Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 27

Thread: I've acquired "Virtumonde"

  1. #11
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    Sounds good to me, here is information to help you control those junk cookies:

    http://www.mvps.org/winhelp2002/cookies.htm
    http://www.microsoft.com/windows/ie/...cy/config.mspx

    Let's see if we can wrap up like this...

    Remove combofix from the computer like this:

    Click START then RUN
    Now type or copy Combofix /u in the runbox and click OK.
    Note the space between the X and the U, it needs to be there.



    Clean the System Restore files like this:

    Turn off System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.

    Reboot

    Turn ON System Restore,
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    UN-Check *Turn off System Restore*.
    Click Apply, and then click OK.

    (you can make the next two scans optional if you wish)

    Update MBAM and scan to be sure we missed none of the junk, there is no need to post a clean scan result.
    (MBAM is yours to keep if you wish, update it and run it once a month or so)

    Update AVG 8 and scan the system, to be sure it is running right and scanning clean. If you have problems with the program, contact tech support for instructions.
    Good information for AVG:
    FAQ: http://www.avg.com/faq
    AVG Free Forum: http://freeforum.avg.com/

    If all is well at this point, let me know and I will close the topic.

    Some good information for you:
    http://users.telenet.be/bluepatchy/m...wcomputer.html
    http://www.microsoft.com/windowsxp/u...s/mcgill1.mspx

    Here is some great information from experts in this field that will help you stay clean and safe online.
    http://users.telenet.be/bluepatchy/m...revention.html
    http://forums.spybot.info/showthread.php?t=279
    http://russelltexas.com/malware/allclear.htm
    http://forum.malwareremoval.com/viewtopic.php?t=14
    http://www.bleepingcomputer.com/forums/topict2520.html
    http://cybercoyote.org/security/not-admin.shtml

    http://www.malwarecomplaints.info/

    Thanks...pskelley
    Safer Networking Forums
    http://www.spybot.info/en/donate/index.html
    If you are reading this information...thank a teacher,
    If you are reading it in English...thank a soldier.

    http://users.telenet.be/bluepatchy/m...oes/Links.html
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  2. #12
    Member
    Join Date
    Feb 2009
    Posts
    45

    Default

    Well, I thought all was well. I removed combofix and cleaned the restore history. I set AVG to scan everyday at 5 AM, so I checked that scan just out of curiosity, and it found 38 infections!

    Here is the AVG log:

    Scan "Scheduled scan" was finished.
    Infections;"38";"38";"0"
    Folders selected for scanning:;"Scan whole computer"
    Scan started:;"Friday, February 06, 2009, 5:00:01 AM"
    Scan finished:;"Friday, February 06, 2009, 6:31:58 AM (1 hour(s) 31 minute(s) 56 second(s))"
    Total object scanned:;"394374"
    User who launched the scan:;"SYSTEM"

    Infections
    File;"Infection";"Result"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\aqljenwc.dll.vir;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\deijhfsx.dll.vir;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\dxkjfjkt.dll.vir;"Trojan horse Generic12.BHZF";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ghpuogbq.dll.vir;"Trojan horse Generic12.BHZF";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ihnrpxyp.dll.vir;"Trojan horse Generic12.BHKW";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\jfgsbequ.dll.vir;"Trojan horse Generic12.BHZF";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\jhdbyljh.dll.vir;"Trojan horse Generic12.BHZF";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\kahedqfk.dll.vir;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\mhnjsy.dll.vir;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\mksvyq.dll.vir;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\orrwjars.dll.vir;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\podpcs.dll.vir;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\rbqsiama.dll.vir;"Trojan horse Generic12.BHKW";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\tbsijq.dll.vir;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ttpcnv.dll.vir;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ttxguktd.dll.vir;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\tuvSjJcC.dll.vir;"Trojan horse Generic12.BHJY";"Moved to Virus Vault"
    C:\Qoobox\Quarantine\C\WINDOWS\system32\usqysxvl.dll.vir;"Trojan horse Generic12.BHZF";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000050.dll;"Trojan horse Generic12.BHKW";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000051.dll;"Trojan horse Generic12.BHKW";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000133.dll;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000134.dll;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000135.dll;"Trojan horse Generic12.BHZF";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000136.dll;"Trojan horse Generic12.BHZF";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000138.dll;"Trojan horse Generic12.BHKW";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000139.dll;"Trojan horse Generic12.BHZF";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000140.dll;"Trojan horse Generic12.BHZF";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000141.dll;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000142.dll;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000143.dll;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000144.dll;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000145.dll;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000147.dll;"Trojan horse Generic12.BHKW";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000148.dll;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000149.dll;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000150.dll;"Trojan horse Generic12.BHKY";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000151.dll;"Trojan horse Generic12.BHJY";"Moved to Virus Vault"
    C:\System Volume Information\_restore{6B4FEAE6-C7FA-4BE4-8B4F-291C5476B0EA}\RP5\A0000152.dll;"Trojan horse Generic12.BHZF";"Moved to Virus Vault"

    Warnings
    File;"Infection";"Result"
    C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\75zeoy3f.default\cookies.sqlite;"Found Tracking cookie.Tacoda";"Healed"
    C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\75zeoy3f.default\cookies.sqlite:\revsci.net.50e13b1b;"Found Tracking cookie.Revsci";"Moved to Virus Vault"
    C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\75zeoy3f.default\cookies.sqlite:\tacoda.net.27341d57;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
    C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\75zeoy3f.default\cookies.sqlite:\tacoda.net.4366831a;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
    C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\75zeoy3f.default\cookies.sqlite:\tacoda.net.5935e89;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
    C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\75zeoy3f.default\cookies.sqlite:\tacoda.net.c4fe2ebb;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
    C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\75zeoy3f.default\cookies.sqlite:\tacoda.net.cd7ce44f;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"
    C:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\75zeoy3f.default\cookies.sqlite:\tacoda.net.ed9c50d1;"Found Tracking cookie.Tacoda";"Moved to Virus Vault"

    Here is the new HJT log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:39:07 AM, on 2/6/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_11.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_11.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
    O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    --
    End of file - 4872 bytes

  3. #13
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    I will have to say it appears somehow the directions did not get followed
    combofix quarantine should have been removed (along with combofix) and the System Restore files AVG is finding should have been removed with the instructions I posted here:
    Clean the System Restore files like this:

    To be sure this is done, follow these direction:

    1) Remove combofix from the computer like this:

    Click START then RUN
    Now type or copy Combofix /u in the runbox and click OK.
    Note the space between the X and the U, it needs to be there.



    To be sure the stuff is gone, look on the C:\ for this:
    C:\Qoobox <<< delete that folder and any content.

    FOLLOW THESE DIRECTIONS AGAIN AND VERY CAREFULLY:

    Clean the System Restore files like this:

    Turn off System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.

    Reboot

    Turn ON System Restore,
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    UN-Check *Turn off System Restore*.
    Click Apply, and then click OK.

    This information will help you control cookies with Internet Explorer:
    http://www.mvps.org/winhelp2002/cookies.htm
    http://www.microsoft.com/windows/ie/...cy/config.mspx

    With Mozilla Firefox:
    http://mozilla.gunnars.net/firefox_h..._tutorial.html

    http://privacy.getnetwise.org/browsi...disablecookies
    http://www.mozilla.org/projects/secu...priv_help.html
    https://addons.mozilla.org/firefox/2497/ <<< Add-ons

    Thanks
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  4. #14
    Member
    Join Date
    Feb 2009
    Posts
    45

    Default

    Could part of the problem be that I can't update MBAM? I click on Update and the connection with malwarebytes.org just hangs. It makes no progress at all.

  5. #15
    Member
    Join Date
    Feb 2009
    Posts
    45

    Default

    Sorry for the confusion... the scan results I posted from AVG took place at 5 A.M., before I had uninstalled combofix and cleaned the registry.

  6. #16
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    http://www.malwarebytes.org/ << see if you can access this website. If you can then remove the old version of MBAM and download it again from
    Malwarebytes' Anti-Malware. Then see if you can get the updates you need.

    Thanks
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  7. #17
    Member
    Join Date
    Feb 2009
    Posts
    45

    Default

    I was able to access the malwarebytes site. I uninstalled the old program as well as the old setup icon, and rebooted. Upon reboot I re-downloaded malwarebytes. The last page of the setup screen prompts you to update the program and then launch. The same problem as before is present again. The update screen comes up, and says "Looking for malwarebytes.org", but makes no progress. I let it try for ~10 minutes and there's no movement whatsoever.

  8. #18
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    This is a new one on me, since I am basically a user of MBAM just as you are, why not ask about the issue here:
    http://www.malwarebytes.org/forums/

    These folks know the tool and will be better at advising you.

    Thanks
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  9. #19
    Member
    Join Date
    Feb 2009
    Posts
    45

    Default

    OK will do... thanks. Were you implying earlier those infections that AVG found are not threats because they have since been deleted by cleaning the registry and uninstalling combofix? The computer still seems to be running well, not great. No other issues, however. I'm leaving for work right now and will be back tonight, at which point I will report back with the results of another AVG scan and hopefully an update from the MBAM forum regarding the update issue. Thank you again.

  10. #20
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,247

    Default

    The items in the combofix quarantine and the infected System Restore files will no longer exist once the directions are followed. The tracking cookies should not be allowed on your computer, you do have the choice.

    Thanks
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •