Jump to content


Photo

about:blank AND icanfindit.net


  • Please log in to reply
5 replies to this topic

#1 charder

charder

    Member

  • Full Member
  • Pip
  • 8 posts

Posted 24 July 2004 - 03:00 PM

I've run the usual programs ad infinitum. The damn thing keeps reappearing..sometimes as about:blank, or lately more icanfindit.net and 4-counter.net. Strange new twist: ia "web dialer" window pops up. This is the moment when all thr crap comes back into tye favorites and the redirects begin. Here's my Hijack log fresh after running Spyhunter and adaware. Please help. I'm losing a lot of time with this plague.

Logfile of HijackThis v1.97.7
Scan saved at 12:52:52 PM, on 7/24/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\basfipm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\System32\gearsec.exe
c:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\system32\scagent.exe
C:\Program Files\Norton Speed Disk\nopdb.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\winproc32.exe
C:\WINDOWS\ntSPsy64s-.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Olympus\DSSPlayerPro\DevDtct.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\chrish\Desktop\security applications\HijackThis.exe

O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\System32\MtyJ62F.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [d3wv32.exe] C:\WINDOWS\system32\d3wv32.exe
O4 - HKLM\..\Run: [bkrtiirq] C:\WINDOWS\System32\afurhmgx.exe
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft Money\System\reminder.exe
O4 - HKCU\..\Run: [Zinio DLM] C:\PROGRA~1\Zinio\ZDLM.exe /hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpywareGuard] C:\WINDOWS\system32\winproc32.exe
O4 - HKCU\..\Run: [Windows Update Checker] C:\WINDOWS\ntSPsy64s-.exe
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DeviceDetect.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com...ex/qtplugin.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = esri.com
O17 - HKLM\Software\..\Telephony: DomainName = esri.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{3D68FA43-7D1C-46E4-B73E-C29D8284C6A6}: Domain = esri.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{A0EB3F58-1AAD-40E8-9D18-B7DA5A985E6C}: Domain = esri.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = esri.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{3D68FA43-7D1C-46E4-B73E-C29D8284C6A6}: Domain = esri.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = esri.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{3D68FA43-7D1C-46E4-B73E-C29D8284C6A6}: Domain = esri.com

Christian Harder
charder@esri.com

#2 mmxx66

mmxx66

    The SWI drummer

  • Retired Staff
  • PipPipPipPipPip
  • 4,412 posts

Posted 24 July 2004 - 06:49 PM

Print out these instructions so you can read them while you clean your system.

Download PeperFix
Save it to your Desktop.
Click on the PeperFix.exe to launch it.

Click the Find and Fix button.

It will scan the %Systemroot% folder and locate all the peper files. You will be prompted to reboot. Reboot and it will delete the peper files.
Ensure that you are online before starting the fix. Make sure to run the fix twice.

Move Hijack This to its own folder.Click My Computer, then C:\
In the menu bar, File->New->Folder.
That will create a folder named New Folder, which you can rename to "HJT" or "HijackThis". Now you have C:\HJT\ folder. Move hijack this there. Hijack this makes backups of everything you fix, these backups are saved in the same folder the program is.


Now close all open windows AND browsers and check these items for HJT to fix:
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\System32\MtyJ62F.exe
O4 - HKLM\..\Run: [d3wv32.exe] C:\WINDOWS\system32\d3wv32.exe
O4 - HKLM\..\Run: [bkrtiirq] C:\WINDOWS\System32\afurhmgx.exe
O4 - HKCU\..\Run: [SpywareGuard] C:\WINDOWS\system32\winproc32.exe
O4 - HKCU\..\Run: [Windows Update Checker] C:\WINDOWS\ntSPsy64s-.exe



Please reboot into safe mode - How do I boot into "Safe" mode?


Delete these files:

C:\WINDOWS\System32\MtyJ62F.exe
C:\WINDOWS\system32\d3wv32.exe
C:\WINDOWS\System32\afurhmgx.exe
C:\WINDOWS\system32\winproc32.exe
C:\WINDOWS\ntSPsy64s-.exe


You may need to show hidden files to delete them.How to show all hidden and system files

The following DIRECTORY CONTENTS (But not the directory) need to be deleted while in safe mode.
* C:\Windows\Temp\
* C:\Documents and Settings\<Your Profile>\Local Settings\Temporary Internet Files\ <=This will delete all your cached internet
content including cookies. This is recommended and strongly suggested.
* C:\Documents and Settings\<Your Profile>\Local Settings\Temp\
* C:\Documents and Settings\<Any other users Profile>\Local Settings\Temporary Internet Files\
* C:\Documents and Settings\<Any other users Profile>\Local Settings\Temp\
* Empty your "Recycle Bin".

Then disable your system restore

1 Right-click My Computer, and then click Properties.
2 Click the System Restore tab.
3 Check the "Turn off System Restore" or "Turn off System Restore on all drives" check box.
4 Click Apply
5 this will delete all existing restore points. Click Yes to do this.
6 Click OK.

Reboot into normal mode enable System Restore and post a fresh log in this thread to give you further recommendations.

#3 charder

charder

    Member

  • Full Member
  • Pip
  • 8 posts

Posted 29 July 2004 - 12:01 PM

OK, things are going much better now. I'm still picking up a lot of crap everytime I run Adaware, and some pop-ups, but the dreaded about:blank and CWS seem vanquished FINALLY. Here's my current log

Logfile of HijackThis v1.97.7
Scan saved at 10:00:16 AM, on 7/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\System32\basfipm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\System32\gearsec.exe
c:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Norton Speed Disk\nopdb.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\mcdntcls.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\atkcad32.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Olympus\DSSPlayerPro\DevDtct.exe
C:\WINDOWS\System32\WISPTIS.EXE
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\chrish\Desktop\security applications\hjt\HijackThis.exe

O2 - BHO: Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} - C:\Program Files\Recommended Hotfix - 421701D\v15\RH.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {C258A4CC-B39C-4396-B24F-5989EF0EC047} - C:\WINDOWS\System32\vzyoo.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKLM\..\Run: [000hpdllhost] C:\WINDOWS\System32\hpdllhost.exe
O4 - HKLM\..\Run: [736j33U] mcdntcls.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [M0ptRTY8T] atkcad32.exe
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DeviceDetect.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com...ex/qtplugin.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297B} - http://downloads.aaa...t-aug-acx13.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = esri.com
O17 - HKLM\Software\..\Telephony: DomainName = esri.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{3D68FA43-7D1C-46E4-B73E-C29D8284C6A6}: Domain = esri.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{A0EB3F58-1AAD-40E8-9D18-B7DA5A985E6C}: Domain = esri.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = esri.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{3D68FA43-7D1C-46E4-B73E-C29D8284C6A6}: Domain = esri.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = esri.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{3D68FA43-7D1C-46E4-B73E-C29D8284C6A6}: Domain = esri.com

#4 mmxx66

mmxx66

    The SWI drummer

  • Retired Staff
  • PipPipPipPipPip
  • 4,412 posts

Posted 29 July 2004 - 12:13 PM

Not clean yet.

close all open windows AND browsers and check these items for HJT to fix:

O2 - BHO: Recommended Hotfix - {0421701D-CF13-4E70-ADF0-45A953E7CB8B} - C:\Program Files\Recommended Hotfix - 421701D\v15\RH.DLL
O2 - BHO: (no name) - {C258A4CC-B39C-4396-B24F-5989EF0EC047} - C:\WINDOWS\System32\vzyoo.dll
O4 - HKLM\..\Run: [736j33U] mcdntcls.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKCU\..\Run: [M0ptRTY8T] atkcad32.exe

Restart in safe mode.

Go to Add/Remove Programs and uninstall
AutoUpdate
Recommended Hotfix

if listed.

Delete the files:
C:\WINDOWS\System32\vzyoo.dll
C:\WINDOWS\System32\atkcad32.exe
C:\WINDOWS\System32\mcdntcls.exe

Delete the folders
C:\Program Files\AutoUpdate
C:\Program Files\Recommended Hotfix

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:


Temporary Files
Temporary Internet Files
Recycle Bin


Reboot to normal mode, scan again with Hijack This and post a new log here.

#5 charder

charder

    Member

  • Full Member
  • Pip
  • 8 posts

Posted 31 July 2004 - 11:32 AM

First let me thank you and whoever started this forum. We're in your debt, and based on the volume of new posts, this crap is spreading like the plague. I'm shocked at how "MAL" this Malware really can be. What an ordeal.

Anyway here's my latest HJT log created just after running CWT, Spybot, and Adaware in safe mode. I am clean yet?

Logfile of HijackThis v1.97.7
Scan saved at 9:24:32 AM, on 7/31/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\basfipm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\System32\gearsec.exe
c:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Norton Speed Disk\nopdb.exe
C:\WINDOWS\System32\CCM\CcmExec.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\System32\ipvhon21.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\wsthrui.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Olympus\DSSPlayerPro\DevDtct.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\chrish\Desktop\security applications\hjt\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKLM\..\Run: [736j33U] ipvhon21.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [M0ptRTY8T] wsthrui.exe
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DeviceDetect.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com...ex/qtplugin.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = esri.com
O17 - HKLM\Software\..\Telephony: DomainName = esri.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{3D68FA43-7D1C-46E4-B73E-C29D8284C6A6}: Domain = esri.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{A0EB3F58-1AAD-40E8-9D18-B7DA5A985E6C}: Domain = esri.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = esri.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{3D68FA43-7D1C-46E4-B73E-C29D8284C6A6}: Domain = esri.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = esri.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{3D68FA43-7D1C-46E4-B73E-C29D8284C6A6}: Domain = esri.com

#6 mmxx66

mmxx66

    The SWI drummer

  • Retired Staff
  • PipPipPipPipPip
  • 4,412 posts

Posted 31 July 2004 - 12:26 PM

Not yet.
DO not reboot

Right click on the task bar, go to Task Manager, in the processes tab stop these processes:
ipvhon21.exe
wsthrui.exe


Close all open windows AND browsers and check these items for HJT to fix:

O4 - HKLM\..\Run: [736j33U] ipvhon21.exe
O4 - HKCU\..\Run: [M0ptRTY8T] wsthrui.exe


Delete these files:
C:\WINDOWS\System32\ ipvhon21.exe
C:\WINDOWS\System32\ wsthrui.exe

Scan with Adaware and let it remove any bad files found

Finally, do an online scan HERE. Let it remove any infected files found.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button