Malwarebytes

View previous topic View next topic Go down

Malwarebytes

Post by Joey Jiggles on 22nd April 2009, 1:50 pm

Important computer.. can you please take a look? I don't know where these came from..

Thanks

Malwarebytes' Anti-Malware 1.36
Database version: 1952
Windows 5.1.2600 Service Pack 3

4/22/2009 9:37:40 AM
mbam-log-2009-04-22 (09-37-40).txt

Scan type: Quick Scan
Objects scanned: 84602
Time elapsed: 4 minute(s), 26 second(s)

Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
C:\WINDOWS\sysguard.exe (Trojan.FakeAlert) -> Unloaded process successfully.
C:\WINDOWS\system32\drivers\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Failed to unload process.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\AvScan (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\system tool (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\drivers\svchost.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\sysguard.exe (Trojan.Agent) -> Quarantined and deleted successfully.

Joey Jiggles
Intermediate
Intermediate

Posts Posts : 187
Joined Joined : 2009-01-12
OS OS : Windows XP
Points Points : 30346
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malwarebytes

Post by Belahzur on 22nd April 2009, 2:00 pm

Hello.

First, please update MBAM.

Database version: 1952

Go into the update tab and check for update. Newest database should be 2025 [at the time of posting this]

Once updated, run another scan.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245121
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Malwarebytes

Post by Joey Jiggles on 22nd April 2009, 2:07 pm

Malwarebytes' Anti-Malware 1.36
Database version: 2025
Windows 5.1.2600 Service Pack 3

4/22/2009 10:07:28 AM
mbam-log-2009-04-22 (10-07-28).txt

Scan type: Quick Scan
Objects scanned: 87809
Time elapsed: 1 minute(s), 30 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 6
Files Infected: 57

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\ErrorSmart (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ErrorSmart (Rogue.ErrorSmart) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\ErrorSmart (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Program Files\ErrorSmart\Microsoft.VC80.CRT (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Program Files\ErrorSmart\Microsoft.VC80.MFC (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Log (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups (Rogue.ErrorSmart) -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\Debbie\Local Settings\Temporary Internet Files\Content.IE5\ZR0ONQLF\kKNsMFGH[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Log\2008 Nov 13 - 09_09_28 AM_487.log (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Log\2008 Nov 13 - 09_09_33 AM_128.log (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-02-01_11-27-50.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-02-01_11-37-08.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-02-05_07-44-12.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-02-07_07-50-58.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-02-12_08-55-49.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-02-13_08-23-11.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-02-14_12-37-03.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-02-20_08-31-08.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-02-26_07-55-45.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-02-28_07-47-54.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-02-29_08-33-44.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-03-04_08-32-15.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-03-11_08-27-45.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-03-14_08-31-06.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-03-18_07-47-05.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-03-26_07-26-46.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-04-01_09-01-05.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-04-09_07-50-27.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-04-11_07-57-53.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-04-14_08-45-03.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-04-24_09-05-48.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-04-29_09-11-14.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-05-13_09-37-32.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-05-19_08-09-58.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-05-28_07-54-09.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-06-10_07-48-10.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-06-12_07-49-27.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-06-18_08-22-45.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-06-23_07-40-00.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-06-25_07-51-19.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-07-01_08-03-08.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-07-10_08-06-10.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-07-11_07-39-25.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-07-17_08-50-08.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-07-24_07-34-45.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-08-01_07-41-05.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-08-04_08-17-18.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-08-11_08-23-11.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-08-13_08-50-33.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-08-15_10-52-44.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-08-20_07-31-42.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-09-08_09-02-39.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-09-11_07-45-00.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-09-17_08-58-00.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-09-22_08-12-27.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-09-23_07-45-18.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-10-02_07-51-22.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-10-03_08-17-22.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-10-16_08-00-37.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-10-27_08-12-13.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-11-05_07-53-05.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Debbie\Application Data\ErrorSmart\Registry Backups\2008-11-11_08-12-30.reg (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\WINDOWS/Tasks/ErrorSmart Scheduled Scan.job (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.

Joey Jiggles
Intermediate
Intermediate

Posts Posts : 187
Joined Joined : 2009-01-12
OS OS : Windows XP
Points Points : 30346
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malwarebytes

Post by Belahzur on 22nd April 2009, 2:52 pm


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run
  • When complete, DDS.txt will open.
  • Save the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245121
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Malwarebytes

Post by Joey Jiggles on 22nd April 2009, 3:07 pm

DDS (Ver_09-03-16.01) - NTFSx86
Run by Debbie at 11:05:26.75 on Wed 04/22/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1197 [GMT -4:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Documents and Settings\All Users\Application Data\SeekeenSrch\seekeen147.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\SeekeenSrch\seekeen.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\AOL\1170340513\ee\AOLSoftware.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wltray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dynex G USB Network Adapter\DynexWCUI.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Intuit\QuickBooks Premier\qbw32.exe
C:\Program Files\Common Files\Intuit\QuickBooks\axlbridge.exe
C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgr.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Debbie\Desktop\HiJackTHIS\dds.scr

============== Pseudo HJT Report ===============

uStart Page = [You must be registered and logged in to see this link.]
uSearch Page = [You must be registered and logged in to see this link.]
uSearch Bar = [You must be registered and logged in to see this link.]
uDefault_Page_URL = [You must be registered and logged in to see this link.]
mDefault_Page_URL = [You must be registered and logged in to see this link.]
mDefault_Search_URL = [You must be registered and logged in to see this link.]
mStart Page = [You must be registered and logged in to see this link.]
uInternet Settings,ProxyOverride = localhost;*.local
uSearchAssistant = [You must be registered and logged in to see this link.]
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
mSearchAssistant = [You must be registered and logged in to see this link.]
uURLSearchHooks: H - No File
uURLSearchHooks: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aim search\AOLSearch.dll
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Freecorder Toolbar: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - c:\program files\freecorder\tbFre1.dll
BHO: Smart-Shopper: {4a7c84e2-e95c-43c6-8dd3-03abcd0eb60e} - c:\program files\smart-shopper\bin\2.5.1\Smrt-Shpr.dll
BHO: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aim search\AOLSearch.dll
BHO: ALOT Toolbar: {5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} - c:\program files\alot\bin\alot.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll
BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll
BHO: NetAssistantBHO Class: {e38fa08e-f56a-4169-abf5-5c71e3c153a1} - c:\program files\my.freeze.com toolbar\NetAssistant.dll
BHO: XBTBPos00 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\my.freeze.com toolbar\freeze_us.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: ALOT Toolbar: {5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} - c:\program files\alot\bin\alot.dll
TB: My.Freeze.com Toolbar: {d0523bb4-21e7-11dd-9ab7-415b56d89593} - c:\program files\my.freeze.com toolbar\freeze_us.dll
TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
TB: Freecorder Toolbar: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - c:\program files\freecorder\tbFre1.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: SmartShopper: {8bcb5337-ec01-4e38-840c-a964f174255b} - c:\program files\smart-shopper\bin\2.5.1\Smrt-Shpr.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [LDM] c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [OM_Monitor] c:\program files\olympus\olympus master\Monitor.exe
uRun: [YSearchProtection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US [You must be registered and logged in to see this link.]
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [AOLDialer] c:\program files\common files\aol\acs\AOLDial.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [HostManager] c:\program files\common files\aol\1170340513\ee\AOLSoftware.exe
mRun: [OM_Monitor] c:\program files\olympus\olympus master\FirstStart.exe
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [trioService] "c:\progra~1\freeze.com\living 3d dolphins\trioService.exe "
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Broadcom Wireless Manager] c:\windows\system32\wltray.exe
mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup
mRunOnce: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dynexw~1.lnk - c:\program files\dynex g usb network adapter\DynexWCUI.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\KEM.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
IE: &AIM Toolbar Search - c:\documents and settings\all users\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB}
IE: {925DAB62-F9AC-4221-806A-057BFB1014AA}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
IE: {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - {6FAC4823-815E-4361-836E-46D65ED2550B} - c:\program files\smart-shopper\bin\2.5.1\Smrt-Shpr.dll
IE: {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - {4CF088BD-BE95-40a5-BE9B-677F8683EDEA} - c:\program files\smart-shopper\bin\2.5.1\Smrt-Shpr.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [You must be registered and logged in to see this link.]
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - [You must be registered and logged in to see this link.]
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\intuit\quickbooks 2009\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

Joey Jiggles
Intermediate
Intermediate

Posts Posts : 187
Joined Joined : 2009-01-12
OS OS : Windows XP
Points Points : 30346
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malwarebytes

Post by Joey Jiggles on 22nd April 2009, 3:07 pm

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\debbie\applic~1\mozilla\firefox\profiles\2jrzubqj.default\
FF - prefs.js: browser.search.defaulturl - [You must be registered and logged in to see this link.]
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - prefs.js: keyword.URL - [You must be registered and logged in to see this link.]
FF - component: c:\documents and settings\debbie\application data\mozilla\firefox\profiles\2jrzubqj.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFAlert.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

============= SERVICES / DRIVERS ===============

R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 SeekeenSrch Service;SeekeenSrch Service;c:\documents and settings\all users\application data\seekeensrch\seekeen147.exe [2009-3-5 4608]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-1-30 24652]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-4-8 38496]
R3 NdisWDM;Dynex Wireless G USB Network Adapter Service;c:\windows\system32\drivers\NdisWDM.sys [2009-3-2 198144]

=============== Created Last 30 ================

2009-04-22 10:08 61,440 a------- c:\windows\system32\drivers\njijqlo.sys
2009-04-22 09:50 61,440 a------- c:\windows\system32\drivers\wqgie.sys
2009-04-21 15:00 --d----- c:\program files\ASIO4ALL v2
2009-04-21 14:59 225,280 a------- c:\windows\system32\rewire.dll
2009-04-21 14:59 --d----- c:\program files\VstPlugins
2009-04-21 14:59 1,294,336 a------- c:\windows\system32\vorbis.acm
2009-04-21 14:59 --d----- c:\program files\Outsim
2009-04-21 14:58 --d----- c:\program files\Image-Line
2009-04-17 16:04 --d----- c:\docume~1\alluse~1\applic~1\Ableton
2009-04-17 16:04 --d----- c:\docume~1\debbie\applic~1\Ableton
2009-04-08 14:44 --d----- c:\docume~1\debbie\applic~1\Malwarebytes
2009-04-08 14:44 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-04-08 14:44 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-08 14:44 --d----- c:\program files\Malwarebytes' Anti-Malware
2009-04-08 14:44 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-07 09:43 --d----- c:\program files\Freecorder
2009-04-07 09:43 --d----- c:\program files\Conduit
2009-04-07 09:42 --d----- c:\windows\Freecorder Toolbar
2009-04-07 09:42 --d----- c:\program files\Freecorder Toolbar
2009-04-03 14:55 3,833,856 a------- c:\windows\system32\cdintf300.dll
2009-04-03 14:49 95 a------- c:\windows\QBChanUtil_Trigger.ini
2009-04-03 14:49 --d----- c:\docume~1\alluse~1\applic~1\SQL Anywhere 10
2009-04-03 12:11 --d----- c:\program files\Akamai

==================== Find3M ====================

2009-02-26 09:50 89,191 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-02-09 07:13 1,846,784 a------- c:\windows\system32\win32k.sys
2009-02-09 07:13 1,846,784 -------- c:\windows\system32\dllcache\win32k.sys
2009-01-28 11:17 7,518,240 a------- c:\program files\Firefox Setup 3.0.5.exe
2006-10-26 11:07 0 a---h--- c:\docume~1\alluse~1\applic~1\gwseh.dat

============= FINISH: 11:05:43.68 ===============

Joey Jiggles
Intermediate
Intermediate

Posts Posts : 187
Joined Joined : 2009-01-12
OS OS : Windows XP
Points Points : 30346
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malwarebytes

Post by Belahzur on 22nd April 2009, 3:12 pm

Please download the current version of HijackThis from [You must be registered and logged in to see this link.]

  • Double click and run the installer.
  • It will install to C:\Program Files\Trend Micro\HijackThis\hijackthis.exe
  • After installing, you should get the user agreement, press accept and Hijack This will run.
  • When Hijack This opens, click "Open the Misc Tools section"
  • Then select "Open Uninstall Manager"
  • Click on "Save List..." (generates uninstall_list.txt)
  • Click Save, copy and paste the results in your next post.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245121
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Malwarebytes

Post by Joey Jiggles on 22nd April 2009, 3:16 pm

Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 7.1.0
Adobe Shockwave Player
AIM 6
AIM Search
AIM Toolbar
ALOT Toolbar
AOL Coach Version 1.0(Build:20040229.1 en)
AOL Uninstaller (Choose which Products to Remove)
AOLIcon
Apple Mobile Device Support
Apple Software Update
ASIO4ALL
Banctec Service Agreement
Bonjour
Collab
Compatibility Pack for the 2007 Office system
Conexant D850 56K V.9x DFVc Modem
Critical Update for Windows Media Player 11 (KB959772)
Dell CinePlayer
Dell Driver Reset Tool
Digital Content Portal
Digital Line Detect
Documentation & Support Launcher
Download Updater (AOL LLC)
Dynex Wireless G USB Network Adapter Setup
FL Studio 8
Freecorder Toolbar
Freecorder Toolbar 3.02 Application
Games, Music, & Photos Launcher
GemMaster Mystic
Google Toolbar for Internet Explorer
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
HP Deskjet 6900 series
hp deskjet 940c series (Remove only)
HP Extended Capabilities 6.0
HP Imaging Device Functions 6.0
HP Photosmart Essential
HP Software Update
HP Solution Center and Imaging Support Tools 6.0
IL Download Manager
ImageMixer VCD/DVD2 for OLYMPUS
Intel(R) Matrix Storage Manager
Intel(R) Quick Resume Technology Drivers
Intel® Viiv™ Software
Internet Service Offers Launcher
iTunes
J2SE Runtime Environment 5.0 Update 6
Living 3D Dolphins Screen Saver
Logitech Desktop Messenger
Logitech SetPoint
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office 2003 Primary Interop Assemblies
Microsoft Office Professional Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual Studio 2005 Tools for Office Runtime
Modem Helper
Mozilla Firefox (3.0.8)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
My.Freeze.com Toolbar
NetWaiting
NVIDIA Drivers
OLYMPUS Master
Otto
PEM Software Systems, Inc
PoiZone
QuickBooks
QuickBooks Premier: Contractor Edition 2009
QuickBooks Pro 2007
QuickBooks Product Listing Service
QuickTime
RealPlayer
RelevantKnowledge
Roxio DLA
Roxio Express Labeler
Roxio MyDVD Plus
Roxio RecordNow Audio
Roxio RecordNow Copy
Roxio RecordNow Data
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Seekeen 1.0 build 147
SmartShopper
Sonic Activation Module
Sonic Encoders
Sonic Update Manager
SupportSoft Assisted Service
Toxic Biohazard
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update Rollup 2 for Windows XP Media Center Edition 2005
Viewpoint Media Player
Visual Studio 2005 Tools for Office Second Edition Runtime
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows Media Player 11
Windows Media Player 11
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB925766
Windows XP Service Pack 3
WinRAR archiver
Yahoo! Search Protection
Yahoo! Toolbar

Joey Jiggles
Intermediate
Intermediate

Posts Posts : 187
Joined Joined : 2009-01-12
OS OS : Windows XP
Points Points : 30346
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malwarebytes

Post by Belahzur on 22nd April 2009, 3:38 pm

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

  • ALOT Toolbar
  • J2SE Runtime Environment 5.0 Update 6
  • My.Freeze.com Toolbar
  • Seekeen 1.0 build 147
  • SmartShopper
  • Viewpoint Media Player

Please download the [You must be registered and logged in to see this link.].

  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :files
    c:\documents and settings\all users\application data\seekeensrch
    c:\program files\viewpoint
    c:\windows\system32\drivers\njijqlo.sys
    c:\windows\system32\drivers\wqgie.sys


  • Return to OTMoveIt3, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245121
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Malwarebytes

Post by Joey Jiggles on 22nd April 2009, 3:57 pm

========== FILES ==========
File/Folder c:\documents and settings\all users\application data\seekeensrch not found.
File/Folder c:\program files\viewpoint not found.
c:\windows\system32\drivers\njijqlo.sys moved successfully.
c:\windows\system32\drivers\wqgie.sys moved successfully.

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04222009_115727

Joey Jiggles
Intermediate
Intermediate

Posts Posts : 187
Joined Joined : 2009-01-12
OS OS : Windows XP
Points Points : 30346
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Malwarebytes

Post by Belahzur on 22nd April 2009, 4:12 pm

We can remove OTMoveIt now.

  • Please double-click OTMoveIt3.exe to run it again.
  • Press the green CleanUp! button.
  • Press Yes cleanup process prompt, do the same for the reboot prompt.
How is the machine running now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245121
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Malwarebytes

Post by Joey Jiggles on 22nd April 2009, 4:35 pm

seems to run great... thank you. I had to take this computer over at work and I decided to run a scan.

Can't thank you enough :-)

Joey Jiggles
Intermediate
Intermediate

Posts Posts : 187
Joined Joined : 2009-01-12
OS OS : Windows XP
Points Points : 30346
# Likes # Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum