Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

odd popup when clicking folders [RESOLVED]


  • This topic is locked This topic is locked

#1
Mad_Night

Mad_Night

    Member

  • Member
  • PipPip
  • 67 posts
I'm getting this odd pop up when clicking on folders and it prompts me to download something.
i posted in the other forum and was told to come here.
this is the popup i get.
Posted Image


i'm posting the HijackThis log and the uninstal_list.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:15:53 PM, on 6/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\program files\support.com\client\bin\tgcmd.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sony.com/vaiopeople
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: CheckHO Class - {576EB0AD-6980-11D5-A9CD-0001032FEE17} - C:\Program Files\Yahoo!\Common\ycheckh.dll
O2 - BHO: Spybot-S&D IE Protection - {B1892F58-1116-4DEC-92AA-577872EC3D3D} - C:\WINDOWS\System32\xmlwin.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [CreateCD_Reminder] C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [VAIOSurvey] c:\program files\sony\vaio survey\surveysa.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] "c:\program files\support.com\client\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\Windows\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\Quicken\billmind.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: wbsys.dll,avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

--
End of file - 8088 bytes


Uninstall_List
µTorrent
Ad-Aware 2007
Adobe Flash Player 9 ActiveX
Adobe Photoshop 7.0
Adobe Reader 6.0
Age of Empires II
Agere Systems AC'97 Modem
AnyDVD
ATI Control Panel
ATI Display Driver
AVG Free 8.0
BSPlayer
CCleaner (remove only)
Click to DVD 1.3
ConvertXtoDVD 3.0.0.9c
CursorXP
Drag'n Drop CD+DVD
DVD Decrypter (Remove Only)
DVD Shrink 3.2
DVgate Plus
foobar2000 v0.9.5.3
HijackThis 2.0.2
IconPackager
Intel® Extreme Graphics Driver
Intel® PRO Network Adapters and Drivers
LiveReg (Symantec Corporation)
LiveUpdate 1.80 (Symantec Corporation)
Magic ISO Maker v5.4 (build 0239)
Memory Stick Formatter
Microsoft Learning and Research Plus Support Files
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft Picture It! Express 7.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Works 7.0
MoodLogic
Mozilla Firefox (2.0.0.10)
MSN Internet Software
MSN Messenger 5.0
Music Visualizer Library 1.4.00
Netscape (7.02)
NVIDIA Windows 2000/XP Display Drivers
ObjectDock Plus
OpenMG Limited Patch 3.2-03-02-21-08
OpenMG Limited Patch 3.2-03-03-18-01
OpenMG Limited Patch 3.2-03-04-14-02
OpenMG Secure Module 3.2
PictureGear Studio 2.0
PowerDVD
Quicken 2003 New User Edition
QuickTime
RealOne Player
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924496)
Shockwave
SonicStage 1.6.00
Sony Certificate PCH
Sony on Yahoo! Essentials
Sony Video Shared Library
Spybot - Search & Destroy 1.4
StartupMonitor
Storm Codec
SUPERAntiSpyware Professional
Sygate Personal Firewall
Turbo Tax Offer
Unlocker 1.8.5
Update for Windows XP (KB898461)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
VAIO BrightColor Wallpaper
VAIO Help and Support
VAIO Media 2.6
VAIO Media Integrated Server 2.6
VAIO Media Redistribution 2.6
VAIO Registration
VAIO Support
VAIO Survey Standalone
VAIO System Information
Viewpoint Media Player (Remove Only)
VobSub v2.23 (Remove Only)
Welcome to VAIO life
WindowBlinds
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinRAR archiver
Yahoo! Install Manager
Yahoo! Toolbar
Your Uninstaller! 2008 Version 6.0
  • 0

Advertisements


#2
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Please print the below instructions or copy them to Notepad. Make sure to work through the fixes in the order mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

Run a scan in HijackThis. Check each of the following if they still exist and hit 'Fix Checked' after you checked the last one:

O2 - BHO: Spybot-S&D IE Protection - {B1892F58-1116-4DEC-92AA-577872EC3D3D} - C:\WINDOWS\System32\xmlwin.dll

Locate the following Files/Folders and delete them if they exist (if no location given, just do a search for them):

C:\WINDOWS\System32\xmlwin.dll

1. Download combofix at http://download.blee...Bs/ComboFix.exe Save it to your Desktop before you run it.
2. Double-click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply.

Note:
Do not click on combofix's window while it's running. That may cause it to stall.
  • 0

#3
Mad_Night

Mad_Night

    Member

  • Topic Starter
  • Member
  • PipPip
  • 67 posts
thankz for the help^^
heres the log

ComboFix 08-06-20.4 - ~Sy~ 2008-06-30 18:49:15.1 - NTFSx86
Running from: C:\Documents and Settings\~Sy~\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\~Sy~\Application Data\inst.exe
C:\Documents and Settings\~Sy~\Local Settings\Temporary Internet Files\101.gif
C:\Documents and Settings\~Sy~\Local Settings\Temporary Internet Files\102.gif
C:\Documents and Settings\~Sy~\Local Settings\Temporary Internet Files\103.gif
C:\Documents and Settings\~Sy~\Local Settings\Temporary Internet Files\104.gif
C:\Documents and Settings\~Sy~\Local Settings\Temporary Internet Files\105.gif
C:\Documents and Settings\~Sy~\Local Settings\Temporary Internet Files\106.gif

.
((((((((((((((((((((((((( Files Created from 2008-06-01 to 2008-07-01 )))))))))))))))))))))))))))))))
.

2008-06-30 17:35 . 2008-06-30 17:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-06-30 13:14 . 2008-06-30 13:14 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-30 09:07 . 2008-06-30 09:29 <DIR> d--h----- C:\$AVG8.VAULT$
2008-06-30 09:00 . 2008-06-30 09:00 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-06-30 09:00 . 2008-06-30 09:00 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-30 09:00 . 2008-06-30 09:00 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-06-30 08:59 . 2008-06-30 09:02 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-06-30 08:52 . 2008-06-30 08:52 <DIR> d-------- C:\Program Files\Sygate
2008-06-30 08:52 . 2004-10-15 18:32 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
2008-06-30 08:52 . 2004-10-15 18:17 60,496 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2008-06-30 08:52 . 2004-10-15 18:18 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2008-06-30 08:52 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg6n.sys
2008-06-30 08:52 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg5n.sys
2008-06-30 08:52 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg4n.sys
2008-06-30 08:52 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2008-06-30 08:50 . 2008-06-30 08:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
2008-06-29 22:49 . 2008-06-29 22:50 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\Media Player Classic
2008-06-29 22:36 . 2008-06-29 22:36 <DIR> d-------- C:\Program Files\Webteh
2008-06-29 22:36 . 2008-06-29 22:41 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\BSplayer Pro
2008-06-29 22:35 . 2008-06-29 22:35 <DIR> d-------- C:\Program Files\Gabest
2008-06-29 21:25 . 2008-06-29 21:25 <DIR> d-------- C:\Program Files\AVG
2008-06-29 20:41 . 2008-06-30 13:05 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\foobar2000
2008-06-29 20:39 . 2008-06-29 20:39 26,624 --a------ C:\WINDOWS\system32\xmlsys.dll
2008-06-29 20:35 . 2008-06-29 20:35 26,624 --a------ C:\WINDOWS\system32\xmlview.dll
2008-06-29 20:31 . 2008-06-29 20:33 <DIR> d-------- C:\Program Files\foobar2000
2008-06-29 20:16 . 2008-06-29 20:16 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\WinRAR
2008-06-29 20:15 . 2008-06-29 20:15 <DIR> d-------- C:\WINDOWS\peernet
2008-06-29 20:14 . 2008-06-29 20:14 <DIR> d-------- C:\WINDOWS\provisioning
2008-06-29 20:12 . 2008-06-29 20:12 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-06-29 20:06 . 2008-06-29 20:06 <DIR> d-------- C:\WINDOWS\EHome
2008-06-29 19:21 . 2008-06-29 19:21 <DIR> d-------- C:\Program Files\DVD Decrypter
2008-06-29 19:16 . 2008-06-29 20:36 <DIR> d-------- C:\Program Files\Common Files\Stardock
2008-06-29 19:16 . 2002-04-15 21:11 67,866 --------- C:\WINDOWS\system32\drivers\netwlan5.img
2008-06-29 19:16 . 2002-08-28 21:39 21,504 --a------ C:\WINDOWS\system32\CINTLGNT.IME
2008-06-29 19:16 . 2004-08-04 00:56 11,776 --------- C:\WINDOWS\system32\spnpinst.exe
2008-06-29 19:16 . 2004-08-02 14:20 7,208 --------- C:\WINDOWS\system32\secupd.sig
2008-06-29 19:16 . 2004-08-02 14:20 4,569 --------- C:\WINDOWS\system32\secupd.dat
2008-06-29 19:14 . 2008-06-29 19:14 <DIR> d-------- C:\Program Files\CursorXP
2008-06-29 19:10 . 2008-06-29 19:10 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-06-29 19:10 . 2008-06-29 19:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-29 19:10 . 2008-06-29 19:10 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\SUPERAntiSpyware.com
2008-06-29 19:06 . 2008-06-29 20:36 <DIR> d-------- C:\Program Files\Stardock
2008-06-29 19:06 . 2003-02-26 20:27 36,864 --a------ C:\WINDOWS\system32\wbsys.dll
2008-06-29 19:06 . 2005-01-22 18:05 20,480 --a------ C:\WINDOWS\system32\wbload.dll
2008-06-29 19:04 . 2008-06-29 19:04 <DIR> d-------- C:\Program Files\MagicISO
2008-06-29 19:03 . 2008-06-29 19:03 <DIR> d-------- C:\Program Files\DVD Shrink
2008-06-29 19:03 . 2008-06-29 19:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-06-29 19:03 . 2008-06-29 19:03 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\SlySoft
2008-06-29 19:02 . 2008-06-29 19:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SlySoft
2008-06-29 18:59 . 2008-06-29 18:59 <DIR> d-------- C:\Program Files\VSO
2008-06-29 18:59 . 2008-06-29 19:00 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\Vso
2008-06-29 18:59 . 2004-05-04 12:53 1,645,320 --a------ C:\WINDOWS\gdiplus.dll
2008-06-29 18:59 . 2006-05-20 17:16 1,184,984 --a------ C:\WINDOWS\system32\wvc1dmod.dll
2008-06-29 18:59 . 2006-09-29 13:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll
2008-06-29 18:59 . 2006-09-29 13:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll
2008-06-29 18:59 . 2006-09-29 13:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll
2008-06-29 18:59 . 2007-03-18 21:37 65,602 --a------ C:\WINDOWS\system32\cook3260.dll
2008-06-29 18:59 . 2008-06-29 18:59 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2008-06-29 18:59 . 2008-06-29 18:59 47,360 --a------ C:\Documents and Settings\~Sy~\Application Data\pcouffin.sys
2008-06-29 18:58 . 2008-06-29 18:58 <DIR> d-------- C:\Program Files\SlySoft
2008-06-29 18:57 . 2008-06-29 18:58 34,308 --a------ C:\WINDOWS\system32\Chip.dll
2008-06-29 18:54 . 2005-10-20 15:20 1,082,368 --a------ C:\WINDOWS\system32\esent.dll
2008-06-29 18:47 . 2008-06-29 18:47 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-29 18:47 . 2008-06-30 08:52 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-29 18:47 . 2008-06-29 18:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-29 18:44 . 2008-06-29 18:53 <DIR> d-------- C:\Program Files\Unlocker
2008-06-29 18:44 . 2008-06-29 18:44 <DIR> d-------- C:\Program Files\Ringz Studio
2008-06-29 18:43 . 2008-06-29 22:33 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-29 18:43 . 2008-06-30 00:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-29 18:42 . 2008-06-29 18:42 <DIR> d-------- C:\Program Files\CCleaner
2008-06-29 18:40 . 2008-06-29 18:40 <DIR> d-------- C:\WINDOWS\system32\bits
2008-06-29 18:39 . 2008-06-29 21:17 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-06-29 18:39 . 2008-06-29 18:39 <DIR> d-------- C:\Program Files\uTorrent
2008-06-29 18:39 . 2008-06-30 18:45 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\uTorrent
2008-06-29 18:39 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-06-29 18:38 . 2004-08-04 00:56 351,232 --a------ C:\WINDOWS\system32\winhttp.dll
2008-06-29 18:38 . 2004-08-04 00:56 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2008-06-29 18:38 . 2004-08-04 00:56 8,192 --------- C:\WINDOWS\system32\bitsprx2.dll
2008-06-29 18:38 . 2004-08-04 00:56 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2008-06-29 18:34 . 2007-07-30 19:19 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2008-06-29 18:34 . 2007-07-30 19:19 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2008-06-29 18:34 . 2007-07-30 19:19 216,408 --a------ C:\WINDOWS\system32\wuaucpl.cpl
2008-06-29 18:34 . 2007-07-30 19:19 203,096 --a------ C:\WINDOWS\system32\wuweb.dll
2008-06-29 18:34 . 2004-08-03 14:03 186,136 --a------ C:\WINDOWS\system32\wuaueng1.dll
2008-06-29 18:34 . 2004-08-03 14:01 167,704 --a------ C:\WINDOWS\system32\wuauclt1.exe
2008-06-29 18:34 . 2007-07-30 19:18 33,624 --a------ C:\WINDOWS\system32\wups.dll
2008-06-29 18:29 . 2008-06-29 18:29 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\Macromedia
2008-06-29 18:25 . 2008-06-29 18:25 0 --a------ C:\WINDOWS\nsreg.dat
2008-06-29 18:03 . 2008-06-29 18:03 <DIR> d-------- C:\Program Files\Your Uninstaller 2008
2008-06-29 18:03 . 2008-06-30 08:45 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-29 18:03 . 2008-06-29 18:03 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\URSoft
2008-06-29 17:52 . 2008-06-29 17:53 <DIR> d-------- C:\Program Files\Microsoft Money
2008-06-29 17:50 . 2008-06-29 17:50 <DIR> d-------- C:\Program Files\Encarta Online
2008-06-29 17:48 . 2008-06-29 17:51 <DIR> d-------- C:\Program Files\Microsoft Works
2008-06-29 17:47 . 2008-06-29 17:47 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\Symantec
2008-06-29 17:46 . 2008-06-29 18:06 <DIR> d-------- C:\Program Files\Symantec
2008-06-29 17:46 . 2008-06-29 18:06 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-06-29 17:46 . 2008-06-29 18:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-06-29 17:43 . 2008-06-29 17:43 <DIR> d-------- C:\Program Files\Microsoft Games
2008-06-29 17:42 . 2003-06-12 20:08 791 --------- C:\WINDOWS\system32\Px.ini
2008-06-29 17:41 . 2008-06-29 17:41 <DIR> d-------- C:\Program Files\drag'n drop cd+dvd
2008-06-29 17:41 . 2008-06-29 17:41 <DIR> d-------- C:\Program Files\cyberlink
2008-06-29 17:41 . 2008-06-29 17:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-06-29 17:40 . 2003-08-13 20:06 <DIR> d--h----- C:\Documents and Settings\~Sy~\Templates
2008-06-29 17:40 . 2008-06-29 18:40 <DIR> dr------- C:\Documents and Settings\~Sy~\Start Menu
2008-06-29 17:40 . 2008-06-29 18:44 <DIR> dr-h----- C:\Documents and Settings\~Sy~\SendTo
2008-06-29 17:40 . 2008-06-30 18:48 <DIR> dr-h----- C:\Documents and Settings\~Sy~\Recent
2008-06-29 17:40 . 2003-08-13 13:03 <DIR> d--h----- C:\Documents and Settings\~Sy~\PrintHood
2008-06-29 17:40 . 2003-08-13 13:03 <DIR> d--h----- C:\Documents and Settings\~Sy~\NetHood
2008-06-29 17:40 . 2008-06-30 18:53 <DIR> d--h----- C:\Documents and Settings\~Sy~\Local Settings
2008-06-29 17:40 . 2008-06-29 21:19 <DIR> dr------- C:\Documents and Settings\~Sy~\Favorites
2008-06-29 17:40 . 2008-06-30 18:47 <DIR> d-------- C:\Documents and Settings\~Sy~\Desktop
2008-06-29 17:40 . 2008-06-30 17:36 <DIR> d---s---- C:\Documents and Settings\~Sy~\Cookies
2008-06-29 17:40 . 2003-08-15 12:29 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\Real
2008-06-29 17:40 . 2003-08-15 12:36 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\MSN6
2008-06-29 17:40 . 2008-06-29 18:25 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\Mozilla
2008-06-29 17:40 . 2008-06-30 08:58 <DIR> d---s---- C:\Documents and Settings\~Sy~\Application Data\Microsoft
2008-06-29 17:40 . 2003-08-13 20:08 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\Identities
2008-06-29 17:40 . 2003-08-15 19:03 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\AdobeUM
2008-06-29 17:40 . 2008-06-29 18:29 <DIR> d-------- C:\Documents and Settings\~Sy~\Application Data\Adobe
2008-06-29 17:40 . 2008-06-30 18:53 <DIR> dr-h----- C:\Documents and Settings\~Sy~\Application Data
2008-06-29 17:40 . 2008-06-29 21:14 <DIR> d-------- C:\Documents and Settings\~Sy~
2008-06-29 17:40 . 2008-06-30 18:53 2,359,296 --ah----- C:\Documents and Settings\~Sy~\NTUSER.DAT
2008-06-29 17:39 . 2003-08-15 12:36 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\MSN6
2008-06-29 17:39 . 2003-08-15 19:03 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\AdobeUM

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-30 01:55 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-30 01:42 --------- d-----w C:\Program Files\Yahoo!
2008-06-30 00:54 --------- d-----w C:\Program Files\Sony
2008-06-30 00:45 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-30 00:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Corporation
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2008-06-29 18:58 1337032]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-01 15:05 1481968]
"CursorXP"="C:\Program Files\CursorXP\CursorXP.exe" [2005-01-19 17:44 140288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2003-07-16 11:22 4743168]
"nwiz"="nwiz.exe" [2003-07-16 11:22 323584 C:\WINDOWS\system32\nwiz.exe]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"CreateCD_Reminder"="C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe" [2003-04-17 17:51 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2003-08-15 12:23 77824]
"ezShieldProtector for Px"="C:\WINDOWS\System32\ezSP_Px.exe" [2002-08-20 10:29 40960]
"VAIOSurvey"="c:\program files\sony\vaio survey\surveysa.exe" [2003-03-17 11:52 1056768]
"ZTgServerSwitch"="c:\program files\support.com\client\bin\tgcmd.exe" [2003-06-23 17:32 1409024]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-06 13:01 335872]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-04-07 00:19 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-04-07 00:07 114688]
"AGRSMMSG"="AGRSMMSG.exe" [2003-02-14 12:59 88107 C:\WINDOWS\AGRSMMSG.exe]
"VAIO Recovery"="C:\Windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-19 22:08 28672]
"Run StartupMonitor"="StartupMonitor.exe" [2000-05-20 17:23 86016 C:\WINDOWS\StartupMonitor.exe]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 10:19 15872]
"StormCodec_Helper"="C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" [2006-11-26 11:30 97357]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 22:31 208952]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2002-08-28 21:39 59392]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-08-28 21:39 455168]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-08-28 21:39 455168]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-06-30 08:59 1177368]

C:\Documents and Settings\~Sy~\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2008-06-29 20:36:18 3581680]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-06-29 18:56:04 113664]
Billminder.lnk - C:\Program Files\Quicken\billmind.exe [2002-09-20 12:19:46 36864]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2002-09-20 12:20:02 53248]
Quicken Startup.lnk - C:\Program Files\Quicken\QWDLLS.EXE [2002-09-20 12:20:06 36864]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll 2005-12-20 22:57 176128 C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll,avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\support.com\\client\\bin\\tgcmd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-06-30 09:00]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-06-30 08:59]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-06-30 08:59]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-30 09:00]
R2 Stormser;Stormser;C:\PROGRA~1\RINGZS~1\STORMC~1\Stormser.exe [2008-06-20 12:35]

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-06-30 00:38:55 C:\WINDOWS\Tasks\Registration reminder 1.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2008-06-30 00:38:56 C:\WINDOWS\Tasks\Registration reminder 2.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2008-06-30 00:38:56 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-30 18:53:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
Completion time: 2008-06-30 18:56:49
ComboFix-quarantined-files.txt 2008-07-01 01:56:44

Pre-Run: 3,223,515,136 bytes free
Post-Run: 3,344,228,352 bytes free

241 --- E O F --- 2008-06-30 05:02:10
  • 0

#4
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Download Malwarebytes ' Anti-Malware at http://www.besttechi.../mbam-setup.exe or http://www.majorgeek...ware_d5756.html Double-click on mbam-setup.exe to install the application.

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform Full Scan, then click Scan.
* The scan may take some time to finish, so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to restart (see Extra Note below).
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy & paste the entire report into your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


Open up your Notepad editor (Start->Run, type in notepad and click OK). Copy the text from the quotebox below into Notepad:

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

Save this as CFScript.txt in the same location as the ComboFix.exe tool.
Drag the CFScript.txt into ComboFix.exe
Follow the prompts. When finished, it shall produce a log for you. Post that log in your next reply.

Note: Do not click on combofix's window while it's running. That may cause it to stall.

How is it running so far?
  • 0

#5
Mad_Night

Mad_Night

    Member

  • Topic Starter
  • Member
  • PipPip
  • 67 posts
my pc seems to be running just fine now. no popups or anything else.
Thank you for all your help.

heres the MBAM log

Malwarebytes' Anti-Malware 1.19
Database version: 910
Windows 5.1.2600 Service Pack 2

9:55:21 PM 6/30/2008
mbam-log-6-30-2008 (21-55-21).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 90506
Time elapsed: 52 minute(s), 38 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • 0

#6
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Good job. Your log is clean :)

To help prevent future spyware infections, read the Anti-Spyware Tutorial and use the tools provided.

Go to Start->Run, copy/paste in combofix /u and hit OK to remove it. You should be set to go.
  • 0

#7
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP