Jump to content

Windows XP home edition, freezing with continuous beeping


Recommended Posts

Hi

I have a laptop running Windows XP home edition. Since yesterday it has developed some problem. It boots OK but after few minutes it freezes completely giving continuous annoying beep. Only way to recover is to power off and on. So far I have ran MBAM,Spy-bot and McAfee in safe mode and it was clean. HW diagnostics was clean so no memory issues. I would really appreciate if someone can help me here

cheers

cucm

Link to post
Share on other sites

A beep code like that denotes a hardware problem. The beep codes are supposed to mean something, but I've found bad memory trigger pretty much every type of beep code a PC will throw out.

If you have run Memtest86+ through at least 5 passes, then your memory is most likely OK. If you have not done so, then I would hesitate to declare the memory OK, as most hardware diagnostics are pitiful at best.

Other possibilities include the power supply, the video card, and the CPU. If the memory is truly OK, then take a look at the capacitors around the CPU socket (make sure to unplug the computer first). They will be the taller cylindrical things (of various sizes) standing strait up, usually with metal tops. The tops on all of them should be either flat, or bowed inward just slightly. If any of the tops are domed upward, or have stuff leaking out of them, then a power surge (quite possibly from lightening) has damaged them, and the motherboard needs replaced.

Here is a picture of a good capacitor:

PW%20SERIES%2020.0%208D,10D%20996-999.jpg

Here are pictures of capacitors that have been damaged by power surges:

question_cap.jpg

Vented%20Motherboard%20Capacitor.jpg

capblown_6.jpg

Link to post
Share on other sites

Thanks. I had a strong feeling that it was a MBR related issue. After ruling out HW and doing some research I ran the program RootRepeal which found the rootkit and removed it. After this I had missing ntldr message which was resolved after running xp recovery mode. Original problem was resolved

Today I found that lot of messages were sent from facebook account. I ran MBAM which found switch.dialer and removed it

I am worried and would appreciate some advice by experts

cucm

Link to post
Share on other sites

I am worried and would appreciate some advice by experts

1) Change passwords.

2) If you shopped online during a period of time that the computer may have been infected, then call your credit card company and see if they can send you a new card. Also make sure any online banking accounts, or PayPal accounts, are secure and that the passwords get changed.

3) If you are a member of any online sites other than Facebook, then check your accounts there as well.

4) If you are unsure as to whether or not your computer is still infected, then please contact our technical support by sending an e-mail to support@malwarebytes.org and someone will be able to give you instructions and analyze logs for you. :D

Link to post
Share on other sites

Hi

I have changed passwords etc. No infections reported in MBAM ,MacAfee and Spy-bot. I ran Conbofix yesterday , copying the log here


ComboFix 09-12-19.03 - ati 20/12/2009 21:54:05.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1393 [GMT 0:00]
Running from: c:\documents and settings\ati\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\windows\system32\kWab.dll

.
((((((((((((((((((((((((( Files Created from 2009-11-20 to 2009-12-20 )))))))))))))))))))))))))))))))
.

2009-12-19 11:07 . 2009-12-19 11:07 -------- d-----w- c:\documents and settings\HelpAssistant\WINDOWS
2009-12-19 11:07 . 2009-12-19 11:07 -------- d-----w- c:\documents and settings\HelpAssistant\UserData
2009-12-19 11:07 . 2009-12-19 11:07 -------- d-----w- c:\documents and settings\HelpAssistant\Tracing
2009-12-19 11:07 . 2009-12-19 11:07 -------- d-----w- c:\documents and settings\HelpAssistant\temp
2009-12-19 11:07 . 2009-12-19 11:07 -------- d-----w- c:\documents and settings\HelpAssistant\PrivacIE
2009-12-19 11:07 . 2009-12-19 11:07 -------- d-----w- c:\documents and settings\HelpAssistant\Phone Browser
2009-12-19 11:07 . 2009-12-19 11:07 -------- d-----w- c:\documents and settings\HelpAssistant\outlook express contact
2009-12-18 14:22 . 2009-12-18 14:22 -------- d-----w- c:\documents and settings\HelpAssistant\InstallAnywhere
2009-12-18 14:22 . 2009-12-18 14:22 -------- d-----w- c:\documents and settings\HelpAssistant\IECompatCache
2009-12-18 14:22 . 2009-12-18 14:22 -------- d-----w- c:\documents and settings\HelpAssistant\DoctorWeb
2009-12-18 14:22 . 2009-12-18 14:22 -------- d-----w- c:\documents and settings\HelpAssistant\Contacts
2009-12-18 14:21 . 2009-12-18 14:21 -------- d-----w- c:\documents and settings\HelpAssistant\.jrtmt
2009-12-18 14:21 . 2009-12-18 14:21 -------- d-----w- c:\documents and settings\HelpAssistant\.cisco
2009-12-18 14:21 . 2009-12-18 14:21 -------- d-----w- c:\documents and settings\HelpAssistant\.asdm
2009-12-04 10:03 . 2009-12-04 10:03 251376 ----a-w- c:\documents and settings\ati\Application Data\Mozilla\plugins\npgoogletalk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-20 21:48 . 2007-07-27 09:19 -------- d-----w- c:\documents and settings\All Users\Application Data\VMware
2009-12-20 21:48 . 2007-07-27 09:20 -------- d-----w- c:\documents and settings\LocalService\Application Data\VMware
2009-12-20 13:11 . 2009-01-01 13:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-12-19 12:17 . 2007-05-19 08:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-17 22:18 . 2009-01-01 22:55 -------- d-----w- c:\program files\McAfee
2009-12-17 10:43 . 2007-05-09 21:17 -------- d-----w- c:\program files\Google
2009-12-09 20:23 . 2007-08-08 09:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-05 20:27 . 2007-05-09 21:22 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-04 09:08 . 2008-12-31 12:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-04 09:08 . 2009-01-05 22:53 4844296 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-03 16:14 . 2008-12-31 12:32 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 16:13 . 2008-12-31 12:32 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-26 10:59 . 2007-10-07 08:32 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-26 10:47 . 2007-05-14 11:31 -------- d-----w- c:\documents and settings\ati\Application Data\OpenOffice.org2
2009-11-20 15:52 . 2009-11-20 15:52 67504 ---ha-w- c:\windows\system32\mlfcache.dat
2009-11-17 17:23 . 2007-05-19 08:55 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-02 20:42 . 2009-10-03 07:04 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 07:45 . 2004-08-10 11:51 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-28 09:46 . 2007-07-27 09:31 -------- d-----w- c:\documents and settings\ati\Application Data\VMware
2009-10-22 10:12 . 2009-10-22 10:12 -------- d-----w- c:\program files\IPexpertVoiceQuizzer
2009-10-22 10:11 . 2009-10-22 10:11 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-10-22 10:10 . 2009-10-22 10:12 38208 ----a-w- c:\documents and settings\ati\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-21 05:38 . 2004-08-10 11:51 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 11:51 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2008-05-15 12:51 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-10 11:51 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-10 11:51 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-10 11:51 79872 ----a-w- c:\windows\system32\raschap.dll
2009-06-04 13:38 . 2009-06-04 13:37 2440754 ----a-w- c:\program files\Common Files\UnifiedClientInstall.log
2009-03-24 12:11 . 2009-03-24 12:12 1897 ----a-w- c:\program files\Common Files\pcc.ssl
2009-09-12 21:37 . 2007-05-19 15:00 168 --sh--r- c:\windows\system32\0ABFAD259E.sys
2009-09-12 21:37 . 2007-05-19 15:00 5954 --sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 282624]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-10-31 1392640]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"PD0620 STISvc"="P0620Pin.dll" [2005-05-10 36864]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-04 198160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

c:\documents and settings\ati\Start Menu\Programs\Startup\
lab route.bat [2009-3-15 51]
OneNote Table Of Contents.onetoc2 [2008-7-29 3656]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfetdik]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfetdik.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^ati^Start Menu^Programs^Startup^ERUNT AutoBackup.lnk]
path=c:\documents and settings\ati\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
backup=c:\windows\pss\ERUNT AutoBackup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 04:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DelayShred]
2009-09-25 11:22 113168 ----a-w- c:\progra~1\McAfee\MSHR\ShrCL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-10-03 09:39 133104 ----atw- c:\documents and settings\ati\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 04:42 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
2007-03-23 11:20 227328 -c--a-w- c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2007-04-27 08:41 282624 ----a-w- c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UMonit]
2007-06-18 03:40 200704 ----a-r- c:\windows\system32\UMonit.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2009-05-26 20:06 4351216 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
2009-02-23 13:05 111856 ----a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Belkin\\All-in-One Print Server\\MFPAgent.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Dynamips\\dynamips.exe"=
"c:\\Program Files\\Cisco Systems\\Cisco IP Communicator\\communicatork9.exe"=
"c:\\Program Files\\IP blue\\VTGO\\bin\\VTGOhttpServer.exe"=
"c:\\Documents and Settings\\ati\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\ati\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Documents and Settings\\ati\\temp\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Cisco Systems\\Cisco Unified Personal Communicator\\CUPCK9.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\3Com\\3CDaemon\\3CDaemon.EXE"=
"c:\\Program Files\\Cisco Systems\\Cisco IP Communicator\\AudioTuningWizard.exe"=
"c:\\Program Files\\IP blue\\VTGO\\Media\\BlueMedia.exe"=
"c:\\Program Files\\RealVNC\\VNC4\\vncviewer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"3246:TCP"= 3246:TCP:Services
"2479:TCP"= 2479:TCP:Services

R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [18/08/2009 20:39 58728]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [18/08/2009 20:39 333928]
R2 CdpPacket;Cisco Discovery Protocol Packet Driver;c:\windows\system32\drivers\CdpPacket.sys [24/01/2008 18:47 35692]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [28/10/2008 16:42 156968]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [01/01/2009 22:59 93320]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [18/08/2009 20:39 955624]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
R3 WUSBVBus;MFP Server Detector;c:\windows\system32\drivers\mfpvbus.sys [24/06/2007 11:18 9472]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [13/11/2008 14:13 639224]
S2 ALIWEHCD;Belkin All-In-One Print Server Enhanced Controller;c:\windows\system32\drivers\mfpec.sys [24/06/2007 11:18 53152]
S2 gupdate1c994fa5f5c1598;Google Update Service (gupdate1c994fa5f5c1598);c:\program files\Google\Update\GoogleUpdate.exe [22/02/2009 14:32 133104]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [06/11/2007 20:22 42000]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [01/10/2006 12:37 26624]
S3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\DRIVERS\covpndrv.sys --> c:\windows\system32\DRIVERS\covpndrv.sys [?]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://uk.yahoo.com
uInternet Connection Wizard,ShellNext = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=5070509
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Dial with VT&GO - file:///c:\program files\IP blue\VTGO\Scripts\dialer.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\ati\Application Data\Mozilla\Firefox\Profiles\7fqay5vh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://uk.search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - www.google.co.uk
FF - prefs.js: keyword.URL - hxxp://uk.search.yahoo.com/search?fr=mcafee&p=
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\ati\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\ati\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [url="http://www.gmer.net"]http://www.gmer.net[/url]
Rootkit scan 2009-12-20 21:58
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
Completion time: 2009-12-20 22:01:09
ComboFix-quarantined-files.txt 2009-12-20 22:01

Pre-Run: 48,402,468,864 bytes free
Post-Run: 48,363,266,048 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Home Edition" /Fastdetect

- - End Of File - - B3E8ABEE9643C7A35694EE20FA80E046

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.