1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

User had a bad dialer - maybe not all cleaned

Discussion in 'Security and Privacy' started by Newt, 2004/05/03.

Thread Status:
Not open for further replies.
  1. 2004/05/03
    Newt

    Newt Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    I suggested he post the hijackthis log here. Since he couldn't, I am while I try to find out what happened with the user account - Newt

    Newt, I have tried posting in windows bbs security forum but for some reason I do not have permission. I have been registered on there for over a year, I will persevere, in the meantime, here is my hijackthis log:
    I have removed some items since my last post on the advice of the modemhelp forum, and have been clear since, but I'm not convinced its gone.

    Logfile of HijackThis v1.97.7
    Scan saved at 11:57:09, on 03/05/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Logitech\iTouch\iTouch.exe
    C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\System32\qttask.exe
    C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
    C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe
    C:\Program Files\Logitech\iTouch\kbdtray.exe
    C:\Program Files\BTopenworld\DialBTIAnytime.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\David\My Documents\Personal\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.timesupport.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.btinternet.com/DiallerCh...openworld.com?duser=j.dcranmer@btinternet.com
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar_en_2.0.108-big.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar_en_2.0.108-big.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Supastatus] C:\Program Files\Internet Explorer\Connection Wizard\status.exe
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [Gtwatch] C:\WINDOWS\gtwatch.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
    O4 - HKLM\..\Run: [System Process] C:\WINDOWS\svchost.exe /i
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
    O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
    O4 - Global Startup: Ulead Photo Express 3.0 SE Calendar Checker.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar_en_2.0.108-big.dll/cmsearch.html
    O8 - Extra context menu item: Backward &Links - res://c:\windows\GoogleToolbar_en_2.0.108-big.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\windows\GoogleToolbar_en_2.0.108-big.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Si&milar Pages - res://c:\windows\GoogleToolbar_en_2.0.108-big.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar_en_2.0.108-big.dll/cmtrans.html
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O14 - IERESET.INF: START_PAGE_URL=http://www.timesupport.com
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/19b058372c22e80ba205/netzip/RdxIE601.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://housecall.trendmicro-europe.com/housecall/Xscan53.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - http://register.btopenworld.com/templates/btwebcontrol012.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{D255BE7B-6309-4E50-8890-D1C6F206B7A4}: NameServer = 213.1.119.100 213.1.119.99
     
    Newt,
    #1
  2. 2004/05/03
    Newt

    Newt Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Errr - anybody want to offer an opinion on this log?
     
    Newt,
    #2

  3. to hide this advert.

  4. 2004/05/03
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    This is definately a nasty. Fix for sure.
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.btinternet.com/DiallerCh...@btinternet.com
    O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - http://register.btopenworld.com/tem...bcontrol012.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{D255BE7B-6309-4E50-8890-D1C6F206B7A4}: NameServer = 213.1.119.100 213.1.119.99


    Interesting info here. http://www.the-scream.co.uk/forums/t11119.html I would lean toward fixing all of these. Pacmans startup list suggests status.exe not need at startup.
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.timesupport.com
    O4 - HKLM\..\Run: [Supastatus] C:\Program Files\Internet Explorer\Connection Wizard\status.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.timesupport.com


    This is a leftover from a DirectX 6.0 upgrade. It was supposed to run once and go away but on some systems it sticks around. You can fix and then delete the executable file.
    O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A


    Related to cracking program. Should be fixed and file removed.
    O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\S6U12BX\WATCH.exe


    Not needed at startup.
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Desktop Messenger\8876480\Program\LDMConf.exe


    Very suspicious! By default in the C:\Windows\system32 folder. Not in running processes and associated with some viri, although the [System Process] would lead one to believe it's valid. ????? Suggest some online scans. Also saw one instance where this entry was gone after running CWShredder, so recommend that too. My instincts say fix it, rename file and later delete if no problems arise.
    O4 - HKLM\..\Run: [System Process] C:\WINDOWS\svchost.exe /i

    Clean out all temps;
    C:\Temp
    C:\Windows\temp
    C:\Documents and Settings\All Usernames\Local Settings\temp
    Delete all Temporary Internet Files
    Empty recycle bin.
    Run both Spybot and Ad-aware with up-to-date builds and reference files.
    Reboot and post a new log.
     
  5. 2004/05/03
    goddez1

    goddez1 Inactive

    Joined:
    2002/01/12
    Messages:
    2,975
    Likes Received:
    49
    Unless your isp service provider is BT Openworld:
    http://www.btopenworld.com/default

    Although the above url does lead to a site message stating that "your Anytime Dialup Software is out of date ". I noticed this site offers several different types of accounts. Also read something about free upgrades BT Yahoo. Their home page is:
    http://www.btopenworld.com/default/0,6706,,00.html
    Their offered accounts are:
    http://www.btyahoo.com/internet/prices



    Unless you have set and locked or allowed this site to set and lock your home page to (and subscribe to):
    http://www.timesupport.com/
     
    Last edited: 2004/05/03
  6. 2004/05/04
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Yikes!!! :eek: :eek: What did I do?? My apologies to the poster! Must be a hijacker in my head. I kept reading this as abetterinternet, the hijacker. Don't know what else to say.......... :eek: :eek:
    Right on the money again, Ann. Thank you!

    Maybe I should quit doing logs until the twins allow me a bit more sleep, and concentration :(
     
  7. 2004/05/04
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    mmmmgrumble :D

    Start Hijackthis and place a check next to these items
    Close all browser windows and shut down all other programs(even Folders) that show in the taskbar. Then Hit fix selected
    O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
    O4 - HKLM\..\Run: [System Process] C:\WINDOWS\svchost.exe /i
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
    ==========
    Reboot and delete that and only that svchost.
    You might have to have windows show hidden file's and folder's in order to see them.
    How to Show hidden files and folders.

    then run cwsredder to
    Downloadand and run
    Cwsredder.exe <<from there
    Click Fix, don't just scan. You have several CoolWebSearch components which it should remove.
    If you already have it, just download another copy and overwrite the old one..
    To ensure its the latest version. currently its ver 1.57

    Reboot after doing so
    come back then scan and repost another Hijackthis Log
     
  8. 2004/05/04
    Newt

    Newt Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Thanks guys. Not sure if David has a working account here at this point or not so I emailed him asking for a status update. Will post details when I get them.
     
    Newt,
    #7
  9. 2004/05/05
    David C

    David C Inactive

    Joined:
    2003/03/11
    Messages:
    56
    Likes Received:
    0
    Thanks guys, I followed your advice. Hopefully I'm clear now. I'll get cwshredder & repost the log when I've done it.

    Much appreciated
     
  10. 2004/05/05
    David C

    David C Inactive

    Joined:
    2003/03/11
    Messages:
    56
    Likes Received:
    0
    More searching hidden files has turned up another svchost here:

    SVCHOST - C:\WINDOWS\I386

    size 7kb, last modified date is 18-8-2001, same as the good file in system32, so I'm guessing its good, I'll leave it alone unless you advise otherwise.
     
  11. 2004/05/05
    David C

    David C Inactive

    Joined:
    2003/03/11
    Messages:
    56
    Likes Received:
    0
    Here is my new hijackthis log after fixing & running cwshredder:

    Logfile of HijackThis v1.97.7
    Scan saved at 10:45:18, on 05/05/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Logitech\iTouch\iTouch.exe
    C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\System32\qttask.exe
    C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
    C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe
    C:\Program Files\Logitech\iTouch\kbdtray.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
    C:\Documents and Settings\David\My Documents\Personal\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.timesupport.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.btinternet.com/DiallerCh...openworld.com?duser=j.dcranmer@btinternet.com
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar_en_2.0.108-big.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar_en_2.0.108-big.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Supastatus] C:\Program Files\Internet Explorer\Connection Wizard\status.exe
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [Gtwatch] C:\WINDOWS\gtwatch.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
    O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
    O4 - Global Startup: Ulead Photo Express 3.0 SE Calendar Checker.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 3.0 SE\CalCheck.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar_en_2.0.108-big.dll/cmsearch.html
    O8 - Extra context menu item: Backward &Links - res://c:\windows\GoogleToolbar_en_2.0.108-big.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\windows\GoogleToolbar_en_2.0.108-big.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Si&milar Pages - res://c:\windows\GoogleToolbar_en_2.0.108-big.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar_en_2.0.108-big.dll/cmtrans.html
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O14 - IERESET.INF: START_PAGE_URL=http://www.timesupport.com
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://housecall.trendmicro-europe.com/housecall/Xscan53.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - http://register.btopenworld.com/templates/btwebcontrol012.cab



    Thanks, David
     
  12. 2004/05/05
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Looks good to me
    There are a couple otionals,, I'd can backweb, but its differant on all pc's
    in Logitech options should be an item to uncheck so it doenst automaticly check for updates, then you might need to uncheck BackWeb-8876480.exe using msconfig.

    This can be fixed with hijackthis, But i suggest to use msconfig
    O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe


    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    this one also ^^ but afterward reboot then before using real one player
    find and rename realsched.old
    its not needed and the player can still be used.

    Be sure to keep all programs that use the net up to date.
    there were two recently , one a few months back that requires an redownload of realplayer or an over the top install, you should check.
    if you do update it then the above will need to be done again, (the renaming)

    and a more recent bug in quicktime/iTunes 4.x
    http://secunia.com/advisories/11071/
    CRITICAL:
    Highly critical

    Did cwsredder find anything ?
    You should go get a housecall if you havent already

    Im not sure, wait the others here will know for sure, :)
     
  13. 2004/05/05
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Glad to see you can post again. :) I386 contains the Windows setup files, so there should be an svchost file there.
     
  14. 2004/05/05
    Newt

    Newt Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Glad your account is alive and well again David.

    How is your PC running now?
     
  15. 2004/05/06
    David C

    David C Inactive

    Joined:
    2003/03/11
    Messages:
    56
    Likes Received:
    0
    Thanks guys, everything seems ok. now.
    Cwshredder said everything was clean, I'll keep it updated & check it regularly. Also looks like I need a decent firewall (XP's firewall let this thing through)

    Thanks again, David
     
  16. 2004/05/06
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Very good decision, IMO. :) When SP2 gets released, XP's firewall will presumably be much better.

    Kerio, Sygate and Zone Alarm are the most popular freebies.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.