Jump to content

Foresite Software LLC

Members
  • Posts

    4
  • Joined

  • Last visited

Everything posted by Foresite Software LLC

  1. I fixed the problem myself. 1) With the infected computer disconnected from the Internet I un-installed ESET Antivirus and Malwarebytes. 2) From a "clean" computer, I downloaded a trial of Kaspersky Antivirus 2010. 3) I copied Kaspersky's setup file to the infected computer via USB thumb drive and installed it on the infected computer. 4) I did need to connect the infected computer to the Internet to register Kaspersky and get the latest virus definitions, but this worked OK where all other antivirus programs I tried would not update and on-line scan sites were blocked. 5) I scanned and cleaned the following: (hope they help the Malwarebytes folks) **** Status: Deleted (events: 8) 2/17/2010 4:59:17 PM Deleted Trojan program Trojan-PSW.Win32.Kates.bh c:\Documents and Settings\KieraS\Local Settings\Temp\amjrc.old High 2/17/2010 5:07:39 PM Deleted Trojan program Exploit.JS.Pdfka.bpf C:\Documents and Settings\Administrator\Local Settings\Temp\AcrD2.tmp High 2/17/2010 5:07:39 PM Deleted Trojan program Exploit.JS.Pdfka.bpf C:\Documents and Settings\Administrator\Local Settings\Temp\AcrD2.tmp//data0001 High 2/17/2010 5:07:19 PM Deleted Trojan program Trojan.Win32.Monder.cyip C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\9T5UVQTY\dfghfghgfj[1].dll High 2/17/2010 5:07:19 PM Deleted Trojan program Exploit.JS.Pdfka.bpf C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Z20O583Z\collab[1].pdf High 2/17/2010 5:07:19 PM Deleted Trojan program Exploit.JS.Pdfka.bpf C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Z20O583Z\collab[1].pdf//data0001 High 2/17/2010 5:07:25 PM Deleted Trojan program Backdoor.Win32.Inject.dnt C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Z20O583Z\update[1].exe High 2/17/2010 5:14:47 PM Deleted Trojan program Packed.Win32.Krap.an C:\Documents and Settings\KieraS\Local Settings\Temp\pdfupd.exe High Status: Absent (events: 2) 2/17/2010 5:34:56 PM Not found Trojan program Packed.Win32.Krap.an C:\Documents and Settings\KieraS\Local Settings\Temp\pdfupd.exe//PE_Patch.UPX High 2/17/2010 5:34:56 PM Not found Trojan program Packed.Win32.Krap.an C:\Documents and Settings\KieraS\Local Settings\Temp\pdfupd.exe//PE_Patch.UPX//UPX High Status: Disinfected (events: 2) 2/17/2010 5:13:48 PM Disinfected Trojan program Backdoor.Win32.Bifrose.fsb C:\Documents and Settings\KieraS\Local Settings\Temporary Internet Files\Content.Word\~WRF{8BF2C974-0019-4EE4-A529-AD25B3CDC35B}.tmp High 2/17/2010 5:13:48 PM Disinfected Trojan program Backdoor.Win32.Bifrose.fsb C:\Documents and Settings\KieraS\Local Settings\Temporary Internet Files\Content.Word\~WRF{8BF2C974-0019-4EE4-A529-AD25B3CDC35B}.tmp//C:/DOCUME~1/Owner/Desktop/W00TYQ~1.COM/W00TYQ~1.COM/W2.exe High *** 6) After cleaning and a re-boot I was able to run and update Malwarebytes. Then I scanned with Malwarebytes and found/cleaned 212 more problems. 7) Un-installed Kaspersky trial, re-install ESET NOD32. 8) Verified that ESET could update properly. 9) Final scan with ESET 10) Looks good! I guess the reason I didn't get a response from the folks at this list is because I added a reply to my original post within 48 hours, so they probably thought I was being helped already. Yeah, I wish I had help on this one, but the forum in itself is a wealth of information and I'm so glad that there are folks out there who do help others, even if it wasn't me. Oh well, guess I'll just have to buy _myself_ a beer this time!
  2. Forgot to mention that I can start GMER Rootkit Scanner and it runs for 15 minutes of so and then the PC reboots on its own.
  3. Malewarebytes won't run long enough to generate a log, so no log file. ESET was on the machine at time of infection, and seems to work but it can't update anymore. I can connect to the Internet. I know I had an infection with sms32.exe/winlogon32.exe which disabled task manager and changed "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" setting. After some manual edits things are better but Malwarebytes still won't run (it'll start and shut down in three or four seconds). I went through forums.malwarebytes.org/index.php?showtopic=17607 with no luck. I'm following "I'm infected -- what do I do now" Thanks in advance for any help. DDS (Ver_09-12-01.01) - NTFSx86 Run by Administrator at 14:37:19.56 on Mon 02/15/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3045.2562 [GMT -6:00] AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Intel\AMT\atchksrv.exe C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe C:\Program Files\Lenovo\Rescue and Recovery\ADM\IUService.exe C:\Program Files\Intel\AMT\UNS.exe C:\Program Files\Common Files\Lenovo\Logger\logmon.exe c:\program files\lenovo\system update\suservice.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Analog Devices\SoundMAX\Smax4.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Lenovo\AwayTask\AwaySch.EXE C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe C:\WINDOWS\system32\SearchIndexer.exe C:\temp\psexp\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://lenovo.live.com mWinlogon: Userinit=c:\windows\system32\userinit.exe BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll BHO: 1 (0x1) - No File BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [atchk] mRun: [soundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [soundMAX] "c:\program files\analog devices\soundmax\Smax4.exe" /tray mRun: [igfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [TVT Scheduler Proxy] c:\program files\common files\lenovo\scheduler\scheduler_proxy.exe mRun: [sunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [iSUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [iSUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [AwaySch] c:\program files\lenovo\awaytask\AwaySch.EXE mRun: [LPManager] c:\progra~1\thinkv~1\prdctr\LPMGR.exe mRun: [AMSG] c:\program files\thinkvantage\amsg\Amsg.exe /startup mRun: [DiskeeperSystray] "c:\program files\diskeeper corporation\diskeeper\DkIcon.exe" mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe" mRun: [<NO NAME>] mRun: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-ba7e-000000000002}\SC_Acrobat.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe mPolicies-explorer: NoWelcomeScreen = 1 (0x1) mPolicies-explorer: HonorAutoRunSetting = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL LSP: c:\windows\system32\helpers32.dll Trusted Zone: buy-security-essentials.com Trusted Zone: download-soft-package.com Trusted Zone: download-software-package.com Trusted Zone: get-key-se10.com Trusted Zone: is-software-download.com DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/SmileyCentralInitialSetup1.0.1.1.cab DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www1.snapfish.com/SnapfishActivia.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://softprocorp.webex.com/client/T26L/support/ieatgpc.cab Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll ============= SERVICES / DRIVERS =============== R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-11-16 108792] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-11-16 96408] R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-11-16 735960] R2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\lenovo\rescue and recovery\rrpservice.exe [2007-7-11 569344] R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\intel\amt\UNS.exe [2008-8-19 2514944] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-2-15 38224] R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\drivers\tvti2c.sys [2007-5-22 30336] S0 nielprt;Nielsen Patch Service;c:\windows\system32\drivers\nielprt.sys --> c:\windows\system32\drivers\nielprt.sys [?] S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys --> c:\windows\system32\drivers\nielgfx.sys [?] =============== Created Last 30 ================ 2010-02-15 20:17:42 0 d-----w- c:\program files\Security Task Manager 2010-02-15 20:03:18 1389904 ----a-w- C:\mstart.exe 2010-02-15 19:16:09 0 d-----w- c:\docume~1\admini~1\applic~1\Windows Search 2010-02-15 18:02:47 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-15 18:02:45 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-02-15 18:02:44 0 d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-02-15 18:01:09 0 d-----w- c:\program files\ESET 2010-02-15 16:44:01 0 d-----w- c:\docume~1\alluse~1\applic~1\SecTaskMan 2010-02-15 16:06:30 549376 ----a-w- C:\OTL.exe 2010-02-13 19:55:13 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll 2010-02-13 19:55:10 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll 2010-02-13 19:55:09 18944 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll 2010-02-13 19:55:07 27648 ----a-w- c:\windows\system32\dllcache\xrxftplt.exe 2010-02-13 19:55:04 4608 ----a-w- c:\windows\system32\dllcache\xrxflnch.exe 2010-02-13 19:53:58 19016 ----a-w- c:\windows\system32\dllcache\w926nd.sys 2010-02-13 19:52:58 26624 ----a-w- c:\windows\system32\dllcache\umaxu22.dll 2010-02-13 19:51:58 185344 ----a-w- c:\windows\system32\dllcache\thawbrkr.dll 2010-02-13 19:50:59 48736 ----a-w- c:\windows\system32\dllcache\srwlnd5.sys 2010-02-13 19:49:58 91294 ----a-w- c:\windows\system32\dllcache\skfpwin.sys 2010-02-13 19:48:59 23936 ----a-w- c:\windows\system32\dllcache\sccmusbm.sys 2010-02-13 19:47:53 19584 ----a-w- c:\windows\system32\dllcache\rasirda.sys 2010-02-13 19:46:59 259328 ----a-w- c:\windows\system32\dllcache\perm3dd.dll 2010-02-13 19:45:59 198144 ----a-w- c:\windows\system32\dllcache\nv3.sys 2010-02-13 19:44:59 19968 ----a-w- c:\windows\system32\dllcache\mxicfg.dll 2010-02-13 19:43:58 48768 ----a-w- c:\windows\system32\dllcache\maestro.sys 2010-02-13 19:42:58 23552 ----a-w- c:\windows\system32\dllcache\irmk7.sys 2010-02-13 19:41:59 10096640 ----a-w- c:\windows\system32\dllcache\hwxcht.dll 2010-02-13 19:40:59 108827 ----a-w- c:\windows\system32\dllcache\hanja.lex 2010-02-13 19:39:58 595647 ----a-w- c:\windows\system32\dllcache\es56cvmp.sys 2010-02-13 19:38:59 38985 ----a-w- c:\windows\system32\dllcache\disrvsu.dll 2010-02-13 19:37:58 248064 ----a-w- c:\windows\system32\dllcache\cl546xm.sys 2010-02-13 19:36:59 104832 ----a-w- c:\windows\system32\dllcache\atiraged.dll 2010-02-13 19:33:58 0 d-----w- c:\windows\system32\zh-TW 2010-02-13 18:20:45 0 d-----w- c:\temp\psexp 2010-02-13 18:05:37 0 ----a-w- c:\documents and settings\administrator\defogger_reenable 2010-02-12 23:41:16 0 d-sh--w- c:\documents and settings\administrator\PrivacIE 2010-02-12 15:53:23 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2010-02-12 15:53:23 32128 ----a-w- c:\windows\system32\dllcache\usbccgp.sys 2010-02-12 14:30:52 0 d-----w- c:\windows\system32\NtmsData 2010-02-12 14:21:08 0 d-----w- c:\docume~1\admini~1\applic~1\Malwarebytes 2010-02-12 14:19:49 0 d-----w- c:\docume~1\admini~1\applic~1\Windows Desktop Search 2010-02-11 22:45:12 0 d-sh--w- c:\documents and settings\administrator\IETldCache 2010-02-11 22:41:59 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes ==================== Find3M ==================== 2009-12-31 16:50:03 353792 ----a-w- c:\windows\system32\dllcache\srv.sys 2009-12-31 16:50:03 353792 ------w- c:\windows\system32\drivers\srv.sys 2009-12-21 13:19:18 173056 ----a-w- c:\windows\system32\dllcache\ie4uinit.exe 2009-12-16 18:43:27 343040 ----a-w- c:\windows\system32\dllcache\mspaint.exe 2009-12-16 18:43:27 343040 ------w- c:\windows\system32\mspaint.exe 2009-12-14 07:08:23 33280 ----a-w- c:\windows\system32\dllcache\csrsrv.dll 2009-12-14 07:08:23 33280 ------w- c:\windows\system32\csrsrv.dll 2009-12-08 19:27:51 2189184 ----a-w- c:\windows\system32\dllcache\ntoskrnl.exe 2009-12-08 19:26:15 2145280 ----a-w- c:\windows\system32\dllcache\ntkrnlmp.exe 2009-12-08 19:26:15 2145280 ------w- c:\windows\system32\ntoskrnl.exe 2009-12-08 18:43:51 2023936 ----a-w- c:\windows\system32\dllcache\ntkrpamp.exe 2009-12-08 18:43:51 2023936 ------w- c:\windows\system32\ntkrnlpa.exe 2009-12-08 18:43:50 2066048 ----a-w- c:\windows\system32\dllcache\ntkrnlpa.exe 2009-12-08 09:23:28 474112 ----a-w- c:\windows\system32\dllcache\shlwapi.dll 2009-12-04 18:22:22 455424 ----a-w- c:\windows\system32\dllcache\mrxsmb.sys 2009-11-27 17:11:44 17920 ----a-w- c:\windows\system32\dllcache\msyuv.dll 2009-11-27 17:11:44 17920 ------w- c:\windows\system32\msyuv.dll 2009-11-27 17:11:44 1291776 ----a-w- c:\windows\system32\dllcache\quartz.dll 2009-11-27 17:11:44 1291776 ------w- c:\windows\system32\quartz.dll 2009-11-27 16:07:35 8704 ----a-w- c:\windows\system32\dllcache\tsbyuv.dll 2009-11-27 16:07:35 8704 ------w- c:\windows\system32\tsbyuv.dll 2009-11-27 16:07:35 28672 ----a-w- c:\windows\system32\dllcache\msvidc32.dll 2009-11-27 16:07:35 28672 ------w- c:\windows\system32\msvidc32.dll 2009-11-27 16:07:34 84992 ----a-w- c:\windows\system32\dllcache\avifil32.dll 2009-11-27 16:07:34 84992 ------w- c:\windows\system32\avifil32.dll 2009-11-27 16:07:34 48128 ----a-w- c:\windows\system32\dllcache\iyuv_32.dll 2009-11-27 16:07:34 48128 ------w- c:\windows\system32\iyuv_32.dll 2009-11-27 16:07:34 11264 ----a-w- c:\windows\system32\dllcache\msrle32.dll 2009-11-27 16:07:34 11264 ------w- c:\windows\system32\msrle32.dll 2009-11-21 15:51:04 471552 ----a-w- c:\windows\system32\dllcache\aclayers.dll 2008-08-19 07:25:40 32768 --sh--w- c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat 2008-09-06 01:06:01 32768 --sh--w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090520080906\index.dat ============= FINISH: 14:38:08.59 =============== Attach.txt.zip
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.