The BullGuard products and services are part of NortonLifeLock Inc., a global leader in consumer Cyber Safety with a portofolio of brands including Norton, Avira and more. Learn more at NortonLifeLock.com

Spy sherriff

Posted 1/17/2006 11:33 PM
#26966
User avatar

ken123 Member

Date Joined Nov 2016
Total Posts: 8
Hi im struggling to remove spy sherrif. Ive ran hjt and have the following log file-grateful for anyones help as
to which files to remove and what then

Logfile of HijackThis v1.99.1
Scan saved at 23:30:56, on 17/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\quickenw\QAGENT.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\mrtMngr.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Nokia\PC Suite for Nokia 6600\connmngmntbox.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Nokia\PC Suite for Nokia 6600\ectaskscheduler.exe
C:\quickenw\QWDLLS.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Nokia\PCSUIT~1\Elogerr.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Intuwave\Shared\mRouterRunTime\mRouterRuntime.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\PROGRA~1\Nokia\PCSUIT~1\BROADC~1.EXE
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\PROGRA~1\Nokia\PCSUIT~1\SCRFS.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MICROS~3\Office10\OUTLOOK.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Net Nanny Toolbar - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\Net Nanny Toolbar\toolbar.dll
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QAGENT] C:\quickenw\QAGENT.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ZeroSpyware Lite] "C:\Program Files\FBM Software\ZeroSpyware Lite\ZeroSpyware Lite.exe" -STARTUP
O4 - HKCU\..\Run: [NetGuard Lite] "C:\Program Files\FBM Software\ZeroSpyware Lite\NetGuard Lite.exe" -STARTUP
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0\aoltray.exe
O4 - Global Startup: Billminder.lnk = C:\quickenw\BILLMIND.EXE
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HPAiODevice(hp officejet k series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: PCSuiteForNokia6600 Detect.lnk = ?
O4 - Global Startup: PCSuiteForNokia6600 TS.lnk = ?
O4 - Global Startup: Quicken Startup.lnk = C:\quickenw\QWDLLS.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - https://www.rawflow.com/passion/Rawflow.cab
O16 - DPF: {28F00B0F-DC4E-11D3-ABEC-005004A44EEB} (Register Class) - https://content.hiwirenetworks.net/inbrowser/cabfiles/2.5.30/Hiwire.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - https://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - https://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-9.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - https://sib1.od2.com/common/Member/ClientInstall/7.20.0003/OCI/setup.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - https://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - https://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - https://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe



thanks ken
Posted 1/18/2006 12:28 AM
#26974
User avatar

JSntgvr Advanced member

Date Joined Nov 2016
Total Posts: 526
Click here to download smitRem.exe:

https://noahdfear.geekstogo.com/click%20counter/click.php?id=1

*Save the file to your desktop.
*It is a self extracting file.
*Doubleclick the smitRem.exe and it will extract the files to a smitRem folder on your desktop.
*Do not do anything with it yet. You will run the RunThis.bat file later in safe mode

Download Killbox from any of the sites below, and have it ready to run later-on:

https://www.downloads.subratam.org/KillBox.exe

https://www.downloads.subratam.org/KillBox.zip

Download the trial version of Ewido Security Suite:

https://www.ewido.net/en/download/

· Install Ewido.
· During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".

*Launch ewido
*It will prompt you to update click the OK button and it will go to
the main screen
*On the left side of the main screen click update
*Click on Start and let it update.

*DO NOT run a scan yet. You will do that later in safe mode.

Run Hijackthis. Place a checkmark on the following lines and click on Fix Checked:

O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe

* Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.

* Restart your computer into safe mode now.

https://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam

Perform the following steps in safe mode:

* Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.

Wait for the tool to complete and disk cleanup to finish.

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the Full Path of File to Delete box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confirmation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the Paste Full Path of File to Delete box.

c:\secure32.html
C:\WINDOWS\system32\paytime.exe
C:\winstall.exe

Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure not to miss any.

Exit the Killbox.

* Run Ewido:

*Click on scanner
*Click Complete System Scan and the scan will begin.
*During the scan it will prompt you to clean files, click OK
*When the scan is finished, look at the bottom of the screen and click the Save report button.
*Save the report to your desktop

* Go to Control Panel > Internet Options. Click on the Programs tab, then click the "Reset Web Settings" button. Click Apply then OK.

* Next go to Control Panel > Display. Click on the "Desktop" tab then click the "Customize Desktop" button. Click on the "Web" tab. Under "Web Pages" you should see an entry checked called something like "Security info" or similar. If it is there, select that entry and click the "Delete" button. Click OK then Apply and OK.

* Restart back into Windows normally now.

* Run ActiveScan online virus scan

https://www.pandasoftware.com/products/activescan.htm

When the scan is finished, anything that it cannot clean have it delete it. Make a note of the file location of anything that cannot be deleted so you can delete it yourself.

- Save the results from the scan to the desktop!

Post a new HijackThis log along with the results from ActiveScan and Ewido.
Posted 1/21/2006 3:48 PM
#27128
User avatar

ken123 Member

Date Joined Nov 2016
Total Posts: 8
Hi thanks tried to post this reply already so sorry if its a duplicate
I sem to have lost spy sherriff but all is not well in win explorer it seems a downloader is trying to take over the machine grateful for your help



hjt:



Logfile of HijackThis v1.99.1
Scan saved at 15:25:25, on 21/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\quickenw\QAGENT.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\mrtMngr.EXE
C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
C:\Program Files\Nokia\PC Suite for Nokia 6600\connmngmntbox.exe
C:\Program Files\Nokia\PC Suite for Nokia 6600\ectaskscheduler.exe
C:\quickenw\QWDLLS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Nokia\PCSUIT~1\Elogerr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Intuwave\Shared\mRouterRunTime\mRouterRuntime.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\PROGRA~1\Nokia\PCSUIT~1\BROADC~1.EXE
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\PROGRA~1\Nokia\PCSUIT~1\SCRFS.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ewido anti-malware\SecuritySuite.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\MICROS~3\Office10\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.thesun.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QAGENT] C:\quickenw\QAGENT.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ZeroSpyware Lite] "C:\Program Files\FBM Software\ZeroSpyware Lite\ZeroSpyware Lite.exe" -STARTUP
O4 - HKCU\..\Run: [NetGuard Lite] "C:\Program Files\FBM Software\ZeroSpyware Lite\NetGuard Lite.exe" -STARTUP
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0\aoltray.exe
O4 - Global Startup: Billminder.lnk = C:\quickenw\BILLMIND.EXE
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HPAiODevice(hp officejet k series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: PCSuiteForNokia6600 Detect.lnk = ?
O4 - Global Startup: PCSuiteForNokia6600 TS.lnk = ?
O4 - Global Startup: Quicken Startup.lnk = C:\quickenw\QWDLLS.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - https://www.rawflow.com/passion/Rawflow.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - https://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - https://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-9.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - https://sib1.od2.com/common/Member/ClientInstall/7.20.0003/OCI/setup.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - https://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - https://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - https://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe



Active scan:

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 07:18:43, 20/01/2006
+ Report-Checksum: 40920610

+ Scan result:

HKU\S-1-5-21-2765703236-2031576664-3894886214-1006\Software\Coulomb -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-2765703236-2031576664-3894886214-1006\Software\Coulomb\Page3 -> Dialer.Generic : Cleaned with backup


::Report End
Posted 1/21/2006 4:56 PM
#27132
User avatar

ken123 Member

Date Joined Nov 2016
Total Posts: 8
Weirdest thing all seems ok but when i use ebay and click on an item,, it starts to download what appears to be a virus im sure its all related but could be that ive put too much security on the browser ?? Grateful as always for any input
Posted 1/21/2006 6:48 PM
#27139
User avatar

JSntgvr Advanced member

Date Joined Nov 2016
Total Posts: 526
It could be an ActiveX to recognize you.


O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - https://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - https://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-9.cab
Posted 1/21/2006 10:37 PM
#27147
User avatar

ken123 Member

Date Joined Nov 2016
Total Posts: 8
Thanks - I clicked on the links and they seem to have saved to temp internet files logged back on same problem bounced the box and updated xp still same



Strange bit is that it happpens only when im signed in to ebay, if i browse the item not logged in its fine when i click on an item i sometimes see the following this is part of the page display in iexplorer

f ]) ‹í=ksã6’Ÿ“ªý¦Æ²7Ö[rlÙRÊÖØ'öŒÆòdvsuå¢HHbL AZÖNò_¦j?Ý¿¼n€oR/KvR{§ë€@£ÑèÀÉ؝˜“1UõÎß¾>yU,Ò3uF~®É„?NLÒ(UÈ?澊E|jB]•Œ]×.Òß<ã¡­t™åRË-ÞÎlªMþj+.}tËØà1Ñƪé۾ì¿/6ŠU¥#ë±Ô m+:åšcØ®Á¬X†¥“wªÅˆÑc:éÖ=¹¢ª;¦骜’3uD.nÎÏIþ}ü‰Lðpo…ÎMª¹³ “}rÝ«“ž©Î ãTÓ(çÌ1(fœÚ¶IeÉ l„Muéˆ93Â,‚è*i¬äÝ—’=¸§³)st È÷sažò<ˆ}€0×pMÚ‰€m­ˆÆub÷^!.w —NHó°qXkÔšGMBa0\cBI¥YüQµŠ•R­·*µV퀼½¾Ý;)ËV‘ª¸£]ê-ò³A§—P ÐM–jzŽ:š¨1|Y¬¨©Ú˜&{ꌪñB^‰7ûµqð=“D#ZüÛתCŒ¡vö@uÒ&®ãÑc̱˜N‡ªgºçAúß¾.—´rPü$}[AP[å²ai¦§Ó¨3¡F'å_y™6êGeï¾üD\ÝaBãW¨NwCåÂÔðg ø ‹Z?¡oÅ¡:1ÌYëÔ1Tsÿj>PhJÝçªÅ‹œ:Æðø¿<)–®:ú¾ümûŸn þ7n«–ÿÕ3ý/,ø¢›²inü‹¶‹|¢šfÔŠÚR5×x ûÁOè&üñ`pè³þYc&sZßTàÕíÆN8:ªTŽŽ¢¶Cýâ ;ä*ûþý ³tA£Ç W}¨J¶:¢‚cýšPÝð&òù)5Fc·5`¦ž÷8âmôøòYÞÊDuF†U0×e“VÍ~Œµ[ Úå0áñ¥!—Ý\x-xߦš1¦±>ðF—@_I@_ˆn¼Ÿ¢ÊX?rá.щ=V±åù },èk‰:s‚âHo±Ü15í ó@¼b™¶aÓˆ Ž..b™úL‘’¥>##ÅŸ©£«–GY† K8·ìqÕc'Ñ¿Ñ£õªÊtÜbr?ˏ䖀 ]ƒà€)óY7¸ B¦e1‹Æ±ê¸cC»ÿL¦¢j#«Ec25twÜ"ÕJåõ1Ë!#HßdR:-™ièD`¼Û%U‘¥j÷#‡yˆ?#ÕšµQcä›7Ý7Ý‹óœÖdF ÍH¤7lúÙ¯¢è2çglM ˆMàtŽàã~E ]fzës¬jN! E()¼†‡1*Ï_Ñ¡TeÂ÷MêºA$• 4oRÛ™@Ïç$²6ìéÊun!k¶ù¼A³7ô»>ª5"æx‹ÜRgbXªÏƒý)¥ÊJp d}Ç™êIÀG"î@j´9^«‰æÂÖÔ1°†T[2-¨¯yqÿrZ:3!)ÑŽÏV¤"…ÍÀ§00NLG¥ÙdªÞV Ëpw÷Žé¤‘-,†G×SÍ:p@nìÞ¬°wü`¼塤"§¿œ`m¥¢˜?±_8ⱟr´b ò«d±ÁLð7hÉêâ' wQü‘Å5jš¨|Ö(üm«º.~7¡èH ¤­€<ÂVèÀŸ.”» Îh vŒŽËAQ«TŠ•j±rHjÕV³ÿ÷÷÷I¤×b9_i¿ªªL…ž«ÖÈÆÝV~„Ô¾H­–À¤ò•ÕwAÇ-,Va ÿ~õþ}E´‰þµíB ±ËÌ 5cÌ€‘ÐŒÉ*åž½¤Îu1'ЀU—ئ!f¹¥;Ð&‘Pfî*c1ž] 00Q÷Jwô‘j»ÊÔÝKÌ­þ˜RWÙËGÛ–¡9ÜU4&æ Sª) $ýeƒ€h¦Êy[Á€h‡Ì™IÊ“…ºcÓZU|KL¢ OUG+íÕÁÄpe=sÐVࢴ¦@XOþ«¯°š¤l@´òAAÒ„……J¥Ž}œOÄ¢S"KY¨ !!ež÷S‚ Ý4¡ï†e{ÁðŒ ]§VÐÙ¡Ã& yPM~Ü4"v‘â!GÈáq΂Ì«½(Ù˜ %Dþie329s؈$"°Ñ: Ñ8Nã8D”MFq¨&:jYÀêDˆ$¬šhªã l0R¦ …MroX:'lHÐjáO…|ü ø;ªL[«-ÎVl0ŒÒ]æà’ÉÓ±Òª©TÖö•´ÊIЗ}¢^;%w´ Εpmt(À÷£I­ö¬^©êW…0) F¢À[bn 6“‡Oj•!„aÏ-ÎGF†4’ZÙÓ„™p¬,ÍÊ(]ËB~oWŒ7–‰ñÆ2êôŸKM¼±7ˆO;PÃæh‚ý1³ XR Uºtòúº4ùÞŠ)ciI*ûR¿ÏuÇó$0ˆ©äõA0Ì…p%MbÈ·ŽªÝKà„z+Vf × †Y¿+“™€ungRô•L<ËpçÁ3ÏÚÇE< tú}©Â»¥a¡õIõ"ÒÆÀáF9Ù˜0ô¬°›T±~ÿ±Có{ŸCè­/ƒ%B}I”‹…·Ô%XrŸ qa[µø”:T\Þ„#]Ãd¤é{¶Í7ìþ“ž]¿ßØÄ‹[4æleüʱâi|™ð84˜Ðù±kAz9¨µvTÙßã"Rû¦ }Ì ï.睑{œñs­Ü^ó zp”ßb~èèÚ<)«‹=È1Ûc2ˆåMí%GáÙùmDËìÍ?Ÿ·:«·F@Ñ >ªq²_¬Ú.¶½ã~gx]FLnþ²jè_‘ú…ø1& ¯º¡·•©êjchVI‘wb%yŽ绵’ŠJ5½®4fÓó‰j˜§žX^½e q,]Ì2œ›íh†(Qõ• E±9bc#oÆrŒ67"ƒ„fàg|©<˜™Ít‰Ä0ÆâÎ!kÐLf¬r4) gtcÍ™ûÛr d`M7šáÆÍxXD(y¶ æy+™øóøÙÀM IÚñçÇ4åRz·^`úåO¯\“5Ö£Ús©C)6¯èڐ*ÏÐp®ŽXÂó7fڏ9ØMÍÌÉÖÍà;œ3wÒ²cd4Ç#Q]÷9^¾¬@‹‘¯»àL(*â…)#Ö™f D¸11LU.’5Ù´$âSñ–ÎMÌ£gœÛõ -v mÇïãÓ—të!rľ??öÌlm ŠÁá±ëó›îÝÏ—]E($s²R‘áÙÐq®9Ì4Sˆh-¶ÿäwGiF,áZǍњlÒSá9ôêîÈßm…|K®Á (‰`ü]ùUdíî‘¿ãÖ˜Ê^ävÅb0z©ƒ.Fy¢¾£av@J`L³…óå-u»㼇%ùw\ì¦àÔ1×ōwÕ™Ö®6µJý ¶“šUðs(ØôíÊN`Ù·…i¿c  ‚íúŽ{\݉ÇÔA/Ž*;|lØ0z`km½ÜA,Å(;þftø²á®­bu%þ_IjÀgEuÿ½G^nÍt¶¨®ì‰j|ou¹Lnø¯3 ´Dèg@‡M9®Ëî¾£.×T›’ƒR­|yNö@±z ¸Ú‚§¹G¹¬‘S÷Ö˜Pæ¹»…Õ,™Lžª’CmSÕèn0¨{…ý8-üDøÔË\äÙ”¤>ÿ"¶Ìv-°„î¸m`_!Ù6‚òGG®Çý‰ë3¨'›8üž$Èbª÷sÒöNH7à´ïû—P@ìÌ0ôtÊ–d™DÕö„YíéÒ,`nµuE`å“ÀŠD—z\…Ž»6úí^×*蹃ôÝÁ‡ï½ƒo迃3uïèÃÃB¯k½WðåãO;¸fG>Œ´ÇAva½]ÕÅƲ‚«&=·td÷íjµ~Ð88¨6 ·A-P ž¬ï„Ò5’¥|̦B÷Ež”Ä #1: ß’Â0% kË„a‚ŠþB20 ×|ÑW[Kö=ï ÞZ²»]:y“]u«¦êj䮺%UòÜÍ"µÊA¢…Eœ7öH¼S±Õ‡n°ú²›ùmÔRmÔ’mD+¸™EŨÑé&hÂœÍ>›1M6‰µJbN7Ã缂{F0Èï²3'?ór2’yÁY*±¼+ë>û¡±ÇÌec&ÖÝpsŸfÀL˜˜ç¸ ¸ânáó7É ¾ù£°ç÷Ð_¾NÅPTDO¡€èf¥^6Ê•fY¯–h¹úÝ]­ôcïmb|3p‘ˆÐ½Ü>^ Lhw`¶›ŸÞÐRœ™žKÅ®pÜ Œ[ïñƒ †i¸³–Üïwü¯¢XVl > ›ñßhYšK¬Ne]TPA}¡— ¢ö ¢ïÝÌé@DâÍìZOŽ‡9 ƒÜœ_þu.ÑI$IxæVëÙÚÁXS&\# ÖNÞN‘mu^îµ·˜3QML 1©xËq)d)V®@£éšë94ð2#.)ì6óìε±Ò­å1ÿÆÑ륤š•4þöäÄnäÔN_6Rg‘*¨,Úç{=ÔDAÜÙ ÚR¸YäÌ°ºÌÎdáãÃAøDz;J² Æî@±q-ÔêÂG>!·!ø%ã®ÉÏü橸ž3K•ЂRócª×¡ŒaÝU›ÍF,VùÌ›‘K—¼cÓp^`’Þ³C£­xR.éàšÔ¿¥££/b-*¹háÇ~¦ùa}3f[‹sÇ<Æ›ÀbÞ:fЫs\C ú8Ç°‹;^1ô^é䟭6w.gLäŽ/<°Í"4À+5¿/ÕF«Rÿ²U*‡!¦NëË\ÏûRØšf(»/ü‚ÂûîqaìL¨yó¾!=ò†žpÈ™Æ%•×¿}½› JÚJ”NS¬ì‰1T,YH­ÍãŽ+hÉIA °®x=ÏŠÐ\¥hÕ"V›s.M£ÛXL<®H.Tî’7Ô4¨3{%Avê|´p»ù pFïr„×Ó‹¢«÷$ ÌéáQ+. yYԁ4Oæ#Ø‚:c>yšŸtÐ!ñ¥XürÃf e\c|C ê"bHߏÓH®G¥ ”…ÀÄùªßö—H[é Û†úÛÔ×$´Å:ZÎŽÛZeImo«£úØÙfm¨‹Fªã|,øC¶Ol™BtêÂÈÈíZ=Î"6k¶(nñY"’žMŒê®×Sá鐴5¢µòÂ\.'ý"›†åù¿ŸÉc=7’2$öZ¨¥åÇëlÏg5èHŸ¢¿—R0dý“n,Äb-¤×ž%ö®±ZLÀFb=¶È™ÕMDÒЙ´k‡@ŸQÑ¿¶¦Á©têµJl–«Æ†3n Çüò ¿Â5æPt5`´]·"gû,,´Æ†ÕPxÜRÕD]÷®Ö|¬5åæÕ\­kûT¶¥õÅ|ÎÝ ñg„¸f½‘Õ¹‘Ñ‘ItºEÄPo t4ð`a‘'{&¹¦åL¸ai”ÔŠ?zf±ÒÀ½suª-ÊÍ—ç9ñ¯[›Ü7TÕIPÁí ’ð­íåù«àkÉž&܏b»}õêRØ tM˜NÛñ4¡¢óò"\0ÝñÚØäëúéëÚüOM So‰Ö_×/‚ƒ_×бóºþ&%@b;Ìû·7?µ®Ï/ú­Ó7o~¾Ä æ:òÈ õÆv)‘]øÏÄÜ ïœ˜ï.ð”S~/ÑðÁ£U9:ô7üIאÙþsºá€‚å~¿Ž~É´u'†…ßI%D%¿ù9ÿqc’=6áîSåÃ:é/Ž?|»¿¥6‰´î#¦À Û`ÄÁ/R©|ü$ìüøRÊVtùäšLž+äYM‰Õ6eåø“r·Û'¼GÛ³+rLæ-ìQ“ÚVÍ2<Ò³ïêÍ´» ÞLº 2«5vzO5‰pe’žÃ\iW‘b‘|´‘Ïþ» :©Æ¨¤7)@yÉ û  β³bü ° cñkŽ±TráP¼ÅD€‡2×·ÚÁ)J¼ÆÒòÒÄÉ4.dè(Úʶ‡…œS-?Ûv—Àô hô×Mcà”Buo+Á]+QÏ_aÂ-Yn›»§b¨Ëí„vÄ0›c½o=lmK`Gñ ñk¤àØÈ JǸ§†(±ðýLñYbv±<‡¿o¡i íµ7–åF¾Aô|*q[ç¤ÀKŒgîqPrÈ‚¥-_ç⸥ž‹s€Êmf±âè/¹Ø·!ԏI-2<çRøjQNÙ8ª §å|P6\UÚÖDh,ÁÖjg=ä/|%–1¢« V‚øÁpË\u-sHAò–ǺS܏ô»D²:Ú:Èȯ:·Ú”‚´½žÔž¯'µUzâÏæmt¥þ|]©ÏïJzk[xNYb¨âFGÄ⇃á!äW>ÌƒÄô2ËÆÈÅ><É‹ºW§ù¼¢£Ã§ :»ö™PŒ8²\2T5qùÞŸE¢ ´HtƒVx¶m®w6â› O—‹®®Óä^§K F$mR9N&ó¾gƒÌk`&§~&Ç´>@ññæ*váDzò_Tf–ˆ„„ºÚòm oIaGÄ¥½‘wEáUíZ&\­ì-ä½p¹Ì9 -Ð.s"3*f³’Ž^p,L*z±î´48¶z7á±>´€¥3Dëk;¸¢d¢ªÒ'¦avv{~–PÈ /9£#Ã"1£í 9éq·çÿ¸-ž^]¾}×"j$¦‚6Î:'ýÞé»à‹÷ïn‹ýË_Î[¤Ú°ÝcÒ}õþ¦Eâê!"²/N¯/¯þÙ"b‚*?/Žm¸$Žm)Š£\NʽÎ×'½Î >)'}Ãÿ± —R@4Ž]ݱÜ>–ïä¤ }/cUáÇSê•@Õ:iX¢¤sòýãÄl!‰{‰8¶ù #Þƒ©xŽÕâÚ˜NT^œšÃ8ºE Ÿ1JO~(¤Ü9a-ê•ï²vÿë—éS2r`ˆ #L÷ÄAÀa€ DîŽÉÝ'º.ƒè2y0²ÎÀ,À@°C2vø«ü> oaG‰¬ûã¼]]v|‡÷ÏÁ'…:R ‹»¸u Ot¡2’EÇu$"|cТæ¹dÌðºj ªÓ.wÏSÕ^kQŒСéFâD6øwöFá1¬K}æãnÂpßÓpZŠ&ñÖ%ƒ‰¼²E¦u¡ßžÓ’0”!å¤,úÖ‹¡25ß’”,ÍÍkÎÞɸmð¯OoÞ^UW€rÄ_–&œ£Ë‹ªé¶ˆê¹,‘#[Og¢¥Ú"f…˜ ™UbYõ˜'.r¨Š·„)KJMÃJqº$X8¨ºA®oñfa)ȾB¶_P„„Û®8ÞºJnØDµ”€^¢



Any ideas ?
Posted 1/22/2006 12:10 AM
#27149
User avatar

JSntgvr Advanced member

Date Joined Nov 2016
Total Posts: 526
No idea. Unsupported language or wrong format. As a member of Ebay, are you entitled to support. This could be a good question for them.
Posted 1/22/2006 7:52 AM
#27161
User avatar

ken123 Member

Date Joined Nov 2016
Total Posts: 8
thanks for all your help anyway-best regards
  • Unread posts or replies
  • No unread posts or replies
  • Unread Posts (Read Only Forum)
  • No Unread Posts (Read Only Forum)

Forum Information

Currently it is Wednesday, August 10, 2022, 4:19 AM (GMT +2)
There are a total of 61,974 posts in 13,697 threads.
In the last 3 days there were 0 new threads and 0 reply posts.

Who's online

This forum has 38,573 registered members. Please welcome our newest member, iAwake.
27 Guest(s), 0 Registered Member(s) are currently online.