pablo1020 Posted December 21, 2007 Report Share Posted December 21, 2007 Hi, I need help too. I download Hijackthis and appear this (i don't speak well english i'm spanish)Logfile of Trend Micro HijackThis v2.0.2Scan saved at 22:05:01, on 21-12-2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\HPConfig.exeC:\Archivos de programa\HPQ\Notebook Utilities\HPWirelessMgr.exeC:\WINDOWS\Explorer.exeC:\WINDOWS\system32\carpserv.exeC:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exeC:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exeC:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Archivos de programa\HPQ\One-Touch\OneTouch.EXEC:\ARCHIV~1\mcafee.com\agent\mcregwiz.exeC:\ARCHIV~1\mcafee.com\agent\mcagent.exec:\archiv~1\mcafee.com\vso\mcvsescn.exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAL.EXEC:\WINDOWS\avp.exeC:\WINDOWS\mgrs.exeC:\WINDOWS\lsass.exeC:\WINDOWS\system32\ctfmon.exeC:\Archivos de programa\MSN Messenger\MsnMsgr.ExeC:\WINDOWS\system32\svchost.exec:\archiv~1\mcafee.com\vso\mcvsftsn.exeC:\Archivos de programa\Messenger\msmsgs.exeC:\Archivos de programa\Internet Explorer\iexplore.exeC:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WLLoginProxy.exeC:\WINDOWS\system32\svchost.exeC:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.cl/R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = VÃnculosF2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\shell.exeO2 - BHO: (no name) - {1B7E0550-C0F3-4886-A9BE-ECADB6DD8C4D} - C:\WINDOWS\system32\browsel.dllO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar1.dllO2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dllO2 - BHO: e404 helper - {F10587E9-0E47-4CBE-84AE-7DD20B8684BB} - C:\Archivos de programa\Helper\Helper6.dllO3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\archiv~1\mcafee.com\vso\mcvsshl.dllO3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar1.dllO4 - HKLM\..\Run: [CARPService] carpserv.exeO4 - HKLM\..\Run: [synTPLpr] C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exeO4 - HKLM\..\Run: [synTPEnh] C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [ATIPTA] C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [Cpqset] C:\Archivos de programa\HPQ\Default Settings\cpqset.exeO4 - HKLM\..\Run: [Display Settings] C:\Archivos de programa\HPQ\Notebook Utilities\hptasks.exe /sO4 - HKLM\..\Run: [QT4HPOT] C:\Archivos de programa\HPQ\One-Touch\OneTouch.EXEO4 - HKLM\..\Run: [McRegWiz] C:\ARCHIV~1\mcafee.com\agent\mcregwiz.exe /autorunO4 - HKLM\..\Run: [VSOCheckTask] "c:\ARCHIV~1\mcafee.com\vso\mcmnhdlr.exe" /checktaskO4 - HKLM\..\Run: [VirusScan Online] "c:\ARCHIV~1\mcafee.com\vso\mcvsshld.exe"O4 - HKLM\..\Run: [MCAgentExe] c:\ARCHIV~1\mcafee.com\agent\mcagent.exeO4 - HKLM\..\Run: [MCUpdateExe] C:\ARCHIV~1\mcafee.com\agent\mcupdate.exeO4 - HKLM\..\Run: [watch199.exe] watch199.exeO4 - HKLM\..\Run: [setup System] C:\windows\windrop\setup.exeO4 - HKLM\..\Run: [Windows Services Registry] C:\WINDOWS\system\services.exeO4 - HKLM\..\Run: [ink Monitor] C:\Archivos de programa\EPSON\Ink Monitor\InkMonitor.exeO4 - HKLM\..\Run: [EPSON Stylus C67 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAL.EXE /P23 "EPSON Stylus C67 Series" /O6 "USB001" /M "Stylus C67"O4 - HKLM\..\Run: [intec Service Drivers0] UpdateWins.exeO4 - HKLM\..\Run: [internet Explorer 6.0 pro] winxpsp.exeO4 - HKLM\..\Run: [iexplore Data1 Centerl] C:\WINDOWS\system32\winzm.exeO4 - HKLM\..\Run: [undernet FLood] qiowhaei.exeO4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exeO4 - HKLM\..\Run: [smgr] mgrs.exeO4 - HKLM\..\Run: [lsass] C:\WINDOWS\lsass.exeO4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\printer.exeO4 - HKLM\..\Run: [NI.UGA6PY_0001_N122M2910] "C:\Documents and Settings\Marco Piffradi\Datos de programa\install_es[1].exe"O4 - HKLM\..\RunServices: [setup System] C:\windows\windrop\setup.exeO4 - HKLM\..\RunServices: [intec Service Drivers0] UpdateWins.exeO4 - HKLM\..\RunServices: [internet Explorer 6.0 pro] winxpsp.exeO4 - HKLM\..\RunServices: [iexplore Data1 Centerl] C:\WINDOWS\system32\winzm.exeO4 - HKLM\..\RunServices: [undernet FLood] qiowhaei.exeO4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /backgroundO4 - HKCU\..\Run: [intec Service Drivers0] UpdateWins.exeO4 - HKCU\..\Run: [internet Explorer 6.0 pro] winxpsp.exeO4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\MARCOP~1\CONFIG~1\Temp\winlogon.exeO4 - HKCU\..\Run: [spoolsv] C:\WINDOWS\system32\spoolvs.exeO4 - HKCU\..\RunServices: [setup System] C:\windows\windrop\setup.exeO4 - HKCU\..\RunServices: [intec Service Drivers0] UpdateWins.exeO4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICIO LOCAL')O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Servicio de red')O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')O4 - Startup: .protectedO4 - Startup: findfast.exeO4 - Global Startup: .protectedO4 - Global Startup: autorun.exeO4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXEO7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1O8 - Extra context menu item: &Windows Live Search - res://C:\Archivos de programa\Windows Live Toolbar\msntb.dll/search.htmO8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspxO8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~3\Office10\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.2\bin\npjpi142.dllO9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.2\bin\npjpi142.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exeO16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cabO20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dllO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: FCI - Unknown owner - C:\WINDOWS\system32\svchost.exe:ext.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exeO23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Archivos de programa\HPQ\Notebook Utilities\HPWirelessMgr.exeO23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\ARCHIV~1\McAfee.com\Agent\mcupdmgr.exeO23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\ARCHIV~1\mcafee.com\vso\mcvsrte.exe--End of file - 8478 bytesAnd you say to the other guy: ReRun HijackThis and put a check next to the followingF2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\proper.exeand to me appear this:F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\shell.exeI need to click that an then click fix checked?? plz, I need help, and I didn't found any of this tutorials in spanishThanks Link to post Share on other sites
jwbirdsong Posted December 21, 2007 Report Share Posted December 21, 2007 (edited) Download SDFix and save it to your desktop.Double click SDFix.exe and it will extract the files to C:\SDFixPlease then reboot your computer in Safe Mode (without Networking) by doing the following :Restart your computerAfter hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;Instead of Windows loading as normal, the Advanced Options Menu should appear;Select the option, to run Windows in Safe Mode, then press Enter.Choose your usual account. Open the C:\SDFix folder and double click RunThis.bat to start the script. Type Y to begin the cleanup process. It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot. Press any Key and it will restart the PC. When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons. Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt(Report.txt will also be copied to Clipboard ready for posting back on the forum). Finally paste the contents of the Report.txt back here along with a Combofix log..(below) Download Combofix to your desktop.Doubleclick combofix.exeFollow the prompts.Don't click on the window while the fix is running, because that will cause your system to hang.When finished and after reboot (in case it asks to reboot), it should open a log, combofix.txt. Post this log in your next reply .++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++Traducido con los pescados de Babel. Usted debe chascar acoplamiento en poste del englsh. Espere que esto ayude a algunoDescargue SDFix y ahórrelo a su tablero del escritorio. Doble el tecleo SDFix.exe y extraerá los archivos a C:\SDFix Entonces reanude por favor su computadora en modo seguro (sin establecimiento de una red) haciendo el siguiente: * Recomience su computadora * Después de oÃr su computadora señaló una vez durante arranque, pero antes de que aparezca el icono de Windows, golpea ligeramente la llave F8 continuamente; * En vez del cargamento de Windows como normal, el menú avanzado de las opciones debe aparecer; * Seleccione la opción, para funcionar Windows en modo seguro, después la prensa entra. * Elija su cuenta generalmente. * Abra la carpeta y el tecleo doble RunThis.bat de C:\SDFix para comenzar la escritura. * MecanografÃe Y para comenzar el proceso de la limpieza. * Quitará cualesquiera servicios de Trojan y entrada del registro que encuentre entonces aviso usted para presionar cualquier llave para reanudar. * Presione cualquier llave y recomenzará la PC. * Cuando la PC recomienza el Fixtool funcionará otra vez y terminar el proceso del retiro después exhiba acabado, presione cualquier llave para terminar la escritura y para cargar sus iconos de escritorio. * Una vez que la carga de escritorio de los iconos que el informe de SDFix se abrirá en la pantalla y también excepto en la carpeta de SDFix como Report.txt (Report.txt también será copiado al sujetapapeles listo para fijar detrás en el foro). * Finalmente pegue el contenido del Report.txt detrás aquà junto con un Combofix log..(below) Descargue Combofix a su tablero del escritorio. Doubleclick combofix.exe sigue los avisos. No chasque encendido la ventana mientras que el arreglo está funcionando, porque ése hará su sistema colgar. Cuando está acabado y después del reboot (en caso de que pide reanudar), él debe abrir un registro, combofix.txt. Fije esta conexión su contestación siguiente. Edited December 21, 2007 by jwbirdsong Link to post Share on other sites
pablo1020 Posted December 21, 2007 Author Report Share Posted December 21, 2007 (edited) Here Is the report:SDFix: Version 1.119Run by Marco Piffradi on 22-12-2007 at 12:01Microsoft Windows XP [Versión 5.1.2600]Running From: C:\SDFixSafe Mode:Checking Services: Name:FCIcaiplgdrPath:C:\WINDOWS\system32\svchost.exe:ext.exe system32\drivers\vkrukkpm.dat FCI - Deletedcaiplgdr - DeletedKilling PID 812 'shell.exe'Restoring Windows Registry ValuesRestoring Windows Default Hosts FileRebooting...Service caiplgdr - Deleted after RebootNormal Mode:Checking Files: Trojan Files Found:C:\WINDOWS\system32\drivers\vkrukkpm.dat - DeletedC:\WINDOWS\SYSTEM32\LOHVAUUG.EXE - DeletedC:\WINDOWS\SYSTEM32\YPSHZZ~1.EXE - DeletedC:\WINDOWS\SYSTEM32\NETTHROT.EXE - DeletedC:\10.TMP - DeletedC:\12.TMP - DeletedC:\14.TMP - DeletedC:\16.TMP - DeletedC:\D.TMP - DeletedC:\E.TMP - DeletedC:\WINDOWS\SYSTEM32\AUFIQDIF.TMP - DeletedC:\WINDOWS\SYSTEM32\ATI3DUA.DLL - DeletedC:\WINDOWS\SYSTEM32\BROWSEL.DLL - DeletedC:\WINDOWS\SYSTEM32\COMSVC.DLL - DeletedC:\WINDOWS\SYSTEM32\D3DPMES.DLL - DeletedC:\WINDOWS\SYSTEM32\DDEM.DLL - DeletedC:\WINDOWS\SYSTEM32\DESKAD.DLL - DeletedC:\Documents and Settings\Marco Piffradi\Escritorio\Find Spyware Remover.lnk - DeletedC:\Documents and Settings\Marco Piffradi\Escritorio\Free Online Dating.lnk - DeletedC:\Documents and Settings\Marco Piffradi\Escritorio\Go to Casino.lnk - DeletedC:\WINDOWS\system32\shift.exe.exe - DeletedC:\Archivos de programa\Helper\Helper6.dll - DeletedC:\Archivos de programa\Helper\smss.exe - DeletedC:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio\autorun.exe - DeletedC:\Documents and Settings\Marco Piffradi\Menú Inicio\Programas\Inicio\findfast.exe - DeletedC:\Archivos de programa\spoolsv.exe - DeletedC:\Documents and Settings\Marco Piffradi\Datos de programa\antivirus.exe - DeletedC:\DOCUME~1\MARCOP~1\CONFIG~1\Temp\1.reg - DeletedC:\DOCUME~1\MARCOP~1\CONFIG~1\Temp\hostsys.exe - DeletedC:\DOCUME~1\MARCOP~1\CONFIG~1\Temp\monagent.exe - DeletedC:\DOCUME~1\MARCOP~1\CONFIG~1\Temp\syn16.exe - DeletedC:\a.bat - DeletedC:\WINDOWS\avp.exe - DeletedC:\WINDOWS\Casino.ico - DeletedC:\WINDOWS\Free Online Dating.ico - DeletedC:\WINDOWS\lsass.exe - DeletedC:\WINDOWS\mgrs.exe - DeletedC:\WINDOWS\shell.exe - DeletedC:\WINDOWS\Spyware Remover.ico - DeletedC:\WINDOWS\system32\netthrot.exe - DeletedC:\WINDOWS\system32\printer.exe - DeletedC:\WINDOWS\system32\spoolvs.exe - DeletedC:\WINDOWS\system32\svcp.csv - DeletedC:\WINDOWS\system32\winsub.xml - DeletedFolder C:\Archivos de programa\Helper - RemovedRemoving Temp Files...ADS Check:C:\WINDOWSNo streams found. C:\WINDOWS\system32No streams found. C:\WINDOWS\system32\svchost.exe : ADS Found!svchost.exe: deleted 25600 bytes in 1 streams.Checking for remaining StreamsC:\WINDOWS\system32\svchost.exeNo streams found.C:\WINDOWS\system32\ntoskrnl.exeNo streams found.Then I open the comobofix Folder and appear a lot of thing but No one say Combofix.txt But in my Desktop Appear A txt Called catchme and a Winrar Document or.... (i don't know how to write it) With the same name. I open it and appear 4 Things (I don't Know What are that thing or document):· BROWSEL.DLL· symavc32.sys· vkrukkpm.dat· vkrukkpm.dat.1And this say the Txt (catchme):catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-12-22 12:52:28Windows 5.1.2600 Service Pack 2 NTFSscanning hidden processes ...scanning hidden services & system hive ...[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Wrei39]"Type"=dword:00000001"Tag"=dword:00000001"Group"="System ReservedBoot Bus ExtenderSystem Bus ExtenderSCSI miniportPortPrimary DiskSCSI ClassSCSI CDROM ClassFSFilter InfrastructureFSFilter SystemFSFilter BottomFSFilter Copy ProtectionFSFilter Security EnhancerFSFilter Open FileFSFilter Physical Quota ManagementFSFilter EncryptionFSFilter CompressionFSFilter HSMFSFilter Cluster File SystemFSFilter System RecoveryFSFilter Quota ManagementFSFilter Content ScreenerFSFilter Continuous BackupFSFilter ReplicationFSFilter Anti-VirusFSFilter UndeleteFSFilter Activity MonitorFSFilter TopFilterBoot File SystemBasePointer PortKeyboard PortPointer ClassKeyboard ClassVideo InitVideoVideo SaveFile SystemEvent LogStreams DriversNDIS WrapperCOM InfrastructureUIGroupLocalValidationPlugPlayPNP_TDINDISTDINetBIOSGroupShellSvcGroupSchedulerGroupSpoolerGroupAudioGroupSmartCardGroupNetworkProviderRemoteValidationNetDDEGroupParallel arbitratorExtended BasePCI Configuration""ErrorControl"=dword:00000001"Start"=dword:00000000[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Wrei39]"Type"=dword:00000001"Tag"=dword:00000001"Group"="System ReservedBoot Bus ExtenderSystem Bus ExtenderSCSI miniportPortPrimary DiskSCSI ClassSCSI CDROM ClassFSFilter InfrastructureFSFilter SystemFSFilter BottomFSFilter Copy ProtectionFSFilter Security EnhancerFSFilter Open FileFSFilter Physical Quota ManagementFSFilter EncryptionFSFilter CompressionFSFilter HSMFSFilter Cluster File SystemFSFilter System RecoveryFSFilter Quota ManagementFSFilter Content ScreenerFSFilter Continuous BackupFSFilter ReplicationFSFilter Anti-VirusFSFilter UndeleteFSFilter Activity MonitorFSFilter TopFilterBoot File SystemBasePointer PortKeyboard PortPointer ClassKeyboard ClassVideo InitVideoVideo SaveFile SystemEvent LogStreams DriversNDIS WrapperCOM InfrastructureUIGroupLocalValidationPlugPlayPNP_TDINDISTDINetBIOSGroupShellSvcGroupSchedulerGroupSpoolerGroupAudioGroupSmartCardGroupNetworkProviderRemoteValidationNetDDEGroupParallel arbitratorExtended BasePCI Configuration""ErrorControl"=dword:00000001"Start"=dword:00000000scanning hidden registry entries ...[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup]"LogLevel"=dword:00000000scanning hidden files ...C:\WINDOWS\KB896423.log 6203 bytesC:\WINDOWS\KB896428.log 5982 bytesC:\WINDOWS\KB935839.log 5878 bytesC:\WINDOWS\KB942615.log 6642 bytesC:\WINDOWS\KB944653.log 5433 bytesPD: I don't run Completly combofix because appear a window and says that thet program have a Suspect Archive or a virus (It's my antivirus: McAffe)So I close Comobofix. It's Combofix secure? Edited December 21, 2007 by pablo1020 Link to post Share on other sites
jwbirdsong Posted December 21, 2007 Report Share Posted December 21, 2007 I don't run Completly combofix because appear a window and says that thet program have a Suspect Archive or a virusYes this happens some time. ComboFix is NOT a virus..it is safe to run....Please do so. Link to post Share on other sites
Recommended Posts