Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HijackThis Log: Please Help Diagnose


  • Please log in to reply
1 reply to this topic

#1 edbarbie

edbarbie

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:03:46 AM

Posted 13 May 2005 - 10:49 AM

Logfile of HijackThis v1.99.1
Scan saved at 11:41:25 AM, on 5/13/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...B_PVER}&ar=home
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O1 - Hosts: com
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\plg0\cxtpls.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CATLEvents Object - {18722863-6D1D-4300-BF29-406948EDA7CB} - C:\DOCUME~1\MARY~1.LYM\LOCALS~1\Temp\bdtac.dat
O2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\MARY~1.LYM\LOCALS~1\Temp\nurgepj.dat
O2 - BHO: CATLEvents Object - {446CF8A5-617E-4D91-95AE-AE78CE0D06AF} - C:\DOCUME~1\MARY~1.LYM\LOCALS~1\Temp\ofnilitu.dat (file missing)
O2 - BHO: CATLEvents Object - {44E5B409-35A2-4E8D-BF94-344222323A53} - C:\DOCUME~1\MARY~1.LYM\LOCALS~1\Temp\vrsteni.dat
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: CATLEvents Object - {ED5ABC42-8E4F-4C39-9972-F0CF619D672F} - C:\DOCUME~1\MARY~1.LYM\LOCALS~1\Temp\ptfsmw.dat (file missing)
O2 - BHO: (no name) - {EEBB54B3-B425-93D7-7031-BCA930ED5B9B} - C:\WINNT\system32\ieag.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [vptray] C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [WeatherOnTray] C:\Program Files\Hotbar\bin\4.4.6.0\WeatherOnTray.exe
O4 - HKLM\..\Run: [SysUpd] C:\WINNT\sysupd.exe
O4 - HKLM\..\Run: [utilodbc] C:\WINNT\system32\Com\utilodbc.exe
O4 - HKLM\..\Run: [cabs] C:\WINNT\Driver Cache\cabs.exe
O4 - HKLM\..\Run: [playcat] C:\WINNT\inf\playcat.exe
O4 - HKLM\..\Run: [acbak] C:\WINNT\system32\spool\acbak.exe
O4 - HKLM\..\Run: [smp3] C:\WINNT\Config\smp3.exe
O4 - HKLM\..\Run: [jpegrun] C:\WINNT\Tasks\jpegrun.exe
O4 - HKLM\..\Run: [nutsvr] C:\WINNT\Config\nutsvr.exe
O4 - HKLM\..\Run: [*smp3] C:\WINNT\Config\smp3.exe
O4 - HKLM\..\Run: [*utilodbc] C:\WINNT\system32\Com\utilodbc.exe
O4 - HKLM\..\Run: [*mainun] C:\WINNT\Driver Cache\mainun.exe
O4 - HKLM\..\Run: [*dbip] C:\WINNT\Windows Update Setup Files\dbip.exe
O4 - HKLM\..\Run: [*vgacat] C:\WINNT\msagent\chars\vgacat.exe
O4 - HKLM\..\Run: [*fontip] C:\WINNT\Help\fontip.exe
O4 - HKLM\..\Run: [*dnshard] C:\WINNT\Fonts\dnshard.exe
O4 - HKLM\..\Run: [*vgasvr] C:\WINNT\repair\vgasvr.exe
O4 - HKLM\..\Run: [*runcr] C:\WINNT\addins\runcr.exe
O4 - HKLM\..\Run: [*rasbas] C:\WINNT\Windows Update Setup Files\rasbas.exe
O4 - HKLM\..\Run: [*tcpav] C:\WINNT\Driver Cache\tcpav.exe
O4 - HKLM\..\Run: [*svctask] C:\WINNT\security\Database\svctask.exe
O4 - HKLM\..\Run: [*inetsrv] C:\WINNT\Windows Update Setup Files\inetsrv.exe
O4 - HKLM\..\Run: [*dvdbas] C:\WINNT\msagent\dvdbas.exe
O4 - HKLM\..\Run: [*mcrun] C:\WINNT\Driver Cache\mcrun.exe
O4 - HKLM\..\Run: [*rasdisk] C:\WINNT\msagent\chars\rasdisk.exe
O4 - HKLM\..\Run: [*rundns] C:\WINNT\Tasks\rundns.exe
O4 - HKLM\..\Run: [*logc] C:\WINNT\security\Database\logc.exe
O4 - HKLM\..\Run: [*wmssvc] C:\WINNT\Fonts\wmssvc.exe
O4 - HKLM\..\Run: [*doceula] C:\WINNT\Driver Cache\doceula.exe
O4 - HKLM\..\Run: [*fontrun] C:\WINNT\Config\fontrun.exe
O4 - HKLM\..\Run: [*dnsfont] C:\WINNT\inf\dnsfont.exe
O4 - HKLM\..\Run: [*imgvga] C:\WINNT\Fonts\imgvga.exe
O4 - HKLM\..\Run: [*acmfc] C:\WINNT\Tasks\acmfc.exe
O4 - HKLM\..\Run: [*fontdll] C:\WINNT\security\Database\fontdll.exe
O4 - HKLM\..\Run: [*cmd] C:\WINNT\Windows Update Setup Files\cmd.exe
O4 - HKLM\..\Run: [*imgdb] C:\WINNT\Fonts\imgdb.exe
O4 - HKLM\..\Run: [*apmc] C:\WINNT\Fonts\apmc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [pkbux] C:\WINNT\pkbux.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [rF8V3pi] iepclr40.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Xajuffc] C:\WINNT\system32\w?nlogon.exe
O4 - HKCU\..\Run: [aor9RfGnP] ie4rscs.exe
O4 - HKCU\..\Run: [atkctrs] C:\WINNT\system32\atkctrs.exe
O4 - HKCU\..\Run: [Utip] C:\Documents and Settings\mary.LYMEPROPERTIES\Application Data\aecr.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Startup: Monitor My eRooms.lnk = C:\Program Files\eRoom 6\ERClient.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {E876D003-BCDE-11D3-9131-000094B61529} (ERPageAddin Class) - https://extranet.piperrudnick.com/eroomsetup/client.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = lymeproperties.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = lymeproperties.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = lymeproperties.com
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O20 - Winlogon Notify: PCANotify - C:\WINNT\SYSTEM32\PCANotify.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: WebSeach Toolbar support NT service (TBPSSvc) - Unknown owner - C:\PROGRA~1\Toolbar\TBPSSvc.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe

BC AdBot (Login to Remove)

 


#2 bricat

bricat

  • Members
  • 205 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:46 AM

Posted 14 May 2005 - 06:54 AM

Welcome to the Bleeping computer forum.:thumbsup:


Click Start > Run > type services.msc, then click OK
Scroll down and right click on 'WebSeach Toolbar support'and "WinTools for IE service"
"Select 'Properties' and set the "Service Status" option to "Stop" on both of these.
Set "Startup type" to "Disabled", click Apply, then OK.


Rerun HJT,and put a tick beside these :-



R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...er=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...B_PVER}&ar=home
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O1 - Hosts: com
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\plg0\cxtpls.dll
O2 - BHO: CATLEvents Object - {18722863-6D1D-4300-BF29-406948EDA7CB} - C:\DOCUME~1\MARY~1.LYM\LOCALS~1\Temp\bdtac.dat
O2 - BHO: CATLEvents Object - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\DOCUME~1\MARY~1.LYM\LOCALS~1\Temp\nurgepj.dat
O2 - BHO: CATLEvents Object - {446CF8A5-617E-4D91-95AE-AE78CE0D06AF} - C:\DOCUME~1\MARY~1.LYM\LOCALS~1\Temp\ofnilitu.dat (file missing)
O2 - BHO: CATLEvents Object - {44E5B409-35A2-4E8D-BF94-344222323A53} - C:\DOCUME~1\MARY~1.LYM\LOCALS~1\Temp\vrsteni.dat
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: CATLEvents Object - {ED5ABC42-8E4F-4C39-9972-F0CF619D672F} - C:\DOCUME~1\MARY~1.LYM\LOCALS~1\Temp\ptfsmw.dat (file missing)
O2 - BHO: (no name) - {EEBB54B3-B425-93D7-7031-BCA930ED5B9B} - C:\WINNT\system32\ieag.dll
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [SysUpd] C:\WINNT\sysupd.exe
O4 - HKLM\..\Run: [utilodbc] C:\WINNT\system32\Com\utilodbc.exe
O4 - HKLM\..\Run: [cabs] C:\WINNT\Driver Cache\cabs.exe
O4 - HKLM\..\Run: [playcat] C:\WINNT\inf\playcat.exe
O4 - HKLM\..\Run: [acbak] C:\WINNT\system32\spool\acbak.exe
O4 - HKLM\..\Run: [smp3] C:\WINNT\Config\smp3.exe
O4 - HKLM\..\Run: [jpegrun] C:\WINNT\Tasks\jpegrun.exe
O4 - HKLM\..\Run: [nutsvr] C:\WINNT\Config\nutsvr.exe
O4 - HKLM\..\Run: [*smp3] C:\WINNT\Config\smp3.exe
O4 - HKLM\..\Run: [*utilodbc] C:\WINNT\system32\Com\utilodbc.exe
O4 - HKLM\..\Run: [*mainun] C:\WINNT\Driver Cache\mainun.exe
O4 - HKLM\..\Run: [*dbip] C:\WINNT\Windows Update Setup Files\dbip.exe
O4 - HKLM\..\Run: [*vgacat] C:\WINNT\msagent\chars\vgacat.exe
O4 - HKLM\..\Run: [*fontip] C:\WINNT\Help\fontip.exe
O4 - HKLM\..\Run: [*dnshard] C:\WINNT\Fonts\dnshard.exe
O4 - HKLM\..\Run: [*vgasvr] C:\WINNT\repair\vgasvr.exe
O4 - HKLM\..\Run: [*runcr] C:\WINNT\addins\runcr.exe
O4 - HKLM\..\Run: [*rasbas] C:\WINNT\Windows Update Setup Files\rasbas.exe
O4 - HKLM\..\Run: [*tcpav] C:\WINNT\Driver Cache\tcpav.exe
O4 - HKLM\..\Run: [*svctask] C:\WINNT\security\Database\svctask.exe
O4 - HKLM\..\Run: [*inetsrv] C:\WINNT\Windows Update Setup Files\inetsrv.exe
O4 - HKLM\..\Run: [*dvdbas] C:\WINNT\msagent\dvdbas.exe
O4 - HKLM\..\Run: [*mcrun] C:\WINNT\Driver Cache\mcrun.exe
O4 - HKLM\..\Run: [*rasdisk] C:\WINNT\msagent\chars\rasdisk.exe
O4 - HKLM\..\Run: [*rundns] C:\WINNT\Tasks\rundns.exe
O4 - HKLM\..\Run: [*logc] C:\WINNT\security\Database\logc.exe
O4 - HKLM\..\Run: [*wmssvc] C:\WINNT\Fonts\wmssvc.exe
O4 - HKLM\..\Run: [*doceula] C:\WINNT\Driver Cache\doceula.exe
O4 - HKLM\..\Run: [*fontrun] C:\WINNT\Config\fontrun.exe
O4 - HKLM\..\Run: [*dnsfont] C:\WINNT\inf\dnsfont.exe
O4 - HKLM\..\Run: [*imgvga] C:\WINNT\Fonts\imgvga.exe
O4 - HKLM\..\Run: [*acmfc] C:\WINNT\Tasks\acmfc.exe
O4 - HKLM\..\Run: [*fontdll] C:\WINNT\security\Database\fontdll.exe
O4 - HKLM\..\Run: [*cmd] C:\WINNT\Windows Update Setup Files\cmd.exe
O4 - HKLM\..\Run: [*imgdb] C:\WINNT\Fonts\imgdb.exe
O4 - HKLM\..\Run: [*apmc] C:\WINNT\Fonts\apmc.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [pkbux] C:\WINNT\pkbux.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [rF8V3pi] iepclr40.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKCU\..\Run: [Xajuffc] C:\WINNT\system32\w?nlogon.exe
O4 - HKCU\..\Run: [aor9RfGnP] ie4rscs.exe
O4 - HKCU\..\Run: [atkctrs] C:\WINNT\system32\atkctrs.exe
O4 - HKCU\..\Run: [Utip] C:\Documents and Settings\mary.LYMEPROPERTIES\Application Data\aecr.exe
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
O23 - Service: WebSeach Toolbar support NT service (TBPSSvc) - Unknown owner - C:\PROGRA~1\Toolbar\TBPSSvc.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe


now close all windows and browsers and click FIX CHECKED



Then boot up in SAFE MODE

Then navigate to and delete these files\folders in BOLD

C:\WINNT\sysupd.exe << This file
C:\PROGRAM FILES\Toolbar << This folder
C:\Program Files\CxtPls<< This folder.
C:\PROGRAM FILES\COMMON FILES\WinTools << This folder


Then boot up normally


This process will clean out your Temp files and your Temporary Internet Files. Please do both steps:

Step 1:Delete Temp Files
To clean out your temp files, click on Start and then run, and type %temp% and press the ok button.

This should open up the temp directory that your machine uses. Please delete all files that are found there. If you get an error when deleting a file, skip that file and delete all the others. If you had trouble deleting a file, reboot into Safe Mode and follow this step again. You should now be able to delete all the files.

Step 2: Delete Temporary Internet Files
Now I want you to open up Internet Explorer, and click on the Tools menu and then Internet Options. At the General tab, which should be the first tab you are currently on, click on the Delete Files button and put a checkmark in Delete offline content. Then press the OK button. This may take quite a while, so do not be alarmed with how long it takes. When it is done, your Temporary Internet Files will now be deleted.


run two online virus scans from any of the following locations :-

http://www.kaspersky.com/beta?product=161744315 KASPERSKY
http://www.ravantivirus.com/scan/ - RAV
http://www.bitdefender.com/scan/licence.php - BitDefender
(If using Kasperskey, please empty the quarantine sections of any AV or Anti-Spyware programs you have installed before running the scan.)




then reboot and post a fresh Hijackthis log.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users