Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

MSN hijack, and mail bot and ...[RESOLVED]


  • This topic is locked This topic is locked

#1
solo-2450

solo-2450

    New Member

  • Member
  • Pip
  • 5 posts
I'm Very Very stressed out... I Finnaly found you guys out here... HELP!!!

Logfile of HijackThis v1.99.1
Scan saved at 6:44:16 PM, on 5/17/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\PROGRA~1\CA\ETRUST~1\ETRUST~2\ca.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Stop-the-Pop-Up\stopthepop.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\ctfmon.exe
D:\zipitpro\ZipItFast.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
D:\Program Files\AIM\aim.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
D:\Program Files\Easy\TV Capture\RemoteCtl.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
D:\Program Files\MagicDisc\MagicDisc.exe
C:\DOCUME~1\SETHST~1\LOCALS~1\Temp\ztv6\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/ht...x.cfm?p=16&m=43
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - D:\Program Files\Desktop Sidebar\sbhelp.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] D:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] D:\PROGRA~1\CA\ETRUST~1\ETRUST~2\ca.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [sureshotpopupkiller] "C:\Program Files\Stop-the-Pop-Up\stopthepop.exe" -minimized
O4 - HKLM\..\Run: [RAM Idle] D:\Program Files\Customizer XP\RAMIdle.exe
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitehod32.exe
O4 - HKLM\..\RunServices: [strmsnmsgr] msnmsgrs.exe
O4 - HKLM\..\RunServices: [The Intranet] intranet.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
O4 - HKCU\..\RunServices: [The Intranet] intranet.exe
O4 - Startup: MagicDisc.lnk = D:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: TV Capture Remote Control.lnk = D:\Program Files\Easy\TV Capture\RemoteCtl.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe

If you e-mail I might not get it if you send it to the listed email
AVG stopped the bot from actually sending anything out. But I get all the returned mail in my INbox.
The elitebar32.exe or elite... whatever it's called... I deleted so now I get an error pop-up when it tries to run.

I locked down every non-essencial prog. from accessing the internet.

don't know if this will be of any use...
StartupList report, 5/17/2005, 7:48:19 PM
StartupList version: 1.52
Started from : C:\Documents and Settings\Seth Stevens\Desktop\StartupList.EXE
Detected: Windows XP (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 (6.00.2600.0000)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Stop-the-Pop-Up\stopthepop.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
D:\Program Files\Easy\TV Capture\RemoteCtl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
D:\Program Files\Spyware Doctor\swdoctor.exe
C:\Documents and Settings\Seth Stevens\Desktop\StartupList.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Seth Stevens\Start Menu\Programs\Startup]
MagicDisc.lnk = D:\Program Files\MagicDisc\MagicDisc.exe

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
TV Capture Remote Control.lnk = D:\Program Files\Easy\TV Capture\RemoteCtl.exe
Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

Edited by solo-2450, 17 May 2005 - 05:50 PM.

  • 0

Advertisements


#2
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Welcome to GTG.

No need to give us the startuplist. We just need the log (the first/top one you posted).

Hopefully this one won't be too much trouble to remove :tazz:

Before you do anything else, please create a folder for HijackThis and put it in a permanent folder (like C:\HJT) instead of the Temp folder. This is required because HijackThis will create backups and we don't want them to be deleted.

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Go to My Computer->Tools/View->Folder Options->View tab and make sure that 'Show hidden files and folders' (or 'Show all files') is enabled. Also make sure that 'Display the contents of system folders' is checked. If you have Windows XP, the search feature is a little different. When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. Make sure that 'Search system folders', 'Search hidden files and folders', and 'Search subfolders' are checked.

For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).

Download ETRemover and unzip it. Don't run it yet.

Reboot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work. Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):

O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitehod32.exe
O4 - HKLM\..\RunServices: [strmsnmsgr] msnmsgrs.exe
O4 - HKLM\..\RunServices: [The Intranet] intranet.exe
O4 - HKCU\..\RunServices: [The Intranet] intranet.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.r...ip/RdxIE601.cab


Delete the following Files/Folders (delete folders if no filename is specified) according to their directory (if none, just do a search for them) and delete them if they exist:

C:\windows\system32\elitehod32.exe
C:\windows\system32\msnmsgrs.exe
C:\windows\system32\intranet.exe


Run ETRemover.exe now.

Reboot into Normal Mode run a new HijackThis scan. Save the log file and post it here.
  • 0

#3
solo-2450

solo-2450

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Logfile of HijackThis v1.99.1
Scan saved at 12:27:16 AM, on 5/18/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\PROGRA~1\CA\ETRUST~1\ETRUST~2\ca.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
C:\Program Files\Stop-the-Pop-Up\stopthepop.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\Program Files\Customizer XP\RAMIdle.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\CTsvcCDA.exe
D:\Program Files\AIM\aim.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
D:\Program Files\Easy\TV Capture\RemoteCtl.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/ht...x.cfm?p=16&m=43
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - D:\Program Files\Desktop Sidebar\sbhelp.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] D:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Zone Labs Client] D:\PROGRA~1\CA\ETRUST~1\ETRUST~2\ca.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [sureshotpopupkiller] "C:\Program Files\Stop-the-Pop-Up\stopthepop.exe" -minimized
O4 - HKLM\..\Run: [RAM Idle] D:\Program Files\Customizer XP\RAMIdle.exe
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] D:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RcMan.exe
O4 - Startup: MagicDisc.lnk = D:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: TV Capture Remote Control.lnk = D:\Program Files\Easy\TV Capture\RemoteCtl.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - D:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZONELABS\vsmon.exe

I Don't know if it helped yet... :tazz:
  • 0

#4
solo-2450

solo-2450

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts

I Don't know if it helped yet...  :woot:

View Post


Correction... didn't work completely. I still have something on my computer sending out e-mail. 17,000 undeliverable messages last night.
I Followed the directions exactly as they appeared.
Although
C:\windows\system32\msnmsgrs.exe
C:\windows\system32\intranet.exe
did not exist.
:tazz: :) :wave: :) ;) ;) :) :yeah: :beer:

ok.. what can I do?

(PS: looking at this site at work befor I go home and get flooded.)

Additional info: I found a rar.exe file on my C:\ I deleted it after looking at the info. Built by "The bandwidth Bandits" it was executing reinstalls of all removed softwre. I removed this befor following your steps.

Edited by solo-2450, 18 May 2005 - 07:29 AM.

  • 0

#5
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Bandwith bandits is not good, so it's good that you deleted that file.

Whatever it is, it's not showing up here. How are you sending your emails? Outlook? Outlook Express?

You don't have any updates there. What I suggest to do now is install at least SP1. If you can, I think you are clear to install Service Pack 2 even. So go straight to SP2 if you can.

If that doesn't stop whatever is sending out all these emails, then do this:

Please empty any Quarantine folder in your antivirus program and purge all recovery items in the Spybot program (if you use it) before running this tool.

Download the Mwav virus checker at http://www.mwti.net/antivirus/mwav.asp (Use Link 3)

1. Save it to a folder.
2. Reboot into Safe Mode.
3. Double click the Mwav.exe file. This is a stand alone tool and NOT just a virus checker......so it won't install anything.
4. Select all local drives, scan all files, and press SCAN. When it is completed, anything found will be displayed in the lower pane.
5. In the Virus Log Information Pane......
Left click and highlight all the information in the Lower pane --- Use &CTRL C &on your keyboard to copy everything found in the lower pane and save it to a notepad file
*Note* If prompted that a virus was found and you need to purchase the product to remove the malware, just close out the prompt and let it continue scanning. We are not going to use this to remove anything...but to ID the bad files.

Once you copy that to a Notepad file...highlight the text and copy it here.
  • 0

#6
solo-2450

solo-2450

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
Object "BearShare Spyware/Adware" found in File System! Action Taken: No Action Taken.

Object "BearShare Spyware/Adware" found in File System! Action Taken: No Action Taken.

Object "BearShare Spyware/Adware" found in File System! Action Taken: No Action Taken.

Object "gmt Spyware/Adware" found in File System! Action Taken: No Action Taken.

Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.

Object "bearsharechatnotifymsg Spyware/Adware" found in File System! Action Taken: No Action Taken.

Object "Browser Hijack Object Spyware/Adware" found in File System! Action Taken: No Action Taken.

Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\RdxIE.dll". Action Taken: No Action Taken.

Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\MSXML3A.DLL". Action Taken: No Action Taken.

Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\DIMM.DLL". Action Taken: No Action Taken.

Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\DOCUME~1\SETHST~1\LOCALS~1\Temp\_ISTMP1.DIR\_ISTMP0.DIR\FileGrp\Msvcrt10.dll". Action Taken: No Action Taken.

Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\RdxIE.dll". Action Taken: No Action Taken.

Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\pxwma.dll". Action Taken: No Action Taken.

Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\CTDetect.cpl". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{29822AB8-F302-11D0-9953-00C04FD919C1}" refers to invalid object "WAMREGPS.DLL". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{31DCAB85-BB3E-11D0-9299-00C04FB6678B}" refers to invalid object "C:\WINDOWS\System32\inetsrv\logui.ocx". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{31DCAB86-BB3E-11D0-9299-00C04FB6678B}" refers to invalid object "C:\WINDOWS\System32\inetsrv\logui.ocx". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{31DCAB87-BB3E-11D0-9299-00C04FB6678B}" refers to invalid object "C:\WINDOWS\System32\inetsrv\logui.ocx". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{31DCAB88-BB3E-11D0-9299-00C04FB6678B}" refers to invalid object "C:\WINDOWS\System32\inetsrv\logui.ocx". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{39b16f50-a8ba-11d1-aa91-00aa006bc80b}" refers to invalid object "C:\WINDOWS\System32\inetsrv\mailmsg.dll". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{4C171D40-8277-11D5-AD55-00010333D0AD}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{5443AED3-A8AF-4351-B7E1-929EABCAF250}" refers to invalid object "C:\WINDOWS\System32\inetsrv\appconf.dll". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{56336BCA-3D8A-11d6-A00B-0050DA18DE71}" refers to invalid object "C:\DOCUME~1\SETHST~1\LOCALS~1\Temp\InfoWindow.dll". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{7C4E1804-E342-483D-A43E-A850CFCC8D18}" refers to invalid object "C:\WINDOWS\System32\wamregps.dll". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{9EFBF860-5685-11D3-AA3D-00C04F4C5275}" refers to invalid object "cdooff.dll". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{B0693766-5278-4ec6-B9E1-3CE40560EF5A}" refers to invalid object "CaPlgin.ax". Action Taken: No Action Taken.

Entry "HKCR\CLSID\{b4f34438-afec-11d1-9868-00a0c922e703}" refers to invalid object "iisext.dll". Action Taken: No Action Taken.

Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.

Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.

Entry "HKCR\IISWebService" refers to invalid object "{40B8F873-B30E-475d-BEC5-4D0EBB0DBAF3}". Action Taken: No Action Taken.

Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.

Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.

Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.

Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.

Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.

Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.

Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.

Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.

Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.

Entry "HKCR\WMPShell.HWEventHandler" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.

Entry "HKCR\WMPShell.HWEventHandler.1" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.

File C:\WINDOWS\sql.exe infected by "Trojan-Dropper.Win32.Agent.kq" Virus! Action Taken: No Action Taken.

File C:\WINDOWS\ucmoreiex.exe tagged as "not-a-virus:AdWare.ToolBar.Ucmore.a". Action Taken: No Action Taken.

File C:\WINDOWS\system32\KILLAPPS.EXE tagged as not-a-virus:RiskWare.Tool.KillApp.c. No Action Taken.

File C:\WINDOWS\system32\menu.exe infected by "Trojan.Win32.LowZones.an" Virus! Action Taken: No Action Taken.

File C:\WINDOWS\system32\KILLAPPS.EXE tagged as not-a-virus:RiskWare.Tool.KillApp.c. No Action Taken.

File C:\WINDOWS\system32\menu.exe infected by "Trojan.Win32.LowZones.an" Virus! Action Taken: No Action Taken.

File C:\WINDOWS\Downloaded Program Files\website.ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus! Action Taken: No Action Taken.

File C:\WINDOWS\sql.exe infected by "Trojan-Dropper.Win32.Agent.kq" Virus! Action Taken: No Action Taken.

File C:\WINDOWS\ucmoreiex.exe tagged as "not-a-virus:AdWare.ToolBar.Ucmore.a". Action Taken: No Action Taken.

File C:\Documents and Settings\Seth Stevens\Local Settings\Application Data\{32A3A4F2-B792-11D6-A78A-00B0D0150010}\J2SE Development Kit 5.0 Update 1.msi tagged as not-a-virus:JavaClass.Chart. No Action Taken.

File C:\Documents and Settings\Seth Stevens\Desktop\sp1\Good Method\WinXP.Activation.v1.1.English.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.

File C:\Documents and Settings\Seth Stevens\Desktop\sp1\FILE.VBS infected by "Email-Worm.VBS.Gedza" Virus! Action Taken: No Action Taken.

File C:\Program Files\Common Files\Java\Update\Base Images\jdk1.5.0_01.b08\demos.zip tagged as not-a-virus:JavaClass.Chart. No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP143\A0020291.exe tagged as "not-a-virus:AdWare.Sahat.m". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP143\A0020292.exe tagged as "not-a-virus:AdWare.Wintol.ab". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP143\A0020293.exe tagged as "not-a-virus:AdWare.WebSearch.aj". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP143\A0020295.dll tagged as "not-a-virus:AdWare.ToolBar.Ucmore.a". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP143\A0020299.exe tagged as "not-a-virus:AdWare.WebSearch.aj". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP143\A0020300.exe tagged as "not-a-virus:AdWare.Wintol.aa". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP144\A0020654.dll tagged as "not-a-virus:AdWare.Toolbar.Ucmore". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP144\A0020659.exe tagged as "not-a-virus:AdWare.Wintol.aa". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP144\A0020660.exe infected by "Trojan-Downloader.Win32.Wintool.f" Virus! Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP144\A0020666.exe tagged as "not-a-virus:AdWare.WebSearch.aj". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP144\A0020667.dll tagged as "not-a-virus:AdWare.WebSearch.aj". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP144\A0020702.dll tagged as "not-a-virus:AdWare.ToolBar.Ucmore.a". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP144\A0020703.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP144\A0020704.exe tagged as "not-a-virus:AdWare.Wintol.aa". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP144\A0020705.dll tagged as "not-a-virus:AdWare.Wintol.y". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP144\A0020706.exe tagged as "not-a-virus:AdWare.WebSearch.aj". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP145\A0020767.exe infected by "Trojan.Win32.VB.vv" Virus! Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP145\A0020772.exe infected by "Trojan-Downloader.Win32.IstBar.is" Virus! Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP145\A0021122.exe tagged as "not-a-virus:[bleep]-Dialer.Win32.ALifeDialer". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP145\A0021135.dll tagged as "not-a-virus:AdWare.WinAD.am". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP145\A0021136.exe tagged as "not-a-virus:AdWare.WinAD.am". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP145\A0021137.exe tagged as "not-a-virus:AdWare.WinAD.am". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP147\A0023258.exe infected by "Backdoor.Win32.IRCBot.aw" Virus! Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP147\A0023259.exe infected by "Trojan.Win32.LowZones.an" Virus! Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP147\A0023260.exe infected by "Backdoor.Win32.VBbot.b" Virus! Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP148\A0023285.exe infected by "Trojan-Downloader.Win32.Apropo.ab" Virus! Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP148\A0023287.exe tagged as "not-a-virus:[bleep]-Dialer.Win32.ALifeDialer". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP148\A0023293.dll tagged as "not-a-virus:AdWare.BHO.Thingies". Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP149\A0023386.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP149\A0023388.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP149\A0023389.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP167\A0027696.VBS infected by "Email-Worm.VBS.Gedza" Virus! Action Taken: No Action Taken.

File C:\System Volume Information\_restore{0239BA7E-8FD6-4629-99DC-DFC7D4B233E6}\RP167\A0027697.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
:tazz: ;) ;) :) :) :) :yeah: :beer: :woot: :wave: :D :) :) :) :) :) :) :) :)
  • 0

#7
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Uninstall these from your Add/Remove Panel if they are listed there:

BearShare
WhenU
Save
GMT


Delete these files if they exist:

C:\Documents and Settings\Seth Stevens\Desktop\sp1\FILE.VBS
C:\Documents and Settings\Seth Stevens\Desktop\sp1\Good Method\WinXP.Activation.v1.1.English.exe
C:\WINDOWS\ucmoreiex.exe
C:\WINDOWS\system32\menu.exe
C:\WINDOWS\Downloaded Program Files\website.ocx
C:\WINDOWS\sql.exe
C:\WINDOWS\System32\inetsrv\ - delete folder if it's there


Restart.

Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore. Click Apply and then OK. Restart your computer and uncheck the same box to enable System Restore.

Restart again.

Any problems now?
  • 0

#8
solo-2450

solo-2450

    New Member

  • Topic Starter
  • Member
  • Pip
  • 5 posts
The e-mail bot stopped
:tazz:

Thank You Very Much
  • 0

#9
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP