Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Potential trojan - please help reports attached


  • This topic is locked This topic is locked
16 replies to this topic

#1 alanclo

alanclo

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:55 AM

Posted 11 June 2015 - 12:40 PM

Hi,
 
A couple fo days ago I got a trojan warning on Avira. I didn't take a note of it but since then Avira cannot complete a scan and hangs at about 42%. I'm pretty sure I know the folder it gets stuck at, and now my computer won't let me delete it (c:/ProgramData/PRICache).
 
I've uninstalled Avira, run the Avira registry cleaner tool and reinstalled but it still stalls.
 
I've run an avira scan in safe mode and completes without any problem and finds nothing. I've also ran a host of other programmes and will attach reports, these include:
  • Kapersky virus removal tool
  • Malwarebytes anti rootkit
  • Malwarebytes anti malware
  • farbar recory scan tool
  • security check
  • adwcleaner
  • rkill
  • JRT
  • spybot search and destroy
  • roguekiller
None of them find anything except roguekiller that found a suspicious path. [V2][SUSP PATH] OFFICE2013ACT : C:\ProgramData\Microsoft\Windows\OFFICEICON.vbs [-] -> FOUND
 
Security check won't work properly and hangs at "performing system health check".
 
I'm concerned that something has got onto my computer for Avira to flag a trojan and then stopped Avira working properly and is now hiding away somewhere. I have no problem reformatting hdd and reinstalling windows if i really have to but I'm not even sure if that will definitely get rid of it.
 
Thanks for any help

Attached Files


Edited by nasdaq, 16 June 2015 - 12:19 PM.


BC AdBot (Login to Remove)

 


#2 alanclo

alanclo
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:55 AM

Posted 11 June 2015 - 12:49 PM

I get this error when I stop scanning on avira:

 

C:\swapfile.sys
  [WARNING]   The file could not be opened!

 

Also, SecurityCheck worked so will add the log.



#3 nasdaq

nasdaq

  • Malware Response Team
  • 38,779 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:06:55 AM

Posted 15 June 2015 - 08:59 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===
 

The file office2013act.exe has been seen being distributed by the following 3 URLs.
ftp://vls.yzu.edu.tw/Traditional Chinese/Microsoft/.../Office2013Act.exe
https://mskms.yzu.edu.tw/Office2013Act.exe
ftp://vls.yzu.edu.tw/Chinese/.../Office2013Act.exe


Decide if this item found by the RogueKiller is still required.
[V2][SUSP PATH] OFFICE2013ACT : C:\ProgramData\Microsoft\Windows\OFFICEICON.vbs [-] -> FOUND
===


Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below.
 
start

EmptyTemp:
CloseProcesses:

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
ShellIconOverlayIdentifiers: [SugarSyncBackedUp] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
ShellIconOverlayIdentifiers: [SugarSyncRoot] -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
DPF: HKLM-x32 {4FF78044-96B4-4312-A5B7-FDA3CB328095}
CHR Extension: (Avira Browser Safety) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-05-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
S4 ZAPrivacyService; "C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe" [X]
S3 AndnetBus; \SystemRoot\System32\drivers\lgandnetbus64.sys [X]
S3 AndNetDiag; \SystemRoot\system32\DRIVERS\lgandnetdiag64.sys [X]
S3 ANDNetModem; \SystemRoot\system32\DRIVERS\lgandnetmodem64.sys [X]
AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\ProgramData\Temp:5C321E34

End
Save the files as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
===

Temporarily disable your AV program so it does not interfere.
Info on how to disable your security applications How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs - Security Mini-Guides.

Download Zeok tool from here

When the download appears, save to the Desktop.
On the Desktop, right-click the Zoek.exe file and select: Run as Administrator
(Give it a few seconds to appear.)

Next, copy/paste the entire script inside the code box below to the input field of Zoek:
createsrpoint;
autoclean;
emptyalltemp;
ipconfig /flushdns;b
Now...
Close any open Browsers.
Click the Run script button, and wait. It takes a few minutes to run all the script.

When the tool finishes, the zoek-results.log is opened in Notepad.
The log is also found on the systemdrive, normally C:\
If a reboot is needed, the log is opened after the reboot.

Please attach the zoek-results.log in your reply.

Also, please provide an update on how the computer is behaving after running the above script.

#4 alanclo

alanclo
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:55 AM

Posted 15 June 2015 - 02:11 PM

Many thanks for the reply, i will work through each stage and post individually once completed. Here is stage one, FRST fixlog.

Attached Files



#5 alanclo

alanclo
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:55 AM

Posted 15 June 2015 - 02:18 PM

adwcleaner log

Attached Files



#6 alanclo

alanclo
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:55 AM

Posted 15 June 2015 - 03:15 PM

zoek log

#7 alanclo

alanclo
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:55 AM

Posted 15 June 2015 - 04:29 PM

I'm running avira now, it hung on one file for about an hour but seems to past it now and running ok, It's only 7% complete and been scanning for 2 hours but i'll leave it on overnight and see what happens. Is there anything suspicious in the logs? I'm concerned because i originally had the trojan waring and then Avira wouldn't work and now I can't find a virus anywhere. Is there any chance it's hidden in my computer somewhere?

Update: Avira is not working, I let it run all night an only at 12% now. It just keeps scanning large files names of random letters and not getting very far. It scans fine in safe mode but doesn't find any virus or trojan.


Edited by alanclo, 16 June 2015 - 04:54 AM.


#8 nasdaq

nasdaq

  • Malware Response Team
  • 38,779 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:06:55 AM

Posted 16 June 2015 - 07:09 AM

Please post or attach the Zoek log for my review.

Please Download and run the ComboFix tool.

How to use ComboFix
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Follow the instructions on the page.

Post the content of the C:\ComboFix.txt file for my review.

p.s.
When all is well you can remove the tool by following the Uninstall instructions on the same page.

====

#9 alanclo

alanclo
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:55 AM

Posted 16 June 2015 - 07:36 AM

Thanks, I'll upload the Zoek log tonight. After running it, my computer now says that javascript is disabled and I think that is stopping me from posting attachments properly. How do I enable it?

 

Also, I just noticed that ComboFix isn't supported on Windows 8.1 which is what I have. Sorry, I should have put that in the first post.



#10 nasdaq

nasdaq

  • Malware Response Team
  • 38,779 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:06:55 AM

Posted 16 June 2015 - 12:21 PM

You possibly used all the allocated space by attaching a good number or files.
I removed these that I do not need at the moment.

If still unable to attach logs please copy and post them.
It's easier for me since I can always refer to them without having to download and open them.

#11 alanclo

alanclo
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:55 AM

Posted 16 June 2015 - 03:41 PM

Here's the Zoek results, what should I do about the Combofix as i'm running windows 8.1?


Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by admin on 15/06/2015 at 20:32:47.69.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\admin\Contacts\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

15/06/2015 20:39:38 Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\PROGRA~2\CheckPoint deleted successfully
C:\PROGRA~2\Malwarebytes' Anti-Malware deleted successfully
C:\PROGRA~2\New Folder deleted successfully
C:\PROGRA~3\Energy Manager deleted successfully
C:\PROGRA~3\Lenovo deleted successfully
C:\Users\admin\AppData\Roaming\Malwarebytes deleted successfully
C:\Users\admin\AppData\Roaming\MPC-HC deleted successfully
C:\Users\admin\AppData\Roaming\uTorrent deleted successfully
C:\Users\admin\AppData\Local\CrashDumps deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kfzcmd1m.default

user.js not found
---- Lines search.com removed from prefs.js ----
user_pref("capability.policy.maonoscript.sites", "192.168.1.1 addons.mozilla.org adf.ly afx.ms ajax.aspnetcdn.com ajax.googleapis.com akamaihd.net ant
---- FireFox user.js and prefs.js backups ----

prefs_062015_2047_.backup

==== Batch Command(s) Run By Tool======================


==== Deleting Files \ Folders ======================

C:\PROGRA~2\CheckPoint not found
C:\PROGRA~2\New Folder not found
C:\windows\SysNative\Tasks\OFFICE2013ACT deleted
C:\Users\admin\.android deleted
C:\PROGRA~3\eBay deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\admin\AppData\Local\cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kfzcmd1m.default\extensions\firefox@ghostery.com.xpi deleted
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kfzcmd1m.default\jetpack deleted
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kfzcmd1m.default\extensions\abs@avira.com deleted

==== Firefox Extensions ======================

ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kfzcmd1m.default
- Clickamp;Clean - %ProfilePath%\extensions\clickclean@hotcleaner.com
- Youtube MP3 Podcaster - %ProfilePath%\extensions\youtubemp3podcaster@jeremy.d.gregorio.com
- Shoptimate - %ProfilePath%\extensions\support@shoptimate.com.xpi
- NoScript - %ProfilePath%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- Greasemonkey - %ProfilePath%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
- Adblock Edge - %ProfilePath%\extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\kfzcmd1m.default
2E661988463BCFA1B95D4DAAB9B0B6FA - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll - Shockwave Flash


==== Chromium Look ======================

Google Chrome Version: 43.0.2357.124


Chrome Hotword Shared Module - admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg

==== Chromium Startpages ======================

C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.google.com",
"startup_urls": [ "http://www.google.com" ]


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.google.com"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="http://www.bing.com/search?q={searchTerms}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://www.bing.com/search?q={searchTerms}"
"SearchAssistant"="http://www.bing.com/search?q={searchTerms}"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=371 folders=61 22381497 bytes)

==== Empty Temp Folders ======================

C:\Users\admin\AppData\Local\Temp will be emptied at reboot
C:\Users\ADMINI~1\AppData\Local\Temp emptied successfully
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\admin\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 15/06/2015 at 21:08:47.80 ======================

Edited by alanclo, 16 June 2015 - 03:42 PM.


#12 nasdaq

nasdaq

  • Malware Response Team
  • 38,779 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:06:55 AM

Posted 17 June 2015 - 06:59 AM

Here's the Zoek results, what should I do about the Combofix as i'm running windows 8.1?

Just delete the Downloaded file.

===

How is the computer running now?

#13 alanclo

alanclo
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:55 AM

Posted 18 June 2015 - 12:47 PM

It's just the same. Avira won't scan properly, it keeps getting stuck on files that are named as a load of random letters, numbers and symbols and then eventually crashes. It works fine in safe mode and shows no virus.

#14 alanclo

alanclo
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:11:55 AM

Posted 18 June 2015 - 02:33 PM

i ran roguekiller again. Here is the log. It's showing a bad process, a host file and 2 registry entries, do these mean anything to you? Avira still won't scan, gets stuck on file names made up of random letters and numbers but will work fine in safe mode - would this indicate a virus?

RogueKiller V8.8.8 _x64_ [Feb 19 2014] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 8.1 (6.3.9200 ) 64 bits version
Started in : Normal mode
User : admin [Admin rights]
Mode : Scan -- Date : 06/18/2015 19:19:00
| ARK || FAK || MBR |

¤¤¤ Bad processes : 1 ¤¤¤
[SUSP PATH] RTFTrack.exe -- C:\Windows\RTFTrack.exe [7] -> KILLED [TermProc]

¤¤¤ Registry Entries : 2 ¤¤¤
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM014-1EJ164 +++++
--- User ---
[MBR] 6869f7b477b16acfaabc1c5e54dfdd17
[BSP] 9faf45e3e92aeb30efb8049ee49dc6eb : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097152 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[0]_S_06182015_191900.txt >>
RKreport[0]_S_06112015_180729.txt

Edited by alanclo, 18 June 2015 - 02:34 PM.


#15 nasdaq

nasdaq

  • Malware Response Team
  • 38,779 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:06:55 AM

Posted 19 June 2015 - 08:10 AM

[SUSP PATH] RTFTrack.exe -- C:\Windows\RTFTrack.exe [7] -> KILLED [TermProc]

A File installed by Lenovo EasyCamera

http://www.shouldiremoveit.com/Lenovo-EasyCamera-10166-program.aspx

===

I would remove Avira restart the computer normally.

Reinstall the application.

How to:
http://www.avira.com/en/support-for-home-knowledgebase-detail?kbid=88

===

If the problem persists I would contact Avira.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users