WXP starts in safe mode but not normal mode

Discussion in 'Malware Help (A Specialist Will Reply)' started by cjs56, Aug 5, 2009.

  1. cjs56

    cjs56 Private E-2

    I am able to start in Safe mode, but the machine will not complete a normal boot.

    I ran most of the malware removal procedure and removed numerous infections. In safe mode, I am not able to install SUPERAntiSpyware.

    I have included the log files in two posts.

    Thank you
     

    Attached Files:

  2. cjs56

    cjs56 Private E-2

    Combofix log is too large to attach (273kb).
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Probably because you have used it in the past and never uninstalled it. Thus you probably had a large snapshot sections. Compress the file into a ZIP and attach it or split it into two files and attach them. We need this log to continue.

    Also note you are out of date with Malwarebytes. Thus to be safe, run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.


    Exactly what happens when you try to boot in normal mode?
     
  4. cjs56

    cjs56 Private E-2

    I split the original Combo Fix log and attached them.

    I updated and reran Malwarebytes.

    When I attempt to boot in Normal mode, the system starts up with the list of users. I click my logon and after several minutes I get the ...loading personal settings. It then takes several hours before I get to the background screen. At some point, Spybot kicks in and starts running a scan before my desktop icons appear.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Spybot and SpySweeper then reboot your PC. See if you can run in normal boot mode now.
     
  6. cjs56

    cjs56 Private E-2

    I removed Spysweeper and Spybot.

    Restarted in normal mode. Clicked on my user name. The welcome screen has been up for thirty minutes. And, the hard drive light remains a solid amber.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems may not be malware based on your logs. And also based on what I see in your logs, it appears that your user accounts have had some issues in the past which is why the below accounts show:
    Code:
    "C:\Documents and Settings\"
    COMPAQ~1      Oct 21 2005              "Compaq_Owner"
    COMPAQ~1.YO~  Aug  3 2009              "Compaq_Owner.YOUR-BE71E130BE"
    GUEST         Mar 20 2005              "Guest"
    GUEST~1.YOU   Oct 22 2005              "Guest.YOUR-BE71E130BE"
    MICHELLE      Mar  8 2005              "Michelle"
    MICHEL~1.YOU  Oct 22 2005              "Michelle.YOUR-BE71E130BE"
    SHERRY        Jun 27 2005              "Sherry"
    SHERRY~1.YOU  Aug  2 2006              "Sherry.YOUR-BE71E130BE"
    This is not a malware issue. Some problem with Windows has cause these account changes. This would ne something you need to work in the Software Forum.

    Let's try a couple things.

    Some or many of the below items I'm asking you to fix with HijackThis may no longer be present. That's okay! Just ignore them if not found.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2985] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4756] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\jDRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2630] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5826] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\rDRM0302.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA441] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlPanel\index.html"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4178] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\controlPanel\index.html"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1008] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4586] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1027] command.com /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9270] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install\DRM0302_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4555] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\actorobject.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4246] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\actorobject.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6434] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\dx5drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1039] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\dx5drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA8476] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\dx7drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC7519] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\dx7drv.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA8105] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\jdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8691] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\jdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA44] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\npWTHost.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9217] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\npWTHost.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7980] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\nsIWTHostPlugin.xpt"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5440] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\nsIWTHostPlugin.xpt"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA8781] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\ObjectBundle.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1692] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\ObjectBundle.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA8237] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\rdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC7218] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\rdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1386] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\Sound.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1106] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\Sound.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6007] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wdcaps.ded"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC56] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wdcaps.ded"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2142] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wdengine.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC7903] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wdengine.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA601] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\Webd331.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5607] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\Webd331.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6956] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\Webd331_fileList.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8796] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\Webd331_fileList.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA257] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\Webd331_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6412] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\Webd331_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4858] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4454] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6374] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wildtangent.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3592] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wildtangent.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3827] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wt3d.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8230] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wt3d.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA9544] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\WTHost.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3777] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\WTHost.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3627] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\WTHostCtl.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6496] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\WTHostCtl.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1445] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wtmulti.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3332] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wtmulti.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA451] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wtmulti.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5147] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wtmulti.jar"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1123] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wtwmplug.ax"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9588] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wtwmplug.ax"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1350] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wtwmplug.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC724] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\wtwmplug.ini"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4824] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\controlPanel\index.html"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3985] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\controlPanel\index.html"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1807] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\legacy\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC7539] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\legacy\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC2487] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\legacy\webdriver.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6147] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\legacy\wt3d.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1191] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\legacy\wt3d.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA6151] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\update_info\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC5976] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\files\update_info\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4717] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\install\Webd4_1_1.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC40] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\install\Webd4_1_1.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA5382] command.com /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\install\Webd4_1_1_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9531] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\Webd\4.1.1\install\Webd4_1_1_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA8534] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\WireControl.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4428] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\WireControl.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1463] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC2974] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl.cdanfo"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2608] command.com /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9508] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files\install\WireControl_Uninstall.cdas"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA1893] command.com /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3932] cmd.exe /c del "C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info\data.wts"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA9122] command.com /c del "c:\Program Files\ErrorGuard\setupactive.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC8587] cmd.exe /c del "c:\Program Files\ErrorGuard\setupactive.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA8132] command.com /c del "C:\Program Files\ErrorGuard\ErrorGuard.exe"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC7877] cmd.exe /c del "C:\Program Files\ErrorGuard\ErrorGuard.exe"
    O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now after reboot, click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System Rile Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it. Reboot again after running sfc. Also be sure to tell me if it asks for your CD.

    If you still cannot log in in normal boot mode, the last suggestion I have is for you to uninstall Symantec/Norton.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. cjs56

    cjs56 Private E-2

    I ran MGtools\analyse.exe

    I ran ComboFix in Safe Mode. But I was not there when it rebooted into normal mode. It was unable to finish in normal mode. So, I re-ran ComboFix in safe mode and selected safe mode when it rebooted.

    I tried running sfc /scannow in safe mode, but I get an error:
    Windows File Protection could not be initiate a scan of protected system files. The specific code is 0x000006ba [The RPC Server is unavailable.].

    How shall I proceed?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Microsoft has an article on this which was publish for Windows 2000 systems. It may also apply to your Windows XP system so it may be worth checking out. I will give the link down at the end of this message. But first, let's check to see that your RPC service is running.

    • Click to Start -» Run -» and type in services.msc and click OK.
    • This will open up the Services form.
    • Scroll down to the Remote Procedure Call (RPC) service (NOT the one that says Locator) and check to see if it's started.
    • If it's not started, right click on it and select Start
    • If it was not started, and you managed to start it. Now try running sfc.
    • If this does not help and your PC still cannot boot in normal boot mode, it would be a good idea to run System Restore to restore to a point before running the last fix with ComboFix.
    For future reference, never run ComboFix additional times. Only run it as instructed and if it does not run for any reason, just stop and come back and describe exactly what happened.

    Here is the Microsoft acticle I was referring to:

    http://support.microsoft.com/?kbid=296241
     
  10. cjs56

    cjs56 Private E-2

    I was not able to run System Restore since I turned it off during my initial cleanup process.

    In between posts, I found the WXP install CD and attempted to run a "repair" install as a substitute for running "sfc". However, I was not paying attention to the prompts and hit the enter key instead of R to repair. The good news, is that the machine is running.

    I guess we can close this post. I am hoping to do a full system recovery from the Compaq Recovery partition. Unfortunately, I lost the SMINST folder during the installation and need to find a workaround.

    Thanks for the time and effort.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For your future reference, this is not what our procedures ask you to do. Our procedures specifically do not want you to disable System Restore until malware cleaning has been finished. It is your possible backup just for cases like this. ;)

    Since by now you probably have a freshly installed system, you should work thru the below.

    How to Protect yourself from malware!
     
  12. cjs56

    cjs56 Private E-2

    During the Full system recovery, I received an error message that the formatting was unable to complete. I ran a Maxtor diagnostic disk and it confirmed that the hard drive is bad.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then I guess your course is clean. Install a new hard disk and reinstall your OS.;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds