This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

It Won't Go Away!

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.98.2
Scan saved at 9:09:52 AM, on 8/13/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\progra~1\intern~1\iexplore.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Spy_Hijack_Utils\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://in.webcounter.cc/–/?toaqy (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gmguxtnwae.net/rmO6iP3ia_t_KNOrTBLo…ScSugkakpy8.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.ecgonizisgl.us/rmO6iP3ia_viz_5c…2Oa0nQGmso.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.boredlife.com/search/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=ftp.proxy.intermet.com:80;http=http.proxy.intermet.com:80;https=https.proxy.intermet.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ap30.intermet.com
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: zSearch Bar - {5886A6DC-AAF4-45E9-979A-8E5E6DEE30E7} - C:\Program Files\zSearch\zSearch.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [zSearch] C:\Program Files\zSearch\Zstb.exe
O4 - HKLM\..\Run: [Tick That] C:\PROGRA~1\BLEH16~1\thisstop.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [sws.exe] c:\program files\GlobalDialer\wordi00047\930862781.exe -remove
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [zSearch] C:\Program Files\zSearch\Zstb.exe
O4 - HKCU\..\Run: [Upload Noun Corn Copy] C:\Documents and Settings\All Users\Application Data\dvdtestuploadnoun\4 Ref.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {0A100429-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Inbox 10.0) - http://ap30.intermet.com/TechServices/en-us/atx.cab
O16 - DPF: {0A100528-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Version Control 10.1) - http://ap30.intermet.com/TechServices/en-us/verctrl.cab
O16 - DPF: {0A100603-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Authentication Control 10.1) - http://ap30.intermet.com/TechServices/en-us/atx.cab
O16 - DPF: {0A100781-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Grid 10.1) - http://ap30.intermet.com/TechServices/en-us/Grid.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50183/QDow_AS2.cab
O16 - DPF: {96E14646-9072-4925-8001-6A303CD41030} (ActiveProject PopupMenu 10.1) - http://ap30.intermet.com/TechServices/en-us/PopupMenu.cab
O16 - DPF: {C3A57B60-C117-11D2-BD9B-00105A0A7E89} (SAXFile ActiveX Control) - http://ap30.intermet.com/TechServices/en-us/FileTransfer.cab
O16 - DPF: {FC7152E4-E31A-44F1-8274-D7F7138F5E2B} (ActiveProject Grid 10.0) - http://ap30.intermet.com/TechServices/en-us/Grid.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = intermet.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = intermet.com
O19 - User stylesheet: (file missing)
Click here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'. Reboot when done.

Click here to download Spybot Search & Destroy - install, update, scan and fix all RED items it finds. Reboot when done.

Click here to download Ad-Aware and install. Before scanning click on "check for updates now" to make sure you have the latest reference file. Then click the gear wheel at the top and check these options:

General> activate these: "Automatically save log-file" and "Automatically quarantine objects prior to removal"

Scanning > activate these: "Scan within archives", "Scan active processes", "Scan registry", "Deep scan registry", "Scan my IE Favorites for banned sites" and "Scan my Hosts file"

Tweaks > Scanning Engine> activate this: "Unload recognized processes during scanning."

Tweaks > Cleaning Engine: activate these: "Automatically try to unregister objects prior to deletion" and "Let Windows remove files in use after reboot."

Click "Proceed" to save your settings, then click "Start", make sure "Activate in-depth scan" is ticked green then scan your system. When the scan is finished, the screen will tell you if anything has been found, click "Next". The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".

Reboot when done. Rescan with HJT and post a new log here so that any remnants can be removed manually.
I did as instructed, here is the new log file. Thanks much!

Logfile of HijackThis v1.98.2
Scan saved at 11:14:05 AM, on 8/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Centenn.ial\Audit\CAgent32.exe
C:\Centenn.ial\Audit\xferwan.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Lotus\Notes\ntmulti.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
c:\progra~1\intern~1\iexplore.exe
C:\Spy_Hijack_Utils\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myway.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.yvnxrmcdurzlzmfu.biz/rmO6iP3ia_…2Oa0nQGmso.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=ftp.proxy.intermet.com:80;http=http.proxy.intermet.com:80;https=https.proxy.intermet.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ap30.intermet.com
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [Tick That] C:\PROGRA~1\BLEH16~1\thisstop.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {0A100429-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Inbox 10.0) - http://ap30.intermet.com/TechServices/en-us/atx.cab
O16 - DPF: {0A100528-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Version Control 10.1) - http://ap30.intermet.com/TechServices/en-us/verctrl.cab
O16 - DPF: {0A100603-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Authentication Control 10.1) - http://ap30.intermet.com/TechServices/en-us/atx.cab
O16 - DPF: {0A100781-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Grid 10.1) - http://ap30.intermet.com/TechServices/en-us/Grid.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50183/QDow_AS2.cab
O16 - DPF: {96E14646-9072-4925-8001-6A303CD41030} (ActiveProject PopupMenu 10.1) - http://ap30.intermet.com/TechServices/en-us/PopupMenu.cab
O16 - DPF: {C3A57B60-C117-11D2-BD9B-00105A0A7E89} (SAXFile ActiveX Control) - http://ap30.intermet.com/TechServices/en-us/FileTransfer.cab
O16 - DPF: {FC7152E4-E31A-44F1-8274-D7F7138F5E2B} (ActiveProject Grid 10.0) - http://ap30.intermet.com/TechServices/en-us/Grid.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = intermet.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = intermet.com
O19 - User stylesheet: (file missing)
Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myway.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.yvnxrmcdurzlzmfu.biz/rmO6iP3ia_…2Oa0nQGmso.html
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll (file missing)
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [Tick That] C:\PROGRA~1\BLEH16~1\thisstop.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50183/QDow_AS2.cab
O19 - User stylesheet: (file missing)

Reboot when done, rescan with HJT and post a new log here for a final check over.
Here's the new log

Logfile of HijackThis v1.98.2
Scan saved at 9:54:57 AM, on 8/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Centenn.ial\Audit\CAgent32.exe
C:\Centenn.ial\Audit\xferwan.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Lotus\Notes\ntmulti.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Spy_Hijack_Utils\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=ftp.proxy.intermet.com:80;http=http.proxy.intermet.com:80;https=https.proxy.intermet.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ap30.intermet.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {0A100429-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Inbox 10.0) - http://ap30.intermet.com/TechServices/en-us/atx.cab
O16 - DPF: {0A100528-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Version Control 10.1) - http://ap30.intermet.com/TechServices/en-us/verctrl.cab
O16 - DPF: {0A100603-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Authentication Control 10.1) - http://ap30.intermet.com/TechServices/en-us/atx.cab
O16 - DPF: {0A100781-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Grid 10.1) - http://ap30.intermet.com/TechServices/en-us/Grid.cab
O16 - DPF: {96E14646-9072-4925-8001-6A303CD41030} (ActiveProject PopupMenu 10.1) - http://ap30.intermet.com/TechServices/en-us/PopupMenu.cab
O16 - DPF: {C3A57B60-C117-11D2-BD9B-00105A0A7E89} (SAXFile ActiveX Control) - http://ap30.intermet.com/TechServices/en-us/FileTransfer.cab
O16 - DPF: {FC7152E4-E31A-44F1-8274-D7F7138F5E2B} (ActiveProject Grid 10.0) - http://ap30.intermet.com/TechServices/en-us/Grid.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = intermet.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = intermet.com
Yes, Intermet.com is our parent company.
I logged on as the user, opened IE and it still had the wrong home page (I had reconnected the network cable). I was able to change it to cnn.com, but there was still an unwanted search bar at the bottom. I ran Spybot as the user and it found eZula Hot Text, 74 objects. I logged on as admin, ran CWS, Spybot and Ad-Aware as in the first instruction. They found quite a few problems, I fixed all of them. I logged on as the user again, and his home page had become about:blank, which I couldn't change. I have been running these things as admin, is that correct? Also shoud the PC be on the network when they are run? I selected the option in Ad-Aware to scan for all users, is that okay? The latest log is below. Many thanks for your help.

Logfile of HijackThis v1.98.2
Scan saved at 2:51:31 PM, on 8/17/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Centenn.ial\Audit\CAgent32.exe
C:\Centenn.ial\Audit\xferwan.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Lotus\Notes\ntmulti.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\ORL\VNC\WinVNC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Spy_Hijack_Utils\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.sepglwemzwvvfldymsylwdvw.com/rm…2Oa0nQGmso.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=ftp.proxy.intermet.com:80;http=http.proxy.intermet.com:80;https=https.proxy.intermet.com:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ap30.intermet.com
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O16 - DPF: {0A100429-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Inbox 10.0) - http://ap30.intermet.com/TechServices/en-us/atx.cab
O16 - DPF: {0A100528-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Version Control 10.1) - http://ap30.intermet.com/TechServices/en-us/verctrl.cab
O16 - DPF: {0A100603-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Authentication Control 10.1) - http://ap30.intermet.com/TechServices/en-us/atx.cab
O16 - DPF: {0A100781-B8E6-11D1-BC4D-006008CCBF84} (ActiveProject Grid 10.1) - http://ap30.intermet.com/TechServices/en-us/Grid.cab
O16 - DPF: {96E14646-9072-4925-8001-6A303CD41030} (ActiveProject PopupMenu 10.1) - http://ap30.intermet.com/TechServices/en-us/PopupMenu.cab
O16 - DPF: {C3A57B60-C117-11D2-BD9B-00105A0A7E89} (SAXFile ActiveX Control) - http://ap30.intermet.com/TechServices/en-us/FileTransfer.cab
O16 - DPF: {FC7152E4-E31A-44F1-8274-D7F7138F5E2B} (ActiveProject Grid 10.0) - http://ap30.intermet.com/TechServices/en-us/Grid.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = intermet.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = intermet.com
This thing is driving me crazier. The user had to have his PC back for some meeting preparation, I went over and reconnected the cable, started IE and it came up and looked ok! Haven't been able to talk to him since, so don't know if it stayed that way or not. Just thought I should let you know. Again, thanks!
You're welcome - glad to help :D

To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?



As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI