Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Firefox redirects to click.livesearchnow.com [Solved]


  • This topic is locked This topic is locked

#16
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
OK. Let's continue.

Step 1

Download the adwCleaner

  • Run the Tool
    (Windows Vista and Windows 7 users: right click in the adwCleaner.exe and select the Run as Administrator option)
  • Select the Delete button.
  • When the scan completes, it will open a notepad windows.
  • Please, copy the content of this file in your next reply.

Step 2

  • Run OTL.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open notepad window. OTL.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file, and post it with your next reply.

Step 3

Please don't forget to include these items in your reply:

  • adwCleaner log
  • New OTL scan log
It would be helpful if you could post each log in separate post using "Add Reply" button
  • 0

Advertisements


#17
byron22

byron22

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
# AdwCleaner v2.109 - Logfile created 01/31/2013 at 05:50:12
# Updated 26/01/2013 by Xplode
# Operating system : Windows Vista ™ Home Premium Service Pack 2 (32 bits)
# User : Brian - BRIAN-PC
# Boot Mode : Normal
# Running from : C:\Users\Brian\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk

***** [Registry] *****

Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
Key Deleted : HKLM\SOFTWARE\Software

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.19393

[OK] Registry is clean.

-\\ Mozilla Firefox v18.0.1 (en-US)

File : C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\6yykqdrg.default\prefs.js

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [2347 octets] - [31/01/2013 05:50:12]

########## EOF - C:\AdwCleaner[S1].txt - [2407 octets] ##########
  • 0

#18
byron22

byron22

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
OTL logfile created on: 1/31/2013 5:54:17 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Brian\Desktop\Netscape\Netscape
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19393)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.87 Gb Total Physical Memory | 2.22 Gb Available Physical Memory | 77.18% Memory free
5.95 Gb Paging File | 5.40 Gb Available in Paging File | 90.73% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 455.59 Gb Total Space | 216.30 Gb Free Space | 47.48% Space Free | Partition Type: NTFS
Drive D: | 10.17 Gb Total Space | 1.37 Gb Free Space | 13.45% Space Free | Partition Type: NTFS

Computer Name: BRIAN-PC | User Name: Brian | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/01/28 16:43:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Brian\Desktop\Netscape\Netscape\OTL.exe
PRC - [2010/09/30 02:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
PRC - [2009/04/10 22:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/03/26 08:21:30 | 005,369,856 | ---- | M] (Realtek Semiconductor) -- C:\WINDOWS\RtHDVCpl.exe


========== Modules (No Company Name) ==========

MOD - [2011/05/26 12:42:00 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/03/16 23:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 14:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll


========== Services (SafeList) ==========

SRV - [2013/01/19 13:01:16 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/09/20 13:28:48 | 030,785,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2012/04/08 08:11:14 | 000,253,600 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2010/09/30 02:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor9.0)
SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2008/01/20 21:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Brian\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2012/10/08 19:44:29 | 000,027,424 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\hitmanpro36.sys -- (hitmanpro36)
DRV - [2008/05/08 04:05:18 | 000,266,752 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\HSXHWBS2.sys -- (HSXHWBS2)
DRV - [2008/05/08 04:03:18 | 000,980,992 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\HSX_DP.sys -- (HSF_DP)
DRV - [2008/01/29 07:55:00 | 001,042,464 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2008/01/25 14:02:04 | 000,132,128 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\nvrd32.sys -- (nvrd32)
DRV - [2008/01/25 14:02:02 | 000,140,832 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\nvstor32.sys -- (nvstor32)
DRV - [2007/12/12 03:20:00 | 007,629,376 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2007/10/18 10:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/10/12 10:53:10 | 000,013,312 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\drivers\nvsmu.sys -- (nvsmu)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...resario&pf=cndt
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{1A6F7013-B594-4E76-B64A-9926DF8F0A52}: "URL" = http://www.ask.com/w...}&l=dis&o=uscqd
IE - HKLM\..\SearchScopes\{6DBD9950-6248-4720-9E5B-11E20447196D}: "URL" = http://search.yahoo....ing}&fr=hp-psdt

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...resario&pf=cndt
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{1A6F7013-B594-4E76-B64A-9926DF8F0A52}: "URL" = http://www.ask.com/w...}&l=dis&o=uscqd
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6DBD9950-6248-4720-9E5B-11E20447196D}: "URL" = http://search.yahoo....ing}&fr=hp-psdt
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.co...d_search?hl=en"
FF - prefs.js..extensions.enabledAddons: %7Bb73ea464-ba8c-4b76-86e4-00eaf7b1b88d%7D:3.0.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {0b457cAA-602d-484a-8fe7-c1d894a011ba}:0.95
FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:12.0.0.1912
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_228.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/19 13:01:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/19 13:01:10 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/19 13:01:16 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/19 13:01:10 | 000,000,000 | ---D | M]

[2011/06/06 00:32:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Brian\AppData\Roaming\Mozilla\Extensions
[2013/01/30 18:18:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\6yykqdrg.default\extensions
[2013/01/02 23:40:07 | 000,000,000 | ---D | M] (FireShot) -- C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\6yykqdrg.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2013/01/30 18:18:02 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\6yykqdrg.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2012/05/30 18:52:15 | 000,020,591 | ---- | M] () (No name found) -- C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\6yykqdrg.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi
[2013/01/30 18:18:02 | 000,533,536 | ---- | M] () (No name found) -- C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\6yykqdrg.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/01/13 10:10:23 | 000,004,037 | ---- | M] () (No name found) -- C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Profiles\6yykqdrg.default\extensions\{b73ea464-ba8c-4b76-86e4-00eaf7b1b88d}.xpi
[2013/01/19 13:01:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/01/19 13:01:16 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/08/30 17:59:33 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/13 12:11:37 | 000,002,058 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2013/01/29 12:16:34 | 000,000,027 | ---- | M]) - C:\WINDOWS\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll File not found
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoDriveTypeAutoRun: NoDriveTypeAutoRun = 177
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 177
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.3\IExifMap.htm ()
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.3\IExifCom.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.9.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1D673272-229C-46B3-8E44-6A872B1F279B}: DhcpNameServer = 209.18.47.61 209.18.47.62
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
O24 - Desktop BackupWallPaper: C:\Users\Brian\AppData\Roaming\Mozilla\Firefox\Desktop Background.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/05/05 03:45:19 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/01/31 05:09:13 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013/01/31 05:09:13 | 000,000,000 | ---D | C] -- C:\Users\Brian\AppData\Local\temp
[2013/01/31 05:08:48 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/01/31 04:56:16 | 005,028,065 | R--- | C] (Swearware) -- C:\Users\Brian\Desktop\ComboFix.exe
[2013/01/31 04:52:14 | 000,000,000 | ---D | C] -- C:\Users\Brian\Desktop\sality_regkeys
[2013/01/31 03:18:58 | 000,000,000 | ---D | C] -- C:\Users\Brian\Desktop\salitykiller
[2013/01/31 02:10:27 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2013/01/30 01:46:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2013/01/29 12:01:12 | 000,000,000 | ---D | C] -- C:\Users\Brian\Desktop\Desktop
[2013/01/29 11:34:34 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/01/29 11:34:34 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/01/29 11:34:34 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/01/29 11:31:08 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/01/29 11:30:43 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/01/29 10:58:33 | 002,213,976 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Brian\Desktop\TDSSKiller.exe
[2013/01/28 16:59:12 | 000,000,000 | ---D | C] -- C:\_OTM
[2013/01/26 11:19:02 | 000,000,000 | ---D | C] -- C:\Users\Brian\Documents\My muvees
[2013/01/26 11:18:59 | 000,000,000 | ---D | C] -- C:\Users\Brian\AppData\Roaming\muvee Technologies
[2013/01/25 21:29:16 | 000,000,000 | ---D | C] -- C:\Users\Brian\AppData\Roaming\Malwarebytes
[2013/01/25 21:29:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/25 21:29:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/01/25 21:29:12 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013/01/25 21:29:12 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013/01/19 13:01:09 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013/01/09 17:30:15 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2013/01/09 17:29:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Becker's CPA Exam Review - 2013 Edition
[2013/01/09 17:29:36 | 000,000,000 | ---D | C] -- C:\Program Files\Becker Professional Education
[2013/01/09 17:29:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Becker Professional Education
[2013/01/07 23:11:51 | 000,000,000 | ---D | C] -- C:\Users\Brian\AppData\Local\Apps
[2013/01/07 23:11:50 | 000,000,000 | ---D | C] -- C:\Users\Brian\AppData\Local\Deployment
[2013/01/07 21:20:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/01/07 21:19:58 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2013/01/03 23:05:50 | 000,000,000 | ---D | C] -- C:\Users\Brian\AppData\Roaming\dvdcss
[2013/01/03 23:05:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinX DVD Ripper
[2013/01/03 23:04:58 | 000,000,000 | ---D | C] -- C:\Users\Brian\AppData\Roaming\Digiarty
[2013/01/03 23:04:58 | 000,000,000 | ---D | C] -- C:\Program Files\Digiarty
[2011/06/07 17:09:30 | 000,812,496 | ---- | C] (Adobe Systems Incorporated) -- C:\Program Files\Set-up.exe

