Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

please help me! i have adware.CDN and my norton cant remove it!


  • This topic is locked This topic is locked

#31
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Hi, playsoldier3 :whistling:

Lets check the registry also.

1. Launch Notepad, and copy/paste the contents of the quote box below into a new Notepad file. Save it with file name options.txt and save as file type: all files to your desktop.

RegSearch Options File

[Search]
Cdn

[Exclude]

[Options]
Filter=KVDLUI



2. Download Registry Search to your desktop.
  • Right click on the compressed RegSearch folder, and choose "Extract All". In the box that pops open, click "Next", then "Next" again, and then "Finish". You now have another RegSearch folder on your desktop.
  • Open the new folder, and double click on regsearch.exe
  • Click "Import" in the lower left corner and browse to the options.txt file that you just saved on your desktop. Do not choose the one in the RegSearch folder itself.
  • Click OK and Registry Search will scan your registry for the file(s), and a Notepad box will open with a report.
  • Please reply here with the entire contents of the Notepad file from RegSearch.

  • 0

Advertisements


#32
playsoldier3

playsoldier3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 110 posts
REGEDIT4

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.1.0

; Results at 2006-9-22 22:19:23 for strings:
; 'cdn'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CdnForIE.IEHlprObj]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CdnForIE.IEHlprObj\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CdnForIE.IEHlprObj.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CdnForIE.IEHlprObj.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\CdnClient]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B24B1B30ED6F9d14C8FFCD448E597C7A\Features]
"PrintApplications"="Enm~MSKp)9&56TH$yl=jpbNlKuw,'?(7wdXH$r},BBcVVR&oq@k12Fpx$iZvJ+X7LH-U4=9iulv[d?bMOKkxT~^eX@b+eqI{o=Wrm^tZ@iX_C9Kwfw55@2xhXAoxK$9l{?`qmYw7A@dxM=]-F=)R%9rPb$%bdkvl5H^l`ERM1AfB6W0l~b,&b2[llKrR?@xn2J*(A1AvHvyM+BOww8wll=VeD@-l'V!Gn+PjJ@=rxo?G(3zcQO@1j]NmD=`stJ@,KwOGkv8Tfva(i8Y`Y_%-z+xpZ@(K16U,X?+TmBgV'zOv^iYz1K6NU9s{wgQwAn,zyD6{s[L6bAR,sT0zYa^scQj)=YGf79dufQusq5Yz-{1iv69eB@,sg-RNA1c'_'7X][email protected]!SwHm*k{k`8qN??nuGWPpHj`9P.eTjlxO5@DP83jq77x)}9JtaMT4?@4l!5.UZAge-b_{s0wW5?W70d'Q%bHS1{,u@C{vz8%)0$)[email protected]?n)]A7{R_zHNMR(QFj7yLS8e8Hb7nhEX`*,m'3jr{CTp?3U,qmZXcZ0jFxOJx,Y8=%*ndD*yXVC`~HBoKw?N=*4b,N?ua!6U(uXK`r&9?^4l(@0&sw0,j9@MA3O0?IA-5)V*CS$nB%BY_nvM@=r.Lu(gueZoMvdRz^&0944]9v$G68bbiEg_yTp}@7zPF`u_@8!g^k$DZ8V?AiKHkJ565}gXa2MRgj139e4swNvb?Wg^-sE%fhL4?97W%BkyrB3IYY4eof,4=iq&*NGkveB-qCcRu`rq?*k7[0^7fT*@^5yi_3PR9HV6hBYFV{Ngq[9%)0k,?b?){9vyqHL3Qe1bJ[!.?`kciNh3{[*LDwIG!K7C901`WrC.wQKFd1$J^C}`AjcrXWjOT}i+cX`aPqy%AenVf2CbP_oVgKv1h,DR?$xlB6{A.r^0^RsT.*-Z97wA}y~D@@O?ky*C{52k8F)[eMB6F^S7-'iZ.Wb~=nF7Os}jw%$J=Jefbq2e=4^S~uZO)MV6dp&T]mQT?KiL)k+&,z%(Kfi[OrcU?k3Q4T1i%*Q'{K]C&u0E?JM9J7gs}nj*'Nd2M'[w=YRGAQFc0jy[ebAsK)'!=0HSNfG4=E4,3k0XdY5^8A2)Qu`z03k,.t,uNrs29N[e$,vY{1%5Q[qQS&n0=ND'I$.L'kC]6V~KWpGy85ou9z]]Vrn$]Hoy%V=6@FMDRf]2jlHq97y_0jHP=rmKAS%%`ob`q!qGr.@M@p]71d=H9s5ExiRG'RXm@-FtNxSxRrFr$xyY.lNo?{zVF_r3]Cn1JvekFm~]?wAH[Fh0IGAr1%^5&+e)?%On!Q6ylRnFU%O^@4h4?qV_Pz._Ja-{sw56%mL[@tcI8s*=OHz,@Q}EEwDcA&tAOjVnu~Zxdy0yK0@_?Iv5MIC4AHR^eb$yb1=v@HoyWItkx''B5GFxDwqK=9E3]G@327+N8wl![d{m9$8Nu[)oJAeIWSeeAowr?+M@HDv9bhOKGu=-uZI^8T}]Eh^&Gp-qJnVeb*I7@UACXkX,'ESIF}1!.%!k88ou(a=dFPb)sYFUNr,K=[bvk[h.SA0sFWXqgy&P?7rt)jpiHfG-21O3]6zLAu5EK5Q9PqoA78B.B'Ej=(q90j%'C09C0n2mn?w(A07%dHgYXZ4RWpjQU07T@-tZ-Q9!R@h9Q(WsIg1j=[FAmYm}NS&O%D}5p~X0?^nr%ALENb?!PC(Ax'[==t,1N3%+fL-iI*Z))P?99Y-~sL}~5!?C2EZF=T+W9ZH*z=`OOqQ}$h(DfdBY9kJzX^5.[mcM4C*(QM-x8+Fx,V_qIfh3f`gWP%y^8d{.rRaaQ*whx?8CMJUb9B6lvQIbLUJ^h`U3j35G9c,n{7&OO,MiLOuuDe}`=Mn%ZdvoaT666ExffqC`=*{u,XV5@hs!.%JdB0[Z=wj&coK7!Ci,I?}]XW)CAvGBliD}Ov1Y+UakInvbA18ZXQr!Xs_rlka*2Q4d9Lw5]MdPRu]{4=LuacIS9F?@TS7tH2VTL&}_jZ$q?8Bz$?DD')Bd)eK1a?7!A2K-V4n?AO*F5Uy@6abY?@)}[email protected]+NEN[DWD0GYczf(,J,`=QnOsTVAw85+7QQGb~m^=!XtS)A^juw[Hom[e!}W=PRF18q.7NVgFe+`&oe]8IiWXbhbh-FjX~F'vZ.G?19(`e!DjI)DOXQ`YCV3?K_$`_rPt?d'6br)Cu'@@%~s~r+tpCA0h2GomhJm9xPG[?{F(d!nve+[4WNt@N==~+[0-+dL)No.0?f19mMjMvXlFj3awfYFyGx_9GafiEez5(2=3v}8Gl?a8VX,~t26j4exqt0V2[w,?MuddJI%(=`G3~(WfqvT9t-zi5kj4?XUKm4KffF0A(pA]0i-{,_n'YWy7s=Z8L$W{23hIm8sw8PC6D5e8F7!_7f?SCYTXgxPK95X=81Wx.TY-*5.o0F3&*J}@6D5Y,Qsh4)-2Am8S-iN=tPY'G9790Xsfe-G7Anx@)PDnsEjp=c'+a]GYC]I?Rkh}^]oE3RQ^U_Bzctk9rx7`mXQ!mJZj&xqPzfY?Hf['iXb8E&_H]kRQ?{Z8^BvO9UbM2X.yJ6{y+*U?J(Ff@g5GEd-'QZL0^5n@1DF{d5i2TBEvx[HZ^Z.9EErb]CQO^mB*OfP=6Ix?W3'T-45moI$2zGJh.{r9c%&BU2Bg=6d{Vp$?54P=K4&rtzbN0QRGjg)V?u(Azr(VGtJr+gG_VC^.FYp=&CRCATt'[[9I5gI9q{[?N,KoVuqfv]vNcIMZa=G?h}YAg!e7=x^X2Nw^6rb9yVMd)ve220uh8xrtNDR94$h-w{{.AX7t^k)%AC?9_5uGHk280qf)j4uCKHf9x`(.2Z~^0b[U,ovlGjIA*_15&]$UJKP]$aFzO+IAj%q7zPm.0Dq)[ZW9[y==`gvi%.pPTUZzm7Q[IQl93W%pVC[VmKV%2{(X4Bc@Z_TpO2I7c0P*D2+iKs[8NnCTY@E?85B~q)`I'b1A,HD0xAcQtszsjFKz^bd8D*z(T7aWc5]r^3[dnfD?YteJ2UPPwP9cgQ1ODI1?OeP9vi(W7*(-+A2-RsX@?5rAol0{X']s=^z70w,94'1tm~~AXSvnlz7()uV9di6@?5@ar1qhw7QNs6_?k-?w.'vO]ia5!qy+COw9$c}%z(-0DATYbQ^HYBv?o2%VaZB6V6T_lJK^A1BAX%ov*yIo})8G~}(m9lbA^*2.SgovK+4MK!]K&.EAm'M~O6YtPoga,kIt}F=?U$wc`qDX!wgL[0kVv$-@Qf}?rt]7hS1N[1E(S5RA{qw+ky]]dqMzpUBp@@E?Ej{PFg%5Hi%z$h3DC[y8B.R9`W^StYi4wn&`7}!?2PtTL?W}X.LYk*'}'4MAnf+*S=&75v..]B!wB!^Ar7=)(z$bpyB3&5,B^pf(V%eqFgkW_B83&5,B^pf(V%eqFgkW_B_~BT)zt6D@3PC]i`'k97CO&l.lTb,=]R=e`J)iKfSTWj^[email protected]~n??y=pBz{zreC7f{v2ONN7AIQ($FLMg+kW{gxFsbNF9SIB!Cno*{+Vu'g(5bsb@bp{$u%&qc*{xBOyt-_Y?tKI%Z-Mc.-mfcRGen[z8gxyTC5)$lpFd65]3ik39XNWEr.HA1X2^6k&MYvHA3sJRxaZ.o)cbd1,3yl=ATM)@Zf6](gQ5uLnWGwm?a'am$4_j!6`H$WG,'K{?`PWoFl3XHO&yb[XWL1P=67Cp(7T23(GH3m)$T@`8IL,W!cf8Y.M&-eI0x`U9?_6aCr%=9rjPgH$g%wv9}vA!UP)zsdMUrs6w.0_A1Z~iR0MtPO[_UTbJ*RN?[N!%zEB(bFrjbgy}vb99,3lTgP[9CaCzqbhKFa59~F1xyGq7Uw[?FlHKTkl9w=uFDlYvOej'e-=R6~*?o284Ws`uz(]`OuxJ[EQ=wI~C@dEwA4s'j!GtbWU@SW?)[eK2wgq8_=_q[n.@54`lR]`jq)1Psr].Ie79u+.dnW%bv]$Q4lijs)%=H&d8jpGXnG.Uzxd8(Lk@zET?$js70WjP,H=WCk=9H%WFhbHY?%-8U%]r8V6Ap}?gAAogM.fVR-HJOm5@{8N`Nm8Yjx]]kF,)[dP9.Do,i~Qt9J(R0!H@TIS9@,.s@J^LR4,?k?&AJ_E@IF]big`w5Dez=9$*t&H@$=lUt7V$b0JAO_J-GJJ=Oskw`Q81%S2my[ynl$T?C`i%,v0r03Z4_F9$29&=K&}0?P,J-CDY]5YowxC99lRcs^}pIQosw4n.Zg@A3'YVnejxOQox&8q8uSt@E5}q'U{tHPmfo%juzDI9{~].{)DEx7u2oGRT}CI?30O!VLAQ46Z'jc`8kCF@2rYZiOg][Se*ozX&?n)9(AEwhH?}NUO(PVHMTWL?F^rCShb0$[email protected]{n=xkI4s1Y+l?s4`8F]xVUy_lQx.@B9{k~il?%}M(,OT~O?dFX@%Dh0p@D`ps*wc`R!C^kgVwX=d8Du1(53Wye6BrZ?ko!m3=evrk9}k6(cXRCAZ~!dD9bt9iP%ihM75ZK)ey{RF9BuPs-EVE}nMq^.rqb=f?qd,5EqNap,sb*)S'FQG@iaXj-c!~5h'CtpcX_x{@t1SV*4BR3OoF52HN&&c?-_.LwUKL_^N8]eIo@T9A-Tf`Zv,oHPF-U^%]{d=9.f~O+NiDA2{r0Fld7fF@?xu(qE3&]B.vvU1GcK_9l.(XKm&q,g3aXk@mU*m?n_li[OM1z`CVwv(hrpk?U++in~hLHux1N$[5KvbA%-Jy2{2&1Y'rYO!k0^O?4_?il'78y$x=bkL[iS8A5[H8OhN~Fx2D9PC2qc*@hofbd_dT(XpiV4klpB=@kY7f0BiY29~KTr5*)P`?)+R.W.9zSQ++CN.(UEY@~4h'=yia`WdCMDK?Zkn?kRuGgKlYiKUrQl]NnIB9kg+-2j(a[)H=}]z[T}39^hn0cvv%g_AW6h!MbIk=Js7jG[*qT_0IXwxCh[5@$_=ps]BVzRnUiP$K3'~@19x9W_6oUFp5Is+{71I99X*p%mJ'CJEMn]nl'qNAzQeGxR3Skx8f%eRlLyO?gKbSfRULJ`ER((xqCL8A]MC270blp9'g.(EAFu19M5h2w.$OOj*PP+qogrV=w`TIVA2xDwr-mWagVL(AlQ%buchw.aAuF.EdwFQ=z[=,&tYyM_^wr$CO5i9?=^,J68f@e?b8N&[XROx8^GLBc{~Y)2!0P+_p.EQ9gH!S*x_?kyZ=&)u_,4r95~j]&,uu4k-pk)s[?Vb@,lPDx^$CEaXBe`QL?_v9ESmPRZ'2P0VJ_1)AGy&=`1s&ahB?Wr!93@Dl$?q=wC)q_Tt6&ZM&q&K*T7R?$f}8[CW%r%ZIzLoqP,H@pO*M+@O+8{(&iA&k43y9ZY?}i%-KD.5~kMfxw4q@]2N}(He`!W$ziJq9b8q8J*%j.?KD2J+DbO788VS@9uTrYBcrlKo],okci(!@9g(PSGrmP+,Eq8dw]OWA~.7buvn^@K5ppuXj6^~=lQ$.N9a7&Ou@3izbW,r?VYR05UT$3gUaW3e8xJ?AHJn-M!E881bwr!H^FWk9JJYnoN'{-5T~)9L?+XU@i*%kGMpcDq](Q4QkF9{8=Rn!vque$P`1xZ2,C=[8iiX^TUtTFKXJs5Bu%)p8Ip2fyuNKDGccE3-r3&g96mBEy7QN9`7K+XzowAw8n2$]vno70q%&j]w7En6AZSZyjMyhtuIrh8VorYj9rhhnJ-[6'j+o^6.a{U1@c`1=OCh_qCiIeKYAu0`9]xm`mue.W%{yo7pEnA99]Du]1`L7q5qxQ5yhq^Y8VT@ZiG%zvmroTjCD]C5A6TGRp8An`FRFg=O9vty?qM2fDvEqcjl^`ZeaosL@T^p)G,o'Phi)uFLm6fOA?6*yLbLE6FsbsaJR`pU?M}9Y'XZRS[eZ%=s5mi8Av]rRItwKXg{*NLjnnF4=vPSV!.NzmqmMgj6NG(L9baMx%sT'Y&BC~w8MS0y93g(amLwAST^]gVuf?tl=@1sOP6JCbk?z?lhby~w?BPdV94.XZ@m*i}Ff3Y~9_qo18H-ure01nYQW~`]8dBZ`'U8B^+xSC-1uSWb=aXL]DQev3XF?zn%RUiz8cFBntb1y.X[fE9^^FD}=G]02xLkb]U[*[email protected]]lR)Tu3xt$PX90'C`%W1(42ue@+0J$WA94c,Mc~0v4b'pL.6U1?}9qq}L9yc3uEu3JjH9275@]hWmE{V2aFw)I=B%R?D?gGu6+i}-_Id*5IQicPC9Jy3^oP+r@%OW,4z[wJM@@xtus$Oi3vEelOW8)HRA+5=tuzSyfVy]~WHa~AY8Zk^1@x*MT1$_7h_GDKj9Lw9Pq'CS0W3UD6a6JsH@Vt[KLPyd)iq1oQ*X5NG?DP{J9`&_owV,s_WO]o(=y,$p3O7Nl?3P_=*6HZ`9xEd?[f4~0LSI91LVad+?3GIs6,3uOZo)R+LpD=j9(qxK5hyyCbeK^RKaJ]V@)8.VLs1kB!UjHJqN't&?{DtookcI-[fQ3KOP_Xz?l!xomBLOZgSk6c@F[p}9AnxjI=C`Y!I)oqyu{ju8VgG]gwU^Xvxc7E@G=r6AaLO5U5W`6vp*c.5?p,e8BxXe7{n,?])C*+UUdM,@?@2&qb@gqO&G3&4S6m79G0Qg46Ddvu}FGVr1'.]?Te}DitIk~.fSyAh}''2@A5AAsnPMxcNTC9zDyev?%2CwajJZ0O*6vOU0zz[?V8M87C&g9MUd?C={=qw8fHooD7!XFYe0Khjnyh{@lMw%5Yt_PE`*5UV,cSYA@m3,s^,(c5BH,b`wVTv8Ig*Ay=K,%AHoKSU%nRA9WW1l*gx2E-si]t4~%(a=ofDbsyULj=II02&i(!VAF$N-Tp^Pi'eK7g6),b)AYhOYZ]IBOb4biQd8b$!9SgonD$~G$ghu-8S~U2R9JN+[IM0}HiHwXA0[]?T9L5DCW_`A3`M]O7*'2iT=&]4-(QnQPAvut.Gmf5M?%BZjFTOqDPc[vc[(44@9sX^?DqBCFx]R}%OXG+(=gkgm2.9~m%a}]O5DdXW9'`@S[-^k_X.{0^PeK_Z=q9oNCBOi_Bv,%yFhaW]?]pZOk%!qQgp0=T=2QL)=VXCzW8bqug]n9+VT)?R?q]2KCPNu^cpt9?g4ZZM9K[z!G4Buy8I716yp*]&?MdS`bL,Cf8jCiuU)I&@9ax~hK@tN+zn%3_&Ucj]?$&8k`x+aCjA%4qi7k+y=%[St..%9aW.yEy=KA'69[l3jMwoMUrB{!r&2yWj@(xu*4J(49R09'58NEHv@t$elxbl5KoLdoehb)%3@utcPbb-uZ*i=!nLiqtq@!PcKRRY39y7-Vt&qy4]@R2B9J!pv.P+YD,AYknl9-ufkn(XvjSU.GyeW4i-9_GHL.U'-lbf.chx+}`Y9Tr^vRXb-`GC8jzq6jy.?c+)j['M_[+{R3zyR}zG?-1{T,,+zo.EAld*_+3$?0=pm.MKH@@7*H$ESvCf@BZ8d8cq(*@^iv~Gv2=B?n.Nb%_ToY2iMdxL)8T4@$JXT-=uPn8Fsur[5hfOAzAHGi.R]VT3W5Z=b,3O@Bw%L-F5hR1$e-fV9H2w9{w.eGUnhz14vq@EXov_?HMJhvAVlYpjSqoSW&'_=UQ+qbs&`,rUnoL7cU!%9]QB)oa&.5Z'QhWl,z70=.jWrgyzE)EWG$)sbhp4ATh]AF9[Nb^iNT)-IPjt8awMH+wk=*jvtl)u0jgdAa7@Yl)3x'y{Wo.hgIME=M`-@Y9OS5ZxG,^0uA+t9Z9H%9MJwbg=`SDjAV$0=*6KYWQ7bmXqpXn.iOW-?a'$^nKx^J+6HPy!&5@`?2x1m%5I&xjWA6ud!nUl@r846@3KNO]H(!X4^[OA=dI?dk.mODglYBPAL1l7=9ztH6VEPhg26ufIF*qA=nO5MTVbVasdOwCdNM(g=~S5%A?`FHA?sp%F-*-t94W5o[Sb*zq^j3w+C+jk?[9o]CLdr36)GaXf3-jLA1}1rupPY6Nn(TG1sX(E9nwy!@CA`hJBmKTFpb.EAF[8ziV8Zgk"
"CreativeProjects"="6u!OmmWU}=T.-7ObrNpCba?PzFB@d?zm}1HhA0zZg^ZXj_E.D=?`xEYB=1`$-.'u8]fM&?Z1.jZq.AAGEnm~MSKp)9&56TH$yl=jpbNlKuw,'?(7wdXH$r},BBcVVR&oq@k12Fpx$iZvJ+X7LH-U4=9iulv[d?bMOKkxT~^eX@b+eqI{o=Wrm^tZ@iX_C9Kwfw55@2xhXAoxK$9l{?`qmYw7A@dxM=]-F=)R%9rPb$%bdkvl5H^l`ERM1AfB6W0l~b,&b2[llKrR?@xn2J*(A1AvHvyM+BOww8wll=VeD@-l'V!Gn+PjJ@=rxo?G(3zcQO@1j]NmD=`stJ@,KwOGkv8Tfva(i8Y`Y_%-z+xpZ@(K16U,X?+TmBgV'zOv^iYz1K6NU9s{wgQwAn,zyD6{s[L6bAR,sT0zYa^scQj)=YGf79dufQusq5Yz-{1iv69eB@,sg-RNA1c'_'7X][email protected]!SwHm*k{k`8qN??nuGWPpHj`9P.eTjlxO5@DP83jq77x)}9JtaMT4?@4l!5.UZAge-b_{s0wW5?W70d'Q%bHS1{,u@C{vz8%)0$)[email protected]?n)]A7{R_zHNMR(QFj7yLS8e8Hb7nhEX`*,m'3jr{CTp?3U,qmZXcZ0jFxOJx,Y8=%*ndD*yXVC`~HBoKw?N=*4b,N?ua!6U(uXK`r&9?^4l(@0&sw0,j9@MA3O0?IA-5)V*CS$nB%BY_nvM@=r.Lu(gueZoMvdRz^&0944]9v$G68bbiEg_yTp}@7zPF`u_@8!g^k$DZ8V?AiKHkJ565}gXa2MRgj139e4swNvb?Wg^-sE%fhL4?97W%BkyrB3IYY4eof,4=iq&*NGkveB-qCcRu`rq?*k7[0^7fT*@^5yi_3PR9HV6hBYFV{Ngq[9%)0k,?b?){9vyqHL3Qe1bJ[!.?`kciNh3{[*LDwIG!K7C901`WrC.wQKFd1$J^C}`AjcrXWjOT}i+cX`aPqy%AenVf2CbP_oVgKv1h,DR?$xlB6{A.r^0^RsT.*-Z97wA}y~D@@O?ky*C{52k8F)[eMB6F^S7-'iZ.Wb~=nF7Os}jw%$J=Jefbq2e=4^S~uZO)MV6dp&T]mQT?KiL)k+&,z%(Kfi[OrcU?k3Q4T1i%*Q'{K]C&u0E?JM9J7gs}nj*'Nd2M'[w=YRGAQFc0jy[ebAsK)'!=0HSNfG4=E4,3k0XdY5^8A2)Qu`z03k,.t,uNrs29N[e$,vY{1%5Q[qQS&n0=ND'I$.L'kC]6V~KWpGy85ou9z]]Vrn$]Hoy%V=6@FMDRf]2jlHq97y_0jHP=rmKAS%%`ob`q!qGr.@M@p]71d=H9s5ExiRG'RXm@-FtNxSxRrFr$xyY.lNo?{zVF_r3]Cn1JvekFm~]?wAH[Fh0IGAr1%^5&+e)?%On!Q6ylRnFU%O^@4h4?qV_Pz._Ja-{sw56%mL[@tcI8s*=OHz,@Q}EEwDcA&tAOjVnu~Zxdy0yK0@_?Iv5MIC4AHR^eb$yb1=v@HoyWItkx''B5GFxDwqK=9E3]G@327+N8wl![d{m9$8Nu[)oJAeIWSeeAowr?+M@HDv9bhOKGu=-uZI^8T}]Eh^&Gp-qJnVeb*I7@UACXkX,'ESrnOKq@)P2A0&44yUSMUI}[email protected](HYUk'7_ocOU(FziK??EH9bQ=3rZX!kb.rD[q&?f3hYwffaCMHjlMqksGk8^KAbD+47.q(PiZFV0aE=Ti&@y*^F,n1no7dYDbc?8R}b%Rr't2F%qM4jN1t9[Vi%7?FVj]O.VtvGc-PAgJa(EtjV3v%4?=WcSG&9.d&*dvo'SClNnlQod*)?-!I8$jax+j8[}JiX+5D@L_5JX8mR^RP{v}vUwtg=qT}ws3z,TQa?,`F6[mg?~+Gc15UdFL}q!!!TWMp?V?5dQFe+o`4LOdU&'k+A`y+@]CL?Q*Yesrro{~u?kCsiCJKz&4Lx[-74J('@LASnkzev@+hbO.or%*r8e'S8-cmpqE7T=,{dqFBAklcZL45dQS?0y!073MJ=g(+DEFDB9F9e]p*UA7{9[3UPoS=em*a[ergih}+?vDCfWmWT-iYoTj'O]Y%?{@zsSx?83nZZNc^9h+[AsZjdn!jql&h+6(orTf8AsgVX`uQwP.5=Is^6'kP@rV,]j_mVY7sjWagG{4_9`cm?PZ]6IuvYd9YsByu?y*6j'}2j^3FPmJ$oJl+9K4Y~Jz{im*!9SG'i+s!=t3i(h2ltpHJC-CTZlg?9@H~ksJr.JD_0mg,JR}[Ag)Bs&W8wvL=PjFA]3W4@bc[+WgIv_=uVfbdw2G=98h1K_68rZ3EguV6hPMr9N)Ob7Y6O3EGItVBoe&[Awz?m6mpIMHUhvDRJQyZ=p^`-lIy83?.76?BvU2u9e*G]E,1sWNYe$qB+,,p8H]J$^kS}^&@d81-a8NA96I@TT8K,WPdE-DlCWKH@I[!xG0PSzHgzxz-mRT~=$U$P6%kBc+@qIdv1Kn~?R(y(ywIz(GQ]4X[jeH_8PGZS_yeNV*^vvSy~fN-9uT=bHf?YfxY@afIPw4S=NtWVu901R)rEmjtFzj?=vm5r3ysaJUDoUY.G!B$AAUqtvWvS%G0^AIybM`q8nfD+GTgkt(&?h~bv~cJ=6Y8tDs6XrTX0EAS&UjKAf$%Rn=`b_+]%oj3p2N[9x.N2_NeH(%Nc$AenoU'?^s_!*vpLB^AiB-H0ffr9hqSdAuZR5=[JlvNX,A2@Gv2KQd@LkK0{G'CiFv[?{Zi(LwDG$GM!0pcdd3W=t-kRrM!%9IM@bxp6,ir8Bjks2T~`4y2TsR=!+4CA}2Igg-*sOx_2j]$V!yp?BNCjC~nN0C[{Y{pC{B-9nh3x]pi=lp_qGKZ[08%=^)00kg_.VzAdEIK$Y4h=3rYYBn27tu6bV?7)DrG@1+Q8NcSEk){%(iy.m+*=vxySbH9'vc`ZZv*MT.k8=bz6]tgRMaPVHOt-}N0@r5a%(ox=vm-}eK)Fb(N=v@Fq-}EGEgon*&GN]G+9%-yj[qxIyI8Ub`Pw%aD?{&'Ig+nxrwq2I7Ru-TD=G^I.[$v!'c{Tg5[~Hox8&rV*C5d2F]ExWmb{X-*AnV7-2Lj,v[(mEQ47q@X?&q]YdT3L*,115I'r1$v9&TWU8PfC4C~Vp]cS$1}=P{ku4J,L'5$(?$AE+`S?&_4LIHBnvj9w&cv0FCk9Bw[__i.ZxYz]5)Ci?a?@H(WC_%gqn*QvVQNPk'R=kT@jKY!@OrUIF2Ot*!i@9VfWcXj@vMLA6gtmu[k85+e7*]MtkWR2*OL-+T2@-PnWe]l*Com~xm?k^4[8D'hhFpXXC8bx.!Q5^sm@r-=r+EZ}t.i4R0Ad*BE9**+KsAX6+'hx({9*.=9?([,[%PUe{d%Kxe$oeWe9sV%r`+Ld?vH%(%s'(Tf9G]['=F-S97odRU3A}6j95tgC8-IqP%?4-,dEm3!@IP)mY3,VqdOr12cef,r=oU,s!BS_^v7b_hx[?9x9@!!Ol+DV{v*!jKb5p6896wh]WUM36^,wQs_pUPw?Y29kE6B7urJ=YT-,Nih@Wevgt!TQ@EIF}1!.%!k88ou(a=dFPb)sYFUNr,K=[bvk[h.SA0sFWXqgy&P?7rt)jpiHfG-21O3]6zLAu5EK5Q9PqoA78B.B'Ej=(q90j%'C09C0n2mn?w(A07%dHgYXZ4RWpjQU07T@-tZ-Q9!R@h9Q(WsIg1j=[FAmYm}NS&O%D}5p~X0?^nr%ALENb?!PC(Ax'[==t,1N3%+fL-iI*Z))P?99Y-~sL}~5!?C2EZF=T+W9ZH*z=`OOqQ}$h(DfdBY9kJzX^5.[mcM4C*(QM-x8+Fx,V_qIfh3f`gWP%y^8d{.rRaaQ*whx?8CMJUb9B6lvQIbLUJ^h`U3j35G9c,n{7&OO,MiLOuuDe}`=Mn%ZdvoaT666ExffqC`=*{u,XV5@hs!.%JdB0[Z=wj&coK7!Ci,I?}]XW)CAvGBliD}Ov1Y+UakInvbA18ZXQr!Xs_rlka*2Q4d9Lw5]MdPRu]{4=LuacIS9F?@TS7tH2VTL&}_jZ$q?8Bz$?DD')Bd)eK1a?7!A2K-V4n?AO*F5Uy@6abY?@)}[email protected]+NEN[DWD0Gs!!5x`*259gSFWV.tu?Fbl[37hrz!?dXz@U4OGc,V?N-uf7x~?19C_P+aQ^Bb~R%xi4q^?OvVBxa(0GNUxIN%5{@_9}R0Y_A7}73DkSQdVWzI@1qccB1rNpiLsh2MD,eh@(fKa.~LvVQWfXk,tA0E?pvwG'~Jh9tFc0HvdTl`=+EWYcK9*F.TN'GF`gEs?z!hkKaDCK]w3PEnTU2VA`5J'.uDx~frkA`G9Y-b?qa)dVG`zKaLX}UtrA)l@8YO%C&DX$H_?891RWEn8eOKB^76S*o}Us_uhSqU?(Q`$Y~C^X@)M5{R[N8R=iPq.*2q4IkO%H@Uu?3Z@LhQe*$r94`Fwx^j*&?3=9uf&1YwT~t!`QLi%Um&96ea'[email protected]]ZSlQB+BK_9Q~+G4=K%~G9Y5b=p)pB9'kI2N4g5i(Ulc=o_`*v83$@{tL_JR'*2JYZ?'UQ96TlV9xi.=b2=H6M6q!l9`04tGS^Mug_8%+1Tu%n9dZAgYb%%kAeD[A)'TY`@yh['iG!Z3M7r4qrmI_WAr6NB]-=SdRWk)E`Lj'm?I8}H'g)oVFmm},=s{Rp8M'Nz5Vdyu@3xe()^{1W=xb3cbBAw1n{SjsL[X&M9KWwjGS*z,pYczf(,J,`=QnOsTVAw85+7QQGb~m^=!XtS)A^juw[Hom[e!}W=PRF18q.7NVgFe+`&oe]8IiWXbhbh-FjX~F'vZ.G?19(`e!DjI)DOXQ`YCV3?K_$`_rPt?d'6br)Cu'@@%~s~r+tpCAUtAXWIWB?9_n%L^y'I~tf~iVoJg7`AY@B)ph{~+zQ,a0T%G6'@_8!mV5m!8nr`qX1e7{JAi*[b!^RbwC@)Kl)UvL[8z2fs6~vMt[0Zu$-Cmu$=RqO$`?4xkUa}Y-$IKAx9Y32+1s8Gu*s$nbMa5)$@1r*n?28g9tlinxu-vLZ@dIj5)}ou[tX[[hmIfQ79LV[HALi3@m0I{4&}Sj!?.Rea+F6Bhnv['*tj.R1?)@XSU!z$8Nhk?b9[70*?Rf2of]p(,nYDhKn{2}I9H=ljz^Y+WT^nbPOKts4AX}rU*&!Y}30h2GomhJm9xPG[?{F(d!nve+[4WNt@N==~+[0-+dL)No.0?f19mMjMvXlFj3awfYFyGx_9GafiEez5(2=3v}8Gl?a8VX,~t26j4exqt0V2[w,?MuddJI%(=`G3~(WfqvT9t-zi5kj4?XUKm4KffF0A(pA]0i-{,_n'YWy7s=Z8L$W{23hIm8sw8PC6D5e8F7!_7f?SCYTXgxPK95X=81Wx.TY-*5.o0F3&*J}@6D5Y,Qsh4)-2Am8S-iN=tPY'G9790Xsfe-G7Anx@)PDnsEjp=c'+a]GYC]I?Rkh}^]oE3RQ^U_Bzctk9rx7`mXQ!mJZj&xqPzfY?Hf['iXb8E&_H]kRQ?{Z8^BvO9UbM2X.yJ6{y+*U?J(Ff@g5GEd-'QZL0^5n@1DF{d5i2TBEvx[HZ^Z.9EErb]CQO^mB*OfP=6Ix?W3'T-45moI$2zGJh.{r9c%&BU2Bg=6d{Vp$?54P=K4&rtzbN0QRGjg)V?u(Azr(VGtJr+gG_VC^.FYp=&CRCATt'[[9I5gI9q{[?N,KoVuqfv]vNcIMZa=G?h}YAg!e7=x^X2Nw^6rb9yVMd)ve220uh8xrtNDR94$h-w{{.AX7t^k)%AC?9_5uGHk280qf)j4uCKHf9x`(.2Z~^0b[U,ovlGjIA*_15&]$UJKP]$aFzO+IAj%q7zPm.0Dq)[ZW9[y==`gvi%.pPTUZzm7Q[IQl93W%pVC[VmKV%2{(X4Bc@Z_TpO2I7c0P*D2+iKs[8NnCTY@E?85B~q)`I'b1A,HD0xAcQtszsjFKz^bd8D*z(T7aWc5]r^3[dnfD?YteJ2UPPwP9cgQ1ODI1?OeP9vi(W7*(-+A2-RsX@?5rAol0{X']s=^z70w,94'1tm~~AXSvnlz7()uV9di6@?5@ar1qhw7QNs6_?k-?w.'vO]ia5!qy+COw9$c}%z(-0DATYbQ^HYBv?o2%VaZB6V6T_lJK^A1BAX%ov*yIo})8G~}(m9lbA^*2.SgovK+4MK!]K&.EAm'M~O6YtPoga,kIt}F=?U$wc`qDX!wgL[0kVv$-@Qf}?rt]7hS1N[1E(S5RA{qw+ky]]dqMzpUBp@@E?Ej{PFg%5Hi%z$h3DC[y8B.R9`W^StYi4wn&`7}!?2PtTL?W}X.LYk*'}'4MAnf+*S=&75v..]B!wB!^Ar7=)(z$bpyB3&5,B^pf(V%eqFgkW_B83&5,B^pf(V%eqFgkW_BV2?0@7$9*=IdbugpYRMX}GHaGLdZ==A&kv@Y~]3iui-r60O)l=Em%pCn7G4)2INR3`I9&?giP6x,s{boITzaC}zyQ@Zq3QlMCb0e_~BT)zt6D@3PC]i`'k97CO&l.lTb,=]R=e`J)iKfSTWj^[email protected]~n??y=pBz{zreC7f{v2ONN7AIQ($FLMg+kW{gxFsbNF9SIB!Cno*{+Vu'g(5bsb@bp{$u%&qc*{xBOyt-_Y?tKI%Z-Mc.-mfcRGen[z8gxyTC5)$lpFd65]3ik39XNWEr.HA1X2^6k&MYvHA3sJRxaZ.o)cbd1,3yl=ATM)@Zf6](gQ5uLnWGwm?a'am$4_j!6`H$WG,'K{?`PWoFl3XHO&yb[XWL1P=67Cp(7T23(GH3m)$T@`8IL,W!cf8Y.M&-eI0x`U9?_6aCr%=9rjPgH$g%wv9}vA!UP)zsdMUrs6w.0_A1Z~iR0MtPO[_UTbJ*RN?[N!%zEB(bFrjbgy}vb99,3lTgP[9CaCzqbhKFa59~F1xyGq7Uw[?FlHKTkl9w=uFDlYvOe2I4r&*7K*@oY=$f,0`fxj'e-=R6~*?o284Ws`uz(]`OuxJ[EQ=wI~C@dEwA4s'j!GtbWU@SW?)[eK2wgq8_=_q[n.@54`lR]`jq)1Psr].Ie79u+.dnW%bv]$Q4lijs)%=H&d8jpGXnG.Uzxd8(Lk@zET?$js70WjP,H=WCk=9H%WFhbHY?%-8U%]r8V6Ap}?gAAogM.fVR-HJOm5@{8N`Nm8Yjx]]kF,)[dP9.Do,i~Qt9J(R0!H@TIS9@,.s@J^LR4,?k?&AJ_E@IF]big`w5Dez=9$*t&H@$=lUt7V$b0JAO_J-GJJ=Oskw`Q81%S2my[ynl$T?C`i%,v0r03Z4_F9$29&=K&}0?P,J-CDY]5YowxC99lRcs^}pIQosw4n.Zg@A3'YVnejxOQox&8q8uSt@E5}q'U{tHPmfo%juzDI9{~].{)DEx7u2oGRT}CI?30O!VLAQ46Z'jc`8kCF@2rYZiOg][SgG!8_UR%f?B0M-)~m0.O6f=.pfq,CAMjr0T$Ktr[e*ozX&?n)9(AEwhH?}NUO(PVHMTWL?F^rCShb0$[email protected]{n=xkI4s1Y+l?s4`8F]xVUy_lQxgS8]C2RGt?k-Il@7}M~[FCDvfHd)7AK7DM'o('U!Bsu{dRF1g(Qpy?VXB]2d.@B9{k~il?%}M(,OT~O??su{dRF1g(Qpy?VXB]2d8su{dRF1g(Qpy?VXB]2dL&Qt6Xj6JAfYY}i)1V'55h?)x-[r]8Y}Jne]iF4mj'Qs(P=W]?]rh$_b=T`zNsu{dRF1g(Qpy?VXB]2d_]d%u8j7y8AVDWx23awG3E'+7d?3g(Svy?VXB]2ddFX@%Dh0p@D`ps*wc`R!C^kgVwX=d8Du1(53Wye6BrZ?ko!m3=evrk9}k6(cXRCAZ~!dD9bt9iP%ihM75ZK)ey{RF9BuPs-EVE}nMq^.rqb=f?qd,5EqNap,sb*)S'FQG@iaXj-c!~5h'CtpcX_x{@t1SV*4BR3OoF52HN&&c?-_.LwUKL_^N8]eIo@T9A-Tf`Zv,oHPF-U^%]{d=9.f~O+NiDA2{r0Fld7fF@?xu(qE3&]B.vvU1GcK_9l.