Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HJT jerryc


  • Please log in to reply
10 replies to this topic

#1 jerryc

jerryc

  • Members
  • 91 posts
  • OFFLINE
  •  
  • Local time:11:43 AM

Posted 24 February 2005 - 02:51 AM

I just picked up some problems even though I had spywareblaster, spybot, adaware, and spywareguard all updated and installed before this OS ever saw the internet. To Grinler, this is the OS that I had to find a modem driver for a couple of days ago.
Some details; spywareguard made several BHO warnings about coolwebsearch, changing start and search pages and some others. Repeated scans with adaware and spybot found 40-50 things in total, which I deleted. Warnings then stopped but I was still getting popups, all of which were fake spyware 'help' sites. I ran a Panda online scan which said I had 3 virus and 2 suspicious; a rescan with the checkbox to fix, which I didn't do the first time, found only one suspicious which was se.dll. I submitted it to Panda and haven't heard anything. I got CWShredder and ran it in safemode twice; it found nothing. While in safemode I deleted temp and TIF files, one of which was the se.dll, which would not delete in normal mode. I now have rebooted into normal and got an error msg "error loading....Temp\se.dll The specified module cannot be found" and there's a button on the taskbar that says 'rundll' that relates to that error msg. I haven't clicked on it yet. I also have 3 temp files that won't delete, says they're in use. DFDAF4.tmp, DFC94A.tmp, and DF758D.tmp. Sounds like the 'dyfuca' to me.
Also, I had put HJT on the desktop and ran it before realizing that I should have put it in 'programs', so I dragged it to 'programs' and reran it with the same results, below. Hope that's ok.
Thanks for any assistance.

Logfile of HijackThis v1.99.1
Scan saved at 11:08:57 PM, on 2/23/2005
Platform: Windows 2003 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 (6.00.3790.0000)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\system32\Dfssvc.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\ismserv.exe
F:\Program Files\Network Associates\Common Framework\FrameworkService.exe
F:\WINDOWS\system32\ntfrs.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
F:\WINDOWS\system32\rundll32.exe
F:\Program Files\WinZip\WZQKPICK.EXE
F:\Program Files\SpywareGuard\sgmain.exe
F:\Program Files\SpywareGuard\sgbhp.exe
F:\WINDOWS\system32\wuauclt.exe
F:\WINDOWS\system32\wpabaln.exe
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\Documents and Settings\Administrator\Desktop\HijackThis1991.exe
F:\WINDOWS\system32\NOTEPAD.EXE
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\Program Files\HijackThis1991.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.california.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - F:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "F:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [sp] rundll32 F:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - Startup: SpywareGuard.lnk = F:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: WinZip Quick Pick.lnk = F:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Jerry.HQ
O17 - HKLM\Software\..\Telephony: DomainName = Jerry.HQ
O17 - HKLM\System\CCS\Services\Tcpip\..\{61E30F25-94D7-4B73-BF5D-0D34FE816A4C}: NameServer = 209.3.224.20 209.3.224.21
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Jerry.HQ
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Jerry.HQ
O20 - Winlogon Notify: EFS - F:\WINDOWS\SYSTEM32\sclgntfy.dll
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - F:\Program Files\Network Associates\Common Framework\FrameworkService.exe

BC AdBot (Login to Remove)

 


#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,618 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:43 AM

Posted 27 February 2005 - 11:07 PM

You are currently using hijackthis from a temp directory. This can cause problems. Please create a directory on your c: drive called c:\hijackthis and download and unzip hijackthis into that directory. Run the program from that directory from now on.

For a tutorial on how to use HijackThis please see the following link:

Using HijackThis to Remove Spyware, Browser Hijackers, and Dialers

Print out these instructions and then close all windows including Internet Explorer.

Then I want you to fix some of those entries. Please do the following:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then click the Fix button:

O4 - HKLM\..\Run: [Microsoft Update] Microsoft.exe
O4 - HKLM\..\RunServices: [Microsoft Update] Microsoft.exe
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab

Reboot your computer into Safe Mode

Then delete these files or directories (Do not be concerned if they do not exist)

c:\windows\system32\Microsoft.exe

Reboot your computer to go back to normal mode and please download and install the program Registry Lite from here:

http://www.resplendence.com/reglite

Once it is installed, please double click on the icon that should now be on your desktop. If an icon is not there, then check under programs portion of the Start Menu.

Once it is opened, copy and paste the below line, into the address field of Registrar Lite.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

And press enter. You will now be presented with new information in the bottom right and left sections and on the right section, the name AppInit_DLLs should be highlighted. Double-click on the AppInit_DLLs entry and copy and paste the text found in the value field in your next reply to this post.

#3 jerryc

jerryc
  • Topic Starter

  • Members
  • 91 posts
  • OFFLINE
  •  
  • Local time:11:43 AM

Posted 02 March 2005 - 03:33 AM

I've redone the download, made a new file, F:\ HJT, and rescanned. I should explain; I have 4 OS and this one is on the F drive. I haven't done anything else except rerun spybot and adaware first; adaware found one thing, spybot nothing, but I did get a 'missing se.dll' notice at startup. should I still do the deletions in your last post?
Thx

Logfile of HijackThis v1.99.1
Scan saved at 12:27:59 AM, on 3/2/2005
Platform: Windows 2003 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 (6.00.3790.0000)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\system32\Dfssvc.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\ismserv.exe
F:\Program Files\Network Associates\Common Framework\FrameworkService.exe
F:\WINDOWS\system32\ntfrs.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
F:\Program Files\WinZip\WZQKPICK.EXE
F:\Program Files\SpywareGuard\sgmain.exe
F:\Program Files\SpywareGuard\sgbhp.exe
F:\WINDOWS\system32\wuauclt.exe
F:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.california.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...B_PVER}&ar=home
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - F:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "F:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - Startup: SpywareGuard.lnk = F:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: WinZip Quick Pick.lnk = F:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Jerry.HQ
O17 - HKLM\Software\..\Telephony: DomainName = Jerry.HQ
O17 - HKLM\System\CCS\Services\Tcpip\..\{61E30F25-94D7-4B73-BF5D-0D34FE816A4C}: NameServer = 209.3.224.20 209.3.224.21
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Jerry.HQ
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Jerry.HQ
O20 - Winlogon Notify: EFS - F:\WINDOWS\SYSTEM32\sclgntfy.dll
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - F:\Program Files\Network Associates\Common Framework\FrameworkService.exe

#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,618 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:43 AM

Posted 02 March 2005 - 10:34 AM

Yes do everything stated and post a new log.

#5 jerryc

jerryc
  • Topic Starter

  • Members
  • 91 posts
  • OFFLINE
  •  
  • Local time:11:43 AM

Posted 03 March 2005 - 03:06 AM

Followed all instructions exactly; there were no files in HJT with those names to 'fix'. There was no m'soft.exe to delete. There was no value in the value field, in Reglite. this time at startup I didn't get any msg's about missing se.dll or anything about rundll. Am I home free?
here's the latest HJT log.
Thx
Jerry


Logfile of HijackThis v1.99.1
Scan saved at 11:10:56 PM, on 3/2/2005
Platform: Windows 2003 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 (6.00.3790.0000)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\system32\Dfssvc.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\ismserv.exe
F:\Program Files\Network Associates\Common Framework\FrameworkService.exe
F:\WINDOWS\system32\ntfrs.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
F:\Program Files\WinZip\WZQKPICK.EXE
F:\Program Files\SpywareGuard\sgmain.exe
F:\WINDOWS\system32\mshta.exe
F:\Program Files\SpywareGuard\sgbhp.exe
F:\WINDOWS\system32\wuauclt.exe
F:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.california.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...B_PVER}&ar=home
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - F:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "F:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - Startup: SpywareGuard.lnk = F:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: WinZip Quick Pick.lnk = F:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Jerry.HQ
O17 - HKLM\Software\..\Telephony: DomainName = Jerry.HQ
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Jerry.HQ
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Jerry.HQ
O20 - Winlogon Notify: EFS - F:\WINDOWS\SYSTEM32\sclgntfy.dll
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - F:\Program Files\Network Associates\Common Framework\FrameworkService.exe

#6 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,618 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:43 AM

Posted 03 March 2005 - 10:25 AM

Fix this and post a last log:


R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

#7 jerryc

jerryc
  • Topic Starter

  • Members
  • 91 posts
  • OFFLINE
  •  
  • Local time:11:43 AM

Posted 03 March 2005 - 08:50 PM

I'll do that when I get home; I have a question about 'About blank'.
In spywareblaster it's listed as default search page or something like that; is it sometimes the correct thing and then undermined or so by spyware, or is it always a bad thing? and thus shouldn't be listed by spywareblaster as though it's right?
Am I explaining this in a way that makes sense?
thx

#8 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,618 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:43 AM

Posted 04 March 2005 - 12:42 AM

I think i knwo what you are saying. It was probably undermined by the spyware

#9 jerryc

jerryc
  • Topic Starter

  • Members
  • 91 posts
  • OFFLINE
  •  
  • Local time:11:43 AM

Posted 10 March 2005 - 02:26 PM

I had some outside issues so am late getting this in to you. Hope that's ok. I deleted the 'about blank' line and here's the log.
Thx


Logfile of HijackThis v1.99.1
Scan saved at 11:21:29 AM, on 3/10/2005
Platform: Windows 2003 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 (6.00.3790.0000)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\system32\Dfssvc.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\ismserv.exe
F:\Program Files\Network Associates\Common Framework\FrameworkService.exe
F:\WINDOWS\system32\ntfrs.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
F:\Program Files\WinZip\WZQKPICK.EXE
F:\Program Files\SpywareGuard\sgmain.exe
F:\WINDOWS\system32\mshta.exe
F:\Program Files\SpywareGuard\sgbhp.exe
F:\WINDOWS\system32\wuauclt.exe
F:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.california.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...B_PVER}&ar=home
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - F:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "F:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - Startup: SpywareGuard.lnk = F:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: WinZip Quick Pick.lnk = F:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Jerry.HQ
O17 - HKLM\Software\..\Telephony: DomainName = Jerry.HQ
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Jerry.HQ
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Jerry.HQ
O20 - Winlogon Notify: EFS - F:\WINDOWS\SYSTEM32\sclgntfy.dll
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - F:\Program Files\Network Associates\Common Framework\FrameworkService.exe

#10 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,618 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:43 AM

Posted 10 March 2005 - 05:19 PM

Are you still having a problem?

#11 jerryc

jerryc
  • Topic Starter

  • Members
  • 91 posts
  • OFFLINE
  •  
  • Local time:11:43 AM

Posted 11 March 2005 - 10:51 AM

Yes, but not with this.. ok bad joke. All seems well. Thank you very much.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users