I definitely see infections in that log, but I'd like to see a report from an ewido scan as well before digging in to the fixes.
Please configure and run ewido as follows:
* Open ewido and click the Update button to make sure that you have the absolutely most current updates installed. Close the program once the updates are installed.
* * Reboot your computer in Safe Mode by doing the following :Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Log in to the Administrator account.
Once booted in to Safe Mode:
* Open ewidoClick on scanner at the top of the Ewido sceen
Click on Settings
Under How to Act click on Recommended Action choose Delete.
Under How to scan, all boxes should be selected
Under Possibly unwanted software, all boxes should be selected
On right side under Reports: click on Automatically generate report after every scan.
Under What to scan, select scan every file
Clickon the Scan Tab
Click on Complete system scan
Let the program scan the machine It can take awhile give it time.
When scan has finished At bottom of screen click Apply all Actions
Click Save report
Click Save Report as (Save as window's screen should pop up.)
Click desktop
Click Save
Exit ewido
* Reboot normally and then run HijackThis again.
* Post the contents of the new HijackThis log and the ewido log.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
[Additional info from super_he_man sent to me via PM]:
The computer has gotten much worse. We can't even load it up into windows now.
IT goes past the windows xp screen and goes to a blue screen that says windoes
is loading and stays there for ever. So far i've tried going in through safe
mode, last known configuration, and even tried to reinstall windows xp but when
i tried to install it, it says there is no harddrive hooked up. Any and all
help is greatly appreciated. I have an external hard drive and another computer
to work with if i can. Its looking like we're just going to have to take it to
a computer doctor if we don't get any help.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
If the sytem is corrupting itself badly and quickly enough that the Windows installation CD doesn't even find the drive, you need to:
1. Go in to the computer's BIOS setup utility and determine whether or not the BIOS recognizes the drive.
To enter the BIOS, hit F1, Del, F2 (or whatever BIOS access is used on your particular make/model of computer) just after you turn on/reboot the computer; that is- well before you see the Windows loading screen.
In the BIOS setup, look for a page/section which relates to your installed IDE devices and make sure that the correct information (make, model #, size, etc.) for your drive is listed under the Primary Master IDE device section.
Let us know what you find there.
3. If the BIOS does not see the drive, remove the drive from the computer, install it as a slave drive (making sure to set the drive's Master/Slave jumpers to "Slave"), and see if that computer can access the drive. If so, copy all of your critical data off of the problematic drive and on to the external drive ASAP.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
Do you need make and model and other info?
No, not as long as you have verified that the BIOS correctly reports it.
Does the Windows installation CD message say nodrive found, or no operating system found?
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
It says no drive found
Ugh... if that's the case, you should install it in the other computer and see ifthat computer can acesss it.
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
There are still plenty of signs of infections in your latest HJT log, but it also looks like Norton was damaged or incompletely uninstalled. Can you tell us anything about that before we start performing fixes to the system?
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370