Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

can anyone help with stubborn malware


  • Please log in to reply
17 replies to this topic

#1 superqaz

superqaz

  • Members
  • 284 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:15 AM

Posted 18 October 2015 - 05:27 AM

hi

 

have used 4 reputable scanners but it reappears

 

thanks



BC AdBot (Login to Remove)

 


#2 severac

severac

  • Members
  • 872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Serbia
  • Local time:12:15 PM

Posted 18 October 2015 - 08:30 AM

Hello,

 

Please, provide us with more informations.

 

---

 

Please download Rkill to your Desktop.
There are 2 different versions. If one of them won't run then download and try to run the other one.
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

rKill.exe
http://www.bleepingcomputer.com/download/rkill/dl/10/
iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/
 

§  Double-click on the Rkill desktop icon to run the tool.

§  If using Windows Vista, 7, 8 or 10 right-click on it and choose Run As Administrator.

§  black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.

§  If not, delete the file, then download and use the one provided in Link 2.

§  Do not reboot until instructed.

§  If the tool does not run from any of the links provided, please let me know.

If normal mode still doesn't work, run the tool from Safe Mode.

When the scan is done Notepad will open with rKill log.
Post it in your next reply.

NOTE. rKill.txt log will also be present on your desktop.

------

 

ESET Online Scanner

§  Click here to download the installer for ESET Online Scanner and save it to your Desktop.

§  Disable all your antivirus and antimalware software - see how to do that here.

§  Right click on esetsmartinstaller_enu.exe and select Run as Administrator.

§  Place a checkmark in YES, I accept the Terms of Use, then click Start. Wait for ESET Online Scanner to load its components.

§  Select Enable detection of potentially unwanted applications.

§  Click Advanced Settings, then place a checkmark in the following:

o    Remove found threats

o    Scan archives

o    Scan for potentially unsafe applications

o    Enable Anti-Stealth technology

§  Click Start to begin scanning.

§  ESET Online Scanner will start downloading signatures and scan. Please be patient, as this scan can take quite some time.

§  When the scan is done, click List threats (only available if ESET Online Scanner found something).

§  Click Export, then save the file to your desktop.

§  Click Back, then Finish to exit ESET Online Scanner.

---------

 

Please download Malwarebytes Anti-Malware (MBAM) to your desktop.

NOTE. If you already have MBAM 2.0 installed scroll down.

 

§  Double-click mbam-setup-2.x.x.xxxx.exe and follow the prompts to install the program.

§  At the end, be sure a checkmark is placed next to the following:
 

o    Launch Malwarebytes Anti-Malware

o    A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.

 

§  Click Finish.

§  On the Dashboard, click the 'Update Now >>' link

§  After the update completes, on Settings tab, set under Detection and Protection next options: 

1. 'Scan for rootkits'

2. Non-Malware Protection, for 'PUP detections', check, 'Threat detections as malware' option.

§  Return to Dashboard, click the 'Scan Now >>' button.

§  A Threat Scan will begin.

§  When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.

§  In most cases, a restart will be required.

§  Wait for the prompt to restart the computer to appear, than click on Yes.


If you already have MBAM 2.0 installed:
 

§  On the Dashboard, click the 'Update Now >>' link.

§  After the update completes, on Settings tab, set under Detection and Protection next options: 

1. 'Scan for rootkits'

2. Non-Malware Protection, for 'PUP detections', check, 'Threat detections as malware' option.

§  Return to Dashboard, click the Scan Now >> button.

§  A Threat Scan will begin.

§  When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.

§  In most cases, a restart will be required.

§  Wait for the prompt to restart the computer to appear, than click on Yes.

§  After the restart once you are back at your desktop, open MBAM once more.

§  Click on the History tab > Application Logs.

§  Double click on the Scan Log which shows the Date and time of the scan just performed.

§  Click 'Export'.

§  Click 'Copy to Clipboard'

§  Paste the contents of the clipboard into your reply.

 

-----------

Please download AdwCleaner by Xplode onto your desktop.

§  Close all open programs and internet browsers.

§  Double click on adwcleaner.exe to run the tool.

§  In EULA window click I agree.

§  In Options uncheck Reset Winsock settings.

§  Click on Scan button.

§  When the scan has finished click on Cleaning button.

§  Your computer will be rebooted automatically. A text file will open after the restart.

§  Please post the contents of that logfile with your next reply.

§  You can find the logfile at C:\AdwCleaner[C1].txt as well.

 

----------

Please download Junkware Removal Tool  to your desktop.

§  Shut down your protection software now to avoid potential conflicts.

§  Run the tool by double-clicking it. If you are using Windows Vista, 7, 8 or 10; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".

§  The tool will open and start scanning your system.

§  Please be patient as this can take a while to complete depending on your system's specifications.

§  On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

§  Post the contents of JRT.txt into your next message.


I would like to help you to remove malware. Let's look inside.   :busy:

But I don't know to solve all PC problems.  :smash: 

 


#3 superqaz

superqaz
  • Topic Starter

  • Members
  • 284 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:15 AM

Posted 19 October 2015 - 12:53 PM

report are ready but i cant paste to hear

 

thanks


report are ready but i cant paste to hear

 

thanks



#4 superqaz

superqaz
  • Topic Starter

  • Members
  • 284 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:15 AM

Posted 19 October 2015 - 12:57 PM



it seems i can paste to here, now
thanks for looking at this


Emsisoft Anti-Malware - Version 10.0.0.5735
Last update: 10/19/2015 11:57:25 AM
Initiated by: RIVER\m

Scan settings:

Scan type:
Objects: Rootkits, Memory, Traces, C:\, G:\

Detect PUPs: On
Scan archives: On
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off

Scan start: 10/19/2015 11:57:28 AM
Value: HKEY_USERS\S-1-5-21-3935101415-513640444-3729826549-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR Setting.DisableTaskMgr (A)
Value: HKEY_USERS\S-1-5-21-3935101415-513640444-3729826549-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS Setting.DisableRegistryTools (A)

Scanned 252289
Found 2

Scan end: 10/19/2015 1:44:17 PM
Scan time: 1:46:49



Rkill 2.8.2 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 10/18/2015 05:22:31 PM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* Windows Defender Disabled

[HKLM\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware" = dword:00000001

* Windows Firewall Disabled

[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = dword:00000000

Checking Windows Service Integrity:

* Windows Defender (WinDefend) is not Running.
Startup Type set to: Manual

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* No issues found.

Program finished at: 10/18/2015 05:23:16 PM
Execution time: 0 hours(s), 0 minute(s), and 45 seconds(s)


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 7 Ultimate x64
Ran by m on 19/10/2015 at 9:28:31.08
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] (Default) REG_SZ Crossbrowse



~~~ Files



~~~ Folders

Successfully deleted: [Folder] G:\Users\m\Appdata\Local\crashrpt



~~~ FireFox

Successfully deleted: [File] G:\Users\m\AppData\Roaming\mozilla\firefox\profiles\ij429kvp.default\extensions\firefox1@myibay.com.xpi
Successfully deleted: [File] G:\Users\m\AppData\Roaming\mozilla\firefox\profiles\ij429kvp.default\searchplugins\startpage-hxxps.xml



~~~ Chrome


[G:\Users\m\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[G:\Users\m\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[G:\Users\m\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[G:\Users\m\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19/10/2015 at 11:16:15.63
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\Store
[-] Key Deleted : HKCU\Software\__SP__browser_name__SP__
[-] Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Key Deleted : HKLM\SOFTWARE\GeekBuddyRSP
[-] Key Deleted : HKLM\SOFTWARE\Crashhd
[-] Key Deleted : HKLM\SOFTWARE\NetTcpHandler
[-] Key Deleted : HKLM\SOFTWARE\NtSvcHandler
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiSaver 5.0_is1
[!] Key Not Deleted : [x64] HKCU\Software\Store
[!] Key Not Deleted : [x64] HKCU\Software\__SP__browser_name__SP__
[-] Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKU\S-1-5-21-3935101415-513640444-3729826549-1000\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKU\S-1-5-21-3935101415-513640444-3729826549-1000\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]

***** [ Web browsers ] *****

[-] [G:\Users\m\AppData\Roaming\mozilla\Firefox\Profiles\ij429kvp.default\prefs.js] [Preference] Deleted : user_pref("browser.newtab.url", "www.tohotweb.com?oem=sunadukv3&uid=JPS930HZ34814L_HitachiHDS721010CLA630&tm=1445094874");
[-] [G:\Users\m\AppData\Local\Comodo\Chromodo\User Data\Default\Web Data] [Search Provider] Deleted : uk.ask.com
[-] [G:\Users\m\AppData\Local\Comodo\Chromodo\User Data\Default\Secure Preferences] [Extension] Deleted : jlcgehabolcakkjhgmgpkagpolbjlhfa

*************************


########## EOF - G:\AdwCleaner\AdwCleaner[C1].txt - [3557 bytes] ##########

#5 severac

severac

  • Members
  • 872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Serbia
  • Local time:12:15 PM

Posted 20 October 2015 - 12:27 AM

Hi, 

 

What about Kaspersky log? And AdwCleaner?

 

Do you still have problems?


I would like to help you to remove malware. Let's look inside.   :busy:

But I don't know to solve all PC problems.  :smash: 

 


#6 superqaz

superqaz
  • Topic Starter

  • Members
  • 284 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:15 AM

Posted 20 October 2015 - 05:35 AM

sorry i missed adaware, dont see mention of Kaspersky

pc very slow today. last night after i sent reports i reinstalled freemake video converter as it got removed, i was very careful not to install the extra programs . do u know if its OTHERWISE safe

thanks

Edited by superqaz, 20 October 2015 - 05:45 AM.


#7 superqaz

superqaz
  • Topic Starter

  • Members
  • 284 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:15 AM

Posted 20 October 2015 - 05:59 AM

here it is: also i am running kaspersky now, i assume its the one offered on this site

thanks, mark


# AdwCleaner v5.014 - Logfile created 20/10/2015 at 11:52:23
# Updated 18/10/2015 by Xplode
# Database : 2015-10-18.5 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : m - RIVER
# Running from : G:\Users\m\Downloads\AdwCleaner(1).exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : G:\Users\m\AppData\Roaming\RHEng

***** [ Files ] *****

[-] File Deleted : G:\Users\m\AppData\Roaming\mozilla\Firefox\Profiles\ij429kvp.default\searchplugins\bing-lavasoft.xml

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\NetTcpHandler
[-] Key Deleted : HKLM\SOFTWARE\GeekBuddyRSP
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Data Restored : HKU\S-1-5-21-3935101415-513640444-3729826549-1000\Software\Microsoft\Internet Explorer\Main [Start Page]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[!] Key Not Deleted : HKU\S-1-5-21-3935101415-513640444-3729826549-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : HKU\S-1-5-21-3935101415-513640444-3729826549-1000\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]

***** [ Web browsers ] *****

[-] [G:\Users\m\AppData\Roaming\mozilla\Firefox\Profiles\ij429kvp.default\prefs.js] [Preference] Deleted : user_pref("browser.newtab.url", "hxxp://www.bing.com/?pc=COSP&ptag=D101915-A166D148A50&form=CONMHP&conlogo=CT3334470");
[-] [G:\Users\m\AppData\Roaming\mozilla\Firefox\Profiles\ij429kvp.default\prefs.js] [Preference] Deleted : user_pref("browser.startup.homepage", "hxxp://www.bing.com/?pc=COSP&ptag=D101915-A166D148A50&form=CONMHP&conlogo=CT3334470");

*************************

:: Winsock settings cleared

########## EOF - G:\AdwCleaner\AdwCleaner[C2].txt - [2335 bytes] ##########

#8 superqaz

superqaz
  • Topic Starter

  • Members
  • 284 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:15 AM

Posted 20 October 2015 - 06:13 AM

kaspersy found nothing.

would be interested to know what u think of Freemake as tech support alert/gizmo site reviewed it recently and apart from malware warning rated it as best program

thanks

#9 severac

severac

  • Members
  • 872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Serbia
  • Local time:12:15 PM

Posted 20 October 2015 - 12:06 PM

Can you explain to me your problems with more details?


I would like to help you to remove malware. Let's look inside.   :busy:

But I don't know to solve all PC problems.  :smash: 

 


#10 superqaz

superqaz
  • Topic Starter

  • Members
  • 284 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:15 AM

Posted 20 October 2015 - 03:48 PM

if u mean original problem it was all kinds of malware [over 400 in one scan] i used several reputable scanners but they kept returning. everything was drastically slowed down.

would be interested to know what u think of Freemake

things seem ok now especially since a defrag today

#11 severac

severac

  • Members
  • 872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Serbia
  • Local time:12:15 PM

Posted 20 October 2015 - 05:05 PM

I don't use Freemake, but as I can see it should be ok to use. 

 

Which programs did you use?


I would like to help you to remove malware. Let's look inside.   :busy:

But I don't know to solve all PC problems.  :smash: 

 


#12 superqaz

superqaz
  • Topic Starter

  • Members
  • 284 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:15 AM

Posted 21 October 2015 - 04:13 AM

all the ones u suggested and kaspasky and spybot s and d and comodo and super malware bytes. right now firefox is really complaining about playing videos, thats very new

Edited by superqaz, 21 October 2015 - 09:13 AM.


#13 severac

severac

  • Members
  • 872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Serbia
  • Local time:12:15 PM

Posted 21 October 2015 - 11:55 AM

SpyBot is obsolete. Remove it. 

 

Please download MiniToolBox, save it to your desktop and run it.
Checkmark the following checkboxes:

§  Flush DNS

§  Report IE Proxy Settings

§  Reset IE Proxy Settings

§  Report FF Proxy Settings

§  Reset FF Proxy Settings

§  List content of Hosts

§  List IP configuration

§  List Winsock Entries

§  List last 10 Event Viewer log

§  List Installed Programs

§  List Devices

§  List Users, Partitions and Memory size.

§  List Minidump Files

§  List Restore Points

Click Go and post the result (MTB.txt). A copy of MTB.txt will be saved in the same directory the tool is run.

------


I would like to help you to remove malware. Let's look inside.   :busy:

But I don't know to solve all PC problems.  :smash: 

 


#14 superqaz

superqaz
  • Topic Starter

  • Members
  • 284 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:15 AM

Posted 21 October 2015 - 02:56 PM

ok i will remove spybot but can u say what u mean by obsolete,,,,not good enough???, or...

MiniToolBox by Farbar Version: 25-07-2015 01
Ran by m (administrator) on 21-10-2015 at 20:45:48
Running from "G:\Users\m\Downloads"
Microsoft Windows 7 Ultimate Service Pack 1 (X64)
Model: Aspire X1430 Manufacturer: Acer
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================


"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================



========================= IP Configuration: ================================

Realtek PCIe GBE Family Controller = Local Area Connection (Connected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : river
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : default

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . : default
Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
Physical Address. . . . . . . . . : C8-9C-DC-6D-69-F2
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::e1dd:bc27:8474:cbcb%11(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.1.182(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : 21 October 2015 10:10:01
Lease Expires . . . . . . . . . . : 23 October 2015 14:48:50
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DHCPv6 IAID . . . . . . . . . . . : 248028380
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1D-7A-9D-B5-C8-9C-DC-6D-69-F2
DNS Servers . . . . . . . . . . . : 192.168.1.1
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.default:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . : default
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Server: BrightBox.ee
Address: 192.168.1.1

Name: google.com
Addresses: 2a00:1450:4009:80b::200e
216.58.208.78


Pinging google.com [216.58.208.78] with 32 bytes of data:
Reply from 216.58.208.78: bytes=32 time=15ms TTL=55
Reply from 216.58.208.78: bytes=32 time=15ms TTL=55

Ping statistics for 216.58.208.78:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 15ms, Maximum = 15ms, Average = 15ms
Server: BrightBox.ee
Address: 192.168.1.1

Name: yahoo.com
Addresses: 2001:4998:58:c02::a9
2001:4998:c:a06::2:4008
2001:4998:44:204::a7
98.138.253.109
206.190.36.45
98.139.183.24


Pinging yahoo.com [98.138.253.109] with 32 bytes of data:
Reply from 98.138.253.109: bytes=32 time=128ms TTL=45
Reply from 98.138.253.109: bytes=32 time=129ms TTL=45

Ping statistics for 98.138.253.109:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 128ms, Maximum = 129ms, Average = 128ms

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
11...c8 9c dc 6d 69 f2 ......Realtek PCIe GBE Family Controller
1...........................Software Loopback Interface 1
12...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.182 20
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.1.0 255.255.255.0 On-link 192.168.1.182 276
192.168.1.182 255.255.255.255 On-link 192.168.1.182 276
192.168.1.255 255.255.255.255 On-link 192.168.1.182 276
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.1.182 276
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.1.182 276
===========================================================================
Persistent Routes:
None

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
1 306 ::1/128 On-link
11 276 fe80::/64 On-link
11 276 fe80::e1dd:bc27:8474:cbcb/128
On-link
1 306 ff00::/8 On-link
11 276 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 G:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 G:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 G:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 G:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 G:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog5 06 G:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 G:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128] (Apple Inc.)
Catalog9 01 G:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 02 G:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 03 G:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 04 G:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 05 G:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 06 G:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 07 G:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 08 G:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 09 G:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 10 G:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
x64-Catalog5 01 G:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 G:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 G:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 G:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 G:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog5 06 G:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 G:\Program Files\Bonjour\mdnsNSP.dll [133392] (Apple Inc.)
x64-Catalog9 01 G:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 02 G:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 03 G:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 04 G:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 05 G:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 06 G:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 07 G:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 08 G:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 09 G:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 10 G:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (10/21/2015 05:48:12 PM) (Source: Application Error) (User: )
Description: Faulting application name: imgSeek.exe, version: 0.8.5.0, time stamp: 0x41015dd3
Faulting module name: ntdll.dll, version: 6.1.7601.23142, time stamp: 0x55b02db8
Exception code: 0xc0000005
Fault offset: 0x000222d2
Faulting process id: 0x1598
Faulting application start time: 0ximgSeek.exe0
Faulting application path: imgSeek.exe1
Faulting module path: imgSeek.exe2
Report Id: imgSeek.exe3

Error: (10/21/2015 12:38:25 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15647

Error: (10/21/2015 12:38:25 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15647

Error: (10/21/2015 12:38:25 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (10/21/2015 10:09:55 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/20/2015 07:55:47 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 10952

Error: (10/20/2015 07:55:47 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 10952

Error: (10/20/2015 07:55:47 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (10/20/2015 07:55:46 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9953

Error: (10/20/2015 07:55:46 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9953


System errors:
=============
Error: (10/21/2015 04:01:39 PM) (Source: Disk) (User: )
Description: The driver detected a controller error on \Device\Harddisk2\DR2.

Error: (10/21/2015 04:01:38 PM) (Source: Disk) (User: )
Description: The driver detected a controller error on \Device\Harddisk2\DR2.

Error: (10/21/2015 04:01:38 PM) (Source: Disk) (User: )
Description: The driver detected a controller error on \Device\Harddisk2\DR2.

Error: (10/21/2015 10:09:40 AM) (Source: Service Control Manager) (User: )
Description: The PDIHWCTL service failed to start due to the following error:
%%2

Error: (10/20/2015 10:01:49 PM) (Source: DCOM) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (10/20/2015 05:29:24 PM) (Source: volsnap) (User: )
Description: The shadow copies of volume G: were aborted because the shadow copy storage could not grow due to a user imposed limit.

Error: (10/20/2015 04:19:44 PM) (Source: Service Control Manager) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.

Error: (10/20/2015 11:54:44 AM) (Source: Service Control Manager) (User: )
Description: The PDIHWCTL service failed to start due to the following error:
%%2

Error: (10/20/2015 11:53:01 AM) (Source: DCOM) (User: )
Description: {9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (10/20/2015 11:52:31 AM) (Source: Service Control Manager) (User: )
Description: The BlueStacks Updater Service service terminated unexpectedly. It has done this 1 time(s).


Microsoft Office Sessions:
=========================
Error: (10/21/2015 05:48:12 PM) (Source: Application Error)(User: )
Description: imgSeek.exe0.8.5.041015dd3ntdll.dll6.1.7601.2314255b02db8c0000005000222d2159801d10c1fde6d3673G:\Program Files (x86)\imgSeek\imgSeek.exeG:\Windows\SysWOW64\ntdll.dll838a3d6b-7813-11e5-8558-c89cdc6d69f2

Error: (10/21/2015 12:38:25 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15647

Error: (10/21/2015 12:38:25 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15647

Error: (10/21/2015 12:38:25 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (10/21/2015 10:09:55 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (10/20/2015 07:55:47 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 10952

Error: (10/20/2015 07:55:47 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 10952

Error: (10/20/2015 07:55:47 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (10/20/2015 07:55:46 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9953

Error: (10/20/2015 07:55:46 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9953


=========================== Installed Programs ============================

µTorrent (HKCU\...\uTorrent) (Version: 3.4.4.40911 - BitTorrent Inc.)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.207 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 4.1 64-bit (HKLM\...\{F7ADB493-B913-4D61-9A63-DA736C20C3F2}) (Version: 4.1.2 - Adobe)
Adobe Photoshop Lightroom 5.5 64-bit (HKLM\...\{19BBD0F3-7A31-480D-8A23-19AE28035E9C}) (Version: 5.5.0 - Adobe Systems Incorporated)
AOMEI Backupper Standard (HKLM-x32\...\{A83692F5-3E9B-4E95-9E7E-B5DF5536C09F}_is1) (Version: - AOMEI Technology Co., Ltd.)
Apple Application Support (32-bit) (HKLM-x32\...\{A50679D9-6CBD-4FCD-BACB-62EF3894F6F3}) (Version: 4.0.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{1F72FDD5-A069-45B4-928F-D0F16492DC69}) (Version: 4.0.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Audacity 2.1.1 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.1 - Audacity Team)
Awesome Duplicate Photo Finder v. 1.1 (HKLM-x32\...\Awesome Duplicate Photo Finder_is1) (Version: - Duplicate-Finder.com)
Belarc Advisor 8.5a (HKLM-x32\...\Belarc Advisor) (Version: 8.5.1.0 - Belarc Inc.)
BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.10.0.4321 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\...\{473E82D7-79E2-43DF-8FA0-025407C93191}) (Version: 0.10.0.4321 - BlueStack Systems, Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Calibrize 2.0 (HKLM-x32\...\Calibrize_is1) (Version: - Colorjinn)
CCleaner (HKLM\...\CCleaner) (Version: 5.09 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.6.5844 - CDBurnerXP)
Chromodo (HKLM-x32\...\Chromodo) (Version: 45.6.11.383 - Comodo)
COMODO Internet Security Premium (HKLM\...\{367D1EA4-24FD-402F-AFF0-08A678D2EE28}) (Version: 8.2.0.4674 - COMODO Security Solutions Inc.)
Data Lifeguard Diagnostic for Windows 1.24 (HKLM-x32\...\{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1) (Version: - Western Digital Corporation)
Desktop Icon Position Saver (64-bit) (HKLM-x32\...\dips64) (Version: - )
DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation)
Emsisoft Anti-Malware (HKLM-x32\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 10.0 - Emsisoft Ltd.)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
Evernote v. 5.9 (HKLM-x32\...\{AFFCD322-4AAE-11E5-A01D-0050569584E9}) (Version: 5.9.0.8665 - Evernote Corp.)
Eye-One Match 3.6.2 (HKLM-x32\...\Eye-One Match_is1) (Version: 3.6.2 - GretagMacbeth)
FastStone Image Viewer 5.5 (HKLM-x32\...\FastStone Image Viewer) (Version: 5.5 - FastStone Soft)
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 7.2.0.722 - Foxit Software Inc.)
GeekBuddy (HKLM\...\{A09AEC8C-5054-4E92-93DE-EA0B8C73BCF2}) (Version: 4.21.144 - Comodo Security Solutions Inc)
GOM Player (HKLM-x32\...\GOM Player) (Version: 2.2.69.5228 - Gretech Corporation)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.28.15 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
HandBrake 0.10.2 (HKLM-x32\...\HandBrake) (Version: 0.10.2 - )
HP LaserJet 1020 Series (HKLM\...\HP LaserJet 1020 Series) (Version: - )
HP Support Solutions Framework (HKLM-x32\...\{F6A11738-3EE4-4573-AEA5-6CD5D491C167}) (Version: 12.0.30.81 - Hewlett-Packard Company)
i1_driver_installer_utility_i1Match version 1.0 (HKLM-x32\...\i1_driver_installer_utility_i1Match_is1) (Version: - X-Rite)
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
imgSeek (remove only) (HKLM-x32\...\imgSeek) (Version: - )
iTunes (HKLM\...\{96984DE8-1DB8-425C-AC8C-3098BC696F04}) (Version: 12.3.0.44 - Apple Inc.)
Kana Clip 1.1 (HKLM-x32\...\Kana Clip_is1) (Version: 1.1 - Kana Solution)
Kana Reminder 1.5 (HKLM-x32\...\Kana Reminder_is1) (Version: 1.5 - Kana Solution)
K-Lite Codec Pack 11.4.0 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 11.4.0 - )
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 4.6 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.00081 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation)
MiniTool Partition Wizard Free 9.1 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.)
MozBackup 1.5.1 (HKLM-x32\...\MozBackup) (Version: - Pavel Cvrcek)
Mozilla Firefox 41.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 41.0.1 (x86 en-US)) (Version: 41.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 41.0.1.5750 - Mozilla)
Mozilla Thunderbird 38.2.0 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 38.2.0 (x86 en-US)) (Version: 38.2.0 - Mozilla)
Multi Reminders 3.15 (HKLM-x32\...\Multi Reminders) (Version: 3.15 - Kevin Solway)
MyDefrag v4.3.1 (HKLM\...\MyDefrag v4.3.1_is1) (Version: 4.0.0.0 - J.C. Kessels)
NotesHolder 2.3 (HKLM-x32\...\NotesHolder_is1) (Version: 2.3 - A!K Research Labs)
PhraseExpress v11.0.114 (HKLM-x32\...\PhraseExpress_is1) (Version: 11.0.114 - Bartels Media GmbH)
QuickTime 7 (HKLM-x32\...\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
ShellFolderFix 1.1.4 (HKLM\...\{3DD823AB-145A-4522-B9F6-A9566121F837}_is1) (Version: - )
Shrink Pic (remove) (HKLM-x32\...\Shrink Pic) (Version: - )
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1204 - SUPERAntiSpyware.com)
Syncios version 4.3.4 (HKLM-x32\...\{068A5D84-8419-4BDE-9689-FE65F412EFBB}_is1) (Version: 4.3.4 - Anvsoft, Inc.)
Turbo Lister 2 (HKLM-x32\...\{8927E07C-97F7-4A54-88FB-D976F50DD46E}) (Version: 2.00.0000 - eBay Inc.)
UK's Kalender 2.4.3 (HKLM-x32\...\UK's Kalender_is1) (Version: - Ulrich Krebs)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WordWeb (HKLM-x32\...\WordWeb) (Version: 7 - WordWeb Software)
ZAR X (HKLM\...\{85DA9B81-D7F9-4165-8E62-F776B57213F8}_is1) (Version: - www.z-a-recovery.com)

========================= Devices: ================================


========================= Memory info: ===================================

Percentage of memory in use: 40%
Total physical RAM: 3579.28 MB
Available physical RAM: 2118.3 MB
Total Virtual: 7156.75 MB
Available Virtual: 4552.54 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:809.19 GB) (Free:583.13 GB) NTFS
4 Drive g: (New Volume) (Fixed) (Total:122.09 GB) (Free:75.69 GB) NTFS
5 Drive o: (USB DISK) (Fixed) (Total:0.93 GB) (Free:0.71 GB) FAT32

========================= Users: ========================================

User accounts for \\RIVER

Administrator Guest m

========================= Minidump Files ==================================

No minidump file found

========================= Restore Points ==================================


**** End of log ****

#15 severac

severac

  • Members
  • 872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Serbia
  • Local time:12:15 PM

Posted 22 October 2015 - 02:06 AM

Obsoletete=out of date.

 

Remove SUPERAntiSpyware also, it is outdated. 

----

If you still have problems, you can get an expert opinion by asking for help in the Virus, Trojan, Spyware, and Malware Removal Logs forum. You will need to follow instructions in the Preparation Guide. Start with Step 6 and post FRST log in new topic, and link this topic there. 

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help

 

They can use tool which are not allowed here. 

 

Let me know if you need any help with that. 


I would like to help you to remove malware. Let's look inside.   :busy:

But I don't know to solve all PC problems.  :smash: 

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users