Help needed.

Discussion in 'Malware Help (A Specialist Will Reply)' started by yorks, Nov 19, 2005.

  1. yorks

    yorks Private E-2

    Hi,

    I have followed the initial instructions on the 'read this first' but am still getting annoying pop-ups.

    Problem started with Powerscan trying to install. (Blocked by Microsoft AntiSpyware).

    Spybot/Microsoft AntiSpyware both find registry entries for 'Yoursearch.bar or IsearchTech.YSB - but fail to remove it, and i am unable to delete it manually using 'regedit'.

    I have looked on Processlibrary.com to try and identify rogue processes, but have come to the conclusion that i need an expert's help.

    • Edit by bjgarrick: Unrequested, Inline HJT log removed!
    Regards,

    Yorks.
     
    Last edited by a moderator: Nov 19, 2005
  2. yorks

    yorks Private E-2

    Please help. :)
     
  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  4. yorks

    yorks Private E-2

    Thanks for the reply.

    I'll try again :)

    Regards,

    Yorks.
     

    Attached Files:

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download this trial version of Ewido Security Suite


    • Install ewido security suite
    • Launch ewido, there should be an icon on your desktop double-click it.
    • The program will have a window come up. One of the buttons on the left is to Update. Click the Update button.and then Start the Update. The update will start and a progress bar will show the updates being installed.
    • After it completes the update, click the Scanner button

    Now exit Ewido. Now print the below instructions or save them locally because I want you do have no browsers opened and also have no connection to the internet (unplug your cable) while doing the below.

    Okay, reboot into safe mode and follow the steps below. (If you have any problems at all trying to get into safe mode to complete these steps, just run them in normal boot mode and make sure you tell me when you come back.)

    Open up Ewido and do the following:



    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.

    Once the scan has completed, there will be a button located on the bottom of the screen named Save report



    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    Reboot into normal mode and reconnect to the internet.

    Come back here and post the Ewido Scan Report along with a fresh HJT log.
     
  6. yorks

    yorks Private E-2

    Thanks SPD,

    Here are my latest results.

    Regards,

    Yorks. :)
     

    Attached Files:

  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Ewido foun and got rid of YourSiteBar. Your HijackThis log isn't showing much.

    Please download Spy Sweeper


    • Click the link above to download the program.
    • Install it. Once the program is installed, it will open.
    • It will prompt you to update to the latest definitions, click Yes.
    • Once the definitions are installed, click Options on the left side.
    • Click the Sweep Options tab.
    • Under What to Sweep please put a check next to the following:
      • Sweep Memory
      • Sweep Registry
      • Sweep Cookies
      • Sweep All User Accounts
      • Enable Direct Disk Sweeping
      • Sweep Contents of Compressed Files
      • Sweep for Rootkits
      • Please UNCHECK Do not Sweep System Restore Folder.
    • Click Sweep Now on the left side.
    • Click the Start button.
    • When it's done scanning, click the Next button.
    • Make sure everything has a check next to it, then click the Next button.
    • It will remove all of the items found.
    • Click Session Log in the upper right corner, copy everything in that window.
    • Click the Summary tab and click Finish.
    • Paste the contents of the session log you copied into notepad and save it as spysweeper.txt and attach it to your next post.
     
  8. yorks

    yorks Private E-2

    Thanks SPD,

    Have run SpySweeper. (Normal mode).

    After running, program reported 'internet explorer hijack'.

    Gave me instructions to 'Reset IE Page Settings to defaults' if i experienced any problems.

    I have ignored this as both IE and Firefox are behaving normally - barring for popups! lol.

    Here is the requested log.

    Popups still present. :(

    Regards,

    Yorks :)
     

    Attached Files:

  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Spy Sweeper found a few more things and removed those.

    Since you are still getting pop-ups.

    Please run Panda Online Scan. After the scan attach the log to your next post. Also please follow the below:

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder named C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.

    Now come back here and post all three logs as attachments
     
  10. yorks

    yorks Private E-2

    Thanks SPD,

    Please see attachments as requested.

    Regards,

    Yorks. :)
     

    Attached Files:

  11. yorks

    yorks Private E-2

    And the third one. :)

    Popups remain :(

    Regards,

    Yorks
     

    Attached Files:

  12. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Download WinPFind

    Extract it to the root folder of drive C ( C:\ ). This will create a folder called WinPFind in the C:\ folder. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.

    When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard. Then save it to a file using notepad and upload the text file here as an attachment.

     
  13. yorks

    yorks Private E-2

    Thanks SPD.

    Killbox did not give any prompts when pasting files and clicking X. I unzipped and repeated process several times.

    The only thing found in safe mode was 'totem shared', which i deleted.

    I have noticed a folder on root called '!Killbox'

    The folder contains all the files which i chose to delete at reboot, and a log file showing my numerous executions of the program :rolleyes:
    Should i delete this folder and it's contents?:confused:

    I have also noticed that since running SpySweeper that my computer is running slower,for instance when i click on 'my computer' or when using right click menus, and when i browse folders to upload logs.

    'My computer' takes about 25 seconds to diplay contents as opposed to the usual half a second.

    Regards,

    Yorks. :)
     

    Attached Files:

  14. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You can delete everything in the !Killbox folder.

    Boot to Safe Mode and delete the following files:
    Reboot to Normal Mode. Post a fresh HijackThis log.

    How is your computer running?
     
  15. yorks

    yorks Private E-2

    Thanks SPD,

    Have deleted the three .ini files from system32.

    Popups still remain. (Cassava - 888.com one of the frequent ones)

    PC still running slow when accessing 'my computer' via desktop icon or explore option. Not a deal of hard drive activity while waiting for it to load.

    Other folders open normally - ie. c: but if i hit the back button then the torch appears again and it takes a further 25 seconds to re-display contents of 'my computer'

    Although the symptoms appeared after running SpySweeper, unistalling it has made no difference.

    Microsoft Word docs open at normal speed.

    I have attached lateast hjt log as requested.

    Regards,

    Yorks :)
     

    Attached Files:

  16. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Have HijackThis fix the following:
    Do a full system scan with Microsoft Antispyware, update teh definitions before running the scan and post the results of the scan.
     
  17. yorks

    yorks Private E-2

    Thanks SPD,

    Microsoft Antispyware drew a blank :confused:

    Regards,

    Yorks :)
     

    Attached Files:

  18. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your logs are not showing those pop ups.

    I would like for you to start over at the beginning with our READ ME First, but this time run the BitDefender and Kaspersky on-line scanners.

    Please make sure System Restore is OFF.

    How to view hidden, system files & folders!

    Searching for Hidden Files on WinXP


    Before running Spybot make sure you have done the following:
     
  19. yorks

    yorks Private E-2

    I have started from the beginning again and have used all 5 online scanners and then followed the instructions (in safe mode) upto and including Microsoft AntiSpyware.

    I have attached my latest HJT log along with 2 other logs. The Panda log shows:

    Adware:adware/savenow which i don't think has been removed.

    Kaspersky log shows quarantined items.

    Popups still present. Pc still slow when browsing ' My computer ' since running SpySweeper earlier.

    Regards,

    Yorks
     

    Attached Files:

  20. yorks

    yorks Private E-2

    And the last one :)
     

    Attached Files:

  21. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Sacn with HijackThis and fix the following:
    Without PandaScan giving a registry key for adware/savenow I have know idea what needs to be changed.

    Your Norton installation appears to be broken, uninstall and reinstall Norton.
     
  22. yorks

    yorks Private E-2

    Thanks SPD,
    I have had HJT fix your recommendations and exploring ' My Computer ' is back to normal speed. :)

    Found removal instructions for adware.savenow on symantec.

    Followed them but found none of the indicated references in registry or folders, described in this article to remove. Perhaps one of the subsequent scans removed it. :confused:

    Unfortunately Popups still remain. They are obviously monitoring the pages that I am browsing, as the popups pertain to the sites I am viewing

    i.e Holiday adverts if visiting Travel Page. Sports Betting when visiting Official soccer sites.

    I have attached my latest HJT log.

    Regards,

    Yorks. :)
     

    Attached Files:

  23. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Run Ewido Security Suite again and post that log.
     
  24. yorks

    yorks Private E-2

    Thanks SPD,

    Here is the requested log.

    Popups still present.

    Regards,

    Yorks. :)
     

    Attached Files:

  25. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Make sure you empty your Norton Protected Recycle bin.

    Ewido did find a few things, and removed them.

    We are going to run some more of the scans we did earlier.

    Run Spy Sweeper again and post that log.
     
  26. yorks

    yorks Private E-2

    Thanks SPD,

    Have updated and run SpySweeper with options enabled as shown earlier.

    Popups still present. i.e 888.com

    PC speed unaffected :)

    Here is the log.

    Regards,

    Yorks

    PS. Ran in normal mode as there was no mention of running in safe mode.
     

    Attached Files:

  27. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Something is preventing Spy Sweeper from reading the registry. Exit MS Anti-Spyware and anything else that you may have that prevents the registry from being read and modified. Then run Spy Sweeper again and post the log.
     
  28. yorks

    yorks Private E-2

    Thanks SPD,

    I disabled Microsoft AntiSpyware and Norton Antivirus and re-ran the scan.

    There still seem to be a lot of 'access denied' areas. Shuold I try scan in safe mode?

    Regards,

    Yorks. :)
     

    Attached Files:

  29. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Have you ever installed CasinoOnNet? If so, uninstall it.

    Yes you can try the scan in safe mode.
     
  30. yorks

    yorks Private E-2

    Thanks SPD,

    No. I have never installed CasinoOnNet. There is nothing sinister on ' add or remove progams' list that I can see.

    I will run Spy Sweeper in safe mode and get back to you.

    This is proving to be rather a persistent little barsteward.

    Regards,

    Yorks:)
     
  31. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Do you have this directory [font=Arial, Helvetica, sans-serif]c:\program files\casinoonnet[/font][font=Arial, Helvetica, sans-serif] on your Hard Drive?
    [/font]
     
  32. yorks

    yorks Private E-2

    Thanks SPD,

    Searched my Hard Drive for 'casino' (including hidden files and folders).

    The only thing it found was 'www.casino.co.uk' in my 'today' internet history folder, which i had just been hit with whilst reading your reply.

    I have run Spy Sweeper in safe mode.

    Found a couple of the usual spy cookies and:-

    Adware Found : apropos .

    I have attached Spy Sweeper log and HJT log.

    Regards,

    Yorks :)
     

    Attached Files:

  33. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download FixAprop to your Desktop.

    Reboot to Safe Mode.

    Run FixAprop.

    Reboot to Safe Mode.

    Run Microsoft AntiSpyware and let it fix what it finds.

    Reboot to Normal Mode.

    This should remove Apropos.

    Something is preventing Spy Sweeper from reading your registry and other system files.

    Run REGEDIT and look for and remove the following Registry entries: (These are associated with CasinoOnNet, 888.com)
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\VHLD[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\VHLD[/font]
    [font=Arial, Helvetica, sans-serif] "DEMOID"="50231567"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\VHLD[/font]
    [font=Arial, Helvetica, sans-serif] "C_LANG"="0"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\VHLD\MACHINE_ID[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\INIT[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\INIT[/font]
    [font=Arial, Helvetica, sans-serif] "MULTI_HAND"="1"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\INIT[/font]
    [font=Arial, Helvetica, sans-serif] "REPORT"="1;0;0;5;"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\INIT[/font]
    [font=Arial, Helvetica, sans-serif] "REPORT_NUM"="1"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\INIT[/font]
    [font=Arial, Helvetica, sans-serif] "COOKIE_ID"="0"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\INIT[/font]
    [font=Arial, Helvetica, sans-serif] "DEMO_PASSWORD"="yhbqd85"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\INIT[/font]
    [font=Arial, Helvetica, sans-serif] "DEMO_USERNAME"="e4qu84v"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\INIT[/font]
    [font=Arial, Helvetica, sans-serif] "P1"="195.244.211.244:8500^"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\INIT[/font]
    [font=Arial, Helvetica, sans-serif] "MEDIAPATH"="C:\PROGRA~1\CASINO~1\"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\INIT[/font]
    [font=Arial, Helvetica, sans-serif] "MAIL_VER"="1"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\INIT[/font]
    [font=Arial, Helvetica, sans-serif] "IP"="realgwa.casino-on-net.com"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\INIT[/font]
    [font=Arial, Helvetica, sans-serif] "IP1"="demogwa.casino-on-net.com"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\SETTINGS[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\SDL[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\SDL[/font]
    [font=Arial, Helvetica, sans-serif] "Upd_Flag"="0"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\SDL[/font]
    [font=Arial, Helvetica, sans-serif] "Upg_Date"="05/09/07"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\SDL[/font]
    [font=Arial, Helvetica, sans-serif] "Upd_Ver"=""[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\SDL[/font]
    [font=Arial, Helvetica, sans-serif] "S_IP"="195.244.211.225"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_CURRENT_USER\Software\casinoonnet\casino\SDL[/font]
    [font=Arial, Helvetica, sans-serif] "Curr_Ver"="(hex data)"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\[/font][font=Arial, Helvetica, sans-serif]CurrentVersion\Uninstall\Casino-on-Net[/font]
    [font=Arial, Helvetica, sans-serif] "UninstallString"="(hex data)"[/font]
    [font=Arial, Helvetica, sans-serif] [/font]
    • [font=Arial, Helvetica, sans-serif]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\[/font]CurrentVersion\Uninstall\Casino-on-Net
    [font=Arial, Helvetica, sans-serif] "DisplayName"="Casino-on-Net"
    [/font]​
    [font=Arial, Helvetica, sans-serif]
    [/font]​
     
  34. yorks

    yorks Private E-2

    Thanks SPD,

    I have been browsing for several hours since my last post without receiving any popups.

    Spy Sweeper in safe mode may have sorted it. :) It is the only thing that i have done.

    I will however follow the steps that you have indicated, in case there is anything else hiding and let you know the results.

    The only site where i have received popups today was:-

    h**p://www.cdrlabs.com/reviews/index.php?reviewid=270&page=Conclusion

    which until today i haven't visited for several months - but i think these may be part of their website! They are not like the popups i have been receiving recently.

    Regards,

    Yorks. :)
     
  35. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Those are from fastclick; which is a legitimate ad server used by servel web sites to display ads and generate revenue for the site.

    May I suggest trying Firefox and using the Fasterfox extension. I rarely get popups with that combination.
     
  36. yorks

    yorks Private E-2

    Thanks SPD,

    Have run all programs. Fixaprop.exe found file. (see attached log).

    Microsoft AntiSpyware found nothing.

    None of the listed entries were present in the Windows registry.

    Although Casino.net/888.com were the most persistent of the popups, i was also getting bombarded with others, ie. O2 (ruputable british mobile phone compamy) amongst others.

    As all popups have now ceased, I can only think that apropos was the culprit, and possibly the progam also responsible for trying to install Power Scan

    I have installed the fasterfox extension which you recommended (thanks) - I use firefox normally (internet explorer as a last resort). Should i see any difference on the browser or is it in the background? When i view 'extensions' it shows that it is installed - but is there anything to configure?

    If I uninstall Spy Sweeper will I be able to install it if I need it at a later date (after the 14 day trial period has expired), or is there a way to fully unistall it?;)

    I have also attached my latest HJT log.

    PS. Have just noticed my new little friend @ the bottom right. :) (page load timer), and found settings on Options menu.

    Regards,

    Yorks :)
     

    Attached Files:

  37. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your system now appears to be clean. Safe Surfing.

    You can uninstall Spy Sweeper using it's own installer. That should fully remove Spy Sweeper from your system.
     
  38. yorks

    yorks Private E-2

    Thanks for all your help SPD. :)

    Regards,

    Yorks. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds