Closed Thread
Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    Oct 2006
    Location
    PA
    Posts
    52
    Points
    0

    Default computer running slow and shutting down

    I've had problems recently with my computer running slow,and just shutting down in the middle of something.It usually happens every 2 days.Any help would be greatly appreciated.Here's all my logfiles:

    SUPERAntiSpyware Scan Log
    SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!

    Generated 03/15/2010 at 01:02 AM

    Application Version : 4.23.1006

    Core Rules Database Version : 4645
    Trace Rules Database Version: 2458

    Scan type : Complete Scan
    Total Scan Time : 00:58:37

    Memory items scanned : 367
    Memory threats detected : 0
    Registry items scanned : 4429
    Registry threats detected : 0
    File items scanned : 16842
    File threats detected : 0




    Malwarebytes' Anti-Malware 1.44
    Database version: 3827
    Windows 5.1.2600 Service Pack 2
    Internet Explorer 6.0.2900.2180

    3/15/2010 1:03:50 AM
    mbam-log-2010-03-15 (01-03-41).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 177730
    Time elapsed: 59 minute(s), 27 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 2

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP248\A0071980.dll (Rogue.Ascentive) -> No action taken.
    C:\WINDOWS\system32\ConTest.dll (Rogue.Ascentive) -> No action taken.




    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:16:05 AM, on 3/15/2010
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\HP\KBD\KBD.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\ALCWZRD.EXE
    C:\WINDOWS\ALCMTR.EXE
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam\Quickcam.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\FinePixViewer\QuickDCF2.exe
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    c:\Program Files\Java\jre6\bin\jqs.exe
    c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\AVG\AVG9\avgemc.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = AOL.com - Welcome to AOL
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo!
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = AOL.com - Welcome to AOL
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = AOL.com - Welcome to AOL
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [AutoTBar] c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\RunOnce: [Setup_bootstrap] "F:\\setup.exe"
    O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - c:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe

    --
    End of file - 6784 bytes

  2. #2
    Moderator Forum Moderator JohnB151's Avatar
    Join Date
    Mar 2009
    Location
    The Netherlands
    Posts
    951
    Points
    38

    Default

    Hi and welcome to the Help2Go forums.
    My name is John Brouwer - if it helps, you can call me John for short. I'll be glad to help you with your computer problems.

    HijackThis logs can take some time to research, so please be patient with me. I know that you need
    your computer working as quickly as possible, and I will work hard to help see that happens.

    Despite that it is important that you first know a couple of things:
    • The fixes are specific to your problem and should only be used for this issue on this machine.
    • It's often worth reading through these instructions and printing them for ease of reference.
    • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
    • If you don't reply within five days after my last instructions this topic will be closed. If you will not be able to reply within five days please tell me how long it will take so the topic will not be closed.


    There are also some things that I want you do so I can work as good as possible:
    • Please be patient. The work I do is voluntary and I also have a private life (school, work, friends and hobbies).
    • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
    • Please reply to this thread. Do not start a new topic.
    • Also, don't post logs as attachments. Other helpers like to view the logs as well and opening a lot of attachments is irritating. It can also contain malware.


    One more thing is very important for users who have Vista as operating system.
    When I instruct to run a tool or program always right-click and choose 'Run as Administrator' instead of just double-clicking the icon.

    Finally, please make a uninstall list using HijackThis and post that log so I know you have read this post.
    To access the Uninstall Manager you would do the following:
    • Start HijackThis
    • Click on the Open The Misc Tool Section button
    • Click on the Open Uninstall Manager button.
    • Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Save the file to your desktop and post the contents in a reply to this topic.


    Regards,
    John.

  3. #3
    Member
    Join Date
    Oct 2006
    Location
    PA
    Posts
    52
    Points
    0

    Default

    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.3
    Agere Systems PCI Soft Modem
    AIM 7
    Apple Application Support
    Apple Software Update
    AVG Free 9.0
    CCleaner
    Download Updater (AOL LLC)
    Help and Support Additions
    High Definition Audio Driver Package - KB835221
    HijackThis 2.0.2
    HP Software Update
    IntelliMover Data Transfer Demo
    InterVideo DiscLabel
    InterVideo WinDVD Player
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 17
    KBD
    Logitech QuickCam
    Logitech® Camera Driver
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft Visual C++ 2005 Redistributable
    Mozilla Firefox (3.6)
    MVision
    PC-Doctor for Windows
    PS2
    QuickTime
    Sonic RecordNow!
    Updates from HP
    Windows Installer 3.1 (KB893803)
    Windows Media Format Runtime
    Windows Media Player 10
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB883667
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB888239
    Windows XP Hotfix - KB890175

  4. #4
    Moderator Forum Moderator JohnB151's Avatar
    Join Date
    Mar 2009
    Location
    The Netherlands
    Posts
    951
    Points
    38

    Default

    Hi,

    Your log looks fine, so let's dig a little deeper.

    Please copy the fix to Word, or print it, because you won't always have internet access!

    Step 1: Download and Run DDS
    Please download DDS and save it to your desktop:
    http://download.bleepingcomputer.com/sUBs/dds.scr

    Double click on dds to run it.

    When done, DDS.txt will open. Another file called Attach.txt will open after a short while. Please save these 2 files to your desktop as they will be deleted once you close them.

    Step 2: Download and Run Gmer
    Please download Gmer to your desktop and unzip it to your desktop.
    http://www.gmer.net/gmer.zip
    • Disconnect from internet and close running programs. There is a small chance this application may crash your computer so save any work you have open.
    • Double click the .exe file. If asked to allow gmer.sys driver to load, please allow that.
    • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO
    • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
      • Sections
      • IAT/EAT
      • Drives/Partition other than Systemdrive (typically C:\)
      • Show All (don't miss this one)
    • Then click the Scan button & wait for it to finish.
    • Once done click on the Save button, and in the File name area, type in "Gmer.txt" or it will save as a .log file.
    • Save it where you can easily find it, such as your desktop.

    Note: Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

    Step 3: Post logs
    Please post the following logs in a reply to this topic (use multiple posts if needed):
    • DDS.txt
    • Attach.txt
    • Gmer log


    Regards,
    John.

  5. #5
    Member
    Join Date
    Oct 2006
    Location
    PA
    Posts
    52
    Points
    0

    Default

    DDS (Ver_10-03-17.01) - NTFSx86
    Run by HP_Owner at 21:01:11.21 on Wed 03/24/2010
    Internet Explorer: 6.0.2900.2180
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.297 [GMT -5:00]

    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    c:\Program Files\Java\jre6\bin\jqs.exe
    C:\windows\system\hpsysdrv.exe
    c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\HP\KBD\KBD.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\ALCWZRD.EXE
    C:\WINDOWS\ALCMTR.EXE
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\Program Files\AVG\AVG9\avgemc.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam\Quickcam.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\FinePixViewer\QuickDCF2.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Documents and Settings\HP_Owner\My Documents\Downloads\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.yahoo.com/
    uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    mDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    mSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - No File
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
    uRun: [Aim] "c:\program files\aim\aim.exe" /d locale=en-US
    uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
    uRunOnce: [Setup_bootstrap] "f:\\setup.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    mRun: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [AGRSMMSG] AGRSMMSG.exe
    mRun: [KBD] c:\hp\kbd\KBD.EXE
    mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
    mRun: [PS2] c:\windows\system32\ps2.exe
    mRun: [SoundMan] SOUNDMAN.EXE
    mRun: [AlcWzrd] ALCWZRD.EXE
    mRun: [Alcmtr] ALCMTR.EXE
    mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    mRun: [Reminder] "c:\windows\creator\Remind_XP.exe"
    mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [AutoTBar] c:\program files\hp\digital imaging\bin\AUTOTBAR.EXE
    mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
    mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\exifla~1.lnk - c:\program files\finepixviewer\QuickDCF2.exe
    IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
    Notify: avgrsstarter - avgrsstx.dll
    Notify: igfxcui - igfxsrvc.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\hp_owner\applic~1\mozilla\firefox\profiles\ybxbcty7.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
    FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, falsec:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

    ============= SERVICES / DRIVERS ===============

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-2-17 216200]
    R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-2-17 29512]
    R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-2-17 242696]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-5-13 8944]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-5-13 55024]
    R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-3-13 916760]
    R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-13 308064]
    R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-5-13 7408]

    =============== Created Last 30 ================

    2010-03-23 02:31:19 0 d-----w- c:\docume~1\alluse~1\applic~1\AIM
    2010-03-23 02:30:59 0 d-----w- c:\program files\AIM
    2010-03-23 02:30:56 0 d-----w- c:\program files\common files\Software Update Utility
    2010-03-13 14:51:03 12464 ----a-w- c:\windows\system32\avgrsstx.dll
    2010-03-06 17:49:35 0 d-s---w- c:\documents and settings\hp_owner\UserData
    2010-02-24 02:47:31 13848 ----a-r- c:\windows\system32\drivers\lv302af.sys
    2010-02-24 02:44:39 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys
    2010-02-24 02:44:39 10880 ----a-w- c:\windows\system32\dllcache\ndisip.sys
    2010-02-24 02:44:27 15360 ----a-w- c:\windows\system32\drivers\StreamIP.sys
    2010-02-24 02:44:27 15360 ----a-w- c:\windows\system32\dllcache\streamip.sys
    2010-02-24 02:44:26 16384 ----a-w- c:\windows\system32\ipsink.ax
    2010-02-24 02:44:26 16384 ----a-w- c:\windows\system32\dllcache\ipsink.ax
    2010-02-24 02:44:20 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys
    2010-02-24 02:44:20 11136 ----a-w- c:\windows\system32\dllcache\slip.sys
    2010-02-24 02:44:02 19328 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
    2010-02-24 02:44:02 19328 ----a-w- c:\windows\system32\dllcache\wstcodec.sys
    2010-02-24 02:43:46 85376 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
    2010-02-24 02:43:46 85376 ----a-w- c:\windows\system32\dllcache\nabtsfec.sys
    2010-02-24 02:43:41 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
    2010-02-24 02:43:41 17024 ----a-w- c:\windows\system32\dllcache\ccdecode.sys

    ==================== Find3M ====================

    2010-03-13 14:51:07 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2010-03-13 14:49:16 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2010-02-18 01:51:50 411368 ----a-w- c:\windows\system32\deploytk.dll
    2010-02-18 00:13:58 1842 --sha-r- c:\windows\system32\drivers\103C_HP_CPC_PS583AA-ABA a1020n_YC_0Pavi_QCNH516_E52NAheBLU1_47_IGoldfish3_SASUSTeK Computer INC._V1.xx_B3.20_T050331_WXH2_L409_M504_J200_7Intel_8Pentium 4_93.06_#050620_N10EC8139_Z11C1048C_G80862582.MRK
    2006-01-02 01:33:56 26017 -csh--w- c:\windows\gollkdcn.sys

    ============= FINISH: 21:01:27.42 ===============









    DDS (Ver_10-03-17.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 2/17/2010 7:11:48 PM
    System Uptime: 3/24/2010 5:55:50 PM (4 hours ago)

    Motherboard: ASUSTeK Computer INC. | | Goldfish3
    Processor: Intel(R) Pentium(R) 4 CPU 3.06GHz | CPU 1 | 3065/133mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 179 GiB total, 168.433 GiB free.
    D: is FIXED (FAT32) - 8 GiB total, 2.165 GiB free.
    E: is CDROM ()
    F: is CDROM ()
    G: is Removable
    H: is Removable
    I: is Removable
    J: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP1: 2/17/2010 7:17:03 PM - Configured easy Internet sign-up
    RP2: 2/17/2010 7:19:05 PM - Removed Microsoft Office Standard Edition 2003
    RP3: 2/17/2010 7:21:07 PM - Removed Microsoft Plus! Dancer LE
    RP4: 2/17/2010 7:21:26 PM - Removed Microsoft Plus! Digital Media Edition Installer
    RP5: 2/17/2010 7:21:44 PM - Removed Microsoft Plus! Photo Story 2 LE
    RP6: 2/17/2010 7:31:09 PM - Removed Norton Security Center
    RP7: 2/17/2010 7:33:20 PM - Removed HP Organize
    RP8: 2/17/2010 7:33:56 PM - Removed HP Deskjet Preloaded Printer Drivers
    RP9: 2/17/2010 7:52:32 PM - Installed AVG Free 9.0
    RP10: 2/17/2010 8:37:00 PM - Removed Adobe Reader 6.0.1
    RP11: 2/17/2010 8:37:17 PM - Removed Adobe Acrobat - Reader 6.0.2 Update
    RP12: 2/17/2010 8:37:24 PM - Installed Adobe Reader 9.3.
    RP13: 2/17/2010 8:45:34 PM - Configured iTunes
    RP14: 2/17/2010 8:51:45 PM - Installed Java(TM) 6 Update 17
    RP15: 2/17/2010 8:54:26 PM - Removed Sonic Express Labeler
    RP16: 2/17/2010 8:55:13 PM - Removed muvee autoProducer 3.5 magicMoments - HPD
    RP17: 2/17/2010 8:56:18 PM - Removed Microsoft Works
    RP18: 2/18/2010 9:26:07 AM - Avg8 Update
    RP19: 2/18/2010 8:48:57 PM - Installed Windows Installer KB893803v2.
    RP20: 2/19/2010 9:06:32 PM - System Checkpoint
    RP21: 2/21/2010 10:08:12 AM - System Checkpoint
    RP22: 2/22/2010 10:09:58 AM - System Checkpoint
    RP23: 2/23/2010 10:21:34 AM - System Checkpoint
    RP24: 2/23/2010 9:36:07 PM - Logitech Camera Driver Install
    RP25: 2/24/2010 9:44:44 PM - System Checkpoint
    RP26: 2/26/2010 12:28:22 AM - System Checkpoint
    RP27: 2/27/2010 3:15:58 AM - System Checkpoint
    RP28: 2/28/2010 3:40:12 AM - System Checkpoint
    RP29: 3/1/2010 4:28:45 AM - System Checkpoint
    RP30: 3/2/2010 4:57:12 AM - System Checkpoint
    RP31: 3/3/2010 5:55:18 AM - System Checkpoint
    RP32: 3/4/2010 6:39:32 AM - System Checkpoint
    RP33: 3/5/2010 7:36:56 AM - System Checkpoint
    RP34: 3/6/2010 2:09:17 PM - System Checkpoint
    RP35: 3/7/2010 4:10:39 PM - System Checkpoint
    RP36: 3/8/2010 7:21:06 PM - System Checkpoint
    RP37: 3/9/2010 9:58:26 PM - System Checkpoint
    RP38: 3/11/2010 12:39:10 AM - System Checkpoint
    RP39: 3/12/2010 1:55:52 AM - System Checkpoint
    RP40: 3/13/2010 4:09:39 AM - System Checkpoint
    RP41: 3/13/2010 9:48:07 AM - Avg8 Update
    RP42: 3/13/2010 9:51:21 AM - Avg Update
    RP43: 3/14/2010 11:54:29 AM - System Checkpoint
    RP44: 3/15/2010 2:43:10 PM - System Checkpoint
    RP45: 3/16/2010 2:55:47 PM - System Checkpoint
    RP46: 3/17/2010 8:34:56 AM - Avg Update
    RP47: 3/18/2010 1:35:21 PM - System Checkpoint
    RP48: 3/22/2010 8:51:45 AM - System Checkpoint
    RP49: 3/22/2010 6:05:55 PM - Installed QuickTime
    RP50: 3/23/2010 6:13:31 PM - System Checkpoint
    RP51: 3/24/2010 6:23:44 PM - System Checkpoint

    ==== Installed Programs ======================

    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.3
    Agere Systems PCI Soft Modem
    AIM 7
    Apple Application Support
    Apple Software Update
    AVG Free 9.0
    CCleaner
    Download Updater (AOL LLC)
    Help and Support Additions
    High Definition Audio Driver Package - KB835221
    HijackThis 2.0.2
    HP Software Update
    HpSdpAppCoreApp
    IntelliMover Data Transfer Demo
    InterVideo DiscLabel
    InterVideo WinDVD Player
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 17
    KBD
    Logitech QuickCam
    Logitech® Camera Driver
    LS_HSI
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft Visual C++ 2005 Redistributable
    Mozilla Firefox (3.6.2)
    MVision
    PC-Doctor for Windows
    PS2
    QuickTime
    Sonic RecordNow!
    Updates from HP
    WebFldrs XP
    Windows Installer 3.1 (KB893803)
    Windows Media Format Runtime
    Windows Media Player 10
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB883667
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB888239
    Windows XP Hotfix - KB890175
    Yahoo! Messenger

    ==== Event Viewer Messages From Past Week ========

    3/22/2010 9:30:37 PM, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error message: The referenced assembly is not installed on your system. .
    3/22/2010 9:30:37 PM, error: SideBySide [59] - Generate Activation Context failed for C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\AIM_72~1.1\imappver.dll. Reference error message: The operation completed successfully. .
    3/22/2010 9:30:37 PM, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.CRT could not be found and Last Error was The referenced assembly is not installed on your system.
    3/21/2010 11:32:02 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    3/21/2010 11:16:58 PM, error: Dhcp [1002] - The IP address lease 192.168.254.1 for the Network Card with network address 0011D8DE3A6B has been denied by the DHCP server 192.168.254.254 (The DHCP Server sent a DHCPNACK message).

    ==== End Of File ===========================




    GMER 1.0.15.15281 - GMER - Rootkit Detector and Remover
    Rootkit scan 2010-03-24 21:07:25
    Windows 5.1.2600 Service Pack 2
    Running: gmer.exe; Driver: C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\kwaorfow.sys


    ---- System - GMER 1.0.15 ----

    SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xA9CE1F20]

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
    AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    ---- EOF - GMER 1.0.15 ----

  6. #6
    Moderator Forum Moderator JohnB151's Avatar
    Join Date
    Mar 2009
    Location
    The Netherlands
    Posts
    951
    Points
    38

    Default

    Hi,

    The logs look perfect so I think you are not infected. Let's run one more scan though and do some other important things.

    You aren't running Firewall Software. Please download and install one of them first!

    Use a Firewall - Using a Firewall on your computer can be very important. Without a firewall your computer is susceptible to being hacked and taken over. There are some different situations you can be in where a third-party firewall may or may not be a good addition to your system:
    • If you are not using Windows XP or Vista, but an older version I recommend you to use a firewall.
    • If you are using Windows XP or Vista, but are on dial-up I recommend you to use a firewall.
    • If you are using Windows XP or Vista and are using broadband, but are not experienced in using firewalls and getting the choice to allow or disallow things I recommend you to use Windows Firewall.
    • If you are using Windows XP or Vista, are using broadband and experienced, I recommend you to disable Windows Firewall (as it is not perfect) and get a third-party firewall.


    Here are some firewalls which are free for personal use and most used:
    Kerio Personal Firewall (Free version after 30 days)
    Online Armor Free

    Or you could buy their paid version online or in a shop nearby:
    Kerio Personal Firewall (Continue paid version after 30 days)
    Online Armor or Online Armor AV+ with Anti-Virus included

    As you did this, we can begin with the fix.

    Step 1: Update Java
    Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
    First remove the older versions:
    • Click Start
    • Go to Control Panel
    • Go to Add/Remove Programs
    • Find and click Remove for each version of Java that is present
    • Download JavaRa and unzip it to your desktop.
    • Double-click on JavaRa.exe to start the program.
    • From the drop-down menu, choose English and click on Select.
    • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
    • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
    • A logfile will pop up. Please save it to a convenient location.

    Now let's download and install the newest version:
    • Go to the website of Java: Java SE Downloads - Sun Developer Network (SDN)
    • Under JDK 6 Update 18 click the red box called Download JRE.
    • As Platform select your operating system, agree to the License Agreement and click Continue.
    • Now click on the link under Windows Offline Installation and download the installer to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Then from your desktop double-click on the download to install the newest version.
    • Reboot your computer.


    Step 2: Run CCleaner
    CCleaner will remove everything from the temp/temporary folders but please note that it will not make back ups!
    • Double click the CCleaner shortcut on the desktop to start the program.
    • On the Windows tab, under Internet Explorer, uncheck Cookies if you do not want them deleted. (If deleted, you will likely need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
    • If you check Cookies for removal, you can use Options, Cookies to decide which Cookies to keep.
    • If you use the Firefox browser, the box to check for Cookies is on the Applications tab, under Firefox.
    • Click on the Options icon at the left side of the window, then click on Advanced.
      Deselect Only delete files in Windows Temp folders older than 24 hours.
    • Click on the Cleaner icon on the left side of the window, then click Run Cleaner to run the program.
    • Caution: It is not recommended that you use the Registry feature unless you are very familiar with the registry as it has been known to delete legitimate items.
    • After CCleaner has completed its process close the program.

    CCleaner should be run with the above settings for each User Account!

    Step 3: Run Kaspersky Online Scan
    Please go to Kaspersky website to perform an online antivirus scan.
    • Read through the requirements and privacy statement and click on Accept button.
    • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    • When the downloads have finished, click on Settings.
    • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      • Spyware, Adware, Dialers, and other potentially dangerous programs
      • Archives
      • Mail databases
    • Click on My Computer under Scan.
    • Once the scan is complete, it will display the results. Click on View Scan Report.
    • You will see a list of infected items there. Click on Save Report As....
    • Save this report to your desktop by changing the Files of type to Text file (.txt) before clicking on the Save button.
    • Now close the window.


    Step 4: Post logs
    Please post the Kaspersky log together with a new HijackThis log. Also let me know if you are still having problems and tell me about any problems you still have.

    Regards,
    John.

  7. #7
    Moderator Forum Moderator JohnB151's Avatar
    Join Date
    Mar 2009
    Location
    The Netherlands
    Posts
    951
    Points
    38

    Default

    Due to inactivity I have now closed this topic.

    If at any time after this post you still need help or need help again please start a new topic.