What is WAPageViewer?
The Malwarebytes research team has determined that WAPageViewer is adware. These adware applications display advertisements not originating from the sites you are browsing.
How do I know if my computer is affected by WAPageViewer?
You may see this warning during install:

and this Scheduled Task :

How did WAPageViewer get on my computer?
Adware applications use different methods for distributing themselves. This particular one was bundled with other software.
How do I remove WAPageViewer?
Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted program.
- Please download Malwarebytes Anti-Malware to your desktop.
- Double-click mbam-setup-version.exe and follow the prompts to install the program.
- At the end, be sure a check-mark is placed next to the following:
- Enable free trial of Malwarebytes Anti-Malware Premium
- Launch Malwarebytes Anti-Malware
- Then click Finish.
- If an update is found, you will be prompted to download and install the latest version.
- Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
- When the scan is complete , make sure that everything is set to "Quarantine", and click Apply Actions.
- Reboot your computer if prompted.
- No, Malwarebytes' Anti-Malware removes WAPageViewer completely.
- This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks.
- You may be prompted twice to reboot after removal. Malwarebytes Anti-Malware needs to restore your connection after removing this LSP-hijacker.
We hope our application and this guide have helped you eradicate this adware application.
As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the WAPageViewer adware. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late.
Technical details for experts
You will see these signs in a HijackThis log:
O10 - Unknown file in Winsock LSP: c:\windows\system32\vsprotectproxy.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\vsprotectproxy.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\vsprotectproxy.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\vsprotectproxy.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\vsprotectproxy.dll O23 - Service: VSProtectProxy - Visual Protect - C:\Program Files (x86)\Visual Protect Service\vsprotectproxy.exe O23 - Service: Visual Proctect Updater (VSUpdater) - Visual Protect - C:\Program Files (x86)\WAPageViewer\VSUpdater.exeYou may see these signs in FRST logs:
(Visual Protect) C:\Program Files (x86)\Visual Protect Service\VSProtectProxy.exe (Visual Protect) C:\Program Files (x86)\Visual Protect Service\VSProtector.exe (Visual Protect) C:\Program Files (x86)\WAPageViewer\VSUpdater.exe Winsock: Catalog9 01 C:\Windows\SysWOW64\VSProtectProxy.dll [331776 2015-09-17] (Visual Protect) Winsock: Catalog9 02 C:\Windows\SysWOW64\VSProtectProxy.dll [331776 2015-09-17] (Visual Protect) Winsock: Catalog9 03 C:\Windows\SysWOW64\VSProtectProxy.dll [331776 2015-09-17] (Visual Protect) Winsock: Catalog9 04 C:\Windows\SysWOW64\VSProtectProxy.dll [331776 2015-09-17] (Visual Protect) Winsock: Catalog9 15 C:\Windows\SysWOW64\VSProtectProxy.dll [331776 2015-09-17] (Visual Protect) R3 VSProtectProxy; C:\Program Files (x86)\Visual Protect Service\vsprotectproxy.exe [4229120 2015-09-17] (Visual Protect) [File not signed] R2 VSUpdater; C:\Program Files (x86)\WAPageViewer\VSUpdater.exe [1001472 2015-09-09] (Visual Protect) [File not signed] C:\Windows\System32\Tasks\VSProtector (Visual Protect) C:\Windows\SysWOW64\VSProtectProxy.dll C:\Windows\SysWOW64\VSProtectProxyOff.ini C:\Windows\system32\VSProtectProxyOff.ini C:\Users\{username}\AppData\Roaming\Visual Protect Service C:\Program Files (x86)\WAPageViewer C:\Program Files (x86)\Visual Protect Service Task: {347FA8D4-CD66-4643-B8DC-3289B9970E4B} - System32\Tasks\VSProtector => C:\Program Files (x86)\Visual Protect Service\VSProtector.exe [2015-09-17] (Visual Protect) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VSProtectProxy => ""="service" FirewallRules: [{38456D48-81B7-4BCA-861F-20F7F090AEB6}] => (Allow) C:\Program Files (x86)\WAPageViewer\VSUpdater.exe FirewallRules: [{24F441A9-334B-4FA5-9CF0-D4833EE37B4C}] => (Allow) C:\Program Files (x86)\Visual Protect Service\VSProtector.exeAlterations made by the installer:
File system details --------------------------------------------------- In the existing folder C:\Program Files (x86) Adds the file VSConfig"="17/09/2015 08:53, 7824 bytes, A Adds the folder C:\Program Files (x86)\Visual Protect Service Adds the file freebl3.dll"="17/09/2015 08:52, 395264 bytes, A Adds the file nspr4.dll"="17/09/2015 08:52, 302592 bytes, A Adds the file nss3.dll"="17/09/2015 08:52, 904704 bytes, A Adds the file nssckbi.dll"="17/09/2015 08:52, 499200 bytes, A Adds the file nssdbm3.dll"="17/09/2015 08:52, 188928 bytes, A Adds the file nssutil3.dll"="17/09/2015 08:52, 222720 bytes, A Adds the file plc4.dll"="17/09/2015 08:52, 77312 bytes, A Adds the file plds4.dll"="17/09/2015 08:52, 74752 bytes, A Adds the file smime3.dll"="17/09/2015 08:52, 160768 bytes, A Adds the file softokn3.dll"="17/09/2015 08:52, 250880 bytes, A Adds the file sqlite3.dll"="17/09/2015 08:52, 548864 bytes, A Adds the file ssl3.dll"="17/09/2015 08:52, 317440 bytes, A Adds the file userid"="17/09/2015 08:53, 38 bytes, A Adds the file VSConfig"="17/09/2015 08:53, 7824 bytes, A Adds the file VSProtectCert.dll"="17/09/2015 08:52, 184320 bytes, A Adds the file VSProtector.exe"="17/09/2015 08:52, 956416 bytes, A Adds the file VSProtectProxy.dll"="17/09/2015 08:52, 331776 bytes, A Adds the file VSProtectProxy.exe"="17/09/2015 08:52, 4229120 bytes, A Adds the file VSProtectServReg.exe"="17/09/2015 08:52, 284672 bytes, A Adds the file VSProtectServReg.ini"="17/09/2015 08:52, 116 bytes, A Adds the folder C:\Program Files (x86)\WAPageViewer Adds the file VSUpdater.exe"="09/09/2015 16:56, 1001472 bytes, A In the existing folder C:\Users\{username}\AppData\Roaming Adds the file VSConfig"="17/09/2015 08:52, 7824 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Visual Protect Service Adds the file userid"="17/09/2015 08:53, 38 bytes, A In the existing folder C:\Windows\System32 Adds the file VSProtectProxyOff.ini"="17/09/2015 08:53, 8864 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file VSProtector"="17/09/2015 08:53, 3374 bytes, A In the existing folder C:\Windows\SysWOW64 Adds the file VSProtectProxy.dll"="17/09/2015 08:52, 331776 bytes, A Adds the file VSProtectProxyOff.ini"="17/09/2015 08:53, 8864 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Local\VSProtectProxy Adds the file VSProtectProxy.ini"="17/09/2015 08:53, 10979 bytes, A In the existing folder C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming Adds the file VSConfig"="17/09/2015 08:53, 7824 bytes, A Adds the folder C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Visual Protect Service Adds the file userid"="17/09/2015 08:53, 38 bytes, A Registry excerpt ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{223ECDEC-6DAA-4BAA-8BD2-4636D9EDD0F6}] "(Default)"="REG_SZ", "VSProtectProxy" "InstallingUser"="REG_SZ", "bQBlAHQAYQBsAGwAaQBjAGEALQBwAGMAXABtAGUAdABhAGwAbABpAGMAYQAAAA==" "kp1"="REG_DWORD", 0 "LaunchPermission"="REG_BINARY, ..L.\...0................................. ....... ... "LocalService"="REG_SZ", "VSProtectProxy" "ServiceParameters"="REG_SZ", "-Service" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\VSProtectProxy.exe] "AppID"="REG_SZ", "{223ECDEC-6DAA-4BAA-8BD2-4636D9EDD0F6}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{23F5305D-9966-4749-9EA3-A473049C27BC}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{32CDC740-C452-4743-89C4-5D683A329B7D}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3A167540-19D9-4F22-85D8-DAD95F8FF7D9}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55CC8424-39C0-4BBE-89F0-517515DCFD58}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6851003C-BB36-461C-8CF9-B3F41C366321}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{705195EA-ED41-4499-B8F7-12820759490B}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8CCADD6D-980D-4F28-9A13-504FA1A2B78F}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B0153D0A-99CD-48E2-8FFB-13C1C4B0DC86}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C2127401-45C3-4B4F-8C5C-8E2BCE3BE2F3}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C5B3635E-6E16-4B31-942D-750BC9B18CE0}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D1A22D46-0E11-49C1-A192-3EBD6806021D}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E581BC0A-3D88-4B8D-8076-B1612A043F38}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FC3E0BC6-0CCC-43DF-97DF-0D593EE9FEC1}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7D434F0F-1FAD-4FDD-8FA2-79F927E75E9E}\1.0] "(Default)"="REG_SZ", "VSProtectProxy 1.0 Type Library" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7D434F0F-1FAD-4FDD-8FA2-79F927E75E9E}\1.0\0\win32] "(Default)"="REG_SZ", "C:\Program Files (x86)\Visual Protect Service\vsprotectproxy.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7D434F0F-1FAD-4FDD-8FA2-79F927E75E9E}\1.0\FLAGS] "(Default)"="REG_SZ", "0" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7D434F0F-1FAD-4FDD-8FA2-79F927E75E9E}\1.0\HELPDIR] "(Default)"="REG_SZ", "C:\Program Files (x86)\Visual Protect Service" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.DataContainer] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.DataContainer.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.DataController] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.DataController.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.DataTable] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.DataTable.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.DataTableFields] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.DataTableFields.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.DataTableHolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.DataTableHolder.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.LSPLogic] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.LSPLogic.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.ReadOnlyManager] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VSProtectProxyLib.ReadOnlyManager.1] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{14F4B774-7A5C-4DA0-9F38-94F695DC11BF}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{665FF171-3952-44A4-8ACF-73112F083EBA}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{90B76222-AF99-4CEF-A184-A01F910B4B8E}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B43ED7B8-FD23-4332-B6EC-ADEF7F217592}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D8379725-3B2F-4283-B754-5EE2DE2ADB86}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD15BD60-7777-4E7E-AB46-4AD7BB299BFB}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FD2F9534-54A2-4B40-9C0B-35EF21ECAF5A}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{23F5305D-9966-4749-9EA3-A473049C27BC}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{32CDC740-C452-4743-89C4-5D683A329B7D}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{3A167540-19D9-4F22-85D8-DAD95F8FF7D9}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{55CC8424-39C0-4BBE-89F0-517515DCFD58}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6851003C-BB36-461C-8CF9-B3F41C366321}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{705195EA-ED41-4499-B8F7-12820759490B}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{8CCADD6D-980D-4F28-9A13-504FA1A2B78F}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B0153D0A-99CD-48E2-8FFB-13C1C4B0DC86}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{C2127401-45C3-4B4F-8C5C-8E2BCE3BE2F3}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{C5B3635E-6E16-4B31-942D-750BC9B18CE0}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D1A22D46-0E11-49C1-A192-3EBD6806021D}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E581BC0A-3D88-4B8D-8076-B1612A043F38}] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{FC3E0BC6-0CCC-43DF-97DF-0D593EE9FEC1}] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Visual Protect Service\infoUrl] "(Default)"="REG_SZ", "http://afnvj3ml0s70jt.ru/update/[email protected]@@8" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Visual Protect Service\partner] "(Default)"="REG_SZ", "1441810516" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Visual Protect Service\schema] "(Default)"="REG_SZ", "archive_0109" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Visual Protect Service\userID] "(Default)"="REG_SZ", "b1ed1f85_85bc_4d85_aeb5_79e154dfcac8" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\VSProtectProxy] "data"="REG_SZ", "2NsaigpVU4C0SL+Pw2KLYCtHPY3XuphjN9y2gfxje7t5qpZnmwML+0Mv44vEoP8KDZura+75BalZ5Ure8wCTa/wrOactJ8T9wB85fRCNStAqYSBuMHvuErRAadfd3fUmtj+Gu7eczXGS8pV0TQ8sWJDUUfaGjYcPIqIj4XlxeKM4W174kHjrvmCE58YGnJUJEXh2dAfgNZmGGXxElYM1Ku4FZyMHeyWXou4blfIcmN+0cNfdxt9i1JzYLO63jTLctm54rjVy1O2BKjXGDdk14YNZvLWFCa84CKwIGJaeXNAqYSBuMHvuErRAadfd3fUmlblq2ibahunAHzl9EI1K0ArsskyEXD7/X7Fi42OPx08i2JA8h6ZXj7cUgpEwaSwwQy/ji8Sg/woUW0VW1g/qJLSVX4m1Je4SNGzWSqdd0DvtwwxJUf/pD3gZcZJr1cNLdOaOzwjZohwxH2x0ueZNwRjbfMuYonEV9pJClSouVsATZm4CpNABYjS1p3LZymm+g1jVHmXENTlndripfuRCnwQ++OMXr8gX3lGao0TDJRlQLBqisXAZILhbm1ZmM/uMc3sDQUUWItNWBWAl4s61X4yxf2xqM9MaMvqB+LpUHhQ5qguTQrLwn4VVxg5/LmI7MzpRvxPxx4pynXMjrlf9zrR9gsfUNyQu4jt45zcW7B0t2hQsa7baXVxhqOXyeU9aqrp8uNbBP8p30v8edG7JK0TKjJ/LcOsxv6R8YOU8CcArCv+6DgK3qjdvuu21yFwmhIkCBCRV0A/QGukCRz+odKmYvCmldH0vHEfr7d/ISDDemSaIHz0c3rEC/WSdG8rOULjkctJNHCnTWuiT0MWGF/JwYXjDgIOjX3kpmQZh/rTyonwTI1yyi+5QY23kCHoThqFPoVB8L8EZSzSTE0nxdaRNxXycbqdpE/IxYNvC0DH6w16NUVF3BIahT6FQfC/BGUs0kxNJ8XVG0iTaOTcK8o8FknJ+L6Vn/pzyH5JcsSxQuORy0k0cKcBNvhksECkMiLXCc6qo3ki/qPiUCB8+KngZM9gJgUV7ew1aFW3q8IpDb4v+E8VsC+YlyuphhVrJsBjO0DOziLX69GNBGNih+CVKsR6sFRRKlkc4kiL3NNTQdymU2TkuSnW0MwsYI6BKouPx3m/KdElJiqAafDKelC+2IiaEvQx3Qy/ji8Sg/wrpuSVlxzCco3W0MwsYI6BKouPx3m/KdElJiqAafDKelDPKpnd8J2daa5v897Pp8Y9DL+OLxKD/CriDSUQvT+pvdbQzCxgjoEqi4/Heb8p0SUmKoBp8Mp6UQ+s8FW1S6KHzhfWna8yGrUMv44vEoP8KUskM9rYC6rpia1oCbmPVh84Nm5VV17hj2RnVYh662TJrm/z3s+nxj0Mv44vEoP8K0HcplNk5Lkp1tDMLGCOgSqLj8d5vynRJSYqgGnwynpRKIyhgrUGITEMv44vEoP8K0HcplNk5LkqtJR97tV02SF+oQapbLPwNzg2blVXXuGP3M5QY/1zamEMv44vEoP8KjQP6z94ZwDx9i27RCS24zaLblns67Is7veXwGOaL/6cDmSuewxgW1C/qSgA7IA37vWCaJMA57mzsc6YR7LGM0PMD7Uv7H9ufF+1eLQgPTjwwI9nCTFq8srv39tXfGtuWrQtuvUDwYCsda3b6AaBxbGwrNot2YyxevKf0+/uR4yhmpRUZBIw3R3Tij5UCKX+HNXCAb5rSa3PRrHQFXow72kmKoBp8Mp6Uo1uBlJpe5MwXKj6qJdtoTTVwgG+a0mtz0ax0BV6MO9pJiqAafDKelBAcKCCXb4uCVKvWTiKIOjFIKLsEfEnJsTVwgG+a0mtz0ax0BV6MO9pJiqAafDKelOzdKBJqz76nmNEkM6EQPhBpx8AeAROIq7J3hCoB5D0m2wfAS1pPXXFzCntkXJSxJr7QvXmzIMnsZxoDiwAJyELs3SgSas++p/z89Ox9E9wOKY5IYWtRUmI8nnwWZo6QWJ0C0iRL1+2xKY5IYWtRUmIb7aNNcQQ1ZUZbstCP+JmghPyw/k/ocXv7lQkp26qJlVDmRLMkx4B2nrcVUykeURpPEl/dIR9B0F8MtIj9uHNDV8HeU93O0qViLr8tvf4Ed3zjmxx6vju3gEYi+HKmRz5clJJvWUQoVE8SX90hH0HQXwy0iP24c0O97Qc+1vQih7BiiS14fmJI0CJXbxgnlYG3eCUjdSi6r+VzYTfuLr0DNuBvN/d16BM+ch8khzCJ5XxWxV4R9Zgjr5Vt5zBmM32ryDqfPb0yhfjWmicI1B8Kd2IhM8uLP4sVNqZ3zT+eU51jSHjlxNFDHfOHgrrpqxUsgZ6T0zD5cR14wCwn8+cH5OQ7jDkYeGlAtup9Xwy2WoHbXsI9APMxZ22zhO98wUoRRwb7t7651amL8UAVLbc1ANS14nMmZli4ZyJf1+Fev6ANKyUICX63Eof84NQAfceS55ZDgUDZKF0k6NRnRmboN+ZKFhnT+FyLIWKXbg52TyfclzgraKJIMsBYbvCYkMVrlCstF6EIQ+lU9no5Z1rc404xBnZzO8/SY0DCViclCUzcA9v8ubWF8Mntcq2GilN6rESjsqxV3d2pNnyeqVAyKQ29IX4f7rpg7//30jR/c3+sc2qoVbsfmC5SsMycfp3BkE3t6f2RRa8midyNxMZPPkoku0gZdgrjTjEGdnM7z9NOQcEUGEm970CHMevKF+6ox8oGkxeNZwC7Jrv4ljMKatpadE7Kw2VoL5qoJ0llA6mL8UAVLbc1UDLXS0xjRbY8nnwWZo6QWCf20DzC0JEKTzmTC7zGFElENr1a1g4DEeht89gAb4+lDkhtGw41W/s2C8LBnX0blOBGz2yjRLvuhAbgXOlFsFThcyb1/96WsNP5Bp7nx/jdd9cjpKNDkDGgDSslCAl+t46eik3OL+xe6QdibZGx1WFgoCqc0iGJ7BekEmR3QwdIDUDIJ+JjXNgfFWrrIm4v7CGV1Sz5UHbUer38bQ7+tLSdAtIkS9ftsUEJw3omdjkEZAtTJ3CezSTISEwTvrCsIYnJJrNiOmbfkQGZmRGJgJZ3YiEzy4s/iycuQ36SZUcGF2r2+zUxxE3lwxuS4pLED4Aq7+MNo3zQxEQH74J/wZN+kwzTv4OCoxdq9vs1McRN5cMbkuKSxA+AKu/jDaN80NBUtTvu5cjt0WnnyGk9y584JyP9nOvuaZM5h57Qkj14FS5Pq4othoigyWpCKN1lFQkjdq1rA4vwz3BggfkTeagEyjSHYGvmx1U3OP4Il6X1xnckiWteq9bWH7pqegCkSco18FAc3w5mALsmu/iWMwppsJBhjmfQlX+RNQKyBViXMpi3RHm3XaiWbfk3uwEpRmwrNot2YyxeeZlnnU7YLzrs3SgSas++pyf20DzC0JEKeZlnnU7YLzp30emDJ/RrcQmsabjccGM/3RtyzjG657rQU5jJ32Nwn4rfV7//jocoT1N/1dPU75Yt15lxPW8jvy9VZOuZzgjbfvS0Wht0esIzvCjqx/xf0ef1Yl+7R3/dCGI+vnAqOMx6sLmuCuUNPCAP8h731Qawrrwzx1dPreA4JyP9nOvuaagttOREc7PrTbr4iLrhvmwuuSxRp5Upy+ht89gAb4+lcApiqgUnF9qD8LZ+2FVDSuNOMQZ2czvPJ7P1m4lbjPgmei/lXJRmGMllMu+0EZ1TEkfmWmmSXWqL9I4PQ7TRgnlHJbIxJMDROooVAtsGRfxugeOXEYvFrjAkx89rcZ/tAl6v6qmKbefs3SgSas++p09Tf9XT1O+WAl6v6qmKbefwye1yrYaKUyTEPPEn+GOl1ZdIzI4zjEP1xB4GKLWpIOFSZo7zjo9ZrQtuvUDwYCsMZLE+ba+9OchITBO+sKwhy66Llo6+RU7weQUv8lTEDthXAJjKumFx9cQeBii1qSDWmhhS++Rj7NgzyWNyaMRNeHp4rmZIgbdsf+/OSbsOf25WsyUZ+HIq/wjwzR+cy1w7OpSsoFmaxWryJZkbpRj8HJeQVLnHsS7R2sEqywYoVnVDjFi/fRbOpHi9Ge1HRgBu+Fh7HuwuFduBsSC6Qw55WVbKl2joXynMLBPaJyvnYoWsnJMQQPZFkdp1Rwy2yezbgbEgukMOeVlWypdo6F8pzCwT2icr52JcwS6XATjO9/yDdy8eBvjvrE7o2HyikiIAMzvDAnv3ovwvAUxY5yJWxjccFPyHKBr9whbBUSb2f7QuGiD3yrY/cdLHfkrmpfKN3cRAa6HGWq0K+GzB6+mavWq7SYNK6EXwO5zF0YUamuaRZRCDW1WdmY3jju0d0tqyoG4Fhb71i/0JaA5ntsTG4vEQkR1BcGq/jLsr2pZrZzPVy3MvMIrTwrwtK4+ayE7iZPr0oPM5a9wnMiUiQws26ZfBUOSE+rxOtLCvxKmJ3b4dtdwK09vVS0SknMuycF8L7H918IBH37jRssonUvt/VrfE2K2eGnrBkNkV9ZHJpYQGYC6j+ZAaxoOPqChaIe5CqTsyvebSDJ4yedseYDb+ygcySu9J0qdgmkVLHhLGx8EkditHACmTYJVg4bGBAHIQsWvOu1uLc+8QGmfry4qAZ8AgR7j6oQY2CFfa0U6JDfWNG3gOC2sdBqjTRO9bmS2yQpLCj2Pnh5jNm09hzOPFaYz/xU/HpXQViDq7udBWR6bXoaS92XbdJo//h209nyAd9b/4K4KD6yTQKCIKXgRq4VsTzCprylALLkaBStBIWZqdzFvkUJe79fwDTW8+5osEBVOZQJMpblyjzVKdzdRfDE2fskbVEYVhcD0SqcVAbgZZx0hSB1hlfZQhq9mBdzy+goZT3y7oKRD1WfPoIt5rjymFTv7B6soGk2gYZxYiiRK4YfebTBE9Rcgj/CYLg3DBPwanduJWMZLcSRZ8AbnLsUpkFuCdWqGuRlwQBv2LboyojTl/9VORQFygwv9QiAKQNELthi0xBxMnameXtTjms1c/IwIpmru+fgGGBKb3YZJ1PZZgHYCMIy2xNIvvp4tF6z7FMaWN8bx+MkUbWKJZM3ni/DKKJMldezsRwz9LY+fOOZZqmyF7yXUOeEVmwDQglLcAySI2+GSYrYqVvqh2DAKb0E9zUk++eLAzvPv+RChfFvzY1mS+Mq67GoeENxneC4iI++OOz4oIDggjSYyfqpL8Av7esHpy4cVatjZx5uebka/hquRk83fafHWRq/QcrhD6qLXx1Xrb9VgFf01quTZ95aX4CpNm1cefJ5bFIMT6aVyNjwNKehzXdGT4lMonloWbCVD2fhWcIMUfVrqAV2VCEwxhIJAW62TtvlXkiXseY70NNboo/1FG4je31iAHjeK50iyr4ZGavEVRmqFJ1k6Y9u7D5k4CY/Hn/rUMaS+hOK81NUl9eBIj2fzlVgvrRbApLkwHPic2584puLbqBEQVR7NnVa2HE01z8m0hEIEGPln9aEWl7QvgleVsct/fF3nsaNOxU6FB5/bgmpbPlSHPk2phfXpWyWil5f1sni9FFhU8Fcl0G9vKCmxpb4oiDRgHTbzuEwZf5j5ozqB4M6qr4C4vXc4yYgvSukQAogsgDNdPJw4p2iouhGLUb1mgijHCeuMCLs4tWS1DLuC23vwclpZisvucGw5yDM3ssn2BkU3YjAwxGEhXs72ZFxRGK7bMlmpc6SVA8EppEKqFBCRTGU+B85YRr/skak6TnLJF/aYruIe6wWYDN1PFAU4jSxktFzry/j1uB+Dqie2Mtxg6CwhQFBtrEDae5g/i7Vv+xClB1VW9yntsZUKCiRdGKVwZ3OjdU2tvbqBJYtYntZtItn9xtYCfGmSBHeb1/R5AdE760gXHvbM/dxCuUU7Qd4P/VqYWMgn/5CAGBCRaXtxeVfEBDSfN2gdFauQEsfE05KXFZJw3cTMSjyzA1KIF+26uKa/DeOD7SVgwxBsUy1Ne93XdaRP2td2JpR3474wo2dFzSd8ciN+u4hlbzR3UZcdpg8TVfT8OaYGHUeOf2/ttmwdRbNQTuFz2gmxjKkwKWBTk1f4LcFGmevj/OxEmYCM0SDXi4dJxe0w6Y4srrK7En1537/gUBZYQ/8d7P4WEBbmtflARRhzMU3XxyYDUmZXC1PjL9/yBXHKPtr6/I/WgE6qmadms5cww/r2M9eYq907HGDlXXJ4ukeMCMins3+O8BO8H/bPUf79GYsrxbKeDSvQPN6XxLK72uzktMh71tTlSeIk628Umrjbsx15GojJuIfzBaG5xcJWD2TgoV1aBtzE94jR8+4bQmiCPU3pXKbOCSBOvHbgnHQGNAzJPqMuLbOwrd7aSN+t1eyngXkxlY8XkpfbZ2Sxt0GyhjMpboLWSbaMK95/abLB8B6kaucW5jA1EyouQBqDbLPRw7AbbB+tVf32alyVFOgspqlr+a0FYSSRUKT2eA0+z2Ap3jbkxvOf+r6ZM4EyH+AfgTY6HlMH6vVyfTowbt3LEw0BqYt92COYRnkfBrvIA8+dsLo/akHtbWQEGYapFZfAOkpNqsVifbYOZNGoelZ+i1jnXeVG7gnkSfdQqWlhlnUuA9ztaw2VkFyJBOMBJewWe21852HQIHrki00NX4mKRLX4mD1gpQRDF6UTrH3z2zfv5nWf13vym0InSwfOMv9m2XckIYBsmI+SoV+oNDXLawoVcoATZL0CIelGPpLz9C3Qn2pmjUqh27n13blcLl66H+0HOYNx1uQ/KROS5ODye114cpcsI447imz4Y9l8pyftvPaRLUHqx/BScex5BWrWM3yArhinyVzTFJLJzOpVNovZLGHQLUuOfhhyEL7lUV4MAjRzxL3d6G/Z0MXGgsykzLIKJaLGSk9T7Ula7vSqD168ggtJacL6BdvgUYBLgt4WxNRhH2YGPCG40dPFeb1W5zH2PvCg9pDEEc6FWqKN6882OxP7etHdTLen5eoCiwbX8DvN/+K98nLEWJHMtrApyR+vNT+LYVUhQf6w86sv34vrYoakV9fvhBmWytxhceDRGG3Wbnr6ID2LofPxH4KvF2fK/tdyg5CGzgBDS3jJaFS9mLxyWWXHtncld2QL6YmZSD5y8vxgf2fk6v00Bttl+faPSrGOC5Z0KbG262E+Wx3jVVCOZ5ut9tq/tLZhkbDkUD5L3Ze7ErL4hKktd6BeKcA2OSxeJEYxSwiVo3B5q88MYFvAj0GZw+DmzcsRujuV/WSU+worJvA9aJxsubjrLTorpVJ/efLd404mwYxuQI8aa22oS91355MPyhrezmlDOGIWfvoJsCK7l53xzjxNp95W5lNvhlnwlTqa70Y5yMkFS7Ohq+Jxwr6L303n8h55DdtI+JDZzbUMCqSoGzysIHEkGWMK/rGKcPZbo8OeEW7ttjlRp1utLN1Sm2jgucxh2ViCehHomcA1/q7cUgJvoZBJjW0K4cMOngGo33N3OorD+q54Uonb0krXbTliOZFURDxRzIrbsHZkJocwTT59iOKKsbA7z0H9hYg01VeLHa5S/J2n1UX2t/54GEeHYbHskk/wxiYnz6HnZWRQp1QqPPRAcMpAtsm5hgeUrMA1VH45oBisNi6Azghc/EJQO4LykRelI4wNsGY7qvfsPfwEcgTuBETtezP7DL4R3u9w+AMObfhYZ8YEc8+gxzn3MLGJLC8k6P6EqEy3GnM1CkbpiFmv+J6wqO7cjGF6emy3tw4cMhuApN3TjFg3ZrD0nltbMGkd3pmDZPvhW1JayrAKF1luPKbWv+L9hlKi/FC92zu7+Pr82lN7Zb3SOM5wrqZTZwdCn3CTCJa+/48R/ZAV7IwjPxwuLXeXJkohbCyhLtTLJ1kelb93pEswP6lQh5vCSkGW3NUNT+gWOxX1vc7MGMZJc0I4jshfgE0ThJv5qTLnR7PmmX7pvjOfpdqYeocKN/ygs+5fKaHz99dH+HcLNpCFedC2hcW7XZwuR0PqUFQgBNK60g7WcBoQ4tIVrJl+CLg7/4V3qHlK5iF3l2+j2GnUuP6wVtBwm0MUSMtSfVBDP/UMh+fd3D0hBczESZfyZQZYZc33l/ms/E/FphxI42dLtnLtItjVxZqz3zQhJ5jA0GD+p8slUFlIvp+I2lDopwty+4LiGs7enNsfaJsuM4xxLSXRbj71eMSXtDokTf1iQMOQed9UqCPQ8/JAbGqH91i++4Bo1CZm2NcXT2izehH8EoJdY5I25dTnb3uhyJjQkhfgXHMrlqRleUspTQpO8u7kmSi9SQohjvweKpAOp4dQpNXT0HU3IUfJSCaV0WYDErMOH7U94wb1XjXNSd4R8OdOxbxXL1l36ybf5FYNlwSeaGy+UQq4hUfbUlOrxIpV9rBCbHtJmmLS+GjzLNbVVm/an0heGMbpfCceXpTcCUckqO73F96LKywzGQHxRZq3paH6H1c9gXnfK+S2OXuv5fttRg3rbq7tSWrxHoSZuFNkm8hYdRagUbQCKyfpqyetOosbqAJ1d4iI4D+EK3qfl/Q7dGw+KdGUYrpxfciuyzgecdy4pq04R29jZl/0f3AKh9W+Oz548aHjb01fSVLuidekk4g3H6ILHTEjDLmv4vuLACGaYOdWWMZ+fgNytvU8cwvXDB7COOjTChXdbb7zE68pBGsex4PXQirEHDYh0wDtaZkMhIGFpDF0mZqajrVF3hG7XU85VDyQjvOMfx2qfZXU+w3H++OtVaycy100jMMgnivtKrzDfqwyRYv6KhlJh5QPrQEVyTRsMUrYCJcDzy3TPiW1Q0/j38jWfrFYAergmiU/N1jFuVrMlGfhyKv8I8M0fnMtcOzqUrKBZmsVq8iWZG6UY/ByXkFS5x7Eu0drBKssGKFZ1Q4xYv30Wzopx1oB8CQHll54H9I3dhng3mPZ4yjtiBDApmeqiOd3QvAlU7ubD3XtxEbqFK/wzrMEE90sTC3sso/ez6gB8d3wxeUrueyxwl3h7J5RNS3qJf/mNNl5a+Bb1xB4GKLWpIDfNKU6PYbasedh1JROlPIZ4eniuZkiBt2x/785Juw5/lh/Vuio299Mdu/9S72acDQERusQ0PV+/+PfyNZ+sVgBdlugGQoFnppkzkv38LGfc17RuL5wTgwJe3KBSb1B9oexjmXyE7rtCeA2gXTTRUPrgDQlDZHH1mgziT1AMI14gvnIbFI1LF2j6P4iwwhu5pO9vxKh8tZgVMO+OJlpRL3hTdveRW+dCL1tRZcnKiUXv7VJhlZsaapxck0oNPakodp37esWkvZ7YsbPhLykMyDFEW8OF/TlKiEUi5YDCXKfxpk6OmTEeSBcCB72EJVB8S4JyjjYnbBLv8o18Ejc9TzyqQ8uCKHUNyymqpHFbQRGBxOoVMSDrBQ0Tk7iG9NsilfLPLXMWYu3MuvV+e4NZRxRpauckJk6Lb82aCscsGBc2s/XaAq5UOBBZcMHxhXOjWFHk18B32mc+SS1gu99RNRh0s+h2tk66obP12gKuVDgQFcC4/g1PSyxJqYwfImLl84Lx2Agw1zTeJcOg3CqXr0tOQeCgAk1NPa1V27RSCeYAAHPdtf3KAL/tUmGVmxpqnIeCeSmgV3hhx7Hq+0A30z3l1B+HqOutpMX6WfEIDCuM6y/GD6GjZLKunGCa+m3ha3Gg370YRp1J6ztZEAMf5vqZD1lvLlF6Zib+gYWH9JdWDOJPUAwjXiC+chsUjUsXaPo/iLDCG7mk72/EqHy1mBVMBlD+uFTJbH4g2ddeGkqeVW0O7Y7iLB6Zrx+DwKnlldZze+4gAwWsvs9fcG+q7PTfxkPqZVYajdfbB86zL6CA+07rkOdFuWpFxSix8NOE4Snn4n3sV3msmDksx4M3fpzqKnCRvJWCBvkRi7eOODswAYiu8vzL3DOHklbUhunDWzdWu+H2x++samZyfI8HC0EDPgITYbsCWM+JD7CyO2pvZdsQsZ8VNrM4eaxQ+mBxxs2Tu2NgpcNLDwAzGXAHrnu4OsTE8kt8W3E7j2V0iMQ9rw1UrcNtDvWDGQGWce1BsfCf3fvgK+a10kvy0edKdKw9Sx9syTern20paE4eDzs0CeuPGrEakUZ3yFvzDgziFwTknKwMvGc1UmmAvCTvs02dTnYQ698o7GfYT8H8O/Zk2rYrNx47MZ8L5jUSbx3TDR1UHSzWynzXkxe1RHX+4giFuoaHexnppZIaBJ5HX1zxQXTNrRFlBDnkctTesPwct4CgF8QCNWrvuIZKqd/Bd19nLjtOzH4doOic/aMbEjk4mcV/xpzOA7B2FiSFrWiWD8zGi79WuJs2LgViXcBprTAEY1tyRWJI7CsCkijUg+9HjXJaKgyaRYJLOD7FU2c17bhx/ymgOcfnXIheB6B/M5kTqFUh2tXbwUrl04DBS+St613gtWhldMPx5gol5okD/O3VzqbLSZ/cNtVf+OfF2ZPQTt63LFux3po9BajrXS0JHtVjJ3ue/n1NAx5J0vvST8u4qz1bd6/FsCGlZ5QdMeFiI+hWlaRavoWVT3FyQBpmckD6yHd6l86d19U6YLXg7kU9X41zGpWLg5QXYLwaEHiQlN9nSH5Yi5t7yeb7vZZ9fn4F91NnTx3KeJwcvOs1rG8yfTInizt7OyZk81JukHPUZxNUirtXioZ3BPE3Bcd7J3pFBnjxmKNr93sMZEy97jSUSS2OvG3DTb02iLLn08Xf6NI3rpKOfx3vwIO1gX5BgIDx4WJ5uGO9N/7Pcr0kRa+8TI97tXiIPlIDJQd7Fijknk0oASLiYcln+nMJq5htPXbuEfLkzsRrXsTOVFy53ZwTz2Es+q7DIxTyy9HLv8LBivMoje3QnYQT2/3aAN2mLhgCF+UzIW1fEg07HH0lU9sWxbPCzroYxWZ6hH4j18dNj1bEhu10Q7aywfZ7E0VRlrwKs/BO14h1+8P+41yUj396Pfa9dt88kpgLSdUGE8mP7ToRyVTXcssdzmwnZ8S2Yg/oMH2R9uMxCbxyFTY+CCjFS/UEC2wAUL75NfirQAf4y7uoYgMQgucmxKuR/YhIAtXBfc85dDzpescSSjWaQkaOIWgxg10pc0V0B0JaI5GxduRbW0zHUh1RtzRw+r8SgEAI61+RMz3WwCX8lrMRP5bEQZrcF89Neg6sg0tf99+v+FYarvuTPvh69EYbV1Ig9Um5jymGKJL+dSmDLFKiQSjh/dZX32sWhVvs7YrdJMQTY9tw5LPuPEuE72nzrvtstz3AjzETJq3wk0u6E8nrza9rCP9yGpEoZPJ7KmmBJQBlhdYh8rrIPNDJCsPjoS6yIIwECEXwqgiXgebhkAJ6yQ1c+42LzdG618BxE4c/FRj7n0h3tulN2PVguagpSPTHKuymfiFZUJb3d4WJm8GGQuO1N6TFDNBFBZgWkkwCPehtVDxfC2xFwz/cnYvhJa6btGCUhEUR3+oZnTYqSZGlbZZJEW9rOBD8QR1wq4hvDNP2AWp3ksGcyg+k/OeoRdrQO5Vzv+opQVQTGu/xuWYp6xjOFAWsSLBZuUxlUdxCnPHuubFogfkMdsuL26BzSSWUquHwQbRnx63l5V5OwNyv0RlXHmF6UEhMO+3Za2Zpae0IcRoryJMRMJ7j1QwoJ5hK6GRn8wTSjhl37ye6DhEzqij+aDyChH2w62X2C3bUdbbGZ9nKR51IzoUZwTeKXRZrQEMoh4LBG0NOZQEQdGm0bZxcdh5ccZfU+j/5zRzs838adCDNdrisGwgnKoU8fsSn7mulrP6Cz9e//UCNiMDNK+7lFgk60mj1OSeBkTnxpS1Yi1xP3UYmRbs7LtmlhuWOHGVQpCyKDbvMoasYuDVpZMWEIUqDVJdzxps8khxGZQL/0UTNDON7aSqb1rd9JOipxAq36VYmZ9XNu7AWFmz4BmCOV3wJB+gFBlBo7QrkrHan4wKRXjJmNdwwTwWpV+IWPg3gF7CiRcO6djp4XyN8Vfj38jWfrFYAdeTBTQUil3bf7LmgxckfYlh2AqXe13TfED/E9Ze47Vj49/I1n6xWAAD/YKk0j5wm1e3CIx9VuKg/X8potTfsQ/a0a9UjDnp7cViKwUkhP9nRbKAP1kPIBEVp8dI90YmhFmVk3YD/MF7h3h6QBTu4VmTbG2JXY30HZnrLJoO70xF/8xIwVD/YznpXKAh8L7gJyUZiQqVYbBkt15lxPW8jvyyBnpPTMPlxvamwiXkj9iATDz0FnZAR/UYRzPLppCB73Q6aO++iglARnOivVGZQokj0nmh9EqGvZNsbYldjfQeHC0QZhR8GUH/zEjBUP9jO36ZANu2OylzjU3gvevLscChv2rr1hLMElUfyeQfRIqV5VL1qrmEMDusUqzCTm/qDxnckiWteq9afun9BtRxmvyLVuVkETFmGcnZC+zJw17DTYkjLlfmJfSJ9D2EcaKsAbUQbNmqlOPOEX1iYVj60+4dvSkb9lEXSlc++Vgux+d1xL9sK1aUIi01KFb9aDbROM5GNRVp22pOHEeoDJF7hjdVOiR41PX1QE2ZuAqTQAWL61zvOpiBj/4kT8Qm/xzNFLcc3r7Rjw/HQq04JlKabXz97WtQc0sfWhJox7a0mABV74ulWKe4/auWHpzcsDxXn6yf8KzrrOQprp17x8g5fYXsNWhVt6vCKkxkgXm5WtML2JEORfwKIoCt6/5d6BmLrtkQ92gkBEkAZuOeuaU06TlC45HLSTRwpSjs0ONIvI3Nyk8vdCPFxfOWHpzcsDxXnUiqmeSyUQTUBKz+VO9lfd3sNWhVt6vCKXyvefLGJuKqkGTG4INr9kqjHygaTF41ns1l6vuILYZykO7+t7XYPzL+o+JQIHz4quGycMmXUIfl7DVoVberwiu1Fl+H91IDjXdxYui4yYxycmdGCGK99EhW1IIPNbGdQNMCzQyVB8tRn5o5m4HD7ztktks4iXt2zUAQnKmzPKek7lGlkf3H/s3Mwfz/17FsEQy/ji8Sg/wqXfhzCnMotitaBUPjOoGuNQy/ji8Sg/wrMjhbkt4SMG8ZrKYhGPKztBwFO6PJ6/ARDL+OLxKD/CsoGO7vbzwc4sI3Jj+m8btD/djsKjSZ4ikbR/2ec3na/a2FTNxQ+5oPSG6mijBwvoXcbvIXPKgIWSiMoYK1BiExDL+OLxKD/CpTlNzdpWexQA6vpA0f28K1rm/z3s+nxj0Mv44vEoP8KzI4W5LeEjBsvx8lTXprWzvOF9adrzIatQy/ji8Sg/wpSyQz2tgLqujp2VuRrBtn2VKvWTiKIOjFje8Db/HHY4QOuKMgzPrMQd5mo4Pif0VGxNOrG2M1GuHsNWhVt6vCKQqxQcLkLPRn5lB1qoYYw8HPwo4Scf3XH2ThFwjT4PnUZteur6BHgTIHt4ERaTDOFQ+FHEG8Y4EUmWGF8bzlg+gVDYdH4elai837RgIOShKCLVtHr967cFMB7u8u3dkGRSxVH1SxK8VYSMs+r28PB9hhCJYaD+J3wXpFG9zFpyvFfeSmZBmH+tMiSNcRxgr/BiOeLuQZ14hIK5Ku/LzGhH1dZ122kxxd8pE3FfJxup2lxTvz+2wvE2h0REpoakzIMDh0s1/igai2WzOlNx2qrEgqGhIqbLSvBLAJvS60VkS6N72CZpGAxpHsNWhVt6vCKCiUUmFvYJPkS5SsxwemfbBwUi5VItT5urOZRs5QPh3t7DVoVberwigolFJhb2CT5EuUrMcHpn2x14+4brWor8zZdtMnKn3uKew1aFW3q8IpxOEBx52i+TIOVxIpVJqazEed7Z6d2KQoeIPP9GueOc7Y/2qjuZw9/MGIoz7VAWzrnBJ7iIF0yielNgaRDebhri1bR6/eu3BTAe7vLt3ZBkUsVR9UsSvFWz4bM8bki9ocUJLpZuXfq73sNOQ+5sFtIfeBcipqvXuT4FIae0FUKXDdvuu21yFwmIIfNDlHkBvnz4DqGO/hXN8h05B+5Gxjm1fHBxRvxFgoFH+90z3b5R/dmGb4Um6KgHgVxQ86nwNLIF2sYGjfVuX9Fq8bIOmxCxgC4E0HWJ95ywPo2ac4Gm7Vnn4bNa+dOvstFAZUTx602C6qhm1UWoqk5CX0GIv4GsVES6b/Rv48vZBndvEn97h/JtyTwh/OJppWtqgMFfbTIF2sYGjfVuX9Fq8bIOmxCxgC4E0HWJ95ywPo2ac4Gm7Vnn4bNa+dOAqY0dBXhNRH4mnTjNkzSLO6ZuDbg8/sPQy/ji8Sg/wqLpaTqMpZkw0zQIB4R2KfXL7YiJoS9DHdDL+OLxKD/Csr01CZ+XTho8xgJsxe5cyA1Z6kFm6qMJH1923eZBBj3REyYp+nXvPK1ujYgbfXw6PiadOM2TNIsyNBXKkWNcPzPWbfkmvliAERMmKfp17zydOaOzwjZohz4mnTjNkzSLJ1G1ClHnxLwTsiwsYzJIINDL+OLxKD/CoulpOoylmTDTNAgHhHYp9dKIyhgrUGITEMv44vEoP8KzI4W5LeEjBtw3x+emFjG6vHEpaE+H1gsQy/ji8Sg/wrKBju7288HODBm/P+4v/+GBcEsmyVBp/ziROQHJ6PDdkBMzTzikUVmu+WzRePm7zBLtMdvbOdAFnVl757aTzH9Qy/ji8Sg/woX7V4tCA9OPFxrpiYmPeNXJdJjtAtu3ArIj+z6vtfp6URMmKfp17zyFhDgM60xwZc=" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VSProtectProxy] "(Default)"="REG_SZ", "service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{24F441A9-334B-4FA5-9CF0-D4833EE37B4C}"="REG_SZ", "v2.10|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|Profile=Private|LPort=80|App=C:\Program Files (x86)\Visual Protect Service\VSProtector.exe|Name=Visual Protect Group VSProtector.exe outbound rule|Desc=Visual Protect Group VSProtector.exe|EmbedCtxt=Visual Protect Group|" "{38456D48-81B7-4BCA-861F-20F7F090AEB6}"="REG_SZ", "v2.10|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|Profile=Private|LPort=80|App=C:\Program Files (x86)\WAPageViewer\VSUpdater.exe|Name=Visual Protect Updater, OUT, TCP, 80 outbound rule|Desc=Visual Protect Updater, OUT, TCP, 80|EmbedCtxt=Visual Protect Group|" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSProtectProxy] "DependOnService"="REG_MULTI_SZ, "RPCSS " "Description"="REG_SZ", "Visual Protect Network Service Provider" "DisplayName"="REG_SZ", "VSProtectProxy" "ErrorControl"="REG_DWORD", 1 "FailureActions"="REG_BINARY, ...................... "ImagePath"="REG_EXPAND_SZ, "C:\Program Files (x86)\Visual Protect Service\vsprotectproxy.exe" "ObjectName"="REG_SZ", "LocalSystem" "Start"="REG_DWORD", 3 "Type"="REG_DWORD", 16 "WOW64"="REG_DWORD", 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VSUpdater] "Description"="REG_SZ", "Automatic updater for Visual Protect Service" "DisplayName"="REG_SZ", "Visual Proctect Updater" "ErrorControl"="REG_DWORD", 1 "ImagePath"="REG_EXPAND_SZ, "C:\Program Files (x86)\WAPageViewer\VSUpdater.exe --service" "ObjectName"="REG_SZ", "LocalSystem" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 16 "WOW64"="REG_DWORD", 1Malwarebytes Anti-Malware log:
Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 17/09/2015 Scan Time: 08:59 Logfile: mbamWAPageViewer.txt Administrator: Yes Version: 2.1.8.1057 Malware Database: v2015.09.16.06 Rootkit Database: v2015.08.16.01 License: Premium Malware Protection: Disabled Malicious Website Protection: Enabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {username} Scan Type: Threat Scan Result: Completed Objects Scanned: 332952 Time Elapsed: 4 min, 16 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 3 PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\WAPageViewer\VSUpdater.exe, 3964, Delete-on-Reboot, [b4e2b37dbfcc59dd6c999a46956c52ae] PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\VSProtectProxy.exe, 3172, Delete-on-Reboot, [2e68d8583d4e4fe7cbd7696409fb4db3] PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\VSProtector.exe, 3800, Delete-on-Reboot, [84127fb118739d9913780a2124df669a] Modules: 8 PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\freebl3.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\nspr4.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\nss3.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\nssutil3.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\plc4.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\plds4.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\smime3.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\VSProtectCert.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], Registry Keys: 75 PUP.Optional.Winsock.HijackBoot, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\VSUpdater, Quarantined, [b4e2b37dbfcc59dd6c999a46956c52ae], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.DataContainer, Quarantined, [257153dd56357db99d0319b4c53f7f81], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.DataContainer.1, Quarantined, [8f07949c1f6c0234821e616c5fa556aa], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.DataController, Quarantined, [bfd76ec2fa91e94daaf6f7d630d421df], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.DataController.1, Quarantined, [9cfa8ca45a31cb6bd0d03a93877d7789], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.DataTable, Quarantined, [c3d382aeacdf1323970915b8f70dfa06], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.DataTable.1, Quarantined, [b0e657d999f2e94d0e92d4f919ebf808], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.DataTableFields, Quarantined, [8115d35dacdfce68346c349911f3f010], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.DataTableFields.1, Quarantined, [bdd9111f6f1cff370a9676573cc8758b], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.DataTableHolder, Quarantined, [0b8b74bcb0dbf5413868418cc341ce32], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.DataTableHolder.1, Quarantined, [0492b17f701b42f49907f1dcf50f05fb], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.LSPLogic, Quarantined, [960035fba1ea81b5732d4984798bff01], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.LSPLogic.1, Quarantined, [2d69b977bfcc76c0128e08c594700000], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.ReadOnlyManager, Quarantined, [99fd5cd4008b57df2779a726c63eee12], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\VSProtectProxyLib.ReadOnlyManager.1, Quarantined, [badc111f4c3f0d29e7b9745921e35aa6], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\APPID\VSProtectProxy.exe, Quarantined, [2b6b81afcebd0d29990617b660a4b050], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\VSProtectProxy.exe, Quarantined, [98fe7eb226654ceac4db309df0146799], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.DataContainer, Quarantined, [2d69e24e7912fb3b940cd0fdc4409070], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.DataContainer.1, Quarantined, [d4c2b27e494242f4d0d03895ce36b848], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.DataController, Quarantined, [2274b779e5a62c0aa3fd20ad47bd9f61], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.DataController.1, Quarantined, [a8ee260a91fabf77bbe514b93cc834cc], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.DataTable, Quarantined, [a0f68aa64942f541f9a71bb27d87ed13], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.DataTable.1, Quarantined, [b1e52c0496f5a78f0f913b9262a205fb], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.DataTableFields, Quarantined, [99fd0e22f69570c6049c58752dd735cb], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.DataTableFields.1, Quarantined, [b3e3969aa1eaea4c7b257954dd275fa1], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.DataTableHolder, Quarantined, [148255db6e1d3ef8920e6a63c2429f61], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.DataTableHolder.1, Quarantined, [0d894be55734979f1e82af1ebe46ba46], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.LSPLogic, Quarantined, [5f3765cb7e0dc274b4ec923bed179769], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.LSPLogic.1, Quarantined, [9df933fd87043303fda39b32c2420ff1], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.ReadOnlyManager, Quarantined, [cfc7929e117a65d17e22b815ca3a9070], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\VSProtectProxyLib.ReadOnlyManager.1, Quarantined, [c6d0cd63b1da74c2831d16b7fb0905fb], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\VSProtectProxy.exe, Quarantined, [1383a38d4d3e9c9afaa512bb6f9544bc], PUP.Optional.Winsock.HijackBoot, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\VSPROTECTPROXY, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\TYPELIB\{7D434F0F-1FAD-4FDD-8FA2-79F927E75E9E}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\INTERFACE\{23F5305D-9966-4749-9EA3-A473049C27BC}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\INTERFACE\{32CDC740-C452-4743-89C4-5D683A329B7D}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\INTERFACE\{3A167540-19D9-4F22-85D8-DAD95F8FF7D9}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\INTERFACE\{55CC8424-39C0-4BBE-89F0-517515DCFD58}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\INTERFACE\{6851003C-BB36-461C-8CF9-B3F41C366321}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\INTERFACE\{705195EA-ED41-4499-B8F7-12820759490B}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\INTERFACE\{8CCADD6D-980D-4F28-9A13-504FA1A2B78F}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\INTERFACE\{B0153D0A-99CD-48E2-8FFB-13C1C4B0DC86}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\INTERFACE\{C2127401-45C3-4B4F-8C5C-8E2BCE3BE2F3}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\INTERFACE\{C5B3635E-6E16-4B31-942D-750BC9B18CE0}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\INTERFACE\{D1A22D46-0E11-49C1-A192-3EBD6806021D}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\INTERFACE\{E581BC0A-3D88-4B8D-8076-B1612A043F38}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC3E0BC6-0CCC-43DF-97DF-0D593EE9FEC1}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{23F5305D-9966-4749-9EA3-A473049C27BC}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{32CDC740-C452-4743-89C4-5D683A329B7D}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3A167540-19D9-4F22-85D8-DAD95F8FF7D9}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55CC8424-39C0-4BBE-89F0-517515DCFD58}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6851003C-BB36-461C-8CF9-B3F41C366321}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{705195EA-ED41-4499-B8F7-12820759490B}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8CCADD6D-980D-4F28-9A13-504FA1A2B78F}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B0153D0A-99CD-48E2-8FFB-13C1C4B0DC86}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C2127401-45C3-4B4F-8C5C-8E2BCE3BE2F3}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{C5B3635E-6E16-4B31-942D-750BC9B18CE0}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D1A22D46-0E11-49C1-A192-3EBD6806021D}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E581BC0A-3D88-4B8D-8076-B1612A043F38}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC3E0BC6-0CCC-43DF-97DF-0D593EE9FEC1}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{23F5305D-9966-4749-9EA3-A473049C27BC}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{32CDC740-C452-4743-89C4-5D683A329B7D}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3A167540-19D9-4F22-85D8-DAD95F8FF7D9}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{55CC8424-39C0-4BBE-89F0-517515DCFD58}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{6851003C-BB36-461C-8CF9-B3F41C366321}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{705195EA-ED41-4499-B8F7-12820759490B}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{8CCADD6D-980D-4F28-9A13-504FA1A2B78F}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B0153D0A-99CD-48E2-8FFB-13C1C4B0DC86}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C2127401-45C3-4B4F-8C5C-8E2BCE3BE2F3}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{C5B3635E-6E16-4B31-942D-750BC9B18CE0}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{D1A22D46-0E11-49C1-A192-3EBD6806021D}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{E581BC0A-3D88-4B8D-8076-B1612A043F38}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{FC3E0BC6-0CCC-43DF-97DF-0D593EE9FEC1}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{7D434F0F-1FAD-4FDD-8FA2-79F927E75E9E}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{7D434F0F-1FAD-4FDD-8FA2-79F927E75E9E}, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3], Registry Values: 2 PUP.Optional.Winsock.HijackBoot, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\VSPROTECTPROXY|ImagePath, C:\Program Files (x86)\Visual Protect Service\vsprotectproxy.exe, Quarantined, [2e68d8583d4e4fe7cbd7696409fb4db3] PUP.Optional.Winsock.HijackBoot, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\VSUPDATER|ImagePath, C:\Program Files (x86)\WAPageViewer\VSUpdater.exe --service, Quarantined, [395d8aa6c3c8a492bbe88548798bcf31] Registry Data: 0 (No malicious items detected) Folders: 3 PUP.Optional.Winsock.HijackBoot, C:\Users\{username}\AppData\Roaming\Visual Protect Service, Quarantined, [7d1957d9f9927db9d3c520adc04417e9], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\WAPageViewer, Delete-on-Reboot, [ade980b0e0ab06300c8044e7b54eef11], Files: 33 PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\WAPageViewer\VSUpdater.exe, Delete-on-Reboot, [b4e2b37dbfcc59dd6c999a46956c52ae], PUP.Optional.Winsock.HijackBoot, C:\Users\{username}\Desktop\VSProxyProtect.exe, Quarantined, [880e36fa8efdde5819eb6c74fc058977], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\VSProtectProxy.dll, Quarantined, [c9cdf13f6922c2745ea86a767b86619f], PUP.Optional.Winsock.HijackBoot, C:\Windows\SysWOW64\VSProtectProxy.dll, Delete-on-Reboot, [4b4b2a064d3e8fa7f115459bbc4536ca], PUP.Optional.Winsock.HijackBoot, C:\Users\{username}\AppData\Roaming\Visual Protect Service\userid, Quarantined, [7d1957d9f9927db9d3c520adc04417e9], PUP.Optional.Winsock.HijackBoot, C:\Windows\System32\VSProtectProxyOff.ini, Quarantined, [0b8ba28ed2b93ef85f3b666751b37987], PUP.Optional.Winsock.HijackBoot, C:\Windows\SysWOW64\VSProtectProxyOff.ini, Quarantined, [771f57d9612a41f5f1a9369731d3cc34], PUP.Optional.Winsock.HijackBoot, C:\Users\{username}\AppData\Local\Temp\VSProtector.log, Delete-on-Reboot, [0492e84897f426107c1fb31a45bf53ad], PUP.Optional.Winsock.HijackBoot, C:\Users\{username}\AppData\Local\Temp\VSProtectProxyr.log, Quarantined, [1e7856da96f55fd74458d1fc867e6d93], PUP.Optional.Winsock.HijackBoot, C:\Windows\Temp\VSProtectProxy.log, Delete-on-Reboot, [5b3b7bb54a41c76fb0ece8e56a9a8977], PUP.Optional.Winsock.HijackBoot, C:\Windows\Temp\VSProtectProxyr.log, Quarantined, [573f042c0c7fd85e4b51715c8b7930d0], PUP.Optional.Winsock.HijackBoot, C:\Users\{username}\AppData\Local\Temp\VSProtectServReg.ini.log, Quarantined, [8b0bc66a5e2dc274a3fafdd034d0e21e], PUP.Optional.Winsock.HijackBoot, C:\Users\{username}\AppData\Local\Temp\VSUpdater.log, Quarantined, [01950a26f89351e576288c41ca3ac040], PUP.Optional.Winsock.HijackBoot, C:\Windows\Temp\VSUpdater.log, Delete-on-Reboot, [9006b0805e2d90a6108eede012f2e21e], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\VSProtectProxy.exe, Delete-on-Reboot, [2e68d8583d4e4fe7cbd7696409fb4db3], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\freebl3.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\nspr4.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\nss3.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\nssckbi.dll, Quarantined, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\nssdbm3.dll, Quarantined, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\nssutil3.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\plc4.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\plds4.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\smime3.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\softokn3.dll, Quarantined, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\sqlite3.dll, Quarantined, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\ssl3.dll, Quarantined, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\userid, Quarantined, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\VSConfig, Quarantined, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\VSProtectCert.dll, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\VSProtector.exe, Delete-on-Reboot, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\VSProtectServReg.exe, Quarantined, [84127fb118739d9913780a2124df669a], PUP.Optional.Winsock.HijackBoot, C:\Program Files (x86)\Visual Protect Service\VSProtectServReg.ini, Quarantined, [84127fb118739d9913780a2124df669a], Physical Sectors: 0 (No malicious items detected) (end)As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
- Dynamically Blocks Malware Sites & Servers
- Malware Execution Prevention