Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Virtumonde.dll infection


  • Please log in to reply

#16
saleenboy87146

saleenboy87146

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
fixlog:


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-10-2013
Ran by User at 2013-10-11 17:23:56 Run:1
Running from C:\Users\User\Downloads
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
*****************

HKLM\SOFTWARE\Policies\Google => Key deleted successfully.

==== End of Fixlog ====
  • 0

Advertisements


#17
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP
Clear the Java Cache by following the instructions on
http://www.java.com/...lugin_cache.xml

You do not have the latest Java.
First go into Control Panel, Add/Remove Software (XP) or Programs and Features (Vista/Win 7) and remove any old versions (which may call themselves: Java Runtime, Runtime Environment, Runtime, JRE, Java Virtual Machine, Virtual Machine, Java VM, JVM, VM, J2RE, J2SE)
I see:
Java™ 6 Update 37

Java has been very vulnerable to infection so unless you absolutely need it you should not reinstall it.

If you feel you must have Java:
Get the latest Java at:
http://www.java.com/en/

Save it to your PC then close all browsers and install it. Do not let it install the yahoo toolbar or other foistware.
Once installed, go into Control Panel, Java, Security and set the slider to the Highest then OK.


I would dump Microsoft Security Essentials and install the free Avast.


Download and Save the free Avast installer.
http://www.avast.com...ivirus-download
Be careful when downloading. They have started trying to get you to download Chrome and/or Google Toolbar so make sure you uncheck them first.

Uninstall Microsoft Security Essentials
If you have problems uninstalling see: http://support.micro....com/kb/2435760

Reboot

Install Avast by right clicking and Run As Admin. (Register when it asks you - they will try to talk you in to buying the full product but the free version is what we want.) Once you get it installed and updated then before you go to bed tonight:


First mute the speakers so it won't wake you up when Windows loads. Click on the Orange ball. Click on Security. Click on AntiVirus. Scroll down to the bottom and find Boot-time scan. Click on Settings. Where it says Heuristic Sensitivity click on the last rectangle so that all of them are orange and it says High. Then change When a threat is found ... to: Move to Chest. OK. Now click on Schedule Now. Close the Avast window and then reboot. The scan will start and can take up to 7 hours. It will tell you where it will save the report. Usually it's
C:\ProgramData\AVAST Software\Avast\report\aswBoot.txt but it might change so verify the location. When Windows loads Click on the Orange Ball then Maintenance then Scan Logs. Click on the Boot-time scan log and then View Results. If it found anything then open the saved Report and copy and paste the text into a reply so I can see it.

Ron
  • 0

#18
saleenboy87146

saleenboy87146

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
Avast log:

10/11/2013 17:50
Scan of all local drives

File C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-A95000000001}\Data1.cab|>AcroRd32.exe is infected by Win32:Dropper-gen [Drp], Moved to chest
File C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NGNKB4GW\Game schedule3[1].docx|>docProps\core.xml Error 42125 {ZIP archive is corrupted.}
File C:\Users\User\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\Quarantine\quarantine.db|>data Error 42125 {ZIP archive is corrupted.}
File C:\Users\User\Downloads\BestCodecsPackSetup.exe is infected by Win32:InstallBrain-V [PUP], Moved to chest
File C:\Users\User\Downloads\RegCleanPro.exe is infected by Win32:Installer-I [PUP], Moved to chest
File C:\Users\User\Downloads\setup.exe|>{tmp}\Lucky-Savings.exe|>$INSTDIR\LuckySavings.exe|>[Embedded_I#0045ec]|>$PLUGINSDIR\mixer.exe is infected by Win32:Crossrider-C [PUP], Moved to chest
File C:\TDSSKiller_Quarantine\11.10.2013_17.14.33\tdlfs0000\tsk0009.dta is infected by MBR:Alureon-B [Rtk], Moved to chest
File C:\TDSSKiller_Quarantine\16.08.2012_20.56.31\mbr0000\tdlfs0000\tsk0009.dta is infected by MBR:Alureon-B [Rtk], Moved to chest
File C:\Windows\servicing\Packages\Microsoft-Windows-VirtualPC-USB-RPM-Package~31bf3856ad364e35~x86~~6.1.7601.17514.cat Error 0xC000003E {Data Error}
File C:\Windows\temp\avast_ash\iTunes (32 Bit)\BIT1729.tmp|>iTunes.msi|>iTunes.cab|>CoreFP.dll Error 42127 {CAB archive is corrupted.}
File C:\Windows\temp\avast_ash\iTunes (32 Bit)\BIT1729.tmp|>iTunes.msi|>iTunes.cab Error 42144 {OLE archive is corrupted.}
File C:\Windows\temp\avast_ash\iTunes (32 Bit)\BIT1729.tmp|>iTunes.msi Error 42127 {CAB archive is corrupted.}
File C:\Windows\winsxs\Manifests\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16443_none_1a54f6f7bc27cdeb.manifest Error 0xC000003E {Data Error}
File C:\Windows\winsxs\x86_taskschedulersettings_31bf3856ad364e35_6.1.7600.16385_none_4ac159ed65b079f7\taskschd.msc Error 0xC000003E {Data Error}
File C:\Windows\System32\taskschd.msc Error 0xC000003E {Data Error}
File C:\Windows\System32\wbem\AutoRecover\75054C3771DF289038069A9BB1C1FB6E.mof Error 0xC000003E {Data Error}
File C:\Program Files\ArcSoft\WebCam Companion 3\uTemplateParser.dll Error 0xC000003E {Data Error}
File C:\Program Files\Common Files\Adobe\Adobe Photoshop CS5.1\AMT_Driver\es_ES\license.html Error 0xC000003E {Data Error}
File C:\Program Files\Common Files\microsoft shared\OFFICE12\ACECORE.DLL Error 0xC000003E {Data Error}
File C:\Program Files\Common Files\microsoft shared\OFFICE12\ACEREP.DLL Error 0xC000003E {Data Error}
File C:\Program Files\Microsoft Office\Office12\ONBttnOL.dll Error 0xC000003E {Data Error}
File C:\Program Files\epson\escndv\es00b9\escore.cab|>Epjpg.dll Error 42127 {CAB archive is corrupted.}
File C:\Program Files\epson\escndv\es00b9\escore.cab Error 0xC000003E {Data Error}
Number of searched folders: 25439
Number of tested files: 629778
Number of infected files: 6
  • 0

#19
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP
Looks like Avast ran a lot quicker than it does on my PC. It did find a few items is I guess it was worth it.

How is it running now?
  • 0

#20
saleenboy87146

saleenboy87146

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
Ron,

Computer seems to be running good now. I will run malwarebytes and spybot again to make sure that they run all the way through, since that was my first indication that something major was wrong.

The only other thing that I have going on now is I have a bunch of little pink squares all over my screen. This wasn't the case last Sunday when I started looking at the computer. I am assuming a setting or a driver got messed up. I tried installing the lenova update software and the computer said I didn't have the administrative rights to do this. This is weird also because I know I had installed it previously on this computer, but I do not see it in the list of programs on the start menu.

The pink dots are giving me headache, LOL.


Otherwise thanks for all your help so far.


Scott
  • 0

#21
saleenboy87146

saleenboy87146

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
update: If I use the search field on the start menu, I find the lenova updater, but when I try to run it, it says that "system update has detected a serious problem loading language files...."
  • 0

#22
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP
Copy the following:

:Commands
[CLEARALLRESTOREPOINTS]
[Reboot]

Right click on OTL and Run As Administrator. In the Custom Scans/Fixes box at the bottom, paste in the copied text (Ctrl + v) and then hit Run Fix.

That will get the last of the malware off the system.

Then let's check for damage:


Right click on (My) Computer and select Manage (Continue) Then click on the arrow in front of Event Viewer. Next Click on the arrow in front of Windows Logs Right click on System and Clear Log, Clear. Repeat for Application.

Reboot.

Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator. Then type (with an Enter after each line).
sfc  /scannow

(This will check your critical system files. Does this finish without complaint? IF it says it couldn't fix everything then:

Copy the next two lines:

findstr /c:"[SR]" \windows\logs\cbs\cbs.log > \windows\logs\cbs\junk.txt
notepad \windows\logs\cbs\junk.txt

Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue. Right click and Paste or Edit then Paste and the copied line should appear.
Hit Enter. Copy and paste the text from notepad or if it is too big, just attach the file.)


Next do:


1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application.

I wonder if the pink dots show up on a screen capture:

Press the Alt + the Print Screen key on your keyboard. It may be labeled [PrtScn].

Open Microsoft Paint (All Programs, Accessories,Paint).

Go to the Edit menu and choose Paste (or just do Ctrl + v) and the image should appear.


Go to the File Menu and choose Save As.

Navigate to the folder where you want to save the image. (Desktop)

Type a file name for the image: Screen

Select a file type. jpeg

Click the Save button.

Attach Screen.jpg to your Reply.

(Start a Reply. Click on the Browse button, point it at your desktop and click on scree.jpg then Open. Now click on Attach this File)

Let's also run Process Explorer:

Get Process Explorer

http://live.sysinter...com/procexp.exe
Save it to your desktop then run it (Vista or Win7 - right click and Run As Administrator).

View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures


Click twice on the CPU column header to sort things by CPU usage with the big hitters at the top.

Wait a full minute then:

File, Save As, Save. Open the file Procexp.txt on your desktop and copy and paste the text to a reply.
  • 0

#23
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP
Also: What make and model is the PC?
  • 0

#24
saleenboy87146

saleenboy87146

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
Tried running the sfc /scnnow, got to 70% verification and stopped.


Here is the log from next step.


