Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Help me get rid of Winfixer [RESOLVED]


  • This topic is locked This topic is locked

#1
floydian13

floydian13

    New Member

  • Member
  • Pip
  • 4 posts
I keep getting annoying pop-ups from winfixer, searc-h, party-poker, etc.
I've tried getting rid of them using lava-soft adaware, avg, symantec. And they still keep coming back. What the heck can i do?


Logfile of HijackThis v1.99.1
Scan saved at 5:11:39 PM, on 8/10/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGWB.DAT
C:\HJT\UNWISE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://webproxy.ucsd.edu/proxy.pl
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Program Files\Netscape\Users\marc\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX (file missing)
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Logitech Utility] LOGI_MWX.EXE
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [rtvscn95] C:\PROGRA~1\SYMANT~1\SYMANT~1\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\PROGRA~1\SYMANT~1\SYMANT~1\defwatch.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O16 - DPF: Yahoo! MLB StatTracker - http://aud9.sports.y...mlbst8286_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.game...s/y/mjst4_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: Yahoo! Literati - http://download.game...nts/y/tt3_x.cab
O16 - DPF: Yahoo! Graffiti - http://download.game...ts/y/grt5_x.cab
O16 - DPF: JT's Blocks - http://download.game...ts/y/blt1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.game...ts/y/pote_x.cab
O16 - DPF: Yahoo! Dots - http://download.game...ts/y/dtt1_x.cab
O16 - DPF: Yahoo! Bingo - http://download.game...nts/y/xt0_x.cab
O16 - DPF: Yahoo! Klondike Solitaire - http://presence.game...og/y/ks12_x.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v6.cab
  • 0

Advertisements


#2
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Welcome to GTG.

Download Nailfix Utility at http://www.noidea.us...050711214630636 Save it to your desktop. Do NOT run it yet.

Download dsrfix.zip http://www.atribune....oads/dsrfix.zip and save it to your desktop. Unzip the dsrfix.zip contents to your desktop. This will create a new folder on your desktop named dsrfix. Do NOT open that folder yet.

Download CleanUp! http://cleanup.stevengould.org/ (Alternate Link if main link don't work - http://www.greyknigh...spy/CleanUp.exe ) and install it. Don't run it yet.

Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work.

Once in Safe Mode, double click on nailfix.exe.
Click 'Next' in the setup, then make sure 'Run Nailfix' is checked and click 'Finish'.
Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal.

CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp!. Run CleanUp! and click on the Options button. Uncheck 'Scan local drives for temporary files'. Also uncheck those two Newsgroup entries if you don't want to delete them. Click OK and then click on the CleanUp! button. Let it run. After it's done, choose Yes to logoff.

Now open the folder dsrfix on your desktop.
* Double click on dsrfix.bat
* A window will pop up briefly then close, this is normal.

Restart your computer.

Download FindIt's.zip http://forums.net-in...=post&id=142443 to your desktop.

1. Unzip/extract the files to a folder on your desktop.
2. Open the folder. Double click on FindIt's.bat and wait for Notepad to open a text file. It will take a while so please be patient... Note: If you are having problems using FindIt's.bat (16 bit error), copy autoexec.nt from the C:\WINDOWS\repair folder to C:\WINDOWS\system32 folder. Now try running FindIt's.bat.
3. Then post the FindIt's log here along with the HijackThis log.
  • 0

#3
floydian13

floydian13

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
I tried running nalifix in safe mode, but it would not Run because I have windows 98.
  • 0

#4
floydian13

floydian13

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
well i tried:

Windows 98 [Version 4.10.2222]

Current date is Wed 08-10-2005
PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, THERE MIGHT BE LEGIT FILES LISTED AND PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
»»»»»»»»»»»»»»»»»»»»»»»» Todo Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»


»»»»»»»»»»»»»»»»»»»»»»»» aurora Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»


»»»»»»»»»»»»»»»»»»»»»»»» Suspect's »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Dont delete file's in the section without guidance
If any doubt back them up first


»»»»» lagitamate file's can/will show in this section.

»»»»»»»»»»»»»»»»»»»»»»»» Buddy file's »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

»»»»»»»»»»»»»»»»»»»»»»»» SAHAgent Files found »»»»»»»»»»»»»»»»»»»»»»»»»

»»»»»»»»»»»»»»»»»»»»»»»» Misc checks »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


»»»»» Check for Windows\SYSTEM32\cache32_rtneg* folder.


Volume in drive C has no label
Volume Serial Number is 07CF-0C1D
Directory of C:\WINDOWS\SYSTEM32

1,318.13 MB free
»»»»» Checking for SAHAgent ico files.

Volume in drive C has no label
Volume Serial Number is 07CF-0C1D
Directory of C:\WINDOWS\SYSTEM32

1,318.13 MB free

»»»»»»»»»»»»»»»»»»»»»»»».
  • 0

#5
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Please download l2m9xfix at http://www.geekstogo...ds/l2m9xfix.exe

Save it to the desktop and run it. Extract the files. Then open the l2m9xfix folder you just created and run RunThis.bat.

