Unsolved

This post is more than 5 years old

8 Posts

10046

June 19th, 2007 21:00

Virtual 'C' Drive

Dimension 8300
 

I used HijackThis and it appears that there's nothing wrong.  That's the problem.  I have two computers with the same problem.  When you try to correct what seems to be wrong, they won't work.  I have erased the hard drive on both of these computers numerous times.  This is done every few months, because they both get to the point of being inoperable.  I then downloaded a trial version of KillDisk.  After it finishes erasing the hard drive, I reset the program, and this time it read a "virtual C: drive".  This drive was in addition to the one it had completed, and it took twelve to fifteen(12-15) hours to erase!  The same exact thing happened to the other computer I own.  One more note, I have noticed that even when I am not online(working on an "Office" 2003 program), I go to "disc cleanup" and somehow, someway, some one is producing Off-Line Webpages that I delete approximately every thirty(30) minutes to an hour.  I have no idea how to stop all of this stuff!  Somebody Please Help!!!  

 

 

Logfile of HijackThis v1.99.1
Scan saved at 2:55:05 PM, on 6/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O13 - DefaultPrefix:
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1180112819816
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

 

 
 

6 Operator

 • 

34.2K Posts

June 19th, 2007 22:00

SATA or IDE drives?
 
If you have already ruled out nepharious activity, then why are you posting your Hijack log? Or are you just not sure?

6 Operator

 • 

34.2K Posts

June 20th, 2007 16:00

Nefarious = bad stuff :)
 
Honestly, I'd just wipe the drive and reinstall. Why even bother at this point with HijackThis.

8 Posts

June 20th, 2007 16:00

SATA hard drive.
 
Not sure what you mean by 'nepharious', but I first asked for help on the HijackThis forum.  I didn't get a reply.  I thought the added information would help.
 
Thanks.  

8 Posts

June 21st, 2007 16:00

I understand, because that's what I've had to do over and over, and in due time it goes back to the same condition.  I thought someone here might have dealt with this too or have the 'magic bullet'.  I do appreciate your time.

6 Operator

 • 

34.2K Posts

June 21st, 2007 18:00

When you start the installation process, are you deleting partitions? I have a feeling you've installed some sort of file encryption program or drive overlay that is not being deleted.

8 Posts

June 26th, 2007 01:00

Yes, I'm deleting partitions, but it's funny that you ask that type of question.  When I ran the KillDisk program, it could only complete 99% of both drives (the physical 'C' drive and the virtual 'C' drive).  I tried KillDisk on the last 1% again, and it still wouldn't complete the process.   
No Events found!

Top