Jump to content

Another recurring trojan


Recommended Posts

Downloaded Malwarebytes software and has got rid of some nasty sh*t for me. Although, i'm having a problem with a recurring trojan, 'svchost.exe'.

Seems to slow my CPU down quite noticeably and wondering how do i get rid of such a thing. Below are my logs.

Thanks.

MBAM LOG

Malwarebytes' Anti-Malware 1.29

Database version: 1279

Windows 5.1.2600 Service Pack 2

2008-10-23 14:07:17

mbam-log-2008-10-23 (14-07-06).txt

Scan type: Quick Scan

Objects scanned: 52108

Time elapsed: 3 minute(s), 1 second(s)

Memory Processes Infected: 1

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

C:\WINDOWS\svchost.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\svchost.exe (Trojan.Agent) -> No action taken.

END MBAM LOG

PANDA ACTIVE SCAN

;*******************************************************************************

*********************

ANALYSIS: 2008-10-23 14:36:07

PROTECTIONS: 0

MALWARE: 27

SUSPECTS: 4

;*******************************************************************************

*****************

PROTECTIONS

Description Version Active Updated

;===============================================================================

======================

;===============================================================================

=====================

Id Description Type Active Severity Disinfectable Disinfected Location

;===============================================================================

=====================\hwh@casalemedia[1].txt

00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@doubleclick[1].txt

00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@atdmt[2].txt

00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@tradedoubler[2].txt

00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@mediaplex[2].txt

00145758 Cookie/Mysearch TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@mysearch[2].txt

00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@ad.yieldmanager[2].txt

00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@apmebf[1].txt

00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@serving-sys[1].txt

00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@bs.serving-sys[2].txt

00169287 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@adrevolver[1].txt

00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@statse.webtrendslive[2].txt

00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@overture[1].txt

00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@zedo[1].txt

00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\HWH\Cookies\hwh@adrevolver[2].txt

00505668 Application/MyWebSearch HackTools No 0 Yes No C:\Program Files\AskTBar\SrchAstt\1.BIN\A5SRCHAS.DLL

00518189 Application/WebThunder HackTools No 0 Yes No C:\Program Files\Thunder Network\WebThunder\historyinfo_manage.dll

00518189 Application/WebThunder HackTools No 0 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP24\A0011894.DLL

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No F:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP61\A0023448.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\WINDOWS\SYSTEM32\SLPOOV.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\WINDOWS\SYSTEM32\SPLOOV.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No E:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP61\A0023446.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No D:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP61\A0023444.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP62\A0023752.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan Yes 2 Yes No C:\WINDOWS\svchost.exe

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\WINDOWS\BSR.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP62\A0023735.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP62\A0023731.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP62\A0023709.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP62\A0023705.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP61\A0023442.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP61\A0023478.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP61\A0023485.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP61\A0023512.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP61\A0023555.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP61\A0023562.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP61\A0023571.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP61\A0023578.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP61\A0023603.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP61\A0023607.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP62\A0023650.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP62\A0023662.EXE

00521510 Trj/Multidropper.RDM Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP62\A0023666.EXE

01469292 Generic Malware Virus/Trojan No 0 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP24\A0011889.DLL

01469292 Generic Malware Virus/Trojan No 0 Yes No C:\Program Files\Thunder Network\WebThunder\WebThunder_SetupHelper.dll

02069647 Application/WebThunder HackTools No 0 Yes No D:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP7\A0003692.EXE

02931449 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{803C33F0-16E2-4E9F-96CF-5A63FE07B3A0}\RP23\A0013923.EXE

02931449 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{803C33F0-16E2-4E9F-96CF-5A63FE07B3A0}\RP28\A0019726.EXE

03252395 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{803C33F0-16E2-4E9F-96CF-5A63FE07B3A0}\RP23\A0013935.EXE

03252395 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{803C33F0-16E2-4E9F-96CF-5A63FE07B3A0}\RP28\A0019738.EXE

03431940 W32/Gaobot.OXI.worm Virus/Worm No 0 Yes No D:\System Volume Information\_restore{803C33F0-16E2-4E9F-96CF-5A63FE07B3A0}\RP28\A0019725.EXE

03431940 W32/Gaobot.OXI.worm Virus/Worm No 0 Yes No D:\System Volume Information\_restore{803C33F0-16E2-4E9F-96CF-5A63FE07B3A0}\RP23\A0013922.EXE

03446216 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{803C33F0-16E2-4E9F-96CF-5A63FE07B3A0}\RP28\A0019743.EXE

03446216 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{803C33F0-16E2-4E9F-96CF-5A63FE07B3A0}\RP23\A0013940.EXE

03534005 Adware/RogueAntimalware2008 Adware No 0 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP14\A0008361.EXE

03653480 Trj/Rizalof.RV Virus/Trojan No 1 Yes No D:\System Volume Information\_restore{803C33F0-16E2-4E9F-96CF-5A63FE07B3A0}\RP23\A0013934.EXE

03653480 Trj/Rizalof.RV Virus/Trojan No 1 Yes No D:\System Volume Information\_restore{803C33F0-16E2-4E9F-96CF-5A63FE07B3A0}\RP28\A0019737.EXE

03839851 Trj/Downloader.MDW Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP45\A0020964.SYS

03839851 Trj/Downloader.MDW Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP56\A0022503.SYS

03839851 Trj/Downloader.MDW Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP24\A0011974.SYS

03839851 Trj/Downloader.MDW Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP59\A0023129.SYS

03839851 Trj/Downloader.MDW Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{5A843C36-1ABF-4442-B764-5AC2BD315308}\RP14\A0008372.SYS

;==================================================================

Sent Location

;====================================================================

No C:\WINDOWS\FLY.EXE

No C:\Program Files\Tencent\QQMusic\TNProxy.dll

No D:\System Volume Information\_restore{803C33F0-16E2-4E9F-96CF-5A63FE07B3A0}\RP19\A0002199.EXE

No D:\Applications\Trojan Remover 6.7.1\CRACK\RMT.DTA

;======================================================================

VULNERABILITIES

Id Severity Description

;=====================================================================

184380 MEDIUM MS08-002

184379 MEDIUM MS08-001

182048 HIGH MS07-069

182046 HIGH MS07-067

182043 HIGH MS07-064

179553 HIGH MS07-061

176382 HIGH MS07-057

176383 HIGH MS07-058

170911 HIGH MS07-050

170907 HIGH MS07-046

170906 HIGH MS07-045

170904 HIGH MS07-043

164915 HIGH MS07-035

164913 HIGH MS07-033

164911 HIGH MS07-031

160623 HIGH MS07-027

157262 HIGH MS07-022

157261 HIGH MS07-021

157260 HIGH MS07-020

157259 HIGH MS07-019

156477 HIGH MS07-017

150253 HIGH MS07-016

150249 HIGH MS07-013

150248 HIGH MS07-012

150247 HIGH MS07-011

150243 HIGH MS07-008

150242 HIGH MS07-007

150241 MEDIUM MS07-006

141034 HIGH MS06-076

141033 MEDIUM MS06-075

141030 HIGH MS06-072

137571 HIGH MS06-070

137568 HIGH MS06-067

133387 MEDIUM MS06-065

133386 MEDIUM MS06-064

133385 MEDIUM MS06-063

133379 HIGH MS06-057

131654 HIGH MS06-055

129977 MEDIUM MS06-053

129976 MEDIUM MS06-052

126093 HIGH MS06-051

126092 MEDIUM MS06-050

126087 HIGH MS06-046

126086 MEDIUM MS06-045

126083 HIGH MS06-042

126082 HIGH MS06-041

126081 HIGH MS06-040

123421 HIGH MS06-036

123420 HIGH MS06-035

120825 MEDIUM MS06-032

120823 MEDIUM MS06-030

120818 HIGH MS06-025

120815 HIGH MS06-022

120814 HIGH MS06-021

117384 MEDIUM MS06-018

114666 HIGH MS06-015

114664 HIGH MS06-013

108744 MEDIUM MS06-008

108743 MEDIUM MS06-007

108742 MEDIUM MS06-006

104567 HIGH MS06-002

104237 HIGH MS06-001

96574 HIGH MS05-053

93395 HIGH MS05-051

93394 HIGH MS05-050

93454 MEDIUM MS05-049

;=====================

END PANDA ACTIVE SCAN

HIJACK THIS LOG

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:56:15, on 2008-10-23

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\DNA\btdna.exe

C:\WINDOWS\system32\conime.exe

C:\WINDOWS\system32\agrsmsvc.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\StormII\stormliv.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL

O2 - BHO: WebThunderBHO - {00000AAA-A363-466E-BEF5-9BB68697AA7F} - C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_Now.dll

O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL

O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL

O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\StormII\Codec\qttask.exe" -atboottime

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bitTorrent DNA] "C:\Program Files\DNA\btdna.exe"

O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: sploov.exe.lnk = C:\WINDOWS\system32\slpoov.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: 使用WEB迅雷下载 - C:\Program Files\Thunder Network\WebThunder\GetUrl.htm

O8 - Extra context menu item: 使用WEB迅雷下载全部链接 - C:\Program Files\Thunder Network\WebThunder\GetAllUrl.htm

O8 - Extra context menu item: 使用迅雷下载 - C:\Program Files\Thunder Network\Thunder\Program\geturl.htm

O8 - Extra context menu item: 使用迅雷下载全部链接 - C:\Program Files\Thunder Network\Thunder\Program\getallurl.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe (file missing)

O9 - Extra 'Tools' menuitem: 启动迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe (file missing)

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: 启动WEB迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)

O9 - Extra 'Tools' menuitem: 启动WEB迅雷 - {962EFB8E-2683-42d4-AC74-AAA4C759B9C6} - http://my.xunlei.com (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {1E0DFFCF-27FF-4574-849B-55007349FEDA} (iTrusPTA Class) - https://img.alipay.com/download/1101/aliedit.cab

O16 - DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} (EditCtrl Class) - https://img.alipay.com/download/2121/aliedit.cab

O16 - DPF: {73E4740C-08EB-4133-896B-8D0A7C9EE3CD} (AxInputControl Class) - https://b2c.icbc.com.cn/icbc/newperbank/AXSafeControls.cab

O16 - DPF: {F3E70CEA-956E-49CC-B444-73AFE593AD7F} (XPPlayer Class) - http://down.sandai.net/kankan/KanKanPlayer.cab

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: Contrl Center of Storm Media (ccosm) - 北京暴风网际科技有限公司 - C:\Program Files\StormII\stormliv.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O24 - Desktop Component 0: Privacy Protection - (no file)

--

End of file - 5581 bytes

END HIJACKTHIS LOG

Link to post
Share on other sites

  • Root Admin

The log for MBAM says you did not tell it to clean it.

Run HJT and do a Scan only and place a check mark on this item

O4 - Startup: sploov.exe.lnk = C:\WINDOWS\system32\slpoov.exe

Then click on Fix selected...

Start MBAM go to the UPDATE tab and update the program. Do a Quick Scan after update and make sure you FIX anything found and REBOOT your computer.

After the reboot run another HJT scan and save the log then post back the logs from MBAM and HJT

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.