internet connection/trojans/log file from combofix

View previous topic View next topic Go down

internet connection/trojans/log file from combofix

Post by ehowley25 on 27th January 2010, 11:16 pm

I have run Combofix on your advice and the internet now seems to work okay again. Thank you!!! Smile
Does that mean my computer is clear now or just part of iy is fixed???

Here is the log file from the combofix scan:

ComboFix 10-01-27.03 - Eddie Howley 27/01/2010 22:50:55.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.612 [GMT 0:00]
Running from: c:\documents and settings\Eddie Howley\Desktop\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Internet Explorer\msimg32.dll
c:\recycler\S-1-5-21-546286046-1483979584-599923875-1003
c:\windows\Fonts\MyriadPro-Regular.otf
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\twain_32.dll
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((( Files Created from 2009-12-27 to 2010-01-27 )))))))))))))))))))))))))))))))
.

2010-01-25 21:18 . 2010-01-25 21:18 -------- d-----w- C:\MGTools
2010-01-25 20:33 . 2010-01-25 20:33 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\Malwarebytes
2010-01-25 20:32 . 2010-01-25 20:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-25 17:44 . 2010-01-25 17:44 -------- d-----w- c:\program files\CCleaner
2010-01-25 15:44 . 2010-01-25 17:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-25 12:45 . 2010-01-25 12:45 -------- d-----w- c:\program files\AVG
2010-01-25 12:45 . 2010-01-25 17:24 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-25 00:45 . 2010-01-25 00:45 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2010-01-25 00:45 . 2010-01-25 00:45 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\TuneUp Software
2010-01-25 00:43 . 2010-01-25 00:43 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-01-25 00:43 . 2010-01-25 17:06 -------- d-----w- c:\program files\TuneUp Utilities 2009
2010-01-25 00:43 . 2010-01-25 00:43 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2010-01-25 00:01 . 2009-09-20 02:19 84912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVENG.SYS
2010-01-25 00:01 . 2009-09-20 02:19 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVENG32.DLL
2010-01-25 00:01 . 2009-09-20 02:19 1647984 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVEX32A.DLL
2010-01-25 00:01 . 2009-09-20 02:19 1323568 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVEX15.SYS
2010-01-25 00:01 . 2009-09-20 02:19 102448 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\ERASER.SYS
2010-01-25 00:01 . 2009-12-10 09:00 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\CCERASER.DLL
2010-01-25 00:01 . 2009-09-25 08:00 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\ECMSVR32.DLL
2010-01-25 00:01 . 2009-09-20 02:19 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\EECTRL.SYS
2010-01-24 23:40 . 2010-01-24 23:40 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2010-01-24 23:40 . 2010-01-24 23:40 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-01-24 14:57 . 2010-01-24 16:04 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-24 13:39 . 2010-01-24 15:59 -------- d-----w- c:\documents and settings\Eddie Howley\Local Settings\Application Data\nqxvht
2010-01-24 11:42 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\Scxpx86.dll
2010-01-24 11:41 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSXpx86.sys
2010-01-24 11:41 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSxpx86.dll
2010-01-24 11:41 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSvix86.sys
2010-01-24 11:41 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSviA64.sys
2010-01-18 22:49 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSXpx86.sys
2010-01-18 22:49 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\Scxpx86.dll
2010-01-18 22:49 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSxpx86.dll
2010-01-18 22:49 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSvix86.sys
2010-01-18 22:49 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSviA64.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-25 18:18 . 2009-11-06 22:13 65024 ----a-r- c:\documents and settings\Eddie Howley\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
2010-01-25 18:18 . 2009-11-06 22:13 5120 ----a-r- c:\documents and settings\Eddie Howley\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
2010-01-25 18:18 . 2009-11-06 22:13 18944 ----a-r- c:\documents and settings\Eddie Howley\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
2010-01-25 18:05 . 2007-03-13 18:30 -------- d-----w- c:\program files\Common Files\Real
2010-01-25 18:05 . 2007-03-13 18:30 -------- d-----w- c:\program files\Real
2010-01-25 17:59 . 2006-11-24 21:38 -------- d-----w- c:\program files\MSN Messenger
2010-01-25 17:58 . 2007-01-07 22:20 -------- d-----w- c:\program files\Yahoo!
2010-01-25 17:58 . 2007-01-07 22:22 -------- d--h--r- c:\documents and settings\Eddie Howley\Application Data\yahoo!
2010-01-25 17:57 . 2008-01-12 16:41 -------- d-----w- c:\program files\Logitech
2010-01-25 17:56 . 2006-10-08 10:44 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-24 15:07 . 2009-11-06 22:13 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-20 20:24 . 2008-02-18 19:26 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-21 22:20 . 2006-11-24 21:22 -------- d-----w- c:\program files\Google
2009-12-21 19:14 . 2006-10-08 03:21 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-14 20:56 . 2006-11-24 21:26 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\Skype
2009-12-14 20:53 . 2009-08-03 20:27 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\skypePM
2009-12-08 20:05 . 2009-11-06 22:14 117760 ----a-w- c:\documents and settings\Eddie Howley\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-05 17:24 . 2009-12-05 17:21 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\PC Suite
2009-12-05 17:24 . 2009-12-05 17:21 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\Nokia
2009-12-05 17:24 . 2009-12-05 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-12-05 17:24 . 2009-12-05 17:24 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-12-05 17:24 . 2009-12-05 17:24 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-12-05 17:20 . 2009-12-05 17:20 -------- d-----w- c:\program files\Common Files\PCSuite
2009-12-05 17:20 . 2009-12-05 17:20 -------- d-----w- c:\program files\Common Files\Nokia
2009-12-05 17:20 . 2009-12-05 17:19 -------- d-----w- c:\program files\Nokia
2009-12-05 17:20 . 2009-06-29 20:18 -------- d-----w- c:\program files\DIFX
2009-12-05 17:20 . 2009-12-05 17:20 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-05 17:18 . 2009-12-05 17:18 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-12-05 17:18 . 2009-12-05 17:18 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-12-05 17:18 . 2009-12-05 17:18 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-12-05 17:18 . 2009-12-05 17:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-11-21 15:51 . 2006-10-08 03:21 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-05 21:37 . 2009-11-05 21:37 452104 ----a-w- c:\documents and settings\Eddie Howley\Application Data\Real\RealPlayer\setup\AU_setup9.exe
2009-10-30 01:51 . 2009-10-30 01:51 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-14 2001648]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-03-20 1312256]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 577536]
"SMSERIAL"="sm56hlpr.exe" [2004-12-29 544768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 15:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0305020.00B\SymEFA.sys [19/09/2009 12:51 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0305020.00B\BHDrvx86.sys [19/09/2009 12:51 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0305020.00B\cchpx86.sys [19/09/2009 12:51 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSXpx86.sys [24/01/2010 11:41 329592]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/10/2009 21:24 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/10/2009 21:24 74480]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe [19/09/2009 12:51 117640]
R3 EKBfltr;ENE Keyboard Controller;c:\windows\system32\drivers\EKBfltr.sys [08/10/2006 03:24 5504]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [25/01/2010 00:01 102448]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/10/2009 21:24 7408]
S2 gupdate1c9c69527525f0a;Google Update Service (gupdate1c9c69527525f0a);c:\program files\Google\Update\GoogleUpdate.exe [26/04/2009 17:33 133104]
.
Contents of the 'Scheduled Tasks' folder

2010-01-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 12:34]

2010-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-26 17:33]

2010-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-26 17:33]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uSearchMigratedDefaultURL = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
uSearchAssistant = [You must be registered and logged in to see this link.]
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
AddRemove-HijackThis - e:\mgtools\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-01-27 22:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

scanning hȋdden files ...

scan completed successfully
hȋdden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.5.2.11\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
"NoChange"="1"
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
"Installed"="1"
@=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1008)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
.
Completion time: 2010-01-27 22:57:31
ComboFix-quarantined-files.txt 2010-01-27 22:57

Pre-Run: 35,129,360,384 bytes free
Post-Run: 35,364,876,288 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 59303A907BBF4287881F078E08E6C12D

ehowley25
Beginner
Beginner

Posts Posts : 4
Joined Joined : 2010-01-25
OS OS : windows xp
Points Points : 25126
# Likes # Likes : 0

View user profile

Back to top Go down

Re: internet connection/trojans/log file from combofix

Post by Belahzur on 27th January 2010, 11:53 pm

Hello.

  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:

    DDS::
    uInternet Settings,ProxyServer = http=127.0.0.1:5555
    uInternet Settings,ProxyOverride =

    RegLock::
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]

  4. Save this as CFScript.txt, in the same location as ComboFix.exe



  5. Referring to the picture above, drag CFScript into ComboFix.exe
  6. When finished, it shall produce a log for you at C:\ComboFix.txt
  7. Please post the contents of the log in your next reply.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: internet connection/trojans/log file from combofix

Post by ehowley25 on 29th January 2010, 2:07 pm

Here is the log file from the second scan from Combofix. Are you able to tell me whats wrong with my computer and what is being fixed plz:

ComboFix 10-01-28.05 - Eddie Howley 29/01/2010 13:53:16.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.615 [GMT 0:00]
Running from: c:\documents and settings\Eddie Howley\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Eddie Howley\Desktop\CFScript.txt
AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-29 )))))))))))))))))))))))))))))))
.

2010-01-25 21:18 . 2010-01-25 21:18 -------- d-----w- C:\MGTools
2010-01-25 20:33 . 2010-01-25 20:33 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\Malwarebytes
2010-01-25 20:32 . 2010-01-25 20:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-25 17:44 . 2010-01-25 17:44 -------- d-----w- c:\program files\CCleaner
2010-01-25 15:44 . 2010-01-25 17:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-25 12:45 . 2010-01-25 12:45 -------- d-----w- c:\program files\AVG
2010-01-25 12:45 . 2010-01-25 17:24 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-25 00:45 . 2010-01-25 00:45 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2010-01-25 00:45 . 2010-01-25 00:45 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\TuneUp Software
2010-01-25 00:43 . 2010-01-25 00:43 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2010-01-25 00:43 . 2010-01-25 17:06 -------- d-----w- c:\program files\TuneUp Utilities 2009
2010-01-25 00:43 . 2010-01-25 00:43 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2010-01-25 00:01 . 2009-09-20 02:19 84912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVENG.SYS
2010-01-25 00:01 . 2009-09-20 02:19 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVENG32.DLL
2010-01-25 00:01 . 2009-09-20 02:19 1647984 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVEX32A.DLL
2010-01-25 00:01 . 2009-09-20 02:19 1323568 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\NAVEX15.SYS
2010-01-25 00:01 . 2009-09-20 02:19 102448 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\ERASER.SYS
2010-01-25 00:01 . 2009-12-10 09:00 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\CCERASER.DLL
2010-01-25 00:01 . 2009-09-25 08:00 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\ECMSVR32.DLL
2010-01-25 00:01 . 2009-09-20 02:19 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100124.021\EECTRL.SYS
2010-01-24 23:40 . 2010-01-24 23:40 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2010-01-24 23:40 . 2010-01-24 23:40 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-01-24 14:57 . 2010-01-24 16:04 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-24 13:39 . 2010-01-24 15:59 -------- d-----w- c:\documents and settings\Eddie Howley\Local Settings\Application Data\nqxvht
2010-01-24 11:42 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\Scxpx86.dll
2010-01-24 11:41 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSXpx86.sys
2010-01-24 11:41 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSxpx86.dll
2010-01-24 11:41 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSvix86.sys
2010-01-24 11:41 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSviA64.sys
2010-01-18 22:49 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSXpx86.sys
2010-01-18 22:49 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\Scxpx86.dll
2010-01-18 22:49 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSxpx86.dll
2010-01-18 22:49 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSvix86.sys
2010-01-18 22:49 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100116.002\IDSviA64.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-25 18:18 . 2009-11-06 22:13 65024 ----a-r- c:\documents and settings\Eddie Howley\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
2010-01-25 18:18 . 2009-11-06 22:13 5120 ----a-r- c:\documents and settings\Eddie Howley\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
2010-01-25 18:18 . 2009-11-06 22:13 18944 ----a-r- c:\documents and settings\Eddie Howley\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
2010-01-25 18:05 . 2007-03-13 18:30 -------- d-----w- c:\program files\Common Files\Real
2010-01-25 18:05 . 2007-03-13 18:30 -------- d-----w- c:\program files\Real
2010-01-25 17:59 . 2006-11-24 21:38 -------- d-----w- c:\program files\MSN Messenger
2010-01-25 17:58 . 2007-01-07 22:20 -------- d-----w- c:\program files\Yahoo!
2010-01-25 17:58 . 2007-01-07 22:22 -------- d--h--r- c:\documents and settings\Eddie Howley\Application Data\yahoo!
2010-01-25 17:57 . 2008-01-12 16:41 -------- d-----w- c:\program files\Logitech
2010-01-25 17:56 . 2006-10-08 10:44 -------- d-----w- c:\program files\Common Files\InstallShield
2010-01-24 15:07 . 2009-11-06 22:13 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-20 20:24 . 2008-02-18 19:26 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-21 22:20 . 2006-11-24 21:22 -------- d-----w- c:\program files\Google
2009-12-21 19:14 . 2006-10-08 03:21 916480 ------w- c:\windows\system32\wininet.dll
2009-12-14 20:56 . 2006-11-24 21:26 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\Skype
2009-12-14 20:53 . 2009-08-03 20:27 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\skypePM
2009-12-08 20:05 . 2009-11-06 22:14 117760 ----a-w- c:\documents and settings\Eddie Howley\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-05 17:24 . 2009-12-05 17:21 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\PC Suite
2009-12-05 17:24 . 2009-12-05 17:21 -------- d-----w- c:\documents and settings\Eddie Howley\Application Data\Nokia
2009-12-05 17:24 . 2009-12-05 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-12-05 17:24 . 2009-12-05 17:24 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-12-05 17:24 . 2009-12-05 17:24 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-12-05 17:20 . 2009-12-05 17:20 -------- d-----w- c:\program files\Common Files\PCSuite
2009-12-05 17:20 . 2009-12-05 17:20 -------- d-----w- c:\program files\Common Files\Nokia
2009-12-05 17:20 . 2009-12-05 17:19 -------- d-----w- c:\program files\Nokia
2009-12-05 17:20 . 2009-06-29 20:18 -------- d-----w- c:\program files\DIFX
2009-12-05 17:20 . 2009-12-05 17:20 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-05 17:18 . 2009-12-05 17:18 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-12-05 17:18 . 2009-12-05 17:18 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-12-05 17:18 . 2009-12-05 17:18 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-12-05 17:18 . 2009-12-05 17:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-11-21 15:51 . 2006-10-08 03:21 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-05 21:37 . 2009-11-05 21:37 452104 ----a-w- c:\documents and settings\Eddie Howley\Application Data\Real\RealPlayer\setup\AU_setup9.exe
.

((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-29 13:44 . 2010-01-29 13:44 16384 c:\windows\Temp\Perflib_Perfdata_7c.dat
+ 2010-01-29 13:43 . 2010-01-29 13:43 16384 c:\windows\Temp\Perflib_Perfdata_7b8.dat
- 2010-01-27 22:39 . 2010-01-27 22:39 16384 c:\windows\Temp\Perflib_Perfdata_7b8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-14 2001648]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-03-20 1312256]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"SoundMan"="SOUNDMAN.EXE" [2006-03-01 577536]
"SMSERIAL"="sm56hlpr.exe" [2004-12-29 544768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 15:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0305020.00B\SymEFA.sys [19/09/2009 12:51 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0305020.00B\BHDrvx86.sys [19/09/2009 12:51 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0305020.00B\cchpx86.sys [19/09/2009 12:51 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100119.001\IDSXpx86.sys [24/01/2010 11:41 329592]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/10/2009 21:24 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/10/2009 21:24 74480]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe [19/09/2009 12:51 117640]
R3 EKBfltr;ENE Keyboard Controller;c:\windows\system32\drivers\EKBfltr.sys [08/10/2006 03:24 5504]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [25/01/2010 00:01 102448]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/10/2009 21:24 7408]
S2 gupdate1c9c69527525f0a;Google Update Service (gupdate1c9c69527525f0a);c:\program files\Google\Update\GoogleUpdate.exe [26/04/2009 17:33 133104]
.
Contents of the 'Scheduled Tasks' folder

2010-01-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 12:34]

2010-01-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-26 17:33]

2010-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-26 17:33]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uSearchMigratedDefaultURL = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = [You must be registered and logged in to see this link.]
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-01-29 13:59
Windows 5.1.2600 Service Pack 3 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

scanning hȋdden files ...

scan completed successfully
hȋdden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.5.2.11\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.5.2.11\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1012)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(320)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-01-29 14:02:10
ComboFix-quarantined-files.txt 2010-01-29 14:01
ComboFix2.txt 2010-01-27 22:57

Pre-Run: 35,386,466,304 bytes free
Post-Run: 35,346,968,576 bytes free

- - End Of File - - 044A051B2DE9B09D19FA3C480AB4B0AE

ehowley25
Beginner
Beginner

Posts Posts : 4
Joined Joined : 2010-01-25
OS OS : windows xp
Points Points : 25126
# Likes # Likes : 0

View user profile

Back to top Go down

Re: internet connection/trojans/log file from combofix

Post by Belahzur on 29th January 2010, 5:51 pm

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /uninstall

This will also reset your restore points.

How is the machine running now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245091
# Likes # Likes : 1

View user profile

Back to top Go down

Re: internet connection/trojans/log file from combofix

Post by ehowley25 on 29th January 2010, 10:40 pm

Seems to be running okay now. Thanks again for all the help:)

ehowley25
Beginner
Beginner

Posts Posts : 4
Joined Joined : 2010-01-25
OS OS : windows xp
Points Points : 25126
# Likes # Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum