This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Am I clean

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am new to this, so please be patient. Before Christmas, everything seamed to be ok. On Christmas the antivirus software stopped updating on 2 computers and I could not get it going on either one. I removed it on both. Then I could not get it installed on either. Mcafee virtual tech crashed on both. I noticed for the first time that CHKDSK was giving errors on both machines that I have never seen on either machine before. Mcafee support cleaned the computer, but could not get their software to install. They blamed Microsoft. Microsoft could not resolve the problems and blamed the drivers. The drivers were the latest and not corrupted and simultaneous failure of the hardware was blamed. Since then I have tested memory and harddrives without any failures and I had the test computer independently tested to verify it was without error.
I noticed that the CHKDSK errors that only occurred on the boot drives and did not resolve with CHKDSK /F on boot, stop when I disconnected the computer from the internet.
I restriped, low format, verify, mount the largest of the offered partitions, format it and reload XP PRO from scratch. I noticed that the computer had already had in it the name of my active workgroup and I did not have to type over the default "workgroup" as I had to do on all previous reloads of XP PRO. I manually check firewall and check to make sure it is installed. In the hour that it was taking to activate XP PRO I rechecked the firewall and it had been disabled and CHKDSK was giving errors.
I disconnected from the internet and repeated the process reconnected and ran your tests. Am I clean? Thank you and if I am clean, what do I do with the other computers? For completeness CHKDSK gives errors on this computer with Windows Essentials disabled and connected to the internet. They stop when I pull the plug from the internet. They did not start until I loaded Windows Essentials on this computer and it was running. After it completed its first clean scan and posted its results, it kept consuming 50% of the processor and I got the first CHKDSK errors at that time. Windows Essentials was not installed on either computer when the problems started.
defogger_disable by jpshortstuff (29.01.10.1)
Log created at 09:27 on 09/02/2010 (DAV34)

Checking for autostart values…
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers…


-=E.O.F=-GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-09 10:10:50
Windows 5.1.2600 Service Pack 3
Running: 5t4cqdmg.exe; Driver: C:\DOCUME~1\DAV34\LOCALS~1\Temp\pxtdapob.sys


—- Kernel code sections - GMER 1.0.15 —-

init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xBA9F6510]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2/7/2010 10:07:19 AM
System Uptime: 2/9/2010 8:56:59 AM (2 hours ago)

Motherboard: Gigabyte Technology Co., Ltd. | | 8KNXPU64
Processor: Intel® Pentium® 4 CPU 3.40GHz | Socket 478 | 3407/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 68 GiB total, 60.786 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Universal Serial Bus (USB) Controller
Device ID: PCI\VEN_8086&DEV;_25AD&SUBSYS;_50061458&REV;_02\3&13C0B0C5&0&EF;
Manufacturer:
Name: Universal Serial Bus (USB) Controller
PNP Device ID: PCI\VEN_8086&DEV;_25AD&SUBSYS;_50061458&REV;_02\3&13C0B0C5&0&EF;
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Universal Serial Bus (USB) Controller
Device ID: PCI\VEN_1106&DEV;_3104&SUBSYS;_12340925&REV;_51\4&2BA57D2F&0&5AF0
Manufacturer:
Name: Universal Serial Bus (USB) Controller
PNP Device ID: PCI\VEN_1106&DEV;_3104&SUBSYS;_12340925&REV;_51\4&2BA57D2F&0&5AF0
Service:

==== System Restore Points ===================

RP1: 2/7/2010 10:19:15 AM - System Checkpoint
RP2: 2/7/2010 11:05:05 AM - Installed DirectX 9.0
RP3: 2/7/2010 11:12:32 AM - Installed TEG-PCITXR 32bit Gigabit PCI Adatper
RP4: 2/7/2010 11:29:33 AM - Software Distribution Service 3.0
RP5: 2/7/2010 11:29:35 AM - Installed Windows XP KB842773.
RP6: 2/7/2010 11:29:53 AM - Installed Windows XP KB892130.
RP7: 2/7/2010 11:42:08 AM - Software Distribution Service 3.0
RP8: 2/7/2010 11:45:12 AM - Installed Windows XP Service Pack 2.
RP9: 2/7/2010 11:55:28 AM - Software Distribution Service 3.0
RP10: 2/7/2010 12:14:09 PM - Software Distribution Service 3.0
RP11: 2/7/2010 12:36:07 PM - Installed Windows XP WgaNotify.
RP12: 2/7/2010 12:38:41 PM - Software Distribution Service 3.0
RP13: 2/7/2010 1:03:11 PM - Software Distribution Service 3.0
RP14: 2/7/2010 1:20:42 PM - Software Distribution Service 3.0
RP15: 2/9/2010 9:07:53 AM - Software Distribution Service 3.0

==== Installed Programs ======================

Adobe Flash Player 10 ActiveX
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
ATI HydraVision
Enable S3 for USB Device
ERUNT 1.1j
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB976098-v2)
Intel® PRO Network Adapters and Drivers
Intel® PROSet
Malwarebytes' Anti-Malware
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Security Essentials
Realtek AC'97 Audio
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
TEG-PCITXR 32bit Gigabit PCI Adatper
Update for Windows Internet Explorer 8 (KB978506)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB978207)
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows XP Service Pack 3

==== Event Viewer Messages From Past Week ========

2/9/2010 10:14:23 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the SamSs service.
2/9/2010 10:13:53 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the ProtectedStorage service.
2/7/2010 11:22:00 AM, error: NetBT [4311] - Initialization failed because the driver device could not be created.
2/7/2010 10:19:16 AM, error: System Error [1003] - Error code 000000d1, parameter1 00000002, parameter2 00000007, parameter3 00000001, parameter4 f77f0001.

==== End Of File ===========================

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 10:13:19.84 on Tue 02/09/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1510 [GMT -6:00]

AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

============== Running Processes ===============

C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\d\dds.scr

============== Pseudo HJT Report ===============

EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [PRONoMgr.exe] c:\program files\intel\ncs\proset\PRONoMgr.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
StartupFolder: c:\docume~1\dav34\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1265563673841
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll

============= SERVICES / DRIVERS ===============

R0 a320raid;a320raid;c:\windows\system32\drivers\a320raid.sys [2004-8-6 242130]

=============== Created Last 30 ================

2010-02-09 08:58 274,288 a——- c:\windows\system32\mucltui.dll
2010-02-09 08:58 215,920 a——- c:\windows\system32\muweb.dll
2010-02-09 08:58 16,736 a——- c:\windows\system32\mucltui.dll.mui
2010-02-07 13:52 –d—– c:\docume~1\dav34\applic~1\Malwarebytes
2010-02-07 13:52 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-07 13:52 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-07 13:52 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-02-07 13:52 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-02-07 13:20 181,120 ——– c:\windows\system32\MpSigStub.exe
2010-02-07 13:18 –d—– c:\program files\Microsoft Security Essentials
2010-02-07 13:16 –d—– C:\d
2010-02-07 12:59 –dsh— c:\documents and settings\dav34\IECompatCache
2010-02-07 12:59 –dsh— c:\documents and settings\dav34\PrivacIE
2010-02-07 12:43 –d—– c:\windows\system32\scripting
2010-02-07 12:43 –d—– c:\windows\system32\en
2010-02-07 12:43 –d—– c:\windows\l2schemas
2010-02-07 12:42 –d—– c:\windows\network diagnostic
2010-02-07 12:34 –dsh— c:\documents and settings\dav34\IETldCache
2010-02-07 12:30 69,120 -c—— c:\windows\system32\dllcache\iecompat.dll
2010-02-07 12:30 –d—– c:\windows\ie8updates
2010-02-07 12:30 11,070,464 -c—— c:\windows\system32\dllcache\ieframe.dll
2010-02-07 12:30 1,985,536 -c—— c:\windows\system32\dllcache\iertutil.dll
2010-02-07 12:30 594,432 -c—— c:\windows\system32\dllcache\msfeeds.dll
2010-02-07 12:30 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll
2010-02-07 12:30 55,296 -c—— c:\windows\system32\dllcache\msfeedsbs.dll
2010-02-07 12:30 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll
2010-02-07 12:30 -cd-h— c:\windows\ie8
2010-02-07 12:08 208,896 -c—— c:\windows\system32\dllcache\unregmp2.exe
2010-02-07 12:02 272,128 -c—— c:\windows\system32\dllcache\bthport.sys
2010-02-07 12:00 153,088 -c—— c:\windows\system32\dllcache\triedit.dll
2010-02-07 12:00 128,512 -c—— c:\windows\system32\dllcache\dhtmled.ocx
2010-02-07 11:55 –d—– c:\windows\system32\PreInstall
2010-02-07 11:55 –d-h— c:\windows\$hf_mig$
2010-02-07 11:51 –d—– c:\windows\system32\wbem\AutoRecover
2010-02-07 11:47 316,640 a——- c:\windows\WMSysPr9.prx
2010-02-07 11:47 –d—– c:\windows\peernet
2010-02-07 11:47 –d—– c:\windows\provisioning
2010-02-07 11:46 –d—– c:\windows\ServicePackFiles
2010-02-07 11:45 26,144 a——- c:\windows\system32\spupdsvc.exe
2010-02-07 11:44 –d—– c:\windows\EHome
2010-02-07 11:41 11,264 ——– c:\windows\system32\spnpinst.exe
2010-02-07 11:41 7,208 ——– c:\windows\system32\secupd.sig
2010-02-07 11:41 4,569 ——– c:\windows\system32\secupd.dat
2010-02-07 11:35 –ds—- c:\windows\system32\Microsoft
2010-02-07 11:29 –d—– c:\windows\system32\bits
2010-02-07 11:29 438,784 a——- c:\windows\system32\xpob2res.dll
2010-02-07 11:29 354,816 a——- c:\windows\system32\winhttp.dll
2010-02-07 11:29 18,944 a——- c:\windows\system32\qmgrprxy.dll
2010-02-07 11:29 8,192 ——– c:\windows\system32\bitsprx2.dll
2010-02-07 11:29 7,168 ——– c:\windows\system32\bitsprx3.dll
2010-02-07 11:28 217,816 a——- c:\windows\system32\wuaucpl.cpl
2010-02-07 11:28 21,728 a——- c:\windows\system32\wucltui.dll.mui
2010-02-07 11:28 17,632 a——- c:\windows\system32\wuaueng.dll.mui
2010-02-07 11:28 15,072 a——- c:\windows\system32\wuaucpl.cpl.mui
2010-02-07 11:28 15,064 a——- c:\windows\system32\wuapi.dll.mui
2010-02-07 11:27 –dsh— c:\documents and settings\dav34\UserData
2010-02-07 11:27 12,980 a——- c:\windows\system32\wpa.bak
2010-02-07 11:16 22 a——- c:\windows\system32\ati64hlp.stb
2010-02-07 11:12 118,656 a—-r– c:\windows\system32\drivers\Rtnicxp.sys
2010-02-07 11:12 73,728 a—-r– c:\windows\system32\RtNicProp32.dll
2010-02-07 11:12 –d—– c:\program files\TRENDware International, Inc
2010-02-07 11:04 516,096 ——– c:\windows\system32\ati2sgag.exe
2010-02-07 11:04 290,816 a—-r– c:\windows\system32\atiiiexx.dll
2010-02-07 11:04 –d—– c:\program files\ATI Technologies
2010-02-07 10:28 –d—– c:\program files\Realtek Sound Manager
2010-02-07 10:28 –d—– c:\program files\AvRack
2010-02-07 10:27 131,072 a—-r– c:\windows\system32\e1000msg.dll
2010-02-07 10:27 118,784 a—-r– c:\windows\system32\Prounstl.exe
2010-02-07 10:27 24,064 a—-r– c:\windows\system32\IntelNic.dll
2010-02-07 10:27 2,725 a—-r– c:\windows\system32\e1000325.din
2010-02-07 10:27 125,952 a—-r– c:\windows\system32\drivers\e1000325.sys
2010-02-07 10:27 –d—– c:\program files\Gigabyte
2010-02-07 10:27 306,688 a——- c:\windows\IsUninst.exe
2010-02-07 10:19 –dsh— c:\windows\Installer
2010-02-07 10:19 –d—– c:\documents and settings\DAV34
2010-02-07 10:08 8,192 a——- c:\windows\REGLOCS.OLD
2010-02-07 10:06 1,875,968 ac—— c:\windows\system32\dllcache\msir3jp.lex
2010-02-07 10:05 –dsh— c:\documents and settings\all users\DRM
2010-02-07 10:04 –d—– c:\program files\common files\MSSoap
2010-02-07 10:03 –d-h— c:\program files\WindowsUpdate
2010-02-07 10:03 –d—– c:\program files\Online Services
2010-02-07 10:03 –d—– c:\program files\Messenger
2010-02-07 10:03 –d—– c:\program files\MSN Gaming Zone
2010-02-07 10:03 –d—– c:\program files\Windows NT
2010-02-07 03:55 –d–r– c:\documents and settings\all users\Documents
2010-02-07 03:47 –d—– c:\program files\common files\ODBC
2010-02-07 03:47 –d—– c:\program files\common files\SpeechEngines

==================== Find3M ====================

2010-02-07 12:45 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2010-02-07 10:03 21,640 a——- c:\windows\system32\emptyregdb.dat
2009-12-21 23:35 81,920 ——– c:\windows\system32\ieencode.dll
2009-12-21 13:14 916,480 a——- c:\windows\system32\wininet.dll
2009-11-21 09:51 471,552 a——- c:\windows\apppatch\aclayers.dll

============= FINISH: 10:17:13.96 ===============
Hope I did this as stated.
[external image: Posted Image]

DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



The issues with your computer that you list, doesn't appear to be related to Malware/Spyware/Virus but we can have a look.


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
[external image: Posted Image]
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
LDTate, thank you for your advice. I am glad it does not appear to be a virus/mal/spy. I have never had my computers act this way before. Are they going through adolescence or something? They just seamed to change into something other than what they were last year. As you may surmise correctly, I am no computer expert. How does what I stated above make any sense. It does not make any sense to me, however I am not a computer expert like you. Is it now normal for CHKDSK to give errors that only resolve when you unplug your computer from the internet. Somehow I was left out of the loop when this function was added to XP PRO. They never acted that way before. Did they grow up in some way and change their behavior? How does XP PRO now know what the real name of my "workgroup" is without my typing it in for it. Did it just grow up and now can do this for itself? How does XP PRO now have the ability to disable its own firewall? I was left out of the loop again. I see other programs do this to it all the time, but this is the first time I saw it do it to itself. I am perplexed, but I am glad I am dealing with a real expert that can explain this behavior in layman terms. . I will try to download HijackThis and comply with all of your suggestions as soon as possible and in the mean time ignore any of my ignorant babblings, but I would really like to know. The only changed behavior that I am noticing now is that CHKDSK errors occur then resolve when I unplug from the internet. This is behavior I do not recall seeing before. Thank you in advance.
Your question would be more suited for one of the Tech Team members, but the chkdsk thing? I've never seen that happen before myself as it doesn't make any sense to me either. I didn't have you run a HijackThis scan so just pot the results from the MBAM scan if you will.
LDTate, I thank you for your knowledgeable explanations. I, not being a computer expert, was thinking that, if I wanted to communicate with a computer through the internet and that was my only intent, then I would do so in a way that only happened when that computer was connected to the internet. However, since I am not a computer expert, what do I know. Now I am not a computer expert, but there are 2 more things that are happening to my test computer now. The first is what I have seen on another computer that is also giving CHKDSK errors and that is that the IE8 top information bar is black on black. I also have no link to "hijackThis" on your post. However, I can clearly see it from another computer that is not giving CHKDSK errors.
Ok, I see. I am logged in.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:04:09 AM, on 2/10/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1265563673841
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe

–
End of file - 3304 bytes
The black on black went away.
All I can tell you is your computer looks free of any infections. If you want to ask one of the Tech Team members about the chkdsk issues you can start a new topic in the Windows Forum.
LDTate, I thank you for all your input and time and appreciate all your advice. I am personally very disgusted with Windows in general. It now has thrown away all my sign in passwords and I have to manually type them in all over again. Just cannot win with Windows. My disgust is solely with Windows and all who attempt to add malicious content to it and do definitely appreciate you and all in the community that are taking their time to help slow this unending tide and keep computers semi-useful until a real solution is found.
In IE click on Tools > Internet Options and click on the Content tab. In there just click on the Settings button under Autocomplete and check the box for "Prompt me to save passwords". Click OK and you're done. Note: Make sure Web Addresses and Forms are also checked
LDTate, again I do appreciate your help, but it is not so much as to get passwords saved as it is to keep Windows from throwing them all away and forcing me to retype them all back into it. Is there a switch to stop Windows from doing this that I am not aware? There just might be one that I am not aware. If there is, I definitely can benefit from it, since it seems to be a difficult habit to break Windows of recently.
LDTate, I feel like I got my old machines back. I installed ZoneAlarm on both XP PRO computers and the CHKDSK errors stopped immediately on both. I no longer have to unplug from the internet to fix the errors. It has a very busy process called zlclient that keeps popping up in Task Manager every couple of seconds and keeps fixing all the CHKDSK errors on both. Unfortunately, it will not fix my Win 7 Pro computer. I had to switch to it when both XP Pro computers failed in order to keep reading the PNG files that were being sent to me. It then refused to read any PGN files I created and despite that I have checked in Explorer to work in protected mode and block pop ups, it does neither. It also started giving a “can not do requested operation” to sfc /scannow. I did an update/upgrade reinstall of Win 7 Pro and now sfc /scannow verifies, but the other problems persist. I removed a “hijack display” virus from it with “Malwarebytes”, but it now simply crashes after I loaded ZoneAlarm in it every time I try to send anything in Explorer. Otherwise everything I have tested on it is functioning normally. All online scanners, Malwarebytes and Essentials say it is free of virus/malware. I still do not have any answers from “Windows” forum as to what caused the CHKSSK errors in the first place. Another question. Should I ever accept any of the connections FROM the internet that are now being blocked by ZoneAlarm? Also, is it normal for zlclient to constantly being the only very active process in XP PRO computers other then the activity of the CHKDSK tests that are now coming out clean? Basically, no other processes are running in Task Manager. Thank you in advance.
LDTate, thank you again. I still have not heard anything from the “Windows” forum, however , the CHKDSK errors do come back when I uninstall ZoneAlarm and then go away when I reinstall it. ZA also consumes 7 to 9 percent of computer power on one of the computers at rest with no virus program and no other active process. This 7 to 9 percent is a constant range fluctuation and only goes up if I introduce some internet activity. Is this normal? Thank you in advance.
LDTate, , I finally got Win 7 Pro to not have any CHKDSK errors and to work in protected mode, but I had to have it unplugged from the internet during the entire reinstall and reformat of the boot drive. Then and only then did I get it to work. I hope this information is useful to all the other non computer experts here. I also learned to use 8 year old scsi raid 15k drives and not to get the slow solid state drives if you are going to go through all the testing I just did. This lack of speed of the solid states was confirmed to me by the hard drive support people. Now, since I am not getting CHKDSK errors, I can use CHKDSK for its intended purpose and be reasonably assured that the computer is not making unwanted contact to unknown people for unknown purposes. Thank you and the others for all your help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI