I'm seriously gone mad with my BOX... Please help....

Status
Not open for further replies.

vickymustdie

Broken In
Hi Guys.....

Get stucked with my PC again....

I've cleared my entire system with ADAWARE, TROJANHUNTER, SPYWAREBLASTER , CCLEANER and POWERSCAN.... Everything is fine... But still my system runs too slow....

I don't know how again all the spyware software like IST, 180 Search, Search News and etc... gets installed on my system.

Now the main problem.....

1) Even if I shut down my system rudely...improperly or suddenly, it didn't ask for SCANDISK when i start it again...

2) When I press CTRL + ALT + DEL in order to end task any stucked program, I get the error.. "Taskbar has been disabled by your Administrator". As I'm the only person using my system and the only administrator. My system is P4 2.8, runing Windows XP SP2 with AMD motherboard...

3) While working on my computer, suddenly a DOS Program starts automatically and stuck my system. It says the path C:/Windows/System32/mmnm23.exe and i've to shut down the system.

Please help me... I'm really gone mad with my system... :cry:
 

mohit

The Hardware Labs
please post your hijackthis log file.

also visit this thread it maybe useful.
*www.thinkdigit.com/forum/viewtopic.php?t=15701&postdays=0&postorder=asc&start=0

as far as i can understand your system is still affected with spyware/adware etc. what anti-virus and firewall solution do u use ?

My system is P4 2.8, runing Windows XP SP2 with AMD motherboard...

how is that possible ? and amd doesnt make motherboards. please post your complete config also but i dont see any hardware problems but it is always advisable to go for the latest driver,bios updates.

if nothing works plz do a complete format and reinstall xp with sp2. if you want free protection make sure you have the following (all latest versions)

:arrow: Avast anti-virus
:arrow: Zone alaram firewall
:arrow: Ad-aware se by lavasoftusa
:arrow: MS antispyware

all these combined shud offer you very good protection for free. also update windows regularly.
 
K

khattam_

Guest
Oh please mention your system configuration, at least the OS..............

I'll assume it is XP Professional...........

1. If you have Ntfs partition/s then rude shutdowns wont effect data and hence no scandisks.........I'll assume you have FAT32. If you have FAT32, it is some kind of a problem..... I forgot the solution, Hope someone will post it soon. My suggestion to you is that you upgrade to Ntfs. You know how, don't you??

2. Some registry change will do but don't know what??

3. Perform a full system scan at pandasoftware.com for viruses..............

And yeah, HijackThis Logfile always helps............
 

anomit

In the zone
I've cleared my entire system with ADAWARE, TROJANHUNTER, SPYWAREBLASTER , CCLEANER and POWERSCAN

Well, well man :shock:
You used POWERSCAN!!!!!!!!!!

It itself is an adware, and dont take this otherwise it generally comes from the porn sites usually :lol:

powerscan.exe is an advertising program by Integrated Search Technologies. This process comes packaged with a search toolbar for Internet Explorer, but monitors your browsing habits and distributes the data back to the author's servers for analyses. In short a part of the IST family of spywares

Anyway, the removal:

1. Click Start > Run, type 'regedit' to open the Registry Editor.

2. Navigate to the following registry key:

HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run

In the right pane, delete the value named 'Power Scan'.

3. Navigate to and delete the following keys (and subkeys under them):

HKEY_CURRENT_USER\software\powerscan
HKEY_LOCAL_MACHINE\software\powerscan

4. Exit Registry Editor and reboot the computer.

5. Open Windows Explorer, delete the folder 'Power Scan' from 'Program Files' directory.
 

anomit

In the zone
You have not used these. Use a combination of these three:

Spybot S&D, Ad-Aware and MS Antispyware

This is because each of them as a stand-alone don't detect all the spywares, especially Ad-Aware
 
OP
V

vickymustdie

Broken In
Thanks guys for replying...

Let me reply all of you one by one.....

Mohit says :
please post your hijackthis log file.

Here is my HijackThis log file......

Logfile of HijackThis v1.99.1
Scan saved at 2:27:20 AM, on 5/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\cmd32.exe
C:\WINDOWS\system32\kernels32.exe
C:\Program Files\QuickTime\qttask.exe
c:\windows\system32\umnawac.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\COMMON~1\wfzf\wfzfm.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\system32\lvhidsvc.exe
C:\Program Files\Alias\Maya6.5\docs\wrapper.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alias\Maya6.5\docs\jre\bin\java.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
F:\oracle\ora90\bin\agntsrvc.exe
C:\WINDOWS\system32\cmd.exe
F:\oracle\ora90\bin\dbsnmp.exe
F:\oracle\ora90\BIN\TNSLSNR.exe
f:\oracle\ora90\bin\ORACLE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\vxgamet2.exe
C:\Program Files\Yahoo!\Messenger\YPager.exe
C:\WINDOWS\system32\win32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Downloads\hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O2 - BHO: Loader Class - {2E246FAE-8420-11D9-870D-000C2917DE7F} - C:\WINDOWS\SYSTEM\Loader.dll
O2 - BHO: BHOmodObj Class - {7F6828CA-9E42-462C-BC60-418C8144012C} - c:\windows\system\BHOmod.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - (no file)
O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\system32\cmd32.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [yvmjsz] C:\WINDOWS\yvmjsz.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\W
O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\kernels32.exe
O4 - HKLM\..\Run: [WindowsUpdate] C:\WINDOWS\System\svchost.exe /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [zbrvilo] c:\windows\system32\umnawac.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [wupd] C:\WINDOWS\system32\win32.exe
O4 - HKCU\..\Run: [SNInstall] C:\WINDOWS\system32\vxh8jkdq2.exe
O4 - HKCU\..\Run: [wfzf] C:\PROGRA~1\COMMON~1\wfzf\wfzfm.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Save Flash In This Page - C:\PROGRA~1\FLASHS~1.0\save.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1.0\save.htm
O9 - Extra 'Tools' menuitem: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1.0\save.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {6455DD65-722B-405A-AAD1-335817486602} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {6455DD65-722B-405A-AAD1-335817486602} - (no file) (HKCU)
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\PROGRA~1\ELTIMA~1\FLASHD~1\iebt.dll (HKCU)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\PROGRA~1\ELTIMA~1\FLASHD~1\iebt.dll (HKCU)
O13 - DefaultPrefix: *craftsmensearch.com/gall.php?url=
O13 - WWW Prefix: *craftsmensearch.com/gall.php?url=
O13 - Home Prefix: *craftsmensearch.com/gall.php?url=
O13 - Mosaic Prefix: *craftsmensearch.com/gall.php?url=
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - *static.windupdates.com/cab/CDT/ie/bridge-c7.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - *www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{50B67F39-18C1-4A9F-85A2-E8C35EC1DE75}: NameServer = 203.197.38.2 203.197.38.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{87F3CD8D-8CE5-441D-8FD8-D2478ADDE0E5}: NameServer = 203.197.38.2,203.197.38.3
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
O21 - SSODL: System - {AF44CE72-17C8-49DC-B8D9-4CD9E1D788AF} - vr_sys.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LifeView HID Service (LvHidSvc) - Animation Technologies Inc. - C:\WINDOWS\system32\lvhidsvc.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Maya 6.5 Documentation Server (maya65docserver) - Unknown owner - C:\Program Files\Alias\Maya6.5\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya6.5\docs\Wrapper.conf (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: Oracle OLAP 9.0.1.0.1 (OLAPServer) - Oracle Corporation - F:\oracle\ora90\bin\xsolap.exe
O23 - Service: Oracle OLAP Agent - Unknown owner - F:\oracle\ora90\bin\xsaagent.exe
O23 - Service: OracleOraHome90Agent - Oracle Corporation - F:\oracle\ora90\bin\agntsrvc.exe
O23 - Service: OracleOraHome90ClientCache - Unknown owner - F:\oracle\ora90\BIN\ONRSD.EXE
O23 - Service: OracleOraHome90HTTPServer - Unknown owner - F:\oracle\ora90\Apache\Apache\Apache.exe
O23 - Service: OracleOraHome90PagingServer - Unknown owner - F:\oracle\ora90/bin/pagntsrv.exe
O23 - Service: OracleOraHome90SNMPPeerEncapsulator - Unknown owner - F:\oracle\ora90\BIN\ENCSVC.EXE
O23 - Service: OracleOraHome90SNMPPeerMasterAgent - Unknown owner - F:\oracle\ora90\BIN\AGNTSVC.EXE
O23 - Service: OracleOraHome90TNSListener - Unknown owner - F:\oracle\ora90\BIN\TNSLSNR.exe
O23 - Service: OracleServiceANIL - Oracle Corporation - f:\oracle\ora90\bin\ORACLE.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Visibroker Smart Agent (xsSmartAgent) - Unknown owner - F:\oracle\ora90\bin\osagent.exe
O23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe


Here is my System Configuration :

AMD Athlon XP 2600
Microsoft Windows XP SP2
Asus A7N8X - E Motherboard
512 MB Ram
GeForce 5200 LE Graphic Card

Running :
Norton Antivirus 2004 Professional
Windows Firewall


Tiill now... I've used all these softwares for scaning and removing scrap from my system.

1) CCleaner
2) Ad-Aware
3) Trojan Hunter
4) Spyware Blaster
5) Spybot S& D


Khattam says....
If you have Ntfs partition/s then rude shutdowns ......

Yes, I'm having FAT32 Partition on my system.

anomit says:
You used POWERSCAN!!!!!!!!!!
It itself is an adware....

Yes anomit, you are very right. I didn't installed POWERSCAN manually as its get downloaded by itself and works when i boot my system.

Now I need you people help in order to protect my system.

I'll perform the steps given by anomit for POWERSCAN.
 
D

dinesh_singh

Guest
why worry

the simpleast solution to any windows problem is :-
step1:-boot into dos mode
step2:-format c:{parameters}
step3:-reinstall windows
step4:-install every basic soft
step5:-backup ur os with norton ghost

if problem arise next time repeat all the steps.

if u think you are infacted by a virus.
format each and every single partition
:lol: 8)
 

anomit

In the zone
Scan again using HJT and remove these entries(i.e. fix them)


R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

O23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe
 

swatkat

Technomancer
Download Ewido, CleanUp! and install them.

Right-Click on the empty spot of Desktop, choose "New" > "Text Document" to open NotePad. Copy the contents of the below "Code" box, and paste it in NotePad:-
Code:
@ECHO OFF
cd %windir%
Nail.exe /FULLREMOVE
sc config SvcProc start= disabled
sc stop SvcProc
sc delete SvcProc
attrib -s -r -h nail.exe
attrib -s -r -h svcproc.exe
del nail.exe
del svcproc.exe
exit
Go to File> Save As and type filename as Fix.bat and save it. Exit from NotePad.



Boot in SAFE mode.

Double-Click on Fix.bat, window opens up and closes-- this is normal.
Run Ewido and perform a FULL System scan using it.

Run HijackThis and click "Do only a system scan". Put a checkmark against these entries:-

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll
O2 - BHO: Loader Class - {2E246FAE-8420-11D9-870D-000C2917DE7F} - C:\WINDOWS\SYSTEM\Loader.dll
O2 - BHO: BHOmodObj Class - {7F6828CA-9E42-462C-BC60-418C8144012C} - c:\windows\system\BHOmod.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - (no file)
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\system32\cmd32.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [yvmjsz] C:\WINDOWS\yvmjsz.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\W
O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\kernels32.exe
O4 - HKLM\..\Run: [zbrvilo] c:\windows\system32\umnawac.exe
O4 - HKCU\..\Run: [wupd] C:\WINDOWS\system32\win32.exe
O4 - HKCU\..\Run: [SNInstall] C:\WINDOWS\system32\vxh8jkdq2.exe
O4 - HKCU\..\Run: [wfzf] C:\PROGRA~1\COMMON~1\wfzf\wfzfm.exe
O13 - DefaultPrefix: *craftsmensearch.com/gall.php?url=
O13 - WWW Prefix: *craftsmensearch.com/gall.php?url=
O13 - Home Prefix: *craftsmensearch.com/gall.php?url=
O13 - Mosaic Prefix: *craftsmensearch.com/gall.php?url=
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - *static.windupdates.com/cab/CDT/ie/bridge-c7.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - *www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
O21 - SSODL: System - {AF44CE72-17C8-49DC-B8D9-4CD9E1D788AF} - vr_sys.dll (file missing)
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe


Click "Fix Checked" and exit from HijackThis.



Delete these files:-
C:\WINDOWS\system32\cmd32.exe
C:\WINDOWS\system32\kernels32.exe
C:\PROGRA~1\COMMON~1\wfzf\wfzfm.exe
c:\windows\system32\umnawac.exe
C:\WINDOWS\system32\win32.exe
C:\WINDOWS\system32\vxgamet2.exe
C:\WINDOWS\zeta.exe
C:\WINDOWS\nem220.dll
C:\WINDOWS\SYSTEM\Loader.dll
c:\windows\system\BHOmod.dll
C:\WINDOWS\yvmjsz.exe
C:\W
C:\WINDOWS\system32\vxh8jkdq2.exe
C:\WINDOWS\isrvs\mfiltis.dll
C:\WINDOWS\zeta.exe

Run CleanUp! and click "Options", here move the slider to "Thorough" position and click OK to warning message and exit from Options. Click "CleanUp" and after cleaning click "Close" and reboot to Normal Mode and post a FRESH log
 
Status
Not open for further replies.
Top Bottom