
mam blad bo pisze blad systemu i musze resnoc kompa a pozniej jest taki blad winlogon.exe
log hijackthis
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:48:09, on 2008-01-26
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\cFosSpeed\spd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\OneStepSearch\onestep.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\OneStepSearch\onestep.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\DU Meter\DUMeter.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\cFosSpeed\cFosSpeed.exe
E:\GG\Gadu-Gadu\gg.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Opera\Opera.exe
E:\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *gg.muchina.com;*update.nprotect.net;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: TweakMASTER PRO Component - {7DAAC7DE-9EF0-4FF0-BFA5-AFF3E899054C} - C:\PROGRA~1\TWEAKM~1\TweakBHO.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [cFosSpeed] C:\Program Files\cFosSpeed\cFosSpeed.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "E:\GG\Gadu-Gadu\gg.exe" /tray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetupo.dll" "%SystemRoot%\System32\syssetup.dll" (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetupo.dll" "%SystemRoot%\System32\syssetup.dll" (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetupo.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetupo.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
O8 - Extra context menu item: Add to &LinkFox - res://C:\PROGRA~1\TWEAKM~1\TweakBHO.dll/IESCRIPT
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} - http://www.mks.com.pl/skaner/SkanerOnline.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{23BA6566-3066-4C9E-A755-77CE7C2D67A9}: NameServer = 217.17.34.10,195.116.217.32
O17 - HKLM\System\CCS\Services\Tcpip\..\{2FB63434-3201-4E1A-92B4-B305F3F6ED58}: NameServer = 194.204.159.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: cFosSpeed System Service (cFosSpeedS) - cFos Software GmbH - C:\Program Files\cFosSpeed\spd.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Harmonogram automatycznej usługi LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OneStep Search Service - OneStepSearch.net, Inc. - C:\Program Files\OneStepSearch\onestep.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 6810 bytes
combofix
- Kod: Zaznacz wszystko
ComboFix 08-01-23.1C - fdffd 2008-01-26 14:55:54.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.212 [GMT 1:00]
Running from: E:\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\cpuinf32.dll
C:\WINDOWS\system32\DivX.dll
C:\WINDOWS\system32\iconv.dll
C:\WINDOWS\system32\ir50_32.dll
C:\WINDOWS\system32\mplvpx.dll
C:\WINDOWS\system32\ogg.dll
C:\WINDOWS\system32\OggDS.dll
C:\WINDOWS\system32\vorbis.dll
C:\WINDOWS\system32\vorbisenc.dll
C:\WINDOWS\system32\WMV9VCM.dll
.
((((((((((((((((((((((((( Files Created from 2007-12-26 to 2008-01-26 )))))))))))))))))))))))))))))))
.
2008-01-25 18:52 . 2008-01-25 18:52 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-01-25 18:50 . 2008-01-25 18:51 <DIR> d-------- C:\Program Files\Alloy
2008-01-25 18:46 . 2008-01-25 21:00 <DIR> d-------- C:\Program Files\OneStepSearch
2008-01-25 18:46 . 2001-09-06 10:00 1,700,352 --a------ C:\WINDOWS\system32\gdiplus.dll
2008-01-25 18:46 . 2007-06-25 14:02 475,136 --a------ C:\WINDOWS\system32\SkinCrafter2.dll
2008-01-25 17:19 . 2008-01-25 17:19 <DIR> d-------- C:\Program Files\Yamicsoft
2008-01-25 16:18 . 2005-08-27 02:38 1,435,272 --a------ C:\WINDOWS\system32\Flash.ocx
2008-01-25 16:18 . 2002-03-04 12:27 1,140,472 --a------ C:\WINDOWS\system32\IGUltraGrid20.ocx
2008-01-25 16:18 . 2003-11-19 13:59 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2008-01-25 16:18 . 2004-03-08 23:00 131,856 --a------ C:\WINDOWS\system32\MSADODC.ocx
2008-01-25 16:18 . 1999-01-26 19:36 11,012 --a------ C:\WINDOWS\system32\threadapi.tlb
2008-01-25 16:07 . 2007-12-14 20:57 710,872 -ra------ C:\WINDOWS\system32\drivers\cfosspeed.sys
2008-01-25 16:06 . 2007-12-14 20:57 298,200 --a------ C:\WINDOWS\system32\cfosspeed.dll
2008-01-23 15:15 . 2008-01-23 15:15 <DIR> d-------- C:\Program Files\TweakMASTER
2008-01-23 14:42 . 2008-01-23 14:49 <DIR> d-------- C:\Program Files\Microsoft Bootvis
2008-01-23 14:16 . 2008-01-23 14:16 <DIR> d-------- C:\Program Files\Systweak BoostXP2
2008-01-23 14:16 . 2007-10-24 14:45 2,419,200 --a------ C:\WINDOWS\system32\PhotoExplorer2.scr
2008-01-20 10:03 . 2008-01-20 17:27 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-01-19 20:22 . 2008-01-24 08:02 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-01-19 20:22 . 2008-01-24 08:03 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-01-19 18:47 . 2008-01-19 18:48 <DIR> d-------- C:\Program Files\DAEMON Tools
2008-01-15 17:54 . 2008-01-15 17:54 <DIR> d-------- C:\Program Files\IObit
2008-01-15 15:43 . 2008-01-15 17:52 <DIR> d-------- C:\Program Files\Norton SystemWorks Premier
2008-01-15 15:41 . 2008-01-15 17:53 <DIR> d-------- C:\Program Files\Symantec
2008-01-15 15:40 . 2008-01-15 17:53 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-01-14 13:35 . 2008-01-14 14:13 <DIR> d-------- C:\Program Files\Common Files\Blizzard Entertainment
2008-01-14 10:29 . 2008-01-14 10:30 <DIR> d-------- C:\Program Files\Avant Browser
2008-01-13 16:21 . 2008-01-26 14:56 <DIR> d-------- C:\Program Files\cFosSpeed
2008-01-02 13:20 . 2008-01-02 13:20 2,359,350 --a------ C:\WINDOWS\BricoPack Wallpaper.bmp
2008-01-02 13:20 . 2008-01-02 13:20 65,102 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-01-02 13:18 . 2008-01-02 13:18 <DIR> d-------- C:\WINDOWS\BricoPacks
2008-01-02 13:18 . 2008-01-02 13:20 6,114 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2007-12-30 09:48 . 2007-12-30 09:48 <DIR> d-------- C:\Downloaded
2007-12-28 21:36 . 2007-12-28 21:36 <DIR> d-------- C:\Program Files\BearShare Applications
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-18 06:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-02 12:20 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-01-01 18:40 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-01-01 18:40 249,856 ------w C:\WINDOWS\Setup1.exe
2007-12-25 16:47 --------- d-----w C:\Program Files\Opera
2007-12-24 07:53 --------- d-----w C:\Program Files\Samsung
2007-12-21 15:09 --------- d-----w C:\Program Files\VideoLAN
2007-12-21 15:06 --------- d-----w C:\Program Files\Google
2007-12-20 18:09 --------- d-----w C:\Program Files\Winamp Remote
2007-12-20 18:09 --------- d-----w C:\Program Files\Winamp
2007-12-20 15:56 --------- d-----w C:\Program Files\Windows Media Components
2007-12-20 15:52 --------- d-----w C:\Program Files\MarBit
2007-11-23 19:12 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-11-07 09:29 723,968 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-31 18:57 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-10-29 22:44 1,291,264 ----a-w C:\WINDOWS\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
2007-12-02 15:13 394680 --a------ C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="E:\GG\Gadu-Gadu\gg.exe" [2008-01-23 15:07 2119104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2005-07-20 20:07 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-07-20 20:07 86016]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50 155648]
"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [2006-11-27 15:19 1582616]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-07-20 20:07 7110656]
"SoundMan"="SOUNDMAN.EXE" [2006-07-21 15:14 86016 C:\WINDOWS\SoundMan.exe]
"cFosSpeed"="C:\Program Files\cFosSpeed\cFosSpeed.exe" [2007-12-14 20:57 855256]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:44 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="cmd.exe" [2004-08-03 23:44 395776 C:\WINDOWS\system32\cmd.exe]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-03 23:33 44544]
C:\Documents and Settings\adsad\Menu Start\Programy\Autostart\
OpenOffice.ux.pl 2.1.0.lnk - C:\Program Files\OpenOffice.ux.pl 2.1.0\program\quickstart.exe [2006-12-30 04:32:40 17408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Gamma Loader.lnk]
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^RaConfig.lnk]
backup=C:\WINDOWS\pss\RaConfig.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^WinZip Quick Pick.lnk]
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^fdffd^Menu Start^Programy^Autostart^OpenOffice.ux.pl 2.1.0.lnk]
backup=C:\WINDOWS\pss\OpenOffice.ux.pl 2.1.0.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Stefan]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zegarynka]
R2 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2006-09-09 18:48]
R2 OneStep Search Service;OneStep Search Service;"C:\Program Files\OneStepSearch\onestep.exe" "C:\Program Files\OneStepSearch\onestep.dll" Service []
R3 Amps2prt;A4Tech PS/2 Port Mouse Driver;C:\WINDOWS\system32\DRIVERS\Amps2prt.sys [2006-05-09 09:27]
R3 ZSMC302;BenQ Web Camera;C:\WINDOWS\system32\Drivers\usbvm302.sys [2004-09-08 04:27]
S3 ADM8511;Konwerter z USB na Fast Ethernet ADMtek ADM8511/AN986;C:\WINDOWS\system32\DRIVERS\ADM8511.SYS [2005-07-02 13:07]
S3 RT2400;RT2400 Wireless Driver;C:\WINDOWS\system32\DRIVERS\RT2400.sys [2003-10-08 12:14]
S3 trial;trial;C:\Documents and Settings\asdasda\Pulpit\r0 League Cheat\aeq_suxx.sys []
S3 Z302Mic;BenQ Web Camera Mic Audio Filter Driver;C:\WINDOWS\system32\drivers\UsbMicfilt.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-01-25 16:15:00 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- D:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2008-01-26 13:42:34 C:\WINDOWS\Tasks\hl.job"
- C:\Program Files\Valve\hl.exe
"2008-01-15 16:54:57 C:\WINDOWS\Tasks\SmartDefrag.job"
- C:\Program Files\IObit\IObit SmartDefrag\schedule.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-26 14:57:19
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-26 14:57:52
ComboFix-quarantined-files.txt 2008-01-26 13:57:38
ComboFix2.txt 2007-12-13 18:10:47
ComboFix3.txt 2007-12-13 13:44:30
ComboFix4.txt 2007-12-12 19:19:08
.
2008-01-09 19:59:21 --- E O F ---