Trojan Horse found

Discussion in 'Malware Help (A Specialist Will Reply)' started by skipper12, Aug 22, 2005.

  1. skipper12

    skipper12 Private E-2

    Hello All! About 2 nights ago i contracted something bad on my computer and i've been getting ambushed by pop-ups ever since.I run my spysweeper and it finds a bunch of stuff and deletes but they come right back.Today it found a trojan horse called Vesbiz Downloader but can't get rid of it.I have hijack this, would that work and what would I look for in the logfile.I have already looked on it but can't find anything matching them words.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis is not the first or second step. Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. skipper12

    skipper12 Private E-2

    Okay i've made it down to the download tools and thats where i'm stuck in the mud.every time i download ad-aware se after it has finished i get a message that says "ad-aware has caused an error in <unknown> ad-aware will now close" and i can't even get to the scanning and cleaning part.i tried spybot and it won't even start to download.i suppose the trojan is smart enough to keep all this stuff out LOL!!! Any other ideas or should i just wipe everything out with my factory restore,god i hate doing that!!!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's make sure we are clear on when the problem occurs. The below are three different things. Which one does the problem occur on:

    1) downloading the tools from Majorgeeks

    2) installing the tools

    3) running the tools

    The way you wrote your message it sounds like you cannot even do number 1 (download).
    If this is true can you download anything at all from anywhere?

    For example try to download this: SIW (System Info)

    Also try this: a-squared HiJackFree

    What OS do you have?

    Let me know the answer to my questions and the results of trying to download the above two items.
     
  5. skipper12

    skipper12 Private E-2

    I got everything to download except both ad-aware downloads.neither one of them will download properly on my computer for some reason.i'm trying to run the bitdefender and how do you run it in safe mode?Win Me when i go to safe mode i can't get back on the internet.i tried it in normal mode but it says my security settings won't allow active x even though its set on medium security.the last few days i wasn't able to stay on the internet more than 5 minutes because it would freeze or go to blue error screen and i would have to shut down.i figured out if i go to my start-up menu and disable some things that don't look right it runs much better.hopefully this will help someone else.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please don't use msconfig to disable any startups. We are going to need to see everything so we can get you all fixed up.

    Just post your HJT log as I indicated in message # 2.

    Is your Ad-aware problem when you download it, when you install it, or when you try to run Ad-Aware to do a scan?
     
  7. skipper12

    skipper12 Private E-2

    I can download the whole ad-aware se program.it installs and gives me the tutorial and desktop icon and all that good stuff, but right after it completes i get that error message. i can click on the desk top icon and that error message comes up every time and has to close and i can't get into it to scan and clean.my computer seems to be running pretty efficent right now with minumal pop ups and slow down periods ,but still dials up on its own when i power up and spybot still detects a few things like www.coolsearch.if go back in and enable them startup items its probably going to limit my time on the internet before it crashes but i will try to post that hjt log attachment.is there a link that will show me how to do that as i'm still not real clear on how to do it.
     
  8. skipper12

    skipper12 Private E-2

    Never mind i think i found the thread on how to post it.Will try it tomorrow ,i've been tinkering with this thing long enough for one day LOL!!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Post it when you can. We'll be around.
     
  10. skipper12

    skipper12 Private E-2

    I turned my security setting to lowest setting and managed to scan Bitdefender and RavAntivirus.Bitdefender found 27 viruses and 37 infected folders.Rav only found 2 viruses.I'm stuck in the mud trying Attach my hijack this logfile.After i scan and save logfile where does it go to,i can't seem to find it anywhere, or what should i type in for file to upload??
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Assuming you have the hijackthis.log file saved on your PC and you know where it is:
    - Click the Reply button here to answer a message
    - At the bottom of the message window click the Go Advanced button
    - then scroll down a little until you see the Manage Attachments button and click it.
    - in the window that comes up click the Browse button and browse to the location on your PC where the hijackthis.log file is saved.
    - select it by double clicking on it.
    - Then click the Upload button. Observe the messages in that Window you should either see that the file is attached or the could be an error message if you did something wrong.
    - then close that window
    - then save your message
     
  12. skipper12

    skipper12 Private E-2

    I think i finally got it i hope.won't know till i post this.alright!!! it's there.I had to run without saving then save it after i run it and it showed up in my local c-drive
     
    Last edited: Apr 22, 2006
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Read my message on installing and HJT again:
    You have HJT in a temp folder (could be because you did not extract it from the ZIP fil) and you were not in normal boot mode as required.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I needed the log from normal boot mode so the below may not work completely. But hopefully it will get us started. But first you must make sure you get HJT installed properly as requested. Do that before continuing.

    First look in Add/Remove programs for the below and uninstall if found.
    E2G or E2Give
    SpyKiller
    Media Access
    NewdotNet

    You have a load of trojans! Where have you been surfing.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - (no file)
    O2 - BHO: SDWin32 Class - {DE98C0B3-273D-47EC-9B70-D26B2CBAC360} - C:\WINDOWS\SYSTEM\YPPDH.DLL
    O2 - BHO: (no name) - {D99C5EEA-990B-9BA4-7801-CF891A0F3993} - C:\WINDOWS\SYSTEM\JHQGKRKJ.DLL
    O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\DSR.DLL
    O2 - BHO: CControl Object - {3643ABC2-21BF-46B9-B230-F247DB0C6FD6} - C:\Program Files\E2G\IeBHOs.dll
    O4 - HKLM\..\Run: [Command] C:\WINDOWS\ZGVmYXVsdAAA\command.exe
    O4 - HKLM\..\Run: [version] C:\WINDOWS\SYSTEM\LHSRTQ.exe
    O4 - HKLM\..\Run: [secure] C:\WINDOWS\SYSTEM\ZCMWBG.exe
    O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
    O4 - HKLM\..\Run: [Media Access] C:\PROGRAM FILES\MEDIA ACCESS\MediaAccK.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKLM\..\Run: [r83R36X] RASPLUG.EXE
    O4 - HKLM\..\Run: [vpbbwgmv] C:\WINDOWS\SYSTEM\zpfujj.exe
    O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\SYSTEM\winupdtl.exe
    O4 - HKLM\..\Run: [zpfujj] c:\windows\system\zpfujj.exe
    O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
    O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\SYSTEM\exp.exe
    O4 - HKLM\..\Run: [yppdhc] C:\WINDOWS\SYSTEM\yppdhc.exe
    O4 - HKLM\..\Run: [dnam] C:\D140113.A.STUB.EXE
    O4 - HKLM\..\Run: [snss Launcher] "C:\Program Files\snss\snss.exe"
    O4 - HKLM\..\Run: [rvsluc] C:\WINDOWS\SYSTEM\rvsluc.exe
    O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\SYSTEM\VIDCTRL\VIDCTRL.EXE
    O4 - HKCU\..\Run: [DZIG4D] C:\WINDOWS\SYSTEM\DZIG4D.exe
    O4 - HKCU\..\Run: [Reoe] C:\Program Files\bhat\tbar.exe
    O4 - HKCU\..\Run: [Oaxl] \jte.exe
    O4 - HKCU\..\Run: [azs5RWbmQ] QEDCLR40.EXE
    O4 - HKCU\..\Run: [KSUSER] C:\WINDOWS\SYSTEM\KSUSER.EXE
    O4 - HKCU\..\Run: [Mxykyacn] \decglh.exe
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
    O4 - HKCU\..\RunOnce: [DZIG4D] C:\WINDOWS\SYSTEM\DZIG4D.exe
    O9 - Extra button: Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avbabelfish&c=3c00&LC=0409 (file missing)
    O9 - Extra 'Tools' menuitem: AV &Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avbabelfish&c=3c00&LC=0409 (file missing)
    O9 - Extra button: (no name) - {06FE5D02-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avlinksearch&c=3c00&LC=0409 (file missing)
    O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL - {06FE5D02-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avlinksearch&c=3c00&LC=0409 (file missing)
    O9 - Extra button: (no name) - {06FE5D03-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avhostsearch&c=3c00&LC=0409 (file missing)
    O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host - {06FE5D03-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=avhostsearch&c=3c00&LC=0409 (file missing)
    O9 - Extra button: (no name) - {06FE5D04-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=altavista&c=3c00&LC=0409 (file missing)
    O9 - Extra 'Tools' menuitem: AV Live - {06FE5D04-8F11-11d2-804F-00105A133818} - http://search.presario.net/scripts/redirectors/presario/srchredir.dll?s=altavista&c=3c00&LC=0409 (file missing)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Microsoft AntiSpyware helper - {BF4F3CD9-50CE-49D5-A7FC-EB8B62B7AABA} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {BF4F3CD9-50CE-49D5-A7FC-EB8B62B7AABA} - (no file) (HKCU)
    O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\PROGRAM FILES\MEDIA ACCESS <--- the whole folder
    C:\PROGRAM FILES\NEWDOT~1 <--- the whole folder
    C:\Program Files\snss <--- the whole folder
    C:\WINDOWS\SYSTEM\VIDCTRL <--- the whole folder
    C:\Program Files\bhat <--- the whole folder
    C:\Program Files\SpyKiller <--- the whole folder
    C:\Program Files\E2G <--- the whole folder
    C:\WINDOWS\SYSTEM\YPPDH.DLL
    C:\WINDOWS\SYSTEM\JHQGKRKJ.DLL
    C:\WINDOWS\DSR.DLL
    C:\WINDOWS\ZGVmYXVsdAAA\command.exe
    C:\WINDOWS\SYSTEM\LHSRTQ.exe
    C:\WINDOWS\SYSTEM\ZCMWBG.exe
    C:\WINDOWS\SYSTEM\AUNPS2.DLL or C:\WINDOWS\AUNPS2.DLL
    C:\WINDOWS\SYSTEM\RASPLUG.EXE or C:\WINDOWS\RASPLUG.EXE
    C:\WINDOWS\SYSTEM\zpfujj.exe
    C:\WINDOWS\SYSTEM\winupdtl.exe
    C:\WINDOWS\dinst.exe
    C:\WINDOWS\SYSTEM\exp.exe
    C:\WINDOWS\SYSTEM\yppdhc.exe
    C:\D140113.A.STUB.EXE
    C:\WINDOWS\SYSTEM\rvsluc.exe
    C:\WINDOWS\SYSTEM\DZIG4D.exe
    C:\jte.exe or C:\WINDOWS\SYSTEM\jte.exe or C:\WINDOWS\jte.exe
    C:\WINDOWS\SYSTEM\QEDCLR40.EXE or C:\WINDOWS\QEDCLR40.EXE
    C:\WINDOWS\SYSTEM\KSUSER.EXE
    C:\decglh.exe or C:\WINDOWS\SYSTEM\decglh.exe or C:\WINDOWS\decglh.exe
    c:\counter.cab

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  15. skipper12

    skipper12 Private E-2

    Sorry about that,i thought i had to run hijack this in safe mode.i extracted hijackthis to program files then booted to safe mode, i deleted most of the files(some i couldn't find) then ran cc cleaner and reset web settings and that other stuff you told me and booted back to normal then ran and saved logfile for hijackthis offline and attached it.everything seems to be fine for now and think i'll try to download that pesky ad-aware program again just for fun.
     
    Last edited: Apr 22, 2006
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have a problem!

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\ZDHG.EXE

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKCU\..\Run: [Kutv] \zdhg.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:

    C:\ZDHG.EXE

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  17. skipper12

    skipper12 Private E-2

    I just enabled all my startup items before i posted this logfile because i remembered awhileback you said you wanted them all working.now i see alot of them things i deleted earlier.are they back in full force again becuase i did that?? i did get rid of that zdhg.exe found one file and killed it then ran cc cleaner.didn't find it though when i went into safe mode.
     
    Last edited: Apr 22, 2006
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you did not do a system restore???? Just enabling all startups should not have done this unless there was something in there that was a program to reinstall everything.

    Re-run the old steps from msg # 14 and then post a new HJT log when finished.

    Here is the current bad stuff to compare to the old list:


    C:\PROGRAM FILES\BHAT\TBAR.EXE
    O4 - HKLM\..\Run: [version] C:\WINDOWS\SYSTEM\LHSRTQ.exe
    O4 - HKLM\..\Run: [secure] C:\WINDOWS\SYSTEM\ZCMWBG.exe
    O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
    O4 - HKLM\..\Run: [Media Access] C:\PROGRAM FILES\MEDIA ACCESS\MediaAccK.exe
    O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
    O4 - HKLM\..\Run: [r83R36X] RASPLUG.EXE
    O4 - HKLM\..\Run: [vpbbwgmv] C:\WINDOWS\SYSTEM\zpfujj.exe
    O4 - HKLM\..\Run: [winupdtl] C:\WINDOWS\SYSTEM\winupdtl.exe
    O4 - HKLM\..\Run: [zpfujj] c:\windows\system\zpfujj.exe
    O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
    O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\SYSTEM\exp.exe
    O4 - HKLM\..\Run: [yppdhc] C:\WINDOWS\SYSTEM\yppdhc.exe
    O4 - HKLM\..\Run: [dnam] C:\D140113.A.STUB.EXE
    O4 - HKLM\..\Run: [snss Launcher] "C:\Program Files\snss\snss.exe"
    O4 - HKLM\..\Run: [rvsluc] C:\WINDOWS\SYSTEM\rvsluc.exe
    O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\SYSTEM\VIDCTRL\VIDCTRL.EXE
    O4 - HKCU\..\Run: [DZIG4D] C:\WINDOWS\SYSTEM\DZIG4D.exe
    O4 - HKCU\..\Run: [Reoe] C:\Program Files\bhat\tbar.exe
    O4 - HKCU\..\Run: [Oaxl] \jte.exe
    O4 - HKCU\..\Run: [azs5RWbmQ] QEDCLR40.EXE
    O4 - HKCU\..\Run: [KSUSER] C:\WINDOWS\SYSTEM\KSUSER.EXE
    O4 - HKCU\..\Run: [Mxykyacn] \decglh.exe
    O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
     
  19. skipper12

    skipper12 Private E-2

    My system restore disable and show hidden files are still set properly.
     
    Last edited: Apr 22, 2006
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay everything looks clean again.

    Now to help keep you clean, you should complete the steps in the below. The first step there is to goto to Microsoft Update and get any updates for your OS.

    How to Protect yourself from malware!
     
  21. skipper12

    skipper12 Private E-2

    Thanks a whole bunch for all the help you've given me ;) i really appreciate it!My computer is running great now with no pop-ups and doesn't dial up on its own anymore.Still couldn't run that dag gone ad-aware though, don't know what the problem is they must not want me to have it, but who cares i've got all that other great stuff to help me out and will use it.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would try uninstalling all Ad-Aware programs. Then goto the C:\Program Files folder and delete the Lavasoft subfolder. Then reboot your PC. Now download the program again from this link: Ad-Aware SE Personal

    Now reinstall from the one just downloaded. Now see what happens when you run a scan. Do not change any default parameters.
     
  23. skipper12

    skipper12 Private E-2

    Nope still get error message!! i'm just going to forget about it,i've tried everything including saving it to my documents like the tutorial says when downloading it,but the dreaded error message keeps coming up after it installs.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have seen people solve a problem like this by replacing their riched32.dll file with a new copy. The file may be corrupted. First make a backup copy of the riched32.dll file you already have and then try getting a new copy of riched32.dll and putting it in c:\windows\system

    You can get a copy from here:

    http://www.dll-files.com/dllindex/dll-files.shtml?riched32

    Problem is that I'm not sure if it is compatible with your WinME OS. That is why I want you to backup your original first. Maybe you even have a copy on your WinME CD that can be used. Note most WinME DLL file go in c:\windows\system not c:\windows\system32 as indicated on the link above (system32 is for Win2K and XP).
     
  25. skipper12

    skipper12 Private E-2

    You are the man chaslang! I replaced that file and it works alright now.I ran it and it found 28 objects already :(
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Cool! Glad to hear it worked.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds