
What we should change the Initial Size to
and what we should change the Maximum Size to

===
Thanks. Our old laptop (BSOD) cannot even be started. We turn it on and it
runs for a few seconds and then the BSOD; so I have given up on in.
#1- You mention to sent the CCleaner not to delete the "mrt.log." I don't
think there is any way to do that.

Dunno. You'll have to consult CCleaner's FAQs or the Help file to learn
how to configure it. If it's that much of an issue then perhaps you
should uninstall it and manually clean out Temp locations ?

Should I post the following as a separate question?
#2- I'm at my son's house using his laptop. But when he turned on his
desktop (he had 512MB ran, but installed another 512MB about 2 months ago)
and got a small pop-up while he was offline saying something about Virtual
Memory being low and being adjusted. He looked in the System Advanced VM and
saw:
Page file size for selected drive (C:)
Drive: C
Space available: 179034MB
Custom size (checked)
Initial size (MB) 756
Maximum size (MB) 1512

System managed site (not checked)
No paging file (not checked)

Total paging file size for all drives
Minimum allowed: 2 MB
Recommended: 1519 MB
Currently allocated: 756 MB

Do you think anything should be changed (or was something changed
automatically)? We don't know anything about this. (Neighbor said we should
check System Managed Site, but we don't want to do anything that might
screw-up the computer.)
Thanks again,
Alice

Are you referring to System Properties > Advanced > Performance> Advanced ?
The OS sets these parameters, unless there are 3rd party software that
*may* change the Duh-fault settings.
On a 512 MB RAM XP Pro OS, the settings here are:

Initial size: 384
Maximum size : 768

Total paging file size for all drives
Minimum allowed: 2 MB
Recommended: 766 MB
Currently allocated: 384 MB

YMMV

MG


=====
:



Perhaps CCleaner is the cause for the PIDs showing. It would be wise to
set CCleaner to NOT delete the mrt.log. Then you can see if the PIDs
show up again.
BSODs *may* be related to malware but usually are caused by drivers or
failing hardware, Alice. Suggest you check the Event Viewer.
*Right* click My Computer either on the Desktop or on the Start Menu and
choose Manage
Click the plus sign next to Event Viewer and then click on System
Look for Error in the right frame
Double click on any Error listed for a more detailed view and check to
see if any are related to the display adapter or other hardware
If there are none, then I'd suspect that there may be some well hidden
malware resident on the system.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============



AliceZ wrote:


Thanks.
Funny thing. My son said he forgot to look at the mrt.log and did a
CCleaner, and when he tried to look at the log (notepad
%\windir%\debug\mrt.log), it said it was not availabe (having been deleted by
CCleaner). When he remembered, he ran the mrt.exe and then looked at the
mrt.log and he saw all those PIDs (error scans) related to NAV.
For an experiment, we went to my neighbor and had them download the KB890830
and when that finished, the mrt.log only said "no infection found." However,
we did a CCleaner on that machine and then tried to look at the mrt.log, it
reported it could not be found (having been deleted by the CCleaner - same as
happned to my son's computer).
When we then ran the mrt.exe and looked at the log (on my neighbor's
computer), it not only reported "no infection found," but also reported the
'identical' PIDs errors that were reported on my son's mrt.log (after he ran
it after the CCleaner deleted original mrt.log).
Does any of this son make sense? It seems that if we look at the log right
after we log off from the web, we get "no infection found." But, if we run
the CCleaner BEFORE looking at the log and then run mrt.exe and look at the
log, it prints all those NAV PIDs.
(By the way the original laptop we used has gone BSOD. I had gotten the BSOD
a few times in the past months, so it wasn't a big surprise. That is the one
with ZA. My son is letting me use his laptop which has NAV.)
Alice
=============
:



I'd bet that those errors contained in both logs indicate that Symantec
[Norton] and ZoneAlarm are the cause.
For your system you could try Enabling the native XP Firewall from
within the Control Panel and then Disable ZA
Then do a scan with the MRT and check for further errors

Your son can temporarily disable whichever Norton software is installed
by, hopefully, reading the Help file for directions to do so .
If it's a security suite and includes a Firewall then have him Enable
the native XP one before Disabling Norton's.
Then scan with MRT, check for any errors

BTW, one can just type in
mrt
in the Run line, click OK, and it will open.

I'd be curious to see the MRT log with the system booted to Safe Mode.
http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx


MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============



AliceZ wrote:



Just an add-on to my previous post. My son just paid a visit and brought
along a sheet of paper he printed out after he ran the Kb890830 Malicious
tool on his computer and then looking at the mrt.log. This is what he shows
(all of the pid refer to Symantec (Norton), which he has on his computer.
Does anyone know what is going on?...


---------------------------------------------------------------------------------------

Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Wed Jun 13 21:49:40 2007
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2504 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:144 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1600 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1292 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1404 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1456 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:208 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1484 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:1532 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:580 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Wed Jun 13
21:50:26 2007




:




Thanks for the help. I did run the full scan and nothing was detected.
I looked at the log and it did show different PIDs = 168 and 440. I then
opened the Process Explorer and saw that both were related to:
168 vsmon.exe True Vector Service Zone Labs
440 zlclient.exe True Vector Service Zone Labs

The previous PIDs were not listed (but think maybe they were also related to
ZA.)

I am using ZoneAlarm, and wonder if ZA is causing these "scan ERRORs."
I ran AdAware and nothing showing. I am hoping my computer is not
"compromised."

Living on small monthly income and, as I said, cannot afford any unnecessary
expenses.

Alice



=================
:




Those errors may be related to the 'Iomega Activity Disk2'
To determine if that's the case, disconnect it from the system and then
manually start the MRT by going to Start > Run > and type in

mrt.exe

Click OK or press Enter
The Malicious Software Removal Tool window will appear
It should show June 2007 at the very top
If so, click Next
Put a tick next to ' Full scan '
Click Next
When the scan is done a new page will open with the result

If nothing is detected then open the mrt.log once more.
Do the errors still appear ?

As stated in the prior thread covering this :

Windows Error 0x0000054F - 1359
The security account database contains an internal inconsistency.
ERROR_INTERNAL_ERROR

To determine just which programs are pid 212, 464, and 128 are, you can
download and SAVE Process Explorer :
http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/ProcessExplorer.mspx

*Instructions for it's use are on that web page*
The download is in a .zip format
You MUST first extract or decompress the .zip file
Suggest you do so to the My Documents folder

There IS one more error showing in this log then the one you posted last
month and the PIDs differ. That is not a good sign. The MRT does not
target all malware and the system *may* be compromised.

If this is too difficult, then STRONGLY SUGGEST you either bring the
system to a reputable PC tech or have a technically adept acquaintance
check it.

MowGreen [MVP 2003-2007]
===============
*-343-* FDNY
Never Forgotten
===============



AliceZ wrote:




I downloaded the KB890830 (Malicious Tool) Critical Update tonight and when I
did the RUN "for notepage %windir%\debug\mrt.log," I got the following:
===================================
Microsoft Windows Malicious Software Removal Tool v1.30, June 2007
Started On Tue Jun 12 19:24:35 2007
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:464 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:128 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
(1359))
->Scan ERROR: resource process://pid:212 (code 0x0000054F (1359))

Results Summary:
----------------
No infection found.

Return code: 0
Microsoft Windows Malicious Software Removal Tool Finished On Tue Jun 12
19:25:38 2007
=========================================
I manually went to: Winint/system32/mrt.exe
and clicked on that and it only stated: "No malicious software was detected."

(Last month I had approximately the same results, which were:
May 2007 Microsoft Windows Malicious Software Removal Tool v1.29, May 2007
Started On Tue May 08 19:57:36 2007
->Scan ERROR: resource process://pid:976 (code 0x0000054F (1359))
->Scan ERROR: resource process://pid:2272 (code 0x0000054F (1359))
->Scan ERROR: resource service://Iomega Activity Disk2 (code 0x0000054F
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top