Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Yahoo IM Trojan Horse Hijack


  • This topic is locked This topic is locked
2 replies to this topic

#1 tlight

tlight

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 08 December 2009 - 10:49 PM

My wife's laptop was hijacked after she clicked on a link in an IM from a friend. (I know, and now so does she.) Her Norton Virus software deleted a file and quarantined a few others but the browser is still hijacked:

W32.SillyFDC wmismqt.exe (deleted)
Trojan Horse mstcpd.exe (quarantined)
Trojan Horse msrpc01.exe (quarantined)
Trojan Horse 3mc[1].zip (quarantined)

Logs follow and are attached. I attached the RootRepeal and the Attach as outlined, and a Hijackthis log as well.
Thanks in advance for your help.

===========================

DDS (Ver_09-12-01.01) - NTFSx86
Run by LIGHTFOO at 21:03:06.80 on Tue 12/08/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.306 [GMT -6:00]

AV: Symantec Endpoint Protection *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *enabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Symantec AntiVirus\Smc.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
svchost.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Nortel\TunnelGuard\CueAgent_srv.exe
C:\WINDOWS\System32\svchost.exe -k Cognizance
C:\WINDOWS\etlisrv.exe
c:\WINDOWS\system32\IFXSPMGT.exe
c:\WINDOWS\system32\IFXTCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nortel Networks\Remote Access Manager\NNDService.exe
C:\Program Files\PCSRPSrvc\PCSRPSrvc.exe
c:\Program Files\ProtectTools\Embedded Security Software\PSDsrvc.EXE
C:\Program Files\Nortel Networks\Remote Access Manager\RAMSettings.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\HPQ\IAM\bin\asghost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
c:\Program Files\ProtectTools\Embedded Security Software\PSDrt.exe
C:\Program Files\WPMS\wpmsmon.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\etdsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Symantec AntiVirus\SmcGui.exe
C:\Program Files\Nortel Networks\Remote Access Manager\RAMDatabaseUpdater.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE
C:\WINDOWS\system32\AccelerometerSt.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
D:\DBRBackup\Agent.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Nortel\CallPilot\cpnotifier.exe
C:\Program Files\entrust\TrueDelete\Truedel.exe
C:\WINDOWS\system32\etlitr50.exe
C:\Program Files\Nortel\TunnelGuard\platforms\win32\TGIconApp.EXE
C:\Program Files\Open Text\Livelink Explorer\LLSynch3.exe
C:\Program Files\Symantec AntiVirus\SavUI.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Nortel Networks\Extranet_serv.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Nortel Networks PC Client\bin\SMC.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
E:\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://web.us.nortel.com/English/Pages/default.aspx
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.virusheat.com/?aff=1012
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
uURLSearchHooks: SweetIM ToolbarURLSearchHook Class: {eee6c35d-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgHelper.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: Internet Service: {51d81dd5-55b7-497f-95db-d356429bb54e} - c:\program files\netproject\wamdl.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: SweetIM Toolbar for Internet Explorer: {eee6c35b-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Messenger (Yahoo!)] ~"c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRunOnce: [<NO NAME>]
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [TkBellExe] c:\program files\common files\real\update_ob\realsched.exe -osboot
mRun: [RAMConnectionChecker] "c:\program files\nortel networks\remote access manager\RAMConnChecker.exe" -m
mRun: [RAMDatabaseUpdater] "c:\program files\nortel networks\remote access manager\RAMDatabaseUpdater.exe" -u
mRun: [RAMGINAConnWatch] "c:\program files\nortel networks\remote access manager\RAMConnWatcher.exe"
mRun: [IPInSightLAN 01] "c:\program files\visual networks\visual ip insight\nortel\IPClient.exe" -l
mRun: [IPInSightMonitor 01] "c:\program files\visual networks\visual ip insight\nortel\IPMon32.exe"
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [PTHOSTTR] c:\program files\hpq\hp protecttools security manager\PTHOSTTR.EXE /Start
mRun: [AccelerometerSysTrayApplet] c:\windows\system32\AccelerometerSt.exe
mRun: [WatchDog] c:\program files\intervideo\dvd check\DVDCheck.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [CognizanceTS] rundll32.exe c:\progra~1\hpq\iam\bin\AsTsVcc.dll,RegisterModule
mRun: [AgentUiRunKey] "d:\dbrbackup\Agent.exe" -ni -sss -e http://localhost:16386/
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [SweetIM] c:\program files\sweetim\messenger\SweetIM.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [ctfmon.exe] ctfmon.exe
mRunOnce: [<NO NAME>]
dRunOnce: [Runonce] c:\temp\elogoff.exe
dRunOnce: [Remove ShSh Agent UnInstaller Temp Files] c:\windows\system32\cmd.exe /c rd /s /q c:\windows\temp\~SdcBinU.Tmp
dRunOnce: [Remove ShSh Agent Temp Files] c:\windows\system32\cmd.exe /c rd /s /q c:\windows\temp\~SdcBin.Tmp
dRunOnce: [Remove ShSh Agent UnInstaller] c:\windows\system32\cmd.exe /c del "c:\windows\Agent_UnInstall*.Exe"
dRunOnce: [<NO NAME>]
mExplorerRun: [<NO NAME>] 1 (0x1)
StartupFolder: d:\profiles\lightfoo\startm~1\programs\startup\liveli~1.lnk - c:\program files\open text\livelink explorer\LLSynch3.exe
StartupFolder: d:\profiles\alluse~1\startm~1\programs\startup\callpi~1.lnk - c:\program files\nortel\callpilot\cpnotifier.exe
StartupFolder: d:\profiles\alluse~1\startm~1\programs\startup\dvdche~1.lnk - c:\program files\intervideo\dvd check\DVDCheck.exe
StartupFolder: d:\profiles\alluse~1\startm~1\programs\startup\entrus~2.lnk - c:\program files\entrust\ice\ice.exe
StartupFolder: d:\profiles\alluse~1\startm~1\programs\startup\entrus~1.lnk - c:\program files\entrust\truedelete\Truedel.exe
StartupFolder: d:\profiles\alluse~1\startm~1\programs\startup\entrust.lnk - c:\windows\system32\etlitr50.exe
StartupFolder: d:\profiles\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: d:\profiles\alluse~1\startm~1\programs\startup\tunnel~1.lnk - c:\windows\installer\{3c30b143-0c92-4585-8184-b74d82357177}\NewShortcut4_F62BEDE8E6C0428ABDAF1F6312B4B000.exe
uPolicies-explorer: GreyMSIAds = 1 (0x1)
uPolicies-explorer: NoWindowsUpdate = 1 (0x1)
uPolicies-explorer: NoAutoUpdate = 1 (0x1)
uPolicies-explorer: StartMenuLogoff = 1 (0x1)
mPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
mPolicies-system: LogonType = 0 (0x0)
dPolicies-explorer: NoLogoff = 1 (0x1)
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a}
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\windows\system32\msjava.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F}
DPF: AdobeControl - hxxps://selfservice.us.nortel.com/webdynpro/resources/sap.com/tc~wd~dispwda/global/activeComp/AdobeControl.CAB
DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - hxxps://centra.nortel.com/SiteRoots/main/Install/win32/CentraUpdaterAx.cab
DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} - hxxp://www.linkedin.com/cab/LinkedInContactFinderControl.cab
DPF: {547A5E74-F8CA-4326-9A46-95BEBFE6F065} - hxxp://livelink-ott.ca.nortel.com/livelinksupport/webexp/install.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://winstonevents.webex.com/client/T25L/event/ieatgpc.cab
DPF: {F53270D3-0E32-48B7-B63B-159E33210F70} - hxxp://livelink-ott.ca.nortel.com/livelinksupport/webexp/lledit.cab
TCP: {232B8F84-11D2-439B-86A5-2E60E2261194} = 47.103.128.200,47.103.64.210
Notify: IfxWlxEN - IfxWlxEN.dll
Notify: igfxcui - igfxdev.dll
Notify: OneCard - c:\program files\hpq\iam\bin\AsWlnPkg.dll
STS: garcea: {eb9f614b-ea44-40d0-8829-542e4f254739} - c:\windows\system32\rkaxfza.dll
LSA: Notification Packages = scecli AsWlnPkg
mASetup: {EEBF9CA6-567B-41cd-B5F6-EF2C7FEF37B5} - rundll32.exe advpack.dll,LaunchINFSection c:\windows\inf\wmactedp.inf,PerUserStub
Hosts: 209.85.225.99 msnfix.changelog.fr
Hosts: 209.85.225.99 www.incodesolutions.com
Hosts: 209.85.225.99 virusinfo.prevx.com
Hosts: 209.85.225.99 download.bleepingcomputer.com
Hosts: 209.85.225.99 www.dazhizhu.cn

Note: multiple HOSTS entries found. Please refer to Attach.txt

============= SERVICES / DRIVERS ===============

R0 iibvjreh;iibvjreh;c:\windows\system32\drivers\iibvjreh.sys [2009-12-8 40128]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2005-11-29 36768]
R2 aawservice;Ad-Aware 2007 Service;c:\program files\lavasoft\ad-aware 2007\aawservice.exe [2008-3-19 607576]
R2 ASChannel;Local Communication Channel;c:\windows\system32\svchost.exe -k Cognizance [2006-8-15 14336]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2008-12-31 108392]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2008-12-31 108392]
R2 ETDSVC;Entrust/TrueDelete™;c:\windows\system32\etdsvc.exe [2005-1-11 10240]
R2 ETFSDNT;Entrust File System Hook;c:\windows\system32\Etfsdrv.sys [2005-1-11 52432]
R2 NNDService;NNDService;c:\program files\nortel networks\remote access manager\NNDService.exe [2006-8-15 77824]
R2 PCSRPSrvc;PCSRPSrvc;c:\program files\pcsrpsrvc\PCSRPSrvc.exe [2007-11-29 32768]
R2 RAMSettings;RAMSettings;c:\program files\nortel networks\remote access manager\RAMSettings.exe [2006-8-15 65536]
R2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec antivirus\Rtvscan.exe [2008-12-31 2440120]
R2 WPMS;Workstation Performance Monitoring System;c:\program files\wpms\wpmsmon.exe [2006-6-22 114688]
R3 Eacfilt;Eacfilt Miniport;c:\windows\system32\drivers\eacfilt.sys [2006-12-1 26137]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-9-8 102448]
R3 ExtranetAccess;Contivity VPN Service;c:\program files\nortel networks\Extranet_serv.exe [2006-12-1 811008]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2006-8-15 87936]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2006-8-15 36352]
R3 kernelx86;Kernel Debug Service;c:\windows\system32\drivers\kernelx86.sys [2009-12-7 12136]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20091208.002\NAVENG.SYS [2009-12-8 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20091208.002\NAVEX15.SYS [2009-12-8 1323568]
S2 AgentService;AgentService;d:\dbrbackup\agentservice.exe -p 16386 --> d:\dbrbackup\AgentService.exe -p 16386 [?]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-12-31 23888]
S3 CVCBrokerService;CVCBrokerService;c:\program files\nortel networks\remote access manager\CVCBrokerService.exe [2006-8-15 73728]
S3 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [2006-12-1 155152]
S3 LV_Tracker;LV_Tracker;c:\windows\system32\drivers\LV_Tracker.sys [2008-8-1 45384]
S3 OracleOraHome81ClientCache;OracleOraHome81ClientCache;c:\oracle\ora81\bin\ONRSD.EXE [2000-10-19 411244]
S3 vmx_svga;vmx_svga;c:\windows\system32\drivers\vmx_svga.sys [2006-8-15 15744]
S3 vmxnet;VMware Ethernet Adapter Driver;c:\windows\system32\drivers\vmxnet.sys [2006-8-15 22528]

=============== Created Last 30 ================

2009-12-08 15:14:40 0 d--h--w- c:\windows\PIF
2009-12-08 14:49:28 40128 ----a-w- c:\windows\system32\drivers\iibvjreh.sys
2009-12-08 03:49:43 12136 ----a-w- c:\windows\system32\drivers\kernelx86.sys
2009-12-07 16:58:12 71168 ---h--w- c:\windows\system32\secupdat.dat
2009-12-07 16:58:12 6144 ---ha-w- d:\profiles\lightfoo\cckwdk.exe
2009-12-07 16:58:08 51712 ----a-w- c:\windows\system32\drivers\ndisvvan.sys
2009-11-17 18:00:18 198358 ----a-w- c:\windows\visualip_uinst.EXE

==================== Find3M ====================

2009-12-03 23:17:24 149768 ----a-w- c:\windows\system32\drivers\WpsHelper.sys
2009-09-25 05:56:36 662016 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:56:32 81920 ----a-w- c:\windows\system32\ieencode.dll
2008-08-08 18:38:23 10939634 ----a-w- c:\program files\InfoWindow.zip
2006-08-15 15:36:32 2176 ----a-w- c:\program files\INSTALL.LOG

============= FINISH: 21:05:22.13 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 tlight

tlight
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 11 December 2009 - 09:34 PM

Re-imaged hard drive. Thanks anyway.

#3 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,065 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:12:43 AM

Posted 18 December 2009 - 09:59 AM

Topic closed.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users