Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Virus - "your computer is infected!" window appears in t


  • This topic is locked This topic is locked

#1
diespinne

diespinne

    New Member

  • Member
  • Pip
  • 3 posts
Hi,

I've got a problem with a virus :)

That how it looks:

Posted Image

How to fix this?
I used hijackthis.exe and this is the result:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:02:05, on 2009-09-01
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20627)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\sys32_nov.exe
C:\WINDOWS\system32\braviax.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nowe Gadu-Gadu\gg.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\Bobcok\sys32_nov.exe
C:\Documents and Settings\Bobcok\sys32_nov.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nowe Gadu-Gadu\spellchecker_gg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\AcroRd32.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Winamp\winamp.exe
C:\Documents and Settings\Bobcok\Pulpit\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WinFastDTV] C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFDTV\WFWIZ.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Onet.pl AutoUpdate] "C:\Program Files\Common Files\Onet.pl\NewAutoUpdate.exe" /updateexetsr
O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [sys32_nov] C:\WINDOWS\system32\sys32_nov.exe
O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Nowe Gadu-Gadu] "C:\Program Files\Nowe Gadu-Gadu\gg.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [sys32_nov] C:\Documents and Settings\Bobcok\sys32_nov.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O4 - Startup: ikowin32.exe
O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: cru629.dat
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 6888 bytes


I'm sorry, but i looked in the FAQ with all this viruses, but i don't know what is the name of this one :) So that's why i posted a new topic. If it's wrong - please tell me where to post it.

And please - help!
  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there unfortunately Hijackthis does not show the depth of your infection so I will need to run another two analysis tools

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTS to your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on Posted Image to insert the attachment into your post



THEN

Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors).

http://sites.google....rotantirootkit/

Unzip it into a folder on your desktop.

Start the Sysprot.exe program.

  • Click on the Log tab.
  • In the Write to log box select all items.
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new Window should appear.
  • Make sure Scan all drives is selected and click on the Start button.
  • When it is complete a new Window will appear to indicate that the scan is finished.
  • The log will be created and saved automatically in the same folder. Open the text file and copy/paste the log here.

  • 0

#3
diespinne

diespinne

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Everything is in an attachment :)

Thanks for helping me.

Attached Files


  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK then time for some killing :)

Start OTS. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Unregister Dlls]
[Processes - Safe List]
YY -> braviax.exe -> C:\WINDOWS\System32\braviax.exe
YY -> sys32_nov.exe -> C:\Documents and Settings\Bobcok\sys32_nov.exe
YY -> sys32_nov.exe -> C:\Documents and Settings\Bobcok\sys32_nov.exe
YY -> sys32_nov.exe -> C:\WINDOWS\System32\sys32_nov.exe
[Registry - Safe List]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "braviax" -> []
YY -> "PC Antispyware 2010" -> C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe ["C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe" /hide]
YN -> "Regedit32" -> C:\WINDOWS\System32\regedit.exe [C:\WINDOWS\system32\regedit.exe]
YY -> "sys32_nov" -> C:\WINDOWS\System32\sys32_nov.exe [C:\WINDOWS\system32\sys32_nov.exe]
< Run [HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\] > -> HKEY_USERS\S-1-5-21-725345543-1177238915-682003330-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YY -> "sys32_nov" -> C:\Documents and Settings\Bobcok\sys32_nov.exe [C:\Documents and Settings\Bobcok\sys32_nov.exe]
< Bobcok Startup Folder > -> C:\Documents and Settings\Bobcok\Menu Start\Programy\Autostart
YY -> ~EmptyValue -> C:\Documents and Settings\Bobcok\Menu Start\Programy\Autostart\ikowin32.exe
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls
YN -> cru629.dat -> 
YN -> FILES\COM -> 
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
[Files/Folders - Created Within 30 Days]
NY -> wahyzuvi.dl -> C:\Documents and Settings\Bobcok\Dane aplikacji\wahyzuvi.dl
NY -> rotiquzyl.scr -> C:\Program Files\Common Files\rotiquzyl.scr
NY -> ymek.vbs -> C:\Documents and Settings\All Users\Dane aplikacji\ymek.vbs
NY -> subeboq.lib -> C:\WINDOWS\System32\subeboq.lib
NY -> elydinev.bat -> C:\WINDOWS\elydinev.bat
NY -> irytuwesew.db -> C:\WINDOWS\irytuwesew.db
NY -> daxogi.lib -> C:\Documents and Settings\All Users\Dokumenty\daxogi.lib
NY -> vusy.ban -> C:\Documents and Settings\All Users\Dokumenty\vusy.ban
NY -> omoraqyqev.bin -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\omoraqyqev.bin
NY -> ojum.dll -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\ojum.dll
NY -> kemufot.pif -> C:\Program Files\Common Files\kemufot.pif
NY -> ykudimiqe.exe -> C:\Documents and Settings\All Users\Dane aplikacji\ykudimiqe.exe
NY -> adah.lib -> C:\WINDOWS\System32\adah.lib
NY -> linunise.vbs -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\linunise.vbs
NY -> waku.dat -> C:\WINDOWS\waku.dat
NY -> oboqe.dl -> C:\Documents and Settings\All Users\Dane aplikacji\oboqe.dl
NY -> irarajariq.lib -> C:\Program Files\Common Files\irarajariq.lib
NY -> edyzy._sy -> C:\Documents and Settings\Bobcok\Dane aplikacji\edyzy._sy
NY -> sosok.exe -> C:\WINDOWS\sosok.exe
NY -> oficenof.pif -> C:\Program Files\Common Files\oficenof.pif
NY -> nakyjuny.ban -> C:\WINDOWS\nakyjuny.ban
NY -> enemecis.com -> C:\Program Files\Common Files\enemecis.com
NY -> xynoje.exe -> C:\WINDOWS\xynoje.exe
NY -> ytusa.com -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\ytusa.com
NY -> PC_Antispyware2010.lnk -> C:\Documents and Settings\Bobcok\Pulpit\PC_Antispyware2010.lnk
NY -> PC_Antispyware2010 -> C:\Program Files\PC_Antispyware2010
NY -> oashdihasidhasuidhiasdhiashdiuasdhasd -> C:\Documents and Settings\Bobcok\oashdihasidhasuidhiasdhiashdiuasdhasd
NY -> wisdstr.exe -> C:\WINDOWS\System32\wisdstr.exe
NY -> delself.bat -> C:\Documents and Settings\Bobcok\delself.bat
NY -> braviax.exe -> C:\WINDOWS\braviax.exe
NY -> braviax.exe -> C:\WINDOWS\System32\braviax.exe
NY -> sys32_nov.exe -> C:\WINDOWS\System32\sys32_nov.exe
NY -> sys32_nov.exe -> C:\Documents and Settings\Bobcok\sys32_nov.exe
[Files/Folders - Modified Within 30 Days]
NY -> 69 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> 264 C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\*.tmp files -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Temp\*.tmp
NY -> 13 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp
NY -> linunise.vbs -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\linunise.vbs
NY -> wahyzuvi.dl -> C:\Documents and Settings\Bobcok\Dane aplikacji\wahyzuvi.dl
NY -> rotiquzyl.scr -> C:\Program Files\Common Files\rotiquzyl.scr
NY -> ymek.vbs -> C:\Documents and Settings\All Users\Dane aplikacji\ymek.vbs
NY -> subeboq.lib -> C:\WINDOWS\System32\subeboq.lib
NY -> elydinev.bat -> C:\WINDOWS\elydinev.bat
NY -> irytuwesew.db -> C:\WINDOWS\irytuwesew.db
NY -> daxogi.lib -> C:\Documents and Settings\All Users\Dokumenty\daxogi.lib
NY -> vusy.ban -> C:\Documents and Settings\All Users\Dokumenty\vusy.ban
NY -> omoraqyqev.bin -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\omoraqyqev.bin
NY -> ojum.dll -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\ojum.dll
NY -> kemufot.pif -> C:\Program Files\Common Files\kemufot.pif
NY -> ykudimiqe.exe -> C:\Documents and Settings\All Users\Dane aplikacji\ykudimiqe.exe
NY -> adah.lib -> C:\WINDOWS\System32\adah.lib
NY -> waku.dat -> C:\WINDOWS\waku.dat
NY -> oboqe.dl -> C:\Documents and Settings\All Users\Dane aplikacji\oboqe.dl
NY -> irarajariq.lib -> C:\Program Files\Common Files\irarajariq.lib
NY -> edyzy._sy -> C:\Documents and Settings\Bobcok\Dane aplikacji\edyzy._sy
NY -> sosok.exe -> C:\WINDOWS\sosok.exe
NY -> oficenof.pif -> C:\Program Files\Common Files\oficenof.pif
NY -> nakyjuny.ban -> C:\WINDOWS\nakyjuny.ban
NY -> enemecis.com -> C:\Program Files\Common Files\enemecis.com
NY -> xynoje.exe -> C:\WINDOWS\xynoje.exe
NY -> ytusa.com -> C:\Documents and Settings\Bobcok\Ustawienia lokalne\Dane aplikacji\ytusa.com
NY -> PC_Antispyware2010.lnk -> C:\Documents and Settings\Bobcok\Pulpit\PC_Antispyware2010.lnk
NY -> oashdihasidhasuidhiasdhiashdiuasdhasd -> C:\Documents and Settings\Bobcok\oashdihasidhasuidhiasdhiashdiuasdhasd
NY -> wisdstr.exe -> C:\WINDOWS\System32\wisdstr.exe
NY -> braviax.exe -> C:\WINDOWS\System32\braviax.exe
NY -> braviax.exe -> C:\WINDOWS\braviax.exe
NY -> sys32_nov.exe -> C:\Documents and Settings\Bobcok\sys32_nov.exe
NY -> sys32_nov.exe -> C:\WINDOWS\System32\sys32_nov.exe
NY -> wpv131251705172.exe -> C:\WINDOWS\Temp\wpv131251705172.exe
[Empty Temp Folders]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new OTS log.

I will review the information when it comes back in.

THEN

Posted Image Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
  • 0

#5
diespinne

diespinne

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Thank you!

Everything seems to be just perfect now!

wow!
Great!

Cheers mate!

Edit: I can't see "helped me" button :)

Attached Files


Edited by diespinne, 02 September 2009 - 02:19 PM.

  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

I can't see "helped me" button

What button would that be ?

One final scan now to ensure that all has gone :)

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.

  • 0

#7
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP