Results 1 to 4 of 4

Thread: help removing trojan TR/Crypt.ZPACK.gen

  1. #1
    Guest
    Join Date
    Apr 2009
    Posts
    5

    Default help removing trojan TR/Crypt.ZPACK.gen

    alright, i know excactly where the files are for this trojan, including all the hidden ones but whenever i delete/quarintine these files it keeps coming back.

    i have avira antivir and spybot S&D running.

    heres my HJT log.

    Code:
    Logfile of HijackThis v1.99.1
    Scan saved at 6:36:41 PM, on 19/04/2009
    Platform: Unknown Windows (WinNT 6.00.1905 SP1)
    MSIE: Internet Explorer v7.00 (7.00.6001.18226)
    
    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Windows\SOUNDMAN.EXE
    C:\Program Files\OpenVPN\bin\openvpn-gui.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    D:\downloads\programs\WallpaperChanger_v1.90\Wallpaper.exe
    C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\DAEMON Tools Lite\daemon.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    D:\downloads\programs\hijackthis\hjt.exe
    C:\Windows\system32\SearchFilterHost.exe
    
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [WallPaper] D:\DOWNLO~1\programs\WALLPA~1.90\Wallpaper.exe /h
    O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O4 - Global Startup: Bluetooth.lnk = ?
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
    O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O16 - DPF: {96EEC7FF-106A-47F3-90D6-B4BB754AA40E} (POLi Pay Online) - https://autxn.paywithpoli.com/ewcustomer/POLiPayOnline.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: ECB - Sysinternals - www.sysinternals.com - C:\Users\bowan\AppData\Local\Temp\ECB.exe
    O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
    O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - Unknown owner - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe" runservice -w -N "pgsql-8.3" -D "C:\Program Files\PostgreSQL\8.3\data\ (file missing)
    O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: SX - Sysinternals - www.sysinternals.com - C:\Users\bowan\AppData\Local\Temp\SX.exe
    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exe
    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

    also this is the script that was generated from running your program rootalyzer.

    Code:
    Requested file archive at 18/04/2009 10:54:43 PM
    Created by RootAlyzer
    Copyright © 2004-2009 Safer-Networking Limited. All rights reserved.
    
    Folder, No admin in ACL: C:\Windows\Internet Logs
    Registry Key, No admin in ACL: HKEY_LOCAL_MACHINE\SOFTWARE\NOS
    Registry Key, No admin in ACL: HKEY_LOCAL_MACHINE\SOFTWARE\NOS\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}_bowan
    Registry Key, Zero char in key name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG 
    Registry Value, Zero char in value name: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG \Seed TRY-8BE26640-0000
    Registry Value, Invisible to Win32: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG \Seed TRY-8BE26640-0000
    File, No admin in ACL: C:\Windows\temp\ZLT0456a.TMP
    File, No admin in ACL: C:\Windows\temp\ZLT06ad9.TMP
    File, Invisible to Win32: C:\Windows\System32\ovfsthxekctnpfc.dll
    File, Invisible to Win32: C:\Windows\System32\ovfsthxekctnpfc.dll.XXX
    File, Invisible to Win32: C:\Windows\System32\ovfsthxjqysbjfs.dll
    File, Invisible to Win32: C:\Windows\System32\ovfsthxouimpciq.dat
    File, Invisible to Win32: C:\Windows\System32\ovfsthxpegeeqca.dll
    File, Invisible to Win32: C:\Windows\System32\ovfsthxsmispsst.dat
    File, Invisible to Win32: C:\Windows\System32\drivers\ovfsthxkrybotct.sys
    Folder, No admin in ACL: C:\Users\bowan\AppData\LocalLow\NOS
    File, Invisible to Win32: C:\Users\bowan\AppData\Local\Temp\ovfsthxridutpnb000
    Folder, No admin in ACL: C:\Users\All Users\NOS
    File, Unknown ADS: C:\Users\All Users\TEMP:8927A071:$DATA
    File, Unknown ADS: C:\Users\All Users\TEMP:8CEFE51A:$DATA
    Folder, No admin in ACL: C:\Users\All Users\NOS\Adobe_Downloads
    File, No admin in ACL: C:\Users\All Users\NOS\getUninst_Adobe.dat
    File, No admin in ACL: C:\Users\All Users\NOS\Adobe_Downloads\nos_11909.dat
    Folder, No admin in ACL: C:\Users\All Users\Microsoft\OFFICE\DATA
    File, No admin in ACL: C:\Users\All Users\Microsoft\OFFICE\DATA\OPA12.BAK
    File, No admin in ACL: C:\Users\All Users\Microsoft\OFFICE\DATA\opa12.dat
    Folder, No admin in ACL: C:\ProgramData\NOS
    Folder, No admin in ACL: C:\ProgramData\NOS\Adobe_Downloads
    File, No admin in ACL: C:\ProgramData\NOS\getUninst_Adobe.dat
    File, No admin in ACL: C:\ProgramData\NOS\Adobe_Downloads\nos_11909.dat
    Folder, No admin in ACL: C:\ProgramData\Microsoft\OFFICE\DATA
    File, Unknown ADS: C:\Program Files\Cake Poker:MID:$DATA
    File, Unknown ADS: C:\Program Files\Cake Poker\cake.exe:info:$DATA
    
    Requests:
    C:\Windows\Internet Logs\*.*
    C:\Windows\temp\ZLT0456a.TMP
    C:\Windows\temp\ZLT06ad9.TMP
    C:\Windows\System32\ovfsthxekctnpfc.dll
    C:\Windows\System32\ovfsthxekctnpfc.dll.XXX
    C:\Windows\System32\ovfsthxjqysbjfs.dll
    C:\Windows\System32\ovfsthxouimpciq.dat
    C:\Windows\System32\ovfsthxpegeeqca.dll
    C:\Windows\System32\ovfsthxsmispsst.dat
    C:\Windows\System32\drivers\ovfsthxkrybotct.sys
    C:\Users\bowan\AppData\LocalLow\NOS\*.*
    C:\Users\bowan\AppData\Local\Temp\ovfsthxridutpnb000
    C:\Users\All Users\NOS\*.*
    C:\Users\All Users\TEMP:8927A071
    C:\Users\All Users\TEMP:8CEFE51A
    C:\Users\All Users\NOS\Adobe_Downloads\*.*
    C:\Users\All Users\NOS\getUninst_Adobe.dat
    C:\Users\All Users\NOS\Adobe_Downloads\nos_11909.dat
    C:\Users\All Users\Microsoft\OFFICE\DATA\*.*
    C:\Users\All Users\Microsoft\OFFICE\DATA\OPA12.BAK
    C:\Users\All Users\Microsoft\OFFICE\DATA\opa12.dat
    C:\ProgramData\NOS\*.*
    C:\ProgramData\NOS\Adobe_Downloads\*.*
    C:\ProgramData\NOS\getUninst_Adobe.dat
    C:\ProgramData\NOS\Adobe_Downloads\nos_11909.dat
    C:\ProgramData\Microsoft\OFFICE\DATA\*.*
    C:\Program Files\Cake Poker:MID
    C:\Program Files\Cake Poker\cake.exe:info
    
    Operations:
    - could not add: C:\Windows\Internet Logs\*.*
      Cabinet error 1 (type 123)
    + added: C:\Windows\temp\ZLT0456a.TMP
    + added: C:\Windows\temp\ZLT06ad9.TMP
    - could not add: C:\Windows\System32\ovfsthxekctnpfc.dll
      Cabinet error 1 (type 5)
    - could not add: C:\Windows\System32\ovfsthxekctnpfc.dll.XXX
      Cabinet error 1 (type 5)
    + added: C:\Windows\System32\ovfsthxjqysbjfs.dll
    + added: C:\Windows\System32\ovfsthxouimpciq.dat
    + added: C:\Windows\System32\ovfsthxpegeeqca.dll
    + added: C:\Windows\System32\ovfsthxsmispsst.dat
    + added: C:\Windows\System32\drivers\ovfsthxkrybotct.sys
    - could not add: C:\Users\bowan\AppData\LocalLow\NOS\*.*
      Cabinet error 1 (type 123)
    + added: C:\Users\bowan\AppData\Local\Temp\ovfsthxridutpnb000
    + added: C:\Users\All Users\NOS\getUninst_Adobe.dat
    + added: C:\Users\All Users\TEMP:8927A071
    + added: C:\Users\All Users\TEMP:8CEFE51A
    + added: C:\Users\All Users\NOS\Adobe_Downloads\nos_11909.dat
    + added: C:\Users\All Users\NOS\getUninst_Adobe.dat
    + added: C:\Users\All Users\NOS\Adobe_Downloads\nos_11909.dat
    + added: C:\Users\All Users\Microsoft\OFFICE\DATA\OPA12.BAK
    + added: C:\Users\All Users\Microsoft\OFFICE\DATA\opa12.dat
    + added: C:\Users\All Users\Microsoft\OFFICE\DATA\OPA12.BAK
    + added: C:\Users\All Users\Microsoft\OFFICE\DATA\opa12.dat
    + added: C:\ProgramData\NOS\getUninst_Adobe.dat
    + added: C:\ProgramData\NOS\Adobe_Downloads\nos_11909.dat
    + added: C:\ProgramData\NOS\getUninst_Adobe.dat
    + added: C:\ProgramData\NOS\Adobe_Downloads\nos_11909.dat
    + added: C:\ProgramData\Microsoft\OFFICE\DATA\OPA12.BAK
    + added: C:\ProgramData\Microsoft\OFFICE\DATA\opa12.dat
    + added: C:\Program Files\Cake Poker:MID
    + added: C:\Program Files\Cake Poker\cake.exe:info
    not the files with the names ovfsthxjqysbjfs.dll, ovfsthxouimpciq.dat etc are the trojans hidden files.

    i need to find out why after deletion it keeps propogating it self.

    any PROMPT help would be greatly appreciated as i've tried seeking help at other forums over the past week without any responses. i can only assume this is because no one knows how to remove this thing.

  2. #2
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    Hello bowan,

    Please see the stickied procedure for this forum: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance)

    HJT Logs
    To produce a log, run Trend Micro HijackThis 2.0.2, not Beta, HijackThis v1.99.1. or any other version.
    It is preferable, and the log easier to read, if you do not use the [code] or [php] options.


    Members need to read the entire thread.

    However before starting a new topic please provide links to the ones you started at other sites.

    Best regards.



    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  3. #3
    Guest
    Join Date
    Apr 2009
    Posts
    5

    Default

    nvm i dont want to go jumping thru more fcking hoops to get help from people who are probally less qualified to offer advice then i am who just copy and paste useless tripe and never offer any real help so just close the damn thread and ban my account please.

    will just do what i always do and figure it out myself.

  4. #4
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    Have a nice day.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •