1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Blue screen STOP: c000021a {Fatal System Error}

Discussion in 'Malware and Virus Removal Archive' started by spoonmanx, 2015/05/15.

Thread Status:
Not open for further replies.
  1. 2015/05/15
    spoonmanx

    spoonmanx Inactive Thread Starter

    Joined:
    2015/05/14
    Messages:
    4
    Likes Received:
    0
    [Inactive] Blue screen STOP: c000021a {Fatal System Error}

    I'm doing this again because i don't see my previous post anywhere, I hope I don't double post

    My laptop failed to startup. I got a blue screen with this text

    STOP: c000021a {Fatal System Error}
    The initial session process or system process terminated unexpectedly with a status of 0x00000000 (0xc0000001 0x000106c8)
    The system has been shut down.

    I've tried
    -startup repair -> Startup Repair cannot repair this computer automatically
    -System Restore -> the next button is gray (You must enable System Protection on this drive.)
    -Windows Memory Diagnostic -> no problems were found.
    -VAIO Hard Disk diagnostic -> no problems were found.
    -Last good start configuration -> Same blue screen
    -sfc /scannow -> There is a system repair pending which requires reboot to complete. Restart Windows and run sfc again.

    So I searched with google for my error and found this page http://www.windowsbbs.com/malware-virus-removal/108848-solved-

    error-during-startup-stop-c000021a-fatal-system-error.html

    In this post broni advices to use the Farbar Recovery Scan Tool and post it here so here is it, I hope u an help me thank

    you:

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-05-2015 02
    Ran by SYSTEM on MININT-GDILDUT on 15-05-2015 11:01:54
    Running from G:\
    Platform: WIN_7 (X64) OS Language: Español (España, internacional)
    Boot Mode: Recovery

    The current controlset is ControlSet001
    ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-

    recovery-scan-tool/

    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be

    moved.)

    HKLM\...\Winlogon: [Userinit]
    HKLM-x32\...\Winlogon: [Userinit] [X]
    HKLM\...\Winlogon: [Shell] [0 ] () <=== ATTENTION
    HKLM-x32\...\Winlogon: [Shell] [0 ] () <=== ATTENTION
    HKLM\...\InprocServer32: [Default-wbemess] ATTENTION! ====> ZeroAccess?
    HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] ATTENTION! ====> ZeroAccess?
    HKLM\...26dfa299cadb\InprocServer32: [Authentication UI Logon UI] <==== ATTENTION!
    HKU\Cerdeira\...\Run: [AdobeBridge] => [X]
    HKU\Cerdeira\...\Run: [Spotify Web Helper] => C:\Users\Cerdeira\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920 2015-04-25] (Spotify Ltd)
    HKU\Cerdeira\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-11-21] (Apple Inc.)
    Startup: C:\Users\Cerdeira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-04-25]
    ShortcutTarget: Dropbox.lnk -> (No File)

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless

    listed separately.)

    S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
    S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
    S2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-02-24] (Atheros)
    S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2013-12-20] (BlueStack Systems, Inc.)
    S2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2013-12-20] (BlueStack Systems, Inc.)
    S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [104096 2011-07-19] (Atheros Communication Inc.)
    S2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe [377768 2013-11-01] (Intel Corporation)
    S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
    S2 nvservice; C:\Windows\system32\nvservice.exe [192800 2013-02-04] (NVIDIA Corporation)
    S2 Oasis2Service; C:\Program Files (x86)\DDNi\Oasis2Service 1.0\Oasis2Service.exe [46080 2010-03-25] ()
    S2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [258048 2013-03-04] (Sony Corporation)
    S2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.)
    S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe [377768 2013-11-01] (Intel Corporation)
    S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [887000 2011-01-20] (Sony Corporation)
    S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
    S2 Update Greener Web; "C:\Program Files (x86)\Greener Web\updateGreenerWeb.exe" [X]

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    S3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
    S2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [114448 2013-12-20] (BlueStack Systems)
    S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
    S3 semav6thermal64ro; C:\Windows\system32\drivers\semav6thermal64ro.sys [13792 2015-01-24] ()

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-05-15 11:01 - 2015-05-15 11:01 - 00000000 ____D () C:\FRST
    2015-05-04 21:54 - 2015-05-04 21:55 - 00880208 _____ (Google Inc.) C:\Users\Cerdeira\Downloads\ChromeSetup (1).exe
    2015-05-01 12:15 - 2015-05-01 12:15 - 00290848 _____ () C:\Windows\Minidump\050115-22744-01.dmp
    2015-04-30 16:29 - 2015-04-30 16:30 - 00880208 _____ (Google Inc.) C:\Users\Cerdeira\Downloads\ChromeSetup.exe
    2015-04-28 19:34 - 2015-04-28 19:34 - 00829173 _____ () C:\Users\Cerdeira\Downloads\Unidad I Sangre-1.pptx
    2015-04-28 06:49 - 2015-04-28 06:49 - 00861696 _____ () C:\Users\Cerdeira\Downloads\ESQUIZOFRENIA 2.ppt
    2015-04-28 06:49 - 2015-04-28 06:49 - 00247808 _____ () C:\Users\Cerdeira\Downloads\TRAST. SOMATOMORFOS (1).ppt
    2015-04-28 06:49 - 2015-04-28 06:49 - 00207872 _____ () C:\Users\Cerdeira\Downloads\ESQIZOFRENIA Y PSICOTICOS (1).ppt
    2015-04-28 06:49 - 2015-04-28 06:49 - 00164352 _____ () C:\Users\Cerdeira\Downloads\TRAST. DISOCIATIVOS.ppt
    2015-04-28 06:48 - 2015-04-28 06:49 - 00984576 _____ () C:\Users\Cerdeira\Downloads\ESQIZOFRENIA Y PSICOTICOS.ppt
    2015-04-26 11:10 - 2015-04-26 11:10 - 00028626 _____ () C:\Users\Cerdeira\Downloads\CA_izWsVIAIKfDp.jpg-large
    2015-04-24 20:45 - 2015-04-24 20:45 - 00003288 ____N () C:\bootsqm.dat
    2015-04-21 18:17 - 2015-04-21 18:17 - 00289511 _____ () C:\Users\Cerdeira\Downloads\apendice (1).pptx
    2015-04-21 18:14 - 2015-04-21 18:14 - 00289511 _____ () C:\Users\Cerdeira\Downloads\apendice.pptx
    2015-04-21 16:43 - 2015-04-21 16:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
    2015-04-18 20:31 - 2015-04-18 20:31 - 00011970 _____ () C:\Users\Cerdeira\Downloads\Perdoname Gerardo Ortiz.htm
    2015-04-18 20:18 - 2015-04-18 20:18 - 00250368 _____ () C:\Users\Cerdeira\Downloads\TRAST. SOMATOMORFOS.ppt
    2015-04-16 05:38 - 2015-04-16 05:39 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
    2015-04-16 05:17 - 2015-04-16 05:22 - 152362800 _____ (Apple Inc.) C:\Users\Cerdeira\Downloads\iTunes6464Setup (2).exe

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-05-07 06:22 - 2014-06-10 22:41 - 00000000 ____D () C:\Users\Cerdeira\AppData\Local\Spotify
    2015-05-07 06:22 - 2014-06-10 22:40 - 00000000 ____D () C:\Users\Cerdeira\AppData\Roaming\Spotify
    2015-05-07 06:21 - 2014-07-18 16:00 - 00000000 ___RD () C:\Users\Cerdeira\Dropbox
    2015-05-07 06:20 - 2014-07-18 15:58 - 00000000 ____D () C:\Users\Cerdeira\AppData\Roaming\Dropbox
    2015-05-07 06:19 - 2014-06-04 19:08 - 00000000 ____D () C:\users\Cerdeira
    2015-05-07 06:19 - 2014-06-04 17:51 - 00000000 ____D () C:\ProgramData\NVIDIA
    2015-05-07 06:19 - 2009-07-13 22:51 - 00105511 _____ () C:\Windows\setupact.log
    2015-05-06 23:21 - 2014-06-04 17:38 - 01895073 _____ () C:\Windows\WindowsUpdate.log
    2015-05-06 15:43 - 2009-07-13 22:45 - 00029168 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-05-06 15:43 - 2009-07-13 22:45 - 00029168 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-05-05 14:38 - 2014-07-18 16:00 - 00001031 _____ () C:\Users\Cerdeira\Desktop\Dropbox.lnk
    2015-05-05 11:11 - 2014-07-23 01:29 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2015-05-05 11:11 - 2014-07-23 01:29 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2015-05-05 11:11 - 2014-07-23 01:29 - 00000838 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
    2015-05-01 12:15 - 2014-06-11 22:40 - 00000000 ____D () C:\Windows\Minidump
    2015-05-01 12:15 - 2014-06-11 22:39 - 353360222 _____ () C:\Windows\MEMORY.DMP
    2015-04-28 21:39 - 2014-06-04 18:28 - 00747970 _____ () C:\Windows\System32\perfh00A.dat
    2015-04-28 21:39 - 2014-06-04 18:28 - 00159410 _____ () C:\Windows\System32\perfc00A.dat
    2015-04-28 21:39 - 2009-07-13 23:13 - 01678218 _____ () C:\Windows\System32\PerfStringBackup.INI
    2015-04-28 18:33 - 2015-03-02 16:27 - 00000000 ____D () C:\Users\Cerdeira\Documents\My Cmaps
    2015-04-28 18:12 - 2015-03-02 16:25 - 00002233 _____ () C:\Users\Cerdeira\.powerupdate.user.properties
    2015-04-28 12:50 - 2014-06-06 16:39 - 00000000 ____D () C:\Users\Cerdeira\AppData\Local\Microsoft Help
    2015-04-27 15:10 - 2014-06-04 19:10 - 00000000 ____D () C:\Users\Cerdeira\Documents\Bluetooth Folder
    2015-04-27 06:06 - 2015-04-12 15:42 - 00000000 ____D () C:\ProgramData\Avira
    2015-04-27 06:06 - 2010-11-20 21:47 - 00952682 _____ () C:\Windows\PFRO.log
    2015-04-27 03:19 - 2015-04-12 15:42 - 00000000 ____D () C:\Program Files (x86)\Avira
    2015-04-22 08:07 - 2014-06-10 10:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
    2015-04-16 05:54 - 2015-04-12 15:44 - 00000000 ____D () C:\Users\Cerdeira\AppData\Roaming\Avira
    2015-04-16 05:39 - 2015-02-07 14:05 - 00001713 _____ () C:\Users\Public\Desktop\iTunes.lnk
    2015-04-16 05:39 - 2015-02-07 14:04 - 00000000 ____D () C:\Program Files\iTunes
    2015-04-16 05:38 - 2014-06-10 22:34 - 00000000 ____D () C:\Program Files\Common Files\Apple

    Some content of TEMP:
    ====================
    C:\Users\Cerdeira\AppData\Local\Temp\avgnt.exe
    C:\Users\Cerdeira\AppData\Local\Temp\BackupSetup.exe
    C:\Users\Cerdeira\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpbpum9z.dll
    C:\Users\Cerdeira\AppData\Local\Temp\GLF1684.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF1B54.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF2054.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF626F.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF65AB.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF71AD.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF772A.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF82BE.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF8992.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFA2D3.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFA969.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFAF76.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFB33E.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFB7B.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFD54D.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFD879.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFDFD3.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFE18E.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFE1B7.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFEB2F.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFFAB8.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFFEDE.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\install_flashplayer17x32au_ltr5x64d_awc_aih.exe
    C:\Users\Cerdeira\AppData\Local\Temp\instloffer.exe
    C:\Users\Cerdeira\AppData\Local\Temp\LiveSupport_setup.exe
    C:\Users\Cerdeira\AppData\Local\Temp\Quarantine.exe
    C:\Users\Cerdeira\AppData\Local\Temp\sqlite3.dll
    C:\Users\Cerdeira\AppData\Local\Temp\VCPerfService32.exe
    C:\Users\Cerdeira\AppData\Local\Temp\vcredist_x64.exe


    ==================== Known DLLs (Whitelisted) ================


    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== Restore Points =========================

    Restore point made on: 2015-04-12 15:13:19
    Restore point made on: 2015-04-12 15:38:43
    Restore point made on: 2015-04-12 15:47:33
    Restore point made on: 2015-04-12 17:19:51
    Restore point made on: 2015-04-16 05:35:47

    ==================== Memory info ===========================

    Percentage of memory in use: 15%
    Total physical RAM: 4077.86 MB
    Available physical RAM: 3432.5 MB
    Total Pagefile: 4076.01 MB
    Available Pagefile: 3427.68 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.89 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:582.74 GB) (Free:468.86 GB) NTFS
    Drive e: (Recovery) (Fixed) (Total:13.33 GB) (Free:4.02 GB) NTFS ==>[System with boot components (obtained from reading

    drive)]
    Drive g: (MULTIBOOT) (Removable) (Total:14.43 GB) (Free:12.92 GB) FAT32
    Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading

    drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: 261A708D)
    Partition 1: (Not Active) - (Size=13.3 GB) - (Type=27)
    Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=582.7 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (Size: 14.4 GB) (Disk ID: 00000000)

    Partition: GPT Partition Type.


    LastRegBack: 2015-03-23 07:44

    ==================== End Of Log ============================
     
    Last edited by a moderator: 2015/05/15
  2. 2015/05/15
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Welcome to WindowsBBS :)

     

  3. to hide this advert.

  4. 2015/05/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ============================

    [​IMG] Please disable "word wrap" in Notepad because your log was harder to read.

    [​IMG] Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7/8: Now please enter System Recovery Options.
    On Windows XP: Now please boot into the OTLPE CD.
    Run [color= "#0000FF"]FRST(FRST64)[/color] and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

    See if you can start normally.
     

    Attached Files:

  5. 2015/05/15
    spoonmanx

    spoonmanx Inactive Thread Starter

    Joined:
    2015/05/14
    Messages:
    4
    Likes Received:
    0
    I applied the fix but I still got the same blue screen

    Here is the fixlog:

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 14-05-2015 02
    Ran by SYSTEM at 2015-05-15 18:00:40 Run:1
    Running from G:\
    Boot Mode: Recovery
    ==============================================

    Content of fixlist:
    *****************
    HKLM-x32\...\Winlogon: [Userinit] [X]
    HKLM\...\Winlogon: [Shell] [0 ] () <=== ATTENTION
    HKLM-x32\...\Winlogon: [Shell] [0 ] () <=== ATTENTION
    HKLM\...\InprocServer32: [Default-wbemess] ATTENTION! ====> ZeroAccess?
    HKLM\...D6A79037F57F\InprocServer32: [Default-fastprox] ATTENTION! ====> ZeroAccess?
    HKLM\...26dfa299cadb\InprocServer32: [Authentication UI Logon UI] <==== ATTENTION!
    HKU\Cerdeira\...\Run: [AdobeBridge] => [X]
    ShortcutTarget: Dropbox.lnk -> (No File)
    S2 Update Greener Web; "C:\Program Files (x86)\Greener Web\updateGreenerWeb.exe" [X]
    C:\Users\Cerdeira\AppData\Local\Temp\avgnt.exe
    C:\Users\Cerdeira\AppData\Local\Temp\BackupSetup.exe
    C:\Users\Cerdeira\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpbpum9z.dll
    C:\Users\Cerdeira\AppData\Local\Temp\GLF1684.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF1B54.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF2054.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF626F.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF65AB.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF71AD.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF772A.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF82BE.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLF8992.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFA2D3.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFA969.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFAF76.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFB33E.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFB7B.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFD54D.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFD879.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFDFD3.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFE18E.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFE1B7.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFEB2F.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFFAB8.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\GLFFEDE.EXE
    C:\Users\Cerdeira\AppData\Local\Temp\install_flashplayer17x32au_ltr5x64d_aw c_aih.exe
    C:\Users\Cerdeira\AppData\Local\Temp\instloffer.exe
    C:\Users\Cerdeira\AppData\Local\Temp\LiveSupport_setup.exe
    C:\Users\Cerdeira\AppData\Local\Temp\Quarantine.exe
    C:\Users\Cerdeira\AppData\Local\Temp\sqlite3.dll
    C:\Users\Cerdeira\AppData\Local\Temp\VCPerfService32.exe
    C:\Users\Cerdeira\AppData\Local\Temp\vcredist_x64.exe

    *****************

    HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\\Userinit => Value was restored successfully.
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value was restored successfully.
    HKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value was restored successfully.
    HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32\\Default => Value was restored successfully.
    HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\\Default => Value was restored successfully.
    HKLM\Software\Classes\CLSID\{7986d495-ce42-4926-8afc-26dfa299cadb}\InprocServer32\\Default => Value was restored successfully.
    HKU\Cerdeira\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value deleted successfully.
    ShortcutTarget: Dropbox.lnk -> (No File) not found.
    Update Greener Web => Service deleted successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\avgnt.exe => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\BackupSetup.exe => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpbpum9z.dll => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLF1684.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLF1B54.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLF2054.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLF626F.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLF65AB.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLF71AD.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLF772A.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLF82BE.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLF8992.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLFA2D3.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLFA969.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLFAF76.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLFB33E.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLFB7B.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLFD54D.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLFD879.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLFDFD3.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLFE18E.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLFE1B7.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLFEB2F.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLFFAB8.EXE => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\GLFFEDE.EXE => Moved successfully.
    "C:\Users\Cerdeira\AppData\Local\Temp\install_flashplayer17x32au_ltr5x64d_aw c_aih.exe" => File/Directory not found.
    C:\Users\Cerdeira\AppData\Local\Temp\instloffer.exe => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\LiveSupport_setup.exe => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\Quarantine.exe => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\sqlite3.dll => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\VCPerfService32.exe => Moved successfully.
    C:\Users\Cerdeira\AppData\Local\Temp\vcredist_x64.exe => Moved successfully.

    ==== End of Fixlog 18:00:42 ====
     
  6. 2015/05/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Give me fresh FRST log.
     
  7. 2015/05/15
    spoonmanx

    spoonmanx Inactive Thread Starter

    Joined:
    2015/05/14
    Messages:
    4
    Likes Received:
    0
    Here it is, oh and thank you for your help I really appreciate it

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-05-2015 02
    Ran by SYSTEM on MININT-MNJQOI7 on 15-05-2015 19:31:27
    Running from G:\
    Platform: WIN_7 (X64) OS Language: Español (España, internacional)
    Boot Mode: Recovery

    The current controlset is ControlSet001
    ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Registry (Whitelisted) ==================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Winlogon: [Userinit]
    HKU\Cerdeira\...\Run: [Spotify Web Helper] => C:\Users\Cerdeira\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920 2015-04-25] (Spotify Ltd)
    HKU\Cerdeira\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-11-21] (Apple Inc.)
    Startup: C:\Users\Cerdeira\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-04-25]
    ShortcutTarget: Dropbox.lnk -> (No File)

    ==================== Services (Whitelisted) =================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
    S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
    S2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-02-24] (Atheros)
    S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2013-12-20] (BlueStack Systems, Inc.)
    S2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2013-12-20] (BlueStack Systems, Inc.)
    S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [104096 2011-07-19] (Atheros Communication Inc.)
    S2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe [377768 2013-11-01] (Intel Corporation)
    S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
    S2 nvservice; C:\Windows\system32\nvservice.exe [192800 2013-02-04] (NVIDIA Corporation)
    S2 Oasis2Service; C:\Program Files (x86)\DDNi\Oasis2Service 1.0\Oasis2Service.exe [46080 2010-03-25] ()
    S2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [258048 2013-03-04] (Sony Corporation)
    S2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.)
    S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\esrv\esrv_svc.exe [377768 2013-11-01] (Intel Corporation)
    S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [887000 2011-01-20] (Sony Corporation)
    S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)

    ==================== Drivers (Whitelisted) ====================

    (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

    S3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
    S2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [114448 2013-12-20] (BlueStack Systems)
    S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited)
    S3 semav6thermal64ro; C:\Windows\system32\drivers\semav6thermal64ro.sys [13792 2015-01-24] ()

    ==================== NetSvcs (Whitelisted) ===================

    (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


    ==================== One Month Created Files and Folders ========

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-05-15 11:01 - 2015-05-15 19:31 - 00000000 ____D () C:\FRST
    2015-05-04 21:54 - 2015-05-04 21:55 - 00880208 _____ (Google Inc.) C:\Users\Cerdeira\Downloads\ChromeSetup (1).exe
    2015-05-01 12:15 - 2015-05-01 12:15 - 00290848 _____ () C:\Windows\Minidump\050115-22744-01.dmp
    2015-04-30 16:29 - 2015-04-30 16:30 - 00880208 _____ (Google Inc.) C:\Users\Cerdeira\Downloads\ChromeSetup.exe
    2015-04-28 19:34 - 2015-04-28 19:34 - 00829173 _____ () C:\Users\Cerdeira\Downloads\Unidad I Sangre-1.pptx
    2015-04-28 06:49 - 2015-04-28 06:49 - 00861696 _____ () C:\Users\Cerdeira\Downloads\ESQUIZOFRENIA 2.ppt
    2015-04-28 06:49 - 2015-04-28 06:49 - 00247808 _____ () C:\Users\Cerdeira\Downloads\TRAST. SOMATOMORFOS (1).ppt
    2015-04-28 06:49 - 2015-04-28 06:49 - 00207872 _____ () C:\Users\Cerdeira\Downloads\ESQIZOFRENIA Y PSICOTICOS (1).ppt
    2015-04-28 06:49 - 2015-04-28 06:49 - 00164352 _____ () C:\Users\Cerdeira\Downloads\TRAST. DISOCIATIVOS.ppt
    2015-04-28 06:48 - 2015-04-28 06:49 - 00984576 _____ () C:\Users\Cerdeira\Downloads\ESQIZOFRENIA Y PSICOTICOS.ppt
    2015-04-26 11:10 - 2015-04-26 11:10 - 00028626 _____ () C:\Users\Cerdeira\Downloads\CA_izWsVIAIKfDp.jpg-large
    2015-04-24 20:45 - 2015-04-24 20:45 - 00003288 ____N () C:\bootsqm.dat
    2015-04-21 18:17 - 2015-04-21 18:17 - 00289511 _____ () C:\Users\Cerdeira\Downloads\apendice (1).pptx
    2015-04-21 18:14 - 2015-04-21 18:14 - 00289511 _____ () C:\Users\Cerdeira\Downloads\apendice.pptx
    2015-04-21 16:43 - 2015-04-21 16:43 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
    2015-04-18 20:31 - 2015-04-18 20:31 - 00011970 _____ () C:\Users\Cerdeira\Downloads\Perdoname Gerardo Ortiz.htm
    2015-04-18 20:18 - 2015-04-18 20:18 - 00250368 _____ () C:\Users\Cerdeira\Downloads\TRAST. SOMATOMORFOS.ppt
    2015-04-16 05:38 - 2015-04-16 05:39 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
    2015-04-16 05:17 - 2015-04-16 05:22 - 152362800 _____ (Apple Inc.) C:\Users\Cerdeira\Downloads\iTunes6464Setup (2).exe

    ==================== One Month Modified Files and Folders =======

    (If an entry is included in the fixlist, the file\folder will be moved.)

    2015-05-07 06:22 - 2014-06-10 22:41 - 00000000 ____D () C:\Users\Cerdeira\AppData\Local\Spotify
    2015-05-07 06:22 - 2014-06-10 22:40 - 00000000 ____D () C:\Users\Cerdeira\AppData\Roaming\Spotify
    2015-05-07 06:21 - 2014-07-18 16:00 - 00000000 ___RD () C:\Users\Cerdeira\Dropbox
    2015-05-07 06:20 - 2014-07-18 15:58 - 00000000 ____D () C:\Users\Cerdeira\AppData\Roaming\Dropbox
    2015-05-07 06:19 - 2014-06-04 19:08 - 00000000 ____D () C:\users\Cerdeira
    2015-05-07 06:19 - 2014-06-04 17:51 - 00000000 ____D () C:\ProgramData\NVIDIA
    2015-05-07 06:19 - 2009-07-13 22:51 - 00105511 _____ () C:\Windows\setupact.log
    2015-05-06 23:21 - 2014-06-04 17:38 - 01895073 _____ () C:\Windows\WindowsUpdate.log
    2015-05-06 15:43 - 2009-07-13 22:45 - 00029168 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2015-05-06 15:43 - 2009-07-13 22:45 - 00029168 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2015-05-05 14:38 - 2014-07-18 16:00 - 00001031 _____ () C:\Users\Cerdeira\Desktop\Dropbox.lnk
    2015-05-05 11:11 - 2014-07-23 01:29 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2015-05-05 11:11 - 2014-07-23 01:29 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2015-05-05 11:11 - 2014-07-23 01:29 - 00000838 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
    2015-05-01 12:15 - 2014-06-11 22:40 - 00000000 ____D () C:\Windows\Minidump
    2015-05-01 12:15 - 2014-06-11 22:39 - 353360222 _____ () C:\Windows\MEMORY.DMP
    2015-04-28 21:39 - 2014-06-04 18:28 - 00747970 _____ () C:\Windows\System32\perfh00A.dat
    2015-04-28 21:39 - 2014-06-04 18:28 - 00159410 _____ () C:\Windows\System32\perfc00A.dat
    2015-04-28 21:39 - 2009-07-13 23:13 - 01678218 _____ () C:\Windows\System32\PerfStringBackup.INI
    2015-04-28 18:33 - 2015-03-02 16:27 - 00000000 ____D () C:\Users\Cerdeira\Documents\My Cmaps
    2015-04-28 18:12 - 2015-03-02 16:25 - 00002233 _____ () C:\Users\Cerdeira\.powerupdate.user.properties
    2015-04-28 12:50 - 2014-06-06 16:39 - 00000000 ____D () C:\Users\Cerdeira\AppData\Local\Microsoft Help
    2015-04-27 15:10 - 2014-06-04 19:10 - 00000000 ____D () C:\Users\Cerdeira\Documents\Bluetooth Folder
    2015-04-27 06:06 - 2015-04-12 15:42 - 00000000 ____D () C:\ProgramData\Avira
    2015-04-27 06:06 - 2015-04-12 15:42 - 00000000 ____D () C:\Program Files (x86)\Avira
    2015-04-27 06:06 - 2010-11-20 21:47 - 00952682 _____ () C:\Windows\PFRO.log
    2015-04-22 08:07 - 2014-06-10 10:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
    2015-04-16 05:54 - 2015-04-12 15:44 - 00000000 ____D () C:\Users\Cerdeira\AppData\Roaming\Avira
    2015-04-16 05:39 - 2015-02-07 14:05 - 00001713 _____ () C:\Users\Public\Desktop\iTunes.lnk
    2015-04-16 05:39 - 2015-02-07 14:04 - 00000000 ____D () C:\Program Files\iTunes
    2015-04-16 05:38 - 2014-06-10 22:34 - 00000000 ____D () C:\Program Files\Common Files\Apple

    Some content of TEMP:
    ====================
    C:\Users\Cerdeira\AppData\Local\Temp\install_flashplayer17x32au_ltr5x64d_awc_aih.exe


    ==================== Known DLLs (Whitelisted) ================


    ==================== Bamital & volsnap Check =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe => MD5 is legit
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

    ==================== Restore Points =========================

    Restore point made on: 2015-04-12 15:13:19
    Restore point made on: 2015-04-12 15:38:43
    Restore point made on: 2015-04-12 15:47:33
    Restore point made on: 2015-04-12 17:19:51
    Restore point made on: 2015-04-16 05:35:47

    ==================== Memory info ===========================

    Percentage of memory in use: 16%
    Total physical RAM: 4077.86 MB
    Available physical RAM: 3423.88 MB
    Total Pagefile: 4076.01 MB
    Available Pagefile: 3419.12 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.89 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:582.74 GB) (Free:468.86 GB) NTFS
    Drive e: (Recovery) (Fixed) (Total:13.33 GB) (Free:4.02 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    Drive g: (MULTIBOOT) (Removable) (Total:14.43 GB) (Free:12.92 GB) FAT32
    Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    Drive y: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: 261A708D)
    Partition 1: (Not Active) - (Size=13.3 GB) - (Type=27)
    Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=582.7 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 1 (Size: 14.4 GB) (Disk ID: 00000000)

    Partition: GPT Partition Type.


    LastRegBack: 2015-03-23 07:44

    ==================== End Of Log ============================
     
  8. 2015/05/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    We don't have anything malicious there anymore so let's see if we can restore your computer to a date when it booted successfully for the last time.

    Download attached fixlist.txt file and save it to the very same USB flash drive you've been using. Plug the drive back in.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    On Vista or Windows 7/8: Now please enter System Recovery Options.
    On Windows XP: Now please boot into the OTLPE CD.
    Run [color= "#0000FF"]FRST(FRST64)[/color] and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

    See if you can boot now.
     

    Attached Files:

  9. 2015/05/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Still with me?
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.