Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected by Expiro, almost infecting all of my program files


  • This topic is locked This topic is locked
5 replies to this topic

#1 saiyun

saiyun

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:06:05 PM

Posted 11 February 2013 - 11:26 AM

I started getting virus detection from my AVG scanner about a Win32/Expiro infection starting today. I try to remove by AVG but it seem to infect more files. So I downloaded Kaspersky virus remove tool but it didn't remove the virus either. I even try using the virus removal tool in Safe mode but everytime I start my computer Expiro detection will appear. My computer seem 50% slower after I am infected with this Expiro virus. It also seem to really mess up some of my program. Please help me get rid of this virus. Many Thanks!!!!
 
 
DDS (Ver_2012-11-20.01) - NTFS_x86 
Internet Explorer:   BrowserJavaVersion: 10.7.2
Run by Brian at 0:18:31 on 2013-02-12
Microsoft Windows 7 Ultimate   6.1.7600.0.950.852.1033.18.3579.2313 [GMT 8:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVG\AVG2013\avgwdsvc.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Windows\System32\vds.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\System32\wscript.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\RealTemp\RealTemp.exe
C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files\Common Files\ComObjects\update.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Brian\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k Akamai
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://hk.yahoo.com/
BHO: {06433BFE-4946-4E89-823D-CD359C81CD06} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {481EE3EC-C026-4F9A-BA22-FD07654ADFC0} - <orphaned>
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [Google Update] "c:\users\brian\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [MSIAfterburner] "c:\program files\msi afterburner\MSIAfterburnerWrapper.exe" /s
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [TaskMngr] wscript.exe "c:\program files\common files\comobjects\data.js"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AVG_UI] "c:\program files\avg\avg2013\avgui.exe" /TRAYONLY
StartupFolder: c:\users\brian\appdata\roaming\micros~1\windows\startm~1\programs\startup\realte~1.lnk - c:\realtemp\RealTemp.exe
StartupFolder: c:\users\brian\appdata\roaming\micros~1\windows\startm~1\programs\startup\sticky~1.lnk - c:\st\StickyNotes.exe
StartupFolder: c:\users\brian\appdata\roaming\micros~1\windows\startm~1\programs\startup\_uninst_.lnk - c:\users\brian\appdata\local\temp\_uninst_.bat
StartupFolder: c:\users\brian\appdata\roaming\micros~1\windows\startm~1\programs\startup\_unins~1.lnk - c:\users\brian\appdata\local\temp\_uninst_72936508.bat
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
Trusted Zone: hkjc.com
Trusted Zone: hkjc.com
Trusted Zone: hongkongjockeyclub.com
Trusted Zone: hongkongjockeyclub.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: NameServer = 192.168.8.1
TCP: Interfaces\{01DBAE16-7148-42BA-B003-FFC5D8F71A06} : DHCPNameServer = 192.168.8.1
TCP: Interfaces\{3C08251A-5A0D-42F6-A3C8-E3089A83B5DA} : NameServer = 203.198.23.208 218.102.32.208
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - 
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [2012-10-15 55776]
R0 Avglogx;AVG Logging Driver;c:\windows\system32\drivers\avglogx.sys [2012-9-21 177376]
R0 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2012-11-15 94048]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2012-9-14 35552]
R1 AppleCharger;AppleCharger;c:\windows\system32\drivers\AppleCharger.sys [2010-6-22 18472]
R1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [2012-10-22 179936]
R1 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [2012-9-21 19936]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2012-10-2 159712]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-7-14 20992]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2013\avgwdsvc.exe [2012-10-22 196664]
R2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [2010-6-23 20968]
R2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files\common files\intuit\update service v4\IntuitUpdateService.exe [2011-8-25 13672]
R2 UNS;Intel® Management & Security Application User Notification Service;c:\program files\intel\intel® management engine components\uns\UNS.exe [2010-6-22 2320920]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2010-6-22 233472]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\realtemp\WinRing0.sys [2010-6-23 14416]
RUnknown 48663686;48663686; [x]
RUnknown 7144267drv;7144267drv; [x]
S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\adobe\photoshop elements 7.0\photoshopelementsfileagent.exe --> c:\program files\adobe\photoshop elements 7.0\PhotoshopElementsFileAgent.exe [?]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2013\avgidsagent.exe [2012-11-15 5814904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe --> c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [?]
S2 HTCMonitorService;HTCMonitorService;"c:\program files\htc\htc sync manager\hsmserviceentry.exe" --> c:\program files\htc\htc sync manager\HSMServiceEntry.exe [?]
S2 PassThru Service;Internet Pass-Through Service;c:\program files\htc\internet pass-through\passthrusvr.exe --> c:\program files\htc\internet pass-through\PassThruSvr.exe [?]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-1-8 161536]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 etdrv;etdrv;c:\windows\etdrv.sys [2010-6-22 17488]
S3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [2010-6-22 24944]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [2009-10-26 25088]
S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [2010-6-23 23040]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2011-5-29 121192]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2011-5-29 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2011-5-29 136680]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [2011-5-29 114152]
.
=============== Created Last 30 ================
.
2013-02-11 15:49:50    316928    -c--a-w-    c:\windows\system32\spoolsv.exe
2013-02-11 15:49:38    452608    -c--a-w-    c:\windows\system32\vds.exe
2013-02-11 15:47:29    --------    dc----w-    c:\programdata\Kaspersky Lab
2013-02-11 15:39:52    --------    dc----w-    c:\users\brian\appdata\roaming\AVG2013
2013-02-11 09:49:20    --------    dc----w-    c:\users\brian\appdata\roaming\TuneUp Software
2013-02-11 09:48:00    --------    dc----w-    c:\programdata\AVG2013
2013-02-11 09:35:59    --------    dc----w-    c:\users\brian\appdata\local\MFAData
2013-02-11 09:35:59    --------    dc----w-    c:\users\brian\appdata\local\Avg2013
2013-02-11 08:47:10    35840    -c--a-w-    c:\windows\system32\UI0Detect.exe
2013-02-11 08:04:27    --------    dc----w-    c:\program files\ESET
2013-02-11 07:41:32    --------    dc----w-    c:\users\brian\appdata\roaming\DriverCure
2013-02-11 07:41:31    --------    dc----w-    c:\users\brian\appdata\roaming\SpeedyPC Software
2013-02-11 07:41:09    --------    dc----w-    c:\programdata\SpeedyPC Software
2013-02-07 14:13:45    --------    dc----r-    c:\program files\Skype
2013-02-07 14:07:55    --------    dc----w-    c:\users\brian\appdata\local\{68155F49-F14B-40FE-86FE-1EA107474A80}
2013-02-05 15:55:42    --------    dc----w-    c:\users\brian\appdata\local\{4CA92FAC-853D-44A8-9321-A79C842166D1}
2013-02-02 01:35:37    --------    dc----w-    c:\users\brian\appdata\local\{BCE87AF5-320E-4911-B13C-4F894BCF3941}
2013-01-27 14:38:16    --------    dc----w-    c:\users\brian\appdata\local\{E66198EE-39B8-492F-A3A0-4F9A3D8FBC54}
2013-01-24 14:45:51    --------    dc----w-    c:\users\brian\appdata\local\{CAB4829B-8ADA-4F88-A8BD-7AF1881C886D}
2013-01-23 16:00:00    --------    dc----w-    c:\program files\Boilsoft
2013-01-22 16:08:46    --------    dc----w-    c:\users\brian\appdata\local\{05603AE9-3D96-4250-9AF0-1AFBF294183F}
2013-01-19 17:24:59    94208    -c--a-w-    c:\program files\mozilla firefox\plugins\nprpjplug.dll
2013-01-19 17:24:59    144984    -c--a-w-    c:\program files\mozilla firefox\plugins\nppl3260.dll
2013-01-19 17:24:57    --------    dc----w-    c:\users\brian\appdata\local\Real
2013-01-19 04:27:11    --------    dc----w-    c:\users\brian\appdata\local\{B2F13E85-DB4E-4F0F-A628-EC650399A222}
2013-01-18 18:03:45    --------    dc----w-    c:\users\brian\appdata\local\Programs
2013-01-17 14:15:29    --------    dc----w-    c:\users\brian\appdata\local\{C99443A4-B2F3-48CC-AA85-BF6256CB7A44}
.
==================== Find3M  ====================
.
2013-02-11 16:07:24    73216    -c--a-w-    c:\windows\system32\msiexec.exe
2013-02-11 16:07:24    59392    -c--a-w-    c:\windows\system32\alg.exe
2013-02-11 16:07:24    3179520    -c--a-w-    c:\windows\system32\sppsvc.exe
2013-02-11 16:07:24    134144    -c--a-w-    c:\windows\system32\msdtc.exe
2013-02-11 14:47:17    503808    ----a-w-    c:\windows\system32\msinfo32.exe
2013-02-09 10:29:09    74096    -c--a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
2013-02-09 10:29:09    697712    -c--a-w-    c:\windows\system32\FlashPlayerApp.exe
2012-12-16 15:48:50    5    -c--a-w-    c:\windows\system32\lMMLDeleteUserData42107612FX.tmp
2012-12-14 08:49:28    21104    -c--a-w-    c:\windows\system32\drivers\mbam.sys
.
============= FINISH:  0:18:49.48 ===============


BC AdBot (Login to Remove)

 


#2 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,505 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:09:05 PM

Posted 11 February 2013 - 11:07 PM

Hello saiyun,

  • Welcome to Bleeping Computer.
  • My name is fireman4it and I will be helping you with your Malware problem.

    Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools.
      
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing.
      
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean".
  • In the upper right hand corner of the topic you will see a button called Watch Topic.I suggest you click it and select Immediate E-Mail notification and click on Proceed. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

      
  • Finally, please reply using the ADD REPLY  button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply, unless they do not fit into the post.
  •   I will be analyzing your log. I will get back to you with instructions.

 

 

1.

IMPORTANT NOTE: One or more of the identified infections is a backdoor Trojan. Backdoor Trojans, Botnets, and IRCBots are very dangerous because they compromise system integrity by making changes that allow it to be used by the attacker for malicious purposes. They can disable your anti-virus and security tools to prevent detection and removal. Remote attackers use backdoors as a means of accessing and taking control of a computer that bypasses security mechanisms. This type of exploit allows them to steal sensitive information like passwords, personal and financial data which is then sent back to the hacker. Read Danger: Remote Access Trojans.

You should disconnect the computer from the Internet and from any networked computers until it is cleaned. If your computer was used for online banking, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for banking, email, eBay, paypal and any online activities which require a username and password. You should consider them to be compromised and change passwords from a clean computer, not the infected one. If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified immediately of the possible security breach. Failure to notify your financial institution and local law enforcement can result in refusal to reimburse funds lost due to fraud or similar criminal activity. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again.

Although the infection has been identified and may be removed, your machine has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume the computer is secure even if the malware appears to have been removed. In some instances an infection may have caused so much damage to your system that it cannot be successfully cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them. Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read:


Whenever a system has been compromised by a backdoor payload, it is impossible to know if or how much the backdoor has been used to affect your system...There are only a few ways to return a compromised system to a confident security configuration. These include:
• Reimaging the system
• Restoring the entire system using a full system backup from before the backdoor infection
• Reformatting and reinstalling the system

Backdoors and What They Mean to You

This is what Jesper M. Johansson at Microsoft TechNet has to say: Help: I Got Hacked. Now What Do I Do?.[quote]The only way to clean a compromised system is to flatten and rebuild. That’s right. If you have a system that has been completely compromised, the only thing you can do is to flatten the system (reformat the system disk) and rebuild it from scratch (reinstall Windows and your applications).

 

Because your computer was compromised please read:

 

 

2.

Please download the Expiro Removal tool from AVG . Please follow the direction from running the tool.

http://free.avg.com/us-en/remove-win32-expiro

 

Things to include in your next reply::

How is your machine running now?


" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#3 saiyun

saiyun
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:06:05 PM

Posted 12 February 2013 - 12:56 AM

Hi Fireman4it, thanks for your reply.

 

I really hope to use full reformat and reinstall OS as my last resort as I hope i can clean the infection. I downloaded and ran Expiro Removal tool from AVG and the weird thing is there is 0 files found that is infected. But when I still get Exipro infection warning from my AVG resident shield. My computer seem to be running normally except having the infection warning every so often. Also some of my program is not behaving normally after being infected with virus so I have uninstall those problem software.



#4 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,505 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:09:05 PM

Posted 12 February 2013 - 10:37 PM

Hello,

 

Can you please tell me which file AVG is saying is infected.


" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#5 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,505 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:09:05 PM

Posted 15 February 2013 - 12:54 PM

Hello.

Are you still there?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 2-3 days the topic will need to be closed.

Thanks for understanding smile.png

With Regards,
fireman4it

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#6 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,505 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:09:05 PM

Posted 20 February 2013 - 11:04 AM

There has been no reply in 5 days therefore this topic will be closed, If you need this topic reopened contact Myself or a Moderator.


Edited by fireman4it, 20 February 2013 - 11:05 AM.

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users