Options

Unable to boot in normal mode

Hi,

I was using the Internet yesterday, specifically browsing Facebook while closing the browser I received a lot of pop-ups and then something called as Rapid virus removal. I closed everything and then restarted the computer after turning off the internet. It would not let me boot in the normal mode and went in a restart loop.
I am using Win XP SP2, I restarted the computer and booted to safe mode with networking and removed the files that were suspicious in my startup list and process. But am still not able to boot to normal mode.

Getting Application error c0000145.

Please provide suggestions in rectifying this.

Thanks
Chris

the hijackthis logfile after the first scan

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:34:20 PM, on 4/2/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\TEMP\7AF2.tmp
C:\WINDOWS\TEMP\7AF2.tmp
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll
O21 - SSODL: SysRun - {D7FFD784-5276-42D1-887B-00267870A4C7} - C:\WINDOWS\system32\svshost.dll
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

--
End of file - 3554 bytes

Any help on this would be appreciated. Thanks
Chris

Comments

  • edited April 2009
    Adobe Flash Player ActiveX
    Adobe Reader 7.0
    Adobe Shockwave Player
    Agere Systems PCI Soft Modem
    Any Video Converter 2.6.7
    CueClub
    DVDfunSTUDIO
    DVD-MovieAlbumSE 4.3
    DVD-RAM Driver
    EA SPORTS(TM) Cricket 07
    GemMaster Mystic
    High Definition Audio Driver Package - KB888111
    HijackThis 2.0.2
    HP Customer Participation Program 7.0
    HP Deskjet Printer Preload
    HP DigitalMedia Archive
    HP Document Viewer 5.3
    HP Game Console and games
    HP Image Zone 5.3
    HP Image Zone for Media Center PC
    HP Imaging Device Functions 7.0
    HP Multimedia Keyboard Software
    HP Photosmart 330,380,420,470,7800,8000,8200 Series
    HP Photosmart and Deskjet 7.0 Software
    HP Photosmart Cameras 5.0
    HP Photosmart Essential
    HP PSC & OfficeJet 5.3.B
    HP Software Update
    HP Solution Center 7.0
    HP Tunes
    HPTunesAddIn
    Intel(R) Graphics Media Accelerator Driver
    Intel(R) PRO Network Connections Drivers
    InterVideo WinDVD Player
    iTunes
    J2SE Runtime Environment 5.0
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1
    Microsoft Money
    Microsoft Office Professional Edition 2003
    Microsoft Works
    Mozilla Firefox (2.0.0.20)
    Otto
    PC-Doctor 5 for Windows
    PS2
    Python 2.2 pywin32 extensions (build 203)
    Python 2.2.3
    QuickTime
    RealPlayer
    Security Update for Windows XP (KB883939)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896422)
    Skypeâ„¢ 3.6
    Software for DVD Video Camera
    Sonic Encoders
    Sonic Express Labeler
    Sonic MyDVD Plus
    Sonic RecordNow Audio
    Sonic RecordNow Copy
    Sonic RecordNow Data
    Sonic Update Manager
    TeamViewer 4
    VideoLAN VLC media player 0.8.6e
    VIMICRO USB PC Camera(ZC0301PL)
    WildTangent Web Driver
    Windows Media Format Runtime
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB883667
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB888113
    Windows XP Hotfix - KB890175
    Windows XP Hotfix - KB891781
    Windows XP Hotfix - KB893066
    Yahoo! Messenger



  • TroganTrogan London, UK
    edited April 2009
    Hi,

    Apologies for the delay. Could you please post a new HijackThis log.

    Thanks.
  • edited April 2009
    Had been out, I will post the log file in a day. Is there something else you would want me to do?

    There has been few more developments lately.......
    1. I am not able to install any anti-virus software now
    2. Not able to run any online anti-virus software
    3. Was able to install Spybot S&D which found some infection
    4. Able to boot to normal mode, (no 3rd party services, no startup
    items) but get the error system is shutting down because of NT
    Authority System Services.exe.
    5. Able to stop that using Shutdown -a, but computer freezes after that
    and cannot be used further.
    6. Getting another error Services and App has encountered a problem and
    needs to close

    Apart from these the computer works well in safemode with networking.

    Thanks



  • TroganTrogan London, UK
    edited April 2009
    Hi, sorry for the delay.

    If you can, post a HijackThis log from Normal Mode please.
Sign In or Register to comment.