Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virtumonde And Smitfraud


  • This topic is locked This topic is locked
2 replies to this topic

#1 lovingtahoe

lovingtahoe

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Location:South Lake Tahoe
  • Local time:01:50 PM

Posted 09 February 2008 - 06:22 PM

Hello Everyone,
ThankYou fo taking the time to read this. Unfortunately my computer contracted Virtumonde and Smitfraud. I believe I unsuccessfully removed them. The annoying little icon (the yellow yield sign) and the blue wallpaper are gone now, but my computer is running at 50-60% CPU usage with no major programs running. I have ran all of the below programs:

SpywareBlaster
Spybot Search and destroy
Lavasoft Adaware
SmitFraud Fix
VundoFix
Combofix
Cleanup
The Shield AntiVirus





HiJack This Log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:08:24 PM, on 2/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESTsoft\ALZip\ALZip.exe
C:\Program Files\HijackThis\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: Farstone Url Blocker - {316AEF8D-3C37-423E-9E6E-13820A9DC37A} - C:\PROGRA~1\PCSECU~1\THESHI~1\IrlOnIE.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Farstone Popup Blocker - {E22F9B9D-1A1F-473E-BED6-D8BC152441F4} - C:\PROGRA~1\PCSECU~1\THESHI~1\FARPOP~1.DLL
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Vrmon] C:\Program Files\PCSecurityShield\ShieldAntivirus\vrmonnt.exe Main
O4 - HKLM\..\Run: [VrSchedule] C:\Program Files\PCSecurityShield\ShieldAntivirus\Vrres.exe
O4 - HKLM\..\Run: [dwStart] C:\Program Files\PCSecurityShield\The Shield Firewall\FireWall.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKLM\..\Policies\Explorer\Run: [0ONIAx1pR0] rundll32.exe "C:\WINDOWS\wpwbklin.dll",DllCleanServer
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: worsock.dll
O10 - Unknown file in Winsock LSP: worsock.dll
O10 - Unknown file in Winsock LSP: worsock.dll
O10 - Unknown file in Winsock LSP: worsock.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: Office Source Engine (ose) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (file missing)
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: ViRobot Expert Monitoring (vrmonsvc) - HAURI - C:\Program Files\PCSecurityShield\ShieldAntivirus\vrmonsvc.exe

--
End of file - 5885 bytes




ComboFix Log:

ComboFix 08-02.05.3 - Owner 2008-02-09 10:19:09.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.700 [GMT -8:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\riqfkmpf.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\absolute key logger.lnk
C:\WINDOWS\cbinst$.exe
C:\WINDOWS\daxtime.dll
C:\WINDOWS\default.htm
C:\WINDOWS\dp0.dll
C:\WINDOWS\eventlowg.dll
C:\WINDOWS\ie_32.exe
C:\WINDOWS\ngd.dll
C:\WINDOWS\pbar.dll
C:\WINDOWS\PerfInfo
C:\WINDOWS\PerfInfo\0ONIAx1pR0wp.exe
C:\WINDOWS\spredirect.dll
C:\WINDOWS\system32\ijllm.ini
C:\WINDOWS\system32\ijllm.ini2
C:\WINDOWS\system32\mllji.dll
C:\WINDOWS\system32\pmnlllm.dll
C:\WINDOWS\system32\riqfkmpf.dll
C:\WINDOWS\system32\riqfkmpf.dllbox
C:\WINDOWS\system32\rppwhpyo.ini
C:\WINDOWS\system32\sqtsjolw.dll
C:\WINDOWS\wml.exe
C:\WINDOWS\xadbrk_.exe
D:\Autorun.inf

----- BITS: Possible infected sites -----

hxxp://www.download.windowsupdate.com

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_IPRIP
-------\LEGACY_NPF
-------\Iprip


((((((((((((((((((((((((( Files Created from 2008-01-09 to 2008-02-09 )))))))))))))))))))))))))))))))
.

2008-02-09 10:15 . 2004-08-03 23:00 260,272 --a------ C:\cmldr
2008-02-09 09:49 . 2004-08-10 11:00 388,608 --a------ C:\kmd.exe
2008-02-09 08:37 . 2008-02-09 08:42 3,038 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-09 07:41 . 2008-02-09 07:41 225 --a------ C:\WINDOWS\wininit.ini
2008-02-08 21:03 . 2008-02-08 21:03 116 --a------ C:\WINDOWS\VFLog.dat
2008-02-08 19:08 . 2008-02-08 19:08 <DIR> d-------- C:\_backupD
2008-02-08 19:08 . 2007-02-08 15:54 278,910 --a------ C:\win32delfkil.exe
2008-02-08 17:11 . 2008-02-08 17:11 10,752 --a------ C:\WINDOWS\system32\worsock.dll
2008-02-08 17:09 . 2008-02-08 17:09 1 --a------ C:\WINDOWS\system32\rc.dat
2008-02-08 17:09 . 2008-02-08 17:09 1 --a------ C:\WINDOWS\system32\ps1.dat
2008-02-08 17:09 . 2008-02-08 17:09 1 --a------ C:\WINDOWS\system32\cs.dat
2008-02-08 16:58 . 2008-02-08 16:58 <DIR> d-------- C:\WINDOWS\srqtvalv
2008-02-08 16:57 . 2008-02-08 17:00 58,368 --a------ C:\wpohl.exe
2008-02-08 11:30 . 2008-02-08 11:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-02-08 11:23 . 2008-02-08 11:23 <DIR> d-------- C:\Program Files\Bonjour
2008-02-08 11:19 . 2008-02-08 11:19 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-02-07 14:10 . 2008-02-07 14:10 <DIR> d-------- C:\Program Files\Apple Software Update
2008-02-07 14:10 . 2008-02-07 14:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-02-07 10:35 . 2008-02-07 10:36 <DIR> d-------- C:\Program Files\eMusic Download Manager
2008-02-07 10:35 . 2008-02-07 10:35 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\InstallShield
2008-01-23 13:15 . 2008-01-23 14:17 <DIR> d-------- C:\Program Files\Crimson Editor
2008-01-23 12:23 . 2008-01-23 12:23 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Uniblue
2008-01-18 22:33 . 2008-01-18 22:33 <DIR> d-------- C:\Program Files\CodeIgniter_1.5.4
2008-01-18 18:20 . 2008-01-18 18:20 <DIR> d-------- C:\Program Files\wordpress
2008-01-17 17:16 . 2008-01-17 17:16 7,680 --ahs---- C:\WINDOWS\Thumbs.db

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-09 15:53 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-09 03:10 53,248 ----a-w C:\Process.exe
2008-02-09 03:10 42,496 ----a-w C:\swreg.exe
2008-02-09 03:10 40,960 ----a-w C:\swsc.exe
2008-02-09 03:10 4,175 ----a-w C:\SMWNCV.cmd
2008-02-09 03:10 4,096 ----a-w C:\REBOOT.EXE
2008-02-09 03:10 16,384 ----a-w C:\restart.exe
2008-02-08 21:29 --------- d-----w C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-02-08 21:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-08 21:10 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-07 21:00 4,484,128 ----a-w C:\WINDOWS\system32\drivers\vrcore.sys
2008-02-07 18:35 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-31 21:00 40,025 ----a-w C:\WINDOWS\system32\drivers\vrfil.sys
2008-01-30 01:23 1,978 ----a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
2008-01-19 19:02 --------- d-----w C:\Program Files\SpywareBlaster
2007-12-21 01:16 --------- d-----w C:\Program Files\Punch! Home Design - Platinum
2007-12-20 23:01 --------- d-----w C:\Program Files\DivX
2007-12-20 22:59 --------- d-----w C:\Documents and Settings\Owner\Application Data\DivX
2007-12-17 16:00 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-14 22:59 --------- d-----w C:\Program Files\CrossFnt
2007-12-11 19:46 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-02-10 16:53 804 ----a-w C:\Program Files\Shortcut to HijackThis.lnk
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6607E676-1BDE-4cb3-9913-4DC5EBCAE35E}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F10587E9-0E47-4CBE-ABCD-7DD20B8622FF}]
C:\Program Files\Helper\1202518911.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB6155"="command /c del C:\WINDOWS\system32\wml.exe_tobedeleted" [ ]
"SpybotDeletingD3161"="cmd /c del C:\WINDOWS\system32\wml.exe_tobedeleted" [ ]
"SpybotDeletingB4030"="command /c del C:\WINDOWS\system32\vxddsk.exe_tobedeleted" [ ]
"SpybotDeletingD7506"="cmd /c del C:\WINDOWS\system32\vxddsk.exe_tobedeleted" [ ]
"SpybotDeletingB8160"="command /c del C:\WINDOWS\system32\mllji.dll_tobedeleted" [ ]
"SpybotDeletingD3757"="cmd /c del C:\WINDOWS\system32\mllji.dll_tobedeleted" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelAudioStudio"="C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" [2005-07-20 00:55 7090176]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-04-25 10:32 114688]
"Vrmon"="C:\Program Files\PCSecurityShield\ShieldAntivirus\vrmonnt.exe" [2006-01-18 17:07 249916]
"VrSchedule"="C:\Program Files\PCSecurityShield\ShieldAntivirus\Vrres.exe" [2004-03-11 12:00 266304]
"dwStart"="C:\Program Files\PCSecurityShield\The Shield Firewall\FireWall.exe" [2004-08-04 20:13 405504]
"OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 10:00 49152]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"nmctxth"="C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2007-10-01 20:08 451896]
"nmapp"="C:\Program Files\Pure Networks\Network Magic\nmapp.exe" [2007-10-29 22:04 451896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA1886"="command /c del C:\WINDOWS\system32\wml.exe_tobedeleted" [ ]
"SpybotDeletingC4006"="cmd /c del C:\WINDOWS\system32\wml.exe_tobedeleted" [ ]
"SpybotDeletingA6974"="command /c del C:\WINDOWS\system32\vxddsk.exe_tobedeleted" [ ]
"SpybotDeletingC441"="cmd /c del C:\WINDOWS\system32\vxddsk.exe_tobedeleted" [ ]
"SpybotDeletingA1365"="command /c del C:\WINDOWS\system32\mllji.dll_tobedeleted" [ ]
"SpybotDeletingC4415"="cmd /c del C:\WINDOWS\system32\mllji.dll_tobedeleted" [ ]
"SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" [2005-05-31 01:04 4393096]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"0ONIAx1pR0"= rundll32.exe "C:\WINDOWS\wpwbklin.dll",DllCleanServer

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
C:\Program Files\AlienGUIse\fastload.dll 2001-12-20 23:34 24576 C:\Program Files\AlienGUIse\fastload.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll

S1 4fdw;4fdw;C:\WINDOWS\system32\4fdw.dll []
S2 asc3550o;asc3550o;C:\WINDOWS\system32\drivers\asc3550o.sys [2004-08-10 11:00]
S3 FarStoneFireWallDrive;FarStoneFireWallDrive;C:\WINDOWS\system32\Drivers\FarDrive.sys [2004-05-19 23:53]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2004-08-10 11:00]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2004-08-10 11:00]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2004-08-10 11:00]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2004-08-10 11:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8272ebe7-8cb4-11dc-96d7-001320a81698}]
\Shell\AutoRun\command - J:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2007-02-07 17:46:09 C:\WINDOWS\Tasks\ISP signup reminder 2.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2007-02-07 17:46:09 C:\WINDOWS\Tasks\ISP signup reminder 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-09 10:30:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-09 10:33:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-09 18:33:52

BC AdBot (Login to Remove)

 


m

#2 lovingtahoe

lovingtahoe
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Location:South Lake Tahoe
  • Local time:01:50 PM

Posted 10 February 2008 - 11:13 AM

The problem has FIXED itself! Thank-you.

#3 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:01:50 PM

Posted 17 February 2008 - 04:38 PM

Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users