ComboFix 08-08-18.05 - Cassie 2008-08-20 19:09:02.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1170 [GMT 10:00]
Running from: C:\Documents and Settings\Cassie\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Cassie\Cookies\cassie@adsfac[3].txt
C:\Documents and Settings\Cassie\Cookies\cassie@serving-sys[2].txt
C:\Documents and Settings\Cassie\UserData
C:\Documents and Settings\Cassie\UserData\index.dat
C:\Documents and Settings\Cassie\UserData\PYFSNRSH\IsOnIE6tbPromo[1].xml
C:\Documents and Settings\Cassie\UserData\ZQVB6PQZ\oWindowsUpdate[1].xml
.
---- Previous Run -------
.
C:\WINDOWS\system32\AutoRun.inf
.
((((((((((((((((((((((((( Files Created from 2008-07-20 to 2008-08-20 )))))))))))))))))))))))))))))))
.
2008-08-20 18:06 . <DIR> C:\WINDOWS\LastGood.Tmp
2008-08-14 21:53 . 2008-08-14 21:53 17 --a------ C:\WINDOWS\Ezonebashout.prf
2008-08-14 21:52 . 2008-08-14 21:52 17 --a------ C:\WINDOWS\Ezoneblingball.prf
2008-08-14 21:50 . 2008-08-14 21:50 17 --a------ C:\WINDOWS\Ezonecanetoad.prf
2008-08-09 14:30 . 2008-08-09 14:30 <DIR> d-------- C:\Documents and Settings\Cassie\Application Data\Alawar
2008-08-09 13:52 . 2008-08-09 14:09 <DIR> d-------- C:\Program Files\Motorola Phone Tools
2008-08-09 13:52 . 2007-06-18 15:18 23,680 --a------ C:\WINDOWS\system32\drivers\motmodem.sys
2008-08-09 10:54 . 2008-08-09 11:25 <DIR> d-------- C:\Program Files\ElastoMania111
2008-08-08 20:18 . 2008-08-08 20:18 <DIR> d-------- C:\Documents and Settings\Cassie\Application Data\ViquaSoft
2008-08-05 22:03 . 2008-08-05 22:03 <DIR> d-------- C:\Program Files\iTunes
2008-08-05 22:03 . 2008-08-05 22:03 <DIR> d-------- C:\Program Files\iPod
2008-07-31 17:09 . 2008-07-31 17:09 17 --a------ C:\WINDOWS\Ezonebangbuck.prf
2008-07-30 19:33 . 2008-07-30 19:33 17 --a------ C:\WINDOWS\Ezonesurfing.prf
2008-07-29 18:11 . 2008-08-16 18:15 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-27 20:06 . 2008-07-27 20:06 17 --a------ C:\WINDOWS\Ezonecookiebumper.prf
2008-07-27 19:45 . 1993-04-28 21:00 394,384 --a------ C:\WINDOWS\system32\VBRUN300.DLL
2008-07-27 19:45 . 1998-06-18 00:00 89,360 --a------ C:\WINDOWS\system32\VB5DB.DLL
2008-07-27 19:45 . 1994-12-08 05:44 85,988 --a------ C:\WINDOWS\WINLIB.DLL
2008-07-27 19:45 . 1994-03-31 21:15 34,816 --a------ C:\WINDOWS\TOSRUN.SCR
2008-07-27 19:45 . 2008-07-30 19:38 259 --a------ C:\WINDOWS\TOS.INI
2008-07-27 19:45 . 2008-07-27 19:45 58 --a------ C:\WINDOWS\101aasg.ini
2008-07-27 19:44 . 2008-07-27 19:45 <DIR> d-------- C:\101aasg
2008-07-27 18:19 . 2008-07-27 18:28 <DIR> d-------- C:\Program Files\FrostWire
2008-07-27 18:19 . 2008-07-27 18:19 <DIR> d-------- C:\Program Files\AskSBar
2008-07-27 18:19 . 2008-08-18 21:35 <DIR> d-------- C:\Documents and Settings\Cassie\Application Data\FrostWire
2008-07-27 17:16 . 2008-07-27 17:16 <DIR> d-------- C:\Program Files\Maxis
2008-07-27 15:40 . 2008-07-27 15:40 <DIR> d-------- C:\Program Files\alot
2008-07-27 15:40 . 2008-07-27 19:24 <DIR> d-------- C:\Documents and Settings\Cassie\Application Data\alot
2008-07-23 14:17 . 2008-08-20 17:04 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-23 14:17 . 2008-07-23 14:17 <DIR> d-------- C:\Program Files\AVG
2008-07-23 14:17 . 2008-07-26 17:09 <DIR> d-------- C:\Documents and Settings\Cassie\Application Data\AVGTOOLBAR
2008-07-23 14:17 . 2008-07-23 14:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-23 14:17 . 2008-07-23 14:17 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-23 14:17 . 2008-07-23 14:17 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-23 14:17 . 2008-07-23 14:17 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-20 15:34 . 2008-07-20 15:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FreshGames
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-18 06:06 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-16 10:16 --------- d-----w C:\Program Files\MSN Games
2008-08-16 10:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sandlot Games
2008-08-16 10:09 --------- d-----w C:\Program Files\Shockwave.com
2008-08-09 03:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-05 12:21 --------- d-----w C:\Program Files\Apple Software Update
2008-07-30 08:25 --------- d-----w C:\Program Files\Avanquest update
2008-07-25 07:43 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-23 04:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-07-20 10:59 --------- d-----w C:\Program Files\Zylom Games
2008-07-20 05:18 --------- d-----w C:\Program Files\Java
2008-07-15 06:54 --------- d-----w C:\Documents and Settings\Cassie\Application Data\Zylom
2008-07-15 06:54 --------- d-----w C:\Documents and Settings\Cassie\Application Data\PlayFirst
2008-07-15 06:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zylom
2008-07-15 06:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-07-12 10:13 --------- d-----w C:\Program Files\QuickTime
2008-07-12 09:47 --------- d-----w C:\Program Files\Safari
2008-07-09 23:35 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-07-09 07:34 --------- d-----w C:\Program Files\CCleaner
2008-06-29 04:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-06-27 02:44 --------- d-----w C:\Program Files\Aimersoft
2008-06-21 08:51 --------- d-----w C:\Program Files\Sierra On-Line
2008-06-21 08:42 --------- d-----w C:\Program Files\WON
2008-06-09 06:31 24,192 ----a-w C:\Documents and Settings\Cassie\usbsermptxp.sys
2008-06-09 06:31 22,768 ----a-w C:\Documents and Settings\Cassie\usbsermpt.sys
.
------- Sigcheck -------
2008-03-25 17:07 502272 6225f14b8ce08ccba8b25ad27843c674 C:\WINDOWS\system32\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-07-27 18:19 66912]
[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-07-27 18:19 66912 --a------ C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 22:00 15360]
"MsnMsgr"="C:\PROGRA~1\WINDOW~4\MESSEN~1\MsnMsgr.Exe" [2007-10-18 10:34 5724184]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2008-05-10 15:00 16384]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-02-28 22:06 2321600]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-23 18:01 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-31 08:35 7634944]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-31 08:35 86016]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 23:47 31016]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 14:10 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 21:55 54832]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 14:57 153136]
"SecurDisc"="C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 14:55 1628208]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 14:55 1057328]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 15:40 1884160]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 20:34 49152]
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2002-07-22 01:10 577602]
"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2002-07-09 08:50 28672]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2003-06-30 20:56 188416]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2003-06-30 21:00 65536]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-23 14:17 1232152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 10:47 289064]
"nwiz"="nwiz.exe" [2006-10-31 08:35 1622016 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-27 16:20 16844800 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-08-03 15:22 1826816 C:\WINDOWS\SkyTel.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"symPCCheckup"="C:\WINDOWS\system32\Adobe\Shockwave 11\symcheckupstub.exe" [2008-08-20 18:09 234872]
C:\Documents and Settings\Ros\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 19:24:54 98632]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 20:26:24 210520]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-08-11 02:22:40 757760]
Kodak software updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 14:12:08 16423]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-05-10 15:00:54 169472]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2008-03-25 19:26:13 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Documents and Settings\\Cassie\\My Documents\\Games\\Halo CE\\play.exe"=
"C:\\Documents and Settings\\Cassie\\My Documents\\Games\\Halo CE\\haloceded.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\FrostWire\\FrostWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-23 14:17]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-23 14:17]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-23 14:17]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-23 14:17]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 08:05]
S3 LCcfltr;Logitech USB Filter Driver;C:\WINDOWS\system32\drivers\lccfltr.sys [2002-07-09 19:50]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{214a5130-fab7-11dc-8b01-001e8c1bd44b}]
\Shell\AutoRun\command - F:\
.
Contents of the 'Scheduled Tasks' folder
2008-08-05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-08-20 C:\WINDOWS\Tasks\Norton PC Checkup Setup.job
- C:\WINDOWS\system32\Adobe\Shockwave 11\symcheckupstub.exe [2008-08-20 18:09]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-DrvIcon - C:\Program Files\Vista Drive Icon\DrvIcon.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com
R1 -: HKCU-Internet Settings,ProxyOverride = *.local;localhost
O8 -: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 -: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 -: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 -: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 -: eBay Search - C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-20 19:15:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-08-20 19:25:02 - machine was rebooted [Cassie]
ComboFix-quarantined-files.txt 2008-08-20 09:23:58
Pre-Run: 220,635,635,712 bytes free
Post-Run: 221,150,572,544 bytes free
255