Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Suspected Infection - Peer Log Review


  • Please log in to reply
1 reply to this topic

#1 donlee2

donlee2

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:07:57 PM

Posted 13 February 2008 - 12:14 AM

My first post. I hope I get this right! This system was infected with many bugs. I had several services that were fried, sfc cleaned them up. After spending a few days cleaning this is what's left. Could someone take a look at my combofix and hijackthis logs. THANKS GUYS!

COMBOFIX LOG:

ComboFix 08-02-13.2 - Dan 2008-02-12 22:07:13.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.278 [GMT -6:00]
Running from: C:\Documents and Settings\Dan\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-01-13 to 2008-02-13 )))))))))))))))))))))))))))))))
.

2008-02-12 21:35 . 2008-02-12 21:35 <DIR> d-------- C:\Program Files\Windows Defender
2008-02-12 20:44 . 2008-02-12 21:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\comodo
2008-02-12 20:44 . 2008-02-12 20:44 139,008 --a------ C:\WINDOWS\system32\guard32.dll
2008-02-12 20:44 . 2008-02-12 20:44 83,064 --a------ C:\WINDOWS\system32\drivers\cmdGuard.sys
2008-02-12 20:44 . 2008-02-12 20:44 23,800 --a------ C:\WINDOWS\system32\drivers\cmdhlp.sys
2008-02-12 20:11 . 2008-02-12 20:11 <DIR> d-------- C:\Program Files\Windows Media Connect 2
2008-02-12 20:05 . 2008-02-12 20:07 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-02-12 17:57 . 2007-12-06 20:21 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-02-12 17:57 . 2007-06-30 21:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-02-12 17:57 . 2007-06-30 21:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-02-12 17:57 . 2007-12-06 20:21 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-02-12 17:57 . 2007-12-06 20:21 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-02-12 17:57 . 2007-12-06 20:21 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-02-12 17:57 . 2007-12-06 20:21 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-02-12 17:57 . 2007-12-06 20:21 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-02-12 17:57 . 2007-12-06 05:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-12 17:24 . 2008-02-12 18:56 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2008-02-12 17:04 . 2008-02-12 20:48 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-02-12 16:35 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\000001_.tmp
2008-02-12 16:11 . 2008-02-12 16:11 <DIR> d-------- C:\Program Files\CNet
2008-02-12 15:55 . 2008-02-12 16:19 <DIR> d-------- C:\Documents and Settings\Dan\Application Data\U3
2008-02-11 22:28 . 2001-08-17 13:28 771,581 --a--c--- C:\WINDOWS\system32\dllcache\winacisa.sys
2008-02-11 22:28 . 2001-08-17 13:28 701,386 --a--c--- C:\WINDOWS\system32\dllcache\wdhaalba.sys
2008-02-11 22:28 . 2004-08-03 21:31 154,624 --a--c--- C:\WINDOWS\system32\dllcache\wlluc48.sys
2008-02-11 22:28 . 2001-08-17 22:36 87,040 --a--c--- C:\WINDOWS\system32\dllcache\wiafbdrv.dll
2008-02-11 22:28 . 2001-08-17 22:36 53,760 --a--c--- C:\WINDOWS\system32\dllcache\wiamsmud.dll
2008-02-11 22:28 . 2001-08-17 12:10 35,871 --a--c--- C:\WINDOWS\system32\dllcache\wbfirdma.sys
2008-02-11 22:28 . 2001-08-17 12:12 34,890 --a--c--- C:\WINDOWS\system32\dllcache\wlandrv2.sys
2008-02-11 22:28 . 2004-08-03 21:29 33,599 --a--c--- C:\WINDOWS\system32\dllcache\watv04nt.sys
2008-02-11 22:28 . 2004-08-03 21:29 23,615 --a--c--- C:\WINDOWS\system32\dllcache\wch7xxnt.sys
2008-02-11 22:28 . 2004-08-03 21:29 19,551 --a--c--- C:\WINDOWS\system32\dllcache\watv02nt.sys
2008-02-11 22:28 . 2004-08-03 22:07 8,832 --a--c--- C:\WINDOWS\system32\dllcache\wmiacpi.sys
2008-02-11 22:26 . 2001-08-17 22:36 525,568 --a--c--- C:\WINDOWS\system32\dllcache\tridxp.dll
2008-02-11 22:25 . 2001-08-17 12:18 285,760 --a--c--- C:\WINDOWS\system32\dllcache\stlnata.sys
2008-02-11 22:24 . 2001-08-17 22:36 386,560 --a--c--- C:\WINDOWS\system32\dllcache\sgiul50.dll
2008-02-11 22:23 . 2001-08-17 22:36 495,616 --a--c--- C:\WINDOWS\system32\dllcache\sblfx.dll
2008-02-11 22:22 . 2001-08-17 13:28 899,146 --a--c--- C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2008-02-11 22:21 . 2001-08-17 14:05 351,616 --a--c--- C:\WINDOWS\system32\dllcache\ovcodek2.sys
2008-02-11 22:20 . 2004-08-03 21:31 132,695 --a--c--- C:\WINDOWS\system32\dllcache\netwlan5.sys
2008-02-11 22:19 . 2004-08-03 23:56 56,832 --a--c--- C:\WINDOWS\system32\dllcache\msdvbnp.ax
2008-02-11 22:19 . 2004-08-03 22:09 51,328 --a--c--- C:\WINDOWS\system32\dllcache\msdv.sys
2008-02-11 22:19 . 2004-08-03 22:09 49,024 --a--c--- C:\WINDOWS\system32\dllcache\mstape.sys
2008-02-11 22:19 . 2001-08-17 14:02 35,200 --a--c--- C:\WINDOWS\system32\dllcache\msgame.sys
2008-02-11 22:19 . 2004-08-03 22:00 22,016 --a--c--- C:\WINDOWS\system32\dllcache\msircomm.sys
2008-02-11 22:19 . 2001-08-17 13:48 12,416 --a--c--- C:\WINDOWS\system32\dllcache\msriffwv.sys
2008-02-11 22:19 . 2001-08-17 13:48 6,016 --a--c--- C:\WINDOWS\system32\dllcache\msfsio.sys
2008-02-11 22:19 . 2004-08-03 21:58 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys
2008-02-11 22:19 . 2001-08-17 14:00 2,944 --a--c--- C:\WINDOWS\system32\dllcache\msmpu401.sys
2008-02-11 22:17 . 2001-08-17 22:36 242,176 --a--c--- C:\WINDOWS\system32\dllcache\kdsusd.dll
2008-02-11 22:16 . 2001-08-17 22:36 372,824 --a--c--- C:\WINDOWS\system32\dllcache\iconf32.dll
2008-02-11 22:15 . 2004-08-04 06:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-02-11 22:14 . 2004-08-04 06:00 10,096,640 --a--c--- C:\WINDOWS\system32\dllcache\hwxcht.dll
2008-02-11 22:13 . 2001-08-17 14:56 1,733,120 --a--c--- C:\WINDOWS\system32\dllcache\g400d.dll
2008-02-11 22:12 . 2001-08-17 13:28 634,134 --a--c--- C:\WINDOWS\system32\dllcache\el656ct5.sys
2008-02-11 22:11 . 2001-08-17 12:14 952,007 --a--c--- C:\WINDOWS\system32\dllcache\diwan.sys
2008-02-11 22:10 . 2001-08-17 22:36 419,357 --a--c--- C:\WINDOWS\system32\dllcache\dgconfig.dll
2008-02-11 22:09 . 2001-08-17 12:13 980,034 --a--c--- C:\WINDOWS\system32\dllcache\cicap.sys
2008-02-11 22:08 . 2004-08-04 06:00 195,618 --a--c--- C:\WINDOWS\system32\dllcache\c_10002.nls
2008-02-11 22:07 . 2001-08-17 13:28 871,388 --a--c--- C:\WINDOWS\system32\dllcache\bcmdm.sys
2008-02-11 22:06 . 2001-08-17 14:07 56,960 --a--c--- C:\WINDOWS\system32\dllcache\aic78xx.sys
2008-02-11 22:06 . 2001-08-17 14:07 55,168 --a--c--- C:\WINDOWS\system32\dllcache\aic78u2.sys
2008-02-11 22:06 . 2004-08-03 21:31 36,224 --a--c--- C:\WINDOWS\system32\dllcache\an983.sys
2008-02-11 22:06 . 2001-08-17 12:11 27,678 --a--c--- C:\WINDOWS\system32\dllcache\ali5261.sys
2008-02-11 22:06 . 2001-08-17 13:49 26,624 --a--c--- C:\WINDOWS\system32\dllcache\alifir.sys
2008-02-11 22:06 . 2001-08-17 22:37 24,576 --a--c--- C:\WINDOWS\system32\dllcache\agcgauge.ax
2008-02-11 22:06 . 2001-08-17 12:11 16,969 --a--c--- C:\WINDOWS\system32\dllcache\amb8002.sys
2008-02-11 22:06 . 2001-08-17 13:52 12,800 --a--c--- C:\WINDOWS\system32\dllcache\aha154x.sys
2008-02-11 22:06 . 2001-08-17 13:52 12,032 --a--c--- C:\WINDOWS\system32\dllcache\amsint.sys
2008-02-11 22:06 . 2001-08-17 13:51 5,248 --a--c--- C:\WINDOWS\system32\dllcache\aliide.sys
2008-02-11 21:21 . 2001-08-17 14:56 66,048 --a--c--- C:\WINDOWS\system32\dllcache\s3legacy.dll
2008-02-11 21:20 . 2008-02-11 21:58 <DIR> d-------- C:\I386
2008-02-11 19:12 . 2008-02-11 19:35 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-02-11 18:01 . 2008-02-11 18:01 <DIR> d-------- C:\WINDOWS\Recent
2008-02-11 18:01 . 2008-02-11 18:01 <DIR> d-------- C:\WINDOWS\Cookies
2008-02-11 13:49 . 2008-02-12 20:44 <DIR> d-------- C:\Program Files\COMODO
2008-02-11 13:49 . 2008-02-12 20:45 <DIR> d-------- C:\Documents and Settings\Dan\Application Data\Comodo
2008-02-11 13:11 . 2008-02-11 13:11 <DIR> d-------- C:\Program Files\7-Zip
2008-02-11 13:10 . 2008-02-11 13:10 1,167 --a------ C:\WINDOWS\mozver.dat
2008-02-11 12:24 . 2008-02-11 12:24 1,270 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-11 11:18 . 2008-02-11 11:18 0 --a------ C:\WINDOWS\nsreg.dat
2008-02-11 11:02 . 2008-02-11 11:02 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-11 11:02 . 2008-02-11 11:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-11 11:01 . 2008-02-11 11:01 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-11 11:00 . 2008-02-11 11:39 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-11 11:00 . 2008-02-12 17:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-11 11:00 . 2007-01-18 06:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-02-11 10:59 . 2008-02-11 11:10 <DIR> d-------- C:\Documents and Settings\Dan\Pavark
2008-02-11 10:56 . 2008-02-12 17:23 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-02-08 15:27 . 2008-02-08 15:27 <DIR> d-------- C:\Program Files\CCleaner
2008-02-08 15:20 . 2008-02-08 15:20 <DIR> d-------- C:\Program Files\Avira
2008-02-08 15:20 . 2008-02-08 15:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-02-08 15:20 . 2008-02-08 15:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-02-06 18:02 . 2008-02-12 20:05 <DIR> d-------- C:\WINDOWS\system32\LogFiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-12 22:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-12 22:10 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-11 17:26 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-02-08 21:26 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-08 21:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-02-08 21:06 --------- d-----w C:\Program Files\Hewlett-Packard
2008-02-08 21:03 --------- d-----w C:\Program Files\Kodak
2008-02-07 21:29 --------- d-----w C:\Program Files\Microsoft Works
2008-02-07 21:25 --------- d-----w C:\Program Files\Google
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS\system32\oleaut32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-11 11:14 249896]
"COMODO Firewall Pro"="C:\Program Files\COMODO\Firewall\cfp.exe" [2008-02-12 20:44 5046016]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=

R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2008-02-12 20:44]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2008-02-12 20:44]
R3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [2002-01-11 00:22]
S3 ati2mpaa;ati2mpaa;C:\WINDOWS\system32\DRIVERS\ati2mpaa.sys [2001-08-17 06:48]
S3 SIWIO;SIWIO;C:\WINDOWS\TEMP\SiwIo.sys []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe

*Newly Created Service* - WINDEFEND
.
Contents of the 'Scheduled Tasks' folder
"2008-02-13 03:38:55 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-12 22:10:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\guard32.dll

PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\WINDOWS\system32\guard32.dll
.
Completion time: 2008-02-12 22:11:59
.
2008-02-13 02:35:02 --- E O F ---



HIJACKTHIS LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:49 PM, on 2/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Dan\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -s
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

--
End of file - 3962 bytes

BC AdBot (Login to Remove)

 


m

#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:02:57 AM

Posted 23 February 2008 - 05:02 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum.
My name is Richie and i'll be helping you to fix your problems.

Apologies for the late response,as i'm sure you can appreciate we are extremely busy.

If you've already recieved help at another forum and your issues have been resolved,or you're presently recieving help elsewhere then please let us know.

If you have not followed the info in the link below prior to posting your log then please do so now:
Preparation Guide for use before posting a HijackThis Log:
http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/

If you still require help,please post a new Hijackthis log into this topic in your next reply.

Also post a detailed description of the issues you're experiencing.

*Note*
Post all reports/logs directly into this topic,not as attachments or inside code boxes,thanks.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users