Tech Support banner

Status
Not open for further replies.
1 - 9 of 9 Posts

·
Registered
Joined
·
15 Posts
Discussion Starter #1
I have always be able to view a certain website. Now it comes up as page cannot be displayed. I ran hijack this and would like some expert help, since I cannot fix it. I have tried all kind of scans and fixes.

Here is my results of hijack this:

Logfile of HijackThis v1.97.7
Scan saved at 11:05:59 AM, on 9/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
C:\WINDOWS\system32\wwSecure.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe
C:\Program Files\KlipFolio\KlipFolio.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Registry Fix 3.0.2\Registry Fix.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\PAMRUS~1\LOCALS~1\Temp\Temporary Directory 1 for HijackThis%20v1.97[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O1 - Hosts: 66.103.149.154 www.cashtwist.com
O1 - Hosts: 216.69.130.32 www.internetcashmatrix.com
O1 - Hosts: 67.18.102.135 www.1lineclub.com
O1 - Hosts: 66.235.209.184 www.articparadise.com
O1 - Hosts: 216.93.185.164 www.cycleout.com
O1 - Hosts: 206.130.97.112 doublemania.com
O1 - Hosts: 64.239.43.222 doublertracker.com
O1 - Hosts: 63.209.100.155 fastque.doubledprofits.com
O1 - Hosts: 67.18.102.135 www.hyipsociety.org
O1 - Hosts: 69.28.211.179 e-cashportal.com
O1 - Hosts: 67.18.102.135 moneymakersociety.com
O1 - Hosts: 209.59.136.133 mycashdoubler.com
O1 - Hosts: 209.157.71.50 www.programalert.com
O1 - Hosts: 67.19.249.250 www.santadouble.com
O1 - Hosts: 69.41.166.22 www.subdubb.com
O1 - Hosts: 206.65.184.236 www.thegamblingswami.web.com
O1 - Hosts: 209.50.253.122 www.addesigner.com
O1 - Hosts: 209.237.237.100 www.alexa.com
O1 - Hosts: 64.87.100.117 www.allfreelancework.com
O1 - Hosts: 67.133.37.68 www.annualcreditreport.com
O1 - Hosts: 217.115.142.65 www.ascii-art.de
O1 - Hosts: 216.218.218.36 www.asciiartfarts.com
O1 - Hosts: 66.114.67.118 artcode.org
O1 - Hosts: 128.227.163.16 www.afn.org
O1 - Hosts: 67.130.100.130 www.automaticmoneymachine.com
O1 - Hosts: 209.47.167.142 www.jonstyer.com
O1 - Hosts: 213.239.201.184 www.autosurf.org
O1 - Hosts: 204.246.1.55 personalpages.tds.net
O1 - Hosts: 64.176.54.159 www.picompany.com
O1 - Hosts: 64.202.167.129 www.lovevine.us
O1 - Hosts: 216.54.186.34 www.crimetime.com
O1 - Hosts: 64.14.126.119 www.brainbench.com
O1 - Hosts: 69.57.146.6 www.cartercountymarket.com
O1 - Hosts: 64.90.182.202 home.universalclass.com
O1 - Hosts: 66.239.220.248 www.contractedwork.com
O1 - Hosts: 66.98.130.67 www.courts.net
O1 - Hosts: 66.179.26.243 www.prosavvy.com
O1 - Hosts: 64.143.1.18 www.daybreakventure.com
O1 - Hosts: 212.40.5.42 www.wagenschenke.ch
O1 - Hosts: 196.7.147.30 mol.co.za
O1 - Hosts: 216.144.69.200 www.ediets.com
O1 - Hosts: 216.144.69.201 www.efitness.com
O1 - Hosts: 66.35.204.10 www.findlaw.com
O1 - Hosts: 212.189.37.153 www.bornsquishy.com
O1 - Hosts: 64.70.221.70 www.cartooncottage.com
O1 - Hosts: 67.15.24.45 aaascreensavers.com
O1 - Hosts: 66.132.216.76 www.smart-estore.com
O1 - Hosts: 205.244.47.245 www.freeautobot.com
O1 - Hosts: 69.93.164.74 www.freelanceworkexchange.com
O1 - Hosts: 66.181.9.246 www.freeviral.com
O1 - Hosts: 209.51.153.50 www.gptboycott.com
O1 - Hosts: 199.174.114.36 www.mindspring.com
O1 - Hosts: 198.31.50.70 www.mastermcom.net
O1 - Hosts: 194.117.143.77 abemaca.pwp.blueyonder.co.uk
O1 - Hosts: 209.35.35.231 www.homebiztools.com
O1 - Hosts: 209.87.112.25 www.mypoints.com
O1 - Hosts: 216.58.226.189 www.nsca-cc.org
O1 - Hosts: 170.97.67.13 www.hud.gov
O1 - Hosts: 212.189.37.153 www.kersbergen.com
O1 - Hosts: 209.50.230.94 www.limneos.net
O1 - Hosts: 204.65.1.126 wit.twc.state.tx.us
O1 - Hosts: 38.119.100.33 www.freewebs.com
O1 - Hosts: 63.246.130.50 www.onlinemoneymaking.net
O1 - Hosts: 207.171.170.23 www.imdb.com
O1 - Hosts: 67.18.102.135 www.moneymakersociety.com
O1 - Hosts: 216.52.167.194 www.movietickets.com
O1 - Hosts: 206.104.153.100 fun1.mysurvey.com
O1 - Hosts: 216.64.18.226 www.naco.org
O1 - Hosts: 63.110.130.187 www.netronline.com
O1 - Hosts: 207.200.81.154 dmoz.org
O1 - Hosts: 64.136.25.171 www.finegifts.iwarp.com
O1 - Hosts: 68.142.133.168 www.mvelopes.com
O1 - Hosts: 66.224.214.31 www.radiantresearch.com
O1 - Hosts: 65.220.68.226 www.rockvalesquareoutlets.com
O1 - Hosts: 64.239.2.81 www.ipostad.com
O1 - Hosts: 64.95.77.68 www.net-temps.com
O1 - Hosts: 38.113.1.97 www.search-plus.net
O1 - Hosts: 217.26.52.19 www.severin.ch
O1 - Hosts: 65.246.163.53 www.smackerooz.com
O1 - Hosts: 209.151.65.147 www.surefire-detective.com
O1 - Hosts: 66.45.51.198 www.surveysavvy.com
O1 - Hosts: 168.51.178.4 www.tdcj.state.tx.us
O1 - Hosts: 207.44.210.115 tds101.com
O1 - Hosts: 66.98.236.110 www.roboform.com
O1 - Hosts: 160.42.128.69 dbs.dshs.state.tx.us
O1 - Hosts: 207.106.91.63 thefreesite.com
O1 - Hosts: 80.247.215.21 totalfreedom4u.goedbegin.com
O1 - Hosts: 209.18.68.100 www.ts25.com
O1 - Hosts: 66.197.151.245 www.typeinternational.com
O1 - Hosts: 204.65.3.99 m06hostp.twc.state.tx.us
O1 - Hosts: 216.25.120.109 www.pharmacysources.com
O1 - Hosts: 209.61.155.107 www.weht.net
O1 - Hosts: 69.20.85.253 www.towerwebsites.com
O1 - Hosts: 64.38.250.155 www.sexyads.net
O1 - Hosts: 206.138.130.5 inmateloc.bop.gov
O1 - Hosts: 204.64.245.145 www.twc.state.tx.us
O1 - Hosts: 69.93.196.162 www.winxpfix.com
O1 - Hosts: 65.216.115.171 www.business.com
O1 - Hosts: 65.75.166.160 www.runabot.com
O1 - Hosts: 207.44.194.111 aimsource.com
O1 - Hosts: 66.98.142.9 www.aimuser.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\spyware tools\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe"
O4 - HKLM\..\Run: [KlipFolio] "C:\Program Files\KlipFolio\KlipFolio.exe" /BOOT
O4 - HKLM\..\Run: [Registry Fix] C:\Program Files\Registry Fix 3.0.2\Registry Fix.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Save Forms &[ - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: A-ha (HKLM)
O9 - Extra button: Yahoo! Services (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O9 - Extra button: NeoTrace It! (HKCU)
O15 - Trusted Zone: http://www.myleague.com
O15 - Trusted Zone: http://www.pogo.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -

Thanks for your help

Nightowl1963200
 

·
Registered
Joined
·
100 Posts
OOPS!! Disregard that previous reply...

Please print or cut and paste these instructions and follow them. Be certain to not skip any instructions.

Download the following programs but do not install them yet.

CWShredder
Ad-Aware

Now, run CWShredder to make sure that your computer is not host to the CoolWebSearch trojan(s) before proceeding with anything else. If so, have CWShredder remove it/them.

Install and run Ad-Aware to determine if your computer is host to spyware. If so, have it quarantine and delete them.

Weather Bug is not dangerous but not necessary. You can uninstall it if you want, but this could be why your computer is running sluggish.

Several entries in your host file is preventing access to the internet. Ad-Aware should fix this. Add another Hijackthis log to this thread.

Curtis Bryant
AKA J. Spygone Agent 007
 

·
Registered
Joined
·
15 Posts
Discussion Starter #4
Hijack this

Ok here is what I have after doing everything you told me. I am still unable to get to the site I was trying to get.

Results:

Logfile of HijackThis v1.97.7
Scan saved at 1:13:47 PM, on 9/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
C:\WINDOWS\system32\wwSecure.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\KlipFolio\KlipFolio.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Pam Russell\Local Settings\Temp\Temporary Directory 1 for HijackThis%20v1.97[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O1 - Hosts: 66.103.149.154 www.cashtwist.com
O1 - Hosts: 216.69.130.32 www.internetcashmatrix.com
O1 - Hosts: 67.18.102.135 www.1lineclub.com
O1 - Hosts: 66.235.209.184 www.articparadise.com
O1 - Hosts: 216.93.185.164 www.cycleout.com
O1 - Hosts: 206.130.97.112 doublemania.com
O1 - Hosts: 64.239.43.222 doublertracker.com
O1 - Hosts: 63.209.100.155 fastque.doubledprofits.com
O1 - Hosts: 67.18.102.135 www.hyipsociety.org
O1 - Hosts: 69.28.211.179 e-cashportal.com
O1 - Hosts: 67.18.102.135 moneymakersociety.com
O1 - Hosts: 209.59.136.133 mycashdoubler.com
O1 - Hosts: 209.157.71.50 www.programalert.com
O1 - Hosts: 67.19.249.250 www.santadouble.com
O1 - Hosts: 69.41.166.22 www.subdubb.com
O1 - Hosts: 206.65.184.236 www.thegamblingswami.web.com
O1 - Hosts: 209.50.253.122 www.addesigner.com
O1 - Hosts: 209.237.237.100 www.alexa.com
O1 - Hosts: 64.87.100.117 www.allfreelancework.com
O1 - Hosts: 67.133.37.68 www.annualcreditreport.com
O1 - Hosts: 217.115.142.65 www.ascii-art.de
O1 - Hosts: 216.218.218.36 www.asciiartfarts.com
O1 - Hosts: 66.114.67.118 artcode.org
O1 - Hosts: 128.227.163.16 www.afn.org
O1 - Hosts: 67.130.100.130 www.automaticmoneymachine.com
O1 - Hosts: 209.47.167.142 www.jonstyer.com
O1 - Hosts: 213.239.201.184 www.autosurf.org
O1 - Hosts: 204.246.1.55 personalpages.tds.net
O1 - Hosts: 64.176.54.159 www.picompany.com
O1 - Hosts: 64.202.167.129 www.lovevine.us
O1 - Hosts: 216.54.186.34 www.crimetime.com
O1 - Hosts: 64.14.126.119 www.brainbench.com
O1 - Hosts: 69.57.146.6 www.cartercountymarket.com
O1 - Hosts: 64.90.182.202 home.universalclass.com
O1 - Hosts: 66.239.220.248 www.contractedwork.com
O1 - Hosts: 66.98.130.67 www.courts.net
O1 - Hosts: 66.179.26.243 www.prosavvy.com
O1 - Hosts: 64.143.1.18 www.daybreakventure.com
O1 - Hosts: 212.40.5.42 www.wagenschenke.ch
O1 - Hosts: 196.7.147.30 mol.co.za
O1 - Hosts: 216.144.69.200 www.ediets.com