2013-10-12 15:56:56, Info CSI 00000009 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:56:56, Info CSI 0000000a [SR] Beginning Verify and Repair transaction
2013-10-12 15:57:23, Info CSI 0000000c [SR] Verify complete
2013-10-12 15:57:23, Info CSI 0000000d [SR] Verifying 100 (0x00000064) components
2013-10-12 15:57:23, Info CSI 0000000e [SR] Beginning Verify and Repair transaction
2013-10-12 15:57:37, Info CSI 00000010 [SR] Verify complete
2013-10-12 15:57:37, Info CSI 00000011 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:57:37, Info CSI 00000012 [SR] Beginning Verify and Repair transaction
2013-10-12 15:57:57, Info CSI 00000014 [SR] Verify complete
2013-10-12 15:57:57, Info CSI 00000015 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:57:57, Info CSI 00000016 [SR] Beginning Verify and Repair transaction
2013-10-12 15:58:03, Info CSI 00000018 [SR] Verify complete
2013-10-12 15:58:04, Info CSI 00000019 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:58:04, Info CSI 0000001a [SR] Beginning Verify and Repair transaction
2013-10-12 15:58:10, Info CSI 0000001c [SR] Verify complete
2013-10-12 15:58:10, Info CSI 0000001d [SR] Verifying 100 (0x00000064) components
2013-10-12 15:58:10, Info CSI 0000001e [SR] Beginning Verify and Repair transaction
2013-10-12 15:58:14, Info CSI 00000020 [SR] Verify complete
2013-10-12 15:58:15, Info CSI 00000021 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:58:15, Info CSI 00000022 [SR] Beginning Verify and Repair transaction
2013-10-12 15:58:20, Info CSI 00000024 [SR] Verify complete
2013-10-12 15:58:21, Info CSI 00000025 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:58:21, Info CSI 00000026 [SR] Beginning Verify and Repair transaction
2013-10-12 15:58:27, Info CSI 00000028 [SR] Verify complete
2013-10-12 15:58:28, Info CSI 00000029 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:58:28, Info CSI 0000002a [SR] Beginning Verify and Repair transaction
2013-10-12 15:58:33, Info CSI 0000002c [SR] Verify complete
2013-10-12 15:58:34, Info CSI 0000002d [SR] Verifying 100 (0x00000064) components
2013-10-12 15:58:34, Info CSI 0000002e [SR] Beginning Verify and Repair transaction
2013-10-12 15:58:39, Info CSI 00000030 [SR] Verify complete
2013-10-12 15:58:39, Info CSI 00000031 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:58:39, Info CSI 00000032 [SR] Beginning Verify and Repair transaction
2013-10-12 15:58:46, Info CSI 00000034 [SR] Verify complete
2013-10-12 15:58:46, Info CSI 00000035 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:58:46, Info CSI 00000036 [SR] Beginning Verify and Repair transaction
2013-10-12 15:58:51, Info CSI 00000038 [SR] Verify complete
2013-10-12 15:58:51, Info CSI 00000039 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:58:51, Info CSI 0000003a [SR] Beginning Verify and Repair transaction
2013-10-12 15:58:56, Info CSI 0000003c [SR] Verify complete
2013-10-12 15:58:57, Info CSI 0000003d [SR] Verifying 100 (0x00000064) components
2013-10-12 15:58:57, Info CSI 0000003e [SR] Beginning Verify and Repair transaction
2013-10-12 15:59:04, Info CSI 00000040 [SR] Verify complete
2013-10-12 15:59:04, Info CSI 00000041 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:59:04, Info CSI 00000042 [SR] Beginning Verify and Repair transaction
2013-10-12 15:59:14, Info CSI 00000044 [SR] Verify complete
2013-10-12 15:59:15, Info CSI 00000045 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:59:15, Info CSI 00000046 [SR] Beginning Verify and Repair transaction
2013-10-12 15:59:22, Info CSI 0000004b [SR] Verify complete
2013-10-12 15:59:23, Info CSI 0000004c [SR] Verifying 100 (0x00000064) components
2013-10-12 15:59:23, Info CSI 0000004d [SR] Beginning Verify and Repair transaction
2013-10-12 15:59:33, Info CSI 00000050 [SR] Verify complete
2013-10-12 15:59:33, Info CSI 00000051 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:59:33, Info CSI 00000052 [SR] Beginning Verify and Repair transaction
2013-10-12 15:59:41, Info CSI 00000056 [SR] Verify complete
2013-10-12 15:59:41, Info CSI 00000057 [SR] Verifying 100 (0x00000064) components
2013-10-12 15:59:41, Info CSI 00000058 [SR] Beginning Verify and Repair transaction
2013-10-12 16:00:00, Info CSI 00000062 [SR] Verify complete
2013-10-12 16:00:00, Info CSI 00000063 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:00:00, Info CSI 00000064 [SR] Beginning Verify and Repair transaction
2013-10-12 16:00:10, Info CSI 00000066 [SR] Verify complete
2013-10-12 16:00:11, Info CSI 00000067 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:00:11, Info CSI 00000068 [SR] Beginning Verify and Repair transaction
2013-10-12 16:00:19, Info CSI 0000006a [SR] Verify complete
2013-10-12 16:00:19, Info CSI 0000006b [SR] Verifying 100 (0x00000064) components
2013-10-12 16:00:19, Info CSI 0000006c [SR] Beginning Verify and Repair transaction
2013-10-12 16:00:27, Info CSI 0000006e [SR] Verify complete
2013-10-12 16:00:28, Info CSI 0000006f [SR] Verifying 100 (0x00000064) components
2013-10-12 16:00:28, Info CSI 00000070 [SR] Beginning Verify and Repair transaction
2013-10-12 16:00:37, Info CSI 00000072 [SR] Verify complete
2013-10-12 16:00:37, Info CSI 00000073 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:00:37, Info CSI 00000074 [SR] Beginning Verify and Repair transaction
2013-10-12 16:00:45, Info CSI 00000076 [SR] Verify complete
2013-10-12 16:00:45, Info CSI 00000077 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:00:45, Info CSI 00000078 [SR] Beginning Verify and Repair transaction
2013-10-12 16:00:56, Info CSI 0000007a [SR] Verify complete
2013-10-12 16:00:56, Info CSI 0000007b [SR] Verifying 100 (0x00000064) components
2013-10-12 16:00:56, Info CSI 0000007c [SR] Beginning Verify and Repair transaction
2013-10-12 16:01:11, Info CSI 00000080 [SR] Verify complete
2013-10-12 16:01:11, Info CSI 00000081 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:01:11, Info CSI 00000082 [SR] Beginning Verify and Repair transaction
2013-10-12 16:01:24, Info CSI 00000084 [SR] Verify complete
2013-10-12 16:01:25, Info CSI 00000085 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:01:25, Info CSI 00000086 [SR] Beginning Verify and Repair transaction
2013-10-12 16:01:46, Info CSI 00000088 [SR] Verify complete
2013-10-12 16:01:46, Info CSI 00000089 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:01:46, Info CSI 0000008a [SR] Beginning Verify and Repair transaction
2013-10-12 16:01:59, Info CSI 0000008c [SR] Verify complete
2013-10-12 16:01:59, Info CSI 0000008d [SR] Verifying 100 (0x00000064) components
2013-10-12 16:01:59, Info CSI 0000008e [SR] Beginning Verify and Repair transaction
2013-10-12 16:02:03, Info CSI 00000090 [SR] Verify complete
2013-10-12 16:02:03, Info CSI 00000091 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:02:03, Info CSI 00000092 [SR] Beginning Verify and Repair transaction
2013-10-12 16:02:05, Info CSI 00000094 [SR] Verify complete
2013-10-12 16:02:05, Info CSI 00000095 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:02:05, Info CSI 00000096 [SR] Beginning Verify and Repair transaction
2013-10-12 16:02:13, Info CSI 00000098 [SR] Verify complete
2013-10-12 16:02:13, Info CSI 00000099 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:02:13, Info CSI 0000009a [SR] Beginning Verify and Repair transaction
2013-10-12 16:02:24, Info CSI 000000b8 [SR] Verify complete
2013-10-12 16:02:24, Info CSI 000000b9 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:02:24, Info CSI 000000ba [SR] Beginning Verify and Repair transaction
2013-10-12 16:02:27, Info CSI 000000bc [SR] Verify complete
2013-10-12 16:02:28, Info CSI 000000bd [SR] Verifying 100 (0x00000064) components
2013-10-12 16:02:28, Info CSI 000000be [SR] Beginning Verify and Repair transaction
2013-10-12 16:02:33, Info CSI 000000c0 [SR] Verify complete
2013-10-12 16:02:34, Info CSI 000000c1 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:02:34, Info CSI 000000c2 [SR] Beginning Verify and Repair transaction
2013-10-12 16:02:39, Info CSI 000000c4 [SR] Verify complete
2013-10-12 16:02:39, Info CSI 000000c5 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:02:39, Info CSI 000000c6 [SR] Beginning Verify and Repair transaction
2013-10-12 16:02:51, Info CSI 000000c8 [SR] Verify complete
2013-10-12 16:02:51, Info CSI 000000c9 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:02:51, Info CSI 000000ca [SR] Beginning Verify and Repair transaction
2013-10-12 16:03:04, Info CSI 000000cd [SR] Verify complete
2013-10-12 16:03:05, Info CSI 000000ce [SR] Verifying 100 (0x00000064) components
2013-10-12 16:03:05, Info CSI 000000cf [SR] Beginning Verify and Repair transaction
2013-10-12 16:03:10, Info CSI 000000d1 [SR] Verify complete
2013-10-12 16:03:10, Info CSI 000000d2 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:03:10, Info CSI 000000d3 [SR] Beginning Verify and Repair transaction
2013-10-12 16:03:14, Info CSI 000000d5 [SR] Verify complete
2013-10-12 16:03:15, Info CSI 000000d6 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:03:15, Info CSI 000000d7 [SR] Beginning Verify and Repair transaction
2013-10-12 16:03:27, Info CSI 000000d9 [SR] Verify complete
2013-10-12 16:03:27, Info CSI 000000da [SR] Verifying 100 (0x00000064) components
2013-10-12 16:03:27, Info CSI 000000db [SR] Beginning Verify and Repair transaction
2013-10-12 16:03:36, Info CSI 000000dd [SR] Verify complete
2013-10-12 16:03:37, Info CSI 000000de [SR] Verifying 100 (0x00000064) components
2013-10-12 16:03:37, Info CSI 000000df [SR] Beginning Verify and Repair transaction
2013-10-12 16:03:46, Info CSI 000000e1 [SR] Verify complete
2013-10-12 16:03:47, Info CSI 000000e2 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:03:47, Info CSI 000000e3 [SR] Beginning Verify and Repair transaction
2013-10-12 16:04:04, Info CSI 00000109 [SR] Verify complete
2013-10-12 16:04:05, Info CSI 0000010a [SR] Verifying 100 (0x00000064) components
2013-10-12 16:04:05, Info CSI 0000010b [SR] Beginning Verify and Repair transaction
2013-10-12 16:04:17, Info CSI 0000010d [SR] Verify complete
2013-10-12 16:04:17, Info CSI 0000010e [SR] Verifying 100 (0x00000064) components
2013-10-12 16:04:17, Info CSI 0000010f [SR] Beginning Verify and Repair transaction
2013-10-12 16:04:40, Info CSI 00000111 [SR] Verify complete
2013-10-12 16:04:41, Info CSI 00000112 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:04:41, Info CSI 00000113 [SR] Beginning Verify and Repair transaction
2013-10-12 16:04:54, Info CSI 00000116 [SR] Verify complete
2013-10-12 16:04:54, Info CSI 00000117 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:04:54, Info CSI 00000118 [SR] Beginning Verify and Repair transaction
2013-10-12 16:05:09, Info CSI 0000011a [SR] Verify complete
2013-10-12 16:05:10, Info CSI 0000011b [SR] Verifying 100 (0x00000064) components
2013-10-12 16:05:10, Info CSI 0000011c [SR] Beginning Verify and Repair transaction
2013-10-12 16:05:22, Info CSI 0000011e [SR] Verify complete
2013-10-12 16:05:22, Info CSI 0000011f [SR] Verifying 100 (0x00000064) components
2013-10-12 16:05:22, Info CSI 00000120 [SR] Beginning Verify and Repair transaction
2013-10-12 16:05:30, Info CSI 00000122 [SR] Verify complete
2013-10-12 16:05:30, Info CSI 00000123 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:05:30, Info CSI 00000124 [SR] Beginning Verify and Repair transaction
2013-10-12 16:05:38, Info CSI 00000126 [SR] Verify complete
2013-10-12 16:05:39, Info CSI 00000127 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:05:39, Info CSI 00000128 [SR] Beginning Verify and Repair transaction
2013-10-12 16:05:48, Info CSI 0000012b [SR] Verify complete
2013-10-12 16:05:48, Info CSI 0000012c [SR] Verifying 100 (0x00000064) components
2013-10-12 16:05:48, Info CSI 0000012d [SR] Beginning Verify and Repair transaction
2013-10-12 16:06:09, Info CSI 0000012f [SR] Verify complete
2013-10-12 16:06:09, Info CSI 00000130 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:06:09, Info CSI 00000131 [SR] Beginning Verify and Repair transaction
2013-10-12 16:06:21, Info CSI 00000134 [SR] Verify complete
2013-10-12 16:06:22, Info CSI 00000135 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:06:22, Info CSI 00000136 [SR] Beginning Verify and Repair transaction
2013-10-12 16:06:30, Info CSI 00000138 [SR] Verify complete
2013-10-12 16:06:30, Info CSI 00000139 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:06:30, Info CSI 0000013a [SR] Beginning Verify and Repair transaction
2013-10-12 16:06:40, Info CSI 0000013c [SR] Verify complete
2013-10-12 16:06:41, Info CSI 0000013d [SR] Verifying 100 (0x00000064) components
2013-10-12 16:06:41, Info CSI 0000013e [SR] Beginning Verify and Repair transaction
2013-10-12 16:06:59, Info CSI 00000141 [SR] Verify complete
2013-10-12 16:06:59, Info CSI 00000142 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:06:59, Info CSI 00000143 [SR] Beginning Verify and Repair transaction
2013-10-12 16:07:11, Info CSI 00000145 [SR] Verify complete
2013-10-12 16:07:11, Info CSI 00000146 [SR] Verifying 100 (0x00000064) components
2013-10-12 16:07:11, Info CSI 00000147 [SR] Beginning Verify and Repair transaction
2013-10-12 16:07:20, Info CSI 00000149 [SR] Verify complete
2013-10-12 16:07:20, Info CSI 0000014a [SR] Verifying 100 (0x00000064) components
2013-10-12 16:07:20, Info CSI 0000014b [SR] Beginning Verify and Repair transaction
2013-10-12 16:07:32, Info CSI 0000014d [SR] Verify complete
2013-10-12 16:07:33, Info CSI 0000014e [SR] Verifying 100 (0x00000064) components
2013-10-12 16:07:33, Info CSI 0000014f [SR] Beginning Verify and Repair transaction
  • 0

#25
saleenboy87146

saleenboy87146

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
event viewr log: system



Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 12/10/2013 4:34:05 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 12/10/2013 9:16:07 PM
Type: Error Category: 0
Event: 9 Source: iaStor
The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Log: 'System' Date/Time: 12/10/2013 9:15:47 PM
Type: Error Category: 0
Event: 9 Source: iaStor
The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Log: 'System' Date/Time: 12/10/2013 9:15:20 PM
Type: Error Category: 0
Event: 9 Source: iaStor
The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Log: 'System' Date/Time: 12/10/2013 9:14:52 PM
Type: Error Category: 0
Event: 9 Source: iaStor
The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Log: 'System' Date/Time: 12/10/2013 9:14:03 PM
Type: Error Category: 0
Event: 9 Source: iaStor
The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Log: 'System' Date/Time: 12/10/2013 9:13:12 PM
Type: Error Category: 0
Event: 9 Source: iaStor
The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Log: 'System' Date/Time: 12/10/2013 9:13:05 PM
Type: Error Category: 0
Event: 9 Source: iaStor
The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Log: 'System' Date/Time: 12/10/2013 9:12:13 PM
Type: Error Category: 0
Event: 9 Source: iaStor
The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Log: 'System' Date/Time: 12/10/2013 9:10:45 PM
Type: Error Category: 0
Event: 9 Source: iaStor
The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Log: 'System' Date/Time: 12/10/2013 9:10:05 PM
Type: Error Category: 0
Event: 9 Source: iaStor
The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Log: 'System' Date/Time: 12/10/2013 9:09:37 PM
Type: Error Category: 0
Event: 9 Source: iaStor
The device, \Device\Ide\iaStor0, did not respond within the timeout period.

Log: 'System' Date/Time: 12/10/2013 8:55:32 PM
Type: Error Category: 0
Event: 14332 Source: Microsoft-Windows-WMPNSS-Service
Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 12/10/2013 8:53:42 PM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WUDFRd failed to load for the device USB\VID_0483&PID_2016\5&37c8a9dc&0&2.

Log: 'System' Date/Time: 12/10/2013 8:52:56 PM
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped.
  • 0

Advertisements


#26
saleenboy87146

saleenboy87146

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
event viewr log: Application

Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 12/10/2013 4:37:07 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 12/10/2013 8:52:53 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-2033630711-3411533705-1815766804-1000:
Process 764 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2033630711-3411533705-1815766804-1000
Process 764 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2033630711-3411533705-1815766804-1000
Process 764 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2033630711-3411533705-1815766804-1000\Software\Microsoft\SystemCertificates\My
Process 764 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2033630711-3411533705-1815766804-1000\Software\Microsoft\SystemCertificates\CA
Process 764 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2033630711-3411533705-1815766804-1000\Software\Microsoft\SystemCertificates\Disallowed
  • 0

#27
saleenboy87146

saleenboy87146

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
screen shot of pink dots attached

Attached Thumbnails

  • Pink Dots.jpg

  • 0

#28
saleenboy87146

saleenboy87146

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
by the way, I am using a lenova thinkpad t60 with windows 7
  • 0

#29
saleenboy87146

saleenboy87146

    Member

  • Topic Starter
  • Member
  • PipPip
  • 66 posts
process explorer log:


Process CPU Private Bytes Working Set PID Description Company Name Verified Signer
ACDaemon.exe 2,128 K 6,252 K 2660 ArcSoft Connect Daemon ArcSoft Inc. (Verified) ArcSoft
ACService.exe 864 K 3,028 K 2536 ArcSoft Connect Service ArcSoft Inc. (Verified) ArcSoft
AEADISRV.EXE 616 K 2,408 K 2596 Andrea filters APO access service (32-bit) Andrea Electronics Corporation (No signature was present in the subject) Andrea Electronics Corporation
armsvc.exe 816 K 2,944 K 2572 Adobe Acrobat Update Service Adobe Systems Incorporated (Verified) Adobe Systems
Ati2evxx.exe 1,064 K 3,696 K 1052 ATI External Event Utility EXE Module ATI Technologies Inc. (Verified) Microsoft Windows Hardware Compatibility Publisher
Ati2evxx.exe 1,912 K 6,212 K 1456 ATI External Event Utility EXE Module ATI Technologies Inc. (Verified) Microsoft Windows Hardware Compatibility Publisher
audiodg.exe 13,956 K 13,664 K 5476 Windows Audio Device Graph Isolation Microsoft Corporation (Verified) Microsoft Windows
chrome.exe 39,988 K 67,968 K 3668 Google Chrome Google Inc. (Verified) Google Inc
chrome.exe 40,844 K 69,772 K 804 Google Chrome Google Inc. (Verified) Google Inc
chrome.exe 43,692 K 103,116 K 4504 Google Chrome Google Inc. (Verified) Google Inc
chrome.exe 24,872 K 54,264 K 3992 Google Chrome Google Inc. (Verified) Google Inc
GrooveMonitor.exe 2,776 K 7,132 K 3508 GrooveMonitor Utility Microsoft Corporation (Verified) Microsoft Corporation
ibmpmsvc.exe 964 K 2,920 K 944 Lenovo Power Management Service Lenovo. (Verified) LENOVO(JAPAN)LTD.
lsm.exe 1,504 K 3,200 K 772 Local Session Manager Service Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
lvvsst.exe 1,400 K 4,536 K 3124 Auto Scroll Start Service Lenovo Group Limited (Verified) Lenovo(Japan)Ltd.
mbamscheduler.exe 1,976 K 5,216 K 3176 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
mbamservice.exe 102,488 K 3,344 K 3276 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
notepad.exe 1,424 K 7,464 K 1840 Notepad Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
PresentationFontCache.exe 11,976 K 9,236 K 2812 PresentationFontCache.exe Microsoft Corporation (Verified) Microsoft Windows
rundll32.exe 3,864 K 11,288 K 3112 Windows host process (Rundll32) Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
SCHTASK.EXE 2,384 K 4,876 K 4236 Power Manager Power Agenda Lenovo Group Limited (Verified) Lenovo(Japan)Ltd.
SeaPort.EXE 3,792 K 7,820 K 3348 Microsoft SeaPort Search Enhancement Broker Microsoft Corporation (Verified) Microsoft Corporation
services.exe 4,840 K 7,416 K 752 Services and Controller app Microsoft Corporation (Verified) Microsoft Windows
smax4pnp.exe 6,064 K 5,932 K 3788 SMax4PNP Analog Devices, Inc. (Verified) Microsoft Windows Hardware Compatibility Publisher
smss.exe 256 K 816 K 492 Windows Session Manager Microsoft Corporation (Verified) Microsoft Windows
spoolsv.exe 6,264 K 10,448 K 740 Spooler SubSystem App Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
svchost.exe 1,408 K 4,720 K 3436 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
svchost.exe 2,720 K 7,428 K 4840 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
svchost.exe 1,992 K 4,428 K 1356 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
svchost.exe 1,768 K 4,464 K 2328 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
svchost.exe 2,868 K 6,864 K 872 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 15,152 K 15,956 K 1164 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
svchost.exe 31,516 K 16,660 K 4388 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
SynTPHelper.exe 604 K 532 K 2884 Synaptics Pointing Device Helper Synaptics Incorporated (Verified) Synaptics Incorporated
SynTPLpr.exe 1,140 K 532 K 4152 TouchPad Driver Helper Application Synaptics Incorporated (Verified) Microsoft Windows Hardware Compatibility Publisher
taskeng.exe 1,364 K 4,768 K 2056 Task Scheduler Engine Microsoft Corporation (Verified) Microsoft Windows
tphkload.exe 1,668 K 4,936 K 1788 ThinkPad Message Client Loader Lenovo Group Limited (Verified) Lenovo(Japan)Ltd.
TPHKSVC.exe 1,952 K 5,400 K 1952 On screen display Fn+Fx handler Lenovo Group Limited (Verified) Lenovo(Japan)Ltd.
TPONSCR.exe 2,048 K 6,028 K 2292 On screen display drawer Lenovo Group Limited (Verified) Lenovo(Japan)Ltd.
TpScrex.exe 2,220 K 5,456 K 2332 ThinkPad UltraZoom Lenovo Group Limited (Verified) Lenovo(Japan)Ltd.
upeksvr.exe 2,552 K 8,388 K 1764 Fingerprint Server Process for Vista UPEK Inc. (Verified) UPEK Inc.
VM331_STI.EXE 1,232 K 4,232 K 1812 VM331 StiMnt Vimicro (Verified) Microsoft Windows Hardware Compatibility Publisher
wininit.exe 996 K 3,420 K 648 Windows Start-Up Application Microsoft Corporation (Verified) Microsoft Windows
winlogon.exe 2,328 K 6,384 K 712 Windows Logon Application Microsoft Corporation (Verified) Microsoft Windows
WLIDSVCM.EXE 640 K 2,344 K 3688 Microsoft® Windows Live ID Service Monitor Microsoft Corp. (Verified) Microsoft Corporation
WmiPrvSE.exe 2,136 K 5,032 K 3420 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
wuauclt.exe 1,612 K 5,264 K 5768 Windows Update Microsoft Corporation (Verified) Microsoft Windows Component Publisher
WUDFHost.exe 2,128 K 4,532 K 1500 Windows Driver Foundation - User-mode Driver Framework Host Process Microsoft Corporation (Verified) Microsoft Windows
EPCP.exe < 0.01 3,444 K 6,528 K 2776 Epson Customer Participation SEIKO EPSON CORPORATION (Verified) SEIKO EPSON Corporation
SynTPEnh.exe < 0.01 8,112 K 972 K 2132 Synaptics TouchPad Enhancements Synaptics Incorporated (Verified) Microsoft Windows Hardware Compatibility Publisher
WLIDSVC.EXE 0.01 4,568 K 10,920 K 3532 Microsoft® Windows Live ID Service Microsoft Corp. (Verified) Microsoft Corporation
svchost.exe 0.01 13,452 K 13,436 K 1576 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
csrss.exe 0.01 1,340 K 3,520 K 588 Client Server Runtime Process Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
mbamgui.exe 0.01 2,368 K 6,424 K 3356 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
taskhost.exe 0.01 6,068 K 9,312 K 764 Host Process for Windows Tasks Microsoft Corporation (Verified) Microsoft Windows
XAudio.exe 0.01 664 K 2,332 K 3584 Modem Audio Service Conexant Systems, Inc. (Verified) Microsoft Windows Hardware Compatibility Publisher
SASCore.exe 0.01 688 K 2,748 K 2492 Core Service SUPERAntiSpyware.com (Verified) SUPERAntiSpyware.com
eEBSvc.exe 0.01 3,340 K 5,580 K 2172 eEBAPI Core Process module SEIKO EPSON CORPORATION (No signature was present in the subject) SEIKO EPSON CORPORATION
wmpnetwk.exe 0.02 10,456 K 8,352 K 4116 Windows Media Player Network Sharing Service Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 0.02 8,336 K 13,728 K 1228 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
svchost.exe 0.03 6,320 K 11,724 K 4580 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
SearchIndexer.exe 0.04 18,608 K 10,720 K 3232 Microsoft Windows Search Indexer Microsoft Corporation (Verified) Microsoft Windows
svchost.exe 0.04 73,424 K 80,436 K 1196 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
TpShocks.exe 0.05 908 K 3,336 K 3896 ThinkVantage Active Protection System Lenovo. (No signature was present in the subject) Lenovo.
svchost.exe 0.05 3,028 K 5,900 K 1004 Host Process for Windows Services Microsoft Corporation (Verified) Microsoft Windows
AvastUI.exe 0.05 7,944 K 5,836 K 2728 avast! Antivirus AVAST Software (Verified) AVAST Software
AvastSvc.exe 0.07 32,196 K 3,428 K 1752 avast! Service AVAST Software (Verified) AVAST Software
TPOSDSVC.exe 0.09 6,280 K 6,888 K 2200 On screen display message generator for ThinkPad Lenovo Group Limited (Verified) Lenovo(Japan)Ltd.
AppleMobileDeviceService.exe 0.13 2,612 K 8,228 K 2624 MobileDeviceService Apple Inc. (Verified) Apple Inc.
explorer.exe 0.25 66,764 K 99,116 K 2696 Windows Explorer Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
lsass.exe 0.51 5,644 K 13,272 K 760 Local Security Authority Process Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
svchost.exe 0.71 16,972 K 29,732 K 1260 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
virtscrl.exe 0.83 1,656 K 5,496 K 3196 Lenovo Auto Scroll Utility Lenovo Group Limited (Verified) Lenovo(Japan)Ltd.
csrss.exe 0.84 7,840 K 12,020 K 660 Client Server Runtime Process Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
svchost.exe 1.03 12,620 K 14,152 K 1888 Host Process for Windows Services Microsoft Corporation (No signature was present in the subject) Microsoft Corporation
System 2.24 60 K 5,228 K 4
Interrupts 3.92 0 K 0 K n/a Hardware Interrupts and DPCs
dwm.exe 5.36 35,464 K 70,888 K 2684 Desktop Window Manager Microsoft Corporation (Verified) Microsoft Windows
procexp.exe 15.86 25,368 K 47,012 K 4448 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
System Idle Process 67.78 0 K 24 K 0
  • 0

#30
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP
Looks like a bad video driver. If you boot into the Safe mode menu and choose the Low Resolution Video option do you get the pink spots?

(Reboot and when you see the maker's logo, hear a beep or it talks about F8, start tapping the F8 key slowly. Keep tapping until the Safe Mode Menu appears and choose Low Resolution Video option. Login with your usual login.)

Turns out I need a 4 digit number to identify Your Lenovo exactly. Should be on a Lenovo sticker on the bottom of the laptop.
It should be safe to update the Intel Chipset Support:

http://support.lenov...?DocID=DS014952

You want the one called: Intel Chipset Support (WW)

Download, Save and right click on it and then Run As Admin.

I think we also need the Windows Repair All In one:


http://www.tweaking....all_in_one.html

Download it and save it then run it by right clicking and Run As Admin.

You can skip to step 4 or 5 where it gives you the same picture as in the above link.

Make sure all of these are checked before hitting Start:

Reset Registry Permissions
Reset File Permissions
Register System Files
Repair WMI
Repair Windows Firewall
Repair Internet Explorer
Repair MDAC & MS Jet
Repair Hosts File
Remove Policies Set By Infections
Repair Icons
Repair Winsock & DNS Cache
Remove Temp Files
Repair Proxy Settings
Unhide Non System Files
Repair Windows Updates
Repair CD/DVD Missing/Not Working

Reboot when done and run VEW again as before.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP