NTAuthority, unknown administartors, and very strange beha..

G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

Please be nice to me as I am new here. I have been wrestling with my PC for
a couple of months ago. I am scientist by degree and profiession so my need
to "understand what is happening" might be my own udoing when it comes to XP.
At the urging of my Girl friend I finally took the PC, XP SP2 and everything
to a computer store and had a technician install everything and "guarntee" it
was all safe. (Its XP home edition)

Well I am not convivienced it is. I have anti virus, widows firewall,
several anti spy programs, registry fixer, system mechanic 5.5 (not loaded
now)

Who is NTauthority and local service? I also have other unknow user who I
can sometime find when i check a file or directories permissions. When i
check the logs (system and secutiry) I see all kind of strange activivity.
Especially using audit to grant special persmission for opening ports,
running imaging stuff, changing registry info, and remotely connecting which
I thought I had disabled.

I am using road runner internet service with a LAN connection on my PC. I
turn off my PC and disconnect the cable to modem after signing off (just in
case).

How do I secure this PC with XP and why is all this other happening. Oh, i
forgot to mention i have a process viewer and I do not understand half these
processes. I have been reading and am confused about which ones should. i
noticed many Svchosts and half were not even from \windows\system32 folder.
there was also some other services running which did not have a source
directory. Also, what is with the files NTuser.dat and .log I can not open
them or even scan them for viruses. There seem to be several other files
like this as well.

Is there some way i can straighten this out? Like maybe a
procedure....starting from safe mode and/or using msconfig to start from and
slowly fix and build back up to a know safe mode.

It seems to me that whatever is going on is even tricking whatever I do to
fix it.

Thanks for the help



I
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

Services Guide for Windows XP
http://www.theeldergeek.com/services_guide.htm

--
Carey Frisch
Microsoft MVP
Windows XP - Shell/User
Microsoft Newsgroups

Get Windows XP Service Pack 2 with Advanced Security Technologies:
http://www.microsoft.com/athome/security/protect/windowsxp/choose.mspx

-------------------------------------------------------------------------------------------

"XPConfused" wrote:

| Please be nice to me as I am new here. I have been wrestling with my PC for
| a couple of months ago. I am scientist by degree and profiession so my need
| to "understand what is happening" might be my own udoing when it comes to XP.
| At the urging of my Girl friend I finally took the PC, XP SP2 and everything
| to a computer store and had a technician install everything and "guarntee" it
| was all safe. (Its XP home edition)
|
| Well I am not convivienced it is. I have anti virus, widows firewall,
| several anti spy programs, registry fixer, system mechanic 5.5 (not loaded
| now)
|
| Who is NTauthority and local service? I also have other unknow user who I
| can sometime find when i check a file or directories permissions. When i
| check the logs (system and secutiry) I see all kind of strange activivity.
| Especially using audit to grant special persmission for opening ports,
| running imaging stuff, changing registry info, and remotely connecting which
| I thought I had disabled.
|
| I am using road runner internet service with a LAN connection on my PC. I
| turn off my PC and disconnect the cable to modem after signing off (just in
| case).
|
| How do I secure this PC with XP and why is all this other happening. Oh, i
| forgot to mention i have a process viewer and I do not understand half these
| processes. I have been reading and am confused about which ones should. i
| noticed many Svchosts and half were not even from \windows\system32 folder.
| there was also some other services running which did not have a source
| directory. Also, what is with the files NTuser.dat and .log I can not open
| them or even scan them for viruses. There seem to be several other files
| like this as well.
|
| Is there some way i can straighten this out? Like maybe a
| procedure....starting from safe mode and/or using msconfig to start from and
| slowly fix and build back up to a know safe mode.
|
| It seems to me that whatever is going on is even tricking whatever I do to
| fix it.
|
| Thanks for the help
|
| I
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

Thanks Carey,

I did look at that last night and I had already messed with the services
earlier. I down loaded a bunch of new spyware and virus stuff and a new
firewall. When i try to edit my services, i cant look at there properties
now. I also can't see my taskbar and it boots very very slowly.

I want to clear off most of what i have and load it back on slowly with
firewall in place and realtime protection on.

How do I fix the taskbar? Should I repair XP with the original desk? Boot
from and then selst repair? I also had trouple trying to remove many of the
programs i have.

Any suggestions?



"Carey Frisch [MVP]" wrote:

> Services Guide for Windows XP
> http://www.theeldergeek.com/services_guide.htm
>
> --
> Carey Frisch
> Microsoft MVP
> Windows XP - Shell/User
> Microsoft Newsgroups
>
> Get Windows XP Service Pack 2 with Advanced Security Technologies:
> http://www.microsoft.com/athome/security/protect/windowsxp/choose.mspx
>
> -------------------------------------------------------------------------------------------
>
> "XPConfused" wrote:
>
> | Please be nice to me as I am new here. I have been wrestling with my PC for
> | a couple of months ago. I am scientist by degree and profiession so my need
> | to "understand what is happening" might be my own udoing when it comes to XP.
> | At the urging of my Girl friend I finally took the PC, XP SP2 and everything
> | to a computer store and had a technician install everything and "guarntee" it
> | was all safe. (Its XP home edition)
> |
> | Well I am not convivienced it is. I have anti virus, widows firewall,
> | several anti spy programs, registry fixer, system mechanic 5.5 (not loaded
> | now)
> |
> | Who is NTauthority and local service? I also have other unknow user who I
> | can sometime find when i check a file or directories permissions. When i
> | check the logs (system and secutiry) I see all kind of strange activivity.
> | Especially using audit to grant special persmission for opening ports,
> | running imaging stuff, changing registry info, and remotely connecting which
> | I thought I had disabled.
> |
> | I am using road runner internet service with a LAN connection on my PC. I
> | turn off my PC and disconnect the cable to modem after signing off (just in
> | case).
> |
> | How do I secure this PC with XP and why is all this other happening. Oh, i
> | forgot to mention i have a process viewer and I do not understand half these
> | processes. I have been reading and am confused about which ones should. i
> | noticed many Svchosts and half were not even from \windows\system32 folder.
> | there was also some other services running which did not have a source
> | directory. Also, what is with the files NTuser.dat and .log I can not open
> | them or even scan them for viruses. There seem to be several other files
> | like this as well.
> |
> | Is there some way i can straighten this out? Like maybe a
> | procedure....starting from safe mode and/or using msconfig to start from and
> | slowly fix and build back up to a know safe mode.
> |
> | It seems to me that whatever is going on is even tricking whatever I do to
> | fix it.
> |
> | Thanks for the help
> |
> | I
>