Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Combofux Log help


  • This topic is locked This topic is locked
3 replies to this topic

#1 aris123

aris123

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:10:20 AM

Posted 30 June 2012 - 05:06 AM

Hello. I have been having a persistant problem for last 2 weeks.
It was like this:
At the middle of the work, there would be a messege saying “system will shut down” and then account down, but after the count-down ends, nothing happens, I can work on, but when I try to shut it down, it hangs at “saving your settings” page.

I tried several things like Malwarebyte. Then I ran combofix, I know that is not advicable without being advanced user, but I did. This is the log, can anyone analyse it for me please?
Till now there hv not been another of that problem, but Im not sure.

I should also add that following a similar problem in another form and the advice given there, I uploaded to ndis.sys to jotti scan but it said "file is empty". I post the combofix log below.
Help appreciated.
:thumbup2: :cold:

ComboFix 12-06-28.03 - Sourav kg 30/06/2012 14:37:51.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1013.328 [GMT 5.5:30]
Running from: c:\documents and settings\Sourav kg\Desktop\ComboFix.exe
AV: AVG Anti-Virus *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Privatefirewall *Enabled* {AF0CFAAE-AAB5-450a-8C74-0DEEB429DF4F}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgfinst.dat
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfapx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfarx.dll
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgntdumpx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgrunasx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avi7.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\compat.ini
c:\documents and settings\All Users\Application Data\TEMP\AVG\crt_x64.msi
c:\documents and settings\All Users\Application Data\TEMP\AVG\files.dat
c:\documents and settings\All Users\Application Data\TEMP\AVG\htmlayout.dll
c:\documents and settings\All Users\Application Data\TEMP\AVG\incavi.avm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_cz.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_da.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_es.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_fr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ge.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_hu.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_id.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_in.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_it.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_jp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ko.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ms.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_nl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pb.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ru.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sc.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sk.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_tr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_us.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zh.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaconf.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfacz.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfada.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaes.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfafr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfage.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfahu.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaid.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfain.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfait.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfajp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfako.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfams.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfanl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapb.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaru.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasc.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfask.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfatr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaus.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfavera.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaverx.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazh.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\microavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\miniavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.dat
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.ini
c:\documents and settings\All Users\Application Data\TEMP\AVG\vcredis1.cab
c:\documents and settings\All Users\Application Data\TEMP\AVG\vcredist.msi
c:\documents and settings\Sourav kg\Application Data\FFSJ
c:\documents and settings\Sourav kg\Application Data\FFSJ\FFSJ.cfg
c:\documents and settings\Sourav kg\WINDOWS
c:\windows\IsUn0407.exe
.
c:\windows\system32\drivers\ndis.sys . . . is infected!!
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NVUPDSERVICE
-------\Legacy_ONETWO
-------\Legacy_SVNGAGE
-------\Legacy_WVCHATTS
-------\Service_svngage
.
.
((((((((((((((((((((((((( Files Created from 2012-05-28 to 2012-06-30 )))))))))))))))))))))))))))))))
.
.
2012-06-30 06:23 . 2012-06-30 06:23 -------- d-----w- c:\documents and settings\Sourav kg\Local Settings\Application Data\Privatefirewall
2012-06-30 06:19 . 2012-05-25 13:04 135272 ----a-w- c:\windows\system32\drivers\pwipf6.sys
2012-06-30 06:19 . 2012-06-30 06:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Privacyware
2012-06-29 16:47 . 2012-06-29 16:47 -------- d-----w- C:\VundoFix Backups
2012-06-29 16:47 . 2012-06-29 16:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Grisoft
2012-06-29 12:37 . 2012-06-29 12:37 -------- d-----w- c:\documents and settings\Sourav kg\Application Data\SUPERAntiSpyware.com
2012-06-29 12:37 . 2012-06-29 12:37 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2012-06-28 22:07 . 2012-06-29 16:46 -------- d-----w- C:\Rustbfix
2012-06-28 20:33 . 2012-06-28 20:33 -------- d-----w- c:\windows\system32\wbem\Repository
2012-06-27 17:03 . 2012-06-29 16:47 -------- d-----w- c:\documents and settings\Sourav kg\Application Data\uTorrent(4)
2012-06-27 10:07 . 2012-06-27 10:07 -------- d-----w- c:\documents and settings\Sourav kg\Local Settings\Application Data\uTorrentControl2
2012-06-27 10:07 . 2012-06-27 10:07 -------- d-----w- c:\program files\uTorrentControl2
2012-06-26 18:58 . 2012-06-27 10:08 -------- d-----w- c:\documents and settings\Sourav kg\Application Data\uTorrent(3)
2012-06-25 21:49 . 2012-06-25 21:49 -------- d-----w- c:\documents and settings\Sourav kg\Application Data\PC Cleaners
2012-06-25 21:49 . 2012-06-27 10:11 -------- d-----w- c:\documents and settings\Sourav kg\Application Data\PCPro
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2011-11-16 03:46 . !HASH: COULD NOT OPEN FILE !!!!! . 215168 . . [------] . . c:\windows\system32\drivers\ndis.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{687578b9-7132-4a7a-80e4-30ee31099e03}"= "c:\program files\uTorrentControl2\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{687578b9-7132-4a7a-80e4-30ee31099e03}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{687578b9-7132-4a7a-80e4-30ee31099e03}]
2011-05-09 08:49 176936 ----a-w- c:\program files\uTorrentControl2\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{687578b9-7132-4a7a-80e4-30ee31099e03}"= "c:\program files\uTorrentControl2\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{687578b9-7132-4a7a-80e4-30ee31099e03}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{687578B9-7132-4A7A-80E4-30EE31099E03}"= "c:\program files\uTorrentControl2\prxtbuTor.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{687578b9-7132-4a7a-80e4-30ee31099e03}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ILO_Office_Manager"="IntEdReg.exe" [2002-10-14 53760]
"SpybotSD TeaTimer"="d:\firewall\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2007-08-31 22879528]
"SUPERAntiSpyware"="d:\progrms\SUPERAntiSpyware.exe" [2012-06-29 3905408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-11 16132608]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-11 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-11 155648]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-11 131072]
"Intense Registry Service"="IntEdReg.exe" [2002-10-14 53760]
"RemoteControl"="d:\programe files\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="d:\programe files\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"AVG8_TRAY"="d:\progra~1\AVG\avgtray.exe" [2011-12-26 2042208]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Privatefirewall"="f:\firewall\PFGUI.exe" [2012-05-31 3006840]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\progrms\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- d:\progrms\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2011-12-26 10:08 11952 ----a-w- c:\windows\system32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C:\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"cmdAgent"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Documents and Settings\\Sourav kg\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"d:\\Programe Files\\AVG\\avgam.exe"=
"d:\\Programe Files\\AVG\\avgemc.exe"=
"d:\\Programe Files\\AVG\\avgupd.exe"=
"d:\\Programe Files\\AVG\\avgnsx.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4937:TCP"= 4937:TCP:focsjdhe
"135:TCP"= 135:TCP:DCOM(135)
.
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [26/12/2011 14:13 12552]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [01/01/2012 02:10 14776]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [23/12/2010 21:39 685816]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [26/12/2011 14:13 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [26/12/2011 14:13 108552]
R1 SASDIFSV;SASDIFSV;d:\progrms\sasdifsv.sys [22/07/2011 21:57 12880]
R1 SASKUTIL;SASKUTIL;d:\progrms\SASKUTIL.SYS [13/07/2011 03:25 67664]
R2 !SASCORE;SAS Core Service;d:\progrms\SASCore.exe [12/08/2011 05:08 116608]
R2 avg8emc;AVG8 E-mail Scanner;d:\progra~1\AVG\avgemc.exe [26/12/2011 15:38 908056]
R2 avg8wd;AVG8 WatchDog;d:\progra~1\AVG\avgwdsvc.exe [26/12/2011 15:38 297752]
R2 PFNet;Privacyware network service;f:\firewall\pfsvc.exe [31/05/2012 17:26 374160]
R3 pwipf6;Privacyware Filter Driver;c:\windows\system32\drivers\pwipf6.sys [30/06/2012 11:49 135272]
S0 xzcr;xzcr; [x]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\SOURAV~1\LOCALS~1\Temp\ALSysIO.sys --> c:\docume~1\SOURAV~1\LOCALS~1\Temp\ALSysIO.sys [?]
S3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys --> c:\windows\system32\drivers\mbam.sys [?]
S3 PID_0920;Labtec WebCam(PID_0920);c:\windows\system32\drivers\LV532AV.SYS [22/12/2009 04:01 163328]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
upyisue
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = hxxp://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: Interfaces\{35D318C3-8108-42AE-8D5F-D4E43F86B611}: NameServer = 218.248.240.179,218.248.240.79
FF - ProfilePath - c:\documents and settings\Sourav kg\Application Data\Mozilla\Firefox\Profiles\t50rn8hr.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3072253&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?ref=hp
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3072253&SearchSource=2&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - g:\programs\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: TVU Web Player: firefox@tvunetworks.com - %profile%\extensions\firefox@tvunetworks.com
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - d:\programe files\AVG\Firefox
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
SafeBoot-klmdb.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-06-30 14:54
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1104)
d:\progrms\SASWINLO.DLL
.
- - - - - - - > 'explorer.exe'(2544)
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
d:\programe files\Nero 7\InCD\InCDsrv.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\wdfmgr.exe
d:\progra~1\AVG\avgam.exe
d:\progra~1\AVG\avgrsx.exe
d:\progra~1\AVG\avgnsx.exe
d:\programe files\AVG\avgcsrvx.exe
d:\programe files\AVG\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
d:\intense language office\COMMON\Offman.exe
.
**************************************************************************
.
Completion time: 2012-06-30 14:58:03 - machine was rebooted
ComboFix-quarantined-files.txt 2012-06-30 09:28
ComboFix2.txt 2009-05-04 20:13
.
Pre-Run: 9,258,459,136 bytes free
Post-Run: 9,393,168,384 bytes free
.
- - End Of File - - B5BCA1F08BCF2EFC367B4138D36F5D12

BC AdBot (Login to Remove)

 


#2 aris123

aris123
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:10:20 AM

Posted 01 July 2012 - 01:58 AM

Hello, just to add, I did a search and this is the exact problem I am having in this link:

http://forums.majorgeeks.com/showthread.php?t=260857

#3 nasdaq

nasdaq

  • Malware Response Team
  • 40,236 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:20 AM

Posted 04 July 2012 - 01:27 PM

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2


If your operating system is 64 bit download this tool:
SystemLook_x64.exe
  • Double-click SystemLook.exe to run it.
  • Copy and paste the content of the following bold text into the main textfield:


    :filefind
    ndis.sys

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please post the logs and let me know if you have the XP installation disk or access to an other XP machine.

Let me know also the problem with this computer.

#4 nasdaq

nasdaq

  • Malware Response Team
  • 40,236 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:20 AM

Posted 10 July 2012 - 09:19 AM

Are you still with me?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users