Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Please Help Me Remove W32.myzor.fk@yf


  • Please log in to reply
2 replies to this topic

#1 biscoac

biscoac

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:15 AM

Posted 29 November 2007 - 07:58 PM

I pulled this from an old post on the board since I'm in the same situation.

Can someone please help me. I have somehow got a virus on my work computer (or spyware/malware) and can't get it off. I have gone through all the steps in the thread of how to get rid of it (Ad-Aware, Spybot) etc and it finds and removes things but they all come back. I also tried doing the steps mentioned here www.bleepingcomputer.com/forums/lofiversion/index.php/t71806.html which I thought worked but no luck.

W32.Myzor.fk@yf


I also have already done this

Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6 update 3'.
3. Click the "Download" button to the right.
4. Check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java version.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.


If you have previously downloaded ComboFix,please delete that version now.
Now download Combofix and save to your desktop:
Note:
It is important that it is saved directly to your desktop
Close any open browsers.
Disconnect from the Internet.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.
Do NOT post the ComboFix-quarantined-files.txt unless I ask.
*Note*
In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.
Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.

Now go to:
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
Right click on Hijackthis.exe and select 'Rename', rename it to abc.bat
Double click on abc.bat(which is still Hijackthis.exe),post that log into your next reply please.


Any assistance is greatly appreciated!

ComboFix 07-11-30.3 - Owner 2007-11-29 19:15:30.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.136 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Administrator.SUEFABS\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Administrator.SUEFABS\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Administrator.SUEFABS\Favorites\Online Security Guide.lnk
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Owner\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Owner\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Owner\Favorites\Online Security Guide.lnk
C:\Program Files\WinBudget
C:\WINDOWS\cookies.ini
C:\WINDOWS\mrofinu.exe
C:\WINDOWS\system32\aslpxkar.dll
C:\WINDOWS\system32\awturom.dll
C:\WINDOWS\system32\blbymtph.dll
C:\WINDOWS\system32\bwmurtec.dll
C:\WINDOWS\system32\dnyiiwht.dll
C:\WINDOWS\system32\eplsrptc.dll
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\fonandhs.dll
C:\WINDOWS\system32\hggedee.dll
C:\WINDOWS\system32\jmgyqqlx.dll
C:\WINDOWS\system32\oqstv.ini
C:\WINDOWS\system32\oqstv.ini2
C:\WINDOWS\system32\ornhslmx.dll
C:\WINDOWS\system32\pmnkklm.dll
C:\WINDOWS\system32\pmnnomj.dll
C:\WINDOWS\system32\prdtlhmn.dll
C:\WINDOWS\system32\rakxplsa.ini
C:\WINDOWS\system32\tmps9
C:\WINDOWS\system32\vtsqo.dll
C:\WINDOWS\system32\xguaqjmx.dll
C:\WINDOWS\system32\xguaqjmx.dllbox
C:\WINDOWS\system32\yayvwts.dll
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
-------\nm


((((((((((((((((((((((((( Files Created from 2007-10-28 to 2007-11-30 )))))))))))))))))))))))))))))))
.

2007-11-29 18:58 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-11-29 18:57 . 2007-11-29 18:57 <DIR> d-------- C:\Program Files\Common Files\Java
2007-11-29 18:34 . 2007-11-29 18:34 <DIR> d-------- C:\Documents and Settings\Administrator.SUEFABS\Application Data\Grisoft
2007-11-27 20:19 . 2004-08-27 04:54 <DIR> d-------- C:\Documents and Settings\Administrator.SUEFABS\WINDOWS
2007-11-27 20:19 . 2005-02-25 16:39 <DIR> d-------- C:\Documents and Settings\Administrator.SUEFABS\Application Data\SampleView
2007-11-27 20:12 . 2007-11-27 20:12 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Grisoft
2007-11-27 20:11 . 2007-11-27 20:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-27 20:11 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-27 19:49 . 2007-11-27 21:33 <DIR> d-------- C:\Program Files\HiJack This
2007-11-26 21:28 . 2007-11-27 21:46 784,365 --ahs---- C:\WINDOWS\system32\jhmbsnis.ini
2007-11-20 21:19 . 2007-11-22 18:00 143 --a------ C:\WINDOWS\system32\mcrh.tmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-29 23:58 --------- d-----w C:\Program Files\Java
2007-11-29 23:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-28 03:11 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-28 03:06 --------- d-----w C:\Program Files\McAfee
2007-11-28 02:55 --------- d-----w C:\Program Files\Symantec AntiVirus
2007-11-28 02:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-19 17:11 --------- d-----w C:\Program Files\Lx_cats
2007-10-28 19:34 --------- d-----w C:\Program Files\iTunes
2007-10-28 19:29 --------- d-----w C:\Program Files\Lexmark 8300 Series
2007-10-24 23:26 --------- d-----w C:\Program Files\QuickTime
2007-09-13 09:16 2,508 ----a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
2005-06-08 17:27 0 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 50,736 2006-09-26 00:52:48 C:\Program Files\Common Files\AOL\1133312852\ee\bak\AOLSoftware.exe

----a-r 71,216 2006-10-23 12:50:37 C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe

----a-w 58,488 2004-08-28 00:22:40 C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe

----a-w 32,768 2003-11-01 03:42:40 C:\Program Files\CyberLink\PowerDVD\bak\PDVDServ.exe

----a-w 68,856 2007-07-12 22:27:28 C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe

----a-w 256,576 2006-10-30 14:36:36 C:\Program Files\iTunes\bak\iTunesHelper.exe
----a-w 256,576 2006-10-30 14:36:36 C:\Program Files\iTunes\iTunesHelper.exe

----a-w 88,024 2007-08-08 19:53:16 C:\Program Files\Lavasoft\Ad-Aware 2007\bak\AAWTray.exe
----a-w 87,392 2007-11-27 01:40:59 C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe

----a-w 94,208 2005-08-01 12:05:04 C:\Program Files\Lexmark 8300 Series\bak\ezprint.exe

----a-w 200,704 2005-09-30 14:49:22 C:\Program Files\Lexmark 8300 Series\bak\lxcjmon.exe

----a-w 245,760 2004-08-18 02:26:38 C:\Program Files\McAfee.com\Agent\bak\mcagent.exe

----a-w 139,264 2004-07-29 21:55:34 C:\Program Files\McAfee.com\Agent\bak\McRegWiz.exe

----a-w 184,320 2004-10-03 00:34:04 C:\Program Files\McAfee.com\Agent\bak\bak\mcupdate.exe

----a-w 184,320 2004-10-03 00:34:04 C:\Program Files\McAfee.com\Agent\bak\bak\mcupdate.exe

----a-w 282,624 2006-10-25 23:58:18 C:\Program Files\QuickTime\bak\qttask.exe

----a-w 125,120 2006-10-25 00:33:00 C:\Program Files\Symantec AntiVirus\bak\VPTray.exe

----a-w 684,032 2004-08-12 23:12:50 C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe

----a-w 102,400 2004-08-12 23:13:16 C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe

----a-w 212,992 2002-09-13 20:42:26 C:\WINDOWS\SMINST\bak\RECGUARD.EXE

----a-w 118,784 2004-08-20 23:51:14 C:\WINDOWS\system32\bak\hkcmd.exe

----a-w 155,648 2004-08-20 23:55:14 C:\WINDOWS\system32\bak\igfxtray.exe

----a-w 155,648 2001-07-09 19:50:42 C:\WINDOWS\system32\bak\NeroCheck.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" []
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" []
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" []
"LXCJCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll" [2005-09-08 13:45]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 07:44:06]
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0b\aoltray.exe [2005-07-21 21:42:13]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-09-07 21:14:18]
Picture Package Menu.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2005-06-06 14:18:27]
Picture Package VCD Maker.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2005-06-06 14:18:21]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\vtsqo.dll


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b7db3d91-8771-11d9-afea-806d6172696f}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

.
Contents of the 'Scheduled Tasks' folder
"2007-11-28 03:05:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2005-05-31 10:37:42 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************

catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-29 19:37:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-29 19:40:29 - machine was rebooted
.
--- E O F ---


and here is the hijack this

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:57:28 PM, on 11/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0b\aoltray.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LXCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0b\aoltray.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by132fd.bay132.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxcj_device - - C:\WINDOWS\system32\lxcjcoms.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--
End of file - 5387 bytes



BC AdBot (Login to Remove)

 


m

#2 biscoac

biscoac
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:15 AM

Posted 02 December 2007 - 09:51 AM

Anything on this yet? THanks for your time

#3 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,388 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:07:15 AM

Posted 12 December 2007 - 01:58 PM

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

When posting the logs, please post them normally. No need to use a code box.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users