[Major Infection help needed] - Computers



Search Tech-Forums - link takes you to our Forum's search page.

Note: The following is only a text archive!


To view the actual forum discussion, please visit our website at http://www.tech-forums.net

Pages:1



Major Infection help needed

(Click here to view the original thread with full colors/images)



Posted by: PoisonPorkchop

ok this is kind of long but my computer is so infected with spyware/adware/viruses.

symptoms:
cant enter; my computer, add/remove program list, or recycle bin without windows restarting.
everytime i run ad aware i get 500+ critical objects, even if it is RIGHT after one another.
homepage is CONSTANTLY changed
new icons are added constantly such as party poker
woke up this morning with 44 popups

i have no virus scanner because i am only 14 and cant drive to the store to buy one and parents are "very busy"

what should i do



Posted by: PoisonPorkchop

guys i need help fast. i have a very screwed up computer and was trying to fix it. i downloaded firefox instead of ie and downloaded spybot search and destroy. now after i start my computer after about a minute it completely freezes(mouse and everything) i dont know what to do. the only thing i can think of is to start my comp in safemode and run adaware and spybot, but i dont know how to do this. please help me im desperate



Posted by: Warez Monster

Go to start, run, type msconfig, then go to startup, then click disable all, reboot, run your adaware, and spybot, delete your tifs and cookies, reboot, and run your adaware programs again and see if that helps.



Posted by: PoisonPorkchop

i tried but before i could do that it froze.
*sob*



Posted by: Warez Monster

Post your HiJack this long then,....



Posted by: PoisonPorkchop

wait i made it and ran all that crap then it told me it couldent delete everything so i should restart so i did and it said it couldent delete everything again. then i downloaded avg and as i was installing it it froze and i dont know what to do please dont leave me. lol but ok how do i use hijack this?



Posted by: PoisonPorkchop

what causes adware? everytime i run ad-aware i have about 500 plus adware even if they are right after one another. why is this?



Posted by: OIDanTheManIO

How often are you running a scan? If you're scanning daily and you're getting that many critical objects, I would suggest that you format ASAP. But if you get that many in one week, it would probably be a good idea if you watched what websites you went to and stopped downloading sh*t.

-Dan The Man



Posted by: Warez Monster

Do what I told you to do in the other post, but dont reboot yet, now go to add/remove and remove any programs that you know shouldnt be there, then go to c:\windows\prefetch and delete the prefetch folder, next delete your cookies and temporary internet files, do a screen shot of your task managers processes and post it here so I can see what is running that shouldnt be, or someone on here, if you cant remove anything, go into safe mode, also check your c drive in the program files for folders and files that shouldnt be there, if you find one/some, delete them, if they wont delete, rename them to whatever you want, then delete it, if it still wont delete, reboot then try to delete it, next we will run hijackthis...



Posted by: PoisonPorkchop

warez youre the only one on that is willing to help me so is there an easier way to communicate? i dont know how to take a screenshot. sorry about not knowing how to do anything but thanks for the help in advance though



Posted by: PoisonPorkchop

ok youre the only one helping me right now so ill just make a seperate thread. one thing i thought was wierd is it shows i have 2 drives when i know i only have one. it says i have a c drive with 15 gigs and a d drive with 60. i verified that this is not just a random problem because i can install stuff to both. i think my d drive is fine and that my c drive is screwed up but i dont know where to go from here

thanks so much



Posted by: rstones12

As Warez Monster has stated please post a HJT log and we can take a look at it.

Download HijackThis 1.99.1
[url]http://www.majorgeeks.com/download3155.html[/url]

Create a folder on your C:\ drive and name it C:\HJT

Run HijackThis from that folder from now on.

rstones12



Posted by: PoisonPorkchop

heres my hjt log



Posted by: PoisonPorkchop

woops whats a better way to post that?



Posted by: rstones12

PoisonPorkchop,
Thanks for the log, please copy the HJT log and post it by using Post a Reply, not a text file.

Thanks,
rstones12



Posted by: PoisonPorkchop

k 1 sec



Posted by: PoisonPorkchop

Logfile of HijackThis v1.99.1
Scan saved at 12:10:36 AM, on 3/12/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\isrvs\desktop.exe
C:\Program Files\Media Pass\MediaPassK.exe
C:\Program Files\Media Pass\MediaPass.exe
C:\PROGRA~1\Toolbar\TBPS.exe
C:\PROGRA~1\Toolbar\PIB.exe
C:\WINDOWS\System32\rundll32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
c:\PROGRA~1\Toolbar\radio.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system\imeegse.exe
D:\Steam\Steam.exe
d:\steam\steamapps\sbostick90\counter-strike source\hl2.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\progra~1\intern~1\iexplore.exe
D:\firefox.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Scott\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://www.sony.com/vaiopeople[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = [url]http://www.websearch.com/ie.aspx?tb_id=50220[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Scott\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int
ernet Settings,ProxyServer = http=192.168.0.1:85
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O1 - Hosts: comments (such as these) may be inserted on individual
O1 - Hosts: 64.12.152.18 search.netscape.com
O2 - BHO: (no name) - {4BF556D5-291E-5B70-D7AF-5031D8E54761} - C:\DOCUME~1\Scott\APPLIC~1\PUREDO~1\KindMapi.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: (no name) - {E782A5A5-1737-468A-B0F9-377DEDE5E996} - C:\WINDOWS\System32\efnn.dll
O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file)
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPassK.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\Scott\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [multi rdr] C:\DOCUME~1\Scott\APPLIC~1\IDLEDE~1\settingsproxyp
art.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - [url]http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebiof5_3_10_0.cab[/url]
O17 - HKLM\System\CCS\Services\Tcpip\..\{4645ACD2-3AF8-463E-8114-3EBA36AF56F5}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A334517-B35D-4F4C-B973-B73D162673C3}: NameServer = 192.168.0.1
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
O18 - Filter: text/html - {F738C13F-166C-4014-B5F6-5CD8180738DF} - C:\WINDOWS\System32\efnn.dll
O18 - Filter: text/plain - {F738C13F-166C-4014-B5F6-5CD8180738DF} - C:\WINDOWS\System32\efnn.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe



Posted by: MicroBell

[b]Hi and Welcome to TSF[/b]

Please consider installing the SP1/SP2 service packs for both IE6 and XP. You have about 5 hijackers taking place so we will remove them in steps.

[color=blue][b]Before attacking an adware/spyware problem with hijackthis make sure you have already run[color=red] ad-aware SE[/color] with [color=red]VX2[/color] add-on cleaner, [color=red]Spybot Search & Destroy[/color] (with updated database) and [color=red]CWShredder[/color] as these programs will clean a lot of the crap out first. All links to programs are in my signature. Ok..on to the log…..[/color][/b]

Download and install [b]CleanUp[/b] [url]http://cleanup.stevengould.org/[/url]

Download [b]Hoster[/b] [url]http://members.aol.com/toadbee/hoster.zip[/url]

Download [url=http://www.bleepingcomputer.com/files/windows/Winsock2Fix.zip][b]Winsock2Fix[/b][/url] and unzip it. DO NOT RUN IT YET!


Go to My Computer->Tools->Folder Options->View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing/visible also. Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore.

Reboot into Safe Mode (hit F8 key until menu shows up). Make sure to close any open browsers. Open add/remove programs and remove the following if listed.

[b]Media Pass
Toolbar
isrvs[/b]

Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one if they are still listed (they shouldn't be but make sure)

[b]C:\WINDOWS\isrvs\desktop.exe
C:\Program Files\Media Pass\MediaPassK.exe
C:\Program Files\Media Pass\MediaPass.exe
C:\PROGRA~1\Toolbar\TBPS.exe
C:\PROGRA~1\Toolbar\PIB.exe
c:\PROGRA~1\Toolbar\radio.exe
C:\WINDOWS\system\imeegse.exe[/b]

Check and fix the following in HijackThis if they still exist (make sure you do not miss an entry)

[b]R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Scott\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about :blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = [url]http://www.websearch.com/ie.aspx?tb_id=50220[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Scott\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about :blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about :blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about :blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about :blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about :blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{8952A998-1E7E-4716-B23D-3DBE03910972} - (no file)
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O1 - Hosts: comments (such as these) may be inserted on individual
O1 - Hosts: 64.12.152.18 search.netscape.com
O2 - BHO: (no name) - {4BF556D5-291E-5B70-D7AF-5031D8E54761} - C:\DOCUME~1\Scott\APPLIC~1\PUREDO~1\KindMapi.exe
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: (no name) - {E782A5A5-1737-468A-B0F9-377DEDE5E996} - C:\WINDOWS\System32\efnn.dll
O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file)
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [Media Pass] C:\Program Files\Media Pass\MediaPassK.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\Scott\LOCALS~1\Temp\se.dll,DllInstall
O4 - HKCU\..\Run: [multi rdr] C:\DOCUME~1\Scott\APPLIC~1\IDLEDE~1\settingsproxyp
art.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\ua_lsp.dll
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
O18 - Filter: text/html - {F738C13F-166C-4014-B5F6-5CD8180738DF} - C:\WINDOWS\System32\efnn.dll
O18 - Filter: text/plain - {F738C13F-166C-4014-B5F6-5CD8180738DF} - C:\WINDOWS\System32\efnn.dll[/b]

Delete the following Files/Folders in [color=red][b]RED[/color][/b] (delete folders if no filename is specified or if they are highlighted in RED) according to their directory (If you can't find them...do a search for them…make sure you have search hidden files, folders, sub directorys..ect enabled if it applys to your OS)


[b]C:\WINDOWS\[color=red]isrvs\desktop.exe[/color]
C:\Program Files\[color=red]Media Pass\MediaPassK.exe[/color]
c:\PROGRA~1\[color=red]Toolbar\radio.exe[/color]
C:\WINDOWS\system\[color=red]imeegse.exe[/color]
C:\DOCUME~1\Scott\APPLIC~1\[color=red]PUREDO~1\Kin
dMapi.exe[/color]
C:\WINDOWS\System32\[color=red]efnn.dll[/color]
C:\DOCUME~1\Scott\APPLIC~1\[color=red]IDLEDE~1\set
tingsproxypart.exe[/b][/color]

Now open and run the hoster program to reset/restore your hosts file.

Run the cleanup utility and reboot/logoff when prompted.

Once done reboot into Normal Mode and post a new HijackThis log and proceed to the next step.

[color=red][b]**Note** If you can't reconnect to the internet...run that winsock2fix file. ONLY IF you can't connect.[/b][/color]

==================================

Please download the [b]Appinit.zip[/b] file located in this post.
[url]http://techsupportforum.com/showthread.php?p=199172&posted=1#post199172[/url]

Open the zip file and extract the Appinit.bat file to your desktop.
Double click on [b]Appinit.bat[/b]
This will create a file on the desktop named [b]windows.txt[/b]
Copy and paste that log here



Download L2mfix from one of these two locations:

[url]http://www.atribune.org/downloads/l2mfix.exe[/url]
[url]http://www.downloads.subratam.org/l2mfix.exe[/url]

Save the file to your desktop and double click [B]l2mfix.exe[/B]. Click the [B]Install[/B] button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click [B]l2mfix.bat[/B] and select option #[B]1[/B] for [B]Run Find Log[/B] by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

[COLOR=red]IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so![/COLOR]

So I need 3 logs..

1. Hijackthis
2. windows.txt
3. L2mfix log





vBulletin Copyright ©2000 - 2003, Jelsoft Enterprises Limited.


PPC Management
vB Easy Archive Final - Created by Xenon