This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please review my Log

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks, really, I appreciate the help your giving me and been sticking with me through this whole mess
I read that information and tried it, still the same "your version installed now is newer than on the cd"
But, I will continue to try throughout the night.

Heres a hjt log

Logfile of HijackThis v1.99.1
Scan saved at 6:27:33 PM, on 3/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1199413662829
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{08EAC639-0F1E-4130-9EA2-98E8C19E6BB2}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{08EAC639-0F1E-4130-9EA2-98E8C19E6BB2}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
well i did click install windows, i never got anything saying press any key to continue when I did click install windows, It said my version installed now is newer than the version on the cd and thats as far as I can go
Ok Bizzy we have tried this hard enough.
Let's clean this machine. We probably have most of that done already.


__________________________________
I want you to delete the combofix.exe you already have. It has been updated several times since you and I started.
So I want a scan by the latest version.

Please run it the way I ask you to.



1. Download Combo fix from one of these locations.
* IMPORTANT !!! Place combofix.exe on your Desktop

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

2. Click start/run and copy and Paste this in exactly using the picture below for reference:

"%userprofile%\desktop\combofix.exe" /killall


[external image: Posted Image]

3. Combo will begin to run DO NOTHING while this is happeneing.
  • It will kill a few processes and disconnect you from the internet.
  • If by chance it stops prematurly you can re-establish your internet connection by restarting your computer.
  • This needs to be done so the program can work most efficiently for you.
Do not attempt to use the internet or anything else while it's doing its job for you.

If when it's completed you can not get on the internet just reboot the computer

Post the log from comboFix for me located in
c:\comboFix.txt





______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.

  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Registry function to clean anything with this program. Having anything auto clean your regisrty is risky).


_________________________________

Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan







_________________________
In your next reply I would like to see:
  • ComboFix
  • The report from Kasperskys
  • Let me know how the machine is behaving at this point.
  • Any issues we need to address ?
Gosh wow.
Scan 1 hour and 37 minutes, But my internet disconnected.
Im gonna rescan and post the log, but heres a combofix.
and that kaspersky did find like 13 virus
Also, only issue is sound, and internet. Not sure if its the infection but my internet seems to time out/disconnect at around 1-2 to even 3 hours of log on
my computer is the same as my second HJT i posted on page one


ComboFix 08-03-08.1 - Donald 2008-03-08 17:49:30.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.278 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
.

2008-03-01 18:47 . 2002-04-03 15:51 425,472 –a—— C:\WINDOWS\system32\tbc39.tmp
2008-02-26 16:01 . 2002-04-03 15:51 425,472 –a—— C:\WINDOWS\system32\tbc31.tmp
2008-02-25 16:40 . 2008-02-25 16:40 d——– C:\WINDOWS\ERUNT
2008-02-24 17:41 . 2008-02-24 17:41 d——– C:\Documents and Settings\Donald\Application Data\Grisoft
2008-02-24 17:41 . 2007-05-30 04:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-24 17:35 . 2008-02-24 17:35 d——– C:\Program Files\CCleaner
2008-02-22 00:52 . 1998-09-24 13:03 171,967 –a—— C:\WINDOWS\system32\Odbcjet.hlp
2008-02-22 00:52 . 2001-05-14 18:15 10,368 –a—— C:\WINDOWS\system32\drivers\omci.sys
2008-02-22 00:52 . 1998-09-24 13:03 7,348 –a—— C:\WINDOWS\system32\Odbcjet.cnt
2008-02-20 00:09 . 2008-02-20 00:09 d——– C:\Program Files\Common Files\Turtle Beach
2008-02-19 21:31 . 2002-04-03 15:51 425,472 –a—— C:\WINDOWS\system32\tbc10.tmp
2008-02-19 18:01 . 2008-03-08 17:52 5,558 –a—— C:\WINDOWS\system32\Config.MPF
2008-02-19 17:58 . 2007-07-21 09:08 201,288 –a—— C:\WINDOWS\system32\drivers\mfehidk.sys
2008-02-19 17:58 . 2007-07-13 09:20 113,952 –a—— C:\WINDOWS\system32\drivers\Mpfp.sys
2008-02-19 17:58 . 2007-07-24 07:40 79,304 –a—— C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-02-19 17:58 . 2007-07-21 09:08 40,488 –a—— C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-02-19 17:58 . 2007-07-21 09:08 35,240 –a—— C:\WINDOWS\system32\drivers\mfebopk.sys
2008-02-19 17:58 . 2007-07-24 12:02 33,800 –a—— C:\WINDOWS\system32\drivers\mferkdk.sys
2008-02-19 17:57 . 2008-02-19 17:57 d——– C:\Program Files\McAfee.com
2008-02-19 17:57 . 2008-02-19 18:42 d——– C:\Program Files\Common Files\McAfee
2008-02-19 17:56 . 2008-02-19 20:19 d——– C:\Program Files\McAfee
2008-02-19 17:27 . 2008-02-19 18:00 d——– C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-18 18:07 . 2008-02-19 17:46 d——– C:\Program Files\Spyware Doctor
2008-02-18 18:07 . 2008-02-18 18:07 d——– C:\Documents and Settings\Donald\Application Data\PC Tools
2008-02-18 18:07 . 2005-09-23 07:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2008-02-18 18:07 . 2005-07-06 17:13 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2008-02-18 18:07 . 2005-07-06 17:13 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2008-02-18 18:07 . 2007-05-23 16:58 83,024 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-02-18 18:07 . 2007-05-23 16:58 57,424 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-02-18 18:07 . 2007-05-23 16:58 53,840 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-02-18 18:07 . 2007-05-23 16:58 39,376 –a—— C:\WINDOWS\system32\drivers\ikfileflt.sys
2008-02-18 18:07 . 2007-05-23 16:58 29,264 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-02-18 05:33 . 2008-02-18 05:33 d——– C:\Documents and Settings\All Users\Application Data\Uniblue
2008-02-18 02:08 . 2008-03-02 03:01 d——– C:\Program Files\RegScrubXP
2008-02-18 02:06 . 2007-12-04 15:44 23,600 –a—— C:\WINDOWS\system32\drivers\TVICHW32.SYS
2008-02-18 01:55 . 2005-08-25 18:18 118,784 –a—— C:\WINDOWS\system32\MSSTDFMT.DLL
2008-02-18 01:28 . 2008-03-05 22:28 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-08 11:00 ——— d—–w C:\Program Files\Starcraft
2008-03-02 10:49 ——— d—–w C:\Program Files\Warcraft III
2008-03-02 03:00 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-19 03:40 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-02-19 03:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-18 13:32 ——— d—–w C:\Documents and Settings\Donald\Application Data\Uniblue
2008-02-14 10:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-14 10:21 ——— d—–w C:\Program Files\QuickTime
2008-01-31 06:58 ——— d—–w C:\Program Files\LimeWire
2008-01-31 05:39 ——— d—–w C:\Program Files\Microsoft Games
2008-01-08 23:57 94,208 —-a-w C:\WINDOWS\ScUnin.exe
.

——- Sigcheck ——-

2001-08-18 04:00 12800 0f7d9c87b0ce1fa520473119752c6f79 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
2004-08-04 00:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
2008-02-19 17:51 16896 35de7705f9fb23992740523b5c9fdac5 C:\WINDOWS\system32\svchost.exe

2001-08-18 04:00 430080 2b0e480e975ee51f2d5ce5f068fed6e2 C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2004-08-04 00:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2004-08-04 00:56 506368 aa296c1d23a15a9e878ab0796b1125b1 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 14:53 88024]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 22:33 582992]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 01:25 6731312]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Documents and Settings\Donald\My Documents\My Pictures\bizzy, thugsta.jpg
FriendlyName=

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RSVP"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [2004-08-03 22:31]
S3 Aldebaran;Aldebaran - Storage Filter Drivers;C:\WINDOWS\system32\Drivers\Aldebaran.sys []
S3 iMSPQMn;iMSPQMn;C:\DOCUME~1\Donald\LOCALS~1\Temp\iMSPQMn.sys []
S3 tbcspud;Santa Cruz Driver;C:\WINDOWS\system32\drivers\tbcspud.sys []
S3 tbcwdm;Santa Cruz WDM Driver;C:\WINDOWS\system32\drivers\tbcwdm.sys []
S3 vtdg46xx;vtdg46xx;C:\PROGRA~1\TURTLE~1\SANTAC~1\CONTRO~1\vtdg46xx.sys []

.
Contents of the 'Scheduled Tasks' folder
"2008-02-20 02:41:39 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe'
"2008-02-20 02:41:39 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2008-02-18 13:47:01 C:\WINDOWS\Tasks\Uniblue SpyEraser Nag.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2008-02-18 13:46:58 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-08 17:54:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2008-03-08 17:57:05 - machine was rebooted [Donald]
ComboFix-quarantined-files.txt 2008-03-09 01:57:00
ComboFix2.txt 2008-02-26 00:17:18
ComboFix3.txt 2008-02-19 01:06:59
ComboFix4.txt 2008-02-18 14:17:53
The kaspersky scan should have ended like this.

[external image: Posted Image]

At which point you save it to your desktop so it's easy to find. Naming it what ever you like.

I am sorry but if you didn't save the log I am going to need it. You may have to run the scan again.
>xo..i never got a window like that, but right now its scanning. I will post the log in about 2 hours :yeah: ok its done here it is, i didnt fully run the activex the first time Also, almost everytime when I was scanning, my internet cut out and I would have to restart computer to get a connection. Do you have any ideas on what it could be? Sunday, March 09, 2008 9:29:45 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 10/03/2008 Kaspersky Anti-Virus database records: 620850 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer A:\ C:\ D:\ E:\ Scan Statistics Total number of scanned objects 47140 Number of viruses found 13 Number of infected objects 19 Number of suspicious objects 2 Duration of the scan process 01:35:36 Infected Object Name Virus Name Last Action C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\Events.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{C9C4B3A8-5E4B-4E20-A23D-69E94F6BD23C}.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Data\TFR2.tmp Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant.zip/v1.8.4/wbuninst.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WebBuyingAssistant.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\Donald\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Donald\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\Donald\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Donald\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Donald\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Donald\Local Settings\History\History.IE5\MSHist012008030920080310\index.dat Object is locked skipped C:\Documents and Settings\Donald\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Donald\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Donald\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Donald\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Donald\UserData\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP196\A0058459.exe Infected: not-a-virus:AdWare.Win32.BHO.abh skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP264\A0068547.exe Infected: Trojan.Win32.Agent.djw skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0068602.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0068618.exe Infected: Trojan-Downloader.Win32.Tibs.tb skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0068620.exe Infected: not-virus:Hoax.Win32.Renos.bbm skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0068639.exe Infected: Trojan.Win32.DNSChanger.apn skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0076292.exe/mwsSetup.CommonCodebase.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0076292.exe CAB: infected - 1 skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0076295.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.as skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0076296.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0076297.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0076298.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0076305.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.bc skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP265\A0080656.exe Infected: Trojan-Downloader.Win32.Tibs.tb skipped C:\System Volume Information\_restore{2A331A2F-5902-4805-8F67-0A4B79A5F4BB}\RP269\change.log Object is locked skipped C:\Valve\Steam\steamapps\lil_ripsta34\counter-strike source\cstrike\pony\pony.zip/Pony.exe/vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped C:\Valve\Steam\steamapps\lil_ripsta34\counter-strike source\cstrike\pony\pony.zip/Pony.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.c skipped C:\Valve\Steam\steamapps\lil_ripsta34\counter-strike source\cstrike\pony\pony.zip ZIP: infected - 2 skipped C:\WINDOWS\5.tmp Infected: not-a-virus:AdWare.Win32.LinkOptimizer.a skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\winlogon.exe Infected: Trojan.Win32.Patched.aa skipped C:\WINDOWS\TEMP\mcafee_M3aBdOPicm28cAm Object is locked skipped C:\WINDOWS\TEMP\mcmsc_IcQEs5ZQuWvcjW3 Object is locked skipped C:\WINDOWS\TEMP\mcmsc_YLXgbEBlB3XsQoU Object is locked skipped Scan process completed. dayam, sorry i saved it a webpage txt and its so messy , i thought i could change it when it was on desktop

dayam, sorry i saved it a webpage txt and its so messy , i thought i could change it when it was on desktop


You need to start following direction more carefully. Some things we might do if you go at them thinking "
I can do this another way" you may just kill your machine. And I don't want that responsibility.


Did you receive a private message from me ?
Pleas e look closely to the top right of the page.
Scroll to the top and look for 1 New message and click that.

My Controls · View New Posts · My Assistant · 1 New Messages




There are some experts that have seen this thread that think a reformat is really your best option.
Hi again Bizzy ,

Print these instructions out so you have them in front of you during this process.


Also completely read through them at least once before you begin as some of the steps require you to act within a few seconds. Ask questions before you get started if you have any.

First let's download and save a new antivirus and save it to a CD or usb flash drive for use later.

I will list 2 free and reputable anti virus programs. Please just choose one.

Avast

Avira AntiVir Personal Edition Classic


Go there and download and save that to a disk or flash drive/usb stick
we will install that later.



IMPORTANT!!!!
If you used a flash drive/usb stick to save the program on, REMOVE it from the machine before continuing.
DO NOT LEAVE IT IN DURING THE REFORMATTING PROCESS. The only thing I want left in the machine is the one windows instalation cd.



Next I want to ensure that the settings you changed the other day took and stayed. If they didn't a new Battery may be in order to continue. You can find them at any electronic shop for about 1 dollar US.
If you found that the CD rom wasn't the first choice that may be why were having problems.

Do this following the directions below.

______________________________________________________
1. Place your windows installation CD in the cd rom.
Close any windows that open from it. Just ignore them.

2. Restart your computer.

3. When the blue Dell™ logo appears, press F2 immediately.

  • This will take you to a completely different looking screen. In there you will find the different settings for your machine.

    NOTE: Using your arrow OR + and - keys on the key board in this screen is the way to navigate around and using the enter key to make choices.

  • You will be looking for this one and this one only. Make no other changes.

    Boot Sequence


    Your CD rom needs to be listed as the 1st boot device. If it isn't any longer please change it so it is.

    4. Now carefully follow the instructions, probably at the bottom of the screen, or in a small panel on the lower right, for saving the change and exiting. If it asks you to confirm the change, confirm it. ( usually the F10) key saves changes and asks for a confirmation but check first.)

  • Once this is done and you saved the settings when your computer will restart itself. It may just go directly into windows the first time. If it does restart the machine from there once again.

    When it restarts you should see a black screen in a few seconds that says
    "Press any key to boot from CD" You have about 5 seconds to press any key. Press any key from a_z. No other keys please. If you do not press the key fast enough your computer will start in windows normally and you must restart again and press any key when prompted to. Timing counts here.

  • If this doesn't work this time please recheck that the settings in the Bios (F2) stayed this time. Then if you have another CD rom in the machine I want you to try placing the CD in there and rebooting .


  • Once that is done you will have a license agreement to agree to and apply (F8 key)

  • Be certain to select the option for a new install of Windows XP when the choice is offered. DO not repair.

  • Follow the prompts to delete and existing partitions. It will ask for confirmation for each partition.
    The picture below is what you might see. You may also see more than 1 partition. Delete any you find by highlighting it and hitting the 'D" key to delete the selected partition.. It will also see you CD rom more than likely. That one it will tell you it can't reformat. Don't worry about it.

    [external image: Posted Image]

  • Choose reformat using the NTFS option Completely avoid using the quick format options.

  • Windows will begin reformatting that may take some time depending on your Hard drive size.
  • Then windows will begin to install.

  • You will be prompted to answer a few simple questions

  • After a wile your computer will reboot asking you again to Press any key to boot from CD. DO NOT PRESS IT AGAIN. Just Ignore it and windows will continue loading.

  • Once windows is completely done installing you can remove the Installation CD from drive and store it safely away.

    Now install the anti virus you downloaded and saved to disk before connectiong to the internet.


  • The next your going to need the other software disks that came with your computer to install all the other software and drivers that came with your machine. Your anti virus program may be part of this software.
After reading these instructions several times, ive tried it three times, and it didnt work. questions: The settings were saved, but what role does the battery play? I dont recall ever putting a new battery into my computer, other than into my mouse. "if this doesn't work this time please recheck that the settings in the Bios (F2) stayed this time. Then if you have another CD rom in the machine I want you to try placing the CD in there and rebooting ." Do you mean another cd disc, like say If i place a computer game inside the cd tray, and try to reboot then. or Insert the windows xp cd in another cd tray, i have a dvd drive and floppy disk and the cd drive also, my autorun is disabled for some reason, would that have anything to do with it? also, one of the programs i bought was a mcafee anti virus, would that be a sufficient av program?
If you recently bought McAfee and have a subscription to it that will be fine. No need to download a new anti virus program.


The Battery:
It saves any settings in your Bios that you set or that are set when it comes to you.
When the battery goes bad you can reset settings in your Bios until your blue in the face, if your battery is bad they will reset to default settings each time you turn the computer off. You'll know this because your clock will be wrong in the Bios each time you look at it after resetting it to the correct time and date. Some may last 8 yrs some may last 2. You just never know with these batteries.



__________________________________
ComboFix disables the auto run feature in all computers. The auto run feature is used extensively by malware. This simply means you have to click on the CD from MY COMPUTER to start it.

_______________________________________

You asked about :

Insert the windows xp cd in another cd tray, i have a dvd drive and floppy disk and the cd drive


That is exactly what I meant. Place your Windows Installation CD in the other CD/DVD tray reboot and try that way.

Please try that.


______________________________–
I want to ask you this:
When you reboot does it seem as if the computer is looking for a CD in the drive bays. You would know this as they would start to spin and the light would start to flicker. Check that for me.

I ask this as sometimes motherboards do not recognize hardware correctly and still may work while windows boots up. You can see this in (F2) Bios you should see something similar to this.

Standard CMOS features.

Entering that menus you should see both your Hard drive and 1 or 2 CD and DVD roms listed.

similar to this:

You can see that the Primary Master is showing his Hard drive as a Western Digital
WD2000jbj

and the secondary master is CD drive
CDus5211

[external image: Posted Image]

If you do not see these things it's probably time to take this machine to a repair shop if your not comfortable doing some repair work yourself.

Have a look at these things for me and let me know what you see..
hi i havent tried the cd in the dvd drive yet but i will tonight. Also, If i put the windows xp in the dvd drive, I would have to go to BIOS and set dvd as the first to boot instead of the cd rom in the 1st slot right? Yes, it does make sounds and i do hear the disc tray either spinning or searched Im going to restart and I will post my master drive info to you edit: >xO!! OMG IT WORKED ! I SAW THE PRESS ANY KEY TO BOOT OFF CD , BUT I DIDNT PRESS A KEY BECAUSE I WAS TO SLOW its in the dvd drive. Also, heres what i get when press f2 about my master drives Drive 0 - hard drive drive 1 - off secondary drive 0 - cdrom reader secondary drive 1 - cdrom reader and in boot sequence, i have cdrom as 1 diskette drive as 2 and hardrive as 3 I will not start to reformat, until i get the clear from you
:woot: Go ahead and do the reformat now. Just as you did when you saw the "Press any key to boot from CD"
Change Nothing.

Hopefully next time I hear from you you'll be on a fresh install of windows.

Be sure to install your anti virus program the very first thing after windows is installed.
hi!! im on my computer after reformatting, this is awesome thanks for all your help, really, If i had a job and was old enough I would donate to the site. Questions though. My windows service pack, I dont have a cd namd windows xp service pack, Do i use the operating system cd for that? Edit: Nevermind, Ive updated and got the service pack. and when i scroll using firefox, it scrolls choppy when I try to install my mcafee, a warning pops up showing. "Th version of windows installed on this machine is not supported" what does this mean?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI