Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

CWS.bootconf and cws.svchost32


  • Please log in to reply

#1
tome

tome

    New Member

  • Member
  • Pip
  • 9 posts
I really hope some one can help me on this... seems like everyone is having the same problem of shredding CWS.bootconf and CWS.Svchost32 . It seems everytime i use any program to get rid of these nasty trojans they just keep coming back immidiatly

what is worse they keep downloading more adware programs which is sending me up the wall! Pop ups everywhere

here is my HJT log

Logfile of HijackThis v1.99.0
Scan saved at 11:39:11 PM, on 12/01/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
c:\Program Files\PestPatrol\ppmemcheck.exe
c:\Program Files\PestPatrol\ppcontrol.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

O1 - Hosts: 69.20.16.1ted by Spybot - Search & Destroy
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PESTPA~1\PPMemCheck.exe
  • 0

Advertisements


#2
tome

tome

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Here is my FIND IT Log


REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\maawt.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"


------------- Locate.com Results -------------

C:\WINDOWS\SYSTEM32\
guard.tmp Wed 12 Jan 2005 22:20:34 ..S.R 223,853 218.61 K
hr8m05~1.dll Thu 6 Jan 2005 20:25:28 ..S.R 223,232 218.00 K
htf_inst.dll Thu 6 Jan 2005 13:15:10 ..S.R 223,232 218.00 K
iiircl.dll Thu 6 Jan 2005 8:38:40 ..S.R 223,232 218.00 K
irjql5~1.dll Tue 11 Jan 2005 20:29:22 ..S.R 225,368 220.09 K
j4p0le~1.dll Tue 11 Jan 2005 0:11:10 ..S.R 223,853 218.61 K
k8no0i~1.dll Wed 12 Jan 2005 12:15:32 ..S.R 224,211 218.95 K
kfsys32.dll Wed 12 Jan 2005 9:30:54 ..S.R 223,853 218.61 K
ktrsl7~1.dll Wed 12 Jan 2005 9:30:54 ..S.R 225,650 220.36 K
maawt.dll Tue 11 Jan 2005 21:56:26 ..S.R 223,853 218.61 K
moxmlr.dll Thu 6 Jan 2005 11:40:34 ..S.R 223,232 218.00 K
nlrrhook.dll Thu 6 Jan 2005 13:49:42 ..S.R 225,275 219.99 K
okecli.dll Fri 7 Jan 2005 23:23:46 ..S.R 223,047 217.82 K
q0nu0a~1.dll Tue 11 Jan 2005 21:56:26 ..S.R 224,803 219.53 K
s6rs0g~1.dll Tue 11 Jan 2005 20:15:58 ..S.R 223,927 218.68 K

15 items found: 15 files, 0 directories.
Total of file sizes: 3,360,621 bytes 3.20 M

-------- Strings.exe Qoologic Results --------


--------- Strings.exe Aspack Results ---------


-------------- HKLM Run Key ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_04\\bin\\jusched.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"PestPatrol Control Center"="c:\\PROGRA~1\\PESTPA~1\\PPControl.exe"
"PPMemCheck"="c:\\PROGRA~1\\PESTPA~1\\PPMemCheck.exe"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"



  • 0

#3
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Download and unzip:
http://www.downloads...org/KillBox.zip
Run killbox and paste each of these lines into the box, select delete on reboot then press the red X button, when it says reboot now, say no and continue to paste the lines into the box in turn and follow the above procedure every time, after the last line has been pasted let it reboot.

C:\WINDOWS\SYSTEM32\guard.tmp
C:\WINDOWS\SYSTEM32\hr8m05~1.dll
C:\WINDOWS\SYSTEM32\htf_inst.dll
C:\WINDOWS\SYSTEM32\iiircl.dll
C:\WINDOWS\SYSTEM32\irjql5~1.dll
C:\WINDOWS\SYSTEM32\j4p0le~1.dll
C:\WINDOWS\SYSTEM32\k8no0i~1.dll
C:\WINDOWS\SYSTEM32\kfsys32.dll
C:\WINDOWS\SYSTEM32\ktrsl7~1.dll
C:\WINDOWS\SYSTEM32\maawt.dll
C:\WINDOWS\SYSTEM32\moxmlr.dll
C:\WINDOWS\SYSTEM32\nlrrhook.dll
C:\WINDOWS\SYSTEM32\okecli.dll
C:\WINDOWS\SYSTEM32\q0nu0a~1.dll
C:\WINDOWS\SYSTEM32\s6rs0g~1.dll <= save till last

After the reboot copy and paste the text in bold below into a text editor such as Notepad.
Save this text as FixVX2.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop.
Double-click on FixVX2.reg. When it asks you to merge the information to the registry click Yes.


REGEDIT4

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer]


Download VX2Finder from:
http://www.downloads...g/VX2Finder.exe
Run it and use the User Agent$ and Restore Policy button

Then copy & paste the text in bold below into notepad and save it as recyclerem.bat
(Set filetype to "All Files")


attrib -r -s -h %systemdrive%\Recycler
del %systemdrive%\Recycler
attrib -r -s -h %systemdrive%\Recycled
del %systemdrive%\Recycled
shutdown /r /t 0 /f


Close all programs and doubleclick recyclerem.bat

Your computer will reboot and you will have a shiny new (empty) recycle bin.

Reboot and post a new HijackThis log.

Regards,

Pieter
  • 0

#4
tome

tome

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
HEy thanks for the speedy reply here is my new HJT log! ... well my Bin is fixed! but unfortunatly cws.bootconf and cws.Svchost32 is still present :tazz:

i did every thing you told me to, except with VX2finder , the button 'User Agent$'
i was unable to click?! but i did press Restore Policy!

Logfile of HijackThis v1.99.0
Scan saved at 9:59:14 AM, on 13/01/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\HJT\HijackThis.exe

O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
  • 0

#5
tome

tome

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
OK bin is no longer fixed the comp restarted and its full of nothing again...

?!?!
  • 0

#6
tome

tome

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
...just curious... the files i delete where are they going?! are they been deleted or stored somewhere on my computer?
  • 0

#7
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Which files?

The one you deleted with Killbox are in a hidden folder called !Submit

I do not know what you did with HijackThis but your log looks as if everything was fixed including all the stuff you need.

To help you get rid of VX2 I will need to answer a FindIt log before you reboot.
So post a new one and do NOT reboot untill you get an answer.

Regards,

Pieter
  • 0

#8
tome

tome

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
OK here is my FINDit log! my HJT log has those redirected hosts, and i noticed when i was looking in pestpatrol it said that rundll32 was is running in my prosesses
...thank you for your time and patience :tazz:



Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

Find.bat is running from: C:\Documents and Settings\Zildjian.TOME\Desktop\Find It NT-2K-XP

------- System Files in System32 Directory -------

Volume in drive C is RATM
Volume Serial Number is 4855-9010

Directory of C:\WINDOWS\System32

13/01/2005 11:31 AM 223,157 n4r2le9o1h.dll
13/01/2005 10:32 AM 223,066 l2r0lc9m1f.dll
13/01/2005 09:55 AM 223,563 jtr4079qe.dll
13/01/2005 09:47 AM 224,211 andiosrv.dll
13/01/2005 09:12 AM 224,211 mkxbde40.dll
12/01/2005 10:20 PM 223,853 mvpml9711.dll
11/01/2005 07:55 PM <DIR> dllcache
08/04/2004 02:49 PM <DIR> Microsoft
30/09/1999 08:21 PM 166,672 mstext35.dll
28/09/1999 10:42 PM 1,050,896 msjet35.dll
09/09/1999 11:06 PM 252,688 msexcl35.dll
09/09/1999 11:06 PM 168,720 msltus35.dll
25/08/1999 03:57 PM 415,504 msrepl35.dll
10/06/1999 10:34 AM 24,848 msjter35.dll
10/06/1999 10:34 AM 123,664 msjint35.dll
07/06/1999 07:59 PM 250,128 mspdox35.dll
25/04/1999 06:00 PM 252,176 Msrd2x35.dll
25/04/1999 06:00 PM 287,504 Msxbse35.dll
16 File(s) 4,334,861 bytes
2 Dir(s) 23,319,965,696 bytes free

------- Hidden Files in System32 Directory -------

Volume in drive C is RATM
Volume Serial Number is 4855-9010

Directory of C:\WINDOWS\System32

11/01/2005 07:55 PM <DIR> dllcache
08/04/2004 11:46 AM <DIR> GroupPolicy
08/04/2004 11:31 AM 488 WindowsLogon.manifest
08/04/2004 11:31 AM 488 logonui.exe.manifest
08/04/2004 11:31 AM 749 nwc.cpl.manifest
08/04/2004 11:31 AM 749 sapi.cpl.manifest
08/04/2004 11:31 AM 749 ncpa.cpl.manifest
08/04/2004 11:31 AM 749 cdplayer.exe.manifest
08/04/2004 11:31 AM 749 wuaucpl.cpl.manifest
7 File(s) 4,721 bytes
2 Dir(s) 23,319,965,696 bytes free

------------ Files Named "Guard" ---------------

Volume in drive C is RATM
Volume Serial Number is 4855-9010

Directory of C:\WINDOWS\System32

14/01/2005 08:41 AM 223,066 guard.tmp
1 File(s) 223,066 bytes
0 Dir(s) 23,319,961,600 bytes free

------ Temp Files in System32 Directory ------

Volume in drive C is RATM
Volume Serial Number is 4855-9010

Directory of C:\WINDOWS\System32

14/01/2005 08:41 AM 223,066 guard.tmp
03/08/2004 11:56 PM 1,236,480 msxml3.dll.tmp
23/08/2001 11:00 PM 2,577 CONFIG.TMP
3 File(s) 1,462,123 bytes
0 Dir(s) 23,319,961,600 bytes free

------------------ User Agent ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{4824BE20-CB1D-438D-A53E-4DB30DC72C99}"=""


------------- Keys Under Notify -------------

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\l2r0lc9m1f.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"


------------- Locate.com Results -------------

C:\WINDOWS\SYSTEM32\
andiosrv.dll Thu 13 Jan 2005 9:47:48 ..S.R 224,211 218.95 K
jtr407~1.dll Thu 13 Jan 2005 9:55:04 ..S.R 223,563 218.32 K
l2r0lc~1.dll Thu 13 Jan 2005 10:32:54 ..S.R 223,066 217.84 K
mkxbde40.dll Thu 13 Jan 2005 9:12:48 ..S.R 224,211 218.95 K
mvpml9~1.dll Wed 12 Jan 2005 22:20:34 ..S.R 223,853 218.61 K
n4r2le~1.dll Thu 13 Jan 2005 11:31:44 ..S.R 223,157 217.93 K

6 items found: 6 files, 0 directories.
Total of file sizes: 1,342,061 bytes 1.28 M

-------- Strings.exe Qoologic Results --------


--------- Strings.exe Aspack Results ---------


-------------- HKLM Run Key ----------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_04\\bin\\jusched.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"PestPatrol Control Center"="C:\\PROGRA~1\\PESTPA~1\\PPControl.exe"
"PPMemCheck"="C:\\PROGRA~1\\PESTPA~1\\PPMemCheck.exe"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"iTunesHelper"="C:\\Program Files\\iTunes\\iTunesHelper.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"



  • 0

#9
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Download and unzip:
http://www.downloads...org/KillBox.zip
Run killbox and paste each of these lines into the box, select delete on reboot then press the red X button, when it says reboot now, say no and continue to paste the lines into the box in turn and follow the above procedure every time, after the last line has been pasted let it reboot.

C:\WINDOWS\System32\n4r2le9o1h.dll
C:\WINDOWS\System32\jtr4079qe.dll
C:\WINDOWS\System32\andiosrv.dll
C:\WINDOWS\System32\mkxbde40.dll
C:\WINDOWS\System32\guard.tmp
C:\WINDOWS\System32\mvpml9711.dll
C:\WINDOWS\System32\l2r0lc9m1f.dll <= save till last

After the reboot copy and paste the text in bold below into a text editor such as Notepad.
Save this text as FixVX2.reg. Make sure the "Save as type:" is "All Files (*.*)" and save it to your desktop.
Double-click on FixVX2.reg. When it asks you to merge the information to the registry click Yes.


REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{4824BE20-CB1D-438D-A53E-4DB30DC72C99}"=-

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Installer]


Download VX2Finder from:
http://www.downloads...g/VX2Finder.exe
Run it and use the Restore Policy button

Then copy & paste the text in bold below into notepad and save it as recyclerem.bat
(Set filetype to "All Files")


attrib -r -s -h %systemdrive%\Recycler
del %systemdrive%\Recycler
attrib -r -s -h %systemdrive%\Recycled
del %systemdrive%\Recycled
shutdown /r /t 0 /f


Close all programs and doubleclick recyclerem.bat

Your computer will reboot and you will have a shiny new (empty) recycle bin.

Post back with a HijackThis log.

Regards,

Pieter
  • 0

#10
tome

tome

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
Well thanks for your time.... but i don't know what i have but it wont piss off

my main problem i think is those hosts at the end of this log! every time i fix them they just come back and redirect them again!

Logfile of HijackThis v1.99.0
Scan saved at 11:17:33 PM, on 14/01/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HJT\HijackThis.exe

O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
  • 0

#11
tome

tome

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
I THINK I"VE FIXED IT!!!!!!! i am soo excited like really i read another thread and it said to use 'deldomains' file thing , and i think its done the job... dammm trojans

thanks heaps pieter ROCK ON METALLICA
  • 0

#12
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Glad we could help. :tazz:

Get some protection,

Pieter
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP