Hi
Please download and unzip
Icesword to its own folder on your desktop
If you get a lot of "red entries" in an IceSword log, don't panic.Step 1 : Close all windows and run IceSword. Click the
Processes tab and watch for processes displayed in
red color. A red colored process in this list indicates that it's hidden. Write down the
PathName of any processes in red color. Then click on
LOG at the top left. It will prompt you to save the log, call this
Processes and save it to your desktop.
Step 2 : Click the
Win32 Services tab and look out for red colored entries in the services list. Write down the
Module name of any services in red color, you will need to expand out the Module tab to see the full name. Then click on
LOG. It will prompt you to save the log, call this
Services and save it to your desktop.
Step 3 : Click the
Startup tab and look out for red colored entries in the startup list. Write down the
Path of any startup entries in red color. Then click on
LOG. It will prompt you to save the log, call this
Startup and save it to your desktop.
Step 4 : Click the
SSDT tab and check for
red colored entries. If there are any, write down the
KModule name.
Step 5 : Click the
Message Hooks tab and check for any entries that are underneath Type and labelled WH_KEYBOARD. Write down the
Process Path of these entries if present.
Now post all of the data collected under the headings for :
Processes
Win32 Services
Startup
SSDT
Message Hooks