Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads

User Tag List

hijacked by ICE Cyber Crime Center?

This is a discussion on hijacked by ICE Cyber Crime Center? within the Resolved HJT Threads forums, part of the Tech Support Forum category. hi: I'm using Windows XP. When I turn on my PC and log in, the screen immediately goes to some


 
 
Thread Tools Search this Thread
Old 09-05-2013, 08:07 PM   #1
Registered Member
 
Join Date: Feb 2009
Posts: 133
OS: win xp



hi: I'm using Windows XP. When I turn on my PC and log in, the screen immediately goes to some bogus warning from the "ICE Cyber Crime Center" demanding a payment to "unlock" my PC. I literally cannot access anything else on my PC. The only way I can shut down the PC is to turn off the power. A few months ago I got some help from this forum to remove some viruses. Although it seemed to work at that time, my PC never really did behave normally after that -- extremely slow, and IE8 would lock up anytime I had anything with a lot of graphics or more than one tab open. I'm sorry I can't load any DDS scans or anything else, but as I said, I literally can't access anything on my PC. You guys have always been WONDERFUL help before, and I'm hoping you can help me out here again. Thanks.
dredla is offline  
Sponsored Links
Advertisement
 
Old 09-06-2013, 07:33 AM   #2
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



Hello and Welcome to TSF.

If you haven't already, please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant notification by email, then click Add Subscription.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

------------------------------------------------------

If necessary, download and run the tools in Safe Mode with Networking:
  • Restart your computer.
  • After hearing your computer beep once during startup, but before the Windows icon appears, start pressing the F8 key.
  • In some systems, this may be the F5 key.
  • Instead of Windows loading as normal, a menu should appear.
  • Use the up arrow key to highlight Safe Mode with Networking and press 'Enter'.
  • Login on your usual account.
------------------------------------------------------
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
Old 09-06-2013, 05:17 PM   #3
Registered Member
 
Join Date: Feb 2009
Posts: 133
OS: win xp



hi: thanks very much for taking the time to help me. I tried to log in as prescribed in your e-mail. I got to the log-in page, but before I could log in, the log-in screen was replaced by a screen saying the computer was shutting down. After a few seconds, my regular log-in page appeared. I did log-in from there, but got the ICD screen almost immediately.
dredla is offline  
Sponsored Links
Advertisement
 
Old 09-06-2013, 05:32 PM   #4
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



Did you restart in Safe Mode with Networking?
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
Old 09-07-2013, 10:15 AM   #5
Registered Member
 
Join Date: Feb 2009
Posts: 133
OS: win xp



Yes, I did.
dredla is offline  
Old 09-07-2013, 12:18 PM   #6
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



Hello dredla. This assumes you know exactly what date you became infected.

Print out the following directions or read off of another computer. Be careful. One typo and it won't work.

1. Restart your computer like you're going to Safe Mode, except choose Start Windows Normally and press 'Enter'.
2. Before Windows loads, you will be prompted to choose which Operating System to start.
3. Use the up and down arrow key to select Microsoft Windows Recovery Console
4. You must enter which Windows installation to log onto. Type 1 and press 'Enter'.
5. If prompted for Administrator password, enter it and press 'Enter', or if no password, just press 'Enter'.
6. At the C:\Windows prompt, type the following bolded entries one at a time, taking care to include all spaces and underscores, and press 'Enter':

set allowallpaths = true

cd c:\system~1\_resto~1

dir

7. When you hit 'Enter' it will list all the restore points folders like rp1, rp2, etc. If there are no restore points, type exit, press 'Enter', stop here and let me know. If the restore points have more than one page then keep pressing 'Enter' to view more restore point folders. You will have to choose a restore point to before you started having trouble.

8. Type the following bolded entries one at a time, and press 'Enter':

cd rp# (Note: Example: cd rp9, if rp9 is a restore point to before you started having trouble.)

cd snapshot

9. Now the command prompt will look like this c:\system~1\_resto~1\rp9\snapshot

10. Type the following bolded entries one at a time, taking care to include all spaces and underscores, and press 'Enter':

copy _registry_machine_system c:\windows\system32\config\system

Type y to the prompt and press 'Enter'.

copy _registry_machine_software c:\windows\system32\config\software

Type y to the prompt and press 'Enter'.

exit

Windows should now begin loading. Let me know.

