Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Cannot Find Script File "c:\sys.dll.vbs


  • Please log in to reply
1 reply to this topic

#1 taher

taher

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:53 AM

Posted 30 April 2008 - 09:00 AM

please find my combofix log report after malware removal for your feedback and advice

ComboFix 08-04-24.1 - AUD5 2008-04-30 15:19:46.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.549 [GMT -7:00]
Running from: C:\Documents and Settings\MASTER\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\MASTER\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
C:\Documents and Settings\MASTER\Favorites\Online Security Test.url
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-03-28 to 2008-04-30 )))))))))))))))))))))))))))))))
.

2008-04-27 12:54 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-04-27 12:54 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-04-26 06:41 . 2001-08-17 13:57 16,128 --a------ C:\WINDOWS\system32\drivers\MODEMCSA.sys
2008-04-26 06:41 . 2001-08-17 13:57 16,128 --a--c--- C:\WINDOWS\system32\dllcache\modemcsa.sys
2008-04-23 11:14 . 2001-08-17 13:56 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2008-04-23 11:14 . 2001-08-17 13:56 7,552 --a--c--- C:\WINDOWS\system32\dllcache\sonypvu1.sys
2008-04-22 11:56 . 2008-04-22 11:57 <DIR> d-------- C:\Program Files\Ahead
2008-04-22 11:24 . 2008-04-22 11:24 <DIR> d-------- C:\Program Files\Microsoft Office2000
2008-04-22 11:24 . 2008-04-22 11:24 <DIR> d-------- C:\Documents and Settings\MASTER\Application Data\Microsoft Web Folders
2008-04-21 19:10 . 2008-04-22 07:55 <DIR> d-------- C:\Documents and Settings\MASTER\Contacts
2008-04-21 18:09 . 2008-04-21 18:10 <DIR> d-------- C:\Program Files\Google
2008-04-21 17:47 . 2008-04-21 17:49 <DIR> d-------- C:\Documents and Settings\MASTER\Application Data\Ulead Systems
2008-04-21 17:45 . 2008-04-21 17:45 <DIR> d-------- C:\Program Files\Windows Media Components
2008-04-21 17:45 . 2008-04-21 17:45 <DIR> d-------- C:\Program Files\SmartSound Software
2008-04-21 17:45 . 2008-04-21 17:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
2008-04-21 17:45 . 2008-04-21 17:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-04-21 17:43 . 2008-04-21 17:43 <DIR> d-------- C:\Program Files\Ulead Systems
2008-04-21 17:43 . 2008-04-21 17:43 <DIR> d-------- C:\Program Files\Common Files\Ulead Systems
2008-04-21 17:43 . 2008-04-21 17:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-04-21 17:41 . 2008-04-21 17:41 <DIR> d-------- C:\Program Files\honestech
2008-04-21 17:41 . 2005-07-19 21:00 401,408 -ra------ C:\WINDOWS\713xRMT.exe
2008-04-21 17:41 . 2005-07-19 21:00 352,256 -ra------ C:\WINDOWS\713xRMTMon.exe
2008-04-21 17:41 . 2001-05-16 01:54 309,616 -ra------ C:\WINDOWS\system32\wmv8dmod.dll
2008-04-21 17:39 . 2001-08-17 22:36 324,608 --a------ C:\WINDOWS\system32\hpojwia.dll
2008-04-21 17:38 . 2004-08-03 22:58 207,360 --a------ C:\WINDOWS\system32\drivers\Dot4.sys
2008-04-21 17:38 . 2004-08-03 22:58 207,360 --a--c--- C:\WINDOWS\system32\dllcache\dot4.sys
2008-04-21 17:38 . 2001-08-17 13:47 23,808 --a------ C:\WINDOWS\system32\drivers\Dot4usb.sys
2008-04-21 17:38 . 2001-08-17 13:47 23,808 --a--c--- C:\WINDOWS\system32\dllcache\dot4usb.sys
2008-04-17 19:19 . 2008-04-17 19:24 <DIR> d-------- C:\My Music
2008-04-16 10:26 . 2008-04-16 10:26 <DIR> d-------- C:\Program Files\Kongsoft
2008-04-16 10:25 . 2008-04-16 10:25 <DIR> d-------- C:\WINDOWS\system32\IOSUBSYS
2008-04-16 10:25 . 2008-04-16 10:25 <DIR> d-------- C:\Program Files\MP3
2008-04-16 10:25 . 2008-04-16 10:25 <DIR> d-------- C:\Documents and Settings\MASTER\WINDOWS
2008-04-16 10:25 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-04-16 10:25 . 2003-03-25 09:05 18,912 --a------ C:\WINDOWS\system32\drivers\SMMD.sys
2008-04-13 19:53 . 2008-04-13 19:53 <DIR> d-------- C:\Documents and Settings\MASTER\Application Data\Media Player Classic
2008-04-13 17:28 . 2008-04-30 15:19 <DIR> d-------- C:\QUARANTINE
2008-04-13 09:56 . 2008-04-13 09:56 13,646 --a------ C:\WINDOWS\system32\wpa.bak
2008-04-13 09:52 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-04-13 09:52 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-04-13 09:52 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-04-13 09:52 . 2001-08-17 14:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-04-12 19:48 . 2008-04-12 19:48 <DIR> d-------- C:\Documents and Settings\COMMON_MASTER\Application Data\ACD Systems
2008-04-12 19:45 . 2008-04-12 19:45 <DIR> d-------- C:\Documents and Settings\COMMON_MASTER
2008-04-12 19:45 . 2008-04-30 15:19 1,024 --ah----- C:\Documents and Settings\COMMON_MASTER\ntuser.dat.LOG
2008-04-12 19:12 . 2001-10-04 12:13 66,082 --a--c--- C:\WINDOWS\system32\dllcache\c_10021.nls
2008-04-12 19:04 . 2008-04-12 19:04 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-04-12 19:04 . 2008-04-22 11:25 376 --a------ C:\WINDOWS\ODBC.INI
2008-04-12 19:00 . 2008-04-22 11:25 <DIR> d-------- C:\WINDOWS\ShellNew
2008-04-12 19:00 . 2008-04-12 19:00 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-04-12 18:55 . 2008-04-12 18:55 <DIR> d-------- C:\Program Files\Real
2008-04-12 18:55 . 2008-04-12 18:55 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-04-12 18:55 . 2008-04-12 18:55 <DIR> d-------- C:\Program Files\Common Files\Real
2008-04-12 18:55 . 2008-04-12 18:55 25 --a------ C:\WINDOWS\cdplayer.ini
2008-04-12 18:54 . 2008-04-12 19:51 2,359,350 --a------ C:\WINDOWS\ACD Wallpaper.bmp
2008-04-12 18:52 . 2008-04-12 18:52 <DIR> d-------- C:\Documents and Settings\MASTER\Application Data\ACD Systems
2008-04-12 18:50 . 2008-04-12 18:50 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2008-04-12 18:50 . 2008-04-12 18:50 <DIR> d-------- C:\Program Files\ACD Systems
2008-04-12 18:50 . 2008-04-12 18:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-04-12 18:50 . 2008-04-12 18:50 9,856 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-04-12 18:50 . 2008-04-12 18:50 268 --ah----- C:\sqmdata00.sqm
2008-04-12 18:50 . 2008-04-12 18:50 244 --ah----- C:\sqmnoopt00.sqm
2008-04-12 18:49 . 2008-04-21 19:09 <DIR> d-------- C:\Program Files\MSN Messenger
2008-04-12 18:47 . 2008-04-12 18:48 <DIR> d-------- C:\Program Files\Yahoo!
2008-04-12 18:47 . 2008-04-12 18:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-04-12 18:44 . 2008-04-12 18:44 <DIR> d-------- C:\Program Files\Macromedia
2008-04-12 18:41 . 2008-04-12 18:46 <DIR> d-------- C:\Program Files\Winamp
2008-04-12 18:41 . 2008-04-12 18:41 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-04-12 18:40 . 2008-04-12 18:40 <DIR> d-------- C:\Program Files\Nokia
2008-04-12 18:40 . 2008-04-12 18:40 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-04-12 18:40 . 2008-04-12 18:40 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-04-12 18:39 . 2008-04-12 18:39 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2008-04-12 18:39 . 2008-04-12 18:39 <DIR> d-------- C:\Program Files\QuickTime
2008-04-12 18:39 . 1999-11-10 11:05 86,016 --a------ C:\WINDOWS\unvise32qt.exe
2008-04-12 18:38 . 2008-04-12 18:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-04-12 18:36 . 2008-04-22 11:50 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-04-12 18:29 . 2008-04-12 18:29 <DIR> d-------- C:\WINDOWS\system32\RTCOM
2008-04-12 18:29 . 2008-04-12 18:29 <DIR> d-------- C:\WINDOWS\RTSkin
2008-04-12 18:29 . 2008-04-12 18:29 <DIR> d-------- C:\Program Files\Realtek
2008-04-12 18:29 . 2008-04-21 17:43 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-04-12 18:29 . 2008-04-21 17:43 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-04-12 18:29 . 2006-10-11 18:36 16,267,776 --a------ C:\WINDOWS\RTHDCPL.exe
2008-04-12 18:29 . 2006-10-12 09:52 4,387,328 --a------ C:\WINDOWS\system32\drivers\RtkHDAud.Sys
2008-04-12 18:29 . 2006-10-11 17:42 2,157,568 --a------ C:\WINDOWS\MicCal.exe
2008-04-12 18:29 . 2006-09-28 14:00 1,183,744 --a------ C:\WINDOWS\RtlUpd.exe
2008-04-12 18:29 . 2006-09-12 14:34 499,712 --a------ C:\WINDOWS\RtlExUpd.dll
2008-04-12 18:29 . 2006-08-18 06:58 282,624 --a------ C:\WINDOWS\system32\RTSndMgr.Cpl
2008-04-12 18:29 . 2006-08-01 15:02 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe
2008-04-12 18:29 . 2005-03-08 16:05 1,996 --a------ C:\WINDOWS\system32\drivers\HDACfg.dat
2008-04-12 18:26 . 2008-04-12 18:26 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-04-12 18:26 . 2008-04-12 18:26 <DIR> d-------- C:\Program Files\Broadcom
2008-04-12 18:26 . 2006-05-10 15:00 156,160 --a------ C:\WINDOWS\system32\drivers\b57xp32.sys
2008-04-12 18:26 . 2006-05-10 15:00 156,160 --a--c--- C:\WINDOWS\system32\dllcache\b57xp32.sys
2008-04-12 18:26 . 2006-10-06 11:09 155,648 --a------ C:\WINDOWS\system32\igfxres.dll
2008-04-12 18:26 . 2006-04-07 14:07 88,064 --a------ C:\WINDOWS\system32\Baspxp32.dll
2008-04-12 18:23 . 2008-04-12 18:29 <DIR> d-------- C:\SWSetup
2008-04-12 18:23 . 2008-04-12 18:23 <DIR> d-------- C:\Program Files\Intel
2008-04-12 18:15 . 2008-04-12 18:15 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-04-12 18:15 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\000001_.tmp
2008-04-12 18:14 . 2006-09-06 16:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-13 00:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-04-13 00:52 --------- d-----w C:\Program Files\McAfee
2008-04-13 00:52 --------- d-----w C:\Program Files\Common Files\McAfee
2008-04-13 00:52 --------- d-----w C:\Program Files\Common Files\Cisco Systems
2008-04-13 00:34 --------- d-----w C:\Program Files\microsoft frontpage
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 05:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-04-21 18:10 171448]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [2006-11-30 08:50 112216]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 13:39 136768]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-10-06 11:11 98304]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-10-06 11:13 114688]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-10-06 11:10 94208]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-11 18:36 16267776 C:\WINDOWS\RTHDCPL.exe]
"UVS10 Preload"="C:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe" [2006-03-07 00:52 36864]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-12 18:55 180269]
"NeroCheck"="C:\WINDOWS\system32\\NeroCheck.exe" [2001-07-09 03:50 155648]
"MSConfig"="C:\WINDOWS\sys.dll.vbs" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MSConfig"="C:\WINDOWS\sys.dll.vbs" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-04-22 11:50:42 113664]
Microsoft Office.lnk - C:\Program Files\Microsoft Office2000\Office\OSA9.EXE [2000-01-21 01:15:54 65588]
Scheduler for OEM.lnk - C:\Program Files\honestech\honestech TVR\scheduleTV.exe [2008-04-21 17:41:14 307200]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.ac3filter"= ac3filter.acm
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-04-12 18:39 98304 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-04-12 18:55 180269 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2005-12-08 23:30 35328 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2006-11-30 21:49 4662776 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=

R2 713xTVCard;SAA7130 TV Card;C:\WINDOWS\system32\DRIVERS\SAA713x.sys [2006-05-20 13:00]
R2 WDMTVTuner;Universal WDM TV Tuner;C:\WINDOWS\system32\drivers\WDMTuner.sys [2006-05-20 13:00]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4314f8b4-14b8-11dd-8cec-001871715c40}]
\Shell\AutoRun\command - h1dwg20.exe
\Shell\explore\Command - h1dwg20.exe
\Shell\open\Command - h1dwg20.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e4e9953f-153b-11dd-8ced-001871715c40}]
\Shell\AutoRun\command - G:\v.cmd
\Shell\explore\Command - G:\v.cmd
\Shell\open\Command - G:\v.cmd

.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-30 15:22:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\Common Framework\Mctray.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\igfxsrvc.exe
.
**************************************************************************
.
Completion time: 2008-04-30 15:25:18 - machine was rebooted [AUD5]
ComboFix-quarantined-files.txt 2008-04-30 22:25:12

Pre-Run: 93,893,693,440 bytes free
Post-Run: 94,073,307,136 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

232

BC AdBot (Login to Remove)

 


#2 Yourhighness

Yourhighness

    The BSG Malware Fighter


  • Malware Response Team
  • 7,943 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Hamburg
  • Local time:06:53 AM

Posted 21 May 2008 - 01:08 PM

Hello taher and welcome to BleepingComputer!

Apollogies for the delay. The forum has been very busy lately and. If you are still having problems, then please post a brand new HijackThis log as a reply to this topic. Before posting the log, please make sure you follow all the steps found in this topic: Preparation Guide For Use Before Posting A Hijackthis Log. Please also post the problems you are having.

When posting your log, please make sure you post the HijackThis log as a reply and not as an attachment. If we do not hear back from you within a couple of days we will need to close your topic.

Thanks,

Johannes

"How did I get infected?" - "Safe-hex" - Member of UNITE -
Posted Image





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users