Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijack This Log


  • This topic is locked This topic is locked
11 replies to this topic

#1 Bigjones1014

Bigjones1014

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:35 AM

Posted 01 January 2006 - 10:30 PM

Hello,
I've tried running Ad-aware and Spybot, but I cant get rid of a browser hijacker and popups.
Here is my Hijack This log



Logfile of HijackThis v1.99.1
Scan saved at 9:22:25 PM, on 1/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\nvctrl.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ejxqi.dll/sp.html#53142%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ejxqi.dll/sp.html#53142%resultposition.net
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - Default URLSearchHook is missing
O2 - BHO: HomepageBHO - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpF0C3.tmp
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {130F2761-BD57-755B-E945-7F5C1CDC87A3} - http://85.255.113.214/1/gdnUS2332.exe
O16 - DPF: {37D17ADA-D2CD-252B-C969-7CCC0D4F98B5} - http://85.255.113.214/1/gdnUS2332.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.1.74.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcSandraSrv.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe (file missing)



Any help you could offer would be greatliy appreciated.
Thank you,

Bigjones1014

BC AdBot (Login to Remove)

 


#2 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:12:35 PM

Posted 06 January 2006 - 03:42 PM

Hi,

The forums are really busy, that explains why logs get behind. We start with the oldest logs first. If you still need some help, please start with posting a new hijackthislog in this thread. Don't start with a new thread.
Then I'll take a look. :thumbsup:
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 Bigjones1014

Bigjones1014
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:35 AM

Posted 07 January 2006 - 01:20 AM

Logfile of HijackThis v1.99.1
Scan saved at 12:19:41 AM, on 1/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.1.74.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcSandraSrv.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe (file missing)



Thanks for the response

#4 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:12:35 PM

Posted 07 January 2006 - 01:41 AM

Hi, I can't see anything suspicious anymore.
Looks like you already solved the problem. Are you still having problems now?
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 Bigjones1014

Bigjones1014
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:35 AM

Posted 07 January 2006 - 04:45 PM

Im still getting popups though

#6 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:12:35 PM

Posted 07 January 2006 - 05:49 PM

Ok, what popups are you still getting? What have you been using previously? Because your second log doesn't show the bad entries in it anymore.

Anyway, you were dealing with a desktop hijacker before and I am not sure if everything related is gone, although it doesn't show anything anymore in your log.
So perform next..

* Download smitRem and save the file to your desktop.
Doubleclick it and choose install. This will create a new folder on your desktop with the name smitrem.
* Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Your desktop and taskbar will disappear. This is normal.
Wait for the tool to complete and disk cleanup to finish.

Then, Please perform this online scan: Kaspersky Webscan
1. Read the Requirements and Privacy statement, then select "Accept"
2. A dialogue box will appearing asking "Do you want to install this software?" Name: kavwebscan_unicode.cab
3. Select "Install" to download the ActiveX controls that allows ActiveScan to run.
4. If running MSAS beta you may receive an alert that an IE ActiveX program requires your approval. Click "Allow"
5. When the download is complete it will say ready, click "Next"
6. Click "Scan Settings" and check the option to use the EXTENDED DATABASE, then click "OK"
7. Select a target to scan: Click on "My Computer"
8. When the scan is complete choose to save the results as "Save as Text"
9. Post the Kaspersky scan results in your next reply along with the contents of smitfiles.txt which is present on your Homedrive (C:\ in most cases) by using Add Reply.

It could be possible, after reboot that your system is using the windows classic theme again.
To restore this and set it back to XP-theme, rightclick on your desktop > properties > tab Appearances and choose Windows XP style again under windows and buttons.
Click apply and OK.

AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 Bigjones1014

Bigjones1014
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:35 AM

Posted 08 January 2006 - 04:34 PM

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Sunday, January 08, 2006 15:32:19
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 8/01/2006
Kaspersky Anti-Virus database records: 169968
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\

Scan Statistics:
Total number of scanned objects: 66262
Number of viruses found: 29
Number of infected objects: 70
Number of suspicious objects: 0
Duration of the scan process: 3339 sec

Infected Object Name - Virus Name
C:\HJT\backups\backup-20060105-000458-143.dll Infected: Trojan-Downloader.Win32.Zlob.dx
C:\HJT\backups\backup-20060106-190957-235.dll Infected: Trojan-Downloader.Win32.Zlob.dz
C:\Program Files\Common Files\Download\mc-58-12-0000140.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.l
C:\Program Files\Common Files\InetGet\mc-58-12-0000140.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.h
C:\Program Files\Common Files\Windows\mc-58-12-0000140.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.h
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\146111EF Infected: P2P-Worm.Win32.Alcan.a
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\15CB4660 Infected: P2P-Worm.Win32.Alcan.a
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1AEB1304 Infected: P2P-Worm.Win32.Alcan.a
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1B9C0FFA Infected: Backdoor.Win32.Rbot.pd
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\1D0643AF.exe Infected: P2P-Worm.Win32.Krepper.c
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\22215ECD Infected: P2P-Worm.Win32.Alcan.a
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\26FC5AB9.exe Infected: P2P-Worm.Win32.Krepper.c
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\27F87BA4.exe Infected: P2P-Worm.Win32.Krepper.c
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\28B828D0.exe Infected: Virus.Win32.Parite.b
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2D293BED.exe Infected: P2P-Worm.Win32.Krepper.c
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2D6D2DA2.exe Infected: P2P-Worm.Win32.Krepper.c
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2DA82161.exe Infected: P2P-Worm.Win32.Krepper.c
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2DBC1D4C.exe Infected: Virus.Win32.Parite.b
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2DED1316.exe Infected: Virus.Win32.Parite.b
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2E3B02BF.exe Infected: Virus.Win32.Parite.b
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\301125D1.exe Infected: P2P-Worm.Win32.Krepper.c
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\36EB6DDA Infected: Exploit.Java.ByteVerify
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4C5164AB Infected: Trojan.Java.ClassLoader.u
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\57D6193D Infected: Email-Worm.VBS.Gedza
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5F5E44AD.exe Infected: Virus.Win32.Parite.b
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5F99386C.exe Infected: Virus.Win32.Parite.b
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5FE47E19.exe Infected: Virus.Win32.Parite.b
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\648D32C1 Infected: Trojan.Java.ClassLoader.u
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP555\A0115818.tlb Infected: Trojan-Downloader.Win32.Zlob.dx
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115832.exe Infected: Trojan-Downloader.Win32.Small.bqq
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115833.exe Infected: Trojan-Downloader.Win32.Small.bqq
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115834.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.j
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115835.dll/Catcher.dll Infected: not-a-virus:AdWare.Win32.Maxifiles.s
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115835.dll/gui.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.a
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115835.dll Infected: not-a-virus:AdWare.Win32.Maxifiles.a
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115836.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.h
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115837.exe Infected: not-a-virus:AdWare.Win32.Maxifiles.a
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115838.exe Infected: P2P-Worm.Win32.Wupeer.a
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115840.exe Infected: Email-Worm.Win32.VB.an
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115841.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115842.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115843.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115844.old:iejxq:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115845.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115846.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115847.exe Infected: Trojan-Downloader.Win32.Small.vu
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115848.exe Infected: Trojan-Downloader.Win32.Zlob.bu
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115849.dll Infected: Trojan.Win32.Small.ev
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115850.exe Infected: Backdoor.Win32.Rbot.adf
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115851.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115852.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115853.exe Infected: Trojan-Clicker.Win32.Spywad.n
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115854.exe Infected: Backdoor.Win32.Rbot.adf
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115860.dll Infected: not-virus:Hoax.Win32.Renos.ak
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115865.tlb Infected: Trojan-Downloader.Win32.Zlob.dx
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115871.exe Infected: Trojan-Downloader.Win32.Zlob.dx
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP559\A0115889.exe Infected: Trojan-Downloader.Win32.Zlob.dz
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP559\A0115890.exe Infected: Trojan-Downloader.Win32.Zlob.ea
C:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP559\A0115891.tlb Infected: Trojan-Downloader.Win32.Zlob.dz
C:\WINDOWS\d3dx.dat:hnevmj:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\d3dx.dat:nxshmx:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\KB887742.log:uyrvpc:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\Soap Bubbles.bmp:afbdks:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\system32\ld687F.tmp Infected: Trojan-Downloader.Win32.Zlob.dk
C:\WINDOWS\system32\mscornet.exe Infected: Trojan-Downloader.Win32.Zlob.dm
C:\WINDOWS\{BA5575ED-7742-4E30-B990-D8B8461F5898}.dat:dihhia:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\{BA5575ED-7742-4E30-B990-D8B8461F5898}.dat:khobgp:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\{BA5575ED-7742-4E30-B990-D8B8461F5898}.dat:sphniw:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\{BA5575ED-7742-4E30-B990-D8B8461F5898}.dat:vjrmck:$DATA Infected: Trojan-Downloader.Win32.Agent.td
D:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115855.exe Infected: P2P-Worm.Win32.Wupeer.a

Scan process completed.













smitRem © log file
version 2.8

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
The current date is: Sun 01/08/2006
The current time is: 14:18:11.57

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key

WinHound.com key present!



Running WinHound.com fix!



WinHound.com key was successfully removed! :thumbsup:




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SpyAxeFix © by noahdfear

spyaxe directory present

spyaxe uninstaller present

Starting spyaxe uninstaller

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Winhound uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~

SpyAxe


~~~ Shortcuts ~~~

Online Security Guide.url
Security Troubleshooting.url
Install.dat


~~~ Favorites ~~~

Antivirus Test Online.url


~~~ system32 folder ~~~

atmtd.dll._
svcp.csv
winsub.xml
1024 dir
msvol.tlb
ld****.tmp
mssearchnet.exe
ncompat.tlb
nvctrl.exe
mscornet.exe
hp***.tmp


~~~ Icons in System32 ~~~

ts.ico
ot.ico


~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1532 'explorer.exe'
Killing PID 1532 'explorer.exe'
Killing PID 1532 'explorer.exe'
Killing PID 1532 'explorer.exe'
Killing PID 1532 'explorer.exe'
Killing PID 1532 'explorer.exe'
Killing PID 1532 'explorer.exe'

Starting registry repairs

Deleting files


Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~

ld****.tmp
mssearchnet.exe
ncompat.tlb
nvctrl.exe
mscornet.exe
hp***.tmp


~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~



~~~ Miscellaneous Files/folders ~~~




~~~ Wininet.dll ~~~

CLEAN! :flowers:

#8 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:12:35 PM

Posted 08 January 2006 - 04:45 PM

Ok, I already see now..

We'll have to run the smitrem again, but this time in safe mode, because it won't get rid of the files in normal mode.

Strange your hijackthislog before didn't show any of them. Normally they must been present in the running processes.

Also, I see you are dealing with another infection as well which needs to go, so please perform my steps in the right order.

Looks like you're dealing with ADS as well.

Open Hijackthis, click config (bottom right)
choose 'misc tools'
choose 'Open ADS spy'
Make sure 'Ignore safe system info streams' are checked.
Click scan, select the entries being found and choose 'remove selected'

Then, Download Brute Force Uninstaller.
Unzip it to a folder of itís own (c:\BFU).
Read here how to unzip/extract properly:
http://metallica.geekstogo.com/xpcompressedexplanation.html
Start the Brute Force Uninstaller by doubleclicking BFU.exe

Next to the 'scriptfile to execute'-window you'll see a little icon as shown in next picture: Posted Image
When you click that icon, a little window will open that says: 'Please enter the full URL to the sript you want to execute'
In the field, copy and paste next URL:

http://downloads.subratam.org/BFUscripts/igetnetfreepod.BFU

Click Ok
Then click execute in Brute Force Uninstaller.

Wait for the complete script execution box to popup and press OK.
Press exit to terminate the BFU program.

Delete the Smitrem-folder and smitrem.exe present on your desktop and redownload it, because it has been updated a couple of hours ago.
The downloadlocation is the same.

Also update your Ewido. Don't run the scan yet.

Then boot in safe mode!
įTo get into the Safe mode as the computer is booting press and hold your "F8 Key". Use your arrow keys to move to "Safe Mode" and press your Enter key.

* Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

* Now open Ewido Security Suite
Click on scanner

* Click Complete System Scan and the scan will begin.
* During the scan it will prompt you to clean files, click OK
* When the scan is finished, look at the bottom of the screen and click the Save report button.
* Save the report to your desktop

* Close Ewido

* Go to start > control panel > Display properties > Desktop > Customize Desktop... > Web tab > uncheck and delete everything you find in there. (except for "My current home page")

* Reboot back into Windows.

Post a new HijackThis Log, the contents of smitfiles.txt which is present on your Homedrive (C:\ in most cases) and the Ewido Log by using Add Reply.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 Bigjones1014

Bigjones1014
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:35 AM

Posted 08 January 2006 - 09:54 PM

Logfile of HijackThis v1.99.1
Scan saved at 8:52:43 PM, on 1/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.1.74.cab
O16 - DPF: {7E547FA7-8D86-449D-4C14-450A7196383C} - http://85.255.113.214/1/gdnUS2332.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005\RpcSandraSrv.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe (file missing)



---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 8:41:54 PM, 1/8/2006
+ Report-Checksum: 4B90ADB1

+ Scan result:

C:\Documents and Settings\Eric\Cookies\eric@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Eric\Cookies\eric@cnn.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Eric\Cookies\eric@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Eric\Cookies\eric@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\HJT\backups\backup-20060105-000458-143.dll -> Downloader.Zlob.dx : Cleaned with backup
C:\HJT\backups\backup-20060106-190957-235.dll -> Downloader.Zlob.dx : Cleaned with backup
D:\System Volume Information\_restore{13A6698E-1A4C-473E-B451-F67EF06692C4}\RP556\A0115855.exe -> Worm.Wupeer.a : Cleaned with backup


::Report End


smitRem © log file
version 2.8

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
The current date is: Sun 01/08/2006
The current time is: 18:53:34.48

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~

ld****.tmp
mssearchnet.exe
ncompat.tlb
nvctrl.exe
mscornet.exe
hp***.tmp


~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1296 'explorer.exe'
Killing PID 1296 'explorer.exe'

Starting registry repairs

Deleting files


Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~



~~~ Miscellaneous Files/folders ~~~




~~~ Wininet.dll ~~~

CLEAN! :thumbsup:

#10 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:12:35 PM

Posted 09 January 2006 - 03:21 AM

Hello,

Check and fix next entry in hijackthis:

O16 - DPF: {7E547FA7-8D86-449D-4C14-450A7196383C} - http://85.255.113.214/1/gdnUS2332.exe

How are things running now?
Please visit windowsupdate asap to install the latest security patch to prevent you from wmf exploits you were dealing wth previously.

Perform a full scan with an updated Adaware SE and/or Spybot S&D to get rid of some leftovers if still present.
If you don't have those programs yet, you can find the downloadlocations in my sig.

To keep this clean in the future, I would suggest the following things:

Install Spywareblaster
SpywareBlaster doesn`t scan and clean for so-called spyware, but prevents it from being installed in the first place. It blocks the popular spyware ActiveX controls, and also prevents the installation of any of them via a webpage.

* Avoid illegal sites, because that's where most malware is present.
* Don't click on links inside popups.
* Don't click on links in spam messages claiming to offer anti-spyware software; because most of these so called removers ARE spyware.
* Download free software only from sites you know and trust. Because a lot of free software can bundle other software, including spyware.

Let your antispywarescanner(s) scan frequently and don't forget to update before.

And I do suggest you perform an online virusscan once in a while. (Housecall and/or Bitdefender). Because what one virusscanner can't find another one maybe can.
Also make sure that your virusscanner, the one that is installed on your system is always up to date!

Make sure your windows has the latest updates: http://windowsupdate.microsoft.com/

If you are having XP SP2, read here how to configure Security Features for Internet Explorer:
http://www.microsoft.com/technet/security/...xp/iesecxp.mspx

Also visit this Free Online Scanner for PC Health and Safety

More info on how to prevent malware you can also find here (By Tony Klein)
and here: http://wiki.castlecops.com/Malware_Prevent...nt_Re-infection

Happy surfing again! :thumbsup:
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#11 Bigjones1014

Bigjones1014
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:04:35 AM

Posted 11 January 2006 - 07:57 AM

That fixed it all.

Thank you very much for your help.


Bigjones1014

#12 miekiemoes

miekiemoes

    Malware Killer Dog


  • Malware Response Team
  • 19,420 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Belgium
  • Local time:12:35 PM

Posted 11 January 2006 - 08:11 AM

Glad I could help. :thumbsup:

Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! My computer is slow---My Blog---Follow me on Twitter.
My help is ALWAYS FREE, but if you want to donate to help me continue my fight against malware -- click here!
Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users