Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Beginner needs to confirm with expert that I have to Recover Hard Drive  (Read 13116 times)

0 Members and 1 Guest are viewing this topic.

nhchap

    Topic Starter


    Rookie

    I am not usually the one who "cares for" our PC.  Unfortunately he is not able to help or be here right now so I am turning to the experts here at Computer Hope.  I fear that I am not going to be able to save this PC as it was and would like to know if my fear is true or not.  I have had numerous problems such as losing all sound, browser changing on me, being blocked from websites I used to access and too many more to mention.  I read through the instructions to remove Malware and got stuck at Step 5 Updating Java.  I got a message that said that it was not found or that my cabinet may be corrupt.  I have logs of the work I did do and shall attach those if I can figure out how to do so successfully. 

    My PC is a HP Pavilion a1310n AMD 64 running Windows XP Service Pack 3 Media Center Edition 4.0 Platform Win32 Internet Explorer 7.0 Screen resolution 1024 x 768/ 32 bit color Net versions: 1.0.9705 -1.1.4322 - 2.0.50727 Cookies are enabled
    Plugins:
    Adobe Acrobat version: unknown
    Flash version: 10.0.12.36
    Java version: 1.6.0.11 (Enabled: true)
    JavaScript version: 1.3
    QuickTime version: 7.31.31.0
    RealPlayer version: unknown
    Shockwave version: 11.0.3.472
    Silverlight version: 2.0.31005.0
    Windows Media Player version: 11.0.5721.5230
    VB Script version: 5.7.18066
    DevalVR version: missing
    VRML plugins detected: missing
    X3D plugins detected: missing

    Any time spent and help provided is gratefully accepted.  You are truly wonderful to be here for us!

    [attachment deleted by admin]

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Download random's system information tool (RSIT) by random/random from and save it to your Desktop.

    • Double click on RSIT.exe to run.
    • Click Continue at the disclaimer screen.
    • Once it has finished, two logs will open.
    • log.txt <will be maximized and info.txt <will be minimized
    • Please post the contents of both logs in the next reply.

    nhchap

      Topic Starter


      Rookie

      Thank you for your help.  Here are the logs.  Just a note ~ if this computer looks like it's been smoking some 'good stuff' that's because it's operator was!  He's 8 months sober now but before that he was hiding all kinds of files and applications from view and seems to have me restricted to using only certain apps and only certain websites.  I was fearful that the porn sites or web cam chat sites had possibly polluted the system.  I just know that the "scan" continually trys to load at every new web page and that I have no sound.  I can't really tell what else is wrong.  I'd like to remove all of the restrictions as he is no longer living here and while he might return, it will be without all the "smokescreens" if that's what happens.  Just in case you could guide me in that direction?

      [attachment deleted by admin]

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Open HijackThis and select Do a system scan only.

      Place a check mark next to the following entries: (if there)

      • O4 - HKLM\..\Run: [AlcxMonitor] \"C:\WINDOWS\ALCXMNTR.EXE\"
      • O4 - HKLM\..\Run: [HPHUPD08] D
      • O4 - HKCU\..\Run: [Pareto_Update] \"C:\Program Files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe\"
      .
      Important: Close all open windows except for HijackThis and then click Fix checked.

      Once completed, exit HijackThis.

      ----------

      Go to Add or Remove Programs and uninstall:
      • J2SE Runtime Environment 5.0 Update 5
      • Java(TM) 6 Update 5
      • Java(TM) 6 Update 7
      • LiveReg (Symantec Corporation)
      • Norton AntiVirus Parent MSI
      • Norton Internet Security 2005 (Symantec Corporation)
      • Norton Internet Security
      • ParetoLogic Data Recovery
      • ParetoLogic Privacy Controls
      • PC-Doctor 5 for Windows
      • RegCure 1.5.0.1
      • Symantec Technical Support Web Controls
      • Viewpoint Media Player
      .
      ----------

      First install the new Sun Java Runtime Environment

      Be sure to close all browser windows before beginning the install.

      Remove the old version(s)

      Download JavaRa
      • Unzip the file and open the JavaRa.exe
      • Click Remove Older Versions
      • JavaRa will search for and remove any outdated version of Java and remove any that are found.
      • Click Additional Tasks
      • Place a check next to Remove Useless JRE Files and click Go
      • Exit JavaRa
      • Delete the JavaRa files from the Desktop
      .
      Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.

      ----------

      Download the Norton Removal Tool (SymNRT) to your Desktop.

      Once downloaded please close ALL open browsers, also save any work because this may require a restart.
      • Go to your desktop and double click on the removal tool and then click Setup.
      • Once open Click Next
      • Accept the license agreement and click Next
      • Type in the letters/numbers that you see into the text box then click Next.
      • Then click Next and the tool will start running.
      • Once finished restart the PC and run the tool again to ensure everything has been removed.
      • Delete Nortonremoval tool from your Desktop.
      .
      ----------

      Download Lop S&D by Eric_71 and save it to your Desktop. Lop S&D will only run on Windows XP and Windows Vista

      Disable your antivirus and antimalware programs so they do not interfere with the running of Lop S&D. If needed see: How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

      Double click LopSD.exe - If you are using Windows Vista, right-click on the LopSD icon and select Run as administrator to perform this scan.

      • Choose the language by typing of the corresponding letter and press Enter
      • Click OK at the informative window
      • Type 1, to choose Option 1 (Search) then press Enter
      • Wait until the end of the scan
      • A report will be generated, post the contents of it in your next reply.
      A copy of the report can be found at this location: %systemdrive%\lopR.txt, in most cases C:\lopR.txt

      nhchap

        Topic Starter


        Rookie

        Ok, I was able to run the HiJack scan as you requested.  I was able to install most of the programs you listed, only Norton ones giving me trouble.  But when I got to the JAVA I ran into trouble again.  The message was:

        Error 1330.A file that is required can not be installed because the cabinet file c:\Docs and Sett\...\Data1.
        Cabinet has an invalid digital signature.  This might indicate the file is corrupt.

        I was able to run the program that installed all the old versions of JAVA however.

        During this time I ran into problems getting connected to the internet and had to call Verizon finally to help.  It was connecting but very slowly.  I remembered something that had helped before... going to RUNAS and browsing for IE there.  It worked.  I am able to get on and quickly.  That may not be how it is supposed to work but for now it solved my problem of downloading the next two items.

        The Norton Removal Tool would not load either.  It could not complete the download and now I've forgotten, didn't write down the error message.  I'm so sorry.  Tired...  So I was unable to install Norton completely although on the Control Panel-Remove Prog- it shows that the Norton programs have zero bytes.

        Lastly, I disabled all of the virus, spyware and firewalls that I knew about and ran the last program.  The log is attached as requested. 

        I can't thank you enough.  Honestly, I mean that. 

        [attachment deleted by admin]

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Download the OTMoveIt3 by OldTimer

        Note: If you are running on Vista, right-click on OTMoveIt3.exe and choose Run As Administrator.

        * Save it to your Desktop.
        * Double-click OTMoveIt3.exe to run it.
        * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

        Code: [Select]
        :Processes
        explorer.exe

        :files
        C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic
        C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic Anti-Virus PLUS
        C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec
        C:\DOCUME~1\HP_ADM~1\APPLIC~1\ParetoLogic
        C:\DOCUME~1\HP_ADM~1\APPLIC~1\Registry Defender
        C:\DOCUME~1\HP_ADM~1\APPLIC~1\Symantec
        C:\DOCUME~1\HP_ADM~1.YOU\APPLIC~1\Symantec
        C:\DOCUME~1\NANCYA~1\APPLIC~1\ParetoLogic
        C:\DOCUME~1\NANCYA~1\APPLIC~1\Registry Defender
        C:\DOCUME~1\NANCYA~1\APPLIC~1\Symantec
        C:\Program Files\ParetoLogic
        C:\Program Files\Symantec
        C:\Program Files\Symantec Technical Support
        C:\Program Files\Common Files\ParetoLogic
        C:\Program Files\Common Files\Symantec Shared
        C:\WINDOWS\tasks\ParetoLogic Update Version2.job
        C:\WINDOWS\tasks\ParetoLogic Registration.job
        C:\WINDOWS\tasks\ParetoLogic Update.job
        C:\WINDOWS\tasks\Norton Security Scan.job
        C:\DOCUME~1\NANCYA~1\LOCALS~1\Temp\startup.bmp
        C:\DOCUME~1\NANCYA~1\Favorites\discovery places\Vipcams.literotica.com Warez Download Crack Serial Number Keygen CD Key Generator Torrent Activation Code Full Version.url

        :Commands
        [purity]
        [emptytemp]
        [start explorer]
        [Reboot]

        * Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
        * Click the red Moveit! button.
        * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
        Close OTMoveIt3

        Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.

        nhchap

          Topic Starter


          Rookie

          Ok, here's the results from running that program...


          ========== PROCESSES ==========
          Process explorer.exe killed successfully.
          ========== FILES ==========
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic\UUS2\Temp moved successfully.
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic\UUS2\Privacy Controls\Temp moved successfully.
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic\UUS2\Privacy Controls moved successfully.
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic\UUS2\Data Recovery\Temp moved successfully.
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic\UUS2\Data Recovery moved successfully.
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic\UUS2 moved successfully.
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic\Privacy Controls moved successfully.
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic\PLAS moved successfully.
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic moved successfully.
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic Anti-Virus PLUS\6\Quarantine Archives moved successfully.
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic Anti-Virus PLUS\6 moved successfully.
          C:\DOCUME~1\ALLUSE~1\APPLIC~1\ParetoLogic Anti-Virus PLUS moved successfully.
          C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec moved successfully.
          C:\DOCUME~1\HP_ADM~1\APPLIC~1\ParetoLogic\Privacy Controls moved successfully.
          C:\DOCUME~1\HP_ADM~1\APPLIC~1\ParetoLogic moved successfully.
          C:\DOCUME~1\HP_ADM~1\APPLIC~1\Registry Defender\Backups moved successfully.
          C:\DOCUME~1\HP_ADM~1\APPLIC~1\Registry Defender moved successfully.
          C:\DOCUME~1\HP_ADM~1\APPLIC~1\Symantec\Shared\Sessions moved successfully.
          C:\DOCUME~1\HP_ADM~1\APPLIC~1\Symantec\Shared moved successfully.
          C:\DOCUME~1\HP_ADM~1\APPLIC~1\Symantec moved successfully.
          C:\DOCUME~1\HP_ADM~1.YOU\APPLIC~1\Symantec\Shared\Sessions moved successfully.
          C:\DOCUME~1\HP_ADM~1.YOU\APPLIC~1\Symantec\Shared moved successfully.
          C:\DOCUME~1\HP_ADM~1.YOU\APPLIC~1\Symantec moved successfully.
          C:\DOCUME~1\NANCYA~1\APPLIC~1\ParetoLogic\Privacy Controls moved successfully.
          C:\DOCUME~1\NANCYA~1\APPLIC~1\ParetoLogic moved successfully.
          C:\DOCUME~1\NANCYA~1\APPLIC~1\Registry Defender\Backups moved successfully.
          C:\DOCUME~1\NANCYA~1\APPLIC~1\Registry Defender moved successfully.
          C:\DOCUME~1\NANCYA~1\APPLIC~1\Symantec\Shared moved successfully.
          C:\DOCUME~1\NANCYA~1\APPLIC~1\Symantec moved successfully.
          C:\Program Files\ParetoLogic\Privacy Controls\images moved successfully.
          C:\Program Files\ParetoLogic\Privacy Controls\html\images moved successfully.
          C:\Program Files\ParetoLogic\Privacy Controls\html moved successfully.
          C:\Program Files\ParetoLogic\Privacy Controls moved successfully.
          C:\Program Files\ParetoLogic moved successfully.
          C:\Program Files\Symantec\LiveUpdate moved successfully.
          C:\Program Files\Symantec moved successfully.
          C:\Program Files\Symantec Technical Support\controls moved successfully.
          C:\Program Files\Symantec Technical Support moved successfully.
          C:\Program Files\Common Files\ParetoLogic\UUS2\Images moved successfully.
          C:\Program Files\Common Files\ParetoLogic\UUS2 moved successfully.
          C:\Program Files\Common Files\ParetoLogic\PLAVEngine moved successfully.
          C:\Program Files\Common Files\ParetoLogic moved successfully.
          C:\Program Files\Common Files\Symantec Shared\VirusDefs\tmp354f.tmp moved successfully.
          C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060923.007 moved successfully.
          C:\Program Files\Common Files\Symantec Shared\VirusDefs\20060922.018 moved successfully.
          C:\Program Files\Common Files\Symantec Shared\VirusDefs\20050912.024 moved successfully.
          C:\Program Files\Common Files\Symantec Shared\VirusDefs moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymSetup\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}_10_0_1_86\Support\Reporter moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymSetup\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}_10_0_1_86\Support moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymSetup\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}_10_0_1_86\Setup\Setup\APP moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymSetup\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}_10_0_1_86\Setup\Setup moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymSetup\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}_10_0_1_86\Setup moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymSetup\{5AA2CD16-706F-41f3-87C5-2B5A031F2B3B}_10_0_1_86 moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymSetup moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\BinHub moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20080713.002 moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e\20080618.017 moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\virusdefs-2.5-e moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs\20061208.003 moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\nco1.0defs moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20080724.001 moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20080723.001 moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20080707.002 moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\ids-diskless\incoming moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\ids-diskless\BinHub moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\ids-diskless\20060922.092 moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\ids-diskless\20060920.091 moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData\ids-diskless moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SymcData moved successfully.
          C:\Program Files\Common Files\Symantec Shared\SPManifests moved successfully.
          C:\Program Files\Common Files\Symantec Shared\Security Console moved successfully.
          C:\Program Files\Common Files\Symantec Shared\Security Center moved successfully.
          C:\Program Files\Common Files\Symantec Shared\PEPUtilities moved successfully.
          C:\Program Files\Common Files\Symantec Shared\IDS moved successfully.
          C:\Program Files\Common Files\Symantec Shared\Help moved successfully.
          C:\Program Files\Common Files\Symantec Shared\EENGINE moved successfully.
          C:\Program Files\Common Files\Symantec Shared\Decomposers moved successfully.
          C:\Program Files\Common Files\Symantec Shared\CCPD-LC moved successfully.
          Folder move failed. C:\Program Files\Common Files\Symantec Shared scheduled to be moved on reboot.
          C:\WINDOWS\tasks\ParetoLogic Update Version2.job moved successfully.
          C:\WINDOWS\tasks\ParetoLogic Registration.job moved successfully.
          C:\WINDOWS\tasks\ParetoLogic Update.job moved successfully.
          C:\WINDOWS\tasks\Norton Security Scan.job moved successfully.
          C:\DOCUME~1\NANCYA~1\LOCALS~1\Temp\startup.bmp moved successfully.
          C:\DOCUME~1\NANCYA~1\Favorites\discovery places\Vipcams.literotica.com Warez Download Crack Serial Number Keygen CD Key Generator Torrent Activation Code Full Version.url moved successfully.

          nhchap

            Topic Starter


            Rookie

            Please bear with me... I couldn't figure out for a minute what I should do so I only posted part of the filein my last post.  Now let me try this again...


            ========== COMMANDS ==========
            File delete failed. C:\DOCUME~1\NANCYA~1\LOCALS~1\Temp\CMLS--2009-03-03--06-20-33.log scheduled to be deleted on reboot.
            File delete failed. C:\DOCUME~1\NANCYA~1\LOCALS~1\Temp\JET2DEE.tmp scheduled to be deleted on reboot.
            File delete failed. C:\DOCUME~1\NANCYA~1\LOCALS~1\Temp\SQL.LOG scheduled to be deleted on reboot.
            User's Temp folder emptied.
            User's Temporary Internet Files folder emptied.
            User's Internet Explorer cache folder emptied.
            Local Service Temp folder emptied.
            Local Service Temporary Internet Files folder emptied.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0556DD42-59C7-467D-A377-F9A6CF2BAE0E.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS096E6DFD-DEA0-4725-A0AA-EE3F46AAA256.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS0E860E09-79FE-4F6E-8FDC-D9417F6D5737.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS193E7AF1-D766-4F12-9A25-E59227F4D3B8.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1CE4F3CB-33FF-4483-B68D-E1D86419CF33.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS1E12F069-0D53-4F76-8452-54BFE2A351CB.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS205ED748-893B-473E-99A2-4A1E36EF2633.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS20FF10AD-A50A-4058-AC5B-0D4A2B8D302F.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS22ACF72D-2B3D-46BF-A21F-CBF560539BF7.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS236A598D-D5CA-466F-AC98-5CADEB434421.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS238104B8-E67C-415E-B30E-B1C0C604550C.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS23D10CAC-11B9-4874-9D84-594BA3916101.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS23F6656C-6215-4B71-80A4-BF05CDA1060D.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2648888C-8FD9-45A2-88E4-C3093066CA05.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2848D3E1-EEF9-48FE-A81A-76D77CF9E09A.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2A592FAE-4206-412D-9730-069FB0D3D3F1.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2B614A6E-C647-4932-8EA0-61E8AC446899.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2E7E3680-7A34-407C-A225-BCB38DCBAF27.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS2F0372A5-EA09-451B-AAE5-E84998B093F0.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS39915C3A-5141-4267-88C3-8F95E66C304D.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS3FD43A02-A77D-412A-B754-9CB9AE4D32A6.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4077FF3A-4A39-42EC-9662-0A99B96AF1EB.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS40BF51A6-B7FE-48B1-9AE5-7141FA98403A.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS43F07C38-6EE4-4CFC-88F8-2CF264F0B940.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS475A0F04-29BF-4A0D-ACDE-DDA17125FB80.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS495E9720-DE20-445B-AB86-E2B7B0FAE575.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4E66DFF9-6C56-478E-9FC8-C5B41B0363D1.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4F7AAC1F-2861-4097-9E6B-1828B1ACB030.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS4FA0DB2F-E769-4296-B7FD-C58175D92AF4.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5003A3AC-CCFC-4135-BFFF-FC9B16EF4B7B.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5053430D-DC80-4E6B-8A98-895E00A9DABE.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS51CA7D36-7F0A-40BB-B259-20CFF3E7F959.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS53A4C4F6-DD83-4DE9-8AAE-2613AE3F2259.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS53E6EE26-DC59-491B-8938-1823DE6A013D.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS56B05849-46B5-4653-9071-B1A4DF2350F9.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS5784C5D9-F7EB-4105-84B8-8910F6B02A00.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS59BE050A-3843-4D1F-8923-CC3CEA1811A7.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6045E47E-8A23-4ADE-8BA2-D8C623049B19.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS60FDDC56-C52C-458F-8EEB-144FD479CE87.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6548E73B-8B04-423A-9A13-3148B26C8DF8.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS66C5C263-9215-4A91-8A73-7E9CB77D866B.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS67B09FA1-467E-478F-AAEB-EC923B5AC3A6.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS68689B58-88FB-4237-837E-A7352604AD20.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6ABAC3E3-4077-4B3C-9378-2F962D16E9A3.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6B8544AB-A28B-4541-B0AE-8F31A4C1A71A.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS6D1B774C-3926-41E1-BA6C-D2809439BBA2.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS73E1EFB7-37C3-4B9C-8CE5-40F0201800B3.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS75B40773-2FFD-40BC-8239-3F1657CA93E0.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS76960BF3-365C-4A9B-8750-B8467FED0E14.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS785381BF-074E-414F-9D07-974295E32C12.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7A280D4C-BCAF-4A5D-97BB-1B248F85E8F4.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7C3B111E-7E15-42EA-8A15-5E84721F7634.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7C82E81E-3FCA-4380-B157-D99654794A95.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7CA85906-2830-44BD-A104-42ED4759C43D.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS7F76F369-DB05-4829-AD1B-9B25EF06E7DF.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS82D53D88-B993-4030-B97C-486B9FA9E71F.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS83313267-3B03-44D2-80C0-D69685C07F22.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS84FE1318-7645-43FF-8A7C-C2E0CB078E05.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8842FB33-7A8B-48D3-96E7-58E88D4925B4.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS892A3CFB-FE09-4B82-BDD3-EE6C6BE5B648.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8B0302EE-173B-4AB6-B186-AAD8C6254484.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8B17DBC7-4356-402C-9E1A-132CC2A9672F.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8CDF7DAB-8D8E-4C61-B206-778DFC1F7655.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8F5E386F-3F28-401D-A17E-49136C130759.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS8F8709FA-0E8F-4C8B-9184-423E358EB661.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9083A984-5FEA-4648-9C9B-CF6FB5CE9DCF.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS912400D3-5863-4212-8261-3A2615900771.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS937BC14F-397A-4A78-92DD-2E9FBCC9C167.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS93F6A842-BFB8-4E73-8C01-D8A8C56B6CFE.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS94D19742-A0D5-4EC9-8804-AB2B39E1525A.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9DA7B4E0-E9B8-4CD5-B5D5-28D554E1CC56.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMS9E5585CC-E734-4B27-B9B5-1DDD269771C4.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA6453D09-98AC-41B5-A32F-77C0FAEF20E8.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA67EFD06-FDA2-4149-AA91-5078441F9F7A.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSA6D34E47-5584-4BF0-8801-71B90062605E.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSAA46093C-2177-40F7-9970-6CFBFC571CA4.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSAA8CD259-0F5D-47AE-8FED-8702C65BD1B1.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSAD485650-EE1C-44FE-9774-C8AF2DA9BC7B.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSAD726222-5542-4D06-A16C-FEC39D28B37F.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSAFA9F014-B8BE-475C-A3CD-A484B952EDBB.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB08308FF-C9F3-4014-8DC2-B0BCF8219041.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB75D525C-5577-4B94-8A3E-7D8E9D3530F3.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSB7876C2A-7214-4BB1-9CC6-6E22E61509FA.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSC3E4C887-45AF-4AD2-802E-F86828630D77.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSC4A66F3E-9EC9-48C2-B2E6-CEE2CEEF5FD8.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSCC723626-C7A2-41CE-9047-BC7B55BDFD89.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSCDF26C7E-02BE-4500-AE92-611A2847F6DD.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD39B808C-A140-41F4-ACB9-675E321839DF.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD521B52B-D2A2-4E65-9E22-C86950687126.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD75890B8-A3AE-4195-8485-062542BCD5ED.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSD89256F0-E753-4FB6-A5CB-FA442B556E7D.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDA6CF51B-E7D3-4222-8DD2-27BB2469B2EB.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDA7A7053-DED6-42AF-840B-89231D120182.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDCD6A758-66CC-4396-B70E-80ABB446F4A5.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDD4EDE75-540E-4C9A-A0E4-EFFFBBFF72F1.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSDDD6353E-B3D3-4C6C-8172-B7B2FE0A212A.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE1483231-9F01-45A5-86D9-095DFF077140.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE904B5D3-E8A5-4C5A-B9D0-0156B33A972D.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSE9EC74AA-1F0C-4DE8-A841-177F87E76E82.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEA48A3EF-50C5-4625-946C-463A61A20BF1.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSEEE85D82-3806-418E-B9DF-21A5437954B2.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSF3F9ADB1-2EDF-4063-9E9F-665E1E2FCE82.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSF9381A47-0CF2-469C-9CC4-9B4B82C3DDE2.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\wrstemp\SSMSFD909C71-F542-47FE-8898-DDFD56CEFCDD.tmp scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_200.dat scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\SQL.LOG scheduled to be deleted on reboot.
            Windows Temp folder emptied.
            Java cache emptied.
            FireFox cache emptied.
            Temp folders emptied.
            Explorer started successfully
             
            OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03032009_154028


            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

            Link #1
            Link #2

            **Note:  It is important that it is saved directly to your Desktop

            Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

            Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
             
            Double click combofix.exe & follow the prompts.
            When finished ComboFix will produce a log for you.
            Post the ComboFix log in your next reply.

            Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

            Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

            If you have problems with ComboFix usage, see How to use ComboFix

            nhchap

              Topic Starter


              Rookie

              Wheew!  Got that accomplished.  The log is attached.

              [attachment deleted by admin]

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Beginner needs to confirm with expert that I have to Recover Hard Drive
              « Reply #10 on: March 04, 2009, 10:50:36 AM »
              Download Rooter.exe to your desktop

              * Double click Rooter.exe to start the tool.
              * A DOS window will appear and show the scan progress.
              * Once complete a notepad file containing the report will open.
              * Copy & paste the results in your next reply.
              * Close notepad and Rooter will close.

              A log will also save at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have Windows installed).

              nhchap

                Topic Starter


                Rookie

                Re: Beginner needs to confirm with expert that I have to Recover Hard Drive
                « Reply #11 on: March 04, 2009, 04:45:37 PM »
                Have I mentioned how wonderful you all are there?  I did?  Well, let me say it again!

                Here's the log...

                Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
                X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3700+ )
                BIOS : Phoenix - AwardBIOS v6.00PG
                USER : Nancy and Kent ( Administrator )
                BOOT : Normal boot

                Antivirus : Webroot AntiVirus with AntiSpyware 6.0.2.39 (Not Activated)
                Firewall  : Webroot Internet Security Essentials 6.0.0.0 (Not Activated)

                C:\ (Local Disk) - NTFS - Total:177 Go (Free:130 Go)
                D:\ (Local Disk) - FAT32 - Total:8 Go (Free:1 Go)
                E:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
                F:\ (USB)
                G:\ (USB)
                H:\ (USB)
                I:\ (USB)

                Wed 03/04/2009|15:40

                ----------------------\\  Search..

                No infections found !


                1 - "C:\Rooter$\Rooter_1.txt" - Wed 03/04/2009|15:41

                ----------------------\\  Scan completed at 15:41


                Question:  If my other computer is/was networked with this one, should I check it too?  It is not having nearly the issues this one was but I have no sound on it either right now and was concerned that there may be other issues I'm not aware of.
                Thank you

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: Beginner needs to confirm with expert that I have to Recover Hard Drive
                « Reply #12 on: March 04, 2009, 04:57:30 PM »
                You can do the other computer just start a new topic for it.

                How is this one running now?

                nhchap

                  Topic Starter


                  Rookie

                  Re: Beginner needs to confirm with expert that I have to Recover Hard Drive
                  « Reply #13 on: March 04, 2009, 08:01:22 PM »
                  I know I feel better now.  The computer is much better.  I still have two issues that I need help with.  1) the sound issue and 2) I still can't access some web pages that I used to be able to access.  For example, I was asking a legal question on a site where I have an account and deposit money when necessary and last night and tonight, I am unable to do so. The page says it can not be displayed.  I realize there are many error codes and I didn't note which one it said but I can go and look. 

                  A question:  When my guy left here, there were numerous internet connections ie. LAN, Broadband, AOL Dial-up, VPN (2), and PP??  Anyway where did they all go and how or why does that happen?  I had to reinstall my broadband provider and use the LAN connection.  But that gives me trouble connecting to AOL where my mail is.  Do I need to post this question in another thread?

                  evilfantasy

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Calm like a bomb
                  • Thanked: 493
                  • Experience: Experienced
                  • OS: Windows 11
                  Re: Beginner needs to confirm with expert that I have to Recover Hard Drive
                  « Reply #14 on: March 04, 2009, 08:09:34 PM »
                  Quote
                  I still have two issues that I need help with.  1) the sound issue

                  Have you looked in the Device Manager and tried to reinstall or update the sound driver?

                  Quote
                  2) I still can't access some web pages

                  Download HostsXpert
                  • Unzip HostXpert to your Desktop
                  • Open up the HostXpert program.
                  • Make sure that the "Make Hosts Writable?" button in the upper right corner is enabled.
                  • Click Create Back Up
                  • Then click on Restore Microsoft's Host Files
                  • Close the HostXpert program
                  .
                  Note: if you use SpywareBlaster, Spybot and/or IE-SPYAD, it will be necessary to re-install the protection they afford. For SpywareBlaster, run the program and select Enable all protection. For Spybot run the program and select Immunize. For IE-SPYAD, run the batch file and reinstall the protection.

                  Quote
                  there were numerous internet connections ie. LAN, Broadband, AOL Dial-up, VPN (2), and PP??  Anyway where did they all go and how or why does that happen?

                  You'll have to ask that in the Networking forum. http://www.computerhope.com/forum/index.php/board,12.0.html

                  Did HostsXpert work?