Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I'm Infected!


  • This topic is locked This topic is locked
2 replies to this topic

#1 123456

123456

  • Banned Spammer
  • 3 posts
  • OFFLINE
  •  
  • Local time:04:09 AM

Posted 15 September 2007 - 06:35 AM

ComboFix 07-08-14.4 - "es02" 2007-09-15 19:18:06.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.217 [GMT 8:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\rising855.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\nm


((((((((((((((((((((((((( Files Created from 2007-08-15 to 2007-09-15 )))))))))))))))))))))))))))))))


2007-09-15 19:15 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-09-15 19:04 <DIR> d-------- C:\WINDOWS\pss
2007-09-14 13:44 <DIR> d--hs---- C:\heap41a
2007-09-13 10:28 16,942 --a------ C:\WINDOWS\sys332.exe
2007-09-12 21:27 23,552 --a------ C:\WINDOWS\system32\xumezi.dll
2007-09-12 20:24 24,576 --a------ C:\WINDOWS\system32\idogem.dll
2007-09-12 20:23 30,720 --a------ C:\WINDOWS\dlolss.exe
2007-09-12 20:22 32,256 --a------ C:\WINDOWS\pxrdbu.exe
2007-09-12 20:22 30,720 --a------ C:\WINDOWS\jdvrxc.exe
2007-09-12 20:22 24,576 --a------ C:\WINDOWS\system32\qyvgey.dll
2007-09-12 20:22 23,552 --a------ C:\WINDOWS\system32\kekgmz.dll
2007-09-12 20:18 24,576 --a------ C:\WINDOWS\system32\znckyq.dll
2007-09-12 20:18 23,552 --a------ C:\WINDOWS\system32\arghof.dll
2007-09-12 20:05 24,576 --a------ C:\WINDOWS\system32\srenmb.dll
2007-09-12 20:04 23,552 --a------ C:\WINDOWS\system32\mspvge.dll
2007-09-12 19:58 24,576 --a------ C:\WINDOWS\system32\qldwmo.dll
2007-09-12 19:58 23,552 --a------ C:\WINDOWS\system32\tzajvn.dll
2007-09-08 21:39 <DIR> d-------- C:\Pokemon
2007-09-08 15:40 <DIR> d-------- C:\Program Files\Chinese Star
2007-09-08 15:18 20 --a------ C:\WINDOWS\system32\mhsha1.dat
2007-09-07 22:23 <DIR> d-------- C:\DOCUME~1\es02\APPLIC~1\Real
2007-09-07 20:03 <DIR> d-------- C:\Program Files\SB
2007-09-07 19:48 27,648 --a------ C:\WINDOWS\system32\SHQ.DLL
2007-09-07 19:48 20 --a------ C:\DOCUME~1\es02\mhsha1.dat
2007-09-04 22:22 <DIR> d-------- C:\DOCUME~1\es02\APPLIC~1\gemsweeperextractedgfx
2007-09-04 22:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\My Games
2007-08-15 19:55 <DIR> d-------- C:\WINDOWS\system32\NtmsData


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-12 12:29 --------- d-------- C:\DOCUME~1\es02\APPLIC~1\LimeWire
2007-09-08 17:32 --------- d-------- C:\Program Files\mIRC
2007-09-04 22:20 --------- d-------- C:\Program Files\MSN Games
2007-08-24 14:42 --------- d-------- C:\Program Files\Yahoo! Games
2007-08-24 14:35 --------- d-------- C:\Program Files\Gamenext
2007-08-24 14:34 --------- d-------- C:\Program Files\Common Files\Oberon Media
2007-08-12 14:11 --------- d-------- C:\Program Files\GameHouse
2007-08-11 23:47 4608 --a------ C:\WINDOWS\system32\w95inf32.dll
2007-08-11 23:47 2272 --a------ C:\WINDOWS\system32\w95inf16.dll
2007-08-11 23:47 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-11 23:47 --------- d-------- C:\Program Files\Capcom
2007-08-09 14:31 --------- d-------- C:\Program Files\TryMedia
2007-08-06 16:46 --------- d-------- C:\Program Files\MagicTwin
2007-08-01 16:35 --------- d-------- C:\Program Files\New Folder
2007-07-30 20:13 --------- d-------- C:\Program Files\LimeWire
2007-07-28 22:16 --------- d-------- C:\DOCUME~1\es02\APPLIC~1\MSNInstaller
2007-07-25 17:18 --------- d-------- C:\Program Files\Google
2007-07-22 19:44 --------- d-------- C:\DOCUME~1\es02\APPLIC~1\Gaijin Ent
2007-07-22 01:22 --------- d-------- C:\Program Files\VideoCAM Eye
2007-07-22 01:22 --------- d-------- C:\Program Files\Common Files\VCAMEye
2007-07-22 00:42 --------- d-------- C:\Program Files\Common Files\InstallShield
2007-07-19 19:12 --------- d-------- C:\Program Files\MP3 Player Utilities 4.00
2007-07-16 17:37 --------- d-------- C:\DOCUME~1\es02\APPLIC~1\Help
2007-07-06 00:55 499712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-07-06 00:55 348160 --a------ C:\WINDOWS\system32\msvcr71.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000185-C745-43D2-44F1-01A1C789C738}]
C:\PROGRA~1\SB\SMART-~1\BHO010~1.DLL

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C7DE9B8-CAA6-4B31-BC09-45AFC6B90FDE}]
2005-12-30 19:51 135168 --a------ C:\WINDOWS\system32\iesense.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 06:32]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:32]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:32]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 15:19]
"C-Media Mixer"="Mixer.exe" [2002-01-28 16:16 C:\WINDOWS\mixer.exe]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
""="" []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFavoritesMenu"=01000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{798977F1-34FC-4DDD-AF6D-1B5C196B4EB4}"= C:\Program Files\Common Files\Microsoft Shared\MSINFO\System6.ins [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\KmWinLog]
Kmlogon.dll 2005-08-26 12:07 368640 C:\WINDOWS\system32\Kmlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CSMContext]
C:\WINDOWS\system32\CSMContext.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

R0 HpPCIRsr;Multiuser PCI Bus Resolver;C:\WINDOWS\system32\drivers\KmPciRsr.sys
R0 HpPciVga;Multiuser PCI VGA Station Driver (MultiScreen);C:\WINDOWS\system32\drivers\KmWpsMs.sys
R0 HpStore;Multiuser Devices Control Service;C:\WINDOWS\system32\drivers\KmStore.sys
R0 HpUsbKeyboard;Multiuser USB Keyboard Class Driver;C:\WINDOWS\system32\drivers\KmKbdCls.sys
R0 HpUsbMouse;Multiuser USB Mouse Class Driver;C:\WINDOWS\system32\drivers\KmMouCls.sys
R1 HpHelper;Multiuser User Mode Helper Driver;C:\WINDOWS\system32\drivers\KmHlprk.sys
R2 HpLegacyKeyboard;Multiuser Legacy Keyboard Port Driver;C:\WINDOWS\system32\drivers\KmJBox.sys
R3 HpXpHidCls;Multiuser HID Device Control Service;C:\WINDOWS\system32\drivers\KmHidCls.sys
R3 HpXpKbdPnp;Multiuser Keyboard Control Service;C:\WINDOWS\system32\drivers\KmKbdPnp.sys
R3 HpXpMouPnp;Multiuser mouse Control Service;C:\WINDOWS\system32\drivers\KmMouPnp.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7ac4ae51-4c9b-11dc-b622-003018a0d1c6}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Flash.10.Setup.exe
Explore\command- Flash.10.Setup.exe
Open\command- Flash.10.Setup.exe
Scan for Viruses\command- Scanner.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6d42021-4a6e-11dc-b61b-003018a0d1c6}]
AutoRun\command- F:\LaunchU3.exe -a


Contents of the 'Scheduled Tasks' folder
2007-09-14 16:00:00 C:\WINDOWS\Tasks\At1.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-08-06 08:46:10 C:\WINDOWS\Tasks\At10.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-13 02:00:00 C:\WINDOWS\Tasks\At11.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-13 03:00:00 C:\WINDOWS\Tasks\At12.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-13 04:00:00 C:\WINDOWS\Tasks\At13.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-13 05:00:00 C:\WINDOWS\Tasks\At14.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-14 06:00:00 C:\WINDOWS\Tasks\At15.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-15 07:00:00 C:\WINDOWS\Tasks\At16.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-15 08:00:00 C:\WINDOWS\Tasks\At17.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-15 09:00:00 C:\WINDOWS\Tasks\At18.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-15 10:00:00 C:\WINDOWS\Tasks\At19.job
2007-09-14 17:00:00 C:\WINDOWS\Tasks\At2.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-15 11:00:00 C:\WINDOWS\Tasks\At20.job
2007-09-14 12:00:00 C:\WINDOWS\Tasks\At21.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-14 13:00:00 C:\WINDOWS\Tasks\At22.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-14 14:00:00 C:\WINDOWS\Tasks\At23.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-14 15:00:00 C:\WINDOWS\Tasks\At24.job
2007-09-14 18:00:00 C:\WINDOWS\Tasks\At3.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-14 19:00:00 C:\WINDOWS\Tasks\At4.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-08-13 20:01:00 C:\WINDOWS\Tasks\At5.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-09-08 21:00:00 C:\WINDOWS\Tasks\At6.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-08-06 08:46:10 C:\WINDOWS\Tasks\At7.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-08-06 08:46:10 C:\WINDOWS\Tasks\At8.job - C:\WINDOWS\system32\0eIJVr26.exe
2007-08-06 08:46:10 C:\WINDOWS\Tasks\At9.job - C:\WINDOWS\system32\0eIJVr26.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-15 19:26:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NVMCTRAY.DLL,NvTaskbarInit"

Completion time: 2007-09-15 19:27:52 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-15 19:27

--- E O F ---
COMBOFIX

after combo fix here

hijacklog



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:32, on 2007-09-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\KmServc.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\heap41a\svchost.exe
C:\heap41a\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hoathachthao.info/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: BHO - {00000185-C745-43D2-44F1-01A1C789C738} - C:\PROGRA~1\SB\SMART-~1\BHO010~1.DLL (file missing)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: KPBHO Class - {7C7DE9B8-CAA6-4B31-BC09-45AFC6B90FDE} - C:\WINDOWS\system32\iesense.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKLM\..\Policies\Explorer\Run: [status] present
O4 - HKLM\..\Policies\Explorer\Run: [winlogon] C:\heap41a\svchost.exe C:\heap41a\std.txt
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Add to Media Manager... - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo...Plugin11USA.cab
O20 - Winlogon Notify: KmWinLog - C:\WINDOWS\SYSTEM32\Kmlogon.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Multiuser Service (HpService) - NComputing Co.,Ltd. - Korea - C:\WINDOWS\System32\KmServc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 4994 bytes

i'm using an annoymous account to get information about this at first i saw Policies\***\Loader.exe and alot of LOADER type in my registry running when i try to run FIREFOX it says USE IE YOU DOPE

BC AdBot (Login to Remove)

 


#2 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:09 AM

Posted 22 September 2007 - 10:09 PM

Hello 123456,


NOTE: If you have downloaded ComboFix previously please delete that version and download it again!

1. Download this file - combofix.exe to your Desktop.
Note:
It is important that it is saved directly to your desktop

2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you, C:\ComboFix.txt. Post the ComboFix log and a fresh Hijackthis log in your next reply.
Do NOT post the ComboFix-quarantined-files.txt - unless I ask you to.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 SifuMike

SifuMike

    malware expert


  • Staff Emeritus
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:02:09 AM

Posted 28 September 2007 - 06:56 PM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact me or a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users