ComboFix 13-09-08.02 - Joanna 09/09/2013 1:38.8.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2047.1285 [GMT 2:00] Running from: c:\documents and settings\Joanna\Desktop\MK\ComboFix.exe . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\All Users\Application Data\BrowserDefender c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\bl c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.settings c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\dm c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\FirefoxExtension\bprotector.js c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\00 c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\01 c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\02 c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\03 c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\10 c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\11 c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\12 c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\13 c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\20 c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\21 c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\22 c:\documents and settings\All Users\Application Data\BrowserDefender\2.6.1519.190\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\traking_settings\23 c:\documents and settings\Joanna\Local Settings\Application Data\lollipop c:\documents and settings\Joanna\Local Settings\Application Data\lollipop\logo.ico c:\documents and settings\Joanna\Local Settings\Application Data\lollipop\lollipop.bat c:\documents and settings\Joanna\Local Settings\Application Data\lollipop\Lollipop.exe c:\documents and settings\Joanna\Local Settings\Application Data\lollipop\lollipop.lpd c:\documents and settings\Joanna\Local Settings\Application Data\lollipop\lollipop_cfg.lpd c:\documents and settings\Joanna\Local Settings\Application Data\lollipop\lollipop_ps.lpd c:\documents and settings\Joanna\Local Settings\Application Data\Minibar c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome.pem c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\background.html c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\cached_http_request.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\extension_info.json c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\icons\icon128.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\icons\icon19.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\icons\icon32.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\icons\icon48.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\includes\content.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\includes\content_kango.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\includes\content_menu.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\includes\content_messaging.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\includes\content_pageutils.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\includes\content_popup.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\includes\content_toolbar.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\includes\content_toolbar_customfixes.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\includes\content_userscript.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango-ui\button.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango-ui\toolbar.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango-ui\ui.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango\browser.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango\console.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango\event_listener.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango\initialize.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango\io.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango\jsonstorage.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango\kango.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango\lang.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango\messaging.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango\userscript_engine.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\kango\xhr.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\main.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\manifest.json c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\minibar\actions.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\minibar\cachedxhr.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\minibar\config.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\minibar\macros.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\minibar\minibar.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\MinibarPlugin.dll c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\popup.html c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\popup.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\tab.html c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome\tab.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\chrome_installer.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\common.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome.manifest c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\content.xul c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\extension_info.json c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\icons\icon128.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\icons\icon19.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\icons\icon32.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\icons\icon48.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\initial_config.json c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\button.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\popup.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\popup_window.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\popup_window.xul c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\bottom-left.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\bottom-middle.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\bottom-right.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\middle-left.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\middle-right.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\style.css c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\tail-bottom.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\tail-left.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\tail-right.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\tail-top.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\top-left.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\top-middle.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\theme\bubble\top-right.png c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\toolbar.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\toolbar_stub.html c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango-ui\ui.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\browser.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\console.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\event_listener.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\initialize.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\io.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\jsonstorage.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\kango.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\lang.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\messaging.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\storage.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\uninstall_observer.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\userscript_engine.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\kango\xhr.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\main.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\actions.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\cachedxhr.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\config.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\homepage_helper.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\macros.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\minibar.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\search_helper.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\search_hook.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\chrome\content\minibar\tabpage_helper.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\install.rdf c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox\plugins\npMinibarPlugin.dll c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\firefox_installer.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\ie_installer.js c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\minibar.crx c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\minibar.xpi c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\SettingsHelper.exe c:\documents and settings\Joanna\Local Settings\Application Data\Minibar\Uninstall.exe c:\program files\Delta\delta\1.8.24.6\bh\delta.dll c:\program files\Delta\delta\1.8.24.6\deltaApp.dll c:\program files\Delta\delta\1.8.24.6\deltaEng.dll c:\program files\Delta\delta\1.8.24.6\deltasrv.exe c:\program files\Delta\delta\1.8.24.6\deltaTlbr.dll c:\windows\system32\Cache c:\windows\system32\Cache\075884af680ff6dc.fb c:\windows\system32\Cache\227113dfa1ca894d.fb c:\windows\system32\Cache\49fbbc5a8678d502.fb c:\windows\system32\Cache\55e1ce73480af9d0.fb c:\windows\system32\Cache\5c54eb1a1655b076.fb c:\windows\system32\Cache\613e8ce7ab7106af.fb c:\windows\system32\Cache\633a76311867bd11.fb c:\windows\system32\Cache\691f14230153a9e1.fb c:\windows\system32\Cache\6cb409d7ac73d9f1.fb c:\windows\system32\Cache\7614bd6cfa99e546.fb c:\windows\system32\Cache\77664b6ccc36be9f.fb c:\windows\system32\Cache\881b3593316772f0.fb c:\windows\system32\Cache\98657d0579ae1930.fb c:\windows\system32\Cache\d5c0f4e7bbe35bf3.fb c:\windows\system32\Cache\d9ca663388d21ec0.fb c:\windows\system32\Cache\f2cda51fd108941f.fb c:\windows\system32\Cache\f34d8db84131d925.fb . . ((((((((((((((((((((((((( Files Created from 2013-08-08 to 2013-09-08 ))))))))))))))))))))))))))))))) . . 2013-09-08 19:01 . 2013-09-08 19:18 16046 ----a-w- c:\windows\system32\drivers\fvstore.dat 2013-09-08 19:01 . 2013-09-08 19:01 -------- d-----w- C:\VTRoot 2013-09-08 15:16 . 2013-09-08 15:16 -------- d-----w- c:\program files\Delta 2013-09-08 15:16 . 2013-09-08 15:16 -------- d-----w- c:\documents and settings\Joanna\Application Data\Delta 2013-09-08 15:15 . 2013-09-08 15:15 -------- d-----w- c:\documents and settings\Joanna\Application Data\BabSolution 2013-09-08 15:15 . 2013-09-08 15:15 -------- d-----w- c:\documents and settings\Joanna\Application Data\Babylon 2013-09-08 15:13 . 2013-09-08 15:13 -------- d-----w- c:\documents and settings\Joanna\Local Settings\Application Data\AppsHat Mobile Apps 2013-09-08 15:13 . 2013-09-08 15:34 -------- d-----w- c:\documents and settings\Joanna\Local Settings\Application Data\WebPlayer 2013-09-08 15:13 . 2013-09-08 15:13 -------- d-----w- c:\program files\Minibar 2013-09-08 15:12 . 2013-09-08 15:12 -------- d-----w- c:\documents and settings\Joanna\Local Settings\Application Data\FilesFrog Update Checker 2013-09-07 10:21 . 2013-09-07 10:22 -------- d-----w- c:\program files\PDF Architect 2013-09-07 10:20 . 2013-09-07 10:20 -------- d-----w- c:\documents and settings\Joanna\Local Settings\Application Data\AVG SafeGuard toolbar 2013-09-07 10:20 . 2012-05-05 09:54 137000 ----a-w- c:\windows\system32\MSMAPI32.OCX 2013-09-07 10:20 . 2012-05-05 09:54 662288 ----a-w- c:\windows\system32\MSCOMCT2.OCX 2013-09-07 10:20 . 2012-05-05 09:54 23552 ----a-w- c:\windows\system32\MSMPIDE.DLL 2013-09-07 10:19 . 2013-09-07 10:19 -------- d-----w- c:\documents and settings\Joanna\Application Data\AVG SafeGuard toolbar 2013-09-07 10:19 . 2013-09-08 14:48 37664 ----a-w- c:\windows\system32\drivers\avgtpx86.sys 2013-09-07 10:19 . 2013-09-07 10:19 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG SafeGuard toolbar 2013-09-07 10:19 . 2013-09-07 10:19 -------- d-----w- c:\program files\Common Files\AVG Secure Search 2013-09-07 10:19 . 2013-09-08 14:48 -------- d-----w- c:\program files\AVG SafeGuard toolbar 2013-09-04 07:27 . 2013-09-04 07:27 -------- d-----w- c:\documents and settings\All Users\GlarySoft 2013-09-04 07:26 . 2013-09-04 07:26 -------- d-----w- c:\documents and settings\All Users\Application Data\GlarySoft 2013-09-03 23:18 . 2013-09-03 23:18 -------- d-----w- c:\documents and settings\Joanna\dwhelper 2013-09-03 22:57 . 2013-09-04 04:59 -------- d-----w- c:\documents and settings\Joanna\Application Data\Apple Computer 2013-09-03 22:53 . 2013-09-03 22:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll 2013-09-03 22:53 . 2013-09-03 22:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll 2013-09-03 22:53 . 2013-09-03 22:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll 2013-09-03 22:53 . 2013-09-03 22:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll 2013-09-03 22:53 . 2013-09-03 22:54 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll 2013-09-03 22:53 . 2013-09-03 22:53 159744 ----a-w- c:\program files\Internet Explorer\Wtyczki\npqtplugin5.dll 2013-09-03 22:53 . 2013-09-03 22:52 159744 ----a-w- c:\program files\Internet Explorer\Wtyczki\npqtplugin4.dll 2013-09-03 22:53 . 2013-09-03 22:52 159744 ----a-w- c:\program files\Internet Explorer\Wtyczki\npqtplugin3.dll 2013-09-03 22:53 . 2013-09-03 22:52 159744 ----a-w- c:\program files\Internet Explorer\Wtyczki\npqtplugin2.dll 2013-09-03 22:53 . 2013-09-03 22:52 159744 ----a-w- c:\program files\Internet Explorer\Wtyczki\npqtplugin.dll 2013-09-03 22:52 . 2013-09-03 22:52 -------- d-----w- c:\program files\QuickTime 2013-09-03 22:52 . 2013-09-03 22:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer 2013-09-03 22:49 . 2013-09-03 22:49 -------- d-----w- c:\documents and settings\Joanna\Local Settings\Application Data\Apple 2013-09-03 22:49 . 2013-09-03 22:49 -------- d-----w- c:\program files\Apple Software Update 2013-09-03 22:49 . 2013-09-03 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple 2013-09-01 14:35 . 2013-09-01 14:35 -------- d-----w- c:\program files\Defraggler 2013-08-28 20:45 . 2013-08-28 20:48 -------- d-----w- c:\program files\Autostart Kreator 2.5 2013-08-27 18:51 . 2013-08-27 19:14 -------- d-----w- c:\program files\ArtixMedia Menu Studio 2013-08-26 18:57 . 2013-08-26 18:57 -------- d-----w- c:\documents and settings\Joanna\Local Settings\Application Data\WinAVI 2013-08-26 18:57 . 2013-08-26 18:57 -------- d-----w- c:\windows\WinAVI Video Converter 9.0 2013-08-26 18:57 . 2013-08-26 18:57 -------- d-----w- c:\program files\WinAVI Video Converter 9.0 2013-08-26 18:32 . 2013-08-26 18:34 -------- d-----w- c:\program files\AviSynth 2.5 2013-08-25 20:30 . 2013-08-25 20:30 -------- d-----w- c:\documents and settings\Joanna\.thumb 2013-08-25 08:27 . 2013-09-08 23:45 664352 ----a-w- c:\windows\system32\drivers\sfi.dat 2013-08-25 08:24 . 2013-08-25 08:24 -------- d-----w- c:\program files\COMODO 2013-08-25 08:23 . 2013-08-25 08:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo 2013-08-25 08:23 . 2013-08-25 08:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo Downloader 2013-08-21 08:39 . 2013-08-21 08:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Ashampoo 2013-08-21 08:39 . 2013-08-21 08:39 -------- d-----w- c:\program files\Ashampoo 2013-08-19 20:03 . 2013-08-19 20:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Auslogics 2013-08-19 20:03 . 2013-09-01 14:32 -------- d-----w- c:\program files\Auslogics 2013-08-18 14:33 . 2013-08-18 14:36 -------- d-----w- c:\program files\Sony Media Go Install 2013-08-14 18:48 . 2013-08-14 18:52 -------- d-----w- c:\windows\system32\MRT 2013-08-13 07:07 . 2013-08-13 07:07 -------- d-----w- c:\documents and settings\Joanna\Application Data\0P1C1F1N1C1T1H1BtF1E1I 2013-08-13 07:07 . 2013-08-13 07:07 -------- d-----w- c:\documents and settings\All Users\Application Data\eSafe 2013-08-13 07:07 . 2013-08-13 07:07 -------- d-----w- c:\documents and settings\Joanna\Application Data\eIntaller 2013-08-13 06:56 . 2013-08-13 07:20 -------- d-----w- c:\documents and settings\All Users\Application Data\architekt3d . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-08-25 09:30 . 2012-01-21 20:47 13120 ----a-w- c:\windows\system32\drivers\StarOpen.sys 2013-08-20 18:30 . 2012-05-02 09:49 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-08-20 18:30 . 2012-02-27 13:24 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-08-03 12:18 . 2006-10-18 21:47 1543680 ------w- c:\windows\system32\wmvdecod.dll 2013-08-02 17:29 . 2011-09-09 16:39 217176 ----a-w- c:\windows\system32\unrar.dll 2013-07-26 02:47 . 2008-04-14 04:42 920064 ----a-w- c:\windows\system32\wininet.dll 2013-07-26 02:47 . 2008-04-14 04:41 43520 ----a-w- c:\windows\system32\licmgr10.dll 2013-07-26 02:47 . 2008-04-14 04:42 1469440 ----a-w- c:\windows\system32\inetcpl.cpl 2013-07-25 15:52 . 2008-04-13 23:07 385024 ----a-w- c:\windows\system32\html.iec 2013-07-10 10:37 . 2008-04-14 04:42 406016 ----a-w- c:\windows\system32\usp10.dll 2013-07-04 03:03 . 2008-04-13 23:54 2149888 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-07-04 02:08 . 2008-04-14 00:01 2028544 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-06-12 19:48 . 2012-09-20 10:05 867240 ----a-w- c:\windows\system32\npdeployJava1.dll 2013-06-12 19:48 . 2010-09-17 18:53 789416 ----a-w- c:\windows\system32\deployJava1.dll 2013-06-12 19:48 . 2013-06-19 17:10 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-06-12 19:35 . 2012-09-20 10:05 144896 ----a-w- c:\windows\system32\javacpl.cpl 2012-10-20 12:17 . 2012-10-20 12:18 730121 ----a-w- c:\program files\Common Files\unins000.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2010-07-28 1267024] . [HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1] [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}] [HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch] . [HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] 2013-09-08 14:48 3122864 ----a-w- c:\program files\AVG SafeGuard toolbar\15.5.0.2\AVG SafeGuard toolbar_toolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG SafeGuard toolbar\15.5.0.2\AVG SafeGuard toolbar_toolbar.dll" [2013-09-08 3122864] . [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}] [HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj.1] [HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "UIHost"="c:\windows\system32\logonui.exe" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppsHat] 2012-10-26 06:49 202752 ----a-w- c:\documents and settings\Joanna\Local Settings\Application Data\WebPlayer\AppsHat\WebPlayer.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2013-04-21 19:43 59720 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2008-04-14 04:42 15360 ----a-w- c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPLA!] 2013-03-13 16:47 21047208 ----a-w- c:\program files\ipla\ipla.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PAC7302_Monitor] 2006-11-03 10:01 319488 ------w- c:\windows\PixArt\PAC7302\Monitor.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2013-05-01 01:59 421888 ----a-w- c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDP] 2013-01-31 14:10 201808 ----a-w- c:\documents and settings\Joanna\Local Settings\Application Data\FilesFrog Update Checker\update_checker.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2013-06-21 07:58 19875432 ----a-r- c:\program files\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipCheapCom] 2013-06-11 07:54 19547464 ----a-w- c:\program files\VoipCheapCom\voipcheapcom.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt] 2013-09-08 14:48 2314416 ----a-w- c:\program files\AVG SafeGuard toolbar\vprot.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] 2012-06-28 15:40 74752 ----a-w- c:\program files\Winamp\winampa.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "SkypeUpdate"=2 (0x2) "Skype C2C Service"=2 (0x2) "AdobeFlashPlayerUpdateSvc"=3 (0x3) "WPFFontCache_v0400"=3 (0x3) "WMPNetworkSvc"=3 (0x3) "WmiApSrv"=3 (0x3) "VSS"=3 (0x3) "UPS"=3 (0x3) "SysmonLog"=3 (0x3) "SwPrv"=3 (0x3) "Sony PC Companion"=3 (0x3) "RSVP"=3 (0x3) "Microsoft Office Groove Audit Service"=3 (0x3) "hpqddsvc"=2 (0x2) "hkmsvc"=3 (0x3) "ClipSrv"=3 (0x3) "CiSvc"=3 (0x3) "BITS"=3 (0x3) "BBUpdate"=3 (0x3) "BBSvc"=2 (0x2) "AppMgmt"=3 (0x3) "ALG"=3 (0x3) "Spooler"=2 (0x2) . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "ctfmon.exe"=c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "nwiz"=nwiz.exe /install "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime . [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\VoipCheapCom\\VoipCheapCom.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Gadu-Gadu\\gg.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"= "c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"= "c:\\Program Files\\YourFileDownloader\\YourFile.exe"= "c:\\Documents and Settings\\Joanna\\Application Data\\BitTorrent\\BitTorrent.exe"= "c:\\Program Files\\Winamp\\winamp.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Sony Ericsson\\Update Engine\\Sony Ericsson Update Engine.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "443:TCP"= 443:TCP:War Thunder "20010:UDP"= 20010:UDP:War Thunder "3478:UDP"= 3478:UDP:War Thunder "7850:TCP"= 7850:TCP:War Thunder "27022:TCP"= 27022:TCP:War Thunder "6881:TCP"= 6881:TCP:War Thunder "33333:TCP"= 33333:TCP:War Thunder "20443:TCP"= 20443:TCP:War Thunder "8090:TCP"= 8090:TCP:War Thunder . R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [20/08/2012 06:51 18544] R1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [07/09/2013 12:19 37664] R2 NAUpdate;@c:\program files\Nero\Update\NASvc.exe,-200;c:\program files\Nero\Update\NASvc.exe [29/03/2011 16:33 598312] R2 PDF Architect Helper Service;PDF Architect Helper Service;c:\program files\PDF Architect\HelperService.exe [08/04/2013 18:44 1320496] R2 vToolbarUpdater15.5.0;vToolbarUpdater15.5.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe [08/09/2013 16:49 1643184] S2 PDF Architect Service;PDF Architect Service;c:\program files\PDF Architect\ConversionService.exe [08/04/2013 18:43 799280] S4 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.391.0\BBSvc.EXE [11/06/2012 17:22 193616] S4 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.391.0\SeaPort.EXE [11/06/2012 17:22 240208] S4 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [14/08/2013 11:10 3291008] S4 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [21/06/2013 09:53 162408] S4 Sony PC Companion;Sony PC Companion;c:\program files\Sony\Sony PC Companion\PCCService.exe [30/05/2013 17:41 155824] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder . 2013-09-08 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-02 18:31] . 2013-09-03 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57] . 2013-09-08 c:\windows\Tasks\YourFile DownloaderUpdate.job - c:\program files\YourFileDownloader\YourFileUpdater.exe [2012-11-28 18:49] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www2.delta-search.com/?babsrc=HP_ss&mntrId=9C3A001A4D0E6349&affID=119357&tt=080913_nch&tsp=4999 uInternet Connection Wizard,ShellNext = iexplore uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 TCP: DhcpNameServer = 87.204.204.204 62.233.233.233 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\15.5.0\ViProtocol.dll FF - ProfilePath - c:\documents and settings\Joanna\Application Data\Mozilla\Firefox\Profiles\btuy0sva.default\ FF - prefs.js: browser.startup.homepage - hxxp://www2.delta-search.com/?babsrc=HP_ss&mntrId=9C3A001A4D0E6349&affID=119357&tt=080913_nch&tsp=4999 FF - prefs.js: keyword.URL - FF - ExtSQL: 2013-08-07 12:41; ffxtlbr@delta.com; c:\documents and settings\Joanna\Application Data\Mozilla\Firefox\Profiles\btuy0sva.default\extensions\ffxtlbr@delta.com FF - ExtSQL: 2013-09-04 01:21; paulsaintuzb@gmail.com; c:\documents and settings\Joanna\Application Data\Mozilla\Firefox\Profiles\btuy0sva.default\extensions\paulsaintuzb@gmail.com.xpi FF - ExtSQL: 2013-09-07 12:19; avg@toolbar; c:\documents and settings\All Users\Application Data\AVG SafeGuard toolbar\FireFoxExt\15.5.0.2 FF - ExtSQL: 2013-09-07 12:22; FFPDFArchitectConverter@pdfarchitect.com; c:\program files\PDF Architect\FFPDFArchitectExt FF - ExtSQL: 2013-09-08 17:13; {97A78363-B868-4B48-AC91-A783A31215AF}; c:\documents and settings\Joanna\Application Data\Mozilla\Firefox\Profiles\btuy0sva.default\extensions\{97A78363-B868-4B48-AC91-A783A31215AF} FF - ExtSQL: !HIDDEN! 2012-09-20 12:48; smartwebprinting@hp.com; c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 FF - user.js: yahoo.homepage.dontask - true FF - user.js: extensions.claro.tlbrSrchUrl - FF - user.js: extensions.claro.id - 9c3a1b8c000000000000001a4d0e6349 FF - user.js: extensions.claro.appId - {C3110516-8EFC-49D6-8B72-69354F332062} FF - user.js: extensions.claro.instlDay - 15645 FF - user.js: extensions.claro.vrsn - 1.8.3.10 FF - user.js: extensions.claro.vrsni - 1.8.3.10 FF - user.js: extensions.claro_i.vrsnTs - 1.8.3.1012:48 FF - user.js: extensions.claro.prtnrId - claro FF - user.js: extensions.claro.prdct - claro FF - user.js: extensions.claro.aflt - babsst FF - user.js: extensions.claro_i.smplGrp - none FF - user.js: extensions.claro.tlbrId - claro FF - user.js: extensions.claro.instlRef - sst FF - user.js: extensions.claro.dfltLng - en FF - user.js: extensions.claro.excTlbr - false FF - user.js: extensions.claro.admin - false FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 FF - user.js: extensions.delta.tlbrSrchUrl - FF - user.js: extensions.delta.id - 9c3a1b8c000000000000001a4d0e6349 FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} FF - user.js: extensions.delta.instlDay - 15956 FF - user.js: extensions.delta.vrsn - 1.8.24.6 FF - user.js: extensions.delta.vrsni - 1.8.24.6 FF - user.js: extensions.delta.vrsnTs - 1.8.24.617:16 FF - user.js: extensions.delta.prtnrId - delta FF - user.js: extensions.delta.prdct - delta FF - user.js: extensions.delta.aflt - babsst FF - user.js: extensions.delta.smplGrp - none FF - user.js: extensions.delta.tlbrId - base FF - user.js: extensions.delta.instlRef - sst FF - user.js: extensions.delta.dfltLng - en FF - user.js: extensions.delta.excTlbr - false FF - user.js: extensions.delta.ffxUnstlRst - true FF - user.js: extensions.delta.admin - false FF - user.js: extensions.delta_i.babTrack - affID=119357&tt=080913_nch&tsp=4999 FF - user.js: extensions.delta_i.babExt - FF - user.js: extensions.delta_i.srcExt - ss FF - user.js: extensions.delta.autoRvrt - false FF - user.js: extensions.delta.rvrt - false FF - user.js: extensions.delta.newTab - false . - - - - ORPHANS REMOVED - - - - . MSConfigStartUp-COMODO Internet Security - c:\program files\COMODO\COMODO Internet Security\cistray.exe MSConfigStartUp-lollipop - c:\documents and settings\joanna\local settings\application data\lollipop\lollipop.exe AddRemove-lollipop - c:\documents and settings\joanna\local settings\application data\lollipop\lollipop.bat . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2013-09-09 01:48 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'lsass.exe'(952) c:\windows\system32\guard32.dll c:\windows\system32\mswsock.dll c:\windows\System32\wshtcpip.dll . - - - - - - - > 'csrss.exe'(772) c:\windows\system32\cmdcsr.dll . Completion time: 2013-09-09 01:51:00 ComboFix-quarantined-files.txt 2013-09-08 23:50 ComboFix2.txt 2013-03-03 16:19 ComboFix3.txt 2013-01-13 21:01 ComboFix4.txt 2012-12-23 08:21 ComboFix5.txt 2013-03-07 16:49 . Pre-Run: 163,191,078,912 bytes free Post-Run: 163,479,044,096 bytes free . - - End Of File - - 2ADC84660D2D92DEDDEB9F535B607BF6 8F558EB6672622401DA993E1E865C861