========== Files - Modified Within 30 Days ==========

[2013/01/31 05:51:55 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/31 05:51:55 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/31 05:51:53 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/31 05:51:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/01/31 05:51:45 | 3085,385,728 | -HS- | M] () -- C:\hiberfil.sys
[2013/01/31 05:49:26 | 000,580,235 | ---- | M] () -- C:\Users\Brian\Desktop\adwcleaner.exe
[2013/01/31 04:56:20 | 005,028,065 | R--- | M] (Swearware) -- C:\Users\Brian\Desktop\ComboFix.exe
[2013/01/31 04:51:53 | 000,008,050 | ---- | M] () -- C:\Users\Brian\Desktop\sality_regkeys.zip
[2013/01/31 03:18:37 | 000,164,134 | ---- | M] () -- C:\Users\Brian\Desktop\salitykiller.zip
[2013/01/31 03:00:51 | 000,005,843 | ---- | M] () -- C:\Users\Brian\Desktop\vrtlog.zip
[2013/01/31 02:51:26 | 003,753,160 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/01/31 02:28:50 | 000,608,406 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/01/31 02:28:50 | 000,105,908 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/01/31 01:23:14 | 000,002,595 | ---- | M] () -- C:\Users\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Excel 2010.lnk
[2013/01/30 01:45:15 | 159,882,056 | ---- | M] () -- C:\Users\Brian\Desktop\setup_11.0.0.1245.x01_2013_01_29_22_08.exe
[2013/01/29 23:47:38 | 000,002,637 | ---- | M] () -- C:\Users\Brian\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Word 2010.lnk
[2013/01/29 12:16:34 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013/01/29 10:58:39 | 002,213,976 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Brian\Desktop\TDSSKiller.exe
[2013/01/26 11:17:57 | 000,000,600 | ---- | M] () -- C:\Users\Brian\AppData\Roaming\winscp.rnd
[2013/01/25 21:29:14 | 000,000,649 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/13 10:15:39 | 000,006,527 | ---- | M] () -- C:\Users\Brian\AppData\Local\b73ea464-ba8c-4b76-86e4-00eaf7b1b88d.crx
[2013/01/09 22:12:05 | 000,002,571 | ---- | M] () -- C:\Users\Brian\Desktop\Microsoft Excel 2010.lnk
[2013/01/09 17:29:52 | 000,002,000 | ---- | M] () -- C:\Users\Public\Desktop\Becker's CPA Exam Review - 2013 Edition.lnk
[2013/01/07 12:47:09 | 000,083,456 | ---- | M] () -- C:\Users\Brian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/03 23:05:00 | 000,001,021 | ---- | M] () -- C:\Users\Public\Desktop\WinX DVD Ripper.lnk

========== Files Created - No Company Name ==========

[2013/01/31 05:49:24 | 000,580,235 | ---- | C] () -- C:\Users\Brian\Desktop\adwcleaner.exe
[2013/01/31 04:51:53 | 000,008,050 | ---- | C] () -- C:\Users\Brian\Desktop\sality_regkeys.zip
[2013/01/31 03:18:37 | 000,164,134 | ---- | C] () -- C:\Users\Brian\Desktop\salitykiller.zip
[2013/01/31 03:00:50 | 000,005,843 | ---- | C] () -- C:\Users\Brian\Desktop\vrtlog.zip
[2013/01/30 01:45:14 | 159,882,056 | ---- | C] () -- C:\Users\Brian\Desktop\setup_11.0.0.1245.x01_2013_01_29_22_08.exe
[2013/01/29 11:34:34 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/01/29 11:34:34 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/01/29 11:34:34 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/01/29 11:34:34 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/01/29 11:34:34 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/01/25 21:29:14 | 000,000,649 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/10 21:39:48 | 000,006,527 | ---- | C] () -- C:\Users\Brian\AppData\Local\b73ea464-ba8c-4b76-86e4-00eaf7b1b88d.crx
[2013/01/09 17:29:52 | 000,002,000 | ---- | C] () -- C:\Users\Public\Desktop\Becker's CPA Exam Review - 2013 Edition.lnk
[2013/01/03 23:05:00 | 000,001,021 | ---- | C] () -- C:\Users\Public\Desktop\WinX DVD Ripper.lnk
[2012/10/08 19:44:29 | 000,027,424 | ---- | C] () -- C:\Windows\System32\drivers\hitmanpro36.sys
[2012/04/14 09:46:22 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Internet Services
[2012/04/14 09:46:22 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Internet Plug-Ins
[2012/04/14 09:46:22 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Instrument Library
[2012/04/14 09:46:22 | 000,000,268 | RH-- | C] () -- C:\Users\Brian\AppData\Roaming\InkjetPrinter
[2012/04/14 09:46:22 | 000,000,268 | RH-- | C] () -- C:\Users\Brian\AppData\Roaming\Importer
[2012/04/14 09:46:22 | 000,000,268 | RH-- | C] () -- C:\Users\Brian\AppData\Roaming\Images
[2012/04/14 09:46:22 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLev.DAT
[2012/04/14 09:46:22 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLet.DAT
[2012/04/14 09:46:22 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLes.DAT
[2011/10/29 21:21:59 | 000,000,600 | ---- | C] () -- C:\Users\Brian\AppData\Roaming\winscp.rnd
[2011/08/28 21:13:40 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2011/08/28 21:13:12 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2011/06/07 17:05:12 | 000,133,280 | ---- | C] () -- C:\Program Files\Creative Suite 5 Design Premium Read Me.pdf
[2011/06/06 23:55:34 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2011/06/06 19:54:57 | 000,083,456 | ---- | C] () -- C:\Users\Brian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/06 01:02:31 | 000,175,616 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2011/06/06 00:28:56 | 000,000,680 | ---- | C] () -- C:\Users\Brian\AppData\Local\d3d9caps.dat

========== ZeroAccess Check ==========

[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 12:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/10 22:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/10 22:28:26 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/09/27 19:22:05 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\AVG2013
[2011/10/31 22:05:13 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2013/01/03 23:05:06 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Digiarty
[2011/08/14 20:01:16 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\FireShot
[2012/08/07 10:20:58 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Foxit Software
[2012/08/23 21:31:03 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Mp3tag
[2013/01/26 11:19:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\muvee Technologies
[2011/11/08 23:52:26 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NCH Swift Sound
[2011/06/07 19:48:43 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\NeatImage PS 32
[2012/04/14 09:48:45 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Nikon
[2011/06/06 00:03:36 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\Snapfish
[2011/06/22 21:58:59 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/09/27 18:55:50 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\TuneUp Software
[2011/07/04 10:46:09 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\VitySoft
[2012/07/13 00:27:50 | 000,000,000 | ---D | M] -- C:\Users\Brian\AppData\Roaming\WinFF

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:D62C83D5

< End of report >
  • 0

#19
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
HOw is your system now. Do you still get redirects?

If you do then please answer these questions for me so we can narrow the problem.
  • Do you use router to to access internet?
  • Do you have any other PCs connected to that router and does they get redirected?
  • Do you get redirected in all browsers you use or this redirection only effect one browser?

  • 0

#20
byron22

byron22

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
The system looks a lot better. CPU usage dropped from 70% to 2%. I have not been redirected from my searches. Thank you!
  • 0

#21
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Glad to hear that. Test your system for few hours and I'll prepare some cleanup for you.
  • 0

#22
byron22

byron22

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Unfortunately I'm still getting redirects. I have a router that connects my other PC, but no redirects there. The redirects have only been in Mozilla Firefox.
  • 0

#23
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Click on Start then in search box type:

firefox.exe -safe-mode

And press OK button
If it ask you press Continue in Safe Mode
Test Google searches now and let me know results.

If you don't experience any problems in safe-mode then you must check your add-ons in Firefox.

Open Firefox and from Tools menu select Add-ons
Disable them all and restart your Firefox
If you don't experience any problems then go to Add-ons and enable first add-on then restart Firefox
If problems starts then this is the bad one
If problems don't start then enable another one and so on until you find bad one

When you find it remove it from Add-ons.

Let me know results.
  • 0

#24
byron22

byron22

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
I tried to run the tests but I have not been redirected since my last post a couple days ago. Strange.
  • 0

#25
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Hi byron22,

Nice to hear that. Test your system for few hours more and I'll prepare some cleanup for you. Stay tunned...
  • 0

Advertisements


#26
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Hi byron22,

Your logs and system are clean now. I'm glad we fix up your computer.

Step 1

Please close all running programs and Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL

    :Commands
    [purity]
    [emptytemp]
    [resethosts]
    [clearallrestorepoints]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
Step 2

We need to clean up your PC from programs we used.

Please start OTL one more time and click CleanUp button. OTL will restart your system at the end.

In case that any of the software we used in this fix still remains on your system please delete it manually (Right click on it and select Delete).

General recommendations

Here are some recommendations you should follow to minimize infection risk in the future:

1. Something to read

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?

2. Make Backups of Important Files

Please read this article Home Computer Data Backup.

3. Regularly update your software

To eliminate design flaws and security vulnerabilities, all software needs to be updated to the latest version or the vendor’s patch installed.

You should download Update Checker from here. The program will automaticly check for newer version of software installed on your system.
  • 0

#27
byron22

byron22

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
The redirects came back so I ran the test and found that my out of date Java add-on was the source of the problem. I installed the new version and uninstalled the older one. Hopefully this fixes it.
  • 0

#28
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Thank you for letting me know. I really appreciate it. I'll close this topic now as all seems fine.

Goodbye and stay safe :thumbsup:
  • 0

#29
maliprog

maliprog

    Trusted Helper

  • Malware Removal
  • 6,172 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP