Results 1 to 7 of 7
  1. #1
    Member poohbearjim's Avatar
    Join Date
    Sep 2004
    Posts
    3
    Points
    0

    Default Ads234.com / netspry.com / sandboxer

    Hello,

    I have spyware/adware (Ads234.com / netspry.com / sandboxer are only the ones I know about!) that has made it onto my computer and does not seem to be able to be deleted. I've gone through all of the recommended steps: ispfix, Panda Activescan, Housecall, Windows Updates, CWShredder, spybot S&D and AdAware. The problems persist - they seem to keep reinstalling themselves after I get rid of them.

    My computer is a Dell Dimension 4100, Intel Pentium III processor, 863 MHz, 128 MB RAM, Windows XP (service pack 2 recently installed).

    I was wondering if I would be able to get some assistance and hopefully I won't have to wipe everything out and reinstall. Here is my HijackThis log:

    Logfile of HijackThis v1.98.2
    Scan saved at 7:58:31 PM, on 9/3/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Microsoft Hardware\Mouse\point32.exe
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
    C:\WINDOWS\System32\hphmon04.exe
    C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
    C:\docume~1\jim\locals~1\temp\iWBe.exe
    C:\docume~1\jim\locals~1\temp\fQc3T.exe
    C:\docume~1\jim\locals~1\temp\TWFG8.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Winamp\winampa.exe
    C:\documents and settings\jim\local settings\temp\PvCtRTA.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\documents and settings\jim\local settings\temp\1E.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\documents and settings\jim\local settings\temp\Ae00.exe
    C:\documents and settings\jim\local settings\temp\KxLj.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Windows Media Components\Encoder\WMENCAGT.EXE
    C:\Palm\HOTSYNC.EXE
    C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    C:\WINDOWS\System32\Edij3r2.exe
    C:\WINDOWS\System32\Hzq6z5p.exe
    C:\WINDOWS\System32\HPHipm11.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\PROGRA~1\HEWLET~1\HPSHAR~1\HPGS2WNF.EXE
    C:\Hijack This\Newest\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.livejournal.com/users/poohbearjim/friends/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = MindSpring Internet Explorer
    N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.yahoo.com"); (C:\Program Files\Netscape\Users\jim\prefs.js)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
    O2 - BHO: WinPage Affiliate - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Program Files\Common Files\midaddle\midaddle.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [POINTER] point32.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
    O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
    O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
    O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
    O4 - HKLM\..\Run: [iWBe] C:\docume~1\jim\locals~1\temp\iWBe.exe
    O4 - HKLM\..\Run: [fQc3T] C:\docume~1\jim\locals~1\temp\fQc3T.exe
    O4 - HKLM\..\Run: [TWFG8] C:\docume~1\jim\locals~1\temp\TWFG8.exe
    O4 - HKLM\..\Run: [26LWH3Q29582CC] C:\WINDOWS\System32\RnuQDB55.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [PvCtRTA] C:\documents and settings\jim\local settings\temp\PvCtRTA.exe
    O4 - HKLM\..\Run: [1E] C:\documents and settings\jim\local settings\temp\1E.exe
    O4 - HKLM\..\Run: [Ae00] C:\documents and settings\jim\local settings\temp\Ae00.exe
    O4 - HKLM\..\Run: [updater] C:\DOCUME~1\jim\LOCALS~1\Temp\updater.exe
    O4 - HKLM\..\Run: [KxLj] C:\documents and settings\jim\local settings\temp\KxLj.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Semagic.lnk = C:\Program Files\Semagic\LiveJournal.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Encoder Agent.lnk = C:\Program Files\Windows Media Components\Encoder\WMENCAGT.EXE
    O4 - Global Startup: PowerReg Scheduler.exe
    O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0819.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0819.DLL
    O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
    O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Dell Home - {EE117DAA-A30B-40FC-945C-38AE1B80C1FA} - http://www.dellepro.com/corporate (file missing) (HKCU)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {0320C93D-706C-4B70-81B6-69A947071524} (Downloader.clsDownloader) - http://www.icugames.com/install/downloader.cab
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti...l_v1-0-3-9.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab


    Thank you in advance!

    Jim Daniel
    poohbearjim

  2. #2
    Member
    Join Date
    Jan 2003
    Posts
    12,000
    Points
    1191

    Default

    This will not fix the current problem, but you also have a Peper Trojan. To remove THIS<<<< click here to remove the peper trojan from your computer ( Remain connected to the internet when you run this uninstall program)

    POst another log by using the reply button at the bottom of this page.

    Our HJT Guru is off line with PC problems and it is going to be many,many hours, possibly days before he will be able to assist you.

    Cheers

  3. #3
    Member poohbearjim's Avatar
    Join Date
    Sep 2004
    Posts
    3
    Points
    0

    Default

    Thank you kindly. I have run the Peper Trojan removal and have run Hijack This again. Here is the new log:

    Logfile of HijackThis v1.98.2
    Scan saved at 11:40:31 PM, on 9/3/2004
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Microsoft Hardware\Mouse\point32.exe
    C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
    C:\WINDOWS\System32\hphmon04.exe
    C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
    C:\docume~1\jim\locals~1\temp\iWBe.exe
    C:\docume~1\jim\locals~1\temp\fQc3T.exe
    C:\docume~1\jim\locals~1\temp\TWFG8.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Winamp\winampa.exe
    C:\documents and settings\jim\local settings\temp\PvCtRTA.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\documents and settings\jim\local settings\temp\1E.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\documents and settings\jim\local settings\temp\Ae00.exe
    C:\documents and settings\jim\local settings\temp\KxLj.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Windows Media Components\Encoder\WMENCAGT.EXE
    C:\Palm\HOTSYNC.EXE
    C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    C:\WINDOWS\System32\HPHipm11.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\PROGRA~1\HEWLET~1\HPSHAR~1\HPGS2WNF.EXE
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Hijack This\Newest\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.livejournal.com/users/poohbearjim/friends/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = MindSpring Internet Explorer
    N1 - Netscape 4: user_pref("browser.startup.homepage", "http://www.yahoo.com"); (C:\Program Files\Netscape\Users\jim\prefs.js)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\jim\Local Settings\Temp\gAZp.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [POINTER] point32.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
    O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
    O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
    O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
    O4 - HKLM\..\Run: [iWBe] C:\docume~1\jim\locals~1\temp\iWBe.exe
    O4 - HKLM\..\Run: [fQc3T] C:\docume~1\jim\locals~1\temp\fQc3T.exe
    O4 - HKLM\..\Run: [TWFG8] C:\docume~1\jim\locals~1\temp\TWFG8.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [PvCtRTA] C:\documents and settings\jim\local settings\temp\PvCtRTA.exe
    O4 - HKLM\..\Run: [1E] C:\documents and settings\jim\local settings\temp\1E.exe
    O4 - HKLM\..\Run: [Ae00] C:\documents and settings\jim\local settings\temp\Ae00.exe
    O4 - HKLM\..\Run: [updater] C:\DOCUME~1\jim\LOCALS~1\Temp\updater.exe
    O4 - HKLM\..\Run: [KxLj] C:\documents and settings\jim\local settings\temp\KxLj.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Semagic.lnk = C:\Program Files\Semagic\LiveJournal.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Encoder Agent.lnk = C:\Program Files\Windows Media Components\Encoder\WMENCAGT.EXE
    O4 - Global Startup: PowerReg Scheduler.exe
    O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0819.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0819.DLL
    O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
    O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Dell Home - {EE117DAA-A30B-40FC-945C-38AE1B80C1FA} - http://www.dellepro.com/corporate (file missing) (HKCU)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {0320C93D-706C-4B70-81B6-69A947071524} (Downloader.clsDownloader) - http://www.icugames.com/install/downloader.cab
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti...l_v1-0-3-9.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab



    No problem if it takes a couple of days for a response. I fully understand!

    Jim Daniel

  4. #4
    Member steamwiz's Avatar
    Join Date
    Sep 2003
    Location
    Yorkshire U.K.
    Posts
    14,022
    Points
    2335

    Default

    Hi Jim

    Disconnect from the internet Close ALL browser windows (including this one) - run hijackthis and tick to fix (check the box next to) the list below.........when all are ticked (checked) click the Fix Checked button at the bottom. :-

    O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
    O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\jim\Local Settings\Temp\gAZp.dll

    O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
    O4 - HKLM\..\Run: [iWBe] C:\docume~1\jim\locals~1\temp\iWBe.exe
    O4 - HKLM\..\Run: [fQc3T] C:\docume~1\jim\locals~1\temp\fQc3T.exe
    O4 - HKLM\..\Run: [TWFG8] C:\docume~1\jim\locals~1\temp\TWFG8.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [PvCtRTA] C:\documents and settings\jim\local settings\temp\PvCtRTA.exe
    O4 - HKLM\..\Run: [1E] C:\documents and settings\jim\local settings\temp\1E.exe
    O4 - HKLM\..\Run: [Ae00] C:\documents and settings\jim\local settings\temp\Ae00.exe
    O4 - HKLM\..\Run: [updater] C:\DOCUME~1\jim\LOCALS~1\Temp\updater.exe
    O4 - HKLM\..\Run: [KxLj] C:\documents and settings\jim\local settings\temp\KxLj.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE


    Then reboot into >>>safe mode<<< Click Here for instructions find and delete :-

    .....The entire contents of the C:\documents and settings\jim\local settings\temp folder ( Do NOT delete the folder itself)

    PLEASE NOTE The local settings folder is a hidden folder.....Click here >>> How to Show Hidden/System Files <<<

    steam
    Look here for Ways to keep your computer safe
    M'SOFT MVP -Windows Security 2004/8 .member ASAP -

  5. #5
    Member jcw7373's Avatar
    Join Date
    Sep 2004
    Posts
    2
    Points
    0

    Default

    I have gone through the same steps as you, and still cannot get rid of netspry. Let me know if you figure this thing out?

  6. #6
    Member poohbearjim's Avatar
    Join Date
    Sep 2004
    Posts
    3
    Points
    0

    Default

    That seemed to work. I followed the recommendations last night and I haven't had any problems since! Thank you!!!!!

  7. #7
    Member steamwiz's Avatar
    Join Date
    Sep 2003
    Location
    Yorkshire U.K.
    Posts
    14,022
    Points
    2335

    Default

    Hi

    Great ... you're very welcome

    steam
    Look here for Ways to keep your computer safe
    M'SOFT MVP -Windows Security 2004/8 .member ASAP -