Jump to content

shahdad

Member
  • Posts

    19
  • Joined

  • Last visited

  • Donations

    0.00 USD 
  • Country

    Canada

Everything posted by shahdad

  1. i took it apart and connect directly to a sata cable, bios wont even pick it up... i think its really dead
  2. Hi, I have a WD usb external 500gb hard drive and it has stopped working.... Today I plugged it in to my laptop as usual for file transfering and find that it does not work. On boot up it makes a nice clicking noise so most likely its dead.... I have called WD and ordered a RMA but I need to figure out a way to get my data. I have data recovery software but the problem is that I cant even get the drive to register in windows xp. I plug in the usb cable and the drive powers up. The blue night in the front comes on and you can hear it powering up. A few seconds later you here the windows chime that indicates a usb drive has been connected. The Safety Remove Hardware icon also shows up in the the task bar and when you dbl click on it there's a USB Mass storage device listed. However, nothing shows up in my computer. So I ran a cross-ref to dbl check, in computer management, in Device manager, under Disk Drives it registers as WD External USB Device. BUT under Disk Management there is DISK 1, only the DISK 0 which is the internal drive.... wtf??? Is there anyway to get the drive to register so i can run a data recovery on it??? Any help would be appreciated, thanks
  3. i just thought of the other things i will need do after ive installed xp so... revision of thought 1. format 2. partition 3. install xp 4. defrag after install 5. install appz off cd's (no internet connection yet) office, norton wow thats it, haha, everything else is downloaded of the net 6. degrag again 7. set clean system restore point here. now connect to the net 8. update norton 9. windows update 10. dl & install windows defender 11. dl & install firefox - also about:config at this pioint for tweaks: ---> use detailed guide at www.tweakfactor.com/articles/tweaks/firefoxtweak/4.html 12. dl & install fiirefox preloader 13. dl & install adobe reader 14. dl & install anything else that comes to mind at this point that i may have missed now 15. degrag 16. set another system restore point 17. now im on my marry way to screw up the computer again wow i think i just made a guide, haha so any tips or input on the above? i miss or skip anything crucial or even minor?
  4. okay i give up.... haha DonDamm, im going to do exactly what you said, little bit of work now will save me a lots in the future is there a more in depth guide, just like all your steps, that will cover things that I might miss since im doing this for the first time? you only realize afterwards that you missed something, if theres a guide, many others have made the mistakes already so we can learn from them thanks all for your help
  5. lol, yup should have just done a format. I would have done it but i never set up a partition because the notebook came nice and set up by dell. haha, and i still still got crap - downloaded superantispyware, first run picks up trojan.winfixer - 6 items i ran a RootkitRevealer but it didnt come up with anything ... back to the drawing boards option 1. save my self a lot of time = format option 2. waste a lot of time bc im going to get this **** thing now - its war! haha
  6. update: i found an app called ComboFix. ran it, fixed everything.... insane, 1 program fixed everything it seems. ive run 20 different things up till now, i find that one... and zap all probs seem to be fixed got my taskbar items back, no pop ups after log in final check to go still but all looks good i think
  7. So I ran all of the scans again, and all came up clean. I ran: Ad-Aware AVG Anti-Spyware Spybot - Search & Destroy TrojanHunter Scanner Windows Defender I thought everything was fixed, and too check, I powered down fully and power up few hours later. as soon as i logged in, pop up in ie - (didnt go anywhere bc my wireless was off). I also noticed everything that suppose to be in my taskbar is missing. ive ran several hijack this, but all logs looked clean. so i renamed it to shahdad.exe, now ive got some hits. can i post logs here? also, i ran the root searches but they didnt find anything
  8. I've run every possible scan there is, and this thing is still in the system. Trojan hunter Norton antivirus avg ad-aware bit defender online scanner cwshredder stinger winsockxpfix cleanup s&d it first started with the computer logging onto the net and playing audio, random audio with nothing open. norton blocked a few things with the messages indicating trojans - couldn't get the names. widows defender also block stuff (stop working now - cant run it) i tried to log into safemode but im thinking something is blocking this as i only get a black screen after selecting a user. i did however manage to run all the above by ctrl+alt+del then start new task hijack this looks clean too the appz only seem to be piking up Trojan.agent.alz in avg / agent.100 in trojanhunter ive run out of ideas..... help plz Back to top View user's profile Send private message
  9. and the problem was....... power supply new one in and all is good bought one from staples, 465w for $50 good enough for now
  10. i cannot find anything in the bios that resembles C.O.P. where i can change the value all i can find close to that under the power setting is apm configuration where there are many settings i can choose from but nothing to do with cpu temp there is a throttle slow clock ratio - thats set at 50% - dont know what it is though under hardwarre monitor, cpy temp rises to about 40C and the mb temp stays around 25C im going to leave it in bios and monitor the temps and see if it shuts down at higher temps if i wanted to swap out hte power supply what do i have to check to make sure its compatible? does it just have to be atx? thanks
  11. i forgot to ask what are the chances that its overheating? fan speed is at high rpm, all voltages are in range, cpu temp was about 40C and board temp was about a is that too high? and do mb have a auto shut off if temp goes too hight?
  12. yup looks that way, short somewhere and its not the battery, just took it out and its in the green ill have replace cables one by one and go from there i called asus tech support, he didnt even care about the problem, he checked to see if it was under warranty and it was so he said call the rma dep during the week and get it replaced, lol, ill take a new mobo but for now ill screw around and see if i figure out where the short is thanks
  13. thanks for the reply, i think it might be the batt b/c the power supply is good and all leads are connected. i dont suspect any cables as they are fairly new but one question if the battery is low that could cause the comp to turn off even if its plugged in and turns on initially?
  14. hi all any help would be great, my pc shuts off by itself after a while i turn it on, come back and its off. it even turned off while i was just using it. when i try and turn it back on it will not turn on. i have to unplug it, wait about 10 sec, then plug back in and then it turns on. i opened the case and the only thing ive noticed is that the light on the motherboard goes out after the 10 sec when its unplugged cpu is celeron 1.8 mb is asus p4p800s let me know if anything else is needed, thx
  15. all right something is still wrong, i cannot rename files placed on desktop, i cannot rename by clicking on it, rename under right click is not there, selecting item and pressing f2 does not work eiteher why is this and what is the solution?
  16. problem solved but one question if you right click on desktop then go NEW then select say, TEXT DOCUMENT, it will creat a new text document on desktop BUT DOES IT MAKE A SOUND??? when i create a file by right click methos>new>text document it makes a beep and places the file on desktop is this normal?
  17. I cannot create new icons on destop? i cant move a file to desktop. i cant even view the files i have on destop. all that is on desktop is, My computer, my documents, recycle bin, internet exploer, and monzila firefox i had lots of other files on desktop but the only way to view them is to go to C:\Documents and Settings\Shahdad\Desktop something is screwed with the registry, how do i fix it so it goes back to the way it was? heres a hijack this log if it helps Logfile of HijackThis v1.99.1 Scan saved at 12:19:32 PM, on 11/16/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\ibmpmsvc.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\brsvc01a.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\brss01a.exe C:\WINDOWS\system32\Brmfrmps.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\AGRSMMSG.exe C:\Program Files\GIANT Company Software\GIANT AntiSpyware\gcasServ.exe C:\WINDOWS\system32\RunDll32.exe C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE C:\Program Files\GIANT Company Software\GIANT AntiSpyware\gcasDtServ.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe C:\Program Files\GIANT Company Software\GIANT AntiSpyware\GIANTAntiSpywareMain.exe C:\Documents and Settings\Shahdad\My Documents\Spyware\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file) O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [gcasServ] C:\Program Files\GIANT Company Software\GIANT AntiSpyware\gcasServ.exe O4 - HKLM\..\Run: [gcasDtServ] gcasDtServ.exe O4 - HKLM\..\Run: [bMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor O4 - HKLM\..\Run: [bMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE O4 - HKLM\..\Run: [bMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe O4 - HKLM\..\Run: [sSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe O4 - HKLM\..\Run: [indexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: Download Using &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: http://www.plentyoffish.com O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/games/clients/y/at1_x.cab O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potd_x.cab O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com ActionRunner Class) - file://c:\Program Files\ThinkPad\Access Support\Agent\common\install\sprt\tgctlar.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...l_v1-0-3-18.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe O16 - DPF: {5DD731E6-D4F0-11D3-BE3F-00105A6FDA50} (V3ProX Control) - http://ahnlabdownload.nefficient.co.kr/plugin/myv3/myv3.cab O16 - DPF: {605D405B-C484-4D30-B6D2-031CB2F440A4} (Vmon Control) - http://ahnlabdownload.nefficient.co.kr/plugin/vmon/vmon.cab O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - file://c:\Program Files\ThinkPad\Access Support\Agent\common\install\ibmegath.cab O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v45/sol/sol.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/d.../ITDetector.cab O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{F8DD9B52-8530-452A-9E4F-88AB880262BD}: NameServer = 192.168.1.1 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing) O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
  18. now the fact that i changed the desktop value under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders from something to %USERSPROFILE%\desktop isnt the the reason it keeps on making hte file on destop?
  19. I keep on getting this folder on desktop even after I delete it, it comes back after a while The folder is named %USERSPROFILE% and then these folders, in the order of openining- Application Data Microsoft CryptnetUrlCache & SystemCertificates Content & MetaData My two long files two long files Certificates & CRLs & CTLs HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders destop string under user shell folders is also called %USERSPROFILE%\desktop im thinking that this is the string that is incorrect, what shold it be so the folder does not get created on desktop?
×
×
  • Create New...