1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

cant remove infostealer.gamepass silent runner log attatched

Discussion in 'Malware and Virus Removal Archive' started by superfishball, 2008/01/23.

  1. 2008/01/23
    superfishball

    superfishball Inactive Thread Starter

    Joined:
    2008/01/23
    Messages:
    1
    Likes Received:
    0
    hi
    yesterday my com found a virus called Infostealer.Gamepass and cannot remove it no matter which antivirus software i tried, one of my friends told me i should post a silent runner log here so help. sooo here it is

    "Silent Runners.vbs ", revision 55, http://www.silentrunners.org/
    Operating System: Windows Vista
    Output limited to non-default values, except where indicated by "{++} "


    Startup items buried in registry:
    ---------------------------------

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
    "WMPNSCFG" = "C:\Program Files\Windows Media Player\WMPNSCFG.exe" [MS]

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
    "Windows Defender" = "C:\Program Files\Windows Defender\MSASCui.exe -hide "
    "NvSvc" = "RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart" [MS]
    "NvCplDaemon" = "RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup" [MS]
    "NvMediaCenter" = "RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit" [MS]
    "Apoint" = "C:\Program Files\Apoint\Apoint.exe" [ "Alps Electric Co., Ltd."]
    "ISBMgr.exe" = " "C:\Program Files\Sony\ISB Utility\ISBMgr.exe" " [ "Sony Corporation"]
    "E-Flyer" = " "C:\Program Files\Sony\E-Flyer\SubFlyer.exe" " [null data]
    "ccApp" = " "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" " [ "Symantec Corporation"]
    "osCheck" = " "C:\Program Files\Norton Internet Security\osCheck.exe" " [ "Symantec Corporation"]
    "ISUSScheduler" = " "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start" [ "Macrovision Corporation"]
    "VAIOCameraUtility" = " "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" " [ "Sony Corporation"]
    "PrepareYourVAIO" = "C:\Program Files\Sony\Prepare your VAIO\PYVAlert.exe" [ "Sony Corporation"]
    "Symantec PIF AlertEng" = " "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" " [ "Symantec Corporation"]
    "QuickTime Task" = " "C:\Program Files\QuickTime\QTTask.exe" -atboottime" [ "Apple Inc."]
    "AVG7_CC" = "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP" [ "GRISOFT, s.r.o."]

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "Adobe PDF Reader Link Helper "
    \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" [ "Adobe Systems Incorporated"]
    {1E8A6170-7264-4D0F-BEAE-D42A53123C75}\(Default) = (no title provided)
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll" [ "Symantec Corporation"]

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
    "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class "
    -> {HKLM...CLSID} = "DesktopContext Class "
    \InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" [ "NVIDIA Corporation"]
    "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper "
    -> {HKLM...CLSID} = "NVIDIA CPL Extension "
    \InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" [ "NVIDIA Corporation"]
    "{ED58A35B-B554-42AF-A26C-6F3D424200D3}" = "Sony Power Management Extensiond "
    -> {HKLM...CLSID} = "SPMPanel "
    \InProcServer32\(Default) = "C:\Program Files\Sony\VAIO Power Management\SPMPanel.dll" [ "Sony Corporation"]
    "{C6643EC0-49AC-4c15-A455-04104DB900A9}" = "Image Converter context menu extension "
    -> {HKLM...CLSID} = "Image Converter context menu "
    \InProcServer32\(Default) = "C:\PROGRA~1\Sony\IMAGEC~1\CtxMenu.dll" [" "]
    "{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C}" = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search "
    -> {HKLM...CLSID} = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search "
    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\ONFILTER.DLL" [MS]
    "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler "
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [MS]
    "{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler "
    -> {HKLM...CLSID} = "Microsoft Office Metadata Handler "
    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]
    "{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler "
    -> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler "
    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]
    "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension "
    -> {HKLM...CLSID} = "WinRAR "
    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
    "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension "
    -> {HKLM...CLSID} = "AVG7 Shell Extension Class "
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" [ "GRISOFT, s.r.o."]
    "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension "
    -> {HKLM...CLSID} = "AVG7 Find Extension Class "
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" [ "GRISOFT, s.r.o."]

    HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\
    <<!>> text/xml\CLSID = "{807563E5-5146-11D5-A672-00B0D022E945} "
    -> {HKLM...CLSID} = "Microsoft Office InfoPath XML Mime Filter "
    \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL" [MS]

    HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
    {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info "
    -> {HKLM...CLSID} = "PDF Shell Extension "
    \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" [ "Adobe Systems, Inc."]

    HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
    AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} "
    -> {HKLM...CLSID} = "AVG7 Shell Extension Class "
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" [ "GRISOFT, s.r.o."]
    ImageConverter3\(Default) = "{C6643EC0-49AC-4c15-A455-04104DB900A9} "
    -> {HKLM...CLSID} = "Image Converter context menu "
    \InProcServer32\(Default) = "C:\PROGRA~1\Sony\IMAGEC~1\CtxMenu.dll" [" "]
    Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} "
    -> {HKLM...CLSID} = "IEContextMenu Class "
    \InProcServer32\(Default) = "C:\PROGRA~1\NORTON~1\NORTON~1\NavShExt.dll" [ "Symantec Corporation"]
    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA} "
    -> {HKLM...CLSID} = "WinRAR "
    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

    HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
    ImageConverter3\(Default) = "{C6643EC0-49AC-4c15-A455-04104DB900A9} "
    -> {HKLM...CLSID} = "Image Converter context menu "
    \InProcServer32\(Default) = "C:\PROGRA~1\Sony\IMAGEC~1\CtxMenu.dll" [" "]
    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA} "
    -> {HKLM...CLSID} = "WinRAR "
    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

    HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
    AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} "
    -> {HKLM...CLSID} = "AVG7 Shell Extension Class "
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" [ "GRISOFT, s.r.o."]
    Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA} "
    -> {HKLM...CLSID} = "IEContextMenu Class "
    \InProcServer32\(Default) = "C:\PROGRA~1\NORTON~1\NORTON~1\NavShExt.dll" [ "Symantec Corporation"]
    WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA} "
    -> {HKLM...CLSID} = "WinRAR "
    \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


    Group Policies {GPedit.msc branch and setting}:
    -----------------------------------------------

    Note: detected settings may not have any effect.

    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\

    "ConsentPromptBehaviorAdmin" = (REG_DWORD) dword:0x00000002
    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    User Account Control: Behavior Of The Elevation Prompt For Administrators In Admin Approval Mode}

    "ConsentPromptBehaviorUser" = (REG_DWORD) dword:0x00000001
    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    User Account Control: Behavior Of The Elevation Prompt For Standard Users}

    "EnableInstallerDetection" = (REG_DWORD) dword:0x00000001
    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    User Account Control: Detect Application Installations And Prompt For Elevation}

    "EnableLUA" = (REG_DWORD) dword:0x00000001
    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    User Account Control: Run All Administrators In Admin Approval Mode}

    "EnableSecureUIAPaths" = (REG_DWORD) dword:0x00000001
    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    User Account Control: Only elevate UIAccess applications that are installed in secure locations}

    "EnableVirtualization" = (REG_DWORD) dword:0x00000001
    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    User Account Control: Virtualize file and registry write failures to per-user locations}

    "PromptOnSecureDesktop" = (REG_DWORD) dword:0x00000001
    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    User Account Conrol: Switch to the secure desktop when prompting for elevation}

    "shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001
    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    Shutdown: Allow system to be shut down without having to log on}

    "undockwithoutlogon" = (REG_DWORD) dword:0x00000001
    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    Devices: Allow undock without having to log on}

    "FilterAdministratorToken" = (REG_DWORD) dword:0x00000000
    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    User Account Control: Admin Approval Mode for the Built-in Administrator Account}


    Active Desktop and Wallpaper:
    -----------------------------

    Active Desktop may be disabled at this entry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

    Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
    HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
    "Wallpaper" = "C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp "

    Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
    HKCU\Control Panel\Desktop\
    "Wallpaper" = "C:\Users\User\AppData\Roaming\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp "


    Enabled Screen Saver:
    ---------------------

    HKCU\Control Panel\Desktop\
    "SCRNSAVE.EXE" = "C:\Windows\system32\logon.scr" [MS]


    Startup items in "User" & "All Users" startup folders:
    ------------------------------------------------------

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    "Bluetooth Manager" -> shortcut to: "C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe" [ "TOSHIBA CORPORATION."]


    Winsock2 Service Provider DLLs:
    -------------------------------

    Namespace Service Providers

    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
    000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS]
    000000000002\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
    000000000003\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
    000000000004\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS]
    000000000005\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
    000000000006\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]

    Transport Service Providers

    HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
    0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
    %SystemRoot%\system32\mswsock.dll [MS], 01 - 22


    Toolbars, Explorer Bars, Extensions:
    ------------------------------------

    Toolbars

    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
    "{F2CF5485-4E02-4F68-819C-B92DE9277049} "
    -> {HKLM...CLSID} = "&Links "
    \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS]

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
    "{90222687-F593-4738-B738-FBEE9C7B26DF}" = "NCO Toolbar "
    -> {HKLM...CLSID} = "Show Norton Toolbar "
    \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll" [ "Symantec Corporation"]

    Explorer Bars

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\

    HKLM\SOFTWARE\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Research "
    Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
    InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL" [MS]

    Extensions (Tools menu items, main toolbar menu buttons)

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
    {2670000A-7350-4F3C-8081-5663EE0C6C49}\
    "ButtonText" = "Send to OneNote "
    "MenuText" = "S&end to OneNote "
    "CLSIDExtension" = "{48E73304-E1D6-4330-914C-F5F514E3486C} "
    -> {HKLM...CLSID} = "Send to OneNote from Internet Explorer button "
    \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll" [MS]

    {92780B25-18CC-41C8-B9BE-3C9C571A8263}\
    "ButtonText" = "Research "


    HOSTS file
    ----------

    C:\Windows\System32\drivers\etc\HOSTS

    maps: 2 domain names to IP addresses,
    1 of the IP addresses is *not* localhost!


    Running Services (Display Name, Service Name, Path {Service DLL}):
    ------------------------------------------------------------------

    Automatic LiveUpdate Scheduler, Automatic LiveUpdate Scheduler, " "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" " [ "Symantec Corporation"]
    AVG E-mail Scanner, AVGEMS, "C:\PROGRA~1\Grisoft\AVG7\avgemc.exe" [ "GRISOFT, s.r.o."]
    AVG Firewall Service, AVGFw2kv, "C:\PROGRA~1\Grisoft\AVG7\avgfw2kv.exe /srvfsys" [ "GRISOFT, s.r.o."]
    AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe" [ "GRISOFT, s.r.o."]
    AVG7 Resident Shield Service, AvgCoreSvc, "C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe" [ "GRISOFT, s.r.o."]
    AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe" [ "GRISOFT, s.r.o."]
    CNG Key Isolation, KeyIso, "C:\Windows\system32\lsass.exe" [MS]
    Computer Browser, Browser, "C:\Windows\System32\svchost.exe -k netsvcs" { "C:\Windows\System32\browser.dll" [MS]}
    Extensible Authentication Protocol, EapHost, "C:\Windows\System32\svchost.exe -k netsvcs" { "C:\Windows\System32\eapsvc.dll" [MS]}
    IviRegMgr, IviRegMgr, "C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe" [ "InterVideo"]
    LiveUpdate Notice Service Ex, LiveUpdate Notice Ex, " "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon" [ "Symantec Corporation"]
    SigmaTel Audio Service, STacSV, "C:\Windows\system32\stacsv.exe" [ "SigmaTel, Inc."]
    SQL Server (VAIO_VEDB), MSSQL$VAIO_VEDB, " "C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sVAIO_VEDB" [MS]
    Symantec AppCore Service, SymAppCore, " "C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe" " [ "Symantec Corporation"]
    Symantec Core LC, Symantec Core LC, " "C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe" " [ "Symantec Corporation"]
    Symantec Event Manager, ccEvtMgr, " "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon" [ "Symantec Corporation"]
    Symantec Lic NetConnect service, CLTNetCnService, " "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon" [ "Symantec Corporation"]
    Symantec Settings Manager, ccSetMgr, " "C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon" [ "Symantec Corporation"]
    TOSHIBA Bluetooth Service, TOSHIBA Bluetooth Service, "C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe" [ "TOSHIBA CORPORATION"]
    VAIO Entertainment Database Service, VzCdbSvc, " "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe" " [ "Sony Corporation"]
    VAIO Entertainment File Import Service, VzFw, "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe" [ "Sony Corporation"]
    VAIO Entertainment UPnP Client Adapter, Vcsw, "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe -RunBySCM" [ "Sony Corporation"]
    VAIO Event Service, VAIO Event Service, "C:\Program Files\Sony\VAIO Event Service\VESMgr.exe" [ "Sony Corporation"]
    Windows Driver Foundation - User-mode Driver Framework, wudfsvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" { "C:\Windows\System32\WUDFSvc.dll" [MS]}
    Windows Image Acquisition (WIA), stisvc, "C:\Windows\system32\svchost.exe -k imgsvc" { "C:\Windows\System32\wiaservc.dll" [MS]}
    Windows Media Player Network Sharing Service, WMPNetworkSvc, " "C:\Program Files\Windows Media Player\wmpnetwk.exe" " [MS]
    WLAN AutoConfig, Wlansvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" { "C:\Windows\System32\wlansvc.dll" [MS]}
    XAudioService, XAudioService, "C:\Windows\system32\DRIVERS\xaudio.exe" [ "Conexant Systems, Inc."]


    Print Monitors:
    ---------------

    HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\
    Send To Microsoft OneNote Monitor\Driver = "msonpmon.dll" [MS]
    Toshiba Bluetooth Monitor\Driver = "tbtmon.dll" [ "TOSHIBA CORPORATION."]


    ---------- (launch time: 2008-01-24 12:43:10)
    <<!>>: Suspicious data at a malware launch point.

    + This report excludes default entries except where indicated.
    + To see *everywhere* the script checks and *everything* it finds,
    launch it from a command prompt or a shortcut with the -all parameter.
    + The search for DESKTOP.INI DLL launch points on all local fixed drives
    took 163 seconds.
    ---------- (total run time: 313 seconds)
     
  2. 2008/01/24
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi superfishball
    Welcome to Windowsbbs :)

    Thanks for the Silent Runners Log, But we need to see a couple different logs.

    Please do the following.

    Please download and install HijackThis and Run a scan then close HJT, then run Deckard's System Scanner and post the main.txt log here. Links and instructions here.

    Thanks
    Geri
     
    Geri,
    #2

  3. to hide this advert.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.