Here's Round 2:
----------------------------------------------------------------------
FRESH
HjT LOG:
Logfile of
HijackThis v1.99.1
Scan saved at 10:48:56 AM, on 5/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\CDProxyServ.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
C:\Program Files\Labtec\Mouse\2.1\moffice.exe
C:\Program Files\D4\D4.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Labtec\Mouse\2.1\MOUSE32A.EXE
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [LMPDPSRV] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Mouse\2.1\moffice.exe
O4 - HKLM\..\Run: [Dimension4] C:\Program Files\D4\D4.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and Settings\Chad\Desktop\hijackthis\HijackThis.exe /startupscan
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office2000\Office\OSA9.EXE
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! MLB StatTracker -
http://aud12.sports.sc5.yahoo.com/java/y/mlbst8408_x.cabO16 - DPF: {405BBF5B-2FD8-4614-AC51-D8566F635B94} (SafeWallet Class) -
http://idsm.citadelprocessing.com/SafeCommon/downloads/WalletCab.CABO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by10fd.bay10.hotmail.msn.com/resources/MsnPUpld.cabO16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...O16 - DPF: {D0B5B58D-8CB9-4EDB-8BB0-9D34AEF727CF} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cabO16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - https://music.msn.com/client/msnmusax2614.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4749/mcfs...O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
----------------------------------------------------------------------
EWIDO'S LOG:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 10:43:14 AM, 5/3/2006
+ Report-Checksum: 56DE9F2A
+ Scan result:
:mozilla.44:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.138:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.175:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Chad\Application Data\Mozilla\Firefox\Profiles\sn956f90.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@-1shz2prbmdj6wvny-1sez2pra2dj6wfkychazwfqq-1dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@-1shz2prbmdj6wvny-1sez2pra2dj6wjny-1ncpmgogydj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@y-1shz2prbmdj6wvny-1sez2pra2dj6wjk4opcjmepaqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkosmcpicqq2dj6x9ny-1seq-2-2.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkoukdzwcqqwdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyohajodowsdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyunczkkqaydj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@y-1shz2prbmdj6wvny-1sez2pra2dj6wjlisldjskpgqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@y-1shz2prbmdj6wvny-1sez2pra2dj6wjliuodpoboqmdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@y-1shz2prbmdj6wvny-1sez2pra2dj6wjloujcpkepa6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmisoczakqa2dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnygmc5ibpwwdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temp\Cookies\chad@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyogc5kgogidj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temporary Internet Files\Content.IE5\45UN0PY7\gdnUS2218[1].exe -> Downloader.Small.ayl : Cleaned with backup
C:\Documents and Settings\Chad\Local Settings\Temporary Internet Files\Content.IE5\XJCL65WT\thexxxarchive[1].htm -> Not-A-Virus.Exploit.HTML.Iframe.FileDownload : Cleaned with backup
C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream.a : Cleaned with backup
C:\RECYCLER\S-1-5-21-4211684999-2382317117-2604735499-1006\Dc29.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\RECYCLER\S-1-5-21-4211684999-2382317117-2604735499-1006\Dc30.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\RECYCLER\S-1-5-21-4211684999-2382317117-2604735499-1006\Dc31.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\RECYCLER\S-1-5-21-4211684999-2382317117-2604735499-1006\Dc32.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\RECYCLER\S-1-5-21-4211684999-2382317117-2604735499-1006\Dc33.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\RECYCLER\S-1-5-21-4211684999-2382317117-2604735499-1006\Dc34.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\RECYCLER\S-1-5-21-4211684999-2382317117-2604735499-1006\Dc35.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\RECYCLER\S-1-5-21-4211684999-2382317117-2604735499-1006\Dc36.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\RECYCLER\S-1-5-21-4211684999-2382317117-2604735499-1006\Dc37.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\RECYCLER\S-1-5-21-4211684999-2382317117-2604735499-1006\Dc38.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\RECYCLER\S-1-5-21-4211684999-2382317117-2604735499-1006\Dc39.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\RECYCLER\S-1-5-21-4211684999-2382317117-2604735499-1006\Dc40.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\RECYCLER\S-1-5-21-4211684999-2382317117-2604735499-1006\Dc41.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1028\A0065602.dll -> Adware.MegaSearch : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1032\A0065942.exe -> Trojan.Dialer.u : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1034\A0066035.exe -> Not-A-Virus.PornDownloader.Win32.TibSystems : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1038\A0066070.dll -> Adware.Aws : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1040\A0066073.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1040\A0066074.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1040\A0066075.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1040\A0066076.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1040\A0066077.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1042\A0066180.dll -> Not-A-Virus.Hoax.Win32.Renos.cu : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1043\A0066207.exe -> Not-A-Virus.PornDownloader.Win32.TibSystems : Cleaned with backup
C:\WINDOWS\SYSTEM32\regperf.exe -> Downloader.Zlob.mx : Cleaned with backup
C:\WINDOWS\Temp\bggolomd.exe -> Trojan.Dialer.ay : Cleaned with backup
C:\WINDOWS\Temp\jcmlcnmd.exe -> Trojan.Dialer.ay : Cleaned with backup
::Report End
----------------------------------------------------------------------
RAPPORT.TXT CONTENTS:
SmitFraudFix v2.37
Scan done at 9:11:42.35, Wed 05/03/2006
Run from C:\Documents and Settings\Chad\Desktop\SmitFraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600]
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\atmclk.exe Deleted
C:\WINDOWS\system32\dcomcfg.exe Deleted
C:\WINDOWS\system32\hp????.tmp Deleted
C:\WINDOWS\system32\ld????.tmp Deleted
C:\WINDOWS\system32\simpole.tlb Deleted
C:\WINDOWS\system32\stdole3.tlb Deleted
C:\WINDOWS\system32\1024\ Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» End
----------------------------------------------------------------------