Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Unknown malware


  • This topic is locked This topic is locked
2 replies to this topic

#1 bbeeler

bbeeler

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Location:Austin, TX
  • Local time:05:52 PM

Posted 01 May 2009 - 11:57 AM

Computer was running very slow. Ran spybot search & destroy. Got a hit during the scan on SDRA64.exe as a virus and on virtumonde. Antivirus couldn't cure & spybot couldn't completely clean. Ran it in safe mode and it appeared to clean virtumonde. Ran HijackThis and found an odd dll, hbnoadq.dll. I can't find anything on it. Everytime you delete it, it immediately reappears. I find it in windows\system32 and in the registry. I suspect it is malware.


DDS (Ver_09-03-16.01) - FAT32x86
Run by bpbeeler at 11:28:52.43 on Fri 05/01/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.108 [GMT -5:00]

FW: COMODO Firewall *enabled*

============== Running Processes ===============

C:\Program Files\Common Files\Virtual Token\vtserver.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\RunDll32.exe
svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\TpKmpSVC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\bpbeeler\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
mWinlogon: System=ziswin.exe
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: : {6b984262-e24e-4443-b3e3-c4209d8fe64d} - c:\windows\system32\hbnoadq.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\MMonitor.exe"
mRun: [<NO NAME>]
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [QCWLICON] c:\program files\thinkpad\connectutilities\QCWLICON.EXE
mRun: [Realtime Monitor] c:\progra~1\ca\etrust~1\realmon.exe -s
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [TP4EX] tp4ex.exe
mRun: [TPHOTKEY] c:\progra~1\thinkpad\pkgmgr\hotkey\TPHKMGR.exe
mRun: [TPKMAPHELPER] c:\program files\thinkpad\utilities\TpKmapAp.exe -helper
mRun: [TpShocks] TpShocks.exe
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [BLOG] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog
mRun: [BMMGAG] RunDll32 c:\progra~1\thinkpad\utilit~1\pwrmonit.dll,StartPwrMonitor
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [BMMLREF] c:\program files\thinkpad\utilities\BMMLREF.EXE
mRun: [BMMMONWND] rundll32.exe c:\progra~1\thinkpad\utilit~1\BatInfEx.dll,BMMAutonomicMonitor
mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe
mRun: [IBMPRC] c:\ibmtools\utils\ibmprc.exe
mRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\FirstStart.exe" /OM
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\Acrobat Assistant.lnk.disabled
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\Adobe Reader Speed Launch.lnk.disabled
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\Digital Line Detect.lnk.disabled
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
uPolicies-explorer: NoActiveDesktop = 1 (0x1)
uPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
uPolicies-explorer: ForceStartMenuLogOff = 1 (0x1)
uPolicies-explorer: DisallowRun = 1 (0x1)
uPolicies-disallowrun: 1 = bitcomet.exe
uPolicies-disallowrun: 2 = ChatRoom.exe
uPolicies-disallowrun: 3 = copyso.exe
uPolicies-disallowrun: 4 = emule.exe
uPolicies-disallowrun: 5 = HDRoom.exe
uPolicies-disallowrun: 6 = kubao.exe
uPolicies-disallowrun: 7 = kugoo.exe
uPolicies-disallowrun: 8 = popo.exe
uPolicies-disallowrun: 9 = qq.exe
uPolicies-disallowrun: 10 = qqgame.exe
uPolicies-disallowrun: 11 = QQLiveUpdate.exe
uPolicies-disallowrun: 12 = QQMusic.exe
uPolicies-disallowrun: 13 = TTraveler.exe
uPolicies-disallowrun: 14 = winrar.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - c:\program files\thinkpad\pkgmgr\\PkgMgr.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {2DAD3559-2923-4935-AD49-B673D2539944} - hxxp://www-307.ibm.com/pc/support/acpir.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1217898456381
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4.1/jinstall-141-win.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: QConGina - QConGina.dll
Notify: svtkpwvw - hbnoadq.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Notification Packages = scecli pwdmon c:\windows\system32\nelefujo.dll dvcr40.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\bpbeeler\applic~1\mozilla\firefox\profiles\unxxvbx6.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - plugin: c:\documents and settings\bpbeeler\my documents\divx\divx content uploader\npUpload.dll
FF - plugin: c:\documents and settings\bpbeeler\my documents\divx\divx web player\npdivx32.dll
FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmusicn.dll
FF - HiddenExtension: XUL Cache: {6C041DE2-1A15-4BBB-9AC4-2C747BB4550A} - c:\documents and settings\bpbeeler\local settings\application data\{6C041DE2-1A15-4BBB-9AC4-2C747BB4550A}
FF - HiddenExtension: XUL Cache: {86487F38-5849-4249-A532-C03CC2E1C5BA} - c:\documents and settings\administrator\local settings\application data\{86487f38-5849-4249-a532-c03cc2e1c5ba}\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============

R0 kvcucbnf;kvcucbnf;c:\windows\system32\drivers\kvcucbnf.sys [1980-1-1 23424]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-3-30 64160]
R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [2006-1-25 59520]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.sys [2006-1-25 11520]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-5-1 110992]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-5-1 24336]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.SYS [2006-1-25 2432]
R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [2006-1-25 4608]
R1 TPPWR;TPPWR;c:\windows\system32\drivers\TPPWR.SYS [2006-1-25 16384]
R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2009-5-1 700152]
R2 ibmfilter;ibmfilter;c:\windows\system32\drivers\ibmfilter.sys [2004-9-23 64256]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 953168]
R2 SmiHlp;SMI helper driver;c:\program files\thinkvantage fingerprint software\smihlp.sys [2005-7-12 3328]
R2 yrgbzxvy;TC USB Kernel Monitor;c:\windows\system32\svchost.exe -k netsvcs [1980-1-1 14336]
S3 QCNDISIF;QCNDISIF;c:\windows\system32\drivers\qcndisif.sys [2006-1-25 12288]

=============== Created Last 30 ================

2009-05-01 10:10 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Comodo
2009-05-01 10:10 155,384 a------- c:\windows\system32\guard32.dll
2009-05-01 10:10 110,992 a------- c:\windows\system32\drivers\cmdguard.sys
2009-05-01 10:10 24,336 a------- c:\windows\system32\drivers\cmdhlp.sys
2009-05-01 10:09 <DIR> --d----- c:\program files\COMODO
2009-05-01 10:08 <DIR> --d----- c:\docume~1\bpbeeler\applic~1\tuqzanhp
2009-05-01 08:47 <DIR> --d----- c:\program files\Windows Installer Clean Up
2009-05-01 08:46 <DIR> --d----- c:\program files\MSECACHE
2009-04-14 16:13 401,408 -------- c:\windows\system32\dllcache\rpcss.dll
2009-04-14 16:13 284,160 -------- c:\windows\system32\dllcache\pdh.dll
2009-04-14 16:13 473,600 -------- c:\windows\system32\dllcache\fastprox.dll
2009-04-14 16:13 453,120 -------- c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-14 16:13 729,088 -------- c:\windows\system32\dllcache\lsasrv.dll
2009-04-14 16:13 714,752 -------- c:\windows\system32\dllcache\ntdll.dll
2009-04-14 16:13 617,472 -------- c:\windows\system32\dllcache\advapi32.dll
2009-04-14 16:12 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-04-14 16:12 1,203,922 -------- c:\windows\system32\dllcache\sysmain.sdb
2009-04-13 19:29 410,984 a------- c:\windows\system32\deploytk.dll
2009-04-13 19:29 73,728 a------- c:\windows\system32\javacpl.cpl
2009-04-05 14:49 <DIR> --dsh--- c:\windows\system32\lowsec
2009-04-03 16:53 1,089,593 -------- c:\windows\system32\dllcache\ntprint.cat
2009-04-03 09:22 <DIR> --d----- c:\program files\CCleaner
2009-04-03 08:29 <DIR> --d----- c:\windows\pss
2009-04-02 23:08 <DIR> --d----- c:\windows\system32\XPSViewer
2009-04-02 23:07 <DIR> --d----- C:\5a424fa03f596fe5acfce6
2009-04-02 23:07 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-04-02 23:07 1,676,288 -------- c:\windows\system32\dllcache\xpssvcs.dll
2009-04-02 23:07 597,504 -------- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-04-02 23:07 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-04-02 23:07 575,488 -------- c:\windows\system32\dllcache\xpsshhdr.dll
2009-04-02 23:07 117,760 -------- c:\windows\system32\prntvpt.dll
2009-04-02 23:07 89,088 -------- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-04-02 22:30 337,408 -------- c:\windows\system32\dllcache\netapi32.dll
2009-04-02 22:21 2,145,280 -------- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-02 22:21 2,023,936 -------- c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-02 22:20 455,296 -------- c:\windows\system32\dllcache\mrxsmb.sys
2009-04-02 22:20 333,952 -------- c:\windows\system32\dllcache\srv.sys
2009-04-02 22:20 331,776 -------- c:\windows\system32\dllcache\msadce.dll
2009-04-02 22:20 691,712 -------- c:\windows\system32\dllcache\inetcomm.dll
2009-04-02 22:16 1,106,944 -------- c:\windows\system32\dllcache\msxml3.dll
2009-04-01 18:42 552 a------- c:\windows\system32\d3d8caps.dat
2009-04-01 17:16 0 a---h--- c:\windows\system32\BIT38.tmp

==================== Find3M ====================

2009-04-05 17:13 20,544 a------- c:\docume~1\bpbeeler\applic~1\GDIPFONTCACHEV1.DAT
2009-04-01 22:03 49,152 a------- c:\windows\system32\crap.dll
2009-03-21 09:06 989,696 -------- c:\windows\system32\dllcache\kernel32.dll
2009-03-10 22:18 934,792 -------- c:\windows\system32\dllcache\WgaTray.exe
2009-03-10 22:18 239,496 -------- c:\windows\system32\dllcache\wgaLogon.dll
2009-03-09 14:06 15,688 a------- c:\windows\system32\lsdelete.exe
2009-03-06 09:22 284,160 a------- c:\windows\system32\pdh.dll
2009-03-02 19:18 826,368 a------- c:\windows\system32\wininet.dll
2009-03-02 19:18 826,368 a------- c:\windows\system32\dllcache\wininet.dll
2009-02-27 23:54 636,072 a------- c:\windows\system32\dllcache\iexplore.exe
2009-02-20 05:20 70,656 a------- c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 05:20 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 00:14 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
2009-02-09 07:10 729,088 a------- c:\windows\system32\lsasrv.dll
2009-02-09 07:10 714,752 a------- c:\windows\system32\ntdll.dll
2009-02-09 07:10 617,472 a------- c:\windows\system32\advapi32.dll
2009-02-09 07:10 401,408 a------- c:\windows\system32\rpcss.dll
2009-02-09 06:13 1,846,784 a------- c:\windows\system32\win32k.sys
2009-02-09 06:13 1,846,784 -------- c:\windows\system32\dllcache\win32k.sys
2009-02-07 19:02 2,066,048 a------- c:\windows\system32\ntkrnlpa.exe
2009-02-07 19:02 2,066,048 a------- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-06 06:11 110,592 a------- c:\windows\system32\services.exe
2009-02-06 06:11 110,592 a------- c:\windows\system32\dllcache\services.exe
2009-02-06 06:08 2,189,056 a------- c:\windows\system32\ntoskrnl.exe
2009-02-06 06:08 2,189,056 a------- c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-06 05:39 35,328 a------- c:\windows\system32\sc.exe
2009-02-06 05:39 35,328 a------- c:\windows\system32\dllcache\sc.exe
2009-02-06 05:10 227,840 a------- c:\windows\system32\dllcache\wmiprvse.exe
2009-02-03 14:59 56,832 a------- c:\windows\system32\secur32.dll
2009-02-03 14:59 56,832 -------- c:\windows\system32\dllcache\secur32.dll
2007-09-25 18:00 92,064 a------- c:\documents and settings\bpbeeler\mqdmmdm.sys
2007-09-25 18:00 79,328 a------- c:\documents and settings\bpbeeler\mqdmserd.sys
2007-09-25 18:00 66,656 a------- c:\documents and settings\bpbeeler\mqdmbus.sys
2007-09-25 18:00 25,600 a------- c:\documents and settings\bpbeeler\usbsermptxp.sys
2007-09-25 18:00 22,768 a------- c:\documents and settings\bpbeeler\usbsermpt.sys
2007-09-25 18:00 9,232 a------- c:\documents and settings\bpbeeler\mqdmmdfl.sys
2007-09-25 18:00 6,208 a------- c:\documents and settings\bpbeeler\mqdmcmnt.sys
2007-09-25 18:00 5,936 a------- c:\documents and settings\bpbeeler\mqdmwhnt.sys
2007-09-25 18:00 4,048 a------- c:\documents and settings\bpbeeler\mqdmcr.sys
2008-08-04 23:03 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008080420080805\index.dat

============= FINISH: 11:40:47.07 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:06:52 AM

Posted 02 May 2009 - 11:37 AM

Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix.. Please visit HERE if you don't know how.. Please re-enable them back after performing all steps given..

Please download ComboFix by sUBs from one of the locations below, and save it to your Desktop.Link 1
Link 2
Link 3
Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed.

If ComboFix asked you to install Recovery Console, please do so.. It will be your best interest..

When finished, it shall produce a log for you. Post that log and a fresh HijackThis log in your next reply..

Note: DON'T do anything with your computer while ComboFix is running.. Let ComboFix finishes its job..

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#3 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:06:52 AM

Posted 08 May 2009 - 06:34 AM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users