Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Antivirus/tojan removal/exe/related sites don't work


  • This topic is locked This topic is locked
3 replies to this topic

#1 Khlyra

Khlyra

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:07:27 PM

Posted 08 November 2009 - 12:49 PM

Hi there,

May I start with thanking whomever works with me on this!

Yesterday morning I did all my normal daily scans/virus etc.and everything was clean. I know exactly where and when I got this host of trojans, and I know there are many. I was going to watch a tv show off a steaming site and I knew instantly I was in trouble. (Wisevid) I was able to run superantispyware for a few minutes before it closed iteself and rebooted system, then everything did not work. I did notice the following trojans all pop up in the display just as it closed. wmdtc.exe, win32agent, mundo of some sort, there we more but I couldn't read them fast enough. This has also disabled win defender, catalyst and a couple other programs I didn't catch as it was so fast. It also seems to have rolled my system back in some areas. I also see the "a.exe" trojan in my task manager. I can end this but it comes right back.

All of my normal programs will not work. I run Avast, malwarebytes, superantispyware, ccleaner and spybot. All of which give me: "Windows cannot access the specified file or path. You may not have the appropriate permissions to access this file". In addition, any sites that have online scanners, related to removal, MS etc will not work.

I have tried combofix and I get the error that I have an infected copy etc. I can not get hijackthis to run - same thing. I have tried doing everything in safe mode etc. The one thing I have been able to get is a log from GMER. This is due to the fact that I can rename these and have them run, but they close instantly after. I noticed on the 2nd try that gmer would run anthoer 10 secs or so after the last line was propagated, so I ran a 3rd time and quickly copied it before it closed and gave the "Windows cannot access the specified file or path. You may not have the appropriate permissions to access this file". EDIT: pasting the GMER file.

GMER 1.0.15.15163 - http://www.gmer.net
Rootkit scan 2009-11-07 19:30:36
Windows 6.0.6000
Running: span.exe; Driver: C:\Users\KH\AppData\Local\Temp\fwroypoc.sys


---- Kernel code sections - GMER 1.0.15 ----

? win32k.sys:1 The system cannot find the file specified. !
? win32k.sys:2 The system cannot find the file specified. !

---- User code sections - GMER 1.0.15 ----

.text C:\Windows\system32\csrss.exe[484] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\csrss.exe[484] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\csrss.exe[484] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\csrss.exe[484] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\csrss.exe[484] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\csrss.exe[484] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\csrss.exe[484] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\wininit.exe[492] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\wininit.exe[492] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\wininit.exe[492] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\wininit.exe[492] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\wininit.exe[492] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\wininit.exe[492] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\wininit.exe[492] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\wininit.exe[492] USER32.dll!IsThreadDesktopComposited + 3FD 75DBBEB1 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\wininit.exe[492] GDI32.dll!SetROP2 + 90 757C89E7 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\wininit.exe[492] GDI32.dll!CreateFontA + 9E 757D154B 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\winlogon.exe[520] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\winlogon.exe[520] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\winlogon.exe[520] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\winlogon.exe[520] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\winlogon.exe[520] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\winlogon.exe[520] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\winlogon.exe[520] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\winlogon.exe[520] USER32.dll!IsThreadDesktopComposited + 3FD 75DBBEB1 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\winlogon.exe[520] GDI32.dll!SetROP2 + 90 757C89E7 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\winlogon.exe[520] GDI32.dll!CreateFontA + 9E 757D154B 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\services.exe[564] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\services.exe[564] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\services.exe[564] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\services.exe[564] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\services.exe[564] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\services.exe[564] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\services.exe[564] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\services.exe[564] USER32.dll!IsThreadDesktopComposited + 3FD 75DBBEB1 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\services.exe[564] GDI32.dll!SetROP2 + 90 757C89E7 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\services.exe[564] GDI32.dll!CreateFontA + 9E 757D154B 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\lsass.exe[576] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\lsass.exe[576] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\lsass.exe[576] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\lsass.exe[576] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\lsass.exe[576] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\lsass.exe[576] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\lsass.exe[576] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\lsm.exe[588] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\lsm.exe[588] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\lsm.exe[588] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\lsm.exe[588] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\lsm.exe[588] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\lsm.exe[588] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\lsm.exe[588] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\svchost.exe[736] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\svchost.exe[736] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\svchost.exe[736] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\svchost.exe[736] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\svchost.exe[736] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\svchost.exe[736] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\svchost.exe[736] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\svchost.exe[796] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\svchost.exe[796] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\svchost.exe[796] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\svchost.exe[796] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\svchost.exe[796] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\svchost.exe[796] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\svchost.exe[796] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\svchost.exe[796] GDI32.dll!SetROP2 + 90 757C89E7 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[796] GDI32.dll!CreateFontA + 9E 757D154B 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[796] USER32.dll!IsThreadDesktopComposited + 3FD 75DBBEB1 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\System32\svchost.exe[836] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\System32\svchost.exe[836] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\System32\svchost.exe[836] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\System32\svchost.exe[836] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\System32\svchost.exe[836] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\System32\svchost.exe[836] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\System32\svchost.exe[836] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\System32\svchost.exe[948] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\System32\svchost.exe[948] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\System32\svchost.exe[948] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\System32\svchost.exe[948] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\System32\svchost.exe[948] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\System32\svchost.exe[948] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\System32\svchost.exe[948] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\System32\svchost.exe[948] GDI32.dll!SetROP2 + 90 757C89E7 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\System32\svchost.exe[948] GDI32.dll!CreateFontA + 9E 757D154B 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\System32\svchost.exe[948] USER32.dll!IsThreadDesktopComposited + 3FD 75DBBEB1 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\svchost.exe[972] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\svchost.exe[972] GDI32.dll!SetROP2 + 90 757C89E7 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[972] GDI32.dll!CreateFontA + 9E 757D154B 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[972] USER32.dll!IsThreadDesktopComposited + 3FD 75DBBEB1 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\System32\svchost.exe[1044] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\System32\svchost.exe[1044] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\System32\svchost.exe[1044] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\System32\svchost.exe[1044] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\System32\svchost.exe[1044] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\System32\svchost.exe[1044] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\System32\svchost.exe[1044] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\System32\svchost.exe[1044] GDI32.dll!SetROP2 + 90 757C89E7 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\System32\svchost.exe[1044] GDI32.dll!CreateFontA + 9E 757D154B 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\System32\svchost.exe[1044] USER32.dll!IsThreadDesktopComposited + 3FD 75DBBEB1 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1100] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\svchost.exe[1100] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\svchost.exe[1100] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\svchost.exe[1100] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\svchost.exe[1100] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\svchost.exe[1100] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\svchost.exe[1100] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\svchost.exe[1100] GDI32.dll!SetROP2 + 90 757C89E7 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1100] GDI32.dll!CreateFontA + 9E 757D154B 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1100] USER32.dll!IsThreadDesktopComposited + 3FD 75DBBEB1 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1128] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\svchost.exe[1128] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\svchost.exe[1128] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\svchost.exe[1128] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\svchost.exe[1128] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\svchost.exe[1128] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\svchost.exe[1128] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\svchost.exe[1128] GDI32.dll!SetROP2 + 90 757C89E7 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1128] GDI32.dll!CreateFontA + 9E 757D154B 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1128] USER32.dll!IsThreadDesktopComposited + 3FD 75DBBEB1 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1384] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\svchost.exe[1384] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\svchost.exe[1384] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\svchost.exe[1384] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\svchost.exe[1384] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\svchost.exe[1384] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\svchost.exe[1384] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\svchost.exe[1384] GDI32.dll!SetROP2 + 90 757C89E7 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1384] GDI32.dll!CreateFontA + 9E 757D154B 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1384] USER32.dll!IsThreadDesktopComposited + 3FD 75DBBEB1 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\Explorer.EXE[1420] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\Explorer.EXE[1420] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\Explorer.EXE[1420] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\Explorer.EXE[1420] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\Explorer.EXE[1420] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\Explorer.EXE[1420] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\Explorer.EXE[1420] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\Explorer.EXE[1420] GDI32.dll!SetROP2 + 90 757C89E7 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\Explorer.EXE[1420] GDI32.dll!CreateFontA + 9E 757D154B 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\Explorer.EXE[1420] USER32.dll!IsThreadDesktopComposited + 3FD 75DBBEB1 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1504] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\svchost.exe[1504] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\svchost.exe[1504] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\svchost.exe[1504] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\svchost.exe[1504] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\svchost.exe[1504] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\svchost.exe[1504] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\svchost.exe[1504] GDI32.dll!SetROP2 + 90 757C89E7 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1504] GDI32.dll!CreateFontA + 9E 757D154B 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1504] USER32.dll!IsThreadDesktopComposited + 3FD 75DBBEB1 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Users\RAC\Desktop\New Folder\span.exe[1532] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Users\RAC\Desktop\New Folder\span.exe[1532] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Users\RAC\Desktop\New Folder\span.exe[1532] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Users\RAC\Desktop\New Folder\span.exe[1532] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Users\RAC\Desktop\New Folder\span.exe[1532] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Users\RAC\Desktop\New Folder\span.exe[1532] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Users\RAC\Desktop\New Folder\span.exe[1532] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\svchost.exe[1604] ntdll.dll!NtCreateFile 76F5F414 5 Bytes CALL 7FFA46DE
.text C:\Windows\system32\svchost.exe[1604] ntdll.dll!NtCreateProcess 76F5F4D4 5 Bytes CALL 7FFA476D
.text C:\Windows\system32\svchost.exe[1604] ntdll.dll!NtCreateProcessEx 76F5F4E4 5 Bytes CALL 7FFA477A
.text C:\Windows\system32\svchost.exe[1604] ntdll.dll!NtDeviceIoControlFile 76F5F844 5 Bytes CALL 7FFA49FE
.text C:\Windows\system32\svchost.exe[1604] ntdll.dll!NtOpenFile 76F5FBF4 5 Bytes CALL 7FFA4763
.text C:\Windows\system32\svchost.exe[1604] ntdll.dll!NtQueryInformationProcess 76F5FE94 5 Bytes CALL 7FFA47BB
.text C:\Windows\system32\svchost.exe[1604] ntdll.dll!NtCreateUserProcess 76F608A4 5 Bytes CALL 7FFA4787
.text C:\Windows\system32\svchost.exe[1604] GDI32.dll!SetROP2 + 90 757C89E7 7 Bytes CALL 35672DDE \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1604] GDI32.dll!CreateFontA + 9E 757D154B 7 Bytes CALL 35672DC2 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
.text C:\Windows\system32\svchost.exe[1604] USER32.dll!IsThreadDesktopComposited + 3FD 75DBBEB1 7 Bytes CALL 35672D96 \\?\globalroot\Device\__max++>\1F3C7414.x86.dll

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Windows\system32\wininit.exe[492] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\wininit.exe[492] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\winlogon.exe[520] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\winlogon.exe[520] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\services.exe[564] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\services.exe[564] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[796] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[796] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\System32\svchost.exe[948] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\System32\svchost.exe[948] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[972] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[972] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\System32\svchost.exe[1044] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\System32\svchost.exe[1044] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[1100] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[1100] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[1128] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[1128] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[1384] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[1384] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [739FFE0C] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [739CC53D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [739BA31F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [739BCBEF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [739B8AAA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [739CDAB8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [739B7D8D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [739B7CF4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [739B6A4E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [73A4BE7C] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [739D8A5E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [739B90CD] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [739C2248] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [739C2273] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [739C7724] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [739C7546] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [739F861D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\Explorer.EXE[1420] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[1504] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[1604] @ C:\Windows\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672A94] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll
IAT C:\Windows\system32\svchost.exe[1604] @ C:\Windows\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A1E] \\?\globalroot\Device\__max++>\1F3C7414.x86.dll

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Processes - GMER 1.0.15 ----

Library \\?\globalroot\Device\__max++>\1F3C7414.x86.dll (*** hidden *** ) @ C:\Windows\system32\wininit.exe [492] 0x35670000
Library \\?\globalroot\Device\__max++>\1F3C7414.x86.dll (*** hidden *** ) @ C:\Windows\system32\winlogon.exe [520] 0x35670000
Library \\?\globalroot\Device\__max++>\1F3C7414.x86.dll (*** hidden *** ) @ C:\Windows\system32\services.exe [564] 0x35670000
Library \\?\globalroot\Device\__max++>\1F3C7414.x86.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [796] 0x35670000
Library \\?\globalroot\Device\__max++>\1F3C7414.x86.dll (*** hidden *** ) @ C:\Windows\System32\svchost.exe [948] 0x35670000
Library \\?\globalroot\Device\__max++>\1F3C7414.x86.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [972] 0x35670000
Library \\?\globalroot\Device\__max++>\1F3C7414.x86.dll (*** hidden *** ) @ C:\Windows\System32\svchost.exe [1044] 0x35670000
Library \\?\globalroot\Device\__max++>\1F3C7414.x86.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1100] 0x35670000
Library \\?\globalroot\Device\__max++>\1F3C7414.x86.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1128] 0x35670000
Library \\?\globalroot\Device\__max++>\1F3C7414.x86.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1384] 0x35670000
Library \\?\globalroot\Device\__max++>\1F3C7414.x86.dll (*** hidden *** ) @ C:\Windows\Explorer.EXE [1420] 0x35670000
Library \\?\globalroot\Device\__max++>\1F3C7414.x86.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1504] 0x35670000
Library \\?\globalroot\Device\__max++>\1F3C7414.x86.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [1604] 0x35670000

---- Registry - GMER 1.0.15 ----

Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{825236CA-D55C-E496-A56F-F359360D8B15}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{825236CA-D55C-E496-A56F-F359360D8B15}@habeihdicbcbnjhn 0x6A 0x61 0x64 0x62 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{825236CA-D55C-E496-A56F-F359360D8B15}@iahdcmjhhoccjchnhi 0x6A 0x61 0x64 0x62 ...


Thanks in advance for the help. I await your reply.

Edited by Khlyra, 08 November 2009 - 12:51 PM.


BC AdBot (Login to Remove)

 


#2 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,719 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:05:27 AM

Posted 13 November 2009 - 06:58 AM

Hi Khlyra,

Welcome to BC HijackThis forum and sorry for the delay. I am farbar. I am going to assist you with your problem.

Please refrain from making any changes to your system (scanning or running other tools, updating Windows, installing applications, removing files, etc.) from now on as it might interfere with our fixes. Please let me know in your next reply if you agree with this.

Please update me on the current condition of your computer in case the issue is not solved.

#3 Khlyra

Khlyra
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:07:27 PM

Posted 13 November 2009 - 01:24 PM

I formatted system, please close topic.
Thank you for replying though.

#4 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,719 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:05:27 AM

Posted 13 November 2009 - 02:02 PM

Thanks for letting me know.

This thread will now be closed since the issue seems to be resolved.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users