Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

ComboFix log


  • This topic is locked This topic is locked
3 replies to this topic

#1 JBD201485

JBD201485

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:10:38 AM

Posted 16 April 2014 - 04:21 PM

New here, hope im following forum rules ok. Have run combofix to try to remove mysearchdial. Will post log below.

 

ComboFix 14-04-12.01 - Num 1 Twilight Fan 16/04/2014  21:52:47.1.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.44.1033.18.2812.1281 [GMT 1:00]
Running from: c:\users\Num 1 Twilight Fan\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Enabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\wininit.ini
.
.
(((((((((((((((((((((((((   Files Created from 2014-03-16 to 2014-04-16  )))))))))))))))))))))))))))))))
.
.
2014-04-16 21:00 . 2014-04-16 21:00    --------    d-----w-    c:\users\Default\AppData\Local\temp
2014-04-16 20:32 . 2014-04-01 01:15    10651696    ----a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BB8C606E-AC89-414B-BAB6-D347C03AB98C}\mpengine.dll
2014-04-15 02:01 . 2014-03-06 06:00    359936    ----a-w-    c:\program files\Internet Explorer\IEShims.dll
2014-04-15 02:00 . 2014-03-06 10:21    23549440    ----a-w-    c:\windows\system32\mshtml.dll
2014-04-14 18:51 . 2014-04-14 18:52    --------    d-----w-    c:\users\Num 1 Twilight Fan\AppData\Local\WinZip
2014-04-14 18:51 . 2014-04-14 18:51    --------    d-----w-    c:\programdata\WinZip
2014-04-14 18:51 . 2014-04-14 18:51    --------    d-----w-    c:\users\Num 1 Twilight Fan\AppData\Roaming\mysearchdial
2014-04-14 18:51 . 2014-04-14 18:51    --------    d-----w-    c:\program files\WinZip
2014-04-14 16:33 . 2014-03-07 04:43    10521840    ----a-w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2014-04-05 13:05 . 2014-02-20 01:12    1031560    ------w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{328391D6-53BD-4FAA-8CEC-B5D2698B65C3}\gapaengine.dll
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-04-09 18:28 . 2013-06-22 02:05    90655440    ----a-w-    c:\windows\system32\MRT.exe
2014-03-11 23:57 . 2013-01-22 23:15    71048    ----a-w-    c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-03-11 23:57 . 2013-01-22 23:15    692616    ----a-w-    c:\windows\SysWow64\FlashPlayerApp.exe
2014-03-11 08:52 . 2013-01-20 14:59    133928    ----a-w-    c:\windows\system32\drivers\NisDrvWFP.sys
2014-03-04 09:17 . 2014-04-09 01:05    44032    ----a-w-    c:\windows\apppatch\acwow64.dll
2014-02-20 01:12 . 2013-07-17 07:25    1031560    ------w-    c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2014-02-07 01:23 . 2014-03-14 23:38    3156480    ----a-w-    c:\windows\system32\win32k.sys
2014-02-04 02:32 . 2014-03-14 23:38    1424384    ----a-w-    c:\windows\system32\WindowsCodecs.dll
2014-02-04 02:32 . 2014-03-14 23:38    624128    ----a-w-    c:\windows\system32\qedit.dll
2014-02-04 02:04 . 2014-03-14 23:38    1230336    ----a-w-    c:\windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04 . 2014-03-14 23:38    509440    ----a-w-    c:\windows\SysWow64\qedit.dll
2014-01-29 02:32 . 2014-03-14 23:38    484864    ----a-w-    c:\windows\system32\wer.dll
2014-01-29 02:06 . 2014-03-14 23:38    381440    ----a-w-    c:\windows\SysWow64\wer.dll
2014-01-28 02:32 . 2014-03-14 23:38    228864    ----a-w-    c:\windows\system32\wwansvc.dll
2014-01-25 00:19 . 2014-01-25 00:19    268512    ----a-w-    c:\windows\system32\drivers\MpFilter.sys
2014-01-19 07:33 . 2013-01-22 22:39    270496    ------w-    c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spotify Web Helper"="c:\users\Num 1 Twilight Fan\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2014-04-06 1171000]
"MusicManager"="c:\users\Num 1 Twilight Fan\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [2014-03-03 7382528]
"FLV Player"="c:\users\Num 1 Twilight Fan\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe" [2012-10-26 202752]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-11-16 641704]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute    REG_MULTI_SZ       autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys;c:\windows\SYSNATIVE\DRIVERS\pgeffect.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192Ce.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2014-04-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-22 23:57]
.
2014-04-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3865778931-4247345411-1172290839-1000Core.job
- c:\users\Num 1 Twilight Fan\AppData\Local\Google\Update\GoogleUpdate.exe [2013-07-26 23:02]
.
2014-04-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3865778931-4247345411-1172290839-1000UA.job
- c:\users\Num 1 Twilight Fan\AppData\Local\Google\Update\GoogleUpdate.exe [2013-07-26 23:02]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-03-11 1271072]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://start.mysearchdial.com/?f=1&a=wnzp_14_16_ff&cd=2XzuyEtN2Y1L1QzuyCzz0AtA0CyEtCyDzzyB0EtAyDzy0FyEtN0D0Tzu0SzztAyDtN1L2XzutBtFtBtDtFtCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StD0EtB0F0Dzy0CyBtGtDtB0FyEtG0DzytA0EtGtC0B0A0CtGtDyByB0ByD0DzyyD0B0C0BtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBzy0D0D0DyD0AzztGyDtCzytDtGtDyByB0BtGyDtCyCyBtGyEyD0CyBtC0D0EyCyD0FtD0D2Q&cr=2115214382&ir=
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = localhost:8080
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
FF - ProfilePath - c:\users\Num 1 Twilight Fan\AppData\Roaming\Mozilla\Firefox\Profiles\h1l0tuqj.default\
FF - prefs.js: browser.search.selectedEngine - Mysearchdial
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=UP22DF&PC=UP22&dt=020313&q=
FF - user.js: extensions.irmysearch.aflt - wnzp_14_16_ff
FF - user.js: extensions.irmysearch.instlRef - 140305_a
FF - user.js: extensions.irmysearch.cr - 2115214382
FF - user.js: extensions.irmysearch.cd - 2XzuyEtN2Y1L1QzuyCzz0AtA0CyEtCyDzzyB0EtAyDzy0FyEtN0D0Tzu0SzztAyDtN1L2XzutBtFtBtDtFtCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StD0EtB0F0Dzy0CyBtGtDtB0FyEtG0DzytA0EtGtC0B0A0CtGtDyByB0ByD0DzyyD0B0C0BtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBzy0D0D0DyD0AzztGyDtCzytDtGtDyByB0BtGyDtCyCyBtGyEyD0CyBtC0D0EyCyD0FtD0D2Q
FF - user.js: extensions.mysearchdial.hmpg - true
FF - user.js: extensions.mysearchdial.hmpgUrl - hxxp://start.mysearchdial.com/?f=1&a=wnzp_14_16_ff&cd=2XzuyEtN2Y1L1QzuyCzz0AtA0CyEtCyDzzyB0EtAyDzy0FyEtN0D0Tzu0SzztAyDtN1L2XzutBtFtBtDtFtCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StD0EtB0F0Dzy0CyBtGtDtB0FyEtG0DzytA0EtGtC0B0A0CtGtDyByB0ByD0DzyyD0B0C0BtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBzy0D0D0DyD0AzztGyDtCzytDtGtDyByB0BtGyDtCyCyBtGyEyD0CyBtC0D0EyCyD0FtD0D2Q&cr=2115214382&ir=
FF - user.js: extensions.mysearchdial.dfltSrch - true
FF - user.js: extensions.mysearchdial.srchPrvdr - Mysearchdial
FF - user.js: extensions.mysearchdial.dnsErr - true
FF - user.js: extensions.mysearchdial_i.newTab - false
FF - user.js: extensions.mysearchdial.newTabUrl - hxxp://start.mysearchdial.com/?f=2&a=wnzp_14_16_ff&cd=2XzuyEtN2Y1L1QzuyCzz0AtA0CyEtCyDzzyB0EtAyDzy0FyEtN0D0Tzu0SzztAyDtN1L2XzutBtFtBtDtFtCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StD0EtB0F0Dzy0CyBtGtDtB0FyEtG0DzytA0EtGtC0B0A0CtGtDyByB0ByD0DzyyD0B0C0BtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBzy0D0D0DyD0AzztGyDtCzytDtGtDyByB0BtGyDtCyCyBtGyEyD0CyBtC0D0EyCyD0FtD0D2Q&cr=2115214382&ir=
FF - user.js: extensions.mysearchdial.tlbrSrchUrl - hxxp://start.mysearchdial.com/?f=3&a=wnzp_14_16_ff&cd=2XzuyEtN2Y1L1QzuyCzz0AtA0CyEtCyDzzyB0EtAyDzy0FyEtN0D0Tzu0SzztAyDtN1L2XzutBtFtBtDtFtCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StD0EtB0F0Dzy0CyBtGtDtB0FyEtG0DzytA0EtGtC0B0A0CtGtDyByB0ByD0DzyyD0B0C0BtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBzy0D0D0DyD0AzztGyDtCzytDtGtDyByB0BtGyDtCyCyBtGyEyD0CyBtC0D0EyCyD0FtD0D2Q&cr=2115214382&ir=&q=
FF - user.js: extensions.mysearchdial.id - 68A3C41587E359F4
FF - user.js: extensions.mysearchdial.instlDay - 16174
FF - user.js: extensions.mysearchdial.vrsn - 1.8.29.0
FF - user.js: extensions.mysearchdial.vrsni - 1.8.29.0
FF - user.js: extensions.mysearchdial_i.vrsnTs - 1.8.29.019:51
FF - user.js: extensions.mysearchdial.prtnrId - mysearchdial
FF - user.js: extensions.mysearchdial.prdct - mysearchdial
FF - user.js: extensions.mysearchdial.aflt - wnzp_14_16_ff
FF - user.js: extensions.mysearchdial_i.smplGrp - none
FF - user.js: extensions.mysearchdial.tlbrId - base
FF - user.js: extensions.mysearchdial.instlRef - 140305_a
FF - user.js: extensions.mysearchdial.dfltLng -
FF - user.js: extensions.mysearchdial.appId - {CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}
FF - user.js: extensions.mysearchdial.excTlbr - false
FF - user.js: extensions.mysearchdial.cr - 2115214382
FF - user.js: extensions.mysearchdial.cd - 2XzuyEtN2Y1L1QzuyCzz0AtA0CyEtCyDzzyB0EtAyDzy0FyEtN0D0Tzu0SzztAyDtN1L2XzutBtFtBtDtFtCtFtDtN1L1CzutCyEtDtAtDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StD0EtB0F0Dzy0CyBtGtDtB0FyEtG0DzytA0EtGtC0B0A0CtGtDyByB0ByD0DzyyD0B0C0BtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StBzy0D0D0DyD0AzztGyDtCzytDtGtDyByB0BtGyDtCyCyBtGyEyD0CyBtC0D0EyCyD0FtD0D2Q
FF - user.js: extensions.mysearchdial.AL - 2
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-04-16  22:03:55
ComboFix-quarantined-files.txt  2014-04-16 21:03
.
Pre-Run: 201,195,888,640 bytes free
Post-Run: 203,693,830,144 bytes free
.
- - End Of File - - C8BAAFD358F46F0406BCF8E26DE3EED5
A36C5E4F47E84449FF07ED3517B43A31
 



BC AdBot (Login to Remove)

 


#2 Jo*

Jo*

  • Malware Response Team
  • 3,303 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:38 AM

Posted 18 April 2014 - 02:59 AM

:welcome:

Hello JBD201485,

my name is Jo and I will help you with your computer problems.



Please follow these guidelines:
  • Logs can take a while to research, so please be patient.
  • Read and follow the instructions in the sequence they are posted.
  • print or copy & save instructions.
  • back up all your private data / important files on another (external) drive before using our tools.
  • Do not install / uninstall any applications, unless otherwise instructed.
  • Use only that tools you have been instructed to use.
  • Copy and Paste the log files inside your post, unless otherwise instructed.
  • Ask for clarification, if you have any questions.
  • Stay with this topic til you get the all clean post.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

***


1. Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    Vista / Windows 7/8 users right-click and select Run As Administrator.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

***


2. Download OTL to your desktop.
  • Double click on the icon to run it.
    Vista / Windows 7/8 users right-click and select Run As Administrator.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note: These logs can be located in the OTL folder on your C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

***


Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#3 Jo*

Jo*

  • Malware Response Team
  • 3,303 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:38 AM

Posted 21 April 2014 - 07:19 AM


Hi,

it has been several days since I sent my last set of instructions to help with your computer problem.

Please let me know if you are having problems and still need help.

Note: Threads will be closed if no response after 3 days.

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#4 Jo*

Jo*

  • Malware Response Team
  • 3,303 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:11:38 AM

Posted 23 April 2014 - 01:26 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users