(XKm&q,g3aXk@mU*m?n_li[OM1z`CVwv(hrpk?U++in~hLHux1N$[5KvbA%-Jy2{2&1Y'rYO!k0^O?4_?il'78y$x=bkL[iS8A5[H8OhN~Fx2D9PC2qc*@hofbd_dT(XpiV4klpB=@kY7f0BiY29~KTr5*)P`?)+R.W.9zSQ++CN.(UEY@~4h'=yia`WdCMDK?Zkn?kRuGgKlYiKUrQl]NnIB9kg+-2j(a[)H=}]z[T}39^hn0cvv%g_s(la=Ud&y@6$9$Z)tEtYP?EYY)7*7=))jgP~&q7vW`(tnIt@19{K8!HvXVNX^[,6+%5U9?xf}Ea,uQT?8.k2C)0ef99Z7NbRwsFls9qGB)NK6?75rQ$PrA+]vN{TF%=j*@z&1*YsJ6+l^]'%S4e~t9[%B?2K,l&Yq8opf+RT~=&-r79*^UC[H^VH-tWTj8P9IMjf!R?Sp*drR+a'H@HBsc^L.m4Xb9TXB*{f(=[mUAPAM{(mkT$-+[9'!@ehGsBRMsL@OhfvK{U{2A~2,G1RD0J(5(DCNr`['=yK9`K(9u,tU?6&U'J~o@i0]tG0D0D@2x7XpM%2R=R=FADL2Z*^C.3ilt*ocA3GMnia`c.eE?{tieg^r8ZER9LIjbk@oSsK&rW!C9us%mAp^V7fFvue=4T=G?v.)w&$ix*kv2aARLnG2A1?oJBT6]1BylRiZX*@'9Czstq*zsz9H$+yBqG`^Aw3p+ssW@zls,ljRkONP@3AYZO[8+koUL$E+o$-u8t1kqF_CG&jp0]dxqfTQ?HYMOga+uu(4FS4SUz{{=}SFK`l=lvvAW6h!MbIk=Js7jG[*qT_0IXwxCh[5@$_=ps]BVzRnUiP$K3'~@19x9W_6oUFp5Is+{71I99X*p%mJ'CJEMn]nl'qNAzQeGxR3Skx8f%eRlLyO?gKbSfRULJ`ER((xqCL8A]MC270blp9'g.(EAFu19M5h2w.$OOj*PP+qogrV=w`TIVA2xDwr-mWagVL(AlQ%buchw.aAuF.EdwFQ=z[=,&tYyM_^wr$CO5i9?=^,J68f@e?b8N&[XROx8^GLBc{~Y)2!0P+_p.EQ9gH!S*x_?kyZ=&)u_,4r95~j]&,uu4k-pk)s[?Vb@,lPDx^$CEaXBe`QL?_v9ESmPRZ'2P0VJ_1)AGy&=`1s&ahB?Wr!93@Dl$?q=wC)q_Tt6&ZM&q&K*T7R?$f}8[CW%r%ZIzLoqP,H@pO*M+@O+8{(&iA&k43y9ZY?}i%-KD.5~kMfxw4q@]2N}(He`!W$ziJq9b8q8J*%j.?KD2J+DbO788VS@9uTrYBcrlKc[vc[(44@9sX^?DqBCFx]R}%OXG+(=gkgm2.9~m%a}]O5DdXW9'`@S[-^k_X.{0^PeK_Z=q9oNCBOi_Bv,%yFhaW]?]pZOk%!qQgp0=T=2QL)=VXCzW8bqug]n9+VT)?R?q]2KCPNu^cpt9?g4ZZM9K[z!G4Buy8I716yp*]&?MdS`bL,Cf8jCiuU)I&@9ax~hK@tN+zn%3_&Ucj]?$&8k`x+aCjA%4qi7k+y=%[St..%9aW.yEy=KA'69[l3jMwoMUrB{!r&2yWj@(xu*4J(49R09'58NEHv@t$elxbl5KoLdoehb)%3@utcPbb-uZ*i=!nLiqtq@!PcKRRY39y7-Vt&qy4]@R2B9J!pv.P+YD,AYknl9-ufkn(XvjSU.GyeW4i-9_GHL.U'-lbf.chx+}`Y9Tr^vRXb-`GC8jzq6jy.?c+)j['M_[+{R3zyR}zG?-1{T,,+zo.EAld*_+3$?0=pm.MKH@@7*H$ESvCf@BZ8d8cq(*@^iv~Gv2=B?n.Nb%_ToY2iMdxL)8T4@$JXT-=uPn8Fsur[5hfOAzAHGi.R]VT3W5Z=b,3O@Bw%L-F5hR1$e-fV9H2w9{w.eGUnhz14vq@EXov_?HMJhvAVlYpjSqoSW&'_=UQ+qbs&`,rUnoL7cU!%9]QB)oa&.5Z'QhWl,z70=.jWrgyzE)EWG$)sbhp4ATh]AF9[Nb^iNT)-IPjt8awMH+wk=*jvtl)u0jgdAa7@Yl)3x'y{Wo.hgIME=M`-@Y9OS5ZxG,^0uA+t9Z9H%9MJwbg=`SDjAV$0=*6KYWQ7bmXqpXn.iOW-?a'$^nKx^J+6HPy!&5@`?2x1m%5I&xjWA6ud!nUl@r846@3KNO]H(!X4^[OA=dI?dk.mODglYBPAL1l7=9ztH6VEPhg26ufIF*qA=nO5MTVbVasdOwCdNM(g=~S5%A?`FHA?sp%F-*-t94W5o[Sb*zq^j3w+C+jk?[9o]CLdr36)GaXf3-jLA1}1rupPY6Nn(TG1sX(E9nwy!@CA`hJG8DUztdy093[iM4KfpPl%oNG][l27@3rpC6zJyB7I(K_VLl[+?PbKp1F(tB4(,k58h`ad@r'fTx.,X*v-lIyqFL*Y=-SFTjx5e^yno'w%td(c?UxPZ!$IHKn0KUZCZ+8eA5Zx+``0c.s]P.^0m5Kc@Wp0^pomJ[a@agr2v7qd8Od96(+.835h@wEmx%b[8E3NV%}C,yE1olD*'-E%AcG3dHS!i2kYAv'h(gP}=jNce[@10zcRuUa=GHVs=$x66knG1F?g10i!hd,A@GFWvd'4r!!_0t%7=%HJ9v']]070eg,4rtz7HPwf@bj&br%F]y20G}n_tt``@Sh=oSHAR?QY)MyTwnJc@Rr5Q99c2j6l1LVp$K){@?&(,!04HSo{tb,O$6H+=]oKXw@5mf,z,jOjJ7GHAEMtCM&XVRXIMK-gR01c=(+,$pCVy6+l`z~DGwxn9SGC!E}1(e!EafPqx$[$A`e5ZQhKBpoZWS[8xubw9n05kZzjjHsf}CL3^Yq!@UIf4HaiG*u$5&tww[Sh8od[1%-7rQ^9k=o5AGQBAlmCGU^J)^OWOedoQ7Uz95dj&^^'Az!5YTrE*~Qg?V{Y786l(*rK{(+6~To=9linP*A2$vl0)gDsk2-U@'}x8*I@RqSVa)8iRGtb9,`o2aH2Zg(ixXk7T1g[?N?$YyD]CA-09!B4dAB?=oV_wOs(2Bug*XeSjmO'=&[~pyJAyJdIVv34ID3n@@n3FuuL`cDxyLTAN@uN@gD*n@IeC3mMJn5E3?RQ?IjLYZQ8)IFfZe+uN[t^@9Q,%!58Fno7vUM0t-YA9pU0TULeEb+~4t'IfuUl?LX_[_{Zx[J%Ml2Z~S$H?j5TE4tMiN+fl7*y1i9??K@fpp%,(7l[]E@e=TYx8v}0^1}qb]*I]]8-=+%,A-+5YV%N9@*zaYaqu?^$@i}fvjcb_NJ-!-UaEc*A@UpNQZ_1@diQXxiq5&={?X'c,]uptJaqwpz3B+fH=?.pYq6(-}aT]zpj{'NJ@9P=,j^h+SG=]Di]cc5R=+hp3g,FS-6ZFL@CB)iD@+GsQgI`tpOT,agL@x2m8@lmkpsX$X9qDh8(,fc^9lNoS3pOTEY[IIS5KlQ-@(,[D3^g^$0HG-GX[OBT?plfo20%m+qBmKTFpb.EAF[8ziV8Zgk"
"CreativeProjectsPlugins"="6u!OmmWU}=T.-7ObrNpCba?PzFB@d?zm}1HhA0zZg^ZXj_E.D=?`xEYB=1`$-.'u8]fM&?Z1.jZq.AAGEnm~MSKp)9&56TH$yl=jpbNlKuw,'?(7wdXH$r},BBcVVR&oq@k12Fpx$iZvJ+X7LH-U4=9iulv[d?bMOKkxT~^eX@b+eqI{o=Wrm^tZ@iX_C9Kwfw55@2xhXAoxK$9l{?`qmYw7A@dxM=]-F=)R%9rPb$%bdkvl5H^l`ERM1AfB6W0l~b,&b2[llKrR?@xn2J*(A1AvHvyM+BOww8wll=VeD@-l'V!Gn+PjJ@=rxo?G(3zcQO@1j]NmD=`stJ@,KwOGkv8Tfva(i8Y`Y_%-z+xpZ@(K16U,X?+TmBgV'zOv^iYz1K6NU9s{wgQwAn,zyD6{s[L6bAR,sT0zYa^scQj)=YGf79dufQusq5Yz-{1iv69eB@,sg-RNA1c'_'7X][email protected]!SwHm*k{k`8qN??nuGWPpHj`9P.eTjlxO5@DP83jq77x)}9JtaMT4?@4l!5.UZAge-b_{s0wW5?W70d'Q%bHS1{,u@C{vz8%)0$)[email protected]?n)]A7{R_zHNMR(QFj7yLS8e8Hb7nhEX`*,m'3jr{CTp?3U,qmZXcZ0jFxOJx,Y8=%*ndD*yXVC`~HBoKw?N=*4b,N?ua!6U(uXK`r&9?^4l(@0&sw0,j9@MA3O0?IA-5)V*CS$nB%BY_nvM@=r.Lu(gueZoMvdRz^&0944]9v$G68bbiEg_yTp}@7zPF`u_@8!g^k$DZ8V?AiKHkJ565}gXa2MRgj139e4swNvb?Wg^-sE%fhL4?97W%BkyrB3IYY4eof,4=iq&*NGkveB-qCcRu`rq?*k7[0^7fT*@^5yi_3PR9HV6hBYFV{Ngq[9%)0k,?b?){9vyqHL3Qe1bJ[!.?`kciNh3{[*LDwIG!K7C901`WrC.wQKFd1$J^C}`AjcrXWjOT}i+cX`aPqy%AenVf2CbP_oVgKv1h,DR?$xlB6{A.r^0^RsT.*-Z97wA}y~D@@O?ky*C{52k8F)[eMB6F^S7-'iZ.Wb~=nF7Os}jw%$J=Jefbq2e=4^S~uZO)MV6dp&T]mQT?KiL)k+&,z%(Kfi[OrcU?k3Q4T1i%*Q'{K]C&u0E?JM9J7gs}nj*'Nd2M'[w=YRGAQFc0jy[ebAsK)'!=0HSNfG4=E4,3k0XdY5^8A2)Qu`z03k,.t,uNrs29N[e$,vY{1%5Q[qQS&n0=ND'I$.L'kC]6V~KWpGy85ou9z]]Vrn$]Hoy%V=6@FMDRf]2jlHq97y_0jHP=rmKAS%%`ob`q!qGr.@M@p]71d=H9s5ExiRG'RXm@-FtNxSxRrFr$xyY.lNo?{zVF_r3]Cn1JvekFm~]?wAH[Fh0IGAr1%^5&+e)?%On!Q6ylRnFU%O^@4h4?qV_Pz._Ja-{sw56%mL[@tcI8s*=OHz,@Q}EEwDcA&tAOjVnu~Zxdy0yK0@_?Iv5MIC4AHR^eb$yb1=v@HoyWItkx''B5GFxDwqK=9E3]G@327+N8wl![d{m9$8Nu[)oJAeIWSeeAowr?+M@HDv9bhOKGu=-uZI^8T}]Eh^&Gp-qJnVeb*I7@UACXkX,'ESrnOKq@)P2A0&44yUSMUI}[email protected](HYUk'7_ocOU(FziK??EH9bQ=3rZX!kb.rD[q&?f3hYwffaCMHjlMqksGk8^KAbD+47.q(PiZFV0aE=Ti&@y*^F,n1no7dYDbc?8R}b%Rr't2F%qM4jN1t9[Vi%7?FVj]O.VtvGc-PAgJa(EtjV3v%4?=WcSG&9.d&*dvo'SClNnlQod*)?-!I8$jax+j8[}JiX+5D@L_5JX8mR^RP{v}vUwtg=qT}ws3z,TQa?,`F6[mg?~+Gc15UdFL}q!!!TWMp?V?5dQFe+o`4LOdU&'k+A`y+@]CL?Q*Yesrro{~u?kCsiCJKz&4Lx[-74J('@LASnkzev@+hbO.or%*r8e'S8-cmpqE7T=,{dqFBAklcZL45dQS?0y!073MJ=g(+DEFDB9F9e]p*UA7{9[3UPoS=em*a[ergih}+?vDCfWmWT-iYoTj'O]Y%?{@zsSx?83nZZNc^9h+[AsZjdn!jql&h+6(orTf8AsgVX`uQwP.5=Is^6'kP@rV,]j_mVY7sjWagG{4_9`cm?PZ]6IuvYd9YsByu?y*6j'}2j^3FPmJ$oJl+9K4Y~Jz{im*!9SG'i+s!=t3i(h2ltpHJC-CTZlg?9@H~ksJr.JD_0mg,JR}[Ag)Bs&W8wvL=PjFA]3W4@bc[+WgIv_=uVfbdw2G=98h1K_68rZ3EguV6hPMr9N)Ob7Y6O3EGItVBoe&[Awz?m6mpIMHUhvDRJQyZ=p^`-lIy83?.76?BvU2u9e*G]E,1sWNYe$qB+,,p8H]J$^kS}^&@d81-a8NA96I@TT8K,WPdE-DlCWKH@I[!xG0PSzHgzxz-mRT~=$U$P6%kBc+@qIdv1Kn~?R(y(ywIz(GQ]4X[jeH_8PGZS_yeNV*^vvSy~fN-9uT=bHf?YfxY@afIPw4S=NtWVu901R)rEmjtFzj?=vm5r3ysaJUDoUY.G!B$AAUqtvWvS%G0^AIybM`q8nfD+GTgkt(&?h~bv~cJ=6Y8tDs6XrTX0EAS&UjKAf$%Rn=`b_+]%oj3p2N[9x.N2_NeH(%Nc$AenoU'?^s_!*vpLB^AiB-H0ffr9hqSdAuZR5=[JlvNX,A2@Gv2KQd@LkK0{G'CiFv[?{Zi(LwDG$GM!0pcdd3W=t-kRrM!%9IM@bxp6,ir8Bjks2T~`4y2TsR=!+4CA}2Igg-*sOx_2j]$V!yp?BNCjC~nN0C[{Y{pC{B-9nh3x]pi=lp_qGKZ[08%=^)00kg_.VzAdEIK$Y4h=3rYYBn27tu6bV?7)DrG@1+Q8NcSEk){%(iy.m+*=vxySbH9'vc`ZZv*MT.k8=bz6]tgRMaPVHOt-}N0@r5a%(ox=vm-}eK)Fb(N=v@Fq-}EGEgon*&GN]G+9%-yj[qxIyI8Ub`Pw%aD?{&'Ig+nxrwq2I7Ru-TD=G^I.[$v!'c{Tg5[~Hox8&rV*C5d2F]ExWmb{X-*AnV7-2Lj,v[(mEQ47q@X?&q]YdT3L*,115I'r1$v9&TWU8PfC4C~Vp]cS$1}=P{ku4J,L'5$(?$AE+`S?&_4LIHBnvj9w&cv0FCk9Bw[__i.ZxYz]5)Ci?a?@H(WC_%gqn*QvVQNPk'R=kT@jKY!@OrUIF2Ot*!i@9VfWcXj@vMLA6gtmu[k85+e7*]MtkWR2*OL-+T2@-PnWe]l*Com~xm?k^4[8D'hhFpXXC8bx.!Q5^sm@r-=r+EZ}t.i4R0Ad*BE9**+KsAX6+'hx({9*.=9?([,[%PUe{d%Kxe$oeWe9sV%r`+Ld?vH%(%s'(Tf9G]['=F-S97odRU3A}6j95tgC8-IqP%?4-,dEm3!@IP)mY3,VqdOr12cef,r=oU,s!BS_^v7b_hx[?9x9@!!Ol+DV{v*!jKb5p6896wh]WUM36^,wQs_pUPw?Y29kE6B7urJ=YT-,Nih@Wevgt!TQ@EIF}1!.%!k88ou(a=dFPb)sYFUNr,K=[bvk[h.SA0sFWXqgy&P?7rt)jpiHfG-21O3]6zLAu5EK5Q9PqoA78B.B'Ej=(q90j%'C09C0n2mn?w(A07%dHgYXZ4RWpjQU07T@-tZ-Q9!R@h9Q(WsIg1j=[FAmYm}NS&O%D}5p~X0?^nr%ALENb?!PC(Ax'[==t,1N3%+fL-iI*Z))P?99Y-~sL}~5!?C2EZF=T+W9ZH*z=`OOqQ}$h(DfdBY9kJzX^5.[mcM4C*(QM-x8+Fx,V_qIfh3f`gWP%y^8d{.rRaaQ*whx?8CMJUb9B6lvQIbLUJ^h`U3j35G9c,n{7&OO,MiLOuuDe}`=Mn%ZdvoaT666ExffqC`=*{u,XV5@hs!.%JdB0[Z=wj&coK7!Ci,I?}]XW)CAvGBliD}Ov1Y+UakInvbA18ZXQr!Xs_rlka*2Q4d9Lw5]MdPRu]{4=LuacIS9F?@TS7tH2VTL&}_jZ$q?8Bz$?DD')Bd)eK1a?7!A2K-V4n?AO*F5Uy@6abY?@)}[email protected]+NEN[DWD0Gs!!5x`*259gSFWV.tu?Fbl[37hrz!?dXz@U4OGc,V?N-uf7x~?19C_P+aQ^Bb~R%xi4q^?OvVBxa(0GNUxIN%5{@_9}R0Y_A7}73DkSQdVWzI@1qccB1rNpiLsh2MD,eh@(fKa.~LvVQWfXk,tA0E?pvwG'~Jh9tFc0HvdTl`=+EWYcK9*F.TN'GF`gEs?z!hkKaDCK]w3PEnTU2VA`5J'.uDx~frkA`G9Y-b?qa)dVG`zKaLX}UtrA)l@8YO%C&DX$H_?891RWEn8eOKB^76S*o}Us_uhSqU?(Q`$Y~C^X@)M5{R[N8R=iPq.*2q4IkO%H@Uu?3Z@LhQe*$r94`Fwx^j*&?3=9uf&1YwT~t!`QLi%Um&96ea'[email protected]]ZSlQB+BK_9Q~+G4=K%~G9Y5b=p)pB9'kI2N4g5i(Ulc=o_`*v83$@{tL_JR'*2JYZ?'UQ96TlV9xi.=b2=H6M6q!l9`04tGS^Mug_8%+1Tu%n9dZAgYb%%kAeD[A)'TY`@yh['iG!Z3M7r4qrmI_WAr6NB]-=SdRWk)E`Lj'm?I8}H'g)oVFmm},=s{Rp8M'Nz5Vdyu@3xe()^{1W=xb3cbBAw1n{SjsL[X&M9KWwjGS*z,pYczf(,J,`=QnOsTVAw85+7QQGb~m^=!XtS)A^juw[Hom[e!}W=PRF18q.7NVgFe+`&oe]8IiWXbhbh-FjX~F'vZ.G?19(`e!DjI)DOXQ`YCV3?K_$`_rPt?d'6br)Cu'@@%~s~r+tpCAUtAXWIWB?9_n%L^y'I~tf~iVoJg7`AY@B)ph{~+zQ,a0T%G6'@_8!mV5m!8nr`qX1e7{JAi*[b!^RbwC@)Kl)UvL[8z2fs6~vMt[0Zu$-Cmu$=RqO$`?4xkUa}Y-$IKAx9Y32+1s8Gu*s$nbMa5)$@1r*n?28g9tlinxu-vLZ@dIj5)}ou[tX[[hmIfQ79LV[HALi3@m0I{4&}Sj!?.Rea+F6Bhnv['*tj.R1?)@XSU!z$8Nhk?b9[70*?Rf2of]p(,nYDhKn{2}I9H=ljz^Y+WT^nbPOKts4AX}rU*&!Y}30h2GomhJm9xPG[?{F(d!nve+[4WNt@N==~+[0-+dL)No.0?f19mMjMvXlFj3awfYFyGx_9GafiEez5(2=3v}8Gl?a8VX,~t26j4exqt0V2[w,?MuddJI%(=`G3~(WfqvT9t-zi5kj4?XUKm4KffF0A(pA]0i-{,_n'YWy7s=Z8L$W{23hIm8sw8PC6D5e8F7!_7f?SCYTXgxPK95X=81Wx.TY-*5.o0F3&*J}@6D5Y,Qsh4)-2Am8S-iN=tPY'G9790Xsfe-G7Anx@)PDnsEjp=c'+a]GYC]I?Rkh}^]oE3RQ^U_Bzctk9rx7`mXQ!mJZj&xqPzfY?Hf['iXb8E&_H]kRQ?{Z8^BvO9UbM2X.yJ6{y+*U?J(Ff@g5GEd-'QZL0^5n@1DF{d5i2TBEvx[HZ^Z.9EErb]CQO^mB*OfP=6Ix?W3'T-45moI$2zGJh.{r9c%&BU2Bg=6d{Vp$?54P=K4&rtzbN0QRGjg)V?u(Azr(VGtJr+gG_VC^.FYp=&CRCATt'[[9I5gI9q{[?N,KoVuqfv]vNcIMZa=G?h}YAg!e7=x^X2Nw^6rb9yVMd)ve220uh8xrtNDR94$h-w{{.AX7t^k)%AC?9_5uGHk280qf)j4uCKHf9x`(.2Z~^0b[U,ovlGjIA*_15&]$UJKP]$aFzO+IAj%q7zPm.0Dq)[ZW9[y==`gvi%.pPTUZzm7Q[IQl93W%pVC[VmKV%2{(X4Bc@Z_TpO2I7c0P*D2+iKs[8NnCTY@E?85B~q)`I'b1A,HD0xAcQtszsjFKz^bd8D*z(T7aWc5]r^3[dnfD?YteJ2UPPwP9cgQ1ODI1?OeP9vi(W7*(-+A2-RsX@?5rAol0{X']s=^z70w,94'1tm~~AXSvnlz7()uV9di6@?5@ar1qhw7QNs6_?k-?w.'vO]ia5!qy+COw9$c}%z(-0DATYbQ^HYBv?o2%VaZB6V6T_lJK^A1BAX%ov*yIo})8G~}(m9lbA^*2.SgovK+4MK!]K&.EAm'M~O6YtPoga,kIt}F=?U$wc`qDX!wgL[0kVv$-@Qf}?rt]7hS1N[1E(S5RA{qw+ky]]dqMzpUBp@@E?Ej{PFg%5Hi%z$h3DC[y8B.R9`W^StYi4wn&`7}!?2PtTL?W}X.LYk*'}'4MAnf+*S=&75v..]B!wB!^Ar7=)(z$bpyB3&5,B^pf(V%eqFgkW_B83&5,B^pf(V%eqFgkW_BV2?0@7$9*=IdbugpYRMX}GHaGLdZ==A&kv@Y~]3iui-r60O)l=Em%pCn7G4)2INR3`I9&?giP6x,s{boITzaC}zyQ@Zq3QlMCb0e_~BT)zt6D@3PC]i`'k97CO&l.lTb,=]R=e`J)iKfSTWj^[email protected]~n??y=pBz{zreC7f{v2ONN7AIQ($FLMg+kW{gxFsbNF9SIB!Cno*{+Vu'g(5bsb@bp{$u%&qc*{xBOyt-_Y?tKI%Z-Mc.-mfcRGen[z8gxyTC5)$lpFd65]3ik39XNWEr.HA1X2^6k&MYvHA3sJRxaZ.o)cbd1,3yl=ATM)@Zf6](gQ5uLnWGwm?a'am$4_j!6`H$WG,'K{?`PWoFl3XHO&yb[XWL1P=67Cp(7T23(GH3m)$T@`8IL,W!cf8Y.M&-eI0x`U9?_6aCr%=9rjPgH$g%wv9}vA!UP)zsdMUrs6w.0_A1Z~iR0MtPO[_UTbJ*RN?[N!%zEB(bFrjbgy}vb99,3lTgP[9CaCzqbhKFa59~F1xyGq7Uw[?FlHKTkl9w=uFDlYvOe2I4r&*7K*@oY=$f,0`fxj'e-=R6~*?o284Ws`uz(]`OuxJ[EQ=wI~C@dEwA4s'j!GtbWU@SW?)[eK2wgq8_=_q[n.@54`lR]`jq)1Psr].Ie79u+.dnW%bv]$Q4lijs)%=H&d8jpGXnG.Uzxd8(Lk@zET?$js70WjP,H=WCk=9H%WFhbHY?%-8U%]r8V6Ap}?gAAogM.fVR-HJOm5@{8N`Nm8Yjx]]kF,)[dP9.Do,i~Qt9J(R0!H@TIS9@,.s@J^LR4,?k?&AJ_E@IF]big`w5Dez=9$*t&H@$=lUt7V$b0JAO_J-GJJ=Oskw`Q81%S2my[ynl$T?C`i%,v0r03Z4_F9$29&=K&}0?P,J-CDY]5YowxC99lRcs^}pIQosw4n.Zg@A3'YVnejxOQox&8q8uSt@E5}q'U{tHPmfo%juzDI9{~].{)DEx7u2oGRT}CI?30O!VLAQ46Z'jc`8kCF@2rYZiOg][SgG!8_UR%f?B0M-)~m0.O6f=.pfq,CAMjr0T$Ktr[e*ozX&?n)9(AEwhH?}NUO(PVHMTWL?F^rCShb0$[email protected]{n=xkI4s1Y+l?s4`8F]xVUy_lQxgS8]C2RGt?k-Il@7}M~[FCDvfHd)7AK7DM'o('U!Bsu{dRF1g(Qpy?VXB]2d.@B9{k~il?%}M(,OT~O??su{dRF1g(Qpy?VXB]2d8su{dRF1g(Qpy?VXB]2dL&Qt6Xj6JAfYY}i)1V'55h?)x-[r]8Y}Jne]iF4mj'Qs(P=W]?]rh$_b=T`zNsu{dRF1g(Qpy?VXB]2d_]d%u8j7y8AVDWx23awG3E'+7d?3g(Svy?VXB]2ddFX@%Dh0p@D`ps*wc`R!C^kgVwX=d8Du1(53Wye6BrZ?ko!m3=evrk9}k6(cXRCAZ~!dD9bt9iP%ihM75ZK)ey{RF9BuPs-EVE}nMq^.rqb=f?qd,5EqNap,sb*)S'FQG@iaXj-c!~5h'CtpcX_x{@t1SV*4BR3OoF52HN&&c?-_.LwUKL_^N8]eIo@T9A-Tf`Zv,oHPF-U^%]{d=9.f~O+NiDA2{r0Fld7fF@?xu(qE3&]B.vvU1GcK_9l.(XKm&q,g3aXk@mU*m?n_li[OM1z`CVwv(hrpk?U++in~hLHux1N$[5KvbA%-Jy2{2&1Y'rYO!k0^O?4_?il'78y$x=bkL[iS8A5[H8OhN~Fx2D9PC2qc*@hofbd_dT(XpiV4klpB=@kY7f0BiY29~KTr5*)P`?)+R.W.9zSQ++CN.(UEY@~4h'=yia`WdCMDK?Zkn?kRuGgKlYiKUrQl]NnIB9kg+-2j(a[)H=}]z[T}39^hn0cvv%g_s(la=Ud&y@6$9$Z)tEtYP?EYY)7*7=))jgP~&q7vW`(tnIt@19{K8!HvXVNX^[,6+%5U9?xf}Ea,uQT?8.k2C)0ef99Z7NbRwsFls9qGB)NK6?75rQ$PrA+]vN{TF%=j*@z&1*YsJ6+l^]'%S4e~t9[%B?2K,l&Yq8opf+RT~=&-r79*^UC[H^VH-tWTj8P9IMjf!R?Sp*drR+a'H@HBsc^L.m4Xb9TXB*{f(=[mUAPAM{(mkT$-+[9'!@ehGsBRMsL@OhfvK{U{2A~2,G1RD0J(5(DCNr`['=yK9`K(9u,tU?6&U'J~o@i0]tG0D0D@2x7XpM%2R=R=FADL2Z*^C.3ilt*ocA3GMnia`c.eE?{tieg^r8ZER9LIjbk@oSsK&rW!C9us%mAp^V7fFvue=4T=G?v.)w&$ix*kv2aARLnG2A1?oJBT6]1BylRiZX*@'9Czstq*zsz9H$+yBqG`^Aw3p+ssW@zls,ljRkONP@3AYZO[8+koUL$E+o$-u8t1kqF_CG&jp0]dxqfTQ?HYMOga+uu(4FS4SUz{{=}SFK`l=lvvAW6h!MbIk=Js7jG[*qT_0IXwxCh[5@$_=ps]BVzRnUiP$K3'~@19x9W_6oUFp5Is+{71I99X*p%mJ'CJEMn]nl'qNAzQeGxR3Skx8f%eRlLyO?gKbSfRULJ`ER((xqCL8A]MC270blp9'g.(EAFu19M5h2w.$OOj*PP+qogrV=w`TIVA2xDwr-mWagVL(AlQ%buchw.aAuF.EdwFQ=z[=,&tYyM_^wr$CO5i9?=^,J68f@e?b8N&[XROx8^GLBc{~Y)2!0P+_p.EQ9gH!S*x_?kyZ=&)u_,4r95~j]&,uu4k-pk)s[?Vb@,lPDx^$CEaXBe`QL?_v9ESmPRZ'2P0VJ_1)AGy&=`1s&ahB?Wr!93@Dl$?q=wC)q_Tt6&ZM&q&K*T7R?$f}8[CW%r%ZIzLoqP,H@pO*M+@O+8{(&iA&k43y9ZY?}i%-KD.5~kMfxw4q@]2N}(He`!W$ziJq9b8q8J*%j.?KD2J+DbO788VS@9uTrYBcrlKc[vc[(44@9sX^?DqBCFx]R}%OXG+(=gkgm2.9~m%a}]O5DdXW9'`@S[-^k_X.{0^PeK_Z=q9oNCBOi_Bv,%yFhaW]?]pZOk%!qQgp0=T=2QL)=VXCzW8bqug]n9+VT)?R?q]2KCPNu^cpt9?g4ZZM9K[z!G4Buy8I716yp*]&?MdS`bL,Cf8jCiuU)I&@9ax~hK@tN+zn%3_&Ucj]?$&8k`x+aCjA%4qi7k+y=%[St..%9aW.yEy=KA'69[l3jMwoMUrB{!r&2yWj@(xu*4J(49R09'58NEHv@t$elxbl5KoLdoehb)%3@utcPbb-uZ*i=!nLiqtq@!PcKRRY39y7-Vt&qy4]@R2B9J!pv.P+YD,AYknl9-ufkn(XvjSU.GyeW4i-9_GHL.U'-lbf.chx+}`Y9Tr^vRXb-`GC8jzq6jy.?c+)j['M_[+{R3zyR}zG?-1{T,,+zo.EAld*_+3$?0=pm.MKH@@7*H$ESvCf@BZ8d8cq(*@^iv~Gv2=B?n.Nb%_ToY2iMdxL)8T4@$JXT-=uPn8Fsur[5hfOAzAHGi.R]VT3W5Z=b,3O@Bw%L-F5hR1$e-fV9H2w9{w.eGUnhz14vq@EXov_?HMJhvAVlYpjSqoSW&'_=UQ+qbs&`,rUnoL7cU!%9]QB)oa&.5Z'QhWl,z70=.jWrgyzE)EWG$)sbhp4ATh]AF9[Nb^iNT)-IPjt8awMH+wk=*jvtl)u0jgdAa7@Yl)3x'y{Wo.hgIME=M`-@Y9OS5ZxG,^0uA+t9Z9H%9MJwbg=`SDjAV$0=*6KYWQ7bmXqpXn.iOW-?a'$^nKx^J+6HPy!&5@`?2x1m%5I&xjWA6ud!nUl@r846@3KNO]H(!X4^[OA=dI?dk.mODglYBPAL1l7=9ztH6VEPhg26ufIF*qA=nO5MTVbVasdOwCdNM(g=~S5%A?`FHA?sp%F-*-t94W5o[Sb*zq^j3w+C+jk?[9o]CLdr36)GaXf3-jLA1}1rupPY6Nn(TG1sX(E9nwy!@CA`hJG8DUztdy093[iM4KfpPl%oNG][l27@3rpC6zJyB7I(K_VLl[+?PbKp1F(tB4(,k58h`ad@r'fTx.,X*v-lIyqFL*Y=-SFTjx5e^yno'w%td(c?UxPZ!$IHKn0KUZCZ+8eA5Zx+``0c.s]P.^0m5Kc@Wp0^pomJ[a@agr2v7qd8Od96(+.835h@wEmx%b[8E3NV%}C,yE1olD*'-E%AcG3dHS!i2kYAv'h(gP}=jNce[@10zcRuUa=GHVs=$x66knG1F?g10i!hd,A@GFWvd'4r!!_0t%7=%HJ9v']]070eg,4rtz7HPwf@bj&br%F]y20G}n_tt``@Sh=oSHAR?QY)MyTwnJc@Rr5Q99c2j6l1LVp$K){@?&(,!04HSo{tb,O$6H+=]oKXw@5mf,z,jOjJ7GHAEMtCM&XVRXIMK-gR01c=(+,$pCVy6+l`z~DGwxn9SGC!E}1(e!EafPqx$[$A`e5ZQhKBpoZWS[8xubw9n05kZzjjHsf}CL3^Yq!@UIf4HaiG*u$5&tww[Sh8od[1%-7rQ^9k=o5AGQBAlmCGU^J)^OWOedoQ7Uz95dj&^^'Az!5YTrE*~Qg?V{Y786l(*rK{(+6~To=9linP*A2$vl0)gDsk2-U@'}x8*I@RqSVa)8iRGtb9,`o2aH2Zg(ixXk7T1g[?N?$YyD]CA-09!B4dAB?=oV_wOs(2Bug*XeSjmO'=&[~pyJAyJdIVv34ID3n@@n3FuuL`cDxyLTAN@uN@gD*n@IeC3mMJn5E3?RQ?IjLYZQ8)IFfZe+uN[t^@9Q,%!58Fno7vUM0t-YA9pU0TULeEb+~4t'IfuUl?LX_[_{Zx[J%Ml2Z~S$H?j5TE4tMiN+fl7*y1i9??K@fpp%,(7l[]E@e=TYx8v}0^1}qb]*I]]8-=+%,A-+5YV%N9@*zaYaqu?^$@i}fvjcb_NJ-!-UaEc*A@UpNQZ_1@diQXxiq5&={?X'c,]uptJaqwpz3B+fH=?.pYq6(-}aT]zpj{'NJ@9P=,j^h+SG=]Di]cc5R=+hp3g,FS-6ZFL@CB)iD@+GsQgI`tpOT,agL@x2m8@lmkpsX$X9qDh8(,fc^9lNoS3pOTEY[IIS5KlQ-@(,[D3^g^$0HG-GX[OBT?plfo20%m+qBmKTFpb.EAF[8ziV8Zgk3$Qlz,ZR8@Rd_heP=.A3oO%0lNqcY9~mA0z{j=dNk[cPx}V*(@3jJVd&)kt*PUKMA[8[Z?nVPhS`S0qX%'J}mNnJa=(0}-1IDK]&!mlj2`M[U9iE`DhfS_0$tmsUvq.QEA[LT8,s-pxU^H-xd7!O]AQ{^06Mgdbc^(f.uDT*B9E54Kq]afTuRM.X7A$~[??Zwu[C*hgC]YP)5ki[6ANLO.xy&NLHbprfv'9REAV=FFFUU*+D['ZXeyOrO9fCw92vg%`]2c.bYk?]NARCq}FtdocA3d*~quhX*=u-%OJAYHY.Q-S.)Fg&Q=!~Hvl_8*IyxQI5J3]bT=QOb9TxbOD+84Ycp1S9d@*Yv^s8c,9.o.$j,4Hi)ARn5GON0mFSgT_t!Nlyv8IsO=?6X&iAXaB'=?c8Q=_`2w-lf[d&!9y*T{x8k9ch3MB[us^reE+M(D)4&?*leU6_cBUo^[}g_}UUZ83yK.c?kO4j2!It[c~~IAi3$*M(~lyDT$F4f`0u=@leORtC!`8VlY$k$s{w&AVP?z!!fHm[%~,ud}+X`AvAgH@?QM8[T0]}xC{lb9YZZ84yKp(F,9g*`]gbA=]dMbYEuyYsUQu*)1u@h97Z6Vl=Db.T}s4r+(yzB@4q]gSWFsr%Am0vDo?&9=pT8~.AdVdEg$k9oik5h?},=5'Yg8$B-+LfMh8{6?]*fWBL,lk$=HKJInWE_?3^IYvmN&zM$5'$B5['Y=pnznk9UFq]*X[]'33t4@}}9}H1fJ1ZB3{@7CY`6=?GWy'*38fmQozFmlO~W=!$qmK8{7BH-U8!sLuy9?L3qYm%S~.pnS*FU*wqs8^s_WidSyLUd!PB'3_AX=6^mKrkys!E!5bdj+FJt8W{eQ1Imgmw!7{,=6%!5AtDN)pcZLB_,{lzd2I4P=l]~_%(mhX`~OTBeV8d?@m@z9dgQG[TO1i=B{o[R=@3JlwA&0.1}2)!,S}Dt?3-^P%G+HU16XJ?yr['392r?r.PnOSct`,}7cAhp={Ade%i+uO1vQQ5cdQo[8()kS40be%_?&afc[0B59m2Ndn7j3-&)A$L_(PA&9S52j.U@E&V4=3AEo)2^8@[S'=Ob~.b4*9NB^5b]9uZcaYe(h8,F'mww`.y*A*bzaYXPgBOhAPK*T[Kv9{-8DJR2`dnn7F6TYUlSATM=6J=j4wRfTf!Ge%n6=%pg`Ne4d%Qk%WyCZz?Q?X%@L!7%+Yk3{Gt@eYye@`V!,?Pd!raGMG=Qun^*=JQ,qX[mXuUpv))3^_S3?}dMHY6_d.c^=9[&0Og5@`AchI~HtATy1m&$LNX_?Hkd5$_h%eIXBZ&5~wTcA1%r`I7K_P0m2QGbj4+$?.b_s&BKd[bH22HF!,.V=qX-n%jy,Mm8yaXSjwXJ@fi*lMlu3(DtL]_X(?DT?[n4,9an2%F6IB*uRyZ4=!}&Tnq2*{1}fi~W?gc19iV&W`Bb`S2M9sqhr2wc@I}OQbP,.61XvG]$p6Mb?]&46KL+CxW5tfqj0GvDA]s~=qvauB`v97P8E1NX?,evLU31nf1l89u'2)=)?*y[`*0?,Ec4ax$IGJ^%?s3,h`XPs0QEF@I2O4'z9-Gbq`!3?Pi11Hf00U``A%dI,T~}~sf0E-W@57eN=}%w.pYTlli_e~,?ERt+9.POeBLgR9J!zDYrx2QaA'30IGorX(C(~5HE3fKc=tBJuq(VGgQJG.gBGC5r8}viD+{heyhMr&aUEqf_A]pGA*{zE('nJq~-f2~E=h`]gfr3=p&B&?(+*5Y&=HD$~0!xV,X*KJQRkSFV9pylW(Hvna`_c'Mj`{V[?[3%lR9B4T2mQyS6uL(M=GQ+G6MZf~3=n9@=zbK1AjWsh]'`I~KgTRBWpFhO?l?n=ziDf0YI@%F9HB~Y?QQzngpajuEj]d39v@lP?Y8Km&Z3+`]'BrW'rx5X9$X.$lkjMG*v-]9HgFTt=+}36BEboszdSdlek+pIAmRXoRLJ)jV*$!VVq-=x@T70~'$?~BK$,%pJX6z4ADXTSBwqb$O"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BE57927156491684595B7CBBD6D36EA2\Features]
"PrintApplications"="Enm~MSKp)9&56TH$yl=jpbNlKuw,'?(7wdXH$r},BBcVVR&oq@k12Fpx$iZvJ+X7LH-U4=9iulv[d?bMOKkxT~^eX@b+eqI{o=Wrm^tZ@iX_C9Kwfw55@2xhXAoxK$9l{?`qmYw7A@dxM=]-F=)R%9rPb$%bdkvl5H^l`ERM1AfB6W0l~b,&b2[llKrR?@xn2J*(A1AvHvyM+BOww8wll=VeD@-l'V!Gn+PjJ@=rxo?G(3zcQO@1j]NmD=`stJ@,KwOGkv8Tfva(i8Y`Y_%-z+xpZ@(K16U,X?+TmBgV'zOv^iYz1K6NU9s{wgQwAn,zyD6{s[L6bAR,sT0zYa^scQj)=YGf79dufQusq5Yz-{1iv69eB@,sg-RNA1c'_'7X][email protected]!SwHm*k{k`8qN??nuGWPpHj`9P.eTjlxO5@DP83jq77x)}9JtaMT4?@4l!5.UZAge-b_{s0wW5?W70d'Q%bHS1{,u@C{vz8%)0$)[email protected]?n)]A7{R_zHNMR(QFj7yLS8e8Hb7nhEX`*,m'3jr{CTp?3U,qmZXcZ0jFxOJx,Y8=%*ndD*yXVC`~HBoKw?N=*4b,N?ua!6U(uXK`r&9?^4l(@0&sw0,j9@MA3O0?IA-5)V*CS$nB%BY_nvM@=r.Lu(gueZoMvdRz^&0944]9v$G68bbiEg_yTp}@7zPF`u_@8!g^k$DZ8V?AiKHkJ565}gXa2MRgj139e4swNvb?Wg^-sE%fhL4?97W%BkyrB3IYY4eof,4=iq&*NGkveB-qCcRu`rq?*k7[0^7fT*@^5yi_3PR9HV6hBYFV{Ngq[9%)0k,?b?){9vyqHL3Qe1bJ[!.?`kciNh3{[*LDwIG!K7C901`WrC.wQKFd1$J^C}`AjcrXWjOT}i+cX`aPqy%AenVf2CbP_oVgKv1h,DR?$xlB6{A.r^0^RsT.*-Z97wA}y~D@@O?ky*C{52k8F)[eMB6F^S7-'iZ.Wb~=nF7Os}jw%$J=Jefbq2e=4^S~uZO)MV6dp&T]mQT?KiL)k+&,z%(Kfi[OrcU?k3Q4T1i%*Q'{K]C&u0E?JM9J7gs}nj*'Nd2M'[w=YRGAQFc0jy[ebAsK)'!=0HSNfG4=E4,3k0XdY5^8A2)Qu`z03k,.t,uNrs29N[e$,vY{1%5Q[qQS&n0=ND'I$.L'kC]6V~KWpGy85ou9z]]Vrn$]Hoy%V=6@FMDRf]2jlHq97y_0jHP=rmKAS%%`ob`q!qGr.@M@p]71d=H9s5ExiRG'RXm@-FtNxSxRrFr$xyY.lNo?{zVF_r3]Cn1JvekFm~]?wAH[Fh0IGAr1%^5&+e)?%On!Q6ylRnFU%O^@4h4?qV_Pz._Ja-{sw56%mL[@tcI8s*=OHz,@Q}EEwDcA&tAOjVnu~Zxdy0yK0@_?Iv5MIC4AHR^eb$yb1=v@HoyWItkx''B5GFxDwqK=9E3]G@327+N8wl![d{m9$8Nu[)oJAeIWSeeAowr?+M@HDv9bhOKGu=-uZI^8T}]Eh^&Gp-qJnVeb*I7@UACXkX,'ESIF}1!.%!k88ou(a=dFPb)sYFUNr,K=[bvk[h.SA0sFWXqgy&P?7rt)jpiHfG-21O3]6zLAu5EK5Q9PqoA78B.B'Ej=(q90j%'C09C0n2mn?w(A07%dHgYXZ4RWpjQU07T@-tZ-Q9!R@h9Q(WsIg1j=[FAmYm}NS&O%D}5p~X0?^nr%ALENb?!PC(Ax'[==t,1N3%+fL-iI*Z))P?99Y-~sL}~5!?C2EZF=T+W9ZH*z=`OOqQ}$h(DfdBY9kJzX^5.[mcM4C*(QM-x8+Fx,V_qIfh3f`gWP%y^8d{.rRaaQ*whx?8CMJUb9B6lvQIbLUJ^h`U3j35G9c,n{7&OO,MiLOuuDe}`=Mn%ZdvoaT666ExffqC`=*{u,XV5@hs!.%JdB0[Z=wj&coK7!Ci,I?}]XW)CAvGBliD}Ov1Y+UakInvbA18ZXQr!Xs_rlka*2Q4d9Lw5]MdPRu]{4=LuacIS9F?@TS7tH2VTL&}_jZ$q?8Bz$?DD')Bd)eK1a?7!A2K-V4n?AO*F5Uy@6abY?@)}[email protected]+NEN[DWD0GYczf(,J,`=QnOsTVAw85+7QQGb~m^=!XtS)A^juw[Hom[e!}W=PRF18q.7NVgFe+`&oe]8IiWXbhbh-FjX~F'vZ.G?19(`e!DjI)DOXQ`YCV3?K_$`_rPt?d'6br)Cu'@@%~s~r+tpCA0h2GomhJm9xPG[?{F(d!nve+[4WNt@N==~+[0-+dL)No.0?f19mMjMvXlFj3awfYFyGx_9GafiEez5(2=3v}8Gl?a8VX,~t26j4exqt0V2[w,?MuddJI%(=`G3~(WfqvT9t-zi5kj4?XUKm4KffF0A(pA]0i-{,_n'YWy7s=Z8L$W{23hIm8sw8PC6D5e8F7!_7f?SCYTXgxPK95X=81Wx.TY-*5.o0F3&*J}@6D5Y,Qsh4)-2Am8S-iN=tPY'G9790Xsfe-G7Anx@)PDnsEjp=c'+a]GYC]I?Rkh}^]oE3RQ^U_Bzctk9rx7`mXQ!mJZj&xqPzfY?Hf['iXb8E&_H]kRQ?{Z8^BvO9UbM2X.yJ6{y+*U?J(Ff@g5GEd-'QZL0^5n@1DF{d5i2TBEvx[HZ^Z.9EErb]CQO^mB*OfP=6Ix?W3'T-45moI$2zGJh.{r9c%&BU2Bg=6d{Vp$?54P=K4&rtzbN0QRGjg)V?u(Azr(VGtJr+gG_VC^.FYp=&CRCATt'[[9I5gI9q{[?N,KoVuqfv]vNcIMZa=G?h}YAg!e7=x^X2Nw^6rb9yVMd)ve220uh8xrtNDR94$h-w{{.AX7t^k)%AC?9_5uGHk280qf)j4uCKHf9x`(.2Z~^0b[U,ovlGjIA*_15&]$UJKP]$aFzO+IAj%q7zPm.0Dq)[ZW9[y==`gvi%.pPTUZzm7Q[IQl93W%pVC[VmKV%2{(X4Bc@Z_TpO2I7c0P*D2+iKs[8NnCTY@E?85B~q)`I'b1A,HD0xAcQtszsjFKz^bd8D*z(T7aWc5]r^3[dnfD?YteJ2UPPwP9cgQ1ODI1?OeP9vi(W7*(-+A2-RsX@?5rAol0{X']s=^z70w,94'1tm~~AXSvnlz7()uV9di6@?5@ar1qhw7QNs6_?k-?w.'vO]ia5!qy+COw9$c}%z(-0DATYbQ^HYBv?o2%VaZB6V6T_lJK^A1BAX%ov*yIo})8G~}(m9lbA^*2.SgovK+4MK!]K&.EAm'M~O6YtPoga,kIt}F=?U$wc`qDX!wgL[0kVv$-@Qf}?rt]7hS1N[1E(S5RA{qw+ky]]dqMzpUBp@@E?Ej{PFg%5Hi%z$h3DC[y8B.R9`W^StYi4wn&`7}!?2PtTL?W}X.LYk*'}'4MAnf+*S=&75v..]B!wB!^Ar7=)(z$bpyB3&5,B^pf(V%eqFgkW_B83&5,B^pf(V%eqFgkW_B_~BT)zt6D@3PC]i`'k97CO&l.lTb,=]R=e`J)iKfSTWj^[email protected]~n??y=pBz{zreC7f{v2ONN7AIQ($FLMg+kW{gxFsbNF9SIB!Cno*{+Vu'g(5bsb@bp{$u%&qc*{xBOyt-_Y?tKI%Z-Mc.-mfcRGen[z8gxyTC5)$lpFd65]3ik39XNWEr.HA1X2^6k&MYvHA3sJRxaZ.o)cbd1,3yl=ATM)@Zf6](gQ5uLnWGwm?a'am$4_j!6`H$WG,'K{?`PWoFl3XHO&yb[XWL1P=67Cp(7T23(GH3m)$T@`8IL,W!cf8Y.M&-eI0x`U9?_6aCr%=9rjPgH$g%wv9}vA!UP)zsdMUrs6w.0_A1Z~iR0MtPO[_UTbJ*RN?[N!%zEB(bFrjbgy}vb99,3lTgP[9CaCzqbhKFa59~F1xyGq7Uw[?FlHKTkl9w=uFDlYvOej'e-=R6~*?o284Ws`uz(]`OuxJ[EQ=wI~C@dEwA4s'j!GtbWU@SW?)[eK2wgq8_=_q[n.@54`lR]`jq)1Psr].Ie79u+.dnW%bv]$Q4lijs)%=H&d8jpGXnG.Uzxd8(Lk@zET?$js70WjP,H=WCk=9H%WFhbHY?%-8U%]r8V6Ap}?gAAogM.fVR-HJOm5@{8N`Nm8Yjx]]kF,)[dP9.Do,i~Qt9J(R0!H@TIS9@,.s@J^LR4,?k?&AJ_E@IF]big`w5Dez=9$*t&H@$=lUt7V$b0JAO_J-GJJ=Oskw`Q81%S2my[ynl$T?C`i%,v0r03Z4_F9$29&=K&}0?P,J-CDY]5YowxC99lRcs^}pIQosw4n.Zg@A3'YVnejxOQox&8q8uSt@E5}q'U{tHPmfo%juzDI9{~].{)DEx7u2oGRT}CI?30O!VLAQ46Z'jc`8kCF@2rYZiOg][Se*ozX&?n)9(AEwhH?}NUO(PVHMTWL?F^rCShb0$[email protected]{n=xkI4s1Y+l?s4`8F]xVUy_lQx.@B9{k~il?%}M(,OT~O?dFX@%Dh0p@D`ps*wc`R!C^kgVwX=d8Du1(53Wye6BrZ?ko!m3=evrk9}k6(cXRCAZ~!dD9bt9iP%ihM75ZK)ey{RF9BuPs-EVE}nMq^.rqb=f?qd,5EqNap,sb*)S'FQG@iaXj-c!~5h'CtpcX_x{@t1SV*4BR3OoF52HN&&c?-_.LwUKL_^N8]eIo@T9A-Tf`Zv,oHPF-U^%]{d=9.f~O+NiDA2{r0Fld7fF@?xu(qE3&]B.vvU1GcK_9l.(XKm&q,g3aXk@mU*m?n_li[OM1z`CVwv(hrpk?U++in~hLHux1N$[5KvbA%-Jy2{2&1Y'rYO!k0^O?4_?il'78y$x=bkL[iS8A5[H8OhN~Fx2D9PC2qc*@hofbd_dT(XpiV4klpB=@kY7f0BiY29~KTr5*)P`?)+R.W.9zSQ++CN.(UEY@~4h'=yia`WdCMDK?Zkn?kRuGgKlYiKUrQl]NnIB9kg+-2j(a[)H=}]z[T}39^hn0cvv%g_0IXwxCh[5@$_=ps]BVzRnUiP$K3'~@19x9W_6oUFp5Is+{71I99X*p%mJ'CJEMn]nl'qNAzQeGxR3Skx8f%eRlLyO?gKbSfRULJ`ER((xqCL8A]MC270blp9'g.(EAFu19M5h2w.$OOj*PP+qogrV=w`TIVA2xDwr-mWagVL(AlQ%buchw.aAuF.EdwFQ=z[=,&tYyM_^wr$CO5i9?=^,J68f@e?b8N&[XROx8^GLBc{~Y)2!0P+_p.EQ9gH!S*x_?kyZ=&)u_,4r95~j]&,uu4k-pk)s[?Vb@,lPDx^$CEaXBe`QL?_v9ESmPRZ'2P0VJ_1)AGy&=`1s&ahB?Wr!93@Dl$?q=wC)q_Tt6&ZM&q&K*T7R?$f}8[CW%r%ZIzLoqP,H@pO*M+@O+8{(&iA&k43y9ZY?}i%-KD.5~kMfxw4q@]2N}(He`!W$ziJq9b8q8J*%j.?KD2J+DbO788VS@9uTrYBcrlKAW6h!MbIk=Js7jG[*qT_o],okci(!@9g(PSGrmP+,Eq8dw]OWA~.7buvn^@K5ppuXj6^~=lQ$.N9a7&Ou@3izbW,r?VYR05UT$3gUaW3e8xJ?AHJn-M!E881bwr!H^FWk9JJYnoN'{-5T~)9L?+XU@i*%kGMpcDq](Q4QkF9{8=Rn!vque$P`1xZ2,C=[8iiX^TUtTFKXJs5Bu%)p8Ip2fyuNKDGccE3-r3&g96mBEy7QN9`7K+XzowAw8n2$]vno70q%&j]w7En6AZSZyjMyhtuIrh8VorYj9rhhnJ-[6'j+o^6.a{U1@c`1=OCh_qCiIeKYAu0`9]xm`mue.W%{yo7pEnA99]Du]1`L7q5qxQ5yhq^Y8VT@ZiG%zvmroTjCD]C5A6TGRp8An`FRFg=O9vty?qM2fDvEqcjl^`ZeaosL@T^p)G,o'Phi)uFLm6fOA?6*yLbLE6FsbsaJR`pU?M}9Y'XZRS[eZ%=s5mi8Av]rRItwKXg{*NLjnnF4=vPSV!.NzmqmMgj6NG(L9baMx%sT'Y&BC~w8MS0y93g(amLwAST^]gVuf?tl=@1sOP6JCbk?z?lhby~w?BPdV94.XZ@m*i}Ff3Y~9_qo18H-ure01nYQW~`]8dBZ`'U8B^+xSC-1uSWb=aXL]DQev3XF?zn%RUiz8cFBntb1y.X[fE9^^FD}=G]02xLkb]U[*[email protected]]lR)Tu3xt$PX90'C`%W1(42ue@+0J$WA94c,Mc~0v4b'pL.6U1?}9qq}L9yc3uEu3JjH9275@]hWmE{V2aFw)I=B%R?D?gGu6+i}-_Id*5IQicPC9Jy3^oP+r@%OW,4z[wJM@@xtus$Oi3vEelOW8)HRA+5=tuzSyfVy]~WHa~AY8Zk^1@x*MT1$_7h_GDKj9Lw9Pq'CS0W3UD6a6JsH@Vt[KLPyd)iq1oQ*X5NG?DP{J9`&_owV,s_WO]o(=y,$p3O7Nl?3P_=*6HZ`9xEd?[f4~0LSI91LVad+?3GIs6,3uOZo)R+LpD=j9(qxK5hyyCbeK^RKaJ]V@)8.VLs1kB!UjHJqN't&?{DtookcI-[fQ3KOP_Xz?l!xomBLOZgSk6c@F[p}9AnxjI=C`Y!I)oqyu{ju8VgG]gwU^Xvxc7E@G=r6AaLO5U5W`6vp*c.5?p,e8BxXe7{n,?])C*+UUdM,@?@2&qb@gqO&G3&4S6m79G0Qg46Ddvu}FGVr1'.]?Te}DitIk~.fSyAh}''2@A5AAsnPMxcNTC9zDyev?%2CwajJZ0O*6vOU0zz[?V8M87C&g9MUd?C={=qw8fHooD7!XFYe0Khjnyh{@lMw%5Yt_PE`*5UV,cSYA@m3,s^,(c5BH,b`wVTv8Ig*Ay=K,%AHoKSU%nRA9WW1l*gx2E-si]t4~%(a=ofDbsyULj=II02&i(!VAF$N-Tp^Pi'eK7g6),b)AYhOYZ]IBOb4biQd8b$!9SgonD$~G$ghu-8S~U2R9JN+[IM0}HiHwXA0[]?T9L5DCW_`A3`M]O7*'2iT=&]4-(QnQPAvut.Gmf5M?%BZjFTOqDPc[vc[(44@9sX^?DqBCFx]R}%OXG+(=gkgm2.9~m%a}]O5DdXW9'`@S[-^k_X.{0^PeK_Z=q9oNCBOi_Bv,%yFhaW]?]pZOk%!qQgp0=T=2QL)=VXCzW8bqug]n9+VT)?R?q]2KCPNu^cpt9?g4ZZM9K[z!G4Buy8I716yp*]&?MdS`bL,Cf8jCiuU)I&@9ax~hK@tN+zn%3_&Ucj]?$&8k`x+aCjA%4qi7k+y=%[St..%9aW.yEy=KA'69[l3jMwoMUrB{!r&2yWj@(xu*4J(49R09'58NEHv@t$elxbl5KoLdoehb)%3@utcPbb-uZ*i=!nLiqtq@!PcKRRY39y7-Vt&qy4]@R2B9J!pv.P+YD,AYknl9-ufkn(XvjSU.GyeW4i-9_GHL.U'-lbf.chx+}`Y9Tr^vRXb-`GC8jzq6jy.?c+)j['M_[+{R3zyR}zG?-1{T,,+zo.EAld*_+3$?0=pm.MKH@@7*H$ESvCf@BZ8d8cq(*@^iv~Gv2=B?n.Nb%_ToY2iMdxL)8T4@$JXT-=uPn8Fsur[5hfOAzAHGi.R]VT3W5Z=b,3O@Bw%L-F5hR1$e-fV9H2w9{w.eGUnhz14vq@EXov_?HMJhvAVlYpjSqoSW&'_=UQ+qbs&`,rUnoL7cU!%9]QB)oa&.5Z'QhWl,z70=.jWrgyzE)EWG$)sbhp4ATh]AF9[Nb^iNT)-IPjt8awMH+wk=*jvtl)u0jgdAa7@Yl)3x'y{Wo.hgIME=M`-@Y9OS5ZxG,^0uA+t9Z9H%9MJwbg=`SDjAV$0=*6KYWQ7bmXqpXn.iOW-?a'$^nKx^J+6HPy!&5@`?2x1m%5I&xjWA6ud!nUl@r846@3KNO]H(!X4^[OA=dI?dk.mODglYBPAL1l7=9ztH6VEPhg26ufIF*qA=nO5MTVbVasdOwCdNM(g=~S5%A?`FHA?sp%F-*-t94W5o[Sb*zq^j3w+C+jk?[9o]CLdr36)GaXf3-jLA1}1rupPY6Nn(TG1sX(E9nwy!@CA`hJBmKTFpb.EAF[8ziV8Zgk"
"PrintSubsystem"="Enm~MSKp)9&56TH$yl=jpbNlKuw,'?(7wdXH$r},BBcVVR&oq@k12Fpx$iZvJ+X7LH-U4=9iulv[d?bMOKkxT~^eX@b+eqI{o=Wrm^tZ@iX_C9Kwfw55@2xhXAoxK$9l{?`qmYw7A@dxM=]-F=)R%9rPb$%bdkvl5H^l`ERM1AfB6W0l~b,&b2[llKrR?@xn2J*(A1AvHvyM+BOww8wll=VeD@-l'V!Gn+PjJ@=rxo?G(3zcQO@1j]NmD=`stJ@,KwOGkv8Tfva(i8Y`Y_%-z+xpZ@(K16U,X?+TmBgV'zOv^iYz1K6NU9s{wgQwAn,zyD6{s[L6bAR,sT0zYa^scQj)=YGf79dufQusq5Yz-{1iv69eB@,sg-RNA1c'_'7X][email protected]!SwHm*k{k`8qN??nuGWPpHj`9P.eTjlxO5@DP83jq77x)}9JtaMT4?@4l!5.UZAge-b_{s0wW5?W70d'Q%bHS1{,u@C{vz8%)0$)[email protected]?n)]A7{R_zHNMR(QFj7yLS8e8Hb7nhEX`*,m'3jr{CTp?3U,qmZXcZ0jFxOJx,Y8=%*ndD*yXVC`~HBoKw?N=*4b,N?ua!6U(uXK`r&9?^4l(@0&sw0,j9@MA3O0?IA-5)V*CS$nB%BY_nvM@=r.Lu(gueZoMvdRz^&0944]9v$G68bbiEg_yTp}@7zPF`u_@8!g^k$DZ8V?AiKHkJ565}gXa2MRgj139e4swNvb?Wg^-sE%fhL4?97W%BkyrB3IYY4eof,4=iq&*NGkveB-qCcRu`rq?*k7[0^7fT*@^5yi_3PR9HV6hBYFV{Ngq[9%)0k,?b?){9vyqHL3Qe1bJ[!.?`kciNh3{[*LDwIG!K7C901`WrC.wQKFd1$J^C}`AjcrXWjOT}i+cX`aPqy%AenVf2CbP_oVgKv1h,DR?$xlB6{A.r^0^RsT.*-Z97wA}y~D@@O?ky*C{52k8F)[eMB6F^S7-'iZ.Wb~=nF7Os}jw%$J=Jefbq2e=4^S~uZO)MV6dp&T]mQT?KiL)k+&,z%(Kfi[OrcU?k3Q4T1i%*Q'{K]C&u0E?JM9J7gs}nj*'Nd2M'[w=YRGAQFc0jy[ebAsK)'!=0HSNfG4=E4,3k0XdY5^8A2)Qu`z03k,.t,uNrs29N[e$,vY{1%5Q[qQS&n0=ND'I$.L'kC]6V~KWpGy85ou9z]]Vrn$]Hoy%V=6@FMDRf]2jlHq97y_0jHP=rmKAS%%`ob`q!qGr.@M@p]71d=H9s5ExiRG'RXm@-FtNxSxRrFr$xyY.lNo?{zVF_r3]Cn1JvekFm~]?wAH[Fh0IGAr1%^5&+e)?%On!Q6ylRnFU%O^@4h4?qV_Pz._Ja-{sw56%mL[@tcI8s*=OHz,@Q}EEwDcA&tAOjVnu~Zxdy0yK0@_?Iv5MIC4AHR^eb$yb1=v@HoyWItkx''B5GFxDwqK=9E3]G@327+N8wl![d{m9$8Nu[)oJAeIWSeeAowr?+M@HDv9bhOKGu=-uZI^8T}]Eh^&Gp-qJnVeb*I7@UACXkX,'ESIF}1!.%!k88ou(a=dFPb)sYFUNr,K=[bvk[h.SA0sFWXqgy&P?7rt)jpiHfG-21O3]6zLAu5EK5Q9PqoA78B.B'Ej=(q90j%'C09C0n2mn?w(A07%dHgYXZ4RWpjQU07T@-tZ-Q9!R@h9Q(WsIg1j=[FAmYm}NS&O%D}5p~X0?^nr%ALENb?!PC(Ax'[==t,1N3%+fL-iI*Z))P?99Y-~sL}~5!?C2EZF=T+W9ZH*z=`OOqQ}$h(DfdBY9kJzX^5.[mcM4C*(QM-x8+Fx,V_qIfh3f`gWP%y^8d{.rRaaQ*whx?8CMJUb9B6lvQIbLUJ^h`U3j35G9c,n{7&OO,MiLOuuDe}`=Mn%ZdvoaT666ExffqC`=*{u,XV5@hs!.%JdB0[Z=wj&coK7!Ci,I?}]XW)CAvGBliD}Ov1Y+UakInvbA18ZXQr!Xs_rlka*2Q4d9Lw5]MdPRu]{4=LuacIS9F?@TS7tH2VTL&}_jZ$q?8Bz$?DD')BYczf(,J,`=QnOsTVAw85+7QQGb~m^=!XtS)A^juw[Hom[e!}W=PRF18q.7NVgFe+`&oe]8IiWXbhbh-FjX~F'vZ.G?19(`e!DjI)DOXQ`YCV3?K_$`_rPt?d'6br)Cu'@@%~s~r+tpCA0h2GomhJm9xPG[?{F(d!nve+[4WNt@N==~+[0-+dL)No.0?f19mMjMvXlFj3awfYFyGx_9GafiEez5(2=3v}8Gl?a8VX,~t26j4exqt0V2[w,?MuddJI%(=`G3~(WfqvT9t-zi5kj4?XUKm4KffF0A(pA]0i-{,_n'YWy7s=Z8L$W{23hIm8sw8PC6D5e8F7!_7f?SCYTXgxPK95X=81Wx.TY-*5.o0F3&*J}@6D5Y,Qsh4)-2Am8S-iN=tPY'G9790Xsfe-G7Anx@)PDnsEjp=c'+a]GYC]I?Rkh}^]oE3RQ^U_Bzctk9rx7`mXQ!mJZj&xqPzfY?Hf['iXb8E&_H]kRQ?{Z8^BvO9UbM2X.yJ6{y+*U?J(Ff@g5GEd-'QZL0^5n@1DF{d5i2TBEvx[HZ^Z.9EErb]CQO^mB*OfP=6Ix?W3'T-45moI$2zGJh.{r9c%&BU2Bg=6d{Vp$?54P=K4&rtzbN0QRGjg)V?u(Azr(VGtJr+gG_VC^.FYp=&CRCATt'[[9I5gI9q{[?N,KoVuqfv]vNcIMZa=G?h}YAg!e7=x^X2Nw^6rb9yVMd)ve220uh8xrtNDR94$h-w{{.AX7t^k)%AC?9_5uGHk280qf)j4uCKHf9x`(.2Z~^0b[U,ovlGjIA*_15&]$UJKP]$aFzO+IAj%q7zPm.0Dq)[ZW9[y==`gvi%.pPTUZzm7Q[IQl93W%pVC[VmKV%2{(X4Bc@Z_TpO2I7c0P*D2+iKs[8NnCTY@E?85B~q)`I'b1A,HD0xAcQtszsjFKz^bd8D*z(T7aWc5]r^3[dnfD?YteJ2UPPwP9cgQ1ODI1?OeP9vi(W7*(-+A2-RsX@?5rAol0{X']s=^z70w,94'1tm~~AXSvnlz7()uV9di6@?5@ar1qhw7QNs6_?k-?w.'vO]ia5!qy+COw9$c}%z(-0DATYbQ^HYBv?o2%VaZB6V6T_lJK^A1BAX%ov*yIo})8G~}(m9lbA^*2.SgovK+4MK!]K&.EAm'M~O6YtPoga,kIt}F=?U$wc`qDX!wgL[0kVv$-@Qf}?rt]7hS1N[1E(S5RA{qw+ky]]dqMzpUBp@@E?Ej{PFg%5Hi%z$h3DC[y8B.R9`W^StYi4wn&`7}!?2PtTL?W}X.LYk*'}'4MAnf+*S=&75v..]B!wB!^Ar7=)(z$bpyB3&5,B^pf(V%eqFgkW_B83&5,B^pf(V%eqFgkW_B_~BT)zt6D@3PC]i`'k97CO&l.lTb,=]R=e`J)iKfSTWj^[email protected]~n??y=pBz{zreC7f{v2ONN7AIQ($FLMg+kW{gxFsbNF9SIB!Cno*{+Vu'g(5bsb@bp{$u%&qc*{xBOyt-_Y?tKI%Z-Mc.-mfcRGen[z8gxyTC5)$lpFd65]3ik39XNWEr.HA1X2^6k&MYvHA3sJRxaZ.o)cbd1,3yl=ATM)@Zf6](gQ5uLnWGwm?a'am$4_j!6`H$WG,'K{?`PWoFl3XHO&yb[XWL1P=67Cp(7T23(GH3m)$T@`8IL,W!cf8Y.M&-eI0x`U9?_6aCr%=9rjPgH$g%wv9}vA!UP)zsdMUrs6w.0_A1Z~iR0MtPO[_UTbJ*RN?[N!%zEB(bFrjbgy}vb99,3lTgP[9CaCzqbhKFa59~F1xyGq7Uw[?FlHKTkl9w=uFDlYvOej'e-=R6~*?o284Ws`uz(]`OuxJ[EQ=wI~C@dEwA4s'j!GtbWU@SW?)[eK2wgq8_=_q[n.@54`lR]`jq)1Psr].Ie79u+.dnW%bv]$Q4lijs)%=H&d8jpGXnG.Uzxd8(Lk@zET?$js70WjP,H=WCk=9H%WFhbHY?%-8U%]r8V6Ap}?gAAogM.fVR-HJOm5@{8N`Nm8Yjx]]kF,)[dP9.Do,i~Qt9J(R0!H@TIS9@,.s@J^LR4,?k?&AJ_E@IF]big`w5Dez=9$*t&H@$=lUt7V$b0JAO_J-GJJ=Oskw`Q81%S2my[ynl$T?C`i%,v0r03Z4_F9$29&=K&}0?P,J-CDY]5YowxC99lRcs^}pIQosw4n.Zg@A3'YVnejxOQox&8q8uSt@E5}q'U{tHPmfo%juzDI9{~].{)DEx7u2oGRT}CI?30O!VLAQ46Z'jc`8kCF@2rYZiOg][Se*ozX&?n)9(AEwhH?}NUO(PVHMTWL?F^rCShb0$[email protected]{n=xkI4s1Y+l?s4`8F]xVUy_lQx.@B9{k~il?%}M(,OT~O?dFX@%Dh0p@D`ps*wc`R!C^kgVwX=d8Du1(53Wye6BrZ?ko!m3=evrk9}k6(cXRCAZ~!dD9bt9iP%ihM75ZK)ey{RF9BuPs-EVE}nMq^.rqb=f?qd,5EqNap,sb*)S'FQG@iaXj-c!~5h'CtpcX_x{@t1SV*4BR3OoF52HN&&c?-_.LwUKL_^N8]eIo@T9A-Tf`Zv,oHPF-U^%]{d=9.f~O+NiDA2{r0Fld7fF@?xu(qE3&]B.vvU1GcK_9l.(XKm&q,g3aXk@mU*m?n_li[OM1z`CVwv(hrpk?U++in~hLHux1N$[5KvbA%-Jy2{2&1Y'rYO!k0^O?4_?il'78y$x=bkL[iS8A5[H8OhN~Fx2D9PC2qc*@hofbd_dT(XpiV4klpB=@kY7f0BiY29~KTr5*)P`?)+R.W.9zSQ++CN.(UEY@~4h'=yia`WdCMDK?Zkn?kRuGgKlYiKUrQl]NnIB9kg+-2j(a[)H=}]z[T}39^hn0cvv%g_0IXwxCh[5@$_=ps]BVzRnUiP$K3'~@19x9W_6oUFp5Is+{71I99X*p%mJ'CJEMn]nl'qNAzQeGxR3Skx8f%eRlLyO?gKbSfRULJ`ER((xqCL8A]MC270blp9'g.(EAFu19M5h2w.$OOj*PP+qogrV=w`TIVA2xDwr-mWagVL(AlQ%buchw.aAuF.EdwFQ=z[=,&tYyM_^wr$CO5i9?=^,J68f@e?b8N&[XROx8^GLBc{~Y)2!0P+_p.EQ9gH!S*x_?kyZ=&)u_,4r95~j]&,uu4k-pk)s[?Vb@,lPDx^$CEaXBe`QL?_v9ESmPRZ'2P0VJ_1)AGy&=`1s&ahB?Wr!93@Dl$?q=wC)q_Tt6&ZM&q&K*T7R?$f}8[CW%r%ZIzLoqP,H@pO*M+@O+8{(&iA&k43y9ZY?}i%-KD.5~kMfxw4q@]2N}(He`!W$ziJq9b8q8J*%j.?KD2J+DbO788VS@9uTrYBcrlKAW6h!MbIk=Js7jG[*qT_c[vc[(44@9sX^?DqBCFx]R}%OXG+(=gkgm2.9~m%a}]O5DdXW9'`@S[-^k_X.{0^PeK_Z=q9oNCBOi_Bv,%yFhaW]?]pZOk%!qQgp0=T=2QL)=VXCzW8bqug]n9+VT)?R?q]2KCPNu^cpt9?g4ZZM9K[z!G4Buy8I716yp*]&?MdS`bL,Cf8jCiuU)I&@9ax~hK@tN+zn%3_&Ucj]?$&8k`x+aCjA%4qi7k+y=%[St..%9aW.yEy=KA'69[l3jMwoMUrB{!r&2yWj@(xu*4J(49R09'58NEHv@t$elxbl5KoLdoehb)%3@utcPbb-uZ*i=!nLiqtq@!PcKRRY39y7-Vt&qy4]@R2B9J!pv.P+YD,AYknl9-ufkn(XvjSU.GyeW4i-9_GHL.U'-lbf.chx+}`Y9Tr^vRXb-`GC8jzq6jy.?c+)j['M_[+{R3zyR}zG?-1{T,,+zo.EAld*_+3$?0=pm.MKH@@7*H$ESvCf@BZ8d8cq(*@^iv~Gv2=B?n.Nb%_ToY2iMdxL)8T4@$JXT-=uPn8Fsur[5hfOAzAHGi.R]VT3W5Z=b,3O@Bw%L-F5hR1$e-fV9H2w9{w.eGUnhz14vq@EXov_?HMJhvAVlYpjSqoSW&'_=UQ+qbs&`,rUnoL7cU!%9]QB)oa&.5Z'QhWl,z70=.jWrgyzE)EWG$)sbhp4ATh]AF9[Nb^iNT)-IPjt8awMH+wk=*jvtl)u0jgdAa7@Yl)3x'y{Wo.hgIME=M`-@Y9OS5ZxG,^0uA+t9Z9H%9MJwbg=`SDjAV$0=*6KYWQ7bmXqpXn.iOW-?a'$^nKx^J+6HPy!&5@`?2x1m%5I&xjWA6ud!nUl@r846@3KNO]H(!X4^[OA=dI?dk.mODglYBPAL1l7=9ztH6VEPhg26ufIF*qA=nO5MTVbVasdOwCdNM(g=~S5%A?`FHA?sp%F-*-t94W5o[Sb*zq^j3w+C+jk?[9o]CLdr36)GaXf3-jLA1}1rupPY6Nn(TG1sX(E9nwy!@CA`hJ"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\C168B70F9B274A04B8A1AADEC4607A8E\Features]
"QuickTimeEssentials"="`$LiH-(lv8[cWPhecTIL*wdErlmYS9+*yq?_IkZ!TD_.UDBXu9BWe%xw`*tdZhs7l)0d,APqZbPM[2*(4z2ey8W`a?D][email protected]{wUL^qGU9+V'pFBY167$8!_Ybs}-?.O0CEPt)N@$Iw5SV0?z@oz1dE_(~Zir&yS?)jd2=s4qL'&K&]DA[hddxHdg=T$[77]0RY(Pq8G!DDJ+?XUH52f{V.hWfNVY4!3cA-F6n2-atXtQ[[w?O[Ft?i+]O!&C?todA*0[DkQS9~j=6,?!GhQ20p4YymJ+=^jfLO9!NbR?s]i^Eh$4=V0~{Irc5!(`5uXN,k-}?yq[nA^NJK*4Zi4U$vly9[eA(A3zHmm$jm8[TD!C?ZGQvISNfy^e$h)4K2}]@PnN.ONtwG3i?iObgW!Y@Kt%dM.{HTuLSq@vvIH(?E=5m3sDcoYhD8f.KZhu?&dw?G7u'fPY(M'Oa8YX?JlP@zA]?dPU'[}?D]p_8aFZU26(O)[g!k!9TzPM@)}t+*JIz1iOU-WKewhJAW+cnwVo8~Gzfo.6e(KeAg$b)n.g0eY3xCRE$sf??9s4rg{{amEfx]&i`tLc?e@(-c[U,TpMqkwbm~Rq8%Xk!`%M'$Y@=UBE4J}W@((MkkP8^Gf&p~ojuDs'@a0o3L1l,JtS{oSd8GBF@?hC$@7]*RUe&V`CIjAr9e`_nQ6jAbpk0(&YhlrM@0}}7j`}nYs+i)7Vvr^p8]CSa`*RH)iUSOobE4)e983mmG7Lt53F_Vb1*%s4@56!71O,n9,8k4B-GjX`=_37IxWY[9B&4Je.~`L}@5yo_TyU+p)AL,*!b+~{@^8M?s?Ax=b`d]&G[1_^?yeKadHdS}MFDjyg$NA0?]o%eNAJlza1_G,mj$Z+A-t,'EKJVLN-NBobLolc@lnc^+8QwaavDGp2w'-n@lRHWtzz+BZBQ-.tt5,[=dVCSAUt8n7XzahO*]v=?yFMM-2P&6,K^@[yT!7e9zDdpvYNr*9wR,[email protected][vNRB.DHjA9M[gOP@8(!.n&Y2~x[~{x[)RJ+A+ZOMpQU[q^9t6C,@I6!=!-=3h-KbHO!qX((hlf_?[mR9mnVp(a!@2%_&@$n?5=I,e&1o4k6rAVTAEU,=i(i''E^)@WJmYC9{^t=?N[CQMP*'2E2zcr@J$f{=tLi?t_y0[i}5SSXVG&-?@t6n8@4'IC+NHMEw!9]?WxK$%m$@+PwCSbC$?Z)?4c.MxS7Sw[3zJGu3qQJ9rTb!B$qwb,6aUMN?Ptb=doz^4kcBH%=shc3(ffp9uEznd7hutB4{[email protected]@~(Q^e@H.]AokF{59B5dy5,haF^MAdAsg+uh7tt}S!XEIt{9UB?(8dka%`@Z`NPj1F2{j8=y&M)W+d?d2N0.WF%)Cs9upA^,v_Vr'(-AEOL53{@T(a7^3AM_a~iple^8$~9a-ZCBhuN%b5]NKGbtf9?Jk@qu_T,H'@TzpGqx!l8919[Dh`n,1~h6zDmF0k9bF42?EHw6oe`7n)Ba)2?ebQf*[5u&xCW]BM*3X+At*YXa8mlveGa]b8YkQ}@5ZEJ]e@su7MXJJEDdd'=Kh52SB)S3?rK2l0IxP2Ai%cOd4M0}I}5s!luY{RA+SL_3aY5B[!sPb37j$F@NXcI!g&3u1].tf]P?$*@5jwIsYQ!vF]3!`SK2?w?-+4?!~ALWkA1-_*klps8)Mp=cy$gS].tNeCBHlr9y7-)09~sm@v!r=Taf[dAb`IbHJD(9qv$UYHQ!zX=q{HOtFk5`3UV517S%U@=1cPi,3g~?j8m(SWpm9.?)Bp(M8H50U)HTIodmIt@)cY9w)Cnh*))+IDzS-&@3XFID@,poiZV.spJug9Ac5,8i3xCiI,fPSe=6ki=mX*HQ'GzJc?u1Ic-.9t9t.]DvpQ^nu~r~ab'n3H=M+pBgRpr9ouuD8EtbPl9f`4kedY]}vzlt'nkXt_8x[9(O6s6k%q1_LyG7?I=dbcIz9r'Ib2watV0EPi@Rc_85r~Bx^0yd9+fBBD?7_V7qBgZ-Hq)bD3I~y*='lGW8AQi@j*shTn?YPA=$g^[mxagX]E,gKe^RC3=hu$11WA2AhV)S(M$+Kz?=u0p1c_24xa.3}Ts%60@=Rnkin+{CaA&0c&kRTN=@1`fe?gZ_busP1_o@N+=,AHeCMcYwu5`*!@jv.E=i{YS_=BQ1L0n.V`.Fhj9'tP]M==QAeGG^[g9b^O9@WFUWB']pS+wD4)5]1XAQ1M^gLdW8'}`Ojlj=gV=IN%VFKkmA.Q1`ha1?!d?2Sip,$f'9f.$?uC0XS0@}yO5[663r.XV-`IL!Y*9!m0oC@S-5&-g`g3{xMg=cuu88moFecW7=?vGH_n?=.2(4^ZafG5T(Ehpckt8tGT_QOAu1P?qucXkHwp9r)arlSU,sfYc}50c{XG9ozCVFkH8F$tk$sVRsOi?RYUE,NPwRqDJ%?I2)Gh=z`!~otkoZA$xu,D'8S&9.s?0'+-y%GW1HKjrnwb8W'CS0O7G56ztJ5F1%)2?*Chj+mDGuW%H_wjj]*7=&-JtD4La3!dsRDA1xeK?K^_]$.4dBTsaZ!1EdeL?=levhI$OvyORj!mf$in9SJ0s&aADYeV*l&?km6e8q1CJkAxOa4o&xoSSWZM9UQ5g5mh?O7x(WO=daiJ?qITr1@FaV8]TKqjL]h[8VD2)huq`6sM$69SytH89?2&}AZ{8PIq2~Tkxn=N@%&,hvPJ?kT-m=dXDsi}9+Ww}$0jjJ,VoKHh!B`d85pS%2T-@9A!sF.WMDvY8a37B!Szi&4Gwgk!Z]-n8[?K)9+{0lt5'3ppf4yE@9Q$A6DR`lQ}D5S)0J!3@{)$g^9p^IP_l9WzD~8z@hL^,bTPRV!0gkGYIIARA0cCIF*=m8o'zVfr{n7~9So&S2j-&dkL394a*@Uw?=BA=w&-XoRw2W)(haYe8lFIrJ0WU[!fAIH0Dfbb@z!Nr%Qnr6I[w$cyu{2z9K)1GVP[yPLg6Z{8ew5!A{(hJ[UC~?Mw?&%_bV9DA=6yglh&9Z!J^.(,iEfv@STsVIml^@evm.0V,[zN9!*PLE_cYCh*jYVYW{$99M5!FR%ffl`Vmp@-N9)bA'Dhmof@V]O=VDB*Udav=xie6sJ-y1(qY+J0ox$WACC?Re@G]CbRfnxnSbX9AkaMU?G7D6gFe9_iVB?[9s2O}KB0Ejq3*l_3_5Tg8pfxg&KT35H]x?{XyZ6'=,-bJ&YCaxFhH5ZMj+pi=Ft6wrw~k.O{(C]@4{~N=860@2In'fibJOALN2hu9hG@v%Yi_H%PnC=g9ek)Ah.QH4yYI)*_]^Q]WLyK@RIFjPir!Z3STsA=D0P`8Sazq=aQ__1na5A^7iVT?i5=[+7uFUlAbA]%.=l'=2mpcr%U?3sK{522?[h`?Y['$5J8mjQE3TSK*av?@dHs!A?gg%Z(%O!oG9f69g`_d@kSF(7MlaBgNL^I@-,$@4i~p_j6xCYpDJWU=gnuVO-[4zTgeOJy7)Iz@xn1nuUNB%hPS`M%fC&}@,=FKNC9.rZ&xRf(A9M(?]P,To{@l&Qu`3)=k}J~@rQKU=m5*AXIPi+tXSF]=!e9WZji(Z`qHYF+@G3b=1{&~8Lda`ZymbAd)svU9brywcefgC(rPwidw8R9A?DyPWS^h?VzJpv[gNl?9Tw,@QtKA*&5]O9ruJ=S=r[fuMCLE3,I[D6%3T[k@B4pEk]n,B?GY3'']Y[G?Zp`5wsmVJolIettLo(w=51zM]dM*=PY2!{DOxb7=l@KkxerW^yKaKC2,p[J@e5RiEul^,y]urOax1E%=E`UmvT+~85JoEQnNDf.?qmqS-8ta~2.&O0cggC&@dF-[p2?aXGyXCt4JGa@AV+D0em0nuBLU%H!E_eN?vw4HvC^!Ea7MPJT7u!7A{JQ+DHqUpus]Q.knot+=hpz&cqC+=uc&hS^DAl*@B&8=dyHnM9my(}DW?1[?t%r6'6q-577rMV80qb9Aa{Tdt}946_X]RXltV!&@fLL%x7[PPvOys+,~o$B=q@T@[%*N1_`.S3R&3&r?g=Ep-y?gLGI,&4Zqx7p@jGkic[tFkQ9D1FPxprT@Am)3x9P')U&QIn1a7[v@8!lCChi1xprG}XwH7{8Ai`mH6XGcEWOX@%yvgHW=oMveQg'p?tjF3j]Waf'@NSPdPO%{nbF$3O^{LQB?h.B1tsW8,?Q(3Hcb41?@,gztPkXXP(I1bA38]1!@Dr~I-lSg[Rg&!ta?7h{8G^Z@GHmLKUbOxmC!r+i8-78VKS*.j.C(x*rP+3j?,L3Eo'W1n47p2cdN-[cAgibpPWU.k8v9vvmJ~6n8h=O*O+N7Hz4JE}aVx''9D44V)4qRH+(7$f$a8Zh8A'62sYUX-rg&bSE(UF_=-CUN(&Oei9U?Sz3H-K49q~O_YOYJN7Be=(oxnX!@aS[G
  • 0

#33
playsoldier3

playsoldier3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 110 posts
HKLM\S-1-5-21-1841074112-1566241960-291420975-1008\Software\Microsoft\MediaPlayer\Preferences\BackgroundScanCompleteDate 9/22/2006 9:26 PM 36 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed 9/22/2006 9:26 PM 80 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg 5/27/2006 5:29 PM 0 bytes Access is denied.
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\Working\database_53E5_C8EC_1902_80E0\fsr00429.log 9/22/2006 9:37 PM 128.00 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\MessengerCache\1tTP7VEDUKTpAmGicvjdpf2Ftny4= 9/22/2006 10:00 PM 16.64 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\OnlineScanner\Anti-Virus\fsbl7331.sys 9/22/2006 9:26 PM 18.50 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\OnlineScanner\Anti-Virus\fsse7331.dll 9/22/2006 9:26 PM 136.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\CHSD0BG5\rss[1].xml 9/22/2006 9:28 PM 13.38 KB Visible in Windows API, directory index, but not in MFT.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ODYZ45YB\rss[1].xml 9/22/2006 9:28 PM 16.41 KB Visible in Windows API, MFT, but not in directory index.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\PL56NN5E\rss[4].xml 9/22/2006 9:58 PM 13.38 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\VMJFIUA6\rss[1].xml 9/22/2006 9:32 PM 14.51 KB Hidden from Windows API.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\VMJFIUA6\rss[2].xml 9/22/2006 9:22 PM 6.82 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\689DTT4Q\adsense[2].htm 9/22/2006 9:48 PM 4.78 KB Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\689DTT4Q\ln1[1].htm 9/22/2006 8:50 PM 1.31 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\689DTT4Q\ln[1].htm 9/22/2006 9:20 PM 6.94 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\689DTT4Q\s[11].htm 9/22/2006 9:32 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\HS6OXYEK\61[1].htm 9/22/2006 9:15 PM 376 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\HS6OXYEK\63[1].htm 9/22/2006 9:54 PM 376 bytes Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\HS6OXYEK\63[3].htm 9/22/2006 9:11 PM 376 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\HS6OXYEK\63[4].htm 9/22/2006 9:02 PM 376 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\HS6OXYEK\ads[2].htm 9/22/2006 9:45 PM 5.60 KB Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\HS6OXYEK\CAFY8FFP.gif 9/22/2006 9:57 PM 49 bytes Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\HS6OXYEK\CARY47J1.gif 9/22/2006 9:32 PM 35 bytes Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\HS6OXYEK\quote.users.51[1].htm 9/22/2006 9:32 PM 1.72 KB Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\HS6OXYEK\r[8].htm 9/22/2006 7:56 PM 6.33 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\HS6OXYEK\r[9].htm 9/22/2006 9:32 PM 6.33 KB Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\HS6OXYEK\rotate[2].htm 9/22/2006 8:50 PM 263 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\N68JPMD0\63[1].htm 9/22/2006 9:50 PM 376 bytes Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\N68JPMD0\adsense[1].htm 9/22/2006 9:06 PM 4.81 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\N68JPMD0\ln[2].htm 9/22/2006 10:01 PM 6.63 KB Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\N68JPMD0\rotate[1].htm 9/22/2006 9:32 PM 263 bytes Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\N68JPMD0\s[3].htm 9/22/2006 7:15 PM 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\N68JPMD0\track[8].xml 9/22/2006 9:32 PM 162 bytes Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SQPA7Y83\61[1].htm 9/22/2006 9:57 PM 376 bytes Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SQPA7Y83\63[1].htm 9/22/2006 9:13 PM 376 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SQPA7Y83\63[3].htm 9/22/2006 9:43 PM 376 bytes Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SQPA7Y83\ln1[1].htm 9/22/2006 9:32 PM 1.31 KB Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SQPA7Y83\quote.users.51[1].htm 9/22/2006 8:50 PM 1.72 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\Norton AntiVirus\Savrt\0540NAV~.TMP 9/22/2006 9:39 PM 0 bytes Hidden from Windows API.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP268\A0037923.dll 9/22/2006 8:49 PM 439.85 KB Hidden from Windows API.
D: 0 bytes Error mounting volume
  • 0

#34
playsoldier3

playsoldier3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 110 posts
Scanning Report
Friday, September 22, 2006 21:26:08 - 22:43:31

Computer name: YOUR-55E5F9E3D2
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\ D:\
Result: 7 malware found
Packed.Win32.Klone.j (virus)

* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\NORTON ANTIVIRUS\QUARANTINE\0EA52E96.EXE (Submitted)

Possible Browser Hijack attempt (spyware)

* System (Disinfected)

Trojan-Clicker.Win32.BHO.f (virus)

* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\NORTON ANTIVIRUS\QUARANTINE\161C2411.DLL (Submitted)

Trojan-Downloader.Win32.Delf.aku (virus)

* C:\DOCUMENTS AND SETTINGS\HP_ADMINISTRATOR\DOCTORWEB\QUARANTINE\A0030221.EXE (Renamed)

Trojan-Downloader.Win32.VB.ama (virus)

* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\NORTON ANTIVIRUS\QUARANTINE\5AF017B6.EXE (Submitted)

Trojan-Dropper.Win32.Agent.awb (virus)

* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\NORTON ANTIVIRUS\QUARANTINE\39E84BDE.EXE (Submitted)

Trojan-Dropper.Win32.Delf.zg (virus)

* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SYMANTEC\NORTON ANTIVIRUS\QUARANTINE\1BA551F9.EXE (Submitted)

Statistics
Scanned:

* Files: 38197
* System: 7358
* Not scanned: 8

Actions:

* Disinfected: 1
* Renamed: 1
* Deleted: 0
* None: 5
* Submitted: 5

Files not scanned:

* C:\HIBERFIL.SYS
* C:\PAGEFILE.SYS
* C:\WINDOWS\SYSTEM32\DRIVERS\DTSCSI.SYS
* C:\WINDOWS\SYSTEM32\DRIVERS\SPTD.SYS
* C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCRST.DLL
* C:\DOCUMENTS AND SETTINGS\HP_ADMINISTRATOR\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{3A2A5310-D7D0-4840-AEA5-3C09D73D77D5}
* C:\DOCUMENTS AND SETTINGS\ALL USERS\DOCUMENTS\RECORDED TV\TEMPREC\TEMPSBE\MSDVRMM_419594464_2031616_18162

Options
Scanning engines:

* F-Secure AVP: 6.0.171, 2006-09-22
* F-Secure Libra: 2.4.1, 2006-09-22
* F-Secure Blacklight: 1.0.31, 0000-00-00
* F-Secure Orion: 1.2.37, 2006-09-21
* F-Secure Pegasus: 1.19.0, 2006-08-14

Scanning options:

* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX
* Use Advanced heuristics




Logfile of HijackThis v1.99.1
Scan saved at 22:44:49, on 2006-9-22
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\OpenSSL.exe
C:\WINDOWS\system32\inetinfo.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\HP\KBD\KBD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk32.exe
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fssm32.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...arm1=seconduser
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityrespo...er/fix_homepage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.h...arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.h...arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...arm1=seconduser
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HPHUPD08] "c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe"
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPwuSchd2.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE" /P26 "EPSON Stylus CX4600 Series" /O6 "USB001" /M "Stylus CX4600"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] "C:\Program Files\AGEIA Technologies\TrayIcon.exe"
O4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [inetinfo] C:\WINDOWS\system32\inetinfo.exe
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [EPSON Stylus CX4600 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE" /P26 "EPSON Stylus CX4600 Series" /M "Stylus CX4600" /EF "HKCU"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: VeryCD³¬¼¶ËÑË÷ - C:\PROGRA~1\YOK.com\SUPERS~1\yoksch.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec....trl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec....trl/tgctlsr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.s...rl/LSSupCtl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1156487740671
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-sec.../ols3/fscax.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
  • 0

#35
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Hi, playsoldier3 :whistling:

Lets try to remove the registry entries throughout a registry scipt, then delete the offending file. If that fails, then we will need to be more agressive.:

The steps that I am about to suggest involve modifying the registry. Modifying the registry can be dangerous so we will make a backup of the registry first.
Modification of the registry can be EXTREMELY dangerous if you do not know exactly what you are doing so follow the steps that are listed below EXACTLY. if you cannot preform some of these steps or if you have ANY questions please ask BEFORE proceeding.

Backing Up Your Registry
  • Go Here and download ERUNT
    (ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
  • Install ERUNT by following the prompts
    (use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
  • Start ERUNT
    (either by double clicking on the desktop icon or choosing to start the program at the end of the setup)
  • Choose a location for the backup
    (the default location is C:\WINDOWS\ERDNT which is acceptable).
  • Make sure that at least the first two check boxes are ticked
  • Press OK
  • Press YES to create the folder.
Registry Modifications

Download the enclosed file:
Save and extract its contents to the desktop. It is a folder containing a Registry Entries file, Regfix.reg . Once extracted, open the folder and double click on the Regfix.reg file and select Yes when prompted to merge it into the registry.

Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to Delete:
C:\WINDOWS\system32\inetinfo.exe

Folders to delete:
C:\Program Files\CNNIC\Cdn
C:\Program Files\CNNIC


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
Please copy/paste the content of c:\avenger.txt into your reply along with a fresh Hijackthis log .

If you see that the entries remain, please provide me with the following:

Create a Startup List
  • Open HiJackThis
  • Click on the "Config..." button on the bottom right
  • Click on the tab "Misc Tools"
  • Check off the 2 boxes next to the Box that says "Generate StartupList log"
  • Click on the button "Generate StartupList log"
  • Copy and past the StartupList from the notepad into your next post

Download the enclosed file:
Save and extract its contents to the desktop. It is a folder containing a Batch file, DatFind.bat . Once extracted, open the folder and double click on the DatFind.bat file varius documents will be produced. Please post the contents of these documents in your next reply.
  • 0

#36
playsoldier3

playsoldier3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 110 posts
it doesnt seem to ask me about installing start-up folder...
  • 0

#37
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Hi, playsoldier3 :blink:

it doesnt seem to ask me about installing start-up folder...



Can you expand on this? :whistling:
  • 0

#38
playsoldier3

playsoldier3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 110 posts
when i try to install the program, it doesnt ask me to install start up folder like yo usaid, it just install ap, it says next ,next and stuff, and where to install, but doesnt ask me to install start up folder or not
  • 0

#39
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Hi, playsoldier3 :whistling:

Ah! You are referring to ERUNT. Just follow the prompts and install the application as it comes.
  • 0

#40
playsoldier3

playsoldier3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 110 posts
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\djoxlydd

*******************

Script file located at: rugxjrbm

Could not open script file! Error

Could not open script file! Status: 0xc000003b Abort!




Logfile of HijackThis v1.99.1
Scan saved at 14:22:09, on 2006-9-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\arservice.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\inetinfo.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\OpenSSL.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
c:\windows\system\hpsysdrv.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...arm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...arm1=seconduser
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityrespo...er/fix_homepage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.h...arm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.h...arm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...arm1=seconduser
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HPHUPD08] "c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe"
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPwuSchd2.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE" /P26 "EPSON Stylus CX4600 Series" /O6 "USB001" /M "Stylus CX4600"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] "C:\Program Files\AGEIA Technologies\TrayIcon.exe"
O4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [inetinfo] C:\WINDOWS\system32\inetinfo.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [CdnCtr] C:\Program Files\CNNIC\Cdn\cdnup.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [EPSON Stylus CX4600 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE" /P26 "EPSON Stylus CX4600 Series" /M "Stylus CX4600" /EF "HKCU"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: VeryCD³¬¼¶ËÑË÷ - C:\PROGRA~1\YOK.com\SUPERS~1\yoksch.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec....trl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec....trl/tgctlsr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.s...rl/LSSupCtl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1156487740671
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-sec.../ols3/fscax.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe






StartupList report, 2006-9-23, 14:23:36
StartupList version: 1.52.2
Started from : C:\HJT\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\arservice.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\inetinfo.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\OpenSSL.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\svchost.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
c:\windows\system\hpsysdrv.exe
C:\HJT\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup]
*No files*

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\SYSTEM32\Userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ehTray = C:\WINDOWS\ehome\ehtray.exe
AlwaysReady Power Message APP = ARPWRMSG.EXE
RTHDCPL = RTHDCPL.EXE
HPHUPD08 = "c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe"
PCDrProfiler =
HPBootOp = "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
LSBWatcher = c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
HP Software Update = "C:\Program Files\HP\HP Software Update\HPwuSchd2.exe"
EPSON Stylus CX4600 Series = "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE" /P26 "EPSON Stylus CX4600 Series" /O6 "USB001" /M "Stylus CX4600"
SunJavaUpdateSched = "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
ATICCC = "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
DAEMON Tools = "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
AGEIA PhysX SysTray = "C:\Program Files\AGEIA Technologies\TrayIcon.exe"
MSPY2002 = "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNC
PHIME2002A = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
PHIME2002ASync = "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
Windows Defender = "C:\Program Files\Windows Defender\MSASCui.exe" -hide
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
inetinfo = C:\WINDOWS\system32\inetinfo.exe
SpySweeper = "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
CdnCtr = C:\Program Files\CNNIC\Cdn\cdnup.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
MsnMsgr = "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
EPSON Stylus CX4600 Series = "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE" /P26 "EPSON Stylus CX4600 Series" /M "Stylus CX4600" /EF "HKCU"

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
*No values found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

--------------------------------------------------

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\system32\mshta.exe "%1" %*

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[KB910393] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\EasyCDBlock.inf,PerUserInstall

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{407408d4-94ed-4d86-ab69-a7f649d112ee}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection QuickLaunchShortcut 640 %systemroot%\inf\mcdftreg.inf

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{4b218e3e-bc98-4770-93d3-2731b9329278}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf

[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install

[{8b15971b-5355-4c82-8c07-7e181ea07608}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser

--------------------------------------------------

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

--------------------------------------------------

Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6}
NAV Helper - C:\Program Files\Norton AntiVirus\NavShExt.dll - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD}

--------------------------------------------------

Enumerating Task Scheduler jobs:

MP Scheduled Scan.job
Norton AntiVirus - Run Full System Scan - HP_Administrator.job
wrSpySweeper20060316203855.job

--------------------------------------------------

Enumerating Download Program Files:

[SupportSoft SmartIssue]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\tgctlsi.dll
CODEBASE = http://www.symantec....trl/tgctlsi.cab

[SupportSoft Script Runner Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\tgctlsr.dll
CODEBASE = http://www.symantec....trl/tgctlsr.cab

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll
CODEBASE = http://go.microsoft....k/?linkid=39204

[LSSupCtl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\LSSupCtl.dll
CODEBASE = https://www-secure.s...rl/LSSupCtl.cab

[Minesweeper Flags Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\minesweeper.dll
CODEBASE = http://messenger.zon...er.cab31267.cab

[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://update.micros...b?1156487740671

[WScanCtl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\webscan.dll
CODEBASE = http://www3.ca.com/s...nfo/webscan.cab

[Java Plug-in 1.5.0_08]
InProcServer32 = C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[MessengerStatsClient Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll
CODEBASE = http://messenger.zon...nt.cab31267.cab

[ActiveScan Installer Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\asinst.dll
CODEBASE = http://acs.pandasoft...free/asinst.cab

[F-Secure Online Scanner 3.0]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\fscax.dll
CODEBASE = http://support.f-sec.../ols3/fscax.cab

[MsnMessengerSetupDownloadControl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx
CODEBASE = http://messenger.msn...pDownloader.cab

[Java Plug-in]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[Java Plug-in 1.5.0_08]
InProcServer32 = C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[Java Plug-in 1.5.0_08]
InProcServer32 = C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
CODEBASE = http://java.sun.com/...indows-i586.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx
CODEBASE = http://download.macr...ash/swflash.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
NameSpace #4: C:\WINDOWS\System32\nwprovau.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll
Protocol #12: C:\WINDOWS\system32\mswsock.dll
Protocol #13: C:\WINDOWS\system32\mswsock.dll
Protocol #14: C:\WINDOWS\system32\mswsock.dll
Protocol #15: C:\WINDOWS\system32\mswsock.dll
Protocol #16: C:\WINDOWS\system32\mswsock.dll
Protocol #17: C:\WINDOWS\system32\mswsock.dll
Protocol #18: C:\WINDOWS\system32\mswsock.dll
Protocol #19: C:\WINDOWS\system32\mswsock.dll
Protocol #20: C:\WINDOWS\system32\mswsock.dll
Protocol #21: C:\WINDOWS\system32\mswsock.dll
Protocol #22: C:\WINDOWS\system32\mswsock.dll
Protocol #23: C:\WINDOWS\system32\mswsock.dll
Protocol #24: C:\WINDOWS\system32\mswsock.dll

--------------------------------------------------

Enumerating Windows NT/2000/XP services

Microsoft ACPI Driver: system32\DRIVERS\ACPI.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD: \SystemRoot\System32\drivers\afd.sys (system)
Agere Systems Soft Modem: system32\DRIVERS\AGRSM.sys (manual start)
Alerter: %SystemRoot%\system32\svchost.exe -k LocalService (disabled)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
aracpi: system32\DRIVERS\aracpi.sys (manual start)
MS Ar HID Filter Driver: system32\DRIVERS\arhidfltr.sys (manual start)
Microsoft PS2 Keyboard Filter: system32\DRIVERS\arkbcfltr.sys (manual start)
Microsoft PS2 Mouse Filter: system32\DRIVERS\armoucfltr.sys (manual start)
1394 ARP Client Protocol: system32\DRIVERS\arp1394.sys (manual start)
ARPolicy: system32\DRIVERS\arpolicy.sys (manual start)
ARSVC: C:\WINDOWS\arservice.exe (autostart)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: system32\DRIVERS\atapi.sys (system)
Ati HotKey Poller: %SystemRoot%\system32\Ati2evxx.exe (autostart)
ATI Smart: C:\WINDOWS\system32\ati2sgag.exe (autostart)
ati2mtag: system32\DRIVERS\ati2mtag.sys (manual start)
ATM ARP Client Protocol: system32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: system32\DRIVERS\audstub.sys (manual start)
Automatic LiveUpdate Scheduler: "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" (autostart)
Promise driver accelerator: system32\DRIVERS\bb-run.sys (system)
Background Intelligent Transfer Service: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Computer Browser: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Closed Caption Decoder: system32\DRIVERS\CCDECODE.sys (manual start)
Symantec Event Manager: "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" (autostart)
Symantec Settings Manager: "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" (autostart)
CD-ROM Driver: system32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisvc.exe (manual start)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
COM+ System Application: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DHCP Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Disk Driver: system32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
Logical Disk Manager Driver: System32\drivers\dmio.sys (system)
dmload: System32\drivers\dmload.sys (system)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
dtscsi: \SystemRoot\System32\Drivers\dtscsi.sys (manual start)
Intel® PRO Network Connection Driver: system32\DRIVERS\e100b325.sys (manual start)
Symantec Eraser Control driver: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (system)
Media Center Receiver Service: C:\WINDOWS\eHome\ehRecvr.exe (autostart)
Media Center Scheduler Service: C:\WINDOWS\eHome\ehSched.exe (autostart)
EraserUtilRebootDrv: \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINDOWS\system32\svchost.exe -k netsvcs (manual start)
ewido anti-spyware 4.0 driver: \??\C:\Program Files\ewido anti-spyware 4.0\guard.sys (system)
ewido anti-spyware 4.0 guard: C:\Program Files\ewido anti-spyware 4.0\guard.exe (autostart)
fasttx2k: system32\DRIVERS\fasttx2k.sys (system)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Fax: %systemroot%\system32\fxssvc.exe (manual start)
Floppy Disk Controller Driver: system32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: system32\DRIVERS\flpydisk.sys (manual start)
FltMgr: system32\DRIVERS\fltMgr.sys (system)
Volume Manager Driver: system32\DRIVERS\ftdisk.sys (system)
ftsata2: system32\DRIVERS\ftsata2.sys (system)
GEAR CDRom Filter: SYSTEM32\DRIVERS\GEARAspiWDM.sys (manual start)
Generic Packet Classifier: system32\DRIVERS\msgpc.sys (manual start)
Hauppauge WinTV PVR PCI II ([23|25|26]xxx): system32\DRIVERS\hcwPP2.sys (manual start)
Microsoft UAA Bus Driver for High Definition Audio: system32\DRIVERS\HDAudBus.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Microsoft Infrared HID Driver: system32\DRIVERS\hidir.sys (manual start)
HID Input Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i8042 Keyboard and PS/2 Mouse Port Driver: system32\DRIVERS\i8042prt.sys (system)
InstallDriver Table Manager: "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" (manual start)
CD-Burning Filter Driver: system32\DRIVERS\imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINDOWS\system32\imapi.exe (manual start)
Service for Realtek HD Audio (WDM): system32\drivers\RtkHDAud.sys (manual start)
IntelIde: system32\DRIVERS\intelide.sys (system)
Intel Processor Driver: system32\DRIVERS\intelppm.sys (system)
IPv6 Windows Firewall Driver: system32\DRIVERS\Ip6Fw.sys (manual start)
IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: system32\DRIVERS\ipnat.sys (manual start)
iPod Service: "C:\Program Files\iPod\bin\iPodService.exe" (manual start)
IPSEC driver: system32\DRIVERS\ipsec.sys (system)
Infrared bus filter driver for eHome remote controls: system32\DRIVERS\IrBus.sys (manual start)
IR Enumerator Service: system32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: system32\DRIVERS\isapnp.sys (system)
Keyboard Class Driver: system32\DRIVERS\kbdclass.sys (system)
Keyboard HID Driver: system32\DRIVERS\kbdhid.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Server: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
LightScribeService Direct Disc Labeling Service: "C:\Program Files\Common Files\LightScribe\LSSrvc.exe" (autostart)
LiveUpdate: "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE" (manual start)
TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Media Center Extender Service: C:\WINDOWS\ehome\mcrdsvc.exe (autostart)
Machine Debug Manager: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" (autostart)
Messenger: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
MHN: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
MHN driver: system32\DRIVERS\mhndrv.sys (manual start)
NetMeeting Remote Desktop Sharing: C:\WINDOWS\system32\mnmsrvc.exe (manual start)
Mouse Class Driver: system32\DRIVERS\mouclass.sys (system)
Mouse HID Driver: system32\DRIVERS\mouhid.sys (manual start)
WebDav Client Redirector: system32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: system32\DRIVERS\mrxsmb.sys (system)
Distributed Transaction Coordinator: C:\WINDOWS\system32\msdtc.exe (manual start)
Windows Installer: C:\WINDOWS\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: system32\DRIVERS\mssmbios.sys (manual start)
Microsoft Streaming Tee/Sink-to-Sink Converter: system32\drivers\MSTEE.sys (manual start)
NABTS/FEC VBI Codec: system32\DRIVERS\NABTSFEC.sys (manual start)
Norton AntiVirus Auto-Protect Service: "C:\Program Files\Norton AntiVirus\navapsvc.exe" (autostart)
NAVENG: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060922.018\NAVENG.Sys (manual start)
NAVEX15: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060922.018\NavEx15.Sys (manual start)
Microsoft TV/Video Connection: system32\DRIVERS\NdisIP.sys (manual start)
Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: system32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: system32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: system32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\system32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Net MD: System32\Drivers\NETMDUSB.sys (manual start)
1394 Net Driver: system32\DRIVERS\nic1394.sys (manual start)
Network Location Awareness (NLA): %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Norton AntiVirus Firewall Monitor Service: "C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe" (autostart)
NPPTNT2: \??\C:\WINDOWS\system32\npptNT2.sys (system)
Norton Protection Center Service: "C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE" (manual start)
NT LM Security Support Provider: %SystemRoot%\system32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
Client Service for NetWare: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.sys (manual start)
NWLink IPX/SPX/NetBIOS Compatible Transport Protocol: system32\DRIVERS\nwlnkipx.sys (autostart)
NWLink NetBIOS: system32\DRIVERS\nwlnknb.sys (autostart)
NWLink SPX/SPXII Protocol: system32\DRIVERS\nwlnkspx.sys (autostart)
NetWare Rdr: system32\DRIVERS\nwrdr.sys (manual start)
VIA OHCI Compliant IEEE 1394 Host Controller: system32\DRIVERS\ohci1394.sys (system)
Office Source Engine: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" (manual start)
Creative WebCam NX Ultra: system32\DRIVERS\P1120Vid.sys (manual start)
Parallel port driver: system32\DRIVERS\parport.sys (manual start)
PCI Bus Driver: system32\DRIVERS\pci.sys (system)
PCIIde: system32\DRIVERS\pciide.sys (system)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
Pml Driver HPZ12: C:\WINDOWS\system32\HPZipm12.exe (system)
IPSEC Services: %SystemRoot%\system32\lsass.exe (autostart)
WAN Miniport (PPTP): system32\DRIVERS\raspptp.sys (manual start)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
PS2: system32\DRIVERS\PS2.sys (manual start)
QoS Packet Scheduler: system32\DRIVERS\psched.sys (manual start)
Direct Parallel Link Driver: system32\DRIVERS\ptilink.sys (manual start)
PxHelp20: System32\Drivers\PxHelp20.sys (system)
Remote Access Auto Connection Driver: system32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: system32\DRIVERS\raspti.sys (manual start)
Rdbss: system32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Terminal Server Device Redirector Driver: system32\DRIVERS\rdpdr.sys (manual start)
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: system32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
Remote Registry: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Remote Procedure Call (RPC) Locator: %SystemRoot%\system32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\system32\rsvp.exe (manual start)
Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver: system32\DRIVERS\RTL8139.SYS (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
SAVRT: \??\C:\Program Files\Norton AntiVirus\SAVRT.SYS (system)
SAVRTPEL: \??\C:\Program Files\Norton AntiVirus\SAVRTPEL.SYS (system)
Symantec AVScan: "C:\Program Files\Norton Ant
  • 0

Advertisements


#41
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Hi, playsoldier3 :whistling:

Run the DatFind.bat file and post its results.
  • 0

#42
playsoldier3

playsoldier3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 110 posts
what is datfind?
  • 0

#43
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Hi, playsoldier3 :whistling:

It is at the botton of post #35.
  • 0

#44
playsoldier3

playsoldier3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 110 posts
Volume in drive C is HP_PAVILION
Volume Serial Number is 1902-80E0

Directory of C:\

2006-09-23 16:59 0 CdnFiles.txt
2006-09-23 14:18 1,072,152,576 hiberfil.sys
2006-09-23 14:18 1,610,612,736 pagefile.sys
2006-09-23 14:17 588 avenger.txt
2006-08-26 22:14 171,357 resolve.log
2006-08-21 07:08 244 sqmnoopt00.sqm
2006-05-12 08:09 3,893 log.txt
2006-03-02 22:30 170 threatalerts.txt
2005-12-10 22:13 24,455 CtDrvStp.log
2005-12-10 22:13 326 CtDrvIns.log
2005-12-09 22:51 281 boot.ini
2005-12-09 22:46 211 BOOT.BAK
2005-10-31 08:56 700,416 StubInstaller.exe
2005-10-18 09:10 100 AUTOEXEC.BAT
2005-01-28 03:41 0 CONFIG.SYS
2005-01-28 03:41 0 MSDOS.SYS
2005-01-28 03:41 0 IO.SYS
2004-08-09 22:00 260,272 cmldr
2004-08-09 22:00 47,564 NTDETECT.COM
2004-08-09 22:00 250,032 ntldr
20 File(s) 2,684,225,221 bytes
0 Dir(s) 199,302,754,304 bytes free
  • 0

#45
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Hi, playsoldier3 :whistling:

There should be six (6) reports.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP