My son claims to have no idea how this happened which is obviously not true. He is more apt with computers then I am & said he could remove the infection. Against my better judgement, I let him try. After reading through the rules for submission, I'm sure he messed up. I saw at the beginning that "combofix" should NOT be used but I see it on the desktop so I imagine it was. He will not be using the PC again until such time as the infection is cleaned and/or I decide to let him back on.
Something in the infection keeps disabling the Windows Firewall as well. After running full Malwarebytes scans, Spybot S&D & AdAware scans ... I can get the computer back to a fairly operable state (and turn the firewall back on)but something inevitably starts the cycle again. I see alot of information in the requested scans coming back to Firefox. I've also noticed that it seems plugin-container.exe opening is a pre-cursor to the infection starting all over again. I know that program is akin to a bundled addon center running. I will do nothing with it at all but hoping that running only internet explorer might help during the time waiting.
I will do nothing on my end, as requested & apologize ahead of time if my son's actions have caused additional complications in this removal process. Thank you for your time in this.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Run by Jason at 13:26:11 on 2011-12-14
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2459 [GMT -5:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\DeviceVM\Browser Configuration Utility\BCUService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Documents and Settings\Jason\Local Settings\Application Data\CrossLoop\CrossLoopService.exe
C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k xmlpros
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\DeviceVM\Browser Configuration Utility\BCU.exe
C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE
C:\Program Files\BrowserCompanion\BCHelper.exe
C:\Documents and Settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.plusnetwork.com/?sp=hp
uSearchAssistant = hxxp://www.plusnetwork.com/?sp=ctbar&q={searchTerms}&dp=MessengerPlus
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Ad-Aware Security Toolbar: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - c:\program files\adawaretb\adawareDx.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Browser Companion Helper Verifier: {963b125b-8b21-49a2-a3a8-e37092276531} - c:\program files\browsercompanion\updatebhoWin32.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
{ae07101b-46d4-4a98-af68-0333ea26e113}
TB: Ad-Aware Security Toolbar: {6c97a91e-4524-4019-86af-2aa2d567bf5c} - c:\program files\adawaretb\adawareDx.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [BCU] "c:\program files\devicevm\browser configuration utility\BCU.exe"
mRun: [Conime] %windir%\system32\conime.exe
mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe"
mRun: [LVCOMS] c:\program files\common files\logitech\qcdriver2\LVCOMS.EXE
mRun: [VMonitorVMUVC] "c:\program files\vimicro corporation\vmuvc\VMonitor.exe" VMUVC
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Browser companion helper] c:\program files\browsercompanion\BCHelper.exe /T=3 /S=7
mRun: [Ad-Aware Browsing Protection] "c:\documents and settings\all users\application data\ad-aware browsing protection\adawarebp.exe"
dRunOnce: [adaware] reg.exe delete "HKCU\Software\AppDataLow\Software\adaware" /f
dRunOnce: [adaware_XP] reg.exe delete "HKCU\Software\adaware" /f
StartupFolder: c:\documents and settings\jason\start menu\programs\startup\CurseClientStartup.ccip
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: com\www.msi
Trusted Zone: com.tw\asia.msi
Trusted Zone: com.tw\global.msi
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} - hxxp://liveupdate.msi.com.tw/autobios/LOnline/install.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{2A0B10C3-D863-430B-9A83-214A47C8E318} : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{A146BBEB-263C-4DFE-87E1-844986D62519} : DhcpNameServer = 192.168.2.1
Handler: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - c:\program files\browsercompanion\tdataprotocol.dll
Handler: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - c:\program files\browsercompanion\tdataprotocol.dll
Handler: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - c:\program files\browsercompanion\tdataprotocol.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: WBSrv - c:\progra~1\stardock\object~1\window~1\wbsrv.dll
Notify: xmlproservice - xmlrpw32.dll
Notify: xmlrpw32 - xmlrpw32.dll
AppInit_DLLs: c:\windows\system32\wbsys.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: Deskscapes Class: {ec654325-1273-c2a9-2b7c-45d29bce68fb} - c:\program files\stardock\object desktop\deskscapes3\deskscapes.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\jason\application data\mozilla\firefox\profiles\neyto10q.default\
FF - prefs.js: browser.search.selectedEngine - Plus! Network
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.plusnetwork.com/?sp=addr&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\jason\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\documents and settings\jason\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-12-12 64512]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2011-7-5 28552]
R2 BCUService;Browser Configuration Utility Service;c:\program files\devicevm\browser configuration utility\BCUService.exe [2009-10-15 223464]
R2 CrossLoopService;CrossLoop Service;c:\documents and settings\jason\local settings\application data\crossloop\CrossLoopService.exe [2011-4-7 560848]
R2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\common files\magix services\database\bin\FABS.exe [2009-8-27 1253376]
R2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\kodak\aio\center\ekdiscovery.exe [2010-5-17 308592]
R2 XMLProvS;Network ProService;c:\windows\system32\svchost.exe -k xmlpros [2006-2-28 14336]
S0 ykyhr;ykyhr;c:\windows\system32\drivers\rkhvnit.sys --> c:\windows\system32\drivers\rkhvnit.sys [?]
S2 AODService;AODService;c:\program files\amd\overdrive\AODAssist.exe [2010-4-23 136616]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-12-2 2152152]
S2 USmsServ;Desktop Window Manager Sessions Manager;c:\windows\desktop manager\dwm.exe --> c:\windows\desktop manager\dwm.exe [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-11-13 1691480]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\atihdxp3.sys --> c:\windows\system32\drivers\AtihdXP3.sys [?]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\common files\magix services\database\bin\fbserver.exe [2008-8-7 3276800]
S3 FLASHSYS;FLASHSYS;c:\program files\msi\live update 4\lu4\FlashSys.sys [2010-11-14 9216]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-12-2 15232]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-8-13 22216]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-12-12 41272]
S3 MSI_DVD_010507;MSI_DVD_010507;c:\progra~1\msi\msiwdev\DVDSYS32_100507.sys [2010-5-10 22328]
S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\progra~1\msi\msiwdev\msibios32_100507.sys [2010-5-10 25912]
S3 MSI_VGASYS_010507;MSI_VGASYS_010507;c:\progra~1\msi\msiwdev\VGASYS32_100507.sys [2010-5-10 16696]
S3 MSILiveVirtualCamera;MSI Live Virtual Camera;c:\windows\system32\drivers\MSILiveVirtualCamera.sys [2007-1-29 449408]
S3 PID_0920;Logitech QuickCam Express(PID_0920);c:\windows\system32\drivers\LV532AV.SYS [2011-7-12 152576]
S3 tvnserver;TightVNC Server;c:\documents and settings\jason\local settings\application data\crossloop\tvnserver.exe [2011-4-7 814080]
S3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\drivers\VMUVC.sys [2011-8-2 252416]
S3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys [2011-8-2 398720]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-8-13 366152]
.
=============== Created Last 30 ================
.
2011-12-14 17:50:53 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-12-14 17:02:04 37888 ----a-w- c:\windows\system32\xmlrpw32.dll
2011-12-14 17:02:04 156672 ----a-w- c:\windows\system32\xmlprw32.dll
2011-12-13 18:45:34 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-12-12 20:21:26 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-12-12 19:04:29 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-12-12 19:02:41 -------- d-----w- c:\documents and settings\jason\local settings\application data\adaware
2011-12-12 19:02:39 -------- d-----w- c:\documents and settings\all users\application data\Ad-Aware Browsing Protection
2011-12-12 19:02:36 -------- d-----w- c:\program files\Toolbar Cleaner
2011-12-12 19:02:31 -------- d-----w- c:\documents and settings\jason\application data\adawaretb
2011-12-12 19:02:30 -------- d-----w- c:\program files\adawaretb
2011-12-12 19:02:23 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-12-12 19:02:18 -------- d-----w- c:\program files\Lavasoft
2011-12-12 18:22:37 -------- d-sh--w- c:\documents and settings\jason\IECompatCache
2011-12-12 17:22:15 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-12-12 16:30:01 64512 ----a-w- c:\windows\system32\drivers\serial.sys
2011-12-12 12:57:28 162816 ----a-w- c:\windows\system32\drivers\netbt.sys
2011-12-11 05:48:09 52480 ----a-w- c:\windows\system32\drivers\i8042prt.sys
2011-12-11 05:46:55 -------- d-sha-r- C:\cmdcons
2011-12-11 05:45:08 98816 ----a-w- c:\windows\sed.exe
2011-12-11 05:45:08 518144 ----a-w- c:\windows\SWREG.exe
2011-12-11 05:45:08 256000 ----a-w- c:\windows\PEV.exe
2011-12-11 05:45:08 208896 ----a-w- c:\windows\MBR.exe
2011-12-11 03:46:22 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-12-11 03:46:22 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-12-09 23:47:25 -------- d-----w- c:\documents and settings\jason\local settings\application data\Messenger_Plus_Live
2011-12-09 23:37:24 -------- d-----w- c:\documents and settings\jason\AppData
2011-12-09 23:37:23 -------- d-----w- c:\program files\BrowserCompanion
2011-12-09 23:37:05 -------- d-----w- c:\documents and settings\jason\local settings\application data\Linkury
2011-12-02 06:12:13 -------- d-----w- c:\documents and settings\jason\local settings\application data\Skyrim
2011-12-02 05:53:59 -------- d-----w- c:\program files\The Elder Scrolls V Skyrim
2011-11-28 20:29:38 -------- d-----w- c:\documents and settings\jason\application data\Ulzak
2011-11-28 20:29:38 -------- d-----w- c:\documents and settings\jason\application data\Asew
2011-11-25 15:39:26 -------- d-----w- c:\program files\AMD APP
2011-11-25 15:30:18 -------- d-----w- c:\documents and settings\jason\application data\Unity
2011-11-25 15:27:53 -------- d-----w- c:\documents and settings\jason\local settings\application data\Unity
.
==================== Find3M ====================
.
2011-12-14 02:09:20 140496 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-12-14 02:09:15 280736 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-12-14 02:09:15 280736 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-12-10 03:46:31 280736 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-11-20 22:22:05 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-26 03:01:40 7412736 ----a-w- c:\windows\system32\drivers\ati2mtag.sys
2011-10-26 02:59:02 311296 ----a-w- c:\windows\system32\atiiiexx.dll
2011-10-26 02:30:50 57344 ----a-w- c:\windows\system32\aticalrt.dll
2011-10-26 02:30:40 53248 ----a-w- c:\windows\system32\aticalcl.dll
2011-10-26 02:27:26 5890048 ----a-w- c:\windows\system32\aticaldd.dll
2011-10-26 02:21:48 56832 ----a-w- c:\windows\system32\OpenVideo.dll
2011-10-26 02:21:34 56832 ----a-w- c:\windows\system32\OVDecoder.dll
2011-10-26 02:20:42 13950464 ----a-w- c:\windows\system32\amdocl.dll
2011-10-26 02:16:30 18968576 ----a-w- c:\windows\system32\atioglxx.dll
2011-10-26 02:06:02 466944 ----a-w- c:\windows\system32\ATIDEMGX.dll
2011-10-26 02:04:50 304128 ----a-w- c:\windows\system32\ati2dvag.dll
2011-10-26 02:04:46 4004864 ----a-w- c:\windows\system32\ati3duag.dll
2011-10-26 01:58:22 956160 ----a-w- c:\windows\system32\ativvamv.dll
2011-10-26 01:44:50 3286400 ----a-w- c:\windows\system32\ativvaxx.dll
2011-10-26 01:44:08 212992 ----a-w- c:\windows\system32\atipdlxx.dll
2011-10-26 01:43:54 155648 ----a-w- c:\windows\system32\Oemdspif.dll
2011-10-26 01:43:46 26112 ----a-w- c:\windows\system32\Ati2mdxx.exe
2011-10-26 01:43:38 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2011-10-26 01:43:26 188416 ----a-w- c:\windows\system32\ati2evxx.dll
2011-10-26 01:42:08 643072 ----a-w- c:\windows\system32\ati2evxx.exe
2011-10-26 01:40:46 53248 ----a-w- c:\windows\system32\ATIDDC.DLL
2011-10-26 01:39:12 159744 ----a-w- c:\windows\system32\atiapfxx.exe
2011-10-26 01:35:00 806912 ----a-w- c:\windows\system32\atikvmag.dll
2011-10-26 01:34:14 499712 ----a-w- c:\windows\system32\atiok3x2.dll
2011-10-26 01:30:52 229376 ----a-w- c:\windows\system32\atiadlxx.dll
2011-10-26 01:30:28 17408 ----a-w- c:\windows\system32\atitvo32.dll
2011-10-26 01:25:38 65024 ----a-w- c:\windows\system32\atimpc32.dll
2011-10-26 01:25:38 65024 ----a-w- c:\windows\system32\amdpcom32.dll
2011-10-26 01:24:58 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2011-10-26 01:24:52 884736 ----a-w- c:\windows\system32\ati2cqag.dll
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
.
============= FINISH: 13:26:29.17 ===============
Attached File(s)
-
ark.txt (3.7K)
Number of downloads: 0 -
attach.txt (18.76K)
Number of downloads: 2

Help
This topic is locked


Back to top












