and the combofix log
ComboFix 08-05-01.3 - ywu 2008-05-06 19:17:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1609 [GMT 8:00]
Running from: C:\Documents and Settings\ywu\Desktop\PC stuff\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\LocalService\Local Settings\Application Data\baidu
C:\Documents and Settings\ywu\Application Data\macromedia\Flash Player\#SharedObjects\R58996YM\iforex.com
C:\Documents and Settings\ywu\Application Data\macromedia\Flash Player\#SharedObjects\R58996YM\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\ywu\Application Data\macromedia\Flash Player\#SharedObjects\R58996YM\www.broadcaster.com
C:\Documents and Settings\ywu\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\ywu\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\Documents and Settings\ywu\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\ywu\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\Documents and Settings\ywu\Local Settings\Application Data\baidu
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\setup.exe
C:\WINDOWS\system32\adylnesu.ini
C:\WINDOWS\system32\alwhaldq.ini
C:\WINDOWS\system32\bayppisc.ini
C:\WINDOWS\system32\bficegjm.ini
C:\WINDOWS\system32\clipfdly.ini
C:\WINDOWS\system32\frfrxout.ini
C:\WINDOWS\system32\friwubxo.ini
C:\WINDOWS\system32\hflnpbiw.ini
C:\WINDOWS\system32\hgjlm.ini
C:\WINDOWS\system32\hgjlm.ini2
C:\WINDOWS\system32\hsghnfym.ini
C:\WINDOWS\system32\hsmyobuq.ini
C:\WINDOWS\system32\htcrwotg.ini
C:\WINDOWS\system32\hujebajt.ini
C:\WINDOWS\system32\iexp_log.txt
C:\WINDOWS\system32\ikuidnbn.ini
C:\WINDOWS\system32\ipnguicl.ini
C:\WINDOWS\system32\jhvwfmud.ini
C:\WINDOWS\system32\jqgqqcso.ini
C:\WINDOWS\system32\jrqmkofg.ini
C:\WINDOWS\system32\jrwfnnmk.ini
C:\WINDOWS\system32\jwtvysoy.ini
C:\WINDOWS\system32\kruaacgg.ini
C:\WINDOWS\system32\maewhcyi.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nswniihl.ini
C:\WINDOWS\system32\ohqkyhki.ini
C:\WINDOWS\system32\olfqiojn.ini
C:\WINDOWS\system32\oqdevkuk.ini
C:\WINDOWS\system32\pneuweqk.ini
C:\WINDOWS\system32\qgensnol.ini
C:\WINDOWS\system32\qnhpxuqj.ini
C:\WINDOWS\system32\qtwkdbrw.ini
C:\WINDOWS\system32\rbylwpya.ini
C:\WINDOWS\system32\rgxwwgnp.ini
C:\WINDOWS\system32\rhlarplo.ini
C:\WINDOWS\system32\rpjlsgnw.ini
C:\WINDOWS\system32\sifyfnkh.ini
C:\WINDOWS\system32\tcccfuir.ini
C:\WINDOWS\system32\txmmgsne.ini
C:\WINDOWS\system32\ujmmxikx.ini
C:\WINDOWS\system32\uqkulyyt.ini
C:\WINDOWS\system32\uqugtlpk.ini
C:\WINDOWS\system32\vircugee.ini
C:\WINDOWS\system32\wtsrqbjl.ini
C:\WINDOWS\system32\xemqnxwu.ini
----- BITS: Possible infected sites -----
hxxp://guilder.staff.biz.uwa.edu.au
.
((((((((((((((((((((((((( Files Created from 2008-04-06 to 2008-05-06 )))))))))))))))))))))))))))))))
.
2008-05-06 18:06 . 2008-05-06 18:06 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-06 18:06 . 2008-05-06 18:06 <DIR> d-------- C:\Documents and Settings\ywu\Application Data\Malwarebytes
2008-05-06 18:06 . 2008-05-06 18:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-06 18:06 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-06 18:06 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-06 06:27 . 2008-05-06 06:27 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-05 17:45 . 2008-05-06 06:13 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-05 17:33 . 2008-05-05 17:57 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-05 17:33 . 2008-05-05 17:33 <DIR> d-------- C:\Program Files\AVG
2008-05-05 17:33 . 2008-05-06 06:23 <DIR> d-------- C:\Documents and Settings\ywu\Application Data\AVGTOOLBAR
2008-05-05 17:33 . 2008-05-05 17:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-05 17:33 . 2008-05-05 17:33 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-05 17:33 . 2008-05-05 17:33 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-05 17:33 . 2008-05-05 17:33 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-05 15:40 . 2008-05-05 17:24 <DIR> d-------- C:\VundoFix Backups
2008-05-05 06:22 . 2008-05-05 06:22 <DIR> d-------- C:\Program Files\Belarc
2008-05-05 06:22 . 2008-02-27 13:49 3,840 --a------ C:\WINDOWS\system32\drivers\BANTExt.sys
2008-04-30 16:05 . 2008-04-30 16:05 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-30 16:05 . 2008-04-30 16:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-21 20:10 . 2008-05-03 20:12 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-21 20:10 . 2008-04-21 20:10 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-13 09:07 . 2008-04-13 09:07 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2008-04-13 09:07 . 2008-04-13 09:07 <DIR> d-------- C:\Program Files\AGEIA Technologies
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-06 09:25 --------- d-----w C:\Program Files\CA
2008-05-05 10:33 --------- d-----w C:\Program Files\GameSpy Arcade
2008-05-04 08:38 --------- d-----w C:\Program Files\SinaPlus
2008-05-04 08:03 --------- d-----w C:\Program Files\SinaTicker
2008-05-03 23:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-03 23:11 --------- d-----w C:\Program Files\iPod
2008-05-03 07:03 --------- d-----w C:\Program Files\NJStar Chinese WP
2008-04-30 08:27 374 ----a-w C:\Documents and Settings\ywu\Application Data\internaldb6334.dat
2008-04-30 08:04 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-28 11:13 555 ----a-w C:\Documents and Settings\ywu\Application Data\internaldb8467.dat
2008-04-28 11:13 18,432 ----a-w C:\Documents and Settings\ywu\Application Data\internaldb41.dat
2008-04-17 02:11 --------- d-----w C:\Program Files\LimeWire
2008-04-17 02:04 --------- d-----w C:\Program Files\Microsoft Games
2008-04-16 12:13 --------- d-----w C:\Program Files\eMule
2008-04-16 11:52 --------- d-----w C:\Program Files\9Dragons
2008-03-20 10:01 --------- d--h--r C:\Documents and Settings\ywu\Application Data\SecuROM
2008-03-20 09:42 --------- d-----w C:\Program Files\Flagship Studios
2008-03-12 11:58 41 ----a-w C:\AClient.dat
2008-03-12 11:58 2,401 ----a-w C:\WINDOWS\system32\drivers\AlKernel.sys
2004-03-11 05:27 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
2005-04-19 11:25 53,323 ----a-w C:\Program Files\opera\program\plugins\PlugDef.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 1,400,944 2004-09-07 13:25:58 C:\Program Files\Ahead\InCD\bak\InCD.exe
----a-w 184,320 2007-03-05 03:12:15 C:\Program Files\Altiris\AClient\bak\AClntUsr.EXE
----a-w 184,320 2008-05-06 11:22:30 C:\Program Files\Altiris\AClient\AClntUsr.EXE
----a-w 493,024 2003-02-13 02:25:48 C:\Program Files\CA\eTrust Antivirus\bak\realmon.exe
----a-w 25,600 2006-03-20 08:10:04 C:\Program Files\Common Files\Microsoft Shared\IME\IMSC40W\bak\IMSCMIG.EXE
----a-w 32,768 2003-12-08 09:35:14 C:\Program Files\CyberLink DVD Solution\PowerDVD\bak\PDVDServ.exe
----a-w 256,576 2006-10-30 01:36:36 C:\Program Files\iTunes\bak\iTunesHelper.exe
----a-w 257,088 2007-04-27 03:25:58 C:\Program Files\iTunes\iTunesHelper.exe
----a-w 282,624 2006-10-25 10:58:18 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 282,624 2007-04-27 01:41:54 C:\Program Files\QuickTime\qttask.exe
----a-w 32,768 2007-02-09 08:41:55 C:\Program Files\SinaPlus\bak\rw1k2i.exe
----a-w 843,776 2005-06-24 13:56:16 C:\Program Files\UltraVNC\bak\WinVNC.exe
----a-r 49,152 2006-07-04 06:16:32 C:\WINDOWS\bak\Domino.exe
----a-r 49,152 2006-07-14 08:24:10 C:\WINDOWS\bak\ZSSnp211.exe
----a-w 15,360 2004-08-03 16:56:50 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-03 16:56:50 C:\WINDOWS\system32\ctfmon.exe
----a-r 77,824 2005-04-05 21:19:18 C:\WINDOWS\system32\bak\hkcmd.exe
----a-w 155,648 2001-07-09 03:50:42 C:\WINDOWS\system32\bak\NeroCheck.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-05 17:33 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-05 17:33 2050816]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-05 17:33 2050816]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]
"PowerBar"="C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" [2004-04-21 10:26 86016]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-16 19:24 167368]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 19:05 204288]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"SigmaTel Audio"="D:\software\Drivers\Audio\setup.exe" [ ]
"WinVNC"="C:\Program Files\UltraVNC\WinVNC.exe" [ ]
"Synchronization Manager"="C:\WINDOWS\system32\mobsync.exe" [2004-08-04 00:56 143360]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [ ]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ]
"AClntUsr"="C:\Program Files\Altiris\AClient\AClntUsr.EXE" [2008-05-06 19:22 184320]
"RwOneKeyToInternet"="C:\Program Files\SinaPlus\rw1k2i.exe" [ ]
"IMSCMIG40W"="C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40W\IMSCMIG.exe" [ ]
"ZSSnp211"="C:\WINDOWS\ZSSnp211.exe" [ ]
"Domino"="C:\WINDOWS\Domino.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-04-27 11:25 257088]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-05 17:33 1177368]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="cmd.exe" [2004-08-04 00:56 388608 C:\WINDOWS\system32\cmd.exe]
C:\Documents and Settings\ywu\Start Menu\Programs\Startup\
Xfire.lnk - C:\Documents and Settings\ywu\Desktop\Xfire\Xfire.exe [2005-09-29 05:32:36 3088520]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 01:19:50 217193]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
NETGEAR WG111v2 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111v2\WG111v2.exe [2006-05-17 16:05:52 2297856]
PowerSettings.bat [2007-11-20 15:41:21 198]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\Program Files\Qualcomm\Eudora\EuShlExt.dll [2005-06-08 10:02 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\[u]0[/u]\[u]0[/u]]
"Script"=wufix.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2274462086-3665701602-1850547962-1459\Scripts\Logoff\[u]0[/u]\[u]0[/u]]
"Script"=logoff.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2274462086-3665701602-1850547962-1459\Scripts\Logon\[u]0[/u]\[u]0[/u]]
"Script"=logon.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2274462086-3665701602-1850547962-1540\Scripts\Logoff\[u]0[/u]\[u]0[/u]]
"Script"=logoff.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2274462086-3665701602-1850547962-1540\Scripts\Logon\[u]0[/u]\[u]0[/u]]
"Script"=logon.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2274462086-3665701602-1850547962-2367\Scripts\Logoff\[u]0[/u]\[u]0[/u]]
"Script"=logoff.cmd
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2274462086-3665701602-1850547962-2367\Scripts\Logon\[u]0[/u]\[u]0[/u]]
"Script"=logon.cmd
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Altiris\\AClient\\AClntUsr.EXE"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Documents and Settings\\ywu\\Desktop\\warcraft 3 e\\Warcraft III.exe"=
"C:\\Program Files\\SJLabs\\SJphone\\SJphone.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\PPLive\\PPLive.exe"=
"C:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-05 17:33]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-05 17:33]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-05 17:33]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-05 17:33]
R2 vnccom;vnccom;C:\WINDOWS\system32\Drivers\vnccom.SYS [2004-05-21 17:08]
S3 IAMTXP;Driver for Intel(R) Active Management Technology - KCS;C:\WINDOWS\system32\DRIVERS\IAMTXP.sys [2005-03-09 22:43]
S3 lac97inf;lac97inf;C:\DOCUME~1\ywu\LOCALS~1\Temp\lac97inf.sys []
S3 pacdcacm;pacdcacm;C:\WINDOWS\system32\DRIVERS\pacdcacm.sys [2005-06-15 19:28]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2006-03-27 17:53]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22164f4c-1fd4-11dc-a2f8-00184d40d6f5}]
\Shell\AutoRun\command - E:\Data.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-05-03 05:12:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-06 19:23:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\RtlGina2.dll
.
r Running Proce
.
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Altiris\AClient\ACLIENT.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgtray.exe
.
**************************************************************************
.
Completion time: 2008-05-06 19:26:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-06 11:26:19
Pre-Run: 201,726,697,472 bytes free
Post-Run: 203,912,581,120 bytes free
275 --- E O F --- 2008-01-06 23:51:17