Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Htepo.com Infection


  • This topic is locked This topic is locked
3 replies to this topic

#1 ChaZZZ55N

ChaZZZ55N

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:02:17 PM

Posted 11 November 2007 - 07:00 PM

Hello,

I have the htepo.com problem like many others (hijacked IE to bogus web pages, pop up lerts and balloons, etc ..). I had spyBot 1.4 and the latest Symantec Anti-virus running, but they did not stop it. I have ftried to follow the Preperation Guide, but have had little success. The Ad-Aware utility did not detect the problem. SbyBot detects "VirtuMonde and VirtuMonde.generic" in the regitry, but was unable to remove it (tried 4 times - even in safe mode). I ran the XoftSpySE and it found the registry entries for "Azersearch" and "Vundo". I ran the latest copy of stinger.exe.

None of these tools has removed the problem. I ran Norton WInDoctor and now the "Vundo" entry seems to have disappeared from the XoftSypSE listing. I am attaching the HijackThis and ComboFix logs. I ran ComboFix 5 times and it deletes the desktop links, but they return before it finishes its log !


**** HiJack Log ****

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:24:41 PM, on 11/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.comcast.net/comcast.html"); (C:\Documents and Settings\BORNHORN\Application Data\Mozilla\Profiles\default\qbvrmdmp.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5Csearchplugins%5CSBWeb_02.src"); (C:\Documents and Settings\BORNHORN\Application Data\Mozilla\Profiles\default\qbvrmdmp.slt\prefs.js)
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\eozrxawr.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [c4c140c7] rundll32.exe "C:\WINDOWS\system32\bfywfqen.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O16 - DPF: GenealogyBrowser.Cab - http://209.90.101.200/cabs/zinst.cab
O16 - DPF: ZInst.Cab - http://209.90.101.200/cabs/zinst.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {84C81EF3-B20B-4773-8A86-DB90589B0F54} (webconference.Encoder) - https://www.webconference.com/downloads/v5install/setup2.exe
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C3912D64-6023-4A77-9BE1-9CA1DA5D80DE}: NameServer = 192.168.42.1,68.80.0.5
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 6718 bytes


**** ComboFix Log ****

ComboFix 07-11-08.1 - bornhorn 2007-11-11 18:28:17.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.735 [GMT -5:00]
Running from: C:\Downloads\combofix.exe
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\bornhorn\Desktop\Live Safety Center.lnk
C:\Documents and Settings\bornhorn\Desktop\Online Security Guide.lnk
C:\Documents and Settings\bornhorn\Favorites\Online Security Guide.lnk
C:\Documents and Settings\hipple\Favorites\Online Security Guide.lnk
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\eozrxawr.dllbox
C:\WINDOWS\system32\jkklj.dll
C:\WINDOWS\SYSTEM32\jlkkj.bak1
C:\WINDOWS\SYSTEM32\jlkkj.ini

.
((((((((((((((((((((((((( Files Created from 2007-10-11 to 2007-11-11 )))))))))))))))))))))))))))))))
.

2007-11-11 18:11 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-11 17:48 <DIR> d-------- C:\Documents and Settings\bornhorn\Application Data\Uniblue
2007-11-11 16:33 <DIR> d-------- C:\Program Files\XoftSpySE
2007-11-10 19:46 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-10 14:47 <DIR> d-------- C:\Documents and Settings\bornhorn\Application Data\AdwareAlert
2007-11-10 11:02 85,056 --a------ C:\WINDOWS\SYSTEM32\bfywfqen.dll
2007-11-10 10:59 81,472 --a------ C:\WINDOWS\SYSTEM32\ocwsdjpm.dll
2007-11-10 10:56 145,774 --a------ C:\WINDOWS\SYSTEM32\kicqgkhp.dll
2007-11-10 10:56 145,774 --a------ C:\WINDOWS\SYSTEM32\eozrxawr.dll
2007-11-09 22:46 36,352 --a------ C:\WINDOWS\SYSTEM32\xxyabby.dll
2007-11-09 22:45 <DIR> d-------- C:\WINDOWS\SYSTEM32\rMa01yy
2007-11-09 22:45 <DIR> d-------- C:\Temp\abW9
2007-11-09 22:45 <DIR> d-------- C:\Temp
2007-11-09 22:45 36,352 --a------ C:\WINDOWS\SYSTEM32\cbxyaxu.dll
2007-11-09 22:45 35,840 --a------ C:\WINDOWS\mrofinu572.exe
2007-10-28 11:30 <DIR> d-------- C:\Downloads
2007-10-28 11:30 <DIR> d-------- C:\Documents and Settings\hipple\Application Data\GetRightToGo
2007-10-12 10:15 110,952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS
2007-10-12 10:15 48,768 --a------ C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
2007-10-12 10:14 <DIR> d-------- C:\Program Files\Symantec AntiVirus

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-11 21:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-11 18:07 --------- d-----w C:\Program Files\QuickTime
2007-11-11 18:07 --------- d-----w C:\Program Files\Dell AIO Printer A920
2007-11-11 18:07 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-11 18:06 --------- d-----w C:\Program Files\DellSupport
2007-11-10 19:32 --------- d-----w C:\Program Files\FishTycoon_at
2007-11-10 19:20 --------- d-----w C:\Program Files\Atari
2007-10-14 00:41 --------- d-----w C:\Program Files\The Print Shop 20
2007-10-13 00:32 --------- d-----w C:\Program Files\Google
2007-10-12 17:22 --------- d-----w C:\Program Files\Netscape
2007-10-12 15:16 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-12 15:16 8,014 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-12 15:16 --------- d-----w C:\Program Files\Symantec
2007-10-12 15:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-09-22 18:37 --------- d-----w C:\Program Files\SmartMusic 9
2007-09-16 00:57 --------- d-----w C:\Documents and Settings\hipple\Application Data\Jasc
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-01-14 14:51 81 ----a-w C:\Documents and Settings\hipple\CTX.DAT
.

((((((((((((((((((((((((((((( snapshot@2007-11-10_20.08.47.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-08-24 13:28:54 141,424 ----a-w C:\WINDOWS\Downloaded Program Files\asinst.dll
+ 2006-08-02 17:39:06 73,728 ----a-w C:\WINDOWS\SYSTEM32\asuninst.exe
- 2007-09-06 00:50:44 17,474,680 ----a-w C:\WINDOWS\SYSTEM32\MRT.exe
+ 2007-09-28 05:19:39 18,089,592 ----a-w C:\WINDOWS\SYSTEM32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01CD0B31-9154-45F2-9414-F5D64B74EAF6}]
2007-11-09 22:45 36352 --a------ C:\WINDOWS\system32\cbxyaxu.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-10 10:56 145774 --a------ C:\WINDOWS\system32\eozrxawr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e8a4d9df-8cad-45d0-8385-27fbb91b9d35}]
2007-11-10 10:59 81472 --a------ C:\WINDOWS\system32\ocwsdjpm.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\eozrxawr.dll [2007-11-10 10:56 145774]

[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2003-08-26 20:47]
"Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 13:25]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-05-12 16:45]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-29 14:12]
"nwiz"="nwiz.exe" [2006-06-29 14:12 C:\WINDOWS\SYSTEM32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-06-29 14:12 C:\WINDOWS\SYSTEM32\nvmctray.dll]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 16:38]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-03-14 18:49]
"c4c140c7"="C:\WINDOWS\system32\bfywfqen.dll" [2007-11-10 11:02]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2004-07-26 18:14]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe

C:\Documents and Settings\bornhorn\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2003-12-22 20:12:30]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{01CD0B31-9154-45F2-9414-F5D64B74EAF6}"= C:\WINDOWS\system32\cbxyaxu.dll [2007-11-09 22:45 36352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbxyaxu]
cbxyaxu.dll 2007-11-09 22:45 36352 C:\WINDOWS\SYSTEM32\cbxyaxu.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\eozrxawr]
eozrxawr.dll 2007-11-10 10:56 145774 C:\WINDOWS\SYSTEM32\eozrxawr.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\jkklj.dll

R2 NVXBAR;nVidia WDM A/V Crossbar;C:\WINDOWS\system32\DRIVERS\NVxbar.sys
S3 musbehco;musbehco;\??\C:\DOCUME~1\bornhorn\LOCALS~1\Temp\musbehco.sys
S3 SNDP202;WFDC;C:\WINDOWS\system32\DRIVERS\sndp202.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-11-10 19:48:04 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.exe
"2007-11-11 23:36:43 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2007-11-11 21:33:58 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-11 18:38:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-11 18:41:55 - machine was rebooted
.
--- E O F ---


thanks for any help you can supply !

Chas

BC AdBot (Login to Remove)

 


#2 ChaZZZ55N

ChaZZZ55N
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:02:17 PM

Posted 11 November 2007 - 08:50 PM

I have added the FindAFW report log, not much to that ...


Find AWF report by noahdfear 2006
Version 1.40

The current date is: Sun 11/11/2007
The current time is: 19:09:36.54


bak folders found
~~~~~~~~~~~



Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~



end of report :wacko: :thumbsup: :blink:

#3 rookie147

rookie147

  • Members
  • 5,321 posts
  • OFFLINE
  •  
  • Local time:08:17 PM

Posted 25 November 2007 - 12:43 PM

Sorry for the delay. If you are still having problems please post a brand new HijackThis log as a reply to this topic. Before posting the log, please make sure you follow all the steps found in this topic:
Preparation Guide For Use Before Posting A HijackThis Log
Thanks,
Charles

If you are pleased with the service I have offered, you may like to consider making a donation. Posted Image
Posted Image


#4 rookie147

rookie147

  • Members
  • 5,321 posts
  • OFFLINE
  •  
  • Local time:08:17 PM

Posted 07 December 2007 - 03:06 PM

Due to lack of feedback, this topic is now closed.
If you need this topic reopened, please request this by sending me a Personal Message including a link to your thread.
This applies only to the original topic starter. Everyone else please begin a New Topic.

If you are pleased with the service I have offered, you may like to consider making a donation. Posted Image
Posted Image





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users