Cutolo Posted February 2, 2009 ID:52668 Share Posted February 2, 2009 My dad has been using this computer recently and has gotten many Avira guard warnings some having to relate to Symantec Antivirus. The computer has had a recent history of Avira detections all different. I do question where my dad got this computer from. My sister and my dad share the computer. My dad goes on hxxp://www.163.com for news, and I suspect that site is causing the problems.Malwarebytes' Anti-Malware 1.33Database version: 1714Windows 5.1.2600 Service Pack 22009-2-1 20:12:16mbam-log-2009-02-01 (20-12-16).txtScan type: Full Scan (A:\|C:\|D:\|E:\|F:\|G:\|)Objects scanned: 84293Time elapsed: 27 minute(s), 36 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 0Registry Values Infected: 0Registry Data Items Infected: 0Folders Infected: 0Files Infected: 1Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:(No malicious items detected)Registry Values Infected:(No malicious items detected)Registry Data Items Infected:(No malicious items detected)Folders Infected:(No malicious items detected)Files Infected:C:\Program Files\Veoh Networks\VeohWebPlayer\uninst.exe (Trojan.Downloader) -> Quarantined and deleted successfully.~~~~~~~~~~~~~~~~~~~~~~~~~Logfile of Trend Micro HijackThis v2.0.2Scan saved at 19:46:03, on 2009-2-1Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exeC:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeC:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exeC:\PROGRA~1\AVG\AVG8\avgwdsvc.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\PROGRA~1\AVG\AVG8\avgrsx.exeC:\PROGRA~1\AVG\AVG8\avgnsx.exeC:\Program Files\Tall Emu\Online Armor\oacat.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\PROGRA~1\AVG\AVG8\avgemc.exeC:\Program Files\AVG\AVG8\avgcsrvx.exeC:\WINDOWS\System32\alg.exeC:\WINDOWS\system32\ctfmon.exeC:\Nexon\MapleStory\npkcmsvc.exeC:\Program Files\AIM6\aolsoftware.exeC:\Program Files\Avira\AntiVir PersonalEdition Classic\avscan.exeC:\WINDOWS\system32\wuauclt.exeC:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exeC:\Program Files\AIM6\aim6.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Malwarebytes' Anti-Malware\mbam.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeC:\WINDOWS\system32\wbem\wmiprvse.exeO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dllO2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dllO2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLLO2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\NetTransport 2\NTIEHelper.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLLO3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dllO4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNCO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMENameO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNCO4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startupO4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exeO4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /minO4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -kO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exeO4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exeO4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')O8 - Extra context menu item: 导出到 Microsoft Excel(&x) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra button: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Program Files\herov8\STHSDVD.EXEO9 - Extra 'Tools' menuitem: 豪杰超级解霸V8 - {367E0A21-8601-4986-9C9A-153BF5ACA118} - C:\Program Files\herov8\STHSDVD.EXEO9 - Extra button: 微软 - {6096E38F-5AC1-4391-8EC4-75DFA92FB32F} - http://www.microsoft.com/china/index.htm (file missing)O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1096088341547O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dllO20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dllO23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeO23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exeO23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exeO23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exeO23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exeO23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\MapleStory\npkcmsvc.exeO23 - Service: Online Armor Helper Service (OAcat) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oacat.exeO23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exeO23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exeO23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe--End of file - 7171 bytes~~~~~~~~~~~~~~~~~~~~~~~Avira AntiVir PersonalReport file date: 2009年2月1日 19:17Scanning for 1304962 virus strains and unwanted programs.Licensed to: Avira AntiVir PersonalEdition ClassicSerial number: 0000149996-ADJIE-0001Platform: Windows XPWindows version: (Service Pack 2) [5.1.2600]Boot mode: Normally bootedUsername: SYSTEMComputer name: DISCOVERVersion information:BUILD.DAT : 8.2.0.337 16934 Bytes 2008-11-18 13:05:00AVSCAN.EXE : 8.1.4.10 315649 Bytes 2008-11-26 04:15:18AVSCAN.DLL : 8.1.4.0 40705 Bytes 2008-5-26 14:56:42LUKE.DLL : 8.1.4.5 164097 Bytes 2008-6-12 19:44:20LUKERES.DLL : 8.1.4.0 12033 Bytes 2008-5-26 14:58:54ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 2008-10-27 01:13:18ANTIVIR1.VDF : 7.1.1.113 2817536 Bytes 2009-1-14 22:37:56ANTIVIR2.VDF : 7.1.1.207 1359360 Bytes 2009-1-30 23:28:46ANTIVIR3.VDF : 7.1.1.210 40448 Bytes 2009-2-1 23:28:16Engineversion : 8.2.0.70 AEVDF.DLL : 8.1.1.0 106868 Bytes 2009-1-30 23:29:06AESCRIPT.DLL : 8.1.1.39 344443 Bytes 2009-1-30 23:29:04AESCN.DLL : 8.1.1.6 127348 Bytes 2009-1-30 23:29:02AERDL.DLL : 8.1.1.3 438645 Bytes 2008-11-6 01:13:46AEPACK.DLL : 8.1.3.5 393588 Bytes 2009-1-8 22:10:30AEOFFICE.DLL : 8.1.0.33 196987 Bytes 2008-12-12 01:14:30AEHEUR.DLL : 8.1.0.89 1569143 Bytes 2009-1-30 23:29:00AEHELP.DLL : 8.1.2.0 119159 Bytes 2008-11-18 02:36:52AEGEN.DLL : 8.1.1.12 328053 Bytes 2009-1-30 23:28:52AEEMU.DLL : 8.1.0.9 393588 Bytes 2008-10-14 17:05:58AECORE.DLL : 8.1.6.3 176501 Bytes 2009-1-30 23:28:48AEBB.DLL : 8.1.0.3 53618 Bytes 2008-10-14 17:05:58AVWINLL.DLL : 1.0.0.12 15105 Bytes 2008-7-9 15:40:06AVPREF.DLL : 8.0.2.0 38657 Bytes 2008-5-16 16:28:02AVREP.DLL : 8.0.0.2 98344 Bytes 2008-11-6 01:13:26AVREG.DLL : 8.0.0.1 33537 Bytes 2008-5-9 18:26:42AVARKT.DLL : 1.0.0.23 307457 Bytes 2008-2-12 15:29:24AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 2008-6-12 19:27:50SQLITE3.DLL : 3.3.17.1 339968 Bytes 2008-1-23 00:28:04SMTPLIB.DLL : 1.2.0.23 28929 Bytes 2008-6-12 19:49:42NETNT.DLL : 8.0.0.1 7937 Bytes 2008-1-25 19:05:12RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 2008-6-12 20:48:08RCTEXT.DLL : 8.0.52.0 86273 Bytes 2008-6-27 20:34:38Configuration settings for the scan:Jobname..........................: Complete system scanConfiguration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avpLogging..........................: lowPrimary action...................: interactiveSecondary action.................: ignoreScan master boot sector..........: onScan boot sector.................: onBoot sectors.....................: C:, D:, E:, F:, Process scan.....................: onScan registry....................: onSearch for rootkits..............: offScan all files...................: All filesScan archives....................: onRecursion depth..................: 20Smart extensions.................: onMacro heuristic..................: onFile heuristic...................: mediumStart of the scan: 2009年2月1日 19:17The scan of running processes will be startedScan process 'avscan.exe' - '1' Module(s) have been scannedScan process 'avcenter.exe' - '1' Module(s) have been scannedScan process 'firefox.exe' - '1' Module(s) have been scannedScan process 'aolsoftware.exe' - '1' Module(s) have been scannedScan process 'aim6.exe' - '1' Module(s) have been scannedScan process 'npkcmsvc.exe' - '1' Module(s) have been scannedScan process 'wuauclt.exe' - '1' Module(s) have been scannedScan process 'ctfmon.exe' - '1' Module(s) have been scannedScan process 'schedhlp.exe' - '1' Module(s) have been scannedScan process 'TimounterMonitor.exe' - '1' Module(s) have been scannedScan process 'TrueImageMonitor.exe' - '1' Module(s) have been scannedScan process 'jusched.exe' - '1' Module(s) have been scannedScan process 'avgnt.exe' - '1' Module(s) have been scannedScan process 'avgtray.exe' - '1' Module(s) have been scannedScan process 'Mixer.exe' - '1' Module(s) have been scannedScan process 'VPTray.exe' - '1' Module(s) have been scannedScan process 'ccApp.exe' - '1' Module(s) have been scannedScan process 'alg.exe' - '1' Module(s) have been scannedScan process 'avgcsrvx.exe' - '1' Module(s) have been scannedScan process 'avgemc.exe' - '1' Module(s) have been scannedScan process 'ViewpointService.exe' - '1' Module(s) have been scannedScan process 'TrueImageTryStartService.exe' - '1' Module(s) have been scannedScan process 'Rtvscan.exe' - '1' Module(s) have been scannedScan process 'SVCHOST.EXE' - '1' Module(s) have been scannedScan process 'oacat.exe' - '1' Module(s) have been scannedScan process 'avgnsx.exe' - '1' Module(s) have been scannedScan process 'avgrsx.exe' - '1' Module(s) have been scannedScan process 'jqs.exe' - '1' Module(s) have been scannedScan process 'DefWatch.exe' - '1' Module(s) have been scannedScan process 'avgwdsvc.exe' - '1' Module(s) have been scannedScan process 'avguard.exe' - '1' Module(s) have been scannedScan process 'schedul2.exe' - '1' Module(s) have been scannedScan process 'sched.exe' - '1' Module(s) have been scannedScan process 'spoolsv.exe' - '1' Module(s) have been scannedScan process 'EXPLORER.EXE' - '1' Module(s) have been scannedScan process 'ccEvtMgr.exe' - '1' Module(s) have been scannedScan process 'ccSetMgr.exe' - '1' Module(s) have been scannedScan process 'SVCHOST.EXE' - '1' Module(s) have been scannedScan process 'SVCHOST.EXE' - '1' Module(s) have been scannedScan process 'SVCHOST.EXE' - '1' Module(s) have been scannedScan process 'SVCHOST.EXE' - '1' Module(s) have been scannedScan process 'SVCHOST.EXE' - '1' Module(s) have been scannedScan process 'LSASS.EXE' - '1' Module(s) have been scannedScan process 'SERVICES.EXE' - '1' Module(s) have been scannedScan process 'winlogon.exe' - '1' Module(s) have been scannedScan process 'csrss.exe' - '1' Module(s) have been scannedScan process 'smss.exe' - '1' Module(s) have been scanned47 processes with 47 modules were scannedStarting master boot sector scan:Master boot sector HD0 [iNFO] No virus was found!Start scanning boot sectors:Boot sector 'C:\' [iNFO] No virus was found!Boot sector 'D:\' [iNFO] No virus was found!Boot sector 'E:\' [iNFO] No virus was found!Boot sector 'F:\' [iNFO] No virus was found!Starting to scan the registry.The registry was scanned ( '62' files ).Starting the file scan:Begin scan in 'C:\' <WINXP>C:\pagefile.sys [WARNING] The file could not be opened!C:\hiberfil.sys [WARNING] The file could not be opened!C:\Documents and Settings\Administrator\Local Settings\Temp\WinterStory.zip [0] Archive type: ZIP --> StartGame.exe [DETECTION] Is the TR/Spy.Gen Trojan [NOTE] The file was moved to '49f43ef1.qua'!C:\Documents and Settings\Administrator\Local Settings\Temp\WinterStory-1.zip [0] Archive type: ZIP --> WinterStory/WinterStory.exe [DETECTION] Is the TR/Spy.Gen Trojan [NOTE] The file was moved to '49f43ef6.qua'!C:\System Volume Information\_restore{D2165923-2631-4BC2-BCAA-B324ACFC75BD}\RP9\A0002278.exe [DETECTION] Is the TR/Spy.Gen Trojan [NOTE] The file was moved to '49b64186.qua'!C:\System Volume Information\_restore{D2165923-2631-4BC2-BCAA-B324ACFC75BD}\RP16\A0033099.exe [DETECTION] Is the TR/Spy.Gen Trojan [NOTE] The file was moved to '49b64212.qua'!C:\System Volume Information\_restore{D2165923-2631-4BC2-BCAA-B324ACFC75BD}\RP16\A0033130.exe [DETECTION] Is the TR/Spy.Gen Trojan [NOTE] The file was moved to '49b6422c.qua'!C:\System Volume Information\_restore{D2165923-2631-4BC2-BCAA-B324ACFC75BD}\RP16\A0033141.exe [DETECTION] Is the TR/Spy.Gen Trojan [NOTE] The file was moved to '49b64232.qua'!C:\System Volume Information\_restore{D2165923-2631-4BC2-BCAA-B324ACFC75BD}\RP16\A0033142.exe [DETECTION] Is the TR/Spy.Gen Trojan [NOTE] The file was moved to '49b64241.qua'!C:\System Volume Information\_restore{D2165923-2631-4BC2-BCAA-B324ACFC75BD}\RP16\A0033146.exe [DETECTION] Is the TR/Spy.Gen Trojan [NOTE] The file was moved to '49b64246.qua'!Begin scan in 'D:\'Begin scan in 'E:\'Begin scan in 'F:\'End of the scan: 2009年2月1日 19:50Used time: 33:08 Minute(s)The scan has been done completely. 3182 Scanning directories 102562 Files were scanned 8 viruses and/or unwanted programs were found 0 Files were classified as suspicious: 0 files were deleted 0 files were repaired 8 files were moved to quarantine 0 files were renamed 2 Files cannot be scanned 102552 Files not concerned 460 Archives were scanned 2 Warnings 8 Notes Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 3, 2009 Root Admin ID:53000 Share Posted February 3, 2009 Please visit this webpage for instructions for downloading ComboFix to your DESKTOP : how-to-use-combofixPlease ensure you read this guide carefully and install the Recovery Console first.NOTE!!: You must save and run ComboFix.exe on your DESKTOP and not from any other folder.Also, DO NOT click the mouse or launch any other applications while this is running or it may stall the programAdditional links to download the tool:ComboFix.exeComboFix.exeComboFix.exeNote: The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.Once installed, you should see a blue screen prompt that says:The Recovery Console was successfully installed.Please continue as follows:Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.Click Yes to allow ComboFix to continue scanning for malware.When the tool is finished, it will produce a report for you.Please post the C:\ComboFix.txt along with a new HijackThis log so we may continue cleaning the system. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 4, 2009 Root Admin ID:53361 Share Posted February 4, 2009 Please post a status update on this. Link to post Share on other sites More sharing options...
Cutolo Posted February 4, 2009 Author ID:53533 Share Posted February 4, 2009 I downloaded ComboFix and did everything, until it began scanning. The computer restarted and ComboFix closed. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 5, 2009 Root Admin ID:53624 Share Posted February 5, 2009 Please delete your current version and remove this folder if it exists C:\QooBox\LastRunThen download a NEW fresh copy and try running it again.Additional links to download the tool:ComboFix.exeComboFix.exeComboFix.exe Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 11, 2009 Root Admin ID:55513 Share Posted February 11, 2009 Due to the lack of feedback this Topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Thanks!The fixes and advice in this thread are for this machine only. Do not apply the instructions from this thread to your own machine. Please start a new thread describing your issue and someone will be along to assist you. Link to post Share on other sites More sharing options...
Recommended Posts