1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Generic host process for win32 services has encountered a problem and needs to close.

Discussion in 'Malware and Virus Removal Archive' started by CDF, 2007/01/17.

  1. 2007/01/28
    CDF

    CDF Inactive Thread Starter

    Joined:
    2007/01/17
    Messages:
    21
    Likes Received:
    0
    Hi Temerc,

    Thanks for this. I am trying to follow your instructions but I cannot get Fixwareout to work, the site Subratam has been suspended so I downloaded it from Bleeping Computing, it downloaded ok but when I try and run it I get what looks like the C prompt screen for a split second and then nothing. I have gone to my desktop and ran it from there but still the same, any sugestions ???

    Many Thanks

    Regards

    Iain
     
    CDF,
    #21
  2. 2007/01/28
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Seems a little odd, tho it should have been run from the desktop in the first place. Try downloading a fresh copy.

    The Subratam site works fine for me btw.
     

  3. to hide this advert.

  4. 2007/01/28
    CDF

    CDF Inactive Thread Starter

    Joined:
    2007/01/17
    Messages:
    21
    Likes Received:
    0
    I have tried Subratam again and it worked this time but I still can't install it. If I right click the icon on my desktop and click run as and then just click ok in the next screen I get an error box titled 16 Bit Dos System with this message.

    "C:\Documets\IJS\Desktop\Fixware.exe.
    C:\Documents\IJS\Locals1\Temp\A temporay file needed for initilization could not be created or could not be written to. Make sure that the directory path exists and disk space is available. Choose Close to terminate the application "

    I have a choice of Close or Ignore if I click ignore nothing happens.
     
    CDF,
    #23
  5. 2007/01/28
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Ok, what happens when you just double-click the file to run it, same thing??
     
  6. 2007/01/28
    CDF

    CDF Inactive Thread Starter

    Joined:
    2007/01/17
    Messages:
    21
    Likes Received:
    0
    Hi Tecmerc,

    Yes the same thing, I have downloaded it several times, well I say the same thing, when I double click it I don't get the message I just get a quick flash of the MS Dos window for a split second and then nothing. I found in the properties window of fixwareout an option to unblock a file as that may stop the program from installing so I unblocked it but no difference.

    Thanks
     
    CDF,
    #25
  7. 2007/01/28
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    I'll have to check with the devloper then, I've not seen nor ever encountered a user having problems running this tool.
     
  8. 2007/01/29
    CDF

    CDF Inactive Thread Starter

    Joined:
    2007/01/17
    Messages:
    21
    Likes Received:
    0
    Hi Temerc,

    I have downloaded again Fixwareout five times and on the fifth occasion I managed to get it to install and run so here is the log file follwed by a new HJT file. I will now reboot and run haxfix.exe

    Thanks

    Fixwareout

    Fixwareout
    Last edited 1/27/2007
    Post this report in the forums please
    ...
    Prerun check
    »»»»» HKLM run and Winlogon System values
    »»»»» System restarted
    ...
    Reg Entries that were deleted
    ...
    Random Runs removed from HKLM
    ...

    PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

    »»»»» Searching by size/names...

    »»»»»
    Search five digit cs, dm kd and jb files.
    This WILL/CAN also list Legit Files, Submit them at Virustotal

    Other suspects.

    »»»»» Misc files.

    »»»»» Checking for older varients covered by the Rem3 tool.

    »»»»» Postrun check
    »»»»» HKLM run
    »»»»» Winlogon System value
    "system "=" "
    »»»»»


    »»»»» Current runs

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MCUpdateExe "= "c:\\PROGRA~1\\mcafee.com\\agent\\mcupdate.exe "
    "DLCCCATS "= "rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\DLCCtime.dll,_RunDLLEntry@16 "
    "Barclays Business Manager "= "C:\\Program Files\\Barclays\\Business Manager\\bin\\BarclaysBusinessManager.exe /server "
    "MSKAGENTEXE "= "C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MskAgent.exe "
    "dlccmon.exe "= "\ "C:\\Program Files\\Dell Photo AIO Printer 924\\dlccmon.exe\" "
    "WinFaxAppPortStarter "= "wfxsnt40.exe "
    "WFXSwtch "= "C:\\PROGRA~1\\WinFax\\WFXSWTCH.exe "
    "VSOCheckTask "= "\ "C:\\PROGRA~1\\McAfee.com\\VSO\\mcmnhdlr.exe\" /checktask "
    "VirusScan Online "= "C:\\Program Files\\McAfee.com\\VSO\\mcvsshld.exe "
    "TkBellExe "= "\ "C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot "
    "SunJavaUpdateSched "= "C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\jusched.exe "
    "SigmatelSysTrayApp "= "stsystra.exe "
    "QuickTime Task "= "\ "C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime "
    "PWRISOVM.EXE "= "C:\\Program Files\\PowerISO\\PWRISOVM.EXE "
    "OASClnt "= "C:\\Program Files\\McAfee.com\\VSO\\oasclnt.exe "
    "NvCplDaemon "= "RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup "
    "MSKDetectorExe "= "C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MSKDetct.exe /startup "
    "MPSExe "= "c:\\PROGRA~1\\mcafee.com\\mps\\mscifapp.exe /embedding "
    "MPFExe "= "C:\\PROGRA~1\\McAfee.com\\PERSON~1\\MpfTray.exe "
    "MCAgentExe "= "c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe "
    "iTunesHelper "= "\ "C:\\Program Files\\iTunes\\iTunesHelper.exe\" "
    "ISUSScheduler "= "\ "C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start "
    "ISUSPM Startup "= "\ "C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -startup "
    "IAAnotif "= "C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\iaanotif.exe "
    "HP Software Update "= "\ "C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe\" "
    "Google Desktop Search "= "\ "C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup "
    "WinPatrol "= "C:\\Program Files\\BillP Studios\\WinPatrol\\winpatrol.exe "
    "UserFaultCheck "=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,\
    6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,75,00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
    "Installed "= "1 "

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
    "Installed "= "1 "
    "NoChange "= "1 "

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
    "Installed "= "1 "

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DellSupport "= "\ "C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup "
    "Skype "= "\ "C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized "
    "MSMSGS "= "\ "C:\\Program Files\\Messenger\\msmsgs.exe\" /background "


    HJT Log


    Logfile of HijackThis v1.99.1
    Scan saved at 08:42:09, on 29/01/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\WFXSVC.EXE
    C:\Program Files\WinFax\WFXMOD32.EXE
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
    C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
    C:\WINDOWS\system32\wfxsnt40.exe
    C:\PROGRA~1\WinFax\WFXSWTCH.exe
    C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\WINDOWS\system32\dlcccoms.exe
    c:\program files\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\Program Files\McAfee.com\VSO\oasclnt.exe
    C:\Program Files\Barclays\Business Manager\rsrc\binaries\main\BarclaysBusinessManager0001.exe
    C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trafficswarm.com/cgi-bin/swarm.cgi?590495&1d9281f76a13020047615375f42ad590
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\PROGRA~1\mcafee.com\mps\mcbrhlpr.dll
    O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
    O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
    O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [Barclays Business Manager] C:\Program Files\Barclays\Business Manager\bin\BarclaysBusinessManager.exe /server
    O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
    O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe "
    O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
    O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\WinFax\WFXSWTCH.exe
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
    O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe "
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Palo Alto Software Update Manager 8.0.lnk = C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
    O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
    O16 - DPF: {B40B74C9-C9B3-445C-9397-EC8285292947} (WebImageFX.WIFXLoader) - http://www.responsemagic.com/ewebeditpro4/webimagefx.cab
    O16 - DPF: {DB1B4C3B-8690-43B2-9045-91EDA7A12580} (eWebEditProLibCtl4.eWEPLoader) - http://www.responsemagic.com/ewebeditpro4/ewebeditpro4.cab
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - c:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
    O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.3\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
    O23 - Service: SQL Server (MSSQLSERVER) (MSSQLSERVER) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER (file missing)
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE
     
    CDF,
    #27
  9. 2007/01/29
    CDF

    CDF Inactive Thread Starter

    Joined:
    2007/01/17
    Messages:
    21
    Likes Received:
    0
    Hi Temerc,

    Haxfix log

    HAXFIX logfile - by Marckie

    version 4.37
    29/01/2007 8:49:43.89

    --- Checking for Haxdoor ---

    checking for a3d files
    a3d files not found

    checking for matching notify keys
    no matching notify keys found

    checking for matching services
    no matching services found

    checking for matching safeboot services
    no matching safeboot services found

    checking for other Haxdoor-files
    no other Haxdoor-files found


    --- Checking for Goldun ---


    checking for SSODL keys
    no ssodl keys found

    checking for notify keys
    no notify keys found

    checking for services
    no services found

    checking for other Goldun-files
    no other Goldun-files found

    checking iexplore.exe
    iexplore.exe is not infected


    Finished!
     
    CDF,
    #28
  10. 2007/01/29
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    OK, nothing in those logs, lets keep digging around and see what we can find via online scans.

    Panda ActiveScan
    • Click the [Scan your PC] button. ( You may have to disable any pop up blockers)
    • Then press the green [Check Now] button.
    • Enter your country and state along with a valid email address.
    • Allow the ActiveX install, it may be a few minutes for all components. (For XP SP 2 watch for the yellow bar at the top of IE)
    • Once installation is complete you will need to select a device to scan. Please select 'My Computer' and the scan will begin.
    • Once the scan is done, click the 'See report' button, then the 'save report' button. Be sure to save the log file created in a place easy for you to find.



    Kaspersky Online Scanner

    Click on Kaspersky Online Scanner icon.
    Accept the Kaspersky agreement and the program will load.
    You will then be prompted to install an ActiveX component from Kaspersky, click Yes

    The program will then begin downloading the latest definition files. This will take a good while, even with hi-speed Internet access.
    Once the files have been downloaded click on Next

    Now click on [Scan Settings] button.
    In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
    • Extended (if available otherwise Standard)
    • Scan Options:
      Scan Archives
      Scan Mail Bases
    Click OK

    Now under the Please select a target to scan:
    Select My Computer

    The program will begin the scanning process.
    The scan will take a while so be patient and let it run.
    Once the scan is complete it will display if your system has been infected.
    Then click on the [Save as Text] button
    Save the file to your desktop.

    Copy and paste that information in your next post for me to review.

    **Note:please edit out any references to 'cookies', 'Recyler folder' and 'System Volume Information Folder' from all logs
     
  11. 2007/01/29
    CDF

    CDF Inactive Thread Starter

    Joined:
    2007/01/17
    Messages:
    21
    Likes Received:
    0
    Ok Thanks Temerc

    Activescan log excluding cookies.

    Incident Status Location

    Potentially unwanted tool:Application/Service9x Not disinfected C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll
    Adware:adware/comet Not disinfected C:\Documents and Settings\IJS\Application Data\Starware

    Potentially unwanted tool:Application/Service9x Not disinfected C:\drivers\printer\924\drivers\Win_XP2K\i386\dlcctime.dl_[C:\drivers\printer\924\drivers\Win_XP2K\i386\dlcctime.dll]
    Potentially unwanted tool:Application/Processor Not disinfected C:\Program Files\HaxFix\Process.exe
    Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\process.exe
    Potentially unwanted tool:Application/Service9x Not disinfected C:\WINDOWS\system32\spool\drivers\w32x86\dell_photo_aio_printae86\dlcctime.dll

    Kaspersky Log


    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Monday, January 29, 2007 10:29:20 PM
    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.83.0
    Kaspersky Anti-Virus database last update: 29/01/2007
    Kaspersky Anti-Virus database records: 263047
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    C:\
    D:\
    E:\
    F:\
    G:\
    H:\
    I:\
    Y:\

    Scan Statistics:
    Total number of scanned objects: 127725
    Number of viruses found: 0
    Number of infected objects: 0 / 0
    Number of suspicious objects: 0
    Duration of the scan process: 01:18:07

    Infected Object Name / Virus Name / Last Action
    C:\Documents and Settings\All Users\Application Data\McAfee\SpamKiller\Logs\Filtering.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Logs\TaskScheduler\McTskshd000.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\McAfee.com\VSO\OASLogs\OAS.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall\data\hwcache.xdb Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_50e417e0-e461-474b-96e2-077b80325612 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd0f406f22f86965492c225b5de715e8_50e417e0-e461-474b-96e2-077b80325612 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Microsoft\Outlook\Outlook.NK2 Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Microsoft\Outlook\Outlook.srs Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Skype\drchill32\call256.dbb Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Skype\drchill32\callmember256.dbb Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Skype\drchill32\chat512.dbb Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Skype\drchill32\chatmsg256.dbb Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Skype\drchill32\chatmsg512.dbb Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Skype\drchill32\contactgroup256.dbb Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Skype\drchill32\index2.dat Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Skype\drchill32\profile16384.dbb Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Skype\drchill32\transfer512.dbb Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Skype\drchill32\user1024.dbb Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Skype\drchill32\user16384.dbb Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Skype\drchill32\user4096.dbb Object is locked skipped
    C:\Documents and Settings\IJS\Application Data\Skype\drchill32\voicemail256.dbb Object is locked skipped
    C:\Documents and Settings\IJS\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\ApplicationHistory\hpqgalry.exe.cf8dd223.ini.inuse Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\Microsoft\Outlook\Customers.pst Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\History\History.IE5\MSHist012007012920070130\index.dat Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Temp\hpodvd09.log Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Temp\sqlite_8BES8OE0KUQlJzJ Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Temp\tmp516.tmp Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Temp\tmp9DC.tmp Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Temp\~DFC409.tmp Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Temp\~DFEDFE.tmp Object is locked skipped
    C:\Documents and Settings\IJS\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\IJS\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\IJS\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_1c4.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\master.mdf Object is locked skipped
    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\mastlog.ldf Object is locked skipped
    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\model.mdf Object is locked skipped
    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\modellog.ldf Object is locked skipped
    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdbdata.mdf Object is locked skipped
    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdblog.ldf Object is locked skipped
    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\tempdb.mdf Object is locked skipped
    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\templog.ldf Object is locked skipped
    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\ERRORLOG Object is locked skipped
    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\log_187.trc Object is locked skipped
    C:\Program Files\WinFax\Data\Status.WFD Object is locked skipped
    C:\Program Files\WinFax\Data\Status.WFF Object is locked skipped
    C:\Program Files\WinFax\Data\Status.WFG Object is locked skipped
    C:\Program Files\WinFax\Data\Status.WFR Object is locked skipped
    C:\Program Files\WinFax\Data\Status.WFX Object is locked skipped
    C:\Program Files\WinFax\Data\Status2.WFD Object is locked skipped
    C:\Program Files\WinFax\Data\Status2.WFG Object is locked skipped
    C:\Program Files\WinFax\Data\Status2.WFX Object is locked skipped
    C:\Program Files\WinFax\Data\Status3.WFD Object is locked skipped
    C:\Program Files\WinFax\Data\Status3.WFG Object is locked skipped
    C:\Program Files\WinFax\Data\Status3.WFX Object is locked skipped
    C:\Program Files\WinFax\Data\StatusS.WFD Object is locked skipped
    C:\Program Files\WinFax\Data\StatusS.WFG Object is locked skipped
    C:\Program Files\WinFax\Data\StatusS.WFX Object is locked skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP8\change.log Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\ModemLog_Conexant D850 56K V.9x DFVc Modem.txt Object is locked skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    Scan process completed.


    Thanks

    Iain
     
    CDF,
    #30
  12. 2007/01/29
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
  13. 2007/01/30
    CDF

    CDF Inactive Thread Starter

    Joined:
    2007/01/17
    Messages:
    21
    Likes Received:
    0
    Hi Temerc,

    The system file checker doesn't work I just get a quick flash of the MS Dos box and then nothing, this is the result of chk dsk:

    Microsoft Windows XP [Version 5.1.2600]
    (C) Copyright 1985-2001 Microsoft Corp.

    C:\Documents and Settings\IJS>chkdsk c:
    The type of the file system is NTFS.

    WARNING! F parameter not specified.
    Running CHKDSK in read-only mode.

    CHKDSK is verifying files (stage 1 of 3)...
    File verification completed.
    CHKDSK is verifying indexes (stage 2 of 3)...
    Index verification completed.
    CHKDSK is recovering lost files.
    CHKDSK is verifying security descriptors (stage 3 of 3)...
    Security descriptor verification completed.
    CHKDSK discovered free space marked as allocated in the
    master file table (MFT) bitmap.
    Correcting errors in the Volume Bitmap.
    Windows found problems with the file system.
    Run CHKDSK with the /F (fix) option to correct these.

    309291412 KB total disk space.
    29635112 KB in 130509 files.
    46552 KB in 9694 indexes.
    0 KB in bad sectors.
    228908 KB in use by the system.
    65536 KB occupied by the log file.
    279380840 KB available on disk.

    4096 bytes in each allocation unit.
    77322853 total allocation units on disk.
    69845210 allocation units available on disk.

    C:\Documents and Settings\IJS>

    Do I need to run this with the 'F' option selected?

    Thanks

    Iain
     
    CDF,
    #32
  14. 2007/01/30
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Yes please do.
     
  15. 2007/01/30
    CDF

    CDF Inactive Thread Starter

    Joined:
    2007/01/17
    Messages:
    21
    Likes Received:
    0
    Hi Temerc,

    I have ran chkdsk/f but the system will only do it on a reboot when this happens it tells me the disk is clean so i then ran it again with no /f and got the same report as above??????

    Any suggestions

    Thanks

    Iain
     
    CDF,
    #34
  16. 2007/01/30
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    If the system no longer says it's required to run the /f option, then your ok.

    Not sure which way to proceed, I'll have to do some digging around.
     
  17. 2007/01/30
    CDF

    CDF Inactive Thread Starter

    Joined:
    2007/01/17
    Messages:
    21
    Likes Received:
    0
    Hi Temerc,

    No the system still says run the f option which is odd because I accept to schedule the f option on the next start up and then reboot. It does the check on reboot but says disk is clean and then when I run chkdsk without the f I then get the request to run the f option again its as if on the reboot with the f option scheduled it doesn't actually fix it???????

    I will leave it with you and thanks for the help so far!!

    Regards

    Iain
     
    CDF,
    #36
  18. 2007/01/31
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    I'm not very well versed in some of the problems with system utilities so I'm going to ask one of the other members to peek at this problem with chkdsk.
     
  19. 2007/02/01
    CDF

    CDF Inactive Thread Starter

    Joined:
    2007/01/17
    Messages:
    21
    Likes Received:
    0
    OK Thanks!
     
    CDF,
    #38
  20. 2007/02/01
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hello Iain,

    Go to the HD manufacturer's site and download/install the diagnostic program for the hard drive.

    Regards - Charles
     
  21. 2007/02/20
    bcp

    bcp Inactive

    Joined:
    2007/02/20
    Messages:
    1
    Likes Received:
    0
    try this

    try running it chkdsk /r
     
    bcp,
    #40

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.