Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Pos.tmp Help!


  • This topic is locked This topic is locked
4 replies to this topic

#1 Alice Ann

Alice Ann

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:52 AM

Posted 28 February 2008 - 12:27 AM

Okay so I've been getting A LOT of pos.tmp etc. files in my C: Drive and My Docs. I also have a Red X for the icon of my C Drive. I also have these "system messages":

System Warning:
Windows performed illegal operation. Your system files could have critical errors.
It could cause unpredictable or erratic behavior, freezes and crashes.
Fixing these errors can increase your computers's performance and prevent data your personal data loss.
Would you like to open System Troubleshooting center to fix the problem? (Recommended)

Your system could become unstable
A potential problem has been detected and Windows has been shutdown
buggy application to prevent damage to your computer.
****WXYZ.SYS - Address F73120AE base at C00000, DateStamp 36b072A3
Kernel Debugger Using: COM2 (Port 0x28f, Baud rate 192000)

SysFader: IEXPLORER.EXE - Potential Application Error
The instruction at "0x01d62739" referenced memory at "0x02354e50".
The memory could not be "read. Click OK to terminate.


Here's the HIjackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:46:36 PM, on 2/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\avp.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\windows

O3 - Toolbar: Mirar - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll
O4 - HKLM\..\Run: [BM8767ee28] Rundll32.exe "C:\WINDOWS\system32\xfeqnari.dll",s
O10 - Unknown file in Winsock LSP: c:\windows\system32\od3mdi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\od3mdi.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe
O23 - Service: Microsoft cache control (MSControlService) - Unknown owner - C:\WINDOWS\system32\windows
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Audio Adapter (vGADown) - Unknown owner - C:\WINDOWS\avp.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

--

Edited by Alice Ann, 28 February 2008 - 01:02 AM.


BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:12:52 AM

Posted 28 February 2008 - 04:13 PM

Hello Alice Ann,

Welcome to Bleeping Computer :thumbsup:

1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply please, along with a new HijackThis log.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 Alice Ann

Alice Ann
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:52 AM

Posted 29 February 2008 - 01:53 AM

Thanks for the reply!

Combofix log

ComboFix 08-02-25.3 - Owner 2008-02-28 18:32:17.2 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\d.exe
C:\Documents and Settings\Admin\Application Data\searchtoolbarcorp
C:\Documents and Settings\Admin\Application Data\searchtoolbarcorp\Toolbar Vision\PageHistory.txt
C:\Documents and Settings\Admin\Application Data\searchtoolbarcorp\Toolbar Vision\WebHistory.txt
C:\Documents and Settings\Admin\Application Data\WinAntiVirus Pro 2006
C:\Documents and Settings\Admin\Application Data\WinAntiVirus Pro 2006\Logs\update.log
C:\Documents and Settings\Admin\Application Data\WinAntiVirus Pro 2006\Logs\wa6Support.log
C:\Documents and Settings\Admin\Application Data\WinAntiVirus Pro 2006\Logs\winav.log
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006
C:\Documents and Settings\Guest\Application Data\searchtoolbarcorp
C:\Documents and Settings\Guest\Application Data\searchtoolbarcorp\Toolbar Vision\PageHistory.txt
C:\Documents and Settings\Guest\Application Data\searchtoolbarcorp\Toolbar Vision\WebHistory.txt
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Program Files\Internet Explorer\lawugexi.dll
C:\Program Files\Internet Explorer\lawugexi429.dll
C:\Program Files\WindowsUpdate\zydofape89104.dll
C:\WINDOWS\Downloaded Program Files\temp
C:\WINDOWS\mrofinu.exe
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\mrofinu1188.exe
C:\WINDOWS\system32\atmtd.dll
C:\WINDOWS\system32\atmtd.dll._
C:\WINDOWS\system32\ddccdbx.dll
C:\WINDOWS\system32\dgjlm.ini
C:\WINDOWS\system32\dgjlm.ini2
C:\WINDOWS\system32\dpvswfna.dll
C:\WINDOWS\system32\ehgmtctx.dll
C:\WINDOWS\system32\ehgmtctx.dllbox
C:\WINDOWS\system32\hggdcyx.dll
C:\WINDOWS\system32\mljgd.dll
C:\WINDOWS\system32\mpyqoyxr.dll
C:\WINDOWS\system32\nGpxx18
C:\WINDOWS\system32\nGpxx18\nGpxx182328.exe
C:\WINDOWS\system32\nnnopmj.dll
C:\WINDOWS\system32\omcbwnup.ini
C:\WINDOWS\system32\qyxnlsyb.dll
C:\WINDOWS\system32\rmxwvqci.dll
C:\WINDOWS\system32\rouxtndw.dll
C:\WINDOWS\system32\taskkill.exe
C:\WINDOWS\system32\wdntxuor.ini
C:\WINDOWS\system32\wqwyvnnl.dll
C:\WINDOWS\system32\xfeqnari.dll
C:\WINDOWS\system32\xoswdwwq.dll
C:\WINDOWS\system32\yqnlvuec.ini
C:\WINDOWS\uninstall_nmon.vbs

