This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan/malware infection - now have .dll files missing

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

It worked:

Group:

- Administrators (DAVEMOSS\Administrators) - All permissions (local & remote launch; local & remote activation)
- INTERACTIVE - local permissions only
- SYSTEM - local permissions only

Users:

- Internet Guest Account (DAVEMOSS\IUSR_YOUR-A97EC67E86) - All permissions
- Launch IIS Process Account (DAVEMOSS\IWAM_YOUR-A97EC67E86) - All permissions




OTL log:

OTL logfile created on: 22/10/2010 19:11:16 - Run 5
OTL by OldTimer - Version 3.2.15.2 Folder = C:\Documents and Settings\Dave\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,023.00 Mb Total Physical Memory | 376.00 Mb Available Physical Memory | 37.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 228.49 Gb Total Space | 156.02 Gb Free Space | 68.29% Space Free | Partition Type: NTFS
Drive D: | 451.83 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: DAVEMOSS | User Name: Dave | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Custom Scans ==========



< MD5 for: HAL.DL_ >
[2004/08/03 22:59:20 | 000,053,234 | —- | M] () MD5=84CBCC76EBD13E1370FFE62825704339 – C:\cmdcons\HAL.DL_
[2004/08/10 20:00:00 | 000,053,234 | —- | M] () MD5=84CBCC76EBD13E1370FFE62825704339 – C:\i386\hal.dl_

< MD5 for: HAL.DLL >
[2008/04/13 19:31:28 | 000,134,400 | —- | M] (Microsoft Corporation) MD5=4329EE7D502C9113EBA0F9570392F5EE – C:\WINDOWS\system32\HAL.DLL
[2008/04/13 19:31:32 | 000,105,344 | —- | M] (Microsoft Corporation) MD5=6DB1E72AD3B372DFC451B7F54BA08AA7 – C:\WINDOWS\ServicePackFiles\i386\hal.dll
[2004/08/10 20:00:00 | 000,134,400 | —- | M] (Microsoft Corporation) MD5=DFCE51FD96909D1B97D4A1A72D060D77 – C:\WINDOWS\$NtServicePackUninstall$\hal.dll

< MD5 for: HAL.IN_ >
[2004/08/10 20:00:00 | 000,001,582 | —- | M] () MD5=596EBAE4748DF7D289554ACFD9C14897 – C:\i386\hal.in_

< MD5 for: HAL.INF >
[2004/08/10 20:00:00 | 000,006,053 | —- | M] () MD5=7C10F1B5639ACF1949A82EFA6CB94A54 – C:\WINDOWS\inf\hal.inf

< MD5 for: HAL.PNF >
[2005/12/02 09:51:53 | 000,011,468 | —- | M] () MD5=DA1ECBA7F9F4C68FF44E316143F52D4B – C:\WINDOWS\inf\hal.PNF

< >

< End of report >
Hi say-no-2- trojans, The file seems to been in the correct location. Interesting that you recieve that message and windows still loads? The one folder we checked is related to a tablet PC is this what you are using or is windows actually loading on your computer? Those settings are not the same as I have. Let me check a few computers and see if I can determine what the default should be. Thanks
Hi, windows is loading on the computer. To answer one of your previous Q's ref having original CD, i only have my MESH Recovery CD which is the only disc I got when I bought the PC
Hi say-no-2-trojans,

Windows could not start because the following file is missing or corrupt:
\System32\hal.dll
Please reinstall a copy of the above file


It's just strange that you would recieve this message and Windows would still load.

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
Thanks
MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000001c Kernel Drivers (total 143): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806FF000 \WINDOWS\system32\hal.dll 0xF7C2F000 \WINDOWS\system32\KDCOM.DLL 0xF7B3F000 \WINDOWS\system32\BOOTVID.dll 0xF76E0000 ACPI.sys 0xF7C31000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF76CF000 pci.sys 0xF772F000 isapnp.sys 0xF7CF7000 pciide.sys 0xF79AF000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF773F000 MountMgr.sys 0xF76B0000 ftdisk.sys 0xF7C33000 dmload.sys 0xF768A000 dmio.sys 0xF79B7000 PartMgr.sys 0xF774F000 VolSnap.sys 0xF7672000 atapi.sys 0xF775F000 disk.sys 0xF776F000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF7652000 fltmgr.sys 0xF75FB000 SYMDS.SYS 0xF75E9000 sr.sys 0xF7540000 SYMEFA.SYS 0xF7529000 KSecDD.sys 0xF749C000 Ntfs.sys 0xF746F000 NDIS.sys 0xF7455000 Mup.sys 0xF78EF000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF6938000 \SystemRoot\system32\DRIVERS\nv4_mini.sys 0xF6924000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF68FC000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xF78FF000 \SystemRoot\system32\DRIVERS\atl01_xp.sys 0xF7A0F000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF68D8000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF7A17000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF685D000 \SystemRoot\system32\drivers\hcw88vid.sys 0xF790F000 \SystemRoot\system32\drivers\STREAM.SYS 0xF683A000 \SystemRoot\system32\drivers\ks.sys 0xF7BCF000 \SystemRoot\system32\drivers\hcw88aud.sys 0xF67F1000 \SystemRoot\system32\drivers\hcw88tse.sys 0xF67DD000 \SystemRoot\system32\DRIVERS\parport.sys 0xF7CB7000 \SystemRoot\system32\DRIVERS\ASACPI.sys 0xF791F000 \SystemRoot\system32\DRIVERS\serial.sys 0xF7BD3000 \SystemRoot\system32\DRIVERS\serenum.sys 0xF792F000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF6699000 \SystemRoot\system32\DRIVERS\btkrnl.sys 0xF7D27000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF793F000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF7BDF000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF6682000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF794F000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF795F000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF7A1F000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF6671000 \SystemRoot\system32\DRIVERS\psched.sys 0xF796F000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF7A27000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF7A2F000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF6641000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xF797F000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF7A37000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF7A3F000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7CB9000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF65E3000 \SystemRoot\system32\DRIVERS\update.sys 0xF6E75000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF65B5000 \SystemRoot\system32\drivers\windrvr6.sys 0xF7CBB000 \SystemRoot\system32\drivers\USBD.SYS 0xF799F000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF3F83000 \SystemRoot\system32\drivers\ADIHdAud.sys 0xF3F5F000 \SystemRoot\system32\drivers\portcls.sys 0xF77BF000 \SystemRoot\system32\drivers\drmk.sys 0xF3F3F000 \SystemRoot\system32\drivers\AEAudio.sys 0xF3EDF000 \SystemRoot\system32\drivers\Senfilt.sys 0xF6D6F000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF6D5F000 \SystemRoot\system32\drivers\HCW88BAR.sys 0xF2E7A000 \SystemRoot\system32\drivers\hcw88tun.sys 0xF2E54000 \SystemRoot\system32\drivers\hcw88bda.sys 0xF7C0B000 \SystemRoot\system32\drivers\BdaSup.SYS 0xF7C1F000 \SystemRoot\System32\Drivers\i2omgmt.SYS 0xF25AB000 \SystemRoot\system32\drivers\NIS\1201000.025\SRTSP.SYS 0xF7A5F000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0xF2588000 \SystemRoot\system32\drivers\NIS\1201000.025\Ironx86.SYS 0xF2513000 \SystemRoot\system32\DRIVERS\U2KG54L.sys 0xF7A67000 \SystemRoot\system32\DRIVERS\usbprint.sys 0xF7C27000 \SystemRoot\system32\DRIVERS\BrScnUsb.sys 0xF7A6F000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0xF7C2B000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF6CFF000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF7A77000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF77FF000 \SystemRoot\system32\DRIVERS\IrBus.sys 0xF7415000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0xF7411000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xF7A8F000 \SystemRoot\system32\DRIVERS\hidir.sys 0xF780F000 \SystemRoot\system32\drivers\NIS\1201000.025\SRTSPX.SYS 0xF24C5000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 0xF7CD3000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7E4D000 \SystemRoot\System32\Drivers\Null.SYS 0xF7CD5000 \SystemRoot\System32\Drivers\Beep.SYS 0xF7A7F000 \SystemRoot\System32\drivers\vga.sys 0xF7CD7000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7CD9000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF7A87000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF7A97000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF65A5000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xF2330000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xF22D7000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xF227E000 \SystemRoot\system32\drivers\NIS\1201000.025\SYMTDI.SYS 0xF2258000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF788F000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xF21D8000 \SystemRoot\system32\DRIVERS\netbt.sys 0xF21B6000 \SystemRoot\System32\drivers\afd.sys 0xF789F000 \SystemRoot\system32\DRIVERS\netbios.sys 0xF218B000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xF211B000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF78DF000 \SystemRoot\System32\Drivers\Fips.SYS 0xF20BD000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 0xF20A0000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0xF1FF4000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20101001.001\BHDrvx86.sys 0xF6D8F000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xF1FB4000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF7CDD000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF7431000 \SystemRoot\System32\drivers\Dxapi.sys 0xF7AC7000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7D9F000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\nv4_disp.dll 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xBA4F8000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xB9253000 \SystemRoot\system32\drivers\wdmaud.sys 0xBA438000 \SystemRoot\system32\drivers\sysaudio.sys 0xB8E21000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xF7A07000 \??\C:\WINDOWS\system32\drivers\btserial.sys 0xB8D9F000 \??\C:\WINDOWS\system32\drivers\btslbcsp.sys 0xB8B2E000 \SystemRoot\System32\Drivers\HTTP.sys 0xB88A6000 \SystemRoot\system32\DRIVERS\srv.sys 0xB8976000 \SystemRoot\system32\DRIVERS\secdrv.sys 0xF7CB1000 \SystemRoot\system32\drivers\MSPQM.sys 0xB765C000 \??\C:\WINDOWS\system32\FsUsbExDisk.SYS 0xB67E4000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20101021.003\IDSxpx86.sys 0xB6696000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101023.004\NAVEX15.SYS 0xB6682000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20101023.004\NAVENG.SYS 0xB5E57000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 56): 0 System Idle Process 4 SYSTEM 788 C:\WINDOWS\system32\smss.exe 844 csrss.exe 876 C:\WINDOWS\system32\winlogon.exe 920 C:\WINDOWS\system32\services.exe 932 C:\WINDOWS\system32\lsass.exe 1104 C:\WINDOWS\system32\svchost.exe 1152 svchost.exe 1196 C:\WINDOWS\system32\svchost.exe 1316 svchost.exe 1416 svchost.exe 1652 C:\WINDOWS\system32\spoolsv.exe 216 C:\WINDOWS\explorer.exe 520 C:\WINDOWS\ehome\ehtray.exe 560 C:\Program Files\Java\jre6\bin\jusched.exe 592 C:\Program Files\Analog Devices\Core\smax4pnp.exe 644 C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe 672 C:\Program Files\QuickTime\QTTask.exe 680 C:\Program Files\iTunes\iTunesHelper.exe 280 C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe 1276 C:\PROGRA~1\MSNMES~1\msnmsgr.exe 1288 C:\Program Files\Windows Media Player\wmpnscfg.exe 1300 C:\WINDOWS\system32\ctfmon.exe 1464 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe 1476 C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe 1484 C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe 1596 svchost.exe 1740 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 1760 C:\Program Files\Bonjour\mDNSResponder.exe 1800 C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe 1816 C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe 1828 C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe 1856 C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe 1404 C:\WINDOWS\ehome\ehrecvr.exe 1892 C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe 1944 C:\WINDOWS\ehome\ehSched.exe 180 C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe 400 C:\WINDOWS\system32\FsUsbExService.Exe 584 C:\Program Files\Java\jre6\bin\jqs.exe 1304 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 1528 C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe 2104 C:\WINDOWS\system32\nvsvc32.exe 2204 svchost.exe 2216 C:\WINDOWS\system32\svchost.exe 2320 mcrdsvc.exe 3444 C:\Program Files\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe 3956 C:\WINDOWS\ehome\ehmsas.exe 568 C:\WINDOWS\system32\svchost.exe 2624 wmpnetwk.exe 3136 C:\Program Files\iPod\bin\iPodService.exe 1212 C:\WINDOWS\system32\dllhost.exe 3492 alg.exe 2088 C:\Program Files\Internet Explorer\iexplore.exe 3720 C:\Program Files\Internet Explorer\iexplore.exe 2640 C:\Documents and Settings\Dave\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000001`19697c00 (NTFS) PhysicalDrive0 Model Number: ST3250820AS, Rev: 3.AAC Size Device Name MBR Status ——————————————– 232 GB \\.\PhysicalDrive0 Mesh Computers MBR code detected SHA1: 55BF8DC9C4872B5E44B1DE3E987229A1FA42C844 Done!
Hi say-no-2-trojans, Let's see if we can get rid of the hal.dll error. The last OTL log shows there may be a CD in the drive. If so please remove it and reboot the computer. If the message is still there on restart check the boot order in the bios. Make sure it's set to your hard drive, C: if that option is available. Let me know how you made out.
Tried it without the disc and the message didn't appear - tried it again with the disc and still no message. So that seems to be sorted. The only problem I'm getting now, is where before (before this whole saga began) the computer would just boot up before without ever having to select options, I'm now offered 4 of them: -Microsoft Windows Recovery Console -do not select this [debugger enabled] -Windows XP Media Center Edition -Microsoft Windows XP Professional Setup with the bottom option the default selection. Before getting rid of the hal.dll error message, if the 4th option was left to load on it's own, the computer would just reboot and obviously go round in circles. Now that the hal.dll error message is no longer displayed, if this 4th option is left to load on it's own instead of rebooting, it displays the hal.dll error message again - with or without a disc in D drive. I'm guessing that this all started when I loaded the MESH Recovery disc before contacting you, in an effort to fix these problems. If so, how can I get the computer to load directly into the 3rd option, or get rid of these option altogether? Thanks
Hi

]-Microsoft Windows Recovery Console
-do not select this [debugger enabled]-Windows XP Media Center Edition
-Microsoft Windows XP Professional Setup

I think I see the problem. Looks like when you used the Mesh disk it tried to install XP pro and it failed.

The bolded lines were put there by combofix. In opinion the first one should be there by default on XP computers. It's a way to access some parts of the operating system to make repair if needed. The second is just another alternative. So those 2 are no problem.

The third line is your operating system and the fourth is the failed install.

When you used the Mesh disk were you given the option to install XP?

Let's see what we can do. Please post the contents of this file

C:\boot.ini

Thanks
Can't remeber if i was given the option to install XP or not - if I was to make a guess it would be not. Just looked for that file and I can't find it there
Hi

Do this first then look for the file.

Open windows explorer (right click the Start button and click Explore)

At the top of windows explorer, click tools, folder options, click the
view tab
  • check Display the contents of system folders
  • check Show hidden files and folders
  • uncheck "Hide extensions for known file types" box
  • uncheck "Hide protecting operating system files" box
Click apply, click ok
[Boot Loader] Timeout=2 Default=C:\$WIN_NT$.~BT\BOOTSECT.DAT [Operating Systems] C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons UnsupportedDebug="do not select this" /debug multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect C:\$WIN_NT$.~BT\BOOTSECT.DAT="Microsoft Windows XP Professional Setup"
Hi say-no-2-trojans,

The boot,ini is pointing at the failed installed. Before we do anything with the boot.ini we need to confirm you can boot into the recovery console. You may be presented with 2 operating systems to boot to. If you are, choose Windows XP Media Center Edition

Start the computer, you should be presented with an option to either start Windows or the Microsoft Recovery Console. Use the arrow keys to select the Recovery console, press enter.

- You should now see a list of installations and the prompt "Which Windows Installation would you like to log on to?"
Select the appropriate number for the Windows installation that you want to repair. If you only have one, press 1 and press enter
-If you are prompted, type the Administrator password. If the administrator password is blank, just press ENTER.

You should now have a C:\windows> prompt

Type exit and hit enter. Your computer should then boot to windows.

Let me know if you were successful.

Thanks
Hi say-no-2-trojans,

Good.

Open windows explorer and navigate to C:\
  • locate boot.ini
  • right click the file and select rename
  • on the keyboard type boot.old and hit enter
  • ok any confirmations you may recieve

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

[Boot Loader]
Timeout=2
Default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[Operating Systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
C:\$WIN_NT$.~BT\BOOTSECT.DAT="Microsoft Windows XP Professional Setup"

In the notepad
  • Click File, Save as…, and set the Save in to your C:\ (it may appear as Local Disk (C:))
  • In the filename box, type (including quotation marks) as the filename: "boot.ini"
  • Click save

Check in C:\ and confirm you now have a file named boot.ini.

If you do, reboot the computer. On startup is it starting from the correct line?
Starts up perfectly now, thanks. Just discovered another problem - all the games in the 'Games' selection off the Start button/All Programs have disappeared (eg Minesweeper, Solitaire etc). I've tried searching for them on the computer, but they're no longer located. How do I get them back - by downloading off Microsoft website? The other question is - how do I know what else I have lost or had changed since this infection? Otherwise I can't see any more problems

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI