1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Virus.Win32.sality.aa

Discussion in 'Malware and Virus Removal Archive' started by Andy Cool, 2009/10/24.

  1. 2009/10/24
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    [Resolved] Virus.Win32.sality.aa

    Hi guys..

    I have a Virus.Win32.Sality.aa on my the memory stick of my camera.. I was trying to download some picture to my laptop and Kaspersky detected however I was unable to remove..
    Kaspersky kept on scaning the Memory stick and the virus multiplying...

    Appreciate your help.

    Regards,

    Andy
     
  2. 2009/10/24
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Stop using that memory stick immediately!
    Sality is one of polymorphic viruses, which is NOT curable.
    The only way of dealing with it is to either throw the stick away, or fully format it, but not without precautions.
    Unfortunately, one the file types, prone to Sality infection are graphic files.
    Let me know, what you want to do with that stick and we'll go from there.

    We also have to make sure, your computer is OK.

    Upload following files to http://www.virustotal.com/ for security check:
    - explorer.exe located @ C:\Windows
    - userinit.exe and svchost.exe located @ C:\Windows\System32
    Post scans results.
     

  3. to hide this advert.

  4. 2009/10/25
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Hi broni,
    Kasperksy spotted the virus and i neutralized it but i'm not sure if the memory stick was cured or not.
    I have no issues in formatting the stick; however is there a way to check if the pics were infected or I can use them??
    I have run kaspersky full system scan and no virus was given.

    below are scan the scan result you have asked for:


    File userinit.exe received on 2009.10.23 23:25:48 (UTC)
    Current status: finished
    Result: 0/41 (0.00%)
    Compact
    Print results
    Antivirus Version Last Update Result
    a-squared 4.5.0.41 2009.10.23 -
    AhnLab-V3 5.0.0.2 2009.10.23 -
    AntiVir 7.9.1.44 2009.10.23 -
    Antiy-AVL 2.0.3.7 2009.10.23 -
    Authentium 5.1.2.4 2009.10.23 -
    Avast 4.8.1351.0 2009.10.24 -
    AVG 8.5.0.423 2009.10.23 -
    BitDefender 7.2 2009.10.24 -
    CAT-QuickHeal 10.00 2009.10.23 -
    ClamAV 0.94.1 2009.10.23 -
    Comodo 2707 2009.10.23 -
    DrWeb 5.0.0.12182 2009.10.24 -
    eSafe 7.0.17.0 2009.10.22 -
    eTrust-Vet 35.1.7082 2009.10.23 -
    F-Prot 4.5.1.85 2009.10.23 -
    F-Secure 9.0.15370.0 2009.10.22 -
    Fortinet 3.120.0.0 2009.10.23 -
    GData 19 2009.10.24 -
    Ikarus T3.1.1.72.0 2009.10.23 -
    Jiangmin 11.0.800 2009.10.23 -
    K7AntiVirus 7.10.878 2009.10.23 -
    Kaspersky 7.0.0.125 2009.10.24 -
    McAfee 5780 2009.10.23 -
    McAfee+Artemis 5780 2009.10.23 -
    McAfee-GW-Edition 6.8.5 2009.10.23 -
    Microsoft 1.5202 2009.10.23 -
    NOD32 4537 2009.10.23 -
    Norman 6.03.02 2009.10.23 -
    nProtect 2009.1.8.0 2009.10.23 -
    Panda 10.0.2.2 2009.10.23 -
    PCTools 4.4.2.0 2009.10.19 -
    Prevx 3.0 2009.10.24 -
    Rising 21.52.44.00 2009.10.23 -
    Sophos 4.46.0 2009.10.23 -
    Sunbelt 3.2.1858.2 2009.10.23 -
    Symantec 1.4.4.12 2009.10.24 -
    TheHacker 6.5.0.2.051 2009.10.22 -
    TrendMicro 8.950.0.1094 2009.10.23 -
    VBA32 3.12.10.11 2009.10.23 -
    ViRobot 2009.10.23.2003 2009.10.23 -
    VirusBuster 4.6.5.0 2009.10.23 -
    Additional information
    File size: 26112 bytes
    MD5 : a93aee1928a9d7ce3e16d24ec7380f89
    SHA1 : 513f8bdf67a5a9e09803cfb61f590b39f2683853
    SHA256: 944cd2135e171af338352568aa7fe1b8004733a4281395ad6723e0cf43d5f53f
    PEInfo: PE Structure information

    ( base data )
    entrypointaddress.: 0x54AD
    timedatestamp.....: 0x480251A8 (Sun Apr 13 20:32:08 2008)
    machinetype.......: 0x14C (Intel I386)

    ( 3 sections )
    name viradd virsiz rawdsiz ntrpy md5
    .text 0x1000 0x520E 0x5400 5.95 099b53205ad3f1c3b853a5310d08a9b1
    .data 0x7000 0x14C 0x200 1.86 0bb948f267e82975313a03d8c0e8a1cf
    .rsrc 0x8000 0xB50 0xC00 3.27 bac832e39f87c4f5f640e5d5c6a1c2fc

    ( 0 imports )


    ( 0 exports )
    TrID : File type identification
    Win32 Executable MS Visual C++ (generic) (65.2%)
    Win32 Executable Generic (14.7%)
    Win32 Dynamic Link Library (generic) (13.1%)
    Generic Win/DOS Executable (3.4%)
    DOS Executable Generic (3.4%)
    ThreatExpert: http://www.threatexpert.com/report.aspx?md5=a93aee1928a9d7ce3e16d24ec7380f89

    ssdeep: 768:0RMJi8jDLIDSAaQFxfftjaLacmkLGKOq:0RMJbDMDSA7FxffJaLaSLG9q
    PEiD : -
    RDS : NSRL Reference Data Set
    -
    ================================================

    File explorer.exe received on 2009.10.25 09:23:16 (UTC)
    Current status: finished
    Result: 1/41 (2.44%)
    Compact
    Print results
    Antivirus Version Last Update Result
    a-squared 4.5.0.41 2009.10.25 -
    AhnLab-V3 5.0.0.2 2009.10.23 -
    AntiVir 7.9.1.44 2009.10.23 -
    Antiy-AVL 2.0.3.7 2009.10.23 -
    Authentium 5.1.2.4 2009.10.24 -
    Avast 4.8.1351.0 2009.10.25 -
    AVG 8.5.0.423 2009.10.24 -
    BitDefender 7.2 2009.10.25 -
    CAT-QuickHeal 10.00 2009.10.24 -
    ClamAV 0.94.1 2009.10.25 -
    Comodo 2724 2009.10.25 -
    DrWeb 5.0.0.12182 2009.10.25 -
    eSafe 7.0.17.0 2009.10.22 -
    eTrust-Vet 35.1.7082 2009.10.23 -
    F-Prot 4.5.1.85 2009.10.24 -
    F-Secure 9.0.15370.0 2009.10.22 -
    Fortinet 3.120.0.0 2009.10.25 -
    GData 19 2009.10.25 -
    Ikarus T3.1.1.72.0 2009.10.25 -
    Jiangmin 11.0.800 2009.10.24 -
    K7AntiVirus 7.10.879 2009.10.24 -
    Kaspersky 7.0.0.125 2009.10.25 -
    McAfee 5781 2009.10.24 -
    McAfee+Artemis 5781 2009.10.24 -
    McAfee-GW-Edition 6.8.5 2009.10.25 Heuristic.LooksLike.Win32.Suspicious.K
    Microsoft 1.5202 2009.10.25 -
    NOD32 4539 2009.10.24 -
    Norman 6.03.02 2009.10.23 -
    nProtect 2009.1.8.0 2009.10.25 -
    Panda 10.0.2.2 2009.10.25 -
    PCTools 4.4.2.0 2009.10.19 -
    Prevx 3.0 2009.10.25 -
    Rising 21.52.62.00 2009.10.25 -
    Sophos 4.46.0 2009.10.25 -
    Sunbelt 3.2.1858.2 2009.10.24 -
    Symantec 1.4.4.12 2009.10.25 -
    TheHacker 6.5.0.2.053 2009.10.24 -
    TrendMicro 8.950.0.1094 2009.10.25 -
    VBA32 3.12.10.11 2009.10.23 -
    ViRobot 2009.10.23.2003 2009.10.23 -
    VirusBuster 4.6.5.0 2009.10.24 -
    Additional information
    File size: 1033728 bytes
    MD5 : 12896823fb95bfb3dc9b46bcaedc9923
    SHA1 : 9d2bf84874abc5b6e9a2744b7865c193c08d362f
    SHA256: 1e675cb7df214172f7eb0497f7275556038a0d09c6e5a3e6862c5e26885ef455
    PEInfo: PE Structure information

    ( base data )
    entrypointaddress.: 0x1A55F
    timedatestamp.....: 0x48025C30 (Sun Apr 13 21:17:04 2008)
    machinetype.......: 0x14C (Intel I386)

    ( 4 sections )
    name viradd virsiz rawdsiz ntrpy md5
    .text 0x1000 0x44C09 0x44E00 6.38 fd89c9ce334764ffdbb62637ad9b5809
    .data 0x46000 0x1DB4 0x1800 1.30 983f35021232560eaaa99fcbc1b7d359
    .rsrc 0x48000 0xB2268 0xB2400 6.63 95339c37646fa93e3695e06572a21889
    .reloc 0xFB000 0x374C 0x3800 6.78 ec335057489badbf6d8142b57175fd91

    ( 0 imports )


    ( 0 exports )
    TrID : File type identification
    Win32 Executable Generic (42.3%)
    Win32 Dynamic Link Library (generic) (37.6%)
    Generic Win/DOS Executable (9.9%)
    DOS Executable Generic (9.9%)
    Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
    ThreatExpert: http://www.threatexpert.com/report.aspx?md5=12896823fb95bfb3dc9b46bcaedc9923

    ssdeep: 12288:HHmcoCUyZtwAvAs4wTCyrPTloHWYUrkf8w0Vnzac1/g/J/vMS:nmfty/wAvN7lrvbkf8w0VnH1/g/J/k
    PEiD : -
    PDFiD : ['-', None, None]
    RDS : NSRL Reference Data Set
    -
    ===========================================


    File svchost.exe received on 2009.10.25 04:21:26 (UTC)
    Current status: finished

    Result: 0/41 (0.00%)
    Compact Print results Antivirus Version Last Update Result
    a-squared 4.5.0.41 2009.10.24 -
    AhnLab-V3 5.0.0.2 2009.10.23 -
    AntiVir 7.9.1.44 2009.10.23 -
    Antiy-AVL 2.0.3.7 2009.10.23 -
    Authentium 5.1.2.4 2009.10.24 -
    Avast 4.8.1351.0 2009.10.25 -
    AVG 8.5.0.423 2009.10.24 -
    BitDefender 7.2 2009.10.25 -
    CAT-QuickHeal 10.00 2009.10.24 -
    ClamAV 0.94.1 2009.10.25 -
    Comodo 2721 2009.10.25 -
    DrWeb 5.0.0.12182 2009.10.25 -
    eSafe 7.0.17.0 2009.10.22 -
    eTrust-Vet 35.1.7082 2009.10.23 -
    F-Prot 4.5.1.85 2009.10.24 -
    F-Secure 9.0.15370.0 2009.10.22 -
    Fortinet 3.120.0.0 2009.10.25 -
    GData 19 2009.10.25 -
    Ikarus T3.1.1.72.0 2009.10.24 -
    Jiangmin 11.0.800 2009.10.24 -
    K7AntiVirus 7.10.879 2009.10.24 -
    Kaspersky 7.0.0.125 2009.10.25 -
    McAfee 5781 2009.10.24 -
    McAfee+Artemis 5781 2009.10.24 -
    McAfee-GW-Edition 6.8.5 2009.10.25 -
    Microsoft 1.5202 2009.10.24 -
    NOD32 4539 2009.10.24 -
    Norman 6.03.02 2009.10.23 -
    nProtect 2009.1.8.0 2009.10.25 -
    Panda 10.0.2.2 2009.10.25 -
    PCTools 4.4.2.0 2009.10.19 -
    Prevx 3.0 2009.10.25 -
    Rising 21.52.52.00 2009.10.24 -
    Sophos 4.46.0 2009.10.25 -
    Sunbelt 3.2.1858.2 2009.10.24 -
    Symantec 1.4.4.12 2009.10.25 -
    TheHacker 6.5.0.2.053 2009.10.24 -
    TrendMicro 8.950.0.1094 2009.10.24 -
    VBA32 3.12.10.11 2009.10.23 -
    ViRobot 2009.10.23.2003 2009.10.23 -
    VirusBuster 4.6.5.0 2009.10.24 -
    Additional information
    File size: 14336 bytes
    MD5 : 27c6d03bcdb8cfeb96b716f3d8be3e18
    SHA1 : 49083ae3725a0488e0a8fbbe1335c745f70c4667
    SHA256: 2910ebc692d833d949bfd56059e8106d324a276d5f165f874f3fb1b6c613cdd5
    PEInfo: PE Structure information

    ( base data )
    entrypointaddress.: 0x2509
    timedatestamp.....: 0x48025BC0 (Sun Apr 13 21:15:12 2008)
    machinetype.......: 0x14C (Intel I386)

    ( 3 sections )
    name viradd virsiz rawdsiz ntrpy md5
    .text 0x1000 0x2C00 0x2C00 6.29 f6589e1ed3da6afefb0b4294d9ff7f2e
    .data 0x4000 0x210 0x200 1.62 cbd504e46c836e09e8faabdcfbabaec2
    .rsrc 0x5000 0x408 0x600 2.51 dcede0c303bbb48c6875eb64477e5882

    ( 0 imports )


    ( 0 exports )

    TrID : File type identification
    Win32 Executable Generic (42.3%)
    Win32 Dynamic Link Library (generic) (37.6%)
    Generic Win/DOS Executable (9.9%)
    DOS Executable Generic (9.9%)
    Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
    ThreatExpert: http://www.threatexpert.com/report.aspx?md5=27c6d03bcdb8cfeb96b716f3d8be3e18
    ssdeep: 384:IDvi+JmG6yqlCRaJt4RHS5LutGJae7g9VJnpWCNJbW:INcG6xlCRaJKGOA7SHJ
    PEiD : -
    PDFiD : ['-', None, None]
    RDS : NSRL Reference Data Set

    let me know what actions i need to take.

    Thanks for your help
     
  5. 2009/10/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'm not sure, how exactly Kaspersky dealt with Sality infection.
    Memory stick contains just data files, so I'd assume, Kaspersky simply deleted infected file(s).
    Good question arises here: how the heck Sality got on that stick. Did you use it on some other computer, or...?
    If you want to use some of those pictures, I'd recommend scanning the stick with at least one other program.
    Dr.Web CureIt is pretty good with detecting Virut/Sality infection: ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
    When done with transferring healthy files, format the stick.
     
  6. 2009/10/25
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Hi Broni,

    I guess I used it on a friend's PC and it got infected there....unless viruses can be spread by pictures nowadays :)

    I will do another scan as proposed and format the memory stick.

    Thanks for your help mate..
     
  7. 2009/10/25
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Hi Broni,

    Is the ftp a correct one?? i am unable to download it from there... do u have another link plz??
     
  8. 2009/10/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    The link works for me and unfortunately, it's the only one, you can use.
     
  9. 2009/10/27
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Hi Broni,

    At last I was able to download Drweb and performed a scan of the memory stick. Below is the log. The .exe and .pif files weren't there i guess they are related to the sality infection.[Scan path] F:\
    F:\MEMSTICK.IND - OK
    F:\MSTK_PRO.IND - OK
    F:\nexqja.exe - OK
    F:\autorun.inf - OK
    F:\rrxft.pif - OK
    F:\goaigs.exe - OK
    F:\djpgam.pif - OK
    F:\ndqca.pif - OK
    F:\fdtv.cmd - OK
    F:\pjmq.cmd - OK
    F:\luvl.pif - OK
    F:\heev.pif - OK
    F:\asysaf.exe - OK
    F:\phpysu.exe - OK
    F:\dnkpyt.exe - OK
    F:\ynrdli.exe - OK
    F:\wsrf.exe - OK
    F:\kmjqg.pif - OK
    F:\drdb.pif - OK
    F:\qlqvcr.pif - OK
    F:\swtyvh.exe - OK
    F:\hbotid.cmd - OK
    F:\wfoavn.exe - OK
    F:\eowgg.pif - OK
    F:\hjmqqx.pif - OK
    F:\ybdp.pif - OK
    F:\ghjr.pif - OK
    F:\fbte.exe - OK
    F:\koxwmm.pif - OK
    F:\ddui.cmd - OK
    F:\ssrd.exe - OK
    F:\wrbrf.exe - OK
    F:\fbjat.cmd - OK
    F:\ievwo.exe - OK
    F:\abevr.exe - OK
    F:\dwnadf.exe - OK
    F:\mouyn.exe - OK
    F:\cpywoh.cmd - OK
    F:\xaecl.exe - OK
    F:\hmynw.pif - OK
    F:\gkcrlk.exe - OK
    F:\oiqj.pif - OK
    F:\agrqm.cmd - OK
    F:\dfqr.pif - OK
    F:\tpsixe.pif - OK
    F:\hschog.exe - OK
    F:\upuwy.cmd - OK
    F:\acbg.exe - OK
    F:\nmjjqc.pif - OK
    F:\ujkft.pif - OK
    F:\ylwpsm.pif - OK
    F:\vlujg.exe - OK
    F:\kavpns.pif - OK
    F:\qoyr.pif - OK
    F:\xshqd.pif - OK
    F:\viwv.cmd - OK
    F:\glxih.exe - OK
    F:\qereyk.exe - OK
    F:\eubrww.exe - OK
    F:\irdfj.pif - OK
    F:\qjqsk.pif - OK
    F:\sqswq.pif - OK
    F:\emeh.pif - OK
    F:\pyec.pif - OK
    F:\xgnudc.exe - OK
    F:\tjgd.cmd - OK
    F:\knqm.pif - OK
    F:\rnkl.cmd - OK
    F:\guhhc.exe - OK
    F:\qdpwp.exe - OK
    F:\xipxja.exe - OK
    F:\ysgd.exe - OK
    F:\fejwv.cmd - OK
    F:\wisp.pif - OK
    F:\tknyva.pif - OK
    F:\pvut.exe - OK
    F:\nhoy.cmd - OK
    F:\jioau.pif - OK
    F:\uyuaph.pif - OK
    F:\xtveuj.pif - OK
    F:\hdnn.pif - OK
    F:\meto.exe - OK
    F:\fobg.pif - OK
    F:\acdxba.cmd - OK
    F:\bava.pif - OK
    F:\fnwv.exe - OK
    F:\jxrqi.pif - OK
    F:\ievc.pif - OK
    F:\nferi.pif - OK
    F:\opdm.cmd - OK
    F:\yanrro.exe - OK
    F:\jynu.pif - OK
    F:\axlm.pif - OK
    F:\ifexu.pif - OK
    F:\eqeakr.pif - OK
    F:\mxti.pif - OK
    F:\ihkxjj.exe - OK
    F:\kgxt.pif - OK
    F:\hcgcj.cmd - OK
    F:\agpws.cmd - OK
    F:\aqnno.exe - OK
    F:\ocepy.exe - OK
    F:\rygf.pif - OK
    F:\bbrln.exe - OK
    F:\gpgosy.pif - OK
    F:\tfwje.exe - OK
    F:\aonhe.exe - OK
    F:\owmbr.pif - OK
    F:\jcbjr.exe - OK
    F:\gveucc.pif - OK
    F:\hmjt.exe - OK
    F:\ilir.pif - OK
    F:\soml.cmd - OK
    F:\knpu.exe - OK
    F:\iuosem.exe - OK
    F:\yffxxo.cmd - OK
    F:\kjdjw.pif - OK
    F:\uwkb.pif - OK
    F:\dmhoe.pif - OK
    F:\cfdbmx.exe - OK
    F:\vmhhn.exe - OK
    F:\knlawx.exe - OK
    F:\rvdsv.exe - OK
    F:\dggj.cmd - OK
    F:\qlou.cmd - OK
    F:\ycptm.pif - OK
    F:\djueog.cmd - OK
    F:\pklc.pif - OK
    F:\bywhx.pif - OK
    F:\vyabe.pif - OK
    F:\vjpxnd.exe - OK
    F:\mlef.cmd - OK
    F:\mdkrrm.pif - OK
    F:\imaspq.cmd - OK
    F:\skhb.cmd - OK
    F:\weqfsb.pif - OK
    F:\tqjruf.pif - OK
    F:\tnaip.exe - OK
    F:\iufm.pif - OK
    F:\oascs.exe - OK
    F:\fpbx.pif - OK
    F:\yljf.cmd - OK
    F:\trvbs.pif - OK
    F:\uvnp.exe - OK
    F:\ibrd.pif - OK
    F:\yyqd.exe - OK
    F:\lyphxp.exe - OK
    F:\mcnra.pif - OK
    F:\ekngjm.cmd - OK
    F:\teyis.pif - OK
    F:\ngafc.exe - OK
    F:\fcbgwi.exe - OK
    F:\aqye.cmd - OK
    F:\dsxtb.exe - OK
    F:\kmqs.cmd - OK
    F:\smpb.pif - OK
    F:\hxugjf.exe - OK
    F:\yisgtd.exe - OK
    F:\qxvcgw.exe - OK
    F:\lydnvr.exe - OK
    F:\lkala.exe - OK
    F:\jvcr.exe - OK
    F:\efue.pif - OK
    F:\ourwt.cmd - OK
    F:\tctu.exe - OK
    F:\garvs.cmd - OK
    F:\exhnx.exe - OK
    F:\avreh.pif - OK
    F:\kqpt.exe - OK
    F:\kuvbr.pif - OK
    F:\cowd.exe - OK
    F:\cmap.cmd - OK
    F:\jftr.pif - OK
    F:\excx.exe - OK
    F:\ypli.pif - OK
    F:\axmy.pif - OK
    F:\utur.cmd - OK
    F:\irdahs.exe - OK
    F:\whyjs.exe - OK
    F:\lajal.pif - OK
    F:\srfh.pif - OK
    F:\rqprbf.pif - OK
    F:\dgfbl.exe - OK
    F:\ruraqy.pif - OK
    F:\heclt.cmd - OK
    F:\rmmmw.pif - OK
    F:\yplonp.exe - OK
    F:\lrko.exe - OK
    F:\ofxp.pif - OK
    F:\ecebs.pif - OK
    F:\oeyubt.pif - OK
    F:\bgrsx.cmd - OK
    F:\ipdpbr.pif - OK
    F:\fftv.exe - OK
    F:\wsue.cmd - OK
    F:\hjbqwb.exe - OK
    F:\fufh.pif - OK
    F:\bealc.exe - OK
    F:\omwny.pif - OK
    F:\wxwwum.exe - OK
    F:\edsq.pif - OK
    F:\dvwclj.pif - OK
    F:\slaf.pif - OK
    F:\pdiwgk.cmd - OK
    F:\bgibpx.cmd - OK
    F:\rnhjj.exe - OK
    F:\ivgt.exe - OK
    F:\atxxmv.pif - OK
    F:\edkygu.pif - OK
    F:\jdtpye.exe - OK
    F:\danpr.pif - OK
    F:\nrxgxb.exe - OK
    F:\bggsv.pif - OK
    F:\qtxsnh.pif - OK
    F:\qsak.pif - OK
    F:\tnfu.exe - OK
    F:\tmanm.cmd - OK
    F:\nguc.pif - OK
    F:\bwigef.cmd - OK
    F:\ddgvm.exe - OK
    F:\orvt.cmd - OK
    F:\hcncrk.exe - OK
    F:\uvymlm.pif - OK
    F:\agyjyi.pif - OK
    F:\abkklq.pif - OK
    F:\neun.cmd - OK
    F:\rhfna.cmd - OK
    F:\cufajv.cmd - OK
    F:\ppomuh.cmd - OK
    F:\kdffw.pif - OK
    F:\bosfji.exe - OK
    F:\vibvkn.exe - OK
    F:\hcve.pif - OK
    F:\blof.cmd - OK
    F:\fpfrg.cmd - OK
    F:\qckig.pif - OK
    F:\ixrlm.pif - OK
    F:\xpujtb.pif - OK
    F:\yrfkf.pif - OK
    F:\eajhgv.pif - OK
    F:\huqddn.pif - OK
    F:\mmnx.cmd - OK
    F:\agwtfp.pif - OK
    F:\rusxwq.cmd - OK
    F:\wuuno.exe - OK
    F:\aofo.cmd - OK
    F:\wjront.pif - OK
    F:\wnewpc.pif - OK
    F:\wybpry.exe - OK
    F:\drvf.exe - OK
    F:\wfumag.exe - OK
    F:\dyssga.pif - OK
    F:\qugata.pif - OK
    F:\uogfwu.pif - OK
    F:\twohtn.pif - OK
    F:\ihwlfq.pif - OK
    F:\yjqfu.exe - OK
    F:\xjge.cmd - OK
    F:\oqyj.cmd - OK
    F:\hmcjsp.pif - OK
    F:\jycs.exe - OK
    F:\hjpbjf.pif - OK
    F:\gudrni.exe - OK
    F:\tpnj.exe - OK
    F:\njpk.exe - OK
    F:\ucnvx.exe - OK
    F:\ewlkb.pif - OK
    F:\pvxc.exe - OK
    F:\breby.exe - OK
    F:\ebsqgo.exe - OK
    F:\aokmtj.pif - OK
    F:\amwba.pif - OK
    F:\pbwkbf.pif - OK
    F:\xwsbwg.cmd - OK
    F:\xkrplw.exe - OK
    F:\spnae.pif - OK
    F:\tkuj.cmd - OK
    F:\qrdo.exe - OK
    F:\qsoe.pif - OK
    F:\jtjdbr.pif - OK
    F:\shxw.exe - OK
    F:\ssrf.exe - OK
    F:\ggpahc.cmd - OK
    F:\gdhh.exe - OK
    F:\klvv.pif - OK
    F:\oamm.exe - OK
    F:\exmha.pif - OK
    F:\lsnuft.cmd - OK
    F:\vojlv.pif - OK
    F:\lpjlb.exe - OK
    F:\cqwcor.exe - OK
    F:\ktkx.exe - OK
    F:\sietdg.pif - OK
    F:\qjsg.exe - OK
    F:\xblefs.pif - OK
    F:\kshm.pif - OK
    F:\nholb.pif - OK
    F:\gdgprd.exe - OK
    F:\ennlxr.pif - OK
    F:\edpci.exe - OK
    F:\efut.exe - OK
    F:\irymol.exe - OK
    F:\baef.exe - OK
    F:\awgklr.exe - OK
    F:\eawhwo.pif - OK
    F:\ldajsx.pif - OK
    F:\weehg.pif - OK
    F:\opgvhh.pif - OK
    F:\mifpsy.pif - OK
    F:\vkpib.pif - OK
    F:\ycgeet.cmd - OK
    F:\wowb.pif - OK
    F:\grvoni.pif - OK
    F:\kwhtg.pif - OK
    F:\fhfv.exe - OK
    F:\kbci.exe - OK
    F:\qfldj.exe - OK
    F:\ssqby.exe - OK
    F:\mrqy.pif - OK
    F:\tkww.pif - OK
    F:\fuli.exe - OK
    F:\ymhv.pif - OK
    F:\kwkxx.pif - OK
    F:\friy.pif - OK
    F:\cenx.pif - OK
    F:\mhsex.pif - OK
    F:\cqeg.pif - OK
    F:\rlsvu.exe - OK
    F:\hxia.pif - OK
    F:\ccsdva.pif - OK
    F:\hdkox.pif - OK
    F:\hdnf.pif - OK
    F:\crlr.pif - OK
    F:\yepq.pif - OK
    F:\bptogc.cmd - OK
    F:\hfbr.pif - OK
    F:\DCIM\101MSDCF\MOV00026.MPG - OK
    F:\DCIM\101MSDCF\DSC00002.JPG - OK
    F:\DCIM\101MSDCF\DSC00097.JPG - OK
    F:\DCIM\101MSDCF\MOV00026.THM - OK
    F:\DCIM\101MSDCF\DSC00005.JPG - OK
    F:\DCIM\101MSDCF\MOV00027.MPG - OK
    F:\DCIM\101MSDCF\MOV00027.THM - OK
    F:\DCIM\101MSDCF\MOV00028.MPG - OK
    F:\DCIM\101MSDCF\MOV00028.THM - OK
    F:\DCIM\101MSDCF\MOV00029.MPG - OK
    F:\DCIM\101MSDCF\MOV00029.THM - OK
    F:\DCIM\101MSDCF\DSC00030.JPG - OK
    F:\DCIM\101MSDCF\DSC00031.JPG - OK
    F:\DCIM\101MSDCF\DSC00032.JPG - OK
    F:\DCIM\101MSDCF\DSC00033.JPG - OK
    F:\DCIM\101MSDCF\MOV00034.MPG - OK
    F:\DCIM\101MSDCF\MOV00034.THM - OK
    F:\DCIM\101MSDCF\MOV00035.MPG - OK
    F:\DCIM\101MSDCF\MOV00035.THM - OK
    F:\DCIM\101MSDCF\MOV00036.MPG - OK
    F:\DCIM\101MSDCF\MOV00036.THM - OK
    F:\DCIM\101MSDCF\MOV00037.MPG - OK
    F:\DCIM\101MSDCF\MOV00037.THM - OK
    F:\DCIM\101MSDCF\DSC00038.JPG - OK
    F:\DCIM\101MSDCF\DSC00039.JPG - OK
    F:\DCIM\101MSDCF\DSC00040.JPG - OK
    F:\DCIM\101MSDCF\DSC00041.JPG - OK
    F:\DCIM\101MSDCF\MOV00042.MPG - OK
    F:\DCIM\101MSDCF\MOV00042.THM - OK
    F:\DCIM\101MSDCF\DSC00043.JPG - OK
    F:\DCIM\101MSDCF\DSC00044.JPG - OK
    F:\DCIM\101MSDCF\MOV00045.MPG - OK
    F:\DCIM\101MSDCF\MOV00045.THM - OK
    F:\DCIM\101MSDCF\DSC00046.JPG - OK
    F:\DCIM\101MSDCF\DSC00047.JPG - OK
    F:\DCIM\101MSDCF\DSC00048.JPG - OK
    F:\DCIM\101MSDCF\DSC00049.JPG - OK
    F:\DCIM\101MSDCF\DSC00050.JPG - OK
    F:\DCIM\101MSDCF\DSC00051.JPG - OK
    F:\DCIM\101MSDCF\DSC00052.JPG - OK
    F:\DCIM\101MSDCF\DSC00053.JPG - OK
    F:\DCIM\101MSDCF\DSC00054.JPG - OK
    F:\DCIM\101MSDCF\DSC00055.JPG - OK
    F:\DCIM\101MSDCF\DSC00056.JPG - OK
    F:\DCIM\101MSDCF\DSC00057.JPG - OK
    F:\DCIM\101MSDCF\DSC00058.JPG - OK
    F:\DCIM\101MSDCF\DSC00059.JPG - OK
    F:\DCIM\101MSDCF\DSC00060.JPG - OK
    F:\DCIM\101MSDCF\DSC00061.JPG - OK
    F:\DCIM\101MSDCF\DSC00062.JPG - OK
    F:\DCIM\101MSDCF\DSC00063.JPG - OK
    F:\DCIM\101MSDCF\DSC00064.JPG - OK
    F:\DCIM\101MSDCF\DSC00065.JPG - OK
    F:\DCIM\101MSDCF\DSC00066.JPG - OK
    F:\DCIM\101MSDCF\DSC00073.JPG - OK
    F:\DCIM\101MSDCF\DSC00075.JPG - OK
    F:\DCIM\101MSDCF\DSC00076.JPG - OK
    F:\DCIM\101MSDCF\DSC00070.JPG - OK
    F:\DCIM\101MSDCF\DSC00077.JPG - OK
    F:\DCIM\101MSDCF\DSC00072.JPG - OK
    F:\DCIM\101MSDCF\DSC00078.JPG - OK
    F:\DCIM\101MSDCF\DSC00079.JPG - OK
    F:\DCIM\101MSDCF\DSC00080.JPG - OK
    F:\DCIM\101MSDCF\DSC00081.JPG - OK
    F:\DCIM\101MSDCF\DSC00082.JPG - OK
    F:\DCIM\101MSDCF\DSC00083.JPG - OK
    F:\DCIM\101MSDCF\DSC00084.JPG - OK
    F:\DCIM\101MSDCF\DSC00085.JPG - OK
    F:\DCIM\101MSDCF\DSC00086.JPG - OK
    F:\DCIM\101MSDCF\DSC00087.JPG - OK
    F:\DCIM\101MSDCF\DSC00088.JPG - OK
    F:\DCIM\101MSDCF\DSC00089.JPG - OK
    F:\DCIM\101MSDCF\DSC00090.JPG - OK
    F:\DCIM\101MSDCF\DSC00091.JPG - OK
    F:\DCIM\101MSDCF\DSC00092.JPG - OK
    F:\DCIM\101MSDCF\DSC00093.JPG - OK
    F:\DCIM\101MSDCF\DSC00094.JPG - OK
    F:\DCIM\101MSDCF\DSC00095.JPG - OK
    F:\DCIM\101MSDCF\DSC00098.JPG - OK
    F:\DCIM\101MSDCF\DSC00099.JPG - OK
    F:\DCIM\101MSDCF\DSC00100.JPG - OK
    F:\DCIM\101MSDCF\DSC00101.JPG - OK
    F:\DCIM\101MSDCF\DSC00102.JPG - OK
    F:\DCIM\101MSDCF\DSC00103.JPG - OK
    F:\DCIM\101MSDCF\DSC00104.JPG - OK
    F:\DCIM\101MSDCF\DSC00105.JPG - OK
    F:\DCIM\101MSDCF\DSC00106.JPG - OK
    F:\DCIM\101MSDCF\DSC00107.JPG - OK
    F:\DCIM\101MSDCF\DSC00108.JPG - OK
    F:\DCIM\101MSDCF\DSC00109.JPG - OK
    F:\DCIM\101MSDCF\DSC00110.JPG - OK
    F:\DCIM\101MSDCF\DSC00111.JPG - OK
    F:\DCIM\101MSDCF\DSC00112.JPG - OK
    F:\DCIM\101MSDCF\DSC00113.JPG - OK
    F:\DCIM\101MSDCF\DSC00114.JPG - OK
    F:\DCIM\101MSDCF\DSC00115.JPG - OK
    F:\DCIM\101MSDCF\DSC00116.JPG - OK
    F:\DCIM\101MSDCF\DSC00117.JPG - OK
    F:\DCIM\101MSDCF\DSC00118.JPG - OK
    F:\DCIM\101MSDCF\DSC00119.JPG - OK
    F:\DCIM\101MSDCF\DSC00120.JPG - OK
    F:\DCIM\101MSDCF\DSC00121.JPG - OK
    F:\DCIM\101MSDCF\DSC00122.JPG - OK
    F:\DCIM\101MSDCF\DSC00123.JPG - OK
    F:\DCIM\101MSDCF\DSC00124.JPG - OK
    F:\DCIM\101MSDCF\DSC00125.JPG - OK
    F:\DCIM\101MSDCF\DSC00126.JPG - OK
    F:\DCIM\101MSDCF\DSC00127.JPG - OK
    F:\DCIM\101MSDCF\DSC00128.JPG - OK
    F:\DCIM\101MSDCF\DSC00129.JPG - OK
    F:\DCIM\101MSDCF\DSC00131.JPG - OK
    F:\DCIM\101MSDCF\DSC00132.JPG - OK
    F:\DCIM\101MSDCF\DSC00133.JPG - OK
    F:\DCIM\101MSDCF\DSC00138.JPG - OK
    F:\DCIM\101MSDCF\DSC00141.JPG - OK
    F:\DCIM\101MSDCF\DSC00136.JPG - OK
    F:\DCIM\101MSDCF\DSC00142.JPG - OK
    F:\DCIM\101MSDCF\DSC00143.JPG - OK
    F:\DCIM\101MSDCF\DSC00144.JPG - OK
    F:\DCIM\101MSDCF\DSC00145.JPG - OK
    F:\DCIM\101MSDCF\DSC00146.JPG - OK
    F:\DCIM\101MSDCF\DSC00147.JPG - OK
    F:\DCIM\101MSDCF\DSC00148.JPG - OK
    F:\DCIM\101MSDCF\DSC00149.JPG - OK
    F:\DCIM\101MSDCF\DSC00150.JPG - OK
    F:\DCIM\101MSDCF\DSC00151.JPG - OK
    F:\DCIM\101MSDCF\DSC00152.JPG - OK
    F:\DCIM\101MSDCF\DSC00153.JPG - OK
    F:\DCIM\101MSDCF\DSC00154.JPG - OK
    F:\DCIM\101MSDCF\DSC00155.JPG - OK
    F:\DCIM\101MSDCF\DSC00156.JPG - OK
    F:\DCIM\101MSDCF\DSC00157.JPG - OK
    F:\DCIM\101MSDCF\DSC00158.JPG - OK
    F:\DCIM\101MSDCF\DSC00159.JPG - OK
    F:\DCIM\101MSDCF\DSC00160.JPG - OK
    F:\DCIM\101MSDCF\DSC00161.JPG - OK
    F:\DCIM\101MSDCF\DSC00162.JPG - OK
    F:\DCIM\101MSDCF\DSC00163.JPG - OK
    F:\DCIM\101MSDCF\DSC00164.JPG - OK
    F:\DCIM\101MSDCF\DSC00165.JPG - OK
    F:\DCIM\101MSDCF\DSC00166.JPG - OK
    F:\DCIM\101MSDCF\DSC00167.JPG - OK
    F:\DCIM\101MSDCF\DSC00168.JPG - OK
    F:\DCIM\101MSDCF\DSC00169.JPG - OK
    F:\DCIM\101MSDCF\DSC00170.JPG - OK
    F:\DCIM\101MSDCF\DSC00171.JPG - OK
    F:\DCIM\101MSDCF\DSC00172.JPG - OK
    F:\DCIM\101MSDCF\DSC00173.JPG - OK
    F:\DCIM\101MSDCF\DSC00174.JPG - OK
    F:\DCIM\101MSDCF\DSC00175.JPG - OK
    F:\DCIM\101MSDCF\DSC00176.JPG - OK
    F:\DCIM\101MSDCF\DSC00177.JPG - OK
    F:\DCIM\101MSDCF\DSC00178.JPG - OK
    F:\DCIM\101MSDCF\DSC00179.JPG - OK
    F:\DCIM\101MSDCF\DSC00180.JPG - OK
    F:\DCIM\101MSDCF\DSC00181.JPG - OK
    F:\DCIM\101MSDCF\DSC00182.JPG - OK
    F:\DCIM\101MSDCF\DSC00183.JPG - OK
    F:\DCIM\101MSDCF\DSC00184.JPG - OK
    F:\DCIM\101MSDCF\DSC00185.JPG - OK
    F:\DCIM\101MSDCF\DSC00186.JPG - OK
    F:\DCIM\101MSDCF\DSC00187.JPG - OK
    F:\DCIM\101MSDCF\DSC00188.JPG - OK
    F:\DCIM\101MSDCF\DSC00189.JPG - OK
    F:\DCIM\101MSDCF\DSC00190.JPG - OK
    F:\DCIM\101MSDCF\DSC00191.JPG - OK
    F:\DCIM\101MSDCF\DSC00192.JPG - OK
    F:\DCIM\101MSDCF\DSC00209.JPG - OK
    F:\DCIM\101MSDCF\DSC00210.JPG - OK
    F:\DCIM\101MSDCF\DSC00211.JPG - OK
    F:\DCIM\101MSDCF\DSC00212.JPG - OK
    F:\DCIM\101MSDCF\DSC00213.JPG - OK
    F:\DCIM\101MSDCF\DSC00214.JPG - OK
    F:\DCIM\101MSDCF\DSC00215.JPG - OK
    F:\DCIM\101MSDCF\DSC00216.JPG - OK
    F:\DCIM\101MSDCF\DSC00217.JPG - OK
    F:\DCIM\101MSDCF\DSC00285.JPG - OK
    F:\DCIM\101MSDCF\DSC00286.JPG - OK
    F:\DCIM\101MSDCF\DSC00287.JPG - OK
    F:\DCIM\101MSDCF\DSC00288.JPG - OK
    F:\DCIM\101MSDCF\DSC00289.JPG - OK
    F:\DCIM\101MSDCF\DSC00290.JPG - OK
    F:\DCIM\101MSDCF\DSC00292.JPG - OK
    F:\DCIM\101MSDCF\DSC00293.JPG - OK
    F:\DCIM\101MSDCF\DSC00294.JPG - OK
    F:\DCIM\101MSDCF\DSC00295.JPG - OK
    F:\DCIM\101MSDCF\DSC00296.JPG - OK
    F:\DCIM\101MSDCF\DSC00297.JPG - OK
    F:\DCIM\101MSDCF\DSC00298.JPG - OK
    F:\DCIM\101MSDCF\DSC00299.JPG - OK
    F:\DCIM\101MSDCF\DSC00300.JPG - OK
    F:\DCIM\101MSDCF\DSC00301.JPG - OK
    F:\DCIM\101MSDCF\DSC00302.JPG - OK
    F:\DCIM\101MSDCF\DSC00303.JPG - OK
    F:\DCIM\101MSDCF\DSC00304.JPG - OK
    F:\DCIM\101MSDCF\DSC00305.JPG - OK
    F:\DCIM\101MSDCF\DSC00306.JPG - OK
    F:\DCIM\101MSDCF\DSC00307.JPG - OK
    F:\DCIM\101MSDCF\DSC00308.JPG - OK
    F:\DCIM\101MSDCF\DSC00309.JPG - OK
    F:\DCIM\101MSDCF\DSC00310.JPG - OK
    F:\DCIM\101MSDCF\DSC00311.JPG - OK
    F:\DCIM\101MSDCF\DSC00312.JPG - OK
    F:\DCIM\101MSDCF\DSC00313.JPG - OK
    F:\DCIM\101MSDCF\DSC00314.JPG - OK
    F:\DCIM\101MSDCF\DSC00315.JPG - OK
    F:\DCIM\101MSDCF\DSC00316.JPG - OK
    F:\DCIM\101MSDCF\DSC00317.JPG - OK
    F:\DCIM\101MSDCF\DSC00318.JPG - OK
    F:\DCIM\101MSDCF\DSC00319.JPG - OK
    F:\DCIM\101MSDCF\DSC00320.JPG - OK
    F:\DCIM\101MSDCF\DSC00321.JPG - OK
    F:\DCIM\101MSDCF\DSC00322.JPG - OK
    F:\DCIM\101MSDCF\DSC00323.JPG - OK
    F:\DCIM\101MSDCF\DSC00324.JPG - OK
    F:\DCIM\101MSDCF\DSC00325.JPG - OK
    F:\DCIM\101MSDCF\DSC00326.JPG - OK
    F:\DCIM\101MSDCF\DSC00329.JPG - OK
    F:\DCIM\101MSDCF\DSC00330.JPG - OK
    F:\DCIM\101MSDCF\DSC00331.JPG - OK
    F:\DCIM\101MSDCF\DSC00332.JPG - OK
    F:\DCIM\101MSDCF\DSC00333.JPG - OK
    F:\DCIM\101MSDCF\DSC00334.JPG - OK
    F:\DCIM\101MSDCF\DSC00335.JPG - OK
    F:\DCIM\101MSDCF\DSC00336.JPG - OK
    F:\DCIM\101MSDCF\DSC00337.JPG - OK
    F:\DCIM\101MSDCF\DSC00338.JPG - OK
    F:\DCIM\101MSDCF\DSC00339.JPG - OK
    F:\DCIM\101MSDCF\DSC00340.JPG - OK
    F:\DCIM\101MSDCF\DSC00341.JPG - OK
    F:\DCIM\101MSDCF\DSC00342.JPG - OK
    F:\DCIM\101MSDCF\DSC00343.JPG - OK
    F:\DCIM\101MSDCF\DSC00344.JPG - OK
    F:\DCIM\101MSDCF\DSC00345.JPG - OK
    F:\DCIM\101MSDCF\DSC00346.JPG - OK
    F:\DCIM\101MSDCF\DSC00347.JPG - OK
    F:\DCIM\101MSDCF\DSC00348.JPG - OK
    F:\DCIM\101MSDCF\DSC00349.JPG - OK
    F:\DCIM\101MSDCF\DSC00350.JPG - OK
    F:\DCIM\101MSDCF\DSC00351.JPG - OK
    F:\DCIM\101MSDCF\DSC00352.JPG - OK
    F:\DCIM\101MSDCF\DSC00353.JPG - OK
    F:\DCIM\101MSDCF\DSC00354.JPG - OK
    F:\DCIM\101MSDCF\DSC00355.JPG - OK
    F:\DCIM\101MSDCF\DSC00356.JPG - OK
    F:\DCIM\101MSDCF\DSC00357.JPG - OK
    F:\DCIM\101MSDCF\DSC00358.JPG - OK
    F:\DCIM\101MSDCF\DSC00359.JPG - OK
    F:\DCIM\101MSDCF\DSC00360.JPG - OK
    F:\DCIM\101MSDCF\DSC00361.JPG - OK
    F:\DCIM\101MSDCF\DSC00362.JPG - OK
    F:\DCIM\101MSDCF\DSC00363.JPG - OK
    F:\DCIM\101MSDCF\DSC00364.JPG - OK
    F:\DCIM\101MSDCF\DSC00365.JPG - OK
    F:\DCIM\101MSDCF\DSC00366.JPG - OK
    F:\DCIM\101MSDCF\DSC00367.JPG - OK
    F:\DCIM\101MSDCF\DSC00368.JPG - OK
    F:\DCIM\101MSDCF\DSC00369.JPG - OK
    F:\MSSONY\DSC_MISC\DB00.DDT - OK
    F:\MSSONY\DSC_MISC\DB0DCF.DIX - OK
    F:\MSSONY\DSC_MISC\DB0DATE.DIX - OK
    F:\MSSONY\DSC_MISC\DB0FACE.DIX - OK
    F:\MSSONY\DSC_MISC\DB0FAVOR.DIX - OK
    F:\MSSONY\DSC_MISC\DB0.DID - OK
    F:\MSSONY\DSC_MISC\DB.DHY - OK
    F:\MSSONY\DSC_MISC\DB10.DDT - OK
    F:\MSSONY\DSC_MISC\DB1DCF.DIX - OK
    F:\MSSONY\DSC_MISC\DB1DATE.DIX - OK
    F:\MSSONY\DSC_MISC\DB1FACE.DIX - OK
    F:\MSSONY\DSC_MISC\DB1FAVOR.DIX - OK
    F:\MSSONY\DSC_MISC\DB1.DID - OK

    -----------------------------------------------------------------------------
    Scan statistics
    -----------------------------------------------------------------------------
    Scanned: 607
    Infected: 0
    Modifications: 0
    Suspicious: 0
    Adware: 0
    Dialers: 0
    Jokes: 0
    Riskware: 0
    Hacktools: 0
    Cured: 0
    Deleted: 0
    Renamed: 0
    Moved: 0
    Ignored: 0
    Scan speed: 15018 Kb/s
    Scan time: 00:01:05
    -----------------------------------------------------------------------------

    Shall I move the pics on my hard and format the memory stick??

    Thanks and regards
     
  10. 2009/10/27
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Take a deep breath and go ahead :)
     
  11. 2009/10/28
    Andy Cool

    Andy Cool Inactive Thread Starter

    Joined:
    2007/10/12
    Messages:
    208
    Likes Received:
    0
    Hi Broni,

    Thanks for your help was able to get my pics on my hard safely. I have run a full system scan just to check and everything looks fine...will format my memory stick now...

    Thanks for your help you may flag the threat as resolved :)
     
  12. 2009/10/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome :)
    Stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.