1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Having Major pop unders from Top-banners!

Discussion in 'Virus & Other Malware Removal' started by Passani, Jun 20, 2006.

Thread Status:
Not open for further replies.
Advertisement
  1. Passani

    Passani Thread Starter

    Joined:
    Jun 20, 2006
    Messages:
    14
    Hello,
    ***(Here is a duplicate of a message sent to a member - FYI)

    I'm posting here because I see the extensive help you've provided your members and would like to ask for assistance in removing 'top-banners' pop unders from my PC. I have installed and ran over 7 anti-spyware/adware/malware programs, with a few removed malicious files, without a cure for the pop unders... Please help!! I have BitDefender, Panda ActiveScan and HJT log files as well as the previously mentioned programs still installed (Webroot SpySweeper, Spyware Nuker XT, Spybot S&D, TrendMicro Antispyware, SpyRemover, Spyware BeGone and Lavasoft Ad-Aware 6 - I also have CCleaner, Windows Malicious Software removal tool, Microsoft defender, CWS Shredder and Kill2Me)

    Needless to say I have been trying EVERYTHING! I understand programs, etc. fairly well but cannot seem to isolate where these programs are either located or respwaning from...

    Here is the HJT log from today.. just after running Webroot Spy Sweeper. Also, please include how to donate to your site. I have searched high and low and think that the assistance you've given to the other posters I've read is excellent and should be compensated for.

    ********************HJT LOG START*****************************


    Logfile of HijackThis v1.99.1
    Scan saved at 11:53:56 AM, on 6/20/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
    C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
    C:\PROGRA~1\TRISNA~1\SSI\SYSENF~1.EXE
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
    C:\Program Files\McAfee\Managed VirusScan\Agent\myAgttry.exe
    C:\Program Files\UltraVNC\winvnc.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    E:\PROGRAMS\Hijack This\HijackThis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
    O4 - HKLM\..\Run: [McAfee Managed Services Tray] "C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe"
    O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O13 - Gopher Prefix:
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} (SecureObjectFactory Class) - http://vs.mcafeeasap.com/SW/ENU/VS40/bin/myCioAgt.20060504183849.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = usfundinggrp.local
    O17 - HKLM\Software\..\Telephony: DomainName = usfundinggrp.local
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = usfundinggrp.local
    O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.0.0.358.dll
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: Media Center - C:\WINDOWS\system32\kvdes.dll (file missing)
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    O23 - Service: EIVCJ - Unknown owner - C:\DOCUME~1\PASSAN~1\LOCALS~1\Temp\EIVCJ.exe (file missing)
    O23 - Service: GYK - Unknown owner - C:\DOCUME~1\PASSAN~1\LOCALS~1\Temp\GYK.exe (file missing)
    O23 - Service: IQVAYAYLFVV - Unknown owner - C:\DOCUME~1\PASSAN~1\LOCALS~1\Temp\IQVAYAYLFVV.exe (file missing)
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: LGHFX - Unknown owner - C:\DOCUME~1\PASSAN~1\LOCALS~1\Temp\LGHFX.exe (file missing)
    O23 - Service: McShield - McAfee, Inc. - C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
    O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe" -sMICROSOFTSMLBIZ (file missing)
    O23 - Service: McAfee Total Protection Agent Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i MICROSOFTSMLBIZ (file missing)
    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    O23 - Service: SonicWALL Agent Service (SWAGENT) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: SysEnforce - Unknown owner - C:\PROGRA~1\TRISNA~1\SSI\SYSENF~1.EXE
    O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
    O23 - Service: ZUQI - Unknown owner - C:\DOCUME~1\PASSAN~1\LOCALS~1\Temp\ZUQI.exe (file missing)

    ********************END HJT LOG***********************************

    Thanks again,
    J. Matlock
    Passani Electronics, Inc.
     
  2. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    You may want to print this or save it to notepad as we will go to safe mode.

    Fix these with HJT – mark them, close IE, click fix checked

    O20 - Winlogon Notify: Media Center - C:\WINDOWS\system32\kvdes.dll (file missing)

    O23 - Service: EIVCJ - Unknown owner - C:\DOCUME~1\PASSAN~1\LOCALS~1\Temp\EIVCJ.exe (file missing)

    O23 - Service: GYK - Unknown owner - C:\DOCUME~1\PASSAN~1\LOCALS~1\Temp\GYK.exe (file missing)

    O23 - Service: IQVAYAYLFVV - Unknown owner - C:\DOCUME~1\PASSAN~1\LOCALS~1\Temp\IQVAYAYLFVV.exe (file missing)

    O23 - Service: LGHFX - Unknown owner - C:\DOCUME~1\PASSAN~1\LOCALS~1\Temp\LGHFX.exe (file missing)

    O23 - Service: SysEnforce - Unknown owner - C:\PROGRA~1\TRISNA~1\SSI\SYSENF~1.EXE

    O23 - Service: ZUQI - Unknown owner - C:\DOCUME~1\PASSAN~1\LOCALS~1\Temp\ZUQI.exe (file missing)
    ===================

    Click Start > Run > and type in:

    services.msc

    Click OK.

    In the services window find this exact name

    EIVCJ

    Rightclick and choose "Properties". On the "General" tab under "Service Status" click the "Stop" button to stop the service. Beside "Startup Type" in the dropdown menu select "Disabled". Click Apply then OK. File-Exit the Services utility.
    --------
    Repeat the above for :
    GYK
    IQVAYAYLFVV
    LGHFX
    SysEnforce
    ZUQI

    DownLoad http://www.downloads.subratam.org/KillBox.zip

    Restart your computer into safe mode now. (Tapping F8 at the first black screen) Perform the following steps in safe mode:

    Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confimation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the "Paste Full Path of File to Delete" box.

    C:\PROGRA~1\TRISNA~1

    Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure you don't miss any.

    START – RUN – type in %temp% OK - Edit – Select all – File – Delete

    Delete everything in the C:\Windows\Temp folder or C:\WINNT\temp

    Not all temp files will delete and that is normal
    Empty the recycle bin
    Boot and post a new log from normal NOT safe mode

    Please give feedback on what worked/didn’t work and the current status of your system
     
  3. Passani

    Passani Thread Starter

    Joined:
    Jun 20, 2006
    Messages:
    14
    I followed the above steps and all went well... files deleted as requested. When I logged back in I had two pop unders before the browser window I had clicked even finished opening! Sad I know.. Here is the log file:

    Logfile of HijackThis v1.99.1
    Scan saved at 2:30:50 PM, on 6/20/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
    C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
    C:\Program Files\UltraVNC\WinVNC.exe
    C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Program Files\Outlook Express\msimn.exe
    E:\PROGRAMS\Hijack This\HijackThis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
    O4 - HKLM\..\Run: [McAfee Managed Services Tray] "C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe"
    O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O13 - Gopher Prefix:
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} (SecureObjectFactory Class) - http://vs.mcafeeasap.com/SW/ENU/VS40/bin/myCioAgt.20060504183849.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = usfundinggrp.local
    O17 - HKLM\Software\..\Telephony: DomainName = usfundinggrp.local
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = usfundinggrp.local
    O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.0.0.358.dll
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: McShield - McAfee, Inc. - C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
    O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe" -sMICROSOFTSMLBIZ (file missing)
    O23 - Service: McAfee Total Protection Agent Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i MICROSOFTSMLBIZ (file missing)
    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    O23 - Service: SonicWALL Agent Service (SWAGENT) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    Please let me know what you think
     
  4. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    BTW AdAware 6 is out of date - AdAware SE 1.06 http://www.majorgeeks.com/download506.html
    =============
    Kill Windows Messenger - http://vlaurie.com/computers2/Articles/messenger.htm


    ==============
    Download the trial version of Ewido Security Suite http://www.ewido.net/en/download/ (W2K/XP Only)
    · Install ewido.
    · During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
    · Launch ewido
    · It will prompt you to update click the OK button and it will go to the main screen
    · On the left side of the main screen click update
    · Click on Start and let it update.
    · DO NOT run a scan yet. You will do that later in safe mode.
    Restart your computer into safe mode now. Perform the following steps in safe mode:
    (Start tapping F8 at the first black screen after power up)

    Run Ewido:
    · Click on scanner
    · Click Complete System Scan and the scan will begin.
    · During the scan it will prompt you to clean files, click OK
    · When the scan is finished, look at the bottom of the screen and click the Save report button.
    · Save the report to your C: Drive
    This will take some time to run!
    Boot to normal mode
    Post that log and a new HiJack log
     
  5. Passani

    Passani Thread Starter

    Joined:
    Jun 20, 2006
    Messages:
    14
    Steps above were complete. Here is the log that you requested....

    ---------------------------------------------------------
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 4:24:22 PM 6/20/2006

    + Scan result:



    HKU\S-1-5-21-4228700071-3779749593-1413654825-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{56F1D444-11BF-4879-A12B-79CF0177F038} -> Adware.180Solutions : Cleaned with backup (quarantined).
    :mozilla.178:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.17:C:\RECYCLER\NPROTECT\00000253.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.18:C:\RECYCLER\NPROTECT\00000253.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.208:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.53:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.54:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.56:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.57:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.84:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.118:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Aavalue : Cleaned.
    :mozilla.119:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Aavalue : Cleaned.
    :mozilla.120:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Aavalue : Cleaned.
    :mozilla.121:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Aavalue : Cleaned.
    :mozilla.122:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Aavalue : Cleaned.
    :mozilla.123:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Aavalue : Cleaned.
    :mozilla.124:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Aavalue : Cleaned.
    :mozilla.125:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Aavalue : Cleaned.
    :mozilla.134:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Adserver : Cleaned.
    :mozilla.135:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Adserver : Cleaned.
    :mozilla.19:C:\RECYCLER\NPROTECT\00000253.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.20:C:\RECYCLER\NPROTECT\00000253.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.37:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.38:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.39:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.12:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Atdmt : Cleaned.
    :mozilla.13:C:\RECYCLER\NPROTECT\00000253.txt -> TrackingCookie.Atdmt : Cleaned.
    :mozilla.90:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Bfast : Cleaned.
    :mozilla.109:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Burstbeacon : Cleaned.
    :mozilla.110:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Burstnet : Cleaned.
    :mozilla.111:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Burstnet : Cleaned.
    :mozilla.222:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.223:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.62:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Clickbank : Cleaned.
    :mozilla.25:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Coremetrics : Cleaned.
    :mozilla.15:C:\RECYCLER\NPROTECT\00000253.txt -> TrackingCookie.Doubleclick : Cleaned.
    :mozilla.34:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Doubleclick : Cleaned.
    :mozilla.6:C:\RECYCLER\NPROTECT\00000200.MOZ -> TrackingCookie.Doubleclick : Cleaned.
    :mozilla.16:C:\Documents and Settings\Passani_Electronics\Application Data\Mozilla\Firefox\Profiles\g2qcfng1.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.17:C:\Documents and Settings\Passani_Electronics\Application Data\Mozilla\Firefox\Profiles\g2qcfng1.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.18:C:\Documents and Settings\Passani_Electronics\Application Data\Mozilla\Firefox\Profiles\g2qcfng1.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.19:C:\Documents and Settings\Passani_Electronics\Application Data\Mozilla\Firefox\Profiles\g2qcfng1.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.20:C:\Documents and Settings\Passani_Electronics\Application Data\Mozilla\Firefox\Profiles\g2qcfng1.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.21:C:\Documents and Settings\Passani_Electronics\Application Data\Mozilla\Firefox\Profiles\g2qcfng1.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.102:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.103:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.104:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.105:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.151:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.155:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.164:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.165:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.167:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.176:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.187:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.205:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.216:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.244:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.256:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.82:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.89:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.10:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.6:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.7:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.8:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.162:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.163:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.78:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.79:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.80:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.41:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Mediaplex : Cleaned.
    :mozilla.93:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Overture : Cleaned.
    :mozilla.29:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.31:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.32:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.33:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.68:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.59:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Realtracker : Cleaned.
    :mozilla.60:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Realtracker : Cleaned.
    :mozilla.13:C:\Documents and Settings\Passani_Electronics\Application Data\Mozilla\Firefox\Profiles\g2qcfng1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.211:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.212:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.9:C:\RECYCLER\NPROTECT\00000118.MOZ -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.227:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.188:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Web-stat : Cleaned.
    :mozilla.189:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Web-stat : Cleaned.
    :mozilla.22:C:\Documents and Settings\Passani_Electronics\Application Data\Mozilla\Firefox\Profiles\g2qcfng1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.23:C:\Documents and Settings\Passani_Electronics\Application Data\Mozilla\Firefox\Profiles\g2qcfng1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.24:C:\Documents and Settings\Passani_Electronics\Application Data\Mozilla\Firefox\Profiles\g2qcfng1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.270:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.271:C:\RECYCLER\NPROTECT\00000423.txt -> TrackingCookie.Yieldmanager : Cleaned.


    ::Report end

    Thanks again!
     
  6. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    How are things?? If not good then post the current HiJack log
     
  7. Passani

    Passani Thread Starter

    Joined:
    Jun 20, 2006
    Messages:
    14
    Things are better! No more top-banners pop unders, however I do keep getting a small IE javascript initiated window (it says javascript as the header before changing to the destination title),.. that is small and seems to be intermittent. Here is the current log..

    Logfile of HijackThis v1.99.1
    Scan saved at 10:01:38 AM, on 6/21/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    C:\Program Files\UltraVNC\WinVNC.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
    C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
    C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
    C:\Program Files\McAfee\Managed VirusScan\Agent\myAgttry.exe
    E:\PROGRAMS\Hijack This\HijackThis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\Agent\Splash.exe
    O4 - HKLM\..\Run: [McAfee Managed Services Tray] "C:\Program Files\McAfee\Managed VirusScan\Agent\myagttry.exe"
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O13 - Gopher Prefix:
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} (SecureObjectFactory Class) - http://vs.mcafeeasap.com/SW/ENU/VS40/bin/myCioAgt.20060504183849.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = usfundinggrp.local
    O17 - HKLM\Software\..\Telephony: DomainName = usfundinggrp.local
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = usfundinggrp.local
    O18 - Protocol: myrm - {4D034FC3-013F-4B95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt4.0.0.358.dll
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: McShield - McAfee, Inc. - C:\PROGRA~1\McAfee\MANAGE~1\VScan\McShield.exe
    O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe" -sMICROSOFTSMLBIZ (file missing)
    O23 - Service: McAfee Total Protection Agent Service (myAgtSvc) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i MICROSOFTSMLBIZ (file missing)
    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    O23 - Service: SonicWALL Agent Service (SWAGENT) - McAfee, Inc. - C:\Program Files\McAfee\Managed VirusScan\Agent\swAgent.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    Please let me know what you think.... and thank you for the help so far ! Greatly appreciated!
     
  8. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
  9. Passani

    Passani Thread Starter

    Joined:
    Jun 20, 2006
    Messages:
    14
    Restore points have been off, so I'll get them on as you requested.. As for the java, it is a small window, maybe 600x100 pixels that displays an ad of some sorts... I can capture it if you that'll help.. do you want the page source?
     
  10. Passani

    Passani Thread Starter

    Joined:
    Jun 20, 2006
    Messages:
    14
    Here is the address for one of the pop ups... not sure it this was the java window or not... I pulled it from history.
     
  11. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
    Scrn Prnt - I see no address
     
  12. Passani

    Passani Thread Starter

    Joined:
    Jun 20, 2006
    Messages:
    14
  13. MFDnNC

    MFDnNC

    Joined:
    Sep 7, 2004
    Messages:
    49,014
  14. Passani

    Passani Thread Starter

    Joined:
    Jun 20, 2006
    Messages:
    14
    Downloaded the toolbar! I stopped Messenger a while back.. never like un-needed services.. I'll keep you posted.
     
  15. Passani

    Passani Thread Starter

    Joined:
    Jun 20, 2006
    Messages:
    14
    Here is the java pop-ups source:

    <HTML><HEAD><TITLE>&nbsp;</TITLE></HEAD><BODY LEFTMARGIN=0 TOPMARGIN=0 MARGINHEIGHT=0 MARGINWIDTH=0><table align="center" width=350 cellspacing="0" cellpadding="0"><tr><td><a href="http://www.yourstats.net/click.php?adsid=19660bc&url=http%3A%2F%2Fwebmaster.windowscasino.com%2Faffiliates%2Faiddownload.asp%3Faffid%3D63858" target=_blank><img src="http://www.myvegasonline.com/banner_casino.gif" border=0 width=468 height=60></a></td></tr></table></body></html><script src="http://service.multi-pops.com/xbannered.php?sn=821150913887&uip=
    209.95.32.34&siteid=Luweb&unsold=&serverfile=popdirect&ref=http%3A%2F%2F
    www.top-banners.com/tmc/to.php?id=ActDkTp2&unsold=true&data=
    rSe_2%D1%CB%CE%C9%D6%C9%D4%D1%D3%D7%C6%2Fg%5E%5DcY%DD%
    E6%2B-%7E%FA%C7%29-%7E%26+%3B%7E%29%2F%27%D9%C0%FA%FD-%
    7D%22%D6%CC%D9%D6%D5.L%5B+i%25+%29%DA%7D%282%2F%28%22%
    DD%D1%24Zm%5CF2%FB%22%7E..%DE%BF%FC%210%F0sKdci6%D7%BF%
    2B%28%28-%22%7B%DD1.sO&url="></script>
     
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/476968

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice