Help with a MGlog please

Discussion in 'Malware Help (A Specialist Will Reply)' started by Edgehead, Sep 23, 2011.

  1. Edgehead

    Edgehead Private E-2

    so, this morning i started mozilla like always, and from google it redirected to something called corkingsearchsystem.com
    i tried to investigate what the problem was, apparently it's a google redirecting malware problem, i tried to do some scans with hijackthis, malware bites, rootrepeal, superantispyware, etc like u advised here on the forums, but none of the scans completes succesfully. the only one that did was MGlogs, so i hope that u can point me in the right direction with the log that i'll send
    thanks
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you also run Malware Bytes and SUPERantispyware?? What about Rootrepeal and Combofix? You need to have run all those, attach logs for them please. Then also do this:

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. Edgehead

    Edgehead Private E-2

    yes, malware bytes, super anti spyware, rootrepeal and combofix, i tried them all as said in the forum, but none of them worked, they would close in the middle of the scan.
    the only one that worked was mgtools and mbrcheck also worked, i forgot about that sorry.. i'll send the log from mbrcheck
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have a ZeroAccess infection. I will return after work with a suitable fix. :)
     
  5. Edgehead

    Edgehead Private E-2

    thank u :)
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    WinPcap 4.1.1 <--- Uninstall this unless you deliberately installed it yourself.


    What's inside of this folder?

    C:\windows\system32\Service


    Download and run Win32kDiag per the below instructions:
    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log
    C:\win32kdiag.exe -f -r


    Now we need to scan the system with this special tool.
    • Please download Junction.zip and save it to your root folder (C:\Junction.zip)
    • Unzip it and put junction.exe in the root folder (C:\junction.exe)
    • Now click Start => Run... => Copy and paste the following command in the run box and click OK:
      cmd /c junction -s c:\ >C:\log.txt
    • A command prompt window opens and also a license agreement from SysInternals will appear.
    • Accept the license agreement and the scan will begin.
    • Wait until a log file opens. Attach this C:\log.txt when it finishes (the command prompt window will close when it finishes). (How to attach items to your post)
    • NOTE: It scans your whole hard disk so if can take a long time. Be patient and don't do anything else while it is scanning.


    And one more scanning tool I want to use to collect more information is OTL per the below.

    Please download OTL by Old Timer to your desktop.
    See the download links under this icon: http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    1. Double-click OTL.exe to run (Vista and Win7 right click and select Run as Administrator)
    2. When OTL opens, change the Output (at the top-right portion of the program) to Minimal Output.
    3. Put check-marks in LOP Check and Purity Check.
    4. Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • When the scan is complete, two logs entitled OTL.txt and Extras.txt will be created on your desktop.
    • Attach both of these logs to your next message as well as any other requested logs.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "{629E2511-F293-D3B0-A1B5-5F077F0E9A6D}"=-
    "NetLog2"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "ApnUpdater"=-
    
    :files
    C:\Windows\svc2.exe
    C:\windows\system32\REN4834.tmp
    C:\windows\system32\REN4835.tmp
    C:\windows\system32\RENEB96.tmp
    C:\windows\system32\RENEB97.tmp
    C:\windows\system32\RENEB98.tmp
    C:\Windows\3269553366
    C:\Windows\assembly\GAC_MSIL\Desktop.ini
    C:\Users\Edge\AppData\Roaming\Vees
    C:\Program Files\Ask.com
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Please try and see if Combofix runs at this point.


    Run TDSSKiller again and attach its log please.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  7. Edgehead

    Edgehead Private E-2

    inside of C:\windows\system32\Service there's one notebook file named 23092011_TIS17_SfFniAU.log

    the win32kdiag test did not conclude i think, but it still generated one log file which i'll send
    as for the junction one the prompt window opened, but imediatly closed.
    with otl the scan stopped halfway.
    otm worked, combofix didn't.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    See this:

    I want you to get rid of that with TDSSKiller, not skip it. Are you able to run TDSSKiller and cure or delete it instead of skip? Let me know.

    You forgot to attach the OTL log. You attached an OTM log.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Give win32diag another run please and attach the log.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
    Last edited: Sep 24, 2011
  9. Edgehead

    Edgehead Private E-2

    Running TDSSkiller i deleted the infected file, rebooted, and then scanned again, but the file was still there.
    I didn't post any OTL log because the scan didn't finish, it didn't produced any logs.

    Tried the avenger, all went well, but the 3269553366.exe file is still running on the task manager processes and still on the windows folder

    Win32diag didn't work again
     

    Attached Files:

    Last edited: Sep 24, 2011
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run Win32diag again and attach the log.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Run TDSSKiller again and attach it's log.


    • Please download a ZeroAccess Removal Tool (By Webroot)to your desktop.
    • Double click on it to run it (If running Vista or Windows 7, right click on it and select "Run as an Administrator")
    • Type y and press enter to run the scan .
    • Hit any key to exit once it has finished it's scan.
    • Attach the log which will be in the same location as you ran the tool from. (Should be desktop)

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK. What about Combofix, after following all those instructions please see if it will run now. If it does attach a log.
     
  12. Edgehead

    Edgehead Private E-2

    Win32diag continues to do the same thing.. an error appears and it closes.
    MGtools is still scanning, i'll post the results as soon as it finishes as i exceed the maximum attachments per post in this one.
     

    Attached Files:

  13. Edgehead

    Edgehead Private E-2

    Here's the MGlog

    As for combofix i think it's working now, what should i do?
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run it as per the instructions and attach the log it produces.
     
  15. Edgehead

    Edgehead Private E-2

    finally the scan from combofix is finished, here's the log

    i tested to see if it solved anything and i'm not being redirected anymore from the google results and the 3269553366.exe file is gone
     

    Attached Files:

    • log.txt
      File size:
      113.5 KB
      Views:
      4
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. :) I had a busy night at work last night and also there have been background discussions taking place between myself. Now, I have a fix prepared for you.

    I would like for you to disconnect from the internet whilst carrying out the below instructions! I think the back of it has now been broken so some of this fix is just for redundancy.

    These programs have become compromised and even if they hadn't/haven't they could get in the way of the fix so if you are able to, please uninstall them now before we continue.

    • Advanced WindowsCare Personal
    • Microsoft Security Essentials
    • Spyware Doctor 8.0
    • Trend Micro Internet Security
    • Messenger Plus! Live
    • SUPERAntiSpyware
    • Apple Mobile Device Support
    • Bonjour
    • iTunes

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    ADS::
    C:\Windows\3269553366
    Driver::
    ntiomin
    zyslwnu
    File:: 
    C:\Windows\3269553366
    c:\windows\system32\drivers\zyslwnur.sys
    C:\Windows\assembly\GAC_MSIL\Desktop.ini
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    • Please now run TDSSKiller again and attach the log.
    • Now re run Win32Diag again and attach it's log.
    • Try and see if OTL will now run too. Attach the log if it does.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!

    I will return later on tonight, I have a busy day again, I only logged in to get this fix done for you.
     
  17. Edgehead

    Edgehead Private E-2

    Hey :) take your time, i'm the one who should be thanking for every minute you spend to help me, i appreciate it.

    Last night after the combofix scan, and as i saw that i wasn't being redirected anymore i installed one firewall.. just in case. i installed the comodo firewall.. i hope i did no wrong. i closed it as u said beofore doing the scans u told me to do.

    i was able do uninstall some of the programs u told me, but i wasn't able do find some others like messenger plus live for example.

    tdsskiler found no threats this time, but win32diag still doesn't work.
    OTL did work this time.

    Have a nice day.
     

    Attached Files:

  18. Edgehead

    Edgehead Private E-2

    And there's the MGlog
     

    Attached Files:

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, you should not have done this. As I said, protection software might only hinder us or become infected at this point. Best to refrain from making any system changes other than those directed by us until you are clean. :)

    We are almost done, but there was a typo in part of my last fix so one file and service remains as well as some other crap which we will deal with right now:

    Please uninstall the below using Revo if possible.

    • Advanced WindowsCare Personal
    • Microsoft Security Essentials
    • Spyware Doctor 8.0
    • Trend Micro Internet Security
    • Messenger Plus! Live
    • SUPERAntiSpyware
    • Apple Mobile Device Support
    • Bonjour
    • iTunes

    Try Revo Uninstaller.
    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.



    We need to run an OTL Fix

    • Right-click OTL.exe And select " Run as administrator " to run it. If Windows UAC prompts you, please allow it.
    • Copy and Paste the following code into the textbox. Do not include the word Code
    Code:
    Code:
    :otl
    @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:60C897F3
    @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DFC5A2B2 
    
    :commands
    [EMPTYTEMP]
    
    • Then click the Run Fix button at the top.
    • Click Image.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. ATTACH that report in your next reply.


    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    c:\users\Edge\AppData\Local\NPE
    Driver::
    zyslwnur
    File::
    c:\windows\system32\drivers\zyslwnur.sys
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Please navigate now to C:\MGTools\analyse.exe double click to run it (Or right click and run as admin if using vista/Win 7) Agree to the trend micro license agreement, you may have to click YES twice.

    Do a system scan only and save a log file for my reviewal.

    Does Win32diag now run or not?

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    How are things running?
     
  20. Edgehead

    Edgehead Private E-2

    Sorry but i didn't understood that part.. i downloaded revo unistaller, have it opened but i don't see what option you want me to choose
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Choose the uninstaller option, then the advanced option (fourth in list)
     
  22. Edgehead

    Edgehead Private E-2

    I don't have any options below the "uninstaller" button. I took a printscreen for u to see
     

    Attached Files:

  23. Edgehead

    Edgehead Private E-2

    Analyse.exe from MGTools gave an error, it said i cannot access it because i may not have the right privileges.
    Win32diag still doesn't run.
    The other things u told me to do went fine, and there's the logs in attachment.
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You missed out this part:
    I also included screenshots of what you should be doing with REVO.

    Choose this option...
    uninstaller.png
    Then once you click that you will be given these choices, choose the 4th one.
    advanced option.png
     
  25. Edgehead

    Edgehead Private E-2

    I didn't miss out on that part, as i said Analyse.exe from MGTools gave an error, it said i cannot access it because i may not have the right privileges. Even after reboot it gave the same error.

    I noticed that i have some files under some folders that are nameless, and when i try to delete them they simply won't let me.

    As for Revo Uninstaller, it found 78 programs for me to uninstall, but there aren't any of those that u told me to uninstall.
     

    Attached Files:

  26. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahhh! Ok! Looking good, those programs are gone. :) I would feel more confident if you would uninstall this though and install a fresh copy afterwards. I just think it is possible that it could have been affected by the ZA infection.
    • COMODO Internet Security

    Now, from looking at one of your logs it would appear you have a proxy set up. So, if you do not deliberately have a proxy set up then please follow these instructions:

    Proxy Server - Changing Settings


    Then I am discussing in the background just one or two other items that I would like some advice on, again about programs that are installed which could be affected.

    Thanks for your patience, I know this has been long and drawn out, but I won't let a thread go until I know the machine is spotless.
     
  27. Edgehead

    Edgehead Private E-2

    I have now uninstalled the Comodo firewall, as for the proxy it was set up by me some time ago, but even so i removed it now. :)
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK Edgehead, it seems as if the battle is over. :) But if you don't mind waiting a little while we will see what my colleagues say about the remaining questions that I have.
     
  29. Edgehead

    Edgehead Private E-2

    Yeah, no problem, i'll wait :) Thank u
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Reinstall Anti-virus in the mean time!! :) (Only use ONE antivirus)
     
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      mscorsvw.exe
      nvvsvc.exe
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  32. Edgehead

    Edgehead Private E-2

    There's the systemlook log
     

    Attached Files:

  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to virustotal and upload the following files for analysis, and let me know the results.

    C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    In fact, also do this please.

    Could you please get this: mscorsvw.exe into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:
    log retrievable @ C:\collect.zip
     
  35. Edgehead

    Edgehead Private E-2

    Attached Files:

  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looks good to me. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  37. Edgehead

    Edgehead Private E-2

    ok, it's all done! :)
     
  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad to hear it. :) Surf safely.
     
  39. Edgehead

    Edgehead Private E-2

    I'll try ;) Thank u very much, u were awesome.
     
  40. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are *most* welcome. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds