Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help Me, Please.


  • This topic is locked This topic is locked
5 replies to this topic

#1 enozym

enozym

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:02:20 PM

Posted 23 September 2006 - 01:36 AM

Hello,

Iíve had a lot of trouble with virus malware type of things of my PC for a long time, and I donít want to be a bother and I have gotten rid of some of them by myself, but I feel, It would probably be best to post a log here and see if I anyone would be able to help me out a bit... well a lot, if itís not to much trouble. I'm not sure where to start.


At the moment Iím running, spybot, Mcafee firewall, and ad-aware SE personal, hijackthis. In the past I know Iíve used programs called ewido, registrar lite, killbot, which still have but I donít believe are installed at the moment.



Symptoms:

At the moment Iíve been having adds popping up in internet explorer advertising
System doctor
Win-antivirus pro
System integrity scan wizard.
And a number of other programs and things to buy and download etcÖ popups basically, warnings in McAfee that things are trying to access the internet and programs wanting me to install them.
The other day i think i got rid of toolbar888 which showed up on my Pc.

A long-term problem Iíve had, has been not being able to update McAfee firewall, and the Mcafee site being blocked from me all together. And I believe there used to be a similar problem when I had Norton, but I no longer have it now.

I have reoccurring problems that come up in spybot, that I canít get rid of with that program, even when scanning in safemode. Isearchtech.YSB as well as some other ones that come and go.

Just today IĎve had a blue screen saying i have 'fatal systems errors', making me restart, they seem to be the result of winlogon.exe failing and closing, which happens when I try to run a scan in ad-aware.



Some things that may be unrelated:

And no matter how much space I seem to free up, my computer constantly tells me that Iíve run out of space on C and D drive, but again I donít think this is probably a symptom, it might just be I really need to clean out and format properly.

And I have a program which I feel is probably more related to my computers power supply or ram etcÖ which is the computer constantly turns off while booting up, and wonít restart unless I cut power to the power supply for awhile and turn it back on again, usually it goes dead 10 or so times before I can finally get it into windows, but itís usually just fine after Iíve logged in.



In the past Iíve also had:

Something that took over my startpage, I think Iíve finally gotten rid of that. But Iím not sure if itís really gone or just disabled somehow. And it disturbs me slightly that I can see the name of the website I used to be redirected to in my hijack log. www. mycrasoft. biz

I had something once that blocked google and hotmail, which I canít recall how it stopped.

And recently I had some strange programs running in taskmanager, I think one may have been called ishost, but ad-aware seems to have gotten rid of thatÖ I hope.
In the past I also had something called Lich.exe as well, which i'm not sure if it's really gone properly.


I hope that i posted this properly and that someone may be able to help me.
Thankyou.

T.E.




Logfile of HijackThis v1.99.1
Scan saved at 4:11:34 PM, on 9/23/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Telstra\Toolbar\bpumTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
D:\My Documents\Tinanit\programs\adobe reader\01\Reader\reader_sl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\McAfee\McAfee Firewall\CPDCLNT.EXE
D:\My Documents\Tinanit\programs\virus killers\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://www.mycrasoft.biz
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.mycrasoft.biz
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://www.mycrasoft.biz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mycrasoft.biz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mycrasoft.biz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mycrasoft.biz
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by APC
O1 - Hosts: 216.130.185. 143 websearch.com
O1 - Hosts: 216.130.185. 143 www.adwave.com
O1 - Hosts: 216.130.185. 143 adwave.com
O1 - Hosts: 216.130.185. 143 www.xzoomy.com
O1 - Hosts: 216.130.185. 143 xzoomy.com
O1 - Hosts: 216.130.185. 143 www.advnt01.com
O1 - Hosts: 216.130.185. 143 advnt01.com
O1 - Hosts: 216.130.185. 143 websearch.com
O1 - Hosts: 216.130.185. 143 www.adwave.com
O1 - Hosts: 216.130.185. 143 adwave.com
O1 - Hosts: 216.130.185. 143 www.xzoomy.com
O1 - Hosts: 216.130.185. 143 xzoomy.com
O1 - Hosts: 216.130.185. 143 www.advnt01.com
O1 - Hosts: 216.130.185. 143 advnt01.com
O1 - Hosts: 216.130.185. 143 websearch.com
O1 - Hosts: 216.130.185. 143 www.adwave.com
O1 - Hosts: 216.130.185. 143 adwave.com
O1 - Hosts: 216.130.185. 143 www.xzoomy.com
O1 - Hosts: 216.130.185. 143 xzoomy.com
O1 - Hosts: 216.130.185. 143 www.advnt01.com
O1 - Hosts: 216.130.185. 143 advnt01.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: BigPond Toolbar - {7A431EC4-CC21-4DF7-9DB1-A2CF74C4CC98} - C:\Program Files\Telstra\Toolbar\bpumToolBand.dll
O4 - HKLM\..\Run: [BigPond Toolbar] "C:\Program Files\Telstra\Toolbar\bpumTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [uhvjsul.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\uhvjsul.dll,mrpmvyf
O4 - HKLM\..\RunServices: [ati control panel] atiphexx.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [Microsoft Windows Update] scvvhost.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\My Documents\Tinanit\programs\adobe reader\01\Reader\reader_sl.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O16 - DPF: {00000000-0000-0000-0000-100005000004} - http://code.trasferimento.biz/l/af9e656328...332f981a_28.exe
O16 - DPF: {11311111-1111-1111-1111-111111111157} - file://C:\Recycled\Q330995.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {3146427B-2CA2-0423-E59A-0F1C1DBB5BDF} - http://63.219.176.203/1/gdnAU1569.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by14fd.bay14.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,8...pdatePortal.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as...rl/SymAData.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = vic.bigpond.net.au
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = vic.bigpond.net.au
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

BC AdBot (Login to Remove)

 


#2 Mr_JAk3

Mr_JAk3

    HJT Team Member


  • Members
  • 527 posts
  • OFFLINE
  •  
  • Location:Finland
  • Local time:09:20 PM

Posted 23 September 2006 - 06:41 AM

Hi enozym and welcome to Bleeping Computer :thumbsup:

You got some infections there...

Please rename HijackThis.exe to Scanner.exe
Then post a fresh HijackThis (scanner.exe) log to here.

Then we'll continue :flowers:
UNITE & ASAP member since 2006
Posted Image
Posted Image

#3 enozym

enozym
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:02:20 PM

Posted 23 September 2006 - 09:10 AM

um... okay, i think i did that now.
Is this better?



Logfile of HijackThis v1.99.1
Scan saved at 12:01:24 AM, on 9/24/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\McAfee\McAfee Firewall\CPDCLNT.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
D:\My Documents\Tinanit\programs\adobe reader\01\Reader\reader_sl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\My Documents\Tinanit\programs\virus killers\hijackthis\Scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://www.mycrasoft.biz
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.mycrasoft.biz
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://www.mycrasoft.biz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mycrasoft.biz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.mycrasoft.biz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mycrasoft.biz
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by APC
O1 - Hosts: 216.130.185. 143 websearch.com
O1 - Hosts: 216.130.185. 143 www.adwave.com
O1 - Hosts: 216.130.185. 143 adwave.com
O1 - Hosts: 216.130.185. 143 www.xzoomy.com
O1 - Hosts: 216.130.185. 143 xzoomy.com
O1 - Hosts: 216.130.185. 143 www.advnt01.com
O1 - Hosts: 216.130.185. 143 advnt01.com
O1 - Hosts: 216.130.185. 143 websearch.com
O1 - Hosts: 216.130.185. 143 www.adwave.com
O1 - Hosts: 216.130.185. 143 adwave.com
O1 - Hosts: 216.130.185. 143 www.xzoomy.com
O1 - Hosts: 216.130.185. 143 xzoomy.com
O1 - Hosts: 216.130.185. 143 www.advnt01.com
O1 - Hosts: 216.130.185. 143 advnt01.com
O1 - Hosts: 216.130.185. 143 websearch.com
O1 - Hosts: 216.130.185. 143 www.adwave.com
O1 - Hosts: 216.130.185. 143 adwave.com
O1 - Hosts: 216.130.185. 143 www.xzoomy.com
O1 - Hosts: 216.130.185. 143 xzoomy.com
O1 - Hosts: 216.130.185. 143 www.advnt01.com
O1 - Hosts: 216.130.185. 143 advnt01.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\My Documents\tinanit\programs\adobe reader\01\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {278B661A-14A8-D8B0-6AF4-03088B866149} - C:\WINDOWS\System32\unaoakg.dll
O2 - BHO: ActivateBand Class - {4C7B6DE1-99A4-4CF1-8B44-68889900E1D0} - C:\Program Files\Telstra\Toolbar\bpumToolBand.dll
O2 - BHO: (no name) - {F451A64B-2C0A-4E24-9F9B-22516723ACA3} - C:\WINDOWS\System32\yabbc.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: BigPond Toolbar - {7A431EC4-CC21-4DF7-9DB1-A2CF74C4CC98} - C:\Program Files\Telstra\Toolbar\bpumToolBand.dll
O4 - HKLM\..\Run: [BigPond Toolbar] "C:\Program Files\Telstra\Toolbar\bpumTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [uhvjsul.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\uhvjsul.dll,mrpmvyf
O4 - HKLM\..\RunServices: [ati control panel] atiphexx.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [Microsoft Windows Update] scvvhost.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\My Documents\Tinanit\programs\adobe reader\01\Reader\reader_sl.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O16 - DPF: {00000000-0000-0000-0000-100005000004} - http://code.trasferimento.biz/l/af9e656328...332f981a_28.exe
O16 - DPF: {11311111-1111-1111-1111-111111111157} - file://C:\Recycled\Q330995.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {3146427B-2CA2-0423-E59A-0F1C1DBB5BDF} - http://63.219.176.203/1/gdnAU1569.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by14fd.bay14.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,8...pdatePortal.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as...rl/SymAData.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = vic.bigpond.net.au
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = vic.bigpond.net.au
O20 - Winlogon Notify: winrzf32 - C:\WINDOWS\SYSTEM32\winrzf32.dll
O20 - Winlogon Notify: yabbc - C:\WINDOWS\System32\yabbc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

#4 Mr_JAk3

Mr_JAk3

    HJT Team Member


  • Members
  • 527 posts
  • OFFLINE
  •  
  • Location:Finland
  • Local time:09:20 PM

Posted 23 September 2006 - 10:22 AM

That revealed more infections...

Before we may continue, you must do the following:

Please download and install Windows XP Service Pack 1A -> Windows XP SP1a
NOTE! Do NOT install Service Pack 2 yet. We'll have to get you cleaned first

When you're ready, please post a fresh HijackThis log to here :thumbsup:
UNITE & ASAP member since 2006
Posted Image
Posted Image

#5 enozym

enozym
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:02:20 PM

Posted 24 September 2006 - 10:40 PM

thankyou for taking your time to try to help me, but unfortunatly, yesterday i don't know whether it was a power surge, because we had a slight blackout for a bit, or if it just finally gave up the ghost, but yesterday my computer would only load windows in safe mode, i tried to make backups of my files, but unfortunatly my external harddrive for some stupid reason kept loosing the conection to my main computer and i gave up, but i wish i hadn't because this morning when tried to turn it on, the lights flash and it imited a buzz and nothing, even cutting the power and retrying didn't get me anywhere... i think it's probably the powersupply, as i thought that was what was causing it not to boot properly before, but i guess, it's gone (*cries* my poor dizzy is dead *pats dead computer*). I'm going to try to put my harddrive into another computer and trasfer off my files, like the one i'm borrowing now, but that means i'll probably end up copying off all the viruses if i try anyway, so perhaps i'll have to seek out you're help again if i ever manage to get a new computer.

So thankyou for everything, i really so appreciate it, but i guess my computer was just a bit far gone for help.

sincerly
T.E.

#6 Mr_JAk3

Mr_JAk3

    HJT Team Member


  • Members
  • 527 posts
  • OFFLINE
  •  
  • Location:Finland
  • Local time:09:20 PM

Posted 25 September 2006 - 05:23 AM

Ok, thanks for letting us know :thumbsup:

You're welcome ;)
UNITE & ASAP member since 2006
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users