1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

HijackThis Log file

Discussion in 'Security and Privacy' started by dobhar, 2004/04/16.

Thread Status:
Not open for further replies.
  1. 2004/04/16
    dobhar Lifetime Subscription

    dobhar Inactive Thread Starter

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    Hi all...

    Would appreciate if someone could look at this log file for me...I'm working on a friends PC. Spent the last couple hours cleaning it up (Spyware, Trojans, and Virii). I have cleaned up a few items using HojackThis already but am not sure about the items in RED...

    Thanks in advance...

    Logfile of HijackThis v1.97.7
    Scan saved at 10:53:36 AM, on 4/16/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Nhksrv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\WINDOWS\System32\gearsec.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\System32\devldr32.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
    C:\WINDOWS\DELLMMKB.EXE
    C:\Program Files\Messenger Plus! 2\MsgPlus.exe
    C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Netropa\OSD.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\HiJackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.dellnet.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - (no file)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe "
    O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
    O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe "
    O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [CIPVCJ] C:\WINDOWS\CIPVCJ.exe
    O4 - HKLM\..\Run: [CPDT] C:\WINDOWS\CPDT.exe
    O4 - HKLM\..\Run: [ANUELRYE] C:\WINDOWS\ANUELRYE.exe
    O4 - HKLM\..\Run: [DKQXHOVB] C:\WINDOWS\DKQXHOVB.exe

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe "
    O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMREMIND.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O9 - Extra button: MoneySide (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
     
  2. 2004/04/16
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Here's my analysis. :)


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about :blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about :blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about :blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about :blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about :blank
    R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - (no file)<<<<Huntbar
    O4 - HKLM\..\Run: [CIPVCJ] C:\WINDOWS\CIPVCJ.exe
    O4 - HKLM\..\Run: [CPDT] C:\WINDOWS\CPDT.exe
    O4 - HKLM\..\Run: [ANUELRYE] C:\WINDOWS\ANUELRYE.exe
    O4 - HKLM\..\Run: [DKQXHOVB] C:\WINDOWS\DKQXHOVB.exe
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?

    No info found on those run entries you pointed out. I would definately delete the files after fixing.

    I would fix this and uninstall Windows Messenger. Command line uninstaller RunDll32 advpack.dll,LaunchINFSection %windir%\INF\msmsgs.inf,BLC.Remove

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background


    If you didn't use Spybot's immunize feature, fix this. It keeps you from accessing the Internet options menu. There's a check box in Spybot to undo this also.

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

    Info on the Winsock entries. If you fix them, you will need WinsockFix or LSPFix. http://www.kephyr.com/spywarescanner/library/targetsoft.inetadpt/index.phtml

    O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\inetadpt.dll


    This is Windows Auto-update in Millenium but usually represents a trojan in XP.
    C:\WINDOWS\System32\wuauclt.exe

    Would need to disable system restore, dump TIF's, Temps and recycle bin for final cleanup, as you probably already know.
     

  3. to hide this advert.

  4. 2004/04/16
    dobhar Lifetime Subscription

    dobhar Inactive Thread Starter

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    Hi Mark...Thanks for the reply...

    Took a look and found (in C:\Windows\System32\...

    wuauclt.exe
    wuaucpl.cpl.manifest
    wuaueng.dll
    wuauserv.dll

    Note: I have these same files on my WinXP PC but wuauclt.exe is not a running process on my PC and I am totally clean.
     
    Last edited: 2004/04/16
  5. 2004/04/16
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Did a little more digging and found that I didn't read far enough before . wuauclt.exe is also the update client in XP and the trojan that uses this creates a run entry. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft auto update = WUAUCLT.EXE

    That's not what's on your log, so disregard my previous statement please. :rolleyes: I suppose since it is a running process though, that Auto Update is enabled??

    BTW, it's Dave not Mark. :)
     
  6. 2004/04/16
    dobhar Lifetime Subscription

    dobhar Inactive Thread Starter

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    DDDOOOOHHHHH!!!!!!!

    Sorry about that chief! -->Maxwell Smart imitation... :)

    Fixed up all but still getting one other problem that I forgot to mention. About 10 to 15 minutes after connecting to internet "winlogon.exe" goes 100% CPU and basically the PC is hosed. Using task manager (before winlogon.exe goes ballistic) I noticed also that there are 2 instances of "svhost.exe" running with one of them running at 25% CPU...then when winlogon kicks in I get 2 more instances of svhost.exe.

    I'm almost at the point of telling them to backup there files and reinstall the PC...
     
  7. 2004/04/16
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    See this thread about svchost. Might be a good idea to post another log. It wouldn't be a bad idea to get rid of this either. C:\WINDOWS\System32\P2P Networking\P2P Networking.exe and fix it's HJT entry
    O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART

    Assume you've done some online virus scans. I'd do two or three different ones.
     
  8. 2004/04/17
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    yes Post another log please :)


    Never never fix O10 's with hijackthis, instead use lsp fix. then after a reboot delte that file.Like Dave said.

    what are the symtom's ? Popups , misdirects ? mention any ?
    about :blank isnt a good sign.

    C:\WINDOWS\CIPVCJ.exe
    C:\WINDOWS\CPDT.exe
    C:\WINDOWS\ANUELRYE.exe
    C:\WINDOWS\DKQXHOVB.exe
    Curious check the properties of these files ?

    inetadpt.dll might be a sign of a Look2me Vx2 h.abetterinternet
    Infection, an easy way to tell would be >

    copy and past into IE's addressbar
    javascript:navigator.userAgent
    Hit enter or go
    and copy paste that back here for us please

    P2P Networking >
    Uninstall P2P Networking through Add/Remove Programs.While off line. If/when asked whether you also want to remove Altnet components, say 'Yes'.
    P2P Networking is a totally useless Kazaa add-on, and it's been reported to be responsible for serious system slowdowns.
    Subsequently remove the P2P Networking folder in C:\Windows\System, if still there.
    and the allthenet folder to,C:\Program Files\Altnet
    then run hijackthis and remove its entries.

    Messenger Plus! contains LOP parisite, although i dont see it in the log just know.
    ======my notes on same=====
    I would also like to recommend getting rid of Messenger Plus 2 It is third party MSN Messenger extension Not recommended as it includes Lop.com - see here. I have included it in the removal with HJT but I would recommend that you go to Start>Control Panel>Add Remove Programs and look for it in the list there. If you find it, please Remove it with the Change/Remove button. There are other safer Instand Messenging Programs.
    http://www.spywareinfo.com/newsletter/archives/june-2003/3.php
     
  9. 2004/04/17
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    Chances are these files are Hidden, in Windows Explorer, change the Folder Options to Show All Files.
    C:\WINDOWS\CIPVCJ.exe
    C:\WINDOWS\CPDT.exe
    C:\WINDOWS\ANUELRYE.exe
    C:\WINDOWS\DKQXHOVB.exe
     
  10. 2004/04/17
    dobhar Lifetime Subscription

    dobhar Inactive Thread Starter

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    Hi guys...thanks for the reponses...

    Unfortunately my friend had to take the computer back as they (4 users - Mom, Dad and 2 children) wanted to backup the PC incase we do a full reinstall. My friend also wanted to educate his kids as they were the reason the PC got infected. I'm hoping to get the PC back on Monday to continue with the cleanup so I will post back a little later.

    --------------------------------------
    Dave...

    I did uninstall the P2P Networking. Unfortunately I could never complete an online Trojan scan (from www.trojanscan.com) as after about 15 minutes of scanning the "winlogon.exe" would go ballistic with 100% CPU so the PC was hosed.

    I did download a shareware (free for 30 days) Trojan scanner called Trojan Hunter. It did find some suspected files and we removed them but the 100% CPU problem still comes up.
    ---------------------------------------
    Lonny...

    Yes...I followed Dave's suggestion with the 010 problem using the LSPFix.

    I will try, when I get the PC back, your suggestion with the "java script:navigator.userAgent "
    ---------------------------------------
    markp62...

    I did use HijackThis to remove the entries and will make sure the files are not on the PC.
    ---------------------------------------

    To all of you thanks (my friend also thanks you) for your suggestions and I will post back a new log in a couple days

    :D :D
     
  11. 2004/04/17
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    When you get that back, try to end task on the winlogon.exe when it starts up while scanning. Might even search the drive for it and just scan those locations for starters. Didn't see winlogon.exe in the HJT log. Was it in previous scans? If it was, check it against this<<<(I've been having trouble accessing this site and have to refresh a few times to get results) for location and startup item/name.

    Understand and agree with teaching the kids safe surfing, but I didn't see a firewall running. Maybe I'm just missing it?? When you get this back and fully cleaned up, I'd suggest putting one in for them, setting the AV to automatically update, make an excludes list of HJT, install IESpyads and last but not least, have your friend make backups before problems set in. :)
     
  12. 2004/04/17
    dobhar Lifetime Subscription

    dobhar Inactive Thread Starter

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    Tried end task on the Winlogon.exe but got the no permissions error...even tried it with being logged on as local administrator but still got error.

    It was in the original HJT log I posted...
    I has already installed SpywareGuard and SpywareBlaster as well as IESpyAD yesterday...good minds think alike...hehehehe
     
    Last edited: 2004/04/17
  13. 2004/04/17
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Another log would be helpfull :)
     
  14. 2004/04/20
    dobhar Lifetime Subscription

    dobhar Inactive Thread Starter

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    Hi all...

    My friend e-mailed me his last log yesterday...

    Logfile of HijackThis v1.97.7
    Scan saved at 5:37:25 PM, on 4/19/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\System32\devldr32.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
    C:\WINDOWS\DELLMMKB.EXE
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\Netropa\OSD.exe
    C:\Utility_Tools\HiJackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe "
    O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O9 - Extra button: MoneySide (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
    O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.trojanscan.com/trojanscan/TDECntrl.CAB
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    Looks pretty clean to me
     
  15. 2004/04/20
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Don't get much cleaner than that. How about the winlogon problem?
     
  16. 2004/04/20
    dobhar Lifetime Subscription

    dobhar Inactive Thread Starter

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    Hey Dave...

    He said that it happens but not as much. We are looking at a reload sometime in the very near future. He's just getting the wife and kids to clean up and backup their files (ie Kids MP3's, pics, etc).

    Thanks for all your help.

    PS...Did you try the FProt definition upgrade from UBCD? If I get time I'm going to try this weekend. Been a little busy doing yard work (raking grass) since the snow has melted and were finally getting some decent weather.

    Laters,
     
  17. 2004/04/21
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    No, haven't tried the update yet. Well, I guess if it's going to get wiped anyway, and it's working well enough to backup, there's not much point in trying to figure it out. I only hope they don't end up backing up some nasty and putting it back on a clean system. :eek:
     
  18. 2004/04/21
    dobhar Lifetime Subscription

    dobhar Inactive Thread Starter

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    I'm going to be helping him with the new installation so I'm going to make sure things are nice and clean before going back on the PC.

    Thanks to all that helped with this post.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.