Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

64.192.130.141 and other Spyware sites[CLOSED]


  • This topic is locked This topic is locked

#1
gilligan128

gilligan128

    Member

  • Member
  • PipPip
  • 10 posts
I have removed my family'ignorant spyware downloads so many times, that I am jsut too tired to sift throught the logfile to find this one. SO here is the HijackThis logfile. It seems to be the usual stubborn spyware dll, but I do not know what the file(s) is/are or where it/they is/are located.


Logfile of HijackThis v1.99.1
Scan saved at 6:35:50 PM, on 6/2/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\AOL Instant Messenger\aim.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINNT\system32\nsvsvc\nsvsvc.exe
C:\WINNT\system32\picsvr\picsvr.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimt.../aimtoolbar.jsp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimt.../aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [tsvcin] C:\WINNT\system32\n20050308.EXE
O4 - HKLM\..\Run: [Nsv] C:\WINNT\system32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\Run: [picsvr] C:\WINNT\system32\picsvr\picsvr.exe
O4 - HKCU\..\Run: [AIM] C:\AOL Instant Messenger\aim.exe -cnetwait.odl
O4 - Startup: AdDestroyer.lnk = C:\Program Files\AdDestroyer\AdDestroyer.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0a\aoltray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AOL Instant Messenger\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\dolsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
O20 - Winlogon Notify: Uninstall - C:\WINNT\system32\n0p40a7qed.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe

THank you for any help you can give.
  • 0

Advertisements


#2
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Hello and welcome to GeeksToGo! My name is Kat, and I will be helping you get your computer fixed back up and on the go! You should either print these instructions, or save them to a Notepad file on your desktop. Part of the fix may require you to be in Safe Mode, and you will be unable to access the internet at that time!

1. A malicious .DLL file is disrupting the LSP chain on your computer. We need to get rid of it.

1. Please download LSPFix from here.
2. Run the LSPFix.exe that you have just finished downloading.
3. Check the I know what I'm doing box.
4. In the Keep box you should see one or more instances of dolsp.dll
5. Select every instance of dolsp.dll and move each one to the Remove box by clicking the >> button.
6. When you are done click Finish>>.


2. Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [tsvcin] C:\WINNT\system32\n20050308.EXE
O4 - HKLM\..\Run: [picsvr] C:\WINNT\system32\picsvr\picsvr.exe
O20 - Winlogon Notify: Uninstall - C:\WINNT\system32\n0p40a7qed.dll

Now close all windows other than HiJackThis, then click Fix Checked. Reboot into safe mode.

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Please remove these entries from Add/Remove Programs in the Control Panel(if present):

Viewpoint
VBouncer

Please note any other programs that you dont recognize in that list in your next response

Please delete these folders using Windows Explorer(if present):

C:\Program Files\Viewpoint
C:\PROGRA~1\VBouncer

Please delete these files using Windows Explorer(if present):

C:\WINNT\system32\n20050308.EXE
C:\WINNT\system32\picsvr\picsvr.exe

After that, Reboot.

3. I need you to download MWav to a convenient location.

This scan might take around 3+ hours to finish when set to scan everything.
I need you to run MWav by double-clicking on mwav.exe.
Put a check next to the below items before scanning:
  • Memory
  • Startup Folders
  • Drive - All Local Drives
  • Folder - then click "browse" to change the directory to C: (default is C:\Windows)
  • Registry
  • System Folders
  • Services
  • Include Sub-Directory
  • Scan All Files
Please make sure ALL of these are checked, then press the Scan button. This typically will take hours to complete.

**NOTE*** Sometimes MWav will pause and it appears to be finished, but it isn't done. Just let it run until it says it's complete.

On the bottom portion of the window, you will see the lower panel where MWav is listing "infected items", please highlight everything in that lower panel and copy them by holding CTRL + C then paste it here. The whole log will be extremely BIG so there is no way to post the log. I just need the infected items list.

4. Please make a reply here with a fresh HijackThis log, as well as a copy of the MWav Infected Files log, if there is one!
  • 0

#3
gilligan128

gilligan128

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Ok, here iis the new HijackThis logfile. Also, on e thing to note is that i forgot to remove virtual bouncer and viewpoint manager until after i ran the mwav scan. SOrry about any confusion that may bring.

Logfile of HijackThis v1.99.1
Scan saved at 10:17:34 PM, on 6/2/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\AOL Instant Messenger\aim.exe
C:\Program Files\wats\alsr.exe
C:\WINNT\system32\??rss.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\AdDestroyer\AdDestroyer.exe
C:\program files\tvs\tvs_b.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINNT\system32\bpc_inst_1014.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimt.../aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: FlashEnhancer Ext - {5EDB03AF-0341-4e96-9E9B-3171522E4BAF} - c:\Program Files\Fla\fla.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINNT\EliteToolBar\EliteToolBar version 60.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [tvs_b] C:\program files\tvs\tvs_b.exe
O4 - HKLM\..\Run: [checkrun] c:\winnt\system32\elitecln32.exe
O4 - HKLM\..\Run: [FlaCPY] "c:\Program Files\Common Files\Java\flacpy.exe"
O4 - HKCU\..\Run: [AIM] C:\AOL Instant Messenger\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Stio] C:\Program Files\wats\alsr.exe
O4 - HKCU\..\Run: [Bdwztrw] C:\WINNT\system32\??rss.exe
O4 - HKCU\..\RunOnce: [Web Offer] Command /c del C:\WINNT\system32\EZPOPS~1.EXE
O4 - Startup: AdDestroyer.lnk = C:\Program Files\AdDestroyer\AdDestroyer.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0a\aoltray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AOL Instant Messenger\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
O20 - Winlogon Notify: RunOnce - C:\WINNT\system32\l02s0af7ed2.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINNT\wanmpsvc.exe



Mwav log file: (it is really really long):

File C:\WINNT\ELITET~1\ELITET~1.DLL tagged as "not-a-virus:AdWare.ToolBar.EliteBar.af". Action Taken: No Action Taken.
File C:\WINNT\system32\SJSSETUP.DLL tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\dflsp.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File c:\winnt\system32\elitecln32.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.
Object "eZula Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "eZula Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "ElitebarBHO Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "ElitebarBHO Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "BrowserAid Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "LetsSearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "EliteBar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "EliteBar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "EliteBar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AdDestroyer Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AdDestroyer Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AdDestroyer Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AdDestroyer Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AdDestroyer Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "CWS.therealsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKCR\CLSID\{04bb4b23-7c70-4fc5-96ee-5252612ad900}" refers to invalid object "C:\WINNT\system32\glycpp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C}" refers to invalid object "C:\PROGRA~1\AWS\WEATHE~1\MINIBU~1.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{9E9A550A-F284-4F1E-A5FC-9B85A52F35EA}" refers to invalid object "C:\WINNT\system32\guard.tmp". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{A4845882-333F-11D0-B724-00AA0062CBB7}" refers to invalid object "C:\WINNT\System32\WBEM\WBEMSTUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B0693766-5278-4ec6-B9E1-3CE40560EF5A}" refers to invalid object "CaPlgin.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B7C02D00-5865-4D4D-838D-C77026228E06}" refers to invalid object "C:\WINNT\system32\guard.tmp". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}" refers to invalid object "C:\Program Files\CxtPls\proxystub.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E07D3492-32B5-11D0-B724-00AA0062CBB7}" refers to invalid object "C:\WINNT\System32\WBEM\WBEMSTUB.DLL". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost.2" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\SymWriter.pdb" refers to invalid object "{520DC67A-752E-11D3-8D56-00C04F680B2B}". Action Taken: No Action Taken.
File C:\WINNT\icont.exe tagged as "not-a-virus:AdWare.AdURL.c". Action Taken: No Action Taken.
File C:\WINNT\iconu.exe tagged as "not-a-virus:AdWare.Zestyfind". Action Taken: No Action Taken.
File C:\WINNT\woinstall.exe tagged as "not-a-virus:AdWare.EZula.ak". Action Taken: No Action Taken.
File C:\WINNT\system32\aza0l3jm1.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\D0CE0C16B1.DLL infected by "Trojan-Clicker.Win32.Agent.dh" Virus! Action Taken: No Action Taken.
File C:\WINNT\system32\dn6801jue.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\docore.dll tagged as "not-a-virus:AdWare.Couponage.a". Action Taken: No Action Taken.
File C:\WINNT\system32\dolsp.dll infected by "Trojan-Downloader.Win32.Agent.br" Virus! Action Taken: No Action Taken.
File C:\WINNT\system32\dosync.dll tagged as "not-a-virus:AdWare.Couponage.a". Action Taken: No Action Taken.
File C:\WINNT\system32\elitegdl32.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.
File C:\WINNT\system32\ezPopStub.exe tagged as "not-a-virus:AdWare.EZula.av". Action Taken: No Action Taken.
File C:\WINNT\system32\fp6u03j9e.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\fprq0395e.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\gp60l3jm1.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\i2420choef4c0.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\i2jq0c15ef.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\ik41_qcx.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\jt0007dme.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\ktj0l71m1.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\ktpol7731.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\lrrmonui.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINNT\system32\mlc42.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINNT\system32\mvl8l93u1.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\mvr8l99u1.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\nmlanui.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINNT\system32\PopOops.dll tagged as "not-a-virus:AdWare.VirtualBouncer.g". Action Taken: No Action Taken.
File C:\WINNT\system32\PopOops2.dll tagged as "not-a-virus:AdWare.VirtualBouncer.g". Action Taken: No Action Taken.
File C:\WINNT\system32\rtuteext.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINNT\system32\SWLAD1.dll tagged as "not-a-virus:AdWare.VirtualBouncer.g". Action Taken: No Action Taken.
File C:\WINNT\system32\SWLAD2.dll tagged as "not-a-virus:AdWare.VirtualBouncer.g". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\Temp\bw2.com infected by "Trojan-Downloader.Win32.Small.ru" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\Temp\ntechin.exe tagged as "not-a-virus:AdWare.DelphinMediaViewer.c". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\Temp\temp.frB9D7 tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\Temp\uppicsvr.exe tagged as "not-a-virus:AdWare.DelphinMedia.Viewer.f". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\Temp\vmstmp\vmstmp.exe tagged as "not-a-virus:AdWare.DelphinMediaViewer.c". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\Temp\~vis0000\rebootnt.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\9A23M5XG\AM_1.0.163[1].exe infected by "Trojan-Downloader.Win32.Apropo.s" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\9A23M5XG\AppWrap[1].exe tagged as "not-a-virus:AdWare.AdURL.c". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\9A23M5XG\track26[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\9A23M5XG\woinstall[1].exe tagged as "not-a-virus:AdWare.EZula.ak". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\DHL119K6\AppWrap[1].exe infected by "Trojan-Downloader.Win32.Small.ru" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\DHL119K6\AppWrap[3].exe tagged as "not-a-virus:AdWare.Zestyfind". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\DHL119K6\AproposClientInstaller[1].exe infected by "Trojan-Downloader.Win32.Apropo.s" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\DHL119K6\upd203[1].exe tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\DHL119K6\woinstall[1].exe tagged as "not-a-virus:AdWare.EZula.ak". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\QR123VNF\AppWrap[1].exe tagged as "not-a-virus:AdWare.AdURL.c". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\QR123VNF\AppWrap[2].exe infected by "Trojan-Dropper.Win32.Small.of" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\QR123VNF\AppWrap[3].exe tagged as "not-a-virus:AdWare.AdURL.c". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\QR123VNF\AppWrap[4].exe tagged as "not-a-virus:AdWare.Zestyfind". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\QR123VNF\AppWrap[5].exe infected by "Trojan-Downloader.Win32.Small.ru" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\QR123VNF\AppWrap[6].exe infected by "Trojan-Downloader.Win32.Small.ru" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\QR123VNF\eZinstall[1].exe tagged as "not-a-virus:AdWare.EZula.ak". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\Z9D7C1QK\AppWrap[1].exe infected by "Trojan-Downloader.Win32.Small.ru" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\Z9D7C1QK\AppWrap[2].exe tagged as "not-a-virus:AdWare.AdURL.c". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\Z9D7C1QK\AppWrap[3].exe infected by "Trojan-Downloader.Win32.Small.ru" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\Z9D7C1QK\aun_0010[1].exe infected by "Trojan-Downloader.Win32.Small.akz" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\Z9D7C1QK\eZinstall[1].exe tagged as "not-a-virus:AdWare.EZula.ak". Action Taken: No Action Taken.
File C:\DOCUME~1\REBECC~1\LOCALS~1\TEMPOR~1\Content.IE5\Z9D7C1QK\protector[1].exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users.WINNT\Application Data\wsxs\patchme.exe tagged as "not-a-virus:AdWare.DelphinMedia.Viewer.f". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temp\bw2.com infected by "Trojan-Downloader.Win32.Small.ru" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temp\ntechin.exe tagged as "not-a-virus:AdWare.DelphinMediaViewer.c". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temp\temp.frB9D7 tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temp\uppicsvr.exe tagged as "not-a-virus:AdWare.DelphinMedia.Viewer.f". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temp\vmstmp\vmstmp.exe tagged as "not-a-virus:AdWare.DelphinMediaViewer.c". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temp\~vis0000\rebootnt.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\9A23M5XG\AM_1.0.163[1].exe infected by "Trojan-Downloader.Win32.Apropo.s" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\9A23M5XG\AppWrap[1].exe tagged as "not-a-virus:AdWare.AdURL.c". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\9A23M5XG\track26[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\9A23M5XG\woinstall[1].exe tagged as "not-a-virus:AdWare.EZula.ak". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\DHL119K6\AppWrap[1].exe infected by "Trojan-Downloader.Win32.Small.ru" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\DHL119K6\AppWrap[3].exe tagged as "not-a-virus:AdWare.Zestyfind". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\DHL119K6\AproposClientInstaller[1].exe infected by "Trojan-Downloader.Win32.Apropo.s" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\DHL119K6\upd203[1].exe tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\DHL119K6\woinstall[1].exe tagged as "not-a-virus:AdWare.EZula.ak". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\QR123VNF\AppWrap[1].exe tagged as "not-a-virus:AdWare.AdURL.c". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\QR123VNF\AppWrap[2].exe infected by "Trojan-Dropper.Win32.Small.of" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\QR123VNF\AppWrap[3].exe tagged as "not-a-virus:AdWare.AdURL.c". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\QR123VNF\AppWrap[4].exe tagged as "not-a-virus:AdWare.Zestyfind". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\QR123VNF\AppWrap[5].exe infected by "Trojan-Downloader.Win32.Small.ru" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\QR123VNF\AppWrap[6].exe infected by "Trojan-Downloader.Win32.Small.ru" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\QR123VNF\eZinstall[1].exe tagged as "not-a-virus:AdWare.EZula.ak". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\Z9D7C1QK\AppWrap[1].exe infected by "Trojan-Downloader.Win32.Small.ru" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\Z9D7C1QK\AppWrap[2].exe tagged as "not-a-virus:AdWare.AdURL.c". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\Z9D7C1QK\AppWrap[3].exe infected by "Trojan-Downloader.Win32.Small.ru" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\Z9D7C1QK\aun_0010[1].exe infected by "Trojan-Downloader.Win32.Small.akz" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\Z9D7C1QK\eZinstall[1].exe tagged as "not-a-virus:AdWare.EZula.ak". Action Taken: No Action Taken.
File C:\Documents and Settings\Rebecca Henke\Local Settings\Temporary Internet Files\Content.IE5\Z9D7C1QK\protector[1].exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.
File C:\Program Files\AdDestroyer\AdDestroyer.exe tagged as "not-a-virus:AdWare.VirtualBouncer.g". Action Taken: No Action Taken.
File C:\Program Files\America Online 9.0\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0a\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\Common Files\aolback\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe tagged as "not-a-virus:AdWare.DelphinMedia.Viewer.f". Action Taken: No Action Taken.
File C:\Program Files\sdf.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.
File C:\Program Files\VBouncer\AdDestroyerInner.EXE tagged as "not-a-virus:AdWare.VirtualBouncer.j". Action Taken: No Action Taken.
File C:\Program Files\VBouncer\BundleOuter.EXE tagged as "not-a-virus:AdWare.VirtualBouncer.j". Action Taken: No Action Taken.
File C:\Program Files\VBouncer\VBouncerInner.EXE tagged as "not-a-virus:AdWare.VirtualBouncer". Action Taken: No Action Taken.
File C:\Program Files\VBouncer\VirtualBouncer.exe tagged as "not-a-virus:AdWare.VirtualBouncer.i". Action Taken: No Action Taken.
File C:\WINNT\icont.exe tagged as "not-a-virus:AdWare.AdURL.c". Action Taken: No Action Taken.
File C:\WINNT\iconu.exe tagged as "not-a-virus:AdWare.Zestyfind". Action Taken: No Action Taken.
File C:\WINNT\system32\aza0l3jm1.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\D0CE0C16B1.DLL infected by "Trojan-Clicker.Win32.Agent.dh" Virus! Action Taken: No Action Taken.
File C:\WINNT\system32\dn6801jue.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\docore.dll tagged as "not-a-virus:AdWare.Couponage.a". Action Taken: No Action Taken.
File C:\WINNT\system32\dolsp.dll infected by "Trojan-Downloader.Win32.Agent.br" Virus! Action Taken: No Action Taken.
File C:\WINNT\system32\dosync.dll tagged as "not-a-virus:AdWare.Couponage.a". Action Taken: No Action Taken.
File C:\WINNT\system32\elitegdl32.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.
File C:\WINNT\system32\ezPopStub.exe tagged as "not-a-virus:AdWare.EZula.av". Action Taken: No Action Taken.
File C:\WINNT\system32\fp6u03j9e.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\fprq0395e.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\gp60l3jm1.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\i2420choef4c0.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\i2jq0c15ef.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\ik41_qcx.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\jt0007dme.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\ktj0l71m1.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\ktpol7731.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\lrrmonui.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINNT\system32\mlc42.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINNT\system32\mvl8l93u1.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\mvr8l99u1.dll tagged as "not-a-virus:AdWare.Look2Me.u". Action Taken: No Action Taken.
File C:\WINNT\system32\nmlanui.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINNT\system32\nsvsvc\nsv.ocx tagged as "not-a-virus:AdWare.DelphinMediaViewer.c". Action Taken: No Action Taken.
File C:\WINNT\system32\nsvsvc\nsvs.dll tagged as "not-a-virus:AdWare.DelphinMedia.Viewer.f". Action Taken: No Action Taken.
File C:\WINNT\system32\nsvsvc\nsvsvc.exe tagged as "not-a-virus:AdWare.DelphinMedia.Viewer.f". Action Taken: No Action Taken.
File C:\WINNT\system32\picsvr\picsvr.exe infected by "Trojan-Downloader.Win32.Delmed.b" Virus! Action Taken: No Action Taken.
File C:\WINNT\system32\PopOops.dll tagged as "not-a-virus:AdWare.VirtualBouncer.g". Action Taken: No Action Taken.
File C:\WINNT\system32\PopOops2.dll tagged as "not-a-virus:AdWare.VirtualBouncer.g". Action Taken: No Action Taken.
File C:\WINNT\system32\rtuteext.dll tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINNT\system32\SWLAD1.dll tagged as "not-a-virus:AdWare.VirtualBouncer.g". Action Taken: No Action Taken.
File C:\WINNT\system32\SWLAD2.dll tagged as "not-a-virus:AdWare.VirtualBouncer.g". Action Taken: No Action Taken.
File C:\WINNT\system32\vmss\vmss.exe_tobedeleted tagged as "not-a-virus:AdWare.DelphinMediaViewer.c". Action Taken: No Action Taken.
File C:\WINNT\Temp\bw2.exe infected by "Trojan-Downloader.Win32.Small.ru" Virus! Action Taken: No Action Taken.
File C:\WINNT\Temp\nsdtmp09.dll tagged as "not-a-virus:AdWare.MetaDirect.a". Action Taken: No Action Taken.
File C:\WINNT\Temp\tsvcin.exe tagged as "not-a-virus:AdWare.DelphinMedia.Viewer.f". Action Taken: No Action Taken.
File C:\WINNT\Temp\upd203.exe tagged as "not-a-virus:AdWare.Look2Me.ab". Action Taken: No Action Taken.
File C:\WINNT\Temp\uppicsvr.exe tagged as "not-a-virus:AdWare.DelphinMedia.Viewer.f". Action Taken: No Action Taken.
File C:\WINNT\Temp\~apropos0\CxtPls.exe infected by "Trojan-Downloader.Win32.Apropo.x" Virus! Action Taken: No Action Taken.
File C:\WINNT\Temp\~apropos0\pm.exe infected by "Trojan-Downloader.Win32.Apropo.d" Virus! Action Taken: No Action Taken.
File C:\WINNT\woinstall.exe tagged as "not-a-virus:AdWare.EZula.ak". Action Taken: No Action Taken.


Thanks again for helping me.
  • 0

#4
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Ouch. Ok there are going to be several small steps we need to take to get you cleaned up. Hang in there with me, and we WILL get you clean again! :tazz:

First , I want you to locate and uninstall the following programs if found:
eZula
AltNet
EliteBar


Second , Download CWShredder Here.
Update CWShredder
  • Open CWShredder and click I AGREE
  • Click Check For Update
  • Close Shredder
Third , Please download CleanUp!. Install it but dont run it yet.

Fourth , please reboot into Safe Mode. Open CWShredder, click "I agree" then "Fix" and then "Next" and let it fix everything it finds. Then exit Shredder and reboot back into normal Windows.

Fifth, please open the CleanUp program, and click the CleanUp button. Allow it to run and clean out your temp files, etc. Then close the program.

Sixth, Please download ewido security suite it is a trial version of the program.
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will prompt you to update click the OK button
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
The update will start and a progress bar will show the updates being installed.
Once the updates are installed do the following:
  • Click on scanner
  • Make sure the following boxes are checked before scanning:
    • Binder
    • Crypter
    • Archives
  • Click on Start Scan
  • Let the program scan the machine
While the scan is in progress you will be prompted to clean files, click OK
Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report
  • Save the report to your desktop
Seventh, You have the latest version of VX2. Download L2mfix from one of these two locations:

http://www.atribune....oads/l2mfix.exe
http://www.downloads....org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop.

Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Save this log to your desktop.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!

Eighth Please make a reply here after all the above are done so we can finish cleaning what's left. In the reply, I need a fresh HJT log, the copy of the Ewido log, and the saved L2M log! ;)
  • 0

#5
gilligan128

gilligan128

    Member

  • Topic Starter
  • Member
  • PipPip
  • 10 posts
Freakin Direct Revenue! Alright I will start on thisas soon as I can tomorrow. Thank you in th emeantime.
  • 0

#6
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member with address of this thread. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP