Windows XP Virus Help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by helpmeplease2, Nov 21, 2014.

  1. helpmeplease2

    helpmeplease2 Private E-2

    Thank you in advance!

    Issue: Virus behavor
    Examples:
    Permission Changes

    explorer crash Appname explorer.exe App
    ver:6.0.2900.5512 mod name: NTDLL.DLL mod
    ver:5.1.2600.6055 offset:000673be
    exception info code 0xc0000024 flags
    0x0000000007c9673be record 0x000000000000 address
    0x0000000007c9673be

    Lots of unrecognizeable services running.List upon request

    Slow pc=alot of crunching

    "DXDIAG" Displays:
    MS XP HOME ED 5.1 Build 2600
    manufacturer HP Pavilion 061
    System Model px731AA-ABA-A808X
    BIOS:pheonix Award Bios v6.00OG
    Processor: AMD Atlon 64 Processor 33200+,MMX,3D now,
    2.2 GHz
    Memory 1408 MB Ram
    Page File 611 used, 1222MB Available

    Uses I.E. and Firefox. A few weeks ago he said I.E. was
    having a plugin container error when trying to watch videos
    then just watched from Firefox so we didn't have to
    troubleshoot it.

    Does not have system restore turned on,cannot turn it on

    We share this PC mostly to watch netflix.He uses it more
    and has unidentified, to me, programs.List upon request if
    needed

    Tried to run AdAware and it displayed a "permissions
    error". The profile is an admin
    I tried to find a way to change permissions to no avail
    Removed AdAware

    I ran malwarebytes (as per your instruction) and
    quarrentined. After reboot, displayed that it would not run the
    program due to "software restriction"

    I enabled Hidden files and Folder

    We do not have an antivirus program. I think he was using
    an online scanner periodically.

    32 bit system

    Missed the part about the CCcleaner. 12 hours later as I
    was looking around the forums, I see this part. If you want me to
    run it now, please reinstruct. Husband may be helping.

    I do not know what is a CD Emulator program?He may have
    them installed.

    Did find Trojan.Poweliks - Removal from Symantec but have
    done nothing yet per your instructions except turn off internet
    access. Using a diffrent system for communicating with you.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.

    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    FYI: This PC does not have enough memory to properly run Windows XP SP3 and even worse, there is way too little free diskspace on drive I to run just about anything properly. You need to free up space on drive I immediately. You need to free up at least 5 to 10 GB.

    Then rerun Malwarebytes and this time fix what it finds. You previous log shows that you did not fix anything.
     
  4. helpmeplease2

    helpmeplease2 Private E-2

    As it's running, displays error: "msiexec.exe has encountered a problem and needs to close".
    Exception Information:
    Code:0xc0000005
    I:\DOCUME~1\server\LOCALS~1\tEMP\1b622_appcompat.txt
    Shall I click "Close" or just leave it up?
    This is my first time using a forum so please bear with me. Thank you in advance.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As what's running?

    You need to free up diskspace first before doing anything. The hard drive is out of space and this can cause all kinds of problems.
     
  6. helpmeplease2

    helpmeplease2 Private E-2

    Freed up 6MB

    Yes, thank you, the directions READ & RUN ME FIRST. Malware Removal Guide
    NOTICES:
    5.Please do not try to fix anything without being asked.

    I did Quarantine as per "Using Malwarebytes Anti-Malware instructions". It took some time but I did get the "Clean" message.

    So, as per my post, after reboot a display showed that it would not run the program due to "software restriction". Do I need to uninstall and reinstall or is there a workaround? TIA
     
  7. helpmeplease2

    helpmeplease2 Private E-2

    Farbar
     
  8. helpmeplease2

    helpmeplease2 Private E-2

    Farbar continued to run. Attached are the text files. I will wait on your comment to my malwarebytes question before I proceed. TIA
     

    Attached Files:

  9. helpmeplease2

    helpmeplease2 Private E-2

    Husband has just urged me to run the Malwarebytes and see what happens. So, I will repost in about 4 hrs. I think that's how long it took last time. TIA
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See what I posted in message # 3. I already asked you to run that. ALso you are not supposed to be doing anything on your own! See what we was request in the READ & RUN ME FIRST. Once you start, you must only do what we request.

    Not 6 MB of free space is not enough. You need 1000 times that. 6 GB.
     
    Last edited: Nov 21, 2014
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I also noticed that you had and may still have a CryptoWall infection! If you still have this, you really need to just erase everything on this PC and reinstall. Your security is at risk and these encrypted files cannot be decrypted.
     
  12. helpmeplease2

    helpmeplease2 Private E-2

    I apologize. I think we are having a miscommunication. I know you told me to run Malwarebytes. I wrote to you, in a later reply, that I had written in my original post that a window came up after running Malwarebytes and rebooting, that displayed the program will not run due to a "software restriction". I asked "Do I need to uninstall/reinstall or is there a work around? "I was thinking maybe the virus had changed another permission after it saw the name Malwarebytes and thought the virus would not allow me to re-run it. After my husband saw me post that, he told me to run it as you said to see what happens. So it is running. Although this time it did say the trial period is over. I guess I just need to get some sleep as I have been up working on this for almost 24 hours and I am a little confused on how to communicate to you. Do I always click to include the original post when responding? I was treating it as a kind of "Chat atmosphere" until you replied "as what's running" when I replied after I saw to run the Farbar post but before I saw to run the Malwarebytes. Well, the Malwarebytes is almost done so hopefully the rest of my communication to finish this up will not be so bad. Thanks for your help.
     
  13. helpmeplease2

    helpmeplease2 Private E-2

    Well, hopefully it's "had" the virus because I don't know how to reimage/reinstall if MS doesn't support XP anymore. I don't think this desktop could handle a more recent Operating System. Is there a place online to get all the updates like Service packs and such? I wanted to do that right off the bat but husband reminded me of this sad truth. I tried little tweaks from an era gone by but to no avail. So then I looked to your sight for help. I was hoping to get this resolved then avoid Internet Explorer for the life of the desktop. I'm too financially poor to afford anything else.
     
  14. helpmeplease2

    helpmeplease2 Private E-2

    Ok, Malwarebytes has finished. I clicked Quarantine All and I am attaching log file. Should I now reboot?
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes reboot and then continue with the below.

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.

    Download this >> View attachment fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Please attach the above two log first before you continue with the below.
    Also at this point, I want to double check the status of Poweliks by having you run another scan with FRST like in my last message and attach the new FRST.txt and Addition.txt logs.
     
  16. helpmeplease2

    helpmeplease2 Private E-2

    Hi. When I click the link you said to save as a text file "fixlink.txt",The name s attachment.php, then I click Save as, my choice is Save as a .php file. Should I download it and then change the extension? Thanks
     
  17. helpmeplease2

    helpmeplease2 Private E-2

    I downloaded the attachment and opened it with Notepad then saved it as fixlist.txt.

    I am using a friends Vista laptop and wireless networking hardware so I put fixlist.txt on a pen drive and put it on the XP desktop's Desktop. I made ure the wireless connection was disconnected. I right clicked the FRST.exe, chose Run as and picked a profile with admin rights. As it was executing, an error window popped up. I attached 2 screen shots to this reply. TIA
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure why you are getting this error but let's try running this differently.

    Just reboot your PC up in safe boot mode. Then Don't use right click to run FRST. Simply double click on it to run it. See if it runs this way.
     
  19. helpmeplease2

    helpmeplease2 Private E-2

    Hi. It would not boot into Safemode. When I would choose an option, it would try to load DOS files then come back to the same screen. So that's a different issue I can try to troubleshoot at a different time.

    I tried running FRST.exe by just double clicking and it completed. Attached is the log.

    I then ran C:\MGtools\GetLogs.bat file by double clicking on it. I got a Hijack this error. Screenshot attached. It completed after I chose no to report the error. I attached C:\MGlogs.zip.

    Should I proceed with another scan with FRST like in your last message and attach the new FRST.txt and Addition.txt logs?
     
  20. helpmeplease2

    helpmeplease2 Private E-2

    Reposting with attachments
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot the final part of my last instructions which stated the below
    But just get the FRST.txt log.

    After attaching the new FRST.txt log, continue on with the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    O4 - HKUS\S-1-5-18\..\Run: [XobeDsuz] regsvr32.exe "I:\Documents and Settings\All Users\Application Data\XobeDsuz\XobeDsuz.dat" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [WoypEkep] regsvr32.exe "I:\Documents and Settings\All Users\Application Data\WoypEkep\WoypEkep.dat" (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [XobeDsuz] regsvr32.exe "I:\Documents and Settings\All Users\Application Data\XobeDsuz\XobeDsuz.dat" (User 'Default user')


    After clicking Fix, exit HJT.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
     
    :Files
    I:\Documents and Settings\All Users\Application Data\XobeDsuz
    I:\Documents and Settings\All Users\Application Data\WoypEkep
    I:\Documents and Settings\All Users\Application Data\WararXozna
    I:\Documents and Settings\server\Start Menu\Programs\Startup\8718f58.exe
    I:\Documents and Settings\server\Start Menu\Programs\Startup\QEXPLORER.EXE
    I:\8718f58\8718f58.exe
    I:\Documents and Settings\server\Application Data\8718f58.exe
    I:\Documents and Settings\server\Application Data\FrameworkUpdate\ChromeUpdate.exe
    I:\Documents and Settings\server\Local Settings\Application Data\noblimu.dll
    
    
    :Reg
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "XobeDsuz"=-
    "WoypEkep"=-
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
    "JavaQuickStarterService"=-
    "gupdatem"=-
    "gupdate"=-
    "avast! Antivirus"=-
    
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\I:^Documents and Settings^server^Start Menu^Programs^Startup^8718f58.exe]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\I:^Documents and Settings^server^Start Menu^Programs^Startup^QEXPLORER.EXE]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\8718f5]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\8718f58]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ChromeUpdate]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMSGS]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\noblimu]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WararXozna]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now rerun Hitman Pro like you did the first time but this time allow it to fix all malware items and Potentially Unwanted Programs if it still reports them.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  22. helpmeplease2

    helpmeplease2 Private E-2

    Attaching FRST.TXT log then continuing C:\MGtools\analyse.exe
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it appears that a few things did not get fixed. In my last instructions the first part had a fix with analyse.exe that asked you to fix the below

    O4 - HKUS\S-1-5-18\..\Run: [XobeDsuz] regsvr32.exe "I:\Documents and Settings\All Users\Application Data\XobeDsuz\XobeDsuz.dat" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [WoypEkep] regsvr32.exe "I:\Documents and Settings\All Users\Application Data\WoypEkep\WoypEkep.dat" (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [XobeDsuz] regsvr32.exe "I:\Documents and Settings\All Users\Application Data\XobeDsuz\XobeDsuz.dat" (User 'Default user')


    Did you not find them? Try again. If you find them and have analyse.exe fix them then reboot your PC and scan again to see if they are really gone. Let me know. Maybe that error you had with analyse.exe ( really hijackthis.exe ) cause them not to get fixed. Did you still get that error while running the fix in message # 21?
     
  24. helpmeplease2

    helpmeplease2 Private E-2

    Now attaching error received from step 2 running Hijack this
    I Clicked "no" to report and it continued on with executing

    Also attaching log from OTM and errors received upon reboot
    then continuing on with Junkware removal tool

    then will run hitman pro in step 4

    then will run the C:\MGtools\GetLogs.bat file and attach files in step 5
     
  25. helpmeplease2

    helpmeplease2 Private E-2

    Now step/request 3 attaching Junkware removal tool JRT.txt and when I launched mozilla on affected computer says something was installed so attaced that screenshot

    then will run hitman pro in step 4

    then will run the C:\MGtools\GetLogs.bat file and attach files in step 5
     

    Attached Files:

    • JRT.txt
      File size:
      1.5 KB
      Views:
      2
  26. helpmeplease2

    helpmeplease2 Private E-2

    I do not see the attachments so I an reattaching...something installed http nowhere and I think it affected me coming to your site and attaching files
     

    Attached Files:

  27. helpmeplease2

    helpmeplease2 Private E-2

    Hi. I see your message to post all logs/errors together. Sorry I misunderstood the instructions. I am running the step Hitman pro and am confused on what to do. I see 1 Trojan = msiexec.exe,3 Suspicious = FRST.exe, 37 listed as Newplayer, 1 flv player, 4 pcoptimizer pro. There is a Delete displayed beside all but the FRST which has a ignore. Just click next?
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you want to remove all the Malware and Potentially Unwanted Programs which of course does not inclued FRST. ;)
     
  29. helpmeplease2

    helpmeplease2 Private E-2

    Well, now Hitman Pro is asking me for a product key. I clicked "I do not have a product key" and it took me to surfright.nt to purchase but I cannot afford it. Is there a workaround?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Seems your trial periode has already expired. Too bad. Your PC is having lots of problems. Some of them may be due to the way it is configured with drive I being the Windows boot drive. It seems to becausing issues for quite a few of the tools. Problems are showing up in your logs on drive I bu when we go to fix them, it keeps reporting that they are not found or you have those crashes in the applications. These all indicates issues with your Windows installation. It is getting difficult to work around these problems because many of the tools are not able to run properly.

    Please run RogueKiller and have it fix any of the Powerlik items if they still show up. Then immediately reboot and after reboot, run a new scan with RogueKiller and attach the new log.
     
  31. helpmeplease2

    helpmeplease2 Private E-2

    Hi. Executed Roguekiller. Posting log because I don't want to accidentally delete something I need. Please advise.
     

    Attached Files:

  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that is looking much better than the original log. Just have it fix the below which you will find on the Registry tab

    [Suspicious.Path] HKEY_USERS\S-1-5-21-1409082233-616249376-1417001333-1004\Software\Microsoft\Windows\CurrentVersion\Run | XobeDsuz : regsvr32.exe "I:\Documents and Settings\All Users\Application Data\XobeDsuz\XobeDsuz.dat" -> Found

    After fixing this, reboot and run a new scan. Attach the new log.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also do the below.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  34. helpmeplease2

    helpmeplease2 Private E-2

    Thank you

    Executed Roguekiller. deleted Suspicious.Path] HKEY_USERS\S-1-5-21-1409082233-616249376-1417001333-1004\Software\Microsoft\Windows\CurrentVersion\Run | XobeDsuz : regsvr32.exe "I:\Documents and Settings\All Users\Application Data\XobeDsuz\XobeDsuz.dat" -> Found

    rebooted, Posting log

    Ran fixme.reg = sucessful

    Do you still want me to run the C:\MGtools\GetLogs.bat file and attach files?
     

    Attached Files:

  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    No not right now. Let's run Hitman Pro now and just perform a scan and save a new log to attach.

    Also how are things running at this point?
     
  36. helpmeplease2

    helpmeplease2 Private E-2


    Did a little testing. Running very good.
    No Hard drive crunching Yay!
    No Permission Changes Windows popping up Yay!
    No Crashes Yay!
    Normal services running in Task Manager Yay!
    PC not running slow anymore Yay!
    Anxiety down to a minimum.
     

    Attached Files:

  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounding pretty good. Let's delete a few items manually and then run one last check with MGtools.

    Please delete the below. The one in purple is a folder name. The rest are files.

    I:\Documents and Settings\server\Desktop\FRST-OlderVersion\FRST.exe
    I:\Documents and Settings\server\Desktop\FRST-OlderVersion
    I:\Documents and Settings\server\Desktop\FRST.exe
    I:\Documents and Settings\server\My Documents\NETWORK SHARE\PC Help\FRST.exe


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  38. helpmeplease2

    helpmeplease2 Private E-2

    Thank you
    Received attached error numerous times.
    Pressed continue until it finished executing.
     

    Attached Files:

  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When? While trying to delete those files and folder? Or only when trying to delet the last one that has the NETWORK SHARE folder in the path? Why is this a network share????? All these error you keep having arel indicating issues with your Windows Installation.

    • Is drive I accessible to you?
    • Can you find and open the I:\Documents and Settings\server folder?
    • What can you tell me about the setup of this PC? Is it configured in some strange way?
    • Is it really being used as a server?
    • Does the other user account ( the adan account ) on this PC work properly or does it have strange problems too?
     
  40. helpmeplease2

    helpmeplease2 Private E-2

    I got the error only when executing C:\MGtools\GetLogs.bat
    Everything you told me to manually delete, deleted successfully

    *Drive I: is accessible
    *Yes I can Access I:\Documents and Settings\server
    *I am not sure how to answer "What can you tell me about the setup of this PC? Is it configured in some strange way?" I am told when MS Windows XP installed, it set it's own drive letters. It has a lot of ports in the front of the PC.
    * I am not sure the definition of a server but this desktop was being used by itself hardwired and then shortly after put on a wireless network and when the networked laptop died, the wireless network was taken down. I got the wireless networking equipment back from friend and borrowed their laptop to troubleshoot this issue faster.
    *I only created the ADAN account to try to workaround the permissions issue and would like to remove it. It did not help me.
     
  41. helpmeplease2

    helpmeplease2 Private E-2

    Adding to my post #40, It is connected to a TV for a display via PC to TV device and connected to an amp via the soundcard. The 3.5 floppy doesn't work, the cd/dvd reader/writer doesn't work the cd-rom doesn't work. The USB ports do work. The rest of the ports have not been tested. I'm really not sure what information is important to you so I will wait for your next post.
    I never tested the rest.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay thanks for the info. You can see info about that error message in the below link:

    http://answers.microsoft.com/en-us/windows/forum/windows_xp-system/windows-no-disk-exception-processing-message/b1a67525-d5e8-46ae-9801-6b169547e656


    Your logs are clean. General assessment is that this PC has some problems within Windows itself which is the cause for all of the error messages we have been seeing. If it runs okay for what you need to do then just live with it. Oherwise I suggest getting a new PC with an updated more secure operating system. If you cannot afford a new PC and the problems on this PC are causing you a lot of grief then look into a clean reinstall ( not a topic for this forum ).



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  43. helpmeplease2

    helpmeplease2 Private E-2

    Thank you so much for your time and effort. I have great news too. My friend came by this morning and said I may keep her laptop and my old wireless hardware . She is getting one Black Friday and since I have helped her, her friends and family over the years with their computers, she is gifting me this one. I still need the desktop for watching TV /Netflix and all those darn files but can do other surfing with this one. Hopefully the desktop will hold long enough for me to save for a new one. :-D
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely and enjoy your gift. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds