ComboFix 10-05-23.08 - owner 05/24/2010 13:46:16.5.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.946 [GMT -4:00] Running from: c:\documents and settings\owner\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\owner\Application Data\inst.exe c:\documents and settings\owner\Local Settings\Tempals_inst.exe c:\program files\Cheat Engine\dbk32.sys c:\program files\INSTALL.LOG c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb c:\windows\jestertb.dll c:\windows\system32\Data c:\windows\system32\STEC3.sys . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_STEC3 -------\Legacy_ZHUDONGFANGYU -------\Service_STEC3 ((((((((((((((((((((((((( Files Created from 2010-04-24 to 2010-05-24 ))))))))))))))))))))))))))))))) . 2010-05-23 10:32 . 2010-05-23 10:32 12464 ----a-w- c:\windows\system32\avgrsstx.dll 2010-05-23 10:32 . 2010-05-23 10:32 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2010-05-23 10:32 . 2010-05-23 10:32 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2010-05-23 10:32 . 2010-05-23 10:32 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2010-05-23 10:31 . 2010-05-24 09:29 -------- d-----w- c:\windows\system32\drivers\Avg 2010-05-23 08:24 . 2010-05-23 19:31 -------- d-----w- c:\program files\TuneUp Utilities 2010 2010-05-23 08:23 . 2010-05-23 19:31 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software 2010-05-23 08:23 . 2010-05-23 08:23 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC} 2010-05-07 00:44 . 2010-05-07 00:44 -------- d-----w- c:\documents and settings\owner\Application Data\MSNInstaller 2010-05-03 21:52 . 2010-05-03 21:52 -------- d-sh--w- c:\documents and settings\owner\IECompatCache 2010-05-03 02:00 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe 2010-04-26 20:13 . 2010-05-03 01:44 -------- d-----w- c:\program files\Sol Edit . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-05-24 17:54 . 2010-03-16 06:34 -------- d-----w- c:\program files\Common Files\Akamai 2010-05-24 17:51 . 2010-04-12 11:33 -------- d-----w- c:\program files\Cheat Engine 2010-05-23 15:19 . 2007-11-23 22:04 -------- d-----w- c:\program files\Steam 2010-05-23 13:12 . 2009-08-12 10:02 188152 ----a-w- c:\documents and settings\owner\Application Data\Mozilla\Firefox\Profiles\rcm9qv56.default\FlashGot.exe 2010-05-23 10:27 . 2010-01-04 00:56 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9 2010-05-23 08:25 . 2007-06-24 06:42 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-05-23 06:15 . 2007-06-02 21:16 -------- d-----w- c:\program files\SpeedFan 2010-05-19 14:51 . 2006-05-03 02:37 -------- d-----w- c:\documents and settings\owner\Application Data\Azureus 2010-05-09 14:07 . 2006-05-01 16:19 94256 ----a-w- c:\documents and settings\owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-05-07 00:30 . 2008-07-01 21:31 -------- d-----w- c:\program files\SpywareBlaster 2010-05-04 10:06 . 2007-11-03 07:10 -------- d-----w- c:\documents and settings\owner\Application Data\Vso 2010-05-03 21:54 . 2009-02-15 02:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-04-29 19:39 . 2009-02-15 02:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-04-29 19:39 . 2009-02-15 02:38 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-04-19 16:49 . 2006-05-01 16:25 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-04-08 10:34 . 2008-01-21 20:38 -------- d-----w- c:\program files\G-Collections 2010-04-05 00:15 . 2010-04-05 00:15 -------- d-----w- c:\program files\Veetle 2010-03-10 06:15 . 2005-01-22 20:37 420352 ----a-w- c:\windows\system32\vbscript.dll 2010-02-25 06:24 . 2005-01-22 20:30 916480 ----a-w- c:\windows\system32\wininet.dll 2010-02-24 13:11 . 2005-01-22 20:42 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2003-12-18 15:33 . 2007-07-08 00:50 20102 ----a-w- c:\program files\Readme.txt 2003-09-03 11:46 . 2007-07-08 00:50 10960 ----a-w- c:\program files\EULA.txt . ------- Sigcheck ------- [7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys [-] 2008-04-13 18:40 . AAC640F7C769545CFC962F168EF99C98 . 96512 . . [------] . . c:\windows\system32\drivers\atapi.sys [7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys [7] 2004-08-04 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0A0DDBD3-6641-40B9-873F-BBDD26D6C14E}] 2009-05-27 20:31 147928 ----a-w- c:\program files\eMule\modules\IE2EM.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952] "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168] "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168] "SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 790528] "CTSysVol"="c:\program files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2002-10-13 294912] "RestoreIT!"="c:\program files\FarStone\RestoreIT!\RestoreIT!_XP\VBPTASK.EXE" [2003-03-26 208896] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-16 149280] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768] c:\documents and settings\owner\Start Menu\Programs\Startup\ Webshots.lnk - c:\program files\Webshots\Launcher.exe [2006-7-24 45056] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2010-05-23 10:32 12464 ----a-w- c:\windows\system32\avgrsstx.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^owner^Start Menu^Programs^Startup^Webshots.lnk] path=c:\documents and settings\owner\Start Menu\Programs\Startup\Webshots.lnk backup=c:\windows\pss\Webshots.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] 2005-12-10 14:57 133016 ----a-w- c:\program files\DAEMON Tools\daemon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] 2008-09-25 02:57 133104 ----atw- c:\documents and settings\owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] 2001-07-09 15:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2006-05-03 05:27 155648 ----a-w- c:\program files\QuickTime\qttask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "ose"=3 (0x3) "odserv"=3 (0x3) "MDM"=2 (0x2) "IDriverT"=3 (0x3) "Creative Service for CDROM Access"=2 (0x2) "aspnet_state"=3 (0x3) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Google Update"="c:\documents and settings\owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "UpdReg"=c:\windows\UpdReg.EXE "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\AIM\\aim.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Azureus\\Azureus.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"= "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "9842:TCP"= 9842:TCP:*:Disabled:SolidNetworkManager "9842:UDP"= 9842:UDP:*:Disabled:SolidNetworkManager "1031:TCP"= 1031:TCP:Akamai NetSession Interface "5000:UDP"= 5000:UDP:Akamai NetSession Interface R0 VVBackd5;VVBackd5;c:\windows\system32\drivers\VVBackd5.sys [5/1/2006 5:04 PM 180074] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/23/2010 6:32 AM 216200] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/23/2010 6:32 AM 242896] R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [1/22/2005 4:30 PM 14336] R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [5/23/2010 6:30 AM 308064] S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [5/1/2006 8:01 AM 20160] S3 XDva346;XDva346;\??\c:\windows\system32\XDva346.sys --> c:\windows\system32\XDva346.sys [?] S3 XDva347;XDva347;\??\c:\windows\system32\XDva347.sys --> c:\windows\system32\XDva347.sys [?] S3 XDva349;XDva349;\??\c:\windows\system32\XDva349.sys --> c:\windows\system32\XDva349.sys [?] S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/5/2006 12:01 PM 642560] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] Akamai REG_MULTI_SZ Akamai . Contents of the 'Scheduled Tasks' folder 2010-05-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-1682526488-839522115-1003Core.job - c:\documents and settings\owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-25 02:57] 2010-05-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-1682526488-839522115-1003UA.job - c:\documents and settings\owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-25 02:57] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ IE: Download All by FlashGet - c:\program files\FlashGet\jc_all.htm IE: Download by easyMule - c:\program files\eMule\IE2EM.htm IE: Download using FlashGet - c:\program files\FlashGet\jc_link.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html FF - ProfilePath - c:\documents and settings\owner\Application Data\Mozilla\Firefox\Profiles\rcm9qv56.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll FF - plugin: c:\documents and settings\owner\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll FF - plugin: c:\program files\Veetle\Player\npvlc.dll FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); . - - - - ORPHANS REMOVED - - - - MSConfigStartUp-DAEMON Tools-1033 - c:\program files\D-Tools\daemon.exe MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe MSConfigStartUp-MSMSGS - c:\program files\Messenger\msmsgs.exe MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe ************************************************************************** scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-117609710-1682526488-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Xuse\8l`恘0񇠴00 * *S0n0'Y0Wn0済f0g0 * ] "Order"=hex:08,00,00,00,02,00,00,00,16,03,00,00,01,00,00,00,06,00,00,00,98,00, 00,00,00,00,00,00,8a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,78,00,32,\ [HKEY_USERS\S-1-5-21-117609710-1682526488-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:c1,59,f2,93,ca,95,64,52,4c,c8,ec,02,19,8b,07,c8,be,8c,74,28,52,79,2f, c3,53,6e,3e,a0,0b,e0,19,8d,8e,5f,f0,ae,93,1e,28,74,a2,02,59,5d,ab,ef,cc,1c,\ "??"=hex:9d,1c,be,28,e9,d9,e2,ec,55,b4,35,85,0f,32,fa,bd [HKEY_USERS\S-1-5-21-117609710-1682526488-839522115-1003\Software\SecuROM\License information*] "datasecu"=hex:33,2a,a1,07,d7,cf,50,22,01,f4,83,52,8c,59,cd,5d,6e,2d,69,36,50, 9c,b8,2f,26,df,22,2e,23,bf,f1,28,5b,62,0a,fd,d8,c7,cf,7e,a0,94,59,b5,48,19,\ "rkeysecu"=hex:ed,4c,b7,cf,ae,0b,b8,4d,eb,6b,8d,33,4e,45,3a,c1 [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*] "OODEFRAG11.00.00.01WORKSTATION"="17E1B515B7593705FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A6A0AC4980AC79335D575E7D6A3B9808A6A0AC4980AC79339084EDAFB24B78B48AA684F64FEAD42DAC700FA9A6794AB7D67D12B3799B4F53DED3E85527609B8DF6AF4B017AE6D579E37126DA490194A2FE05C7B8DDF131248A6CD4B7B334E6C2D64D0FE884D8C0A0B715F58428EF5D7447AD252EB9837E5CFB3A93CD9A216C3D8EF099F53C739D2EA6F74ADC3EF140796CD99C5B551589294F09DE0E1224512936F007F0648E86EF6997471DFAD6EE4061D2748E6F8EB67B540B427645DF51F71A86C8A6B4232DF668D7E0064392AC1DCDC64814B7FEFE868CD41C075199BADF3C52A3695651D21A400261586F3D52260B4386425315EFC0B06023C4C8BB6FD7CFD5AE906ADC4F73433E67DBCA93CB3627BEF26F5C272B69AC8ADB393154E520BEF7587283AA8E62781F63DA1573986C661023F6DE2CE57E9F9524EE04952837248161EF27C78F0716169B2404E1CE2D3E7581395BC36944DB262B78AF54D363D0A15EE7D1E064490C7AAA0A3E08951FD88E4F1A482D9245EAC5F4E8978B1C2DC86BB7C272CA36D2FB09FC63E02F292D165F1C000ECCD3C98863595A8FD747634654AA68EBFB3F903960D40C79C95A860750D05888ACB0E5A2CD8268E27CAF15B4384746958ECEB5CF04C8608E690D9E72AC26110BF942E9DC3BF134CFDD429834D3F2CF39424838FB5BC04517C7392C53A72E1F5884B8F10FC67B63080883869ACA66F79779225330B17D1F00C06BA958D3C8F9ABC1535745EB469CB02708BC6FA2AE3A613BE9038F360EDAA853C5D7E32BAD1CAFCAE63ABD0DCD8CE40E7A5BEE462B944132BC8B77FCD8E564A279398C87E70687DB5D806E6F63E6B23199480B8413884EAD4E71F17C98337C784F949BAA563BC65634D17C3CA85C9B2CB7ADE60FEC991A20E600C212D938AB40267592B82C44F6BFFC19440017A8963CB9765BFA9654A62160455E7A007124896BABA0BBEDAB953FDB08D52EF9078C439B54F44541C4EAEBAB92ED5A3FDC8708A4C8AE9D788113238B91749AF0B7DB486ABEF4CB6F7DD2DD4A7ED0B9227C6F946A24D5307AD8D5DCD76E177FEE8056F2C9EACECF7D92BC7B54E396038658E6A9685AE42776CAB37F239B6979BDA9C292EE5AACF7159E7BE9F55F85861E79EDE75FC95F1C43F17C4562D7CA8A777FDA98254B69CFB840D6F56D5597F66DEFF914A215F9898AED718A9E2750980C53CB1CC8C295453C18898C0EE8796BD0CD71949CA4A1D14DE245D0F4D23F6B3F7839D44D8B76A9C94BC1C2BE870D60F3A93175C62272B8DBF7233C17E695B1AA49B723B9B20534DB84244E7B5D67B4D89D8968327D4066DED8A6964AB200FCB7A0D1062708" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(448) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(2700) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\program files\AVG\AVG9\avgchsvx.exe c:\program files\AVG\AVG9\avgrsx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Analog Devices\SoundMAX\SMAgent.exe c:\windows\system32\MsPMSPSv.exe c:\program files\AVG\AVG9\avgnsx.exe c:\windows\system32\wscntfy.exe c:\program files\Webshots\webshots.scr . ************************************************************************** . Completion time: 2010-05-24 13:58:06 - machine was rebooted ComboFix-quarantined-files.txt 2010-05-24 17:58 Pre-Run: 54,005,731,328 bytes free Post-Run: 54,756,962,304 bytes free Current=3 Default=3 Failed=2 LastKnownGood=5 Sets=1,2,3,4,5 - - End Of File - - 317047D0983533079CF2039BB13EEE2D