I have an xp pc that was running ok despite the fact that i can not acess windows update for years but since i run mbam it works ok, although mbam keeps on blocking out-coming and incoming web access with a defined ip adress.
Ok not ideal but it was working well enough but recently it reach a point where at reboot with no programs running, the cpu goes from 10% to 100% erratically. So I tried go to windows update but IE and firefox can not acess the website (error message) !!
i tried other ways to access no success even with a windows update downloader and panda my antivirus no good neither. So then i decide to REpair XP or reinstall
but when I have to choose which windows installation I need to repair then the pc shuts down completely and i have to switch if off in the back to reboot it again. However going to my existing xp takes time but it works !! so I do not think it can be a hardware problem
maybe the BIOS is affected. I mention also that i run a system files check scannow sucessfully...
I nonetheless manage to run ZHPdiag despite 100% cpu, it took ages but here is the log
the shut down at xp install is worrying me, can i fix it or wait for it to die ?
i already tried TDSSkiller it never found anything and this time also
not result, it also true when i run mbam it does not found anything.
ok i run the zhp fix ok , after reboot it seems a bit faster and cpu stay more still than before when no programs running but it still goes high sometimes. However when i run any programs it goes to 99%
thanks for your help i haven't got a log yet, it takes ages. I 'll put it later.
(click on the download @ bleeping computer button)
2.Close all open Windows including this one.
Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix.
3. Double click on the ComboFix icon.
Windows is issuing this prompt because ComboFix does not have a digital signature. This is perfectly normal and safe and you can click on the Run button to continue.
4. Accept the disclaimer and the recovery
5.You should now press the Yes button to continue. If at any time during the Recovery Console installation you receive a message stating that it failed to install, please allow ComboFix to continue with the scan of your computer.
ComboFix will disconnect your computer from the Internet, so do not be surprised or concerned if you receive any warnings stating that you are no longer on the Internet. When ComboFix has finished it will automatically restore your Internet connection.
While the program is scanning your computer, it will change your clock format, so do not be concerned when you see this happen. When ComboFix is finished it will restore your clock settings to their previous settings.
If you see your Windows desktop disappear, do not worry. This is normal and ComboFix will restore your desktop before it is finished. Eventually you will see a new screen that states the program is almost finished and telling you the programs log file, or report, will be located at C:\ComboFix.txt.
During the process, please do not mouse click nor must you tap on the keyboard. Let the tool run.
je suis de la région auvergne près du puy de dome
ok je continue en anglais donc?
i 've run the gmer soft it found some things rookit
but i don't know if it fixed it, I just say ok
then i disinstall programs you mentioned
here is the log
thanks again but I won't be close to that computer for a few days I will reply
when I can work on it again
I wonder if you have sent me the correct log. If all of the previous ZHP Diag logs have not been completely deleted from the computer and if you attempt another analysis, the logs will not be updated.
The reasons I say this is that the rootkit shows and also the cracked software and key gens. The cracked software and keygen contained the rootkit which were sent to you by UTorrent, Soulseek and Soulseek2.
Have you deleted the cracks and key gen before or after the ZHP Diag analysis ?
Like the following line is definately a rootkit:
O81 - IFC: Internet Feature Controls [HKUS\.DEFAULT] [FEATURE_BROWSER_EMULATION] -- svchost.exe
thanks, this will be also my last mail.
I did all you said, still there was high cpu then i look at process explorer and there was hardware interrupts eating most of the cpu !! looking up
from the net I've check if it had switched to PIO instead of DMA transfer and it was the case for one of my partition !! so it was not a malware problem (even if my pc was full of problem) but a hardware problem. It seem that windows try 8 time to use DMA and if no success it switches to PIO transfer (using all cpu) , the solution uninstall all primary and secondary ati ide in device manager and then reboot !!!!! windows reisntall all/
ok so now everything is even better than before thanks to you and your disponibility, merci