View Single Post
Old 12-02-2008, 01:49 PM   #3 (permalink)
matua105
Registered User
 
Join Date: Mar 2007
Posts: 12
OS: Windows XP


Re: Unsolicited New Window pop ups on IE7 and Firefox

Thanks very much Chemist for your response. Here is the Combofix log:

ComboFix 08-12-01.03 - unpingco 2008-12-02 12:17:35.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.341 [GMT -8:00]
Running from: c:\documents and settings\unpingco\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\unpingco\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\autorun.inf
c:\windows\Downloaded Program Files\setup.inf
c:\windows\IE4 Error Log.txt
c:\windows\system32\ayurupan.ini
c:\windows\system32\buyoziyi.dll
c:\windows\system32\fofajivo.dll
c:\windows\system32\iyibihap.ini
c:\windows\system32\kakinahu.dll
c:\windows\system32\kalerazo.dll
c:\windows\system32\mezutilo.dll
c:\windows\system32\napuruya.dll
c:\windows\system32\nefuwipi.dll
c:\windows\system32\pafigewi.dll
c:\windows\system32\pahibiyi.dll
c:\windows\system32\uhanikak.ini
c:\windows\system32\zitofavi.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ISODRIVE
-------\Service_ISODrive


((((((((((((((((((((((((( Files Created from 2008-11-02 to 2008-12-02 )))))))))))))))))))))))))))))))
.

2008-12-02 12:37 . 0 c:\windows\system32\PerfStringBackup.TMP
2008-12-01 11:50 . 2008-12-01 12:04 <DIR> d-------- c:\documents and settings\unpingco\.SunDownloadManager
2008-12-01 11:22 . 2008-12-01 11:22 <DIR> d-------- c:\program files\Gmer
2008-12-01 11:17 . 2008-12-01 16:16 250 --a------ c:\windows\gmer.ini
2008-11-30 16:50 . 2008-11-30 16:50 1,281,506 --a------ C:\Sym_LoadPointDiag.zip
2008-11-30 16:43 . 2008-11-30 16:50 <DIR> d-------- C:\Sym_LoadPointDiag
2008-11-30 15:11 . 2008-11-30 15:11 578,560 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-11-30 15:04 . 2008-11-30 15:04 <DIR> d-------- c:\windows\ERUNT
2008-11-30 14:53 . 2008-11-30 15:35 <DIR> d-------- C:\SDFix
2008-11-30 01:26 . 2008-11-30 01:26 0 --a------ C:\AVScript26.js
2008-11-29 12:06 . 2008-11-29 12:06 <DIR> d-------- c:\program files\Panda Security
2008-11-29 12:06 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys
2008-11-13 17:19 . 2008-11-13 17:19 1,138,869 --a------ C:\ESUGLPDU_2.01.exe
2008-11-11 20:16 . 2008-10-24 03:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-11 20:12 . 2008-09-04 09:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-08 17:52 . 2008-11-25 22:21 <DIR> d-------- c:\documents and settings\unpingco\Application Data\LimeWire
2008-11-08 17:51 . 2008-11-25 22:22 <DIR> d-------- c:\program files\LimeWire

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 19:42 --------- d-----w c:\program files\symantec antivirus
2008-12-02 00:11 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-02 00:10 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-02 00:10 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-01 23:18 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-18 16:14 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-03 20:58 --------- d-----w c:\documents and settings\unpingco\Application Data\FileZilla
2008-11-02 04:24 --------- d-----w c:\program files\QuickTime
2008-11-02 04:23 --------- d-----w c:\program files\Common Files\Apple
2008-11-02 04:08 --------- d-----w c:\program files\Bonjour
2008-10-30 14:27 --------- d-----w c:\program files\McAfee
2008-10-29 21:29 --------- d-----w c:\program files\FileZilla FTP Client
2008-10-29 21:28 3,696,811 ----a-w c:\program files\FileZilla_3.1.5_win32-setup.exe
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 13:21 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-16 14:36 --------- d-----w c:\program files\HPAVAdminScan
2008-10-14 15:54 --------- d-----w c:\documents and settings\unpingco\Application Data\Apple Computer
2008-10-14 15:51 349,880 ----a-w c:\windows\adminScanInstall.EXE
2008-10-08 20:35 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-10-07 15:01 3,659,444 ----a-w c:\program files\FileZilla_3.1.3.1_win32-setup.exe
2008-09-02 23:38 3,648,871 ----a-w c:\program files\FileZilla_3.1.2_win32-setup.exe
2008-09-02 15:52 380,416 ----a-w c:\program files\CommunicatorPoliciesDocumentation.msi
2008-08-26 19:01 5,249,122 ----a-w c:\program files\FileZilla_3.1.1.1_win32.zip
2008-06-06 19:37 31,356,640 ----a-w c:\documents and settings\unpingco\symcdefsi32.exe
2008-03-07 23:31 260,608 ----a-w c:\program files\WordMailSupport.msi
2007-04-02 10:46 13,248 ----a-w c:\windows\system32\config\systemprofile\createprof.vbs
2007-04-02 10:46 13,248 ----a-w c:\documents and settings\hpadmin\createprof.vbs
2007-04-02 10:46 13,248 ----a-w c:\documents and settings\Default User\createprof.vbs
2007-02-23 14:43 851 ----a-w c:\windows\system32\config\systemprofile\enablecoe.vbs
2007-02-23 14:43 851 ----a-w c:\documents and settings\hpadmin\enablecoe.vbs
2006-10-28 05:06 2,480 ----a-w c:\program files\README.HTM
2008-02-01 19:05 88 --sh--r c:\windows\system32\9999CCE4CD.sys
2008-02-01 19:05 2,828 --sha-w c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-09 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"HP Virtual Rooms"="c:\progra~1\HEWLET~1\HPVIRT~1.0\\HPVIRT~1.EXE" [2008-02-24 10294616]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COEMsgDisplay"="c:\program files\Hewlett-Packard\PC COE\COEMsgDisplay.exe" [2007-04-11 26624]
"QuickPassword"="c:\program files\ActivCard\ActivCard Gold\agquickp.exe" [2007-06-26 225280]
"IDA"="c:\program files\Hewlett-Packard\PC COE\IDA.EXE" [2008-08-12 176128]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-07-13 344064]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-01-18 185896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-02-15 39792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"T-Mobile Connection Manager"="c:\program files\T-Mobile\Connection Manager\TMobileCM.exe" [2007-07-23 18968]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"Communicator"="c:\program files\Microsoft Office Communicator\communicator.exe" [2008-08-19 5720072]
"GetIT"="c:\program files\Hewlett-Packard\GetIT\GetIT.exe" [2007-12-03 286720]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-07-08 115560]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"Corel Photo Downloader"="c:\program files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" [2007-08-28 531272]

c:\documents and settings\unpingco\Start Menu\Programs\Startup\
SDK Tray Menu.lnk - c:\sun\SDK\jdk\bin\javaw.exe [2008-01-09 135168]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-01-05 113664]
Sonic CinePlayer Quick Launch.lnk - c:\program files\Common Files\Sonic Shared\CineTray.exe [2006-07-25 114688]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
"DisableNT4Policy"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoMSAppLogo5ChannelNotify"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"Btn_Back"= 0 (0x0)
"Btn_Forward"= 0 (0x0)
"Btn_Stop"= 0 (0x0)
"Btn_Refresh"= 0 (0x0)
"Btn_Home"= 0 (0x0)
"Btn_Search"= 0 (0x0)
"Btn_History"= 0 (0x0)
"Btn_Favorites"= 0 (0x0)
"Btn_Media"= 0 (0x0)
"Btn_Folders"= 0 (0x0)
"Btn_Fullscreen"= 0 (0x0)
"Btn_Tools"= 0 (0x0)
"Btn_MailNews"= 0 (0x0)
"Btn_Size"= 0 (0x0)
"Btn_Print"= 0 (0x0)
"Btn_Edit"= 0 (0x0)
"Btn_Discussions"= 0 (0x0)
"Btn_Cut"= 0 (0x0)
"Btn_Copy"= 0 (0x0)
"Btn_Paste"= 0 (0x0)
"Btn_Encoding"= 0 (0x0)
"Btn_PrintPreview"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Hewlett-Packard\\PC COE 3\\OV CMS\\radexecd.exe"=
"c:\\Program Files\\Hewlett-Packard\\PC COE 3\\OV CMS\\RADUISHELL.exe"=
"c:\\Program Files\\Hewlett-Packard\\PC COE 3\\OV CMS\\RadTray.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Hewlett-Packard\\PC COE\\Ida.exe"=
"c:\\Program Files\\ActivCard\\ActivCard Gold\\agutils.exe"=
"c:\\Program Files\\ActivCard\\ActivCard Initialization Utility\\ResetUtil.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\Hewlett-Packard\\PC COE\\AboutCOE.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office Communicator\\communicator.exe"=
"c:\\Program Files\\symantec antivirus\\Smc.exe"=
"c:\\Program Files\\symantec antivirus\\SNAC.EXE"=
"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-11-29 28544]
R2 acautoreg;ActivCard Gold Autoregister;c:\program files\Common Files\ActivCard\acautoreg.exe [2007-06-26 53248]
R2 Accoca;ActivCard Gold service;c:\program files\Common Files\ActivCard\accoca.exe [2004-05-12 143360]
R2 AppServer9PE;SunJavaSystemAppserver9PE;c:\sun\SDK\lib\appservService.exe "\"c:\sun\SDK\bin\asadmin.bat\" start-domain --user admin domain1" "\"c:\sun\SDK\bin\asadmin.bat\" stop-domain domain1\" []
R2 AvChgSvc;HP-AV Change Monitor Service;c:\progra~1\HPAVAD~1\avChgSvc.exe [2008-10-07 238080]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\McAfee\SiteAdvisor\McSACore.exe" [2008-07-31 203280]
R2 msralinkmonitor;MSRA Link Monitor;"c:\program files\Remote tools\msraLinkMonitor.exe" [2007-08-28 147456]
R2 radexecd;HP OVCM Notify Daemon;"c:\program files\Hewlett-Packard\PC COE 3\OV CMS\radexecd.exe" [2007-02-20 270510]
R2 radsched;HP OVCM Scheduler Daemon;"c:\program files\Hewlett-Packard\PC COE 3\OV CMS\radsched.exe" [2007-03-22 172205]
R2 Radstgms;HP OVCM MSI Redirector;"c:\program files\Hewlett-Packard\PC COE 3\OV CMS\Radstgms.exe" [2008-07-03 315570]
R2 WGX;Extend WG Protocol Driver;c:\windows\system32\Drivers\WGX.SYS [2008-07-08 38632]
R3 akbus;ActivCard Virtual Reader Enumerator;c:\windows\system32\DRIVERS\akbus.sys [2007-01-26 13619]
R3 akpcsc;ActivCard Virtual PC/SC Device Driver;c:\windows\system32\DRIVERS\akpcsc.sys [2007-01-26 9493]
R3 aksbus;ActivIdentity Virtual Reader Enumerator;c:\windows\system32\DRIVERS\aksbus.sys [2007-04-06 13647]
R3 AKSIM;ActivKey Sim;c:\windows\system32\drivers\aksim.sys [2007-06-28 27008]
R3 akspcsc;ActivIdentity Virtual PC/SC Device Driver;c:\windows\system32\DRIVERS\akspcsc.sys [2007-06-28 10161]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-20 99376]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\DRIVERS\HSFHWATI.sys [2005-08-23 231424]
R3 RadiaMsi;RadiaMsi;c:\windows\system32\DRIVERS\radiamsi.sys [2007-08-03 23424]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\DRIVERS\ipsecw2k.sys [2008-01-03 114016]
S2 WinDefend;Windows Defender;"c:\program files\Windows Defender\MsMpEng.exe" [2006-11-03 13592]
S3 COH_Mon;COH_Mon;\??\c:\windows\system32\Drivers\COH_Mon.sys [2008-07-08 23888]
S3 IPSECSHM;Nortel IPSECSHM Adapter;c:\windows\system32\DRIVERS\ipsecw2k.sys [2008-01-03 114016]
S3 magaService;Lan Discover Agent;c:\program files\Sygate\SSA\maga\maga.exe []
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 [2006-12-02 2805000]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C99D666B-62E4-461B-A346-9375D55AB9BC}]
"c:\program files\Common Files\Hewlett-Packard\ActSet\HpActSet.exe"
.
Contents of the 'Scheduled Tasks' folder

2008-11-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]

2008-12-02 c:\windows\Tasks\IDA{07A2D605-F561-11D1-BEE5-AC785AC8CD4E}000.job
- c:\windows\system32\rundll32.exe [2008-04-13 16:12]

2008-12-02 c:\windows\Tasks\IDA{07A2D605-F561-11D1-BEE5-AC785AC8CD4E}001.job
- c:\windows\system32\rundll32.exe [2008-04-13 16:12]

2008-12-02 c:\windows\Tasks\IDA{5B940D5F-0A3F-11D2-95B5-080009DC8202}000.job
- c:\windows\system32\rundll32.exe [2008-04-13 16:12]

2008-12-02 c:\windows\Tasks\IDA{5B940D5F-0A3F-11D2-95B5-080009DC8202}001.job
- c:\program files\Hewlett-Packard\PC COE\coetl32.exe [2007-06-24 00:27]

2008-12-02 c:\windows\Tasks\IDA{E1B2A4DD-AE06-4B97-9B55-8E8F1348E7FB}000.job
- c:\windows\system32\rundll32.exe [2008-04-13 16:12]
.
- - - - ORPHANS REMOVED - - - -

BHO-{7c65880c-643b-4724-890f-4d191275a79e} - c:\windows\system32\nefuwipi.dll
Notify-NavLogon - (no file)
SafeBoot-Symantec Antvirus


.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\unpingco\Application Data\Mozilla\Firefox\Profiles\ccvwf14m.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.30523.8\npctrl.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30401.0.dll
FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - c:\program files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 12:34:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1060)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\accsp.dll
c:\windows\system32\acerrmes.dll
c:\windows\system32\asphat32.dll
c:\windows\system32\acpinto.dll
c:\windows\system32\aspcom.dll
c:\program files\ActivCard\ActivCard Gold\resources\acerrmrc.dll
c:\program files\ActivCard\ActivCard Gold\resources\asphatrc.dll
c:\program files\ActivCard\ActivCard Gold\resources\accsprc.dll
c:\windows\system32\acgnd.dll
c:\program files\ActivCard\ActivCard Gold\resources\acgndrc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\symantec antivirus\Smc.exe
c:\program files\symantec antivirus\SNAC.EXE
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\windows\system32\scardsvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\sun\SDK\lib\appservService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\PSIService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\symantec antivirus\Rtvscan.exe
c:\sun\SDK\jdk\bin\java.exe
c:\program files\UPHClean\uphclean.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\ati2evxx.exe
c:\program files\symantec antivirus\SmcGui.exe
c:\progra~1\HPQ\Shared\HPQTOA~1.EXE
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\searchfilterhost.exe
.
**************************************************************************
.
Completion time: 2008-12-02 12:44:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-02 20:43:10

Pre-Run: 23,637,913,600 bytes free
Post-Run: 23,819,386,880 bytes free

295 --- E O F --- 2008-11-12 15:22:18

Regards,
matua105
matua105 is offline