1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Backdoor Sdbot has taken over my computer

Discussion in 'Virus & Other Malware Removal' started by cesarcarlos, Apr 4, 2004.

Thread Status:
Not open for further replies.
Advertisement
  1. cesarcarlos

    cesarcarlos Thread Starter

    Joined:
    Jan 11, 2004
    Messages:
    44
    Hello,

    I am having so much trouble with my computer, I hope you can help me.

    I am running Windows 2000 Professional and McAfee VirusScan Online.

    About two weeks ago strange things began happening. Whenever I would switch my computer on everything would start fine until the point where I was asked for my user and psw. I would write them, click OK, then I would see my wallpaper image and then nothing. No Taskbar, no Icons on the desktop, no start menu, nothing. I could use the computer in restore mode where the antivirus would repeatedly detect files in C:/WINNT infected wit W32/Sdbot.worm.gen or W32/Gaobot or variations of these viruses.

    I had my disk formatted and Windows reinstalled. I got the computer back yesterday. I started installing my software and suddenly McAfee VirusScan Online started detecting files infected in WINNT, like every 5 mins. Examples are:

    C:\msword.dat
    W32/Sdbot.worm.gen

    C:\WINNT\system32\msword.exe (this one like 3 times)
    W32/Sdbot.worm.gen

    C:\msconfig.dat
    W32/Sdbot.worm.gen

    More weird, I left for a while and when I came back I found a couple of pop ups with some porn advertising. Not web ads, but system alerts. (gray boxes with text)

    I tried running Stinger but that found nothing.

    I went online to Trend Micro and used their online virus Scan. It found out that my Mouse Driver had within it's files this:

    BKDR_SDBOT.GEN

    I deleted the infected virus Trend Micro found. Looks like the pop up thing got fixed.

    Apparently when I installed the mouse software the computer got infected.

    I also found NewsUpd running in my computer. I used Spybot S&D to get rid of it and other spyware.

    LAst night my Antivirus (McAfee VirusScan) stopped working. I tried reinstalling it but the download would stop all of a sudden. Up to this moment I haven't been able to install it again.

    I went online today and talked with McAfee tech support. They told me to do a DOS Scan and gave me a zip file to download so I could do it. I did, it found a couple of viruses and deleted them. Still I couldn't reinstall McAfee.

    I then noticed that whenever I run REGEDIT it closes whenever I try to open a folder or use an option from the menus.

    The latest is that I can't go to McAfee's web page anymore. I can't go to computercops.biz either. I asked friends if they could and they said they could go to the site with no problem. I get the typical error window (like when you mistype an address; server may be down something like that)

    I'm also noticing that I can't cut and paste text or that I can't open links in messenger windows or in Outlook Express. I click on the links and nothing happens. I have to write the address myself.

    I've ran Spybot, AdAware, Stinger and HijackThis.

    I don't know what else to do

    Can anyone please help me? Obviously the virus is still in my system and won't leave.

    More examples of infected files I've been getting are:

    C/WINNT\system32\wuamgrd.exe
    W32/Gaobot.worm.gen.e

    C:\WINNT\system32\msconfig.dat
    W32/Sdbot.worm.gen

    C:\WINNT\system32\regedlt.exe
    W32/Randbot.worm

    C:\WINNT\system32\lsass.exe
    W32/Gaobot.worm.gen.f

    I hope you can help me. If you need more info just let me know.

    Thank you very much

    CPG
     
  2. buckaroo

    buckaroo

    Joined:
    Mar 25, 2001
    Messages:
    3,334

    Go here and try another online AV scan:

    http://www.bitdefender.com/scan/licence.php


    Also, post your HJT log after the scan.

    :)
     
  3. cesarcarlos

    cesarcarlos Thread Starter

    Joined:
    Jan 11, 2004
    Messages:
    44
    I did as you said. I ran the antivirus and it detected and deleted the following:

    C:\WINNT\system32\mssmgrd.exe
    Infected with BAckdoor SDBot Gen

    C:\WINNT\system32\TFTP1056
    Infected with Backdoor SDBot Gen

    C:\WINNT\system32\winhlpp32.exe
    Infected with Backdoor Agobot.3.Gen


    Also, here's the HT log file after the scan.

    Thanks

    CPG


    Logfile of HijackThis v1.97.7
    Scan saved at 07:10:02 p.m., on 04/04/2004
    Platform: Windows 2000 SP2 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\CTSvcCDA.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\spoolsvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\SYSTEM32\3cmlink.exe
    C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\WINNT\loadqm.exe
    C:\winnt\$ntservicepackuninstall$\services.exe
    C:\WINNT\SYSTEM32\3cshtdwn.exe
    C:\WINNT\SYSTEM32\3cmlink.exe
    C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe
    C:\Documents and Settings\Cesar Puch\Escritorio\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = VĂ­nculos
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\archiv~1\mcafee.com\vso\mcvsshl.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [3c1807pd] C:\WINNT\SYSTEM32\3cmlink.exe RunServices \Device\3cpipe-3c1807pd
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\ARCHIV~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] "c:\ARCHIV~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [MCAgentExe] c:\ARCHIV~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\ARCHIV~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [Services] c:\winnt\$ntservicepackuninstall$\services.exe
    O4 - HKLM\..\Run: [Service Host Process] spoolsvc.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\RunServices: [Service Host Process] spoolsvc.exe
    O4 - HKCU\..\Run: [msword] msword.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Archivos de programa\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! Search - file:///C:\Archivos de programa\Yahoo!\Common/ycsrch.htm
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,81/mcinsctl.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
    O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/i486/NTANSI/retail/DASAct.cab
    O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,19/mcgdmgr.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4346/mcfscan.cab
     
  4. sleekluxury

    sleekluxury

    Joined:
    Oct 5, 2003
    Messages:
    3,752
    Open Hijack This again, put a check mark next to all listed below, close all other programs and then hit 'FIX CHECKED':

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
     
  5. cesarcarlos

    cesarcarlos Thread Starter

    Joined:
    Jan 11, 2004
    Messages:
    44
    I tried those fixes and restarted.

    I still can't go to www.mcafee.com, my regedit keep closing after a few secs and I still can't reinstall McAfee Scan Online (and eitherway I won't be able to download the reinstall since I can't go to mcafee.com)

    :( :( :(

    Anyone else has a suggestion?

    Thanks anyway sleekluxury.

    :'(

    CPG
     
  6. Flrman1

    Flrman1

    Joined:
    Jul 26, 2002
    Messages:
    46,329
    You missed the worst ones in that log Sleek.

    Boot to safe mode.

    In safe mode run Hijack This again and put a check by these. Close all windows except HijackThis and click "Fix checked"

    O4 - HKLM\..\Run: [Service Host Process] spoolsvc.exe

    O4 - HKLM\..\RunServices: [Service Host Process] spoolsvc.exe

    O4 - HKCU\..\Run: [msword] msword.exe


    Now while in safe mode delete:

    The C:\WINNT\System32\spoolsvc.exe file (DO NOT delete spoolsv.exe)

    Do a file search for msword.exe and delete it. It will likely be in the C:\WINNT directory.

    You should also find and delete the other files that you said were infected while in safe mode.

    How to start your computer in safe mode
     
  7. cesarcarlos

    cesarcarlos Thread Starter

    Joined:
    Jan 11, 2004
    Messages:
    44
    Thanks to flrman1 it appears that now regedit won't close after a few seconds. I tried making a backup of the registry (just for a test) and it did the task fine. That's some progress. Also McAfee loaded fine and didn't close.

    However I still can't go to www.mcafee.com. I want to go there so I can make a reinstall of VirusScan online in case some components were corrupted.

    Another site I can't go to is www.computercops.biz

    It's really weird.


    Any suggestions on this?

    Thanks for the help so far. You guys are great (y)

    CPG
     
  8. cesarcarlos

    cesarcarlos Thread Starter

    Joined:
    Jan 11, 2004
    Messages:
    44
    Really bad news!

    Seems like I lost my printer after that fix :( :( :(

    I can print, but it takes like a whole minute from the moment I send the print order till the actual printing. It used to be almost instantly.

    CPG
     
  9. mjack547

    mjack547 Malware Specialist

    Joined:
    Sep 1, 2003
    Messages:
    3,181
    Post a new HijackThis Log

    Thanks
     
  10. cesarcarlos

    cesarcarlos Thread Starter

    Joined:
    Jan 11, 2004
    Messages:
    44
    Here's the newest log mjack
    Thanks!

    CPG



    Logfile of HijackThis v1.97.7
    Scan saved at 08:54:14 p.m., on 04/04/2004
    Platform: Windows 2000 SP2 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\CTSvcCDA.exe
    C:\WINNT\System32\svchost.exe
    c:\ARCHIV~1\mcafee.com\vso\mcvsrte.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\SYSTEM32\3cmlink.exe
    C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\WINNT\loadqm.exe
    C:\ARCHIV~1\mcafee.com\vso\mcvsshld.exe
    C:\ARCHIV~1\mcafee.com\agent\mcagent.exe
    C:\winnt\$ntservicepackuninstall$\services.exe
    C:\WINNT\SYSTEM32\3cshtdwn.exe
    C:\WINNT\SYSTEM32\3cmlink.exe
    C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe
    c:\ARCHIV~1\mcafee.com\vso\mcshield.exe
    C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\Cesar Puch\Escritorio\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = VĂ­nculos
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\archiv~1\mcafee.com\vso\mcvsshl.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [3c1807pd] C:\WINNT\SYSTEM32\3cmlink.exe RunServices \Device\3cpipe-3c1807pd
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\ARCHIV~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] "c:\ARCHIV~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [MCAgentExe] c:\ARCHIV~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\ARCHIV~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [Services] c:\winnt\$ntservicepackuninstall$\services.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Archivos de programa\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! Search - file:///C:\Archivos de programa\Yahoo!\Common/ycsrch.htm
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,81/mcinsctl.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
    O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/i486/NTANSI/retail/DASAct.cab
    O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,19/mcgdmgr.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4346/mcfscan.cab
     
  11. buckaroo

    buckaroo

    Joined:
    Mar 25, 2001
    Messages:
    3,334
  12. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/217073

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice