ComboFix log
ComboFix 10-03-04.06 - Chef 03/05/2010 9:22.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1408 [GMT -8:00]
Running from: c:\documents and settings\Chef\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Chef\Desktop\CFScript.txt
AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
file zipped: c:\windows\Qmibujabowixan.bin
file zipped: c:\windows\Xhafituyih.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Chef\Application Data\BitTorrent
c:\program files\UseNeXT
c:\program files\UseNeXT\DevComponents.DotNetBar.dll
c:\program files\UseNeXT\groups.dat
c:\program files\UseNeXT\IXP.DLL
c:\program files\UseNeXT\language_de.txt
c:\program files\UseNeXT\language_en.txt
c:\program files\UseNeXT\language_es.txt
c:\program files\UseNeXT\language_fr.txt
c:\program files\UseNeXT\log.txt
c:\program files\UseNeXT\pp\gulli.ico
c:\program files\UseNeXT\unins000.exe
c:\windows\Qmibujabowixan.bin
c:\windows\Xhafituyih.dat
.
((((((((((((((((((((((((( Files Created from 2010-02-05 to 2010-03-05 )))))))))))))))))))))))))))))))
.
2010-03-05 15:58 . 2010-02-04 09:00 84912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100305.004\NAVENG.SYS
2010-03-05 15:58 . 2010-02-04 09:00 1324720 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100305.004\NAVEX15.SYS
2010-03-05 15:58 . 2009-08-25 08:00 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100305.004\NAVENG32.DLL
2010-03-05 15:58 . 2009-08-25 08:00 1647984 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100305.004\NAVEX32A.DLL
2010-03-05 15:58 . 2009-12-09 09:00 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100305.004\CCERASER.DLL
2010-03-05 15:58 . 2009-09-22 08:00 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100305.004\ECMSVR32.DLL
2010-03-05 15:58 . 2009-08-26 08:00 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100305.004\EECTRL.SYS
2010-03-05 15:58 . 2009-08-26 08:00 102448 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100305.004\ERASER.SYS
2010-03-05 05:28 . 2010-02-02 03:20 165240 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2010-03-05 05:21 . 2006-05-03 13:18 247808 ----a-w- c:\windows\system32\drivers\iaStor.sys
2010-03-03 16:50 . 2010-03-03 16:50 -------- d-----w- c:\documents and settings\Chef\Application Data\Malwarebytes
2010-03-03 16:50 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-03 16:50 . 2010-03-03 16:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-03 16:50 . 2010-03-03 16:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-03 16:50 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-02 03:21 . 2010-03-02 03:24 -------- d-----w- c:\documents and settings\Chef\Application Data\Download Manager
2010-02-26 02:06 . 2010-02-26 02:07 -------- d-----w- c:\documents and settings\Chef\vw
2010-02-26 02:06 . 2010-02-26 02:06 -------- d-----w- c:\documents and settings\Chef\Visual IP Trace
2010-02-26 02:06 . 2010-02-26 02:06 -------- d-----w- c:\program files\Visual IP Trace 2009
2010-02-25 20:46 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSvix86.sys
2010-02-25 20:46 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSXpx86.sys
2010-02-25 20:46 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\Scxpx86.dll
2010-02-25 20:46 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSxpx86.dll
2010-02-25 20:46 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSviA64.sys
2010-02-22 09:12 . 2010-02-22 09:13 -------- d-----w- c:\program files\ERUNT
2010-02-21 01:02 . 2010-02-21 01:02 -------- d-----w- c:\program files\PHP
2010-02-21 00:59 . 2010-02-21 00:59 -------- d-----w- c:\documents and settings\Chef\blank
2010-02-21 00:53 . 2010-02-21 00:53 300616 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-02-21 00:53 . 2010-02-21 00:53 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-02-21 00:53 . 2010-02-21 00:53 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-02-21 00:53 . 2010-02-21 00:53 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-02-21 00:53 . 2010-02-21 00:53 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-02-21 00:53 . 2010-02-21 00:53 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-02-21 00:53 . 2010-02-21 00:53 118784 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-02-21 00:53 . 2010-02-21 00:53 329312 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-02-21 00:53 . 2010-02-21 00:53 -------- d-----w- c:\program files\Common Files\xing shared
2010-02-20 20:26 . 2010-02-20 20:26 -------- d-----w- c:\program files\JRE
2010-02-20 19:46 . 2010-02-20 19:46 -------- d-----w- c:\program files\Sun
2010-02-20 19:44 . 2010-02-20 19:45 -------- d-----w- c:\program files\Java
2010-02-20 07:14 . 2010-02-20 07:14 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2010-02-20 00:40 . 2010-02-20 07:22 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-20 00:40 . 2010-02-20 06:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-19 23:58 . 2010-02-19 23:58 388096 ----a-r- c:\documents and settings\Chef\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-02-19 23:53 . 2010-02-21 07:07 -------- d-----w- c:\program files\Windows Live Safety Center
2010-02-19 22:36 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100218.001\Scxpx86.dll
2010-02-19 22:36 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100218.001\IDSXpx86.sys
2010-02-19 22:36 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100218.001\IDSvix86.sys
2010-02-19 22:36 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100218.001\IDSxpx86.dll
2010-02-19 22:36 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100218.001\IDSviA64.sys
2010-02-19 19:25 . 2010-02-19 19:25 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-02-19 19:17 . 2010-02-19 19:17 -------- d-----w- c:\documents and settings\Chef\Local Settings\Application Data\Symantec
2010-02-18 19:27 . 2010-02-18 19:27 -------- d-----w- c:\program files\Common Files\Config
2010-02-18 19:27 . 2010-02-18 19:27 5686272 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\19153-191714.dll
2010-02-17 02:06 . 2010-02-17 02:06 -------- d-----w- c:\program files\Lame for Audacity
2010-02-17 02:03 . 2010-02-17 02:03 -------- d-----w- c:\program files\Audacity
2010-02-16 04:44 . 2010-02-25 23:54 -------- d-----w- c:\documents and settings\Chef\Application Data\Bioshock2
2010-02-16 04:39 . 2009-09-05 01:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-02-16 04:39 . 2009-09-05 01:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-02-16 04:38 . 2010-02-16 04:38 -------- d-----w- c:\windows\Logs
2010-02-16 04:38 . 2010-02-16 04:39 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-02-16 04:38 . 2010-02-16 04:38 -------- d-----w- c:\windows\system32\xlive
2010-02-11 21:06 . 2010-02-11 21:06 -------- d-----w- c:\documents and settings\Chef\Local Settings\Application Data\Acupartner
2010-02-11 11:02 . 2010-02-11 11:02 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft Help
2010-02-10 21:34 . 2010-02-10 21:34 7410688 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191319-191429.dll
2010-02-10 21:33 . 2010-02-10 21:33 7032320 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191222-191319.dll
2010-02-10 21:33 . 2010-02-10 21:33 6301696 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191127-191222.dll
2010-02-10 21:32 . 2010-02-10 21:32 2776576 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\191429-19153.dll
2010-02-10 21:30 . 2010-02-18 19:27 241512 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\QWPATCH.EXE
2010-02-10 21:30 . 2010-02-10 21:30 230752 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\patchw32.dll
2010-02-10 21:30 . 2010-02-10 21:30 956 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\patch\Update\rebase.cmd
2010-02-10 21:30 . 2010-01-13 18:30 4199784 ----a-w- c:\windows\system32\cdintf400.dll
2010-02-10 21:30 . 2010-01-13 18:27 26472 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\Premier\Custom\billmind.exe
2010-02-10 21:30 . 2010-01-13 18:27 26472 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\Hab\Custom\billmind.exe
2010-02-10 21:30 . 2010-01-13 18:27 26472 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Sku\RPM\Custom\billmind.exe
2010-02-10 21:29 . 2010-02-18 19:27 -------- d-----w- c:\program files\Quicken
2010-02-10 07:11 . 2006-10-27 03:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-02-10 07:11 . 2008-11-10 19:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2010-02-10 07:10 . 2010-02-10 07:10 -------- d-----w- c:\program files\Microsoft.NET
2010-02-10 07:08 . 2010-02-10 07:08 -------- d-----w- c:\documents and settings\Chef\Local Settings\Application Data\Microsoft Help
2010-02-10 07:08 . 2010-02-17 09:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-02-10 07:07 . 2010-02-10 07:07 -------- d-----r- C:\MSOCache
2010-02-10 06:57 . 2010-02-10 07:05 -------- d-----w- c:\documents and settings\Chef\Application Data\GetRightToGo
2010-02-06 06:08 . 2010-02-06 06:08 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2010-02-05 22:41 . 2009-10-28 22:37 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\Scxpx86.dll
2010-02-05 22:41 . 2009-10-28 22:37 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSvix86.sys
2010-02-05 22:41 . 2009-10-28 22:37 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSXpx86.sys
2010-02-05 22:41 . 2009-10-28 22:37 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSxpx86.dll
2010-02-05 22:41 . 2009-10-28 22:37 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100204.001\IDSviA64.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-05 17:20 . 2008-07-07 06:26 9145652 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-03-05 17:15 . 2009-03-07 22:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-03-05 06:05 . 2006-09-17 21:38 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-03-05 05:09 . 2010-03-05 05:15 5437440 ----a-w- c:\windows\Internet Logs\xDB1C.tmp
2010-03-05 05:09 . 2010-03-05 05:15 1195008 ----a-w- c:\windows\Internet Logs\xDB1B.tmp
2010-03-02 03:01 . 2007-03-20 06:59 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-03-02 03:01 . 2007-10-30 07:43 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-02-27 22:13 . 2010-02-27 22:16 35840 ----a-w- c:\windows\Internet Logs\xDB19.tmp
2010-02-27 22:13 . 2010-02-27 22:16 4964352 ----a-w- c:\windows\Internet Logs\xDB1A.tmp
2010-02-27 21:43 . 2010-02-27 21:43 4961280 ----a-w- c:\windows\Internet Logs\xDB18.tmp
2010-02-27 21:43 . 2010-02-27 21:43 826880 ----a-w- c:\windows\Internet Logs\xDB17.tmp
2010-02-27 19:17 . 2006-09-18 01:26 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-02-25 21:54 . 2006-10-01 06:37 -------- d-----w- c:\program files\Steam
2010-02-24 09:26 . 2010-02-24 19:37 1065984 ----a-w- c:\windows\Internet Logs\xDB16.tmp
2010-02-22 09:07 . 2010-02-22 09:07 131697 ----a-w- c:\windows\Internet Logs\vsmon_2nd_2010_02_21_13_45_47_small.dmp.zip
2010-02-21 21:29 . 2006-09-14 04:06 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-21 01:10 . 2006-09-14 03:00 69360 ----a-w- c:\documents and settings\Chef\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-21 00:53 . 2006-09-22 17:03 -------- d-----w- c:\program files\Common Files\Real
2010-02-21 00:53 . 2006-09-22 17:03 -------- d-----w- c:\program files\Real
2010-02-21 00:52 . 2003-03-19 05:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-02-21 00:52 . 2003-02-21 11:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-02-20 20:26 . 2009-08-01 20:13 -------- d-----w- c:\program files\OpenOffice.org 3
2010-02-20 19:45 . 2008-12-15 17:20 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-20 19:21 . 2006-09-18 20:10 -------- d-----w- c:\documents and settings\All Users\Application Data\BVRP Software
2010-02-20 19:21 . 2006-09-14 02:05 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-19 15:14 . 2009-09-18 09:55 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-18 15:20 . 2008-10-14 07:10 -------- d-----w- c:\documents and settings\Chef\Application Data\Online Backup
2010-02-18 05:44 . 2006-09-19 00:42 -------- d-----w- c:\documents and settings\Chef\Application Data\Canon
2010-02-17 01:35 . 2006-12-25 02:59 -------- d-----w- c:\program files\MediaMonkey
2010-02-16 00:27 . 2008-04-21 05:26 -------- d-----w- c:\documents and settings\Chef\Application Data\Bioshock
2010-02-14 10:50 . 2007-02-18 21:55 -------- d-----w- c:\documents and settings\Chef\Application Data\Skype
2010-02-13 19:32 . 2010-02-13 19:32 131857 ----a-w- c:\windows\Internet Logs\vsmon_2nd_2010_02_13_11_27_23_small.dmp.zip
2010-02-13 10:21 . 2006-09-18 20:40 -------- d-----w- c:\program files\Microsoft Works
2010-02-12 09:58 . 2010-02-12 20:54 4721664 ----a-w- c:\windows\Internet Logs\xDB15.tmp
2010-02-12 09:58 . 2010-02-12 20:54 1842688 ----a-w- c:\windows\Internet Logs\xDB14.tmp
2010-02-06 06:10 . 2006-12-10 19:52 -------- d-----w- c:\program files\Google
2010-02-03 07:20 . 2010-02-03 07:19 -------- d-----w- c:\program files\iTunes
2010-02-03 07:20 . 2010-02-03 07:20 -------- d-----w- c:\program files\iPod
2010-02-03 07:20 . 2008-12-30 05:21 -------- d-----w- c:\program files\Common Files\Apple
2010-02-03 07:17 . 2010-02-03 07:17 -------- d-----w- c:\program files\QuickTime
2010-01-23 21:03 . 2010-01-23 21:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-01-23 03:51 . 2010-01-23 03:51 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-01-18 19:31 . 2007-09-17 19:45 -------- d-----w- c:\documents and settings\Chef\Application Data\dvdcss
2010-01-17 07:04 . 2008-07-18 00:50 166705 ----a-w- c:\documents and settings\Chef\Application Data\Thunderbird\Profiles\dr464kb8.default\Mail\Local Folders\Business.sbd\F.sbd\Flashloaded.com
2010-01-13 18:26 . 2010-01-13 18:26 91 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\Quicken\Inet\Common\Pnf\Pas\reg.bat
2010-01-07 21:18 . 2009-08-16 19:46 -------- d-----w- c:\documents and settings\Flo\Application Data\Canon
2010-01-02 02:47 . 2009-08-04 02:05 1 ----a-w- c:\documents and settings\Chef\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-31 16:50 . 2001-08-23 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-28 08:10 . 2009-12-28 17:28 2948096 ----a-w- c:\windows\Internet Logs\xDB13.tmp
2009-12-21 19:14 . 2004-01-08 22:23 916480 ------w- c:\windows\system32\wininet.dll
2009-12-20 18:46 . 2009-12-20 18:46 20299200 ----a-w- c:\documents and settings\Chef\Application Data\TomTom\HOME\Profiles\sbrhqw6q.default\Updates\v2_7_3_1894_win.exe
2009-12-16 18:43 . 2006-09-14 01:42 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 19:15 . 2009-12-14 19:15 2146304 ----a-w- c:\windows\system32\GPhotos.scr
2009-12-14 07:08 . 2001-08-23 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:26 . 2001-08-23 12:00 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2001-08-17 13:48 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-02-28_20.14.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-05 17:15 . 2010-03-05 17:15 16384 c:\windows\Temp\Perflib_Perfdata_7b8.dat
+ 2010-03-05 17:16 . 2010-03-05 17:16 16384 c:\windows\Temp\Perflib_Perfdata_1a0.dat
+ 2010-03-05 17:14 . 2010-03-05 17:14 16384 c:\windows\Temp\Perflib_Perfdata_138.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"@BackupScheduler"="c:\program files\Online Backup\OnlineBackup.exe" [2008-10-14 611768]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-05-03 151552]
"JMB36X Configure"="c:\windows\System32\JMRaidTool.exe" [2006-04-25 385024]
"RCSystem"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-17 49152]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-17 49152]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2005-03-15 196608]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 56080]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2006-11-11 1051648]
"RTHDCPL"="RTHDCPL.EXE" [2006-04-17 16143872]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-03-30 624248]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 56080]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-10-17 1037192]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"StartupDelayer"="c:\program files\r2 Studios\Startup Delayer\Startup Launcher GUI.exe" [2009-03-08 147456]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-05-08 2780432]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-02-21 202256]
c:\documents and settings\Chef\Start Menu\Programs\Startup\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2009-6-24 803176]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Conversion to PDF with ScanSnap Organizer.lnk - c:\program files\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe [2009-6-17 15360]
ScanSnap Manager.lnk - c:\program files\PFU\ScanSnap\Driver\PfuSsMon.exe [2009-6-17 1048576]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ASUS WiFi-AP Solo.lnk]
backup=c:\windows\pss\ASUS WiFi-AP Solo.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DataViz Inc Messenger.lnk]
backup=c:\windows\pss\DataViz Inc Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Chef^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Chef^Start Menu^Programs^Startup^palmOne Registration.lnk]
backup=c:\windows\pss\palmOne Registration.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe_ID0EYTHM]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
2004-12-03 01:23 102400 ------w- c:\program files\Creative\MediaSource\Detector\CTDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDVDDET]
2003-06-18 08:00 45056 ------w- c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
2007-04-11 22:32 56080 ----a-w- c:\windows\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2006-11-10 19:35 90112 ----a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 08:00 90112 ------w- c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"QBFCService"=3 (0x3)
"NBService"=3 (0x3)
"MDM"=2 (0x2)
"LVCOMSer"=2 (0x2)
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"Creative Service for CDROM Access"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"Adobe Version Cue CS3"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\kav\\kav7\\setup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\peggle deluxe\\Peggle.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\peggle extreme\\PeggleExtreme.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\bioshock\\Builds\\Release\\Bioshock.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\bioshock 2\\SP\\Builds\\Binaries\\Bioshock2Launcher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\bioshock 2\\MP\\Builds\\Binaries\\Bioshock2Launcher.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
"67:UDP"= 67:UDP:0.0.0.0/255.255.255.255:Enabled

HCP Discovery Service
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1008000.029\SymEFA.sys [2/2/2010 11:21 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1008000.029\BHDrvx86.sys [2/2/2010 11:21 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1008000.029\cchpx86.sys [2/2/2010 11:20 AM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100224.002\IDSXpx86.sys [2/25/2010 12:46 PM 329592]
R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\drivers\VCdRom.sys [10/24/2006 6:34 PM 8576]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe [2/2/2010 11:20 AM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/26/2009 11:37 PM 102448]
S2 gupdate1c99f732a046a29;Google Update Service (gupdate1c99f732a046a29);c:\program files\Google\Update\GoogleUpdate.exe [3/7/2009 2:22 PM 133104]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [11/13/2009 3:31 AM 92008]
S3 BS_DEF;BS_DEF;c:\program files\ASUS\AsusUpdate\BS_DEF.sys [3/19/2009 9:57 AM 12800]
S3 CLAVIAUSB;CLAVIAUSB;c:\windows\system32\drivers\ClaviaUSB.sys [10/5/2009 8:30 PM 19712]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [6/17/2009 4:20 AM 12648]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [9/13/2006 6:14 PM 332928]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-02-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
2010-03-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-01 01:49]
2010-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-07 22:22]
2010-03-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-07 22:22]
2010-03-05 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-789336058-776561741-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-10 02:38]
2010-03-05 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-789336058-776561741-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-10 02:38]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Chef\Application Data\Mozilla\Firefox\Profiles\bf5ftzln.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.addthis.com/search?pco=fxe-3.0.0&locale=en-US&q=
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\Chef\Application Data\Mozilla\Firefox\Profiles\bf5ftzln.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-05 09:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:1a,3c,8b,f5,d5,be,b8,e7,56,1b,4f,f6,f0,76,c5,b5,57,93,fc,fa,a3,
12,f5,46,9b,0c,1f,ca,52,87,fc,c0,a4,2c,4b,bd,5c,1a,c2,db,da,6b,18,6c,48,4d,\
[HKEY_LOCAL_MACHINE\software\Classes\giffile\shell\Open\ddeexec]
@DACL=(02 0000)
@="\"file:%1\",,-1,,,,,"
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:1a,3c,8b,f5,d5,be,b8,e7,56,1b,4f,f6,f0,76,c5,b5,57,93,fc,fa,a3,
12,f5,46,9b,0c,1f,ca,52,87,fc,c0,a4,2c,4b,bd,5c,1a,c2,db,da,6b,18,6c,48,4d,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1380)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-03-05 09:32:30
ComboFix-quarantined-files.txt 2010-03-05 17:32
ComboFix2.txt 2010-03-05 05:46
ComboFix3.txt 2010-02-28 20:23
Pre-Run: 15,082,328,064 bytes free
Post-Run: 15,027,822,592 bytes free
- - End Of File - - B7AC17B2EA69E840EE8890AA17E372AE
Upload was successful