A window will open, and your desktop will disappear, then reappear. Please be patient until the batch says it is completed.

Then restart your computer, and post a new HijackThis log as well as the log.txt file which should be in the same folder as RunThis.bat.
  • 0

#6
floydian13

floydian13

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Seems to be running a bit faster already

Here is Hijack this:

Logfile of HijackThis v1.99.1
Scan saved at 9:08:06 PM, on 8/10/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\HJT\UNWISE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://webproxy.ucsd.edu/proxy.pl
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Program Files\Netscape\Users\marc\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX (file missing)
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Logitech Utility] LOGI_MWX.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\RunServices: [defwatch] C:\PROGRA~1\SYMANT~1\SYMANT~1\defwatch.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [rtvscn95] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\rtvscn95.exe
O16 - DPF: Yahoo! MLB StatTracker - http://aud9.sports.y...mlbst8286_x.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.game...s/y/mjst4_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: Yahoo! Literati - http://download.game...nts/y/tt3_x.cab
O16 - DPF: Yahoo! Graffiti - http://download.game...ts/y/grt5_x.cab
O16 - DPF: JT's Blocks - http://download.game...ts/y/blt1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.game...ts/y/pote_x.cab
O16 - DPF: Yahoo! Dots - http://download.game...ts/y/dtt1_x.cab
O16 - DPF: Yahoo! Bingo - http://download.game...nts/y/xt0_x.cab
O16 - DPF: Yahoo! Klondike Solitaire - http://presence.game...og/y/ks12_x.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.game...aploader_v6.cab


AND LOG.TXT

Log of L2M9XFix v1

************

Running from directory:
C:\WINDOWS\Desktop\l2m9xfix

************

Files found:

C:\WINDOWS\system\afrtl30.dll
C:\WINDOWS\system\afrtl30.dll
C:\WINDOWS\system\afrtl30.dll
C:\WINDOWS\system\afrtl30.dll
C:\WINDOWS\system\COICONFG.DLL
C:\WINDOWS\system\COICONFG.DLL
C:\WINDOWS\system\COICONFG.DLL
C:\WINDOWS\system\COICONFG.DLL
C:\WINDOWS\system\DP7VB.DLL
C:\WINDOWS\system\DP7VB.DLL
C:\WINDOWS\system\DP7VB.DLL
C:\WINDOWS\system\DP7VB.DLL
C:\WINDOWS\system\DRRAWEX.DLL
C:\WINDOWS\system\DRRAWEX.DLL
C:\WINDOWS\system\DRRAWEX.DLL
C:\WINDOWS\system\DRRAWEX.DLL
C:\WINDOWS\system\DU3J.DLL
C:\WINDOWS\system\DU3J.DLL
C:\WINDOWS\system\DU3J.DLL
C:\WINDOWS\system\DU3J.DLL
C:\WINDOWS\system\DUTMSFT3.DLL
C:\WINDOWS\system\DUTMSFT3.DLL
C:\WINDOWS\system\DUTMSFT3.DLL
C:\WINDOWS\system\DUTMSFT3.DLL
C:\WINDOWS\system\DV8VB.DLL
C:\WINDOWS\system\DV8VB.DLL
C:\WINDOWS\system\DV8VB.DLL
C:\WINDOWS\system\DV8VB.DLL
C:\WINDOWS\system\ETSHARED.DLL
C:\WINDOWS\system\ETSHARED.DLL
C:\WINDOWS\system\ETSHARED.DLL
C:\WINDOWS\system\ETSHARED.DLL
C:\WINDOWS\system\FMDB.DLL
C:\WINDOWS\system\FMDB.DLL
C:\WINDOWS\system\FMDB.DLL
C:\WINDOWS\system\FMDB.DLL
C:\WINDOWS\system\HGVMON.DLL
C:\WINDOWS\system\HGVMON.DLL
C:\WINDOWS\system\HGVMON.DLL
C:\WINDOWS\system\HGVMON.DLL
C:\WINDOWS\system\ipctl.dll
C:\WINDOWS\system\ipctl.dll
C:\WINDOWS\system\ipctl.dll
C:\WINDOWS\system\ipctl.dll
C:\WINDOWS\system\IRSTRSA.DLL
C:\WINDOWS\system\IRSTRSA.DLL
C:\WINDOWS\system\IRSTRSA.DLL
C:\WINDOWS\system\IRSTRSA.DLL
C:\WINDOWS\system\IY41_32.DLL
C:\WINDOWS\system\IY41_32.DLL
C:\WINDOWS\system\IY41_32.DLL
C:\WINDOWS\system\IY41_32.DLL
C:\WINDOWS\system\IY_NDI.DLL
C:\WINDOWS\system\IY_NDI.DLL
C:\WINDOWS\system\IY_NDI.DLL
C:\WINDOWS\system\IY_NDI.DLL
C:\WINDOWS\system\LQGIF80N.DLL
C:\WINDOWS\system\LQGIF80N.DLL
C:\WINDOWS\system\LQGIF80N.DLL
C:\WINDOWS\system\LQGIF80N.DLL
C:\WINDOWS\system\lVprxy.dll
C:\WINDOWS\system\lVprxy.dll
C:\WINDOWS\system\lVprxy.dll
C:\WINDOWS\system\lVprxy.dll
C:\WINDOWS\system\MNXML.DLL
C:\WINDOWS\system\MNXML.DLL
C:\WINDOWS\system\MNXML.DLL
C:\WINDOWS\system\MNXML.DLL
C:\WINDOWS\system\MRPIX.DLL
C:\WINDOWS\system\MRPIX.DLL
C:\WINDOWS\system\MRPIX.DLL
C:\WINDOWS\system\MRPIX.DLL
C:\WINDOWS\system\mUpistub.dll
C:\WINDOWS\system\mUpistub.dll
C:\WINDOWS\system\mUpistub.dll
C:\WINDOWS\system\mUpistub.dll
C:\WINDOWS\system\NBFTS.DLL
C:\WINDOWS\system\NBFTS.DLL
C:\WINDOWS\system\NBFTS.DLL
C:\WINDOWS\system\NBFTS.DLL
C:\WINDOWS\system\nlwrsno.dll
C:\WINDOWS\system\nlwrsno.dll
C:\WINDOWS\system\nlwrsno.dll
C:\WINDOWS\system\nlwrsno.dll
C:\WINDOWS\system\ORE32.DLL
C:\WINDOWS\system\ORE32.DLL
C:\WINDOWS\system\ORE32.DLL
C:\WINDOWS\system\ORE32.DLL
C:\WINDOWS\system\OUENGL32.DLL
C:\WINDOWS\system\OUENGL32.DLL
C:\WINDOWS\system\OUENGL32.DLL
C:\WINDOWS\system\OUENGL32.DLL
C:\WINDOWS\system\PMS.DLL
C:\WINDOWS\system\PMS.DLL
C:\WINDOWS\system\PMS.DLL
C:\WINDOWS\system\PMS.DLL
C:\WINDOWS\system\QZAP.DLL
C:\WINDOWS\system\QZAP.DLL
C:\WINDOWS\system\QZAP.DLL
C:\WINDOWS\system\QZAP.DLL
C:\WINDOWS\system\RMAUI.DLL
C:\WINDOWS\system\RMAUI.DLL
C:\WINDOWS\system\RMAUI.DLL
C:\WINDOWS\system\RMAUI.DLL
C:\WINDOWS\system\RWAUI.DLL
C:\WINDOWS\system\RWAUI.DLL
C:\WINDOWS\system\RWAUI.DLL
C:\WINDOWS\system\RWAUI.DLL
C:\WINDOWS\system\ugrar.dll
C:\WINDOWS\system\ugrar.dll
C:\WINDOWS\system\ugrar.dll
C:\WINDOWS\system\ugrar.dll
C:\WINDOWS\system\ukp10.dll
C:\WINDOWS\system\ukp10.dll
C:\WINDOWS\system\ukp10.dll
C:\WINDOWS\system\ukp10.dll
C:\WINDOWS\system\VMR.DLL
C:\WINDOWS\system\VMR.DLL
C:\WINDOWS\system\VMR.DLL
C:\WINDOWS\system\VMR.DLL
C:\WINDOWS\system\wfp.dll
C:\WINDOWS\system\wfp.dll
C:\WINDOWS\system\wfp.dll
C:\WINDOWS\system\wfp.dll
C:\WINDOWS\system\whvdmod.dll
C:\WINDOWS\system\whvdmod.dll
C:\WINDOWS\system\whvdmod.dll
C:\WINDOWS\system\whvdmod.dll

************

Registry entries found:

[HKEY_CLASSES_ROOT\CLSID\{A61AA860-E674-11D9-8C43-0050DAB76DD0}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\HGVMON.DLL"
[HKEY_CLASSES_ROOT\CLSID\{A61AA860-E674-11D9-8C43-0050DAB76DD0}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\HGVMON.DLL"
[HKEY_CLASSES_ROOT\CLSID\{A61AA860-E674-11D9-8C43-0050DAB76DD0}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\HGVMON.DLL"
[HKEY_CLASSES_ROOT\CLSID\{A61AA860-E674-11D9-8C43-0050DAB76DD0}\InprocServer32]
@="C:\\WINDOWS\\SYSTEM\\HGVMON.DLL"


************

Killing Explorer
Done!

Killing Rundll32
Done!

Removing malicious CLSID(s)
Done!

Restarting Explorer
Done!

Deleting malicious files
Done!


Finished!
  • 0

#7
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
:tazz: I knew I sensed that infection there earlier ;)

Your log is clean.

To help prevent future spyware installations/infections, please read the Anti-Spyware Tutorial and use the tools provided.

Are there any problems now? If not, you should be set to go.
  • 0

#8
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP