Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Hijacked PC and infected with Win32/Cryptor


  • This topic is locked This topic is locked
6 replies to this topic

#1 marco00168

marco00168

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:24 PM

Posted 28 July 2009 - 08:01 AM

I cannot get rid of Win32/Cryptor virus with AVG, also ran Malwarebytes' Anti-Malware with no luck. Firefox opens by itself with this site (which is not my home page) www.thenewspedia.com/index.php/components/hobbies (or other topics).
I infected two pc's with this hijack and virus. In this post I will talk about one pc.

I don't know if it started from this website: www.novaferr.com or the delicious addon to firefox and explorer.
I did not have a firewall running at the time and was running avast. I now activated Windows firewall and switched to AVG.

My DDT.txt file is:
12.25 28/07/2009
DDS (Ver_09-06-26.01) - NTFSx86
Run by Marco at 12.06.32,82 on 28/07/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.39.1040.18.768.135 [GMT 2:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Programmi\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\Iomega\System32\ActivityDisk.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Programmi\Iomega\DriveIcons\ImgIcon.exe
C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
C:\Programmi\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Programmi\Iomega\AutoDisk\AD2KClient.exe
C:\Programmi\Xobni\XobniService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Siber Systems\GoodSync\GoodSync.exe
C:\Programmi\IObit\Advanced SystemCare 3\AWC.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Programmi\AVG\AVG8\avgcsrvx.exe
C:\Programmi\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Programmi\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Marco\Documenti\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.it/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.google.it/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\programmi\avg\avg8\toolbar\IEToolbar.dll
mWinlogon: SfcDisable=-99 (0xffffff9d)
mWinlogon: Taskman=c:\recycler\s-1-5-21-6807905879-7872320822-850596274-5186\nissan.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programmi\file comuni\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\programmi\avg\avg8\avgssie.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\programmi\avg\avg8\toolbar\IEToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\programmi\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\programmi\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\programmi\avg\avg8\toolbar\IEToolbar.dll
uRun: [Iomega Active Disk] c:\programmi\iomega\autodisk\AD2KClient.exe
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [GoodSync] "c:\programmi\siber systems\goodsync\GoodSync.exe" /min
uRun: [Advanced SystemCare 3] "c:\programmi\iobit\advanced systemcare 3\AWC.exe" /startup
mRun: [PMXInit] c:\windows\system32\pmxinit.exe
mRun: [Iomega Startup Options] c:\programmi\iomega\common\ImgStart.exe
mRun: [Iomega Drive Icons] c:\programmi\iomega\driveicons\ImgIcon.exe
mRun: [SSBkgdUpdate] "c:\programmi\file comuni\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [OpwareSE4] "c:\programmi\scansoft\omnipagese4.0\OpwareSE4.exe"
mRun: [WrtMon.exe] c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [Adobe Reader Speed Launcher] "c:\programmi\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\programmi\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\programmi\k-lite mega codec pack\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\programmi\itunes\iTunesHelper.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRunOnce: [WIAWizardMenu] RUNDLL32.EXE c:\windows\system32\sti_ci.dll,WiaCreateWizardMenu
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&sporta in Microsoft Excel - c:\progra~1\micros~1\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office11\REFIEBAR.DLL
DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
TCP: {422CC8BC-FCBB-4D02-BD84-07BC24A02FAC} = 193.70.152.15,193.70.152.25
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\programmi\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\programmi\xobni\Skype4COM.dll
Notify: avgrsstarter - avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\marco\datiap~1\mozilla\firefox\profiles\tdyrc9u8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - prefs.js: keyword.URL - hxxp://it.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_it&p=
FF - component: c:\programmi\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\programmi\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\programmi\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\programmi\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\programmi\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\programmi\google\picasa3\npPicasa3.dll
FF - plugin: c:\programmi\k-lite mega codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\programmi\k-lite mega codec pack\real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\programmi\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\programmi\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\programmi\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\programmi\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\programmi\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\programmi\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\programmi\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\programmi\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\programmi\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\programmi\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\programmi\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\programmi\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\programmi\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\programmi\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\programmi\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\programmi\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-7-27 335752]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-7-27 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-7-27 108552]
R1 DK12DRV;DK12 WindowsNT Driver;c:\windows\system32\drivers\DK12DRV.SYS [2007-12-12 7744]
R2 aawservice;Lavasoft Ad-Aware Service;c:\programmi\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-7-27 298776]
R2 DK2DRV;DK2 WindowsNT Driver;c:\windows\system32\drivers\DK2DRV.SYS [2007-12-12 24304]
R2 EdgeStat;EdgeStat;c:\windows\system32\drivers\edgestat.sys [2008-1-9 6912]
R2 Par1284;Par1284;c:\windows\system32\drivers\PAR1284.SYS [2008-1-9 51296]
R2 XobniService;XobniService;c:\programmi\xobni\XobniService.exe [2009-3-25 45288]
R3 DFSTR2K;Base USB Mass Storage Driver;c:\windows\system32\drivers\DFSTOR2K.SYS [2007-10-22 38037]
R3 powervr;powervr;c:\windows\system32\drivers\powervr.sys [2002-9-27 566496]

=============== Created Last 30 ================

2009-07-27 13:15 <DIR> --d-h--- C:\$AVG8.VAULT$
2009-07-27 12:50 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-07-27 12:50 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-07-27 12:50 335,752 a------- c:\windows\system32\drivers\avgldx86.sys
2009-07-27 12:49 <DIR> --d----- c:\windows\system32\drivers\Avg
2009-07-27 12:49 <DIR> --d----- c:\docume~1\alluse~1\datiap~1\AVG Security Toolbar
2009-07-27 12:49 <DIR> --d----- c:\programmi\AVG
2009-07-27 12:49 <DIR> --d----- c:\docume~1\alluse~1\datiap~1\avg8
2009-07-27 12:33 <DIR> --d----- c:\windows\system32\NtmsData
2009-07-27 10:33 <DIR> --d----- c:\docume~1\marco\datiap~1\Malwarebytes
2009-07-27 10:33 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-27 10:33 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-07-27 10:33 <DIR> --d----- c:\docume~1\alluse~1\datiap~1\Malwarebytes
2009-07-27 10:33 <DIR> --d----- c:\programmi\Malwarebytes' Anti-Malware
2009-07-24 15:30 61,952 a------- C:\ddqf.exe
2009-07-09 11:09 <DIR> --d----- c:\programmi\Xobni

==================== Find3M ====================

2009-07-09 11:23 456,614 a------- c:\windows\system32\perfh010.dat
2009-07-09 11:23 77,526 a------- c:\windows\system32\perfc010.dat
2009-06-05 11:42 2,060,288 a------- c:\windows\system32\usbaaplrc.dll
2009-06-05 11:42 39,424 a------- c:\windows\system32\drivers\usbaapl.sys
2000-12-12 12:17 100,432 -------- c:\programmi\Win2000PPAHotfix.exe
2008-01-05 11:41 7,608,352 a--sh--- c:\windows\system32\drivers\fidbox.dat

============= FINISH: 12.07.46,43 ===============

Attached Files



BC AdBot (Login to Remove)

 


m

#2 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:12:24 AM

Posted 31 July 2009 - 06:04 AM

Download RootRepeal.zip and unzip it to your Desktop. <<<mirror>>>
  • Double click RootRepeal.exe to start the program
  • Click on the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:
    • Drivers
    • Files
    • Processes
    • SSDT
    • Stealth Objects
    • Hidden Services
  • Click the OK button
  • In the next dialog, select all drives showing
  • Click OK to start the scan

    Note: The scan can take some time. DO NOT run any other programs while the scan is running

  • When the scan is complete, the Save Report button will become available
  • Click this and save the report to your Desktop as RootRepeal.txt
  • Go to File, then Exit to close the program
  • Attach the report in your next reply


NEXT


Download this tool to desktop:

http://www2.gmer.net/mbr/mbr.exe

Double click it & post the log it creates on desktop. (mbr.log)

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#3 marco00168

marco00168
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:24 PM

Posted 31 July 2009 - 06:50 AM

Thank you for answering my post. My problem is that in my office we have now three pc's infected with the win32/Criptor virus and today we close for vacation until Sept. 1. I looked at the post that you resolved for member 5678 and followed to the letter your advice SysProt,Combo-Fix,Est Online Scanner and finally OTC. AVG does not find the virus anymore and I don't get the unsolicited browser popup. Can I send you my logs? Please don't be mad that I could not wait for your post since at 5 pm (Rome time) we go on vacation.

Thank You

#4 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:12:24 AM

Posted 31 July 2009 - 09:21 AM

Don't worry, you can still send me logs.. If somehow you manage to get it resolved, you can just tell me :thumbup2:

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#5 marco00168

marco00168
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:24 PM

Posted 04 August 2009 - 03:20 AM

Thanks. I will be back at work and I will send you the logs. Have a great summer!

Marco

#6 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:12:24 AM

Posted 05 August 2009 - 12:12 AM

Ok :thumbup2:

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#7 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:12:24 AM

Posted 15 August 2009 - 04:27 AM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users