------------------------------------------------------
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
Old 09-07-2013, 10:24 PM   #7
Registered Member
 
Join Date: Feb 2009
Posts: 133
OS: win xp



I was able to log in under another profile.

I was able to run DDS, but was not able to successfully complete the GMER scan. My PC locked up on me the first time I tried to run it. I deleted GMER, then reinstalled it. The second time I ran it, it ran verrry slowly. After running for about 2.5 hrs, I started getting pop-up messages: Windows - No Disk. Exception processing message c0000013 75b6bf7c 4 75b6bf7c 75b6b7c. Every time I'd get the message to close, it would pop up again. Suggestions?

See "attach.zip"

DDS text follows

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.13.2
Run by Compaq_Administrator at 20:01:00 on 2013-09-07
.
============== Running Processes ================
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe
C:\Program Files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Kodak\printer\center\KodakSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Kodak\Printer\Center\EKDiscovery.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\QuickTime\qttask.exe
C:\Documents and Settings\Compaq_Administrator\Application Data\Spotify\Data\SpotifyWebHelper.exe
C:\WINDOWS\system32\wuauclt.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
c:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/
mSearch Bar = hxxp://www.google.com/
mSearchMigratedDefaultURL = hxxp://www.google.com/
uURLSearchHooks: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [Spotify Web Helper] "c:\documents and settings\compaq_administrator\application data\spotify\data\SpotifyWebHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [ISUSScheduler] "c:\progra~1\common~1\instal~1\update~1\issch.exe" -start
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: NoDriveAutoRun = dword:67108863
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223}
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {6D5AD93A-F4E2-411F-87E2-9015D0084E12} - hxxps://sharpnet.sharp.com/,DanaInfo=sharpnet.sharp.com+SharpNetCheckUser.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://lawson.sharp.com/dana-cached/setup/JuniperSetupSP1.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://sharpnet.sharp.com/dana-cached/sc/JuniperSetupClient.cab
TCP: NameServer = 192.168.2.1
TCP: Interfaces\{E92C1ED9-A6E0-48D9-A5E5-0F1F1AE3EF62} : DHCPNameServer = 192.168.2.1
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\29.0.1547.66\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
R? Diag69xp;Diag69xp
R? mbamchameleon;mbamchameleon
S? AntiVirSchedulerService;Avira Scheduler
S? AntiVirService;Avira Realtime Protection
S? avgntflt;avgntflt
S? avkmgr;avkmgr
S? Belkin Local Backup Service;Belkin Local Backup Service
S? Belkin Network USB Helper;Belkin Network USB Helper
S? Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service
S? KodakSvc;Kodak AiO Device Service
S? McrdSvc;Media Center Extender Service
S? sxuptp;SXUPTP Driver
.
=============== File Associations ===============
.
ShellExec: MDI2PDF.exe: open=c:\program files\mdiconvertor\MDI2PDF %1
ShellExec: MDI2PDF.exe: openMDIasPDF=c:\program files\mdiconvertor\MDI2PDF pdf:%1
ShellExec: MDI2PDF.exe: openMDIexport=c:\program files\mdiconvertor\MDI2PDF export:%1
.
=============== Created Last 30 ================
.
2013-09-04 14:52:45 156040 ----a-w- c:\documents and settings\all users\application data\qml16jdo3.plz
2013-08-19 10:08:43 -------- d-----w- c:\windows\system32\MRT
.
==================== Find3M ====================
.
2013-08-03 21:18:38 1543680 ------w- c:\windows\system32\wmvdecod.dll
2013-07-26 02:47:17 920064 ----a-w- c:\windows\system32\wininet.dll
2013-07-26 02:47:13 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-07-26 02:47:12 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-07-25 15:52:59 385024 ----a-w- c:\windows\system32\html.iec
2013-07-10 10:37:53 406016 ------w- c:\windows\system32\usp10.dll
2013-07-06 17:11:39 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-07-06 17:11:39 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-07-04 03:03:25 2149888 ------w- c:\windows\system32\ntoskrnl.exe
2013-07-04 02:08:30 2028544 ------w- c:\windows\system32\ntkrnlpa.exe
.
============= FINISH: 20:02:38.93 ===============
Attached Files
File Type: zip attach.zip (3.4 KB, 41 views)
dredla is offline  
Old 09-07-2013, 10:46 PM   #8
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



Hello dredla. Did you try my last instructions?
  • Download and extract Malwarebytes Anti-Rootkit from here mbar-1.07.0.1005.zip and save it to your desktop.
  • Caution: This is a beta version so please be sure to read the disclaimer and back up any important data before using.
  • Double-click mbar.exe inside the mbar folder then click 'Next'.
  • Note: Malwarebytes Anti-Rootkit requires administrative privileges to function properly.
  • Click 'Update'.
  • When finished updating, click 'Next' then 'Scan'.
  • If you are told you have the 'AppInit_Dlls rootkit', choose not to fix it and proceed with the scan.
  • If malware is found, do NOT press the' Cleanup' button yet. Click 'Exit'.
  • Please post the contents of the log created by the tool within the folder from which it was run.
The log will be named system-log.txt

------------------------------------------------------

Please go to: VirusTotal
  • Click the Choose File button.
  • Please copy/paste the following bolded text into the 'File name:' box:

    c:\documents and settings\all users\application data\qml16jdo3.plz

  • Click Open then click the Scan it! button just below.
  • This will scan the file. Please be patient.
  • If you get a message saying File already analyzed: click Reanalyse
  • Once scanned, copy and paste the URL from your browser address bar in your next reply.
------------------------------------------------------
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
Old 09-09-2013, 08:00 AM   #9
Registered Member
 
Join Date: Feb 2009
Posts: 133
OS: win xp



I will work on this tonight when I get home from work.
dredla is offline  
Old 09-09-2013, 07:44 PM   #10
Registered Member
 
Join Date: Feb 2009
Posts: 133
OS: win xp



I'm sorry, but I'm stuck with the log in. I followed your instructions from post#6. I got to the point where the prompt read: c:\system~1\_resto~1\rp68\snapshot

I then typed the next command per your instructions, taking care to enter all characters and spaces exactly as written. It looked like this:

c:\system~1\_resto~1\rp68\snapshot>copy_registry_machine_system c:\windows\system32\config\system

After pressing Enter, I got the message: the command not recognized. I retyped the command several times, and triple checked I got all the right characters, spaces and underscores (and noting there is a space but no underscore after the word "system" and before c:). I'm sure I'm entering it exactly as you directed. what did I miss?
dredla is offline  
Old 09-09-2013, 08:17 PM   #11
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



So you are no longer able to access via the other profile?

There should be a space between copy and _registry_machine_system
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
Old 09-09-2013, 08:54 PM   #12
Registered Member
 
Join Date: Feb 2009
Posts: 133
OS: win xp



hahaha...my eyes are old. I just couldn't see that space. I'll try that now.

to answer your other question, the PC seems to stall just before opening the log-in page. I let it sit there for about 5 minutes, but it just wouldn't advance to the log-in, so that's when I started to try the directions in post #6
dredla is offline  
Old 09-09-2013, 09:00 PM   #13
Registered Member
 
Join Date: Feb 2009
Posts: 133
OS: win xp



OK, I got logged in OK. I'm running GMER now. I'll also run Malwarebytes and Virus Total, and try to post all three logs tonight. thanks.
dredla is offline  
Old 09-09-2013, 10:19 PM   #14
Registered Member
 
Join Date: Feb 2009
Posts: 133
OS: win xp



I still am unable to complete the GMER scan. I keep getting the error message "Windows - No Disk. Exception processing message c0000013 parameters 75b6bf7c 4 75b6bf7c 75b6b7c" I'll click "Try Again," and a few second later the same message would pop up. I tried just canceling the warning, and the message would pop-up again.

I will have to run the Malwarebytes and Virus Total scans tomorrow.
dredla is offline  
Old 09-10-2013, 05:02 AM   #15
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



You don't need to run gmer if you run MBAR.
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
Old 09-10-2013, 10:17 AM   #16
Registered Member
 
Join Date: Feb 2009
Posts: 133
OS: win xp



I'm running MBAR now. Everything's running very slowly. I expect to have a log report later this afternoon.
dredla is offline  
Old 09-10-2013, 04:33 PM   #17
Registered Member
 
Join Date: Feb 2009
Posts: 133
OS: win xp



MBAR still running seven hours later, just FYI
dredla is offline  
Old 09-10-2013, 07:04 PM   #18
Security Team
Moderator, Analyst
Rangemaster, TSF Academy
 
chemist's Avatar

Microsoft Most Valuable Professional
 
Join Date: Oct 2007
Location: Georgia
Posts: 29,790
OS: XP/Win7/Win10



Wow. Never seen it take that long. Let me know.
__________________
Our services are free, but you may contribute to the author of ComboFix via PayPal

Proud member of UNITE

Microsoft MVP - Consumer Security 2014, 2015
chemist is offline  
Old 09-10-2013, 10:14 PM   #19
Registered Member
 
Join Date: Feb 2009
Posts: 133
OS: win xp



12 hours now. Maybe it will be done by tomorrow morning. It has found 3 objects though.
dredla is offline  
Old 09-11-2013, 08:29 AM   #20
Registered Member
 
Join Date: Feb 2009
Posts: 133
OS: win xp



attached is the MBAR log.

I went to Virus Total this morning, but I am unable to paste the text you gave me into the "File name" box. Instead, I'm forced to browse my files. I tried to navigate to c:\documents and settings\all users\application data\qml16jdo3.plz, but no "application data" sub folder appears in the "all users" folder. I did a search for it, and it should be in the "all users" folder, but for some reason it's not showing up.
dredla is offline  
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
Internet Crime Complaint Center virus
Hello, I have got the Internet Crime Complaint Center virus, and I don't know how to remove it, I tried to do everything that says in removal guide, but non of safe modes works..If somebody knows how can I do it please help me Thank You!
Alice28 Windows 7 , Windows Vista Support 1 12-18-2012 07:59 PM
~*~Mixed Bag of Problems~*~
Hi, everyone! I have had a lot of problems with my computer lately and I'm hoping someone would be able to help me out. The most pressing issue right now is that my e-mail is sending out Spam links when I'm not even on my computer. The first time it happened, I changed my password, but tonight the...
TabbyCat725 Virus/Trojan/Spyware Help 156 07-09-2012 07:50 PM
Internet Explorer Loads & Uses Tons of Memory
Internet Explorer runs on it's own--in the background--and uses tons of memory. This is similar to a problem that a user named MalusCalibur had back in 2008. IE loads up and runs from 30K and climbs to anywhere from 100-300K of Memory. I've quelled this problem by constantly having Windows...
Deeke777 Virus/Trojan/Spyware Help 35 06-26-2012 01:11 PM

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is on
Smilies are on
[IMG] code is on
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Post a Question


» Site Navigation
 > FAQ
  > 10.0.0.2
Powered by vBadvanced CMPS v3.2.3


All times are GMT -7. The time now is 06:08 PM.


Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2020, vBulletin Solutions, Inc.
vBulletin Security provided by vBSecurity v2.2.2 (Pro) - vBulletin Mods & Addons Copyright © 2020 DragonByte Technologies Ltd.
User Alert System provided by Advanced User Tagging v3.1.0 (Pro) - vBulletin Mods & Addons Copyright © 2020 DragonByte Technologies Ltd.
Copyright 2001 - 2018, Tech Support Forum

Windows 10 - Windows 7 - Windows XP - Windows Vista - Trojan Removal - Spyware Removal - Virus Removal - Networking - Security - Top Web Hosts