Ok I need a lot of help!

View previous topic View next topic Go down

Solved Ok I need a lot of help!

Post by Seldom Fail on Sun Feb 22, 2009 6:31 pm

K so I recently had a virus on my computer. It was called "Virus Doctor". I downloaded a couple things from GeekPolice and that got the virus off... but ever since, whenever I search things on Google, the top 5 links usually redirect me to some stupid porn sites! And my parents ARE NOT HAPPY.

I downloaded firefox on our family desktop computer downstairs to see if it was the browser. It's not. I think it might be a malware item on my computer. Any ideas on how to fix this?!?

Seldom Fail
Intermediate
Intermediate

Status :
Online
Offline

Posts : 149
Joined : 2009-02-16
Gender : Male
OS : Windows 7

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Belahzur on Sun Feb 22, 2009 6:51 pm

Hello.
Please read here and post a Hijack This log.
[You must be registered and logged in to see this link.]


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Seldom Fail on Sun Feb 22, 2009 6:57 pm

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:55:55 PM, on 2/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Christy\Desktop\hijackgpthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HotSync] "C:\Program Files\PalmSource\Desktop\HotSync.exe" -AllUsers
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Wireless-G Notebook Adapter.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

--
End of file - 7021 bytes

Seldom Fail
Intermediate
Intermediate

Status :
Online
Offline

Posts : 149
Joined : 2009-02-16
Gender : Male
OS : Windows 7

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Belahzur on Sun Feb 22, 2009 7:04 pm

I know of two common Google hijackers, so lets see if I can find it.

  • Now open a new notepad file.
  • Input this into the notepad file:

    regedit /e C:\report.txt "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32"
    start notepad C:\report.txt

  • Save this as look.bat, save it to your desktop.
  • Double click look.bat to run it.
  • Copy and paste the report back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Seldom Fail on Sun Feb 22, 2009 7:05 pm

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midimapper"="midimap.dll"
"msacm.imaadpcm"="imaadp32.acm"
"msacm.msadpcm"="msadp32.acm"
"msacm.msg711"="msg711.acm"
"msacm.msgsm610"="msgsm32.acm"
"msacm.trspch"="tssoft32.acm"
"vidc.cvid"="iccvid.dll"
"vidc.I420"="msh263.drv"
"vidc.iv31"="ir32_32.dll"
"vidc.iv32"="ir32_32.dll"
"vidc.iv41"="ir41_32.ax"
"vidc.iyuv"="iyuv_32.dll"
"vidc.mrle"="msrle32.dll"
"vidc.msvc"="msvidc32.dll"
"vidc.uyvy"="msyuv.dll"
"vidc.yuy2"="msyuv.dll"
"vidc.yvu9"="tsbyuv.dll"
"vidc.yvyu"="msyuv.dll"
"wavemapper"="msacm32.drv"
"msacm.msg723"="msg723.acm"
"vidc.M263"="msh263.drv"
"vidc.M261"="msh261.drv"
"msacm.msaudio1"="msaud32.acm"
"msacm.sl_anet"="sl_anet.acm"
"msacm.iac2"="C:\\WINDOWS\\system32\\iac25_32.ax"
"vidc.iv50"="ir50_32.dll"
"msacm.l3acm"="C:\\WINDOWS\\system32\\l3codeca.acm"
"wave"="wdmaud.drv"
"midi"="wdmaud.drv"
"mixer"="wdmaud.drv"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\Terminal Server]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32\Terminal Server\RDP]
"wave"="rdpsnd.dll"
"mixer"="rdpsnd.dll"
"MaxBandwidth"=dword:000056b9
"wavemapper"="msacm32.drv"
"EnableMP3Codec"=dword:00000001
"midimapper"="midimap.dll"

Seldom Fail
Intermediate
Intermediate

Status :
Online
Offline

Posts : 149
Joined : 2009-02-16
Gender : Male
OS : Windows 7

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Belahzur on Sun Feb 22, 2009 7:13 pm

Okay, it's not that.


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run
  • When complete, DDS.txt will open.
  • Save the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.


Please download [You must be registered and logged in to see this link.] and save it to your Desktop. Double-click Goored.exe to run it. Select 1. Find Goored (no fix) by typing 1 and pressing Enter. A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt). Note: Do not run Option #2 yet.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Seldom Fail on Sun Feb 22, 2009 7:19 pm

Copy and paste DDS.txt back here, I don't need to see attach.txt.
You want me to copy the stuff from the notepad document and paste it here?

Goored log:
GooredFix v1.91 by jpshortstuff
Log created at 13:18 on 22/02/2009 running Option #1 (Christy)
Firefox version 3.0.6 (en-US)

=====Suspect Goored Entries=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.6\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.6\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"jqs@sun.com"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"

Seldom Fail
Intermediate
Intermediate

Status :
Online
Offline

Posts : 149
Joined : 2009-02-16
Gender : Male
OS : Windows 7

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Belahzur on Sun Feb 22, 2009 7:21 pm

Hmm, it' not Goored neither.
DDS makes two report, DDS.txt and attach.txt.

Please post DDS.txt.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Seldom Fail on Sun Feb 22, 2009 7:24 pm

DDS (Ver_09-02-01.01) - NTFSx86
Run by Christy at 13:16:09.84 on Sun 02/22/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.478.109 [GMT -6:00]

AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\Gcc.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\OdHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Christy\Desktop\dds.com
C:\Documents and Settings\Christy\Desktop\dds.com

============== Pseudo HJT Report ===============

uStart Page = [You must be registered and logged in to see this link.]
uSearch Page = [You must be registered and logged in to see this link.]
uSearch Bar = [You must be registered and logged in to see this link.]
mDefault_Page_URL = [You must be registered and logged in to see this link.]
mDefault_Search_URL = [You must be registered and logged in to see this link.]
mSearch Page = [You must be registered and logged in to see this link.]
mStart Page = [You must be registered and logged in to see this link.]
mSearch Bar = [You must be registered and logged in to see this link.]
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
BHO: NoExplorer - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
uRun: [RecordNow!]
uRun: [YSearchProtection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [AdobeUpdater] c:\program files\common files\adobe\updater5\AdobeUpdater.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [HotSync] "c:\program files\palmsource\desktop\HotSync.exe" -AllUsers
dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palm\Hotsync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\program files\linksys\wireless-g notebook adapter\Gcc.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - [You must be registered and logged in to see this link.]
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - [You must be registered and logged in to see this link.]
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [You must be registered and logged in to see this link.]
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\christy\applic~1\mozilla\firefox\profiles\v1hq5pxy.default\
FF - plugin: c:\progra~1\palm\packag~1\NPInstal.dll

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;c:\program files\antivir personaledition classic\avgio.sys [2007-8-16 11840]
R1 IKFileFlt;File Filter Driver;c:\windows\system32\drivers\ikfileflt.sys [2007-8-16 39376]
R1 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2007-8-16 53840]
R1 IkSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2007-8-16 57424]
R1 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2007-8-16 83024]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\adobe\photoshop elements 7.0\PhotoshopElementsFileAgent.exe [2008-9-16 163840]
R2 AntiVirScheduler;AntiVir PersonalEdition Classic Scheduler;c:\program files\antivir personaledition classic\sched.exe [2007-8-16 68865]
R2 AntiVirService;AntiVir PersonalEdition Classic Guard;c:\program files\antivir personaledition classic\avguard.exe [2007-8-16 151297]
R2 sdAuxService;Spyware Doctor Auxiliary Service;c:\program files\spyware doctor\svcntaux.exe [2007-8-16 708688]
R2 sdCoreService;Spyware Doctor Service;c:\program files\spyware doctor\swdsvc.exe [2007-8-16 1309264]
R3 avgntflt;avgntflt;c:\program files\antivir personaledition classic\avgntflt.sys [2007-8-16 52032]

=============== Created Last 30 ================

2009-02-16 12:51 --d----- c:\docume~1\christy\applic~1\Malwarebytes
2009-02-16 12:50 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-02-14 14:44 --d----- C:\System Data Configuration
2009-02-14 14:44 1,718,272 a------- C:\VDoctor.exe
2009-02-14 14:44 --dsh--- c:\docume~1\alluse~1\applic~1\System Data Configuration
2009-02-14 14:43 --dsh--- c:\docume~1\alluse~1\applic~1\b5e6c62
2009-02-12 14:46 --d----- c:\windows\pss
2009-02-08 11:58 --d----- c:\program files\common files\Macrovision Shared
2009-02-08 11:41 129,784 -------- c:\windows\system32\pxafs.dll
2009-02-08 11:41 118,520 -------- c:\windows\system32\pxinsi64.exe
2009-02-08 11:41 116,472 -------- c:\windows\system32\pxcpyi64.exe
2009-02-08 11:41 9,464 -------- c:\windows\system32\drivers\cdralw2k.sys
2009-02-08 11:41 9,336 -------- c:\windows\system32\drivers\cdr4_xp.sys
2009-02-07 11:38 --d----- c:\windows\.file_store_32
2009-02-03 20:38 16,640 a----r-- c:\windows\system32\drivers\PalmUSBD.sys
2009-02-03 20:12 --d----- c:\program files\Palm

==================== Find3M ====================

2009-02-08 11:41 43,528 -------- c:\windows\system32\drivers\pxhelp20.sys
2009-02-07 11:40 34 a------- c:\documents and settings\christy\jagex_runescape_preferences.dat
2009-01-10 19:26 410,984 a------- c:\windows\system32\deploytk.dll
2007-08-17 08:51 5 a--sh--- c:\windows\system32\bfeaaac7_d.dll
2008-10-25 11:09 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008102520081026\index.dat

============= FINISH: 13:16:33.97 ===============

Seldom Fail
Intermediate
Intermediate

Status :
Online
Offline

Posts : 149
Joined : 2009-02-16
Gender : Male
OS : Windows 7

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Belahzur on Sun Feb 22, 2009 7:32 pm

Hello.

Download [You must be registered and logged in to see this link.]

  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
If you use Firefox browser, do this also:

  • Click Firefox at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser, do this also:

  • Click Opera at the top and choose Select All from the list.
  • Click the Empty Selected button.
  • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Please download the [You must be registered and logged in to see this link.].

  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :files
    C:\VDoctor.exe
    c:\docume~1\alluse~1\applic~1\b5e6c62
    c:\windows\system32\bfeaaac7_d.dll


  • Return to OTMoveIt3, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Seldom Fail on Sun Feb 22, 2009 7:37 pm

========== FILES ==========
C:\VDoctor.exe moved successfully.
c:\docume~1\alluse~1\applic~1\b5e6c62\System Data Configuration moved successfully.
c:\docume~1\alluse~1\applic~1\b5e6c62\BackUp moved successfully.
c:\docume~1\alluse~1\applic~1\b5e6c62 moved successfully.
LoadLibrary failed for c:\windows\system32\bfeaaac7_d.dll
c:\windows\system32\bfeaaac7_d.dll NOT unregistered.
c:\windows\system32\bfeaaac7_d.dll moved successfully.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02222009_133641

Seldom Fail
Intermediate
Intermediate

Status :
Online
Offline

Posts : 149
Joined : 2009-02-16
Gender : Male
OS : Windows 7

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Belahzur on Sun Feb 22, 2009 7:38 pm

Hello.
Do you know what this folder is?
C:\System Data Configuration


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Seldom Fail on Sun Feb 22, 2009 7:49 pm

Umm... no...
And this file...:
C:\VDoctor.exe
IS THAT VIRUS DOCTOR? THE VIRUS I HAD IN THE FIRST PLACE?

Seldom Fail
Intermediate
Intermediate

Status :
Online
Offline

Posts : 149
Joined : 2009-02-16
Gender : Male
OS : Windows 7

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Belahzur on Sun Feb 22, 2009 7:51 pm

Maybe, that's why I listed it in OTMoveIt
Okay, since you don't know what that folder is, we'll remove it with OTMoveIt again.

  • Please double-click OTMoveIt3.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :files
    c:\docume~1\alluse~1\applic~1\System Data Configuration
    C:\System Data Configuration


  • Return to OTMoveIt3, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Seldom Fail on Sun Feb 22, 2009 7:54 pm

========== FILES ==========
c:\docume~1\alluse~1\applic~1\System Data Configuration moved successfully.
C:\System Data Configuration moved successfully.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02222009_135336

Seldom Fail
Intermediate
Intermediate

Status :
Online
Offline

Posts : 149
Joined : 2009-02-16
Gender : Male
OS : Windows 7

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Belahzur on Sun Feb 22, 2009 7:56 pm

Hello.
Search something in Google now, see if you still get re-directed or not.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Seldom Fail on Sun Feb 22, 2009 8:01 pm

Ok... when I use Google.com I get redirected to ToseekA.com (another search engine... not porn.)

When I use the FireFox HomePage Google Search Box I get redirected to the bad sites.

Seldom Fail
Intermediate
Intermediate

Status :
Online
Offline

Posts : 149
Joined : 2009-02-16
Gender : Male
OS : Windows 7

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Belahzur on Sun Feb 22, 2009 8:15 pm

Hello.
Hmm, lets go deeper.


  • Download combofix from here
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Please disable your local AV (Anti-virus) by right clicking it's icon in the tray, and exit it. See [You must be registered and logged in to see this link.] for how to disable your AV. (Avira and Spyware Doctor)
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Seldom Fail on Sun Feb 22, 2009 8:26 pm

AVIRA ANTIVIR
Please navigate to the system tray on the bottom right hand corner and look for an open white umbrella on red background

* right click it-> untick the option AntiVir Guard enable.
* You should now see a closed, white umbrella on a red background

You successfully disabled the AntiVir Guard.

I don't see this on my toolbar. I have Avira but I don't know how to shut it off.

Seldom Fail
Intermediate
Intermediate

Status :
Online
Offline

Posts : 149
Joined : 2009-02-16
Gender : Male
OS : Windows 7

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Belahzur on Sun Feb 22, 2009 8:29 pm

Press Start > All Programs.
Find the "Avira" folder, and open the interface from there.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Seldom Fail on Sun Feb 22, 2009 9:47 pm

Sorry it took so long. Something happened to my network.

ComboFix:
ComboFix 09-02-21.01 - Christy 2009-02-22 15:11:09.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.478.152 [GMT -6:00]
Running from: c:\documents and settings\Christy\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated)

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2009-01-22 to 2009-02-22 )))))))))))))))))))))))))))))))
.

2009-02-22 13:36 . 2009-02-22 13:36 d-------- C:\_OTMoveIt
2009-02-16 12:51 . 2009-02-16 12:51 d-------- c:\documents and settings\Christy\Application Data\Malwarebytes
2009-02-16 12:50 . 2009-02-16 12:50 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-08 12:08 . 2009-02-08 12:08 d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2009-02-08 11:58 . 2009-02-08 11:58 d-------- c:\program files\Common Files\Macrovision Shared
2009-02-08 11:41 . 2009-02-08 11:41 129,784 --------- c:\windows\system32\pxafs.dll
2009-02-08 11:41 . 2009-02-08 11:41 118,520 --------- c:\windows\system32\pxinsi64.exe
2009-02-08 11:41 . 2009-02-08 11:41 116,472 --------- c:\windows\system32\pxcpyi64.exe
2009-02-08 11:41 . 2009-02-08 11:41 9,464 --------- c:\windows\system32\drivers\cdralw2k.sys
2009-02-08 11:41 . 2009-02-08 11:41 9,336 --------- c:\windows\system32\drivers\cdr4_xp.sys
2009-02-07 11:38 . 2009-02-07 11:38 d-------- c:\windows\.file_store_32
2009-02-03 20:38 . 2007-12-04 17:10 16,640 -ra------ c:\windows\system32\drivers\PalmUSBD.sys
2009-02-03 20:35 . 2009-02-03 20:35 d-------- c:\documents and settings\Christy\Application Data\Arcsoft
2009-02-03 20:19 . 2009-02-03 20:19 d-------- c:\documents and settings\Christy\Application Data\HotSync
2009-02-03 20:19 . 2009-02-03 20:19 d-------- c:\documents and settings\All Users\Application Data\HotSync
2009-02-03 20:12 . 2009-02-03 20:33 d-------- c:\program files\Palm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-21 22:40 --------- d-----w c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition Classic
2009-02-21 16:35 --------- d-----w c:\documents and settings\Christy\Application Data\Download Manager
2009-02-17 00:09 --------- d-----w c:\program files\No-IP
2009-02-08 17:59 --------- d-----w c:\program files\Common Files\Adobe
2009-02-08 17:41 43,528 ------w c:\windows\system32\drivers\pxhelp20.sys
2009-02-07 17:40 34 ----a-w c:\documents and settings\Christy\jagex_runescape_preferences.dat
2009-01-11 01:26 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-11 01:25 --------- d-----w c:\program files\Java
2008-12-24 21:04 --------- d-----w c:\documents and settings\All Users\Application Data\Trymedia
2008-12-23 23:40 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-25 17:09 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008102520081026\index.dat
.

((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-22 21:02:53 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_544.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 688218]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SDTray"="c:\program files\Spyware Doctor\SDTrayApp.exe" [2007-06-12 1053264]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2008-01-03 1392640]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
Wireless-G Notebook Adapter.lnk - c:\program files\Linksys\Wireless-G Notebook Adapter\Gcc.exe [2008-04-03 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-09-26 13:42 267064 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvc"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 163840]
R2 sdAuxService;Spyware Doctor Auxiliary Service;c:\program files\Spyware Doctor\svcntaux.exe [2007-08-16 708688]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a27f6b10-7510-11dc-bbed-00c09f73e861}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
mStart Page = [You must be registered and logged in to see this link.]
mSearch Bar = [You must be registered and logged in to see this link.]
FF - ProfilePath - c:\documents and settings\Christy\Application Data\Mozilla\Firefox\Profiles\v1hq5pxy.default\
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - plugin: c:\progra~1\Palm\PACKAG~1\NPInstal.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-02-22 15:16:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1472)
c:\program files\Funk Software\Funk Client\odLogin.dll
.
Completion time: 2009-02-22 15:19:24
ComboFix-quarantined-files.txt 2009-02-22 21:18:56
ComboFix2.txt 2009-02-22 20:44:04

Pre-Run: 18,894,684,160 bytes free
Post-Run: 18,882,805,760 bytes free

113 --- E O F --- 2009-01-11 01:37:41

Seldom Fail
Intermediate
Intermediate

Status :
Online
Offline

Posts : 149
Joined : 2009-02-16
Gender : Male
OS : Windows 7

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Belahzur on Sun Feb 22, 2009 9:59 pm

Hello.
No malware there.

I do have two things I want to ask about:
c:\program files\No-IP

I'm guessing this is some sort of proxy program? there has been known to be a few different users who experienced problems and the caused was a proxy program.

And this:
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]

Did you set that as your homepage?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Seldom Fail on Sun Feb 22, 2009 10:10 pm

I did the homepage thing. And I was trying something with another site one time and downloaded the No-Ip thing. I thought I deleted it :/

Seldom Fail
Intermediate
Intermediate

Status :
Online
Offline

Posts : 149
Joined : 2009-02-16
Gender : Male
OS : Windows 7

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Belahzur on Sun Feb 22, 2009 10:13 pm

Well delete this folder:
c:\program files\No-IP

Whatever is causing the re-directions, it isn't malware.
Are you still being re-directed?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Seldom Fail on Sun Feb 22, 2009 10:18 pm

Yes I'm still being re-directed. But I guess instead of clicking the links, I'll have to copy and paste the URL.

Thank you for your time.

Seldom Fail
Intermediate
Intermediate

Status :
Online
Offline

Posts : 149
Joined : 2009-02-16
Gender : Male
OS : Windows 7

View user profile

Back to top Go down

Solved Re: Ok I need a lot of help!

Post by Doctor Inferno on Mon Jul 06, 2009 3:44 am

Since this issue has been addressed, a "solved" tag will be added and this topic will be closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a [You must be registered and logged in to see this link.] for your questions.


Please be a GeekPolice fan on [You must be registered and logged in to see this link.]



Have we helped you? [You must be registered and logged in to see this link.] | Doctor by day, ninja by night.

Doctor Inferno
Administrator
Administrator

Status :
Online
Offline

Posts : 12017
Joined : 2007-12-26
Gender : Male
OS : Windows 7 Home Premium and Ultimate X64

View user profile

Back to top Go down

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum