Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
kaspersky rescue not finding threats
Message
<blockquote data-quote="clydewine" data-source="post: 147458" data-attributes="member: 15735"><p>The virus will not let me use any of the f8 functions. It will shut windows down and reboot normally. However I did get FRST.txt using reatogo.xp following another thread. Here it is</p><p>Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-12-2013</p><p>Ran by SYSTEM on REATOGO on 10-12-2013 10:11:42</p><p>Running from C:\</p><p>WIN_XP (X86) OS Language: English(US)</p><p>Boot Mode: Recovery</p><p>Attention: Could not load system hive.</p><p>Error: The system was unable to find the specified registry key or value</p><p>Attention: System hive is missing.</p><p>==================== Registry (Whitelisted) ==================</p><p>ATTENTION: Software hive is missing.</p><p>ATTENTION: Software hive is not loaded.</p><p></p><p>========================== Services (Whitelisted) =================</p><p></p><p>==================== Drivers (Whitelisted) ====================</p><p></p><p>==================== NetSvcs (Whitelisted) ===================</p><p></p><p>==================== One Month Created Files and Folders ========</p><p>2013-12-10 10:11 - 2013-12-10 10:11 - 00000000 ____D C:\FRST</p><p>2013-12-10 10:11 - 2013-12-10 10:11 - 00000000 _____ C:\FRST.txt</p><p>2013-12-10 09:25 - 2013-12-10 09:22 - 01060641 _____ (Farbar) C:\FRST.exe</p><p>2013-12-10 09:17 - 2013-12-10 09:17 - 00000000 __SHD C:\FOUND.000</p><p>==================== One Month Modified Files and Folders =======</p><p>2013-12-10 10:11 - 2013-12-10 10:11 - 00000000 ____D C:\FRST</p><p>2013-12-10 10:11 - 2013-12-10 10:11 - 00000000 _____ C:\FRST.txt</p><p>2013-12-10 09:22 - 2013-12-10 09:25 - 01060641 _____ (Farbar) C:\FRST.exe</p><p>2013-12-10 09:17 - 2013-12-10 09:17 - 00000000 __SHD C:\FOUND.000</p><p>==================== Known DLLs (Whitelisted) ============</p><p></p><p>==================== Bamital & volsnap Check =================</p><p>C:\Windows\explorer.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\System32\winlogon.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\System32\svchost.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\System32\services.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\System32\User32.dll IS MISSING <==== ATTENTION!.</p><p>C:\Windows\System32\userinit.exe IS MISSING <==== ATTENTION!.</p><p>C:\Windows\System32\Drivers\volsnap.sys IS MISSING <==== ATTENTION!.</p><p>==================== EXE ASSOCIATION =====================</p><p>HKLM\...\.exe: <===== ATTENTION!</p><p>HKLM\...\exefile\DefaultIcon: <===== ATTENTION!</p><p>HKLM\...\exefile\open\command: <===== ATTENTION!</p><p>==================== Restore Points (XP) =====================</p><p></p><p>==================== Memory info ===========================</p><p>Percentage of memory in use: 7%</p><p>Total physical RAM: 3062.39 MB</p><p>Available physical RAM: 2845.41 MB</p><p>Total Pagefile: 2887.11 MB</p><p>Available Pagefile: 2828.17 MB</p><p>Total Virtual: 2047.88 MB</p><p>Available Virtual: 1994.25 MB</p><p>==================== Drives ================================</p><p>Drive b: (RAMDisk) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS</p><p>Drive c: (HITMANPRO) (Removable) (Total:7.45 GB) (Free:7.44 GB) FAT32</p><p>Drive f: (NIKON D5100) (Removable) (Total:15.02 GB) (Free:6.73 GB) FAT32</p><p>Drive x: (ReatogoPE) (CDROM) (Total:0.43 GB) (Free:0 GB) CDFS</p><p>Drive y: (HITMANPRO) (Removable) (Total:7.45 GB) (Free:7.44 GB) FAT32</p><p>==================== MBR & Partition Table ==================</p><p>========================================================</p><p>Disk: 0 (Size: 7 GB) (Disk ID: 84C3731B)</p><p>Partition 1: (Active) - (Size=7 GB) - (Type=0B)</p><p>========================================================</p><p>Disk: 3 (Size: 15 GB) (Disk ID: 8DC18DC1)</p><p>Partition 1: (Not Active) - (Size=15 GB) - (Type=0C)</p><p>==================== End Of Log ============================</p></blockquote><p></p>
[QUOTE="clydewine, post: 147458, member: 15735"] The virus will not let me use any of the f8 functions. It will shut windows down and reboot normally. However I did get FRST.txt using reatogo.xp following another thread. Here it is Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-12-2013 Ran by SYSTEM on REATOGO on 10-12-2013 10:11:42 Running from C:\ WIN_XP (X86) OS Language: English(US) Boot Mode: Recovery Attention: Could not load system hive. Error: The system was unable to find the specified registry key or value Attention: System hive is missing. ==================== Registry (Whitelisted) ================== ATTENTION: Software hive is missing. ATTENTION: Software hive is not loaded. ========================== Services (Whitelisted) ================= ==================== Drivers (Whitelisted) ==================== ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-10 10:11 - 2013-12-10 10:11 - 00000000 ____D C:\FRST 2013-12-10 10:11 - 2013-12-10 10:11 - 00000000 _____ C:\FRST.txt 2013-12-10 09:25 - 2013-12-10 09:22 - 01060641 _____ (Farbar) C:\FRST.exe 2013-12-10 09:17 - 2013-12-10 09:17 - 00000000 __SHD C:\FOUND.000 ==================== One Month Modified Files and Folders ======= 2013-12-10 10:11 - 2013-12-10 10:11 - 00000000 ____D C:\FRST 2013-12-10 10:11 - 2013-12-10 10:11 - 00000000 _____ C:\FRST.txt 2013-12-10 09:22 - 2013-12-10 09:25 - 01060641 _____ (Farbar) C:\FRST.exe 2013-12-10 09:17 - 2013-12-10 09:17 - 00000000 __SHD C:\FOUND.000 ==================== Known DLLs (Whitelisted) ============ ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe IS MISSING <==== ATTENTION!. C:\Windows\System32\winlogon.exe IS MISSING <==== ATTENTION!. C:\Windows\System32\svchost.exe IS MISSING <==== ATTENTION!. C:\Windows\System32\services.exe IS MISSING <==== ATTENTION!. C:\Windows\System32\User32.dll IS MISSING <==== ATTENTION!. C:\Windows\System32\userinit.exe IS MISSING <==== ATTENTION!. C:\Windows\System32\Drivers\volsnap.sys IS MISSING <==== ATTENTION!. ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: <===== ATTENTION! HKLM\...\exefile\DefaultIcon: <===== ATTENTION! HKLM\...\exefile\open\command: <===== ATTENTION! ==================== Restore Points (XP) ===================== ==================== Memory info =========================== Percentage of memory in use: 7% Total physical RAM: 3062.39 MB Available physical RAM: 2845.41 MB Total Pagefile: 2887.11 MB Available Pagefile: 2828.17 MB Total Virtual: 2047.88 MB Available Virtual: 1994.25 MB ==================== Drives ================================ Drive b: (RAMDisk) (Fixed) (Total:0.06 GB) (Free:0.06 GB) NTFS Drive c: (HITMANPRO) (Removable) (Total:7.45 GB) (Free:7.44 GB) FAT32 Drive f: (NIKON D5100) (Removable) (Total:15.02 GB) (Free:6.73 GB) FAT32 Drive x: (ReatogoPE) (CDROM) (Total:0.43 GB) (Free:0 GB) CDFS Drive y: (HITMANPRO) (Removable) (Total:7.45 GB) (Free:7.44 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 7 GB) (Disk ID: 84C3731B) Partition 1: (Active) - (Size=7 GB) - (Type=0B) ======================================================== Disk: 3 (Size: 15 GB) (Disk ID: 8DC18DC1) Partition 1: (Not Active) - (Size=15 GB) - (Type=0C) ==================== End Of Log ============================ [/QUOTE]
Insert quotes…
Verification
Post reply
Top