Jump to content

bobmk

Honorary Members
  • Posts

    30
  • Joined

  • Last visited

Reputation

0 Neutral
  1. Problem resolved, many thanks for your help - great job. Bob
  2. Both scans were clean, the malwarebytes log is attached. Thanks mbam-log-2012-11-14 (10-30-18).txt
  3. Sorry missed that question! It is running better, searches are not redirected and it is quicker. Many Thanks
  4. Here is the report. Thanks ComboFix.txt
  5. This process completed, although the "System Recovery Options from the Advanced Boot Options" did not work since it hung every time it was attempted. "System Recovery Options by using Windows installation disc" worked, the log is attached. TDSSKiller.exe also worked and the log is attached. Malwarebytes provided a clean scan. Thanks Bob Result2.txt TDSSKiller.2.8.15.0_12.11.2012_20.07.30_log.txt
  6. Result.txt attached. Thanks Result.txt
  7. Hi, Here is the screen shot of disk manager. Yes, I can get a CD burnt on another computer. Thanks
  8. It is doing exactly the same in safe mode! There is a brief "hour glass" and then nothing, and no logs in the root of the system drive.
  9. I have downloaded TDSSKiller.exe but it appears to be not running. I have tried running as administrator. There is a brief "hour glass" and then nothing, and no logs in the root of the system drive. Thanks Bob
  10. Hi, Thanks for the prompt response, here is the aswMBR log. Bob aswMBR.txt
  11. We are having our Google and yahoo searches redirected, Malwarebytes and Security Essentials scans are clear. Attach.txt DDS.txt
  12. Thank you! Your help is much appreciated. Bob
  13. Hi, The system seems to be running normally. Here are the latest logs. Thanks Bob Results of screen317's Security Check version 0.99.14 Windows 7 Service Pack 1 (UAC is enabled) Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! ESET Online Scanner v3 Microsoft Security Essentials WMI entry may not exist for antivirus; attempting automatic update. ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware CCleaner Java 6 Update 26 Adobe Flash Player 10.3.181.14 Adobe Reader X (10.1.0) Mozilla Firefox (x86 en-GB..) ```````````````````````````````` Process Check: objlist.exe by Laurent Windows Defender MSMpEng.exe Microsoft Security Essentials msseces.exe Acronis TrueImageHome OnlineBackupStandalone TrueImageMonitor.exe ``````````End of Log```````````` ESET.LOG C:\Program Files\Tftpd32\tftpd32.exe a variant of Win32/TFTPD32.A application cleaned by deleting - quarantined C:\Users\user\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60\6deaabfc-24b3f2bb multiple threats deleted - quarantined C:\Users\user\Documents\Documents\microsoft\braindumps\Transcender_70-285_v2.0.2-rbs.rar a variant of Win32/Tool.TPE.A application deleted - quarantined D:\AQL2\Backup Set 2011-06-09 144850\Backup Files 2011-06-09 144850\Backup files 24.zip multiple threats deleted - quarantined D:\AQL2\Backup Set 2011-06-09 144850\Backup Files 2011-06-09 144850\Backup files 37.zip a variant of Win32/Tool.TPE.A application deleted - quarantined E:\downloads\cisco\Tftpd32-3.35-setup.exe a variant of Win32/TFTPD32.A application deleted - quarantined E:\downloads\keylogger\refog_setup_kl_616.exe multiple threats deleted - quarantined E:\downloads\primopdf\FreewarePrimoPDF.exe Win32/OpenCandy application deleted - quarantined
  14. Sorry for the delay. Bob ComboFix 11-06-08.04 - user 09/06/2011 13:07:52.2.2 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.2937.682 [GMT 1:00] Running from: c:\users\user\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((( Files Created from 2011-05-09 to 2011-06-09 ))))))))))))))))))))))))))))))) . . 2011-06-09 12:28 . 2011-06-09 12:28 -------- d-----w- c:\users\QBDataServiceUser19\AppData\Local\temp 2011-06-09 12:28 . 2011-06-09 12:28 -------- d-----w- c:\users\QBDataServiceUser17\AppData\Local\temp 2011-06-09 12:28 . 2011-06-09 12:28 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp 2011-06-09 12:28 . 2011-06-09 12:28 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-06-09 12:28 . 2011-06-09 12:28 -------- d-----w- c:\users\ADMINI~1\AppData\Local\temp 2011-06-09 12:28 . 2011-06-09 12:28 -------- d-----w- c:\users\Acronis Agent User\AppData\Local\temp 2011-06-09 09:29 . 2011-06-09 09:29 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8FACDE7B-DD47-4EF3-A28C-44A5128CD604}\MpKsl47e8ae10.sys 2011-06-09 09:29 . 2011-05-09 20:46 6962000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8FACDE7B-DD47-4EF3-A28C-44A5128CD604}\mpengine.dll 2011-06-08 00:27 . 2011-06-08 00:27 -------- d-----w- c:\users\user\AppData\Local\Adobe 2011-06-07 09:44 . 2011-06-07 09:44 -------- d-----w- c:\users\user\AppData\Local\Apple 2011-06-07 09:24 . 2011-06-07 21:24 -------- d-----w- c:\users\user\AppData\Local\{A52F6072-8927-4088-9AD6-04482FBC25C2} 2011-06-07 09:12 . 2011-06-09 12:34 -------- d-----w- c:\users\user\AppData\Local\temp 2011-06-06 13:59 . 2011-06-06 13:59 -------- d-----w- c:\users\user\AppData\Local\{87C570AA-0465-43E0-8610-8D2787365749} 2011-06-06 11:45 . 2011-06-06 11:45 -------- d-----w- c:\users\user\AppData\Roaming\ACCM Software 2011-06-06 09:16 . 2011-06-06 09:16 75776 --sha-r- c:\windows\system32\racpldlg6.dll 2011-06-06 09:05 . 2011-06-06 09:05 -------- d-----w- c:\program files\Outlook Email Address Extractor 2011-06-06 09:00 . 2011-06-06 09:00 -------- d-----w- c:\program files\ACCM Software 2011-06-06 02:18 . 2011-06-06 02:18 -------- d-----w- c:\windows\Panther 2011-06-06 01:59 . 2011-06-06 01:59 -------- d-----w- c:\users\user\AppData\Local\{BA878C87-6F91-4974-8C3F-B8977F1D24B3} 2011-05-25 11:52 . 2011-05-25 11:52 -------- d-----w- c:\windows\CheckSur 2011-05-24 21:19 . 2011-04-22 19:14 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys 2011-05-24 14:22 . 2011-05-24 14:22 -------- d-----w- c:\users\user\AppData\Roaming\Wireshark 2011-05-24 13:45 . 2011-05-24 13:45 -------- d-----w- c:\users\user\AppData\Roaming\gtk-2.0 2011-05-24 13:42 . 2011-05-24 13:42 -------- d-----w- c:\program files\WinPcap 2011-05-24 13:42 . 2011-05-24 13:42 -------- d-----w- c:\program files\Wireshark 2011-05-24 13:20 . 2011-05-24 13:20 -------- d-----w- c:\users\user\AppData\Local\Trusteer 2011-05-24 13:19 . 2011-05-24 13:19 -------- d-----w- c:\users\user\AppData\Roaming\Trusteer 2011-05-24 13:18 . 2011-05-24 13:18 -------- d-----w- c:\program files\Trusteer 2011-05-24 13:18 . 2011-05-24 13:18 -------- d-----w- c:\programdata\Trusteer 2011-05-24 02:24 . 2011-05-24 02:24 -------- d-----w- c:\program files\woanware 2011-05-22 21:55 . 2011-05-22 21:55 -------- d-----w- c:\users\user\AppData\Local\{0F6765BF-BF7A-45AF-9A0A-8FB0CAF79992} 2011-05-20 11:29 . 2011-01-30 12:13 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C030B74D-8BC0-4958-A64F-A114FD42910E}\gapaengine.dll 2011-05-18 23:49 . 2011-05-18 23:49 -------- d-----w- c:\program files\Carbonite 2011-05-18 23:49 . 2011-05-18 23:49 -------- d-----w- c:\programdata\Carbonite 2011-05-17 10:45 . 2011-05-17 10:45 -------- d-----w- c:\users\user\AppData\Roaming\SUPERAntiSpyware.com 2011-05-17 10:45 . 2011-05-17 10:45 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2011-05-17 10:45 . 2011-06-06 02:00 -------- d-----w- c:\program files\SUPERAntiSpyware 2011-05-17 10:23 . 2011-06-02 13:48 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-05-17 10:23 . 2011-05-17 10:23 -------- d-----w- c:\users\user\AppData\Local\{CA083B91-CAB7-491D-8226-D8432E54E494} 2011-05-16 09:09 . 2011-05-16 09:09 -------- d-----w- c:\users\user\AppData\Local\{F7F44E43-8581-4714-B377-4BEFA93DBF1A} 2011-05-16 08:52 . 2011-04-09 05:56 123904 ----a-w- c:\windows\system32\poqexec.exe 2011-05-15 16:14 . 2011-05-15 16:14 -------- d-----w- c:\program files\Recuva 2011-05-12 17:48 . 2011-05-12 17:48 186640 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\ZH-TW\ConfApiSat.dll 2011-05-12 17:42 . 2011-05-12 17:42 229648 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\SV-SE\ConfApiSat.dll 2011-05-12 17:42 . 2011-05-12 17:42 186128 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\ZH-CN\ConfApiSat.dll 2011-05-12 17:37 . 2011-05-12 17:37 240400 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\NL-NL\ConfApiSat.dll 2011-05-12 17:36 . 2011-05-12 17:36 238352 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\pt-BR\ConfApiSat.dll 2011-05-12 17:34 . 2011-05-12 17:34 196880 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\ko-KR\ConfApiSat.dll 2011-05-12 17:30 . 2011-05-12 17:30 198928 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\ja-JP\ConfApiSat.dll 2011-05-12 17:27 . 2011-05-12 17:27 241424 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\it-IT\ConfApiSat.dll 2011-05-12 17:21 . 2011-05-12 17:21 247056 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\fr-FR\ConfApiSat.dll 2011-05-12 17:17 . 2011-05-12 17:17 233232 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\FI\ConfApiSat.dll 2011-05-12 17:14 . 2011-05-12 17:14 242960 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\es-ES\ConfApiSat.dll 2011-05-12 17:11 . 2011-05-12 17:11 245520 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\de-DE\ConfApiSat.dll 2011-05-12 17:09 . 2011-05-12 17:09 230672 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\DA\ConfApiSat.dll 2011-05-12 16:42 . 2011-05-12 16:42 227088 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\en-US\ConfApiSat.dll 2011-05-12 16:32 . 2011-05-12 16:32 3321088 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\uccp.dll 2011-05-12 16:32 . 2011-05-12 16:32 2257672 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\CONFAPI.dll 2011-05-12 16:32 . 2011-05-12 16:32 287496 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\RtcRouter.dll 2011-05-12 10:02 . 2011-05-12 10:02 626688 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\MSVCR80.dll 2011-05-12 10:02 . 2011-05-12 10:02 548864 ----a-w- c:\program files\Common Files\Microsoft Shared\LiveMeeting Shared\MSVCP80.dll 2011-05-11 08:12 . 2011-05-11 08:12 -------- d-----w- c:\users\user\AppData\Local\{A314EFBF-D679-437C-8B9B-0DA397FC8CF2} 2011-05-11 00:23 . 2011-03-25 02:58 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys 2011-05-11 00:23 . 2011-03-25 02:58 284672 ----a-w- c:\windows\system32\drivers\usbport.sys 2011-05-11 00:23 . 2011-03-25 02:58 75776 ----a-w- c:\windows\system32\drivers\usbccgp.sys 2011-05-11 00:23 . 2011-03-25 02:57 43008 ----a-w- c:\windows\system32\drivers\usbehci.sys 2011-05-11 00:23 . 2011-03-25 02:57 24064 ----a-w- c:\windows\system32\drivers\usbuhci.sys 2011-05-11 00:23 . 2011-03-25 02:57 5888 ----a-w- c:\windows\system32\drivers\usbd.sys 2011-05-11 00:22 . 2011-04-09 06:02 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe 2011-05-11 00:22 . 2011-04-09 06:02 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-05-29 08:11 . 2010-04-21 09:08 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-29 08:11 . 2010-04-21 09:08 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-05-12 16:32 . 2009-11-05 10:50 82696 ----a-w- c:\windows\system32\lmdimon8.dll 2011-05-12 16:32 . 2009-11-05 10:50 82184 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\lmdippr8.dll 2011-05-09 20:46 . 2010-04-01 14:05 6962000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2011-04-28 13:34 . 2011-04-28 13:34 53816 ----a-w- c:\windows\system32\drivers\RapportKELL.sys 2011-04-14 04:07 . 2011-04-28 07:56 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-04-13 14:02 . 2011-04-13 14:02 40984 ----a-w- c:\windows\system32\drivers\point32.sys 2011-04-12 16:22 . 2010-06-24 10:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-04-08 22:02 . 2011-04-08 22:02 390656 ----a-w- c:\windows\system32\ipcoin815.dll 2011-04-05 20:55 . 2011-04-19 20:55 17712 ----a-w- c:\windows\system32\nitrolocalui.dll 2011-04-05 20:55 . 2011-04-19 20:55 26416 ----a-w- c:\windows\system32\nitrolocalmon.dll 2011-03-28 13:34 . 2010-11-04 00:53 3833856 ----a-w- c:\windows\system32\cdintf300.dll 2011-03-15 13:25 . 2011-03-15 13:25 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2011-03-15 13:25 . 2011-03-15 13:25 161792 ----a-w- c:\windows\system32\msls31.dll 2011-03-15 13:25 . 2011-03-15 13:25 1126912 ----a-w- c:\windows\system32\wininet.dll 2011-03-15 13:25 . 2011-03-15 13:25 86528 ----a-w- c:\windows\system32\iesysprep.dll 2011-03-15 13:25 . 2011-03-15 13:25 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2011-03-15 13:25 . 2011-03-15 13:25 74752 ----a-w- c:\windows\system32\iesetup.dll 2011-03-15 13:25 . 2011-03-15 13:25 63488 ----a-w- c:\windows\system32\tdc.ocx 2011-03-15 13:25 . 2011-03-15 13:25 48640 ----a-w- c:\windows\system32\mshtmler.dll 2011-03-15 13:25 . 2011-03-15 13:25 420864 ----a-w- c:\windows\system32\vbscript.dll 2011-03-15 13:25 . 2011-03-15 13:25 367104 ----a-w- c:\windows\system32\html.iec 2011-03-15 13:25 . 2011-03-15 13:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2011-03-15 13:25 . 2011-03-15 13:25 23552 ----a-w- c:\windows\system32\licmgr10.dll 2011-03-15 13:25 . 2011-03-15 13:25 152064 ----a-w- c:\windows\system32\wextract.exe 2011-03-15 13:25 . 2011-03-15 13:25 150528 ----a-w- c:\windows\system32\iexpress.exe 2011-03-15 13:25 . 2011-03-15 13:25 142848 ----a-w- c:\windows\system32\ieUnatt.exe 2011-03-15 13:25 . 2011-03-15 13:25 1427456 ----a-w- c:\windows\system32\inetcpl.cpl 2011-03-15 13:25 . 2011-03-15 13:25 110592 ----a-w- c:\windows\system32\IEAdvpack.dll 2011-03-15 13:25 . 2011-03-15 13:25 35840 ----a-w- c:\windows\system32\imgutil.dll 2011-03-15 13:25 . 2011-03-15 13:25 1797632 ----a-w- c:\windows\system32\jscript9.dll 2011-03-15 13:25 . 2011-03-15 13:25 11776 ----a-w- c:\windows\system32\mshta.exe 2011-03-15 13:25 . 2011-03-15 13:25 101888 ----a-w- c:\windows\system32\admparse.dll 2011-03-12 11:23 . 2011-04-26 19:59 870912 ----a-w- c:\windows\system32\XpsPrint.dll 2011-05-03 18:06 . 2011-03-23 11:43 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green] @="{95A27763-F62A-4114-9072-E81D87DE3B68}" [HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}] 2011-03-03 19:52 762000 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial] @="{E300CD91-100F-4E67-9AF3-1384A6124015}" [HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}] 2011-03-03 19:52 762000 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow] @="{5E529433-B50E-4bef-A63B-16A6B71B071A}" [HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}] 2011-03-03 19:52 762000 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-07-04 430080] "OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2010-03-16 718208] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016] "GrooveMonitor"="c:\program files\Microsoft Office\Office14\GROOVEMN.EXE" [2010-03-24 944008] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-06-06 2424192] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ThpSrv"="c:\windows\system32\thpsrv" [X] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "TOSDCR"="c:\program files\TOSHIBA\PasswordUtility\TOSDCR.exe" [2007-08-28 169296] "TosAutLk"="c:\program files\TOSHIBA\WirelessKeyLogon\TosAutLk.exe" [2008-04-02 116040] "TAcelMgr"="c:\program files\Toshiba\TOSHIBA Accelerometer Utilities\TAcelMgr\TAcelMgr.exe" [2006-10-31 151216] "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2008-06-24 509816] "RtHDVCpl"="RtHDVCpl.exe" [2008-08-28 6275072] "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-05-31 63048] "ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2008-12-19 83336] "HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-10-31 54608] "Google EULA Launcher"="c:\program files\Google\Google EULA\GoogleEULALauncher.exe" [2008-05-28 20480] "Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2008-08-19 417792] "Button Disable"="c:\program files\Toshiba\TOSHIBA Button Disable\TBD.exe" [2007-11-07 337784] "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-12-15 184320] "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-07-15 726904] "Toshiba TEMPRO"="c:\program files\Toshiba TEMPRO\TemproTray.exe" [2010-05-11 1050072] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-05-29 1047656] "TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2011-02-01 5546632] "Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2010-12-06 390728] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288] "Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2008-11-18 623880] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408] "SAOB Monitor"="c:\program files\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMonitor.exe" [2010-11-16 2536752] "AirPort Base Station Agent"="c:\program files\AirPort\APAgent.exe" [2009-11-11 771360] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-11 137752] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-11 171032] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-11 172568] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 1808784] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-05-29 1047656] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672] "Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2011-03-03 948880] . c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Microsoft SharePoint Workspace.lnk - c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-3-25 30969208] OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2010-3-29 227712] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2011-3-8 984408] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "DisableCAD"= 1 (0x1) "EnableLinkedConnections"= 1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth Manager.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Manager.lnk backup=c:\windows\pss\Bluetooth Manager.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk] backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup backupExtension=.CommonStartup path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk . [HKLM\~\startupfolder\C:^Users^user^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^BITS Background Download {9892956E-3E9B-4F02-A019-1A8B518DBDFA}.lnk] path=c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BITS Background Download {9892956E-3E9B-4F02-A019-1A8B518DBDFA}.lnk backup=c:\windows\pss\BITS Background Download {9892956E-3E9B-4F02-A019-1A8B518DBDFA}.lnk.Startup backupExtension=.Startup . [HKLM\~\startupfolder\C:^Users^user^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office Groove.lnk] path=c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office Groove.lnk backup=c:\windows\pss\Microsoft Office Groove.lnk.Startup backupExtension=.Startup . [HKLM\~\startupfolder\C:^Users^user^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk] path=c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration] 2008-01-11 02:07 574864 ----a-w- c:\program files\TOSHIBA\Registration\ToshibaRegistration.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba TEMPRO] 2010-05-11 08:41 1050072 ----a-w- c:\program files\Toshiba TEMPRO\TemproTray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPCHWMsg] 2008-08-11 15:13 446464 ----a-w- c:\program files\TOSHIBA\TPHM\TPCHWMsg.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPwrMain] 2008-07-30 08:58 431456 ----a-w- c:\program files\TOSHIBA\Power Saver\TPwrMain.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TRot.exe] 2008-08-04 14:06 692224 ----a-w- c:\program files\TOSHIBA\TOSHIBA Rotation Utility\TRot.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TSkrMain] 2006-10-31 19:55 57008 ----a-w- c:\program files\TOSHIBA\TOSHIBA Accelerometer Utilities\Shaker\TSkrMain.exe . R1 MpKsl30dd27be;MpKsl30dd27be;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FF1FCFC5-7DE7-40DF-8E96-8B30F96B8BAF}\MpKsl30dd27be.sys [x] R1 MpKsl4618247b;MpKsl4618247b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E1F5821C-5D40-408B-93A9-961BA70FA240}\MpKsl4618247b.sys [x] R1 MpKsl541df763;MpKsl541df763;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{645BFD4A-2425-4338-AD21-E0CE0EBCA402}\MpKsl541df763.sys [x] R1 MpKsl5df76ba6;MpKsl5df76ba6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6D343388-F63A-4EB3-802E-EFF561B9162A}\MpKsl5df76ba6.sys [x] R1 MpKsl6c07f054;MpKsl6c07f054;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{19FE4682-D309-41F1-BF29-1335A30F7C71}\MpKsl6c07f054.sys [x] R1 MpKsl7eaba854;MpKsl7eaba854;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{420A4507-4426-4B83-9126-C1A4255956A2}\MpKsl7eaba854.sys [x] R1 MpKsl901d2018;MpKsl901d2018;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{264F6789-F516-40D1-9F52-2BD5EF608BB2}\MpKsl901d2018.sys [x] R1 MpKsla16574e2;MpKsla16574e2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3D22B206-BDC1-4694-B558-F534EBE8BF9D}\MpKsla16574e2.sys [x] R1 MpKsla3a0b66b;MpKsla3a0b66b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5539398A-F6DF-409D-82E1-7FCF210D7F9C}\MpKsla3a0b66b.sys [x] R1 MpKslbb1b64da;MpKslbb1b64da;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0BD659FE-CCBF-47DB-9685-62D06821161E}\MpKslbb1b64da.sys [x] R1 MpKslc8ac6f4c;MpKslc8ac6f4c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D4DAB588-BCFC-4347-975C-CFBEA699D21A}\MpKslc8ac6f4c.sys [x] R1 MpKslcf0ba0c3;MpKslcf0ba0c3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{16237298-A87E-45A1-B238-9323B2F77555}\MpKslcf0ba0c3.sys [x] R1 MpKsldab8cd8b;MpKsldab8cd8b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{47C742B7-E4B0-45DF-ABE4-BEFA4883E2CF}\MpKsldab8cd8b.sys [x] R1 MpKslf755276c;MpKslf755276c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D0781780-A2E5-4649-8038-CCBFB96CCCD8}\MpKslf755276c.sys [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\androidusb.sys [2009-10-26 25088] R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-07-13 112128] R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 25088] R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-23 23040] R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2008-08-22 7680] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208] R3 NANMp50;NANMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\NANMp50.sys [2010-03-25 36408] R3 NANSp50;NANSp50 NDIS Protocol Driver;c:\windows\system32\Drivers\NANSp50.sys [2010-03-25 35384] R3 NETw5s32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\DRIVERS\NETw5s32.sys [2010-05-31 6766080] R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-04-22 4231168] R3 QuickBooksDB19;QuickBooksDB19;c:\progra~1\Intuit\QUICKB~2\QBDBMgrN.exe [2009-07-27 131072] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-20 1343400] R4 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2008-12-09 24636] R4 SmartFaceVWatchSrv;SmartFaceVWatchSrv;c:\program files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe [2008-08-25 77824] R4 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-04-01 2271608] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] S0 RapportKELL;RapportKELL;c:\windows\System32\Drivers\RapportKELL.sys [2011-04-28 53816] S0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\DRIVERS\tdrpm273.sys [2011-02-24 752128] S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\Thpdrv.sys [2009-06-29 30272] S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [2009-06-29 13120] S1 MpKsl47e8ae10;MpKsl47e8ae10;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8FACDE7B-DD47-4EF3-A28C-44A5128CD604}\MpKsl47e8ae10.sys [2011-06-09 28752] S1 RapportCerberus_26169;RapportCerberus_26169;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus_26169.sys [2011-04-28 57144] S1 RapportEI;RapportEI;c:\program files\Trusteer\Rapport\bin\RapportEI.sys [2011-04-28 66360] S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2011-04-28 158904] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 Advanced Monitoring Agent;Advanced Monitoring Agent;c:\program files\Advanced Monitoring Agent\winagent.exe [2011-05-11 1824256] S2 afcdpsrv;Acronis Nonstop Backup Service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2011-02-24 3246040] S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2008-04-16 40960] S2 gfi_lanss10_attservice;GFI LANguard 10 Attendant Service;c:\progra~1\ADVANC~1\patchman\lnssatt.exe [2010-10-01 318832] S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn Ignition\LMIGuardianSvc.exe [2010-10-19 374160] S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [2010-05-31 12856] S2 NitroReaderDriverReadSpool;NitroPDFReaderDriverCreatorReadSpool;c:\program files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe [2011-04-05 196912] S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088] S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2010-09-16 80896] S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2011-04-28 870200] S2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\Toshiba TEMPRO\TemproSvc.exe [2010-05-11 124368] S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2008-07-15 106496] S2 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2008-08-11 622592] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [2008-04-30 6144] S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2011-02-24 167968] S3 ATSwpWDF;AuthenTec TruePrint USB WBF WDF Driver;c:\windows\system32\Drivers\ATSwpWDF.sys [2009-12-03 625224] S3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y6232.sys [2010-04-07 223960] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392] S3 NETwNs32;___ Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\DRIVERS\NETwNs32.sys [2010-10-18 7122944] S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144] S3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360] S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000] S3 RapportIaso;RapportIaso;c:\programdata\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportIaso.sys [2011-04-28 18872] S3 TBtnKey;TOSHIBA Tablet PC Buttons Type N HID Driver;c:\windows\system32\DRIVERS\TBtnKey.sys [2006-10-18 10496] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336] S3 wisdpen;Wacom Penabled MiniDriver;c:\windows\system32\DRIVERS\wisdpen.sys [2011-01-04 37232] S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 17920] . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - MPKSL47E8AE10 *NewlyCreated* - MPKSLA7DF1F23 *NewlyCreated* - MPKSLBA8779B4 *NewlyCreated* - MPKSLBDB16DF9 *NewlyCreated* - RAPPORTIASO *Deregistered* - mfeapfk *Deregistered* - mfeavfk *Deregistered* - mfebopk *Deregistered* - mfehidk *Deregistered* - MpKsla7df1f23 *Deregistered* - MpKslba8779b4 *Deregistered* - MpKslbdb16df9 . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.co.uk/ mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA Trusted Zone: aqlad Trusted Zone: customerconsulting.com\mail Trusted Zone: microsoft.com\oas.support Trusted Zone: microsoft.com\support Trusted Zone: o2.co.uk\*.broadband TCP: DhcpNameServer = 192.168.0.49 192.168.0.7 8.8.8.8 TCP: Interfaces\{22659A77-CC1E-4333-8B2D-60E37F6E345A}: NameServer = 10.1.1.16 DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB DPF: {0A43D7AC-D6C1-4622-B309-BF975F427C0E} - hxxps://internetbankingplus1.firstdirect.com/ibplus/frontdoorFD.cab FF - ProfilePath - c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\4tgzx167.default\ FF - prefs.js: network.proxy.type - 0 . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-2533334889-2003507063-1450326229-1000_Classes\VirtualStore\MACHINE\SOFTWARE\Hewlett-Packard\San Diego Shared IO\Protocols\HPZipm12.exe\SNMPCommunityName\Get] @DACL=(02 0000) "192.168.0.11"="public" "NPI93670A"="public" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'Explorer.exe'(440) c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll . Completion time: 2011-06-09 14:27:27 ComboFix-quarantined-files.txt 2011-06-09 13:27 ComboFix2.txt 2011-06-07 09:16 . Pre-Run: 175,028,592,640 bytes free Post-Run: 174,987,530,240 bytes free . - - End Of File - - 14586F6A349222B064292365960B398F
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.