Welcome! Register for a free account (or login) > How does it work?
|
|


Feb 21 2009, 03:14 PM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 7 Joined: 21-February 09 Member No.: 84,319 Operating System: Windows XP |
I have a laptop that would not boot correctly because... "driver unloaded without canceling pending operations". It associated this error with ndisio.sys. I was able to delete this file but the computer is still having many problems. Please instruct me on what to do! I think you may have had some success with this before. Thanks so much. |
|
|
|
![]() |
Feb 21 2009, 04:46 PM
Post
#2
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hello and welcome to
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise. This may cause a delay, but I will do my best to keep it as short as possible. You don't mention if you are now able to boot - do you have an internet connection or are you posting from another machine? If you could please advise your present situation, then I can post back with further instructions. Thank-you |
|
|
|
Feb 21 2009, 06:29 PM
Post
#3
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
could you please read the instructions given HERE
very carefully then post back into this thread with the HJT log |
|
|
|
Feb 21 2009, 11:10 PM
Post
#4
|
|
|
New Member ![]() Group: Authentic Member Posts: 7 Joined: 21-February 09 Member No.: 84,319 Operating System: Windows XP |
Yessir -
I will follow instructions and get back to you as soon as possible. I am using another machine to chat with you. However, I CAN boot on the other machine, and I think I can run a browser. When the infected machine starts, it is terribly slow, and "explorer" does not start automatically. I have to CTL-ALT-DEL and use the "run" option from the toolbar in Task Manager in order to run "explorer" and see icons, etc. Will reply with more information as soon as possible. Thank you - Matt |
|
|
|
Feb 22 2009, 12:15 AM
Post
#5
|
|
|
New Member ![]() Group: Authentic Member Posts: 7 Joined: 21-February 09 Member No.: 84,319 Operating System: Windows XP |
I cannot run "HiJackThis" on the infected computer, even in safe-mode. Here is the list of processes, via Task Manager:
AppleMobileDeviceService.exe BCMWLTRY.EXE ccSetMgr.exe cmd.exe csrss.exe csrssc.exe ctfmon.exe DefWatch.exe explorer.exe GoogleUpdaterService.exe iPodService.exe iTunesHelper.exe lsass.exe mDNSResponder.exe NicConfigSvc.exe prunnet.exe services.exe services.exe smss.exe spoolsv.exe svchost.exe svchost.exe svchost.exe svchost.exe svchost.exe System System Ide Process taskmgr.exe wdfmgr.exe winlognn.exe winlogon.exe WLTRSVC.EXE wmiprvse.exe In safe mode there are less, but I still can't run anything. The one called "csrss.exe" has some CPU activity when I try to load another program. Please let me know how to proceed. |
|
|
|
Feb 22 2009, 05:19 AM
Post
#6
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi
Please try renaming Hijackthis.exe to HijackThis.com Now see if it will run. |
|
|
|
Feb 22 2009, 11:35 AM
Post
#7
|
|
|
New Member ![]() Group: Authentic Member Posts: 7 Joined: 21-February 09 Member No.: 84,319 Operating System: Windows XP |
This did not work either.
I changed the file extension via the command prompt and it still will not run. |
|
|
|
Feb 22 2009, 02:20 PM
Post
#8
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi mattwestfall,
Please follow these instructions EXACTLY. If you cannot download on your machine, download on another that you have access to and transfer over via thumb drive or other media, try to disable your security programs, if they will not disable, run the program and allow to run if your security programs complain. Do the following: Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall** |
|
|
|
Feb 23 2009, 10:16 PM
Post
#9
|
|
|
New Member ![]() Group: Authentic Member Posts: 7 Joined: 21-February 09 Member No.: 84,319 Operating System: Windows XP |
It produced "bug.txt" and here are the contents of that file:
Killing 'Nircmd.com' "C:\32788R22FWJFW\nircmd.com" cmdwait 1500 exec hide "~$folder.system$\cmd.execf" /c 32788R22FWJFW\prep.cmd (4072) PUSHD "C:\32788R22FWJFW" IF NOT EXIST C:\WINDOWS\system32\cmd.exe GOTO Not_NT VER 1>OsVer "C:\WINDOWS\system32\Find.exe" "5.2." OsVer IF -1073741819 == 0 GOTO Not_NT "C:\WINDOWS\system32\Find.exe" "5.1.2" OsVer IF -1073741819 == 0 GOTO NT "C:\WINDOWS\system32\Find.exe" "5.00.2" OsVer IF -1073741819 == 0 GOTO NT GOTO Not_NT IF NOT DEFINED RKEY_ GOTO :EOF CLS CHCP 1252 Active code page: 1252 START NIRCMD.com infobox "Incompatible OS. ComboFix only works for Windows 2000 and XP~n~nOS incompatible. ComboFix ne fonctionne que pour Windows 2000 et XP~n~nOS niet compatibel. ComboFix kan enkel gebruikt worden voor Windows 2000 en XP~n~nInkompatibles Betriebssystem. ComboFix läuft nur unter Windows 2000 und XP~n~nKäyttöjärjestelmä ei ole yhteensopiva. ComboFix toimii vain Windows 2000- ja XP-käyttöjärjestelmissä.~n~nSistema Operativo Incompat¡vel. ComboFix apenas funciona em Windows 2000 e XP~n~nSO. Incompatible. ComboFix funciona únicamente en Windows 2000 y XP~n~nOS Incompatibile. Combofix funziona solo su windows 2000 e XP" "Error - Win32 only" EXIT |
|
|
|
Feb 24 2009, 07:17 AM
Post
#10
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi Mattwestfall,
Combofix did not run correctly. This scan has to be run from I.E. Please do the following: Go to Kaspersky website and perform an online antivirus scan.
|
|
|
|
Feb 24 2009, 06:40 PM
Post
#11
|
|
|
New Member ![]() Group: Authentic Member Posts: 7 Joined: 21-February 09 Member No.: 84,319 Operating System: Windows XP |
Forgive me if I cannot perform this latest task as promptly as I would like.
This is very important to me, and I appreciate your help. I will forward you the results as soon as I can. Again, thank you and please leave this thread open. I can be contacted at for any reason. Matt This post has been edited by Rorschach112: Feb 24 2009, 07:19 PM
Reason for edit: removed email
|
|
|
|
Feb 24 2009, 06:47 PM
Post
#12
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
OK, Thanks for letting me know.
CB |
|
|
|
Mar 1 2009, 03:13 PM
Post
#13
|
|
![]() SuperMember ![]() ![]() ![]() ![]() ![]() Group: Authentic Member Posts: 3,651 Joined: 29-September 07 Member No.: 73,164 Operating System: Windows XP |
Due to inactivity this topic will be closed.
If you need help please start a new thread and post a new HJT log |
|
|
|
Mar 14 2009, 03:43 AM
Post
#14
|
|
![]() Visiting Staff ![]() ![]() ![]() ![]() Group: Visiting Staff Posts: 817 Joined: 18-April 07 From: Thailand Member No.: 69,587 Operating System: XP Pro SP2 - Vista Ultimate |
Reopened at user request.
|
|
|
|
Mar 14 2009, 04:09 AM
Post
#15
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi Mattwestfall, (note: please check "private messages" in your control panel before following these directions - Thank-you)
please do the following: Download Dr.Web CureIt to the desktop:
This post has been edited by CatByte: Mar 14 2009, 04:11 AM |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
5 | Kilmez | 66 | Today, 12:31 PM Last post by: Kilmez |
|||
![]() |
1 | Helpless Oldie | 30 | Today, 09:19 AM Last post by: JonTom |
|||
![]() |
9 | larryri42 | 123 | Today, 02:03 AM Last post by: CatByte |
|||
![]() |
3 | jackbeau | 63 | Yesterday, 09:15 PM Last post by: inzanity |
|||
|
Time is now: 13th March 2010 - 05:41 PM |