Infected, Malware really bytes! help

Discussion in 'Malware Help (A Specialist Will Reply)' started by ferg67, Dec 1, 2009.

  1. ferg67

    ferg67 Private E-2

    This all started with a bad infection, would not allow anything to run, would not allow any installs, message about not having access or privillage is statring to get old. No internet at this point. I had run my usuals, malwarebytes, SAS, tried to install MSES but it failed and now will not uninstall. I then went to this forum and ran the predefined cleaning procedure. This made a big difference, however, Infected still, need help. I am attaching all the logs, if you need more I can get them but the computer is off the INT, so I have to use another one to post. The infected one also had an issue where If i opened user accounts from CP it would open a blank screen, it sauys user accounts at the top and has arrows forward and back but they do nothing. After running through this process I now have user accounts again. Thought maybe was in clear but then i tried to reinstall SP3 and now I am getting the I do not have permissions to open IE. Help I am ready to follow your lead, i dont want to reformat but I will if its the only way.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    Please attach the following requested log(s) -

    *MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.

    Note: Once it is attached, you will be in our queue - working the oldest threads first, and I will get back to you with a set of instructions as soon as possible.

    Thanks for your patience.
    dr.m
     
  3. ferg67

    ferg67 Private E-2

    Thank you so much for getting back to me, I really appreciate it.
    I've attached the MGlogs.zip and will do nothing until you get back to me.
    Thank you again, i can usually clean but this seems to be keeping me at bay.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    Good idea not to make any changes or attempted installs unless instructed.

    Please give me time to go over your logs.

    dr.m
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The below fixes and advice are specific to this member's problem and should only be used for issue(s) on this machine.

    Hello, ferg67, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    Note: We have lots of work to do! It's been awhile since I've seen a machine in this shape.

    I strongly recommend that you clean up this account's Desktop immediately leaving only links.C:\Documents and Settings\julie\Desktop Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    A question: What are these 94 files in C:\WINDOWS\ that start with Summary_.txt ?

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and continue on.
    Step 2:
    Comment: Your machine can r-e-a-l-l-y get messed up by having multiple av's installed.
    We need to remove some remnants from AVG8,McAfee and Norton.
    Please run the following > re-boot > then run the tool again:

    AVG Remover

    Now, repeat those same instructions for the below:

    McAfee Consumer Product Removal Tool

    Norton Removal Tool (SymNRT) 2009.0.5.26

    Step 3:
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Step 4:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 5:
    Now we need to use ComboFix.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):

    Code:
    KILLALL::
    
    File::
    C:\Documents and Settings\julie\Application Data\abiq.dl 
    C:\Documents and Settings\julie\Application Data\amugu.sys
    C:\Documents and Settings\julie\Application Data\axamotyhy.dl
    C:\Documents and Settings\julie\Application Data\bogizaz.dll
    C:\Documents and Settings\julie\Application Data\byrazibyz.lib
    C:\Documents and Settings\julie\Application Data\gala._dl
    C:\Documents and Settings\julie\Application Data\hyjygefug.bin
    C:\Documents and Settings\julie\Application Data\imiseku.exe
    C:\Documents and Settings\julie\Application Data\iwovot.dat
    C:\Documents and Settings\julie\Application Data\nuzupuq.dll
    C:\Documents and Settings\julie\Application Data\omamudity._dl
    C:\Documents and Settings\julie\Application Data\owih.dll
    C:\Documents and Settings\julie\Application Data\pufuheci.com
    C:\Documents and Settings\julie\Application Data\ujiw.bin
    C:\Documents and Settings\julie\Application Data\uxiqysunog.lib
    C:\Documents and Settings\julie\Application Data\uzufuvos.scr
    C:\Documents and Settings\julie\Application Data\walulyxywa.dll
    C:\Documents and Settings\julie\Application Data\wure.lib
    C:\Documents and Settings\julie\Application Data\zojucin.dat
    C:\Documents and Settings\julie\Local Settings\Application Data\akasagub.dll
    C:\Documents and Settings\julie\Local Settings\Application Data\apatu.dat
    C:\Documents and Settings\julie\Local Settings\Application Data\avocisudi.sys
    C:\Documents and Settings\julie\Local Settings\Application Data\dadynamuhu.dll
    C:\Documents and Settings\julie\Local Settings\Application Data\dupyjyruh.com
    C:\Documents and Settings\julie\Local Settings\Application Data\dyfabiq.dll
    C:\Documents and Settings\julie\Local Settings\Application Data\elaqifu.db
    C:\Documents and Settings\julie\Local Settings\Application Data\enadetakobi.dll
    C:\Documents and Settings\julie\Local Settings\Application Data\icowikuzub.db
    C:\Documents and Settings\julie\Local Settings\Application Data\ihamoqaw.exe
    C:\Documents and Settings\julie\Local Settings\Application Data\jalefetolo.exe
    C:\Documents and Settings\julie\Local Settings\Application Data\livocazuto.exe
    C:\Documents and Settings\julie\Local Settings\Application Data\lulerugaja.sys
    C:\Documents and Settings\julie\Local Settings\Application Data\nafi.ban
    C:\Documents and Settings\julie\Local Settings\Application Data\nufi.ban
    C:\Documents and Settings\julie\Local Settings\Application Data\qutad._dl
    C:\Documents and Settings\julie\Local Settings\Application Data\sjglsh40.dll
    C:\Documents and Settings\julie\Local Settings\Application Data\supuc._dl
    C:\Documents and Settings\julie\Local Settings\Application Data\tigumaxu.lib
    C:\Documents and Settings\julie\Local Settings\Application Data\ujow._sy
    C:\Documents and Settings\julie\Local Settings\Application Data\usaku.bin
    c:\documents and settings\julie\Application Data\uzufuvos.scr
    C:\Documents and Settings\julie\Local Settings\Application Data\valyfyqat.ban
    C:\Documents and Settings\julie\Local Settings\Application Data\vysib.dat
    C:\Documents and Settings\julie\Local Settings\Application Data\wefel.db
    C:\Documents and Settings\julie\Local Settings\Application Data\wexydyweq.ban
    C:\Documents and Settings\julie\Local Settings\Application Data\xehufi.lib
    C:\Documents and Settings\julie\Local Settings\Application Data\yvece.dl
    C:\Documents and Settings\julie\Local Settings\Application Data\zeke.ban
    C:\Documents and Settings\julie\Local Settings\Application Data\Xmoradoyad.bin
    C:\Documents and Settings\julie\Local Settings\Application Data\zuje.dll
    C:\Documents and Settings\All Users\Application Data\akyvi.com
    C:\Documents and Settings\All Users\Application Data\alyni.dat
    C:\Documents and Settings\All Users\Application Data\bobibuse.exe
    C:\Documents and Settings\All Users\Application Data\degoc._sy
    C:\Documents and Settings\All Users\Application Data\hapop.com
    C:\Documents and Settings\All Users\Application Data\nela.sys
    C:\Documents and Settings\All Users\Application Data\opyvamum.db
    C:\Documents and Settings\All Users\Application Data\puvi.exe
    C:\Documents and Settings\All Users\Application Data\quxujifo.db
    C:\Documents and Settings\All Users\Application Data\ramohimyga.pif
    C:\Documents and Settings\All Users\Application Data\ricir.lib
    C:\Documents and Settings\All Users\Application Data\rimitacuc.exe
    C:\Documents and Settings\All Users\Application Data\ucirozuzys.sys
    C:\Documents and Settings\All Users\Application Data\upabep.dat
    C:\Documents and Settings\All Users\Application Data\upijekibu.pif
    C:\Documents and Settings\All Users\Application Data\vudus.lib
    C:\Documents and Settings\All Users\Application Data\ycaxyb.exe
    C:\Documents and Settings\All Users\Application Data\ykinelywu.pif
    C:\Documents and Settings\All Users\Application Data\yzasupyx.db
    C:\Documents and Settings\All Users\Application Data\zaxafag._sy
    C:\Program Files\Common Files\adaxawij.bin
    C:\Program Files\Common Files\amepok.sys
    C:\Program Files\Common Files\cucetavur.dll
    C:\Program Files\Common Files\eninabyt._sy
    C:\Program Files\Common Files\hadimun.exe
    C:\Program Files\Common Files\icozawapim.exe
    C:\Program Files\Common Files\imiquke.sys
    C:\Program Files\Common Files\jaluxyd.dl
    C:\Program Files\Common Files\joly.db
    C:\Program Files\Common Files\mababa.lib
    C:\Program Files\Common Files\mahexakad._dl
    C:\Program Files\Common Files\myra.lib
    C:\Program Files\Common Files\pupany.dl
    C:\Program Files\Common Files\qudutosyz.pif
    C:\Program Files\Common Files\uhiqykywi.bin
    C:\Program Files\Common Files\wyza.exe
    C:\Program Files\Common Files\xezaca.sys
    C:\Program Files\Common Files\xoxo.lib
    C:\Program Files\Common Files\xyjyf.dat
    C:\Program Files\Common Files\ybeh.db
    C:\Program Files\Common Files\ygupygu.bin
    C:\Program Files\Common Files\ypamunylah.dll
    C:\Program Files\Common Files\zataduko.exe
    C:\WINDOWS\abidi.com
    C:\WINDOWS\anujovyziz.ban
    C:\WINDOWS\asavo.dl
    C:\WINDOWS\buras.com
    C:\WINDOWS\Bvomaz.dat
    C:\WINDOWS\efupeho.bin
    C:\WINDOWS\eletin._dl
    C:\WINDOWS\erosage.pif
    C:\WINDOWS\ipurexaqix.dat
    C:\WINDOWS\jylofa.sys
    c:\windows\liccyval.dat
    C:\WINDOWS\ohabipupyh.sys
    C:\WINDOWS\onawoluqis.lib
    C:\WINDOWS\oryqu.ban
    C:\WINDOWS\osares.ban
    C:\WINDOWS\pylyzep.ban
    C:\WINDOWS\qihufexawy.bin
    C:\WINDOWS\ridemaqe.lib
    C:\WINDOWS\sutevi.bin
    C:\WINDOWS\syqi.dat
    C:\WINDOWS\uqytix.dat
    C:\WINDOWS\vafuqepit.com
    C:\WINDOWS\vezug.ban
    C:\WINDOWS\vikalelel.bin
    C:\WINDOWS\vobopomudy.bin
    C:\WINDOWS\Xmoradoyad.bin
    C:\WINDOWS\system32\3weg3.ge
    c:\windows\system32\58DC512EDF.sys
    C:\WINDOWS\system32\ahadozefor.dll
    C:\WINDOWS\system32\arivacoj.pif
    C:\WINDOWS\system32\bawiyira
    C:\WINDOWS\system32\caseq._sy
    C:\WINDOWS\system32\ehenos.dat
    C:\WINDOWS\system32\fevawolan.exe
    C:\WINDOWS\system32\fymazokizi.db
    C:\WINDOWS\system32\hyjapebofi.bin
    C:\WINDOWS\system32\iboleqebex.db
    C:\WINDOWS\system32\maludavopo.dl
    C:\WINDOWS\system32\obiveqyqub.sys
    C:\WINDOWS\system32\ofecotinyr.dl
    C:\WINDOWS\system32\opud.bin
    C:\WINDOWS\system32\osacoxiqa.exe
    C:\WINDOWS\system32\pehubeja.ban
    C:\WINDOWS\system32\taviky._sy
    C:\WINDOWS\system32\urukife._sy
    C:\WINDOWS\system32\vuhi.dll
    C:\WINDOWS\system32\wawowiseze.pif
    C:\WINDOWS\system32\yvezitiqe.exe
    
    Folder::
    C:\Documents and Settings\julie\Application Data\AVG8
    C:\Documents and Settings\All Users\Application Data\McAfee
    C:\Program Files\AVG
    C:\Program Files\McAfee
    C:\WINDOWS\35C03C043F1F42C2A989A757EE691F65.TMP
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below


    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 6:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 7:
    *You are way out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Then perform a new "Quick Scan" of your system. And attach this new log.


    Step 8:
    Now install the latest Sun Java Runtime Environment

    Step 9:
    Please use the following link to install your new anti-virus program.... NOW!

    How to Protect yourself from malware!

    Step 10:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt
    • Updated SASlog.txt


    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  6. ferg67

    ferg67 Private E-2

    Thanks for getting back to me.
    Ok, here we go...
    The summary_.txt logs are of unknown origin, i removed them.
    Add/remove the following...
    My Hijack this version was higher then the one you listed so I left it alone.
    the Java you listed was not there either, i had already updated to a new version.
    Viewpoint not there.
    WildTangent web driver, tried to uninstall but it will not, select remove and it just gives me an hourglass for a few seconds then goes back to waiting for me to select something else, the program does not uninstall.
    Same results for Microsoft Security Essentials, will not uninstall.

    I had no problems uninstalling AVG, and Norton however I received an error during the McAfee rremoval about it being enterprise software, can not continue, contact McAfee tech support.

    Messenger removal went without issue.

    Everything else ran fine.
    I am still having issues although mostly in one area.
    I get an error message at startup for Microsoft Security Essentials.
    Error: an error has occured in the program, try to open again. if problem continues reinstall.
    this was from previous to our starting this process but it is still going on.

    Other issues... I can not open IE anything, internet explorer will not even open, i tried to install it previously and I get the message about not having permissions. Based on how it is acting still i am assuming that this issue is still there. Other then these issues the computer seems to be running very good.
    I want to get it back on the internet soon, updating is a pain without internet access. I am attaching the logs requested and waiting to hear your next thoughts. Again thanks for all the help.
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    OK, ferg67

    Let's try this..

    Please download and run Win32kDiag per the below instructions:

    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK.

      C:\win32kdiag.exe -f -r

    • When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log

    Now download Junction.zip to your Windows folder

    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.


    Now we need to reset the permissions altered by the malware on some files.
    • Download and save inhertit.exe to your Desktop:
      Inherit.exe
    • It must be in your Desktop or the below fix will not work!

    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.

    Now - re-boot your pc!

    Next try uninstalling Microsoft Security Essentials and Viewpoint Media Player.

    Then attach the Win32kDiag.txt log to your next reply.

    Also tell me - is IE now working?

    dr.m
     
  8. ferg67

    ferg67 Private E-2

    Ran everything, so-so success, Internet explorer did open, would not connect but it did open which it would not previously.
    The two programs: Microsoft Security Essentials will still not remove, select it and it hour glasses for 10-15 seconds then does nothing, awaiting next command. Second program, Wild Tangent Web Driver same results, will not remove.

    I am now getting the following pop ups, first 5 minutes after booting I get 6 or 7 of them. then they come up but less frequently.

    GoogleUpdate.exe App error
    The instruction at 0x0159806f memory could not be written

    Iexploer.exe –Application Error
    The instruction at “0x02a9806f” referenced memory at “0x02abf8e8”. The memory could not be “written”.
    Click on OK to terminate the program

    I will say this, the computer seems to get faster aftr each new try:)

    As always attaching requested logs and awaiting the next move. Encouraging progress, thanks again.
     

    Attached Files:

  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, ferg67

    Let's see a new set of logs after updating.

    1. Now go to this link MGTools and download the new version of MGtools....overwrite your previous MGtools.exe file with this one.
    2. Next - run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).


    Please attach the below log to your next reply:
    • C:\MGlogs.zip


    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
    Last edited: Dec 14, 2009
  10. ferg67

    ferg67 Private E-2

    Good Morning,
    Well i downloaded and allowed the override of files for MGtools.exe
    Ran all requested .bat files and am attaching the zip of the logs.
    Big issue is I am getting these error pop ups quite consistantly, but since running the .bat files just now they seem to be gone, will keep you posted on that issue. Its late, thanks again and good luck with the logs.
    While uploading logs, i still have not had a pop up, appears that you may have solved that one.
     

    Attached Files:

  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello again, ferg67

    Step 1:
    Using Windows Explorer - Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Step 2:
    Run the "C:\Win32kDiag.exe" tool again
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK.
      C:\win32kdiag.exe -f -r
    • When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    Step 3:
    Now go to this link MGTools and download the new version of MGtools....overwrite your previous MGtools.exe file with this one.
    *Note: Refer to my previous instructions pertaining to runningFixPerm.bat
    Next - in the C:\MGTools folder, run the "FixPerm.bat"
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Please attach the below log to your next reply:
    • C:\MGlogs.zip
    • NewWin32kDiag.txt log

    dr.m
     
    Last edited by a moderator: Dec 20, 2009
  12. ferg67

    ferg67 Private E-2

    I ran everything, attaching both new logs. As for how does system run, so far the only issue left is that I get pop ups about google updater missing some component and has to terminated, and trying to get to internet i get the following error... this comes trying to renew and release ip from command prompt.
    Tried to get an IP from my router, did a release because it listed a default IP,
    Then did a renew and I get an error: error occurred renewing interface Local area Connection: WSAStartup cannot function at this time because the underlying system it uses to provide network services is currently unavailable.

    So I still can not get it on the internet but everything else seems to be running great.
    Thanks and look forward to hearing from you.
     

    Attached Files:

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    You have no remaining malware, and the above problem should be handled in our Networking Forum

    The below will clearup the Goggle "pop ups".
    Now Copy the bold text below to notepad. Save it as fixME.bat to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you post back if you did not receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    * If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:

    Safe surfing and "Happy Holidays"! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds