|
Search Tech-Forums - link takes you to our Forum's search page. Note: The following is only a text archive! To view the actual forum discussion, please visit our website at http://www.tech-forums.net Pages:1 Major Infection help needed(Click here to view the original thread with full colors/images)Posted by: PoisonPorkchop ok this is kind of long but my computer is so infected with spyware/adware/viruses. symptoms: cant enter; my computer, add/remove program list, or recycle bin without windows restarting. everytime i run ad aware i get 500+ critical objects, even if it is RIGHT after one another. homepage is CONSTANTLY changed new icons are added constantly such as party poker woke up this morning with 44 popups i have no virus scanner because i am only 14 and cant drive to the store to buy one and parents are "very busy" what should i do Posted by: PoisonPorkchop guys i need help fast. i have a very screwed up computer and was trying to fix it. i downloaded firefox instead of ie and downloaded spybot search and destroy. now after i start my computer after about a minute it completely freezes(mouse and everything) i dont know what to do. the only thing i can think of is to start my comp in safemode and run adaware and spybot, but i dont know how to do this. please help me im desperate Posted by: Warez Monster Go to start, run, type msconfig, then go to startup, then click disable all, reboot, run your adaware, and spybot, delete your tifs and cookies, reboot, and run your adaware programs again and see if that helps. Posted by: PoisonPorkchop i tried but before i could do that it froze. *sob* Posted by: Warez Monster Post your HiJack this long then,.... Posted by: PoisonPorkchop wait i made it and ran all that crap then it told me it couldent delete everything so i should restart so i did and it said it couldent delete everything again. then i downloaded avg and as i was installing it it froze and i dont know what to do please dont leave me. lol but ok how do i use hijack this? Posted by: PoisonPorkchop what causes adware? everytime i run ad-aware i have about 500 plus adware even if they are right after one another. why is this? Posted by: OIDanTheManIO How often are you running a scan? If you're scanning daily and you're getting that many critical objects, I would suggest that you format ASAP. But if you get that many in one week, it would probably be a good idea if you watched what websites you went to and stopped downloading sh*t. -Dan The Man Posted by: Warez Monster Do what I told you to do in the other post, but dont reboot yet, now go to add/remove and remove any programs that you know shouldnt be there, then go to c:\windows\prefetch and delete the prefetch folder, next delete your cookies and temporary internet files, do a screen shot of your task managers processes and post it here so I can see what is running that shouldnt be, or someone on here, if you cant remove anything, go into safe mode, also check your c drive in the program files for folders and files that shouldnt be there, if you find one/some, delete them, if they wont delete, rename them to whatever you want, then delete it, if it still wont delete, reboot then try to delete it, next we will run hijackthis... Posted by: PoisonPorkchop warez youre the only one on that is willing to help me so is there an easier way to communicate? i dont know how to take a screenshot. sorry about not knowing how to do anything but thanks for the help in advance though Posted by: PoisonPorkchop ok youre the only one helping me right now so ill just make a seperate thread. one thing i thought was wierd is it shows i have 2 drives when i know i only have one. it says i have a c drive with 15 gigs and a d drive with 60. i verified that this is not just a random problem because i can install stuff to both. i think my d drive is fine and that my c drive is screwed up but i dont know where to go from here thanks so much Posted by: rstones12 As Warez Monster has stated please post a HJT log and we can take a look at it. Download HijackThis 1.99.1 [url]http://www.majorgeeks.com/download3155.html[/url] Create a folder on your C:\ drive and name it C:\HJT Run HijackThis from that folder from now on. rstones12 Posted by: PoisonPorkchop heres my hjt log Posted by: PoisonPorkchop woops whats a better way to post that? Posted by: rstones12 PoisonPorkchop, Thanks for the log, please copy the HJT log and post it by using Post a Reply, not a text file. Thanks, rstones12 Posted by: PoisonPorkchop k 1 sec Posted by: PoisonPorkchop Logfile of HijackThis v1.99.1 Scan saved at 12:10:36 AM, on 3/12/2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\isrvs\desktop.exe C:\Program Files\Media Pass\MediaPassK.exe C:\Program Files\Media Pass\MediaPass.exe C:\PROGRA~1\Toolbar\TBPS.exe C:\PROGRA~1\Toolbar\PIB.exe C:\WINDOWS\System32\rundll32.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe c:\PROGRA~1\Toolbar\radio.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system\imeegse.exe D:\Steam\Steam.exe d:\steam\steamapps\sbostick90\counter-strike source\hl2.exe C:\Program Files\Internet Explorer\iexplore.exe c:\progra~1\intern~1\iexplore.exe D:\firefox.exe C:\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Scott\LOCALS~1\Temp\se.dll/sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://www.sony.com/vaiopeople[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = [url]http://www.websearch.com/ie.aspx?tb_id=50220[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Scott\LOCALS~1\Temp\se.dll/sp.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = http=192.168.0.1:85 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - _{8952A998-1E7E-4716-B23D-3DBE03910972} - (no file) R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll O1 - Hosts: comments (such as these) may be inserted on individual O1 - Hosts: 64.12.152.18 search.netscape.com O2 - BHO: (no name) - {4BF556D5-291E-5B70-D7AF-5031D8E54761} - C:\DOCUME~1\Scott\APPLIC~1\PUREDO~1\KindMapi.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll O2 - BHO: (no name) - {E782A5A5-1737-468A-B0F9-377DEDE5E996} - C:\WINDOWS\System32\efnn.dll O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file) O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPassK.exe O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\Scott\LOCALS~1\Temp\se.dll,DllInstall O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKCU\..\Run: [multi rdr] C:\DOCUME~1\Scott\APPLIC~1\IDLEDE~1\settingsproxyp art.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing) O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - [url]http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebiof5_3_10_0.cab[/url] O17 - HKLM\System\CCS\Services\Tcpip\..\{4645ACD2-3AF8-463E-8114-3EBA36AF56F5}: NameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{9A334517-B35D-4F4C-B973-B73D162673C3}: NameServer = 192.168.0.1 O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll O18 - Filter: text/html - {F738C13F-166C-4014-B5F6-5CD8180738DF} - C:\WINDOWS\System32\efnn.dll O18 - Filter: text/plain - {F738C13F-166C-4014-B5F6-5CD8180738DF} - C:\WINDOWS\System32\efnn.dll O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe Posted by: MicroBell [b]Hi and Welcome to TSF[/b] Please consider installing the SP1/SP2 service packs for both IE6 and XP. You have about 5 hijackers taking place so we will remove them in steps. [color=blue][b]Before attacking an adware/spyware problem with hijackthis make sure you have already run[color=red] ad-aware SE[/color] with [color=red]VX2[/color] add-on cleaner, [color=red]Spybot Search & Destroy[/color] (with updated database) and [color=red]CWShredder[/color] as these programs will clean a lot of the crap out first. All links to programs are in my signature. Ok..on to the log…..[/color][/b] Download and install [b]CleanUp[/b] [url]http://cleanup.stevengould.org/[/url] Download [b]Hoster[/b] [url]http://members.aol.com/toadbee/hoster.zip[/url] Download [url=http://www.bleepingcomputer.com/files/windows/Winsock2Fix.zip][b]Winsock2Fix[/b][/url] and unzip it. DO NOT RUN IT YET! Go to My Computer->Tools->Folder Options->View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing/visible also. Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore. Reboot into Safe Mode (hit F8 key until menu shows up). Make sure to close any open browsers. Open add/remove programs and remove the following if listed. [b]Media Pass Toolbar isrvs[/b] Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one if they are still listed (they shouldn't be but make sure) [b]C:\WINDOWS\isrvs\desktop.exe C:\Program Files\Media Pass\MediaPassK.exe C:\Program Files\Media Pass\MediaPass.exe C:\PROGRA~1\Toolbar\TBPS.exe C:\PROGRA~1\Toolbar\PIB.exe c:\PROGRA~1\Toolbar\radio.exe C:\WINDOWS\system\imeegse.exe[/b] Check and fix the following in HijackThis if they still exist (make sure you do not miss an entry) [b]R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Scott\LOCALS~1\Temp\se.dll/sp.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about :blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = [url]http://www.websearch.com/ie.aspx?tb_id=50220[/url] R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Scott\LOCALS~1\Temp\se.dll/sp.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about :blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about :blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about :blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about :blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about :blank R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - _{8952A998-1E7E-4716-B23D-3DBE03910972} - (no file) R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll O1 - Hosts: comments (such as these) may be inserted on individual O1 - Hosts: 64.12.152.18 search.netscape.com O2 - BHO: (no name) - {4BF556D5-291E-5B70-D7AF-5031D8E54761} - C:\DOCUME~1\Scott\APPLIC~1\PUREDO~1\KindMapi.exe O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll O2 - BHO: (no name) - {E782A5A5-1737-468A-B0F9-377DEDE5E996} - C:\WINDOWS\System32\efnn.dll O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file) O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPassK.exe O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\Scott\LOCALS~1\Temp\se.dll,DllInstall O4 - HKCU\..\Run: [multi rdr] C:\DOCUME~1\Scott\APPLIC~1\IDLEDE~1\settingsproxyp art.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll O18 - Filter: text/html - {F738C13F-166C-4014-B5F6-5CD8180738DF} - C:\WINDOWS\System32\efnn.dll O18 - Filter: text/plain - {F738C13F-166C-4014-B5F6-5CD8180738DF} - C:\WINDOWS\System32\efnn.dll[/b] Delete the following Files/Folders in [color=red][b]RED[/color][/b] (delete folders if no filename is specified or if they are highlighted in RED) according to their directory (If you can't find them...do a search for them…make sure you have search hidden files, folders, sub directorys..ect enabled if it applys to your OS) [b]C:\WINDOWS\[color=red]isrvs\desktop.exe[/color] C:\Program Files\[color=red]Media Pass\MediaPassK.exe[/color] c:\PROGRA~1\[color=red]Toolbar\radio.exe[/color] C:\WINDOWS\system\[color=red]imeegse.exe[/color] C:\DOCUME~1\Scott\APPLIC~1\[color=red]PUREDO~1\Kin dMapi.exe[/color] C:\WINDOWS\System32\[color=red]efnn.dll[/color] C:\DOCUME~1\Scott\APPLIC~1\[color=red]IDLEDE~1\set tingsproxypart.exe[/b][/color] Now open and run the hoster program to reset/restore your hosts file. Run the cleanup utility and reboot/logoff when prompted. Once done reboot into Normal Mode and post a new HijackThis log and proceed to the next step. [color=red][b]**Note** If you can't reconnect to the internet...run that winsock2fix file. ONLY IF you can't connect.[/b][/color] ================================== Please download the [b]Appinit.zip[/b] file located in this post. [url]http://techsupportforum.com/showthread.php?p=199172&posted=1#post199172[/url] Open the zip file and extract the Appinit.bat file to your desktop. Double click on [b]Appinit.bat[/b] This will create a file on the desktop named [b]windows.txt[/b] Copy and paste that log here Download L2mfix from one of these two locations: [url]http://www.atribune.org/downloads/l2mfix.exe[/url] [url]http://www.downloads.subratam.org/l2mfix.exe[/url] Save the file to your desktop and double click [B]l2mfix.exe[/B]. Click the [B]Install[/B] button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click [B]l2mfix.bat[/B] and select option #[B]1[/B] for [B]Run Find Log[/B] by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread. [COLOR=red]IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so![/COLOR] So I need 3 logs.. 1. Hijackthis 2. windows.txt 3. L2mfix log vBulletin Copyright ©2000 - 2003, Jelsoft Enterprises Limited. PPC Management vB Easy Archive Final - Created by Xenon |