Looking alot better now
OOOOkay,I did as instructed here are the new logs.
ComboFix 08-07-24.1 - admin 2008-07-24 23:33:21.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.257 [GMT -6:00]
Running from: C:\Documents and Settings\admin\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\BMf3ac7981.txt
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\mainms.vpi
C:\WINDOWS\megavid.cdt
C:\WINDOWS\muotr.so
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\betjjluq.dll
C:\WINDOWS\system32\bfgjqx.dll
C:\WINDOWS\system32\bhjeyn.dll
C:\WINDOWS\system32\btjkkw.dll
C:\WINDOWS\system32\cqscfruf.dll
C:\WINDOWS\system32\dhnaqred.dll
C:\WINDOWS\system32\djogaxcf.dll
C:\WINDOWS\system32\dmwfvtje.dll
C:\WINDOWS\system32\eneicuwl.ini
C:\WINDOWS\system32\eoejobrl.dll
C:\WINDOWS\system32\fbjktuww.dll
C:\WINDOWS\system32\feohujad.dll
C:\WINDOWS\system32\fuohgk.dll
C:\WINDOWS\system32\fzctkf.dll
C:\WINDOWS\system32\gfrtevnk.ini
C:\WINDOWS\system32\gofelfpn.dll
C:\WINDOWS\system32\hljwugsf.bin
C:\WINDOWS\system32\hmgjchcf.ini
C:\WINDOWS\system32\jnnnqrar.ini
C:\WINDOWS\system32\jvtitj.dll
C:\WINDOWS\system32\kbmfidue.dll
C:\WINDOWS\system32\kxkkphqy.dll
C:\WINDOWS\system32\lkgiysjs.dll
C:\WINDOWS\system32\lorljbho.dll
C:\WINDOWS\system32\luhsuvwe.dll
C:\WINDOWS\system32\luzacz.dll
C:\WINDOWS\system32\mbbmetfl.dll
C:\WINDOWS\system32\mbxncr.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mhlriftl.dll
C:\WINDOWS\system32\mpuwsm.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\nhjxckus.ini
C:\WINDOWS\system32\nujmbwwj.dll
C:\WINDOWS\system32\oknqva.dll
C:\WINDOWS\system32\oskmtvhj.dll
C:\WINDOWS\system32\ouaggdhr.dll
C:\WINDOWS\system32\powixtvj.dll
C:\WINDOWS\system32\qltcajtl.dll
C:\WINDOWS\system32\qwtwjz.dll
C:\WINDOWS\system32\rthkvd.dll
C:\WINDOWS\system32\rxjsigvy.ini
C:\WINDOWS\system32\secntlvg.dll
C:\WINDOWS\system32\svimrh.dll
C:\WINDOWS\system32\tqwnctsn.dll
C:\WINDOWS\system32\tsjkclvi.dll
C:\WINDOWS\system32\uxnfpgwx.dll
C:\WINDOWS\system32\veoqoffr.dll
C:\WINDOWS\system32\vkkqgegw.dll
C:\WINDOWS\system32\vpwrbx.dll
C:\WINDOWS\system32\wfolrpjw.dll
C:\WINDOWS\system32\whktmumc.dll
C:\WINDOWS\system32\wjfvcwqw.ini
C:\WINDOWS\system32\wvbpwo.dll
C:\WINDOWS\system32\xnmubw.dll
C:\WINDOWS\system32\xudusctm.ini
.
((((((((((((((((((((((((( Files Created from 2008-06-25 to 2008-07-25 )))))))))))))))))))))))))))))))
.
2008-07-24 23:24 . 2008-07-24 23:24 0 --a------ C:\WINDOWS\BMf3ac7981.xml
2008-07-24 13:57 . 2008-07-24 13:57 <DIR> d-------- C:\Documents and Settings\admin\Application Data\Template
2008-07-24 13:14 . 2008-07-24 13:14 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-24 13:14 . 2008-07-24 13:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-24 13:14 . 2008-07-24 13:14 <DIR> d-------- C:\Documents and Settings\admin\Application Data\Malwarebytes
2008-07-24 13:14 . 2008-07-23 20:21 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-24 13:14 . 2008-07-23 20:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-24 09:28 . 2008-07-24 09:28 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-15 23:56 . 2008-07-15 23:56 <DIR> d-------- C:\Program Files\Safer Networking
2008-07-15 22:59 . 2002-06-05 19:38 <DIR> d-------- C:\Documents and Settings\admin\Application Data\InterTrust
2008-07-15 22:59 . 2008-07-24 12:06 <DIR> d-------- C:\Documents and Settings\admin
2008-07-14 16:36 . 2008-07-14 16:36 77 --a------ C:\Documents and Settings\mat\1063.bat
2008-07-14 01:09 . 2002-06-05 19:38 <DIR> d-------- C:\Documents and Settings\Administrator.MAT1\Application Data\InterTrust
2008-07-14 01:09 . 2008-07-14 01:09 <DIR> d-------- C:\Documents and Settings\Administrator.MAT1
2008-07-12 18:54 . 2008-07-24 12:52 269 --a------ C:\WINDOWS\wininit.ini
2008-07-12 17:31 . 2008-07-12 17:43 <DIR> d---s---- C:\Documents and Settings\Administrator
2008-07-11 15:09 . 2008-07-11 15:09 <DIR> d-------- C:\WINDOWS\system32\olixds18
2008-07-11 15:09 . 2008-07-12 17:13 <DIR> d-------- C:\Temp\stmpv4
2008-07-04 23:15 . 2008-07-04 23:15 32,768 --a------ C:\WINDOWS\system32\olixds18\olixds182328.exe
2008-07-01 12:53 . 2008-07-01 12:53 268 --ah----- C:\sqmdata04.sqm
2008-07-01 12:53 . 2008-07-01 12:53 244 --ah----- C:\sqmnoopt04.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-18 18:17 --------- d-----w C:\Program Files\Java
2008-07-16 05:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-16 05:20 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-18 05:54 --------- d-----w C:\Program Files\Disney
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-11 19:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-06-11 18:35 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-11 18:35 --------- d-----w C:\Program Files\Bonjour
2008-06-11 18:22 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-06-09 13:30 --------- d-----w C:\Program Files\MSN Messenger
2008-05-30 06:10 --------- d-----w C:\Program Files\FxClub
2008-05-29 09:08 --------- d-----w C:\Program Files\MSXML 6.0
2008-05-12 18:33 278,448 ----a-w C:\WINDOWS\ilib31ht.dll
2008-05-12 09:34 51,712 ----a-w C:\WINDOWS\wc98pp.dll
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2002-05-16 16:56 126976]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2002-05-16 16:54 540672]
"eabconfg.cpl"="C:\Program Files\Compaq\EAB\EabServr.exe" [2002-04-09 10:49 69632]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-13 11:00 311350]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-07-13 11:00 28739]
"Cpqset"="c:\compaq\cpqsetup\cpqset.exe" [2002-05-09 13:13 172101]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" [2008-07-07 09:42 4891472]
"ATIModeChange"="Ati2mdxx.exe" [2002-04-07 22:23 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"AtiPTA"="atiptaxx.exe" [2002-04-07 22:23 286720 C:\WINDOWS\system32\atiptaxx.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-04-17 17:27 9117696]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-13 11:00:00 24633]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\srmclean]
--a------ 2001-07-24 13:34 36864 C:\cpqs\scom\srmclean.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
R2 PackethSvc;Virtual NIC Service;C:\WINDOWS\System32\PackethSvc.exe [2001-08-09 15:46]
S3 ALiIRDA;ALi Infrared Device Driver;C:\WINDOWS\system32\DRIVERS\alifir.sys [2001-08-17 12:49]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2008-04-23 05:50:00 C:\WINDOWS\Tasks\Registration reminder 1.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2008-04-28 05:50:01 C:\WINDOWS\Tasks\Registration reminder 2.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2008-05-03 05:50:00 C:\WINDOWS\Tasks\Registration reminder 3.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2008-07-14 07:15:51 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-BMf3ac7981 - C:\WINDOWS\system32\vkkqgegw.dll
MSConfigStartUp-f09f4a1d - C:\WINDOWS\system32\uiyatcwr.dll
MSConfigStartUp-LSA Shellu - C:\Documents and Settings\mat\lsass.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R0 -: HKLM-Main,Search Bar = hxxp://rd.yahoo.com/customize/yessentials_cq/defaults/sb/*
http://www.yahoo.com/search/ie.html
O18 -: Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - C:\WINDOWS\wc98pp.dll
O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
O16 -: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://213.196.182.244/activex/AMC.cab
C:\WINDOWS\Downloaded Program Files\setup.inf
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-24 23:36:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-07-24 23:39:35
ComboFix-quarantined-files.txt 2008-07-25 05:39:13
Pre-Run: 27,203,678,208 bytes free
Post-Run: 28,355,145,728 bytes free
208 --- E O F --- 2008-07-10 02:40:40
HJT log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:41:41 PM, on 7/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Compaq\EAB\EabServr.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://rd.yahoo.com/customize/yessentials_cq/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Advisor - {76026873-0935-499C-B66A-9FF5EEF45BEA} - C:\Program Files\COMPAQ\Compaq Advisor\bin\rbaLauncher.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) -
http://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1208463644181
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) -
http://213.196.182.244/activex/AMC.cab
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
--
End of file - 5737 bytes