ComboFix 12-05-04.03 - auser 04/05/2012 23:04:46.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1279.838 [GMT 3:00] Running from: c:\documents and settings\auser\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\All Users\Application Data\TEMP c:\documents and settings\auser\Application Data\Adobe\plugs c:\documents and settings\auser\Application Data\Local c:\documents and settings\auser\Application Data\Local\Temp\DDM\Settings\3kd2lwh13q0qp.avi.ddr c:\documents and settings\auser\Application Data\Local\Temp\DDM\Settings\eyyfmvjxapej.avi.ddr c:\documents and settings\auser\Application Data\Local\Temp\DDM\Settings\ftrekctgpncf.avi.ddr c:\documents and settings\auser\Application Data\Local\Temp\DDM\Settings\Post_Install_RB_HiQ_en.divx.ddr c:\documents and settings\auser\Application Data\Local\Temp\DDM\Settings\settings.ddi c:\documents and settings\auser\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\Post_Install_RB_HiQ_en.divx c:\documents and settings\auser\Application Data\Local\Temp\DDM\Settings\y1oh7mln1owdu.avi.ddr c:\program files\codec c:\program files\codec\AC3Filter\ac3config.exe c:\program files\codec\CoreAVC\coreavc.ico c:\program files\codec\Divx6\config.exe c:\program files\codec\Divx6\divx.ico c:\program files\codec\history.txt c:\program files\codec\readme.txt c:\program files\codec\Uninstall\unins000.dat c:\program files\codec\Uninstall\unins000.exe c:\program files\codec\XviD\xvid.ico c:\windows\system32\CddbCdda.dll . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_NVUPDSERVICE -------\Service_xcpip . . ((((((((((((((((((((((((( Files Created from 2012-04-04 to 2012-05-04 ))))))))))))))))))))))))))))))) . . 2012-05-04 19:55 . 2012-05-04 19:55 -------- d-----w- C:\TDSSKiller_Quarantine 2012-05-04 19:38 . 2012-05-04 19:38 -------- d-----w- C:\_OTL 2012-04-26 22:36 . 2012-04-26 22:36 -------- d-----w- c:\program files\Mozilla Maintenance Service 2012-04-26 22:36 . 2012-04-26 22:36 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe 2012-04-26 22:36 . 2012-04-26 22:36 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe 2012-04-24 23:26 . 2012-04-24 23:26 -------- d-----w- c:\documents and settings\auser\Application Data\SUPERAntiSpyware.com 2012-04-24 23:25 . 2012-04-24 23:25 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2012-04-24 22:44 . 2012-04-24 22:44 -------- d-----w- c:\documents and settings\auser\Application Data\Malwarebytes 2012-04-24 22:44 . 2012-04-24 22:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2012-04-24 22:44 . 2012-04-04 12:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys 2012-04-24 22:44 . 2012-04-24 22:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2012-04-09 11:41 . 2012-04-24 20:02 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-24 20:02 . 2011-06-30 17:55 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-03-06 23:15 . 2010-10-23 16:08 41184 ----a-w- c:\windows\avastSS.scr 2012-03-06 23:15 . 2010-01-14 00:15 201352 ----a-w- c:\windows\system32\aswBoot.exe 2012-03-06 23:03 . 2011-04-02 17:09 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2012-03-06 23:03 . 2010-01-14 00:16 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys 2012-03-06 23:02 . 2010-01-14 00:16 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2012-03-06 23:01 . 2010-01-14 00:16 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2012-03-06 23:01 . 2010-01-14 00:16 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys 2012-03-06 23:01 . 2010-01-14 00:16 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys 2012-03-06 23:01 . 2010-01-14 00:16 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2012-03-06 22:58 . 2010-01-14 00:16 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys 2012-03-01 11:01 . 2001-08-23 12:00 916992 ----a-w- c:\windows\system32\wininet.dll 2012-03-01 11:01 . 2001-08-23 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll 2012-03-01 11:01 . 2001-08-23 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl 2012-02-29 14:10 . 2001-08-23 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll 2012-02-29 14:10 . 2001-08-23 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll 2012-02-29 12:17 . 2006-10-30 15:36 385024 ----a-w- c:\windows\system32\html.iec 2012-02-24 20:47 . 2012-02-24 20:47 851176 ----a-w- c:\windows\system32\WinUSBCoInstaller2.dll 2012-02-24 20:46 . 2012-02-24 20:47 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll 2012-04-26 22:36 . 2012-02-13 16:01 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2006-10-18 19:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll [-] 2004-08-03 22:56 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll [-] 2004-08-03 22:56 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\ServicePackFiles\i386\mspmsnsv.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2012-03-06 23:15 123536 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Athan"="c:\program files\Athan\Athan.exe" [2007-09-06 1003520] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-16 8491008] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360] "Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "WUAppSetup"="c:\program files\Common Files\logishrd\WUApp32.exe" [2012-01-18 465944] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "h:\program files\SuperAntiSpyware\SASSEH.DLL" [2011-07-19 113024] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2011-05-04 17:54 551296 ----a-w- h:\program files\SuperAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Monitor Apache Servers.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Monitor Apache Servers.lnk backup=c:\windows\pss\Monitor Apache Servers.lnkCommon Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer] c:\program files\Common Files\Nokia\MPlatform\NokiaMServer [X] . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2012-01-02 08:07 843712 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2012-03-27 12:41 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service] 2010-10-27 17:17 207424 ----a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivX Download Manager] 2010-12-08 21:15 63360 ----a-w- c:\program files\DivX\DivX Plus Web Player\DDMService.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate] 2011-01-10 23:25 1230704 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS] 2011-11-11 12:08 205336 ----a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)] 2010-06-01 08:17 5252408 ----a-w- c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] 2007-09-16 23:07 8491008 ----a-w- c:\windows\system32\nvcpl.dll . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] 2007-09-16 23:07 81920 ----a-w- c:\windows\system32\nvmctray.dll . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2009-07-25 02:23 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMware hqtray] 2010-11-11 11:31 64112 ----a-w- c:\program files\VMware\VMware Player\hqtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "gusvc"=3 (0x3) "WZCSVC"=2 (0x2) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Google\\Google Talk\\googletalk.exe"= "c:\\Program Files\\LowRateVoip\\LowRateVoip.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Opera\\opera.exe"= "c:\\Program Files\\eyeBeam\\eyeBeam.exe"= "c:\\Program Files\\Jumblo.com\\Jumblo\\Jumblo.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"= "c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"= "c:\\Program Files\\VMware\\VMware Player\\vmware-authd.exe"= "c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"= "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= "c:\\Program Files\\XBMC\\XBMC.exe"= "c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"= "h:\\Program Files\\VideoLAN\\VLC\\vlc.exe"= "c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "f:\\wamp\\bin\\apache\\Apache2.2.21\\bin\\httpd.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:Remote Desktop "65533:TCP"= 65533:TCP:Services "52344:TCP"= 52344:TCP:Services . R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [02/04/2011 20:09 612184] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [14/01/2010 03:16 337880] R1 SASDIFSV;SASDIFSV;h:\program files\SuperAntiSpyware\sasdifsv.sys [22/07/2011 19:27 12880] R1 SASKUTIL;SASKUTIL;h:\program files\SuperAntiSpyware\SASKUTIL.SYS [13/07/2011 00:55 67664] R2 !SASCORE;SAS Core Service;h:\program files\SuperAntiSpyware\SASCore.exe [12/08/2011 02:38 116608] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [14/01/2010 03:16 20696] R2 UMVPFSrv;UMVPFSrv;c:\program files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe [19/08/2011 12:26 450848] R2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [11/11/2010 14:32 70768] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [04/02/2011 00:43 136176] S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [15/02/2012 14:30 158856] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [09/04/2012 14:41 253088] S3 gupdatem;Google Päivitä-palvelu (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [04/02/2011 00:43 136176] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [27/04/2012 01:36 129976] S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [11/04/2010 15:02 137344] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [25/06/2010 20:07 35088] S3 VMUSBArbService;VMware USB Arbitration Service;c:\program files\Common Files\VMware\USB\vmware-usbarbitrator.exe [11/11/2010 13:31 539248] S3 xpsec;IPSEC driver;c:\windows\system32\drivers\xpsec.sys --> c:\windows\system32\drivers\xpsec.sys [?] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] getPlusHelper REG_MULTI_SZ getPlusHelper . Contents of the 'Scheduled Tasks' folder . 2012-05-04 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 20:02] . 2012-05-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-02-03 21:43] . 2012-05-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2011-02-03 21:43] . 2012-05-04 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-18.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-01-24 12:25] . 2012-05-04 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-1060284298-682003330-1003.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-01-24 12:25] . 2012-05-02 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-18.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-01-24 12:25] . 2012-04-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-1060284298-682003330-1003.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-01-24 12:25] . . ------- Supplementary Scan ------- . uStart Page = IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm LSP: c:\program files\VMware\VMware Player\vsocklib.dll FF - ProfilePath - c:\documents and settings\auser\Application Data\Mozilla\Firefox\Profiles\xc00j5w5.default\ FF - prefs.js: browser.search.defaulturl - FF - prefs.js: browser.search.selectedEngine - Wikipedia (en) FF - prefs.js: browser.startup.homepage - hxxp://www.dawn.com/ FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q= FF - prefs.js: network.proxy.type - 4 FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - ORPHANS REMOVED - - - - . HKU-Default-Run-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe MSConfigStartUp-Google Updater - c:\program files\Google\Google Updater\GoogleUpdater.exe MSConfigStartUp-SUPERAntiSpyware - c:\program files\SaveSystem\SUPERAntiSpyware\SUPERAntiSpyware.exe AddRemove-Codec_is1 - c:\program files\Codec\Uninstall\unins000.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-05-04 23:21 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,65,99,1c,6f,d4,20,2e,44,ae,f6,81,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,65,99,1c,6f,d4,20,2e,44,ae,f6,81,\ . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(852) h:\program files\SuperAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll . - - - - - - - > 'explorer.exe'(2504) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\btncopy.dll c:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\nvsvc32.exe c:\program files\Analog Devices\SoundMAX\SMAgent.exe . ************************************************************************** . Completion time: 2012-05-04 23:28:19 - machine was rebooted ComboFix-quarantined-files.txt 2012-05-04 20:27 . Pre-Run: 676,462,592 bytes free Post-Run: 502,796,288 bytes free . - - End Of File - - 92991119F5BE680E3C2DBA6F0C55F8FA