Help - Search - Members
Full Version: Trojan? Spyware? Help Please : (
Piriform Community Forums > Computer Help and Discussion > Spyware Hell
DemonX
Online waiting..
Tried SmitfraudFix but the problem still there.
Heres the log..

Logfile of HijackThis v1.99.1
Scan saved at 10:34:58 PM, on 8/23/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\winmer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\WinServer.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\wdfmgr32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\conime.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Grisoft\AVG Free\avgwb.dat
C:\WINDOWS\WINLOGON.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\user\Desktop\HiJack\HijackThis.exe

R3 - URLSearchHook: (no name) - {02496EBD-8455-48db-B3C7-5DAC97D9F5A7} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe 1
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: MonitorURL Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\PROGRA~1\DESKAD~1\deskipn.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\Jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [intranet] C:\WINDOWS\System32\intranet.exe
O4 - HKLM\..\Run: [WinSever] C:\WINDOWS\System32\WinServer.exe
O4 - HKLM\..\Run: [wdfmgr32] C:\WINDOWS\System32\wdfmgr32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Desktop] C:\WINDOWS\System32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKLM\..\Run: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
O4 - HKLM\..\RunServices: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [sys001] C:\WINDOWS\rund1132.exe
O4 - HKCU\..\Run: [msnnt] C:\WINDOWS\winampe.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

DemonX
No one could help?
gotta offline soon..
@@"
krit86lr
QUOTE(DemonX @ Aug 23 2006, 10:01 AM) [snapback]47002[/snapback]

No one could help?
gotta offline soon..
@@"

It had only been 20 minutes since you posted a log. Sometimes it takes hours to a day to get help. Someone will be able to help when they get some spare time. Just hang tight. tongue.gif
AndyManchesta
Hi DemonX

Its probably going to be easier for you to backup all your important data and format the machine then reinstall Windows, you have a very nasty trojan (Password Stealer Wowcraft) that changes alot of registry keys so it keeps installing the infection, the last variant I tested of this causes alot of damage to the pc, for example If I opened IE, regedit, msconfig, control panel, exe files, inf files etc.. it reinstalled the infection

This looks like a different variant but the last one I tested causes far too much damage to be able to repair with a couple of malware scans and its very difficult to remove as it drops alot of .com files in different locations and modifies alot of different reg keys to make it reinstall all the time. If you want to clean this machine then I will need some samples of the files to see what damage its causing

If you want to clean the machine then please download Suspicious file Packer from Safer-Networking.Org and unzip it to your desktop.

Run SFP.exe.

Please copy the following lines into the Step 1: Paste Text window:

C:\WINDOWS\System32\winmer.exe
C:\WINDOWS\System32\WinServer.exe
C:\WINDOWS\System32\regedit.com
C:\WINDOWS\System32\msconfig.com
C:\WINDOWS\System32\wdfmgr32.exe
C:\WINDOWS\System32\dxdiag.com
C:\WINDOWS\System32\rundll32.com
C:\WINDOWS\System32\command.pif
C:\WINDOWS\Debug\DebugProgram.exe
C:\Program Files\DeskAdTop\Run.dll
C:\Program Files\Internet Explorer\iexplore.com
C:\Program Files\common files\iexplore.pif
C:\WINDOWS\rund1132.exe
C:\WINDOWS\winampe.exe
C:\WINDOWS\WINLOGON.EXE
C:\WINDOWS\explorer.com
C:\WINDOWS\1.com

then click "Continue".

Some of these may not exist but any that are present will be added to the .cab archive

Please locate the created .cab file on your desktop (named requested-files[Date/Time].cab), right click the file and choose Send To then Compressed (zipped) Folder, right click the newly created zipped folder on your desktop and choose Explore, When it opens click file from the top bar and choose Add A Password, name it malware (all lowercase) then press ok, please email the password protected zipped file to

IPB Image

then delete the zipped file and the requestedfiles.cab file.

Run Hijack This and choose Do A System Scan then place a check next to these entries

R3 - URLSearchHook: (no name) - {02496EBD-8455-48db-B3C7-5DAC97D9F5A7} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe 1
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: MonitorURL Class - {08A312BB-5409-49FC-9347-54BB7D069AC6} - C:\PROGRA~1\DESKAD~1\deskipn.dll
O4 - HKLM\..\Run: [WinSever] C:\WINDOWS\System32\WinServer.exe
O4 - HKLM\..\Run: [wdfmgr32] C:\WINDOWS\System32\wdfmgr32.exe
O4 - HKLM\..\Run: [Desktop] C:\WINDOWS\System32\rundll32.exe "C:\Program Files\DeskAdTop\Run.dll" ,Rundll
O4 - HKLM\..\Run: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
O4 - HKLM\..\RunServices: [Torjan Program] C:\WINDOWS\WINLOGON.EXE
O4 - HKCU\..\Run: [sys001] C:\WINDOWS\rund1132.exe
O4 - HKCU\..\Run: [msnnt] C:\WINDOWS\winampe.exe

Close all open browser and other windows except for Hijack This and press the Fix Checked button

I think its abit risky to be asking you to manually remove the files as there will also be essential Windows files with the same name in the same folders for alot of them and with the malware files missing you may also find alot of things do not work until the damage to the registry is repaired but if you feel confident searching for them check for the files at the beginning of this post after enabling hidden files and showing the extensions but make sure they are not the Microsoft files first by right clicking them and choosing properties and then the version tab:

You will need to set Windows to show hidden files and folders to locate the below files:

Click Start. Goto MyComputer then C:\drive
Select the Tools menu from the top bar and click Folder Options. Select the View Tab.
Under the Hidden files and folders heading select "Show hidden files and folders".
UnCheck the "Hide protected operating system files (recommended)" option.
Uncheck the "Hide file extensions for known file types" option.

Click Yes to confirm then OK

Set this back once you have removed the files by opening the same page and pressing the Restore Defaults button the click Apply and OK.

If you do not feel confident searching for them then please skip that and just send the samples as its likely going to reinstall anyway until we repair the registry damage and locate all its files.

Andy
DemonX
QUOTE(krit86lr @ Aug 23 2006, 11:28 PM) [snapback]47007[/snapback]

It had only been 20 minutes since you posted a log. Sometimes it takes hours to a day to get help. Someone will be able to help when they get some spare time. Just hang tight. tongue.gif


Well im really sorry for saying this but please understand that im seriously desperate when i saw my pc with a serious problem like this.

And also sorry for my slow reply cause i had to offline yesterday for some reason.
I will be try the method you told me Andy.

Thanks and i will tell you what i got later on... ohmy.gif
DemonX
Well...
I try to follow Andy steps but i dont know what my friend did to my pc and now all those application cannot be open/launch. Please notice that is all application.. sad.gif (Including dos)
Let say i try to open IExplore and it just appear a error box with "Windows cannot find 'C:\Program Files\Internet Explorer\IEXPLORE.EXE'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search. blink.gif
Im now surfing with open My Computer and enter the web address there..
But i still can get the HJT to run and heres the new log.
So..
Hope you can give me a hand here. blink.gif
Thanks.

Logfile of HijackThis v1.99.1
Scan saved at 10:06:52 PM, on 8/24/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\wsetup.exe
C:\Documents and Settings\user\Desktop\HiJack\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\Jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe

DemonX
Is anyone here~
AndyManchesta
Hey DemonX

Did your friend confirm every file he removed wasnt the Microsoft file with the same name ? regedit.com is bad , regedit.exe is essential , iexplore.com is bad but iexplore.exe is essential etc... This is why I asked for the file entensions to be shown first and for you to right click the files and check the properties to make sure they are not Microsoft files.

If your friend has right clicked and deleted all the files then please locate the recycle bin icon on the desktop and open it, then restore every file they removed by right clicking the file and choosing restore.

If you sent the files I can help repair the damage but its really a lost cause if you didnt because it makes so many different registry changes so the system will be seriously damaged even if you was able to remove the trojan files. Let us know if you can restore the files you removed from the recycle bin or if you sent them and I will try help more.

Its also worth trying your system restore (Start > All Programs > Accessories > SystemTools > System Restore) and try return your system to a earlier date to repair the damage or remove the trojan infection.
DemonX
Glad to see your reply while im still here Andy.
Well let me tell you a bad news that i cant open any single programe.
This is the most serious problem i had right now.
Any suggestion?
AndyManchesta

Can you open the recycle bin ?

Can you open system restore ?

Do you still have a start menu ? smile.gif

Its difficult to know if your having problems because your friend removed genuine files or if its because all the registry entries that should open exe files and programs have been modified so they are now trying to open the trojan files that you removed.
DemonX
Andy~ T_T
Do you have any other suggestion?
Im still here waiting..
And gotta off within 5 min..

QUOTE(AndyManchesta @ Aug 25 2006, 12:08 AM) [snapback]47120[/snapback]

Can you open the recycle bin ?

Can you open system restore ?

Do you still have a start menu ? smile.gif

Its difficult to know if your having problems because your friend removed genuine files or if its because all the registry entries that should open exe files and programs have been modified so they are now trying to open the trojan files that you removed.


I can only open folders now..
And yes, i still have my start menu with all the program but none of em can be load.
DemonX
Well i gotta go right now..
I've decided to format it now since its so complicated and so much problem it cause to me.
Thanks for your help anyway, you are always the greatest ^^
And allow me to wish you a early "Happy Birthday" : )

Peace.
DemonX
AndyManchesta
The only suggestion if you cannot do anything is Format the pc and tell your friend stay away from it smile.gif

Seriously though, a format is probably easier here anyway as the trojan causes alot of damage to the system but you could perform a repair install using the windows disk to get things up and running again assuming your friend removed genuine files, if your problems are because of the reg changes the trojan made then a repair may not fix them all.

Try going to start menu and run and copy and paste

%systemroot%\system32\restore\rstrui.exe

if it loads then its the system restore feature.

Goto Start C:\Drive and open the RECYCLER folder, if you cannot see it then enable hidden files and folders

Select the Tools menu from the top bar and click Folder Options. Select the View Tab.
Under the Hidden files and folders heading select "Show hidden files and folders".
UnCheck the "Hide protected operating system files (recommended)" option.

Click Yes to confirm then OK

Then open the C:\RECYCLER folder and try to restore the items your friend removed by right clicking the files.

Or try creating a reg file to fix some of the damage to extension:

Open Notepad (Start Menu > Run > Type notepad and press OK)

Copy and Paste the contents of the code box into Notepad making REGEDIT4 the top line.

CODE
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\CLASSES\exefile\shell\open\command] @="\"%1\" %*"

[HKEY_LOCAL_MACHINE\Software\CLASSES\batfile\shell\open\command] @="\"%1\" %*"

[HKEY_LOCAL_MACHINE\Software\CLASSES\comfile\shell\open\command] @="\"%1\" %*"

[HKEY_LOCAL_MACHINE\Software\CLASSES\piffile\shell\open\command] @="\"%1\" %*"

[HKEY_LOCAL_MACHINE\Software\CLASSES\scrfile\shell\open\command] @="\"%1\" %*"


Goto File on the top bar and choose Save As, Change the Save As Type to All Files, Name it Fix.reg then save it to your desktop

Double click Fix.reg (or right click and choose Merge) and it will ask if you want to merge the contents into the registry, choose Yes and the reg entries will be restored to MS Default.

Your best option though is to reinstall Windows as its impossible to reverse its damage without samples of the files,

Andy
AndyManchesta
I just remembered you cannot use exe files so you will not be able to open notepad to create the reg file blink.gif

Its Here if you want to try it, you will have to right click the link and choose save target as then save it to your desktop then double click it or right click and choose merge to use it

Andy
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.