Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Vundo Virus, Explorer.exe Error, Countless Popups, Bogus Malware Warnings


  • This topic is locked This topic is locked
2 replies to this topic

#1 abagley1984

abagley1984

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 10 March 2008 - 02:13 PM

As of last nght i started getting popups about running/downloading spyware from different sites as well as several from credit card sites, fake malware removal, and even an ebay login that was not genuine ebay, and as of this morning adult oriented, great with the kids around....



The other thing im getting is a message saying explorer.exe had an error and needs to close the headed says c++ visual runtime library and then explained a buffer overrun has malfunctioned and the internal stability has been corrupted

im thinking a trojan(s) probably more. I downloaded afew programs for my pda but other than that i have no idea where these came from....

i ran spybot search and destroy with tea timer and have denied two registry changes, as well as adaware 2007, neither finding anything specific. After a full scan with AVG Free it came back with no viruses but "C:\windows\system32\drivers\etc\hosts" as changed.

im running win xp on a HP and i generally use IE 7. to this point i have had no problems at all, a little over a year

i must admit havent ran any spyware tools in sometime until this morning... (adaware and spybot) neither finding anything

after a running trojanhunter 5.0, it found 4 but only deleted 3 trojans
C:\windows\system32\closeapp.exe
C:\windows\system32\amalakpyh.dll
C:\program files\HPQ\quick launch buttons\KbdJp.exe

it was unable to remove C:\windows\system32\uturq.dll - which i think is VundoB or something..., when i browse the system32 folder it is not present.

on restart a notification that amalakpyh.dll was not found displayed, i think thats good? - see this on the hijack log but afraid to do anything to it

im fairly sure i have the vundo virus/trojan like many others here... probably other things as well


vundofix would not work so i've ran virtumundo be gone, the log follows:


03/09/2008, 16:08:53] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Administrator\Desktop\VirtumundoBeGone.exe" )
[03/09/2008, 16:08:59] - Detected System Information:
[03/09/2008, 16:08:59] - Windows Version: 5.1.2600, Service Pack 2
[03/09/2008, 16:08:59] - Current Username: Administrator (Admin)
[03/09/2008, 16:08:59] - Windows is in SAFE mode.
[03/09/2008, 16:08:59] - Searching for Browser Helper Objects:
[03/09/2008, 16:08:59] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/09/2008, 16:08:59] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[03/09/2008, 16:08:59] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[03/09/2008, 16:08:59] - BHO 4: {836BA034-AA9C-48E7-8871-42795DB53594} ()
[03/09/2008, 16:08:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/09/2008, 16:08:59] - Checking for HKLM\...\Winlogon\Notify\vturq
[03/09/2008, 16:08:59] - Key not found: HKLM\...\Winlogon\Notify\vturq, continuing.
[03/09/2008, 16:08:59] - BHO 5: {AFD4306C-BBF7-417F-809D-5D8766AAE9E2} ()
[03/09/2008, 16:08:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/09/2008, 16:08:59] - No filename found. Continuing.
[03/09/2008, 16:08:59] - BHO 6: {FBD29C3C-C642-4843-A627-6E54A947B511} ()
[03/09/2008, 16:08:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/09/2008, 16:08:59] - Checking for HKLM\...\Winlogon\Notify\hggdbxu
[03/09/2008, 16:08:59] - Found: HKLM\...\Winlogon\Notify\hggdbxu - This is probably Virtumundo.
[03/09/2008, 16:08:59] - Assigning {FBD29C3C-C642-4843-A627-6E54A947B511} MSEvents Object
[03/09/2008, 16:08:59] - BHO list has been changed! Starting over...
[03/09/2008, 16:08:59] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/09/2008, 16:08:59] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[03/09/2008, 16:08:59] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[03/09/2008, 16:08:59] - BHO 4: {836BA034-AA9C-48E7-8871-42795DB53594} ()
[03/09/2008, 16:08:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/09/2008, 16:08:59] - Checking for HKLM\...\Winlogon\Notify\vturq
[03/09/2008, 16:08:59] - Key not found: HKLM\...\Winlogon\Notify\vturq, continuing.
[03/09/2008, 16:08:59] - BHO 5: {AFD4306C-BBF7-417F-809D-5D8766AAE9E2} ()
[03/09/2008, 16:08:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/09/2008, 16:08:59] - No filename found. Continuing.
[03/09/2008, 16:08:59] - BHO 6: {FBD29C3C-C642-4843-A627-6E54A947B511} (MSEvents Object)
[03/09/2008, 16:08:59] - ALERT: Found MSEvents Object!
[03/09/2008, 16:08:59] - Finished Searching Browser Helper Objects
[03/09/2008, 16:08:59] - *** Detected MSEvents Object
[03/09/2008, 16:08:59] - Trying to remove MSEvents Object...
[03/09/2008, 16:09:00] - Terminating Process: IEXPLORE.EXE
[03/09/2008, 16:09:01] - Terminating Process: RUNDLL32.EXE
[03/09/2008, 16:09:01] - Disabling Automatic Shell Restart
[03/09/2008, 16:09:01] - Terminating Process: EXPLORER.EXE
[03/09/2008, 16:09:01] - Suspending the NT Session Manager System Service
[03/09/2008, 16:09:01] - Terminating Windows NT Logon/Logoff Manager
[03/09/2008, 16:09:01] - Re-enabling Automatic Shell Restart
[03/09/2008, 16:09:01] - File to disable: C:\WINDOWS\system32\hggdbxu.dll
[03/09/2008, 16:09:01] - Renaming C:\WINDOWS\system32\hggdbxu.dll -> C:\WINDOWS\system32\hggdbxu.dll.vir
[03/09/2008, 16:09:01] - File successfully renamed!
[03/09/2008, 16:09:01] - Removing HKLM\...\Browser Helper Objects\{FBD29C3C-C642-4843-A627-6E54A947B511}
[03/09/2008, 16:09:01] - Removing HKCR\CLSID\{FBD29C3C-C642-4843-A627-6E54A947B511}
[03/09/2008, 16:09:01] - Adding Kill Bit for ActiveX for GUID: {FBD29C3C-C642-4843-A627-6E54A947B511}
[03/09/2008, 16:09:01] - Deleting ATLEvents/MSEvents Registry entries
[03/09/2008, 16:09:01] - Removing HKLM\...\Winlogon\Notify\hggdbxu
[03/09/2008, 16:09:01] - Searching for Browser Helper Objects:
[03/09/2008, 16:09:01] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/09/2008, 16:09:01] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[03/09/2008, 16:09:01] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[03/09/2008, 16:09:01] - BHO 4: {836BA034-AA9C-48E7-8871-42795DB53594} ()
[03/09/2008, 16:09:01] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/09/2008, 16:09:01] - Checking for HKLM\...\Winlogon\Notify\vturq
[03/09/2008, 16:09:01] - Key not found: HKLM\...\Winlogon\Notify\vturq, continuing.
[03/09/2008, 16:09:01] - BHO 5: {AFD4306C-BBF7-417F-809D-5D8766AAE9E2} ()
[03/09/2008, 16:09:01] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/09/2008, 16:09:01] - No filename found. Continuing.
[03/09/2008, 16:09:01] - Finished Searching Browser Helper Objects
[03/09/2008, 16:09:01] - Finishing up...
[03/09/2008, 16:09:01] - A restart is needed.
[03/09/2008, 16:09:05] - Attempting to Restart via STOP error (Blue Screen!)

I dont think it helped anything, as popups are still present, though less often, now it more dialouge boxes about malware warnings, and the occasinal adult add and the darn C++ explorer error every 2 minutes...

here is the hijackthis log after virtumundo be gone:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:58:53 PM, on 3/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\LClock\LClock.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Adam\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BM4ef4ce53] Rundll32.exe "C:\WINDOWS\system32\amlakpyh.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [P2kAutostart] C:\Documents and Settings\Adam\Desktop\p2k\P2kAutostart.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [IMC] C:\Program Files\FriendFinder\FriendFinder Messenger 4\imc.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Adam\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

--
End of file - 10489 bytes




i expect i will need to run ComboFix but im not sure as to which file to download from microsoft for SP2, home or professional, as im running XP media center edition to install the recovery console. there was no windows cd included with the laptop

EDIT: i've been reading and found that media center XP and XP Pro are basiaclly the same, so that is the file that will be needed for combo fix, if it is in fact needed, correct?

Edited by abagley1984, 10 March 2008 - 08:51 PM.


BC AdBot (Login to Remove)

 


#2 abagley1984

abagley1984
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 12 March 2008 - 05:54 PM

problem solved, thanks!

#3 KoanYorel

KoanYorel

    Bleepin' Conundrum


  • Staff Emeritus
  • 19,461 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:65 miles due East of the "Logic Free Zone", in Md, USA
  • Local time:04:30 PM

Posted 12 March 2008 - 10:14 PM

Thanks for informing us.

Should you find other problems, please start a new topic.

This thread is closed.
The only easy day was yesterday.

...some do, some don't; some will, some won't (WR)




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users