Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Inactive Malware Help Topics

User Tag List

PC slow, BHOs added, trojans and adware keeps coming back

This is a discussion on PC slow, BHOs added, trojans and adware keeps coming back within the Inactive Malware Help Topics forums, part of the Tech Support Forum category. Hi, Iam having lots of trouble. Something is constantly adding BHOs, I disable them with BHODemon but more appear. I


 
 
Thread Tools Search this Thread
Old 10-05-2007, 10:22 AM   #1
Guest
 
Join Date: Oct 2007
Posts: 3
OS:



Hi, Iam having lots of trouble. Something is constantly adding BHOs, I disable them with BHODemon but more appear. I was having windows opening trying to get me to download winantivurus pro but this seems to have stopped for the time being. Adaware crashes so does spy sweeper. When I run spy sweeper in safe mode it finds virtumonde, I remove it but it comes back by the next scan.

I've run vundofix, this may have helped but my pc is still slow and AVG still keeps displaying that it is finding trojans such as Downloader.Generic4ZQI.

Panda activescan also found trojan Trj/Downloader.OZB.

Iam having trouble getting dss to work cos my cpu keeps going up to 100% usage and stalling for ages.

Here is my log not sure if I'll be able to get the extra bit from dss. Thanks for help.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:16:26, on 05/10/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\BHODemon 2\BHODemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\Administrator.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\WINNT\system32\taskmgr.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://google.co.uk/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1A02FE62-B851-4E7F-94CD-7CF6D70887BC} - C:\WINNT\system32\awtsp.dll (disabled by BHODemon)
O2 - BHO: (no name) - {1FC4A69B-863D-4613-88E6-BDB001F2AEF0} - (no file)
O2 - BHO: (no name) - {2AA25A47-A1AA-43F0-BBAA-3FDC2F1B2A0F} - C:\WINNT\system32\awtqq.dll (disabled by BHODemon)
O2 - BHO: (no name) - {2BDA66AE-6A3A-4E68-AA71-B1A16829394E} - C:\WINNT\system32\awtsr.dll (disabled by BHODemon)
O2 - BHO: (no name) - {45AD60C4-C089-465C-A939-81C65680BFB8} - (no file)
O2 - BHO: (no name) - {46F45847-6DED-4F1E-A37C-8381FB86DB9F} - (no file)
O2 - BHO: (no name) - {47ECA933-29C0-4DCA-AB12-70B715CFA3B5} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7C748AF2-4AC0-453D-9E86-BA8EEE53E5D6} - C:\WINNT\system32\vtsqp.dll
O2 - BHO: (no name) - {7F50393E-1C50-44B9-80A7-878627D49C8F} - C:\WINNT\system32\ssttu.dll (file missing)
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - (no file)
O2 - BHO: (no name) - {C0172DF6-BEBC-481C-86E8-847D49556783} - C:\WINNT\system32\ddaby.dll (file missing)
O2 - BHO: (no name) - {E84F70C5-17E8-4C1C-B596-674B52E16549} - C:\WINNT\system32\pmkjk.dll (file missing)
O2 - BHO: (no name) - {F9887586-4D3A-4690-B398-C5CF97497A14} - (no file)
O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [pdfFactory Dispatcher v2] "C:\WINNT\system32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINNT\system32\njkgobfi.dll",sitypnow
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: BHODemon 2.0.lnk = C:\Program Files\BHODemon 2\BHODemon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - https://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - https://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - https://update.microsoft.com/windowsu...?1151502492515
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - https://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://download.zonelabs.com/bin/pro...anner37940.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - https://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - https://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - https://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O20 - Winlogon Notify: yayvuut - C:\WINNT\SYSTEM32\yayvuut.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 6874 bytes
Andyhardcore is offline  
Sponsored Links
Advertisement
 
Old 10-08-2007, 09:00 PM   #2
TSF-Enthusiast
 
Aaflac's Avatar
 
Join Date: Mar 2007
Posts: 923
OS: XP Vista W7



Please disable BHODemon before proceeding with this next step.

Then, download ComboFix
Save it to the Desktop

Double-click combofix.exe to run the program
Follow the prompts.
(Don't click on the window while the program is running, it may cause your system to stall.)

When finished, a log, ComboFix.txt, is produced.

~~~~
Run HijackThis once again to obtain a new log.

~~~~
Please post the ComboFix.txt, and a new HijackThis log in your reply.
__________________
Aaflac is offline  
Old 10-09-2007, 11:15 AM   #3
Guest
 
Join Date: Oct 2007
Posts: 3
OS:



Thanks for your help. I installed Spybot S&D after the first post, I think it may have interfered with combofix. Im not sure if I allowed all the changes in time before it made my pc reboot.


Here is the combofix log:

ComboFix 07-10-09.3 - Administrator 09/10/2007 17:23:09.1 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.275 [GMT 1:00]
Script execution time was exceeded on script "C:\ComboFix\osid.vbs".
Script execution was terminated.
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\check_LSA7.txt
C:\WINNT\cookies.ini
C:\WINNT\hosts
C:\WINNT\system32\abmmmfoa.exe
C:\WINNT\system32\awtqq.dll
C:\WINNT\system32\bbeeg.bak1
C:\WINNT\system32\bbeeg.bak1
C:\WINNT\system32\bbeeg.ini
C:\WINNT\system32\bbeeg.ini
C:\WINNT\system32\bcbeg.bak1
C:\WINNT\system32\bcbeg.bak2
C:\WINNT\system32\bcbeg.ini
C:\WINNT\system32\bliilapo.exe
C:\WINNT\system32\cccdd.bak1
C:\WINNT\system32\cccdd.bak1
C:\WINNT\system32\cccdd.bak2
C:\WINNT\system32\cccdd.bak2
C:\WINNT\system32\cccdd.ini
C:\WINNT\system32\cccdd.ini
C:\WINNT\system32\ddccc.dll
C:\WINNT\system32\dpcxcjgu.exe
C:\WINNT\system32\efhkj.bak1
C:\WINNT\system32\efhkj.bak1
C:\WINNT\system32\efhkj.bak2
C:\WINNT\system32\efhkj.bak2
C:\WINNT\system32\efhkj.ini
C:\WINNT\system32\efhkj.ini
C:\WINNT\system32\ffhkj.bak1
C:\WINNT\system32\ffhkj.bak1
C:\WINNT\system32\ffhkj.ini
C:\WINNT\system32\ffhkj.ini
C:\WINNT\system32\fhhkj.bak1
C:\WINNT\system32\fhhkj.bak2
C:\WINNT\system32\fhhkj.ini
C:\WINNT\system32\geebb.dll
C:\WINNT\system32\ibiytbrl.exe
C:\WINNT\system32\jkhfe.dll
C:\WINNT\system32\jkhff.dll
C:\WINNT\system32\jkhff.dll
C:\WINNT\system32\mqouicbg.dll
C:\WINNT\system32\orsqseik.exe
C:\WINNT\system32\pmkjj.dll
C:\WINNT\system32\pqstv.bak1
C:\WINNT\system32\pqstv.bak1
C:\WINNT\system32\pqstv.bak2
C:\WINNT\system32\pqstv.bak2
C:\WINNT\system32\pqstv.ini
C:\WINNT\system32\pqstv.ini
C:\WINNT\system32\pstwa.bak1
C:\WINNT\system32\pstwa.ini
C:\WINNT\system32\qqtwa.bak1
C:\WINNT\system32\qqtwa.bak1
C:\WINNT\system32\qqtwa.bak2
C:\WINNT\system32\qqtwa.bak2
C:\WINNT\system32\qqtwa.ini
C:\WINNT\system32\qqtwa.ini
C:\WINNT\system32\rbironaq.exe
C:\WINNT\system32\uttss.bak1
C:\WINNT\system32\uttss.ini
C:\WINNT\system32\uvcoxxrk.dll
C:\WINNT\system32\vtsqp.dll
C:\WINNT\system32\xbeeg.bak1
C:\WINNT\system32\xbeeg.ini

.
((((((((((((((((((((((((( Files Created from 2007-09-09 to 2007-10-09 )))))))))))))))))))))))))))))))
.

2007-10-09 17:32 16,384 C:\WINNT\system32\Perflib_Perfdata_598.dat
2007-10-09 17:21 51,200 --a------ C:\WINNT\NirCmd.exe
2007-10-07 21:29 28,672 --a------ C:\WINNT\system32\drivers\CO_Mon.sys
2007-10-07 21:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2007-10-07 18:54 1,156 --a------ C:\WINNT\mozver.dat
2007-10-07 18:52 0 --a------ C:\WINNT\nsreg.dat
2007-10-07 18:37 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2007-10-06 21:16 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-04 17:52 824,332 ---hs---- C:\WINNT\system32\rstwa.bak2
2007-10-04 17:33 <DIR> d-------- C:\VundoFix Backups
2007-10-04 17:21 825,132 ---hs---- C:\WINNT\system32\rstwa.bak1
2007-10-03 22:41 <DIR> d-------- C:\ie-spyad_zo
2007-10-03 21:44 <DIR> d-------- C:\Program Files\BHODemon 2
2007-10-03 21:43 <DIR> d-------- C:\Program Files\Lavasoft
2007-10-03 21:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-03 21:11 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-10-02 19:38 813,261 ---hs---- C:\WINNT\system32\ybadd.bak2
2007-10-02 09:21 1,320,040 ---hs---- C:\WINNT\system32\kjkmp.bak1
2007-10-01 21:21 6,633 ---hs---- C:\WINNT\system32\kjkmp.bak2
2007-10-01 11:13 208,896 --a------ C:\WINNT\system32\wmpns.dll
2007-09-30 18:58 <DIR> d-------- C:\Documents and Settings\Andy\Application Data\Webroot
2007-09-29 14:39 163,128 --a------ C:\WINNT\system32\drivers\ssidrv.sys
2007-09-29 14:39 23,864 --a------ C:\WINNT\system32\drivers\sskbfd.sys
2007-09-29 14:39 21,816 --a------ C:\WINNT\system32\drivers\sshrmd.sys
2007-09-29 14:39 20,280 --a------ C:\WINNT\system32\drivers\SSFS0BB8.sys
2007-09-29 14:38 <DIR> d-------- C:\Program Files\Webroot
2007-09-29 14:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2007-09-29 14:38 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Webroot
2007-09-29 14:38 1,521,464 --a------ C:\WINNT\WRSetup.dll
2007-09-26 19:15 16,384 --a----t- C:\WINNT\system32\Perflib_Perfdata_2b0.dat
2007-09-26 17:35 164 --a------ C:\install.dat
2007-09-26 16:50 <DIR> d-------- C:\Documents and Settings\Administrator\.housecall6.6
2007-09-26 06:00 102,664 --a------ C:\WINNT\system32\drivers\tmcomm.sys
2007-09-22 20:22 <DIR> d-a------ C:\Documents and Settings\Andy\.housecall6.6
2007-09-20 20:26 34,816 --a------ C:\WINNT\system32\iifebcy.dll
2007-09-20 20:24 <DIR> d-------- C:\Program Files\LimeWire
2007-09-20 20:24 34,816 --a------ C:\WINNT\system32\yayvuut.dll
2007-09-20 16:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\iolo
2007-09-20 16:46 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\iolo
2007-09-20 07:10 <DIR> d-------- C:\Program Files\Xvid
2007-09-20 07:10 765,952 --a------ C:\WINNT\system32\xvidcore.dll
2007-09-20 07:10 180,224 --a------ C:\WINNT\system32\xvidvfw.dll
2007-09-19 17:23 <DIR> d-------- C:\Program Files\DivX
2007-09-18 21:04 <DIR> d-------- C:\Program Files\PeerGuardian2
2007-09-18 18:34 <DIR> d-a------ C:\Documents and Settings\Andy\Application Data\Azureus
2007-09-18 18:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
2007-09-18 18:33 <DIR> d-------- C:\Program Files\Azureus

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-06 10:22 --------- d-----w C:\Program Files\SpywareBlaster
2007-09-06 15:14 75,248 ----a-w C:\WINNT\zllsputility.exe
2007-09-06 15:14 1,086,952 ----a-w C:\WINNT\system32\zpeng24.dll
2007-07-30 18:19 92,504 ----a-w C:\WINNT\system32\cdm.dll
2007-07-30 18:19 549,720 ----a-w C:\WINNT\system32\wuapi.dll
2007-07-30 18:19 53,080 ----a-w C:\WINNT\system32\wuauclt.exe
2007-07-30 18:19 43,352 ----a-w C:\WINNT\system32\wups2.dll
2007-07-30 18:19 325,976 ----a-w C:\WINNT\system32\wucltui.dll
2007-07-30 18:19 203,096 ----a-w C:\WINNT\system32\wuweb.dll
2007-07-30 18:19 1,712,984 ----a-w C:\WINNT\system32\wuaueng.dll
2007-07-30 18:18 33,624 ----a-w C:\WINNT\system32\wups.dll
2007-07-26 23:06 200,704 ----a-w C:\WINNT\system32\ssldivx.dll
2007-07-26 23:06 1,044,480 ----a-w C:\WINNT\system32\libdivx.dll
2007-07-12 19:30 57,344 ----a-w C:\WINNT\uneng.exe
2007-07-12 19:30 49,152 ----a-w C:\WINNT\system32\cdrtc.dll
2007-07-12 19:30 45,056 ----a-w C:\WINNT\system32\cdral.dll
2005-04-22 09:16 271 ---h--w C:\Program Files\desktop.ini
2005-04-22 09:16 21,952 ---h--w C:\Program Files\folder.htt
2002-07-24 12:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
2007-05-04 15:46:58 825,132 --sh--w C:\WINNT\system32\rstwa.bak1
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{16A1FF10-70A7-479F-9312-01A272BA5609}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A02FE62-B851-4E7F-94CD-7CF6D70887BC}]
C:\WINNT\system32\awtsp.dll__BHODemonDisabled_YDRBFVBLPBQFQOBSAKAIEOAJZLN

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1FC4A69B-863D-4613-88E6-BDB001F2AEF0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2BDA66AE-6A3A-4E68-AA71-B1A16829394E}]
C:\WINNT\system32\awtsr.dll__BHODemonDisabled_VMSDKMGYRFMMMVTC

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3C939157-5817-407D-B6B9-92A0878A22DF}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{45AD60C4-C089-465C-A939-81C65680BFB8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{46F45847-6DED-4F1E-A37C-8381FB86DB9F}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{47ECA933-29C0-4DCA-AB12-70B715CFA3B5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{75AF647B-A702-4CAD-B509-09D393649968}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C748AF2-4AC0-453D-9E86-BA8EEE53E5D6}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7F50393E-1C50-44B9-80A7-878627D49C8F}]
C:\WINNT\system32\ssttu.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7FDD579D-3ED0-4FEA-BC5C-76E450431AFD}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8D768C75-563C-44A0-9035-46967A8EFBD3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C0172DF6-BEBC-481C-86E8-847D49556783}]
C:\WINNT\system32\ddaby.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E84F70C5-17E8-4C1C-B596-674B52E16549}]
C:\WINNT\system32\pmkjk.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F36BF1E0-B513-4102-B1B4-B5050EDD91B9}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9887586-4D3A-4690-B398-C5CF97497A14}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FC43B9CB-8CA3-4634-8AA5-B2E59BBFA0C8}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 12:05 C:\WINNT\system32\mobsync.exe]
"pdfFactory Dispatcher v2"="C:\WINNT\system32\spool\DRIVERS\W32X86\3\fppdis2a.exe" [05-02-13 22:45 ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [07-09-15 08:55 ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [07-05-11 03:06 ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [07-07-12 04:00 ]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [07-09-06 16:14 ]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [07-08-31 16:46 ]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
BHODemon 2.0.lnk - C:\Program Files\BHODemon 2\BHODemon.exe [2005-06-19 12:59:30]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4F8C5BB1-8D81-497D-8E4C-4F81490B8FB8}"= C:\WINNT\system32\yayvuut.dll [07-09-20 20:24 34816]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayvuut]
yayvuut.dll 07-09-20 20:24 34816 C:\WINNT\system32\yayvuut.dll

R0 SSFS0BB8;Spy Sweeper File System Filer Driver: 0BB8;C:\WINNT\system32\Drivers\SSFS0BB8.SYS
R1 Avg7RsNT;AVG7 Resident Driver NT;C:\WINNT\system32\Drivers\avg7rsnt.sys
R2 Belkin 54g Wireless USB Network Adapter Service;Belkin 54g Wireless USB Network Adapter;C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
R3 bkn50USB;Belkin 54Mbps Wireless USB Network Adapter;C:\WINNT\system32\DRIVERS\rt2500usb.sys
S3 pgfilter;pgfilter;\??\C:\Program Files\PeerGuardian2\pgfilter.sys

*Newly Created Service* - IPNAT
*Newly Created Service* - SHAREDACCESS
.
Contents of the 'Scheduled Tasks' folder
"2007-10-07 05:00:07 C:\WINNT\Tasks\wrSpySweeper_LAD8D53F789804F6585ED8D14EB274160.job"
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, https://www.gmer.net
Rootkit scan 2007-10-09 17:32:45
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-09 17:34:43 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-10-09 17:34
.
--- E O F ---

And the Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:09:36, on 09/10/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\BHODemon 2\BHODemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\NOTEPAD.EXE
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://google.co.uk/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {16A1FF10-70A7-479F-9312-01A272BA5609} - (no file)
O2 - BHO: (no name) - {1A02FE62-B851-4E7F-94CD-7CF6D70887BC} - C:\WINNT\system32\awtsp.dll (disabled by BHODemon)
O2 - BHO: (no name) - {1FC4A69B-863D-4613-88E6-BDB001F2AEF0} - (no file)
O2 - BHO: (no name) - {2BDA66AE-6A3A-4E68-AA71-B1A16829394E} - C:\WINNT\system32\awtsr.dll (disabled by BHODemon)
O2 - BHO: (no name) - {3C939157-5817-407D-B6B9-92A0878A22DF} - (no file)
O2 - BHO: (no name) - {45AD60C4-C089-465C-A939-81C65680BFB8} - (no file)
O2 - BHO: (no name) - {46F45847-6DED-4F1E-A37C-8381FB86DB9F} - (no file)
O2 - BHO: (no name) - {47ECA933-29C0-4DCA-AB12-70B715CFA3B5} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {75AF647B-A702-4CAD-B509-09D393649968} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7C748AF2-4AC0-453D-9E86-BA8EEE53E5D6} - (no file)
O2 - BHO: (no name) - {7F50393E-1C50-44B9-80A7-878627D49C8F} - C:\WINNT\system32\ssttu.dll (file missing)
O2 - BHO: (no name) - {7FDD579D-3ED0-4FEA-BC5C-76E450431AFD} - (no file)
O2 - BHO: (no name) - {8D768C75-563C-44A0-9035-46967A8EFBD3} - (no file)
O2 - BHO: (no name) - {C0172DF6-BEBC-481C-86E8-847D49556783} - C:\WINNT\system32\ddaby.dll (file missing)
O2 - BHO: (no name) - {E84F70C5-17E8-4C1C-B596-674B52E16549} - C:\WINNT\system32\pmkjk.dll (file missing)
O2 - BHO: (no name) - {F36BF1E0-B513-4102-B1B4-B5050EDD91B9} - (no file)
O2 - BHO: (no name) - {F9887586-4D3A-4690-B398-C5CF97497A14} - (no file)
O2 - BHO: (no name) - {FC43B9CB-8CA3-4634-8AA5-B2E59BBFA0C8} - (no file)
O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [pdfFactory Dispatcher v2] "C:\WINNT\system32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: BHODemon 2.0.lnk = C:\Program Files\BHODemon 2\BHODemon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - https://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - https://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - https://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - https://update.microsoft.com/windowsu...?1151502492515
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - https://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - https://www.nvidia.com/content/Driver...sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - https://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - https://www.nvidia.com/content/Driver...aSmartScan.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://download.zonelabs.com/bin/pro...anner37940.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - https://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - https://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - https://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
O20 - Winlogon Notify: yayvuut - C:\WINNT\SYSTEM32\yayvuut.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 8197 bytes
Andyhardcore is offline  
Sponsored Links
Advertisement
 
Old 10-10-2007, 09:05 PM   #4
TSF-Enthusiast
 
Aaflac's Avatar
 
Join Date: Mar 2007
Posts: 923
OS: XP Vista W7



My apology for the delay.

Will get back with you tomorrow, and we'll be doing some clean-up.

Thank you for your patience.
__________________
Aaflac is offline  
Old 10-11-2007, 09:47 AM   #5
TSF-Enthusiast
 
Aaflac's Avatar
 
Join Date: Mar 2007
Posts: 923
OS: XP Vista W7



Please open Notepad (Start > Run > in the Open field type: notepad)
Click: OK

Copy/paste the blue text below to Notepad:

File::
C:\WINNT\system32\rstwa.bak2
C:\WINNT\system32\rstwa.bak1
C:\WINNT\system32\ybadd.bak2
C:\WINNT\system32\kjkmp.bak1
C:\WINNT\system32\kjkmp.bak2
C:\WINNT\system32\iifebcy.dll
C:\WINNT\system32\yayvuut.dll
C:\WINNT\system32\awtsp.dll
C:\WINNT\system32\awtsr.dll
C:\WINNT\system32\ssttu.dll
C:\WINNT\system32\ddaby.dll
C:\WINNT\system32\pmkjk.dll

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{16A1FF10-70A7-479F-9312-01A272BA5609}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1A02FE62-B851-4E7F-94CD-7CF6D70887BC}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FC4A69B-863D-4613-88E6-BDB001F2AEF0}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2BDA66AE-6A3A-4E68-AA71-B1A16829394E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3C939157-5817-407D-B6B9-92A0878A22DF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45AD60C4-C089-465C-A939-81C65680BFB8}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{46F45847-6DED-4F1E-A37C-8381FB86DB9F}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75AF647B-A702-4CAD-B509-09D393649968}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C748AF2-4AC0-453D-9E86-BA8EEE53E5D6}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F50393E-1C50-44B9-80A7-878627D49C8F}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7FDD579D-3ED0-4FEA-BC5C-76E450431AFD}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D768C75-563C-44A0-9035-46967A8EFBD3}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0172DF6-BEBC-481C-86E8-847D49556783}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E84F70C5-17E8-4C1C-B596-674B52E16549}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F36BF1E0-B513-4102-B1B4-B5050EDD91B9}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9887586-4D3A-4690-B398-C5CF97497A14}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC43B9CB-8CA3-4634-8AA5-B2E59BBFA0C8}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4F8C5BB1-8D81-497D-8E4C-4F81490B8FB8}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayvuut]



Save as CFScript.txt <-Important!!
Change the Save as type to: All Files
Save it to the Desktop.




Referring to the screenshot above, drag CFScript.txt >>> into >>> ComboFix.exe
ComboFix runs a scan on your system, and may reboot when it finishes. This is normal.

CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

When finished, a log is produced: ComboFix.txt

~~~~
Please run HijackThis once again to obtain a new log.

~~~~
Please provide the contents of the new ComboFix.txt in your next reply, as well as the new HijackThis log.
__________________
Aaflac is offline  
Old 10-13-2007, 12:55 PM   #6
Guest
 
Join Date: Oct 2007
Posts: 3
OS:



I was unable to do the above steps as the computer is so bad it wont boot any more. It blue screens even if I try to boot into safe mode with a message that says the drive may have been affected by a virus or there maybe a fault with the IDE controller. Before this I got a buffer overun error and AVG and zonealarm wouldn't load. So I think its pretty much had it and looks like formatting the hard drive is the only option. Thanks anyway for your help.
Andyhardcore is offline  
Old 10-13-2007, 03:42 PM   #7
TSF-Enthusiast
 
Aaflac's Avatar
 
Join Date: Mar 2007
Posts: 923
OS: XP Vista W7



Sometimes the best solution is to format and reinstall Windows. You will have the reassurance that the system is clean after you do.

When you go this route, start the format, and make sure you are not connected to the Internet (unplug dial-up, DSL, cable, wireless ) when you install the Operating System.

Once Windows is installed, if there is an Internet connection present, you can get re-infected immediately, since there is no protection is present. So, after the OS is on board, install an Antivirus program and a Firewall, reboot, connect to the Internet, and install Service Pack2.

~~~~
Last, install whatever other programs you wish after the computer has protection.

~~~~
Some of the best suggestions and programs to remain malware free are contained in Tony Kleinís article:
How Did I Get Infected In The First Place

It is also a very good practice to perform an online virus scan on a regular basis.
Scanners do not have identical malware definitions, and what one misses, another one can catch.
Some of the scanners are:
BitDefender Online Scanner
ESET NOD32 Online Scanner
F-Secure Online Scanner
Panda ActiveScan
TrendMicro HouseCall

~~~~
If you have any questions or comments, post back. Otherwise...

Good luck, Andyhardcore!
__________________
Aaflac is offline  
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is on
Smilies are on
[IMG] code is on
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Post a Question


» Site Navigation
 > FAQ
  > 10.0.0.2
Powered by vBadvanced CMPS v3.2.3


All times are GMT -7. The time now is 05:32 AM.


Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2020, vBulletin Solutions, Inc.
vBulletin Security provided by vBSecurity v2.2.2 (Pro) - vBulletin Mods & Addons Copyright © 2020 DragonByte Technologies Ltd.
User Alert System provided by Advanced User Tagging v3.1.0 (Pro) - vBulletin Mods & Addons Copyright © 2020 DragonByte Technologies Ltd.
Copyright 2001 - 2018, Tech Support Forum

Windows 10 - Windows 7 - Windows XP - Windows Vista - Trojan Removal - Spyware Removal - Virus Removal - Networking - Security - Top Web Hosts