Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected With Packed.win32.monder.gen !


  • Please log in to reply
11 replies to this topic

#1 getslinky

getslinky

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:57 PM

Posted 23 April 2008 - 09:43 PM

Kaspersky Antivirus is continually popping up with alerts saying that the virus packed.win32.monder.gen is infecting my computer.. over and over again. I have used Malware-Bytes Anti-Malware software on a few occasions and that usually gets rid of it for a few hours, but then its back again! My computer has been slowing down heaps and its really annoying, can anyone help?

BC AdBot (Login to Remove)

 


#2 DaChew

DaChew

    Visiting Alien


  • Members
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:06:57 AM

Posted 23 April 2008 - 10:02 PM

Would you post that last MBAM log?
Chewy

No. Try not. Do... or do not. There is no try.

#3 getslinky

getslinky
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:57 PM

Posted 23 April 2008 - 11:36 PM

Ok i will re-scan the computer and send in the log..

#4 getslinky

getslinky
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:57 PM

Posted 24 April 2008 - 03:32 AM

Here is the log, there wasnt any viruses found, but Kaspersky is till (as we speak) popping up with the virus files. What else can i do?


Malwarebytes' Anti-Malware 1.11
Database version: 652

Scan type: Full Scan (C:\|)
Objects scanned: 163290
Time elapsed: 1 hour(s), 44 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#5 DaChew

DaChew

    Visiting Alien


  • Members
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:06:57 AM

Posted 24 April 2008 - 06:19 AM

Would you please open the logs back up and find a recent one where it actually found something

Can you post a Kaspersky scan log also

If it's doing an auto scan and finding something in a restore point and/or a quaratine file then those can be easily fixed
Chewy

No. Try not. Do... or do not. There is no try.

#6 getslinky

getslinky
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:57 PM

Posted 24 April 2008 - 06:55 PM

Ok here is a MBAM scan from the 20th -



Malwarebytes' Anti-Malware 1.11
Database version: 652

Scan type: Full Scan (C:\|)
Objects scanned: 142039
Time elapsed: 59 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\nnnliGyw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wyGilnnn.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wyGilnnn.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.

-----------------------------------------------------------------



- And this is a kaspersky log of 'scan critical areas' that happened on the 23rd and finished on the 24th -



Protection : running
--------------------
Total scanned: 246545
Detected: 12
Untreated: 0
Attacks blocked: 0
Start time: 4/23/2008 6:53:58 PM
Duration: 1 14:58:21


Detected
--------
Status Object
------ ------
deleted: Trojan program Packed.Win32.Monder.gen File: C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\6UQXQ9FH\c_uz[1]
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.qgr File: C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\DP6KZOLR\idkfa[1]
deleted: Trojan program Packed.Win32.Monder.gen File: C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP345\A0048962.dll//PE_Patch
deleted: Trojan program Packed.Win32.Monder.gen File: C:\WINDOWS\system32\filmyxhk.dll//PE_Patch
deleted: Trojan program Packed.Win32.Monder.gen File: C:\WINDOWS\system32\njedejvi.dll//PE_Patch
deleted: Trojan program Packed.Win32.Monder.gen File: C:\WINDOWS\system32\pqfxphou.dll//PE_Patch
deleted: Trojan program Packed.Win32.Monder.gen File: C:\WINDOWS\system32\wrqoesyc.dll//PE_Patch
deleted: adware not-a-virus:AdWare.Win32.Virtumonde.qom File: C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\SFHGXYF5\css4[1]
deleted: Trojan program Packed.Win32.Monder.gen File: C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP348\A0050162.dll//PE_Patch
deleted: Trojan program Packed.Win32.Monder.gen File: C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP348\A0050163.dll//PE_Patch
deleted: Trojan program Packed.Win32.Monder.gen File: C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP348\A0050164.dll//PE_Patch
deleted: Trojan program Packed.Win32.Monder.gen File: C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP348\A0050165.dll//PE_Patch


Events
------
Time Event
---- -----
4/22/2008 8:59:49 PM You are advised to perform a full computer scan as soon as possible.
4/22/2008 8:59:49 PM Database is out of date, leaving your computer at risk of infection. Please update your database.
4/22/2008 8:59:49 PM Protection of your computer is enabled.
4/22/2008 9:06:12 PM Please restart your computer to complete the installation of new or updated protection components.
4/22/2008 9:06:17 PM Your license key is blacklisted. Updates are disabled. Please contact your dealer or local support service.
4/22/2008 9:06:18 PM Update completed successfully
4/22/2008 9:12:32 PM Kaspersky Internet Security is not activated. You are advised to activate the application as soon as possible.
4/22/2008 9:14:50 PM Protection of your computer is not running. You are advised to resume protection.
4/22/2008 9:16:41 PM You are advised to perform a full computer scan as soon as possible.
4/22/2008 9:16:41 PM Protection of your computer is enabled.
4/22/2008 9:17:09 PM Process (PID 1124) tried to access Kaspersky Internet Security process (PID 752), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AdobeLogo.ico: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Audio/Click1.ogg: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Audio/High1.ogg: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/autorun.cdd: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Buttons/button.btn: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Buttons/exit.btn: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Buttons/min.btn: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Docs/888 Quick Guide.pdf: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Docs/888 Roulette 2 Guide.pdf: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/AdobeLogo.ico: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/aXXo.ico: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/Games2.ico: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/icon2.ico: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/Software.ico: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/XP PPL06.ico: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Images/630C0234.jpg: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Images/bg.jpg: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Images/logo.png: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Images/mask_1.png: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/autorun.exe: is password protected.
4/22/2008 9:57:24 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/aXXo.ico: is password protected.
4/22/2008 10:49:15 PM Process (PID 1656) tried to access Kaspersky Internet Security process (PID 752), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/22/2008 10:49:16 PM Process (PID 3844) tried to access Kaspersky Internet Security process (PID 752), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/22/2008 10:49:16 PM Process (PID 1092) tried to access Kaspersky Internet Security process (PID 752), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/22/2008 10:49:47 PM You are advised to perform a full computer scan as soon as possible.
4/22/2008 10:49:47 PM Protection of your computer is enabled.
4/22/2008 11:11:52 PM Update completed successfully
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AdobeLogo.ico: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Audio/Click1.ogg: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Audio/High1.ogg: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/autorun.cdd: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Buttons/button.btn: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Buttons/exit.btn: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Buttons/min.btn: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Docs/888 Quick Guide.pdf: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Docs/888 Roulette 2 Guide.pdf: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/AdobeLogo.ico: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/aXXo.ico: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/Games2.ico: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/icon2.ico: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/Software.ico: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/XP PPL06.ico: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Images/630C0234.jpg: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Images/bg.jpg: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Images/logo.png: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Images/mask_1.png: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/autorun.exe: is password protected.
4/22/2008 11:49:15 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/aXXo.ico: is password protected.
4/23/2008 12:44:45 AM Process (PID 1656) tried to access Kaspersky Internet Security process (PID 3096), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 12:44:53 AM Process (PID 1428) tried to access Kaspersky Internet Security process (PID 3096), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 12:44:53 AM Process (PID 1092) tried to access Kaspersky Internet Security process (PID 3096), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 12:45:23 AM You are advised to perform a full computer scan as soon as possible.
4/23/2008 12:45:23 AM Protection of your computer is enabled.
4/23/2008 1:09:15 AM Protection of your computer is not running. You are advised to resume protection.
4/23/2008 12:01:31 PM You are advised to perform a full computer scan as soon as possible.
4/23/2008 12:01:31 PM Protection of your computer is enabled.
4/23/2008 12:03:36 PM Update completed successfully
4/23/2008 12:22:46 PM Process C:\Documents and Settings\Owner\Local Settings\Application Data\Micro Forte\Kwari\Kwari.xLoader.32 (PID: 3968): attempt to embed itself into another process allowed.
4/23/2008 12:22:47 PM Process C:\Documents and Settings\Owner\Local Settings\Application Data\Micro Forte\Kwari\Kwari.xLoader.32 (PID: 3968): attempt to embed itself into another process allowed.
4/23/2008 12:22:48 PM Process C:\Documents and Settings\Owner\Local Settings\Application Data\Micro Forte\Kwari\Kwari.xLoader.32 (PID: 3968): attempt to embed itself into another process allowed.
4/23/2008 12:22:50 PM Process C:\Documents and Settings\Owner\Local Settings\Application Data\Micro Forte\Kwari\Kwari.xLoader.32 (PID: 3968): attempt to embed itself into another process allowed.
4/23/2008 12:22:51 PM Process C:\Documents and Settings\Owner\Local Settings\Application Data\Micro Forte\Kwari\Kwari.xLoader.32 (PID: 3968): attempt to embed itself into another process allowed.
4/23/2008 12:22:52 PM Process C:\Documents and Settings\Owner\Local Settings\Application Data\Micro Forte\Kwari\Kwari.xLoader.32 (PID: 3968): attempt to embed itself into another process allowed.
4/23/2008 12:22:54 PM Process C:\Documents and Settings\Owner\Local Settings\Application Data\Micro Forte\Kwari\Kwari.xLoader.32 (PID: 3968): attempt to embed itself into another process allowed.
4/23/2008 12:22:54 PM Process C:\Documents and Settings\Owner\Local Settings\Application Data\Micro Forte\Kwari\Kwari.xLoader.32 (PID: 3968): attempt to embed itself into another process allowed.
4/23/2008 12:22:57 PM Process (PID 3968) tried to access Kaspersky Internet Security process (PID 1324), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 12:22:58 PM Process (PID 3968) tried to access Kaspersky Internet Security process (PID 2020), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 12:22:59 PM Process (PID 3968) tried to access Kaspersky Internet Security process (PID 1224), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 12:23:28 PM Process C:\Documents and Settings\Owner\Local Settings\Application Data\Micro Forte\Kwari\Kwari.xLoader.32 (PID: 2712): attempt to embed itself into another process allowed.
4/23/2008 12:23:29 PM Process (PID 2712) tried to access Kaspersky Internet Security process (PID 1324), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 12:23:29 PM Process (PID 2712) tried to access Kaspersky Internet Security process (PID 2020), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 12:23:30 PM Process (PID 2712) tried to access Kaspersky Internet Security process (PID 1224), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 12:23:35 PM Process C:\Program Files\Kwari\game\Kwari_launcher.exe (PID: 3944): attempt to embed itself into another process allowed.
4/23/2008 12:23:35 PM Process C:\Program Files\Kwari\game\Kwari_launcher.exe (PID: 3944): attempt to embed itself into another process allowed.
4/23/2008 12:38:51 PM Process (PID 300) tried to access Kaspersky Internet Security process (PID 1324), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 12:39:03 PM Process (PID 300) tried to access Kaspersky Internet Security process (PID 2020), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 12:39:37 PM Process (PID 300) tried to access Kaspersky Internet Security process (PID 1224), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AdobeLogo.ico: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Audio/Click1.ogg: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Audio/High1.ogg: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/autorun.cdd: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Buttons/button.btn: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Buttons/exit.btn: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Buttons/min.btn: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Docs/888 Quick Guide.pdf: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Docs/888 Roulette 2 Guide.pdf: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/AdobeLogo.ico: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/aXXo.ico: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/Games2.ico: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/icon2.ico: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/Software.ico: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Icons/XP PPL06.ico: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Images/630C0234.jpg: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Images/bg.jpg: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Images/logo.png: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AutoPlay/Images/mask_1.png: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/autorun.exe: is password protected.
4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/aXXo.ico: is password protected.
4/23/2008 1:56:24 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\6UQXQ9FH\c_uz[1]: detected: Trojan program 'Packed.Win32.Monder.gen'. User: GETSLINKY\Owner, computer: localhost.
4/23/2008 1:56:24 PM Security threats have been detected. You are advised to neutralize them immediately.
4/23/2008 1:57:23 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\6UQXQ9FH\c_uz[1]: deleted.
4/23/2008 2:00:31 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\DP6KZOLR\idkfa[1]: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.qgr'. User: GETSLINKY\Owner, computer: localhost.
4/23/2008 2:00:31 PM Security threats have been detected. You are advised to neutralize them immediately.
4/23/2008 2:14:30 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\DP6KZOLR\idkfa[1]: deleted.
4/23/2008 2:23:48 PM Update completed successfully
4/23/2008 4:23:19 PM File C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP345\A0048962.dll//PE_Patch: detected: Trojan program 'Packed.Win32.Monder.gen'. User: GETSLINKY\Owner, computer: localhost.
4/23/2008 4:23:19 PM Security threats have been detected. You are advised to neutralize them immediately.
4/23/2008 4:43:48 PM Update completed successfully
4/23/2008 4:45:47 PM Process (PID 2312) tried to access Kaspersky Internet Security process (PID 2020), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 4:45:47 PM Process (PID 1092) tried to access Kaspersky Internet Security process (PID 2020), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 4:46:05 PM You are advised to perform a full computer scan as soon as possible.
4/23/2008 4:46:05 PM Security threats have been detected. You are advised to neutralize them immediately.
4/23/2008 4:46:05 PM Protection of your computer is enabled.
4/23/2008 5:09:16 PM Protection of your computer is not running. You are advised to resume protection.
4/23/2008 5:09:39 PM You are advised to perform a full computer scan as soon as possible.
4/23/2008 5:09:39 PM Security threats have been detected. You are advised to neutralize them immediately.
4/23/2008 5:09:39 PM Protection of your computer is enabled.
4/23/2008 6:51:36 PM Update completed successfully
4/23/2008 6:53:58 PM You are advised to perform a full computer scan as soon as possible.
4/23/2008 6:53:58 PM Protection of your computer is enabled.
4/23/2008 6:54:28 PM Process (PID 1124) tried to access Kaspersky Internet Security process (PID 756), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/23/2008 9:11:44 PM Update completed successfully
4/23/2008 11:31:45 PM Update completed successfully
4/24/2008 1:51:09 AM Update completed successfully
4/24/2008 4:11:11 AM Update completed successfully
4/24/2008 6:31:10 AM Update completed successfully
4/24/2008 7:56:02 AM File C:\WINDOWS\system32\filmyxhk.dll//PE_Patch: detected: Trojan program 'Packed.Win32.Monder.gen'.
4/24/2008 7:56:02 AM Security threats have been detected. You are advised to neutralize them immediately.
4/24/2008 7:56:02 AM File C:\WINDOWS\system32\filmyxhk.dll//PE_Patch: is still infected, postponed.
4/24/2008 7:56:39 AM File C:\WINDOWS\system32\njedejvi.dll//PE_Patch: detected: Trojan program 'Packed.Win32.Monder.gen'.
4/24/2008 7:56:39 AM File C:\WINDOWS\system32\njedejvi.dll//PE_Patch: is still infected, postponed.
4/24/2008 7:56:49 AM File C:\WINDOWS\system32\pqfxphou.dll//PE_Patch: detected: Trojan program 'Packed.Win32.Monder.gen'.
4/24/2008 7:56:49 AM File C:\WINDOWS\system32\pqfxphou.dll//PE_Patch: is still infected, postponed.
4/24/2008 7:57:43 AM File C:\WINDOWS\system32\wrqoesyc.dll//PE_Patch: detected: Trojan program 'Packed.Win32.Monder.gen'.
4/24/2008 7:57:43 AM File C:\WINDOWS\system32\wrqoesyc.dll//PE_Patch: is still infected, postponed.
4/24/2008 7:57:48 AM File c:\windows\system32\filmyxhk.dll//PE_Patch: detected: Trojan program 'Packed.Win32.Monder.gen'.
4/24/2008 8:52:17 AM Update completed successfully
4/24/2008 11:07:55 AM File c:\windows\system32\filmyxhk.dll: deleted.
4/24/2008 11:07:55 AM File c:\windows\system32\njedejvi.dll//PE_Patch: detected: Trojan program 'Packed.Win32.Monder.gen'.
4/24/2008 11:07:59 AM File c:\windows\system32\njedejvi.dll: deleted.
4/24/2008 11:07:59 AM File c:\windows\system32\pqfxphou.dll//PE_Patch: detected: Trojan program 'Packed.Win32.Monder.gen'.
4/24/2008 11:08:00 AM File c:\windows\system32\pqfxphou.dll: deleted.
4/24/2008 11:08:00 AM File c:\windows\system32\wrqoesyc.dll//PE_Patch: detected: Trojan program 'Packed.Win32.Monder.gen'.
4/24/2008 11:08:02 AM File c:\windows\system32\wrqoesyc.dll: deleted.
4/24/2008 11:11:12 AM Update completed successfully
4/24/2008 1:20:16 PM Process (PID 480) tried to access Kaspersky Internet Security process (PID 3912), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/24/2008 1:20:17 PM Process (PID 480) tried to access Kaspersky Internet Security process (PID 756), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/24/2008 1:23:58 PM Process (PID 4064) tried to access Kaspersky Internet Security process (PID 3912), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/24/2008 1:23:58 PM Process (PID 4064) tried to access Kaspersky Internet Security process (PID 756), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/24/2008 1:24:28 PM Process (PID 3812) tried to access Kaspersky Internet Security process (PID 756), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/24/2008 1:24:28 PM Process (PID 3812) tried to access Kaspersky Internet Security process (PID 3912), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/24/2008 1:27:40 PM Process (PID 1656) tried to access Kaspersky Internet Security process (PID 3912), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/24/2008 1:27:40 PM Process (PID 1656) tried to access Kaspersky Internet Security process (PID 756), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/24/2008 1:33:04 PM Update completed successfully
4/24/2008 1:58:33 PM Process (PID 1680) tried to access Kaspersky Internet Security process (PID 3912), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/24/2008 1:58:34 PM Process (PID 1680) tried to access Kaspersky Internet Security process (PID 756), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/24/2008 2:24:24 PM Process (PID 1288) tried to access Kaspersky Internet Security process (PID 756), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/24/2008 2:24:36 PM Process (PID 1288) tried to access Kaspersky Internet Security process (PID 3912), but the action has been blocked by the Self-Defense component. No action on your part is required.
4/24/2008 2:31:50 PM Popup window from page http://beta.whereis.com/media.htm?width=30...land&state= has been blocked.
4/24/2008 2:39:41 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\SFHGXYF5\css4[1]: detected: adware 'not-a-virus:AdWare.Win32.Virtumonde.qom'. User: GETSLINKY\Owner, computer: localhost.
4/24/2008 2:39:41 PM Security threats have been detected. You are advised to neutralize them immediately.
4/24/2008 2:39:56 PM File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\SFHGXYF5\css4[1]: deleted.
4/24/2008 3:50:07 PM File C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP348\A0050162.dll//PE_Patch: detected: Trojan program 'Packed.Win32.Monder.gen'. User: GETSLINKY\Owner, computer: localhost.
4/24/2008 3:50:07 PM Security threats have been detected. You are advised to neutralize them immediately.
4/24/2008 3:52:19 PM Update completed successfully
4/24/2008 6:11:15 PM Update completed successfully
4/24/2008 6:31:04 PM File C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP348\A0050162.dll: deleted.
4/24/2008 6:31:08 PM File C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP348\A0050163.dll//PE_Patch: detected: Trojan program 'Packed.Win32.Monder.gen'. User: GETSLINKY\Owner, computer: localhost.
4/24/2008 6:31:08 PM Security threats have been detected. You are advised to neutralize them immediately.
4/24/2008 6:31:12 PM File C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP348\A0050163.dll: deleted.
4/24/2008 6:31:14 PM File C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP348\A0050164.dll//PE_Patch: detected: Trojan program 'Packed.Win32.Monder.gen'. User: GETSLINKY\Owner, computer: localhost.
4/24/2008 6:31:14 PM Security threats have been detected. You are advised to neutralize them immediately.
4/24/2008 6:31:17 PM File C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP348\A0050164.dll: deleted.
4/24/2008 6:31:19 PM File C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP348\A0050165.dll//PE_Patch: detected: Trojan program 'Packed.Win32.Monder.gen'. User: GETSLINKY\Owner, computer: localhost.
4/24/2008 6:31:19 PM Security threats have been detected. You are advised to neutralize them immediately.
4/24/2008 6:31:22 PM File C:\System Volume Information\_restore{BB66D33F-9EFE-463C-A355-5AFDA89156CD}\RP348\A0050165.dll: deleted.
4/25/2008 12:55:52 AM Not all components were updated


Reports
-------
Component Status Start Finish Size
--------- ------ ----- ------ ----
Firewall running 4/23/2008 6:53:58 PM 643.7 KB
Anti-Spam running 4/23/2008 6:53:58 PM 0 bytes
Privacy Control running 4/23/2008 6:53:58 PM 0 bytes
Proactive Defense running 4/23/2008 6:53:58 PM 0 bytes
File Anti-Virus running 4/23/2008 6:53:58 PM 50.4 MB
Mail Anti-Virus running 4/23/2008 6:53:58 PM 0 bytes
Web Anti-Virus running 4/23/2008 6:53:58 PM 9.4 MB
Scan startup objects completed 4/23/2008 6:56:02 PM 4/23/2008 6:56:48 PM 425.7 KB
Update completed 4/23/2008 9:10:44 PM 4/23/2008 9:11:44 PM 0 bytes
Update completed 4/23/2008 11:30:38 PM 4/23/2008 11:31:45 PM 0 bytes
Update completed 4/24/2008 1:50:18 AM 4/24/2008 1:51:09 AM 0 bytes
Update completed 4/24/2008 4:10:19 AM 4/24/2008 4:11:11 AM 0 bytes
Update completed 4/24/2008 6:30:18 AM 4/24/2008 6:31:10 AM 0 bytes
Scan critical areas completed 4/24/2008 7:55:02 AM 4/24/2008 11:08:02 AM 0 bytes
Update completed 4/24/2008 8:50:18 AM 4/24/2008 8:52:17 AM 0 bytes
Update completed 4/24/2008 11:10:19 AM 4/24/2008 11:11:12 AM 0 bytes
Update completed 4/24/2008 1:30:25 PM 4/24/2008 1:33:04 PM 0 bytes
Scan completed 4/24/2008 2:00:36 PM 4/24/2008 2:01:31 PM 40.7 KB
Scan completed 4/24/2008 2:00:56 PM 4/24/2008 2:02:04 PM 53.7 KB
Update completed 4/24/2008 3:50:22 PM 4/24/2008 3:52:19 PM 0 bytes
Update completed 4/24/2008 6:10:18 PM 4/24/2008 6:11:15 PM 0 bytes
Update Not all components were updated 4/24/2008 8:30:19 PM 4/25/2008 12:55:36 AM 0 bytes
Update running 4/25/2008 3:11:38 AM 28.9 KB
Scan critical areas running 4/25/2008 7:55:03 AM 542.6 KB


Quarantine
----------
Status Object Size Added
------ ------ ---- -----


Backup
------
Status Object Size
------ ------ ----

#7 DaChew

DaChew

    Visiting Alien


  • Members
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:06:57 AM

Posted 24 April 2008 - 07:20 PM

aXXo Bonus Guide.exe

might as well just get a sledgehammer out and finish your computer off

putting the name axxo on something is an old torrent trick

clean out the quarantine, empty the temp files and folders and clean up system restore
Chewy

No. Try not. Do... or do not. There is no try.

#8 getslinky

getslinky
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:57 PM

Posted 24 April 2008 - 07:27 PM

What do u mean by finishing the computer off? And what is the Axxo file?
And with the temp files, do u mean the temp in IE7?




What do u mean by finishing the computer off? And what is the Axxo file?
And with the temp files, do u mean the temp in IE7?

#9 DaChew

DaChew

    Visiting Alien


  • Members
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:06:57 AM

Posted 24 April 2008 - 07:30 PM

when I googled it all I got was dangerous sites

Edited by DaChew, 24 April 2008 - 07:31 PM.

Chewy

No. Try not. Do... or do not. There is no try.

#10 DaChew

DaChew

    Visiting Alien


  • Members
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:06:57 AM

Posted 24 April 2008 - 07:34 PM

One of the best ways to distribute malware is to inject it into torrents or other P2P downloads
Chewy

No. Try not. Do... or do not. There is no try.

#11 getslinky

getslinky
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:08:57 PM

Posted 24 April 2008 - 07:53 PM

Where did u see this file?
Was it attached to another file or..?

#12 DaChew

DaChew

    Visiting Alien


  • Members
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:06:57 AM

Posted 24 April 2008 - 08:08 PM

4/23/2008 1:21:00 PM File C:\Documents and Settings\Owner\My Documents\My Downloads\2008 Version Tracker Pro 3 6 1.rar/Version Tracker Pro 3 6 1\aXXo Bonus\aXXo Bonus Guide.exe/AdobeLogo.ico: is password protected.


these are dangerous since they don't come from a legitimate source
Chewy

No. Try not. Do... or do not. There is no try.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users