W32.IRCbot.Gen problem and cannot reboot computer
Dear Peku006:
Thank you very much for your help.
A few other points you should know:
1) I cannot access internet from the computer in safemode with networking. There is something wrong with internet access program perhaps as part of the overall problem.
2) therefore, I am using my second (working) computer to write to you.
3) I recently install daemon tools Pro. Perhaps this may have something to do with it. It kept giving an error saying it would not run without Windows 2000 with SPTD 1.43 or higher and asks me to turn off kernel debugger. It worked last week before my computer crashed. Could it have a virus in it or is it an innocent victim due to the trojan.vundo.h?
4) I do not have the original Windows installation disc for my computer because it was installed by retailers when I bought my computer from them. Therefore, I will have to use a borrowed windows XP installation disc from a friend or download a pirated one. The retailers would not give it to me.
Here is the combofix log (I could not download restore console from microsoft because the affected computer could not access internet as I mentioned before). Nevertheless, the combofix completed its analysis and gave me the log. Thank you once again.
ComboFix 09-11-25.03 - Owner 11/26/2009 6:59.1.2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.330 [GMT 8:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\sosuo.col
c:\windows\system32\clauth1.dll
c:\windows\system32\clauth2.dll
c:\windows\system32\iexp_log.txt
c:\windows\system32\nsprs.dll
c:\windows\system32\ssprs.dll
c:\windows\system32\svjfjqa.dll
c:\windows\Tasks\At1.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDEFKLNA
-------\Service_tdefklna
((((((((((((((((((((((((( Files Created from 2009-10-25 to 2009-11-25 )))))))))))))))))))))))))))))))
.
2009-11-25 16:08 . 2009-11-25 16:08 -------- d-----w- c:\program files\Trend Micro
2009-11-25 16:07 . 2009-11-25 16:08 -------- d-----w- c:\program files\ERUNT
2009-11-23 16:42 . 2009-11-23 16:42 -------- d-----w- c:\program files\NETVIGATOR
2009-11-23 16:42 . 2000-12-08 13:59 122880 ----a-w- c:\windows\UnGins.exe
2009-11-23 16:42 . 2009-11-23 16:42 -------- d-----w- C:\Temp
2009-11-23 15:59 . 2009-11-23 16:17 -------- d-----w- c:\documents and settings\Owner\Application Data\MSN6
2009-11-23 15:59 . 2009-11-23 15:59 -------- d-----w- c:\documents and settings\All Users\Application Data\MSN6
2009-11-22 10:01 . 2009-11-22 10:01 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-11-20 14:41 . 2009-11-20 14:41 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-11-20 14:41 . 2009-09-10 06:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-20 14:41 . 2009-11-20 14:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-20 14:41 . 2009-11-20 14:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-20 14:41 . 2009-09-10 06:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-20 11:39 . 2009-11-20 11:39 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-11-20 11:12 . 2009-11-20 11:12 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Symantec
2009-11-20 11:12 . 2009-11-20 11:12 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-11-19 23:32 . 2007-10-17 16:16 79688 ----a-w- c:\windows\system32\drivers\iksyssec.sys
2009-11-19 23:32 . 2007-10-17 16:16 29000 ----a-w- c:\windows\system32\drivers\kcom.sys
2009-11-19 23:32 . 2007-10-17 16:15 62280 ----a-w- c:\windows\system32\drivers\iksysflt.sys
2009-11-19 23:32 . 2007-10-17 16:14 41288 ----a-w- c:\windows\system32\drivers\ikfilesec.sys
2009-11-19 23:32 . 2009-11-19 23:32 -------- d-----w- c:\documents and settings\Owner\Application Data\PC Tools
2009-11-19 23:32 . 2005-09-23 00:29 626688 ----a-w- c:\windows\system32\msvcr80.dll
2009-11-19 13:51 . 2009-11-19 13:51 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-11-19 13:50 . 2009-11-19 13:50 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Threat Expert
2009-11-19 13:32 . 2009-11-25 22:53 -------- d-----w- c:\program files\Spyware Doctor
2009-11-19 13:31 . 2009-11-19 14:06 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-19 13:00 . 2009-11-19 13:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-11-19 13:00 . 2009-11-19 13:00 -------- d-----w- c:\documents and settings\Owner\Application Data\Yahoo!
2009-11-19 13:00 . 2009-11-19 13:00 -------- d-----w- c:\program files\Yahoo!
2009-11-14 16:56 . 2009-11-14 17:00 -------- d-----w- c:\program files\SPSSEval
2009-11-12 13:38 . 2008-05-02 02:41 3493888 ---ha-w- c:\documents and settings\Owner\Application Data\U3\temp\Launchpad Removal.exe
2009-11-11 12:03 . 2009-11-11 12:03 -------- d--h--r- c:\documents and settings\Owner\Application Data\SecuROM
2009-11-11 11:54 . 2009-11-11 11:54 -------- d-----w- c:\program files\Sierra Online
2009-11-09 09:53 . 2009-11-09 09:53 -------- d-----w- c:\program files\Ubisoft
2009-11-05 22:56 . 2009-11-05 22:56 -------- d-----w- c:\documents and settings\Owner\Application Data\Sports Interactive
2009-11-05 22:46 . 2009-11-05 22:46 -------- d-----w- c:\windows\Downloaded Installations
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-25 22:54 . 2008-10-16 22:38 -------- d-----w- c:\documents and settings\Owner\Application Data\U3
2009-11-20 12:36 . 2008-11-05 16:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-20 00:13 . 2008-10-16 23:09 -------- d-----w- c:\documents and settings\Owner\Application Data\uTorrent
2009-11-19 13:00 . 2008-10-16 22:40 -------- d-----w- c:\program files\CCleaner
2009-11-19 09:56 . 2008-11-05 16:17 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-17 05:25 . 2008-10-14 23:00 -------- d-----w- c:\program files\Symantec AntiVirus
2009-11-14 17:11 . 2008-10-14 22:19 30784 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-11 12:15 . 2008-10-14 22:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-11 12:03 . 2009-10-14 14:12 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-10-26 13:37 . 2009-09-28 23:33 -------- d-----w- c:\program files\GameSpy Arcade
2009-10-26 06:17 . 2009-10-24 06:01 -------- d-----w- c:\program files\Temporary Game file
2009-10-25 17:17 . 2009-10-24 22:57 -------- d-----w- c:\program files\Zombie Shooter
2009-10-24 22:56 . 2009-10-24 22:56 -------- d-----w- c:\program files\ReflexiveArcade
2009-10-24 13:56 . 2009-10-24 13:52 -------- d-----w- c:\program files\DAEMON Tools Pro
2009-10-24 13:56 . 2009-10-24 13:55 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2009-10-24 13:55 . 2009-10-24 13:55 -------- d-----w- c:\documents and settings\Owner\Application Data\DAEMON Tools Pro
2009-10-17 05:06 . 2008-10-26 06:05 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-10-17 04:00 . 2009-10-17 04:00 -------- d-----w- c:\program files\AGEIA Technologies
2009-10-17 03:27 . 2009-10-17 03:27 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-10-17 01:10 . 2009-10-17 01:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-10-17 01:10 . 2009-10-16 16:32 -------- d-----w- c:\program files\Electronic Arts
2009-10-16 16:32 . 2009-10-16 16:32 662 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-10-16 16:32 . 2008-10-14 22:21 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-16 14:32 . 2009-10-16 14:32 1962544 ----a-w- c:\program files\install_flash_player_ax.exe
2009-10-16 14:27 . 2009-10-16 14:27 1962544 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2009-10-14 13:19 . 2009-07-06 12:59 -------- d-----w- c:\program files\MagicISO
2009-10-14 13:19 . 2009-10-14 13:19 3067375 ----a-w- c:\program files\Setup_MagicISO.exe
2009-10-14 13:08 . 2009-10-14 13:08 -------- d-----w- c:\program files\MagicDisc
2009-10-14 13:08 . 2009-10-14 13:08 1352435 ----a-w- c:\program files\setup_magicdisc.exe
2009-10-05 07:42 . 2008-10-14 22:39 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-05 07:38 . 2009-10-05 07:38 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-10-05 07:34 . 2009-10-05 07:34 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-09-28 23:26 . 2009-09-28 23:23 -------- d-----w- c:\program files\Halo
2009-09-28 15:26 . 2009-09-28 15:26 685816 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-09-11 14:18 . 2001-08-23 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2001-08-23 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2001-08-23 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2008-07-19 22:08 . 2008-10-16 22:40 266544 ----a-w- c:\program files\uTorrent.exe
2005-05-14 00:12 . 2005-05-14 00:12 217073 --sha-r- c:\windows\meta4.exe
2005-10-24 18:13 . 2005-10-24 18:13 66560 --sha-r- c:\windows\MOTA113.exe
2005-06-26 22:32 . 2005-06-26 22:32 616448 --sha-r- c:\windows\system32\cygwin1.dll
2005-06-22 05:37 . 2005-06-22 05:37 45568 --sha-r- c:\windows\system32\cygz.dll
2006-05-03 09:06 . 2009-09-15 15:05 163328 --sh--r- c:\windows\system32\flvDX.dll
2004-01-25 07:00 . 2004-01-25 07:00 70656 --sha-r- c:\windows\system32\i420vfw.dll
2007-02-21 10:47 . 2009-09-15 15:05 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2009-09-15 15:05 216064 --sh--r- c:\windows\system32\nbDX.dll
2005-02-28 20:16 . 2005-02-28 20:16 240128 --sha-r- c:\windows\system32\x.264.exe
2004-01-25 07:00 . 2004-01-25 07:00 70656 --sha-r- c:\windows\system32\yv12vfw.dll
.
------- Sigcheck -------
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-04-14 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-14 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2004-08-04 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-17 139264]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Shareaza"="c:\program files\Shareaza\Shareaza.exe" [2008-10-01 5723136]
"FLV Downloader"="c:\program files\Moyea\YouTube FLV Downloader\FLVDownloader.exe" [2009-05-27 3644928]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2007-12-14 413696]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 66680]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2004-03-12 124128]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-26 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-10-14 576000]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-18 65588]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Audiosrv]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HDAudBus]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318}]
@="[6cFgE][S??d, ?駤e???d g??▊?tr?l???!!! !!! !]"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{640167b4-59b0-47a6-b335-a6b3c0695aea}]
@="Portable Media Devices"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Funshion Online\\Funshion\\Funshion.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Documents and Settings\\Owner\\My Documents\\AVIXE pen drive2 stuff\\TuDienHND\\3rdparty\\jre\\bin\\jre.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6346:TCP"= 6346:TCP:shareaza
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9/28/2009 11:26 PM 685816]
S1 jqi0d17;jqi0d17;c:\windows\system32\drivers\jqi0d17.sys --> c:\windows\system32\drivers\jqi0d17.sys [?]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [3/13/2004 6:18 AM 169192]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\svcntaux.exe [11/20/2009 7:32 AM 311112]
SUnknown AppToService_TuDienHND;AppToService_TuDienHND; [x]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\setup.exe
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://hk.yahoo.com/?p=us
IE: 妏蚚厙珜捃濘狟婥
IE: 妏蚚厙珜捃濘狟婥窒蟈諉
IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436}
.
- - - - ORPHANS REMOVED - - - -
BHO-{F92CCA65-3301-4C6B-88B5-95ED581FF3DA} - c:\windows\system32\svjfjqa.dll
SafeBoot-drmkaud
SafeBoot-AudioEndpointBuilder
SafeBoot-HdAudAddService
SafeBoot-MMCSS
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-26 07:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8231F2F6]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf8586f28
\Driver\ACPI -> ACPI.sys @ 0xf83f7cb8
\Driver\atapi -> atapi.sys @ 0xf8389852
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805e668e
ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1
NDIS: Realtek RTL8139/810x Family Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf8295bb0
PacketIndicateHandler -> NDIS.sys @ 0xf82a2a21
SendHandler -> NDIS.sys @ 0xf828087b
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AppToService_TuDienHND]
"ImagePath"="c:\documents and settings\Owner\My Documents\AVIXE pen drive2 stuff\TuDienHND\3rdparty\basta\AppToService.exe /sys \"C:/Documents and Settings/Owner/My Documents/AVIXE pen drive2 stuff/TuDienHND/3rdparty/jre/bin/jrew.exe\" /Arguments:\"-mx64m -cp vietdict.jar vietdict.server.vietdictserver\" /Directory:\"c:/documents and settings/owner/my documents/avixe pen drive2 stuff/tudienhnd\" /Name:\"tudienhnd\" /Startup:A"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-507921405-179605362-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-507921405-179605362-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:bf,61,9c,87,c7,11,f9,a3,3d,3a,b8,09,f4,ba,38,70,93,f8,3b,56,bb,78,30,
ae,94,f6,6f,9a,93,9a,c4,bf,d2,f6,37,ec,4e,59,19,69,b8,c8,c2,4c,02,0f,44,1b,\
"??"=hex:6a,d4,43,5c,8e,72,8a,6a,02,82,58,4c,bd,6d,7e,5d
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(608)
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(672)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(1348)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\program files\Common Files\Ahead\Lib\NeroDigitalExt.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
.
Completion time: 2009-11-26 07:57 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-25 23:56
Pre-Run: 45,339,598,848 bytes free
Post-Run: 45,275,926,528 bytes free
- - End Of File - - 3751DF7ADCFEAA44EAFD3DC99392B84B