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_NETWORK_MONITOR


((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-29 )))))))))))))))))))))))))))))))
.

2008-02-27 20:06 . 2008-02-27 20:06 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-27 19:58 . 2008-02-27 19:58 <DIR> d-------- C:\Deckard
2008-02-27 19:45 . 2008-02-27 19:45 223 --a------ C:\WINDOWS\system32\7480.bat
2008-02-27 19:30 . 2008-02-27 19:30 223 --a------ C:\WINDOWS\system32\6808.bat
2008-02-27 19:09 . 2008-02-27 19:09 223 --a------ C:\WINDOWS\system32\9667.bat
2008-02-26 13:19 . 2008-02-26 13:19 <DIR> d-------- C:\WINDOWS\system32\iDlo18
2008-02-26 13:19 . 2008-02-26 13:19 223 --a------ C:\WINDOWS\system32\2443.bat
2008-02-26 13:18 . 2008-02-26 13:18 <DIR> d-------- C:\temp\sanR24
2008-02-25 08:27 . 2008-02-27 20:25 99,707 --a------ C:\WINDOWS\BM8767ee28.xml
2008-02-25 08:27 . 2008-02-28 18:28 22 --a------ C:\WINDOWS\pskt.ini
2008-02-24 20:20 . 2008-02-25 19:53 <DIR> d--hs---- C:\WINDOWS\QmF1LUhzaW5nIEFubg
2008-02-24 20:19 . 2008-02-24 20:19 <DIR> d-------- C:\WINDOWS\system32\xb8
2008-02-24 20:19 . 2008-02-24 20:19 <DIR> d-------- C:\WINDOWS\system32\to2
2008-02-24 20:19 . 2008-02-24 20:19 <DIR> d-------- C:\WINDOWS\system32\jk5
2008-02-24 20:19 . 2008-02-24 20:19 <DIR> d-------- C:\WINDOWS\system32\ff3
2008-02-24 20:19 . 2008-02-24 20:19 <DIR> d-------- C:\WINDOWS\system32\cms4
2008-02-24 20:19 . 2008-02-27 19:09 52,736 --------- C:\app.exe
2008-02-24 20:19 . 2008-02-26 13:19 36,864 --a------ C:\WINDOWS\mrofinu1188.exe.tmp
2008-02-24 20:19 . 2008-02-24 20:19 223 --a------ C:\WINDOWS\system32\3663.bat
2008-02-20 19:40 . 2008-02-20 19:40 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-20 19:40 . 2008-02-20 19:40 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-11 19:40 . 2008-02-16 18:33 <DIR> d-------- C:\Program Files\wahahah
2008-02-11 19:10 . 2008-02-11 19:10 <DIR> d-------- C:\Program Files\Yahoo! Games
2008-02-11 19:03 . 2008-02-11 19:03 <DIR> d-------- C:\Program Files\bfgclient
2008-02-11 19:03 . 2008-02-11 19:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
2008-02-11 19:00 . 2008-02-27 19:43 218,599 --a------ C:\Program Files\c.zip
2008-02-11 19:00 . 2008-02-27 19:43 217,699 --a------ C:\Program Files\b.zip
2008-02-11 19:00 . 2008-02-27 19:43 217,699 --a------ C:\Program Files\a.zip
2008-02-11 19:00 . 2008-02-11 19:00 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-02-11 19:00 . 2008-02-27 19:44 78,360 --a------ C:\Program Files\uy.exe
2008-02-11 18:46 . 2008-02-11 18:46 <DIR> d-------- C:\Program Files\Kudos_at
2008-02-11 18:42 . 2008-02-11 18:42 <DIR> d-------- C:\Program Files\PlayMP3z
2008-02-11 18:42 . 2008-02-11 18:43 <DIR> d-------- C:\Program Files\FBrowsingAdvisor
2008-02-11 18:42 . 2008-02-11 18:43 <DIR> d-------- C:\Program Files\FBrowserAdvisor
2008-02-11 18:42 . 2008-02-27 22:15 <DIR> d-------- C:\Program Files\BrowsingTool
2008-02-11 18:27 . 2008-02-11 19:44 <DIR> d-------- C:\Program Files\Kudos

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-28 04:32 --------- d-----w C:\Documents and Settings\Guest\Application Data\InterTrust
2008-02-28 03:45 --------- d-----w C:\Program Files\LimeWire
2008-02-28 03:43 417,792 ----a-w C:\Program Files\Video.exe
2008-02-28 03:43 417,792 ----a-w C:\Program Files\Track_03.exe
2008-02-28 03:43 25,214 ----a-w C:\Program Files\B.ico
2008-02-28 03:43 25,214 ----a-w C:\Program Files\A.ico
2008-02-28 03:43 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-28 03:15 --------- d-----w C:\Program Files\Norton AntiVirus
2008-02-25 01:35 --------- d-----w C:\Documents and Settings\Owner\Application Data\uTorrent
2008-02-23 03:23 --------- d-----w C:\Documents and Settings\Owner\Application Data\LimeWire
2008-02-12 03:19 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-12 03:00 --------- d-----w C:\Program Files\Kudos Demo
2007-02-14 07:07 417,792 ----a-w C:\Program Files\Setup.exe
2003-07-24 07:28 808 ----a-w C:\Program Files\INSTALL.LOG
2006-11-12 18:54 1,502,661 --sh--w C:\WINDOWS\alausvs.bak1
2006-11-13 03:38 1,552,917 --sh--w C:\WINDOWS\alausvs.ini2
2006-11-21 04:45 966,183 --sh--w C:\WINDOWS\uneol.bak1
2003-01-25 10:30 32 --sha-w C:\WINDOWS\{432DC6F6-968D-4F5B-A15F-5FECE3F263AD}.dat
2006-11-21 18:45 965,213 --sh--w C:\WINDOWS\addins\pc3mp.bak1
2006-11-21 18:45 712,724 --sh--w C:\WINDOWS\addins\pm3cp.dll
2006-11-19 04:09 969,857 --sh--w C:\WINDOWS\Fonts\lxmvdr.bak1
2006-11-19 04:09 712,724 --sh--w C:\WINDOWS\Fonts\rdvmxl.dll
2006-11-16 06:30 975,025 --sh--w C:\WINDOWS\inf\cmfdcm.bak1
2006-11-16 06:27 712,724 --sh--w C:\WINDOWS\inf\mcdfmc.dll
2006-11-13 06:17 1,499,004 --sh--w C:\WINDOWS\java\Packages\alaursv.bak1
2006-11-13 06:17 712,724 --sh--w C:\WINDOWS\java\Packages\vsruala.dll
2006-11-28 05:14 938,938 --sh--w C:\WINDOWS\Microsoft.NET\drhalur.bak1
2006-11-28 05:13 712,724 --sh--w C:\WINDOWS\Microsoft.NET\rulahrd.dll
2006-11-11 05:55 1,499,694 --sh--w C:\WINDOWS\msagent\cav.bak1
2006-11-10 05:55 712,724 --sh--w C:\WINDOWS\msagent\vac.dll
2005-08-03 00:58 293,888 --sha-r C:\WINDOWS\QmF1LUhzaW5nIEFubg\command.exe
2005-07-30 00:24 472 --sha-r C:\WINDOWS\QmF1LUhzaW5nIEFubg\kAIYMo1WuqcBKHIRv0.vbs
2006-12-04 12:36 712,724 --sh--w C:\WINDOWS\security\logs\nietldl.dll
2006-12-01 06:00 712,724 --sh--w C:\WINDOWS\system\atpibd.dll
2006-10-24 03:44 1,401,076 --sh--w C:\WINDOWS\system32\mlkkj.bak1
2006-12-27 19:15 1,275,027 --sh--w C:\WINDOWS\system32\mlkkj.bak2
2006-12-27 19:48 1,275,114 --sh--w C:\WINDOWS\system32\mlkkj.ini2
2003-01-25 10:30 32 --sha-w C:\WINDOWS\system32\{7A423CBA-2B8A-4A0B-AE91-B7E63A03AA63}.dat
2006-11-19 04:02 969,857 --sh--w C:\WINDOWS\Windows Update Setup Files\pcsis.bak1
2006-11-19 04:02 712,724 --sh--w C:\WINDOWS\Windows Update Setup Files\siscp.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9A9C9B69-F908-4AAB-8D0C-10EA8997F37E}]
C:\WINDOWS\system32\WinNB58.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D0661233-42D4-F7F1-80E1-8A9E0E99E71D}]
2007-12-30 12:48 1019904 --a------ C:\Program Files\BrowsingTool\BrowsingTool-1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{9A9C9B68-F908-4AAB-8D0C-10EA8997F37E}

[HKEY_CLASSES_ROOT\clsid\{9a9c9b68-f908-4aab-8d0c-10ea8997f37e}]
[HKEY_CLASSES_ROOT\TypeLib\{566DEDE9-9ED8-45DA-9BE6-9B2EEAB17F49}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{9A9C9B68-F908-4AAB-8D0C-10EA8997F37E}"= C:\WINDOWS\system32\WinNB58.dll [ ]

[HKEY_CLASSES_ROOT\clsid\{9a9c9b68-f908-4aab-8d0c-10ea8997f37e}]
[HKEY_CLASSES_ROOT\TypeLib\{566DEDE9-9ED8-45DA-9BE6-9B2EEAB17F49}]

C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
PopChar.lnk - C:\Program Files\ergonis\PopChar\PopChar.exe [2006-04-27 15:43:54 401408]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=

S2 vGADown;Audio Adapter;C:\WINDOWS\avp.exe []
S3 msCMTSrvc;Content Monitoring Tool;C:\WINDOWS\system32\msCMTSrvc.exe [2002-03-27 03:42]
S3 MSControlService;Microsoft cache control;C:\WINDOWS\system32\windows []
S3 PCDRDRV;Pcdr Helper Driver;C:\PROGRA~1\PC-DOC~1\DIAGNO~1\PCDRDRV.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dacc8aa2-d8dc-11dc-bde7-00038a000015}]
\Shell\Auto\command - G:\sunny.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sunny.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-02-24 06:43:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-29 02:48:58 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2006-12-28 06:13:29 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-28 18:46:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
.
**************************************************************************
.
Completion time: 2008-02-28 18:57:38 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-02-29 02:57:22
.
2007-08-19 19:12:39 --- E O F ---

#4 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:12:52 AM

Posted 29 February 2008 - 11:30 PM

Hello,

You're most welcome. :thumbsup: Could I please see a new HijackThis log?

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#5 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:12:52 AM

Posted 09 March 2008 - 03:29 PM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users