Again small but a usefult addition, as a part of my more usable forum work.
replace your 
<input name="sendto" value="<% =Request.Querystring("mname") %>" size="50">  <span class="dikkat"><a class="dikkat" href="JavaScript:pmmembers();"><strong>Üye Listesi</strong></a><br />
in your privatesend.asp with the following,
<%
Response.Write "<select name=""sendto"">"
' Declare SQL String
Dim strSQLSendto
' /Declare SQL String
' Declare Recordset Object
Dim objRSSendto
Set objRSSendto = Server.CreateObject("ADODB.Recordset")
' /Declare Recordset Object
strSQLSendto = strSQLSendto & "SELECT * FROM " & strMemberTablePrefix & "MEMBERS ORDER BY M_NAME ASC "
Set objRSSendto = my_Conn.Execute(strSQLSendto)
				Do While Not objRSSendto.EOF
Response.Write "<option value=""" & objRSSendto.Fields("M_NAME") & """"
if objRSSendto.Fields("M_NAME") = Request.Querystring("mname") then
Response.Write "selected"
end if
Response.Write ">" & objRSSendto.Fields("M_NAME") & "</option>"
				objRSSendto.MoveNext
				Loop
Response.Write "</select><br />"
objRSSendto.close
set objRSSendto = nothing
%>
that's it.