Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Safe Mode Shuts Down When Running a AntiVirus


  • This topic is locked This topic is locked

#1
EGCoopey

EGCoopey

    New Member

  • Member
  • Pip
  • 2 posts
So I have Adaware, Spybot, and MBAM all running. MBAM eventually gets a Error 2 code in Normal Mode. All the other AntiVirus progs come back with nothing. My search results are re-directed. I fixed it in a Mozilla file and then 2 days later it comes back.

Then I try to run in Safe Mode to get my Antivirus Progs to see about detecting anything, Nothing comes back or the computer while in safe mode suddenly shuts off. Sometimes I can get into safe mode for a few minutes, sometimes it will just shut off immediately.

I am out of ideas.

Here is my HJT log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:07:01 PM, on 3/21/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Windows\PLFSetI.exe
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe
C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\Cyberlink\Power2Go\CLMLSvc.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
C:\Users\Kellie\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gate...50z1l5a48l1x28p
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {66bd2442-241b-44cd-8c7a-b51037053cdb} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O2 - BHO: ooVoo Toolbar - {59c6f12b-f004-43e5-9997-08f2123119b6} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: TBSB05974 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - (no file)
O3 - Toolbar: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - (no file)
O3 - Toolbar: FrostWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O3 - Toolbar: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O3 - Toolbar: ooVoo Toolbar - {59c6f12b-f004-43e5-9997-08f2123119b6} - (no file)
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe" -h -k
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [VideoWebCamera] "C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe" -a
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [CLMLServer] "c:\Program Files (x86)\Cyberlink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [LvelZkfgnZh.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+
O4 - HKLM\..\Run: [LvelZkfgoMc] C:\Users\Kellie\AppData\Local\Temp\gdi32.exe
O4 - HKLM\..\Run: [LvelZkfgspe] C:\Users\Kellie\AppData\Local\Temp\winamp.exe
O4 - HKLM\..\Run: [LvelZkfgnZ] C:\Users\Kellie\AppData\Local\Temp\cmd.exe
O4 - HKLM\..\Run: [LvelZkfgrxe] C:\Users\Kellie\AppData\Local\Temp\system.exe
O4 - HKLM\..\Run: [LvelZkfgsPc] C:\Users\Kellie\AppData\Local\Temp\win16.exe
O4 - HKLM\..\Run: [LvelZkfgouqc] C:\Users\Kellie\AppData\Local\Temp\iexplarer.exe
O4 - HKLM\..\Run: [LvelZkfgnsc] C:\Users\Kellie\AppData\Local\Temp\drweb.exe
O4 - HKLM\..\Run: [LvelZkfgnsc (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1] C:\Users\Kellie\AppData\Local\Temp\drweb.exe
O4 - HKLM\..\Run: [LvelZkfgrxe (Windows; U; Windows NT 6.0; en-US; rv:1.9.1.1) Gecko/20090715 Firefox/3.5.1] C:\Users\Kellie\AppData\Local\Temp\system.exe
O4 - HKLM\..\Run: [LvelZkfgnscft.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM
O4 - HKLM\..\Run: [LvelZkfgrxenfo&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+q
O4 - HKLM\..\Run: [LvelZkfgsPc.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+
O4 - HKLM\..\Run: [LvelZkfgsPcft.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM
O4 - HKLM\..\Run: [LvelZkfgrxee.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [iSafeCW] C:\Users\Kellie\AppData\Local\PokerStars.NET\Keylogger\winsrv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [LvelZkfgnscft.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM
O4 - HKCU\..\Run: [LvelZkfgrxenfo&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+q
O4 - HKCU\..\Run: [LvelZkfgsPc.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+
O4 - HKCU\..\Run: [LvelZkfgsPcft.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM
O4 - HKCU\..\Run: [LvelZkfgrxee.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/
O4 - HKCU\..\Run: [conhost] C:\Users\Kellie\AppData\Roaming\Microsoft\conhost.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: &Search - ?p=ZNxmk788YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebo...oUploader55.cab
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - http://lads.myspace....ceUploader2.cab
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} - http://trial.trymicr...osoft/wrc32.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{98DD262E-26DB-46ED-84E2-8A212BBF110F}: NameServer = 209.18.47.61,209.18.47.62
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
O23 - Service: Google Update Service (gupdate1ca9165c94bc243) (gupdate1ca9165c94bc243) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: KMService - Unknown owner - C:\Windows\system32\srvany.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 24582 bytes


Any help would be greatly appreciated.

Thanks!
  • 0

Advertisements


#2
Render

Render

    Trusted Helper

  • Malware Removal
  • 4,195 posts
Hi, EGCoopey! Welcome to GeeksToGo! My nick name is Render and I will be assisting you with your Malware/Security problems. Please make sure you read all of the instructions and fixes thoroughly before continuing with them. If you have any queries or you are unsure about anything, just say and I'll help you out :D

It may well be worth you printing/saving the instructions throughout the fix, so you have them to hand just in case you are unable to access this site.

Please note:

  • I am currently in training, so my replies will need to be quickly checked before I post them to you, so there may be a small delay in between.
  • Remember to post your logs, not attach them. So, any logs from any programs we run, should be just 'copied & pasted' into your reply.
  • Please only run the tools that I request. I know malware can be frustrating but running other tools in the meantime and between posts, only makes it harder for us to analyze and fix your PC in the long run.

Sorry for the delay. I will be back soon.
  • 0

#3
Render

Render

    Trusted Helper

  • Malware Removal
  • 4,195 posts
Hi,

For many modern infections HijackThis no longer provides enough information for a complete removal. This is mainly due to the fact that the development of HijackThis stagnated for a long time while malware continued to develop. Malware writers, recognizing the widespread use of HijackThis, specifically wrote their malicious software so that signs would not show up in a HijackThis log. While we still can and sometimes do use HijackThis for malware removal purposes here, for the reasoning above it is no longer our primary tool for malware detection and removal.

PLAN A (If you can boot and work into normal mode)

Step 1

Posted Image OTL Default Scan

  • Download OTL to your desktop.
  • Double click on the Posted Image icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top, make sure Stadard output is selected.
  • Under the Extra Registry section, check Use SafeList
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
  • Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic

Step 2

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it
Posted Image

Click the "Scan" button to start scan
Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply


PLAN B (If you cannot boot into normal mode). You will need another clean Windows based computer with CD/DVD burner, blank CD-R and USB memory stick.


  • On other computer:
  • Download OTLPEStd.exe to your desktop
  • Ensure that you have a blank CD in the drive
  • Double click OTLPEStd.exe and this will then open imgburn to burn the file to CD

    On the infected computer:
  • Reboot your system using the boot CD you just created.
    Note : If you do not know how to set your computer to boot from CD follow the steps here
  • As the CD needs to detect your hardware and load the operating system, I would recommend a nice cup of tea whilst it loads :D
  • Your system should now display a Reatogo desktop.
    Note : as you are running from CD it is not exactly speedy
  • Double-click on the OTLPE icon.
  • Select the Windows folder of the infected drive if it asks for a location
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start.
  • Drag and drop this attached scan.txt into the Custom scans and fixes box
  • Press Run Scan to start the scan.
  • When finished, the file will be saved in drive C:\OTL.txt
  • Copy this file to your USB drive if you do not have internet connection on this system.
  • Right click the file and select send to : select the USB drive.
  • Confirm that it has copied to the USB drive by selecting it
  • You can backup any files that you wish from this OS
  • Please post the contents of the C:\OTL.txt file in your reply from your another computer.

  • 0

#4
EGCoopey

EGCoopey

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts

OTL.txt
OTL logfile created on: 3/23/2011 7:47:43 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Kellie\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 54.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.27 Gb Total Space | 102.95 Gb Free Space | 35.96% Space Free | Partition Type: NTFS
Drive D: | 1.85 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: KELLIESPC | User Name: Kellie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/03/23 19:46:30 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Kellie\Downloads\OTL.exe
PRC - [2011/03/08 12:25:04 | 001,405,384 | ---- | M] (Lavasoft Limited) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2011/03/03 14:16:33 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/02/08 08:55:04 | 000,939,848 | ---- | M] (Lavasoft Limited) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010/12/08 16:03:43 | 000,395,128 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2009/11/01 19:39:48 | 001,094,736 | ---- | M] (Dritek System Inc.) -- C:\Program Files (x86)\Launch Manager\LManager.exe
PRC - [2009/09/24 18:42:34 | 000,244,480 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe
PRC - [2009/09/24 18:42:28 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) -- C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe
PRC - [2009/08/31 18:58:34 | 001,511,544 | ---- | M] (Suyin) -- C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe
PRC - [2009/08/28 05:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe
PRC - [2009/08/12 20:20:00 | 000,200,704 | ---- | M] () -- C:\Windows\PLFSetI.exe
PRC - [2009/07/03 21:47:12 | 000,240,160 | ---- | M] (Acer) -- C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
PRC - [2009/06/04 00:59:02 | 000,103,720 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Cyberlink\Power2Go\CLMLSvc.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2009/01/08 10:36:42 | 002,521,464 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe


========== Modules (SafeList) ==========

MOD - [2011/03/23 19:46:30 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Kellie\Downloads\OTL.exe
MOD - [2010/12/21 01:34:12 | 000,080,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\davclnt.dll
MOD - [2010/08/21 01:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
MOD - [2009/07/13 21:16:19 | 000,156,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winsta.dll
MOD - [2009/07/13 21:16:11 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\ntlanman.dll
MOD - [2009/07/13 21:15:48 | 000,035,328 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\mssprxy.dll
MOD - [2009/07/13 21:15:27 | 000,009,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\IconCodecService.dll
MOD - [2009/07/13 21:15:13 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\drprov.dll
MOD - [2009/07/13 21:15:08 | 000,019,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\davhlpr.dll
MOD - [2008/08/14 08:14:14 | 000,079,240 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/10/29 11:13:34 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2009/09/30 18:44:58 | 000,844,320 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe -- (ePowerSvc)
SRV:64bit: - [2009/07/30 03:03:42 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/03 21:47:12 | 000,240,160 | ---- | M] (Acer) [Auto | Running] -- C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe -- (Updater Service)
SRV - [2011/03/08 12:25:04 | 001,405,384 | ---- | M] (Lavasoft Limited) [Auto | Running] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/10/29 11:13:22 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/09/24 18:42:28 | 000,062,720 | ---- | M] (NewTech Infosystems, Inc.) [Auto | Running] -- C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe -- (NTI IScheduleSvc)
SRV - [2009/08/28 05:38:58 | 001,150,496 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe -- (Greg_Service)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/05/22 14:02:20 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/04/29 15:21:18 | 000,436,736 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\XAudio64.dll -- (HsfXAudioService)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2003/04/18 20:06:26 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\srvany.exe -- (KMService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2010/12/20 19:08:40 | 000,024,152 | ---- | M] (Malwarebytes Corporation) [File_System | Disabled | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2010/12/03 05:05:34 | 000,069,152 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\Lbd.sys -- (Lbd)
DRV:64bit: - [2009/09/21 15:00:44 | 001,537,024 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009/09/18 00:12:06 | 000,292,912 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009/09/02 13:58:08 | 000,225,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2009/08/11 16:59:50 | 000,686,080 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CHDRT64.sys -- (CnxtHdAudService)
DRV:64bit: - [2009/07/30 13:11:24 | 006,038,016 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009/07/24 06:49:00 | 000,119,312 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/20 07:35:00 | 000,317,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink ™
DRV:64bit: - [2009/06/19 22:09:57 | 000,054,272 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\L1E62x64.sys -- (L1E) NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller(NDIS6.20)
DRV:64bit: - [2009/06/10 17:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009/06/10 17:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009/06/10 17:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 16:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/06/10 16:35:35 | 000,620,544 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2009/06/10 16:34:38 | 001,311,232 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/05 19:46:08 | 000,018,432 | ---- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NTIDrvr.sys -- (NTIDrvr)
DRV:64bit: - [2009/05/05 19:46:08 | 000,016,896 | ---- | M] (NewTech Infosystems Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UBHelper.sys -- (UBHelper)
DRV:64bit: - [2009/05/05 04:30:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2009/04/29 15:21:08 | 000,010,240 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\XAudio64.sys -- (XAudio)
DRV:64bit: - [2009/04/28 13:03:42 | 000,067,128 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/04/28 13:03:42 | 000,028,216 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/04/03 10:39:58 | 000,034,872 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2009/02/13 02:24:56 | 001,485,824 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CAX_DPV.sys -- (HSF_DPV)
DRV:64bit: - [2009/02/13 02:20:56 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CAXHWAZL.sys -- (CAXHWAZL)
DRV:64bit: - [2009/02/13 02:19:34 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CAX_CNXT.sys -- (winachsf)
DRV:64bit: - [2006/06/18 10:27:24 | 000,017,024 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\mdmxsdk.sys -- (mdmxsdk)
DRV - [2011/02/04 10:27:14 | 000,017,152 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys -- (Lavasoft Kernexplorer)
DRV - [2009/09/02 13:58:08 | 000,225,280 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2008/08/14 07:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysWow64\drivers\adfs.sys -- (adfs)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gate...50z1l5a48l1x28p
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.gate...50z1l5a48l1x28p
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.gate...50z1l5a48l1x28p
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {66bd2442-241b-44cd-8c7a-b51037053cdb} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "yahoo.com"
FF - prefs.js..extensions.enabledItems: [email protected]:1.6.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.3
FF - prefs.js..extensions.enabledItems: [email protected]:0.6.5
FF - prefs.js..extensions.enabledItems: {66bd2442-241b-44cd-8c7a-b51037053cdb}:3.2.1.3
FF - prefs.js..extensions.enabledItems: {6FF4E2E4-FB2E-4f50-8F65-CFF2777413D5}:2.3
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.1
FF - prefs.js..extensions.enabledItems: {c4dc572a-3295-40eb-b30f-b54aa4cdc4b7}:0.7.25
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: {E4091D66-127C-11DB-903A-DE80D2EFDFE8}:1.6.5
FF - prefs.js..extensions.enabledItems: {2ACE50BC-0F8A-4381-93FF-C458E8CE378B}:1.9.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://www.bing.com/...form=ZGAADF&q="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 58869
FF - prefs.js..network.proxy.no_proxies_on: ""
FF - prefs.js..network.proxy.type: 0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/03/13 21:52:14 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/03/13 21:52:12 | 000,000,000 | ---D | M]

[2010/09/11 21:00:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kellie\AppData\Roaming\Mozilla\Extensions
[2010/09/11 21:00:39 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kellie\AppData\Roaming\Mozilla\Extensions\[email protected]
[2011/03/22 23:07:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\ua5789n0.default\extensions
[2010/12/28 19:56:22 | 000,000,000 | ---D | M] (TVersitybar Community Toolbar) -- C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\ua5789n0.default\extensions\{66bd2442-241b-44cd-8c7a-b51037053cdb}
[2011/02/22 20:07:35 | 000,000,000 | ---D | M] (Opanda IExif) -- C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\ua5789n0.default\extensions\{6FF4E2E4-FB2E-4f50-8F65-CFF2777413D5}
[2010/12/18 14:29:27 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\ua5789n0.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/11/15 21:48:24 | 000,000,000 | ---D | M] (wmlbrowser) -- C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\ua5789n0.default\extensions\{c4dc572a-3295-40eb-b30f-b54aa4cdc4b7}
[2010/11/09 22:37:44 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\ua5789n0.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2011/03/01 15:42:15 | 000,000,000 | ---D | M] ("ImageHost Grabber") -- C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\ua5789n0.default\extensions\{E4091D66-127C-11DB-903A-DE80D2EFDFE8}
[2010/11/15 21:53:41 | 000,000,000 | ---D | M] (User Agent Switcher) -- C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\ua5789n0.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2011/03/10 00:55:36 | 000,000,000 | ---D | M] (Firebug) -- C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\ua5789n0.default\extensions\[email protected]
[2011/01/31 13:08:00 | 000,000,000 | ---D | M] ("urn:mozilla:install-manifest" em:creator="Matthew David Kesack" em:description="Upload images from the web directly to your Photobucket account." em:homepageURL="http://www.photobucket.com/" em:iconURL="chrome://photobucket/content/images/pb-logo.png" em:id="[email protected]" em:name="Photobucket Uploader" em:version="1.3">) -- C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\ua5789n0.default\extensions\[email protected]
[2010/11/13 11:46:53 | 000,000,000 | ---D | M] (SQLite Manager) -- C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\ua5789n0.default\extensions\[email protected]
[2010/11/07 15:51:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kellie\AppData\Roaming\Mozilla\Firefox\Profiles\ua5789n0.default\extensions\[email protected]
[2011/03/13 21:52:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/03/13 20:59:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2011/03/13 21:12:21 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/09/21 23:54:29 | 000,000,000 | ---D | M] (XULRunner) -- C:\USERS\KELLIE\APPDATA\LOCAL\{2ACE50BC-0F8A-4381-93FF-C458E8CE378B}
[2011/02/02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2011/01/28 04:38:46 | 000,425,881 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.123fporn.info
O1 - Hosts: 14693 more lines...
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll (Google Inc.)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {59c6f12b-f004-43e5-9997-08f2123119b6} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O2 - BHO: (no name) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {59c6f12b-f004-43e5-9997-08f2123119b6} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe (Acer Incorporated)
O4:64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:64bit: - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BackupManagerTray] C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\BackupManagerTray.exe (NewTech Infosystems, Inc.)
O4 - HKLM..\Run: [CLMLServer] c:\Program Files (x86)\Cyberlink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [iSafeCW] File not found
O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [LvelZkfgnsc] File not found
O4 - HKLM..\Run: [LvelZkfgnsc (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1] File not found
O4 - HKLM..\Run: [LvelZkfgnscft.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+qZv+qmf+qzP+q///VAP/VM//V
Zv/Vmf/VzP/V////AP//M///Zv//mf//zP///wAAAAAAAAAAAAAAACH5BAEAAPwALAAAAADIADwA
AAj/APcJHEiwoMGDCBMqXMiwocOHECNKhKhsYsRJaDJZ3Mixo0ePaCRWFFixHrSPDeuhETMpk5iQ
+0YOlBlzJsqbH2lufBlj5SSMBevtO2myKE1o9WjqxKlQTCaMMG0SOyj0pE2mFpemJKpV4A0xYMO+
ZDmJIExlFbsaFMpUqNqGGOOSHKhxIFuUbtMqS7oXLUK2SN9e1bpSzFewh8UsJAqtJEWTaz8yhgxR
5V00yuKiubtv5T7OWAmiJYa2tLLGfGOSNr13IMaxYsFGpfuS4MnTNWmWLTiSbVrKvAsqvpm3ZmTe
mY0LRIMG6vLZSkMflAmtZUuWYRM3TxvzNlq+fbk7/1Y4mypE5tJFA7dqEK3L3W4Fap5UO33B5vjp
h9U/tr3o5S/tNhJSM/EVWHg0DTfXTOw1pKB9BKWmVUknOZcJMXXRld9Zn111kFVsNQdVXLAV5plt
Cp30knif0VTVROUt+BB6EC70XWNB4ZhZRspkcqGPGe6DXSY03ueTiC+tZOJYJzpoE1JI+XaXTg0+
dNduNYHmn3A1CvQgQzfaJVNZWO6D4Y/7yIXfkfW8tmSMwcmIEG5JiTZgnXZ5yVFIggUlUHUwTZke
nwA2x5JLIU0lZm4yEcNcmQKhuV+SATYXU5B/KiRTXzFV9FWHBRHooUGfSoQnqJraBalAWjL15X9p
Av+qJFSKJVXPDbuVKBZBQLYok4iWpkrgXtXVN9BsYjjWKEPJmodcpEtVaVCRmXbZWZ5bHvRmYUIa
SiSRMc3HHJ9+mfVSI8S6pVKyYKWqoGJ6CRktqwRBWuV3x6IIl59y2jfJW7EVpliVjY3EHbT3kfiT
X60Z3JlmC4H2ILwDOUoxvQZBA1Zvf57qGsbMwmntfbKV3KxCij6bp1/0lfniSMQ0ViIxjsalWVjM
GUuQghxmqPNA0m42VIsIxXiXxAlJC6ZEsXUmcqpzAjcXZMQKd+TBCG9qmIhPzZokfoqdixSyAy/U
7kLlETX0sTEqXRlj2a59UJkpJyQTZ2X1dduLEab/pTMajZBU7l6ZjJRJqa51XddwKgqe5qOGwtZy
k3p+KB+2wa3K72du5yltVaAdlTHj+hpU9+BTJwhb3A/DNJVMF9IXg9wN4ufSQMm2ijtGX/FIjGw5
Bx8gWPRVG1+kr2J+LM5L6QSnqMqQNndUiSJ04FCcLngWWDInX9C/PU5yg0ZACT5Sf8fh/hlzRJJr
EKJ8uZSkQd53+5MYbii8YX0mC3wRQzEAgABj0IjC1cs6dxIPZ95yP9EQLCGG2VhRmoSWrU1FdyQJ
lJDS5JTiyWd8vOEW/VIin5CsRH4C21D5rPS0mQhwgC8EwGGigjW70SYGOMxEPdzgodQor1ouQdz5
/2Dik+j5CGigqsjFZnOSNb0ENIhCyNno9zVKtQdXlZkWpqQIAANc5wYvXIEBAKQMwIXEOga0U0xw
GAMD4NCNLamYyjYnFMRYLFhniiC4jBinDeYrZX4TA4aCBaBROY1S6EuT5uolQKdMZJHteWFBiBFA
AMwOVZ2BjeJmQsk2xkAMbGyjIzs2yQHNKYJmAcqt6vMUH6Gxla7cmYyS8pIt7uN2TCqZl5IXEmm1
xJVoEGBGXgSaVk1CbdNxjQBXBY0XaqRKZXpNKyfhyZMJiY0PqmGn7BbEVY0lBjsiWqcwpKiKTNOV
6MxIWNYlMPq0sHLARCeQ4lgvAwDgSpgJlUGOCf8rTFakklwEgA4dthz6reQG2JxNJgLYk34+Syvi
GyVBfje/IpqzcBiCzMQ+M5bXbO2X84QlkEZ6JovFakYCLAgYYxCzhPiGIZloJFXAKNCEwOlWliRL
13CF0E9OAkML4hirNtUhZaASdxG8wXLi+FMdZupCsMllQYgUmx/9CEM/ReMr0eAoh4xkEpb8niUN
UMAFdS6ZlaSObwAgRt2Nh1c4hAnxBBnEHIIFqG+JXpWI8ZXEXOqTvBpkJjvK1TKWNCMkpWouBQmR
XMHyJ+iELO7CmimwAoAj7FEGW5V6EJq+0ypjyuFqSpOkN7bkE6MZ7VUxqhHSoFAsQZLfUDJqFXL/
cg1IyZKevEBWxgjC5qwlNBcG0+QjTz5lspedqi1/KJAAGqAuV1VGJcFJGteSs7rXxV0Oq3VDAIio
Jb0xJzkB9MSCaUSPuMVV7IAEnLTgp46Ngd+cLNa7+l3OOCN5Z3MB8CUxuNFDYlhBPu/SoClZUoAr
+IqPQDlA3TYknwut6T5vmeCpMKkl1NPkSAsXvR4RD6mvMpxofoIeg6GwK9CQn1MIY1+QyW2/nCXJ
ACMkHxlCSndiiKGOnQlcbd0Sh3kzi5f+m+Jb2k8xNzjTESM1Xr8sdHwX+opOCKpGuQT2oHFCIYA/
EkAsSVemU5WwQyR5y0m4EQD/wlifCNIIaLDR/ya/pKZdnTLFbp0QPlM9k5C+IhQFZ+gudVNjkhpB
KGJcZ4ojOcz39OtSggiTJDGgpgHE0CBlrGC5dIFljvl71U0jtkc+cjCKliLpnjCVVTcwQIIVpBGd
WPhRPmoVhgwDVc4SA7VUFmq/8JNJRfXHnNzrkAZ7/OKCsLUuDQ1gNhsKEYDaposrwBxWN0zOxBYX
hx3ErSVjYFVDWxVIDr4wUPT8Y01KBaNLs8lBQe1r4mHxcc5qNEIEqJEYcJatsynVcHkF5p0JcF4R
CSW3MdRTbv+nLpxJ7CCTBe5QF8bP1b3QJ0gK0lC3EpAC+d0N2HIh3HkmRtFRyEtrYknZCoTeA/8B
bMD/HUnKMk0syuipG9u4grjaUmRCOedXxxJqUI5yQE8JdGY6PNWmLtwn35Zft2E57Q07PdT3GiA4
Uy5hUBJ7LjGVIUKcbZ6O7+MwiJsLGti47dzBuzRpUs7j4ogmFwPvifi9i8WPWzG0ZwrYQbS4+DKy
M8o9xIjgNnPJR9rIww28LsTe9CKzHmKkhtqGP0nxavapEbc8BcNlOQlQHbI6r2tLybyprl/qURes
IvYnt9xiGTfnEGJYcoEB7FEM9p3ln6FqxiSJTZXafvfd6Nc6QCkX6WMGHtbMaSgloztdlLvkuou6
Xnn205oRElNXL/PSfYyI1IQkwBk6pPlp393/7jF8qcJB1/Nq+Y76A2McJR0KkmbqlWjQDW87dTjQ
J2vNXxb0/Ji8cM3IpBxaoh3dNxFnkmaL1jXgg0mQFWh2ISoutjKvUyen4U6QNVwbxjkdZhqTh0Sb
13dmN33sQXoC5IAW4VtfghYIeHyGJH+3tB3bl2fH5TbcEYMOsxR8EjxPgXbDVxrFZ2hRsRpCVzG2
hD5h0hALxWh/oR3vcxNBhiaQQUNAM15DIVn7VzowMype1hezghb5xCn6Ry4fqBpppFwmGBb/oRN4
o4Q7gzNIdBCYxoIYE2TG0XZfsnnsUReo1y+gxRZJUWlCyBqtUktkkTAMI17g12FhdylFU2eO/8MR
itYQLkIRQFNGkNEqP7IbnrcgpHcsZUJQpcFho1Eu8ReBI3RILEFIahQpXtcuWrGJKuWKDjR91tMR
uiMo+pc+EwV+H7KFrDFaUNNq8uZHU8VzzJQyGgMd1BeH2LEUf9heWbEYNnQao2dD7wNU5JZxG8iB
dHFj/SJkGZcx4Hgf5nJn9KJEcKIWvKctjmgTuQghevGOhmQ9YzhOjzctNPaC2YcqkIIb+hR+rvE0
7uRImIFBgpFRTdGOwUGLDlEUAchcCwGLl6JbPdKECEFPpIhEmhM9+fgl5YFBJrKC7XGJ/1iR3CUc
9YFBtJciEhIRKFaPGVNSmNImhtQmHKIcs/8hNVgTJJZikLsEgns4FCNXbLtIDJwhLQppEb6BLwxx
L/20klBDF2lBMz9SGi2BXeHTI2fSPLJUUEBDYH1nU2GhfGo3j4xYi2YpEgyZlqGCidXGWtVGlRiS
lSZ4JWm0XKFzXyvUlsszI8aYJd84ScI4MumGSRHykDgBf7ySHGwZjk1ER3PxJZkFhkxpVLMSh6ZT
Q1DJEV0BfJgphxvBQy9WJTnHmJqCFoFhEheEmq+DmnhiEnsBHuchQm/IOQ1xdR6BQeKCEU6Fm4/B
J+Dxh6VRHWmxMPGofhHhd1+5EXWUSCxIHRBJmB9SMz8RF6LIGj54GhKCnRZxEmQJIy0WndJiuDxJ
KZ02Yny/MSzNc05xViNXophSFGOg4ja3cZIRcxBuqIbmaS3nNFrYuY0ZmSJyQ3dvgZisd4WX2DlK
wx7YEZ776RAQKB3/WRqjJXqmAV4U+oukMYK+KXIuVWn/6Bm+GRAAOw] File not found
O4 - HKLM..\Run: [LvelZkfgnZ] File not found
O4 - HKLM..\Run: [LvelZkfgnZh.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+qZv+qmf+qzP+q///VAP/VM//V
Zv/Vmf/VzP/V////AP//M///Zv//mf//zP///wAAAAAAAAAAAAAAACH5BAEAAPwALAAAAADIADwA
AAj/APcJHEiwoMGDCBMqXMiwocOHECNKnEixosWLGDNaVKaxYaaPHTkuFKOMWMeJmU4i5ChSJcWW
B4lN+gjS5UGY+8TsU1bSJsNJD0umJIiTaMKiPj3OpJlUYD2BInFCE6hzYEmeO61CNYgU4tCtXAtm
Ita1a9isRhs+nQiNGE2gai8qmyQGTUOOVYnyLFsQp1miJlemVbZWqMK6dMEq/Etwat/HO93OnBTY
IWOGRcVMQlNX59p9n+2CdgwYa99JN0ArdvhVq9FMpvuSTZhy82Y0iS3qRKos09KxAttO/OwTDee6
BfMOzEScZ2WCyF2fbQmXYHWnhK+Thjp2+2qCuOvi/x7YOWH00fV8f3xusLXBet6bIjQuXvm+62Kv
Jrf/feDTqf89Jdpe4DmVEDEmwcTeQZwZZ5to4HlGE1MH/SfWV8QpFB9EG95kUGdiiOEeQmTBFKJD
U41Y0H8izbSPY/C115Nihe1D3yQ4+uZiTvQhRiFB6k3mG1r+CdQaTE9dJhiRBjK0oI0C3XYcfwWV
SN5WNVZJEHz1zGVWVEXeNFRKaCjDWSZiENOlXdu5JVl1uNlGJZAyofHUTACeBZlqCNXEJ5MMqZjT
iyN2lptBbWElRmp63mcVNJ+NCKGjwYHVkohjNThJUSWWuNdVsRXEGV04TrqdY+plgsaQBXW4kFsq
Mv/GWJoMhUjfpFDxdCJtsBW1mXLXqVqqbZtZV157NLkVG2d9fZpggtDAZmN4v74nFm7CstoYoNJN
CNNfgbGUFaSrEgaWq9NWS9SuTe6Tkp8v3rmqZrjVC5eKmp0nEKwL5sljqbhua5CnBNJlr3GBijjZ
jtzGxHBaUJF2qJFVmbtTPagxNxWYSdpIb3Q3oMFebZSJqJmqXzkonWgGTwrrj5pqdhtCGUIMKH8h
5jvqeH9G1h6Os7H2sFVIIaYTmq0Sc0MMMVxXI6QHIYZwTjgWa2RB+E1NnsFG0mRcnArXay4xn0QZ
8IpgPVUzVQSFPKdADhrXiK0XTvhjoNru26qo6k7/NQnTYsTA6F1Ievy1qcoONClQx2l6MI5U6oe1
yNINhC5poeXE7kHJrvdRiDf8mvdFNMWo0HX07iO4GAYE3lJRsPdl6+y4PZWSufXqrKOq1h0lbqXs
AmczioK66zm8RBnX2nG+8WxRqk22tDxVaDAteAx2SsRSZfRCjia1t6YJrxgAAFBVPW50/GLQeu/T
yNljIb1cqkv9lioxmzuFpohbch7ik9TRDNoYor77IK9QA7le4N7WEuLUKzzz2p/hjIaG980MLACI
Qet6V5Ln/IcYCPMWv443lrXtRycQ4giqcvaTEKGLgK9ql/GGEjAIocZ6NzgWg+xFpa+gCYS3MVNv
/wLzPXrFoHwx8FhbSGi398VPc9LhCfS6wkKOnG05IZJWhaZFEhNWaCrecc6MjDSlGzwHR+baTlUy
AbiliaYzAWPfhTZVE2bxyWDxc5NvygcA27glL9V5SnTwt6jVgBBwR4yBiLgENWWIAVKN9MxKjoOW
zGwuQ2ZhJAhzlkOR4C+Hx8EPc5iylvMtDZEf2gxZ3HO/+KlHjySxm+F2UhI0lG9Vf7wNct4IQf6F
yUiKnJEybpBBkTkSKzjBT1H2J5qamSk6L1QImkAZIo6QCXR1gYkomVKVRS1taexxjr0mpMcxeSh/
n0MYHwUFtvDsCToGGFE9brACA2wqVNA5imqO0/+vfShtVXuLSD2mlM2tGKo9/ZufToiByJBZhZxD
2cz7OOchqphmJghiaPlEhM+c7axB4RmKSHzTtA/thGkGIAakxvKcqrzQkWi4AVL211KLTMk0xxnc
cra4llWx8ZSKfAtDGjSQBX2LKn8sk5nKB8ocqQeFD8TPfexU0CNuRRnQwKn1KuUuk+g0YePxjsFg
0kyuWiamdTEJIWUaL3IRp0NpCpECi5cQg0nSKkkaImyyqarAla86dp1WIyg0uqzihXVNK1NOMrS0
FaSEOGQJTHN6tpOcLeg4GXqbhqCCmmwuypcESRBa1kLO1LAxcICz1sYa5q7c0dJNgVEpVRZaPgP/
4OpBdrlKkAA6FpgsjSQ6c156AJBDy7HNXUpylw5LqS+4/RIijswZ3baUCcyxCqvEIckpT/kRF0Vz
p0ZC0FcS9Se6GAAAK7AiHCdFVOfshDIq9RQ06kklOKIWAAayIp0EZhA3ZJEoIcOPgMwal+DUBZQ1
8w0ItfgiozjSRlz4ZgwqM5ZAKkSPpBGRHcVCzAxSjYdR40xveKJYsqTpb0yjq+oMoMjhde05YcxZ
SwiZEpNk+J0LIe3sevObK1rFJFYjyfVW9zP3WBNWWrHSQC74oknwcZdAAYkOI2OmnUAtvqLRYBJn
sioXtQQNK7jBV5Tjl5JMlmIcJSNJuDUJqE3k/5kexRqJ5Hif28Qgwqh1c91Y2it35fUv9GpEh+2C
mNAqrqAcMcmJ+Fei6h1xmd1F06MVNxqFfAJBIV6zx9acGYmQZn8gAixXEOSYDck1cEu7HZHyeLde
KelrK9gohILnT5MM9H1TFk+CUMsfBzJtMmRmjFtkV9z7IIeKEImUrXoDx6sVFavvic+irFfSFw9F
fUsZtsUGYxuBdFhhhzr27/61YfBwhhgslqlZ/mYAxQnpI84Uy7DNJuZ5MqsrdsnSQtrSOIo1dV9j
XJJI5CphN4VWJF36E2yeRJXrEAOJUILb1/BCxmKTp7lWZNoKqtkTsla7hzweXZVSAo189bXGz/+N
ePsMUr9Nk9lWM0nuQU6JaiAqVnqxEZc1mdOfnByxmHPJSsI/dqZ+8qhiUQYAi6vlXm8ncVDWWrWQ
AhY/6fIPTFvCZcDNc2BtgbrQ8dGzvPd3g1OyZC6bomVMHkOY3kDnkazjI3rFHCG74MjZ8WrP/1LC
66NDBYSOPW6DMYkQITHMvvicn8i0dqAe1eUtnMlhzr7Lr30wCofYM2Cc6rU3nLipbAHClaT5WE+m
BexEILFQQv2rE8Sm7PHYI7F0wugRmsxuqrfJ/VA0CySrh65EIGLeUgYWv9XmhWk3iPCztBnVTQ2r
XryjCrwhxRPKsMSvckcKs7RoQityJoNmpGX/9XZFkq1Pp08y+9WotoeTnnpkdmn9MYHE8u6oBUdp
yI8Bg2cbys0IRfubwRxYlW2lNlCbAmYGwAWH4S4xZDaoZQArEAP1xDjnITlZ8TrpITUPshILNxJe
8Rdt8kTz80q3U3139ltZMTswcmlkYjWi0iUJ93dR4ieXwnhRM2/GRVEeszQsxjQPRlQpSCwHcxlZ
FTQylxG2g2ROAg2UIWllxzRPAiviYjpiwxMxuC8qkh4gETBYBxaLcm0y1DsXd0T01FQ+UjGJ1xWR
dVQYsSHbIUXCQzgVg2pME2FAYhhbgjkXkxPSwhI0tCu4ooSrgUz70RqkYSLYgi14JIJwky+5/7J1
jrFKS+IShFGE+4cZuEMg4yc4ZzJEBFZJXYJPXKZoGwYpQDGFoEFOstU/oQKIkBNVdjE6hOY8H1KB
ZNElkrgY8pErXNJgRJJXhUErVoF8aQJCJkR988cVfMd5JnUh4jVDn9EiOvI4HnElEXIY9+ZqHqKH
SBgUoYgWWQVwy/RJNeUfVph4yzFsm8OMUWI8iWMjk1Fn7jQzblhpCvFG+nQTJVGB5udFu8gV5zhu
7ihSBnFzbNgeDJccquQGgRFSOdJtQFJC30FaF0hZFMMQkeiJ0GEcMbJKT/Jdw7EYpiFHn8Ja4sIf
4/gXrhQ2wzI0ZyM9IpdyFTlwR4I2CFI2C/9hMIfIPv6YEbATFabhSlwRim2HFzdSH3PRILhWbljY
PPGYKjHigkvWKEXVXa7CFwh3h5fYEFzzUPLhHd/oT9KTkJX2VjBYcpUTcA0CcyHlUfWhGeGYlLey
ls3lMEMhMaqmGn7xWmRpGYFlM0coH2E5QAORGpWYIfEzRh+xebQBE1l1JwxoLG85lz7yimcIUiyE
XLOxWnexJzWYF4GpET2JKAtoTUUpLtgSk4VHmNQnVRh5IAUilpTmYFDROJ3Bc76IjbwXEgL3EN7x
RzioeW2mSQ/hY3oRmn2ye6tJHL2InAySPxcRjRV1fnryMrcTi9lCM1ZGZywHXQJJEfJTOeLT+RgJ
t20ulhy5lRHfxUkL4RyCeB9MGJ4J1RDxwYU9FyWH2ZlEkhdv+IlUqRXf+Y+sKF05ZHHJyVISMyyX
kmOWMZUJMZpqR0vwYYWN1DEP5psSUSPOiaEEOl2v4jkLMhmHmBwdAR/DWZKHaVgXQ6EpepbHaI0C
CqCsBV3elpmEU3naQxRtdpqfYlih+KPnyEiRqRIcURhtN6F5F6PRZjpfyS8yp3PwkSAJFxi7SaMc
MpMVuaLJqDgQqqQF9BD6hpB9qRCEl4P/yEjlGYNdep5KehEBAQA7==] File not found
O4 - HKLM..\Run: [LvelZkfgoMc] File not found
O4 - HKLM..\Run: [LvelZkfgouqc] File not found
O4 - HKLM..\Run: [LvelZkfgrxe] File not found
O4 - HKLM..\Run: [LvelZkfgrxe (Windows; U; Windows NT 6.0; en-US; rv:1.9.1.1) Gecko/20090715 Firefox/3.5.1] File not found
O4 - HKLM..\Run: [LvelZkfgrxee.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+qZv+qmf+qzP+q///VAP/VM//V
Zv/Vmf/VzP/V////AP//M///Zv//mf//zP///wAAAAAAAAAAAAAAACH5BAEAAPwALAAAAADIADwA
AAj/APcJHEiwoMGDCBMqXMiwocOHECNKnEixYaZMFTNqjKhso0eKHT9OJHZxYMh9mSahOXhS5MaW
LmN6hJnw4qRJF23mTIlRIM19OAnWE0gMjUqDJ5Up3bdU2VCZLAv+hAp1qkCjk2LyzIkTJ8mgWy+S
TCmGpNCE0JgqhVavo1O2TTNapSrzZ0iVR/eJ8Ul3YNqCYgmmRZNJjLKdmb7ynEQMYlulbeE6dcvU
p1KnPuv97Uv35E2jBlfSfTqQNMHDJQveZJwY5tyJpCcz1Ty5NmTOGikLxCsa4d6+0EKaRoizJ0HQ
JA9X5os74eXLj6HHbW5yLF7BCXs3hH5WammUxA4f/yZJjBi08q3RtyboJm9is6cPal64ufJrhR3b
2jfptv/+pd4xtJhNWUWk3UPBASjQcJTdd9BYiWWiTHh4jRdheaiRJ1Z4FwbGkIMM0Vbbct/F16Ba
bhXHE2FiGDfRbxHFdll3SYH4YGohGWWcUolB1KGGEoan4ZARWjihhB0qWFB0yiRY4kE58eXWUJit
9diTB8GYkRhoPMfcaTDVJ2BqA7VIIoeNUefcPm2RJ2R6QibHJGRiivFZmUZxqSV//c243IGOFZRn
l7cZlKZ8YhaU5k4DYbVPfZ/A9+iaLjmYaEFaRkclGmLoKdKeEF26m55KhQfmd6IOJClBUV6VV3Xv
xf+nll/DQeRnRZ1yioZRvMKY1lNv6UdRUIDONJBKu5rXWEdsOTQVaWMNVBhT5p3mYVLYPURlgAX9
pSunXOoq0GKgxlamZeehiJSqoAkEqkK1InQoQZN4OmFw6xI0L5v77KtqSSSZKSt4907UkYSX6qqn
wgUahFfD7jr024TERGqZl8rgBFOxzi6oaIZKXsXlJJqFBxNtlLIU7T68rptWef4u1F8jDHNqH5Uh
zbhUu4+W+te7Gwe5UFeQ+feutqdNEsMNMYjB9A1c9HiQrlkpm7OsJ/kr9bipcYqRkn9pyFeundbL
ls0xd1viZwW2VRjTTovR9CTKGPZcf246qRubNsn/3CZbpoa42XlxLy330jEk7uLUaNBM7X5qNylt
zEOtDFpLC3tNntoGLR4Vb53D3fQNKzwdAzSgYqioVDk1xeUNezVVd7ZWTtVSJojfIJZSk8AO944I
1Z1nv06e1VFRct9wA2MG1VNcY1jlqhBZuXqOknxAoeF8VIfrHviETje215vB85WSXp16ajxTLZpM
n0GFM013lk4v3+JNPCm0Ur1snrdUkLlL3NPSF67ZoKQkmeAZUmC3k05hpFr9Go8EJ0TBT1DQZOKD
nfYQ8rWMpYooOqqXzfLllk75TnkOjFe+9mG4po1QUIkTGL26QjeN+QV9ugpPW5iWOAGuoIddEpJb
/zB0GMYowygUK1Vh2leqjKXPZEe6DloI4rQYQIxVFJsUjHKWPjeQZYX8Ikrh4sYFFDJNQg2BhtLK
eJz03aBMT3sUBpsooecICUX1aJGempa7Miqvh2icj0HOsxg3DHF5B3EDlzZEmEGapHNyO5Db0pYr
cLXoIiHZU0s2Ezczjq5TTYubSkBFmXr8kW5CfA4BYRcDNIYrXEdUX2WycpnzsZCHMTzc0gboEK7k
iUsH6d1NesYhpjRrYHCMweQshinYVfIpqRHWgIIilU5yIXnYNBzcEOmxEhVmaen62BF3xUcCIlMq
E+JTJkqHuAISA2pL44IBDIOfytQjQmiA3c4aw/+WFokpSIl5FYn6BbUubQ19enqXjlZ3rrukZDX1
w6bvYLbET3KTc0rr1Lj0UqoXokSAjbIkYG6STprgroc3uGdKjIJLudVROjeDCdmOMi2g/MQ4AMUI
sPbxO73sSno1KcmevpaYSHEsn9f0HRdCiJgxvnFSJYqoWtAYPFa2JJMi5Z1OcnbPdraSgktJXtM8
JpwwucqSvMqKFLvZL7VBiG5vc2bwJtSe/JGGnttSFHkyhAaLNq0neoJWDGEXFZYlbn5fWpIy+Jim
kg4lLWkxIbjSchM1SkiAMXxkqRK3K5vdzTN3ElmuSJJWjnkOQxqKwVJZEr+lZUdVA2XZuPhpwjL/
xg09VxStawdWtzNui4KPesx8kvfAlrQJglQk26gwyzQdPucTqGST135Dt8v4K59A5QowBfKXnlD0
kUwxXGOl9clQKmRiQvmZcTLaQo1yTSxIaoQZwXRHE4pBTGl72kFRYiM9sRKlrURnnyIowuoGx3/Q
UdheoLnSlUBTOdZDidMw0hqMiJAwprTiQrr0yJcl0C/tjNsNc4sSqBH2gqphGheglKWCEoSZU5RX
AAX4vMcQA3QoOiL/9JWu3pnws0V5Xkc0JjvInPQ3dd3cQHyHzI6UZSv9uvFF7LTETv7Vlu/ycdPA
Rl7lYclfAmxs2kgTr5AQToDJs20h/capHVum/17py1o680dNRyrDmYvBV4fkFjtTQVEthOpXTwC0
kojKVVBIsWjzTMJY7jLHRaYMXzo/OEiVNLGEuDScCGVpkVcO5BNxI5TW7ISGmK3GjwWioUlwx0CZ
lQVj92oLGmxr2zpBsoWOfEoMOXa9gyGOnwf5y6UvqDjw6oWHPJRpQrcIv+ROV6Ne2o208gQ999CY
TPHB83qgSpTEHEh9/o2bTqkoFWcyuTQPzURaMvE0q6SJU2NtSSrLcyncyc0z++Mz4jickPS5mU1P
tUx4OnnVW3GNV9ZJydKyEq/GcLZRYmMO6nwKqtrKj9v0ay+3bgLKsQY1hsV1X4zDGwMDaFpCgv/s
4dIacU74SbZ9VJVW2X7UQR6Fhcp1NHGE32anznlla+49iOjibEfrZsyZfA54YkeFQrYRBk1V3Aul
l/QrVh4OsT7BrMcjcuNvBV3C932vxtwExb0iPOr8Pg+85XZFsB6pdQP/bKnsq7y0lViiF3UOK5dn
xwT2DmoyVMgxWXYnXP4Rgn3FJa9p1yNwGSfUucJfVzAyMsLg6Dn3HOXeUZq8Uht9Y8Tw1XjYOq7R
uZAmGSsn3PZUn7J3/JIRchoXlqZu/LXIKMI+VssExcMyqlzlTIu2sdGExbqpaMpk49RlilMcMdDM
bk+pbiYP18kWTShSEcrJWJJDE0Ku6tgmdKH/WUhSXnOfDC1V5GH6bVu5YDK/kQrpHeK8On/p1yOV
R4LipaG4RI6PrCdLJFIO81PqgiK60gg4ghAeBSRuIlsHZBZ1U16dZG5xw2c2InN8NFgydF0rNUMP
hRN6MkpiNX8hlieK9FPfcoCdFS6bBmc/hSx2woKdhVavBIPg0maN0ysHtDicJnj5VySxZ2LWNEAm
dgOl1jFRpipHFDiAkT0CFUaDNE3IB2Bbpi9g9RA5oR0fxjV2pxcuKCij1CTC0hZug3xIoX3Z1xrz
USwBo3oEZDh2ch+boRwMFRpPN3INAYJV9FcbRYfGBiVd4TAAWGdzsRk0eCz2cjz5Jx4d8hBH/7MX
f5c8A2R9EMGEqwaG7XIw3ZEtWLIQrXEUuRUyxZEQWUEYJEYRzmQzP4dJ1hUckdGJ/aaAs2ZCNOMV
H3ESaZUvXSgRqFVpPHFJTLFSbRNMC9UtKvQi30JxBQJc+vchEZNY4ac7l5gy2fJYQfaE3LI45xcV
xwNjmtVY+cEjKqETrpggWvU1anElOCNcrngizfMzL6RHrzNKJjEn98F64Fc2CKFCDbItapQx9WRs
6LgkN8Rt5ONo++gqnrMUq/FQ3wdGHyI7s1FKzQIgTkZqsDMJcEElc3IlS4E6/fEUkhg7tqIZ+hGO
zHE1hUUUDoEeIDIUhLF4jzaK4/gwp/ginf8iKjlyRQS0K2CiKc0mKKB0NJQ2TH9YjxVJVv2jH59w
ktNxRw9xE+3BLcFEYbyGGjqiQIuGKdsVW3+YFQmTPh5VNAaHKe8UA8KxHQg5G1NXkMtSGmI4OS8l
GZbRPwpZLJK0IPkzKwsxHFgRYQKhQQ9xVQlhGgnlk5lxNwbxRkzYloN0jAG5OkcCiydBWUZJHF+p
bq6ydBkRWUcTmVuiMFZ4K1K3iWoZKLLCFkjyE79yTEVUZ69FldLGEcGWXOVCkBD5PuXjLst2MSGD
mx6hk9RyO8C5D3UFMSeyNwxHdaT3HccImSaUG825SRkBLrTCI2uJPRVRIzBzKUqCFcj5IfWmgAbC
9hpmVpDOiD61+SVz4SCmAZkOYRo6NHVlRh+qQyKoR3gyKS+zaS7/4ZW4OYdt9JlQiIQvwYmOYXCi
okLQsm1HGX3FGCIc5CJtiZImGaBlQqDbuZUIinEciocygX2UMhQ4gWEasRmCFJyClB+ccYFqQptj
4SAHs5/xuRmwSRVskXuOeZovWhe7aChU4Z89+lty0aMfsaO7CRVI2pxG+iBN6hABAQA7] File not found
O4 - HKLM..\Run: [LvelZkfgrxenfo&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+qZv+qmf+qzP+q///VAP/VM//V
Zv/Vmf/VzP/V////AP//M///Zv//mf//zP///wAAAAAAAAAAAAAAACH5BAEAAPwALAAAAADIADwA
AAj/APcJHEiwoMGDCBMqXMiwocOHECMSnISGIkWJAjMRWzgJI0ZlGz0mzCSyZEFlJg9WRJNJzMqK
JjNpZIgmZURlOG3u66jz40KUCie5tFhRDM999TwCBaqRpEMxPSHiJJZJmUxiIKFB5Ak0qk6KL8Fe
jNoVaUaZSQlqTVjT68GyBHOepFqVKsi7WLFWnXlzX1e4CAELRGN0aNG2bgUK9rtPptO4ZoMmftpY
Wb2QC9cOfFw3L8i6Gql6vjlJKBrChClCRZjW59uTjBsTw4xxNWPaXpfuE3Njc8bFCI9GXJtXI0iX
qF0in1TVIGKTXTUPBKq19V+qAqWnPazw+T5ouN0m/7WdMS7wgo8jij2diXB6rG9nK3Op16roT3b5
JjwPOal0tBOJgdxp5HVnUHhuFVheXAgS5B1ja6203mkQ6ScQdg8qBFJ9omXSWmACfXihTEYROBZG
GfI3EHMZKiTgQUk9BhRWygi3oGErlThdSjLVSBKFGEmXUD3QiPidUE0NVZJu9WSYHmzfhbhTJifu
SJCCkQlk42A4UXkakltCJlFZKF2FHZZGflSPXIQpNwldk+3TYoMGaQaUReQBRZ5mEYrR0kstTWeV
TIqBaKVEdRWExmxixgbYWmmRiRqeiNkl5EBpMgRYmPvQuZtD7ZW222pfmiZUlU8eyByhcP2lUFqw
Dv+EnaK2wbeQf1lOSuCDUMHZEEquErSmXIUKhGWxCXWUKaaDVeSGUA899mGMOMVIqF8qqnXStQXt
qZVGa5F5pGmpFZQUSq1dNSQ0OBGLkF3ntbiggY0aRF5LMsm7oJ0hPkZMWsz9epBjRs7XFrsHkvSn
S/N1dOmhI5Ikhp13AcsQMeBR6SVFjXwZ6KfMEkRnV5wKGptKpaWqJUKpgrSbY1IKG7K6Bm0nM1Kp
oTZrsU313DNTxhWZU04UUWnR0US1W2NFKju3UNNxtbSRYIQpNmy1zpXmXarQbKn0Tim3rJdoeLVL
Y1V31YM2jVOZ3W5TPDHnZ2kWTVl0RUhXGZ+7EWX/qJmnLcVwg+B5GvsTsO7SHTd6aRHHoDIwMe3Y
XnRZNehVjs1G0qBHr2R0eyWmjPfQymT8mIDCQfWwYhh7GiWyBIUGsWKCWRWDn8QQJngMF+LUW3YP
Vctul6tClTnmoPk8VWhXEbUx3mAJKGDpzC1GJGTDEwmU2sYJqlxZCo4mZqxFslz864ZGHcMkZWUS
w+1OvWjfXaB2SGOn2GqNdKlMa82STFqjksFOwpv33eCAtyvY0IYVInRtxlcGycQNXFKQ37FNWxVi
TsBWVC/fTMd98LMXb6ByrE59Zj2hY1FpngU6L6GOVZA7SNHs0qTncEtOYiBcYQwYAw99TUxyCQny
/xA0HwE9Bjwm1JBCkIeeAg5ueua6kKwI98QICi53g6Gbs4TiBj+xrm2ua4z0XmS1r9FsOmt6Tlqc
GJJqoeF9PYxZpsp0w7PYa4J+Odu9KLI9810LN5PgYQ4F98T0fKtmE7zBk4gxwsZ4RCv4sVx4lIOG
CSpnM8oxDrAihZT54IRdk6iiVtq3u7IIyTIZA9xRWiKgnX2KSGO83X8AmJ5zTYc3g+PC4G4XA10a
UAxdCQmkGvM+G0nQNkdZXfD0khHpsWQwjSHRGL30HYwx0DKdrGJSGheiQMbxLZ8R5sVwQhhF2st2
I0QDSuhioYEN5I283N3gEDjIG2BmMQVMzw0mcf81OT2kNYVRJzEmIR3VlHMjsjNWckq3Jg2exDLu
8yJ1zHK9XTbJLMtbZGDOJkYoVhCXJWoKRAbaJgPmclFUqScvneIUbu7mdm1Rxg10uct91qhmihEK
cpTULnA6009OqQ4rkROZcP3JKeWMwdDut8lK4rF0TUGX0NDYNuFJkRgTRMOa8mfJoUCtWF+S0Cfq
8cv3qbMgWOXlBNc5u0GmFZjHEVAM1GkjExnEciar1jor2aZNAmthRvmOZQYbG/YlZYJKxRZGl/o+
3LWMdkob1M12wpuOGK2rXoRRjuQWphrN04AIIsbuGnuymDUmkY2Ai/tm+qPSopVvU0PlnZRzg5r/
tGY8yVFZa21jwNLwTU4d2WVP+0i7Nc3KOgPRiiWtIhRL4nEgJWLaokD1xMZyzVi7440j7+qXQbZq
NwdcjbLUQjq9umudjhFQuc4KXfUCM0tRbM4gVySXsFFlcLRZ0/D8wpUOdqq5fhJQVsVAFVPZ56ss
g2MObwCXdPHQnnQa4XPRA0fFoE2vW92PbB6jGiNOKbnK0a4Mi8Re8MbAVi8740FpV5zk6rW0k+to
Vy2psLp84jUaNtZM59mIgkjnre9rzkGgMp/bAYaRE9xqR+iHvpOVyZUhpuRqnFLES0LJcNha8Oai
5KUgBhknG8RxZabSSdU410/QGOEnVuNK18Lu/0qjtefsOgXHwdVRIL/D4VyxpVc7W/goDlStfBBS
W/VCLsRtahOCn6OMYjYlw1KCnKOHFM2r4I3RRZygwhjZShsieLL7yK7gALPGSvISd7eaJ25E+96u
CNnHZCtdYJITvi66JKvLBZ9BDJDDRPWupwsG45EkRyXuNtHDqGwJHvM8oisnZMeknUhYicnDdspw
piWWqTkNsiVrv0vAZOxWomnzJNuEJpByNhsAdZxDpBSURhshotrsU8nMMqaI04VtO5dVZ5jmzCDy
5IJSwxjqwc2olQmZsn7KpyH1Aim5o+prYXeEF4SauocaAxu+FrwqtrVRUJojG20ErBLezGeJQf8t
1CgHkkjCJaRI1R3cPm78E6FQcdtWSkvG/QvEKB9Iyq7+9c6UtuC5UhO6vNwJgeQS2SZH9jOWFBZK
mhtKkiyrzdBFQyMGOV9QexOxNSF4oy0JuFkxmjXOCTFuWImaEd1lJuq8S1hZObiO0KVNBzRP2aqa
F/xsxE7S27KDwF2/rpXINmNv7Jxq+r545xi89hbWt1K15K4sa0WW7IGf0HVMRX+mU+1pl/HqyEh5
Sq+mHkdJRSDH5LcMK6V4xBj9OsKbRjBbNyHKmQbDUpPq3g4z1Ukz4aJNc4VMsEHKhK5D/mIa99b7
pxSpXJcG4xm+a6SACt5nBPUS2Jb8Flvsosr/imfFFOkV1jADWo9I4/Jgm97SAL4UnFPCaL2NVsyf
8G0yAaPs8Ez2iHNIMRZMlB+fkTnBhDlZozSyhzVmAToUpBgDgneUNG1RlGMSFE9PhH27lEOI8WnD
YSUgwT5okyhGsij4wXaIhjqDQhUAQ0vGERoYs0SfJyhP1yRH8SE6IyEDshrbBDnHBxM4pX+xgxmi
NVrypGCN1RoE5xDWcSkPsml5cUFn0Xz/k3FlUjTXly0m9H1Zsxy6UhgstRBaVRQjZF5LYXViJhsQ
eDs1pUtOVGLbZRIfshEfshYdoTX1UTvwIX3wgTxhhn8P9XTEohoGpV4dcyzOE3dUdiV/smSK/yFx
5tFPbvYhfFEjghN/1mVsPTE5LCIybnA/2qIVcEVHPTI2b4IVvuVx7DMV4KGDEvISJRQcKyEzi6Jk
FAgb5SRlbUJQ0zE1KMYQI3RFgrGEy+dAsqIxq+KCGwRGRQIaBfYjYBEqLBFS0WUavygS0jhkHoMa
hxE9hcgTeIN2K9IWbGNKJwFH36QtHrh8sdN6iiIoGsSJLogj5KIk5aFOGtE563GIp0IpL6F1sIgk
E+gneJMeq6gisShD3kEj1wRdiFUgaUGMGgJG52Ec7JM7hoFbpqIl8tgzq2IfUAEWp9GNXiiSQ9E2
DDSORKE/EtIShPglofNvBNEbq/MwsXg14P+BeoCxjvvhjldCa7BYER3iEKKyGwBJGLkzOVTyjJkw
VbJlMX71UFjxiiyTLHF3JYR4Kod3Gh1ziCaSIzniIjXFSfOiRJCRM8nxlRMzWFCpOT0lNC9GZjVC
UKh0jdCFIPEIQM/YiU1GLiUjJYu2ikMmEmORlqYSYoRTIwr4FIkGLdUEipBVD4FHF3/HGJeXRbLh
OlPWEP2TEXmZjAXGEOtoFGTGciZRNQ1hK8XGZ5SWPjSIEgQWY4TpY2JYlgVxNLcZOiOxKp+5Kg+B
JD2CZafpENJRE+exOrTRNmeBdSfROLiiEMl3Jb6xHQ71TrvSExqUnTmSjeOIE7YRnRDHbfr/AiV/
GDI4ZkY9w45EBhZdOZKqExEFki8OsxtFk5DI9RZHMzeeA5+COWcVciyZUpTj9Db5yGmuSVhuppBu
MhS62H/80wgupDfpQ2IrmTNfdZkIwTDYBBHXk3bRshMw8htTsSptEjxxwm3gaBHPYyq6Qi5HNTeP
JI7+6Vtv1pr594CvYyQqMzzVAjPmF6I2qokpQZB68zwbc3TdsZVEkTMBtaQ4qh6rwR/ZolViRhvw
ZiVWFhEdeqKb1TlHeqIMoTYDmZbcGIFhlZCMGRur81tVFqMYkSZr8oJR+HZX8RkzKJFg+hEutCuU
FD1p2adedBEYaiwYg6avkn8d5GojuR56JgOe6JGnkGoTSrqLbcdua6oTzJUcLBJYEvEwD4OnkRqq
CAGEBREQADs===] File not found
O4 - HKLM..\Run: [LvelZkfgsPc] File not found
O4 - HKLM..\Run: [LvelZkfgsPc.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+qZv+qmf+qzP+q///VAP/VM//V
Zv/Vmf/VzP/V////AP//M///Zv//mf//zP///wAAAAAAAAAAAAAAACH5BAEAAPwALAAAAADIADwA
AAj/APcJHCgwUyaCCAtOSsiwocOHECNKfKhsosWLF+spq6gMmkaMEycZXNgwk0g0IFOqXIlQ2UeW
K11u3LexHrSZMwXWgwlx50CTBivSRGgSZUOhQ3kqdYh038GBOVkK3Ui1alWbDX0ShLYUIteEQKHu
I7kPzSSREJt2XbvPJ7GnAompbWlVY9W2c1PmFcuWYN6zBp0yFCkGoVaYe7t+/SmXY2OrUbMWVIl1
oM/DLaEmZol57EiEXyeZzbRZYuG+Mq/erQpXoEuQaDo/rNyQ6+m8NZXK3rd4stNMRjsXTYrx9ESP
kCHTnviW7uuIZGFCEy0GTfVJYkROzXlTusXWY0VG/ycY9qJR18mv9kVIjGFkhuf9UhdtFk39+tip
HxTztCnVtpaVphdBWrVXkknj/SYeRXbdtRZSu21VEHgCmZUdGnLpJxp9G8Z3kXFJRaXWc0wlFKFf
fB2k1WJClbePgRWaxJdA0IBIoW+uZcRbjnn5VN9baDQyGk03NXWjbCDKZt1Y6L0nXI4JtThQbxjB
GFFRN6LhokBkPbUTZs2JdWKPlhHHEGk0yeVXRUZVdKJAYiQ50JIVpuleZi/iSVyCIN141EDi3XjS
PiDyeRhaESG1V5yJbmQlQWSJRmNEIBIKokvQPCoRhF+ppaJEHoEF5VyhkveTSGhCquVC/TF0nVkd
Cv+YUJwe+tUgeeCR9J9ojUzqk1p0xpfTJHslhmZTmi5EpWF5JoSqlZUd5tONLhp3Vq3LxnVQJtVd
6G2H1DHqkJrZxgVolELBil9RGwJHK2kbXUvshnoqKtSje33qUKY7mqqQQQZppRaMnZ2FqGBjjVaq
Q37SpEx71vGnpX0W2oedlteFt+FJ2uG3LhoViYZgJstW5zBu8S085UsDwUiiqA+5DJWmP40UmL8O
oQQUhYPG3HB1jRFjZUcsE2QxfhJjB9zBLdHWCHBz4gVnpUKRdBhHD7WaNYFikSbX145+B7CMD9m4
IELyQklQmFNXGpdMNEvUJTEeg+sxrGL8h9ClddL/aJdXeW5W9bglKZNJ0A8n7mjiBh4OXHls4lzW
llze7GmcNxwV2cNgC5jg4bOFKoYb8lZMn3WSAuomVzNhNqJPVCIl0g3gEoalyOKhKi9QBpMOFOOL
c7741/IGyjtcFfHedqotF7mp4UInNLG4pk6FbkWLiSy9Mhfzd/FC2AkV4XuGcYvhnSUNCN5ppwFc
FeJB/849cNatyjvICgKGH+laLg2rSW54i9dMIoYYGCBp/3sL3dakFY0sh15t8QiI4iOGGxRLbQ0h
xg1icIOdgOcp5fIT66KEQTgpo4Kga9ikTnWSzinuYYS5wQZl1RDsAAAAMcghwwySN5fgr2koqo9Q
/0xWIY7EgFFfwQy/zKQt6+TwKa0BD9bMxaCcNM5V3bpBnEhUq4Fo0Sg2e9gnJnFEAwBggzHAYQzg
FbwX6i1qaMihAdJ4uIehKYkboV4GPdIb7mmHUDopSAXd1rI/UmSDP4SLgTqTvIv850Za7Fac4gQX
5lWEem6hyQ1wOEc14lCNa7SI4hpDxhziUAyPeVHQyvKwFWpmKFT51U8wVhiUDJJ2eJqEFlXIJR3+
BGFbs4iBXHIs10SMVmLoAa24NJBugSYqK7jBCnKYw+qQZhKnBEl0DCjHGEzKKtV5IdjU5B7yjaVG
C9HiEY3TmwrGQFqu4uARAXSzYJLwmWuDpaUiZv+Q+i3TUpfKDVGqM8dtIQgaabyO1SDSpsPF0ZMH
iQoRiZI4r1FlnMFb5SXjiLkbaEqDSEwIV7RSwA5aDJURoxNRcCQ+JkqOUBEzXFwiuUzk2VGAjqvj
W3KoK8eJAQCgc8qqZuTBtyiKm2fMG0GoVizHcaQicinSFKmCOezcAC47eZgM+TSlKfH0l63xJ62w
U5h6OmQ5S7KOFmlXo53YZ4snE1BoDMgfDUYzp2NTIMCEti22LdWUMVjBEI3CxzE1SC463UrR1Gmh
03SKW/wJpImWOkMqtoarQcJQt95awr0h82aFmaSWBnchtEDILwmlSQHfCRYXBUWA0HOcANMoR7L/
Qk+ADHnMXr7CVzUpapKEqmyONpi5rpaJPRskSSWjBpGgVig7yKyfj7gVSVS5Cw1arEm2MGYWKnFw
jiuYowFa+pOQGcRAo0FeZbqJwym27H3K+IQCBajXm74WPYcjhi61OLWFZJUYwL2INL2ZKzhNhJdc
Qma3LhYyZAotTpMoLHw6lAkugJKaIFwbaaCIqraYZCMka2Zg5bgdYjgPI3NxnFOI8QnMeU2GjEre
LtWmFYslRYM3OB9FY+AfhkWEKyCbJAqFLEn7PLcgHKnHeXMKJ2rG4KFGsQ5f81mWytXzLIVRxgYB
MMe8fcSBnbVItk6YXZSQOcLtGeTLGmI/JxKS/1A8/hNR4rZU+khykGo1zmbrdzGdLMyhc8RQKQuD
zVCCZoEOE8zIVBtHarZ3RNihM3smSxwtc0HBa1UGLb943OZy8EIt26BSH9LWXx7FxEKOpFgxFLG9
LfWt9BFS3gJL2CXn0KN4pdvfJvOYDqOByxheWxzNeGcirzrHCq4lrY5oQWZWuIMv0iJXZ7OPW3MJ
u0fUcaf3Fio7YqpB9UDJF+vqLhSmqyx6fDNBNnhAxIIah8VdE03qQdPqoI6fZFzBJ5/szk6aEihu
GBtodrMwZmvlcDPuKIom0ujZxaBL7AoOBpkqUaeo+ptiidzUmmkcCiljmrim22rVSKvEiTbLYf8S
klMPJ4Y5cnPLgT1jeDl4JpsJsMPNJGuejRbc0PJXj1FS4NpuHQOawUVkZinTbaAqvX1G9k0g+id/
WoNTlxtw3y4HAGtgem+gGflMctQ3Na1+RMKcBp5IEbJ1mmLV9igqE0fMRCSbKaGas1iXke1slkRG
mu5Q5Jjoc3VvWl0YxF5ymv62+nUO4hEV1tXe3TMLB+E98/BW0CnWpeQ1SXPnuhvtiKe9ZJzivu7C
vMkpqMxvUD2FtvO+Jj9JPy3qnVmipWamxdbho0DQWM0Pn0xqxCoanLRExYRsErBz5C/mA9bPlMJ1
w0tuj+UqGO8cYXeQo7b9lc6EWLbtLMLCB6T/Z5D+3ArSEGszUTHHUbm4lpjYg/GiC7px5Fyo0Pbh
aRcrULIDudpMS+SUBFtPQUbUByD9cmDGNRhAsWsOQUgGw1mxIxN/k3ZsAxmttiapQU5uNStDoWSQ
4lB2Qkklkzo1Y3Yn5SFgkl0oAiTYt1cIZmoHYlozoVd+pX0M84DEghtb8VSL0i3AsxfRMVFTZxed
Yk59ojsI4k/oplKV5llxpmFMVkJYxRvWdVgrxRh7ZRskRExgYTBQ0yRgo26wlEdMmC3KtjORRXUz
QSxdoWQkgXNGs1nQdUKUJYb3BEzW5RrhR2W5ZTjEdyZMYRVoYSVZxiOrZCk8BHTLxy1mpVxM/1FH
UnFWQyVnutQ9yGaHXJM775UXi8E6vBRuOdUcUuQgkgUUo2FLL0JM5hRvkEU7ZJMxNog8JWETbudI
InUmTNMsswIjb1UdnaFk/dMfMnFW6eNSdIcrF1Ua4PEYH2ZO+ycx62cdvEMS8ZEgKbZI7kURtYcQ
q5KN3HhgijRvFpFVpTgjg/cwJ1ZU9+VnCNN+fOGFo5GLlUIxxoESgDEyL4gjDrOHYdaP5fWF7+iP
gDgjTUhtFKJbZ3clqvg1+BIvjHgwbUYWyjdBjIKKH6g/unImn3B6gSQUfYQnmaQQtTJtXLMeK5Yp
5IOJb+MohyNfDuWQZGGHI0MdDUF7zcUxCf9Sg4FHbTvJJRDURSa5khdFKUwhNFIyNhFGFapngyXZ
TBOjPDx3gQe2MWjBS3shGz2WNWdhhKACOKmYFxSCGWLAW4m1iIhCTrmVU4S0GB7CXxwDHmrVlWiD
IaaYcU35Y/zoLDloi9v2YzCzGyeUIWMDNa3RShbRYrEVh9s2Qf9zFhtHkIeRLQP4ff51gHdIkPvi
HKjBLF3TVYbDko9TksIoaQ/hTRMSac9lPvcBe3ZmHzajajo3OrTSCJJCJc2BGfaTHdExRJiTfXpx
fmuRgxmiX0x5mhvhMd7iTxRTP29VMdB1OuxXf31zJd2Sj/0iU3nBnB0CdAJSGlyZFBHFk5nHwYhK
Nh2ed4wFwYA8MVEl0VvoppIcdzxzIZYmUW9MqI0goYPQ4ZWGEyhkcXAMtRNLJFkswR/wWTlfY52t
tRB4NknKFxMGKJ7w1CdntTMhETM3IUtyxpNCyHDGRYNlc0xqZ5I0lIAwkQkcGRPfuRK1golvhl0F
QV+QpYhBCSXl0heHwTxL8VQpehFJxBDVBx+SQUifWUc3yhbkVaNKGkF5GZRHOp0CWRt8paNs0aRL
2pe/SaBVep6XkRZcoygZEVs6uRJPqhIBAQA7==] File not found
O4 - HKLM..\Run: [LvelZkfgsPcft.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+qZv+qmf+qzP+q///VAP/VM//V
Zv/Vmf/VzP/V////AP//M///Zv//mf//zP///wAAAAAAAAAAAAAAACH5BAEAAPwALAAAAADIADwA
AAj/APcJHEiwoMGDCBMqXMhwITRiDSNKRKhsokWBFS8uFCMGjUQxGhNOCikxE8mTBTOiTDkwUyaV
Kw2i4ThzY8x90EwuhInQo8ibIXnezDSJ6L56QBneoAmyYFOVQgdCNVjPZ8OoR0cm1Jk0ItaJmYgR
g7avqFapXT/O5EgWDUSWDDMi3cfV4Fe0An3OFUi27L67XetVRApYIOG/xMLSdXkW7du0BAujmdTR
6l/DeBH2PQyTZ9N6fXlO6ou5pWGyeyEXxshXmTJirukWNRj6MmTWmRFCBMm0KW60qVtyDe57n2WE
jQ2+vE0QGmiqvwW/fuvSKMHgGCuSzs2c4OPi+zp2/0yuMDHcvM/DHzeodbPd1SEF7wybMedsi4dt
H2UutK7xhOJxFFlBxJBXEBqpNQLTdjnthZpAZ6V3EVbKSIgbMZ+I1ZIbkzx2FWj50YZTTBam5NqJ
sIWXkEprTUaQSW5QNJBlDV4mH2b+jehXaVdVhFWIA8EWFldF5agZaIMNyON+g23XEJDn3aifa7DB
RuVX0HBE0476OSWTVRXWBtJcqXEFn20wpfddYsq4BGF1A2GHE4jOKeQjQnsBdleK7ym03j5Vouha
nuEFCF1eXdajlX99ObfeogtJmKRybRIjBpxl3bdihWfaVh1jbhaVWGJFfqqTdaSpVOVjhYnhpJ2C
nv+oTG/sHeRRmgNRxlpsi13GU1R8CvSSeXmZRJSmAw7WqXdx7neQeDNlIqewRSo0rI7TgjfQq0G+
KNWJAaJRkbYCeShQR//F5eyhiNHHmkuXIotbhduetCBB4kFjYENEuWkXYq/N1CJNmXA0yQ0yZuTf
vgQN/NrDbTZcXGPBSisVt38NCRNjHA3nK2TQwETTJFbJOS2A/j70HlY+hSseZQWLW1llJItBGRoC
2yqeVIGa65diBS2HmY+j8pRYv7p+fJtcNeO877LXzSjskL99G6yKVx1kZFkC22zzZDgfFTPOOEMb
7UEFmjTXS7w2uliRFYm700RTDTQezlFlBDHUBjX/xSdRMdwwSd5C/3nede01dBy6CC0XM7QGABCD
WxkepTeEZrE2ctldlz0JyQWRRTV2lzJF1ZVWvqaZRRl55PMNkscQw9XfAo2xTjwZTlFTNUUFtNgv
AiC55P19rjaaT0EINsmNkC3eDaMSAzbvXlsWK5vNTUuhRGOhNYnkBshuwAqC91Ql2uUKDhPD2w5q
nG8+5zgsbACsIHzkAIihjL6aXn6u0ZSRHQCW8jArNQxmeCsgxMSznK9Mpm7OWpb0DBKD8HEkdhWM
AeMalp0UiQFhGIHdxOLknM48BmzAKRdXhESdmQAgcrMaHvkMUx/9+C0xYnihzTKBhhgMD3ckc4tr
/9imoUhVDU2BW4rQgnKZ4xAjfCvQzgdXIDsfXopYXPscWaxkKS3dIAYsCpLkXKe6vPgGUsICmLk4
NbwYHMuHkXOjVKSEMGWgAXayu4FgrnUDKhpgcKijz++yppAAflAMb/nVQVLzFvD0UHJBE8MKwudD
t/RLW4kMmRgqeJb2BA6M/tEWSIhWRpxoJz2ZeCEAilQ2AUquThkR0It8eAMiToeS5HrRqPylI2ZZ
a5No4MJSUiUWqABLas6SXC0PkpMqXspq9flVH5ciII/EgIoeytKfWKijSR2ofvk7SB+HZ8dxXSks
sJHdCly0rUlY0SJDGpWSEvUXYFaEi20riHS0A/8o0nRIYer0naj+NMrX5IgYshPXrDoyybrYLCXY
c9WcFkIZ4ZUPbbATHmwuZdDJVAYN4eNKXzIhQJS0SZAiCo8ST/SvFdXDPyB8zRfDSRCSsU9qEBES
vXAiu6dMIqR82aAtTWOg7YjqhTEAZM9UVzCLPvNTRbJUHkv1uT4agEYpVRddxOKSnN5Rlr9ZTeo4
KJAMDsmmc7Nbl3BCH3cawEpTZcxD6EMYqFanI0gjivR0msNXmsVUQ3Sn8L6lHl0po4p966NQ7kQ3
Ew1xkxLFTp1k5KGHYe17tCworw5CVaShoTrG66oFeyg7wYglkR/EHOi69U+IWUxYwnunsLjq0Yr/
xDY1qSGZAD3008lFjSRXKqVK9Rcdb1KEW7z6IiV7qjd37eRPsXHrBwEQlleBqyMZKkq8ioIGjO3D
lcIboDJWixGShXdclakK56ZZtgtq8GZfG08u33M+zt6AC5aZC1lwhZavVKVN5CMfUit4qb0YEH2+
2adhUinAyQzLRw/GJ1jpkqnPsrOssUXDJO0nx5HwyoeyY8gTk9omPIJQIXtJzx6Dda8QTnhEUkqI
z/QzkkeCsSoCvKYBiFsug0KwoOUSUlnGKJaH5GQ6KoyMa8TznbzYtIeRa0oq8edGrSxleMv8rVQE
SM0vBu5rlqEaNPPGtXVt8gZCAdFJyAKSScox/zYFyyCBlTy4Ku2XSjpdYB+Nc+FvfSJvVqKZTiEU
Xh5+Ljw+jK2XwxuDNCoEsX8RbFIBVbCbdXCJzBzvo5ZioBqGDsUFKUr4AJCn6PZRjgN6zkOC26bG
fLCnENpKm8oI5pe85MX3I48YRp3o+kXuMY3J3fiACGI0fyu+DTm0QYhBzWbtal0kUaeRZOUTH6lK
Wjs1aLG+duqtsQev+pu1MWXm3kbXSyCxG18cL2qaxuWRq3TxMhhZfK6dNacso/z0IXUSmpNpRBng
00lw5tKZEznOSHcra+BAi7SaQateXUUyvtqUaIg8aCAZnW2meknhlkSvfjGlkpwBs5bxjKZL0f8N
XFHnGRH3IDpwfJmTpwElZGhjRCc0I+Nh//iuUlXnaGHJnHAKiPHYLjnBxqFitREVtA4Nch9e5lMj
K7gCnfz1c5+dWnhuppKYZaLZh7vJTAdHkVl/CyuV2XpKCGwz8haS4aD6eZvOmx1lKBFQseW40482
NZPIapMAcPBn+6VcAtck1AbqWsE2KUz/8ARKT+KLpKO2Kli1DqzEBUnXZKeTQOFpRTW9K+evvs+Z
AoAuPrZO9LCdGAdv0reELUsVFdqwra2v5Pfl8YxX8nrJXUrMzl6SeorztSCeBaFgtAtdP3SooqCo
X/BK9JCmf7QhOjoyGYQKq5QTtk8f0W4zMbb/UEij5osUbLn5YxRtOtK8s6MwSHoj2V2IjrHdk8zv
ZkFRYmLb1f7/vDGOp2PjERuPZxw39X19s1r+JhH7hSEQAWVUt2OON3wHQhkjARG583RXUUQ2hXVE
gTMfuEKCNHhso0qtFWifwyEu4WAAqEwFZhsewiEHoRIGxhAYg1vexTN2phw5VEUJhRSlAyBmlx0c
JFy5YmHcBX3O5xpkQxnxckXABygE8kT2MyypsmTy44SCY0la0XVltkinoxAllFUScSXBpzXik0Hk
MiqHVzVjcTRm8VnG030vxRRd42SpY2uYRhCfACh4JhCj9ntvqH2vkW8dZxepk39lZFzLNjTs/8JM
57aAj5hYVORGlfIY0AA2IWgWxtOFfDITbYIGzZMzylMzhmZrRfMa2IE6B5FoGSEk9AEuZSMoqTMW
KqFsEBF3g6dsn7YdEKRPN0Eak8UUbNKBPMQhONMIDME5pbNZfhg3n7NBq3JQ8Gcl1yIrQyRTVjRE
+2QdsTYwa1EaJNOH7dY4ISguvBh27JIaOXhzcxgWAuMayPIq4BEgH/Unt5JPKbJqYhYyz7g32AiQ
MjZsLPcpXFJ3MyNfBMIdTrI27zg4muIgDIFbhgY2r5EhRPFQ5/YsazE2GxQRXPQQ9ZA6AUklujGD
2aGBLaE7cWKQL2JHZIcRJRd+n+d95/E5k/+ggsYjF+0If0v0kVoGLV/jWLKCT1w0Vix0ULvXUtsy
Y0RnJ8KHOYxhgGaCgTqjJVsSlSy3FUXSiZ8liStSTACpaUUZXFcRTyxJhAtRF5NlJxlSgGtFLbHG
Q3DIlAsxMFqijhdBDDqJiGNphF6CEanjb7uEIX3TELSzkBhRIjtxYFtRe0HjjXF5bwphj23YHS1X
KM+4EKNSOQwxXwSifofIN1LReaE3F+ykFXsRd0uJgJWJlXmJmTH3MEljJ/F0EaC5bMfTLZOpEcK4
KH12kAfZamZyhhuJEe0Im3npi5C4ExCTF9wiSImhPWKoVtWpZMnSFeNlEm53IKGmNZLpEFL12Jyv
+WIJERrT4YzqQSmt6RWHaRF/4zNgKRLcGWy2EjTASC1uokiZMZ9BsTcIAZQ2SYYoh5ICEVNhpxIh
45jHKSO/VWONQXDbMhfJcYDQhz6UWaA9OYOJ2Tdp6Z8XkZZ4YpLGCRYWNqA9ETTzWS2uKZv36aKV
qZUO+pz/JhtbqWU1FTQb2hKD4zEw+qPfdzK+cXEzqF+JtH2gx6MTAn0r2JXwCCpOmldR5XPH4m1L
I5ut1llXZ1damlc/J4cM56RbmjaT0aV/pYQrOGO7CSjz+XhyB6PEGXdbuqVSWqdj+hGExCR94idW
Gh8omhC4pRz9AqIIERAAOw==] File not found
O4 - HKLM..\Run: [LvelZkfgspe] File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [VideoWebCamera] C:\Program Files (x86)\VideoWebCamera\VideoWebCamera.exe (Suyin)
O4 - HKCU..\Run: [conhost] File not found
O4 - HKCU..\Run: [LvelZkfgnscft.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+qZv+qmf+qzP+q///VAP/VM//V
Zv/Vmf/VzP/V////AP//M///Zv//mf//zP///wAAAAAAAAAAAAAAACH5BAEAAPwALAAAAADIADwA
AAj/APcJHEiwoMGDCBMqXMiwocOHECNKhKhsYsRJaDJZ3Mixo0ePaCRWFFixHrSPDeuhETMpk5iQ
+0YOlBlzJsqbH2lufBlj5SSMBevtO2myKE1o9WjqxKlQTCaMMG0SOyj0pE2mFpemJKpV4A0xYMO+
ZDmJIExlFbsaFMpUqNqGGOOSHKhxIFuUbtMqS7oXLUK2SN9e1bpSzFewh8UsJAqtJEWTaz8yhgxR
5V00yuKiubtv5T7OWAmiJYa2tLLGfGOSNr13IMaxYsFGpfuS4MnTNWmWLTiSbVrKvAsqvpm3ZmTe
mY0LRIMG6vLZSkMflAmtZUuWYRM3TxvzNlq+fbk7/1Y4mypE5tJFA7dqEK3L3W4Fap5UO33B5vjp
h9U/tr3o5S/tNhJSM/EVWHg0DTfXTOw1pKB9BKWmVUknOZcJMXXRld9Zn111kFVsNQdVXLAV5plt
Cp30knif0VTVROUt+BB6EC70XWNB4ZhZRspkcqGPGe6DXSY03ueTiC+tZOJYJzpoE1JI+XaXTg0+
dNduNYHmn3A1CvQgQzfaJVNZWO6D4Y/7yIXfkfW8tmSMwcmIEG5JiTZgnXZ5yVFIggUlUHUwTZke
nwA2x5JLIU0lZm4yEcNcmQKhuV+SATYXU5B/KiRTXzFV9FWHBRHooUGfSoQnqJraBalAWjL15X9p
Av+qJFSKJVXPDbuVKBZBQLYok4iWpkrgXtXVN9BsYjjWKEPJmodcpEtVaVCRmXbZWZ5bHvRmYUIa
SiSRMc3HHJ9+mfVSI8S6pVKyYKWqoGJ6CRktqwRBWuV3x6IIl59y2jfJW7EVpliVjY3EHbT3kfiT
X60Z3JlmC4H2ILwDOUoxvQZBA1Zvf57qGsbMwmntfbKV3KxCij6bp1/0lfniSMQ0ViIxjsalWVjM
GUuQghxmqPNA0m42VIsIxXiXxAlJC6ZEsXUmcqpzAjcXZMQKd+TBCG9qmIhPzZokfoqdixSyAy/U
7kLlETX0sTEqXRlj2a59UJkpJyQTZ2X1dduLEab/pTMajZBU7l6ZjJRJqa51XddwKgqe5qOGwtZy
k3p+KB+2wa3K72du5yltVaAdlTHj+hpU9+BTJwhb3A/DNJVMF9IXg9wN4ufSQMm2ijtGX/FIjGw5
Bx8gWPRVG1+kr2J+LM5L6QSnqMqQNndUiSJ04FCcLngWWDInX9C/PU5yg0ZACT5Sf8fh/hlzRJJr
EKJ8uZSkQd53+5MYbii8YX0mC3wRQzEAgABj0IjC1cs6dxIPZ95yP9EQLCGG2VhRmoSWrU1FdyQJ
lJDS5JTiyWd8vOEW/VIin5CsRH4C21D5rPS0mQhwgC8EwGGigjW70SYGOMxEPdzgodQor1ouQdz5
/2Dik+j5CGigqsjFZnOSNb0ENIhCyNno9zVKtQdXlZkWpqQIAANc5wYvXIEBAKQMwIXEOga0U0xw
GAMD4NCNLamYyjYnFMRYLFhniiC4jBinDeYrZX4TA4aCBaBROY1S6EuT5uolQKdMZJHteWFBiBFA
AMwOVZ2BjeJmQsk2xkAMbGyjIzs2yQHNKYJmAcqt6vMUH6Gxla7cmYyS8pIt7uN2TCqZl5IXEmm1
xJVoEGBGXgSaVk1CbdNxjQBXBY0XaqRKZXpNKyfhyZMJiY0PqmGn7BbEVY0lBjsiWqcwpKiKTNOV
6MxIWNYlMPq0sHLARCeQ4lgvAwDgSpgJlUGOCf8rTFakklwEgA4dthz6reQG2JxNJgLYk34+Syvi
GyVBfje/IpqzcBiCzMQ+M5bXbO2X84QlkEZ6JovFakYCLAgYYxCzhPiGIZloJFXAKNCEwOlWliRL
13CF0E9OAkML4hirNtUhZaASdxG8wXLi+FMdZupCsMllQYgUmx/9CEM/ReMr0eAoh4xkEpb8niUN
UMAFdS6ZlaSObwAgRt2Nh1c4hAnxBBnEHIIFqG+JXpWI8ZXEXOqTvBpkJjvK1TKWNCMkpWouBQmR
XMHyJ+iELO7CmimwAoAj7FEGW5V6EJq+0ypjyuFqSpOkN7bkE6MZ7VUxqhHSoFAsQZLfUDJqFXL/
cg1IyZKevEBWxgjC5qwlNBcG0+QjTz5lspedqi1/KJAAGqAuV1VGJcFJGteSs7rXxV0Oq3VDAIio
Jb0xJzkB9MSCaUSPuMVV7IAEnLTgp46Ngd+cLNa7+l3OOCN5Z3MB8CUxuNFDYlhBPu/SoClZUoAr
+IqPQDlA3TYknwut6T5vmeCpMKkl1NPkSAsXvR4RD6mvMpxofoIeg6GwK9CQn1MIY1+QyW2/nCXJ
ACMkHxlCSndiiKGOnQlcbd0Sh3kzi5f+m+Jb2k8xNzjTESM1Xr8sdHwX+opOCKpGuQT2oHFCIYA/
EkAsSVemU5WwQyR5y0m4EQD/wlifCNIIaLDR/ya/pKZdnTLFbp0QPlM9k5C+IhQFZ+gudVNjkhpB
KGJcZ4ojOcz39OtSggiTJDGgpgHE0CBlrGC5dIFljvl71U0jtkc+cjCKliLpnjCVVTcwQIIVpBGd
WPhRPmoVhgwDVc4SA7VUFmq/8JNJRfXHnNzrkAZ7/OKCsLUuDQ1gNhsKEYDaposrwBxWN0zOxBYX
hx3ErSVjYFVDWxVIDr4wUPT8Y01KBaNLs8lBQe1r4mHxcc5qNEIEqJEYcJatsynVcHkF5p0JcF4R
CSW3MdRTbv+nLpxJ7CCTBe5QF8bP1b3QJ0gK0lC3EpAC+d0N2HIh3HkmRtFRyEtrYknZCoTeA/8B
bMD/HUnKMk0syuipG9u4grjaUmRCOedXxxJqUI5yQE8JdGY6PNWmLtwn35Zft2E57Q07PdT3GiA4
Uy5hUBJ7LjGVIUKcbZ6O7+MwiJsLGti47dzBuzRpUs7j4ogmFwPvifi9i8WPWzG0ZwrYQbS4+DKy
M8o9xIjgNnPJR9rIww28LsTe9CKzHmKkhtqGP0nxavapEbc8BcNlOQlQHbI6r2tLybyprl/qURes
IvYnt9xiGTfnEGJYcoEB7FEM9p3ln6FqxiSJTZXafvfd6Nc6QCkX6WMGHtbMaSgloztdlLvkuou6
Xnn205oRElNXL/PSfYyI1IQkwBk6pPlp393/7jF8qcJB1/Nq+Y76A2McJR0KkmbqlWjQDW87dTjQ
J2vNXxb0/Ji8cM3IpBxaoh3dNxFnkmaL1jXgg0mQFWh2ISoutjKvUyen4U6QNVwbxjkdZhqTh0Sb
13dmN33sQXoC5IAW4VtfghYIeHyGJH+3tB3bl2fH5TbcEYMOsxR8EjxPgXbDVxrFZ2hRsRpCVzG2
hD5h0hALxWh/oR3vcxNBhiaQQUNAM15DIVn7VzowMype1hezghb5xCn6Ry4fqBpppFwmGBb/oRN4
o4Q7gzNIdBCYxoIYE2TG0XZfsnnsUReo1y+gxRZJUWlCyBqtUktkkTAMI17g12FhdylFU2eO/8MR
itYQLkIRQFNGkNEqP7IbnrcgpHcsZUJQpcFho1Eu8ReBI3RILEFIahQpXtcuWrGJKuWKDjR91tMR
uiMo+pc+EwV+H7KFrDFaUNNq8uZHU8VzzJQyGgMd1BeH2LEUf9heWbEYNnQao2dD7wNU5JZxG8iB
dHFj/SJkGZcx4Hgf5nJn9KJEcKIWvKctjmgTuQghevGOhmQ9YzhOjzctNPaC2YcqkIIb+hR+rvE0
7uRImIFBgpFRTdGOwUGLDlEUAchcCwGLl6JbPdKECEFPpIhEmhM9+fgl5YFBJrKC7XGJ/1iR3CUc
9YFBtJciEhIRKFaPGVNSmNImhtQmHKIcs/8hNVgTJJZikLsEgns4FCNXbLtIDJwhLQppEb6BLwxx
L/20klBDF2lBMz9SGi2BXeHTI2fSPLJUUEBDYH1nU2GhfGo3j4xYi2YpEgyZlqGCidXGWtVGlRiS
lSZ4JWm0XKFzXyvUlsszI8aYJd84ScI4MumGSRHykDgBf7ySHGwZjk1ER3PxJZkFhkxpVLMSh6ZT
Q1DJEV0BfJgphxvBQy9WJTnHmJqCFoFhEheEmq+DmnhiEnsBHuchQm/IOQ1xdR6BQeKCEU6Fm4/B
J+Dxh6VRHWmxMPGofhHhd1+5EXWUSCxIHRBJmB9SMz8RF6LIGj54GhKCnRZxEmQJIy0WndJiuDxJ
KZ02Yny/MSzNc05xViNXophSFGOg4ja3cZIRcxBuqIbmaS3nNFrYuY0ZmSJyQ3dvgZisd4WX2DlK
wx7YEZ776RAQKB3/WRqjJXqmAV4U+oukMYK+KXIuVWn/6Bm+GRAAOw] File not found
O4 - HKCU..\Run: [LvelZkfgrxee.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+qZv+qmf+qzP+q///VAP/VM//V
Zv/Vmf/VzP/V////AP//M///Zv//mf//zP///wAAAAAAAAAAAAAAACH5BAEAAPwALAAAAADIADwA
AAj/APcJHEiwoMGDCBMqXMiwocOHECNKnEixYaZMFTNqjKhso0eKHT9OJHZxYMh9mSahOXhS5MaW
LmN6hJnw4qRJF23mTIlRIM19OAnWE0gMjUqDJ5Up3bdU2VCZLAv+hAp1qkCjk2LyzIkTJ8mgWy+S
TCmGpNCE0JgqhVavo1O2TTNapSrzZ0iVR/eJ8Ul3YNqCYgmmRZNJjLKdmb7ynEQMYlulbeE6dcvU
p1KnPuv97Uv35E2jBlfSfTqQNMHDJQveZJwY5tyJpCcz1Ty5NmTOGikLxCsa4d6+0EKaRoizJ0HQ
JA9X5os74eXLj6HHbW5yLF7BCXs3hH5WammUxA4f/yZJjBi08q3RtyboJm9is6cPal64ufJrhR3b
2jfptv/+pd4xtJhNWUWk3UPBASjQcJTdd9BYiWWiTHh4jRdheaiRJ1Z4FwbGkIMM0Vbbct/F16Ba
bhXHE2FiGDfRbxHFdll3SYH4YGohGWWcUolB1KGGEoan4ZARWjihhB0qWFB0yiRY4kE58eXWUJit
9diTB8GYkRhoPMfcaTDVJ2BqA7VIIoeNUefcPm2RJ2R6QibHJGRiivFZmUZxqSV//c243IGOFZRn
l7cZlKZ8YhaU5k4DYbVPfZ/A9+iaLjmYaEFaRkclGmLoKdKeEF26m55KhQfmd6IOJClBUV6VV3Xv
xf+nll/DQeRnRZ1yioZRvMKY1lNv6UdRUIDONJBKu5rXWEdsOTQVaWMNVBhT5p3mYVLYPURlgAX9
pSunXOoq0GKgxlamZeehiJSqoAkEqkK1InQoQZN4OmFw6xI0L5v77KtqSSSZKSt4907UkYSX6qqn
wgUahFfD7jr024TERGqZl8rgBFOxzi6oaIZKXsXlJJqFBxNtlLIU7T68rptWef4u1F8jDHNqH5Uh
zbhUu4+W+te7Gwe5UFeQ+feutqdNEsMNMYjB9A1c9HiQrlkpm7OsJ/kr9bipcYqRkn9pyFeundbL
ls0xd1viZwW2VRjTTovR9CTKGPZcf246qRubNsn/3CZbpoa42XlxLy330jEk7uLUaNBM7X5qNylt
zEOtDFpLC3tNntoGLR4Vb53D3fQNKzwdAzSgYqioVDk1xeUNezVVd7ZWTtVSJojfIJZSk8AO944I
1Z1nv06e1VFRct9wA2MG1VNcY1jlqhBZuXqOknxAoeF8VIfrHviETje215vB85WSXp16ajxTLZpM
n0GFM013lk4v3+JNPCm0Ur1snrdUkLlL3NPSF67ZoKQkmeAZUmC3k05hpFr9Go8EJ0TBT1DQZOKD
nfYQ8rWMpYooOqqXzfLllk75TnkOjFe+9mG4po1QUIkTGL26QjeN+QV9ugpPW5iWOAGuoIddEpJb
/zB0GMYowygUK1Vh2leqjKXPZEe6DloI4rQYQIxVFJsUjHKWPjeQZYX8Ikrh4sYFFDJNQg2BhtLK
eJz03aBMT3sUBpsooecICUX1aJGempa7Miqvh2icj0HOsxg3DHF5B3EDlzZEmEGapHNyO5Db0pYr
cLXoIiHZU0s2Ezczjq5TTYubSkBFmXr8kW5CfA4BYRcDNIYrXEdUX2WycpnzsZCHMTzc0gboEK7k
iUsH6d1NesYhpjRrYHCMweQshinYVfIpqRHWgIIilU5yIXnYNBzcEOmxEhVmaen62BF3xUcCIlMq
E+JTJkqHuAISA2pL44IBDIOfytQjQmiA3c4aw/+WFokpSIl5FYn6BbUubQ19enqXjlZ3rrukZDX1
w6bvYLbET3KTc0rr1Lj0UqoXokSAjbIkYG6STprgroc3uGdKjIJLudVROjeDCdmOMi2g/MQ4AMUI
sPbxO73sSno1KcmevpaYSHEsn9f0HRdCiJgxvnFSJYqoWtAYPFa2JJMi5Z1OcnbPdraSgktJXtM8
JpwwucqSvMqKFLvZL7VBiG5vc2bwJtSe/JGGnttSFHkyhAaLNq0neoJWDGEXFZYlbn5fWpIy+Jim
kg4lLWkxIbjSchM1SkiAMXxkqRK3K5vdzTN3ElmuSJJWjnkOQxqKwVJZEr+lZUdVA2XZuPhpwjL/
xg09VxStawdWtzNui4KPesx8kvfAlrQJglQk26gwyzQdPucTqGST135Dt8v4K59A5QowBfKXnlD0
kUwxXGOl9clQKmRiQvmZcTLaQo1yTSxIaoQZwXRHE4pBTGl72kFRYiM9sRKlrURnnyIowuoGx3/Q
UdheoLnSlUBTOdZDidMw0hqMiJAwprTiQrr0yJcl0C/tjNsNc4sSqBH2gqphGheglKWCEoSZU5RX
AAX4vMcQA3QoOiL/9JWu3pnws0V5Xkc0JjvInPQ3dd3cQHyHzI6UZSv9uvFF7LTETv7Vlu/ycdPA
Rl7lYclfAmxs2kgTr5AQToDJs20h/capHVum/17py1o680dNRyrDmYvBV4fkFjtTQVEthOpXTwC0
kojKVVBIsWjzTMJY7jLHRaYMXzo/OEiVNLGEuDScCGVpkVcO5BNxI5TW7ISGmK3GjwWioUlwx0CZ
lQVj92oLGmxr2zpBsoWOfEoMOXa9gyGOnwf5y6UvqDjw6oWHPJRpQrcIv+ROV6Ne2o208gQ999CY
TPHB83qgSpTEHEh9/o2bTqkoFWcyuTQPzURaMvE0q6SJU2NtSSrLcyncyc0z++Mz4jickPS5mU1P
tUx4OnnVW3GNV9ZJydKyEq/GcLZRYmMO6nwKqtrKj9v0ay+3bgLKsQY1hsV1X4zDGwMDaFpCgv/s
4dIacU74SbZ9VJVW2X7UQR6Fhcp1NHGE32anznlla+49iOjibEfrZsyZfA54YkeFQrYRBk1V3Aul
l/QrVh4OsT7BrMcjcuNvBV3C932vxtwExb0iPOr8Pg+85XZFsB6pdQP/bKnsq7y0lViiF3UOK5dn
xwT2DmoyVMgxWXYnXP4Rgn3FJa9p1yNwGSfUucJfVzAyMsLg6Dn3HOXeUZq8Uht9Y8Tw1XjYOq7R
uZAmGSsn3PZUn7J3/JIRchoXlqZu/LXIKMI+VssExcMyqlzlTIu2sdGExbqpaMpk49RlilMcMdDM
bk+pbiYP18kWTShSEcrJWJJDE0Ku6tgmdKH/WUhSXnOfDC1V5GH6bVu5YDK/kQrpHeK8On/p1yOV
R4LipaG4RI6PrCdLJFIO81PqgiK60gg4ghAeBSRuIlsHZBZ1U16dZG5xw2c2InN8NFgydF0rNUMP
hRN6MkpiNX8hlieK9FPfcoCdFS6bBmc/hSx2woKdhVavBIPg0maN0ysHtDicJnj5VySxZ2LWNEAm
dgOl1jFRpipHFDiAkT0CFUaDNE3IB2Bbpi9g9RA5oR0fxjV2pxcuKCij1CTC0hZug3xIoX3Z1xrz
USwBo3oEZDh2ch+boRwMFRpPN3INAYJV9FcbRYfGBiVd4TAAWGdzsRk0eCz2cjz5Jx4d8hBH/7MX
f5c8A2R9EMGEqwaG7XIw3ZEtWLIQrXEUuRUyxZEQWUEYJEYRzmQzP4dJ1hUckdGJ/aaAs2ZCNOMV
H3ESaZUvXSgRqFVpPHFJTLFSbRNMC9UtKvQi30JxBQJc+vchEZNY4ac7l5gy2fJYQfaE3LI45xcV
xwNjmtVY+cEjKqETrpggWvU1anElOCNcrngizfMzL6RHrzNKJjEn98F64Fc2CKFCDbItapQx9WRs
6LgkN8Rt5ONo++gqnrMUq/FQ3wdGHyI7s1FKzQIgTkZqsDMJcEElc3IlS4E6/fEUkhg7tqIZ+hGO
zHE1hUUUDoEeIDIUhLF4jzaK4/gwp/ginf8iKjlyRQS0K2CiKc0mKKB0NJQ2TH9YjxVJVv2jH59w
ktNxRw9xE+3BLcFEYbyGGjqiQIuGKdsVW3+YFQmTPh5VNAaHKe8UA8KxHQg5G1NXkMtSGmI4OS8l
GZbRPwpZLJK0IPkzKwsxHFgRYQKhQQ9xVQlhGgnlk5lxNwbxRkzYloN0jAG5OkcCiydBWUZJHF+p
bq6ydBkRWUcTmVuiMFZ4K1K3iWoZKLLCFkjyE79yTEVUZ69FldLGEcGWXOVCkBD5PuXjLst2MSGD
mx6hk9RyO8C5D3UFMSeyNwxHdaT3HccImSaUG825SRkBLrTCI2uJPRVRIzBzKUqCFcj5IfWmgAbC
9hpmVpDOiD61+SVz4SCmAZkOYRo6NHVlRh+qQyKoR3gyKS+zaS7/4ZW4OYdt9JlQiIQvwYmOYXCi
okLQsm1HGX3FGCIc5CJtiZImGaBlQqDbuZUIinEciocygX2UMhQ4gWEasRmCFJyClB+ccYFqQptj
4SAHs5/xuRmwSRVskXuOeZovWhe7aChU4Z89+lty0aMfsaO7CRVI2pxG+iBN6hABAQA7] File not found
O4 - HKCU..\Run: [LvelZkfgrxenfo&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+qZv+qmf+qzP+q///VAP/VM//V
Zv/Vmf/VzP/V////AP//M///Zv//mf//zP///wAAAAAAAAAAAAAAACH5BAEAAPwALAAAAADIADwA
AAj/APcJHEiwoMGDCBMqXMiwocOHECMSnISGIkWJAjMRWzgJI0ZlGz0mzCSyZEFlJg9WRJNJzMqK
JjNpZIgmZURlOG3u66jz40KUCie5tFhRDM999TwCBaqRpEMxPSHiJJZJmUxiIKFB5Ak0qk6KL8Fe
jNoVaUaZSQlqTVjT68GyBHOepFqVKsi7WLFWnXlzX1e4CAELRGN0aNG2bgUK9rtPptO4ZoMmftpY
Wb2QC9cOfFw3L8i6Gql6vjlJKBrChClCRZjW59uTjBsTw4xxNWPaXpfuE3Njc8bFCI9GXJtXI0iX
qF0in1TVIGKTXTUPBKq19V+qAqWnPazw+T5ouN0m/7WdMS7wgo8jij2diXB6rG9nK3Op16roT3b5
JjwPOal0tBOJgdxp5HVnUHhuFVheXAgS5B1ja6203mkQ6ScQdg8qBFJ9omXSWmACfXihTEYROBZG
GfI3EHMZKiTgQUk9BhRWygi3oGErlThdSjLVSBKFGEmXUD3QiPidUE0NVZJu9WSYHmzfhbhTJifu
SJCCkQlk42A4UXkakltCJlFZKF2FHZZGflSPXIQpNwldk+3TYoMGaQaUReQBRZ5mEYrR0kstTWeV
TIqBaKVEdRWExmxixgbYWmmRiRqeiNkl5EBpMgRYmPvQuZtD7ZW222pfmiZUlU8eyByhcP2lUFqw
Dv+EnaK2wbeQf1lOSuCDUMHZEEquErSmXIUKhGWxCXWUKaaDVeSGUA899mGMOMVIqF8qqnXStQXt
qZVGa5F5pGmpFZQUSq1dNSQ0OBGLkF3ntbiggY0aRF5LMsm7oJ0hPkZMWsz9epBjRs7XFrsHkvSn
S/N1dOmhI5Ikhp13AcsQMeBR6SVFjXwZ6KfMEkRnV5wKGptKpaWqJUKpgrSbY1IKG7K6Bm0nM1Kp
oTZrsU313DNTxhWZU04UUWnR0US1W2NFKju3UNNxtbSRYIQpNmy1zpXmXarQbKn0Tim3rJdoeLVL
Y1V31YM2jVOZ3W5TPDHnZ2kWTVl0RUhXGZ+7EWX/qJmnLcVwg+B5GvsTsO7SHTd6aRHHoDIwMe3Y
XnRZNehVjs1G0qBHr2R0eyWmjPfQymT8mIDCQfWwYhh7GiWyBIUGsWKCWRWDn8QQJngMF+LUW3YP
Vctul6tClTnmoPk8VWhXEbUx3mAJKGDpzC1GJGTDEwmU2sYJqlxZCo4mZqxFslz864ZGHcMkZWUS
w+1OvWjfXaB2SGOn2GqNdKlMa82STFqjksFOwpv33eCAtyvY0IYVInRtxlcGycQNXFKQ37FNWxVi
TsBWVC/fTMd98LMXb6ByrE59Zj2hY1FpngU6L6GOVZA7SNHs0qTncEtOYiBcYQwYAw99TUxyCQny
/xA0HwE9Bjwm1JBCkIeeAg5ueua6kKwI98QICi53g6Gbs4TiBj+xrm2ua4z0XmS1r9FsOmt6Tlqc
GJJqoeF9PYxZpsp0w7PYa4J+Odu9KLI9810LN5PgYQ4F98T0fKtmE7zBk4gxwsZ4RCv4sVx4lIOG
CSpnM8oxDrAihZT54IRdk6iiVtq3u7IIyTIZA9xRWiKgnX2KSGO83X8AmJ5zTYc3g+PC4G4XA10a
UAxdCQmkGvM+G0nQNkdZXfD0khHpsWQwjSHRGL30HYwx0DKdrGJSGheiQMbxLZ8R5sVwQhhF2st2
I0QDSuhioYEN5I283N3gEDjIG2BmMQVMzw0mcf81OT2kNYVRJzEmIR3VlHMjsjNWckq3Jg2exDLu
8yJ1zHK9XTbJLMtbZGDOJkYoVhCXJWoKRAbaJgPmclFUqScvneIUbu7mdm1Rxg10uct91qhmihEK
cpTULnA6009OqQ4rkROZcP3JKeWMwdDut8lK4rF0TUGX0NDYNuFJkRgTRMOa8mfJoUCtWF+S0Cfq
8cv3qbMgWOXlBNc5u0GmFZjHEVAM1GkjExnEciar1jor2aZNAmthRvmOZQYbG/YlZYJKxRZGl/o+
3LWMdkob1M12wpuOGK2rXoRRjuQWphrN04AIIsbuGnuymDUmkY2Ai/tm+qPSopVvU0PlnZRzg5r/
tGY8yVFZa21jwNLwTU4d2WVP+0i7Nc3KOgPRiiWtIhRL4nEgJWLaokD1xMZyzVi7440j7+qXQbZq
NwdcjbLUQjq9umudjhFQuc4KXfUCM0tRbM4gVySXsFFlcLRZ0/D8wpUOdqq5fhJQVsVAFVPZ56ss
g2MObwCXdPHQnnQa4XPRA0fFoE2vW92PbB6jGiNOKbnK0a4Mi8Re8MbAVi8740FpV5zk6rW0k+to
Vy2psLp84jUaNtZM59mIgkjnre9rzkGgMp/bAYaRE9xqR+iHvpOVyZUhpuRqnFLES0LJcNha8Oai
5KUgBhknG8RxZabSSdU410/QGOEnVuNK18Lu/0qjtefsOgXHwdVRIL/D4VyxpVc7W/goDlStfBBS
W/VCLsRtahOCn6OMYjYlw1KCnKOHFM2r4I3RRZygwhjZShsieLL7yK7gALPGSvISd7eaJ25E+96u
CNnHZCtdYJITvi66JKvLBZ9BDJDDRPWupwsG45EkRyXuNtHDqGwJHvM8oisnZMeknUhYicnDdspw
piWWqTkNsiVrv0vAZOxWomnzJNuEJpByNhsAdZxDpBSURhshotrsU8nMMqaI04VtO5dVZ5jmzCDy
5IJSwxjqwc2olQmZsn7KpyH1Aim5o+prYXeEF4SauocaAxu+FrwqtrVRUJojG20ErBLezGeJQf8t
1CgHkkjCJaRI1R3cPm78E6FQcdtWSkvG/QvEKB9Iyq7+9c6UtuC5UhO6vNwJgeQS2SZH9jOWFBZK
mhtKkiyrzdBFQyMGOV9QexOxNSF4oy0JuFkxmjXOCTFuWImaEd1lJuq8S1hZObiO0KVNBzRP2aqa
F/xsxE7S27KDwF2/rpXINmNv7Jxq+r545xi89hbWt1K15K4sa0WW7IGf0HVMRX+mU+1pl/HqyEh5
Sq+mHkdJRSDH5LcMK6V4xBj9OsKbRjBbNyHKmQbDUpPq3g4z1Ukz4aJNc4VMsEHKhK5D/mIa99b7
pxSpXJcG4xm+a6SACt5nBPUS2Jb8Flvsosr/imfFFOkV1jADWo9I4/Jgm97SAL4UnFPCaL2NVsyf
8G0yAaPs8Ez2iHNIMRZMlB+fkTnBhDlZozSyhzVmAToUpBgDgneUNG1RlGMSFE9PhH27lEOI8WnD
YSUgwT5okyhGsij4wXaIhjqDQhUAQ0vGERoYs0SfJyhP1yRH8SE6IyEDshrbBDnHBxM4pX+xgxmi
NVrypGCN1RoE5xDWcSkPsml5cUFn0Xz/k3FlUjTXly0m9H1Zsxy6UhgstRBaVRQjZF5LYXViJhsQ
eDs1pUtOVGLbZRIfshEfshYdoTX1UTvwIX3wgTxhhn8P9XTEohoGpV4dcyzOE3dUdiV/smSK/yFx
5tFPbvYhfFEjghN/1mVsPTE5LCIybnA/2qIVcEVHPTI2b4IVvuVx7DMV4KGDEvISJRQcKyEzi6Jk
FAgb5SRlbUJQ0zE1KMYQI3RFgrGEy+dAsqIxq+KCGwRGRQIaBfYjYBEqLBFS0WUavygS0jhkHoMa
hxE9hcgTeIN2K9IWbGNKJwFH36QtHrh8sdN6iiIoGsSJLogj5KIk5aFOGtE563GIp0IpL6F1sIgk
E+gneJMeq6gisShD3kEj1wRdiFUgaUGMGgJG52Ec7JM7hoFbpqIl8tgzq2IfUAEWp9GNXiiSQ9E2
DDSORKE/EtIShPglofNvBNEbq/MwsXg14P+BeoCxjvvhjldCa7BYER3iEKKyGwBJGLkzOVTyjJkw
VbJlMX71UFjxiiyTLHF3JYR4Kod3Gh1ziCaSIzniIjXFSfOiRJCRM8nxlRMzWFCpOT0lNC9GZjVC
UKh0jdCFIPEIQM/YiU1GLiUjJYu2ikMmEmORlqYSYoRTIwr4FIkGLdUEipBVD4FHF3/HGJeXRbLh
OlPWEP2TEXmZjAXGEOtoFGTGciZRNQ1hK8XGZ5SWPjSIEgQWY4TpY2JYlgVxNLcZOiOxKp+5Kg+B
JD2CZafpENJRE+exOrTRNmeBdSfROLiiEMl3Jb6xHQ71TrvSExqUnTmSjeOIE7YRnRDHbfr/AiV/
GDI4ZkY9w45EBhZdOZKqExEFki8OsxtFk5DI9RZHMzeeA5+COWcVciyZUpTj9Db5yGmuSVhuppBu
MhS62H/80wgupDfpQ2IrmTNfdZkIwTDYBBHXk3bRshMw8htTsSptEjxxwm3gaBHPYyq6Qi5HNTeP
JI7+6Vtv1pr594CvYyQqMzzVAjPmF6I2qokpQZB68zwbc3TdsZVEkTMBtaQ4qh6rwR/ZolViRhvw
ZiVWFhEdeqKb1TlHeqIMoTYDmZbcGIFhlZCMGRur81tVFqMYkSZr8oJR+HZX8RkzKJFg+hEutCuU
FD1p2adedBEYaiwYg6avkn8d5GojuR56JgOe6JGnkGoTSrqLbcdua6oTzJUcLBJYEvEwD4OnkRqq
CAGEBREQADs===] File not found
O4 - HKCU..\Run: [LvelZkfgsPc.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+qZv+qmf+qzP+q///VAP/VM//V
Zv/Vmf/VzP/V////AP//M///Zv//mf//zP///wAAAAAAAAAAAAAAACH5BAEAAPwALAAAAADIADwA
AAj/APcJHCgwUyaCCAtOSsiwocOHECNKfKhsosWLF+spq6gMmkaMEycZXNgwk0g0IFOqXIlQ2UeW
K11u3LexHrSZMwXWgwlx50CTBivSRGgSZUOhQ3kqdYh038GBOVkK3Ui1alWbDX0ShLYUIteEQKHu
I7kPzSSREJt2XbvPJ7GnAompbWlVY9W2c1PmFcuWYN6zBp0yFCkGoVaYe7t+/SmXY2OrUbMWVIl1
oM/DLaEmZol57EiEXyeZzbRZYuG+Mq/erQpXoEuQaDo/rNyQ6+m8NZXK3rd4stNMRjsXTYrx9ESP
kCHTnviW7uuIZGFCEy0GTfVJYkROzXlTusXWY0VG/ycY9qJR18mv9kVIjGFkhuf9UhdtFk39+tip
HxTztCnVtpaVphdBWrVXkknj/SYeRXbdtRZSu21VEHgCmZUdGnLpJxp9G8Z3kXFJRaXWc0wlFKFf
fB2k1WJClbePgRWaxJdA0IBIoW+uZcRbjnn5VN9baDQyGk03NXWjbCDKZt1Y6L0nXI4JtThQbxjB
GFFRN6LhokBkPbUTZs2JdWKPlhHHEGk0yeVXRUZVdKJAYiQ50JIVpuleZi/iSVyCIN141EDi3XjS
PiDyeRhaESG1V5yJbmQlQWSJRmNEIBIKokvQPCoRhF+ppaJEHoEF5VyhkveTSGhCquVC/TF0nVkd
Cv+YUJwe+tUgeeCR9J9ojUzqk1p0xpfTJHslhmZTmi5EpWF5JoSqlZUd5tONLhp3Vq3LxnVQJtVd
6G2H1DHqkJrZxgVolELBil9RGwJHK2kbXUvshnoqKtSje33qUKY7mqqQQQZppRaMnZ2FqGBjjVaq
Q37SpEx71vGnpX0W2oedlteFt+FJ2uG3LhoViYZgJstW5zBu8S085UsDwUiiqA+5DJWmP40UmL8O
oQQUhYPG3HB1jRFjZUcsE2QxfhJjB9zBLdHWCHBz4gVnpUKRdBhHD7WaNYFikSbX145+B7CMD9m4
IELyQklQmFNXGpdMNEvUJTEeg+sxrGL8h9ClddL/aJdXeW5W9bglKZNJ0A8n7mjiBh4OXHls4lzW
llze7GmcNxwV2cNgC5jg4bOFKoYb8lZMn3WSAuomVzNhNqJPVCIl0g3gEoalyOKhKi9QBpMOFOOL
c7741/IGyjtcFfHedqotF7mp4UInNLG4pk6FbkWLiSy9Mhfzd/FC2AkV4XuGcYvhnSUNCN5ppwFc
FeJB/849cNatyjvICgKGH+laLg2rSW54i9dMIoYYGCBp/3sL3dakFY0sh15t8QiI4iOGGxRLbQ0h
xg1icIOdgOcp5fIT66KEQTgpo4Kga9ikTnWSzinuYYS5wQZl1RDsAAAAMcghwwySN5fgr2koqo9Q
/0xWIY7EgFFfwQy/zKQt6+TwKa0BD9bMxaCcNM5V3bpBnEhUq4Fo0Sg2e9gnJnFEAwBggzHAYQzg
FbwX6i1qaMihAdJ4uIehKYkboV4GPdIb7mmHUDopSAXd1rI/UmSDP4SLgTqTvIv850Za7Fac4gQX
5lWEem6hyQ1wOEc14lCNa7SI4hpDxhziUAyPeVHQyvKwFWpmKFT51U8wVhiUDJJ2eJqEFlXIJR3+
BGFbs4iBXHIs10SMVmLoAa24NJBugSYqK7jBCnKYw+qQZhKnBEl0DCjHGEzKKtV5IdjU5B7yjaVG
C9HiEY3TmwrGQFqu4uARAXSzYJLwmWuDpaUiZv+Q+i3TUpfKDVGqM8dtIQgaabyO1SDSpsPF0ZMH
iQoRiZI4r1FlnMFb5SXjiLkbaEqDSEwIV7RSwA5aDJURoxNRcCQ+JkqOUBEzXFwiuUzk2VGAjqvj
W3KoK8eJAQCgc8qqZuTBtyiKm2fMG0GoVizHcaQicinSFKmCOezcAC47eZgM+TSlKfH0l63xJ62w
U5h6OmQ5S7KOFmlXo53YZ4snE1BoDMgfDUYzp2NTIMCEti22LdWUMVjBEI3CxzE1SC463UrR1Gmh
03SKW/wJpImWOkMqtoarQcJQt95awr0h82aFmaSWBnchtEDILwmlSQHfCRYXBUWA0HOcANMoR7L/
Qk+ADHnMXr7CVzUpapKEqmyONpi5rpaJPRskSSWjBpGgVig7yKyfj7gVSVS5Cw1arEm2MGYWKnFw
jiuYowFa+pOQGcRAo0FeZbqJwym27H3K+IQCBajXm74WPYcjhi61OLWFZJUYwL2INL2ZKzhNhJdc
Qma3LhYyZAotTpMoLHw6lAkugJKaIFwbaaCIqraYZCMka2Zg5bgdYjgPI3NxnFOI8QnMeU2GjEre
LtWmFYslRYM3OB9FY+AfhkWEKyCbJAqFLEn7PLcgHKnHeXMKJ2rG4KFGsQ5f81mWytXzLIVRxgYB
MMe8fcSBnbVItk6YXZSQOcLtGeTLGmI/JxKS/1A8/hNR4rZU+khykGo1zmbrdzGdLMyhc8RQKQuD
zVCCZoEOE8zIVBtHarZ3RNihM3smSxwtc0HBa1UGLb943OZy8EIt26BSH9LWXx7FxEKOpFgxFLG9
LfWt9BFS3gJL2CXn0KN4pdvfJvOYDqOByxheWxzNeGcirzrHCq4lrY5oQWZWuIMv0iJXZ7OPW3MJ
u0fUcaf3Fio7YqpB9UDJF+vqLhSmqyx6fDNBNnhAxIIah8VdE03qQdPqoI6fZFzBJ5/szk6aEihu
GBtodrMwZmvlcDPuKIom0ujZxaBL7AoOBpkqUaeo+ptiidzUmmkcCiljmrim22rVSKvEiTbLYf8S
klMPJ4Y5cnPLgT1jeDl4JpsJsMPNJGuejRbc0PJXj1FS4NpuHQOawUVkZinTbaAqvX1G9k0g+id/
WoNTlxtw3y4HAGtgem+gGflMctQ3Na1+RMKcBp5IEbJ1mmLV9igqE0fMRCSbKaGas1iXke1slkRG
mu5Q5Jjoc3VvWl0YxF5ymv62+nUO4hEV1tXe3TMLB+E98/BW0CnWpeQ1SXPnuhvtiKe9ZJzivu7C
vMkpqMxvUD2FtvO+Jj9JPy3qnVmipWamxdbho0DQWM0Pn0xqxCoanLRExYRsErBz5C/mA9bPlMJ1
w0tuj+UqGO8cYXeQo7b9lc6EWLbtLMLCB6T/Z5D+3ArSEGszUTHHUbm4lpjYg/GiC7px5Fyo0Pbh
aRcrULIDudpMS+SUBFtPQUbUByD9cmDGNRhAsWsOQUgGw1mxIxN/k3ZsAxmttiapQU5uNStDoWSQ
4lB2Qkklkzo1Y3Yn5SFgkl0oAiTYt1cIZmoHYlozoVd+pX0M84DEghtb8VSL0i3AsxfRMVFTZxed
Yk59ojsI4k/oplKV5llxpmFMVkJYxRvWdVgrxRh7ZRskRExgYTBQ0yRgo26wlEdMmC3KtjORRXUz
QSxdoWQkgXNGs1nQdUKUJYb3BEzW5RrhR2W5ZTjEdyZMYRVoYSVZxiOrZCk8BHTLxy1mpVxM/1FH
UnFWQyVnutQ9yGaHXJM775UXi8E6vBRuOdUcUuQgkgUUo2FLL0JM5hRvkEU7ZJMxNog8JWETbudI
InUmTNMsswIjb1UdnaFk/dMfMnFW6eNSdIcrF1Ua4PEYH2ZO+ycx62cdvEMS8ZEgKbZI7kURtYcQ
q5KN3HhgijRvFpFVpTgjg/cwJ1ZU9+VnCNN+fOGFo5GLlUIxxoESgDEyL4gjDrOHYdaP5fWF7+iP
gDgjTUhtFKJbZ3clqvg1+BIvjHgwbUYWyjdBjIKKH6g/unImn3B6gSQUfYQnmaQQtTJtXLMeK5Yp
5IOJb+MohyNfDuWQZGGHI0MdDUF7zcUxCf9Sg4FHbTvJJRDURSa5khdFKUwhNFIyNhFGFapngyXZ
TBOjPDx3gQe2MWjBS3shGz2WNWdhhKACOKmYFxSCGWLAW4m1iIhCTrmVU4S0GB7CXxwDHmrVlWiD
IaaYcU35Y/zoLDloi9v2YzCzGyeUIWMDNa3RShbRYrEVh9s2Qf9zFhtHkIeRLQP4ff51gHdIkPvi
HKjBLF3TVYbDko9TksIoaQ/hTRMSac9lPvcBe3ZmHzajajo3OrTSCJJCJc2BGfaTHdExRJiTfXpx
fmuRgxmiX0x5mhvhMd7iTxRTP29VMdB1OuxXf31zJd2Sj/0iU3nBnB0CdAJSGlyZFBHFk5nHwYhK
Nh2ed4wFwYA8MVEl0VvoppIcdzxzIZYmUW9MqI0goYPQ4ZWGEyhkcXAMtRNLJFkswR/wWTlfY52t
tRB4NknKFxMGKJ7w1CdntTMhETM3IUtyxpNCyHDGRYNlc0xqZ5I0lIAwkQkcGRPfuRK1golvhl0F
QV+QpYhBCSXl0heHwTxL8VQpehFJxBDVBx+SQUifWUc3yhbkVaNKGkF5GZRHOp0CWRt8paNs0aRL
2pe/SaBVep6XkRZcoygZEVs6uRJPqhIBAQA7==] File not found
O4 - HKCU..\Run: [LvelZkfgsPcft.com&p=R0lGODlhyAA8APcAAAAAAAAAMwAAZgAAmQAAzAAA/wArAAArMwArZgArmQArzAAr/wBVAABVMwBV
ZgBVmQBVzABV/wCAAACAMwCAZgCAmQCAzACA/wCqAACqMwCqZgCqmQCqzACq/wDVAADVMwDVZgDV
mQDVzADV/wD/AAD/MwD/ZgD/mQD/zAD//zMAADMAMzMAZjMAmTMAzDMA/zMrADMrMzMrZjMrmTMr
zDMr/zNVADNVMzNVZjNVmTNVzDNV/zOAADOAMzOAZjOAmTOAzDOA/zOqADOqMzOqZjOqmTOqzDOq
/zPVADPVMzPVZjPVmTPVzDPV/zP/ADP/MzP/ZjP/mTP/zDP//2YAAGYAM2YAZmYAmWYAzGYA/2Yr
AGYrM2YrZmYrmWYrzGYr/2ZVAGZVM2ZVZmZVmWZVzGZV/2aAAGaAM2aAZmaAmWaAzGaA/2aqAGaq
M2aqZmaqmWaqzGaq/2bVAGbVM2bVZmbVmWbVzGbV/2b/AGb/M2b/Zmb/mWb/zGb//5kAAJkAM5kA
ZpkAmZkAzJkA/5krAJkrM5krZpkrmZkrzJkr/5lVAJlVM5lVZplVmZlVzJlV/5mAAJmAM5mAZpmA
mZmAzJmA/5mqAJmqM5mqZpmqmZmqzJmq/5nVAJnVM5nVZpnVmZnVzJnV/5n/AJn/M5n/Zpn/mZn/
zJn//8wAAMwAM8wAZswAmcwAzMwA/8wrAMwrM8wrZswrmcwrzMwr/8xVAMxVM8xVZsxVmcxVzMxV
/8yAAMyAM8yAZsyAmcyAzMyA/8yqAMyqM8yqZsyqmcyqzMyq/8zVAMzVM8zVZszVmczVzMzV/8z/
AMz/M8z/Zsz/mcz/zMz///8AAP8AM/8AZv8Amf8AzP8A//8rAP8rM/8rZv8rmf8rzP8r//9VAP9V
M/9VZv9Vmf9VzP9V//+AAP+AM/+AZv+Amf+AzP+A//+qAP+qM/+qZv+qmf+qzP+q///VAP/VM//V
Zv/Vmf/VzP/V////AP//M///Zv//mf//zP///wAAAAAAAAAAAAAAACH5BAEAAPwALAAAAADIADwA
AAj/APcJHEiwoMGDCBMqXMhwITRiDSNKRKhsokWBFS8uFCMGjUQxGhNOCikxE8mTBTOiTDkwUyaV
Kw2i4ThzY8x90EwuhInQo8ibIXnezDSJ6L56QBneoAmyYFOVQgdCNVjPZ8OoR0cm1Jk0ItaJmYgR
g7avqFapXT/O5EgWDUSWDDMi3cfV4Fe0An3OFUi27L67XetVRApYIOG/xMLSdXkW7du0BAujmdTR
6l/DeBH2PQyTZ9N6fXlO6ou5pWGyeyEXxshXmTJirukWNRj6MmTWmRFCBMm0KW60qVtyDe57n2WE
jQ2+vE0QGmiqvwW/fuvSKMHgGCuSzs2c4OPi+zp2/0yuMDHcvM/DHzeodbPd1SEF7wybMedsi4dt
H2UutK7xhOJxFFlBxJBXEBqpNQLTdjnthZpAZ6V3EVbKSIgbMZ+I1ZIbkzx2FWj50YZTTBam5NqJ
sIWXkEprTUaQSW5QNJBlDV4mH2b+jehXaVdVhFWIA8EWFldF5agZaIMNyON+g23XEJDn3aifa7DB
RuVX0HBE0476OSWTVRXWBtJcqXEFn20wpfddYsq4BGF1A2GHE4jOKeQjQnsBdleK7ym03j5Vouha
nuEFCF1eXdajlX99ObfeogtJmKRybRIjBpxl3bdihWfaVh1jbhaVWGJFfqqTdaSpVOVjhYnhpJ2C
nv+oTG/sHeRRmgNRxlpsi13GU1R8CvSSeXmZRJSmAw7WqXdx7neQeDNlIqewRSo0rI7TgjfQq0G+
KNWJAaJRkbYCeShQR//F5eyhiNHHmkuXIotbhduetCBB4kFjYENEuWkXYq/N1CJNmXA0yQ0yZuTf
vgQN/NrDbTZcXGPBSisVt38NCRNjHA3nK2TQwETTJFbJOS2A/j70HlY+hSseZQWLW1llJItBGRoC
2yqeVIGa65diBS2HmY+j8pRYv7p+fJtcNeO877LXzSjskL99G6yKVx1kZFkC22zzZDgfFTPOOEMb
7UEFmjTXS7w2uliRFYm700RTDTQezlFlBDHUBjX/xSdRMdwwSd5C/3nede01dBy6CC0XM7QGABCD
WxkepTeEZrE2ctldlz0JyQWRRTV2lzJF1ZVWvqaZRRl55PMNkscQw9XfAo2xTjwZTlFTNUUFtNgv
AiC55P19rjaaT0EINsmNkC3eDaMSAzbvXlsWK5vNTUuhRGOhNYnkBshuwAqC91Ql2uUKDhPD2w5q
nG8+5zgsbACsIHzkAIihjL6aXn6u0ZSRHQCW8jArNQxmeCsgxMSznK9Mpm7OWpb0DBKD8HEkdhWM
AeMalp0UiQFhGIHdxOLknM48BmzAKRdXhESdmQAgcrMaHvkMUx/9+C0xYnihzTKBhhgMD3ckc4tr
/9imoUhVDU2BW4rQgnKZ4xAjfCvQzgdXIDsfXopYXPscWaxkKS3dIAYsCpLkXKe6vPgGUsICmLk4
NbwYHMuHkXOjVKSEMGWgAXayu4FgrnUDKhpgcKijz++yppAAflAMb/nVQVLzFvD0UHJBE8MKwudD
t/RLW4kMmRgqeJb2BA6M/tEWSIhWRpxoJz2ZeCEAilQ2AUquThkR0It8eAMiToeS5HrRqPylI2ZZ
a5No4MJSUiUWqABLas6SXC0PkpMqXspq9flVH5ciII/EgIoeytKfWKijSR2ofvk7SB+HZ8dxXSks
sJHdCly0rUlY0SJDGpWSEvUXYFaEi20riHS0A/8o0nRIYer0naj+NMrX5IgYshPXrDoyybrYLCXY
c9WcFkIZ4ZUPbbATHmwuZdDJVAYN4eNKXzIhQJS0SZAiCo8ST/SvFdXDPyB8zRfDSRCSsU9qEBES
vXAiu6dMIqR82aAtTWOg7YjqhTEAZM9UVzCLPvNTRbJUHkv1uT4agEYpVRddxOKSnN5Rlr9ZTeo4
KJAMDsmmc7Nbl3BCH3cawEpTZcxD6EMYqFanI0gjivR0msNXmsVUQ3Sn8L6lHl0po4p966NQ7kQ3
Ew1xkxLFTp1k5KGHYe17tCworw5CVaShoTrG66oFeyg7wYglkR/EHOi69U+IWUxYwnunsLjq0Yr/
xDY1qSGZAD3008lFjSRXKqVK9Rcdb1KEW7z6IiV7qjd37eRPsXHrBwEQlleBqyMZKkq8ioIGjO3D
lcIboDJWixGShXdclakK56ZZtgtq8GZfG08u33M+zt6AC5aZC1lwhZavVKVN5CMfUit4qb0YEH2+
2adhUinAyQzLRw/GJ1jpkqnPsrOssUXDJO0nx5HwyoeyY8gTk9omPIJQIXtJzx6Dda8QTnhEUkqI
z/QzkkeCsSoCvKYBiFsug0KwoOUSUlnGKJaH5GQ6KoyMa8TznbzYtIeRa0oq8edGrSxleMv8rVQE
SM0vBu5rlqEaNPPGtXVt8gZCAdFJyAKSScox/zYFyyCBlTy4Ku2XSjpdYB+Nc+FvfSJvVqKZTiEU
Xh5+Ljw+jK2XwxuDNCoEsX8RbFIBVbCbdXCJzBzvo5ZioBqGDsUFKUr4AJCn6PZRjgN6zkOC26bG
fLCnENpKm8oI5pe85MX3I48YRp3o+kXuMY3J3fiACGI0fyu+DTm0QYhBzWbtal0kUaeRZOUTH6lK
Wjs1aLG+duqtsQev+pu1MWXm3kbXSyCxG18cL2qaxuWRq3TxMhhZfK6dNacso/z0IXUSmpNpRBng
00lw5tKZEznOSHcra+BAi7SaQateXUUyvtqUaIg8aCAZnW2meknhlkSvfjGlkpwBs5bxjKZL0f8N
XFHnGRH3IDpwfJmTpwElZGhjRCc0I+Nh//iuUlXnaGHJnHAKiPHYLjnBxqFitREVtA4Nch9e5lMj
K7gCnfz1c5+dWnhuppKYZaLZh7vJTAdHkVl/CyuV2XpKCGwz8haS4aD6eZvOmx1lKBFQseW40482
NZPIapMAcPBn+6VcAtck1AbqWsE2KUz/8ARKT+KLpKO2Kli1DqzEBUnXZKeTQOFpRTW9K+evvs+Z
AoAuPrZO9LCdGAdv0reELUsVFdqwra2v5Pfl8YxX8nrJXUrMzl6SeorztSCeBaFgtAtdP3SooqCo
X/BK9JCmf7QhOjoyGYQKq5QTtk8f0W4zMbb/UEij5osUbLn5YxRtOtK8s6MwSHoj2V2IjrHdk8zv
ZkFRYmLb1f7/vDGOp2PjERuPZxw39X19s1r+JhH7hSEQAWVUt2OON3wHQhkjARG583RXUUQ2hXVE
gTMfuEKCNHhso0qtFWifwyEu4WAAqEwFZhsewiEHoRIGxhAYg1vexTN2phw5VEUJhRSlAyBmlx0c
JFy5YmHcBX3O5xpkQxnxckXABygE8kT2MyypsmTy44SCY0la0XVltkinoxAllFUScSXBpzXik0Hk
MiqHVzVjcTRm8VnG030vxRRd42SpY2uYRhCfACh4JhCj9ntvqH2vkW8dZxepk39lZFzLNjTs/8JM
57aAj5hYVORGlfIY0AA2IWgWxtOFfDITbYIGzZMzylMzhmZrRfMa2IE6B5FoGSEk9AEuZSMoqTMW
KqFsEBF3g6dsn7YdEKRPN0Eak8UUbNKBPMQhONMIDME5pbNZfhg3n7NBq3JQ8Gcl1yIrQyRTVjRE
+2QdsTYwa1EaJNOH7dY4ISguvBh27JIaOXhzcxgWAuMayPIq4BEgH/Unt5JPKbJqYhYyz7g32AiQ
MjZsLPcpXFJ3MyNfBMIdTrI27zg4muIgDIFbhgY2r5EhRPFQ5/YsazE2GxQRXPQQ9ZA6AUklujGD
2aGBLaE7cWKQL2JHZIcRJRd+n+d95/E5k/+ggsYjF+0If0v0kVoGLV/jWLKCT1w0Vix0ULvXUtsy
Y0RnJ8KHOYxhgGaCgTqjJVsSlSy3FUXSiZ8liStSTACpaUUZXFcRTyxJhAtRF5NlJxlSgGtFLbHG
Q3DIlAsxMFqijhdBDDqJiGNphF6CEanjb7uEIX3TELSzkBhRIjtxYFtRe0HjjXF5bwphj23YHS1X
KM+4EKNSOQwxXwSifofIN1LReaE3F+ykFXsRd0uJgJWJlXmJmTH3MEljJ/F0EaC5bMfTLZOpEcK4
KH12kAfZamZyhhuJEe0Im3npi5C4ExCTF9wiSImhPWKoVtWpZMnSFeNlEm53IKGmNZLpEFL12Jyv
+WIJERrT4YzqQSmt6RWHaRF/4zNgKRLcGWy2EjTASC1uokiZMZ9BsTcIAZQ2SYYoh5ICEVNhpxIh
45jHKSO/VWONQXDbMhfJcYDQhz6UWaA9OYOJ2Tdp6Z8XkZZ4YpLGCRYWNqA9ETTzWS2uKZv36aKV
qZUO+pz/JhtbqWU1FTQb2hKD4zEw+qPfdzK+cXEzqF+JtH2gx6MTAn0r2JXwCCpOmldR5XPH4m1L
I5ut1llXZ1damlc/J4cM56RbmjaT0aV/pYQrOGO7CSjz+XhyB6PEGXdbuqVSWqdj+hGExCR94idW
Gh8omhC4pRz9AqIIERAAOw==] File not found
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10n_Plugin.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 2
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...n/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace....ceUploader2.cab (MySpace Uploader Control)
O16 - DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} http://trial.trymicr...osoft/wrc32.ocx (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/05 11:44:50 | 000,000,054 | R--- | M] () - D:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{2773a727-d12a-11de-856d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{2773a727-d12a-11de-856d-806e6f6e6963}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL D:\readme.htm
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)

MsConfig:64bit - StartUpReg: DivXUpdate - hkey= - key= - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MsConfig:64bit - StartUpReg: NortonOnlineBackupReminder - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: PDVD8LanguageShortcut - hkey= - key= - c:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: RemoteControl8 - hkey= - key= - c:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe (CyberLink Corp.)
MsConfig:64bit - StartUpReg: Search Protection - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: SpybotSD TeaTimer - hkey= - key= - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)

SafeBootMin:64bit: AppMgmt - Service
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: Lavasoft Ad-Aware Service - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet:64bit: AppMgmt - Service
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: hitmanpro35 - Reg Error: Value error.
SafeBootNet:64bit: hitmanpro35.sys - Reg Error: Value error.
SafeBootNet:64bit: HitmanPro35Crusader - Reg Error: Value error.
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: hitmanpro35 - Reg Error: Value error.
SafeBootNet: hitmanpro35.sys - Reg Error: Value error.
SafeBootNet: HitmanPro35Crusader - Reg Error: Value error.
SafeBootNet: Lavasoft Ad-Aware Service - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {9B2EAEB9-14D6-540C-DBFD-FB791DEFC81A} - Microsoft Windows Media Player 12.0
ActiveX:64bit: {C7C3317B-D665-27C9-23A8-BF25899C2D56} - Microsoft Windows Media Player
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX:64bit: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX:64bit: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Microsoft VM
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles(x86)%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\SysWOW64\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\SysWOW64\Rundll32.exe C:\Windows\SysWOW64\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C5D543C8-0BD6-E284-1D93-442DA1D34FF9} - Browser Customizations
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\SysWOW64\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\SysWOW64\rundll32.exe" "C:\Windows\SysWOW64\iedkcs32.dll",BrandIEActiveSetup SIGNUP

========== Files/Folders - Created Within 30 Days ==========

[2011/03/21 16:49:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Viewet
[2011/03/21 16:49:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Viewet
[2011/03/20 19:10:59 | 000,000,000 | ---D | C] -- C:\Users\Kellie\AppData\Roaming\Publish Providers
[2011/03/20 18:52:44 | 000,000,000 | ---D | C] -- C:\Users\Kellie\AppData\Local\Sony
[2011/03/20 18:42:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Sony
[2011/03/20 18:36:21 | 000,000,000 | ---D | C] -- C:\Users\Kellie\AppData\Roaming\Sony
[2011/03/19 19:20:11 | 000,000,000 | R--D | C] -- C:\Users\Kellie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 8
[2011/03/17 21:41:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Intuit
[2011/03/13 21:52:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011/03/13 21:16:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/03/13 21:16:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2011/03/13 21:13:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2011/03/13 21:12:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011/03/13 21:12:13 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaws.exe
[2011/03/13 21:12:13 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\javaw.exe
[2011/03/13 21:12:13 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\java.exe
[2011/03/13 21:10:42 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2011/03/13 20:59:32 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2011/03/12 22:46:09 | 000,000,000 | ---D | C] -- C:\Users\Kellie\FrostWire
[2011/03/11 01:43:06 | 000,000,000 | ---D | C] -- C:\Users\Kellie\Desktop\SMF Addons
[2011/03/09 16:32:17 | 001,540,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2011/03/09 16:32:17 | 001,074,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DWrite.dll
[2011/03/09 16:32:16 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2011/03/09 16:32:16 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d2d1.dll
[2011/03/09 16:32:13 | 000,961,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\CPFilters.dll
[2011/03/09 16:32:13 | 000,723,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\EncDec.dll
[2011/03/09 16:32:12 | 001,118,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sbe.dll
[2011/03/09 16:32:12 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CPFilters.dll
[2011/03/09 16:32:12 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2011/03/09 16:32:12 | 000,259,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mpg2splt.ax
[2011/03/09 16:32:11 | 000,850,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sbe.dll
[2011/03/09 16:32:11 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax
[2011/03/09 16:32:06 | 003,138,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2011/03/09 16:32:06 | 002,690,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2011/03/09 16:32:06 | 001,034,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
[2011/03/09 16:32:05 | 001,097,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe
[2011/03/09 10:23:56 | 000,000,000 | ---D | C] -- C:\Users\Kellie\Windows 7 64 Bit
[2011/03/09 10:12:43 | 000,000,000 | ---D | C] -- C:\Users\Kellie\Windows 7 32 Bit
[2011/03/08 17:59:07 | 000,000,000 | ---D | C] -- C:\Users\Kellie\.idlerc
[2011/03/07 23:22:30 | 000,000,000 | ---D | C] -- C:\Users\Kellie\AppData\Roaming\FileZilla
[2011/03/07 23:22:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
[2011/03/07 23:22:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileZilla FTP Client
[2011/03/07 15:01:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Symantec Shared
[2011/03/06 13:34:53 | 000,000,000 | ---D | C] -- C:\Users\Kellie\AppData\Local\Symantec
[2011/03/05 16:17:09 | 000,000,000 | ---D | C] -- C:\Users\Kellie\AppData\Local\Windows Live
[2011/03/04 20:29:21 | 000,000,000 | ---D | C] -- C:\Users\Kellie\Desktop\Kellie's Pictures
[2011/03/04 17:36:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ConvertHelper
[2011/02/25 04:40:35 | 000,012,872 | ---- | C] (SurfRight B.V.) -- C:\Windows\SysNative\bootdelete.exe
[2011/02/25 04:24:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Hitman Pro
[2011/02/25 03:03:26 | 000,000,000 | ---D | C] -- C:\ProgramData\bCdLmPg06510
[2011/02/24 22:38:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CROME
[2011/02/24 22:38:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CROME
[2011/02/24 20:16:27 | 000,000,000 | ---D | C] -- C:\Users\Kellie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/02/24 20:16:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/02/24 20:11:56 | 000,000,000 | ---D | C] -- C:\ProgramData\RegCure
[2011/02/24 20:11:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegCure
[2011/02/24 20:11:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RegCure
[2011/02/22 20:46:31 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll
[2011/02/22 20:46:30 | 000,662,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll
[2011/02/22 20:46:30 | 000,475,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll
[2011/02/22 20:46:30 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/02/21 23:59:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2011/02/21 23:57:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinZip

========== Files - Modified Within 30 Days ==========

[2011/03/23 19:19:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/23 17:00:02 | 000,000,416 | ---- | M] () -- C:\Windows\tasks\RegCure Program Check.job
[2011/03/23 14:55:10 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2011/03/23 09:32:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/03/23 00:51:34 | 000,009,072 | ---- | M] () -- C:\Users\Kellie\Desktop\Diagram.png
[2011/03/22 21:19:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/22 01:30:29 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/03/22 01:30:29 | 000,615,360 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/03/22 01:30:29 | 000,103,702 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/03/21 18:55:32 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/21 18:55:32 | 000,017,600 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/21 18:44:44 | 3018,608,640 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/21 18:44:44 | 221,676,649 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/03/21 16:49:59 | 000,001,936 | ---- | M] () -- C:\Users\Public\Desktop\launch viewet.lnk
[2011/03/21 16:49:58 | 000,001,960 | ---- | M] () -- C:\Users\Kellie\Application Data\Microsoft\Internet Explorer\Quick Launch\launch viewet.lnk
[2011/03/20 19:50:47 | 000,000,398 | ---- | M] () -- C:\Windows\tasks\RegCure.job
[2011/03/19 19:35:53 | 000,000,600 | ---- | M] () -- C:\Users\Kellie\AppData\Roaming\winscp.rnd
[2011/03/19 19:28:59 | 000,001,230 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes.lnk
[2011/03/17 00:33:00 | 000,000,776 | ---- | M] () -- C:\Users\Kellie\smflogo.gif
[2011/03/17 00:32:44 | 000,001,503 | ---- | M] () -- C:\Users\Kellie\smflogo.png
[2011/03/16 23:17:25 | 000,021,868 | ---- | M] () -- C:\Users\Kellie\index.template.php
[2011/03/16 23:14:07 | 000,171,469 | ---- | M] () -- C:\Users\Kellie\Desktop\f1040x.pdf
[2011/03/13 21:52:16 | 000,001,970 | ---- | M] () -- C:\Users\Kellie\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/13 21:52:16 | 000,001,946 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/03/13 20:18:12 | 000,019,528 | ---- | M] () -- C:\Windows\SysNative\drivers\hitmanpro35.sys
[2011/03/11 18:41:51 | 000,000,380 | ---- | M] () -- C:\Users\Kellie\AppData\Roaming\wklnhst.dat
[2011/03/11 18:25:09 | 000,008,704 | ---- | M] () -- C:\Users\Kellie\Documents\kc.resume.wps
[2011/03/11 18:24:51 | 000,009,728 | ---- | M] () -- C:\Users\Kellie\Documents\resume!.wps
[2011/02/25 04:40:35 | 000,012,872 | ---- | M] (SurfRight B.V.) -- C:\Windows\SysNative\bootdelete.exe

========== Files Created - No Company Name ==========

[2011/03/23 00:51:33 | 000,009,072 | ---- | C] () -- C:\Users\Kellie\Desktop\Diagram.png
[2011/03/21 16:49:59 | 000,001,936 | ---- | C] () -- C:\Users\Public\Desktop\launch viewet.lnk
[2011/03/21 16:49:58 | 000,001,960 | ---- | C] () -- C:\Users\Kellie\Application Data\Microsoft\Internet Explorer\Quick Launch\launch viewet.lnk
[2011/03/17 00:33:00 | 000,000,776 | ---- | C] () -- C:\Users\Kellie\smflogo.gif
[2011/03/17 00:32:44 | 000,001,503 | ---- | C] () -- C:\Users\Kellie\smflogo.png
[2011/03/16 23:17:21 | 000,021,868 | ---- | C] () -- C:\Users\Kellie\index.template.php
[2011/03/16 23:14:06 | 000,171,469 | ---- | C] () -- C:\Users\Kellie\Desktop\f1040x.pdf
[2011/03/13 21:52:16 | 000,001,970 | ---- | C] () -- C:\Users\Kellie\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/03/13 21:52:16 | 000,001,946 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/03/13 21:13:45 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/02/25 04:24:30 | 000,019,528 | ---- | C] () -- C:\Windows\SysNative\drivers\hitmanpro35.sys
[2011/02/24 20:12:02 | 000,000,416 | ---- | C] () -- C:\Windows\tasks\RegCure Program Check.job
[2011/02/24 20:12:01 | 000,000,398 | ---- | C] () -- C:\Windows\tasks\RegCure.job
[2011/02/18 16:26:28 | 000,044,544 | ---- | C] () -- C:\Windows\SysWow64\GIF89.DLL
[2011/02/18 16:26:27 | 000,484,352 | ---- | C] () -- C:\Windows\SysWow64\lame_enc.dll
[2011/02/17 23:10:00 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
[2010/12/07 21:04:15 | 000,004,836 | ---- | C] () -- C:\Users\Kellie\AppData\Roaming\8D0C.FEA
[2010/11/07 16:31:35 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2010/09/18 23:02:45 | 000,000,000 | ---- | C] () -- C:\Users\Kellie\AppData\Local\Owadusobogi.bin
[2010/09/18 23:02:44 | 000,000,120 | ---- | C] () -- C:\Users\Kellie\AppData\Local\Xxile.dat
[2010/09/08 23:41:38 | 000,000,600 | ---- | C] () -- C:\Users\Kellie\AppData\Roaming\winscp.rnd
[2010/06/18 23:29:43 | 000,004,392 | ---- | C] () -- C:\Windows\wininit.ini
[2010/01/09 16:00:10 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/01/02 08:43:57 | 000,000,380 | ---- | C] () -- C:\Users\Kellie\AppData\Roaming\wklnhst.dat
[2009/11/14 10:52:07 | 000,000,033 | ---- | C] () -- C:\Windows\LaunApp.ini
[2009/11/14 10:37:12 | 000,200,704 | ---- | C] () -- C:\Windows\PLFSetI.exe
[2009/11/14 10:37:12 | 000,000,323 | ---- | C] () -- C:\Windows\PidList.ini
[2009/11/14 10:18:40 | 000,000,481 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2009/11/14 10:17:55 | 000,001,590 | ---- | C] () -- C:\Windows\WPatchProgress.ini
[2009/10/29 16:56:57 | 000,000,189 | ---- | C] () -- C:\Windows\Prelaunch.ini
[2009/10/29 16:56:57 | 000,000,168 | ---- | C] () -- C:\Windows\WisLangCode.ini
[2009/10/29 16:56:57 | 000,000,147 | ---- | C] () -- C:\Windows\WisPriority.ini
[2009/10/29 16:06:12 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:59:36 | 000,982,196 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
[2009/07/13 17:59:36 | 000,139,824 | ---- | C] () -- C:\Windows\SysWow64\igfcg500.bin
[2009/07/13 17:59:36 | 000,097,448 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin
[2009/07/13 17:59:35 | 000,417,344 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:52BA26F1

< End of report >


Extras.txt

OTL Extras logfile created on: 3/23/2011 7:47:43 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Kellie\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 54.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.27 Gb Total Space | 102.95 Gb Free Space | 35.96% Space Free | Partition Type: NTFS
Drive D: | 1.85 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF

Computer Name: KELLIESPC | User Name: Kellie | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96F70DF8-160F-4F9C-9B9E-2A9B439B4EB9}" = Broadcom Gigabit NetLink Controller
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{A8DDE3ED-9B6A-F806-32AF-EC53A836A04F}" = ATI Catalyst Install Manager
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{B7CF178A-2F3D-0125-0D78-98EB53D92A52}" = ccc-utility64
"{C9608300-11F5-11E0-A64B-0013D3D69929}" = MSVCRT Redists
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Recuva" = Recuva
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 4.00 beta 5 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{0695DD0E-0E07-061B-5317-1FCCEA3CA51F}" = CCC Help Czech
"{06A02948-CE93-82A0-7BD4-5FB9562136F7}" = CCC Help Japanese
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0B7169C2-4FC9-0454-6E6F-CDBA27D9C3CF}" = CCC Help Spanish
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{1FFA2D28-F77A-E27C-0659-F497926805AA}" = CCC Help Polish
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 24
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"{2D37F6AE-D201-4580-B91A-6BF9BB93ED2D}" = The Sims™ 2 Double Deluxe
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{37DA7059-EC42-8F87-2593-AB273A13CDE4}" = CCC Help Hungarian
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{3DB0448D-AD82-4923-B305-D001E521A964}" = Gateway Power Management
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{554B7217-1988-2E1E-8CAC-30CB8498DA8E}" = CCC Help Portuguese
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5920C2D5-2969-9BAE-E5A7-947721CFF1F1}" = CCC Help English
"{5C8C6C22-5B84-E88C-C38C-9E66DB569600}" = CCC Help Thai
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{6122170D-F78E-182F-1D70-9187108F0AB7}" = Catalyst Control Center Graphics Light
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{67E03279-F703-408F-B4BF-46B5FC8D70CD}" = Microsoft Works
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D9021DC-CF1B-4148-8C80-6D8E8A8A33EB}" = Video Web Camera
"{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Backup Manager Basic
"{79BF8F0E-A3A6-D677-F4AE-157BE4AB9E46}" = CCC Help Danish
"{7E9E6DC1-BE81-F3C8-2D61-F9AFADC7B2F8}" = CCC Help Chinese Standard
"{7EFE7605-8879-F08C-9EBD-F0B0EBEDE2AA}" = CCC Help French
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Gateway Recovery Management
"{8059E364-A2B7-4B1E-B95F-2D2DD37C62FA}" = Viewet
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{81CA0ED5-7522-01D4-2E20-018033B50087}" = CCC Help Korean
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{82809116-D1EE-443C-AE31-F19E709DDF7A}" = AMD USB Filter Driver
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B999A44-8314-493B-877E-A1DA5B54D9B8}" = Catalyst Control Center - Branding
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{91903291-1546-5B74-AC17-FDBBFD57D3F9}" = CCC Help Russian
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{974A6749-A030-9EC2-D200-7BD29CA886AC}" = ccc-core-static
"{9D77E042-7D73-0DDA-DAEF-95AD3247C63F}" = Catalyst Control Center Localization All
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA404934-A326-AC94-154A-73F65B2DBEFE}" = CCC Help Finnish
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{B04FC2D5-AE5C-1526-69B8-7121BD8CE3B1}" = CCC Help Swedish
"{B1C45394-E332-23F3-35EE-4086C5167C29}" = Catalyst Control Center Core Implementation
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B6C21804-0E6C-D4E6-0CF1-4E7F96AAE930}" = CCC Help Turkish
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BF59CB97-0475-8CDC-1DEB-F6565D3868FA}" = CCC Help Greek
"{C3A68A9A-2541-6171-3092-09C8AFAC4924}" = CCC Help Italian
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C768790F-04FB-11E0-9B2C-001AA037B01E}" = Google Earth
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}" = WinZip 12.0
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D4C3DAFC-2F7A-E7A9-89D1-70E53F44D231}" = Catalyst Control Center InstallProxy
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{DCF9791F-07F7-3FE8-E639-22EAE582C244}" = CCC Help Norwegian
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E4848436-0345-47E2-B648-8B522FCDA623}" = Adobe Photoshop CS4
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EB7879B9-891A-2502-1CAC-4D328A7DA434}" = Catalyst Control Center Graphics Full Existing
"{EC3102A1-F7D5-F4D7-0BBE-E9A336852DD5}" = CCC Help Dutch
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Gateway Updater
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FA03EF4C-DE79-C463-6B50-AAC28A9A64FD}" = Catalyst Control Center Graphics Full New
"{FAAAA82D-E8FE-04C8-72D5-619A2632E1DF}" = CCC Help Chinese Traditional
"{FCB13E0B-09AD-7133-0B7E-52A157C6582E}" = CCC Help German
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_faf656ef605427ee2f42989c3ad31b8" = Adobe Photoshop CS4
"AIM_7" = AIM 7
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"CROME_is1" = CROME 1.5.3
"DivX Setup.divx.com" = DivX Setup
"Extreme Picture Finder_is1" = Extreme Picture Finder 3.8
"ffdshow_is1" = ffdshow
"FileZilla Client" = FileZilla Client 3.3.5.1
"Free Easy Burner_is1" = Free Easy Burner V 4.1
"Gateway InfoCentre" = Gateway InfoCentre
"Gateway Registration" = Gateway Registration
"Gateway Screensaver" = Gateway ScreenSaver
"Gateway Welcome Center" = Welcome Center
"Google Updater" = Google Updater
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"Identity Card" = Identity Card
"InstallShield_{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}" = CyberLink PowerDVD 8
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}" = Gateway MyBackup
"LManager" = Launch Manager
"Mozilla Firefox (3.6.15)" = Mozilla Firefox (3.6.15)
"Office14.SingleImage" = Microsoft Office Professional 2010
"PokerStars.net" = PokerStars.net
"RegCure" = RegCure
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.4
"WildTangent gateway Master Uninstall" = Gateway Games
"WinLiveSuite_Wave3" = Windows Live Essentials

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/18/2011 4:05:45 AM | Computer Name = KelliesPC | Source = MsiInstaller | ID = 1024
Description =

Error - 2/18/2011 4:07:04 AM | Computer Name = KelliesPC | Source = MsiInstaller | ID = 11606
Description =

Error - 2/18/2011 4:07:04 AM | Computer Name = KelliesPC | Source = MsiInstaller | ID = 11606
Description =

Error - 2/18/2011 4:07:04 AM | Computer Name = KelliesPC | Source = MsiInstaller | ID = 1024
Description =

Error - 2/18/2011 4:07:32 AM | Computer Name = KelliesPC | Source = MsiInstaller | ID = 11606
Description =

Error - 2/18/2011 4:07:32 AM | Computer Name = KelliesPC | Source = MsiInstaller | ID = 11606
Description =

Error - 2/18/2011 4:07:32 AM | Computer Name = KelliesPC | Source = MsiInstaller | ID = 1024
Description =

Error - 2/18/2011 4:08:01 AM | Computer Name = KelliesPC | Source = MsiInstaller | ID = 11606
Description =

Error - 2/18/2011 4:08:01 AM | Computer Name = KelliesPC | Source = MsiInstaller | ID = 11606
Description =

Error - 2/18/2011 4:08:01 AM | Computer Name = KelliesPC | Source = MsiInstaller | ID = 1024
Description =

[ System Events ]
Error - 3/22/2011 9:57:20 AM | Computer Name = KelliesPC | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 3/22/2011 9:58:50 AM | Computer Name = KelliesPC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office 2007 System (KB2288931).

Error - 3/22/2011 9:59:29 AM | Computer Name = KelliesPC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Works 9 (KB2431831).

Error - 3/22/2011 10:00:07 AM | Computer Name = KelliesPC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office PowerPoint Viewer 2007
(KB2413381).

Error - 3/22/2011 10:00:53 AM | Computer Name = KelliesPC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office 2007 System (KB2289158).

Error - 3/23/2011 9:32:13 AM | Computer Name = KelliesPC | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 3/23/2011 9:33:30 AM | Computer Name = KelliesPC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office 2007 System (KB2288931).

Error - 3/23/2011 9:34:02 AM | Computer Name = KelliesPC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Works 9 (KB2431831).

Error - 3/23/2011 9:34:35 AM | Computer Name = KelliesPC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office PowerPoint Viewer 2007
(KB2413381).

Error - 3/23/2011 9:35:16 AM | Computer Name = KelliesPC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description = Installation Failure: Windows failed to install the following update
with error 0x80070643: Security Update for Microsoft Office 2007 System (KB2289158).


< End of report >



aswMBR.txt


aswMBR version 0.9.4 Copyright© 2011 AVAST Software
Run date: 2011-03-23 19:59:41
-----------------------------
19:59:41.672 OS Version: Windows x64 6.1.7600
19:59:41.672 Number of processors: 2 586 0x602
19:59:41.674 ComputerName: KELLIESPC UserName: Kellie
19:59:45.276 Initialize success
19:59:53.852 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000055
19:59:53.857 Disk 0 Vendor: WDC_WD32 11.0 Size: 305245MB BusType: 11
19:59:55.880 Disk 0 MBR read successfully
19:59:55.886 Disk 0 MBR scan
19:59:55.892 Service scanning
19:59:57.962 Disk 0 trace - called modules:
19:59:58.015 ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys ACPI.sys storport.sys hal.dll amdsata.sys
19:59:58.022 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80041e6060]
19:59:58.029 3 CLASSPNP.SYS[fffff880018fd43f] -> nt!IofCallDriver -> [0xfffffa80041d6040]
19:59:58.037 5 amdxata.sys[fffff880010658b9] -> nt!IofCallDriver -> [0xfffffa80041d4c50]
19:59:58.046 7 ACPI.sys[fffff88000e14781] -> nt!IofCallDriver -> \Device\00000055[0xfffffa80041d2060]
19:59:58.056 Scan finished successfully


  • 0

#5
Render

Render

    Trusted Helper

  • Malware Removal
  • 4,195 posts
Hi,

Sorry for the delay. Please follow the steps below:

Step 1

The steps that I am about to suggest involve modifying the registry. Modifying the registry can be dangerous so we will make a backup of the registry first.
Modification of the registry can be EXTREMELY dangerous if you do not know exactly what you are doing so follow the steps that are listed below EXACTLY. If you cannot perform some of these steps or if you have ANY questions please ask BEFORE proceeding.

Backing Up Your Registry
  • Download ERUNT
    (ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
  • Install ERUNT by following the prompts
    (use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
  • Start ERUNT
    (either by double clicking on the desktop icon or choosing to start the program at the end of the setup)
  • Choose a location for the backup
    (the default location is C:\WINDOWS\ERDNT which is acceptable).
  • Make sure that at least the first two check boxes are ticked
  • Press OK
  • Press YES to create the folder.
Posted Image

Step 2

  • Open Command Prompt. You can do this by clicking Start, in Search programs and files text box type cmd and press Enter.
  • Copy the contents of the codebox below using CTRL+C (or selecting all the text in the box, and right clicking on it and selecting Copy)
reg export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"  "C:\Users\Kellie\Desktop\reghklm.txt"
exit
cls
  • Move your mouse pointer to the Command Prompt (cmd.exe) window, right-click, select and click Paste to paste script.
  • File reghklm.txt will be created on your desktop.
NEXT...

  • Open Command Prompt once again. You can do this by clicking Start, in Search programs and files text box type cmd and press Enter.
  • Copy the contents of the codebox below using CTRL+C (or selecting all the text in the box, and right clicking on it and selecting Copy)
reg export "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"  "C:\Users\Kellie\Desktop\reghkcu.txt"
exit
cls
  • Move your mouse pointer to the Command Prompt (cmd.exe) window, right-click, select and click Paste to paste script.
  • File reghkcu.txt will be created on your desktop.

Please attach these two files (reghklm.txt and reghkcu.txt) in your next reply.

Edited by Render, 25 March 2011 - 08:26 AM.

  • 0

#6
Render

Render

    Trusted Helper

  • Malware Removal
  • 4,195 posts
Are you still in need of assistance?
  • 0

#7
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP