This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Vundo, Redirect, Trojans suspected on my PC

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello I am new to the website & appreciate any help that I will receive. I have a Gateway home PC running Windows XP. I share the computer with my Mom & we both use separate login rooms so our settings are the way we like them. Mid last week she called me in the room because one of those registry cleaner boxes popped up on the screen after she was playing an online game via a popular social networking site. I asked her if she clicked on anything & she said no so I just did control/alt/delete to exit that screen. I then noticed a few days later that popups were coming up frequently even with the pop-up blocker on & then Mcafee flashed a notification that it had blocked a trojan called Vundo!grb. That kept popping up every few minutes so I researched the trojan name & read that Malwarebytes is good for removing it so downloaded that & sure enough a few items turned up (some with Vundo in name of files) after first scan & it removed them.

So fast forward to a couple days ago my Mom told me that someone sent her an email inviting her to some website called Jhoos & that after she clicked it she got an email from friend who said they accepted her invite but she doesn't remember allowing it to send invites to people. Apparently she clicked on the invite within the email from her friend & Jhoos directed her to enter her username & password to the email service that she uses which I couldn't believe she did but anyway I ended up researching Jhoos & it says it is an aggressive malware which I believe is the source of the latest problems.

I noticed yesterday that Mcafee said it had blocked & removed a trojan called Generic.PSW.b & like before that started to come up every few minutes for a period of time & then I noticed that if I typed in a website somehow I would get redirected to a website that I didn't type. I tried to go to one website that had information about the Generic trojan & when clicking on the website the entire site would disappear. I researched information from my phone accessing the internet since computer was having problems & came to conclusion I was now having a browser hijacking problem. I downloaded Windows Defender yesterday & did a scan but that didn't work.

Then late yesterday I noticed when I started the computer up that the Mcafee symbol in the bottom right corner showed up & then a 2nd & sometimes a 3rd one would appear but they would all disappear after I moused over them. Also the usual Mcafee black screen that shows up at start-up mode no longer shows up like it normally would so I know something has happened with Mcafee as a result of the trojans/viruses that have been appearing. I also noticed that other symbols that would normally appear in the bottom right corner of computer at start up don't show up either. If I click on Mcafee from the desk top the security center will show up & all features for that are on.

When I tried to run the Malwarebytes scan last night I noticed I got the windows alert at the bottom right that said my computer might be at risk so I think something triggered the Mcafee antivirus shutoff. I went to the security center & windows security to see if everything was turned on & in the windows security it indicated the antivirus protection was off. After clicking on a few things there & going back it then appeared everything was back on again. I was not having luck removing what I believe are trojans or viruses as the MCafee symbol would still show up multiple times & disappear & the websites like google would get redirected to other sites after typing in searches for specific virus removal & in some cases regular website searches like CNN.

So this morning when I started up the computer I tried to go to google to search for hijackthis downloads & Mcafee displayed that it blocked and removed a Lando trojan. Then the google screen totally disappeared. After numerous times trying to do a search on hijackthis download and & Lando trojan the screen would continue to disappear. So now something is preventing me from searching for certain things related to trojans removal. So far I have seen the names Vundo!grb, Lando, & Generic.PSW.b pop up on Mcafee that it has removed but I don't believe it has been able to remove any of them. Last night I managed to favorite this website as I was starting to read about the hijackthis download & how to get help so I think the trojan was unable to stop me from opening this website somehow & I was able to successfully install hijackthis download & run the hjt logs. Below is the log I did a little while ago If you need me to post the start-up log or the hjt log from my Mom's login screen that is separate from mine please let me know.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:18:14 PM, on 3/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\GWMDMMSG.exe
C:\WINNT\system32\SK9910DM.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINNT\system32\devldr32.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\WINNT\explorer.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\VirusScan\McShield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adb…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adb…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\support.com\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FlipViewer Library] C:\Program Files\E-Book Systems\FlipViewer\\FlipViewerLibrary.exe /showmode=hide
O4 - HKLM\..\Run: [LXDBCATS] rundll32 C:\WINNT\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [totasaguja] Rundll32.exe "C:\WINNT\system32\mupitera.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [totasaguja] Rundll32.exe "C:\WINNT\system32\mupitera.dll",s (User 'NETWORK SERVICE')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/OneClickFix/tgctlsr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHos…ronGameHost.cab
O16 - DPF: {D1D98C0F-A339-42AB-BD5F-EA0FF5D0E65F} (RockYou Image Uploader Control) - http://www.rockyou.com/RockYouImageUploader.cab
O20 - AppInit_DLLs: sgwhuy.dll c:\winnt\,
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxdb_device - - C:\WINNT\system32\lxdbcoms.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: PictureTaker - Unknown owner - c:\fixit\pt\PCTKRNT.SYS (file missing)

–
End of file - 7257 bytes
Hi sweetiehlm5,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi TomK thanks for your assistance. I have disabled Windows Defender & now I am trying to disable Malwarebytes but didn't see how to disable that. Can you tell me how to disable Malwarebytes? I will then disable Mcafee after that. The progams I have installed are Mcafee, Windows Defender, Malwarebytes, & now Hijackthis. Do I need to disable hijackthis too?
Hi TomK I followed the instructions. I clicked on the first link first & the entire screen disappeared so I brought the instructions up again & clicked on the 2nd combofix link which then brought up the box to run, save, cancel. I clicked save & saved it to my desk top. I then doubleclicked on the combofix round icon on my desktop & it showed a little green strip like it was loading something but then nothing happened after that. What should I do to get it to work?
sweetiehlm5,

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
When I clicked on the dds.scr link both this window & that window that attempted to open disappeared. When I did a google search on dds.scr download & tried to open a website to download it the website disappeared so the trojan/virus appears to be trying to prevent me from accessing websites that will help me remove it. Should I attempt to install the program in safe mode? If so should I keep the firewall & other programs disabled prior to restarting in safe mode if you advise that I try to install in safe mode?
sweetiehlm5,

Can you still run Malwarebytes'?

  • Select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
I did a Malwarebytes run & the results are below. Whatever this trojan/virus is it is bypassing malwarebytes now & mcafee because it is still there I know. I think the only reason I haven't had problems with this website is because last night I saved this site to my favorites before the disappearing website problem started today. Is there something else you can have me try. I was able to download hijackthis & wonder defender so there has to be something I can do to try to remove this.

Malwarebytes' Anti-Malware 1.35
Database version: 1904
Windows 5.1.2600 Service Pack 3

3/28/2009 4:52:14 PM
mbam-log-2009-03-28 (16-52-14).txt

Scan type: Quick Scan
Objects scanned: 84025
Time elapsed: 8 minute(s), 41 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



sweetiehlm5,

Can you still run Malwarebytes'?

  • Select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

sweetiehlm5,

Let's see if we can wear it down.

Backup Your Registry with ERUNT
  • Download ERUNT from here and save it to your desktop.
  • Right-click erunt.zip, choose Extract All… and follow the prompts to unzip the program
  • Open the erunt folder on your Desktop and double-click ERUNT.exe to start the program
  • OK all the prompts to back up your registry to the default location.
Note:
The backups can be restored from here:
C:\windows\ERDNT\\ERDNT.exe

Please open Notepad

  • Click Start , then Run
  • Type notepad.exe in the Run Box.
    Copy and Paste everything from the Quote box into Notepad:

    REGEDIT4

    [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "totasaguja"=-

    [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "totasaguja"=-

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""


    Make sure there are NO blank lines before REGEDIT4
    Make sure there IS one blank line at the end of the file.

    Go to File > Save As
    Save File name as Fix.reg
    Change Save as Type to All Files and save the file to your desktop.

    Close Notepad, and double-click Fix.reg on your Desktop. When it asks if you want to merge the info to the registry, hit YES/OK. Reboot the computer.

Then:

Using Windows Explorer (Windows Key + E), locate the following file and DELETE it (if still present):
C:\WINNT\system32\mupitera.dll <–This file

Now please try again to run ComboFix.
I was able to download erunt but when I rightclicked I didn't see extract all. I saw open with winzip, then also saw winzip with arrow which had options extract to…, extract to here, extract to c/folderdesktop. I clicked open with winzip & it opened a folder file with different erunt files including autoback, erunt, read me, & more. I might have made a mistake because I don't know where to open the erunt folder from now that the file folder opened up. What should I do?
Actually I was able to figure it out. I am now entering the quote in to the notepad. By blank line do you mean typing a blank line like where you put a signature on top of it like this ________________________________________________ ?
sweetiehlm5, No, I mean a blank line as a line with nothing in it. If you just hit enter, your cursor will move down one line. That's what we're looking for.
I did click once to move the curser at the end & saved the file as Fix.reg & changed save as type to all files. I closed notepad & double-clicked on the fix icon on the desktop & it looked like computer might go in to restart mode but nothing happened. I didn't get the question to click yet to merge the info in to the registry. I wonder if I should retry it & do I need to have my firewall & ant-virus software off when doing that process?
sweetiehlm5,

If it didn't ask you if you wanted to merge. It didn't do anything. You shouldn't have to do anything with your firewall and anti-virus.

I don't know if you can download this program. If you can, this will achieve the same thing:

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "totasaguja"=-
    
    [HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "totasaguja"=-
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""
    
    :Files
    C:\WINNT\system32\mupitera.dll
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI