ComboFix 09-05-13.01 - jws 05/14/2009 1:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1025.18.479.156 [GMT 3:00]
Running from: c:\documents and settings\jws\My Documents\Downloads\Programs\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Microsoft Common
c:\program files\Microsoft Common\svchost.exe
c:\windows\system32\instFunc.dll
c:\windows\system32\kakle.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-13 to 2009-05-13 )))))))))))))))))))))))))))))))
.
2009-05-13 13:38 . 2009-05-13 13:38 -------- d-----w c:\documents and settings\jws\Local Settings\Application Data\Conduit
2009-05-13 13:38 . 2009-05-13 13:38 -------- d-----w c:\program files\Conduit
2009-05-13 13:38 . 2009-05-13 13:38 -------- d-----w c:\documents and settings\jws\Application Data\4shared Desktop
2009-05-13 04:18 . 2003-08-15 11:55 348160 ----a-w c:\windows\system32\eSellerateEngine.dll
2009-05-13 04:18 . 2009-05-13 04:19 -------- d-----w c:\program files\Acoustica MP3 Audio Mixer
2009-05-13 04:00 . 2009-05-13 04:00 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-05-12 17:27 . 2009-05-12 17:27 -------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-05-12 14:22 . 2009-05-12 14:22 -------- d-----w c:\documents and settings\jws\Application Data\vlc
2009-05-12 10:11 . 2009-05-12 10:11 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-05-12 09:56 . 2009-05-12 09:56 -------- d-----w c:\program files\Messenger Plus! Live
2009-05-12 09:50 . 2009-05-13 20:53 -------- d-----w c:\documents and settings\jws\Tracing
2009-05-12 09:48 . 2006-11-29 10:06 3426072 ----a-w c:\windows\system32\d3dx9_32.dll
2009-05-12 09:48 . 2009-05-12 09:48 -------- d-----w c:\program files\Microsoft SQL Server Compact Edition
2009-05-12 09:46 . 2009-05-12 09:46 -------- d-----w c:\program files\Microsoft
2009-05-12 09:45 . 2009-05-12 09:45 -------- d-----w c:\program files\Windows Live SkyDrive
2009-05-12 09:45 . 2009-05-12 09:48 -------- d-----w c:\program files\Windows Live
2009-05-12 09:42 . 2009-05-12 09:42 -------- d-----w c:\program files\Common Files\Windows Live
2009-05-12 04:31 . 2009-05-12 04:31 -------- d-----w c:\documents and settings\jws\Application Data\COWON
2009-05-12 04:12 . 2008-10-16 11:09 43544 ----a-w c:\windows\system32\wups2.dll
2009-05-12 02:29 . 2009-05-12 05:01 -------- d-----w c:\documents and settings\jws\Application Data\IDM
2009-05-12 02:29 . 2009-05-13 22:38 -------- d-----w c:\documents and settings\jws\Application Data\DMCache
2009-05-12 02:29 . 2009-05-12 04:00 -------- d-----w c:\program files\Internet Download Manager
2009-05-11 20:50 . 2009-05-11 20:51 -------- d-----w c:\documents and settings\jws\Contacts
2009-05-11 17:52 . 2009-05-11 17:52 0 ----a-w c:\windows\nsreg.dat
2009-05-11 17:52 . 2009-05-11 17:52 -------- d-----w c:\documents and settings\jws\Local Settings\Application Data\Mozilla
2009-05-11 16:56 . 2009-05-12 10:20 -------- d-----w c:\documents and settings\jws\Local Settings\Application Data\Google
2009-05-11 16:44 . 2009-05-12 10:19 -------- d-----w c:\program files\Google
2009-05-11 16:33 . 2009-05-11 16:52 -------- d-----w c:\documents and settings\jws\Application Data\Paltalk
2009-05-11 16:33 . 2009-05-11 16:33 -------- d-----w c:\windows\PaltalkScene
2009-05-11 16:33 . 2009-05-11 16:34 -------- d-----w c:\program files\Paltalk Messenger
2009-05-10 17:37 . 2009-05-10 17:37 -------- d-----w c:\documents and settings\jws\Local Settings\Application Data\Stardock
2009-05-10 17:26 . 2009-05-10 17:34 -------- d-----w c:\windows\Icon_Patcher
2009-05-10 17:25 . 2009-05-10 17:25 -------- d-----w c:\program files\MSECache
2009-05-10 17:06 . 2009-05-11 11:41 101287 ----a-w c:\windows\system32\drivers\klin.dat
2009-05-10 17:06 . 2009-05-11 11:41 89601 ----a-w c:\windows\system32\drivers\klick.dat
2009-05-10 17:05 . 2009-05-13 22:37 788512 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-10 17:05 . 2009-05-13 22:37 237600 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-10 17:05 . 2009-05-10 17:05 -------- d-----w c:\program files\Kaspersky Lab
2009-05-10 17:05 . 2009-05-13 22:38 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-05-10 16:50 . 2009-05-10 16:50 -------- d-----w c:\windows\system32\ar-sa
2009-05-10 16:48 . 2006-10-16 13:10 23856 ----a-w c:\windows\system32\spupdsvc.exe
2009-05-10 16:48 . 2009-05-12 04:20 -------- d--h--w c:\windows\$hf_mig$
2009-05-10 16:43 . 2009-05-10 16:43 -------- d-----w c:\program files\Common FilesMicrosoft Shared
2009-05-10 16:43 . 1998-06-17 21:00 89360 ----a-w c:\windows\system32\VB5DB.DLL
2009-05-10 16:43 . 2009-05-10 16:43 -------- d-----w c:\program files\tringkeyboard
2009-05-10 16:42 . 2009-05-10 16:42 47104 ------w c:\windows\AKDeInstall.exe
2009-05-10 16:42 . 2009-05-10 16:42 -------- d-----w c:\program files\mpegable
2009-05-10 16:42 . 2009-05-10 16:42 -------- d-----w c:\program files\VideoLAN
2009-05-10 16:21 . 2009-05-10 16:21 -------- d-----w c:\windows\speech
2009-05-10 16:20 . 2009-05-10 16:20 -------- d-----w c:\program files\Golden Al-Wafi Translator
2009-05-10 16:19 . 2009-05-10 16:19 172032 ------w c:\windows\Setup1.exe
2009-05-10 16:19 . 2009-05-10 16:19 73216 ----a-w c:\windows\ST6UNST.EXE
2009-05-10 16:18 . 2009-05-10 16:18 196608 ----a-w c:\windows\system32\maag.dll
2009-05-10 16:18 . 2009-05-10 16:18 1212416 ----a-w c:\windows\system32\ckll.dll
2009-05-10 16:18 . 2009-05-10 16:18 1245184 ----a-w c:\windows\system32\bkll.dll
2009-05-10 16:18 . 2009-05-10 16:18 1986560 ----a-w c:\windows\system32\akll.dll
2009-05-10 16:18 . 2009-05-10 16:18 2535424 ----a-w c:\windows\system32\agsaamj.dll
2009-05-10 16:18 . 2009-05-10 16:18 90112 ----a-w c:\windows\system32\agsaami.dll
2009-05-10 16:18 . 2009-05-10 16:18 610304 ----a-w c:\windows\system32\agsaamg.dll
2009-05-10 16:18 . 2009-05-10 16:18 372736 ----a-w c:\windows\system32\agsaamc.dll
2009-05-10 16:18 . 2009-05-10 16:18 53760 ----a-w c:\windows\system\ppacklib.dll
2009-05-10 16:18 . 2009-05-10 16:18 -------- d-----w c:\windows\system32\RMBin
2009-05-10 16:18 . 2009-05-10 16:18 -------- d-----w c:\program files\Real_SC
2009-05-10 16:16 . 2009-05-11 16:05 10 ----a-w c:\windows\popcinfo.dat
2009-05-10 16:16 . 2009-05-10 16:16 -------- d-----w c:\program files\PopCap Games
2009-05-10 16:15 . 2009-05-10 16:15 -------- d-----w c:\program files\Quran_in_Word
2009-05-10 16:13 . 2009-05-10 16:13 -------- d-----w c:\program files\Common Files\xing shared
2009-05-10 16:12 . 2009-05-10 16:12 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-05-10 16:12 . 2009-05-10 16:13 -------- d-----w c:\program files\Common Files\Real
2009-05-10 16:12 . 2009-05-10 16:13 -------- d-----w c:\program files\Real
2009-05-10 15:58 . 2003-04-29 18:07 306688 ----a-w c:\windows\IsUninst.exe
2009-05-10 15:58 . 2009-05-10 15:58 -------- dc----w c:\windows\system32\DRVSTORE
2009-05-10 15:56 . 2009-05-10 15:56 -------- d-----w c:\program files\Macromedia
2009-05-10 15:45 . 2009-05-10 15:45 -------- d-----w c:\program files\CyberLink
2009-05-10 15:38 . 2009-05-10 15:38 -------- d-----w c:\documents and settings\jws\Application Data\BSplayer Pro
2009-05-10 15:38 . 2009-05-10 15:38 -------- d-----w c:\documents and settings\jws\Application Data\BSplayer
2009-05-10 15:38 . 2009-05-10 15:38 -------- d-----w c:\program files\Webteh
2009-05-10 15:27 . 2009-05-11 16:21 -------- d-----w c:\documents and settings\jws\Local Settings\Application Data\Adobe
2009-05-10 15:26 . 2009-05-10 15:59 -------- d-----w c:\program files\Common Files\Adobe
2009-05-10 15:11 . 2007-01-20 18:26 1565480 ----a-w c:\windows\system32\wmv9vcm.dll
2009-05-10 15:11 . 2006-11-01 11:52 765952 ----a-w c:\windows\system32\xvidcore.dll
2009-05-10 15:11 . 2006-11-01 11:54 180224 ----a-w c:\windows\system32\xvidvfw.dll
2009-05-10 15:11 . 2007-01-30 03:03 3596288 ----a-w c:\windows\system32\qt-dx331.dll
2009-05-10 15:11 . 2007-01-30 03:03 200704 ----a-w c:\windows\system32\ssldivx.dll
2009-05-10 15:11 . 2007-01-30 03:03 1044480 ----a-w c:\windows\system32\libdivx.dll
2009-05-10 15:11 . 2007-01-30 02:56 73728 ----a-w c:\windows\system32\dpl100.dll
2009-05-10 15:11 . 2007-01-30 02:56 196608 ----a-w c:\windows\system32\dtu100.dll
2009-05-10 15:11 . 2007-02-01 02:56 639066 ----a-w c:\windows\system32\divx.dll
2009-05-10 15:11 . 2007-01-09 15:46 10752 ----a-w c:\windows\system32\ff_vfw.dll
2009-05-10 15:11 . 2009-05-10 16:12 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-05-10 15:11 . 2009-05-10 15:11 -------- d-----w c:\program files\K-Lite Codec Pack
2009-05-10 14:32 . 2004-08-03 20:08 26496 -c--a-w c:\windows\system32\dllcache\usbstor.sys
2009-05-10 14:32 . 2009-05-10 14:32 -------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-05-10 14:01 . 2003-06-18 14:31 17920 ----a-w c:\windows\system32\mdimon.dll
2009-05-10 14:00 . 2009-05-10 14:00 -------- d-----w c:\program files\Microsoft.NET
2009-05-10 13:59 . 2009-05-10 13:59 -------- d-----w c:\program files\Microsoft Works
2009-05-10 13:58 . 2009-05-10 14:00 -------- d-----w c:\windows\SHELLNEW
2009-05-10 13:56 . 2009-05-10 13:56 -------- d--h--r C:\MSOCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-13 22:37 . 2009-05-10 17:05 7240 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-13 22:37 . 2009-05-10 17:05 1892 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-12 09:49 . 2009-05-09 17:53 101408 ----a-w c:\documents and settings\jws\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-12 04:31 . 2009-05-10 15:53 -------- d-----w c:\program files\JetAudio
2009-05-11 18:53 . 2009-05-09 17:38 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-11 11:41 . 2008-01-29 15:29 33808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-05-10 17:26 . 2004-08-03 21:55 218624 ----a-w c:\windows\system32\uxtheme.dll
2009-05-10 17:26 . 2004-08-03 21:56 1949184 ----a-w c:\windows\system32\logonui.exe
2009-05-10 15:56 . 2009-05-09 19:49 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-10 15:54 . 2009-05-10 15:53 -------- d-----w c:\program files\The KMPlayer
2009-05-10 15:53 . 2009-05-10 15:53 2232 ----a-w c:\windows\java\Packages\Data\RP77VH7F.DAT
2009-05-10 15:53 . 2009-05-10 15:53 155995 ----a-w c:\windows\java\Packages\9BP7VBFZ.ZIP
2009-05-10 15:53 . 2009-05-10 15:53 2678 ----a-w c:\windows\java\Packages\Data\CGCFPRX3.DAT
2009-05-10 15:53 . 2009-05-10 15:53 2678 ----a-w c:\windows\java\Packages\Data\BV9JLNJV.DAT
2009-05-10 15:53 . 2009-05-10 15:53 2678 ----a-w c:\windows\java\Packages\Data\JJVBHVXZ.DAT
2009-05-10 15:53 . 2009-05-10 15:53 2678 ----a-w c:\windows\java\Packages\Data\B31NFR9F.DAT
2009-05-10 15:53 . 2009-05-10 15:53 2678 ----a-w c:\windows\java\Packages\Data\8U0BZ9ZP.DAT
2009-05-09 20:23 . 2009-05-09 19:47 -------- d-----w c:\program files\Common Files\InstallShield
2009-05-09 19:53 . 2009-05-09 19:53 -------- d-----w c:\program files\Silicon Integrated Systems
2009-05-09 19:50 . 2009-05-09 19:48 -------- d-----w c:\program files\SiS VGA Utilities V3.61a
2009-05-09 17:52 . 2001-09-19 12:00 39982 ----a-w c:\windows\system32\perfc001.dat
2009-05-09 17:52 . 2001-09-19 12:00 251478 ----a-w c:\windows\system32\perfh001.dat
2009-05-09 17:39 . 2009-05-09 17:39 -------- d-----w c:\program files\microsoft frontpage
2009-05-09 17:38 . 2001-09-19 12:00 67 --sha-w c:\windows\Fonts\desktop.ini
2009-05-09 17:35 . 2009-05-09 17:35 22144 ----a-w c:\windows\system32\emptyregdb.dat
2009-03-26 15:35 . 2009-05-07 07:42 210352 ----a-w c:\windows\system32\idmmbc.dll
2009-03-13 21:25 . 2009-04-25 03:55 25088 ----a-w c:\windows\system32\msxml3a.dll
.
------- Sigcheck -------
[-] 2009-05-10 17:31 1655296 2FD48AAEAEC9C891F72277BBE701F5DB c:\windows\explorer.exe
[-] 2009-05-10 17:31 1655296 2FD48AAEAEC9C891F72277BBE701F5DB c:\windows\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-05-07 2807216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSRaid"="c:\program files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe" [2004-12-22 892928]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-10 185896]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-05-11 206088]
"VistaStart1.3"="c:\windows\Resources\Themes\Vista_Anthracite\VistaStart\VistaStart1.3.exe" [2006-03-20 510464]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-12-01 77824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-5-10 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2009-4-25 11057664]
Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-5-9 331776]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4830:UDP"= 4830:UDP:Windows Media Format SDK (firefox.exe)
"4831:UDP"= 4831:UDP:Windows Media Format SDK (firefox.exe)
"4832:UDP"= 4832:UDP:Windows Media Format SDK (firefox.exe)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [29/01/2008 06:29 م 33808]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [30/04/2008 06:06 م 24592]
S2 gupdate1c9d2e9ef8fb89a;خدمة تحديث Google (gupdate1c9d2e9ef8fb89a);c:\program files\Google\Update\GoogleUpdate.exe [12/05/2009 01:10 م 133104]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a425c7a-3d6f-11de-a98c-000feacbd09c}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL system.exe
\Shell\Explore\command - F:\system.exe
\Shell\Open\command - F:\system.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a425c7b-3d6f-11de-a98c-000feacbd09c}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL system.exe
\Shell\Explore\command - F:\system.exe
\Shell\Open\command - F:\system.exe
.
Contents of the 'Scheduled Tasks' folder
2009-05-13 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-12 10:10]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - c:\program files\************\tb4sha.dll
Toolbar-{09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - c:\program files\************\tb4sha.dll
WebBrowser-{09EC805C-CB2E-4D53-B0D3-A75A428B81C7} - c:\program files\************\tb4sha.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2233703
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\jws\Application Data\Mozilla\Firefox\Profiles\
0p1wnn5g.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2233703&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - 4shared Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2233703&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2233703&SearchSource=2&q=
FF - component: c:\documents and settings\jws\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - component: c:\documents and settings\jws\Application Data\Mozilla\Firefox\Profiles\
0p1wnn5g.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}\components\FFExternalAlert.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-14 01:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(800)
c:\windows\system32\cscui.dll
- - - - - - - > 'explorer.exe'(1380)
c:\windows\system32\msi.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-13 1:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-13 22:41
Pre-Run: 13,698,011,136 bytes free
Post-Run: 13,878,992,896 bytes free
250