1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Caught the Trojan.Starter.384 and can't remove it

Discussion in 'Malware and Virus Removal Archive' started by Chilly, 2008/08/30.

  1. 2008/09/07
    Chilly

    Chilly Inactive Thread Starter

    Joined:
    2008/08/30
    Messages:
    37
    Likes Received:
    0
    Ok Noahdfear,
    Here are the results of the scan that just finished a few minutes ago:

    SCAN REPORT

    STOPSIGN SCAN 9-7-2008 @ 2:00 - 4:00 p.m.

    Scanner Statistics: Objects Scanned: 82856
    Threats Found: 3
    Threats Deleted: 3
    Threats Remaining: 0

    3 Spyware, Adware and other infection(s):Infection Name: Type: Status:
    Tracking Cookie Spyware Cookie Deleted
    Program.PsExec.171 Riskware Program Deleted
    Program.PsExec.170 Riskware Program Deleted


    Full Spyware, Adware, and Other Threat Details:
    Program.PsExec.170: Riskware Program
    c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp49\a0040914.exe is Deleted.
    Program.PsExec.171: Riskware Program
    c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp49\a0040913.exe:327882R2FWJFW\psexec.cfexe is Deleted.
    Tracking Cookie: Spyware Cookie
    C:\Documents and Settings\Karen\Cookies\karen@msnportal.112.2o7[1].txt is Deleted.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    I do think it's a bit odd that the PsExec.170 & PsExec.171 keep showing up tho, cuz they were both on the scan I did overnight - any ideas about that :confused:

    Also, do you still want me to delete some things off my computer (per ur post above)? If so, plz let me know what to delete and I'll delete whatever it is. Some of this older stuff has been on here for a long time and I probably never used it anyway - in fact I would probably have to do a "search" to find it LOL

    Thanks again :D
     
  2. 2008/09/07
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Yes, please create and run the check.bat per my instructions, then post the results here.
     

  3. to hide this advert.

  4. 2008/09/23
    Chilly

    Chilly Inactive Thread Starter

    Joined:
    2008/08/30
    Messages:
    37
    Likes Received:
    0
    Hi Noadfear,
    Sorry for the delay in getting back to you. I had to replace my NIC card and that took awhile to figure out. First that it was in fact the NIC card that needed replacing, and not the modem (although I ended up replacing them both LOL).

    At any rate, here's the results of the check.dat report:

    ~~winlogon backups~~

    Volume in drive C has no label.
    Volume Serial Number is F464-DE02


    That's all that came up on it. Also, I'm running a virus scan atm but it's only 27% done (this is the first day I've been back online).

    Let me know what you think please.

    Thanx a bunch!
     
  5. 2008/09/23
    Chilly

    Chilly Inactive Thread Starter

    Joined:
    2008/08/30
    Messages:
    37
    Likes Received:
    0
    Ok, ran my virus scanner and nothing serious came up.....I'll post below what it did show though:

    RECENT SCAN

    Objects Scanned: 67628
    Threats Found: 3
    Threats Deleted: 3
    Threats Remaining: 0

    3 Spyware, Adware and other infection(s):Infection Name: Type: Status:
    RealMedia Cookie Spyware Cookie Deleted
    TribalFusion Cookie Spyware Cookie Deleted
    Tracking Cookie Spyware Cookie Deleted

    more...
    Full Spyware, Adware, and Other Threat Details:
    RealMedia Cookie: Spyware Cookie
    C:\Documents and Settings\Karen\Cookies\karen@247realmedia[2].txt is Deleted.
    C:\Documents and Settings\Karen\Cookies\karen@realmedia[2].txt is Deleted.
    Tracking Cookie: Spyware Cookie
    C:\Documents and Settings\Karen\Cookies\karen@msnportal.112.2o7[1].txt is Deleted.
    TribalFusion Cookie: Spyware Cookie
    C:\Documents and Settings\Karen\Cookies\karen@tribalfusion[2].txt is Deleted.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    That's it! Let me know if there's anything further I need to do plz. It looks like everything is pretty well cleaned up. THANX FOR ALL YOUR HELP!! :D
     
  6. 2008/09/23
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Please repeat my instructions from this post. Be patient please, since it could take quite some time for it to complete. The command window should close on it's own when finished.

    There is actually quite a bit of cleanup to do yet, not according to your latest scans with StopSign, but according to the previous Kaspersky scan. Please make note of and respond to the question at the end of the post I linked to above.
     
  7. 2008/09/24
    Chilly

    Chilly Inactive Thread Starter

    Joined:
    2008/08/30
    Messages:
    37
    Likes Received:
    0
    noahdfear,
    Whenever I click on the check.dat icon it brings up a dos screen. Is it supposed to? There's nothing in the dos box and the cursor just sits and blinks. Plz explain.
    Also, I'm not sure which question you want me to respond to...if it's about deleting things I've already said I would. Let me know plz.
    Thanx.
     
    Last edited: 2008/09/24
  8. 2008/09/24
    Chilly

    Chilly Inactive Thread Starter

    Joined:
    2008/08/30
    Messages:
    37
    Likes Received:
    0
    One more thing - the dos box says C:\WINDOWS\system32\cmd.exe.
    The cmd comand was used during the set-up of my new modem, if that helps......
     
  9. 2008/09/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    I hope you named it check.bat as opposed to check.dat, but yes, it will just sit there for a bit ..... it's searching for files. It should close on it's own when done. ;)

    The question I was referring to was about the Instant Messenger utilities that were reported by Kaspersky as infected.
     
  10. 2008/09/24
    Chilly

    Chilly Inactive Thread Starter

    Joined:
    2008/08/30
    Messages:
    37
    Likes Received:
    0
    Sorry, I guess I got a little impatient.....here are the results, thx. And I did answer that question, just tell me what you want me to delete or whatevere, ok.....

    RESULTS

    ~~winlogon backups~~

    Volume in drive C has no label.
    Volume Serial Number is F464-DE02

    Directory of C:\I386

    08/29/2002 03:00 AM 516,608 WINLOGON.EXE
    1 File(s) 516,608 bytes

    Directory of C:\WINDOWS\$NtServicePackUninstall$

    08/04/2004 12:56 AM 502,272 winlogon.exe
    1 File(s) 502,272 bytes

    Directory of C:\WINDOWS\$NtUninstallKB840987$

    08/29/2002 03:00 AM 516,608 winlogon.exe
    1 File(s) 516,608 bytes

    Directory of C:\WINDOWS\ServicePackFiles\i386

    04/13/2008 05:12 PM 507,904 winlogon.exe
    1 File(s) 507,904 bytes

    Directory of C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819

    08/04/2004 12:56 AM 502,272 winlogon.exe
    1 File(s) 502,272 bytes

    Directory of C:\WINDOWS\SYSTEM32

    04/13/2008 05:12 PM 507,904 winlogon.exe
    1 File(s) 507,904 bytes

    ~~services backups~~

    Volume in drive C has no label.
    Volume Serial Number is F464-DE02

    Directory of C:\I386

    08/29/2002 03:00 AM 101,376 SERVICES.EXE
    1 File(s) 101,376 bytes

    Directory of C:\WINDOWS\$NtServicePackUninstall$

    08/04/2004 12:56 AM 108,032 services.exe
    1 File(s) 108,032 bytes

    Directory of C:\WINDOWS\ServicePackFiles\i386

    04/13/2008 05:12 PM 108,544 services.exe
    1 File(s) 108,544 bytes

    Directory of C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819

    08/04/2004 12:56 AM 108,032 services.exe
    1 File(s) 108,032 bytes

    Directory of C:\WINDOWS\SYSTEM32

    04/13/2008 05:12 PM 108,544 services.exe
    1 File(s) 108,544 bytes

    ~~lsass backups~~

    Volume in drive C has no label.
    Volume Serial Number is F464-DE02

    Directory of C:\I386

    08/29/2002 03:00 AM 11,776 LSASS.EXE
    1 File(s) 11,776 bytes

    Directory of C:\WINDOWS\$NtServicePackUninstall$

    08/04/2004 12:56 AM 13,312 lsass.exe
    1 File(s) 13,312 bytes

    Directory of C:\WINDOWS\ServicePackFiles\i386

    04/13/2008 05:12 PM 13,312 lsass.exe
    1 File(s) 13,312 bytes

    Directory of C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819

    08/04/2004 12:56 AM 13,312 lsass.exe
    1 File(s) 13,312 bytes

    Directory of C:\WINDOWS\SYSTEM32

    04/13/2008 05:12 PM 13,312 lsass.exe
    1 File(s) 13,312 bytes

    ~~svchost backups~~

    Volume in drive C has no label.
    Volume Serial Number is F464-DE02

    Directory of C:\I386

    08/29/2002 03:00 AM 12,800 SVCHOST.EXE
    1 File(s) 12,800 bytes

    Directory of C:\WINDOWS\$NtServicePackUninstall$

    08/04/2004 12:56 AM 14,336 svchost.exe
    1 File(s) 14,336 bytes

    Directory of C:\WINDOWS\ServicePackFiles\i386

    04/13/2008 05:12 PM 14,336 svchost.exe
    1 File(s) 14,336 bytes

    Directory of C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819

    08/04/2004 12:56 AM 14,336 svchost.exe
    1 File(s) 14,336 bytes

    Directory of C:\WINDOWS\SYSTEM32

    04/13/2008 05:12 PM 14,336 svchost.exe
    1 File(s) 14,336 bytes

    ~~explorer backups~~

    Volume in drive C has no label.
    Volume Serial Number is F464-DE02

    Directory of C:\WINDOWS

    04/13/2008 05:12 PM 1,033,728 explorer.exe
    1 File(s) 1,033,728 bytes

    Directory of C:\WINDOWS\$NtServicePackUninstall$

    08/04/2004 12:56 AM 1,032,192 explorer.exe
    1 File(s) 1,032,192 bytes

    Directory of C:\WINDOWS\$NtUninstallKB820291$

    08/29/2002 03:00 AM 1,004,032 explorer.exe
    1 File(s) 1,004,032 bytes

    Directory of C:\WINDOWS\ServicePackFiles\i386

    04/13/2008 05:12 PM 1,033,728 explorer.exe
    1 File(s) 1,033,728 bytes

    Directory of C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819

    08/04/2004 12:56 AM 1,032,192 explorer.exe
    1 File(s) 1,032,192 bytes

    ~~spoolsv backups~~

    Volume in drive C has no label.
    Volume Serial Number is F464-DE02

    Directory of C:\I386

    08/29/2002 03:00 AM 51,200 SPOOLSV.EXE
    1 File(s) 51,200 bytes

    Directory of C:\WINDOWS\$hf_mig$\KB896423\SP2GDR

    06/10/2005 04:53 PM 57,856 spoolsv.exe
    1 File(s) 57,856 bytes

    Directory of C:\WINDOWS\$hf_mig$\KB896423\SP2QFE

    06/10/2005 05:17 PM 57,856 spoolsv.exe
    1 File(s) 57,856 bytes

    Directory of C:\WINDOWS\$NtServicePackUninstall$

    06/10/2005 04:53 PM 57,856 spoolsv.exe
    1 File(s) 57,856 bytes

    Directory of C:\WINDOWS\$NtUninstallKB896423$

    08/04/2004 12:56 AM 57,856 spoolsv.exe
    1 File(s) 57,856 bytes

    Directory of C:\WINDOWS\$NtUninstallKB896423_0$

    08/29/2002 03:00 AM 51,200 spoolsv.exe
    1 File(s) 51,200 bytes

    Directory of C:\WINDOWS\ServicePackFiles\i386

    04/13/2008 05:12 PM 57,856 spoolsv.exe
    1 File(s) 57,856 bytes

    Directory of C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819

    08/04/2004 12:56 AM 57,856 spoolsv.exe
    1 File(s) 57,856 bytes

    Directory of C:\WINDOWS\SYSTEM32

    04/13/2008 05:12 PM 57,856 spoolsv.exe
    1 File(s) 57,856 bytes
    ~~~~~~~~~~

    That's it - thx!
     
  11. 2008/09/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Lets see if we can get these system files taken care of first.

    Highlight and copy the contents of the code box below.

    Code:
    @echo off
    echo Please wait
    copy C:\WINDOWS\ServicePackFiles\i386\explorer.exe C:\WINDOWS\system32\dllcache
    copy C:\WINDOWS\ServicePackFiles\i386\lsass.exe C:\WINDOWS\system32\dllcache
    copy C:\WINDOWS\ServicePackFiles\i386\services.exe C:\WINDOWS\system32\dllcache
    copy C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe C:\WINDOWS\system32\dllcache
    copy C:\WINDOWS\ServicePackFiles\i386\svchost.exe C:\WINDOWS\system32\dllcache
    copy C:\WINDOWS\ServicePackFiles\i386\winlogon.exe C:\WINDOWS\system32\dllcache
    if exist C:\WINDOWS\system32\dllcache\winlogon.exe ren C:\WINDOWS\system32\winlogon.exe winlogon.exe.old& echo winlogon renamed>done.txt
    if exist C:\WINDOWS\system32\dllcache\services.exe ren C:\WINDOWS\system32\services.exe services.exe.old& echo services renamed>>done.txt
    if exist C:\WINDOWS\system32\dllcache\lsass.exe ren C:\WINDOWS\system32\lsass.exe lsass.exe.old& echo lsass renamed>>done.txt
    if exist C:\WINDOWS\system32\dllcache\svchost.exe ren C:\WINDOWS\system32\svchost.exe svchost.exe.old& echo svchost renamed>>done.txt
    if exist C:\WINDOWS\system32\dllcache\explorer.exe ren C:\WINDOWS\explorer.exe explorer.exe.old& echo explorer renamed>>done.txt
    if exist C:\WINDOWS\system32\dllcache\spoolsv.exe ren C:\WINDOWS\system32\spoolsv.exe spoolsv.exe.old& echo spoolsv renamed>>done.txt
    start notepad done.txt
    exit
    cls
    
    Click Start>Run and type cmd then hit Enter to open a command window.
    Right click in the command window and select Paste.
    The command window will close on it's own and a text file will open when it completes.
    Post the contents of that log here.
     
  12. 2008/09/24
    Chilly

    Chilly Inactive Thread Starter

    Joined:
    2008/08/30
    Messages:
    37
    Likes Received:
    0
    Here's the results of the cmd report:

    winlogon renamed
    services renamed
    lsass renamed
    svchost renamed
    explorer renamed
    spoolsv renamed
     
  13. 2008/09/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Great! Now, 1 more time before we proceed.

    Highlight and copy the contents of the code box below.

    Code:
    @echo off
    if exist C:\WINDOWS\explorer.exe echo explorer present>done.txt
    if exist C:\WINDOWS\system32\lsass.exe echo lsass present>>done.txt
    if exist C:\WINDOWS\system32\services.exe echo services present>>done.txt
    if exist C:\WINDOWS\system32\spoolsv.exe echo spoolsv present>>done.txt
    if exist C:\WINDOWS\system32\svchost.exe echo svchost present>>done.txt
    if exist C:\WINDOWS\system32\winlogon.exe echo winlogon present>>done.txt
    start notepad done.txt
    exit
    cls
    
    Click Start>Run and type cmd then hit Enter to open a command window.
    Right click in the command window and select Paste.
    The command window will close on it's own and a text file will open when it completes.
    Post the contents of that log here.
     
  14. 2008/09/24
    Chilly

    Chilly Inactive Thread Starter

    Joined:
    2008/08/30
    Messages:
    37
    Likes Received:
    0
    Here ya go!

    explorer present
    lsass present
    services present
    spoolsv present
    svchost present
    winlogon present
     
  15. 2008/09/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Excellent! Now please restart your computer to complete the process.

    I'm still sorting through the list of infected files that showed up in the Kaspersky scan, and I'll post instructions for dealing with those shortly. In the meantime, please delete the current copy you have of ComboFix and download a fresh one from here. We'll be using it to remove the infected files.
     
  16. 2008/09/24
    Chilly

    Chilly Inactive Thread Starter

    Joined:
    2008/08/30
    Messages:
    37
    Likes Received:
    0
    Ok, I restarted my computer and D/L'd the new ComboFix.

    When I D/L'd the new ComboFix my virus scanner comes up with this message though, and it kind of worries me......any ideas?

    File:
    c:\documents and settings\karen\desktop\combofix.exe:32788R22FWJWF\psexec.cfexe

    Virus or Threat:
    Program.PsExec.171

    Action: Delete, Quarantine, Ignore, or Take No Action
     
  17. 2008/09/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Take no action.

    It's a routine embedded in ComboFix and flagged only by it's behavior. Most antivirus applications have excluded it from their detections. I assure you the file is safe. You will need to make sure you prevent your antivirus from interfering with ComboFix whilst it is running too, so please disable it's realtime protection.

    Highlight and copy the contents of the code box below and paste it into a blank notepad, then save it to your desktop as;

    Filename: CFScript.txt
    Save As Type: All Files (*.*)

    Code:
    KillAll::
    File::
    C:\Documents and Settings\Karen\Desktop\Desktop Folders\PUTER PROTECTION\All Y-Fame Versions\YFame6\Y-Famev6.zip
    C:\Documents and Settings\Karen\Desktop\Desktop Folders\PUTER PROTECTION\BOOT ****\+++ VENOM BOMBER +++.zip
    C:\Documents and Settings\Karen\Desktop\Desktop Folders\PUTER PROTECTION\BOOT ****\B O T S by ALL\Y-Famev6.zip
    C:\Documents and Settings\Karen\Desktop\Desktop Folders\PUTER PROTECTION\BOOT ****\B O T S by ALL\yfame7bylucif3r.zip
    C:\Documents and Settings\Karen\Desktop\Desktop Folders\PUTER PROTECTION\BOOT ****\Mortification Creation 3.0.zip
    C:\Documents and Settings\Karen\Desktop\Desktop Folders\PUTER PROTECTION\BOOT ****\Y-Fame6\Y-Fame v6\Y-Fame v6.exe
    C:\Documents and Settings\Karen\Desktop\Desktop Folders\PUTER PROTECTION\BOOT ****\Y-Fame6\Y-Famev6.zip
    C:\Documents and Settings\Karen\Desktop\STB11.25\STB-07.exe
    C:\Documents and Settings\Karen\Desktop\STB11.25\STB11.25.zip
    C:\Documents and Settings\Karen\My Documents\My Received Files\black booting 2.zip
    C:\Documents and Settings\Karen\My Documents\My Received Files\GMC--ChatClientBooterv.2.zip
    C:\Documents and Settings\Karen\My Documents\My Received Files\Y account.zip
    C:\Documents and Settings\LocalService\Application Data\584289103.exe._eac_qt_
    C:\Documents and Settings\LocalService\Application Data\809353461.exe._eac_qt_
    C:\Program Files\aaascreensavers\Keith Urban Active\VVSN_AAAS0741Inst.exe
    C:\Program Files\FileSubmit\Love Somebody Like you\NNEZTX638.exe
    C:\Program Files\Internet Explorer\setupapi.dll._eac_qt_
    C:\Program Files\Mozilla Firefox\setupapi.dll._eac_qt_
    C:\Program Files\MyEmoticons\VVSNI_S3_MYEM_Inst.exe
    C:\Program Files\PestPatrol\Quarantine\20040824015343791\WINDOWS\system\bho001.dll
    C:\Program Files\PestPatrol\Quarantine\20040824015343791\WINDOWS\system\rsp001.dll
    C:\Program Files\PestPatrol\Quarantine\20040824015343791\WINDOWS\system\update_com.dll
    C:\unzipped\black booting 2\BlackBooting v.2.6.exe
    C:\unzipped\ChatKillerlimitedv1\Chat Killer limited.exe
    C:\unzipped\elite_bomber-140\elite_bomber_140\Elite Bomber.exe
    C:\unzipped\GMC--ChatClientBooterv.2\GMC---Chat Client Booter v2.exe
    C:\unzipped\makeashitloadofnamesnshit\Make A ShitLoad of Names N ****!!!!!!!.exe
    C:\unzipped\Mortification Creation 3.0\Mortification Creation 3.0\Mortification_Creation.exe
    C:\unzipped\Occ Bomber\Occ Bomber\Occ.exe
    C:\unzipped\Y-Famev6\Y-Fame v6\Y-Fame v6.exe
    C:\unzipped\yfame7bylucif3r\yfame7bylucif3r\Y-Fame v7.exe
    C:\WINDOWS\b122.exe._eac_qt_
    C:\WINDOWS\b122.exe._eac_qt_
    C:\WINDOWS\Downloaded Program Files\imloader.exe
    C:\WINDOWS\eSearchBar\exactSetup.exe
    C:\WINDOWS\iLookup\ezStub22.exe
    C:\WINDOWS\SYSTEM32\16.tmp._eac_qt_
    C:\WINDOWS\SYSTEM32\b.tmp._eac_qt_
    C:\WINDOWS\SYSTEM32\cbevtsvc.exe._eac_qt_
    C:\WINDOWS\SYSTEM32\~.exe._eac_qt_
    C:\~IntelliMover Files\Go!Zilla Downloads\morph20.exe.GZPT
    C:\WINDOWS\explorer.exe.old
    C:\WINDOWS\system32\lsass.exe.old
    C:\WINDOWS\system32\services.exe.old
    C:\WINDOWS\system32\spoolsv.exe.old
    C:\WINDOWS\system32\svchost.exe.old
    C:\WINDOWS\system32\winlogon.exe.old
    
    Close all other windows and programs. Now drag the CFScript.txt onto ComboFix.exe and drop it, using the left mouse button. Combofix should run and may reboot the computer when it's done. A log will open when it's complete. Post the contents of that log.

    Please do not click on the ComboFix window while it is running a scan. This can cause it to stall.
     
  18. 2008/09/25
    Chilly

    Chilly Inactive Thread Starter

    Joined:
    2008/08/30
    Messages:
    37
    Likes Received:
    0
    See last post for reason for deleation, thx.
     
    Last edited: 2008/09/25
  19. 2008/09/25
    Chilly

    Chilly Inactive Thread Starter

    Joined:
    2008/08/30
    Messages:
    37
    Likes Received:
    0
    See last post for reason for deletion, thx.
     
    Last edited: 2008/09/25
  20. 2008/09/25
    Chilly

    Chilly Inactive Thread Starter

    Joined:
    2008/08/30
    Messages:
    37
    Likes Received:
    0
    Noahdfear,
    The log from the ComboFix was so large that I couldn't post it here without using a huge amount of seperate posts. I dropped the contents into a Word Doc and it's got 417,669 characters and is 112 pages long!

    I can email it to you if you want me to. Otherwise please leave instructions on how you want me to do this because it's going to take up a LOT of space. If you don't want to post your email addy here just send it to me in a private msg and I will forward the ComboFix log to you, unless you have a better idea.

    Thanx.
     
    Last edited: 2008/09/25
  21. 2008/09/25
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.