Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virtumonde File Infection, Request Assistance


  • Please log in to reply
3 replies to this topic

#1 Kentucky1986

Kentucky1986

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:11:23 AM

Posted 29 December 2007 - 10:52 PM

Good Evening

I did get some assistance on another forum and that person recomended a reformat. Before I go that route I would like a second opion.

I have been hammered with a new Virtumonde File Infection.

It has done the following

- Caused crashes in Windows Explorer

- Destroyed Norton AV (I have now installed AVG free addition which I think is better)

- Killed WeatherWatcher.exe

- Brought on multiple pop ups

Since putting in AVG I seemed to have "contained" the issue for now... but before doing the reformat I wanted to see what other options I have..

Below is my HJT log..... Thank You!!!! :-)

=================================================================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:04:32 AM, on 12/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched .exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forecast.weather.gov/MapClick.php?zoneid=FLZ038
F3 - REG:win.ini: load=C:\WINDOWS\system32\pmkjj.exe, C:\WINDOWS\system32\pmkjj.exe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [RecoverFromReboot] C:\WINDOWS\Temp\RecoverFromReboot.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" /minimized
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant .exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [WeatherWatcher] C:\Program Files\Weather Watcher\ww.exe
O4 - HKCU\..\Run: [Ltho] "C:\PROGRA~1\ICROSO~1\fast.exe" -vt yazb
O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMidi] MIDIDEF.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMidi] MIDIDEF.EXE (User 'Default user')
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha...v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1138071306296
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cab
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 7314 bytes

###

Next is my virus scan log
==============================================================================
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, December 28, 2007 11:51:55 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 28/12/2007
Kaspersky Anti-Virus database records: 499159
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\

Scan Statistics:
Total number of scanned objects: 520580
Number of viruses found: 19
Number of infected objects: 186
Number of suspicious objects: 0
Duration of the scan process: 05:46:46

Infected Object Name / Virus Name / Last Action
C:\!KillBox\ssqnnkh.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.clz skipped
C:\5075.tmp/stream/data0002 Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\5075.tmp/stream/data0003 Infected: not-a-virus:AdWare.Win32.Agent.ay skipped
C:\5075.tmp/stream/data0004 Infected: not-a-virus:AdWare.Win32.Agent.br skipped
C:\5075.tmp/stream Infected: not-a-virus:AdWare.Win32.Agent.br skipped
C:\5075.tmp NSIS: infected - 4 skipped
C:\a984e7a723202bf97365129ac18\SETUP.18 Object is locked skipped
C:\a984e7a723202bf97365129ac18\SETUP.7 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor.zip/netmon.exe Infected: not-a-virus:Monitor.Win32.NetMon.a skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NetworkMonitor.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle1.zip/Yazzle1552OinAdmin.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle3.zip/Yazzle1552OinAdmin.exe Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-12-28_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\5074.tmp.bac_a03496/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\5074.tmp.bac_a03496 NSIS: infected - 1 skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\5074.tmp.bac_a03496 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\D1E9C.tmp.bac_a03496/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\D1E9C.tmp.bac_a03496 NSIS: infected - 1 skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\D1E9C.tmp.bac_a03496 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\TMP1A.tmp.bac_a03496 Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\TMP1B.tmp.bac_a03496 Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\TMP1EB3.tmp.bac_a03496 Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\TMP1F01.tmp.bac_a03496 Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\TMP4D.tmp.bac_a03496 Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\TMP56.tmp.bac_a03496 Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\TMP59.tmp.bac_a03496 Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\TMP5D.tmp.bac_a03496 Infected: Trojan-Downloader.Win32.PurityScan.fe skipped
C:\Documents and Settings\Bob\.housecall6.6\Quarantine\VVSNInst.exe.bac_a03496 Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\Documents and Settings\Bob\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Bob\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Bob\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Bob\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bob\Local Settings\History\History.IE5\MSHist012007122820071229\index.dat Object is locked skipped
C:\Documents and Settings\Bob\Local Settings\Temp\D1EA3.tmp/stream/data0001 Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\Documents and Settings\Bob\Local Settings\Temp\D1EA3.tmp/stream Infected: not-a-virus:AdWare.Win32.Agent.vv skipped
C:\Documents and Settings\Bob\Local Settings\Temp\D1EA3.tmp NSIS: infected - 2 skipped
C:\Documents and Settings\Bob\Local Settings\Temp\ismupd1.exe/data0002 Infected: not-a-virus:AdWare.Win32.Agent.br skipped
C:\Documents and Settings\Bob\Local Settings\Temp\ismupd1.exe NSIS: infected - 1 skipped
C:\Documents and Settings\Bob\Local Settings\Temp\RCX1F.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\RCX22.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\RCX28.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\RCX29.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\RCX2C.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\RCX2D.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\RCX2E.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\RCX2F.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\RCX30.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\RCX31.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\RCX36.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\RCX3A.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP18A3.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP1AC0.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP1ED7.tmp Infected: Trojan-Downloader.Win32.Agent.gwh skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP1F2F.tmp Infected: Trojan-Downloader.Win32.Agent.gwh skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP51.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP53D0.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP57.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP6A.tmp Infected: Trojan-Downloader.Win32.Agent.gwh skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP72.tmp Infected: Trojan-Downloader.Win32.Agent.gwh skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP7E.tmp Infected: Trojan-Downloader.Win32.Agent.gwh skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP80.tmp Infected: Trojan-Downloader.Win32.Agent.gwh skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP81.tmp Infected: Trojan-Downloader.Win32.Agent.gwh skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP87.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP8B.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temp\TMP98.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Documents and Settings\Bob\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Bob\ntuser.dat Object is locked skipped
C:\Documents and Settings\Bob\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\download\backups\backup-20071228-003809-449.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.clz skipped
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Common Files\Symantec Shared\ccApp.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\iTunes\iTunesHelper.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Norton AntiVirus\Quarantine\0CF31475.exe Infected: Trojan-Downloader.Win32.Agent.cbx skipped
C:\Program Files\Norton AntiVirus\Quarantine\100F4431.exe Infected: not-a-virus:AdWare.Win32.PurityScan.fn skipped
C:\Program Files\Norton AntiVirus\Quarantine\10D04634.exe Infected: Trojan-Downloader.Win32.Agent.ezc skipped
C:\Program Files\Norton AntiVirus\Quarantine\11AD5340.exe Infected: not-virus:Hoax.Win32.Renos.vm skipped
C:\Program Files\Norton AntiVirus\Quarantine\14AA4DF7.exe Infected: Trojan-Downloader.Win32.Agent.fjv skipped
C:\Program Files\Norton AntiVirus\Quarantine\1C4B6192.exe Infected: Trojan-Downloader.Win32.Agent.fjn skipped
C:\Program Files\Norton AntiVirus\Quarantine\23744BF8 Infected: Trojan-Downloader.Win32.Small.eqn skipped
C:\Program Files\Norton AntiVirus\Quarantine\4DFA057D.exe Infected: not-a-virus:AdWare.Win32.PurityScan.fn skipped
C:\Program Files\Norton AntiVirus\Quarantine\78B36A32.exe Infected: not-a-virus:AdWare.Win32.PurityScan.fn skipped
C:\Program Files\Norton AntiVirus\Quarantine\7AC151EF.exe Infected: not-a-virus:AdWare.Win32.Rond.c skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\QuickTime\qttask.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Unlocker\UnlockerAssistant .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Unlocker\UnlockerAssistant .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Unlocker\UnlockerAssistant .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Unlocker\UnlockerAssistant .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Unlocker\UnlockerAssistant .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Unlocker\UnlockerAssistant .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Unlocker\UnlockerAssistant .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Unlocker\UnlockerAssistant .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Unlocker\UnlockerAssistant .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Unlocker\UnlockerAssistant .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Unlocker\UnlockerAssistant .exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\Unlocker\UnlockerAssistant.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\RECYCLER\S-1-5-21-682003330-1343024091-2147195623-1004\Dc1.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0000023.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001004.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001005.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001008.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001009.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001010.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001013.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001014.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001019.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001031.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001032.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001034.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001035.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001036.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001039.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001040.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001050.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001051.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001052.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001055.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001056.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001057.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001059.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001060.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001063.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001071.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001072.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001074.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001075.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001076.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001078.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001079.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001081.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.clz skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001092.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001093.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001094.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001095.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001096.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001099.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0001100.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0002088.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0002090.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0002091.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0002092.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0002093.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0002095.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0003088.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0003090.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0003091.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0003092.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0003094.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP1\A0003097.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\System Volume Information\_restore{5E288B11-18D7-4511-AD30-FE33C72F1863}\RP2\change.log Object is locked skipped
C:\VundoFix Backups\MSConfig.exe.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\VundoFix Backups\pmkjj.exe.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\VundoFix Backups\RecoverFromReboot.exe.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\VundoFix Backups\ssqnnkh.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.clz skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\mrofinu72.exe.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\PCHealth\HelpCtr\Binaries\msconfig.exe.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\pmkjj.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\system32\RCX2F.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\system32\RCX3E.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\system32\RCX41.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\system32\RCX42.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\system32\RCX43.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\system32\RCX44.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\system32\RCX45.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\system32\RCX46.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\system32\RCX47.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\system32\RCX4E.tmp Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\{00000001-00000000-00000001-00001102-00000004-10061102}.CDF Object is locked skipped

Scan process completed.

###

Thank you very very much!

BP

BC AdBot (Login to Remove)

 


#2 Starbuck

Starbuck

    'r Brudiwr


  • Malware Response Team
  • 4,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Midlands, UK
  • Local time:05:23 PM

Posted 08 January 2008 - 11:35 AM

Hi Kentucky1986
sorry for the delay in answering your post.
If you still need help could you please post back a new Hjt log.... things change so quickly and we need to see what's happening now.
Please let me know one way or another if help is still needed.
Thanks

Starbuck

BBPP6nz.png


#3 Kentucky1986

Kentucky1986
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:11:23 AM

Posted 17 March 2008 - 05:17 PM

Hi Kentucky1986
sorry for the delay in answering your post.
If you still need help could you please post back a new Hjt log.... things change so quickly and we need to see what's happening now.
Please let me know one way or another if help is still needed.
Thanks

Starbuck


Hi!
Just for the record I got it fixed for anyone elses info AVG stopped it in it's tracks. So if anyone else is suffering I hope that helps but again a caution everyones problem is different so ask first

Thanks

BP

#4 Starbuck

Starbuck

    'r Brudiwr


  • Malware Response Team
  • 4,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Midlands, UK
  • Local time:05:23 PM

Posted 17 March 2008 - 05:25 PM

Many thanks for the reply Kentucky1986
It's appreciated :thumbsup:

BBPP6nz.png





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users