Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

consrv.dll infected with trojan-Nothings happened yet? [Closed]


  • This topic is locked This topic is locked

#1
ligadeo

ligadeo

    New Member

  • Member
  • Pip
  • 1 posts
Hello. I have a windows vista 64. While using my computer today AVG notified me of a consrv.dll trojan. I haven't had any problems yet, but i definitely wanna nip this in the bud. After a few searches i found a scanner with the name Farbar Recovery Scan Tool (FRST). After I scanned it i got the log. Now, im not to knowledgeable on computer viruses but maybe you guys can help me remove the trojan, or the consrv.dll file, if that is the case.

Here is the log of FRST's scan:

Scan result of Farbar Recovery Scan Tool Version: 09-06-2012 01
Ran by Leave Me Alone at 09-06-2012 13:47:32
Running from C:\Users\Leave Me Alone\Downloads
Service Pack 2 (X64) OS Language: English(US)
Attention: Could not load system hive.ERROR: The process cannot access the file because it is being used by another process.

ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNTION PROPERLY.

========================== Registry (Whitelisted) =============

HKU\Default\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-11] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-11] (Microsoft Corporation)
HKU\Default User\...\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem [1555968 2009-04-11] (Microsoft Corporation)
HKU\Default User\...\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter [2438656 2009-04-11] (Microsoft Corporation)
HKLM\...\Winlogon: [Userinit]
HKLM-x32\...\Winlogon: [Userinit] [x]
HKLM\...\Winlogon: [Shell] [x ] ()
HKLM-x32\...\Winlogon: [Shell] [x ] ()

==================== Services (Whitelisted) ======


========================== Drivers (Whitelisted) =============


========================== NetSvcs (Whitelisted) ===========


============ One Month Created Files and Folders ==============

2012-06-09 14:28 - 2012-06-09 13:47 - 00000000 ____D C:\FRST
2012-06-09 13:35 - 2012-06-09 13:46 - 00000236 ____A C:\Users\Leave Me Alone\Downloads\Search.txt
2012-06-09 12:35 - 2012-06-09 12:35 - 01399435 ____A C:\Users\Leave Me Alone\Downloads\FRST64.exe
2012-06-08 11:05 - 2012-06-08 11:05 - 00765768 ____A C:\Users\Leave Me Alone\Downloads\Comcast_Desktop_Software_1203.exe
2012-06-08 11:05 - 2012-06-08 11:05 - 00005289 ____A C:\comcastrelease.log
2012-06-08 11:05 - 2012-06-08 11:05 - 00000000 ____D C:\Users\Leave Me Alone\AppData\Local\Xfinity.com
2012-06-05 13:46 - 2012-06-05 13:46 - 00832383 ____A C:\Users\Leave Me Alone\Downloads\1338719634616.jpg
2012-06-04 04:16 - 2012-06-04 10:09 - 00000000 ____D C:\Program Files (x86)\Free RAR Extract Frog
2012-06-04 04:16 - 2012-06-04 04:16 - 00000945 ____A C:\Users\Public\Desktop\Free RAR Extract Frog.lnk
2012-06-04 04:16 - 2012-06-04 04:16 - 00000000 ____D C:\Users\Leave Me Alone\AppData\Roaming\Philipp Winterberg
2012-06-04 04:16 - 2012-06-04 04:16 - 00000000 ____D C:\Program Files (x86)\Ask.com
2012-06-04 04:15 - 2012-06-04 04:15 - 04354784 ____A (Philipp Winterberg) C:\Users\Leave Me Alone\Downloads\InstallFreeRARExtractFrog.exe
2012-06-03 10:47 - 2012-06-03 10:47 - 00000000 ____D C:\Users\Leave Me Alone\Desktop\Santa Rosa
2012-05-26 22:42 - 2012-05-26 23:29 - 00000674 ____A C:\Users\Leave Me Alone\Desktop\Leo JC Confrimeration.txt
2012-05-14 19:09 - 2012-05-14 19:09 - 00069917 ____A C:\Users\Leave Me Alone\Downloads\1337012026190.jpg
2012-05-11 18:48 - 2012-05-11 18:48 - 00000000 ____D C:\67fd886005511002135dd5f7d93a5b38
2012-05-10 05:50 - 2012-03-30 05:45 - 01423744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-05-10 05:49 - 2012-04-03 01:22 - 04699520 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-05-10 05:49 - 2012-04-02 06:59 - 02766848 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-05-10 05:49 - 2012-03-20 16:34 - 00072576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys
2012-05-10 05:49 - 2012-03-01 08:39 - 00327680 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll
2012-05-10 05:49 - 2012-03-01 08:39 - 00196096 ____A (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll
2012-05-10 05:49 - 2012-03-01 07:46 - 00219648 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2012-05-10 05:49 - 2012-03-01 07:46 - 00160768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2012-05-10 05:49 - 2012-02-29 07:40 - 02002944 ____A (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll
2012-05-10 05:49 - 2012-02-29 07:09 - 00834048 ____A (Microsoft Corporation) C:\Windows\System32\d2d1.dll
2012-05-10 05:49 - 2012-02-29 07:08 - 01172480 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2012-05-10 05:49 - 2012-02-29 07:06 - 01556480 ____A (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2012-05-10 05:49 - 2012-02-29 06:44 - 00683008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2012-05-10 05:49 - 2012-02-29 06:41 - 01069056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2012-05-10 05:49 - 2012-02-01 08:30 - 00024576 ____A (Microsoft Corporation) C:\Windows\System32\jnwmon.dll

============ 3 Months Modified Files and Folders =============

2012-06-09 13:47 - 2012-06-09 14:28 - 00000000 ____D C:\FRST
2012-06-09 13:46 - 2012-06-09 13:35 - 00000236 ____A C:\Users\Leave Me Alone\Downloads\Search.txt
2012-06-09 13:41 - 2011-08-16 21:43 - 00000000 ____D C:\Users\Leave Me Alone\AppData\Roaming\uTorrent
2012-06-09 13:37 - 2012-01-04 19:38 - 00000000 ___RD C:\Users\Leave Me Alone\Desktop\GTi
2012-06-09 13:34 - 2011-08-15 02:46 - 01937122 ____A C:\Windows\WindowsUpdate.log
2012-06-09 13:31 - 2006-11-02 08:42 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2012-06-09 13:31 - 2006-11-02 08:22 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2012-06-09 13:31 - 2006-11-02 08:22 - 00003216 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2012-06-09 13:12 - 2008-06-09 21:56 - 00000012 ____A C:\Windows\bthservsdp.dat
2012-06-09 13:12 - 2006-11-02 08:42 - 00032588 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2012-06-09 12:42 - 2006-11-02 05:46 - 00143472 ____A C:\Windows\System32\PerfStringBackup.INI
2012-06-09 12:41 - 2011-08-16 03:41 - 00000000 ___RD C:\Users\Leave Me Alone\Desktop\Old Comp
2012-06-09 12:39 - 2006-11-02 08:27 - 00104738 ____A C:\Windows\setupact.log
2012-06-09 12:35 - 2012-06-09 12:35 - 01399435 ____A C:\Users\Leave Me Alone\Downloads\FRST64.exe
2012-06-09 12:13 - 2011-10-28 16:33 - 00000000 ____D C:\Windows\System32\Drivers\AVG
2012-06-09 12:13 - 2011-10-28 16:24 - 00000000 ____D C:\Users\All Users\MFAData
2012-06-08 11:05 - 2012-06-08 11:05 - 00765768 ____A C:\Users\Leave Me Alone\Downloads\Comcast_Desktop_Software_1203.exe
2012-06-08 11:05 - 2012-06-08 11:05 - 00005289 ____A C:\comcastrelease.log
2012-06-08 11:05 - 2012-06-08 11:05 - 00000000 ____D C:\Users\Leave Me Alone\AppData\Local\Xfinity.com
2012-06-08 04:18 - 2011-11-05 06:24 - 00000000 ___RD C:\Users\Leave Me Alone\Desktop\Gasten's
2012-06-07 14:46 - 2012-01-27 12:14 - 00000680 ____A C:\Users\Leave Me Alone\AppData\Local\d3d9caps.dat
2012-06-06 15:48 - 2011-09-13 23:01 - 00001320 ____A C:\Users\Leave Me Alone\AppData\Roaming\wklnhst.dat
2012-06-06 15:37 - 2011-08-15 04:20 - 00000052 ____A C:\Windows\SysWOW64\DOErrors.log
2012-06-06 11:32 - 2012-01-20 14:56 - 00000000 ____D C:\Users\Leave Me Alone\Desktop\New Folder
2012-06-06 11:18 - 2011-08-18 02:50 - 00123904 ____A C:\Users\Leave Me Alone\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-06-05 13:46 - 2012-06-05 13:46 - 00832383 ____A C:\Users\Leave Me Alone\Downloads\1338719634616.jpg
2012-06-04 10:09 - 2012-06-04 04:16 - 00000000 ____D C:\Program Files (x86)\Free RAR Extract Frog
2012-06-04 10:09 - 2008-01-20 20:26 - 00122788 ____A C:\Windows\PFRO.log
2012-06-04 04:16 - 2012-06-04 04:16 - 00000945 ____A C:\Users\Public\Desktop\Free RAR Extract Frog.lnk
2012-06-04 04:16 - 2012-06-04 04:16 - 00000000 ____D C:\Users\Leave Me Alone\AppData\Roaming\Philipp Winterberg
2012-06-04 04:16 - 2012-06-04 04:16 - 00000000 ____D C:\Program Files (x86)\Ask.com
2012-06-04 04:16 - 2011-08-15 04:03 - 00000000 ____D C:\Users\Leave Me Alone\AppData\LocalLow
2012-06-04 04:15 - 2012-06-04 04:15 - 04354784 ____A (Philipp Winterberg) C:\Users\Leave Me Alone\Downloads\InstallFreeRARExtractFrog.exe
2012-06-03 10:47 - 2012-06-03 10:47 - 00000000 ____D C:\Users\Leave Me Alone\Desktop\Santa Rosa
2012-05-26 23:29 - 2012-05-26 22:42 - 00000674 ____A C:\Users\Leave Me Alone\Desktop\Leo JC Confrimeration.txt
2012-05-21 17:10 - 2008-06-09 23:34 - 00002651 ____A C:\Users\Leave Me Alone\Desktop\Microsoft Office Word 2007.lnk
2012-05-16 06:37 - 2011-10-13 13:25 - 00000000 ____D C:\Users\Leave Me Alone\Desktop\CoverArt
2012-05-14 19:09 - 2012-05-14 19:09 - 00069917 ____A C:\Users\Leave Me Alone\Downloads\1337012026190.jpg
2012-05-13 13:21 - 2006-11-02 08:07 - 00000000 ____D C:\Windows\SysWOW64\XPSViewer
2012-05-13 13:00 - 2008-06-09 23:31 - 00000000 ____D C:\Users\All Users\Microsoft Help
2012-05-13 13:00 - 2006-11-02 05:35 - 57848688 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe
2012-05-12 20:18 - 2006-11-02 08:21 - 04877544 ____A C:\Windows\System32\FNTCACHE.DAT
2012-05-12 20:14 - 2006-11-02 08:07 - 00000000 ____D C:\Program Files\Windows Journal
2012-05-11 18:48 - 2012-05-11 18:48 - 00000000 ____D C:\67fd886005511002135dd5f7d93a5b38
2012-05-11 18:25 - 2011-11-30 02:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2012-05-04 03:57 - 2012-05-04 03:56 - 00250330 ____A C:\Windows\ntbtlog.txt
2012-04-27 09:05 - 2012-04-27 09:05 - 00965128 ____A C:\Users\Leave Me Alone\Downloads\1335541265975.jpg
2012-04-26 23:28 - 2012-01-09 17:54 - 00000000 ____D C:\Users\Leave Me Alone\AppData\Local\Apple Computer
2012-04-14 15:00 - 2012-04-14 15:00 - 00004579 ____A C:\Users\Leave Me Alone\Downloads\Download.pdf
2012-04-06 12:38 - 2011-08-15 04:02 - 00000000 ____D C:\users\Leave Me Alone
2012-04-06 12:37 - 2006-11-02 06:33 - 00000000 ____D C:\Windows\System32\config\TxR
2012-04-06 12:36 - 2006-11-02 05:33 - 72613888 ____A C:\Windows\System32\config\software_previous
2012-04-06 12:36 - 2006-11-02 05:33 - 58982400 ____A C:\Windows\System32\config\components_previous
2012-04-06 12:36 - 2006-11-02 05:33 - 20185088 ____A C:\Windows\System32\config\system_previous
2012-04-06 12:36 - 2006-11-02 05:33 - 00262144 ____A C:\Windows\System32\config\security_previous
2012-04-06 12:36 - 2006-11-02 05:33 - 00262144 ____A C:\Windows\System32\config\sam_previous
2012-04-06 12:36 - 2006-11-02 05:33 - 00262144 ____A C:\Windows\System32\config\default_previous
2012-04-06 12:35 - 2006-11-02 06:34 - 00000000 ____D C:\Windows\System32\spool
2012-04-06 12:35 - 2006-11-02 06:33 - 00000000 ____D C:\Windows\registration
2012-04-06 12:29 - 2008-04-10 03:26 - 00000000 ____D C:\Windows\SMINST
2012-04-06 12:27 - 2012-04-06 12:27 - 00000732 ____A C:\Users\Leave Me Alone\AppData\Local\d3d9caps64.dat
2012-04-03 01:22 - 2012-05-10 05:49 - 04699520 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2012-04-02 06:59 - 2012-05-10 05:49 - 02766848 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-03-30 16:00 - 2012-03-30 16:00 - 00000000 ____D C:\Users\Leave Me Alone\AppData\Roaming\Arduino
2012-03-30 05:45 - 2012-05-10 05:50 - 01423744 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-03-20 16:34 - 2012-05-10 05:49 - 00072576 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\partmgr.sys
2012-03-19 01:34 - 2011-08-15 04:10 - 00076912 ____A C:\Users\Leave Me Alone\AppData\Local\GDIPFONTCACHEV1.DAT
2012-03-13 16:25 - 2011-08-24 05:59 - 00794074 ____A C:\Windows\SysWOW64\PerfStringBackup.INI


========================= Known DLLs (Whitelisted) ============


========================= Bamital & volsnap Check ============

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe
[2011-08-21 02:23] - [2009-04-11 00:10] - 0384512 ____A (Microsoft Corporation) 934E0B7D77FF78C18D9F8891221B6DE3

C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: <===== ATTENTION!
HKLM\...\exefile\DefaultIcon: <===== ATTENTION!
HKLM\...\exefile\open\command: <===== ATTENTION!

========================= Memory info ======================

Percentage of memory in use: 38%
Total physical RAM: 3836.9 MB
Available physical RAM: 2367.51 MB
Total Pagefile: 7878.32 MB
Available Pagefile: 6225.91 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB

======================= Partitions =========================

1 Drive c: () (Fixed) (Total:222.04 GB) (Free:93.89 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
2 Drive d: (HP_RECOVERY) (Fixed) (Total:10.85 GB) (Free:1.82 GB) NTFS
4 Drive f: () (Removable) (Total:0.12 GB) (Free:0.12 GB) FAT

Disk ### Status Size Free Dyn Gpt
-------- ---------- ------- ------- --- ---
Disk 0 Online 233 GB 1024 KB
Disk 1 Online 121 MB 0 B

Partitions of Disk 0:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 222 GB 32 KB
Partition 2 Primary 11 GB 222 GB

======================================================================================================

Disk: 0
Partition 1
Type : 07
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 1 C NTFS Partition 222 GB Healthy System (partition with boot components)

======================================================================================================

Disk: 0
Partition 2
Type : 07
Hidden: No
Active: No

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 2 D HP_RECOVERY NTFS Partition 11 GB Healthy

======================================================================================================

Partitions of Disk 1:
===============

Partition ### Type Size Offset
------------- ---------------- ------- -------
Partition 1 Primary 120 MB 16 KB

======================================================================================================

Disk: 1
Partition 1
Type : 06
Hidden: No
Active: Yes

Volume ### Ltr Label Fs Type Size Status Info
---------- --- ----------- ----- ---------- ------- --------- --------
* Volume 3 F FAT Removable 120 MB Healthy

======================================================================================================

==========================================================

Last Boot: 2012-06-09 13:40

======================= End Of Log ==========================

Edited by ligadeo, 10 June 2012 - 04:24 PM.

  • 0

Advertisements


#2
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
Hi, ligadeo! Posted ImageMy nick name is CompCav and I will be assisting you with your Malware/Security problems. Please make sure you read all of the instructions and fixes thoroughly before continuing with them. If you have any questions or you are unsure about anything, just ask and I will help you out. :)

If you have resolved the issues you were originally experiencing, or have received help elsewhere, please let me know so that this topic can be closed.


Please make sure you are saving and printing the instructions out prior to each fix, this way you will have them on hand just in case you are unable to access this site. One of the steps I will be asking you to do requires you to boot into Safe Mode and this process will be much easier for you to perform if the instructions are printed out for you to follow.

If you are ready to get started, please review and follow these guidelines so that we resolve your issues in a timely and effective manner:
  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instructions that I give you. Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. These instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. However, the one thing that you should always do, is to make sure your anti-virus definitions are up-to-date!
  • Please do not use the Attachment feature for any log file. Just do a Copy/Paste of the entire contents of the log file inside your post and submit.
  • You must reply within four days failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. PM me only if I have not responded to your last post in 2 days.
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to ultimately reformat your hard drive and reinstall the operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Please have the software and storage media for backing up your data available.

Step 1.

Download aswMBR.exe ( 1.8mb ) to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan

Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply

Posted Image

If it does not run rename it iexplore.exe and try it again.


Step 2.

Please delete your current copy of OTL and follow these directions to get a current copy ot OTL.

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select Scan All Users
  • Select Lop Check and Purity Check
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT /s
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS /s
    hklm\software\clients\startmenuinternet|command /rs
    hklm\software\clients\startmenuinternet|command /64 /rs
    C:\Windows\assembly\tmp\U\*.* /s
    C:\Program Files\Common Files\ComObjects\*.* /s
    C:\windows\*. /RP /s
    %Temp%\smtmp\1\*.*
    %Temp%\smtmp\2\*.*
    %Temp%\smtmp\3\*.*
    %Temp%\smtmp\4\*.*
    >C:\commands.txt echo list vol /raw /hide /c
    /wait
    >C:\DiskReport.txt diskpart /s C:\commands.txt /raw /hide /c
    /wait
    type c:\diskreport.txt /c
    /wait
    erase c:\commands.txt /hide /c
    /wait
    erase c:\diskreport.txt /hide /c
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs


Step 3.

Please post:

aswMBR log
OTL.txt
Extras.txt


Give me an update on your computer's issues.
  • 0

#3
CompCav

CompCav

    Member 5k

  • Expert
  • 12,448 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP