
Can't Boot XP Pro SP3, but Recovery Console Installed
#16
Posted 24 March 2010 - 07:32 AM
Register to Remove
#17
Posted 24 March 2010 - 10:14 AM
K: [USB drive] \c
One last Kaspersky 2010 scan of K:\c moments ago showed no events. All files (less those shown below) are now retrievable.
These possibly notable events were logged during this project:
________________________________________________________________________________
_________________________________________
*3/22/2010 10:48:08 AM Deleted Trojan program Trojan-Downloader.Win32.CodecPack.ktn File K:\c\Documents and Settings\Richard Feldman\Desktop\ video-plugin.40030.exe High
3/22/2010 10:56:12 AM Deleted Trojan program Trojan-Dropper.Win32.Agent.brpk File K:\c\Documents and Settings\Richard Feldman\Local Settings\Application Data\ rdr_1267657585.exe.exe High
3/22/2010 11:46:17 AM Deleted Trojan program Trojan-Downloader.Win32.CodecPack.ktn File K:\c\Documents and Settings\Richard Feldman\Local Settings\Application Data\Mozilla\Firefox\Profiles\wzqz4ucw.default\Cache\ 8535FE71d01 High
3/22/2010 10:56:12 AM Deleted Trojan program Trojan.Win32.Agent.dmtl File K:\c\Documents and Settings\Richard Feldman\Local Settings\Application Data\rdr_1267657585.exe.exe// data0000.res High
3/22/2010 10:56:12 AM Deleted Trojan program Trojan-Dropper.Win32.Agent.brpk File K:\c\Documents and Settings\Richard Feldman\Local Settings\Application Data\rdr_1267657585.exe.exe// data0001.res High
3/22/2010 10:56:12 AM Deleted Trojan program Packed.Win32.Krap.as File K:\c\Documents and Settings\Richard Feldman\Local Settings\Temp\ Zvh.exe High
3/22/2010 10:56:12 AM Deleted Trojan program Packed.Win32.Krap.as File K:\c\Documents and Settings\Richard Feldman\Local Settings\Temp\ Zvg.exe High
3/22/2010 10:56:13 AM Deleted Trojan program Packed.Win32.Krap.aq File K:\c\Documents and Settings\Richard Feldman\Local Settings\Temp\ Zvf.exe High
3/22/2010 3:30:24 PM Deleted Trojan program Trojan-PSW.Win32.LdPinch.xew File K:\c\WINDOWS\ exeshl.dll High
3/22/2010 3:38:05 PM Deleted Trojan program Trojan.Win32.Tdss.axqv File K:\c\WINDOWS\Temp\ 000057c8.sys High
3/22/2010 3:38:16 PM Deleted Trojan program Packed.Win32.Krap.aq File K:\c\WINDOWS\system32\spool\prtprocs\w32x86\ 0000599a.tmp High
3/22/2010 3:37:23 PM Disinfected virus Rootkit.Win32.TDSS.u File K:\c\WINDOWS\system32\drivers\ atapi.sys High
________________________________________________________________________________
___________________________________________
* NOTE: "3/22/2010 10:48:08 AM Deleted Trojan program..." ON THE INFECTED COMPUTER THIS FILE NOW RESIDES IN THE REATOGO RECYCLE BIN, NOT C\Documents and Settings\Richard Feldman\Desktop (And no, it didn't change a thing- no help).
Rich
Edited by Rich97702, 24 March 2010 - 10:18 AM.
#18
Posted 24 March 2010 - 10:43 AM
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.

Find us on Facebook
Please LIKE and SHARE
Just a reminder that threads will be closed if no reply in 3 days.
#19
Posted 24 March 2010 - 10:51 AM
#20
Posted 24 March 2010 - 10:55 AM
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.

Find us on Facebook
Please LIKE and SHARE
Just a reminder that threads will be closed if no reply in 3 days.
#21
Posted 24 March 2010 - 10:58 AM
#22
Posted 24 March 2010 - 10:59 AM
Edited by paws, 24 March 2010 - 11:03 AM.
#23
Posted 24 March 2010 - 12:10 PM
"....and you can use Reatogo PE disc to obtain via the "magical jelly bean" the Windows XP licence key..."
Got it (and 3 other keys) I didn't realize the XP PRO # would differ from the # on the COA. Changes with Service Packs maybe?
I'm a bit of a software junkie so it would be nice to repair the machine that had all that stuff up and running on XP PRO SP3. On the other hand, this infection sounds like it should scare me into next week. Although I will be making a donation, I'm not paying for your time. If you both feel it best, all in all, not to try a repair, lets format and reinstall.
Thanks you guys,
Rich
#24
Posted 24 March 2010 - 12:29 PM
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.

Find us on Facebook
Please LIKE and SHARE
Just a reminder that threads will be closed if no reply in 3 days.
#25
Posted 24 March 2010 - 01:28 PM
Register to Remove
#26
Posted 25 March 2010 - 08:20 AM
#27
Posted 25 March 2010 - 09:15 AM
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.

Find us on Facebook
Please LIKE and SHARE
Just a reminder that threads will be closed if no reply in 3 days.
#28
Posted 26 March 2010 - 10:30 AM
Well done on completing the format and reinstall, I think this was the right course of action to take.
Have you taken a disc image?
Now your machine is working fast and sweet with no malware, and with all your applications installed, and running perfectly, now is the time to take a disc image, verify it, keep it safe on removable media, make a bootable CD ( for use in case that some time in the future Windows won't load,) and then in the event that you ever hit serious trouble that cannot be resolved in a timely or cost effective way by the normal means, you will be able to re-image your machine back to its"perfect state," in less time than it takes to walk the dog!
I favour Acronis, for disc imaging, and Paragon is also good, Norton Ghost has been providing imaging for years, but they all cost money! for free software take a look here:
http://www.thefreeco...pandimage.shtml
If you go down the imaging route and everyone else follows your good example then the likes of Ken and me will be out of a job!
Regards and good luck for the future
paws
#29
Posted 26 March 2010 - 01:48 PM
#30
Posted 26 March 2010 - 02:22 PM

2 user(s) are reading this topic
0 members, 2 guests, 0 anonymous users