This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] fruhab.exe, fzd.exe

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

during the installation of a program i noticed some new processes in task manager, google search revealed them as trojan backdoors, i killed the processes and blocked them from internet, i dont know what they have already installed or what they do but would like some help in removing all traces, have already created restore points , registry backups and have hijack this and otl(?) installed… thanks in advance if you can help…
Hi einstein11

:welcome:

I'm martix and I'll be glad to assist you fix your problem.
Please follow my instructions and stay with this topic until I give you the ALL CLEAN post.

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


NEXT


Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt and Attach.txt report in your next reply

  • Please include in your next reply:


    GMER log
    DDS log
sorry for the wait, yes i do still need assistance , i cant seem to finish the gmer scan, the computer hangs at a certain point and the scan stops, having trouble with fire fox as well it goes straight to 100% cpu usage and then i cant even dwnld with your link, will try one last time and send you the reply asap thanks for the patience.
i have retried the gmer scan withe the lan cable unplugged , avg and sygate disabled and minimum of apps running but everytime it goes to the bluescreen and windows restarts, i even tried running gmer.exe with "run as" and unchecked the option "protect computer and data from unauthorized use by this program" (not sure of exact translation , i am using windows in italian language). i have another installation of windows on another partition if it helps i could run the scan from there.
Please download this file, and save it to your Desktop. Once you have downloaded it, save and close all other programs and run it by double-clicking on the file named "RootRepeal.exe".

Once the main window shows up, please click on the "Report" button on the bottom of the window. Next, please click the "Scan" button.

Another window will pop up asking you to select what to include in the scan. Please uncheck everything except for the "Stealth Code" checkbox, and then click OK.

Once the program has finished scanning, the results will appear. Click on the "Save Report" button, and save the report to your desktop.

Finally, please open this report with Notepad, and post it here.
sorry for the wait i was waiting for your reply, root repeal crashed as well… ROOTREPEAL CRASH REPORT ————————- Windows Version: Windows XP SP3 Exception Code: 0xc0000005 Exception Address: 0x7c920a19 Attempt to read from address: 0x00730079 just so you know the operating system isnt that unstable with other programs just with the rootkit scans (cpu goes to 100% when using mozzila),
Ok einstein11,

we'll try another thing, so follow the instructions below in Normal Windows start up. If it crashes try the hole procedure in Safe Mode.

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2


[external image: Posted Image]


[external image: Posted Image]

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
ok, scan completed, i do not have recovery console installed, (when combo fix prompted for the download , it was during restart and the lan drivers hadn't loaded yet) but i have already created a restore point when i first spotted the virus though, (will attempt to install recovery console manually) thankyou…


ComboFix 10-05-16.02 - dani 17/05/2010 17.09.07.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.447.96 [GMT 2:00]
Eseguito da: e:\documents and settings\dani\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Sygate Personal Firewall *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

e:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_SSHNAS
——-\Service_SSHNAS


((((((((((((((((((((((((( Files Creati Da 2010-04-17 al 2010-05-17 )))))))))))))))))))))))))))))))))))
.

2010-05-12 06:08 . 2010-05-12 06:08 ——– d—–w- e:\documents and settings\NetworkService\Impostazioni locali\Dati applicazioni\Apple
2010-05-12 02:02 . 2010-05-12 02:02 ——– d—–w- e:\documents and settings\All Users\Dati applicazioni\TEMP
2010-05-12 01:44 . 2006-06-19 10:01 69632 —-a-w- e:\windows\system32\ztvcabinet.dll
2010-05-12 01:44 . 2006-05-25 12:52 162304 —-a-w- e:\windows\system32\ztvunrar36.dll
2010-05-12 01:44 . 2005-08-25 22:50 77312 —-a-w- e:\windows\system32\ztvunace26.dll
2010-05-12 01:44 . 2003-02-02 17:06 153088 —-a-w- e:\windows\system32\UNRAR3.dll
2010-05-12 01:44 . 2002-03-05 22:00 75264 —-a-w- e:\windows\system32\unacev2.dll
2010-05-12 01:44 . 2010-05-12 01:44 ——– d—–w- e:\programmi\Trojan Remover
2010-05-12 01:44 . 2010-05-12 01:44 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\Simply Super Software
2010-05-12 01:44 . 2010-05-12 01:44 ——– d—–w- e:\documents and settings\All Users\Dati applicazioni\Simply Super Software
2010-05-06 03:07 . 2010-05-06 03:25 ——– d—–w- e:\programmi\ERUNT
2010-05-06 02:18 . 2010-05-06 02:18 ——– d—–w- e:\documents and settings\All Users\Dati applicazioni\Driver Whiz
2010-05-06 01:34 . 2010-05-06 01:34 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\Media Player Classic
2010-05-04 22:45 . 2010-05-04 22:45 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\Facebook
2010-05-04 15:47 . 2010-05-04 15:47 57272 —ha-w- e:\windows\system32\mlfcache.dat
2010-04-29 13:43 . 2010-04-29 13:43 ——– d—–w- e:\programmi\Trend Micro
2010-04-25 04:13 . 2010-05-15 18:48 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\vlc
2010-04-25 01:19 . 2010-04-25 01:19 ——– d—–w- e:\programmi\Mozilla ActiveX Control v1.7.12
2010-04-25 01:17 . 2010-04-25 01:19 ——– d—–w- e:\programmi\Graboid
2010-04-18 00:56 . 2010-04-18 00:56 ——– d—–w- e:\programmi\MSECache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-15 16:43 . 2010-02-11 16:34 664 —-a-w- e:\documents and settings\dani\Impostazioni locali\Dati applicazioni\d3d9caps.dat
2010-05-12 14:44 . 2010-02-21 15:33 ——– d—–w- e:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2010-05-08 12:56 . 2010-01-11 01:17 ——– d—–w- e:\documents and settings\All Users\Dati applicazioni\avg9
2010-05-06 03:22 . 2010-02-03 13:53 ——– d—–w- e:\programmi\TrojanHunter 5.0
2010-05-06 03:21 . 2010-04-17 11:47 ——– d—–w- e:\programmi\Panda Security
2010-05-05 14:21 . 2010-01-14 02:18 ——– d—–w- e:\documents and settings\All Users\Dati applicazioni\Soulseek
2010-04-26 07:16 . 2001-08-31 15:00 96334 —-a-w- e:\windows\system32\perfc010.dat
2010-04-26 07:16 . 2001-08-31 15:00 516544 —-a-w- e:\windows\system32\perfh010.dat
2010-04-23 18:33 . 2010-01-11 02:06 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\Skype
2010-04-23 18:06 . 2010-03-10 12:51 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\skypePM
2010-04-21 07:23 . 2010-01-11 01:17 242896 —-a-w- e:\windows\system32\drivers\avgtdix.sys
2010-04-12 23:13 . 2010-01-17 23:04 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\Intelliremote
2010-04-10 01:30 . 2010-04-10 01:30 ——– d—–w- e:\programmi\File comuni\Java
2010-04-10 01:29 . 2010-01-14 01:20 ——– d—–w- e:\programmi\Java
2010-03-18 15:58 . 2010-01-27 16:56 ——– d—–w- e:\documents and settings\dani\Dati applicazioni\dvdcss
2010-03-13 11:30 . 2010-03-13 11:30 12464 —-a-w- e:\windows\system32\avgrsstx.dll
2010-03-13 11:30 . 2010-01-11 01:17 29512 —-a-w- e:\windows\system32\drivers\avgmfx86.sys
2010-03-13 11:28 . 2010-01-11 01:17 216200 —-a-w- e:\windows\system32\drivers\avgldx86.sys
2010-03-10 12:51 . 2010-03-10 12:51 56 —ha-w- e:\windows\system32\ezsidmv.dat
2010-03-10 06:15 . 2004-08-19 13:39 420352 —-a-w- e:\windows\system32\vbscript.dll
2010-03-09 02:28 . 2010-01-14 01:21 411368 —-a-w- e:\windows\system32\deploytk.dll
2010-02-25 06:16 . 2004-08-19 13:39 916480 —-a-w- e:\windows\system32\wininet.dll
2010-02-24 13:11 . 2004-08-03 21:15 455680 —-a-w- e:\windows\system32\drivers\mrxsmb.sys
2010-02-21 16:21 . 2010-01-10 23:09 76184 —-a-w- e:\documents and settings\dani\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-02-21 15:00 . 2010-02-21 15:00 691696 —-a-w- e:\windows\system32\drivers\sptd.sys
2010-02-16 19:05 . 2004-08-19 13:34 2149888 —-a-w- e:\windows\system32\ntoskrnl.exe
2010-02-16 19:05 . 2004-08-19 15:34 2028032 —-a-w- e:\windows\system32\ntkrnlpa.exe
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="e:\programmi\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="e:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"PHIME2002ASync"="e:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="e:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"acerWireless"="e:\programmi\acer\Wireless\Utility\WlanUtil.exe" [2005-01-10 462848]
"SoundMan"="SOUNDMAN.EXE" [2010-01-10 67584]
"SynTPLpr"="e:\programmi\Synaptics\SynTP\SynTPLpr.exe" [2010-01-10 98304]
"SynTPEnh"="e:\programmi\Synaptics\SynTP\SynTPEnh.exe" [2010-01-10 536576]
"AGRSMMSG"="AGRSMMSG.exe" [2010-01-10 88363]
"LtMoh"="e:\programmi\ltmoh\Ltmoh.exe" [2010-01-10 184320]
"QuickTime Task"="e:\programmi\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="e:\programmi\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"SmcService"="e:\progra~1\Sygate\SPF\smc.exe" [2004-10-15 2577632]
"SunJavaUpdateSched"="e:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="e:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="e:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"GrooveMonitor"="e:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"TrojanScanner"="e:\programmi\Trojan Remover\Trjscan.exe" [2010-02-27 1165192]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-13 11:30 12464 —-a-w- e:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-07-18 16:55 451872 —-a-w- e:\programmi\File comuni\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 15:44 3883856 —-a-w- e:\programmi\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 14:57 153136 —-a-w- e:\programmi\File comuni\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
2009-12-23 19:18 2642168 —-a-w- e:\programmi\Veoh Networks\VeohWebPlayer\veohwebplayer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"NBService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Irmon"=2 (0x2)
"idsvc"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"e:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"e:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"e:\\Programmi\\iTunes\\iTunes.exe"=
"e:\\Programmi\\AVG\\AVG9\\avgemc.exe"=
"e:\\Programmi\\AVG\\AVG9\\avgupd.exe"=
"e:\\Programmi\\AVG\\AVG9\\avgnsx.exe"=
"e:\\Programmi\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"e:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"e:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"e:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"e:\\Programmi\\Skype\\Phone\\Skype.exe"=

R0 sptd;sptd;e:\windows\system32\drivers\sptd.sys [21/02/2010 17.00.22 691696]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;e:\windows\system32\drivers\avgldx86.sys [11/01/2010 3.17.11 216200]
R1 AvgTdiX;AVG Free Network Redirector;e:\windows\system32\drivers\avgtdix.sys [11/01/2010 3.17.24 242896]
R2 avg9emc;AVG Free E-mail Scanner;e:\programmi\AVG\AVG9\avgemc.exe [13/03/2010 13.28.09 916760]
R2 avg9wd;AVG Free WatchDog;e:\programmi\AVG\AVG9\avgwdsvc.exe [13/03/2010 13.30.16 308064]
S3 IPN2220;acer IPN2220 Wireless LAN Card Driver;e:\windows\system32\drivers\i2220ntx.sys [10/01/2010 18.32.00 160896]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-07-18 16:53 451872 —-a-w- e:\programmi\File comuni\LightScribe\LSRunOnce.exe
.
Contenuto della cartella 'Scheduled Tasks'

2010-05-12 e:\windows\Tasks\AppleSoftwareUpdate.job
- e:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2010-05-17 e:\windows\Tasks\OGALogon.job
- e:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]

2010-05-17 e:\windows\Tasks\WGASetup.job
- e:\windows\system32\KB905474\wgasetup.exe [2010-01-12 21:18]
.
.
——- Scansione supplementare ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - e:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - e:\documents and settings\dani\Dati applicazioni\Mozilla\Firefox\Profiles\zs4vq599.default\
FF - plugin: e:\documents and settings\dani\Dati applicazioni\Facebook\npfbplugin_1_0_3.dll
FF - plugin: e:\programmi\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: e:\programmi\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: e:\programmi\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - e:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
e:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
e:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
e:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
e:\programmi\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-17 17:25
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti …

scansione entrate autostart nascoste …

Scansione files nascosti …

Scansione completata con successo
Files nascosti: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spcm.sys >>UNKNOWN [0x8438F938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7591f28
\Driver\ACPI -> ACPI.sys @ 0xf73f9cb8
\Driver\atapi -> atapi.sys @ 0xf7370b40
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805e710a
ParseProcedure -> ntoskrnl.exe @ 0x80578f7a
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805e710a
ParseProcedure -> ntoskrnl.exe @ 0x80578f7a
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
——————— CHIAVI DI REGISTRO BLOCCATE ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\*+áÅ-]
"DisplayName"=""
"DeviceDesc"=""
"ProviderName"=""
"MFG"="????????\02"
"ReinstallString"="??"
"DeviceInstanceIds"=multi:"s\\dani\\documenti\\download\\smbus_ati_5.10.1000.2_xpx86\\smbus_ati_5.10.1000.2_xpx86\\smbus\\smbusati.inf\00"
.
——————— Dlls caricate dai processi in esecuzione ———————

- - - - - - - > 'explorer.exe'(3300)
e:\windows\system32\WININET.dll
e:\windows\system32\SSSensor.dll
e:\windows\system32\webcheck.dll
.
———————— Altri processi in esecuzione ————————
.
e:\programmi\Sygate\SPF\smc.exe
e:\programmi\AVG\AVG9\avgchsvx.exe
e:\programmi\AVG\AVG9\avgrsx.exe
e:\programmi\AVG\AVG9\avgcsrvx.exe
e:\programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
e:\programmi\Bonjour\mDNSResponder.exe
e:\programmi\Java\jre6\bin\jqs.exe
e:\windows\system32\wdfmgr.exe
e:\programmi\AVG\AVG9\avgnsx.exe
e:\programmi\AVG\AVG9\avgcsrvx.exe
e:\windows\system32\wscntfy.exe
e:\windows\system32\wbem\wmiapsrv.exe
e:\windows\SOUNDMAN.EXE
e:\windows\AGRSMMSG.exe
e:\programmi\iPod\bin\iPodService.exe
.
**************************************************************************
.
Ora fine scansione: 2010-05-17 17:38:07 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-05-17 15:37

Pre-Run: 37.725.560.832 byte disponibili
Post-Run: 38.263.533.568 byte disponibili

- - End Of File - - F5C0247BF537B66EFE659B810D54A8EA

Attachments:

sorry but do you have a link for the recovery console? on the microsoft site it seems to be a long process if you dont have original xp disks… :blush:
einstein,

Please download maxlook, saving the file to your desktop.
Double click maxlook.exe to run it. Note - you must run it only once!
As instructed when the tool runs, restart the computer and logon to the Recovery Console.
Execute the following bolded command at the x:\windows> prompt <— the red x represents your operating system drive letter, usually C

batch look.bat

🖼Click to load external image (Posted Image)

You will see 1 file copied many times then return to the x:\windows> prompt.
Type Exit to restart your computer then logon in normal mode.

Once back in Windows, go to Start > Run, and copy/paste the following then press Enter.

maxlook -sig

Follow the prompts, and post (or attach) the log produced, C:\looklog.txt
sorry i will be away from the computer for a couple of days, in the meantime i will try to find the original xp disk with the recovery console install, (as i said i cant install with combofix because combofix runs before my lan and wifi drivers are installed and so it cant connect to the dwnld at microsoft .com), as i said before if you have a direct link to the recovery console dwnld and install it would be a great help, thanks for everything so far,

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI