Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

winlognn, trojans, notepad.exe errors, and ransomware


  • This topic is locked This topic is locked
2 replies to this topic

#1 thejam

thejam

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:09:59 PM

Posted 20 February 2009 - 05:01 PM

Reports of Trojans from my virus checker, malware, ransomware.
Getting errors before opening notepad.exe and most other common windows executables.
Most Anti-Malware programms cannot be installed or just won't start.

Thanks for the help guys! You are always awesome!

Posted Image





DDS (Ver_09-02-01.01) - NTFSx86

Run by theJam at 15:52:13.53 on Fri 02/20/2009

Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1546 [GMT -6:00]





============== Running Processes ===============



C:\WINDOWS\system32\ibmpmsvc.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

C:\WINDOWS\system32\svchost -k rpcss

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\svchost.exe -k NetworkService

C:\WINDOWS\system32\svchost.exe -k LocalService

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe

C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE

C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe

C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe

C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\WINDOWS\system32\acs.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\DNA\btdna.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\xampp\apache\bin\apache.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe

C:\xampp\apache\bin\apache.exe

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\xampp\mysql\bin\mysqld.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe

C:\WINDOWS\system32\TpKmpSVC.exe

C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe

c:\program files\lenovo\system update\suservice.exe

C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\System32\alg.exe

C:\DOCUME~1\theJam\LOCALS~1\Temp\fgq31r334.exe

C:\Documents and Settings\theJam\Desktop\dds.scr

C:\WINDOWS\system32\wbem\wmiprvse.exe



============== Pseudo HJT Report ===============



uSearch Page = hxxp://www.google.com

uSearch Bar = hxxp://www.google.com/ie

uDefault_Search_URL = hxxp://www.google.com/ie

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

uInternet Settings,ProxyOverride = *.local

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

BHO: c:\windows\system32\hs78344kjkfd.dll: {c5bf49a2-94f3-42bd-f434-3604812c8955} - c:\windows\system32\hs78344kjkfd.dll

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"

uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun

uRun: [SmitFraudFixTool] c:\program files\smitfraudfixtool\SmitFraudFixTool.exe -boot

uRun: [bbsn5evszpqmf8vi3ydy0tansjrnhxuhkj3h8c9zz5ejz] c:\docume~1\thejam\locals~1\temp\lpu0d6s82rn.exe

uRun: [w6kxypwvltr2b1cu6jxc7e] c:\docume~1\thejam\locals~1\temp\mpm76bum9r15.exe

uRun: [fjzd99m7nzxm7hykgctjq65e8774q4gknl12xulc6591jcj5] c:\docume~1\thejam\locals~1\temp\yymx9l.exe

uRun: [r9fzmeb0j3glsawyq] c:\docume~1\thejam\locals~1\temp\rdl9rs3.exe

uRun: [cbph5sbe9tnj2yca542se81wpcv] c:\docume~1\thejam\locals~1\temp\qlci92g2f04b.exe

uRun: [k3y67ni8thuoho4bumr8loldmiclhkt1t5j0lyp0chxulj9ql4] c:\docume~1\thejam\locals~1\temp\bipi9u.exe

uRun: [d8qsm679vf8x6nqi5i6i3js3d4ot9oxq] c:\docume~1\thejam\locals~1\temp\pa6nuis1.exe

uRun: [h0id8bj8z3wwznpetindupa2gnfys8] c:\docume~1\thejam\locals~1\temp\d83twpkfpw87.exe

uRun: [ec4idwrvvd02v3rrewc1lepz1q1u6py3] c:\docume~1\thejam\locals~1\temp\vaq4965mpom2j.exe

uRun: [uf5knkf141u146rmj] c:\docume~1\thejam\locals~1\temp\ocwrtj.exe

uRun: [ri3hnffsi6upk99k03071u7l3] c:\docume~1\thejam\locals~1\temp\wgt1y0.exe

uRun: [gcq4luzckfhymkhzfnsahywg4y] c:\docume~1\thejam\locals~1\temp\c5au59vqbtc.exe

uRun: [rno12qxje3q0g67abgokgf2wsltavna5c5fbjw9ldwhwknsymk] c:\docume~1\thejam\locals~1\temp\ub0ag87pnoa.exe

uRun: [igxp7z0bmw4x5ps8ls22k28nwoq6] c:\docume~1\thejam\locals~1\temp\dpg4p29e.exe

uRun: [m68aiyn9cvets8j1b8it4rum4m4ekg] c:\docume~1\thejam\locals~1\temp\nmu0bqqg2.exe

uRun: [v5kry1i6j] c:\docume~1\thejam\locals~1\temp\h2tdqbu.exe

uRun: [chtn3y41dot6qfm4n099e] c:\docume~1\thejam\locals~1\temp\fgq31r334.exe

uRun: [iak7bn7xxdgc9cp] c:\docume~1\thejam\locals~1\temp\ounxa2.exe

mRun: [TVT Scheduler Proxy] c:\program files\common files\lenovo\scheduler\scheduler_proxy.exe

mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe

mRun: [TPHOTKEY] c:\progra~1\lenovo\pkgmgr\hotkey\TPHKMGR.exe

mRun: [TPKMAPHELPER] c:\program files\thinkpad\utilities\TpKmapAp.exe -helper

mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe

mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray

mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe

mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"

mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"

mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime

mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"

mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin

mRun: [jsf8uiw3jnjgffght] c:\windows\temp\winlognn.exe

mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

mRun: [Vyequsobogiseyit] rundll32.exe "c:\windows\Pzihobawuti.dll",e

mRun: [Xvetiyogovitog] rundll32.exe "c:\windows\ifeyopogicabenuw.dll",e

mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto

mRun: [SNM] c:\program files\spynomore\SNM.exe /startup

StartupFolder: c:\docume~1\thejam\startm~1\programs\startup\ccc.lnk - c:\program files\ati technologies\ati.ace\core-static\CCC.exe

uPolicies-explorer: NoFolderOptions = 1 (0x1)

uPolicies-system: DisableRegistryTools = 1 (0x1)

IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

Notify: !saswinlogon - c:\program files\superantispyware\SASWINLO.dll

Notify: ACNotify - ACNotify.dll

Notify: AtiExtEvent - Ati2evxx.dll

Notify: psfus - c:\program files\thinkvantage fingerprint software\psqlpwd.dll

Notify: tpfnf2 - notifyf2.dll

Notify: tphotkey - tphklock.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

STS: c:\windows\system32\hs78344kjkfd.dll: {c5bf49a2-94f3-42bd-f434-3604812c8955} - c:\windows\system32\hs78344kjkfd.dll

SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

LSA: Notification Packages = scecli ACGina c:\program files\thinkvantage fingerprint software\psqlpwd.dll



================= FIREFOX ===================



FF - ProfilePath - c:\docume~1\thejam\applic~1\mozilla\firefox\profiles\irqd4ci1.default\

FF - component: c:\documents and settings\thejam\application data\mozilla\firefox\profiles\irqd4ci1.default\extensions\piclens@cooliris.com\components\coolirisstub.dll

FF - plugin: c:\program files\google\google earth plugin\npgeplugin.dll

FF - plugin: c:\program files\google\google updater\2.4.1439.6872\npCIDetect13.dll

FF - plugin: c:\program files\google\picasa3\npPicasa2.dll

FF - plugin: c:\program files\google\picasa3\npPicasa3.dll

FF - plugin: c:\program files\google\update\1.2.141.5\npGoogleOneClick7.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll

FF - HiddenExtension: XUL Cache: {13317846-E24E-4DD7-AFA0-9E0B8CECBA84} - c:\documents and settings\thejam\local settings\application data\{13317846-E24E-4DD7-AFA0-9E0B8CECBA84}



============= SERVICES / DRIVERS ===============



R0 TPDiskPM;TPDiskPM;c:\windows\system32\drivers\TPDiskPM.sys [2009-1-13 14848]

R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2009-1-21 11520]

R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.sys [2009-1-21 4224]

R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\apache.exe [2008-12-9 24636]

R2 smihlp;SMI Helper Driver (smihlp);c:\program files\common files\thinkvantage fingerprint software\drivers\smihlp.sys [2008-11-21 12560]

R3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2009-1-14 40840]

R3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2009-1-14 66952]

R3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2009-1-14 81288]

R3 TPInput;TPInput;c:\windows\system32\drivers\TPInput.sys [2009-1-13 6528]

R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [2009-1-13 57344]

S2 gupdate1c976ca83575a82;Google Update Service (gupdate1c976ca83575a82);c:\program files\google\update\GoogleUpdate.exe [2009-1-14 133104]

S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-1-14 356920]

S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-1-14 1079176]



=============== Created Last 30 ================



2009-02-20 14:21 <DIR> --d----- c:\program files\Trend Micro

2009-02-20 13:42 664 a------- c:\windows\system32\d3d9caps.dat

2009-02-20 13:16 1,152 a------- c:\windows\system32\windrv.sys

2009-02-20 13:16 <DIR> --d----- c:\program files\common files\Download Manager

2009-02-20 12:46 <DIR> --d----- c:\docume~1\thejam\applic~1\SmitFraudFixTool

2009-02-20 12:46 <DIR> --d----- c:\program files\SmitFraudFixTool

2009-02-20 12:38 <DIR> --d----- c:\program files\SUPERAntiSpyware

2009-02-20 12:38 <DIR> --d----- c:\docume~1\thejam\applic~1\SUPERAntiSpyware.com

2009-02-20 12:37 <DIR> --d----- c:\program files\common files\Wise Installation Wizard

2009-02-20 12:23 <DIR> --d----- c:\windows\pss

2009-02-20 11:41 132,608 a------- c:\windows\ifeyopogicabenuw.dll

2009-02-20 10:58 19,456 a------- C:\isolr.exe

2009-02-20 10:58 1,347 a------- c:\windows\system32\ahtn.htm

2009-02-20 10:58 81,920 a------- C:\hcikwnrx.exe

2009-02-20 10:58 4,785 a------- c:\windows\system32\warning.gif

2009-02-20 10:58 100,590 a------- c:\windows\system32\drivers\4aadffcc.sys

2009-02-20 10:58 439 a------- c:\windows\system32\win32hlp.cnf

2009-02-20 10:58 2 a------- C:\2082816886

2009-02-20 10:58 27,136 a------- C:\edadvna.exe

2009-02-20 10:58 54,272 a------- C:\hqxdf.exe

2009-02-20 10:58 15,000 a------- c:\windows\system32\hs78344kjkfd.dll

2009-02-20 10:57 39,936 a------- c:\windows\Pzihobawuti.dll

2009-02-20 10:57 39,936 a------- C:\vvmmh.exe

2009-02-20 00:49 <DIR> --d----- c:\program files\BitTorrent

2009-02-17 19:34 <DIR> --d----- c:\program files\common files\Macrovision Shared

2009-02-10 13:58 <DIR> --d----- C:\xampp

2009-02-10 13:05 <DIR> --d----- c:\program files\PHP

2009-02-10 13:04 <DIR> --d----- c:\program files\Apache Software Foundation

2009-02-04 19:07 662,288 a------- c:\windows\system32\MSCOMCT2.OCX

2009-02-04 19:07 137,000 a------- c:\windows\system32\MSMAPI32.OCX

2009-02-04 19:07 116,224 a------- c:\windows\system32\pdfcmnnt.dll

2009-02-04 19:07 23,552 a------- c:\windows\system32\MSMPIDE.DLL

2009-02-04 19:07 <DIR> --d----- c:\program files\PDFCreator

2009-02-04 16:13 <DIR> --d----- c:\program files\WinSCP

2009-02-01 01:46 107,368 a------- c:\windows\system32\GEARAspi.dll

2009-02-01 01:46 15,464 a------- c:\windows\system32\drivers\GEARAspiWDM.sys

2009-02-01 01:46 <DIR> --d----- c:\program files\iPod

2009-02-01 01:46 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2009-02-01 01:46 <DIR> --d----- c:\program files\iTunes

2009-02-01 01:46 <DIR> --d----- c:\program files\Bonjour

2009-02-01 01:44 32,000 a------- c:\windows\system32\drivers\usbaapl.sys

2009-01-29 14:13 221,184 a------- c:\windows\system32\wmpns.dll

2009-01-29 14:13 <DIR> --d----- c:\program files\Windows Media Connect 2

2009-01-29 14:12 <DIR> --d----- c:\windows\system32\LogFiles

2009-01-29 10:59 <DIR> --d----- c:\windows\system32\appmgmt

2009-01-24 23:40 410,984 a------- c:\windows\system32\deploytk.dll

2009-01-24 23:40 73,728 a------- c:\windows\system32\javacpl.cpl

2009-01-23 09:04 <DIR> --d----- c:\program files\Microsoft Visual Studio 8

2009-01-23 09:04 <DIR> --d----- c:\windows\SHELLNEW



==================== Find3M ====================



2009-02-20 10:58 104,960 a------- c:\windows\system32\userinit.exe

2009-01-21 13:56 717,296 a------- c:\windows\system32\drivers\sptd.sys

2009-01-21 12:42 30,144 a------- c:\windows\system32\drivers\psadd.sys

2009-01-15 22:55 12,736 a---h--- c:\windows\system32\mlfcache.dat

2009-01-15 16:06 81,288 a------- c:\windows\system32\drivers\iksyssec.sys

2009-01-15 16:06 66,952 a------- c:\windows\system32\drivers\iksysflt.sys

2009-01-15 16:06 40,840 a------- c:\windows\system32\drivers\ikfilesec.sys

2009-01-14 22:48 32 a------- c:\docume~1\alluse~1\applic~1\ezsid.dat

2009-01-14 18:58 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat

2009-01-13 19:07 0 a---hr-- c:\windows\system32\drivers\IBM_2668_WXE_TP.MRK

2009-01-13 19:05 2,086 a------- c:\windows\system32\SMBIOS.bin

2009-01-13 17:29 21,640 a------- c:\windows\system32\emptyregdb.dat

2009-01-05 16:33 3,751,995 a------- c:\windows\system32\GPhotos.scr

2008-12-20 17:15 826,368 a------- c:\windows\system32\wininet.dll

2008-12-10 18:33 200,704 a------- c:\windows\system32\dtu100.dll

2008-12-10 18:33 86,016 a------- c:\windows\system32\dpl100.dll

2008-12-08 20:28 593,920 a------- c:\windows\system32\dpuGUI11.dll

2008-12-08 20:28 344,064 a------- c:\windows\system32\dpus11.dll

2008-12-08 20:28 294,912 a------- c:\windows\system32\dpu11.dll

2008-12-08 20:28 57,344 a------- c:\windows\system32\dpv11.dll



============= FINISH: 15:52:53.37 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 sundavis

sundavis

  • Malware Response Team
  • 2,708 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:10:59 PM

Posted 22 February 2009 - 11:19 PM

Hi,

Welcome to BleepingComputer HijackThis Logs and Malware Removal,thejam. :thumbup2:
My name is sundavis, I will be helping you to deal with your Malware problems today.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times. and we are trying our best to keep up.
In the meantime, please refrain from making any changes to your computer, and please do in the following:

Step1
  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
Step2

Please download GMER Rootkit Scanner from Here or Here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish. For more info, go to Here for your reference.
  • Once done click on the [Save..] button, and in the File name area, type in "GRS.txt" , and copy and paste the contents in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries


In your next reply, please post back:

1.RSIT log.txt and info.txt.
2.GRS.txt

If you have problems to run exe file, Please right click exe file, select rename, change the .exe extention to .com and run it.

Make sure you have unchecked "Word Wrap" under format menu in your text file. While posting the logs, please press Preview Post button to ensure the format is right, then press Add Reply. Thanks.

#3 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:10:59 PM

Posted 27 February 2009 - 05:28 AM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users