BleepingComputer.com: Rootkit.Win32.ZAccess.c ate my computer

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 4 Pages +
  • « First
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • This topic is locked

Rootkit.Win32.ZAccess.c ate my computer

#46 User is offline   heir 

  • Distinguished Member
  • PipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 763
  • Joined: 24-February 08
  • Gender:Male

Posted 30 August 2011 - 11:14 AM

There was a hiccup when I posted my last post and edited it.
Both post wrong. Either way that file shouldn't show up again and again.

Let's let EOS remove what's found.

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.

  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Make sure that the option "Remove found threats" is Checked
  • When the Computer scan settings display shows, click the Advanced option, the place a check next to the following (if it is not already checked):
    • Enable Anti-Stealth technology

  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

Please do not PM me asking for support. Post on the forums instead.
Please post the final results, good or bad. We like to know!
Posted Image
Unified Network of Instructors and Trained Eliminators
My help is always free, but if you want to donate to help me continue my fight against malware then click Posted Image

#47 User is offline   scott_ph 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 33
  • Joined: 03-August 11

Posted 30 August 2011 - 05:38 PM

ESET Log -


C:\Qoobox\Quarantine\C\WINDOWS\assembly\GAC_MSIL\desktop.ini.vir a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\ipsec.sys.vir a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\netbt.sys.vir a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP354\A0144143.exe Win32/Adware.WinPump.O application cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP354\A0144147.sys a variant of Win32/Rootkit.Kryptik.DM trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP354\A0144148.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP354\A0144176.sys a variant of Win32/Rootkit.Kryptik.DM trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP354\A0144177.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0144223.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0144224.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0144225.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0144226.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0144227.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0144228.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0144229.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0144230.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0144231.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0144232.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0144233.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0144234.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0144248.sys a variant of Win32/Rootkit.Kryptik.DM trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0145248.sys a variant of Win32/Rootkit.Kryptik.DM trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP355\A0145249.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP356\A0145543.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP356\A0145558.sys a variant of Win32/Rootkit.Kryptik.DM trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP356\A0146030.sys a variant of Win32/Rootkit.Kryptik.DM trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP356\A0146031.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP357\A0146106.sys a variant of Win32/Rootkit.Kryptik.DM trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP357\A0146107.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP357\A0146161.sys a variant of Win32/Rootkit.Kryptik.DM trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP357\A0146162.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP357\A0146173.sys a variant of Win32/Rootkit.Kryptik.DM trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP357\A0146174.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP357\A0146194.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP357\A0146207.sys a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP357\A0146208.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP357\A0146215.sys a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP357\A0146216.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP357\A0146230.sys a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP357\A0146231.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146242.sys a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146243.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146253.sys a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146254.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146264.sys a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146265.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146276.sys a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146277.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146293.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146326.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146348.sys a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146349.sys a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146350.sys a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146354.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP358\A0146384.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP359\A0146427.sys a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP359\A0146428.ini a variant of Win32/Sirefef.CH trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP360\A0146688.sys a variant of Win32/Sirefef.CO trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP365\A0150249.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP366\A0150257.rbf Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP367\A0150316.rbf Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP367\A0150381.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP367\A0150437.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP367\A0150451.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP367\A0150476.rbf Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP368\A0150593.rbf Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP369\A0150770.rbf Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP369\A0150903.exe Win32/Patched.HN trojan cleaned - quarantined
C:\System Volume Information\_restore{835CB17E-8D4E-495E-BFF4-2A7A64A0EF41}\RP370\A0151195.exe Win32/Patched.HN trojan cleaned - quarantined

#48 User is offline   scott_ph 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 33
  • Joined: 03-August 11

Posted 08 September 2011 - 12:30 PM

Is this the finale for this adventure in computing?

#49 User is offline   heir 

  • Distinguished Member
  • PipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 763
  • Joined: 24-February 08
  • Gender:Male

Posted 11 September 2011 - 06:51 AM

Quote

Is this the finale for this adventure in computing?

Almost.
I'm terribly sorry that I've not been responding lately.

Let's wrap this up now.


Hey there, scott_ph !

OK! Well done, your log is clean again! :thumbsup:

Time for some housekeeping.

Step 1.
Clean up:

We need to do is to remove all the tools that you have used. This is so that should you ever be re-infected, you will download updated versions. It will also remove the quarantined Malware from your computer.


First:
  • Click START then RUN
  • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the /U, it needs to be there.
    Posted Image



Second:
Double-click OTL.exe to start it.
Click the Clean up button
Click Yes to the reboot.

Now delete any tools/logs that is left over after you ran OTL Clean up.

Note! ESET Online Scanner has quarantined some objects. These can be removed by uninstalling ESET Online Scanner from add remove programs.



Step 2.
Prevention:

OK, lets carry out a few preventative steps to make sure you reduce the risk of further infections.

First:
Upgrading Java:

Posted Image Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. NOT supported for use in 9x or ME

Upgrading Java :
  • Download the latest version of Java Platform, Standard Edition.
  • Scroll down an click the Java SE 6 Update 27 "Download JRE" button to the right.
  • Accept the license agreement: "Oracle Binary Code License Agreement for Java SE.".
  • Click on the link to download Windows Offline Installation ( jre-6u27-windows-i586.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u27-windows-i586.exe and select "Run as an Administrator.")



Second:
One of the essentials is to keep your computer updated with the latest operating system patches and security fixes. Windows Updates are constantly being revised to combat the newest hacks and threats, Microsoft releases security updates that help your computer from becoming vunerable. It is best if you have these set to download automatically.

Automatic Updates for Windows
  • Click Start.
  • Select Settings and then Control Panel.
  • Select Automatic Updates.
  • Click Automatic (recommended)
  • Choose a day and a time when you know the computer will be on and connected to the internet.
  • Click Apply then OK.



Third:
Now lets download some preventative programs that will help to keep the nasties away! We will start with Anti Spyware programs. I would advise getting a couple of them at least, and running each at least once a month.

Anti Spyware
  • SpywareBlaster to help prevent spyware from installing in the first place. A tutorial can be found here.
  • SpywareGuard to catch and block spyware before it can execute. A tutorial can be found here.
.
Note: If you find your system slows down after installing any of these, just uninstall it, or disable it from running at startup.


Fourth:
Next lets look at Firewalls. These help to prevent unauthorised access both to and from the internet or your local network. A firewall is considered a first line of defense in protecting private information. Below are two free firewalls to choose from, if you do not already have one. Note: You only need one firewall one your system.

Personal Firewalls

Fifth:
On to personal Anti Virus programs.

One AV is a must have! But never more than one, as this can and will cause conflicts and false readings. I have listed three free AV's below which are as good as any paid subscription AV, as long as you allow them to update themselves.

Anti Virus Programs

Sixth:
Nearly done! If you like to use chat, MSN and Yahoo have vunerabilities that can leave you open to infections. There are however a couple of very good, Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN):

Instant Messengers

Lastly:
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.


I will keep this log open for the next couple of days, so if you have any further problems post another reply here.

OK, all the best, and stay safe!
Please do not PM me asking for support. Post on the forums instead.
Please post the final results, good or bad. We like to know!
Posted Image
Unified Network of Instructors and Trained Eliminators
My help is always free, but if you want to donate to help me continue my fight against malware then click Posted Image

#50 User is offline   scott_ph 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 33
  • Joined: 03-August 11

Posted 14 September 2011 - 01:43 PM

There was a program I ran at the beginning of this process to disable the CD emulators...how do I reverse that?...is there something else in the "Preparation Guide" that I've done and need to undo?

#51 User is offline   heir 

  • Distinguished Member
  • PipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 763
  • Joined: 24-February 08
  • Gender:Male

Posted 17 September 2011 - 03:10 PM

View Postscott_ph, on 14 September 2011 - 01:43 PM, said:

There was a program I ran at the beginning of this process to disable the CD emulators...how do I reverse that?...is there something else in the "Preparation Guide" that I've done and need to undo?


There was a link in the preparation guide on how to enable CD emulation again.

There shouldn't be anything else that needs to be reversed.

/heir
Please do not PM me asking for support. Post on the forums instead.
Please post the final results, good or bad. We like to know!
Posted Image
Unified Network of Instructors and Trained Eliminators
My help is always free, but if you want to donate to help me continue my fight against malware then click Posted Image

#52 User is offline   scott_ph 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 33
  • Joined: 03-August 11

Posted 21 September 2011 - 01:24 AM

Thank you very much for all the time and effort you put in to getting this squared away. I thought I was looking at an OS reinstall at the very least. Everything seems to be doing what it's supposed to be doing and I have no further issues to address.
Thank you again for you patience and professionalism.
Scott

#53 User is offline   heir 

  • Distinguished Member
  • PipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 763
  • Joined: 24-February 08
  • Gender:Male

Posted 25 September 2011 - 05:15 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Please do not PM me asking for support. Post on the forums instead.
Please post the final results, good or bad. We like to know!
Posted Image
Unified Network of Instructors and Trained Eliminators
My help is always free, but if you want to donate to help me continue my fight against malware then click Posted Image

Share this topic:


  • 4 Pages +
  • « First
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users