Another about:blank hijack

Discussion in 'adware, spyware & hijack cleaning' started by Chris TF, May 9, 2004.

Thread Status:
Not open for further replies.
  1. Chris TF

    Chris TF Registered Member

    Joined:
    May 9, 2004
    Posts:
    3
    I guesss I am the latest victim of a home page hijack.
    I'd be grateful on your advice on haow to fix it.
    I use Spyboy S&D and SpyWareBlaster.

    Many thanks

    Chris TF

    Logfile of HijackThis v1.97.7
    Scan saved at 14:40:20, on 09/05/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\Program Files\Network Associates\VirusScan\mcshield.exe
    C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\Program Files\Firebird\bin\ibserver.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://HERO:80/array.dll?Get.Routing.Script
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://HERO:80
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {983BA86F-426D-466C-80FF-87E530D4B621} - C:\WINDOWS\mrhop.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [mswspl] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - Global Startup: Firebird Database Engine.lnk = C:\Program Files\Firebird\bin\ibserver.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O14 - IERESET.INF: START_PAGE_URL=http://intranet
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/29d60cd0eb33119de220/netzip/RdxIE601.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38075.3055671296
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wellington.net.uk
    O17 - HKLM\Software\..\Telephony: DomainName = wellington.net.uk
    O17 - HKLM\System\CCS\Services\Tcpip\..\{346513C3-7795-498F-B6EC-AE6E7E171517}: Domain = wellington-college.berks.sch.uk
    O17 - HKLM\System\CCS\Services\Tcpip\..\{346513C3-7795-498F-B6EC-AE6E7E171517}: NameServer = 192.168.0.2
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = wellington.net.uk
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = wellington.net.uk
    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = wellington.net.uk
     
  2. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Start with the following:
    Surf to http://www10.brinkster.com/expl0iter/freeatlast/PVtool.htm
    And download and unzip Find-All.zip
    Inside the unzipped folder find the file Find All.bat and doubleclick it.

    When it is done it will produce a file output.txt in that same folder.
    Post the content of that file and let me know if your system is dual-boot, whether you have an XP-CD or a bootdisk.

    Regards,

    Pieter
     
  3. Chris TF

    Chris TF Registered Member

    Joined:
    May 9, 2004
    Posts:
    3
    Thanks very much for the prompt reply.
    My system is not dual-boot, and I have an XP-CD.

    Here's the data you asked for:

    --===**'FIND-ALL' VERSION 2, 5/04**===--

    System Info:

    Microsoft Windows XP [Version 5.1.2600]
    C: "" (20D9:5A5D) - FS:NTFS clusters:4k
    Total: 80 015 491 072 [75G] - Free: 58 196 930 560 [54G]


    Locked or 'Suspect' file(s) found...


    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""
    "DeviceNotSelectedTimeout"="15"
    "GDIProcessHandleQuota"=dword:00002710
    "Spooler"="yes"
    "swapdisk"=""
    "TransmissionRetryTimeout"="90"
    "USERProcessHandleQuota"=dword:00002710

    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper

    Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper

    Objects\{53707962-6F74-2D53-2644-206D7942484F}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper

    Objects\{983BA86F-426D-466C-80FF-87E530D4B621}]

    REGEDIT4

    [HKEY_CLASSES_ROOT\PROTOCOLS\Filter]

    [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\Class Install Handler]
    @="AP Class Install Handler filter"
    "CLSID"="{32B533BB-EDAE-11d0-BD5A-00AA00B92AF1}"

    [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\deflate]
    @="AP Deflate Encoding/Decoding Filter "
    "CLSID"="{8f6b0360-b80d-11d0-a9b3-006097942311}"

    [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\gzip]
    @="AP GZIP Encoding/Decoding Filter "
    "CLSID"="{8f6b0360-b80d-11d0-a9b3-006097942311}"

    [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\lzdhtml]
    @="AP lzdhtml encoding/decoding Filter"
    "CLSID"="{8f6b0360-b80d-11d0-a9b3-006097942311}"

    [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/html]
    "CLSID"="{6F573C0B-73D6-49E5-B80B-EC0A2DBBE955}"

    [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/plain]
    "CLSID"="{6F573C0B-73D6-49E5-B80B-EC0A2DBBE955}"

    [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/webviewhtml]
    @="WebView MIME Filter"
    "CLSID"="{733AC4CB-F1A4-11d0-B951-00A0C90312E1}"

    Class Install Handler
    {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1}
    C:\WINDOWS\system32\urlmon.dll

    deflate
    {8f6b0360-b80d-11d0-a9b3-006097942311}
    C:\WINDOWS\system32\urlmon.dll

    gzip
    {8f6b0360-b80d-11d0-a9b3-006097942311}
    C:\WINDOWS\system32\urlmon.dll

    lzdhtml
    {8f6b0360-b80d-11d0-a9b3-006097942311}
    C:\WINDOWS\system32\urlmon.dll

    text/html
    {6F573C0B-73D6-49E5-B80B-EC0A2DBBE955}
    C:\WINDOWS\mrhop.dll

    text/plain
    {6F573C0B-73D6-49E5-B80B-EC0A2DBBE955}
    C:\WINDOWS\mrhop.dll

    text/webviewhtml
    {733AC4CB-F1A4-11d0-B951-00A0C90312E1}
    %SystemRoot%\system32\SHELL32.dll

    {6F573C0B-73D6-49E5-B80B-EC0A2DBBE955} C:\WINDOWS\mrhop.dll
    {983BA86F-426D-466C-80FF-87E530D4B621} C:\WINDOWS\mrhop.dll
    {6F573C0B-73D6-49E5-B80B-EC0A2DBBE955} C:\WINDOWS\mrhop.dll
    {983BA86F-426D-466C-80FF-87E530D4B621} C:\WINDOWS\mrhop.dll

    _______________________________

    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
    C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    {53707962-6F74-2D53-2644-206D7942484F}
    C:\PROGRA~1\SPYBOT~1\SDHelper.dll

    {983BA86F-426D-466C-80FF-87E530D4B621}
    C:\WINDOWS\mrhop.dll

    --==***Probable "bad" file will be represented as
    C:\WINDOWS...System32...XXXX.dll***==--

    Handle v2.2
    Copyright (C) 1997-2004 Mark Russinovich
    Sysinternals - www.sysinternals.com

    ------------------------------------------------------------------------------
    winlogon.exe pid: 468 NT AUTHORITY\SYSTEM
    b4: File

    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805
    b8: File

    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805
    100: Section \BaseNamedObjects\Debug.Memory.1d4
    148: Section \BaseNamedObjects\ShimSharedMemory
    198: File

    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805
    204: File C:\WINDOWS\AppPatch
    208: File C:\WINDOWS\system32\dllcache
    20c: File C:\Program Files\Common Files\Microsoft Shared\web server

    extensions\40\isapi\_vti_adm
    210: File C:\Program Files\Common Files\Microsoft Shared\web server

    extensions\40\_vti_bin\_vti_adm
    214: File C:\WINDOWS\system32
    218: File C:\Program Files\Common Files\Microsoft Shared\web server

    extensions\40\isapi\_vti_aut
    21c: File C:\Program Files\Common Files\Microsoft Shared\web server

    extensions\40\_vti_bin\_vti_aut
    220: File C:\WINDOWS\system32\inetsrv
    224: File C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\bin
    228: File C:\WINDOWS\Fonts
    22c: File C:\WINDOWS\system32\drivers
    230: File C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\servsupp
    234: File C:\Program Files\Common Files\Microsoft Shared\web server

    extensions\40\bots\vinavbar
    238: File C:\Program Files\microsoft frontpage\version3.0\bin
    23c: File C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\_vti_bin
    240: File C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\bin\1033
    244: File C:\Program Files\Common Files\Microsoft Shared\web server extensions\40\isapi
    248: File C:\WINDOWS
    24c: File C:\Program Files\Common Files\Microsoft Shared\DAO
    250: File C:\Program Files\Windows Media Player
    254: File C:\Program Files\Common Files\System\msadc
    258: File C:\Program Files\Common Files\System\ado
    25c: File C:\Program Files\Common Files\System\Ole DB
    260: File C:\WINDOWS\inf
    264: File C:\WINDOWS\system
    268: File C:\WINDOWS\msagent
    26c: File C:\WINDOWS\msagent\intl
    270: File C:\Program Files\MSN Gaming Zone\Windows
    274: File C:\WINDOWS\Help
    278: File C:\WINDOWS\PCHEALTH\HELPCTR\Binaries
    27c: File C:\Program Files\NetMeeting
    280: File C:\WINDOWS\system32\drivers\disdn
    284: File C:\WINDOWS\ime\CHTIME\Applets
    288: File C:\WINDOWS\system32\wbem
    28c: File C:\WINDOWS\system32\IME\CINTLGNT
    290: File C:\WINDOWS\system32\Com
    294: File C:\WINDOWS\system32\Setup
    298: File C:\WINDOWS\ime\imjp8_1
    29c: File C:\Program Files\Common Files\Microsoft Shared\Triedit
    2a0: File C:\Program Files\Windows NT
    2a4: File C:\Program Files\Common Files\System
    2a8: File C:\WINDOWS\system32\1033
    2ac: File C:\Program Files\Common Files\Microsoft Shared\web server

    extensions\40\admcgi\scripts
    2b0: File C:\Program Files\Common Files\Microsoft Shared\web server

    extensions\40\admisapi\scripts
    2b4: File C:\WINDOWS\system32\usmt
    2b8: File C:\WINDOWS\ime\imkr6_1\dicts
    2bc: File C:\WINDOWS\system32\mui\0009
    2c0: File C:\Program Files\Internet Explorer
    2c4: File C:\WINDOWS\ime\imjp8_1\applets
    2c8: File C:\WINDOWS\ime\imkr6_1\applets
    2cc: File C:\WINDOWS\system32\xircom
    2d0: File C:\Program Files\Internet Explorer\Connection Wizard
    2d4: File C:\Program Files\Common Files\Microsoft Shared\MSInfo
    2d8: File C:\WINDOWS\ime\imkr6_1
    2dc: File C:\WINDOWS\ime\shared
    2e0: File C:\WINDOWS\system32\IME\PINTLGNT
    2e4: File C:\Program Files\Common Files\SpeechEngines\Microsoft\Lexicon\1033
    2e8: File C:\WINDOWS\Resources\Themes\Luna
    2ec: File C:\Program Files\Movie Maker
    2f0: File C:\WINDOWS\ime
    2f4: File C:\WINDOWS\srchasst
    2f8: File C:\Program Files\Outlook Express
    2fc: File C:\WINDOWS\system32\oobe
    300: File C:\Program Files\Common Files\MSSoap\Binaries
    304: File C:\Program Files\Common Files\MSSoap\Binaries\Resources\1033
    308: File C:\WINDOWS\mui
    30c: File C:\WINDOWS\system32\npp
    310: File C:\WINDOWS\ime\shared\res
    314: File C:\Program Files\Windows NT\Pinball
    318: File C:\WINDOWS\ime\chsime\applets
    31c: File C:\WINDOWS\system32\Restore
    320: File C:\Program Files\Common Files\SpeechEngines\Microsoft\TTS\1033
    324: File C:\Program Files\Common Files\Microsoft Shared\Speech
    328: File C:\WINDOWS\Resources\Themes\Luna\Shell\NormalColor
    32c: File C:\WINDOWS\Resources\Themes\Luna\Shell\Homestead
    330: File C:\WINDOWS\Resources\Themes\Luna\Shell\Metallic
    334: File C:\WINDOWS\system32\wbem\snmp
    338: File C:\Program Files\Common Files\SpeechEngines\Microsoft
    33c: File C:\Program Files\Common Files\Microsoft Shared\Speech\1033
    340: File C:\WINDOWS\system32\spool\drivers\color
    344: File C:\WINDOWS\system32\IME\TINTLGNT
    348: File C:\WINDOWS\Help\Tours\mmTour
    34c: File C:\WINDOWS\PCHEALTH\UploadLB\Binaries
    350: File C:\Program Files\Common Files\Microsoft Shared\VGX
    354: File C:\WINDOWS\system32\wbem\xml
    358: File C:\Program Files\Windows NT\Accessories
    35c: File C:\WINDOWS\system32\mui\0401
    360: File C:\WINDOWS\system32\mui\0404
    364: File C:\WINDOWS\system32\mui\0405
    368: File C:\WINDOWS\system32\mui\0406
    36c: File C:\WINDOWS\system32\mui\0407
    370: File C:\WINDOWS\system32\mui\0408
    374: File C:\WINDOWS\system32\mui\040b
    378: File C:\WINDOWS\system32\mui\040c
    37c: File C:\WINDOWS\system32\mui\040d
    380: File C:\WINDOWS\system32\mui\040e
    384: File C:\WINDOWS\system32\mui\0410
    388: File C:\WINDOWS\system32\mui\0411
    38c: File C:\WINDOWS\system32\mui\0412
    390: File C:\WINDOWS\system32\mui\0413
    394: File C:\WINDOWS\system32\mui\0414
    398: File C:\WINDOWS\system32\mui\0415
    39c: File C:\WINDOWS\system32\mui\0416
    3a0: File C:\WINDOWS\system32\mui\0419
    3a4: File C:\WINDOWS\system32\mui\041d
    3a8: File C:\WINDOWS\system32\mui\041f
    3ac: File C:\WINDOWS\system32\mui\0804
    3b0: File C:\WINDOWS\system32\mui\0816
    3b4: File C:\WINDOWS\system32\mui\0c0a
    3b8: File C:\WINDOWS\system32\mui\0402
    3bc: File C:\WINDOWS\system32\mui\0418
    3c0: File C:\WINDOWS\system32\mui\041a
    3c4: File C:\WINDOWS\system32\mui\041b
    3c8: File C:\WINDOWS\system32\mui\041e
    3cc: File C:\WINDOWS\system32\mui\0424
    3d0: File C:\WINDOWS\system32\mui\0425
    3d4: File C:\WINDOWS\system32\mui\0426
    3d8: File C:\WINDOWS\system32\mui\0427
    3dc: File C:\Program Files\xerox\nwwia
    3ec: File C:\WINDOWS\WinSxS
    76c: File

    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805
    890: Section \BaseNamedObjects\mmGlobalPnpInfo
    914: File \Dfs
    98c: Section \BaseNamedObjects\__R_000000000007_SMem__
    9bc: Section \BaseNamedObjects\WDMAUD_Device_Interface_Path
    9c0: Section \BaseNamedObjects\WDMAUD_Path_Size
    9cc: Section \BaseNamedObjects\WDMAUD_Callbacks
    a6c: File C:\WINDOWS\system32



    I look forward to your analysis!
    Regards

    Chris TF
     
  4. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Hi Chris,

    This is strange. It may turn out you have yet another new variant.

    Could you mail me C:\WINDOWS\mrhop.dll
    Send it to pieterATwilderssecurity.org (replace AT with @)

    After that check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\mrhop.dll/sp.html (obfuscated)

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

    O2 - BHO: (no name) - {983BA86F-426D-466C-80FF-87E530D4B621} - C:\WINDOWS\mrhop.dll

    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE

    O4 - HKLM\..\Run: [mswspl] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/29d60cd...ip/RdxIE601.cab

    Regards,

    Pieter
     
    Last edited: May 10, 2004
  5. Chris TF

    Chris TF Registered Member

    Joined:
    May 9, 2004
    Posts:
    3
    Pieter
    Just to let you know I will be away from my computer for 2 days from now, but look forward to your next advice. Have sent on the e-mail.
    Thanks for the continued support.
    Chris
     
Thread Status:
Not open for further replies.