C:\resycled\boot.com – cum scap de el ?

Daca poza de mai jos iti este cunoscuta inseamna ca esti unul dintre norocosii care s-au virusat cu cea mai noua varianta de Win32\Sality.
Eroarea (C:\resycled\boot.com is not a valid Win32 application) apare la incercarea de a accesa o partitie din sistem.

Rezolvarea e relativ simpla: se descarca ComboFix de aici: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Apoi te asiguri ca ai inchis toate programele care ruleaza (yahoo messenger, firefox, etc) si rulezi apoi ComboFix. Te va intreba daca sa inceapa curatirea. Confirma cu Yes de fiecare data. Nu-l opri in timp ce scaneaza si dezinfecteaza sistemul. E posibil ca in timpul rularii lui desktop-ul sa dispara, dar nu te ingrijora.
La sfarsit va afisa rezultatele scanarii si teoretic PC-ul tau este curat.

Virusul este foarte raspandit si m-am gandit sa postez aici o solutie pentru cei care s-au confruntat cu el.

Administrator FaraVirusi.com
voluntar al Comodo Malware Research Team, expert Malwarebytes Anti-Malware

91 responses to “C:\resycled\boot.com – cum scap de el ?”

  1. am fost infectat !

    am reusit sa-mi curat driverele cu Flash Desinfector in prima faza……….
    si cu Malware & AntiMalware……..apoi apare mereu……..Avira nu il vede , AVG 8 DA.
    acum incerc solutia ta ,,,sper sa reusesc definitiv,,,,merci radu

  2. bibanul

    Ma ajutat ,am scapat de virus ,recomand combofix ,salut….

  3. Mihay19

    Frate sa iti de-a domnu sanatate mai salvat de la moarte cu virusu ista.

  4. luXfer

    Radu, pt OS XP64 cu aceeasi problema , ce recomanzi ?
    mie nu-mi este compatibil pe 64 biti, combofixul…

  5. luXfer

    Radu, NU mi-a gasit virusul Malwarebytes, o sa incerc flash desinfector…
    dar oricum , da-mi ceva alternative. OS = XP64 profesional.
    si Radu.. mersi frumos pt. raspunsurile prompte ! ma-nclin si astept variante
    da-mi ceva alternative viabile s ascap de virusu asta…

  6. luXfer

    Radu, uite ce-am facut, cred c-am rezolvat problema cu sfaturile de pe linku asta : http://forums.techarena.in/windows-xp-support/1064141.htm — de la pasi aia 15. am lucrat in Cmd si reg edit ambele variante, am sters registrii aia… si presupun c-am sters cu cmd-ul si autorun.inf si resycledurile…. daaaaar
    acum am alta problema :))) mesajul care imi apare cand incerc sa deschid driveurile D si E este : “this file does not have a program associated with it for performing this action. Create an association in the FOlder Options Control panel. ”
    cred ca am scapat de o problema si am dat de alta. tu ce parere ai ? E posibil sa fi rezolvat cu virusul si stergand registrii aia sa fi stricat ceva in Windows… cum fac sa se deschida normal iar drive-urile ? mersi inca o data pt asistenta , si astept raspuns . Ma-nclin cu respecte !

  7. luXfer

    http://forums.techarena.in/windows-xp-support/1064141.htm – ZA complete all errors proof SOLUSHãN 😀 !!!

    GATA fratilor am reusit ! aleluia ! problema de mai sus s-a rezolvat cu un restart :))

    asa ca SOLUTIA care a mers pt mine si care cred ca e completa o gasiti la linkul http://forums.techarena.in/windows-xp-support/1064141.htm — la postul ala cu 15 pasi si la inca unul adica metodele de lucru din “cmd” si din “regedit” super , am urmat atent pasii si am reusit sa scap de belea.
    Multumesc inca o data lui Radu , toate cele bune omu’ ! si sa auzim de probleme rezolvate fara mari cronofagii 😉 ! – Salve !

    [by luXfer.M. – http:\\paganvis.hi5.com , email : v1a7a3v15@yahoo.com – (4 who cares… and wants to get intouch… ) ]

  8. cata

    ms .se pare kam rezolvat problema cu ce miai dat.

  9. luXfer

    cu avira rescue n-am incercat dupa ce rezolvasem asa… ok o sa rulez flashu…
    si ma bucur ca i-a fost de folos si lui cata.
    Sanatate, s-auzim de bine ! spor la problematici 😉

  10. Bogdan

    A mers 😡 Multumim f mult 🙂

  11. Birbal

    Am avut problema asta si nu stiam cum sa scap de ea. A mers cu ComboFix de minune. Multumim de ajutor!

  12. sathish

    my drive cannot open please solution

  13. niki4

    multumesc de ajutor!sa va tina cel de sus in putere ,avem nevoie de voi!

  14. probl

    am shi ei o probl…am reinstalat windows, shi mi-am descarcat de pe net niste kitturi fara sa am antiv instalat….acum deschid calc shi nu pot intra decat pe net …..nu pot sa accesez nik de pe desktop, my computer nici atat, taskbar deloc, start menu delos….nik….ma ajuta cineva pls….fara sa reinstalez windows?

    MERCI

  15. vali din galati

    sall la toata lumea am revenit iar cu o mare preblama

  16. vali din galati

    am schimbat dvd r si cand am dat drumu la calc am primit mesaju Disk Boot Failure.Insert System Disk And Press Enter. Ce inseamna asta ?????? Va rog ajutatima.Multumesc

  17. Vasileeee

    Dar eu folosesc win xp 64b pe care programul spune ca nu poate rula. Alta varianta pentru acest os?

  18. catalin

    mi la detectat mie bitdifender dar a srus ca nu este virus

  19. mako

    excelent programel mi-a reparat partitia 100%, adica sa intru normal in d:, fara clik dr si explore 🙂 Bravo si multam mult!

  20. Robert

    Iti multumesc mult de tot pt acest program. M-ai ajutat enorm.
    Cel mai bine folositi direct acest program, nu formatati partitia pt ca o formatati degeaba.

  21. pipa_olt

    acum merge sa accesez partitia.excelent.mersi

  22. Cody

    Acesta este log.txt dupa scanare:

    ComboFix 09-02-04.04 – Cody 2009-02-05 18:47:36.1 – NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1748 [GMT 2:00]
    Running from: c:\documents and settings\Cody\Desktop\ComboFix.exe
    AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated)
    * Resident AV is active

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\autorun.inf
    c:\docume~1\Cody\LOCALS~1\Temp\tmp1.tmp
    c:\docume~1\Cody\LOCALS~1\Temp\tmp2.tmp
    c:\program files\Mozilla Firefox\components\iamfamous.dll
    c:\recycler\S-0-7-54-100010239-100031690-100008103-7906.com
    c:\windows\system32\drivers\gaopdxmrdbbmjk.sys
    c:\windows\system32\drivers\gaopdxorwwvtnk.sys
    c:\windows\system32\drivers\gaopdxshhbddeh.sys
    c:\windows\system32\gaopdxlwxwhyyq.dll
    D:\Autorun.inf
    d:\recycler\S-0-7-54-100010239-100031690-100008103-7906.com
    d:\recycler\S-3-3-48-100010236-100003026-100017277-8185.com
    d:\recycler\S-3-4-69-100007964-100022877-100015787-7997.com
    d:\recycler\S-4-8-52-100027025-100032109-100008810-4215.com
    E:\Autorun.inf
    e:\recycler\S-0-7-54-100010239-100031690-100008103-7906.com
    e:\recycler\S-3-3-48-100010236-100003026-100017277-8185.com
    e:\recycler\S-3-4-69-100007964-100022877-100015787-7997.com
    e:\recycler\S-4-8-52-100027025-100032109-100008810-4215.com

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    ——-\Service_gaopdxserv.sys

    ((((((((((((((((((((((((( Files Created from 2009-01-05 to 2009-02-05 )))))))))))))))))))))))))))))))
    .

    2009-02-05 13:30 . 2009-02-05 13:35 d——– c:\documents and settings\Cody\Application Data\FileZilla
    2009-02-05 13:29 . 2009-02-05 13:29 d——– c:\program files\FileZilla FTP Client
    2009-02-05 03:28 . 2009-02-05 03:28 7,680 –ahs—- c:\windows\Thumbs.db
    2009-02-04 23:47 . 2009-02-04 23:47 d——– c:\windows\Sun
    2009-02-04 23:46 . 2009-02-04 23:46 d——– c:\program files\Java
    2009-02-04 23:46 . 2009-02-04 23:46 73,728 –a—— c:\windows\system32\javacpl.cpl
    2009-02-04 23:41 . 2009-02-04 23:41 d——– c:\documents and settings\All Users\Application Data\FLEXnet
    2009-02-04 23:41 . 2009-02-04 23:46 410,984 –a—— c:\windows\system32\deploytk.dll
    2009-02-04 23:39 . 2009-02-04 23:39 d——– c:\program files\Adobe Media Player
    2009-02-04 23:37 . 2009-02-04 23:37 d——– c:\program files\Common Files\Adobe AIR
    2009-02-04 23:36 . 2009-02-04 23:36 d——– c:\program files\Common Files\Macrovision Shared
    2009-02-04 23:35 . 2009-02-04 23:39 d——– c:\program files\Common Files\Adobe
    2009-02-04 21:39 . 2009-02-04 21:39 d——– C:\app

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-02-04 23:05 ——— d—–w c:\documents and settings\Cody\Application Data\uTorrent
    2009-02-04 18:37 ——— d–h–w c:\program files\InstallShield Installation Information
    2009-02-04 18:31 ——— d—–w c:\documents and settings\Cody\Application Data\Yahoo!
    2009-02-04 17:47 ——— d—–w c:\program files\IrfanView
    2009-02-04 17:44 ——— d—–w c:\documents and settings\Cody\Application Data\Winamp
    2009-02-04 17:43 ——— d—–w c:\program files\Winamp
    2009-02-04 17:39 ——— d—–w c:\documents and settings\All Users\Application Data\Yahoo! Companion
    2009-02-04 17:34 ——— d—–w c:\program files\Yahoo!
    2009-02-04 17:34 ——— d—–w c:\documents and settings\All Users\Application Data\Yahoo!
    2009-02-04 17:32 ——— d—–w c:\program files\Reference Assemblies
    2009-02-04 17:32 ——— d—–w c:\program files\MSBuild
    2009-02-04 16:44 ——— d—–w c:\program files\uTorrent
    2009-02-04 16:23 ——— d—–w c:\program files\Eset
    2009-02-04 16:23 ——— d—–w c:\documents and settings\All Users\Application Data\ESET
    2009-02-04 15:58 ——— d—–w c:\program files\Realtek
    2009-02-04 15:57 ——— d—–w c:\program files\DIFX
    2009-02-04 15:56 ——— d—–w c:\program files\Common Files\InstallShield
    2009-02-04 15:50 ——— d—–w c:\program files\microsoft frontpage
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    “NvCplDaemon”=”c:\windows\system32\NvCpl.dll” [2007-05-11 8429568]
    “NvMediaCenter”=”c:\windows\system32\NvMcTray.dll” [2007-05-11 81920]
    “egui”=”c:\program files\ESET\ESET NOD32 Antivirus\egui.exe” [2008-07-01 1447168]
    “AdobeCS4ServiceManager”=”c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe” [2008-08-14 611712]
    “SunJavaUpdateSched”=”c:\program files\Java\jre6\bin\jusched.exe” [2009-02-04 136600]
    “RTHDCPL”=”RTHDCPL.EXE” [2006-10-30 c:\windows\RTHDCPL.exe]
    “SkyTel”=”SkyTel.EXE” [2006-05-16 c:\windows\SkyTel.exe]
    “nwiz”=”nwiz.exe” [2007-05-11 c:\windows\system32\nwiz.exe]

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    “%windir%\\system32\\sessmgr.exe”=
    “%windir%\\Network Diagnostic\\xpnetdiag.exe”=
    “c:\\Program Files\\uTorrent\\uTorrent.exe”=
    “c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe”=
    “c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe”=
    “d:\\Jocuri\\Counter-Strike\\hl.exe”=
    “c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe”=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    “5353:TCP”= 5353:TCP:Adobe CSI CS4

    R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-07-01 34312]
    R2 ekrn;Eset Service;c:\program files\Eset\ESET NOD32 Antivirus\ekrn.exe [2008-07-01 468224]
    .
    .
    ——- Supplementary Scan ——-
    .
    uStart Page = hxxp://www.entretieneteds.vze.com
    FF – ProfilePath – c:\documents and settings\Cody\Application Data\Mozilla\Firefox\Profiles\x8f2ttbv.default\
    FF – prefs.js: browser.startup.homepage – hxxp://www.google.ro
    FF – component: c:\program files\Mozilla Firefox\extensions\{4037A226-F33F-427c-803C-DB710DB665EA}\components\bhelper.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista – rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-02-05 18:48:43
    Windows 5.1.2600 Service Pack 3, v.3180 NTFS

    scanning hidden processes …

    scanning hidden autostart entries …

    scanning hidden files …

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2009-02-05 18:49:38
    ComboFix-quarantined-files.txt 2009-02-05 16:49:24

    Pre-Run: 44,944,912,384 bytes free
    Post-Run: 45,321,342,976 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT=”Microsoft Windows Recovery Console” /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=”Microsoft Windows XP Professional” /fastdetect /usepmtimer /NoExecute=OptIn

    125

  23. Partitii din My Computer - Craiova Online Forum

    […] La sfarsit va afisa rezultatele scanarii. Salveaza acel fisier si posteaza continutul ACOLO. http://www.faravirusi.com/2008/11/22/cresy…cum-scap-de-el/ Asa am […]

  24. andrey

    Mersi frumoas petru soft chiar aveam nevoie de acest SOFT….MERSI FRUMOS:-bd

  25. philip

    Salut. N-am probleme cu resycled.boot.com din cate stiu, dar am probleme similare. La un moment dat, trebuie sa-mi fi intrat un virus ceva, caci computerul s-a restartat brusc, apoi la repornire, reteaua wireless mi-a picat, iar programe antivirus precum SuperAntiSpyware, Registry Firewall sau Norton Security (cel preinstalat odata cu Vista) nu mai merg dandu-mi eroare gen “is not a valid Win32 application”.

    System Restore nu da rezultate, scanul Malware mi-a gasit doar doi backdoor bot-i, fara sa remedieze situatia, Registry Medic mi-a gasit vreo 1000 de probleme, dar la fel, iar ComboFix nu merge, nu poate porni.

    Ce-i de facut?

  26. Onitza_77777

    Sa traiesti nene…:D Ms mult..

  27. old shatterhand

    mersi …

  28. Rome

    Combofix este BETON…. aveam un virus nasol, imi mergea greu calculatorul si netul, l-am rulat si dupa aceea zbarnaia ^^

  29. Rome
  30. Monica

    De ce apare “Open with” si imi da lista de programe cand vreau sa deschid partitia D sau C ???? Imi spune-ti si mie va rog ce sa fac???Multumesc!

  31. iulian

    am facut exact cum ai spus tu mai sus si cred ca am scapat de problema. cand porneam calculatorul imi aparea o eroare(ff.exe a intampinat o problema…..). cum ma uitam la un film sau ascultam muzica isi dadea restart calc. acum sper sa nu mai am probleme. mersi mult

  32. VLadut

    NU REUSESC SA SCAP DE NIMIC .. AM LUAT COMBOFIX DAR CAND INTRU IN EL SPUNE : ComboFix.exe is a not valid win32 application ce pot sa fac ?

  33. ionut

    baieti sunte-ti cei mai buni…felicitari…nici nu stiu cum sa va multumesc……bv fara voi experntii multi dintre noi am fi niste neputinciosi

  34. Mittens

    am si yo o problema nu merge sa rulez nici un program de ce /?? nici sa instalez :((

  35. Gaby

    sall! oameni buni! ce poate sa aiba PC-ul meu? pentru ca atunci cand il pornesc, deja apare eroare pe desktop (zice ca nu e compatibil ceva..) si in mai multe programe pe care vreau sa le rulez :-S

  36. ernur

    salutare! si eu am aceeasi problema la windows,de fiecare data cand doresc sa instalez un program,oricare ar fi el imi da o eroare ceva de genul “is not a valid win32 application”.am citit sfaturile de pe aici si am incercat cu combofix,dar problema este ca nici macar pe acela nu pot sa il instalez,aceeasi eroare.Iar windows-ul doar ce l-am instalat,are cateva ore de cand l-am inslatat.Ma puteti ajuta cumva?

  37. daniel

    pe mnn mu ma poti ajuta ca eu nici nu pot sa instalez programul :((((((((((((((

Leave a Reply