Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Aurora ABI [RESOLVED]


  • This topic is locked This topic is locked

#1
vinlander

vinlander

    New Member

  • Member
  • Pip
  • 2 posts
Right -- the lovely Aurora ABI bugger is on my machine and it doesn't seem to want to leave. I've run most of the malware cures, and it's still there. Ewido is in place, and some others. Here's the HijackThis log. And thank you.


Logfile of HijackThis v1.99.1
Scan saved at 9:43:47 AM, on 7/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\PVSW\Bin\W3dbsmgr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\DOCUME~1\Jeff\LOCALS~1\Temp\EYU\aurareco.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office\POWERPNT.EXE
C:\HijackThisAntiMalWare\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [vttksh] "C:\WINDOWS\System32\vttksh.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [zvdxfj] c:\windows\system32\vfrvia.exe r
O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Pervasive.SQL Workgroup Engine.lnk = C:\PVSW\Bin\W3dbsmgr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150...ip/RdxIE601.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
  • 0

Advertisements


#2
Bugbatter

Bugbatter

    Malware Expert

  • Expert
  • 341 posts
  • MVP
Hi, vinlander,

Welcome to GTG. :tazz:

Let's see if we can get things cleaned up for you.

Please print these instructions. You will be working in Safemode and will not have internet access.

Please disable your MicrosoftAntiSpyware until we are finished with our fix. It can interfere with HJT's registry chagnes:
1. Right-click on the Microsoft Anti-Spyware icon in the system tray [it's the one with the red and yellow bulls-eye].
2. Click on "Security Agents Status".
3. Click on "Disable real-time protection".

Next right-click on the Microsoft Anti-Spyware icon in the system tray again to open Microsoft Anti-Spyware.

1. Click on the Options menu and choose Settings.
2. In the left pane column click on "Real Time Protection".
3. Under Startup Options, uncheck "Enable (MSAS) Security Agents on startup (recommended)"
4. Under Real-time spyware threat protection, uncheck and "Enable real-time spyware threat protection" (recommended).
5. Click the Save button and close Microsoft AntiSpyware.

Finally, right-click on the MSAS icon in the system tray and select "Shutdown Microsoft Antispyware".
[After your system is fully cleaned reenable MSAS using the same steps but this time reverse them.]

Now for Aurora....

For your ewido:
[*]When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
[*]When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
[*]From the main ewido screen, click on update in the left menu, then click the Start update button. (There is an update TODAY.)
[*]After the update finishes (the status bar at the bottom will display "Update successful")
[*]Exit Ewido. DO NOT scan yet.

Download CCleaner and install, but do not run it yet.

Please download this installer for the Nailfix utility.
Or from here: http://www.spywareed.../nf/nailfix.exe

DO NOT run it yet.

Reboot into Safe Mode. To do this with Windows XP, you can follow these steps from Microsoft:
  • Restart your computer and start pressing the F8 key on your keyboard. On a computer that is configured for booting to multiple operating systems, you can press the F8 key when you the Boot Menu appears.
  • Select an option when the Windows Advanced Options menu appears, and then press ENTER.
  • When the Boot menu appears again, and the words "Safe Mode" appear in blue at the bottom, select the installation that you want to start, and then press ENTER.

Once in Safe Mode, please double-click on nailfix.exe. Click "Next" in the setup, then make sure "Run Nailfix" is checked and click "Finish". Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal.

Next, run Ewido again.
  • Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
  • If ewido finds anything, it will pop up a notification. We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, pcAnywhere and the game "Risk" have been flagged), select "none" as the action. DO NOT check "Perform action with all infections". If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.
  • When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.

Launch HijackThis, click Scan, and place a checkmark by the following items:

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll (file missing)
O4 - HKLM\..\Run: [vttksh] "C:\WINDOWS\System32\vttksh.exe"
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150...ip/RdxIE601.cab
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

O4 - HKLM\..\Run: [zvdxfj] C:\windows\system32\vfrvia.exe r

** NOTE: The 04 entry may have changed names if you have rebooted since posting the log; look for an entry with a similar format, that will always in in a single letter r.


Close all open windows except for HijackThis and click Fix Checked. Close HJT.

Locate and delete the following Files in BOLD IF they still exist:
c:\windows\system32\vfrvia.exe (or whatever the name it may have changed to, as noted above).
C:\WINDOWS\Nail.exe
C:\WINDOWS\System32\vttksh.exe
C:\WINDOWS\svcproc.exe

Now, run CCleaner.
  • Uncheck "Cookies" under "Internet Explorer".
  • If running Firefox: click on the "Applications" tab and uncheck "Cookies" under "Firefox".
  • Click on Run Cleaner in the lower right-hand corner. This can take quite a while to run.
Finally, restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
  • 0

#3
vinlander

vinlander

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
Thanks for the rapid reply and almost idiot-proof instructions. Here's the Ewido report and the latest HijackThis report follows it.

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 12:15:00 PM, 7/31/2005
+ Report-Checksum: 3D2AA1C1

+ Scan result:

C:\WINDOWS\rprngq.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\dinst.exe -> TrojanDownloader.Intexp.d : Cleaned with backup
C:\Documents and Settings\Jeff\Local Settings\Temp\EYU\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Jeff\Cookies\jeff@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Jeff\Cookies\jeff@abetterinternet[4].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Jeff\Cookies\[email protected][1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Jeff\Cookies\jeff@abetterinternet[6].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Jeff\Cookies\[email protected][1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Jeff\Cookies\[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Jeff\Cookies\[email protected][2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Jeff\Cookies\jeff@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Jeff\Cookies\jeff@abetterinternet[5].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Jeff\Cookies\jeff@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Jeff\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.128:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.139:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.158:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.159:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.160:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.283:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.342:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.343:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
:mozilla.347:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Inet-cash : Cleaned with backup
:mozilla.348:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Inet-cash : Cleaned with backup
:mozilla.349:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Inet-cash : Cleaned with backup
:mozilla.363:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.364:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.365:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.366:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.367:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.368:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.369:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.370:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.371:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.372:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.373:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.374:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.375:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.376:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.377:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.378:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.379:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.380:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.455:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.456:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.471:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Pro-market : Cleaned with backup
:mozilla.475:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Pro-market : Cleaned with backup
:mozilla.476:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Pro-market : Cleaned with backup
:mozilla.525:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.526:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.527:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.528:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.583:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.616:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.619:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.623:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.624:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.625:C:\Documents and Settings\Jeff\Application Data\Mozilla\Firefox\Profiles\7mg5r5vl.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\System Volume Information\_restore{29780DA0-DFDF-4384-B6FC-A717E3F0900F}\RP411\A0070884.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{29780DA0-DFDF-4384-B6FC-A717E3F0900F}\RP411\A0070895.dll -> Spyware.ClearSearch : Cleaned with backup
C:\System Volume Information\_restore{29780DA0-DFDF-4384-B6FC-A717E3F0900F}\RP411\A0070901.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{29780DA0-DFDF-4384-B6FC-A717E3F0900F}\RP411\A0070902.exe -> Spyware.Adtomi : Cleaned with backup
C:\System Volume Information\_restore{29780DA0-DFDF-4384-B6FC-A717E3F0900F}\RP411\A0070903.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{29780DA0-DFDF-4384-B6FC-A717E3F0900F}\RP411\A0070904.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\System Volume Information\_restore{29780DA0-DFDF-4384-B6FC-A717E3F0900F}\RP412\A0070906.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{29780DA0-DFDF-4384-B6FC-A717E3F0900F}\RP412\A0071885.dll -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{29780DA0-DFDF-4384-B6FC-A717E3F0900F}\RP412\A0071886.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{29780DA0-DFDF-4384-B6FC-A717E3F0900F}\RP412\A0071887.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{29780DA0-DFDF-4384-B6FC-A717E3F0900F}\RP412\A0071888.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{29780DA0-DFDF-4384-B6FC-A717E3F0900F}\RP412\A0071893.exe -> Adware.BetterInternet : Cleaned with backup


::Report End

HIJACK THIS REPORT:

Logfile of HijackThis v1.99.1
Scan saved at 12:36:37 PM, on 7/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\PVSW\Bin\W3dbsmgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\HP\DIAGNO~1\bin\hprblog.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HijackThisAntiMalWare\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &

Destroy\SDHelper.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio

Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Pervasive.SQL Workgroup Engine.lnk = C:\PVSW\Bin\W3dbsmgr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool)

- http://go.microsoft....k/?linkid=39204
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -

C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security

suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program

Files\NavNT\rtvscan.exe

HIJACK REPORT ENDS HERE

Thanks again -- and if we're done, any advice on how to keep this nasty little blighter off my windows machine?
  • 0

#4
Bugbatter

Bugbatter

    Malware Expert

  • Expert
  • 341 posts
  • MVP
Good job, vinlander! :tazz:

After something like this it is a good idea to purge the Restore Points and start fresh.
To flush the XP System Restore Points:
(Using XP, you must be logged in as Administrator to do this.)

Go to Start>Run and type msconfig Press enter.
When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left.
Check the box labeled Turn Off System Restore.

Reboot. Go back in and turn System Restore ON. A new Restore Point will be created.

As far as prevention, yes, I have a few suggestions....
You are running Limewire. You might want to uninstall this software.
Here is some info:
http://www.pestpatro.../l/limewire.asp
http://www.benedelman.org/spyware/p2p/
http://www.wellesley...P/limewire.html

If you opt to remove it,
Use the uninstaller:
Open the LimeWire folder.
Double click on the Uninstall LimeWire 18c icon.

When the uninstall has finished, launch HJT and check these items in HijackThis IF they still exist.
** Make sure you disable MSAntiSpyware first. Its protective fetures can prevent HJT from making changes in the Registry.

O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe


Close all windows and click Fix Checked". Exit HJT.
Reboot.

Delete the Limewire folder in your Program files if it still exists.

You can always create another restore point after this removal if you wish.

Here is my standard list of simple steps that you can take to reduce the chance of infection in the future.

You may have already taken some of these steps:
1. Visit Windows Update:
Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS.
Windows Update: http://v4.windowsupd.../en/default.asp

2. Adjust your security settings for ActiveX:
Go to Internet Options/Security/Internet, press 'default level', then OK.
Now press "Custom Level."
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to 'prompt', and 'Initialize and Script ActiveX controls not marked as safe" to 'disable'.

3. Download and install the following free programs:
a. SpywareBlaster: http://www.javacools...areblaster.html
b. SpywareGuard: http://www.javacools...ywareguard.html
Periodically check for updates.

4. Keep your antivirus software and firewall software up to date.
Note: Zone Alarm Firewall (Zone Labs) http://www.zonelabs....ontent/home.jsp is free.
Also Sygate has an optional free version: http://smb.sygate.com/download_buy.htm

5. You might consider installing Mozilla / Firefox.
http://www.mozilla.org/

6. Install spyware detection and removal programs:
You may also want to consider installing either or both of AdAware (free version) and Spybot S&D (freeware). Use these programs to regularly scan your system for and remove many forms of spyware/malware.
a. AdAware: http://www.lavasoft....ftware/adaware/

b. SpyBot S&D: http://safer-network...2005-05-31.html
http://www.majorgeek...wnload2471.html
http://security.koll...n&page=download
** If you already have Spybot 1.3 update to version 1.4.
Before installing Spybot S&D 1.4 remove 1.3 like this:
Open 1.3 . Go to Immunize. Click on UNDO at the top. At the bottom, take the checkmark OUT of "BrowserHelper> "Enable permanent blocking..."
This will disable all protection. Make sure ALL has been disabled.
If you are using Spybot's TeaTimer disable all protection there as well.
If Opera Browser is installed, de-select protection for Opera Immunity
Then go to Add/Remove programs via Start>Settings>Control Panel and REMOVE the old 1.3 Spybot.
Reboot
Go to your Program Files and delete the old Spybot folder.
Delete the old desktop icon.
Then you are ready to install the new version.

I would check for updates in SpyBot once a week or so.
Check for updates in Adaware frequently.
I scan with each at least weekly.

7. Before using or purchasing any Spyware/Malware protection/removal program, always check the Rogue/Suspect Spyware List. It will save you a lot of grief, as well as money if you are thinking of purchasing. Here is the link: http://www.spywarewa...nti-spyware.htm
If you want to know just how effective your anti-spyware program is, or how well any of the "rogue" programs listed at the above link work, check this for an independent comparison of several anti-spyware programs: http://www.spywarewa...-test-guide.htm

8. I also suggest that you delete any files from "temp", "tmp" folders. In Internet Explorer, click on "Tools" => "Internet Options" => "Delete Files" and select the box that says "Delete All Offline Content" and click on "OK" twice. Also, empty the recycle bin by right clicking on it and selecting "Empty Recycle Bin". These steps should be done on a regular basis.

9. After you use Windows XP for some time, the prefetch folder can get full of rarely used or obsolete links which can slow down your computer boot time noticeably. We recommend you delete all files in this folder about once a month.
To find the prefetch folder, enter this in the explorer address bar:
%windir%\prefetch
This should take you to either C:\WINDOWS\PREFETCH or C:\WINNT\PREFETCH. Delete all the files there. http://www.hexff.com/xp_tuneup.php

10. You might want to take a look at this article, too.
http://computercops....tlite7736-.html

Feel free to post a log for final review; otherwise, you're good to go.
Happy and Safe Surfing! ;)
  • 0

#5
Bugbatter

Bugbatter

    Malware Expert

  • Expert
  • 341 posts
  • MVP
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP