Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Fake MBR, invisible webpages opened


  • This topic is locked This topic is locked
3 replies to this topic

#1 7Warpig7

7Warpig7

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:05:56 AM

Posted 14 November 2011 - 01:27 PM

I cannot use DDS (goes for a while then frezes system), Tdsskiller (Nothing happens when clicked, even when renamed), GMER (getting Loaddriver error at start, program goes after that but I am not sure if it's doing anything), Combofix except using /nombr, even then it takes two hours to get through where it normaly takes 10 minutes.


Symptoms are that when using MBRcheck I get fake MBR message. I get ghost webpages opening up that I cannot see but can hear if they have sound. I was having hijacked searches but that seems to be gone after I deleted a bunch of temp files. I tried replacing MBR using both MBRcheck and using System Recovery booting from a CD, both indicate success but rerunning the MBRcheck still indicates a fake MBR.

MBRcheck and the Combofix reports are below:


MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000003d

Kernel Drivers (total 128):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E4000 \WINDOWS\system32\hal.dll
0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
0xB9F79000 ACPI.sys
0xBA5AA000 \WINDOWS\System32\DRIVERS\WMILIB.SYS
0xB9F68000 pci.sys
0xBA0A8000 isapnp.sys
0xBA0B8000 ohci1394.sys
0xBA0C8000 \WINDOWS\System32\DRIVERS\1394BUS.SYS
0xBA670000 pciide.sys
0xBA328000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
0xBA0D8000 MountMgr.sys
0xB9F49000 ftdisk.sys
0xBA330000 PartMgr.sys
0xBA0E8000 VolSnap.sys
0xB9F31000 atapi.sys
0xB9EF1000 mv61xx.sys
0xB9ED9000 \WINDOWS\System32\DRIVERS\SCSIPORT.SYS
0xBA0F8000 disk.sys
0xBA108000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
0xB9EB9000 fltmgr.sys
0xB9EA7000 sr.sys
0xB9E90000 KSecDD.sys
0xB9E7D000 WudfPf.sys
0xB9DF0000 Ntfs.sys
0xB9DC3000 NDIS.sys
0xB9DA9000 Mup.sys
0xBA248000 \SystemRoot\system32\DRIVERS\ATITool.sys
0xBA258000 \SystemRoot\System32\DRIVERS\intelppm.sys
0xB91E8000 \SystemRoot\System32\DRIVERS\ati2mtag.sys
0xB4B5A000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
0xB4B35000 \SystemRoot\System32\DRIVERS\HDAudBus.sys
0xBA490000 \SystemRoot\System32\DRIVERS\usbuhci.sys
0xB4B11000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
0xBA450000 \SystemRoot\System32\DRIVERS\usbehci.sys
0xBA198000 \SystemRoot\System32\DRIVERS\imapi.sys
0xBA1A8000 \SystemRoot\System32\DRIVERS\cdrom.sys
0xBA1B8000 \SystemRoot\System32\DRIVERS\redbook.sys
0xB4AEE000 \SystemRoot\System32\DRIVERS\ks.sys
0xB4AA8000 \SystemRoot\System32\DRIVERS\yk51x86.sys
0xBA1C8000 \SystemRoot\System32\DRIVERS\nic1394.sys
0xBA498000 \SystemRoot\System32\DRIVERS\fdc.sys
0xBA5F4000 \SystemRoot\System32\DRIVERS\ASACPI.sys
0xBA1D8000 \SystemRoot\System32\DRIVERS\serial.sys
0xBA57C000 \SystemRoot\System32\DRIVERS\serenum.sys
0xBA1E8000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xB8383000 \SystemRoot\System32\DRIVERS\kbdclass.sys
0xBA6D9000 \SystemRoot\System32\DRIVERS\audstub.sys
0xB978C000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
0xBA56C000 \SystemRoot\System32\DRIVERS\ndistapi.sys
0xB4A91000 \SystemRoot\System32\DRIVERS\ndiswan.sys
0xB979C000 \SystemRoot\System32\DRIVERS\raspppoe.sys
0xB971C000 \SystemRoot\System32\DRIVERS\raspptp.sys
0xB837B000 \SystemRoot\System32\DRIVERS\TDI.SYS
0xB4A80000 \SystemRoot\System32\DRIVERS\psched.sys
0xBA188000 \SystemRoot\System32\DRIVERS\msgpc.sys
0xBA478000 \SystemRoot\System32\DRIVERS\ptilink.sys
0xB8373000 \SystemRoot\System32\DRIVERS\raspti.sys
0xB97AC000 \SystemRoot\System32\DRIVERS\termdd.sys
0xB836B000 \SystemRoot\System32\DRIVERS\mouclass.sys
0xB4A63000 \SystemRoot\system32\DRIVERS\mcdbus.sys
0xBA5F6000 \SystemRoot\System32\DRIVERS\swenum.sys
0xB4A05000 \SystemRoot\System32\DRIVERS\update.sys
0xBA580000 \SystemRoot\System32\DRIVERS\mssmbios.sys
0xB976C000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xA89C7000 \SystemRoot\system32\drivers\AtiHdmi.sys
0xA89A3000 \SystemRoot\system32\drivers\portcls.sys
0xBA208000 \SystemRoot\system32\drivers\drmk.sys
0xBA218000 \SystemRoot\System32\DRIVERS\usbhub.sys
0xBA5FA000 \SystemRoot\System32\DRIVERS\USBD.SYS
0xA894D000 \SystemRoot\system32\drivers\ADIHdAud.sys
0xA8935000 \SystemRoot\system32\drivers\AEAudio.sys
0xA88D5000 \SystemRoot\system32\drivers\Senfilt.sys
0xBA460000 \SystemRoot\System32\DRIVERS\flpydisk.sys
0xBA3A0000 \??\C:\WINDOWS\system32\SAVRKBootTasks.sys
0xBA5FC000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xBA751000 \SystemRoot\System32\Drivers\Null.SYS
0xBA5FE000 \SystemRoot\System32\Drivers\Beep.SYS
0xBA488000 \SystemRoot\System32\DRIVERS\HIDPARSE.SYS
0xBA468000 \SystemRoot\System32\drivers\vga.sys
0xBA600000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xBA602000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xB833B000 \SystemRoot\System32\Drivers\Msfs.SYS
0xB834B000 \SystemRoot\System32\Drivers\Npfs.SYS
0xB767D000 \SystemRoot\System32\DRIVERS\rasacd.sys
0xA88A2000 \SystemRoot\System32\DRIVERS\ipsec.sys
0xA8849000 \SystemRoot\System32\DRIVERS\tcpip.sys
0xA8821000 \SystemRoot\System32\DRIVERS\netbt.sys
0xA87FB000 \SystemRoot\System32\DRIVERS\ipnat.sys
0xB4BFE000 \SystemRoot\System32\DRIVERS\wanarp.sys
0xA87D9000 \SystemRoot\System32\drivers\afd.sys
0xB4BEE000 \SystemRoot\System32\DRIVERS\netbios.sys
0xB4BCE000 \SystemRoot\System32\DRIVERS\arp1394.sys
0xA87AE000 \SystemRoot\System32\DRIVERS\rdbss.sys
0xA873E000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
0xB4BBE000 \SystemRoot\System32\Drivers\Fips.SYS
0xBA604000 \SystemRoot\system32\drivers\AsIO.sys
0xBA370000 \SystemRoot\System32\DRIVERS\usbccgp.sys
0xB9D75000 \SystemRoot\system32\DRIVERS\usbscan.sys
0xBA458000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xBA4A8000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0xB4B8E000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xB4B7E000 \SystemRoot\System32\Drivers\LHidUsb.Sys
0xB4B6E000 \SystemRoot\System32\Drivers\HIDCLASS.SYS
0xBA408000 \SystemRoot\system32\DRIVERS\LHidFlt2.Sys
0xB9D69000 \SystemRoot\System32\DRIVERS\mouhid.sys
0xBA2C8000 \SystemRoot\system32\DRIVERS\LMouFlt2.Sys
0xA86FE000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xBA60A000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xB8E25000 \SystemRoot\System32\drivers\Dxapi.sys
0xBA3A8000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xB6A02000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\ati2dvag.dll
0xBF063000 \SystemRoot\System32\ati2cqag.dll
0xBF0F0000 \SystemRoot\System32\atikvmag.dll
0xBF163000 \SystemRoot\System32\atiok3x2.dll
0xBF1AD000 \SystemRoot\System32\ati3duag.dll
0xBF59B000 \SystemRoot\System32\ativvaxx.dll
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xA51C4000 \SystemRoot\system32\drivers\wdmaud.sys
0xA5339000 \SystemRoot\system32\drivers\sysaudio.sys
0xA4746000 \SystemRoot\System32\DRIVERS\srv.sys
0xA4525000 \SystemRoot\System32\Drivers\HTTP.sys
0xA42F2000
0x7C900000 \WINDOWS\system32\ntdll.dll

Processes (total 25):
0 System Idle Process
4 System
612 C:\WINDOWS\system32\smss.exe
668 csrss.exe
704 C:\WINDOWS\system32\winlogon.exe
748 C:\WINDOWS\system32\services.exe
760 C:\WINDOWS\system32\lsass.exe
928 C:\WINDOWS\system32\svchost.exe
996 svchost.exe
1092 C:\WINDOWS\system32\svchost.exe
1132 C:\WINDOWS\system32\svchost.exe
1176 svchost.exe
1312 svchost.exe
1364 C:\WINDOWS\system32\spoolsv.exe
1724 C:\WINDOWS\explorer.exe
1852 C:\Program Files\ASUS\EPU-6 Engine\SixEngine.exe
1860 C:\Program Files\Analog Devices\Core\smax4pnp.exe
1888 C:\WINDOWS\system32\ctfmon.exe
1908 C:\Logitech\MouseWare\system\EM_EXEC.EXE
244 C:\WINDOWS\system32\svchost.exe
644 C:\WINDOWS\system32\wuauclt.exe
1660 alg.exe
1416 C:\WINDOWS\system32\wscntfy.exe
1876 C:\Program Files\Internet Explorer\iexplore.exe
2244 C:\Documents and Settings\Owner\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

PhysicalDrive0 Model Number: WDCWD5000AAKS-07A7B0, Rev: 01.03B01

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 MBR Code Faked!
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!



ComboFix 11-11-14.01 - Owner 11/14/2011 10:53:02.8.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.2897 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\mooo.exe
Command switches used :: /nombr
AV: Avira AntiVir PersonalEdition *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\RECYCLER(2)
c:\recycler(2)\S-1-5-21-527237240-764733703-839522115-1003(2)\INFO2
.
.
((((((((((((((((((((((((( Files Created from 2011-10-14 to 2011-11-14 )))))))))))))))))))))))))))))))
.
.
2011-11-14 01:39 . 2011-11-14 01:39 -------- d-----w- c:\windows\system32\wbem\Repository
2011-11-14 00:54 . 2011-11-14 00:54 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2011-11-14 00:54 . 2011-11-14 00:54 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2011-11-14 00:53 . 2011-11-14 00:53 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-31 21:00 . 2010-04-18 00:46 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-28 04:39 . 2011-06-09 01:49 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
((((((((((((((((((((((((((((( SnapShot_2011-09-16_01.43.10 )))))))))))))))))))))))))))))))))))))))))
.
- 2003-03-31 12:00 . 2011-03-23 11:13 68708 c:\windows\system32\perfc009.dat
+ 2003-03-31 12:00 . 2011-11-14 01:42 68708 c:\windows\system32\perfc009.dat
+ 2003-03-31 12:00 . 2011-11-14 01:42 436514 c:\windows\system32\perfh009.dat
- 2003-03-31 12:00 . 2011-03-23 11:13 436514 c:\windows\system32\perfh009.dat
+ 2011-10-20 02:27 . 2011-10-20 02:27 503808 c:\windows\system32\config\systemprofile\ntuser.dat
+ 2011-11-14 01:37 . 2011-11-14 01:39 1429808 c:\windows\system32\Restore\rstrlog.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Six Engine"="c:\program files\ASUS\EPU-6 Engine\SixEngine.exe" [2008-06-03 5964800]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-03-17 1040384]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 19968]
"avgnt"="c:\avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-08 04:02 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICustomerCare]
2010-05-04 21:05 311296 ----a-r- c:\program files\ATI\ATICustomerCare\ATICustomerCare.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch PC Probe II]
2008-04-24 18:11 2137088 ----a-w- c:\program files\ASUS\PC Probe II\Probe2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2010-11-26 02:32 98304 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"WebClient"=2 (0x2)
"WZCSVC"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\World of Warcraft\\Launcher.exe"=
.
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [6/23/2008 5:21 PM 150568]
R1 SAVRKBootTasks;Boot Tasks Driver;c:\windows\system32\SAVRKBootTasks.sys [9/3/2011 7:53 AM 18816]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\1.tmp --> c:\windows\system32\1.tmp [?]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = <local>
TCP: DhcpNameServer = 192.168.15.1
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Common Files\Java\Java Update\jusched.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-14 11:22
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\1.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,5b,81,b9,ab,d2,03,cf,47,83,93,e0,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,5b,81,b9,ab,d2,03,cf,47,83,93,e0,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2011-11-14 11:36:28
ComboFix-quarantined-files.txt 2011-11-14 16:36
ComboFix2.txt 2011-11-12 01:12
ComboFix3.txt 2011-11-11 02:51
ComboFix4.txt 2011-10-21 02:43
ComboFix5.txt 2011-11-14 01:20
.
Pre-Run: 358,176,657,408 bytes free
Post-Run: 358,362,865,664 bytes free
.
- - End Of File - - 1F0704F919E163F3508009B7C6C1AB3B

Edited by 7Warpig7, 14 November 2011 - 01:29 PM.


BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:06:56 AM

Posted 18 November 2011 - 10:23 AM

Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.

  • Do not run any other tool untill instructed to do so!
  • Please Do not Attach logs or put in code boxes.
  • Tell me about any problems that have occurred during the fix.
  • Tell me of any other symptoms you may be having as these can help also.
  • Do not run anything while running a fix.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.


The first thing I would like you to do is run this for me - http://download.bleepingcomputer.com/grinler/unhide.exe after it is complete restart the computer and continue with these steps


Download and run OTL

Download OTL by Old Timer and save it to your Desktop.
  • Double click on OTL.exe to run it.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Under the Custom Scan box paste this in

    %TEMP%\smtmp\*.* /s

  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened and the that I need posted back here
    • Extra.txt <-- Will be minimized - save this one on your desktop in case I ask for it later
  • Please post the contents of OTListIt.txt in your next reply.


information and logs:

  • In your next post I need the following

  • .logs from OTL
  • let me know of any problems you may have had

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:06:56 AM

Posted 21 November 2011 - 02:00 AM

Hello

48 Hour bump

It has been more than 48 hours since my last post.

  • do you still need help with this?
  • do you need more time?
  • are you having problems following my instructions?
  • if after 48hrs you have not replied to this thread then it will have to be closed!

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:06:56 AM

Posted 24 November 2011 - 09:02 PM

Due to the lack of feedback, this topic is now closed.In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users