O1 - Hosts: 216.144.69.201 www.efitness.com
O1 - Hosts: 66.35.204.10 www.findlaw.com
O1 - Hosts: 212.189.37.153 www.bornsquishy.com
O1 - Hosts: 64.70.221.70 www.cartooncottage.com
O1 - Hosts: 67.15.24.45 aaascreensavers.com
O1 - Hosts: 66.132.216.76 www.smart-estore.com
O1 - Hosts: 205.244.47.245 www.freeautobot.com
O1 - Hosts: 69.93.164.74 www.freelanceworkexchange.com
O1 - Hosts: 66.181.9.246 www.freeviral.com
O1 - Hosts: 209.51.153.50 www.gptboycott.com
O1 - Hosts: 199.174.114.36 www.mindspring.com
O1 - Hosts: 198.31.50.70 www.mastermcom.net
O1 - Hosts: 194.117.143.77 abemaca.pwp.blueyonder.co.uk
O1 - Hosts: 209.35.35.231 www.homebiztools.com
O1 - Hosts: 209.87.112.25 www.mypoints.com
O1 - Hosts: 216.58.226.189 www.nsca-cc.org
O1 - Hosts: 170.97.67.13 www.hud.gov
O1 - Hosts: 212.189.37.153 www.kersbergen.com
O1 - Hosts: 209.50.230.94 www.limneos.net
O1 - Hosts: 204.65.1.126 wit.twc.state.tx.us
O1 - Hosts: 38.119.100.33 www.freewebs.com
O1 - Hosts: 63.246.130.50 www.onlinemoneymaking.net
O1 - Hosts: 207.171.170.23 www.imdb.com
O1 - Hosts: 67.18.102.135 www.moneymakersociety.com
O1 - Hosts: 216.52.167.194 www.movietickets.com
O1 - Hosts: 206.104.153.100 fun1.mysurvey.com
O1 - Hosts: 216.64.18.226 www.naco.org
O1 - Hosts: 63.110.130.187 www.netronline.com
O1 - Hosts: 207.200.81.154 dmoz.org
O1 - Hosts: 64.136.25.171 www.finegifts.iwarp.com
O1 - Hosts: 68.142.133.168 www.mvelopes.com
O1 - Hosts: 66.224.214.31 www.radiantresearch.com
O1 - Hosts: 65.220.68.226 www.rockvalesquareoutlets.com
O1 - Hosts: 64.239.2.81 www.ipostad.com
O1 - Hosts: 64.95.77.68 www.net-temps.com
O1 - Hosts: 38.113.1.97 www.search-plus.net
O1 - Hosts: 217.26.52.19 www.severin.ch
O1 - Hosts: 65.246.163.53 www.smackerooz.com
O1 - Hosts: 209.151.65.147 www.surefire-detective.com
O1 - Hosts: 66.45.51.198 www.surveysavvy.com
O1 - Hosts: 168.51.178.4 www.tdcj.state.tx.us
O1 - Hosts: 207.44.210.115 tds101.com
O1 - Hosts: 66.98.236.110 www.roboform.com
O1 - Hosts: 160.42.128.69 dbs.dshs.state.tx.us
O1 - Hosts: 207.106.91.63 thefreesite.com
O1 - Hosts: 80.247.215.21 totalfreedom4u.goedbegin.com
O1 - Hosts: 209.18.68.100 www.ts25.com
O1 - Hosts: 66.197.151.245 www.typeinternational.com
O1 - Hosts: 204.65.3.99 m06hostp.twc.state.tx.us
O1 - Hosts: 216.25.120.109 www.pharmacysources.com
O1 - Hosts: 209.61.155.107 www.weht.net
O1 - Hosts: 69.20.85.253 www.towerwebsites.com
O1 - Hosts: 64.38.250.155 www.sexyads.net
O1 - Hosts: 206.138.130.5 inmateloc.bop.gov
O1 - Hosts: 204.64.245.145 www.twc.state.tx.us
O1 - Hosts: 69.93.196.162 www.winxpfix.com
O1 - Hosts: 65.216.115.171 www.business.com
O1 - Hosts: 65.75.166.160 www.runabot.com
O1 - Hosts: 207.44.194.111 aimsource.com
O1 - Hosts: 66.98.142.9 www.aimuser.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\spyware tools\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [KlipFolio] "C:\Program Files\KlipFolio\KlipFolio.exe" /BOOT
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Save Forms &[ - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: A-ha (HKLM)
O9 - Extra button: Yahoo! Services (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O9 - Extra button: NeoTrace It! (HKCU)
O15 - Trusted Zone: http://www.myleague.com
O15 - Trusted Zone: http://www.pogo.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -

Thanks for any help....

Nightowl19632000
 

·
TSF Security Team, Emeritus
Joined
·
26,363 Posts
Please download Host.zip
Extract the file & overwrite the existing copy located at C:\WINDOWS\SYSTEM32\DRIVERS\ETC\host

Then, Perform an online scan with Internet Explorer with Kaspersky WebScanner

Next Click on Launch Kaspersky Anti-Virus Web Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
    • In the scan settings make that the following are selected:
      • Scan using the following Anti-Virus database:
        • Standard
      • Scan Options:
        • Scan Archives
        • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
Copy and paste that information in your next post along with a new HJT log.

* Turn off the real time scanner of any existing antivirus program while performing the online scan

Tell me which site that is giving you the problems.
 

·
Registered
Joined
·
15 Posts
Discussion Starter #8 (Edited by Moderator)
Hijack this new log.....page cannot be displayed

Here is the findings from the kaspersky on-line scan:

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Saturday, October 01, 2005 20:24:58
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 2/10/2005
Kaspersky Anti-Virus database records: 142815
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 60686
Number of viruses found: 1
Number of infected objects: 1
Number of suspicious objects: 0
Duration of the scan process: 3518 sec

Infected Object Name - Virus Name
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0001280.exe Infected: Trojan-PSW.Win32.LdPinch.uw

Scan process completed.

How do I get rid of this trojan?

The page that I couldn't display is working fine now....it was www.myleague.com/mids.

Now my screensaver says:

Could not find any compatible Direct 3D Devices???

This is now a copy of my hijack log:

Logfile of HijackThis v1.99.1
Scan saved at 8:31:35 PM, on 10/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe
C:\Program Files\KlipFolio\KlipFolio.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G PCI Adapter\WMP54Gv4.exe
C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe
C:\WINDOWS\system32\wwSecure.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Pam Russell\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O1 - Hosts: PKÕ943ÀM-€í(%HOSTS¬\[sܸ±~OUþ+zÛÒÒH^;ûrjt±¤�eëx´Ñ‰Uª-�Äpà ç¢_Ÿn$‡$HÎÙ¥jwÃþÐ
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\spyware tools\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [KlipFolio] "C:\Program Files\KlipFolio\KlipFolio.exe" /BOOT
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe"
O4 - HKLM\..\Run: [LanzarTitanium2006] "C:\DOCUME~1\PAMRUS~1\LOCALS~1\Temp\{7D536B27-C424-48AD-8CE4-08FA74A22134}\ {98032D6F-3EE6-4646-B68C-40BF012AC89B}\..\..\ T2006tmp\Install.exe" /SETUP:"/l0x0009"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\RunServicesOnce: [c:\Program Files\Webroot\Washer\WashIdx.exe] c:\Program Files\Webroot\Washer\WashIdx.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Save Forms &[ - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: A-ha - {484CF120-1742-4393-B73C-D29BB0534994} - C:\Program Files\W5 Technologies\A-ha for WebEmail\a-ha-script.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NeoTracePro\NTXtoolbar.htm (HKCU)
O15 - Trusted Zone: http://www.myleague.com
O15 - Trusted Zone: http://www.pogo.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Adapter\WLService.exe" "WMP54Gv4.exe (file missing)
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

Thanks for all your help!! I guess now I need to get rid of the trojan and get my Direct 3D device back.

nightowl19632000
 

·
Premium Member
Joined
·
14,311 Posts
Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore. Click Apply and then OK. Restart your computer and uncheck the same box to enable System Restore.

Check and fix these in HijackThis:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O1 - Hosts: PKÕ943ÀM-€í(%HOSTS¬\[sܸ±~OUþ+zÛÒÒH^;ûrjt±¤?eëx´Ñ‰Uª-?Äpà ç¢_Ÿn$‡$HÎÙ¥jwÃþÐ


For the Direct 3D problem, did you have these screensavers running before without any problems? Try reinstalling the drivers for your video card or perhaps reinstalling DirectX.

Your log is clean.

To help prevent future spyware installations/infections, please read the Anti-Spyware Tutorial and use the tools provided.

Are there any problems now? If not, you should be set to go.
 
1 - 9 of 9 Posts
Status
Not open for further replies.
Top