1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved suspect ransomware freezing PC when trying to access internet

Discussion in 'Malware and Virus Removal Archive' started by Bearclaw, 2012/08/30.

  1. 2012/09/07
    Bearclaw

    Bearclaw Well-Known Member Thread Starter

    Joined:
    2010/12/09
    Messages:
    151
    Likes Received:
    0
    Results of screen317's Security Check version 0.99.50
    Windows 7 Service Pack 1 x86 (UAC is enabled)
    Internet Explorer 9
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    avast! Antivirus
    AntiVir Desktop
    Antivirus up to date! (On Access scanning disabled!)
    `````````Anti-malware/Other Utilities Check:`````````
    SUPERAntiSpyware
    Malwarebytes Anti-Malware version 1.62.0.1300
    CCleaner
    JavaFX 2.1.1
    Java(TM) 6 Update 31
    Java 7 Update 7
    Adobe Flash Player 11.2.202.235
    Adobe Reader X 10.1.3 Adobe Reader out of Date!
    Mozilla Firefox (14.0.1)
    Mozilla Thunderbird (8.0). Thunderbird out of Date!
    Google Chrome 19.0.1084.52
    ````````Process Check: objlist.exe by Laurent````````
    AVAST Software Avast AvastSvc.exe
    AVAST Software Avast AvastUI.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 0%
    ````````````````````End of Log``````````````````````



    Farbar Service Scanner Version: 06-08-2012
    Ran by Owner (administrator) on 08-09-2012 at 00:09:24
    Running from "C:\Users\Owner\Desktop "
    Microsoft Windows 7 Home Premium Service Pack 1 (X86)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Google.com is accessible.
    Yahoo IP is accessible.
    Yahoo.com is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================


    System Restore:
    ============

    System Restore Disabled Policy:
    ========================


    Action Center:
    ============

    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    Windows Defender:
    ==============

    Other Services:
    ==============


    File Check:
    ========
    C:\Windows\system32\nsisvc.dll => MD5 is legit
    C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
    C:\Windows\system32\dhcpcore.dll => MD5 is legit
    C:\Windows\system32\Drivers\afd.sys => MD5 is legit
    C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
    C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
    C:\Windows\system32\dnsrslvr.dll => MD5 is legit
    C:\Windows\system32\mpssvc.dll => MD5 is legit
    C:\Windows\system32\bfe.dll => MD5 is legit
    C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
    C:\Windows\system32\SDRSVC.dll => MD5 is legit
    C:\Windows\system32\vssvc.exe => MD5 is legit
    C:\Windows\system32\wscsvc.dll => MD5 is legit
    C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
    C:\Windows\system32\wuaueng.dll => MD5 is legit
    C:\Windows\system32\qmgr.dll => MD5 is legit
    C:\Windows\system32\es.dll => MD5 is legit
    C:\Windows\system32\cryptsvc.dll => MD5 is legit
    C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
    C:\Windows\system32\svchost.exe => MD5 is legit
    C:\Windows\system32\rpcss.dll => MD5 is legit


    **** End of log ****


    # AdwCleaner v2.000 - Logfile created 09/08/2012 at 00:11:01
    # Updated 30/08/2012 by Xplode
    # Operating system : Windows 7 Home Premium Service Pack 1 (32 bits)
    # User : Owner - OWNER-PC
    # Boot Mode : Normal
    # Running from : C:\Users\Owner\Desktop\adwcleaner.exe
    # Option [Search]


    ***** [Services] *****


    ***** [Files / Folders] *****

    File Found : C:\Program Files\Mozilla Firefox\Plugins\npvsharetvplg.dll
    File Found : C:\user.js
    Folder Found : C:\Program Files\Conduit
    Folder Found : C:\Program Files\uTorrentBar
    Folder Found : C:\ProgramData\Ask
    Folder Found : C:\ProgramData\InstallMate
    Folder Found : C:\ProgramData\Premium
    Folder Found : C:\Users\Owner\AppData\Local\APN
    Folder Found : C:\Users\Owner\AppData\Local\Conduit
    Folder Found : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp
    Folder Found : C:\Users\Owner\AppData\LocalLow\Conduit
    Folder Found : C:\Users\Owner\AppData\LocalLow\uTorrentBar

    ***** [Registry] *****

    Key Found : HKCU\Software\AppDataLow\Software\Conduit
    Key Found : HKCU\Software\AppDataLow\Software\uTorrentBar
    Key Found : HKCU\Software\AppDataLow\Toolbar
    Key Found : HKCU\Software\Conduit
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1B48071-416D-474E-A13B-BE5456E7FC31}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A97B89CD-B65C-49DD-AF46-2B772C627456}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
    Key Found : HKCU\Software\StartSearch
    Key Found : HKLM\SOFTWARE\Classes\AppID\{1973277F-87B0-4EA3-9ED2-470A91D284CF}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{A1B48071-416D-474E-A13B-BE5456E7FC31}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{A97B89CD-B65C-49DD-AF46-2B772C627456}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
    Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2786678
    Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3007394
    Key Found : HKLM\SOFTWARE\Classes\TypeLib\{99C22A61-21BA-4F81-85FF-CDC9EB5DB10B}
    Key Found : HKLM\Software\Conduit
    Key Found : HKLM\Software\Default Tab
    Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4326C03A-B95F-493E-AFA6-B17245CA2038}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F69B1B6C-8BC9-4C20-92F6-97ADA23A14C8}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A97B89CD-B65C-49DD-AF46-2B772C627456}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\LiveVDO plugin
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentBar Toolbar
    Key Found : HKLM\Software\uTorrentBar
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]
    Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]
    Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}]

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v9.0.8112.16421

    [OK] Registry is clean.

    -\\ Mozilla Firefox v14.0.1 (en-US)

    Profile name : default
    File : C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\sm6exwex.default\prefs.js

    [OK] File is clean.

    -\\ Google Chrome v19.0.1084.52

    File : C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Preferences

    Found [l.1323] : homepage = "hxxp://www.ask.com/?l=dis&o=14676cr ",

    *************************

    AdwCleaner[R1].txt - [4015 octets] - [08/09/2012 00:11:01]

    ########## EOF - C:\AdwCleaner[R1].txt - [4075 octets] ##########
     
  2. 2012/09/07
    Bearclaw

    Bearclaw Well-Known Member Thread Starter

    Joined:
    2010/12/09
    Messages:
    151
    Likes Received:
    0
    I cannot get ESET scanner to run, the page will open fine but when I click on the button to scan it does nothing. I also tried to use the utility for Firefox and others. Same result, just no response...

    grrrrr
     

  3. to hide this advert.

  4. 2012/09/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Try different browser.
     
  5. 2012/09/08
    Bearclaw

    Bearclaw Well-Known Member Thread Starter

    Joined:
    2010/12/09
    Messages:
    151
    Likes Received:
    0
    ESET scan results

    C:\Program Files\FoxTabFLVPlayer\FLVPlayer.exe a variant of Win32/InstallCore.A application
    C:\Users\Owner\Desktop\Installers & Unused\WinZip165.exe a variant of Win32/OpenInstall application
    C:\Users\Owner\Desktop\Major\Desktop\unused & Installations\ffdshow.exe probably a variant of Win32/InstallIQ application
    C:\Users\Owner\Desktop\Major\Desktop\unused & Installations\media.player.codec.pack.v3.9.1.setup.exe Win32/Toolbar.Widgi application


    I may have made an error, I unchecked the box that was for removal or killing found threats. So I am assuming that these evil doers are still lurking about... is there a way to remove them now, or do I need to rerun the ESET scan and do it that way? I did keep the program as a 'just-in-case'.

    Thanks so much for your help!

    jim
     
  6. 2012/09/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You can simply open Windows Explorer and delete those items manually.
    Empty Recycle Bin afterwards.

    =====================================

    Uninstall Java(TM) 6 Update 31.

    ======================================

    Update Adobe Reader

    You can download it from http://www.adobe.com/products/acrobat/readstep2.html
    After installing the latest Adobe Reader, uninstall all previous versions (if present).
    Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

    Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
    It's a much smaller file to download and uses a lot less resources than Adobe Reader.
    Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or any other garbage.

    ======================================

    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Delete.
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.

    Next...

    • Double click on adwcleaner.exe to run the tool.
    • Click on Uninstall.
    • Confirm with yes.

    ======================================

    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [emptyjava]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.
     
  7. 2012/09/08
    Bearclaw

    Bearclaw Well-Known Member Thread Starter

    Joined:
    2010/12/09
    Messages:
    151
    Likes Received:
    0
    OTL scan log (final)

    Files\Folders moved on Reboot...

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
     
  8. 2012/09/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That's not a complete log.
    Redo.
     
  9. 2012/09/08
    Bearclaw

    Bearclaw Well-Known Member Thread Starter

    Joined:
    2010/12/09
    Messages:
    151
    Likes Received:
    0
    OTL redo

    I need to get the OTL anew, trashed it already... be back as soon as possible with new scan results...
     
  10. 2012/09/08
    Bearclaw

    Bearclaw Well-Known Member Thread Starter

    Joined:
    2010/12/09
    Messages:
    151
    Likes Received:
    0
    All processes killed
    Error: Unable to interpret <Code: > in the current context!
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Owner
    ->Temp folder emptied: 1093695 bytes
    ->Temporary Internet Files folder emptied: 80358292 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 58718705 bytes
    ->Google Chrome cache emptied: 32669442 bytes
    ->Flash cache emptied: 11687 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 75462 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 165.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Owner
    ->Flash cache emptied: 0 bytes

    User: Public

    Total Flash Files Cleaned = 0.00 mb


    [EMPTYJAVA]

    User: All Users

    User: Default

    User: Default User

    User: Owner
    ->Java cache emptied: 0 bytes

    User: Public

    Total Java Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.61.2 log created on 09082012_164805

    Files\Folders moved on Reboot...
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\SuggestedSites.dat moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NLECPCHA\click[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NLECPCHA\xd_arbiter[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NLECPCHA\_;dcopt=rcl;mtfIFPath=nofile;ord=0[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CA2JGHCE\aceUAC[2].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7BI1BNJ3\0[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7BI1BNJ3\103500-active-suspect-ransomware-freezing-pc-when-trying-access-internet-2[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7BI1BNJ3\DtCol[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7BI1BNJ3\fastbutton[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7BI1BNJ3\getInPage[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7BI1BNJ3\like[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5KDB07WR\0[3].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5KDB07WR\0[4].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5KDB07WR\0[5].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5KDB07WR\latest[1].xml moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3QD4JNVQ\ext-render-secure[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3QD4JNVQ\latest[1].xml moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0F0PYFLC\csc-render[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0F0PYFLC\fc[1].htm moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0F0PYFLC\st[1] moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0F0PYFLC\st[2] moved successfully.
    C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0F0PYFLC\xd_arbiter[1].htm moved successfully.
    C:\Windows\temp\JETCFBC.tmp moved successfully.

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
     
  11. 2012/09/09
    Bearclaw

    Bearclaw Well-Known Member Thread Starter

    Joined:
    2010/12/09
    Messages:
    151
    Likes Received:
    0
    related issue?

    Broni,

    I realize this might be a bit off the field, but then again maybe it is just a common thing too. Forgive me if I am going astray here, but here is the situation:

    After we finished up the elimination of the ransomeware and 'cleaning' processes, the mouse seems to have lost some function. That is really not all that accurate, so I will elaborate. I noticed that when I tried to go into my hotmail inbox, which I have always done by a left click on the mouse,no longer works. Instead of proceeding to the proper page, it make the current page transform into a 'diagram' of itself sans all graphics. Next I noticed that any time I tried to double click any internet button to open a page, graphic, site or whatever, it just did not work, nothing at all happened. So the shortcut double click has to be replaced by the right click and then 'open' procedure.

    As I said, this is really not a 'mouse' problem, as I have experimented with a total of 5 mouses (mice?) both wired and wireless and the results are the same with all... now this does not occur when I access the same things on a different computer, so whatever happened seems to isolated to the one we were dealing with.

    OK, the regular functions with a single left click still function fine, so this double click failure is a real poser for me... any ideas on what has happened here or how I might go about finding a resolution?

    I have tried restartes and updating mouse software and drivers... not help.

    Sorry to drag on here, any help, advice or direction to other places will be greatly appreciated...

    thanks

    jim
     
  12. 2012/09/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Does it happen in a browser only?
    If so which browser?
    Did you check other browser(s)?
     
  13. 2012/09/09
    Bearclaw

    Bearclaw Well-Known Member Thread Starter

    Joined:
    2010/12/09
    Messages:
    151
    Likes Received:
    0
    Yes, it happens in other browsers as well, which is a bit strange I think... HOWEVER, I did find a solution which is even stranger when considering the other browsers suffering the same condition... the 'fix' was 'resetting' IE9. How that all interacts with VireFox and Chrome is all a mystery, but they too are OK now... (?)

    Just in case others suffer similar problems, this might be of help!!

    OK, thanks for sharing the link to WINDOWS things all wonderful!! :) I shall keep that one handy!!

    OK, I think we are all fixed up now, and I do thank you a million for the help!!

    Will do the 'resolved' thing in just a second!!

    jim
     
  14. 2012/09/09
    Bearclaw

    Bearclaw Well-Known Member Thread Starter

    Joined:
    2010/12/09
    Messages:
    151
    Likes Received:
    0
    the tread tools don't show the 'resolved' button... ? should I just leave it alone or what? :)
     
  15. 2012/09/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    In this forum only I can do it.

    Way to go!! [​IMG]
    Good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.