Here is my MBAM log - it removed three files, but they were all Rkill files which had been named in a way which malware might have allowed to run:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8015
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19120
10/24/2011 11:36:32 PM
mbam-log-2011-10-24 (23-36-32).txt
Scan type: Quick scan
Objects scanned: 191307
Time elapsed: 1 minute(s), 41 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\Jeff\Desktop\eXplorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
c:\Users\Jeff\Desktop\uSeRiNiT.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
c:\Users\Jeff\Desktop\WiNlOgOn.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
Here is my aswMBR log:
aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-10-24 23:40:32
-----------------------------
23:40:32.856 OS Version: Windows x64 6.0.6002 Service Pack 2
23:40:32.856 Number of processors: 2 586 0x1706
23:40:32.857 ComputerName: JEFFVISTA64 UserName: Jeff
23:40:33.506 Initialize success
23:40:33.749 AVAST engine defs: 11102402
23:41:09.759 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000063
23:41:09.760 Disk 0 Vendor: WDC_WD30 03.0 Size: 286168MB BusType: 3
23:41:09.761 Disk 1 \Device\Harddisk1\DR1 -> \Device\00000064
23:41:09.762 Disk 1 Vendor: WDC_WD10 05.0 Size: 953869MB BusType: 3
23:41:09.764 Disk 2 \Device\Harddisk2\DR2 -> \Device\00000067
23:41:09.765 Disk 2 Vendor: WDC_WD15 21.0 Size: 143089MB BusType: 3
23:41:11.781 Disk 0 MBR read successfully
23:41:11.782 Disk 0 MBR scan
23:41:11.784 Disk 0 Windows VISTA default MBR code
23:41:11.786 Service scanning
23:41:13.345 Modules scanning
23:41:13.347 Disk 0 trace - called modules:
23:41:13.359 ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys storport.sys hal.dll nvstor64.sys
23:41:13.683 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8005031150]
23:41:13.685 3 CLASSPNP.SYS[fffffa6001275c33] -> nt!IofCallDriver -> [0xfffffa8004e827c0]
23:41:13.687 5 acpi.sys[fffffa60008fbfde] -> nt!IofCallDriver -> \Device\00000063[0xfffffa8004e82060]
23:41:14.255 AVAST engine scan C:\Windows
23:41:18.822 AVAST engine scan C:\Windows\system32
23:42:07.903 AVAST engine scan C:\Windows\system32\drivers
23:42:12.330 AVAST engine scan C:\Users\Jeff
23:47:08.138 AVAST engine scan C:\ProgramData
23:47:35.763 Scan finished successfully
23:48:35.894 Disk 0 MBR has been saved successfully to "C:\Users\Jeff\Desktop\MBR.dat"
23:48:35.896 The log file has been saved successfully to "C:\Users\Jeff\Desktop\aswMBR.txt"
And here is my combofix log:
ComboFix 11-10-24.05 - Jeff 10/24/2011 23:53:37.2.2 - x64
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.4094.2487 [GMT -5:00]
Running from: c:\users\Jeff\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\users\Jeff\AppData\Local\{0FD55ED5-1212-41C1-BD44-576823EADBFE}\chrome.manifest
c:\users\Jeff\AppData\Local\{0FD55ED5-1212-41C1-BD44-576823EADBFE}\chrome\content\overlay.xul
c:\users\Jeff\AppData\Local\{0FD55ED5-1212-41C1-BD44-576823EADBFE}\install.rdf
c:\users\Jeff\g2mdlhlpx.exe
E:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-09-25 to 2011-10-25 )))))))))))))))))))))))))))))))
.
.
2011-10-25 04:58 . 2011-10-25 04:58 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2011-10-25 04:58 . 2011-10-25 04:58 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-25 04:33 . 2011-10-25 04:33 -------- d-----w- c:\users\Jeff\AppData\Roaming\Malwarebytes
2011-10-25 04:33 . 2011-10-25 04:33 -------- d-----w- c:\programdata\Malwarebytes
2011-10-25 04:33 . 2011-10-25 04:33 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2011-10-25 04:33 . 2011-08-31 22:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-25 01:50 . 2011-10-25 01:52 -------- d-----w- c:\users\Jeff\AppData\Local\Google
2011-10-25 01:50 . 2011-10-25 01:50 -------- d-----w- c:\program files (x86)\Google
2011-10-25 01:50 . 2011-09-06 20:38 301912 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-10-25 01:50 . 2011-09-06 20:36 24408 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-10-25 01:50 . 2011-09-06 20:36 42328 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-10-25 01:50 . 2011-09-06 20:45 254400 ----a-w- c:\windows\system32\aswBoot.exe
2011-10-25 01:50 . 2011-09-06 20:38 601944 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-10-25 01:50 . 2011-09-06 20:36 58200 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-10-25 01:50 . 2011-09-06 20:36 65368 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-10-25 01:49 . 2011-09-06 20:45 41184 ----a-w- c:\windows\avastSS.scr
2011-10-25 01:49 . 2011-09-06 20:45 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
2011-10-25 01:49 . 2011-10-25 01:49 -------- d-----w- c:\programdata\AVAST Software
2011-10-25 01:49 . 2011-10-25 01:49 -------- d-----w- c:\program files\AVAST Software
2011-10-24 18:28 . 2011-10-18 07:27 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F41617A7-82FD-4256-80F7-6D394E464028}\mpengine.dll
2011-10-24 03:29 . 2011-10-24 03:29 -------- d--h--w- c:\users\Jeff\AppData\Local\Take On Helicopters
2011-10-24 03:25 . 2011-10-24 18:13 -------- d-----w- c:\users\Jeff\{61f13630-6f16-42c7-9a60-1be001aa4f87}
2011-10-24 03:24 . 2000-01-05 10:35 208896 ----a-w- c:\program files (x86)\Common Files\InstallShield\engine\6\Intel 32\iuser.dll
2011-10-24 03:24 . 2000-01-04 10:44 151552 ----a-w- c:\program files (x86)\Common Files\InstallShield\engine\6\Intel 32\ctor.dll
2011-10-24 03:24 . 2000-01-04 10:39 32768 ----a-w- c:\program files (x86)\Common Files\InstallShield\engine\6\Intel 32\objectps.dll
2011-10-24 03:24 . 2000-01-04 10:39 212992 ----a-w- c:\program files (x86)\Common Files\InstallShield\engine\6\Intel 32\ILog.dll
2011-10-24 01:28 . 2011-10-24 01:28 -------- d-----w- c:\program files\Bohemia Interactive
2011-10-13 21:32 . 2011-10-13 21:32 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2011-10-12 13:42 . 2011-10-12 13:42 9310 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC(5791)\TEXTBOX.JS
2011-10-12 04:05 . 2011-10-12 13:25 -------- d--h--w- c:\programdata\WSTB
2011-10-05 04:33 . 2011-10-05 05:07 -------- d-----w- c:\windows\SysWow64\Adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-13 19:27 . 2011-05-18 03:56 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-28 04:09 . 2010-08-30 01:00 280736 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-09-28 04:09 . 2009-06-14 23:16 280736 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-09-28 04:07 . 2010-08-30 01:00 270904 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-08-31 01:00 . 2009-08-18 17:49 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2011-08-31 01:00 . 2009-08-18 16:24 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-08-14 13:41 . 2011-08-14 13:41 0 ---ha-w- c:\users\Jeff\AppData\Local\Kronadod.bin
.
.
((((((((((((((((((((((((((((( SnapShot@2011-10-24_21.08.44 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-06-07 03:33 . 2011-10-25 05:05 57514 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 15:44 . 2011-10-25 05:05 70310 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-06-07 03:33 . 2011-10-25 05:05 20238 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1787995230-711523803-3076010400-1000_UserData.bin
- 2008-06-07 02:24 . 2011-10-24 19:17 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-06-07 02:24 . 2011-10-25 05:02 32768 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-06-07 02:24 . 2011-10-25 05:02 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-06-07 02:24 . 2011-10-24 19:17 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-06-07 02:24 . 2011-10-24 19:17 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-06-07 02:24 . 2011-10-25 05:02 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-10-25 01:56 . 2011-10-25 01:56 22016 c:\windows\Installer\48a7cb.msi
- 2011-07-17 16:16 . 2011-10-24 21:08 3657 c:\windows\SysWOW64\mmf.sys
+ 2011-07-17 16:16 . 2011-10-25 05:00 3657 c:\windows\SysWOW64\mmf.sys
+ 2008-07-10 02:49 . 2011-10-25 00:01 3978 c:\windows\system32\WDI\ERCQueuedResolutions.dat
- 2011-10-24 21:08 . 2011-10-24 21:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-10-25 05:00 . 2011-10-25 05:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-10-25 05:00 . 2011-10-25 05:00 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2011-10-24 21:08 . 2011-10-24 21:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-06-07 05:13 . 2011-10-02 09:51 245760 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-06-07 05:13 . 2011-10-25 05:00 245760 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-06-07 05:13 . 2011-10-02 09:51 638976 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-06-07 05:13 . 2011-10-25 05:00 638976 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-11-02 12:46 . 2011-10-24 19:23 672542 c:\windows\system32\perfh009.dat
+ 2006-11-02 12:46 . 2011-10-25 04:45 672542 c:\windows\system32\perfh009.dat
+ 2006-11-02 12:46 . 2011-10-25 04:45 131964 c:\windows\system32\perfc009.dat
- 2006-11-02 12:46 . 2011-10-24 19:23 131964 c:\windows\system32\perfc009.dat
+ 2009-05-01 20:22 . 2011-10-25 05:02 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-05-01 20:22 . 2011-10-24 19:17 262144 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2011-10-25 01:49 . 2011-10-25 01:49 219648 c:\windows\Installer\48a7bb.msi
- 2008-06-07 05:13 . 2011-10-02 09:51 3375104 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-07 05:13 . 2011-10-25 05:00 3375104 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 12:33 . 2011-10-24 18:37 11272192 c:\windows\system32\SMI\Store\Machine\schema.dat
+ 2006-11-02 12:33 . 2011-10-25 01:57 11272192 c:\windows\system32\SMI\Store\Machine\schema.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files (x86)\Windows Media Player\WMPNSCFG.exe" [BU]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AsioThk32Reg"="CTASIO.DLL" [2010-05-06 51712]
"VolPanel"="c:\program files (x86)\Creative\Volume Panel\VolPanlu.exe" [BU]
"TkBellExe"="c:\program files (x86)\Common Files\Real\Update_OB\realsched.exe" [2009-11-23 198160]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"AmazonGSDownloaderTray"="c:\program files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-10-23 326144]
"CTxfiHlp"="CTXFIHLP.EXE" [2010-05-06 25600]
"QuickTime Task"="c:\program files (x86)\MpcStar\Codecs\QuickTime\QTTask.exe" [2011-07-05 421888]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
SetPointII.lnk - c:\program files\Logitech\SetPoint II\SetPointII.exe [2007-8-30 809984]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLUA"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-25 136176]
R3 Amazon Download Agent;Amazon Download Agent;c:\program files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [2009-10-23 401920]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2011-05-10 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-11-19 79360]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [x]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [x]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [x]
R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-25 136176]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 LicCtrlService;LicCtrl Service;c:\windows\runservice.exe [2011-07-17 2560]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-14 2226792]
S3 chdrvr01;CH Control Manager Driver 1;c:\windows\system32\DRIVERS\chdrvr01.sys [x]
S3 chdrvr02;CH Control Manager Driver 2;c:\windows\system32\DRIVERS\chdrvr02.sys [x]
S3 chdrvr03;chdrvr03;c:\windows\system32\DRIVERS\chdrvr03.sys [x]
S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [x]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [x]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [x]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [x]
S3 npusbio;npusbio;c:\windows\system32\Drivers\npusbio_x64.sys [x]
S3 NVNET55;NVIDIA nForce 10/100/1000 Mbps Ethernet ;c:\windows\system32\DRIVERS\nvmimx64.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-25 01:50]
.
2011-10-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-10-25 01:50]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-07-17 134160]
"Launch LgDeviceAgent"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2009-08-14 415752]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2009-08-13 2093064]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2009-08-14 4195848]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-10-01 825184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
Trusted Zone: mozilla.com\www
TCP: DhcpNameServer = 192.168.1.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
FF - ProfilePath - c:\users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\5ttf6sw7.default\
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-Windows Defender - c:\program files (x86)\Windows Defender\MSASCui.exe
AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-BattlEye - c:\program files (x86)\steam\steamapps\common\arma 2BattlEye\UnInstallBE.exe
AddRemove-BattlEye for OA - g:\program files\steam\steamapps\common\arma 2 operation arrowheadExpansion\BattlEye\UnInstallBE.exe
AddRemove-Fallout Mod Manager_is1 - c:\program files (x86)\steam\steamapps\common\fallout 3 goty\fomm\uninstall\unins000.exe
AddRemove-Graphical Enhancement Resources - e:\program files\Mount&Blade\uninstall_commonres_pack.exe
AddRemove-Graphical Enhancement Textures - e:\program files\Mount&Blade\uninstall_texture_pack.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
AddRemove-Steam App 10680 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 12210 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 1500 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 17450 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 1930 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 21970 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 21980 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 24400 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 24960 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 27000 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 28000 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 33900 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 40700 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 42910 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 43110 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 48700 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 550 - c:\program files (x86)\Steam\steam.exe
AddRemove-Steam App 80000 - c:\program files (x86)\Steam\steam.exe
AddRemove-JScreenFix - c:\windows\system32\javaws.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1787995230-711523803-3076010400-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
"??"=hex:f1,e6,84,f6,26,73,a7,60,32,9c,9b,f0,de,16,3b,76,5b,30,f3,60,ab,2f,70,
07,d7,c5,95,59,ad,36,6f,e1,4f,86,ea,1c,c4,ba,29,4a,c6,48,6f,ca,fb,a1,f6,72,\
"??"=hex:c6,9b,7c,aa,dd,7d,a6,fd,b6,bf,b5,8f,fe,30,cd,49
.
[HKEY_USERS\S-1-5-21-1787995230-711523803-3076010400-1000\Software\SecuROM\License information*]
"datasecu"=hex:a6,f5,d4,1d,3b,19,59,5c,43,f3,26,a1,25,c3,6a,28,8b,11,0c,83,8e,
0d,88,60,62,9f,e7,77,7a,84,1c,f7,1a,a5,11,7a,e8,e0,89,98,91,1c,f4,05,10,40,\
"rkeysecu"=hex:84,83,28,42,05,f6,23,8a,bd,5f,77,2c,42,ca,84,50
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.9"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash9f.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9f.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil9f.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
@Denied: (A 2) (Everyone)
@="IFlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \D25BC253F035D347]
"1"=hex:6a,0b,56,13,c1,93,dc,9c,fb,61,a2,a0,e4,ff,91,20,60,bf,2f,c2,35,91,ae,
25
"2"=hex:fb,e6,50,7f,41,f4,51,a7,7f,ec,2d,f9,42,45,3a,02,3a,b7,45,15,3f,9d,8b,
c3
"3"=hex:6a,0b,56,13,c1,93,dc,9c,fb,61,a2,a0,e4,ff,91,20,5d,f5,58,d1,21,e0,48,
8b,38,57,44,9c,4e,8d,78,88,fd,f1,01,9d,86,d8,b5,cb,d9,bf,23,55,4a,bb,31,1f
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \D25BC253F035D347\0472A5F591DE6EF2D1809DE316FEF63A]
"1"=hex:29,fc,2c,6f,ce,aa,f2,69,e8,37,99,34,ad,33,e5,ad
"2"=hex:12,f9,35,71,08,62,dd,b1
"3"=hex:ad,5f,c6,98,7e,bc,0f,22,d1,01,38,55,1a,8b,a2,63,57,68,f0,72,8c,65,90,
f0,40,ba,67,ed,2b,0a,60,03,0f,7a,75,4e,0b,a9,0e,6e,01,84,7f,37,9c,5d,ce,1f,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:29,fc,2c,6f,ce,aa,f2,69,91,58,78,d6,14,eb,6c,a9,de,cd,51,b9,df,64,e3,
ab,8e,48,3d,02,33,b8,24,79,16,a3,2d,4e,34,ce,a4,f8,78,49,2a,cb,3c,6d,8e,47,\
"7"=hex:6a,0b,56,13,c1,93,dc,9c,a0,00,aa,b4,e4,7b,e0,c8,74,2a,16,32,d3,b5,82,
f9,9f,42,18,f6,e4,ae,ab,8d,c8,97,d7,68,80,f0,f7,2b,97,55,94,90,3e,a5,3b,6a,\
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,43,69,70,4c,7e,7f,7c,
de,a0,46,ee,d1,e1,d8,58,7c,16,70,d4,a0,8c,ec,86,77,7d,72,2c,53,77,0b,6f,be,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:d0,71,12,cb,08,b7,a7,d6
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:64,29,c6,72,26,3a,bc,62,7f,ad,70,79,d2,7c,44,4c,f2,9d,e5,18,79,7b,4d,
c0,44,de,5b,b1,a8,50,d5,04,86,e8,10,55,99,d8,c2,69,44,c5,e0,3a,0e,9c,fa,2f,\
"13"=hex:f6,a6,f1,66,bd,09,35,15,47,21,ca,50,14,2b,da,f5,1d,02,33,ac,7a,f0,30,
a1
"14"=hex:15,24,77,86,e3,cd,8e,2c,a9,6f,d7,b7,1a,9c,78,6b
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:6e,03,58,68,65,9c,f5,be,49,f0,3e,aa,ff,42,eb,8b
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:f6,a8,f5,4f,3c,f5,b5,60,2b,ec,47,87,ac,a3,fb,59,9f,0d,30,f3,32,8c,a4,
7a,d5,7c,e3,12,33,5f,08,b6,cd,71,5a,18,a5,df,03,c5,ae,a6,a8,9e,91,b4,71,03,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \D25BC253F035D347\C4838B3D951212E6CDEE180D9201C56E]
"1"=hex:07,1f,1a,27,85,96,85,c3,38,71,53,58,52,6e,65,80,4c,0f,9a,93,b5,f7,5b,
e0
"2"=hex:0d,61,15,35,3f,ec,03,67
"3"=hex:01,01,19,43,70,2d,c9,18,f3,48,c5,94,89,f0,e2,13,ef,cf,90,7a,13,d2,62,
1a,53,a9,d8,55,78,d0,35,72,f2,19,db,7c,99,9c,98,f0,17,83,f1,86,d6,04,4a,8c,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:07,1f,1a,27,85,96,85,c3,38,71,53,58,52,6e,65,80,0a,e7,b1,ce,73,6a,58,
57,ea,89,c4,2a,ac,9b,2f,fa,c1,bc,5c,c1,e9,c5,f3,62,38,ea,16,8c,a1,a7,a5,09,\
"7"=hex:6a,0b,56,13,c1,93,dc,9c,fb,61,a2,a0,e4,ff,91,20,56,a7,02,9d,f0,a0,1d,
cc,28,d9,b1,18,9e,f1,8d,e8,54,e6,61,27,95,2e,52,cc,1c,f7,fa,64,bd,24,b7,82,\
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,43,69,70,4c,7e,7f,7c,
de,a0,46,ee,d1,e1,d8,58,7c,16,70,d4,a0,8c,ec,86,77,7d,72,2c,53,77,0b,6f,be,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:d0,71,12,cb,08,b7,a7,d6
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:e6,b9,76,dd,d5,90,90,b7,2d,65,66,20,8c,4f,cf,fc,d3,53,44,ad,5b,ec,9d,
b3,1f,f0,f1,44,8e,6f,ac,f5,ad,94,6a,55,a3,e9,cc,77,e3,f7,42,5b,ac,85,7d,7d,\
"13"=hex:3c,18,2b,d4,38,26,d5,62,57,b5,56,f4,fc,36,90,70,e8,8c,59,9a,9b,1a,b6,
49
"14"=hex:cc,37,e6,02,49,3c,f3,ea,f2,40,e6,1c,3c,12,e0,3d
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:6e,03,58,68,65,9c,f5,be,49,f0,3e,aa,ff,42,eb,8b
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:3b,eb,c3,4d,0e,fc,32,2d,68,51,f5,00,d3,35,9d,6e,19,a2,c0,e9,ed,d0,47,
34,b8,d1,6f,d2,7b,d3,23,c8,00,be,af,8f,78,c6,5e,10,81,f0,ce,a0,0f,4b,fe,37,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \D25BC253F035D347\DF7B54A6112C2A0959607A574D3D99D6]
"1"=hex:05,a5,52,27,27,68,21,41,63,83,05,15,ef,55,2c,92
"2"=hex:0d,61,15,35,3f,ec,03,67
"3"=hex:7c,30,70,f4,f1,2f,24,2b,07,d4,c8,10,50,5f,b1,9c,4d,4d,7a,5b,f4,dd,bb,
54,0d,ff,07,ba,bf,b1,e5,47,48,8f,f7,1f,d9,50,19,53,72,bb,23,ac,63,7c,ec,71,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:05,a5,52,27,27,68,21,41,e8,57,cb,d5,86,b9,d9,4d,04,e9,ec,33,5f,dc,e0,
5f,f1,36,b3,d4,f9,4f,c1,10,42,ec,21,28,86,84,ba,98,1e,6a,ac,b2,20,42,3f,13,\
"7"=hex:6a,0b,56,13,c1,93,dc,9c,fb,61,a2,a0,e4,ff,91,20,56,a7,02,9d,f0,a0,1d,
cc,28,d9,b1,18,9e,f1,8d,e8,54,e6,61,27,95,2e,52,cc,1c,f7,fa,64,bd,24,b7,82,\
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,43,69,70,4c,7e,7f,7c,
de,a0,46,ee,d1,e1,d8,58,7c,16,70,d4,a0,8c,ec,86,77,7d,72,2c,53,77,0b,6f,be,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:d0,71,12,cb,08,b7,a7,d6
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:d5,90,e6,df,4e,37,01,15,0c,c2,ff,ad,61,7c,6a,9d,39,0c,79,c9,07,ef,e3,
ac,65,be,f2,80,0d,c6,1b,5a,a1,43,f4,b1,0e,10,22,86,33,8d,21,6e,46,8b,6e,d7,\
"13"=hex:f0,33,65,9f,eb,89,46,b0,63,1b,8f,01,9c,12,f9,88,a1,9a,09,82,82,d5,4b,
42
"14"=hex:08,ff,2b,1c,69,18,ef,7b,2e,51,47,6e,41,a5,c7,f7
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:6e,03,58,68,65,9c,f5,be,49,f0,3e,aa,ff,42,eb,8b
"22"=hex:81,20,8f,ab,28,6a,52,9c
"15"=hex:7d,53,1c,0a,cf,9d,47,75,c8,92,3c,95,49,d1,43,24,9c,0b,a9,e3,43,db,f2,
7c,65,49,3b,bf,20,39,49,ec,80,7f,ac,24,3a,ff,e0,15,7b,c4,8f,e5,18,79,04,f6,\
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\IObit\Game Booster\gbtray.exe
c:\program files (x86)\Windows Media Player\wmplayer.exe
.
**************************************************************************
.
Completion time: 2011-10-25 00:07:30 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-25 05:07
.
Pre-Run: 206,310,313,984 bytes free
Post-Run: 206,291,058,688 bytes free
.
- - End Of File - - 35ECEB32026ED4BD9DAC5FE58BEB9C5A
Thanks!