Two Viruses've Invaded My Personal Computer. Help Me Please
Hello Everybody
I formated my computer and downloaded windows Xp SP2. After formating I scanned my system with BitDefender program. It was two multiplied viruses named :
- exploit.win32.cve-2004-1305.gen
- win32.Almsfir.vb.a
However, I deleted hardly the viruses but there was a problem that I could not open any of my drivers e.g: c-d-f....Everytime I opened my driver, an "open with" window is appeared .........
here is a picture explain exactly the situation:
I am waiting your best solution
and thank you very much in advance
best regards,
angls
Comments
-
Hello Everybody
I formated my computer and downloaded windows Xp SP2. After formating I scanned my system with BitDefender program. It was two multiplied viruses named :
- exploit.win32.cve-2004-1305.gen
- win32.Almsfir.vb.a
However, I deleted hardly the viruses but there was a problem that I could not open any of my drivers e.g: c-d-f....Everytime I opened my driver, an "open with" window is appeared .........
here is a picture explain exactly the situation:
I am waiting your best solution
and thank you very much in advance
best regards,
angls
Make sure you are using a legal copy of Windows and none of your software is pirated. As on a fresh install of Windows and the installation of legit software should leave you with no malware on your machine, unless you accidentally visited an infected website unknowingly. You should be able to do a repair installation of Windows by inserting your Windows Disc booting to the installer and selecting Repair this installation where you have the option to install Windows.0 -
Hello angls,
Please download fix drive. Save it on your desktop. Extract the archive by right clicking on it and let it for example extract in a folder called fixdrive_v1_3 Open that folder and double click on FixDrive.exe. Select your drive letter and press on fix.
Please perform another deep scan.
Can you please download combofix you will find it here. Print the following instructions and read them carefully. Please post the output of the scan into your next post. So I or someone else can see if there is still some infections.
Kind regards,
Niels0 -
Dear friends
hi thank you very much for your replay!
Actually, Niels was right . I fixed my drivers and here is the output of combofix's scan:
ComboFix 08-08-18.04 - Dannouf 08/19/2008 10:40:08.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.628 [GMT 3:00]
Running from: C:\Documents and Settings\Dannouf\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dannouf\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\x64
C:\WINDOWS\ufdata2000.log
.
((((((((((((((((((((((((( Files Created from 2008-07-19 to 2008-08-19 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-19 07:40 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-08-19 07:39 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Orbit
2008-08-18 12:43 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Skype
2008-08-17 21:26 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Nokia Multimedia Player
2008-08-17 16:11 --------- d-----w C:\Program Files\Common Files\element5 Shared
2008-08-17 16:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\element5
2008-08-17 16:10 --------- d--h--w C:\Program Files\Zero G Registry
2008-08-17 16:10 --------- d-----w C:\Program Files\Pixologic
2008-08-17 15:45 --------- d-----w C:\Program Files\Macromedia
2008-08-17 15:45 --------- d-----w C:\Program Files\Common Files\Macromedia
2008-08-17 09:03 --------- d-----w C:\Program Files\Orbitdownloader
2008-08-16 21:53 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Nokia
2008-08-16 21:51 --------- d-----w C:\Program Files\Nokia
2008-08-16 21:51 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-08-16 21:51 --------- d-----w C:\Program Files\Common Files\Nokia
2008-08-16 21:51 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\PC Suite
2008-08-16 14:37 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-16 14:37 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\AdobeUM
2008-08-16 14:32 --------- d-----w C:\Program Files\Bradbury
2008-08-16 14:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-16 12:23 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Ahead
2008-08-16 11:58 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Ulead Systems
2008-08-16 11:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-08-16 11:15 --------- d-----w C:\Program Files\Windows Media Components
2008-08-16 11:15 --------- d-----w C:\Program Files\Common Files\Ulead Systems
2008-08-16 11:15 --------- d-----w C:\Program Files\Common Files\InterVideo
2008-08-16 11:15 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-08-16 11:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\InterVideo
2008-08-16 11:14 --------- d-----w C:\Program Files\Ulead Systems
2008-08-16 10:22 --------- d-----w C:\Program Files\QuickEditor
2008-08-16 07:39 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\COWON
2008-08-16 07:03 --------- d-----w C:\Program Files\TEXTware
2008-08-16 07:03 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Oxford
2008-08-16 07:02 --------- d-----w C:\Program Files\Oxford
2008-08-16 06:41 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Media Player Classic
2008-08-15 21:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-08-15 20:56 --------- d-----w C:\Program Files\Bonjour
2008-08-15 20:46 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-08-15 20:22 --------- d-----w C:\Program Files\Google
2008-08-15 20:20 --------- d-----w C:\Program Files\Microsoft Works
2008-08-15 20:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-15 20:19 --------- d-----w C:\Program Files\MSBuild
2008-08-15 20:18 --------- d-----w C:\Program Files\Microsoft.NET
2008-08-15 20:17 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-08-15 19:17 --------- d-----w C:\Program Files\Golden Al-Wafi Translator
2008-08-15 19:16 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-08-15 19:16 172,032 ------w C:\WINDOWS\Setup1.exe
2008-08-15 18:47 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Apple Computer
2008-08-15 18:43 --------- d-----w C:\Program Files\QuickTime
2008-08-15 18:42 --------- d-----w C:\Program Files\iTunes
2008-08-15 18:42 --------- d-----w C:\Program Files\iPod
2008-08-15 18:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-15 18:40 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-08-15 18:40 --------- d-----w C:\Program Files\JetAudio
2008-08-15 18:40 --------- d-----w C:\Program Files\Common Files\COWON
2008-08-15 18:38 --------- d-----w C:\Program Files\Webteh
2008-08-15 18:38 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\BSplayer PRO
2008-08-15 18:37 --------- d-----w C:\Program Files\Allok 3GP PSP MP4 iPod Video Converter
2008-08-15 18:32 --------- d-----w C:\Program Files\Nero
2008-08-15 18:32 --------- d-----w C:\Program Files\Common Files\Ahead
2008-08-15 18:30 --------- d-----w C:\Program Files\Yahoo!
2008-08-15 18:30 --------- d-----w C:\Program Files\Java
2008-08-15 18:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-08-15 18:29 --------- d-----w C:\Program Files\Common Files\Java
2008-08-15 18:28 --------- d-----w C:\Program Files\Skype
2008-08-15 18:28 --------- d-----w C:\Program Files\Common Files\Skype
2008-08-15 18:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-08-15 18:26 --------- d-----w C:\Program Files\Windows Live
2008-08-15 18:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-15 18:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\WindowsLiveInstaller
2008-08-15 18:04 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Bitdefender
2008-08-15 18:03 --------- d-----w C:\Program Files\Common Files\BitDefender
2008-08-15 18:03 --------- d-----w C:\Program Files\BitDefender
2008-08-15 18:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\BitDefender
2008-08-15 17:59 --------- d-----w C:\Program Files\Canon
2008-08-15 17:57 --------- d-----w C:\Program Files\HP
2008-08-15 17:57 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\HP
2008-08-15 17:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-08-15 17:55 --------- d-----w C:\Program Files\Hewlett-Packard
2008-08-15 17:55 --------- d-----w C:\Program Files\Common Files\HP
2008-08-15 17:46 --------- d-----w C:\Program Files\Realtek
2008-08-15 17:32 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [03/27/2007 03:22 PM 4670968]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [08/04/2004 01:06 AM 1667584]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [05/17/2007 01:11 PM 5729136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Orbit.lnk - C:\Program Files\Orbitdownloader\orbitdm.exe [2008-08-17 12:03:39 1585152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Orbit.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk
backup=C:\WINDOWS\pss\Orbit.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDAgent]
--a------ 08/07/2007 07:19 PM 270336 C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 08/04/2004 03:56 AM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
-ra------ 10/05/2006 04:13 PM 114688 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 02/19/2006 02:41 AM 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
-ra------ 10/05/2006 04:11 PM 98304 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 08/04/2004 01:32 AM 208952 C:\WINDOWS\ime\imjp8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 10/06/2005 06:03 PM 278528 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 08/04/2004 01:06 AM 1667584 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 05/17/2007 01:11 PM 5729136 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
--a------ 08/04/2004 01:31 AM 59392 C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 12/13/2005 08:49 AM 217088 C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
-ra------ 10/05/2006 04:10 PM 94208 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 08/04/2004 01:32 AM 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 08/04/2004 01:32 AM 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 08/15/2008 09:43 PM 155648 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 08/31/2007 05:40 PM 22879528 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 03/14/2007 03:43 AM 83608 C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 03/27/2007 03:22 PM 4670968 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
--------- 12/12/2005 09:50 AM 88204 C:\WINDOWS\AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 05/02/2005 07:00 PM 69632 C:\WINDOWS\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
--a------ 08/04/2004 03:56 AM 110592 C:\WINDOWS\system32\bthprops.cpl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 12/17/2006 07:00 PM 16062464 C:\WINDOWS\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
-r------- 05/15/2006 07:00 PM 2879488 C:\WINDOWS\SkyTel.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [07/30/2007 06:47 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{196b1318-6bdd-11dd-9a1e-001e10006c9e}]
\Shell\Auto\command - I:\sal.xls.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sal.xls.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{44637c3c-6b7d-11dd-9a1c-001e10006c9e}]
\Shell\Auto\command - I:\sal.xls.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sal.xls.exe
*Newly Created Service* - 55BD77EB
*Newly Created Service* - B11445D6
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-IMJPMIG8 - msime80.exe
MSConfigStartUp-MsServer - msfir80.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Dannouf\Application Data\Mozilla\Firefox\Profiles\hf97zczq.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-19 10:41:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
.
Completion time: 08/19/2008 10:42:31
ComboFix-quarantined-files.txt 2008-08-19 07:42:27
Pre-Run: 21,170,741,248 bytes free
Post-Run: 21,245,145,088 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
2320 -
So are you still having problems?
The logs look fairly clean.
I suspect I:\sal.xls.exe was one of the infected files.
In case problems still persist, could you please try and find I:\sal.xls.exe(or a file with the same name in c:\Windows\ystem32) and also C:\WINDOWS\Setup1.exe.0 -
So are you still having problems?
The logs look fairly clean.
I suspect I:\sal.xls.exe was one of the infected files.
In case problems still persist, could you please try and find I:\sal.xls.exe(or a file with the same name in c:\Windows\ystem32) and also C:\WINDOWS\Setup1.exe.
hi! thanks for your replay....
NO, I do not see any problem right now... I searched for "sal.xls.exe" I did not see any file named like that.On the other hand, I found Setup1.exe in windows file....
so please tell me if my computer still infected ???
I really thank you for your kind attention.
best regards to you all,
angls0 -
Hello I'm angls,
Can you please do this also. I suppose that I: is a flash disk,pen drive,external hard disk. Plug it in. Now click on start,my computer,right click on I: choose explore. After that go to the tools menu,folder options,press on the display/view tab. Select the option show hidden files and folders press on apply and ok. See if you now can see it.
Archive all the files that Catalin mentioned. To do that follow the instructions in the second post.
After you can add the attachments to a new topic in this forum section. Once you are in the screen for creating a new topic scroll down untill you see the Attachments section press on browse and upload the archives that you have created press on upload. There is an 2 mb file limit.
Kind regards,
Niels0 -
Hello I'm angls,
Can you please do this also. I suppose that I: is a flash disk,pen drive,external hard disk. Plug it in. Now click on start,my computer,right click on I: choose explore. After that go to the tools menu,folder options,press on the display/view tab. Select the option show hidden files and folders press on apply and ok. See if you now can see it.
Archive all the files that Catalin mentioned. To do that follow the instructions in the second post.
After you can add the attachments to a new topic in this forum section. Once you are in the screen for creating a new topic scroll down untill you see the Attachments section press on browse and upload the archives that you have created press on upload. There is an 2 mb file limit.
Kind regards,
Niels
Dear Niels
hi how are you? thanks for your replay
Actually, I formatted my flash memory few days ago. I do not think the file is still located in my flash memory.......However,...
I appreciate your responses very much
thanks/best regards,
Yours sincerely
angls0