Two Viruses've Invaded My Personal Computer. Help Me Please

Hello Everybody


I formated my computer and downloaded windows Xp SP2. After formating I scanned my system with BitDefender program. It was two multiplied viruses named :


- exploit.win32.cve-2004-1305.gen


- win32.Almsfir.vb.a


However, I deleted hardly the viruses but there was a problem that I could not open any of my drivers e.g: c-d-f....Everytime I opened my driver, an "open with" window is appeared .........


here is a picture explain exactly the situation:


Help.jpg


I am waiting your best solution


and thank you very much in advance


best regards,


angls

Comments

  • Hello Everybody


    I formated my computer and downloaded windows Xp SP2. After formating I scanned my system with BitDefender program. It was two multiplied viruses named :


    - exploit.win32.cve-2004-1305.gen


    - win32.Almsfir.vb.a


    However, I deleted hardly the viruses but there was a problem that I could not open any of my drivers e.g: c-d-f....Everytime I opened my driver, an "open with" window is appeared .........


    here is a picture explain exactly the situation:


    Help.jpg


    I am waiting your best solution


    and thank you very much in advance


    best regards,


    angls


    Make sure you are using a legal copy of Windows and none of your software is pirated. As on a fresh install of Windows and the installation of legit software should leave you with no malware on your machine, unless you accidentally visited an infected website unknowingly. You should be able to do a repair installation of Windows by inserting your Windows Disc booting to the installer and selecting Repair this installation where you have the option to install Windows.

  • Niels
    Niels
    edited August 2008

    Hello angls,


    Please download fix drive. Save it on your desktop. Extract the archive by right clicking on it and let it for example extract in a folder called fixdrive_v1_3 Open that folder and double click on FixDrive.exe. Select your drive letter and press on fix.


    Please perform another deep scan.


    Can you please download combofix you will find it here. Print the following instructions and read them carefully. Please post the output of the scan into your next post. So I or someone else can see if there is still some infections.


    Kind regards,


    Niels

  • angls
    edited August 2008

    Dear friends


    hi thank you very much for your replay!


    Actually, Niels was right . I fixed my drivers and here is the output of combofix's scan:


    ComboFix 08-08-18.04 - Dannouf 08/19/2008 10:40:08.1 - NTFSx86


    Microsoft Windows XP Professional 5.1.2600.2.1256.1.1033.18.628 [GMT 3:00]


    Running from: C:\Documents and Settings\Dannouf\Desktop\ComboFix.exe


    Command switches used :: C:\Documents and Settings\Dannouf\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe


    * Created a new restore point


    * Resident AV is active


    .


    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


    .


    C:\WINDOWS\system32\x64


    C:\WINDOWS\ufdata2000.log


    .


    ((((((((((((((((((((((((( Files Created from 2008-07-19 to 2008-08-19 )))))))))))))))))))))))))))))))


    .


    No new files created in this timespan


    .


    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))


    .


    2008-08-19 07:40 81,984 ----a-w C:\WINDOWS\system32\bdod.bin


    2008-08-19 07:39 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Orbit


    2008-08-18 12:43 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Skype


    2008-08-17 21:26 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Nokia Multimedia Player


    2008-08-17 16:11 --------- d-----w C:\Program Files\Common Files\element5 Shared


    2008-08-17 16:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\element5


    2008-08-17 16:10 --------- d--h--w C:\Program Files\Zero G Registry


    2008-08-17 16:10 --------- d-----w C:\Program Files\Pixologic


    2008-08-17 15:45 --------- d-----w C:\Program Files\Macromedia


    2008-08-17 15:45 --------- d-----w C:\Program Files\Common Files\Macromedia


    2008-08-17 09:03 --------- d-----w C:\Program Files\Orbitdownloader


    2008-08-16 21:53 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Nokia


    2008-08-16 21:51 --------- d-----w C:\Program Files\Nokia


    2008-08-16 21:51 --------- d-----w C:\Program Files\Common Files\PCSuite


    2008-08-16 21:51 --------- d-----w C:\Program Files\Common Files\Nokia


    2008-08-16 21:51 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\PC Suite


    2008-08-16 14:37 --------- d-----w C:\Program Files\Common Files\Adobe


    2008-08-16 14:37 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\AdobeUM


    2008-08-16 14:32 --------- d-----w C:\Program Files\Bradbury


    2008-08-16 14:31 --------- d--h--w C:\Program Files\InstallShield Installation Information


    2008-08-16 12:23 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Ahead


    2008-08-16 11:58 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Ulead Systems


    2008-08-16 11:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems


    2008-08-16 11:15 --------- d-----w C:\Program Files\Windows Media Components


    2008-08-16 11:15 --------- d-----w C:\Program Files\Common Files\Ulead Systems


    2008-08-16 11:15 --------- d-----w C:\Program Files\Common Files\InterVideo


    2008-08-16 11:15 --------- d-----w C:\Program Files\Common Files\InstallShield


    2008-08-16 11:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\InterVideo


    2008-08-16 11:14 --------- d-----w C:\Program Files\Ulead Systems


    2008-08-16 10:22 --------- d-----w C:\Program Files\QuickEditor


    2008-08-16 07:39 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\COWON


    2008-08-16 07:03 --------- d-----w C:\Program Files\TEXTware


    2008-08-16 07:03 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Oxford


    2008-08-16 07:02 --------- d-----w C:\Program Files\Oxford


    2008-08-16 06:41 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Media Player Classic


    2008-08-15 21:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet


    2008-08-15 20:56 --------- d-----w C:\Program Files\Bonjour


    2008-08-15 20:46 --------- d-----w C:\Program Files\Common Files\Macrovision Shared


    2008-08-15 20:22 --------- d-----w C:\Program Files\Google


    2008-08-15 20:20 --------- d-----w C:\Program Files\Microsoft Works


    2008-08-15 20:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help


    2008-08-15 20:19 --------- d-----w C:\Program Files\MSBuild


    2008-08-15 20:18 --------- d-----w C:\Program Files\Microsoft.NET


    2008-08-15 20:17 --------- d-----w C:\Program Files\Microsoft Visual Studio 8


    2008-08-15 19:17 --------- d-----w C:\Program Files\Golden Al-Wafi Translator


    2008-08-15 19:16 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE


    2008-08-15 19:16 172,032 ------w C:\WINDOWS\Setup1.exe


    2008-08-15 18:47 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Apple Computer


    2008-08-15 18:43 --------- d-----w C:\Program Files\QuickTime


    2008-08-15 18:42 --------- d-----w C:\Program Files\iTunes


    2008-08-15 18:42 --------- d-----w C:\Program Files\iPod


    2008-08-15 18:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer


    2008-08-15 18:40 --------- d-----w C:\Program Files\K-Lite Codec Pack


    2008-08-15 18:40 --------- d-----w C:\Program Files\JetAudio


    2008-08-15 18:40 --------- d-----w C:\Program Files\Common Files\COWON


    2008-08-15 18:38 --------- d-----w C:\Program Files\Webteh


    2008-08-15 18:38 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\BSplayer PRO


    2008-08-15 18:37 --------- d-----w C:\Program Files\Allok 3GP PSP MP4 iPod Video Converter


    2008-08-15 18:32 --------- d-----w C:\Program Files\Nero


    2008-08-15 18:32 --------- d-----w C:\Program Files\Common Files\Ahead


    2008-08-15 18:30 --------- d-----w C:\Program Files\Yahoo!


    2008-08-15 18:30 --------- d-----w C:\Program Files\Java


    2008-08-15 18:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!


    2008-08-15 18:29 --------- d-----w C:\Program Files\Common Files\Java


    2008-08-15 18:28 --------- d-----w C:\Program Files\Skype


    2008-08-15 18:28 --------- d-----w C:\Program Files\Common Files\Skype


    2008-08-15 18:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype


    2008-08-15 18:26 --------- d-----w C:\Program Files\Windows Live


    2008-08-15 18:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller


    2008-08-15 18:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\WindowsLiveInstaller


    2008-08-15 18:04 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\Bitdefender


    2008-08-15 18:03 --------- d-----w C:\Program Files\Common Files\BitDefender


    2008-08-15 18:03 --------- d-----w C:\Program Files\BitDefender


    2008-08-15 18:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\BitDefender


    2008-08-15 17:59 --------- d-----w C:\Program Files\Canon


    2008-08-15 17:57 --------- d-----w C:\Program Files\HP


    2008-08-15 17:57 --------- d-----w C:\Documents and Settings\Dannouf\Application Data\HP


    2008-08-15 17:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP


    2008-08-15 17:55 --------- d-----w C:\Program Files\Hewlett-Packard


    2008-08-15 17:55 --------- d-----w C:\Program Files\Common Files\HP


    2008-08-15 17:46 --------- d-----w C:\Program Files\Realtek


    2008-08-15 17:32 --------- d-----w C:\Program Files\microsoft frontpage


    .


    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


    .


    .


    *Note* empty entries & legit default entries are not shown


    REGEDIT4


    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]


    "Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [03/27/2007 03:22 PM 4670968]


    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [08/04/2004 01:06 AM 1667584]


    "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [05/17/2007 01:11 PM 5729136]


    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\


    Orbit.lnk - C:\Program Files\Orbitdownloader\orbitdm.exe [2008-08-17 12:03:39 1585152]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]


    "VIDC.YV12"= yv12vfw.dll


    "msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm


    "msacm.MPEGacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\MPEGacm.acm


    "msacm.ulmp3acm"= C:\PROGRA~1\COMMON~1\ULEADS~1\MPEG\ulmp3acm.acm


    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]


    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk


    backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup


    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]


    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk


    backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup


    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]


    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk


    backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup


    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]


    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk


    backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup


    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Orbit.lnk]


    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Orbit.lnk


    backup=C:\WINDOWS\pss\Orbit.lnkCommon Startup


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDAgent]


    --a------ 08/07/2007 07:19 PM 270336 C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]


    --a------ 08/04/2004 03:56 AM 15360 C:\WINDOWS\system32\ctfmon.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]


    -ra------ 10/05/2006 04:13 PM 114688 C:\WINDOWS\system32\hkcmd.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]


    --a------ 02/19/2006 02:41 AM 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]


    -ra------ 10/05/2006 04:11 PM 98304 C:\WINDOWS\system32\igfxtray.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]


    --a------ 08/04/2004 01:32 AM 208952 C:\WINDOWS\ime\imjp8_1\imjpmig.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]


    --a------ 10/06/2005 06:03 PM 278528 C:\Program Files\iTunes\iTunesHelper.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]


    --------- 08/04/2004 01:06 AM 1667584 C:\Program Files\Messenger\msmsgs.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]


    --a------ 05/17/2007 01:11 PM 5729136 C:\Program Files\Windows Live\Messenger\msnmsgr.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]


    --a------ 08/04/2004 01:31 AM 59392 C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]


    --a------ 12/13/2005 08:49 AM 217088 C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]


    -ra------ 10/05/2006 04:10 PM 94208 C:\WINDOWS\system32\igfxpers.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]


    --a------ 08/04/2004 01:32 AM 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]


    --a------ 08/04/2004 01:32 AM 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]


    --a------ 08/15/2008 09:43 PM 155648 C:\Program Files\QuickTime\qttask.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]


    -ra------ 08/31/2007 05:40 PM 22879528 C:\Program Files\Skype\Phone\Skype.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]


    --a------ 03/14/2007 03:43 AM 83608 C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]


    --a------ 03/27/2007 03:22 PM 4670968 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]


    --------- 12/12/2005 09:50 AM 88204 C:\WINDOWS\AGRSMMSG.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]


    -r------- 05/02/2005 07:00 PM 69632 C:\WINDOWS\Alcmtr.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]


    --a------ 08/04/2004 03:56 AM 110592 C:\WINDOWS\system32\bthprops.cpl


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]


    -r------- 12/17/2006 07:00 PM 16062464 C:\WINDOWS\RTHDCPL.exe


    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]


    -r------- 05/15/2006 07:00 PM 2879488 C:\WINDOWS\SkyTel.exe


    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]


    "EnableFirewall"= 0 (0x0)


    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]


    "C:\\Program Files\\Orbitdownloader\\orbitdm.exe"=


    "C:\\Program Files\\Orbitdownloader\\orbitnet.exe"=


    "C:\\Program Files\\Skype\\Phone\\Skype.exe"=


    R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [07/30/2007 06:47 PM]


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]


    bdx REG_MULTI_SZ scan


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{196b1318-6bdd-11dd-9a1e-001e10006c9e}]


    \Shell\Auto\command - I:\sal.xls.exe


    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sal.xls.exe


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{44637c3c-6b7d-11dd-9a1c-001e10006c9e}]


    \Shell\Auto\command - I:\sal.xls.exe


    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sal.xls.exe


    *Newly Created Service* - 55BD77EB


    *Newly Created Service* - B11445D6


    *Newly Created Service* - CATCHME


    *Newly Created Service* - PROCEXP90


    .


    - - - - ORPHANS REMOVED - - - -


    MSConfigStartUp-IMJPMIG8 - msime80.exe


    MSConfigStartUp-MsServer - msfir80.exe


    .


    ------- Supplementary Scan -------


    .


    FireFox -: Profile - C:\Documents and Settings\Dannouf\Application Data\Mozilla\Firefox\Profiles\hf97zczq.default\


    .


    **************************************************************************


    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net


    Rootkit scan 2008-08-19 10:41:40


    Windows 5.1.2600 Service Pack 2 NTFS


    scanning hidden processes ...


    scanning hidden autostart entries ...


    scanning hidden files ...


    scan completed successfully


    hidden files: 0


    **************************************************************************


    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]


    "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\


    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]


    "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\


    .


    Completion time: 08/19/2008 10:42:31


    ComboFix-quarantined-files.txt 2008-08-19 07:42:27


    Pre-Run: 21,170,741,248 bytes free


    Post-Run: 21,245,145,088 bytes free


    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe


    [boot loader]


    timeout=2


    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS


    [operating systems]


    C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons


    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect


    232

  • So are you still having problems?


    The logs look fairly clean.


    I suspect I:\sal.xls.exe was one of the infected files.


    In case problems still persist, could you please try and find I:\sal.xls.exe(or a file with the same name in c:\Windows\ystem32) and also C:\WINDOWS\Setup1.exe.

  • So are you still having problems?


    The logs look fairly clean.


    I suspect I:\sal.xls.exe was one of the infected files.


    In case problems still persist, could you please try and find I:\sal.xls.exe(or a file with the same name in c:\Windows\ystem32) and also C:\WINDOWS\Setup1.exe.


    hi! thanks for your replay....


    NO, I do not see any problem right now... I searched for "sal.xls.exe" I did not see any file named like that.On the other hand, I found Setup1.exe in windows file....


    so please tell me if my computer still infected ???


    I really thank you for your kind attention.


    best regards to you all,


    angls

  • Hello I'm angls,


    Can you please do this also. I suppose that I: is a flash disk,pen drive,external hard disk. Plug it in. Now click on start,my computer,right click on I: choose explore. After that go to the tools menu,folder options,press on the display/view tab. Select the option show hidden files and folders press on apply and ok. See if you now can see it.


    Archive all the files that Catalin mentioned. To do that follow the instructions in the second post.


    After you can add the attachments to a new topic in this forum section. Once you are in the screen for creating a new topic scroll down untill you see the Attachments section press on browse and upload the archives that you have created press on upload. There is an 2 mb file limit.


    Kind regards,


    Niels

  • Hello I'm angls,


    Can you please do this also. I suppose that I: is a flash disk,pen drive,external hard disk. Plug it in. Now click on start,my computer,right click on I: choose explore. After that go to the tools menu,folder options,press on the display/view tab. Select the option show hidden files and folders press on apply and ok. See if you now can see it.


    Archive all the files that Catalin mentioned. To do that follow the instructions in the second post.


    After you can add the attachments to a new topic in this forum section. Once you are in the screen for creating a new topic scroll down untill you see the Attachments section press on browse and upload the archives that you have created press on upload. There is an 2 mb file limit.


    Kind regards,


    Niels


    Dear Niels


    hi how are you? thanks for your replay


    Actually, I formatted my flash memory few days ago. I do not think the file is still located in my flash memory.......However,...


    I appreciate your responses very much


    thanks/best regards,


    Yours sincerely


    angls