Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

win32/ldpinch.gen


  • This topic is locked This topic is locked
9 replies to this topic

#1 kristap0250

kristap0250

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:37 AM

Posted 11 February 2009 - 04:29 PM

Ok, my computer has been running VERY slow with lots of pop-ups from sites with adult topics... My computer has been down for over a year because we relocated from FL to MA... Before moving, I remember thinking that emails were sent from my account that I never sent, but then thought "how could that be" so just put it out of my mind.... My laptop battery died and I neede a new charger so I turned my desktop back on after a year and it is soooo bad.. I ran the microsoft malware recovery tool and it said that it found win32/ldpinch.gen.........

DDS (Ver_09-02-01.01) - NTFSx86
Run by Krista at 15:24:49.10 on Wed 02/11/2009
Internet Explorer: 7.0.5730.11

============== Pseudo HJT Report ===============

uDefault_Page_URL = hxxp://www.dell4me.com/myway
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar =
mSearchAssistant = hxxp://search.bearshare.com/sidebar.html?src=ssb
uURLSearchHooks: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
mURLSearchHooks: H - No File
mWinlogon: SFCDisable=4 (0x4)
BHO: SOFTWARE - No File
BHO: Microsoft - No File
BHO: Windows - No File
BHO: CurrentVersion - No File
BHO: Explorer - No File
BHO: Browser Helper Objects - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: {903d0aff-2162-4ac7-a3f4-2c45fbc3b04d} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
BHO: {FFD46104-E7A5-4765-8BC1-2F98B33FF2A6} - No File
TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: {0494D0D9-F8E0-41AD-92A3-14154ECE70AC} - No File
TB: {40D41A8B-D79B-43D7-99A7-9EE0F344C385} - No File
TB: {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - No File
TB: {5BED3930-2E9E-76D8-BACC-80DF2188D455} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [FSCBoss] c:\program files\fscboss\FSCBoss.exe
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [E6TaskPanel] "c:\program files\earthlink totalaccess\TaskPanl.exe" -winstart
uRun: [MoneyAgent] "c:\program files\microsoft money\system\mnyexpr.exe"
uRun: [saaqa] "c:\documents and settings\krista\local settings\application data\saaqa.exe" saaqa
uRun: [swg] c:\program files\google\googletoolbarnotifier\1.2.911.3380\GoogleToolbarNotifier.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [IntelMeM] "c:\program files\intel\modem event monitor\IntelMEM.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [StorageGuard] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [mmtask] "c:\program files\musicmatch\musicmatch jukebox\mmtask.exe"
mRun: [DeviceDiscovery] "c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe"
mRun: [HostManager] "c:\program files\common files\aol\1145803826\ee\AOLSoftware.exe"
mRun: [IPHSend] "c:\program files\common files\aol\iphsend\IPHSend.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_03\bin\jusched.exe"
mRun: [dlcxmon.exe] "c:\program files\dell photo aio printer 926\dlcxmon.exe"
mRun: [MemoryCardManager] "c:\program files\dell photo aio printer 926\memcard.exe"
mRun: [FaxCenterServer] "c:\program files\dell pc fax\fm3032.exe" /s
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DLCXCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCXtime.dll,_RunDLLEntry@16
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
mRun: [Corel Photo Downloader] c:\program files\corel\corel photo album 6\MediaDetect.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [OneCareUI] "c:\program files\microsoft windows onecare live\winssnotify.exe"
IE: &AIM Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {066040F0-5018-4E15-8AA0-81D36136D989} - {7475D3FD-5D85-49DB-8B9B-6968467B2D80}
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
Notify: dpmmon - dpmmon.dll
Notify: hggefef - hggefef.dll
Notify: igfxcui - igfxsrvc.dll
Notify: WRNotifier - WRLogonNTF.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - No File
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\jkkli.dll

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2009-02-11 10:21 <DIR> --d----- C:\5819c6889d8cab945f
2009-02-10 21:46 <DIR> --d----- c:\program files\Exterminate It!
2009-02-10 17:16 91,328 a------- c:\windows\system32\drivers\msfwdrv.sys
2009-02-10 17:15 116,416 a------- c:\windows\system32\drivers\msfwhlpr.sys
2009-02-10 17:13 53,168 a------- c:\windows\system32\drivers\MpFilter.sys
2009-02-10 17:12 409,600 -------- c:\windows\system32\dllcache\qmgr.dll
2009-02-10 17:12 18,944 -------- c:\windows\system32\dllcache\qmgrprxy.dll
2009-02-10 17:12 7,168 -------- c:\windows\system32\dllcache\bitsprx4.dll
2009-02-10 17:12 7,168 -------- c:\windows\system32\bitsprx4.dll
2009-02-10 17:03 <DIR> --d----- c:\program files\Microsoft Windows OneCare Live
2009-02-09 17:42 <DIR> --d----- c:\windows\system32\CatRoot_bak
2009-02-09 17:33 331,776 -------- c:\windows\system32\dllcache\msadce.dll
2009-02-09 16:23 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-02-09 16:23 268,648 a------- c:\windows\system32\mucltui.dll
2009-02-09 12:15 821 a------- c:\windows\system32\winpfz33.sys
2009-02-09 12:14 183,563 a------- c:\documents and settings\krista\g32.exe

==================== Find3M ====================

2009-02-09 17:29 527,091 ---sh--- c:\windows\hijkkj.ini2
2009-02-09 15:32 5,852 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-01-16 21:35 3,594,752 a------- c:\windows\system32\dllcache\mshtml.dll
2008-12-19 04:10 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 04:10 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 00:25 634,024 -------- c:\windows\system32\dllcache\iexplore.exe
2008-12-19 00:23 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
2008-12-11 06:57 333,184 -------- c:\windows\system32\dllcache\srv.sys
2006-12-29 12:04 452,096 ac------ c:\program files\Dont-Touch-My-Ads.exe
2004-09-03 16:05 37 ac------ c:\docume~1\krista\applic~1\tvmcwrd.dll
2004-09-03 12:30 215,725 ac------ c:\docume~1\krista\applic~1\tvmknwrd.dll
2007-10-21 13:12 6,486 ---sh--- c:\windows\system32\ilkkj.bak1
2007-11-16 20:30 10,620 ---sh--- c:\windows\system32\ilkkj.bak2

============= FINISH: 15:31:56.84 ===============

BC AdBot (Login to Remove)

 


#2 kristap0250

kristap0250
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:37 AM

Posted 11 February 2009 - 04:41 PM

oooooppppps I forgot to attach the other file from the dds.... that file is attached here...

Attached Files



#3 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:10:37 AM

Posted 12 February 2009 - 02:13 AM

Hi,

* Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Post the log from ComboFix in your next reply.

Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix..This because Security Software may see some components ComboFix uses (prep.com for example) as suspicious and blocks the tool, or even deletes it. Please visit HERE if you don't know how.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#4 kristap0250

kristap0250
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:37 AM

Posted 12 February 2009 - 09:19 AM

OK I shut off all the anti virus and firewalls. I think I did it right because my windows one care is currently red insted of green.... Here is a copy of the combo fix log.... I'm assuming I wait now to hear back on what to do next?

Krista


ComboFix 09-02-11.03 - Krista 2009-02-12 8:52:24.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.254.46 [GMT -5:00]
Running from: c:\documents and settings\Krista\Desktop\ComboFix.exe
AV: Windows Live OneCare *On-access scanning disabled* (Updated)
FW: Windows Live OneCare Firewall *disabled*
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Krista\Local Settings\Application Data\saaqa.dat
c:\documents and settings\Krista\Local Settings\Application Data\saaqa.exe
c:\documents and settings\Krista\Local Settings\Application Data\saaqa_nav.dat
c:\documents and settings\Krista\Local Settings\Application Data\saaqa_navps.dat
c:\program files\Instant Buzz
c:\program files\Instant Buzz\.ibp
c:\program files\Instant Buzz\.ibq
c:\program files\Instant Buzz\bugreport.txt
c:\program files\Instant Buzz\kristasp.ibp
c:\program files\Instant Buzz\kristasp.ibq
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\History\search
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\bar\Settings\settings.dat
c:\program files\MyWebSearch\bar\Settings\settings.dat.bak
c:\program files\MyWebSearch\bar\Settings\settings.htm
c:\program files\MyWebSearch\bar\Settings\settings.htm.bak
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\cookies.ini
c:\windows\IE4 Error Log.txt
c:\windows\smdat32a.sys
c:\windows\smdat32m.sys
c:\windows\system32\comrepl.exe
c:\windows\system32\drivers\fad.sys
c:\windows\SYSTEM32\ilkkj.bak1
c:\windows\SYSTEM32\ilkkj.bak2
c:\windows\SYSTEM32\ilkkj.ini
c:\windows\system32\mcrh.tmp
c:\windows\system32\msnav32.ax
c:\windows\system32\nvs2.inf
c:\windows\system32\winpfz32.sys
c:\windows\system32\winpfz33.sys
c:\windows\system32\zxdnt3d.cfg

.
((((((((((((((((((((((((( Files Created from 2009-01-12 to 2009-02-12 )))))))))))))))))))))))))))))))
.

2009-02-12 08:48 . 2009-02-12 08:50 <DIR> d-------- C:\32788R22FWJFW
2009-02-11 22:04 . 2009-02-11 22:08 <DIR> d-------- c:\program files\XoftSpySE
2009-02-11 10:21 . 2009-02-11 12:43 <DIR> d-------- C:\5819c6889d8cab945f
2009-02-10 21:46 . 2009-02-12 08:35 <DIR> d-------- c:\program files\Exterminate It!
2009-02-10 17:16 . 2007-11-27 22:56 91,328 --a------ c:\windows\SYSTEM32\DRIVERS\msfwdrv.sys
2009-02-10 17:15 . 2007-11-27 22:56 116,416 --a------ c:\windows\SYSTEM32\DRIVERS\msfwhlpr.sys
2009-02-10 17:13 . 2009-02-10 17:16 <DIR> d----c--- c:\windows\SYSTEM32\DRVSTORE
2009-02-10 17:13 . 2008-05-15 16:15 53,168 --a------ c:\windows\SYSTEM32\DRIVERS\MpFilter.sys
2009-02-10 17:12 . 2007-03-29 07:56 409,600 --------- c:\windows\SYSTEM32\DLLCACHE\qmgr.dll
2009-02-10 17:12 . 2007-03-29 07:56 18,944 --------- c:\windows\SYSTEM32\DLLCACHE\qmgrprxy.dll
2009-02-10 17:12 . 2007-03-29 07:56 7,168 --------- c:\windows\SYSTEM32\DLLCACHE\bitsprx4.dll
2009-02-10 17:12 . 2007-03-29 07:56 7,168 --------- c:\windows\SYSTEM32\bitsprx4.dll
2009-02-10 17:03 . 2009-02-12 02:34 <DIR> d-------- c:\program files\Microsoft Windows OneCare Live
2009-02-09 19:57 . 2009-02-09 19:57 <DIR> d-------- c:\program files\Windows Defender
2009-02-09 17:42 . 2009-02-09 18:37 <DIR> d-------- c:\windows\SYSTEM32\CatRoot_bak
2009-02-09 17:33 . 2008-05-01 09:30 331,776 --------- c:\windows\SYSTEM32\DLLCACHE\msadce.dll
2009-02-09 16:23 . 2008-10-16 14:06 268,648 --a------ c:\windows\SYSTEM32\mucltui.dll
2009-02-09 16:23 . 2008-10-16 14:06 27,496 --a------ c:\windows\SYSTEM32\mucltui.dll.mui
2009-02-09 16:04 . 2009-02-10 17:03 <DIR> d-------- c:\program files\Windows Live Safety Center
2009-02-09 12:14 . 2009-02-09 12:14 183,563 --a------ c:\documents and settings\Krista\g32.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-12 14:02 --------- d-----w c:\program files\FSCBoss
2009-02-10 22:19 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee.com
2009-02-10 21:37 --------- d-----w c:\documents and settings\All Users\Application Data\IEService
2009-02-10 00:52 --------- d-----w c:\program files\Google
2009-02-10 00:51 --------- d-----w c:\program files\Java
2009-02-10 00:24 --------- d-----w c:\program files\Microsoft Works
2009-02-09 22:29 527,091 --sh--w c:\windows\hijkkj.ini2
2009-02-09 16:38 --------- d-----w c:\documents and settings\All Users\Application Data\Dell
2009-01-16 17:57 --------- d-----w c:\program files\Dl_cats
2006-12-29 17:04 452,096 -c--a-w c:\program files\Dont-Touch-My-Ads.exe
2004-09-03 21:05 37 -c--a-w c:\documents and settings\Krista\Application Data\tvmcwrd.dll
2004-09-03 17:30 215,725 -c--a-w c:\documents and settings\Krista\Application Data\tvmknwrd.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"FSCBoss"="c:\program files\FSCBoss\FSCBoss.exe" [2005-06-10 356352]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"E6TaskPanel"="c:\program files\EarthLink TotalAccess\TaskPanl.exe" [2003-05-19 577536]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe" [2009-02-09 162744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-26 204800]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-05-23 77824]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2003-10-06 53248]
"DeviceDiscovery"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2002-12-02 40960]
"HostManager"="c:\program files\Common Files\AOL\1145803826\ee\AOLSoftware.exe" [2006-04-20 50792]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 292336]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 304008]
"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-11-03 312200]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 106496]
"OneCareUI"="c:\program files\Microsoft Windows OneCare Live\winssnotify.exe" [2008-11-05 64880]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1145803826\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1145803826\\ee\\aim6.exe"=
"c:\\Program Files\\AIM\\AIM Pro\\aimpro.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\mshta.exe"=
"c:\\WINDOWS\\SYSTEM32\\dlcxcoms.exe"=

R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 OcHealthMon;Windows Live OneCare Health Monitor;c:\program files\Microsoft Windows OneCare Live\OcHealthMon.exe [2008-11-05 25968]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-10 24652]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S2 XAMPP;XAMPP Service;c:\program files\xampp\service.exe --> c:\program files\xampp\service.exe [?]
.
Contents of the 'Scheduled Tasks' folder

2009-02-12 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2009-02-04 12:16]

2009-02-12 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2009-02-04 12:16]
.
- - - - ORPHANS REMOVED - - - -

BHO-{903d0aff-2162-4ac7-a3f4-2c45fbc3b04d} - (no file)
BHO-{FFD46104-E7A5-4765-8BC1-2F98B33FF2A6} - (no file)
HKCU-Run-saaqa - c:\documents and settings\krista\local settings\application data\saaqa.exe
Notify-dpmmon - dpmmon.dll
Notify-hggefef - hggefef.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.msn.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.msn.com
mSearch Bar =
IE: &AIM Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-12 09:03:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B2236175-3D9F-05C6-8B4893E47EF3B357}\{715026F0-32B2-9A38-0A89C09A617BF317}\{121623C5-7E2D-B1BB-98FD332A06B7F4F2}*]
"1D1OWFM6WKF6TLM3S2BGKKUUDG1"=hex:01,00,01,00,00,00,00,00,71,4a,e0,45,b7,4f,44,
fb,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
c:\windows\SYSTEM32\dlcxcoms.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\wanmpsvc.exe
c:\program files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
c:\program files\Microsoft Windows OneCare Live\winss.exe
c:\windows\SYSTEM32\wscntfy.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2009-02-12 9:12:21 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-12 14:12:05

Pre-Run: 25,054,277,632 bytes free
Post-Run: 25,413,763,072 bytes free

199 --- E O F --- 2009-02-12 05:11:58

#5 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:10:37 AM

Posted 12 February 2009 - 09:50 AM

Hi,

Please allow Combofix to install the Recovery console.
Also, I see you have Viewpoint installed...
Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This will change from what we know in 2006 read this article: http://www.clickz.com/news/article.php/3561546
I suggest you remove the program now. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.
  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player
By the way, did you purchase Xoftspy? If not, then I also suggest you uninstall it.
Then, * Open notepad - don't use any other texteditor than notepad or the script will fail.
Copy/paste the text in the quotebox below into notepad:

File::
c:\documents and settings\Krista\g32.exe
c:\windows\hijkkj.ini2
c:\documents and settings\Krista\Application Data\tvmcwrd.dll
c:\documents and settings\Krista\Application Data\tvmknwrd.dll
Folder::
c:\documents and settings\All Users\Application Data\IEService
Driver::
XAMPP
Regnull::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B2236175-3D9F-05C6-8B4893E47EF3B357}\{715026F0-32B2-9A38-0A89C09A617BF317}\{121623C5-7E2D-B1BB-98FD332A06B7F4F2}*]


Save this as txtfile CFScript

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

Posted Image

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

Edited by miekiemoes, 12 February 2009 - 09:51 AM.

AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#6 kristap0250

kristap0250
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:37 AM

Posted 12 February 2009 - 01:41 PM

i did not purchase the xoftspy thing, i thought it was free but it wasn't and I had tried to uninstall it a few times but it seems to keep showing up again after I reboot my computer... I uninstalled it again so hopefully it will stay gone now...... I also got rid of the viewpoint manager and player as well. Before I wasn't prompted for the recovery console (i don't think) but I was this time and it seemed to have installed correctly.... Here is the new log...

ComboFix 09-02-12.01 - Krista 2009-02-12 13:16:55.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.254.71 [GMT -5:00]
Running from: c:\documents and settings\Krista\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Krista\Desktop\CFScript.txt
AV: Windows Live OneCare *On-access scanning disabled* (Updated)
FW: Windows Live OneCare Firewall *disabled*
* Created a new restore point

FILE ::
c:\documents and settings\Krista\Application Data\tvmcwrd.dll
c:\documents and settings\Krista\Application Data\tvmknwrd.dll
c:\documents and settings\Krista\g32.exe
c:\windows\hijkkj.ini2
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\IEService
c:\documents and settings\All Users\Application Data\IEService\inf.fil
c:\documents and settings\All Users\Application Data\IEService\inf.ini
c:\documents and settings\Krista\Application Data\tvmcwrd.dll
c:\documents and settings\Krista\Application Data\tvmknwrd.dll
c:\documents and settings\Krista\g32.exe
c:\windows\aceghk.ini
c:\windows\ayccfe.ini
c:\windows\bbehkj.ini
c:\windows\bdcfgh.ini
c:\windows\cdeeeg.ini
c:\windows\deffgh.ini
c:\windows\dfhjkj.ini
c:\windows\dgjilm.ini
c:\windows\eddeeg.ini
c:\windows\efiklm.ini
c:\windows\ggjilm.ini
c:\windows\hijkkj.ini
c:\windows\hijkkj.ini2
c:\windows\hilonn.ini
c:\windows\hkjlmp.ini
c:\windows\kkjilm.ini
c:\windows\kknpqr.ini
c:\windows\klnoqr.ini
c:\windows\lllklm.ini
c:\windows\mlorqr.ini
c:\windows\nmnmnn.ini
c:\windows\nnnqpo.ini
c:\windows\opsvut.ini
c:\windows\poonmp.ini
c:\windows\pqrqss.ini
c:\windows\qsssru.ini
c:\windows\qsuxxx.ini
c:\windows\ruttut.ini
c:\windows\suvxbc.ini
c:\windows\suvxxx.ini
c:\windows\tuwybc.ini
c:\windows\tvybcf.ini
c:\windows\uvxbbc.ini
c:\windows\vvuwwa.ini
c:\windows\vvxbay.ini
c:\windows\vxaycf.ini
c:\windows\vyabcf.ini
c:\windows\waabcf.ini
c:\windows\wvwwwa.ini
c:\windows\wwwxay.ini
c:\windows\xxbbbc.ini
c:\windows\xycfgh.ini
c:\windows\xyybbc.ini
c:\windows\yaybay.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_XAMPP
-------\Service_XAMPP


((((((((((((((((((((((((( Files Created from 2009-01-12 to 2009-02-12 )))))))))))))))))))))))))))))))
.

2009-02-11 22:04 . 2009-02-12 11:42 <DIR> d-------- c:\program files\XoftSpySE
2009-02-11 10:21 . 2009-02-11 12:43 <DIR> d-------- C:\5819c6889d8cab945f
2009-02-10 21:46 . 2009-02-12 08:35 <DIR> d-------- c:\program files\Exterminate It!
2009-02-10 17:16 . 2007-11-27 22:56 91,328 --a------ c:\windows\SYSTEM32\DRIVERS\msfwdrv.sys
2009-02-10 17:15 . 2007-11-27 22:56 116,416 --a------ c:\windows\SYSTEM32\DRIVERS\msfwhlpr.sys
2009-02-10 17:13 . 2009-02-10 17:16 <DIR> d----c--- c:\windows\SYSTEM32\DRVSTORE
2009-02-10 17:13 . 2008-05-15 16:15 53,168 --a------ c:\windows\SYSTEM32\DRIVERS\MpFilter.sys
2009-02-10 17:12 . 2007-03-29 07:56 409,600 --------- c:\windows\SYSTEM32\DLLCACHE\qmgr.dll
2009-02-10 17:12 . 2007-03-29 07:56 18,944 --------- c:\windows\SYSTEM32\DLLCACHE\qmgrprxy.dll
2009-02-10 17:12 . 2007-03-29 07:56 7,168 --------- c:\windows\SYSTEM32\DLLCACHE\bitsprx4.dll
2009-02-10 17:12 . 2007-03-29 07:56 7,168 --------- c:\windows\SYSTEM32\bitsprx4.dll
2009-02-10 17:03 . 2009-02-12 09:07 <DIR> d-------- c:\program files\Microsoft Windows OneCare Live
2009-02-09 19:57 . 2009-02-09 19:57 <DIR> d-------- c:\program files\Windows Defender
2009-02-09 17:42 . 2009-02-09 18:37 <DIR> d-------- c:\windows\SYSTEM32\CatRoot_bak
2009-02-09 17:33 . 2008-05-01 09:30 331,776 --------- c:\windows\SYSTEM32\DLLCACHE\msadce.dll
2009-02-09 16:23 . 2008-10-16 14:06 268,648 --a------ c:\windows\SYSTEM32\mucltui.dll
2009-02-09 16:23 . 2008-10-16 14:06 27,496 --a------ c:\windows\SYSTEM32\mucltui.dll.mui
2009-02-09 16:04 . 2009-02-10 17:03 <DIR> d-------- c:\program files\Windows Live Safety Center

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-12 18:26 --------- d-----w c:\program files\FSCBoss
2009-02-12 16:43 --------- d-----w c:\program files\Viewpoint
2009-02-12 16:43 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-02-10 22:19 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee.com
2009-02-10 00:52 --------- d-----w c:\program files\Google
2009-02-10 00:51 --------- d-----w c:\program files\Java
2009-02-10 00:24 --------- d-----w c:\program files\Microsoft Works
2009-02-09 16:38 --------- d-----w c:\documents and settings\All Users\Application Data\Dell
2009-01-16 17:57 --------- d-----w c:\program files\Dl_cats
2006-12-29 17:04 452,096 -c--a-w c:\program files\Dont-Touch-My-Ads.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-02-12_ 9.09.21.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-12 18:25:38 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_69c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"FSCBoss"="c:\program files\FSCBoss\FSCBoss.exe" [2005-06-10 356352]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"E6TaskPanel"="c:\program files\EarthLink TotalAccess\TaskPanl.exe" [2003-05-19 577536]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.911.3380\GoogleToolbarNotifier.exe" [2009-02-09 162744]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-26 204800]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-05-23 77824]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2003-10-06 53248]
"DeviceDiscovery"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2002-12-02 40960]
"HostManager"="c:\program files\Common Files\AOL\1145803826\ee\AOLSoftware.exe" [2006-04-20 50792]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 292336]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 304008]
"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-11-03 312200]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 106496]
"OneCareUI"="c:\program files\Microsoft Windows OneCare Live\winssnotify.exe" [2008-11-05 64880]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1145803826\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1145803826\\ee\\aim6.exe"=
"c:\\Program Files\\AIM\\AIM Pro\\aimpro.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\mshta.exe"=
"c:\\WINDOWS\\SYSTEM32\\dlcxcoms.exe"=

R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 OcHealthMon;Windows Live OneCare Health Monitor;c:\program files\Microsoft Windows OneCare Live\OcHealthMon.exe [2008-11-05 25968]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.msn.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.msn.com
mSearch Bar =
IE: &AIM Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-12 13:24:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
c:\windows\SYSTEM32\dlcxcoms.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\wanmpsvc.exe
c:\program files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
c:\program files\Microsoft Windows OneCare Live\winss.exe
c:\windows\SYSTEM32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-02-12 13:33:06 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-12 18:32:52
ComboFix2.txt 2009-02-12 14:12:24

Pre-Run: 25,397,481,472 bytes free
Post-Run: 25,298,141,184 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

211 --- E O F --- 2009-02-12 05:11:58

#7 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:10:37 AM

Posted 12 February 2009 - 01:54 PM

Hi,

This looks OK again.

* Go to start > run and copy and paste next command in the field:

ComboFix /u

Make sure there's a space between Combofix and /
Then hit enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

Let me know in your next reply how things are now.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#8 kristap0250

kristap0250
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:37 AM

Posted 12 February 2009 - 02:00 PM

Awesome, it seemed to uninstall ok... And my computer seems to be running a lot better. I'm going to run the Microsoft scan that I originally ran and see how it goes, I'm sure it will be fine though... Thank you so much.....
Krista

#9 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:10:37 AM

Posted 12 February 2009 - 02:18 PM

Glad I could help. :thumbup2:

Please read my Prevention page with lots of info and tips how to prevent this in the future.
And if you want to improve speed/system performance after malware removal, take a look here.
Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan.

Happy Surfing again!
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#10 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:10:37 AM

Posted 17 February 2009 - 09:52 AM

Since this issue appears resolved ... this Topic is closed.
If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users