Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice
Status
Not open for further replies.
1 - 14 of 14 Posts

·
Registered
Joined
·
7 Posts
Discussion Starter · #1 ·
I know the more information the better, but can someone tell me if this log from HijackThis notes anything I need to worry about?

Logfile of HijackThis v1.99.1
Scan saved at 7:46:20 PM, on 09/01/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\ZoneLabs\minilog.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Classic PhoneTools\CapFax.EXE
C:\Program Files\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPROV.EXE
C:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\Kate\My Documents\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://fwalerts.zonelabs.com/fwaler...0,Windows+NT-5.1.2600--SP,2.6.362,ExtBlockAll, (obfuscated)
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - C:\WINDOWS\System32\ipv6mons.dll
O2 - BHO: (no name) - {7ACB5731-5839-13AB-EABC-124791194525} - C:\WINDOWS\System32\msindeo.dll
O2 - BHO: Still Image - {E8656DAF-0229-BA16-E97D-31557D631863} - C:\WINDOWS\system\mtstct32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1168132527343
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1168132507671
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: IEFilter - {40679472-C962-4C35-89B4-17756C8562A8} - C:\WINDOWS\system32\IEFilter.dll
O23 - Service: AVG6 Service (AvgServ) - GRISOFT s.r.o - C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Basic Logging Client (minilog) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\minilog.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I appreciate anyone's help.
Thanks.
 

·
Retired Moderator
Joined
·
72,109 Posts
Hi, Welcome to TSG!!

You need to go here and install "Service Pack 1" This will patch numerous security holes in IE and Windows. As your machine stands now it is wide open to attack from all sorts of nasties. You need to get these updates before we proceed or we will be wasting our time.

DO NOT install Service pack 2 yet. If you install SP 2 on an infected machine it will cause serious problems. Just get Service Pack 1 installed. After you get SP1 installed, restart your computer. Come back here and post the new Hijack This log.
 

·
Registered
Joined
·
7 Posts
Discussion Starter · #3 ·
Thank you for your reply.

I tried to get the Windows Service Pack, but apparently the windows on this computer is not "genuine", so it won't download. I'll have to contact the computer's owner and see what I can do about it.

Thanks again for your help.
 

·
Registered
Joined
·
7 Posts
Discussion Starter · #5 ·
Until I can re-install windows, I decided to scan the system with a more updated scanner. AVG caught some major problems, and I saved the report, which I've posted below. Does this mean that AVG has removed the harmful files? Is there anything more I can do to protect my computer?

Thanks.

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 7:20:59 PM 16/01/2007

+ Scan result:

C:\System Volume Information\_restore{FD9259D5-9868-4893-8C6D-0B3988CABC94}\RP113\A0018211.DLL -> Adware.Funweb : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Cleaned with backup (quarantined).
[172] VM_02600000 -> Logger.BZub.fh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FD9259D5-9868-4893-8C6D-0B3988CABC94}\RP124\A0018866.dll -> Logger.Small.ez : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FD9259D5-9868-4893-8C6D-0B3988CABC94}\RP124\A0018867.dll -> Logger.Small.ez : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FD9259D5-9868-4893-8C6D-0B3988CABC94}\RP124\A0018872.dll -> Logger.Small.ez : Cleaned with backup (quarantined).
C:\Program Files\FunWebProducts\Installr\1.bin\F3EZSETP.DLL -> Not-A-Virus.Downloader.Win32.FunWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FD9259D5-9868-4893-8C6D-0B3988CABC94}\RP124\A0018865.exe -> Proxy.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FD9259D5-9868-4893-8C6D-0B3988CABC94}\RP124\A0018882.exe -> Proxy.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Kate\Cookies\[email protected][1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Bfast : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Centrport : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Clickagents : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Commission-junction : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Findwhat : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Gator : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\DAWN\Cookies\daw[email protected][2].txt -> TrackingCookie.Hitslink : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Linksynergy : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][3].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.X10 : Cleaned.
C:\Documents and Settings\DAWN\Cookies\[email protected][2].txt -> TrackingCookie.Zedo : Cleaned.

::Report end
 

·
Retired Moderator
Joined
·
72,109 Posts
Most of that was tracking cookies in system restore.

Run HijackThis and click Open the Misc Tools section
Click Open Uninstall Manager, Save list and save the log to your Desktop.
A list of programs will open in Notepad. Post the contents of the log here in your next reply.
 

·
Registered
Joined
·
7 Posts
Discussion Starter · #7 ·
ACDSee Classic
Adobe Acrobat 5.0
Adobe Flash Player 9 ActiveX
Ahead InCD
Ahead InCD EasyWrite Reader
Ahead NeroMediaPlayer
aspi
ASUS Features
AVG Anti-Spyware 7.5
Caillou(R) Four Seasons of Fun
Callserve Internet Telephone
CCHelp
CCScore
Classic PhoneTools
CR2
Disney/Pixar's Buzz Lightyear 1st Grade
Easy DVD Player 1.0
EPSON Printer Software
ESSAdpt
ESSANUP
ESSBrwr
ESSCAM
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSTUTOR
ESSvpaht
ESSvpot
FinePixViewer Ver.4.0
FUJIFILM USB Driver
HijackThis 1.99.1
ImageMixer VCD for FinePix
Intel(R) Extreme Graphics Driver
JumpStart 6th Grade 2001
K-Lite Codec Pack 2.82 Standard
Kodak EasyShare software
KSU
Logitech Desktop Messenger
Logitech IM Video Companion
Logitech ImageStudio
Logitech Print Service
Microsoft Office 2000 Premium
Microsoft XML Parser and SDK
MicroStaff WINASPI NT
Nero - Burning Rom
Notifier
OTtBP
PCDLNCH
QuickTime
RAW FILE CONVERTER LE
RealPlayer 7 Basic
SFR
SFR2
SoundMAX
The Baby-sitters Club(tm) 4th Grade
True Internet Color
Winamp3 (remove only)
Windows Live Messenger
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB823980
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB842773
Windows XP Hotfix (SP1) [See Q321856 for more information]
Windows XP Hotfix (SP1) [See Q329390 for more information]
Windows XP Hotfix (SP1) [See Q329441 for more information]
Windows XP Hotfix (SP1) Q329170
Windows XP Hotfix (SP1) Q810577
Windows XP Hotfix (SP1) Q810833
Windows XP Hotfix (SP1) Q815021
Windows XP Hotfix (SP1) Q817606
Windows XP Hotfix (SP2) [See Q329115 for more information]
ZoneAlarm
 

·
Registered
Joined
·
7 Posts
Discussion Starter · #9 ·
I run AVG pretty much daily now, and it always seems to find at least one High Risk item (usually Logger.BZub.hg), and multiple Medium Risk items. Can I come to expect that to happen without proper Windows protection, or is there just something that AVG is not removing? I ran a scan just before writing here and it found a Logger.BZub.hg. When I applied all actions, it did not give me the chance to save the report - instead I was asked to reboot to ensure the threat was removed. I scanned the system after the reboot, and no High Risk items were found.

Also, when I try to update AVG with it's internal update, it says it cannot connect. How can I fix it so that it will?

Lastly, what are the "Windows XP Hotfix" programs listed in the last post?

I really appreciate all your help. Thanks again :)

Below are the last couple scan reports (except the one that asked me to reboot).

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 9:32:58 PM 18/01/2007

+ Scan result:

C:\Documents and Settings\Kate\Cookies\[email protected][1].txt -> TrackingCookie.Atdmt : Cleaned.

::Report end

AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 11:11:19 PM 17/01/2007

+ Scan result:

[440] VM_00B80000 -> Logger.BZub.fh : Cleaned with backup (quarantined).
C:\Documents and Settings\Kate\Cookies\[email protected][2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Kate\Cookies\[email protected][2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Kate\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Kate\Cookies\[email protected][1].txt -> TrackingCookie.Mediaplex : Cleaned.

::Report end

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 10:01:49 PM 17/01/2007

+ Scan result:

[440] VM_02740000 -> Logger.BZub.fh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FD9259D5-9868-4893-8C6D-0B3988CABC94}\RP124\A0018953.DLL -> Not-A-Virus.Downloader.Win32.FunWeb : Cleaned with backup (quarantined).
C:\Documents and Settings\Kate\Cookies\[email protected][1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Kate\Cookies\[email protected][2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Kate\Cookies\[email protected][1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Kate\Cookies\[email protected][2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Kate\Cookies\[email protected][1].txt -> TrackingCookie.Centrport : Cleaned.
C:\Documents and Settings\Kate\Cookies\[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Kate\Cookies\[email protected][1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Kate\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Kate\Cookies\[email protected][1].txt -> TrackingCookie.Tribalfusion : Cleaned.

::Report end---------------------------------------------------------
 

·
Retired Moderator
Joined
·
72,109 Posts
Flush your System Restore:

  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.
  • Restart the computer.

To create a new restore point:
  • Start go to All Programs
  • Accessories, System Tools and select System Restore.
  • In the System Restore wizard, select "Create a restore point" and click the Next button.
  • Type a description for your new restore point. Something like "After trojan/spyware cleanup".
  • Click Create and you're done.
 

·
Registered
Joined
·
7 Posts
Discussion Starter · #11 ·
I turned off the system restore, and when I went to turn it on, there was no wizard or option for "create retore point". It opened the same window as did mycomputer/properties.

Not sure how to go forward.
 

·
Registered
Joined
·
7 Posts
Discussion Starter · #13 ·
I found the wizard, and created the new retore point. Also, the last couple of AVG scans have found Medium Risks, but have not found any High Risk items :)

Should this have helped me to be able to connect the AVG update? And I just want to be sure that "Windows XP Hotfix" programs are not something I should remove.

I'm very grateful that this site is available for this kind of help. You've been great.
 

·
Retired Moderator
Joined
·
72,109 Posts
I would need to see what AVG is finding before I could comment. If they are cookies it's not terrible.

Don't remove the hotfixes they take up space but are harmless.

I'm happy you got the system restore working! :up:


You're welcome, my pleasure!
 
1 - 14 of 14 Posts
Status
Not open for further replies.
Top