Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Redirecting Website Virus


  • This topic is locked This topic is locked
2 replies to this topic

#1 dcchitown853

dcchitown853

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:07:19 AM

Posted 21 October 2010 - 10:56 PM

Among other viruses on my computer was the redirecting virus on firefox...I've ran Malwarebytes, Spybot Search and Destroy, and have AVG 9 (purchased edition), none of which solved the problem. I just finished running Combofix.exe and I believe it solved the problem... here is the log file. Does anyone see anything suspicious? Thank you very much, this board has been a lifesaver for me.



ComboFix 10-10-21.02 - Administrator 10/21/2010 23:34:37.1.2 - x86
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\bbotxxxxxx.exe
c:\documents and settings\Administrator\Local Settings\Application Data\{2695F9AE-4DEB-429A-895C-DF54417F6284}
c:\documents and settings\Administrator\Local Settings\Application Data\{2695F9AE-4DEB-429A-895C-DF54417F6284}\chrome.manifest
c:\documents and settings\Administrator\Local Settings\Application Data\{2695F9AE-4DEB-429A-895C-DF54417F6284}\chrome\content\_cfg.js
c:\documents and settings\Administrator\Local Settings\Application Data\{2695F9AE-4DEB-429A-895C-DF54417F6284}\chrome\content\overlay.xul
c:\documents and settings\Administrator\Local Settings\Application Data\{2695F9AE-4DEB-429A-895C-DF54417F6284}\install.rdf

Infected copy of c:\windows.0\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows.0\ServicePackFiles\i386\winlogon.exe

Infected copy of c:\windows.0\explorer.exe was found and disinfected
Restored copy from - c:\windows.0\ServicePackFiles\i386\explorer.exe

.
((((((((((((((((((((((((( Files Created from 2010-09-22 to 2010-10-22 )))))))))))))))))))))))))))))))
.

2010-10-22 03:16 . 2010-10-22 03:16 -------- d-----w- C:\TDSSKiller_Quarantine
2010-10-21 04:18 . 2010-10-21 04:18 2 --shatr- c:\windows.0\winstart.bat
2010-10-21 03:53 . 2010-10-21 03:53 -------- d-----w- c:\windows.0\system32\wbem\Repository
2010-10-21 01:50 . 2010-10-21 23:18 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Application Data\Spybot - Search & Destroy
2010-10-21 01:50 . 2010-10-21 04:11 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-10-20 03:51 . 2010-10-20 03:51 -------- d-----w- c:\program files\Common Files\Java
2010-10-20 03:51 . 2010-09-15 08:50 472808 ----a-w- c:\windows.0\system32\deployJava1.dll
2010-10-20 03:30 . 2010-04-29 19:39 38224 ----a-w- c:\windows.0\system32\drivers\mbamswissarmy.sys
2010-10-20 03:30 . 2010-10-20 03:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-20 03:30 . 2010-04-29 19:39 20952 ----a-w- c:\windows.0\system32\drivers\mbam.sys
2010-10-20 03:22 . 2010-10-20 03:22 -------- d-----w- c:\program files\CCleaner
2010-10-20 02:49 . 2010-10-20 02:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\MSN6
2010-10-20 02:49 . 2010-10-20 02:49 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Application Data\MSN6
2010-10-20 02:15 . 2010-10-20 02:16 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Temp
2010-10-20 02:15 . 2010-10-20 03:20 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2010-10-20 02:14 . 2010-10-20 02:14 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Deployment
2010-10-20 02:02 . 2010-10-20 02:02 -------- d-----w- c:\documents and settings\All Users.WINDOWS.0\Application Data\NVIDIA
2010-10-19 23:22 . 2010-10-19 23:22 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Help
2010-10-19 22:25 . 2010-10-19 22:28 -------- d-----w- c:\windows.0\nview
2010-10-18 23:59 . 2010-10-20 02:27 -------- d-----w- c:\documents and settings\Administrator\Application Data\Typec
2010-10-18 23:59 . 2010-10-19 00:20 -------- d-----w- c:\documents and settings\Administrator\Application Data\Arnyca
2010-10-18 21:33 . 2010-10-18 21:33 -------- d-----w- c:\documents and settings\Administrator\Application Data\dvdcss
2010-10-15 23:05 . 2010-09-18 06:53 953856 -c----w- c:\windows.0\system32\dllcache\mfc40u.dll
2010-10-15 23:05 . 2010-09-18 06:53 974848 -c----w- c:\windows.0\system32\dllcache\mfc42.dll
2010-10-15 23:05 . 2010-08-23 16:12 617472 -c----w- c:\windows.0\system32\dllcache\comctl32.dll
2010-09-22 22:10 . 2010-09-22 22:10 103864 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-09-27 2102600]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-09-27 16:32 2102600 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-09-27 2102600]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-09-27 2102600]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-05-21 1501064]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-05-26 1468296]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-09-29 2067808]
"NvCplDaemon"="c:\windows.0\system32\NvCpl.dll" [2006-06-29 7618560]
"NvMediaCenter"="NvMCTray.dll" [2006-06-29 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-08-10 421888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SetDefaultMidi"="MIDIDEF.EXE" [2002-12-03 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-03 20:29 12536 ----a-w- c:\windows.0\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C\0autocheck autochk *

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows.0\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"GWMDMpi"=c:\windows.0\GWMDMpi.exe
"PRONoMgr.exe"=c:\program files\Intel\NCS\PROSet\PRONoMgr.exe
"GWMDMMSG"=GWMDMMSG.exe
"NvMediaCenter"=RUNDLL32.EXE c:\windows.0\system32\NvMcTray.dll,NvTaskbarInit
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-09-27 431432]
R3 Avgfwfd;AVG network filter service;c:\windows.0\system32\DRIVERS\avgfwdx.sys [2010-07-03 30104]
R3 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe AVGIDSAgent [x]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [2010-07-03 122448]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [2010-07-03 30288]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [2010-07-03 26192]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows.0\System32\drivers\COMMONFX.SYS [x]
R3 COMMONFX;COMMONFX;c:\windows.0\system32\drivers\COMMONFX.SYS [x]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-07 79360]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows.0\System32\drivers\CTAUDFX.SYS [x]
R3 CTAUDFX;CTAUDFX;c:\windows.0\system32\drivers\CTAUDFX.SYS [x]
R3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows.0\System32\drivers\CTERFXFX.SYS [x]
R3 CTERFXFX;CTERFXFX;c:\windows.0\system32\drivers\CTERFXFX.SYS [x]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows.0\System32\drivers\CTSBLFX.SYS [x]
R3 CTSBLFX;CTSBLFX;c:\windows.0\system32\drivers\CTSBLFX.SYS [x]
R3 PCDRDRV;Pcdr Helper Driver;c:\progra~1\PC-DOC~1\DIAGNO~1\PCDRDRV.sys [x]
R3 vaxscsi;vaxscsi;c:\windows.0\System32\Drivers\vaxscsi.sys [2009-10-17 223128]
R4 sptd;sptd;c:\windows.0\system32\Drivers\sptd.sys [2010-02-10 691696]
S0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows.0\System32\Drivers\AVGIDSxx.sys [2010-07-03 25168]
S0 AvgRkx86;avgrkx86.sys;c:\windows.0\System32\Drivers\avgrkx86.sys [2010-07-03 52872]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows.0\System32\Drivers\avgldx86.sys [2010-07-03 216400]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows.0\System32\Drivers\avgtdix.sys [2010-07-03 243024]
S2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-07-20 921952]
S2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-07-03 308136]
S2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [2002-01-01 2331544]
S3 Avgfwdx;Avgfwdx;c:\windows.0\system32\DRIVERS\avgfwdx.sys [2010-07-03 30104]

.
Contents of the 'Scheduled Tasks' folder

2010-10-21 c:\windows.0\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]

2010-10-20 c:\windows.0\Tasks\AWC AutoCare.job
- c:\program files\IObit\Advanced SystemCare 3\AutoCare.exe [2009-09-26 18:10]

2010-10-22 c:\windows.0\Tasks\AWC AutoSweep.job
- c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2009-09-26 18:11]

2010-10-22 c:\windows.0\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2009-09-26 21:20]

2010-07-16 c:\windows.0\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2009-05-26 19:16]

2010-10-22 c:\windows.0\Tasks\OGALogon.job
- c:\windows.0\system32\OGAEXEC.exe [2009-08-03 20:07]

2010-10-11 c:\windows.0\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-02-05 22:08]
.
.
------- Supplementary Scan -------
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.gatewaybiz.com
uInternet Connection Wizard,ShellNext = hxxp://www.gatewaybiz.com/
uInternet Settings,ProxyOverride = *.local
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
DPF: Microsoft XML Parser for Java - file://c:\windows.0\Java\classes\xmldso.cab
DPF: {511073AD-BE56-4D43-AE68-93390514385E} - file://c:\program files\Gateway\helpspot\TechTools.CAB
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uwy8tpst.default\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uwy8tpst.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-bbotxxxxxx.exe - c:\bbotxxxxxx.exe\bbotxxxxxx.exe


.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1606980848-1715567821-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,80,96,77,1a,b7,bc,d1,48,a2,11,cb,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,80,96,77,1a,b7,bc,d1,48,a2,11,cb,\

[HKEY_USERS\S-1-5-21-1606980848-1715567821-839522115-500\Software\SecuROM\License information*]
"datasecu"=hex:c4,ee,68,08,2c,e5,b5,f4,c4,b6,25,c2,b9,5b,8c,bc,8b,83,8b,28,dd,
bc,6e,b8,bd,8f,87,a3,9c,d9,1e,2f,aa,39,37,49,80,fd,11,2b,72,3c,22,a9,9e,91,\
"rkeysecu"=hex:e7,18,f6,bb,3e,70,18,16,28,fa,dc,e0,ca,5d,20,0f
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3648)
c:\windows.0\system32\WININET.dll
c:\windows.0\system32\msi.dll
c:\windows.0\system32\ieframe.dll
c:\windows.0\system32\webcheck.dll
c:\windows.0\system32\WPDShServiceObj.dll
c:\windows.0\system32\PortableDeviceTypes.dll
c:\windows.0\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows.0\system32\nvsvc32.exe
c:\program files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
c:\program files\AVG\AVG9\avgam.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows.0\system32\wscntfy.exe
c:\windows.0\system32\RunDLL32.exe
c:\program files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
c:\program files\Microsoft IntelliPoint\dpupdchk.exe
.
**************************************************************************
.
Completion time: 2010-10-21 23:49:48 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-22 03:49

Pre-Run: 48,514,263,040 bytes free
Post-Run: 48,833,557,504 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS.0
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS.0="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect
C:\="Previous Operating System on C:"

- - End Of File - - E825BE31B64751086080160C022CDA78

Edited by Budapest, 21 October 2010 - 11:06 PM.
Moved from XP ~BP


BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:07:19 AM

Posted 31 October 2010 - 12:02 AM

Hello dcchitown853 ,

Posted Image

Sorry for the delay. :( If you still need help, please let me know :)

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:07:19 AM

Posted 07 November 2010 - 12:09 PM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users