Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Machine Infected With Malware


  • This topic is locked This topic is locked
2 replies to this topic

#1 karthik_arnold1

karthik_arnold1

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:07:38 AM

Posted 28 May 2008 - 03:48 AM

Hi All

Pls help me in cleaning my machine ,

My machine is infected with malware Pls find the hijackthis log below .

Since my machine is in corporate network online scan is blocked by the firewall



Deckard's System Scanner v20071014.68
Run by Karthikeyan.J on 2008-05-28 14:01:35
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
6: 2008-05-28 08:31:43 UTC - RP6 - Deckard's System Scanner Restore Point
5: 2008-05-27 17:11:48 UTC - RP5 - Removed TextPad 5.
4: 2008-05-27 17:10:24 UTC - RP4 - Removed QuickTime
3: 2008-05-27 17:09:57 UTC - RP3 - Removed Microsoft Tool Web Package:diskpart.exe
2: 2008-05-27 17:09:28 UTC - RP2 - Removed Microsoft Office Communicator 2005


-- First Restore Point --
1: 2008-05-26 15:04:13 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-05-28 14:04:48
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.5730.13)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\RealVNC\VNC4\winvnc4.exe
C:\WINDOWS\system32\CCM\clicomp\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\Network Associates\VirusScan\shstat.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Program Files\Qlock\qlock.exe
C:\Program Files\Jabber\Messenger\JabberMessenger.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\karthikeyan.j\Desktop\dss.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.33.46:3128
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
O2 - BHO: (no name) - {0BE44D33-B341-4655-B70A-3306BFB10C9B} - C:\WINDOWS\system32\rqRIXrsp.dll
O2 - BHO: (no name) - {0CF5D165-517E-48B6-B3C7-3054A24F8BF6} - C:\WINDOWS\system32\yayaAroN.dll
O2 - BHO: (no name) - {505F7312-6AE3-4250-86F5-46A82AEB8663} - C:\WINDOWS\system32\byXRLeFV.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Startup: qlock.lnk = C:\Program Files\Qlock\qlock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: MetaFrame Password Manager Agent Background Process.lnk = C:\Program Files\Citrix\MetaFrame Password Manager\ssoShell.exe
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: CtxLsp.dllO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) - https://www.microsoft.com/resources/virtual...iveXClient1.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab Class) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab
O16 - DPF: {CAFECAFE-0013-0001-0026-ABCDEFABCDEF} (JInitiator 1.3.1.26) - http://mars.corp.mphasis.com/jinitiator/oajinit.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
O17 - HKLM\Software\..\Telephony: DomainName = corp.mphasis.com
O17 - HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: Domain = corp.mphasis.com
O17 - HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: Domain = corp.mphasis.com
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: Domain = corp.mphasis.com
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - Winlogon Notify: winqsc32 - C:\WINDOWS\system32\winqsc32.dll
O20 - Winlogon Notify: yayaAroN - C:\WINDOWS\system32\yayaAroN.dll
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - McAfee, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\winvnc4.exe


--
End of file - 8080 bytes

-- File Associations -----------------------------------------------------------

.scr - scrfile - shell\open\command - "%1" %*


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 NaiAvTdi1 - c:\windows\system32\drivers\mvstdi5x.sys <Not Verified; McAfee Inc.; VirusScan>
R3 EntDrv51 - c:\windows\system32\drivers\entdrv51.sys <Not Verified; McAfee, Inc; VirusScan>
R3 NaiAvFilter1 - c:\windows\system32\drivers\naiavf5x.sys <Not Verified; McAfee Inc.; VirusScan>

S1 LMImirr - c:\windows\system32\drivers\lmimirr.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 McAfeeFramework (McAfee Framework Service) - "c:\program files\network associates\common framework\frameworkservice.exe" /servicestart <Not Verified; Network Associates, Inc.; McAfee Common Framework>
R2 McTaskManager (Network Associates Task Manager) - "c:\program files\network associates\virusscan\vstskmgr.exe" <Not Verified; Network Associates, Inc.; VirusScan Enterprise>
R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-05-28 12:52:37 264 --a------ C:\WINDOWS\Tasks\OGALogon.job
2008-05-28 12:39:02 264 --a------ C:\WINDOWS\Tasks\OGADaily.job


-- Files created between 2008-04-28 and 2008-05-28 -----------------------------

2008-05-27 20:14:06 2667 --a------ C:\WINDOWS\system32\hfdsvfvf.exe
2008-05-27 20:08:05 115712 --a------ C:\WINDOWS\system32\cypvshlg.dll
2008-05-27 20:05:06 126976 --a------ C:\WINDOWS\system32\rkqhcmye.dll
2008-05-27 16:04:53 2462 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-26 21:28:58 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-26 21:28:42 0 d-------- C:\Documents and Settings\admin.BK2B1F-2123D\Application Data\Mozilla
2008-05-26 20:09:24 116736 --a------ C:\WINDOWS\system32\dxmkquam.dll
2008-05-26 20:06:33 2667 --a------ C:\WINDOWS\system32\iamvcsgo.exe
2008-05-26 20:02:25 134144 --a------ C:\WINDOWS\system32\eiyvhsel.dll
2008-05-26 20:02:07 124928 --a------ C:\WINDOWS\system32\svyisvsn.dll
2008-05-26 20:01:26 277748 --ahs---- C:\WINDOWS\system32\psrXIRqr.ini2
2008-05-26 20:01:11 371200 --a------ C:\WINDOWS\system32\rqRIXrsp.dll
2008-05-26 14:27:19 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-25 22:10:22 115712 --a------ C:\WINDOWS\system32\oslhjalb.dll
2008-05-25 22:07:22 2667 --a------ C:\WINDOWS\system32\bgasggpo.exe
2008-05-25 22:04:22 136704 --a------ C:\WINDOWS\system32\usreapig.dll
2008-05-24 22:10:22 2667 --a------ C:\WINDOWS\system32\halxpsjd.exe
2008-05-24 22:04:22 136192 --a------ C:\WINDOWS\system32\vatlugqn.dll
2008-05-24 22:01:22 126464 --a------ C:\WINDOWS\system32\fiynvsgo.dll
2008-05-23 22:35:20 0 d-------- C:\Documents and Settings\admin.BK2B1F-2123D\Application Data\Lavasoft
2008-05-23 22:20:40 0 d--h----- C:\WINDOWS\PIF
2008-05-23 22:17:18 136192 --a------ C:\WINDOWS\system32\fokpqfyp.dll
2008-05-23 22:00:57 2667 --a------ C:\WINDOWS\system32\ajdxdawf.exe
2008-05-23 22:00:35 125952 --a------ C:\WINDOWS\system32\rxdoaose.dll
2008-05-23 21:48:03 2667 --a------ C:\WINDOWS\system32\ndgugrqc.exe
2008-05-23 21:45:39 136192 --a------ C:\WINDOWS\system32\yduwndab.dll
2008-05-23 21:42:04 114176 --a------ C:\WINDOWS\system32\kcgofwie.dll
2008-05-23 21:40:51 125952 --a------ C:\WINDOWS\system32\kknkrlno.dll
2008-05-23 21:37:00 0 d-------- C:\Program Files\QuickTime
2008-05-22 12:49:58 0 d-------- C:\WINDOWS\pss
2008-05-21 17:30:07 6815744 --a------ C:\Documents and Settings\karthikeyan.j\ntuser.dat
2008-05-21 17:29:50 322359 --ahs---- C:\WINDOWS\system32\VFeLRXyb.ini2
2008-05-21 17:24:55 27648 --a------ C:\WINDOWS\system32\winqsc32.dll
2008-05-21 17:24:33 58880 --a------ C:\WINDOWS\system32\jkkJccCS.dll
2008-05-21 17:24:23 58880 --a------ C:\WINDOWS\system32\yayaAroN.dll
2008-05-21 17:24:20 0 d-------- C:\Documents and Settings\karthikeyan.j\Application Data\WinRAR
2008-05-08 18:10:40 0 d-------- C:\Program Files\Microsoft Office Communicator


-- Find3M Report ---------------------------------------------------------------

2008-05-22 12:44:58 0 d-------- C:\Program Files\Online Services
2008-05-21 12:37:23 0 d-------- C:\Documents and Settings\karthikeyan.j\Application Data\messages


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0BE44D33-B341-4655-B70A-3306BFB10C9B}]
05/26/2008 08:01 PM 371200 --a------ C:\WINDOWS\system32\rqRIXrsp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0CF5D165-517E-48B6-B3C7-3054A24F8BF6}]
05/21/2008 05:24 PM 58880 --a------ C:\WINDOWS\system32\yayaAroN.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{505F7312-6AE3-4250-86F5-46A82AEB8663}]
C:\WINDOWS\system32\byXRLeFV.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [09/20/2005 10:35 AM]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [09/20/2005 10:32 AM]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [09/20/2005 10:36 AM]
"DrvLsnr"="C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe" [05/08/2003 11:34 AM]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [09/22/2004 08:00 AM]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [09/27/2005 03:06 AM]
"Network Associates Error Reporting Service"="C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" [10/07/2003 09:48 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 09:54 PM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 05:30 PM]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

C:\Documents and Settings\karthikeyan.j\Start Menu\Programs\Startup\
qlock.lnk - C:\Program Files\Qlock\qlock.exe [4/20/2006 8:44:12 AM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [12/14/2004 4:44:06 AM]
MetaFrame Password Manager Agent Background Process.lnk - C:\Program Files\Citrix\MetaFrame Password Manager\ssoShell.exe [6/14/2005 6:48:22 PM]
Program Neighborhood Agent.lnk - C:\Program Files\Citrix\ICA Client\pnagent.exe [4/4/2005 2:44:48 AM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{0CF5D165-517E-48B6-B3C7-3054A24F8BF6}"= C:\WINDOWS\system32\yayaAroN.dll [05/21/2008 05:24 PM 58880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winqsc32]
winqsc32.dll 05/21/2008 05:24 PM 27648 C:\WINDOWS\system32\winqsc32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayaAroN]
yayaAroN.dll 05/21/2008 05:24 PM 58880 C:\WINDOWS\system32\yayaAroN.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\rqRIXrsp

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1079576523-3858123565-1909679915-107975\Scripts\Logon\0\0]
"Script"=avupdate.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1079576523-3858123565-1909679915-107975\Scripts\Logon\1\0]
"Script"=avupdate.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1079576523-3858123565-1909679915-114422\Scripts\Logon\0\0]
"Script"=avupdate.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1079576523-3858123565-1909679915-114422\Scripts\Logon\1\0]
"Script"=avupdate.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1079576523-3858123565-1909679915-42586\Scripts\Logon\0\0]
"Script"=avupdate.bat


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##172.20.33.221#CD Drive (F)]
AutoRun\command- Z:\SETUP.EXE /AUTORUN
configure\command- Z:\SETUP.EXE
install\command- Z:\SETUP.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b31dcde7-1049-11dd-9bc9-001185169848}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif




-- End of Deckard's System Scanner: finished at 2008-05-28 14:10:13 ------------





Regards
Karthik

BC AdBot (Login to Remove)

 


m

#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:09:08 PM

Posted 28 May 2008 - 01:28 PM

Hello karthik_arnold1,

Welcome to Bleeping Computer :thumbsup:

Since my machine is in corporate network online scan is blocked by the firewall

This really should be handled by your IT guys. I have no idea what company policy is, and I don't want to risk going against it in some way.

Regards,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:09:08 PM

Posted 15 June 2008 - 02:48 PM

Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users