OTL logfile created on: 4/26/2014 8:57:15 AM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Curt\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.11.9600.17041) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.75 Gb Total Physical Memory | 0.88 Gb Available Physical Memory | 23.40% Memory free 7.50 Gb Paging File | 3.05 Gb Available in Paging File | 40.75% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 450.91 Gb Total Space | 357.97 Gb Free Space | 79.39% Space Free | Partition Type: NTFS Computer Name: CURT-PC | User Name: Curt | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2014/04/26 07:18:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Curt\Desktop\OTL.exe PRC - [2014/04/02 09:27:36 | 004,972,864 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe PRC - [2014/03/07 22:34:14 | 000,809,680 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe PRC - [2013/12/18 10:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2013/11/12 11:04:20 | 000,196,616 | ---- | M] (Dell Products, LP.) -- c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe PRC - [2013/10/08 08:05:13 | 000,264,360 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\N360.exe PRC - [2013/06/26 19:21:50 | 000,207,528 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe PRC - [2013/06/26 19:21:46 | 000,523,944 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe PRC - [2012/10/02 14:45:22 | 000,120,728 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe PRC - [2012/10/02 14:41:02 | 000,694,168 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe PRC - [2012/09/07 21:36:46 | 000,087,992 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe PRC - [2011/09/22 12:14:16 | 002,751,808 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe PRC - [2011/09/22 12:11:26 | 000,460,096 | ---- | M] (SoftThinks - Dell) -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe PRC - [2011/09/22 12:06:12 | 001,692,480 | ---- | M] (SoftThinks SAS) -- C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe PRC - [2011/09/21 12:30:12 | 004,109,312 | ---- | M] (SoftThinks - Dell) -- C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe PRC - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) -- C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe PRC - [2006/12/19 19:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2014/02/13 04:46:35 | 001,358,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\5593edae2575d91c62c97959be364aa9\System.WorkflowServices.ni.dll MOD - [2014/02/13 04:46:20 | 001,707,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\fd746553afb4778c8736b6d8af4caa6d\System.ServiceModel.Web.ni.dll MOD - [2014/02/13 04:46:17 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\801b632b8b7ef72f14333dbce41524b8\System.Xml.Linq.ni.dll MOD - [2014/02/13 04:44:50 | 001,084,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\d3df00ba3df9c1790499701b79269570\System.IdentityModel.ni.dll MOD - [2014/02/13 04:44:49 | 002,347,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\f177ea74036d5fdc6c6b9c967dc877cf\System.Runtime.Serialization.ni.dll MOD - [2014/02/13 04:44:47 | 017,477,632 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\5cf4b104c2c79c9563d13e289e39c6ba\System.ServiceModel.ni.dll MOD - [2014/02/13 04:44:47 | 000,256,000 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\8a01cb6ca56adf4f33cdad0592538b58\SMDiagnostics.ni.dll MOD - [2014/02/13 04:44:17 | 002,297,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\868ad9d8acc0bf80a973c0e4e9cae4fa\System.Core.ni.dll MOD - [2014/02/13 04:38:51 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\72284863df9bea3f081ae98996400619\PresentationFramework.Aero.ni.dll MOD - [2014/02/13 04:38:44 | 011,922,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\4b1795df6372b251625f958595e08d3d\System.Web.ni.dll MOD - [2014/02/13 04:38:30 | 014,340,096 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\f703846404bb66a4ae03ef8133755007\PresentationFramework.ni.dll MOD - [2014/02/13 04:38:19 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\8bc548587e91ecf0552a40e47bbf99cc\System.Windows.Forms.ni.dll MOD - [2014/02/13 04:38:14 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5c24d3b0041ebf4f48a93615b9fa3de9\System.Drawing.ni.dll MOD - [2014/02/13 04:38:11 | 012,238,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\660ac5d6da77df8e86fb26f05c6a9816\PresentationCore.ni.dll MOD - [2014/02/13 04:38:03 | 003,348,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1d696b2d3de530f7ee971070263667ff\WindowsBase.ni.dll MOD - [2014/02/13 04:37:59 | 005,464,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\217ece46920546d718414291d463bb1c\System.Xml.ni.dll MOD - [2014/02/13 04:37:56 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\5b6ddf934128d538cd5cd77bf4209b93\System.Configuration.ni.dll MOD - [2014/02/13 04:37:55 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b3a78269847005365001c33870cd121f\System.ni.dll MOD - [2014/02/13 04:37:50 | 011,499,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ede2c6c842840e009f01bcc74fa4c457\mscorlib.ni.dll MOD - [2012/10/02 14:41:02 | 000,694,168 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe MOD - [2011/09/22 12:14:16 | 002,751,808 | ---- | M] () -- C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe [color=#E56717]========== Services (SafeList) ==========[/color] SRV:[b]64bit:[/b] - File not found [Auto | Stopped] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe /McCoreSvc -- (McMPFSvc) SRV:[b]64bit:[/b] - [2014/03/31 07:20:58 | 000,042,808 | ---- | M] (AVG) [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp) SRV:[b]64bit:[/b] - [2014/03/06 04:29:14 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService) SRV:[b]64bit:[/b] - [2011/04/20 02:04:20 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:[b]64bit:[/b] - [2011/03/17 19:03:44 | 000,552,832 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe -- (EpsonCustomerParticipation) SRV:[b]64bit:[/b] - [2010/09/22 20:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc) SRV - [2014/04/02 09:27:36 | 004,972,864 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9) SRV - [2014/03/31 07:21:02 | 002,183,992 | ---- | M] (AVG) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe -- (TuneUp.UtilitiesSvc) SRV - [2014/03/31 07:20:58 | 000,035,640 | ---- | M] (AVG) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp) SRV - [2014/03/11 16:45:47 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2013/12/18 10:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2013/11/12 11:04:20 | 000,196,616 | ---- | M] (Dell Products, LP.) [Auto | Running] -- c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe -- (DellDigitalDelivery) SRV - [2013/10/08 08:05:13 | 000,264,360 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\N360.exe -- (N360) SRV - [2013/09/11 22:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2013/06/26 19:21:50 | 000,207,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa) SRV - [2013/06/26 19:21:46 | 000,523,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist) SRV - [2012/10/02 14:45:22 | 000,120,728 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe -- (Motorola Device Manager) SRV - [2012/09/07 21:36:46 | 000,087,992 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe -- (DeviceMonitorService) SRV - [2011/09/22 12:06:12 | 001,692,480 | ---- | M] (SoftThinks SAS) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe -- (SftService) SRV - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) [Auto | Running] -- C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe -- (PST Service) SRV - [2010/11/25 07:34:18 | 000,219,632 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe -- (RoxWatch12) SRV - [2010/11/25 07:33:18 | 001,116,656 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe -- (RoxMediaDB12OEM) SRV - [2010/10/12 13:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService) SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) SRV - [2006/12/19 19:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV:[b]64bit:[/b] - [2014/04/26 05:31:27 | 000,096,856 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SMR410.SYS -- (SMR410) DRV:[b]64bit:[/b] - [2014/04/25 20:51:39 | 000,177,752 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent) DRV:[b]64bit:[/b] - [2014/01/22 08:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus) DRV:[b]64bit:[/b] - [2013/10/01 22:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:[b]64bit:[/b] - [2013/09/26 23:18:30 | 001,147,480 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\1501000.012\SymEFA64.sys -- (SymEFA) DRV:[b]64bit:[/b] - [2013/09/26 22:45:56 | 000,264,280 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\1501000.012\Ironx64.sys -- (SymIRON) DRV:[b]64bit:[/b] - [2013/09/26 22:26:03 | 000,858,200 | R--- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\N360x64\1501000.012\srtsp64.sys -- (SRTSP) DRV:[b]64bit:[/b] - [2013/09/25 23:28:00 | 000,590,936 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\1501000.012\symnets.sys -- (SymNetS) DRV:[b]64bit:[/b] - [2013/09/25 22:50:25 | 000,162,392 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\1501000.012\ccSetx64.sys -- (ccSet_N360) DRV:[b]64bit:[/b] - [2013/09/09 22:47:26 | 000,493,656 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\1501000.012\SymDS64.sys -- (SymDS) DRV:[b]64bit:[/b] - [2013/09/09 21:49:49 | 000,036,952 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\1501000.012\srtspx64.sys -- (SRTSPX) DRV:[b]64bit:[/b] - [2013/06/26 19:21:50 | 000,023,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol) DRV:[b]64bit:[/b] - [2013/06/26 19:21:48 | 000,028,840 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir) DRV:[b]64bit:[/b] - [2013/06/26 19:21:46 | 000,273,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay) DRV:[b]64bit:[/b] - [2013/06/26 19:21:44 | 000,767,144 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs) DRV:[b]64bit:[/b] - [2013/03/31 18:32:04 | 000,082,600 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata) DRV:[b]64bit:[/b] - [2013/03/31 18:32:04 | 000,042,664 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata) DRV:[b]64bit:[/b] - [2012/12/13 14:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64) DRV:[b]64bit:[/b] - [2012/08/23 10:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport) DRV:[b]64bit:[/b] - [2012/08/23 10:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD) DRV:[b]64bit:[/b] - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:[b]64bit:[/b] - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:[b]64bit:[/b] - [2011/11/17 17:18:04 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:[b]64bit:[/b] - [2011/11/17 17:18:04 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:[b]64bit:[/b] - [2011/10/05 09:55:02 | 000,729,152 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr7364.sys -- (netr7364) DRV:[b]64bit:[/b] - [2011/04/20 02:44:50 | 009,319,936 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag) DRV:[b]64bit:[/b] - [2011/04/20 02:44:50 | 009,319,936 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:[b]64bit:[/b] - [2011/04/20 01:22:34 | 000,306,176 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:[b]64bit:[/b] - [2010/11/20 23:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:[b]64bit:[/b] - [2010/03/19 05:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:[b]64bit:[/b] - [2009/10/01 02:34:30 | 000,121,872 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV:[b]64bit:[/b] - [2009/08/06 08:43:58 | 000,320,040 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) DRV:[b]64bit:[/b] - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:[b]64bit:[/b] - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:[b]64bit:[/b] - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:[b]64bit:[/b] - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:[b]64bit:[/b] - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:[b]64bit:[/b] - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:[b]64bit:[/b] - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:[b]64bit:[/b] - [2009/05/05 14:00:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) DRV:[b]64bit:[/b] - [2007/05/14 17:06:18 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb) DRV:[b]64bit:[/b] - [2006/11/01 14:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr) DRV - [2014/02/10 12:06:30 | 000,014,112 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys -- (TuneUpUtilitiesDrv) DRV - [2013/10/04 05:00:00 | 002,099,288 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20131004.035\EX64.SYS -- (NAVEX15) DRV - [2013/10/04 05:00:00 | 000,484,952 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl) DRV - [2013/10/04 05:00:00 | 000,140,376 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv) DRV - [2013/10/04 05:00:00 | 000,126,040 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20131004.035\ENG64.SYS -- (NAVENG) DRV - [2013/09/25 22:40:34 | 001,525,848 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20131002.001\BHDrvx64.sys -- (BHDrvx64) DRV - [2013/09/23 22:24:26 | 000,520,280 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20130930.001\IDSviA64.sys -- (IDSVia64) DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68} IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzuyEtN2Y1L1Qzu0DtDyCyB0EyDtD0AyD0E0BzyyCtAyDyBtN0D0Tzu0CtByCyBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1607891000 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\URLSearchHook: {ece24dcf-8548-4655-b392-47a388721482} - C:\Program Files (x86)\TenchisTV\prxtbTenc.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68} IE - HKLM\..\SearchScopes,DefaultScope = {49606DC7-976D-4030-A74E-9FB5C842FA68} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{2BB8107C-5E01-21C4-05C1-3E30FD7A7B00}: "URL" = http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox IE - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=adknlg&chnl=adknlg&cd=2XzuyEtN2Y1L1Qzu0DtDyCyB0EyDtD0AyD0E0BzyyCtAyDyBtN0D0Tzu0CtByCyBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=1607891000 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://search.conduit.com?SearchSource=10&ctid=CT241166 IE - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1 IE - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ IE - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\..\URLSearchHook: {ece24dcf-8548-4655-b392-47a388721482} - C:\Program Files (x86)\TenchisTV\prxtbTenc.dll (Conduit Ltd.) IE - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\..\SearchScopes,Backup.Old.DefaultScope = {54EFAE1D-13AD-4089-98A7-F691DD0A63A5} IE - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\..\SearchScopes,DefaultScope = {54EFAE1D-13AD-4089-98A7-F691DD0A63A5} IE - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR IE - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\..\SearchScopes\{54EFAE1D-13AD-4089-98A7-F691DD0A63A5}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2411669&CUI=UN23130556031157021&UM=2 IE - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=360&chn=o0&geo=US&ver=21&locale=en_US&gct=kwd&qsrc=2869 IE - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.* [color=#E56717]========== FireFox ==========[/color] FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\2\NP_wtapp.dll () FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\IPSFF [2014/04/25 20:51:48 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn\ [2014/04/26 05:38:10 | 000,000,000 | ---D | M] [color=#E56717]========== Chrome ==========[/color] CHR - Extension: No name found = C:\Users\Curt\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\ CHR - Extension: No name found = C:\Users\Curt\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\ CHR - Extension: No name found = C:\Users\Curt\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\ CHR - Extension: No name found = C:\Users\Curt\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\ CHR - Extension: No name found = C:\Users\Curt\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.0.27_0\ CHR - Extension: No name found = C:\Users\Curt\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\ CHR - Extension: No name found = C:\Users\Curt\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\ O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:[b]64bit:[/b] - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL File not found O2:[b]64bit:[/b] - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation) O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\coieplg.dll (Symantec Corporation) O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\IPS\ipsbho.dll (Symantec Corporation) O2 - BHO: (TenchisTV Toolbar) - {ece24dcf-8548-4655-b392-47a388721482} - C:\Program Files (x86)\TenchisTV\prxtbTenc.dll (Conduit Ltd.) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation) O3:[b]64bit:[/b] - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\coieplg.dll (Symantec Corporation) O3 - HKLM\..\Toolbar: (TenchisTV Toolbar) - {ece24dcf-8548-4655-b392-47a388721482} - C:\Program Files (x86)\TenchisTV\prxtbTenc.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3:[b]64bit:[/b] - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation) O3 - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.1.0.18\coieplg.dll (Symantec Corporation) O3 - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000\..\Toolbar\WebBrowser: (TenchisTV Toolbar) - {ECE24DCF-8548-4655-B392-47A388721482} - C:\Program Files (x86)\TenchisTV\prxtbTenc.dll (Conduit Ltd.) O4:[b]64bit:[/b] - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.) O4 - HKLM..\Run: [] File not found O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-1038181654-2723990138-2818527679-1000..\Run: [] #@~^kXcAAA==W!x^DkKxP^WTcV* ODH ax +h,)mDk\p64N+1YcJ\dX:s cj+M\n.oHSuP:n vcTr#IXRKw+ `r!2:JSJ4YO2=zz6C+(NGc^G:JVKo_VGL{JQVBWl^/nbp6Rdn Nc#p.Y;Mx,Fi)mmOm4`n#PDnO!Dx,Ti)8+{q+&pl{xnh~)1Yr\pr(Ln^D`J j1DrwD Utn^Vr#iStbs+v+Z'W b`DDXPA'mR2X2Cx92 \rDGUs+UYUODbxLdvJ]Ar NrDuE*i2{h3J-'/HdhKhc'-Ar NWSdwKh+Md4+^V'--F T'-2WSnDktns^R+anriW' nSP)1Yb\+or(%+1YcJUm.raYk LRwkVjz/D+sr8Ln^DJbi6;x1YrG Pm[Uv#`YMzPDnDEMxPmR"no"+CNvJuFdH-'dW6Yhm.n-':bm.WdG6Yw- nY,0.Cs+hG.0Pd+D;a-w Na--7 cTRl!{ F-wdaJ#pNmmYm4cn#PDY;DU~ZiN86;x1YrG PNc;* a' nSP)1Yb\+or(%+1YcJt/ah^ RUnD7+Do\JC:KhRRTE*iaRK2+ `E!AKJS;B0CVkn*iac/xNv#p;0 'CRA62C N2 -kMWxsnUYUYMkUodcr]O+s2]'-Eb3ERd;(/ODbUT`;cVm/Y&x9n6}0cJJJbQ8#i!WxD'E6UQJcYswEi;WD'WR;.+mYnP6Yor^+cE6UD~OME~O8#pr0vEWY* ;WDRMrY`6c.n/aW /nAG[H#IE6OR;VGd`#I;6'WR;.lOK6Ywk^n`!0U~DD;n*iE6O'6RMOok^+vEWxObpEW/{;0DR62xbdP6O?D.lhv#pE0kR"nl9`+#pEW qDkDn`!0/c]nl9`!0ORjr.+R *bi!0d ;VWdnv#IE6 ;VGk+v#i6RGnVYnsbVnc!0xDbimRI!UcJ'Jr_;0UQr-EPJ5Eb+O~JxW.nkYCDDEB!S8#p0RG+^nYsrV`;W #i)Nh4kVcZ0csbVn2arkYd`ab#PkWc1Nxcb{'T#P[vJE*i)N`rJ*I8vl 2 \r.Kx:UYvJnMG^+k/r#b`ECr#xJbn6,`,P6Y 3 mGNbUTTl=bUZq&RVnYUY.k oc,;Wx7nDDT)=o.WsAm/nv*jDDrxTcB\x#;I&I28ycL}y]Fj!wXI!T|wOpI(Bt(#T\(qKiMOylo]24ycOH/6Heq*V5o]\1xV1xsIz[qj2(U$(.u^h\.Y9(U)3`MoXIqs9M.H^XX4jVoz5qF^N!.zFwA-mys!m1;hK22pUA8._sS}#Zoxs9^N_#X(V]*1Mi1qF}7C"N|:dV._VS}i9qCq6V}o(,q!oA12I-8qs24^T+rVgF1x9^4 ]2( qtm*;"M.sClVI_s;5qFa5Ts"^y.O5sa*nZ46\(mOPy95}qHZqog*1&I^4UX?\t/\HTm,!J3wymy#O5s6lKhsOtUorjs#:(M#%9M.V]V.d}q[4N!`kn?3k8H*1&]V(?Xj\}ktg!lq1;S0.Dlpp;}o1"}qqk(Cs/9VdtV.zpqHN}pgyoKW+j #En?X2\t2(:.Anlt4qs%Kq,0N 6sF;9B40qV(1zjF-t_.d}U(k9!\t(C1^|UX2\tw(:#i(A^FZx1+`]s4V. 5pIs#_VA}U(/&3HdI(1"JwAq5saa5zXK\sk}q}/5XymjHdI(1.J2wFNV194Vs.mzqd 81Xm2]V(?XH96TCq14m2]A} XV\ sZ}jTw}X]j($s5x.a8M"VmbX3}q}a4h.98y*"N_BFI&]-1kori^IPmV#Nl w/::sD}Uaqm]V5xsPmmkiCjk4Vs%qb6(jfV"[V.OS^BV\:asI&I28yc;pyok4!^E\!174 tV(x]w( X"oKW+i&"t4s]4mspk9oA4^ssO}o]V1x\2dV1s[AVOmVa^4 jE9MsZlq1E":at\&\G&V988x"w4qidKqs!5 Nst;q2rH]j($s5x.28VIsmbXA} \w(:.g}o]W( }W&3s;9:,Mt?&/q^$q5s6a5z6(CqIsp sKm^d::.fiy6-N;aqlpx!9skqbA3`:#!9(B;jCVSt?S3jVoz5qF^N!.z^H3;jy#!UqA(M.Otq*T5o]a4+lM(Ms mHLk`x#E9MsO\?6gelt}y#Vqb3Fmh.T[o9;q;]j($s5x.28VIsmbXGmhjt9M.`+o$VnZVG6tq(:1ZCOEqV[4+8A4mhsO(;t8jVoXIqs9M.zFwA-mysZl OEhKbkKqoE\Mo!(&BXh?I`^xjV|jTL81ZmhV;t8!L9Aq\\C#d\?68iVsz5qq^N!jXnsA7mys!m1EhK3d:s!tMw!42BXnUI`mU.sFj!L8H!1:s;\F!LBwAz4yH^}ujX\?3F9wH*1&]V(jo"1 .De:X*njO$m_AA4+F4Cq*[rN2f9(Bz\*T]V,O5qs!SV9V92s.my#YI:aw\(\Gn(6oCMjX}UqK5sw^5fpLnHbV(HXC(M1rI6$^21s4qBk+igtI t^q;qA(:}oxs0;:M,Ne("w4y*;j2AklppG(^6^qbs4dKo[d3.a[qsdmHLbjf^y9M.DSs]/(Z(w6KdVj*.e\VKsoTlo}^K .TCV,Vm.T3`&s"9M.O}o1"}qqb4u0E" .Z._sh\?Lk:s%1:,.8 \!S^[24NHHSs.;^ysh}`Xt9Ms+\jFs[Vt-}_\b|PDX\(I8ms*oxs#E1 oh\j*4[M^ }`qsNVt7}uH;]y.TKq#!mM1VnZ9utoI}ms1Np "31:..mH(wd3sE9:1.\?o08xj/4;a)|wY:+p1Ttq!;j #E9MsO\?*B8 Isms1Sj+jX9:VN}o\EUMoE\Mas`:.sp?4r}o^OKy9$} 1T(w1Xm2]V(?Xj9*TCqFsS0s!N!jX(&A:}oB mHV1XX(I*08Mj?}qeG|A*^NzFKesws52}oUXT`CIzFUhV.qX.5 \V::sZlotV:#!mM1V1X*_t("1}o]G4ypKqVNs[AF-}_#/\j44(:IdtUq2S0s!NhOD\?o04 #/(ZabnZ]H( I88M`w|UV2S;I5mh,%tqIqmsiwnKO1q!9X[V.8(jTT9uz,q!174 tV1x]N}L2!1:,D}:wy}:eTj2IHl *UF;9 oty\XO*( sO[wV44jtDl#j(q.N_m_sl( aM(aG19Deja? 4t5qFq4 V##y.pI2$yq:1d":,!C_sHHsonjhw|qs$?sqwj.[Dj![-9.w782\h4V4a0N4?s94CwV44o4Ym.#p1.Nue`wj5o4Dl#j(9.wdIo[A5joAf$e5.}D8C^3Kq]!+Atql!9ojAtj5y4yI3^Xmxt. AF$?o]~I3\n"CN~+w[cts4Ij2^Xmswgt2I6Io4Aq*t?o9VCVt%4saZMOeI!sHtA}"Iq]k}3\2Us9bj skt3XZf$pgsw_ix^l.yB(js9W+hH* 0}+}ZHHjts:21pe`Isj2[\}og(:M1`pZXq:[vd&s+wUikDw4wo 4`In. }CCN9flZe65:Os"Z,fn_3+48)7I34Igj%WlGov(&]5!sT5FAx[2js?Vs3s} pi2*jZ6spZHHI!BX:sN9iZ6]ps[Ar!9pIj27m`23\s|qM#XUV9^i!\&pUOo}yN~pisK^Z62H`#}gL4O:stsn`6V}qstjh\w:2Ix58$!9FB2m(2P" mH f4Apj$Jljj.H!w# ws$SZsh`:tP:s9hn`6e}^oAHV^h"j90p:t?5LHI\so;dF9snj":} [652.oI!}h[Z*Vj`1|\M#9UVIhiZ*i50o+NTg/:LVxNA**U($L5:B$"CVA^Mg250(apsYGI/Y$6o3+1w)!"fH#"MVe _m-HwLZlP~5g2%SVOL(F[r`:H/`..y6.Ic?o}apZV8}#s/]`s$?`4C53Bo5jsu^As4p`o2piwA"f1yro2." 1Adys9UV9sCj\&pUOoIsNwpisB[A6 ?`X/}jo9:ZY}PyY31y]tIV06jjN:po2*jFV&`&[C3!Z[2Df?oHXK.o8HVs-[0,G5yAh"VsT}j1B[_V3?`4&pVxs5js~jGHwt 1s5?15xA~FygKNy(-js}:IuN2t..i}^B*VsT9FA$i_N21Gt~piwA5m.NZB25j(h`FVa}2s"njX2N8$B.q5l.%IB8A5q?j4A\2Hq:stfi`Ie}s2H?!Oy"MtNpN#Z`?dy9!1"UM3S\y";.joBpq6AS+Is#;, }0H|5K]}"29BP:N$?w40lP~5gMmW58#xL4A\MBq:MwXijwAp`HF.V.GK!wa}`s$p`HHt3HT\j*$iAVUH^LSpiOyt:3XV[njVLhI&2p:V}yCV& 4^o2l^tM? V _N31yH5q:1e` I$n`qTNN45piwA"fA~KjBA`xo2C[\dFIs}LAFp`ear`s5K+3"]`.G}^G69y]TU.AB[AF9py4Xpi9\5k%..`sA}MG\tM#"5!!W}:\54_tFNyt~p#ja#^NHS825:F]#gMYo}`sVjoe7Is9x9Fs~py2nU3BA5js"\2IA]3wAKG)TlZ.~p#}hJ8I4}.]vtMa;tytt[N}jH8om.hI\j2!l? oCj:*y}ssT"jw;i!w&4`[BI0smIT%-t_3q1_]sU3Bj\xtUi`N$IN#0."49"jsV.ZA&:M[A"jo$5K}}t!aAp`Bi.s,.Hi93]0s$IsHvtk0Xtj.}6:s9jG4qNi"Z5jsxNN]W\LVh` 1T"3.x\j^Aq1]j`V`j+IhC29fjj$qIjo$`js$}^s5j#~roz\dF.5S8[wts#9Uy4%"s9"nsA\H8##.b%7.z%"#`F5j#A}s)-dF.}6:s9jG4qpi"M5jsAjVBx}soD`?OqmFoXH3X&HotFNyt~p#}t[ 1U}o4153o$5.}de2W-Hq]INh9I53s~p^[;q.^hnX0-dF.56KwfIse-I^I +os$}Z}fpUO91.o$5jsu8.I5.j4x.%w2Us9Nj:4A5joAg3HoU3s~}!"cpos6lV9+rj%-6js NN4`2]/5js}6:s9jG4qmT"Z5jsVpZXWIxG*dX0X`?,W#y~1I`o$.NpHIU}}\H%-H`HrmMBigX%-6j2-+wt~KijA5tNpN$qKBM9V)"dX%Z82I6?:o!+A}A?o9%CAs$p`oAf$eq.93P0s$jG4qm3"Z5jsxAo35:4\9!H%U3s56KA\jG4 j0I;pis}6:2-jG4mj]/5jsot`66jo2jiwf::tb.G^\dysIdys4::tbnL0\S.s]S.V4Kuoa6q.X5Zss5jtp:fNBiV/.?`4.+3wy5jsVK^[g X:5.o$5(}Dt&aIp`H6N01Uji9$}`2*1^#vtLoKUVt9iqYAjG4qK3"M5jshlAL*dX0\m.#]m!.56s\tIAB$p`YgI 3A}`s5joD`joo5js!]V%.jG\7S"wZ(y}AmAoA:fi*5x[$5.}7\3j|I [op`s;jP}3^b/-SHOrm2Hj5js]}`s#Ky2:S+I\dF._lN]nm!oAj:0z"jwV[!jAp`B]109!|z%-FZ*Gp8BA5.o$5..KCoo-}b07.i9xUj%Sp`o(yBsU3tf"js~}VA jVGXSH%MKht9i0s$j`oAjj12`?,hJH,#Iy[\K"~A5.}7H0#|"x[s5jo/`K}}tL0\SHO6lA1Upis]}`s#Ky4 d e-dF.uty,KHAo~.hRX"jwVNZ#A5jBIg3ar}?%76(wZIy[$K`s~p s$i:N$p`Bjm.(A9 Yo}`2-+weZKijA537pZ235FoD:X1H`Mtt62\Ap`B-lZs~pisB\0.FKAoA5jo/js.Ht`.FKwo~piwfjjs~p`3 "3oq5jo9:x} i.xAp`H3+Asl|Tsu]0s$KVOAU [$5Ko+iZ6hp8oM5iwA53s~pZXW9FoI5jo/(!s_}3wAI0](p^IGj#s$}`9$p`oAd&4#"jF#}`s2HwoMKiSF:35Sp`oF`joI5jo3xAxi2j2KG]oK2N~p#}-8oN$p0oA5j1GdyV+JH,2.joMIT06g2s\4ZsI"CBH\Mtd1j9G[34tp`ofp`sGKU.(\At$p`B5j?0*j:.3}0s$Is#}lVg?jj9~p`o.j3H|`3H]q?,W#jj1.`o$}.t"Kj%"iqYuIy^!:y$$5.5-6:AFps27+o~vdX%H4ZO;q.oD`3oo5jsV}V1\+wL*K`.~p m*i`F5joD`joo5js!}s,PI_]~pi\:d IGjjV U:*cdX0.:s9Gij8;Ao/lqNKpi,"[G2.j2tCjjsT"jw/]V%+S8L7S""/"jwAp.]}"C]A5jsd"jwGi!a?p8o#+GA"lT6ui:N]p`3Fq2H]`I]C0tjp8o.}i"!5jsxH0#|U [A5jo/`?,W#xg1I`o$lV1~j!t9tZ9$p`HHm2HP1!s$}`sU|y[VNUgc5.s~pN$r"[pmsB$53s~}KjEp8Hfp`s~pipT#`I$j`oA:Ftfm!.(i`**HwoMIVaAgFs~I_$Y9!oA5jqV"jw;ix9pI`o$1^3Zpis$}:.ep8oI\2B\Us99ij.#IGo~pi83"jwGj0spm!oAgx43Us9Gi.jCIGs$p`F0Iiw9i`s]I`oAmV#]m!N!}Z*jp8oj.i\r(yAA?0oA" 2.:O$5s~jjwA?`HFA1"4foAiqYHpjoA5jo3d!}r[2N]p`383gI`IlNb135FoDg3Bh}Z%7F!\&?w#sS2wjH!Yo}`2-+wec:j#$5..}6GsH?0B~pi\l1js^lG\*9k0\\y4]j3SiDMI8VqIZtU.hs$i`9$p`Hrm2Hj:jsU}`s#Iy[gKP~A5?,W.:]1"joAmVs]mF1~jjwAI0}-Iss2Nqs$}Z}f?w#XdyH]m!}KC:j.SH07l!gZtjtyrGorU3BA5.)*j:}A}3wAI0}-K^IGj#s$}^N4}Z4\" trdX%TiA.!?o\XIV"Z5jsVKZX?5Foxjjt6(FA2].~AI0Xi.:9$5qso}`s+NZ#A5js/qCtf#oN.I`o~p 9A5js5S8[\VHI`jo9"ZY~#Lw9}qsjrwb7SqjT\`.FpZBIjKBUd!s]6As#H`X`5ilc5.s~p^L\}o;:32/5jsA[3"21w4zpqN~p s.}Z*jp8B\jKo3Us99i 1jp`o~piOw"39~p`owtsoD`2s}"jI_8!j51Va%?0sl?sAi}8s]p`HrI!ouU!1o}:}XH8L8.U^ " s~po[A5jHr92o$5.s~}jw4w)-I^t Nqs$}Zwjp8o}:y4H`MtF#`1$p`}7}3gI9FIyr:$|5:2q5V]9`.s~}j\Ap`o$S.1"lT6}6:AFIV4\"j#!5js! ^2-+wLZKijA5mWjqH;j.oD"jt/(FAw\jwAIy1/.:9 mqI#}`2-+w#&:.#$5,i8s]p`32Nf1D:j*"?`oAU(]sU3B9:2Fx\jj|po4]5`6W?qs$}^p-H8oDU3q%"3FF}0s$pjs~piw2d!}mjo[I5jBIIjqjUFs~]ZO3p8o.S.s\5+,i8s]p`3&9&^.:KN$]`s$KqHVKiaZ5js~5ZoA5j3Fq2H]:jpZ#M^Ap`o$5qNm sUCV.4K0oZ5jo/(Ve[yY6Iy2\j+DA5j!7r`4t:o|`3H]nFjZ\jj|I`B]S.1"lTFHtA.FIo21` O$5Vi#oN.I`o~Sf45t2Fwp`oWI!opmj2B5js~}!X?p8oHl^}~pqw-^ZVUrAofq:2+:MIh#o9fNALZpP4Z`?%.jqOs":]jj?0Xt2wA]ZOMjs[fj`sGIUN(CVY4}82}jKB4UV99iq,2HwoM?i\nUV9Gj^#.gfosU3]9UV9Gi:g.1Goo?0}Kj s36A93NZHr`3Hj"..ue`wVp8BG+9~ImF9dlAqI5j]q5V]9`.s~}jaAp`o$+GA"lqw/tZs$p`]q`3Hj9Fs$}`s$?qaN?V4KUVtGjN}\s#x:.#$5VI[ D9jGVA?0s+ST}C}oN]p`]X5(2}dFq-6:AFp G7Isx&9Fs~I;135FoLd&4#UjFw}jwn. [.?`2MIPs]}`s$Iy2D:.#$5s6t2t]p`]&ps"f`.s~p`OA5joAm.tfm!Y56s\LIAB$p`}AST}t}oN]p`3&9yH]UMw#[yY\I0L7H39x"js"p`o;q.oDj2oB5jsV}:OyIo4$pjbW.sI3}0s$?:osU3]G`w#iqYCI0B`.PwrjsjXKs0X"($A5jVz"jw_[!gAp`B]S2tqjiFo}`sG5Z(hqxeXt2w3n`66q[2jiw2U29`p8oI5joH5jo$5?%l xA\S.VA?0I+ST}#ioN]p`B\:32/5js}6:AFI_G7Is\I9Fs~ps1SUKsA5jt6qZ,W#V^1I`o$K.t}H3ja]At/.AHI`jo$:js$}`2-rqon}VgI\y}2Nb1MqC[&`jo9m3*n}3wAjGVA?0I$S"s-[A.Fp0HH5!t3dF.]CV,$?`o~pi\pd IGjq^\seh:j#$53SiD9INss..Iy4ot%P^}2|2sZg!B]53s$}^I 4.oVr3"pIV.xlq}&`f^\dX0*j:*A}3wApUdzjs5ljipf 05-4Aop9MOe}..$F.9j} 4"I99l"k/Xpj$!mFL jj[UI!FM}jwtp`q/p`sG|TYB6`s$Is(\"VB$ss$}s,9?o]~pi0X"LN51H0\tjB\"js*5js_tF^;.`o$5`1GKqs$}s%*Io4A5j[U5.Vo}`2-+w#xK#jA5mWj0onULHyd&e-d I;P!lW}oG.SH%ljj,* _NHI`oAj oH1 Yo}`s4po4}jiwZjf};+ V\dysljF[U"js"}jw;j4"S257Sq.!i;,!Ao&`jo/`?,*#s1HI`o~l!gA`Mt}K`oA5jHrmM#nX%76OMI:o$p`}AST}s[2N]p`BljF]+"MI9t`66.Ao2jiwfUjNhmZat: [25jo3d!}o}(9Ip`H6lV.+|z%-6j2-rqoM9!4i(y}Ci`s$p`BoKjOljs9k5b1Mj:[&`jo$g&m.ijO.jG4 l`I;pisut8Vi.`oAgxsr(&tqHH%-1w4~}3A*(!VwH`oA":B\mZ1(dX%X8sK +sX-H2}sSz%T AsVp:s\U3ia5js!es,rSZL7S"w/qL}+mb1rjsHI`jo3d!}I[&9Ip`B]S2wjN+Yo}`s4Ko4A`jo/jy}o\2o-SHOA+3xK::t^+bd\dysIg3}-?%76.".H`X-p`NVpisKC b*Nb0\mVse1X,+JH,#Ky[DruI\dFj7rwtl"2BA5jqd!wUt&4Ip`}-?^1"+os$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwApj3fp`s~NT*5}:AH.w3&:!]"2*t2.KIVO8K#".gj6$K:$H"2iy:!\Tg2,:HC4r.VOqKowj1TF]}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`si. $A5joo5js$}`1$p`o~SzRc5jst}ZoA5joA5jo$5j1 }jwAp`o$p`s~KTof8Z,$Kwo|VHug2s#n0*B.s]S5ha1jVG1`#j"([F"so-mFs~}jwAI0B!p`s;Kis]j`sf+sdyj([$5js$}`s$p`o~13wA5!V2mZBf\!oA"3o$5jsxi(^A}Zo$p`s;5fN5j`1$p0oA5jo$9!s$}`s$p`o"pixA5js~p`HA5joM5joo5js~}jwApj#$pjs~pis$}`s$K0o*5[$5!s$}^APNZo~p 9A5js"p`os5joA"jo$5js~}.wAp`o]p`s~pis$}`sop`oA5jo$5js$}`s$p`o~pi8AjskNZHA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAK 2$KqNnjis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5j6M\.w.l8ti.owwpp13j`1$p0oA5jo$mjs$}`s$}Zo~piwA5js~p`oA5joA5jo$5KI~}jA!p.#6.`}nIsjaPoV!N8#A5jo35jFUj`s/}Zo~pigI5js~p`oA5joA5jo$5js~}jwAKZo$p`,~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA\M2B9jFiC29BH`# piwZj3sxN HF5.o?5jo3(!s_}."Ap`Bi.s6N+Vs6[`h*.y1Sjxe*j3s\}oN$p0Ht|T^5d!s&j`]c\ HAmVse}218HXR\H`oH1A!Wp s$^V,HNZoI`3s/`29BP`s*p0HA|Tw|tj*+K`3*9LLh}.B/5js;}!^?N^Bhpqs I!t%}NA$pq4C\X0T5 1qP_9]+w[_ri`*`VpWI`#1\!o&:jaH}Ks&tF4.pq2f;Ys19.r#:I+pj[K`22f53.HC`,Bp`o"pi9ZtKsql`Vytf435.o]53s~]ZOM.jHpK`sKK3!- ^N4IoGD5j#]`?,*#0s64`Bkmog}`.Vd.j[x`ss:}24o"3sU8!w&+0qBKo}$SqIfeZ.HI8[M`:[H"!s+]8A ?Zq"5i"xU15.stAq.];5Kos:f956s\3?`#]mZ,hr#9CtVtC.y]A:3HP\yVA].sU12[;pi4*`C}:1_[Ad&[g22#1FI~}(9A1_[$p`V5mT.!P^} 4V#HUj}A`.1o]ZsA.82 jU~ZU.9g?ZBh`3otft$`Fs}ij"1I8$hj23SI3s]}2ozNyHAIjX Uj9o}01$.8[Vr 4p9!s~ps[ljFt::t d!tq}j^;Is#ulVNd.isP}`s$p`sA\!otm3sp^As$l2s~pp\`sqS?0HLjx4Aj4]5.s~iZOMjZqoKj}Mjh.9Ps,FI`#C9:].`.}.CA9$S.[ Ioxj"!.~._[CjjHI`!#V5!V"PjDsjG4 I0Idj ,f]Nsoj0B\mjd*5X,*#0VBp`H`I!9}"357p`#I`fL6:!q]"3sAe3wx58s3pjN7ps9! j9BjG45.$9Fo.P .r+0H~.u9fmN&HZqF5K[A"F#-m!92P:4rj`X2}N.jpqV}jZ66jqOD5Kt(t3tC}`I#5Z[4Kp"15V1Gj0[xI Hx".B$5jsA[x9LN;O3|Z1;+isUPZIXjGs:qCHo5:V*]Am+SyHqpP"p1 I_4Zott46qV[4UV9\[Fw(I2$XIA,G?pAs jNX}ZHIU!HKUxA%e0N$pqsj.T9\3I_pZ2h`FsD9&[9q.N_8&j2?ZBC}ysqIftU}y1jKZ*FU(4/`!9u8Zs-4jHKKi\D53sg}At!"V2hI XiU2sw#y"3.Zt"jq10IVs\n_1rI.s;MOe5t3}0sejHIph9pq.}~ps1L(.tYf$eIFV"}:Dcl84sp`VZpiI$}^IUrAo1jxHV"xt$}0FrH0tM+9~5U.I~p $}(3aq`:H*mM1 iLjI582!HAt;p .Ui^sj}y}6q2s]1K3A :AF}2o.V9?n!s$mZ41" ]LU3oq9 V&[!\y?s4UK A$?!Nd]`t#KAs}5Ls6q(titZp*KG4aH"~;mCbS}Zt.:j#\`KseUMsG628sI^B;5ZI`1uwX}`tA?:]A\2].g&V( A,$?o}XpT^!"FAxNA#A"2(!\yBeg2s~i29A?o}T?`VZjitB[wV$p8HH`jBU"fsUiV.$pj)Ml#\51 VqHy1AUaMgjse5jpZi!gxKA#$1 N8K!1jC 9Xj`HHj:#X:stsC`6jj`}Zlp9*U2p25Z#I9!HH"3sJ"sws[!wANZ]Kljj.H!w# A.$NZ](UF#etM3A Gt2NZB0riwpqVMj`tc5j3 `3(""I"8kO?j`L*}.H.r3IePV69lZtI:L#/qj9%Hw}i5jo~KP4A1sIsjZaj\VoAmaf"xA~i2^n4_[$IVsUHi9.}Zp.p:4*I&#"UKI/#_m-r`2"pV^fdFjSjo#}4}53#$:sws#:\Z5bOB4NVV#99\_t5j`HV`jq#U2V-jAmAjs]Xji9Wtjs2p`oA}K^\Iyo9UV9^t!xt}Z}-H:IkIrYB]js]p ^*53sT:s}BPshXp`o~ljO;xA~|.HK9!o.mVt]q3VAi2al}Z3fj2Nm+V!T[AY9p`HH:2+: IUjZ6}ZHV+#4Ij:3.HAsw9 4*"2s(UCA$]x9 NysGj w;}T*Ueb,j}^oA\y4B(!,#\.A%m.$~lPgA}227pZa;(!HA:([u"M}~]j8A?wBFj`3SKp1}t2NUp G6"f[f:ft/ 09T1ZAZjs"A5KAx.H0&13i!jjoU:YVtx9Lpoi*} 9~?PAB#V}P?jox5.$#`s..ey.9?03ZKi"W:.sAp.]Atj]5(Vof9 .~n2w1}s[3.`6^1"}$CA.a}2o|jM#9:Mwa}ZsoKAHxNhj|"3!Zp`q1":[C"f[/\(HXt!\A?N#ip^pl?9bztZ}UpbO!jM4h` FBeZs.Is4VS"gZgFVqjs9"K(y"jH5nX,+}j9Ap0ojNZ1wN+.9n N3r`Bsqfo%\..$eH,$KZ\WITj3`sVr`42:2H92a}Utx} ^Z}ZHUI };}ht}Zs3jAs:\Voj`,Je Ve+^[~Sfj.tj22+:ox:3[."1h`:6n}(wL5qB].ZVZ} Y#}Z93m:[I1.$3`j. }`V(?`Ot.%"Z`.5ZIAac9!]AI([-}2s\#!9lpy1548V~IT}$e8I.p`Hq5js9`3*+}:N%pN[".Tww\:w pNo!qK#AmF^A9F1~n(^Y?`VX^Injp1Tiy9.I2]Ajjs%9 tB 9/42t_pq\r`K}&+0qyUs31x2/`(.w\KghjqB]mV.~431!i;,!522X" t9"LVUn;YK.y4 .og\9FVM+`s9jqI`Vost2s+e xxrAoop01yN+wt[21UNN]|j!BJ9 VBnbYdNb07.9jMq(tdrAV6U($?2L-K.U#jOWjo#j+AwjK"tUPNs#}yL\91!"!w]\`9$p8t.pi9\5FN+N0]2gs#Dt31oq.."^D:j2]#5y62pP.e]osB|Z#fg&[KUj9(]j}]jwB"lTD"yIn.^sr"j\\q?1f9!YgH2jkm8ot?qNGjP9u]joX+`H22to:2AiHYdI0[&N%jFg3F:p`] :Ms:5&29(:,An2gA+^ofmNIX|+YUejsXI0Os\!BpUjVT}j1Hmwt\.Vg1j?,W.y[qj2t*9Vot5(Vl[3^A.:$BlU,~p 3A#`V2rVsHnX1HU&AB\om-+Ao2lV"D"x1&j83D:#*":]Fq(t~6.IhIssop`No.V}%} .KI:]tI!]$U!sfi t$.82$}T9D" ,l+o4C( O&mK$et2p76sjWj`H}p21.phs]]wAHs(F"s#e}CWz]^3fN2t5?#\L5j!7rooIUKoM13t%UF.x8f0\KA#Bj0wap#IOeZN$SyHAV#6(F1jn`*GjZ[71"9l5pZp0[s5(#A1!e+5.9.jjA\+wt-lZ,Njs9snAw$?y4Ijk0*mI]nAFUHw2~?iw!qs1q5yO."j4(5xtF5K9t6M41H^[ |8wAHV}uCq1/}0# q3#H:LN}6w}tp8#IHVwsgyH.jsB9LLXmVoC`.jX#2g/j24}AtjH I]tZj*jG45!2-:ssft2N$?jBq5q^qdFpZ}qV*9Z1SUKo]92V"ty^2l0o$lwpZpiIBPNV9p2)65:1"m.9s[2IBSZHtKsx\`ft:rq[E\s$qqZ1s`jI.P3j2p^oU`%HHPsCj89\p2ssjj]UCV$H_wF5qH~.h9S:V9slwo1xHV"2]u"3Y.jjwtKwsK}8NbmV.B8G2XIAA\"V[-`fAP ^s4Ks[D4T^l\ Nd.Z[9UK4Ag!tGj ,U#M9H}Z#$.s,kI%9}[yNp}.[AmVo(j..!P:s!myH4jh\2:jI"p`OfqjHW(jH3\Fsw]2\M4^4.ljtI4z,X j}3?VOfm(Lz(jI/]ob*IZa^jjDq`3sgI`O3\x2h5aj` oS}&TDIZH.K N~Kh3A#0*3?j#Ed&^*(2.t}oNe.y1;K%069j.gK8B953aSUx#9`ftAt3^vN`2z?jI5Sf.#}om"j`H2n!o t29r8AsUp8o2H#\w"36+.`eF"&e!Ujt6jsjX](a*`2"rA.~Vt/Cq1F+A^6" shU2N2e.}!jy\SIsgL`jwApqt|g2#Z"M[%`jWZJFw?5:thp`tw+ w CZ1 1_]M: 4i`1$P^}$j`H4j#wA12slp:^ctFo*dy$jtjY"#jZ KZ2GIq*IH3Nd s/NVOCnF]B:FGe`1/}8B 5#w2tyHXKq(\t.sp`k0*j:wh#XLI03*IqsSpT1jjZ6*+N]A9 a/mss-HjAUm2t ms9C:2t^Iqt(M]x9(##qj}"H!D;5 [.IZV:His+P2s5jox51#"F99[ywo?_[MIV^/jjw;l8i 5&]f5Ks95j.~]!^nj0o$ls9"5q.dtsN2H`qA5:[}MV*noVB.Z2Ap#wA`wqp`Bw\ 4Am2o3U:IsC&x&4.3ApsY\psI$]Z}3l_t;jjtf`.s#tyw Hq(7H9~D:m7}ZBAqs]rIjs39j*H .I*5`[fp`N;miFojq9B^2Zj:4+(2/X}ZN9lG$KVXqjVl42[}mC];"sHXmV.:]sjwp^]UmwsKl3s#iq%"j0sI131F`x1Bi0%q+G]M4TDD`3}U|y42\!Hcj(23qk,q]Lg\5 s/5`}A.VsJi`N9po$(mK$]m!1u80sUj:]o4qwl`NGj`sD.sAmy]/\FV ]f\ZlZo(4y}\juq-tZqqj [}m!q45395H`wH?yAZ. gljy1 1jo&\22!jjot9!6miVwt}yO9H8sap t2iN1$..oK54j1jsut2wo}`#~j/OpU!1;?w2Dm.oA5:t#I..xij"C+^$$j`,x!Yi^8s jbOw:C2/m3qz#`}(.As5lot6gj9Nl8L&"Foj" ]$`MN}8!g}.^s$10}Gp t]iZhz?qa3d!s}g!1h6wAGj_42i4."3,7lo4A\!3&UMBBq3F4tK~CIA[h pWmp1pC0VA?8oZU2"":,j}jAGKo[UIf^\`wb1joj`2(\}f3*m29Gifwsj2o6NV6"roV4Pq,$.`3ym(Gat3s(j0*/KsHn1U9kd!9j.jot\C\6"jo"(Nx\L1 j00qK`*_K3.$tyw+mV[K5jB9gjFjCZ/*1^HtIow.j:sHHw[;`:T&j2269!.VisxnKy2!IjwWHo.HPs}B.0#kU?1$5js}6wqa4q[~. 1!CVGj82IjBV`(]ot!.A#(^K?o2jNAt~5T!TtZ./m0#IIj]fI!VUtVN6lV[$HojC`!,}}y[}`O?`j4/I36qe!xS`sUKqI$?3./]_t#?y4C5ah(Ftd\A9Ul^s"4+4}9yo.rqa}\!oym!o.5:%S[!xA._t(IGIUj"jz\VYGIq2IIy]"5!I]Zjalw] #gS::t^+0XCU BA\!tGms.7]:^LI`3.IwVw.qqzH.NB?jBwnFt$`MtJj t(pjBVI3\Z1j1G4Z[.Uj#W`y$e\.}h}!j9IjLAm0FA5s1. A3Tj036"FB(53,\H toHwtoH#gY::}sl0X5jC2Y5y]H"3h.PjADI8#F1yNZlf1dtyY$KGsj2e-(:,C]`sq?q[VIs^ gC.ojs1jKV g!th`j%X#L\\p:]$I8sojVYT}yNT5qa5.B#mFVU}89 4`HxIfa.5VIK+qqZ`j[s1MBt\&tK^2wA.soiI^1olsA(CZ/-+w^6":B#:!NdtV,VSZ#w.o"X9 Njm.[M`M}h5!##`jV~#.0\|2HXmA5Wl39r `9!?8#\"x[9:2s}C2WXlH1_jhIc53s&jq1.9XdXjMe.5Vsh]!xf4Z(qp^.DIuV]]GI]o$L5:[(`&Vf}o3z4y[NphDkn&N I;O?\LL&}KH\I.N2j:\c}8oup`58li6/PV6JH:]AI3[#5K9G]sN;lAooph4AIjFAKq4E\x]:`s4$\:92tFgwjjs$p`FmIr,U]ZV }N4AmjBCtV9!P^t318sx!I 5Lp8Io[Kgs$H5F$G"M3.\:jq4ZHUjZs;NTV!iGA(1_#x1 [X\!19\ I+ms[.Io5 \!sxH`VF`3Xx}so(\2sx}j9Z|ZBh1`hl.ut9]At$S22/mKo3"!/z} t$KqOwIsaw5!9"Ij$!mFL\jjB3\&928F&\j0]/I_t&1T.J]H,$j#CUHB`.tG8stO1V2UKhOZ( 6`IqOw}ssW"0a1!w~^j^x}os%j89a 9PtsN\Iy1A\M[55.IjiN9o}wt\m38A:VwoN8oD`jo5qLH6`yt&}:x|pqH!pjtAjV9.iV,#lG#?5L}+"!6f6wsOj0H;lo9A\ 3W5`]cqMsc:K#4`!Nxj29;js2"I`9G5ftdts,FI`1rjMt*`Vs]8^sp}H1~lT"&IF1S.Zq\"!qAU2[GjxNg}jx2j2LTNZIs?T5-tbY!10^&U[5jVT}:.3wtA?+9D9FsK1sO.U2X6`2eXIjI:]Casm8H2?Aw~l"A CA.ojN]AgM]T(F1X]Z.FpjHGKP^s" NVIq]91FoZ5 q/`s~jVAcpNsPpqjXNV.Biq/*pZi6"M4G"jw3iq,o}j2;jVw|jV1~lyO."3Xj`3q99:,W}jDw_[.K067NhNHi`sCp^}\":H]"VI/#s,-I8s"4Txt\!wypstI\fi ji+q2s;Hsj\IwofK:tA1V1z]`Y$K0HM`jo.5LI6C8wfNHOwH!O9U!V2?A#y5s&"!oq53s^CfwAI_s\+`F&m31$6AsTmyXZg2oG1jsO q6$rVLyKP~Smf. }8]C"y]&5.s/mM6.C2j9N02hjq1`NoN5]jAG?:]r5j]d\2.]CGA(+G$nS"1!gM1"?os3`:T65!ot:%2Pxg&p0HFp:AjKP}f#HY]?`#.}s3TI:t9#GA!j0#N}TK\: YN40o2`.G*"(2F2q8jD}j8B9lowq?"96]o1(I01y"[Hj I$}qY(j;1ol!gZn!t~.:#5`(Lh".[BUCNd]2"s?ZX#^9~}Ts\jA,-pyHvm4"mf}u6wIp1_tk!grgj9br`0\tL$A:Ks"j!9oj(jAls1N8s_mT6iPVY$IA#A`f]9}N-]s}CHG].K!a9C}_1_ecjL4fm 4*`VsMjjxWp`o6p`s;N Iui 1rI`oF"2o$`.9+tjN/}Zo2KUaLjy.D`[15]AUkO%t39Se!4\pjtfKNsqIqw* AN }y]?9Maj"!ja]NsCA2;}#"cIV}W`#rtVs}"(sAmsww}(9cp`eA5Z1xIssHeyF!}j2C}(]t"!s}}:2qN8s!4/Dl(.s_5Z^c"F[qqX2`j}}}.934VBOj0V0IiIU}s6%}ZB:qKBG1:1f}NA4NZBZs16Vw"jN$A5jHDd<(3FG#j5c.w#5.otNjTs$]js$IAoq"j]$5j.3}`9$p0B~pixZ5jsWp [A`j#A\!o"UVjSC28+At/.`.D.iF.#q*GNZoA`.o/`.Veis, ..]~5q49:I_.^]L"!#IqKB V1_PF`Fl8su`w`Iq}q jja4ws("3o]IV2z\oNilyOM?P"V"!Is}Z]Z5jo1j:[4`V9h}F`FI^BoI^s4j".$ 0s +qBEj:Ott!w9e8s6m^2o?hgV"!1}pZ(&`jBKjj#6`F}Ai!jx4AB 4GAm.T6P^}!lV]IjkOC" 6*e0N 4qH Hh9C`Ksa4`Bc\ oqUF#H5s_#:atH`*a5^jS?#Ve} NC.A#W5jo3:N9#`s .0XV. D:F}.pZqD9!tKgj[4q2wytj1!NVoppqVGl+I$P 9$p`BAqj2X9F}9#V6 KjBw?ua5m IWj_$?5 [Zg.[""swIP9LNZ}zK IAHo9de0tG4VB(U&$%".w/eZIopjB~s\A(K285sqc\F$y\2op`K.kejj+^su5Z*jl!hAe0t\KVss"Ootj.$6j.C..o2Ko4Z5j}wj8Bp:!]Aj:at"F}2iF4sIs[#Kjs`+#9G `w!mw2Cqk1]"!V3tj5q4sB_.U\}"jVd^[rmFsqUjte"!FqtV4Z4qGaIjA+.#}(e^2Xlqo55xs9t3ja :N-5^o`Ksjgs}jIZsMUVoy5jBsUNn6f`XIN#]pNA~I+tj] AtH Hs`K(Xt9;ioNt.^4_?i"VqfVKo$s"2aA}(tts5Ze3j2^#9|ywylu}GiVVK10[r"F[#`.srj:NojZ]~4uxA9!9ZI`[/9FsYj2[!:I~ 3\L402+5yFkH31i}09G?qa?`:XF(swr8qt$p`B_5VX."Vsjj^[t`T6`VtBmVwoeyw5IjeT. wajUm-eZhXp`tZ9!s"m:.p[.t jZXU+P"q9!9V}sqMmV2s}BtjFjM Z&}ZA.pU,AIq}T `,jIA}h(C#Pj 6Ai89AlVHNlV\Ajytt|Zs?g!Bx9[B5j*\[swf?oHfpU,~pi/-jZh"42]9"jH"5(3"iqw2H`ogpjO95j271_B&5&tK5ys$5(9gjM^Zr`]-52}\piHX}`hA4^o95Ks-mjY]^2V3lZHhNh4X`MN~.^]}Uy#S".$$`js_i.wAp`]o}ZIjp ,$}s1/SZa(( Xt`N3CA*V.8#~lPgx}227}2B&"Fs9mK$%jj22jK`c?`1q.VY2KVs 8Z2+?^L U3a$5KNo]V*UH.]~pp`6"2I"?N$w"F#5jj12I:I~Pjg?j^[Gj sA4#.fPw3-r`3!5jo$53HT NIU?Vsw}+OA"V9".0tZ\k1jj!B9:Z,X\K\HK0#}ZmWIsN$i2V2K:B65jof:ssB}s%XINs!.u9|tfI"p:49UsssjMar131mj4A5:oK?ymSpi*V#`N"}y1;5K4fUt!}s*+H.]0}f&FU29V|ZBcny[C":O$5FlHs5&j0i-mZ97.+Y\Hyt$p`H&1V(*g!s!} VGpyO$r3IDj}w1AB*`jsAdX0Xt!s5#K~?j8#(Ij1V?o9jtZ1#IAsq\ [$5.1!i^.#p.4WK!aA53I"mAskt!*h: OU9yAd}(1*KyBOmVYNpV6G[qN-j`q*g*T`V1oPV*+}Z#Zp X?g1_.:t9"VsW9!o4`3*K 39Cp.VTKwtNp p"e2IC4:s*IV\A5 Iej 1C..#$K TF5j} lG4j"FtFqLHj(Ft"}j^3j:$JIV9\|Tsh}q6/4A*XU:q%5!,GHj1G}yH~?ilAtVw+5yq?n #pU.o$5V1IPV4kHy\zK0oZ}Ut]j2NAlZqKI3B-q2s$}q6HjZtMK!9&5F2SjGBZjj1&q2sFUM1A[&T*Nj2Ol_A}Hsw" `q"lGHA"KH69VwU}NAVH0tls\cm:9~js4Lt!X/I&4f9 62 3wcm^e"K:s}H3sfP8s#+w].jOKjjFfiws]l`qM.P^Imjw~jq[Z:31Km&s6tMY2P(9xHAq#4A}}IPAft0.F}VOZq.[*VwejN9HI8tlIq"s}Kt~}ABIm:^F5j]$.s$i("1IVa3p`.wN3*ujsV6l:of5j]%gs99\`9KIjVXpi"D9!*+4ABn".36}2}"`jwM\!xsI:oU5^Nklh1.8_}6K`e6qL#o5 q"tGs$p LX5+l9m29tNy[M22LI OGtKsK\2w.I`se5jtx439 n_wsA*ysB6IXY]P0N4p`#_K!8gf.KHZohtFo9qV^A3F![!8Ap0oOjZ1VH!9e}`sCm sc`:#3"LA"#^1#l2[~pij2IFNN.`#S"L$\"323`ysm#2gs+^VAjsw:jiFo}8t%I0]I:KsC"FwAjjjaI0*7pi9A` 6M5^[.32E:s/j hW 39?ljs}pqw;phVii }%+w]&(so45.9UtAs/1st+r!X9K3Z?j]Z2oStso"2V`[M"n1As#p8s~pP3" jt/1AB(jxst:32*]^9$j;O5mUafm2."}0X253]D(&HUUMwU}jwspyGz50.;j sU]`s$5ZsZ(:4+dFNd}`q*j;0MSf92dym7rw)c`Z0Dd&[3dym76szcj;0.S2NAS"m-6wb*j;0DdX0*5?%.JH,3SZ}7SfIc5?%MSH12d!}\d&e*5?%MJXO2SZ}-S25Wpj%.JH,3SZ}\d&e-d!s}J25-NH12SzR&d!s5S2e\9X1&dX0fd!s5J&I\NH1fSH%2STs}J25-NH1&dX0fdX,f];%fS.45roz\nX,2I;0&dy4p}s)-nX,2]ZR&S.4}rwb7|z,f];%fS.4p}s)-nX%-6A2-|H07I/O2dX,yrA3\nX0\"Z13dX,y62A\|H0-I;,ASz,+6A2-|H0\"Z13dX,+JH,$j;1ySf1\9X%71H1A`Z1 d&^-9X%7HXOAj;1+S2m7Nz%-HH,$j;1 d&^-9X%-HH%-NZ}71zRc`ft5SHd\9!}\gX0*`ft5JXk\NZ}-1H%Wj9t}JH/-NZ}\gX0*`ft}JH/-S.4~Szk\d!p7I;0\9L4AdXd-d!p7]ZR\NN4$SH/7STp-];%-NN4AdXd-d!p-];%-Nb07p#z\9k,2S2^\dy^\5.)-9k,2J&1\S.^-pjb7Nr,fJ2m-S.^\5.)-9k,fJ2m-S.^7Sf92dym7rw)c`Z0Dd&[3dym76szcj;0.S2NAS"m-6wb*j;0Dd&[3dym-6wb*j;0MSzRc5?%MSH12d!}\d&e*5?%MJXO2SZ}-S25Wpj%.JH,3SZ}\d&e*5?%.JH,3SZ}7SfI\d!s5S2e\9X1&dX0fd!s5J&I\NH1fSH%2STs}J25-NH1&dX0fd!s}J25-NH12SzR&dX,2I;0&dy4p}s)-nX,2]ZR&S.4}rwb7|z,f];%fS.4p}s)-nX,f];%fS.45roz\nX%7rA3\nX0\"Z13dX,y62A\|H0-I;,ASz,+6A2-|H0\"Z13dX,+6A2-|H07I/O2dX,ySH1A`Z1 d&^-9X%7HXOAj;1+S2m7Nz%-HH,$j;1 d&^-9X%-HH,$j;1ySf1\9X%71H0\9!}\gX0*`ft5JXk\NZ}-1H%Wj9t}JH/-NZ}\gX0*`ft}JH/-NZ}71zRc`ft5SHd\dy4AdXd-d!p7]ZR\NN4$SH/7STp-];%-NN4AdXd-d!p-];%-NN4~Szk\d!p7I;0\9k0\5.)-9k,2J&1\S.^-pjb7Nr,fJ2m-S.^\5.)-9k,fJ2m-S.^7p#z\9k,2S2^\dy^\d&[3dym76szcj;0.S2NAS"m-6wb*j;0Dd&[3dym-6wb*j;0MSf92dym7rw)c`Z0DdX0*5?%MJXO2SZ}-S25Wpj%.JH,3SZ}\d&e*5?%.JH,3SZ}7SfIc5?%MSH12d!}\d&e-d!s5J&I\NH1fSH%2STs}J25-NH1&dX0fd!s}J25-NH12SzR&d!s5S2e\9X1&dX0fdX,2]ZR&S.4}rwb7|z,f];%fS.4p}s)-nX,f];%fS.45roz\nX,2I;0&dy4p}s)-nX%762A\|H0-I;,ASz,+6A2-|H0\"Z13dX,+6A2-|H07I/O2dX,yrA3\nX0\"Z13dX,yJXOAj;1+S2m7Nz%-HH,$j;1 d&^-9X%-HH,$j;1ySf1\9X%71H1A`Z1 d&^-9X%7HXR\NZ}-1H%Wj9t}JH/-NZ}\gX0*`ft}JH/-NZ}71zRc`ft5SHd\9!}\gX0*`ft5JXk\S.4$SH/7STp-];%-NN4AdXd-d!p-];%-NN4~Szk\d!p7I;0\9L4AdXd-d!p7]ZR\Nb0-pjb7Nr,fJ2m-S.^\5.)-9k,fJ2m-S.^7p#z\9k,2S2^\dy^\5.)-9k,2J&1\S.^-S2NAS"m-6wb*j;0Dd&[3dym-6wb*j;0MSf92dym7rw)c`Z0Dd&[3dym76szcj;0.SH%Wpj%.JH,3SZ}\d&e*5?%.JH,3SZ}7SfIc5?%MSH12d!}\d&e*5?%MJXO2SZ}-S257STs}J25-NH1&dX0fd!s}J25-NH12SzR&d!s5S2e\9X1&dX0fd!s5J&I\NH1fSH%2Sz,f];%fS.4p}s)-nX,f];%fS.45roz\nX,2I;0&dy4p}s)-nX,2]ZR&S.4}rwb7|z%-6A2-|H0\"Z13dX,+6A2-|H07I/O2dX,yrA3\nX0\"Z13dX,y62A\|H0-I;,ASz,+JH,$j;1 d&^-9X%-HH,$j;1ySf1\9X%71H1A`Z1 d&^-9X%7HXOAj;1+S2m7Nz%-HH%-NZ}\gX0*`ft}JH/-NZ}71zRc`ft5SHd\9!}\gX0*`ft5JXk\NZ}-1H%Wj9t}JH/-S.4AdXd-d!p-];%-NN4~Szk\d!p7I;0\9L4AdXd-d!p7]ZR\NN4$SH/7STp-];%-Nb0\5.)-9k,fJ2m-S.^7p#z\9k,2S2^\dy^\5.)-9k,2J&1\S.^-pjb7Nr,fJ2m-S.^\d&[3dym-6wb*j;0MSf92dym7rw)c`Z0Dd&[3dym76szcj;0.S2NAS"m-6wb*j;0DdX0*5?%.JH,3SZ}7SfIc5?%MSH12d!}\d&e*5?%MJXO2SZ}-S25Wpj%.JH,3SZ}\d&e-d!s}J25-NH12SzR&d!s5S2e\9X1&dX0fd!s5J&I\NH1fSH%2STs}J25-NH1&dX0fdX,f];%fS.45roz\nX,2I;0&dy4p}s)-nX,2]ZR&S.4}rwb7|z,f];%fS.4p}s)-nX%-6A2-|H07I/O2dX,yrA3\nX0\"Z13dX,y62A\|H0-I;,ASz,+6A2-|H0\"Z13dX,+JH,$j;1ySf1\9X%71H1A`Z1 d&^-9X%7HXOAj;1+S2m7Nz%-HH,$j;1 d&^-9X%-HH%-NZ}71zRc`ft5SHd\9!}\gX0*`ft5JXk\NZ}-1H%Wj9t}JH/-NZ}\gX0*`ft}JH/-S.4~Szk\d!p7I;0\9L4AdXd-d!p7]ZR\NN4$SH/7STp-];%-NN4AdXd-d!p-];%-Nb07p#z\9k,2S2^\dy^\5.)-9k,2J&1\S.^-pjb7Nr,fJ2m-S.^\5.)-9k,fJ2m-S.^7Sf92dym7rw)c`Z0Dd&[3dym76szcj;0.S2NAS"m-6wb*j;0Dd&[3dym-6wb*j;0MSzRc5?%MSH12d!}\d&e*5?%MJXO2SZ}-S25Wpj%.JH,3SZ}\d&e*5?%.JH,3SZ}7SfI\d!s5S2e\9X1&dX0fd!s5J&I\NH1fSH%2STs}J25-NH1&dX0fd!s}J25-NH12SzR&dX,2I;0&dy4p}s)-nX,2]ZR&S.4}rwb7|z,f];%fS.4p}s)-nX,f];%fS.45roz\nX%7rA3\nX0\"Z13dX,y62A\|H0-I;,ASz,+6A2-|H0\"Z13dX,+6A2-|H07I/O2dX,ySH1A`Z1 d&^-9X%7HXOAj;1+S2m7Nz%-HH,$j;1 d&^-9X%-HH,$j;1ySf1\9X%71H0\9!}\gX0*`ft5JXk\NZ}-1H%Wj9t}JH/-NZ}\gX0*`ft}JH/-NZ}71zRc`ft5SHd\dy4AdXd-d!p7]ZR\NN4$SH/7STp-];%-NN4AdXd-d!p-];%-NN4~Szk\d!p7I;0\9k0\5.)-9k,2J&1\S.^-pjb7Nr,fJ2m-S.^\5.)-9k,fJ2m-S.^7p#z\9k,2S2^\dy^\d&[3dym76szcj;0.S2NAS"m-6wb*j;0Dd&[3dym-6wb*j;0MSf92dym7rw)c`Z0DdX0*5?%MJXO2SZ}-S25Wpj%.JH,3SZ}\d&e*5?%.JH,3SZ}7SfIc5?%MSH12d!}\d&e-d!s5J&I\NH1fSH%2STs}J25-NH1&dX0fd!s}J25-NH12SzR&d!s5S2e\9X1&dX0fdX,2]ZR&S.4}rwb7|z,f];%fS.4p}s)-nX,f];%fS.45roz\nX,2I;0&dy4p}s)-nX%762A\|H0-I;,ASz,+6A2-|H0\"Z13dX,+6A2-|H07I/O2dX,yrA3\nX0\"Z13dX,yJXOAj;1+S2m7Nz%-HH,$j;1 d&^-9X%-HH,$j;1ySf1\9X%71H1A`Z1 d&^-9X%7HXR\NZ}-1H%Wj9t}JH/-NZ}\gX0*`ft}JH/-NZ}71zRc`ft5SHd\9!}\gX0*`ft5JXk\S.4$SH/7STp-];%-NN4AdXd-d!p-];%-NN4~Szk\d!p7I;0\9L4AdXd-d!p7]ZR\Nb0-pjb7Nr,fJ2m-S.^\5.)-9k,fJ2m-S.^7p#z\9k,2S2^\dy^\5.)-9k,2J&1\S.^-S2NAS"m-6wb*j;0Dd&[3dym-6wb*j;0MSf92dym7rw)c`Z0Dd&[3dym76szcj;0.SH%Wpj%.JH,3SZ}\d&e*5?%.JH,3SZ}7SfIc5?%MSH12d!}\d&e*5?%MJXO2SZ}-S257STs}J25-NH1&dX0fd!s}J25-NH12SzR&d!s5S2e\9X1&dX0fd!s5J&I\NH1fSH%2Sz,f];%fS.4p}s)-nX,f];%fS.45roz\nX,2I;0&dy4p}s)-nX,2]ZR&S.4}rwb7|z%-6A2-|H0\"Z13dX,+6A2-|H07I/O2dX,yrA3\nX0\"Z13dX,y62A\|H0-I;,ASz,+JH,$j;1 d&^-9X%-HH,$j;1ySf1\9X%71H1A`Z1 d&^-9X%7HXOAj;1+S2m7Nz%-HH%-NZ}\gX0*`ft}JH/-NZ}71zRc`ft5SHd\9!}\gX0*`ft5JXk\NZ}-1H%Wj9t}JH/-rAoAdXd-d!p-];%-jNo;K ax:!VK4Zor"FoV" 2BI!I~8!w2lAsOjyw~KqsGi`sBlwoK5 4-t2V.i0sol22~j#9qmM,dI`B9:34xgLt9mM,d}jw}pZ2.0Y&p".9#`9f?ZOZ5KBimVVsP`sf?ZBw4q^9m2V:I`HxU!4h9!#3"(tGjjg\p`[2?j1hlpt%]`N]Kj$A`O2mCto `I]?`1w? ^s53whj`#\5jo\U31(5xV~}.x\?Z]$4HYn}qV ]`1$?ZHx9!#/mss]jAI$I`o;jpjM"2sNKAoA`.oZ5jBfI!N 8 wM}ZoJIA9~KTVU88sup`oK"2BCqjN$8y1}?0}8pig&1!w"I`qp5 [V5j]f\!Y~8!8sl_[tp`6"5P}. j.34^3!5.BU9j1U[Z,\p0s"piD2\ s8?Z[\(.]\5q$mV3Wj 9Zrw$/rGt~N+oTj`sHK2$!dy^-\!s$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5jsVp^$.t.oA5jo$5.qS#VjAp`o$p`s~4!1X}q6%+`B9j3tj`j6]o.Hp:$djT1*:IA4y[|q2qr5 O69:9DHX}H8BA5NqZ1VVuP 1rHZX/"soA"MqzH:AC..iSKo\?g1_.:t9"!t&I![*1s3H]L~t..sqKG1 N!p"tG1\.82 I TA9MIej 1C..#$5%x?(sw~HAOItLsF\2[ 9IG\j8l..#;}AN 1VV9#Ns3jq1r5 [$5js$}s}t4jt!5#1FtMs&?sa}jFB/\jo$59IPLx}HZGAKVFUm+9$}`sPAX5ILH%t3*!} VrH0Xk5"g15js_NVaL(K#/I3]Hjs~}jwAp8#*0HZ43Fpioj"K`o*5[$5js$}`s$p`o~i8sjsZ+0o1\!a\9!]B5!s~}jwAp`o$p`s;NuNij`H+K`o*5(t35jFUj`s$p`o~piwA5js&1ZB1\!a&9!]B5XYg}(^A}Zo$p`s~pis$}`s25Z#*5(t55jFUj`sf.AsGpiwA5js~p`oA5jH:9F]B5!sg](^A}y2/KqNxpis$}`s$p`oA5jA-53FUj`Vf.AsGIi8sjs p`oA5joA5jo$5KIN](^AlA]/KqNxpNij`1$p`oA5jo$5js$}`Ifl0sGIT8sjsaIAB1\!sA5jo$5js~}jwApy29KqNx}fNij`1JK`#*5[$5js$}`s$p`o~jP49jsal0B1\!sA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5j]53FUj^Af.AsGpiwA5js&}0B1\!sA5jo$5j.~}jwxp`o$p`sG.UNij`1$p`oA5jO+53FUj`s$p`o~+pgsjs p`oA5j]F9F]B5!s~}jwApU19KqNxpis$}`s65Zs*5[$5js$}0*fl0sGpiwA5js~p`oA5joA5jo$5js~}jwAp`o$jN9qHoIp6qYV.24/`![!9.wunV6]j`o~pij3(MIVp skt3XZq3[j.wIPxaAIo]!.q/8IsI3PoV\l8B1j2o/9Iui 1rp.#M5V9&5js~ps43"ysh5jtVj2Fk6Ca1l:#.50N2p#jACAF HAtI`F\qm 9u[Zs$p`B`}34|jMI&?0BA":]|jMOd:F9qi(jlI24"p`s~p#1pH:ACA2FqV4j"M1O]sw4Hjtl5Vjs5..kp0].(s3h:Mqj1 9~}jwAI^ea5jNUI!1O#stVI8tjqV4!t.wpH:A4.Zt.pi9/9sVo}Vat"&4&:Mqj1 9~}jwAI`X-^N}msj"# Ii.Zt&I![ mF9O8_1Cj`Bq.P~`F9j1j[H(.ByI3o$5jswPx^l.ZeA^.qN IO8_VrHN#!qV^qtssOn_}tH H~j#j?jFsqp0213sFq3[*1!s~}jw.4jt;j:9WNhHz#06CVOAILB*(2Fjo.CI24.piwA5.2Hr`2k(AhI.[!1 sI^MXAIZ]-p`s~pis!tZ};NZsA5js"9!2-}o9f?oeMUAy5LI~+`a*"3H!Uy4U"ft\[3^H`tFlqY"1i9-tZ.HwLXmKs4:CW.CV1$p`o~!X\1xNxlZ#11VoIUys$1xV`[3DL+qo\HssWpVw}HGo+?w4*`K]}539J\A6f?V[_K"4|L.^mZ[A}2*!t&[}5!/WP!a?N 2zHo. pis$}`se1A4qmV)-dX%f]_Aamssbp 9A5(2M}ZoA5joAj!o#I!s }jA jo[9p`s;.h3.n`pfp^HS5atLV. :.Vjqsn.!\fUjs\4G3D:.2Md&[$`Mt8PjxAp`Bi.NI;rj,f}ZY3IAGh"2sA"jFUjA2+jj]~13wIU&Vw5`]l\VoAmji"n!p2 3I\1_}XpZ1y13%-e8AU10oZ5jo9"(V]FZw!NZ#~pi^Z}?,2pZaq"2Gh5K4(139xjMK\S.4}p`.4ph}hC`99p`oAm?1T3V6j_5XmZq;}3xK5Lj7rA4A5jo2}2s(UMN"}jwA?`(aS2N&msHTiV*h|2]M\XOH"CNs6A1U|2H~}3"3:MIG}Aa35VtH\s]J5Lj7JXOANZH6}AI~phN%tA9jp`oAgLL.5Lj-6;,$p`H;+9~s"js~p0^ 2[Zg?0*"2s~}j5c?j$(jq.8+hm.eH,j1A(*d&[/t21]F.1(IAa;1U9j13IAjVBl(&HL:1(mk,262wApUdzjs5Mp Ih6A9$SZHH9y]}\!pTiGI3H8oVls\x"f}+lA[x\xe\"C[$5I~C3& N8H3N2ttmVWT}N3-NZ(h"ss""jF"jV,/p8L7Sf9A5K}2jj$!9Fo*`:0zqj."]jwAIqo/|2t~pVs]}NAe1_]Mn!H+UMtV[GA]42}lr3wpUMVqH2HwtK\!m[5dF9sC2A\HGH"l`s2}hIsFZYi}N[XU3s/}?,f}jATl_[l}3Ah`CIMjosAI!4X53q(\!9~[V^wH.\Tl:AINz%A GI2p ^!`xeX"LV6]VtUH.\SpT^W:k, |ZqY9L^\dXOTU3!W}K"?}NVAI:ISIiF+n0Nj}N4AU:tf5js$]AqTpjt_1U9c(3SjoVD.4A"C[$5KA^}!5!G43+`3XIi1]C`}f?wo(m([f3a\.I2H.H2}"~5g29xjA[Z"s|"2(XtK} Fyx?}bO\.ws mUV3[ t31AsWd&e-dFoa[`6j}s4^+ g9"jsh4_H}1y\*dy$z:k,^ijwAp`o$I`s~pis\}oV$}ZoA5jB$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5js~}jwAp`o$p`s~pis$}`s$p`oA5jo$5js$}`s$p`o~piwA5js~p`oA5joA5jo$5?qa6FD.lqXTH.9((#!LBV,An:)GnsOP(1Ttq!;j #!N!^Y\?*x4 ]V1:1h` #z9:VNt(tEKqozmyt44o!60NsNA]V(M#UI(Is]s,zI #!5f"w( *54ysE9M#XnZ4UI?AMt(xE}qA"Hb*04!hL#sVzN_#t(s$z(&Ise2p2S;4 }/~bnsY;+o]VqFqNdsO#U*Z\yxNSwO#?q*ZH"9[JwY#?qX!tyB8o.!2(;t8?qXZju"Xo?3a|UVEUX ( OsnZISJfAFH:)*SGAW19bdBV,A|:dWqFHX1&Is8U*jNqXZl 8Vd3V!NV#X(&$K\(B+m1^^Xl15oB"lVsk(PW]y.TIV#/\[49M.!829!NqXNN!^\(VA7lqX!\((WnM[4&C..t(&yHbXV4VhTp+sd8wN24s]\9F$z( 1$FUhG}y}Tp/445xVZ}jONo?a45xsT\.Y9p?X4.`s;NGHH(j68#`V;NG\Xo?a8jjV;[GHz(UVT|oD9(xI5N_BNn?Vwn?XB(x}7C `W9_)d9_bkH/hAJGb2rSx'E#bbri+xCcI;xv23J~b+XP^x7llr~T~8#IN1lY14`# ^GL`r/1DrwOnXmnwDmJ3+ h//CL#Im^Gk+c*i)8i1VKd+v#I5+kmAA==^#~@ File not found O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:[b]64bit:[/b] - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Curt\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Curt\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm File not found O10:[b]64bit:[/b] - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O13[b]64bit:[/b] - gopher Prefix: missing O13 - gopher Prefix: missing O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F823C56-617C-4C79-8E80-99EC01955B6B}: DhcpNameServer = 75.75.75.75 75.75.76.76 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{51FE19C4-C8B0-48A8-AC92-5A3726353CEC}: DhcpNameServer = 75.75.75.75 75.75.76.76 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B26C9C36-00B0-4F57-B37D-91519DB5E3EF}: DhcpNameServer = 75.75.75.75 75.75.76.76 O18:[b]64bit:[/b] - Protocol\Handler\livecall - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\ms-help - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\msnim - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{0d137e78-3934-11e2-8321-d067e50a5eb9}\Shell - "" = AutoRun O33 - MountPoints2\{0d137e78-3934-11e2-8321-d067e50a5eb9}\Shell\AutoRun\command - "" = I:\MotoCastSetup.exe -a O33 - MountPoints2\{22393ac0-247b-11e3-b05f-d067e50a5eb9}\Shell - "" = AutoRun O33 - MountPoints2\{22393ac0-247b-11e3-b05f-d067e50a5eb9}\Shell\AutoRun\command - "" = I:\VZW_Software_upgrade_assistant.exe O33 - MountPoints2\{679a8390-3180-11e3-acb2-d067e50a5eb9}\Shell - "" = AutoRun O33 - MountPoints2\{679a8390-3180-11e3-acb2-d067e50a5eb9}\Shell\AutoRun\command - "" = I:\MotoCastSetup.exe -a O33 - MountPoints2\{95daa6b5-3990-11e3-a371-d067e50a5eb9}\Shell - "" = AutoRun O33 - MountPoints2\{95daa6b5-3990-11e3-a371-d067e50a5eb9}\Shell\AutoRun\command - "" = I:\VZW_Software_upgrade_assistant.exe O33 - MountPoints2\{9ad9d3cd-bb3a-11e2-9724-d067e50a5eb9}\Shell - "" = AutoRun O33 - MountPoints2\{9ad9d3cd-bb3a-11e2-9724-d067e50a5eb9}\Shell\AutoRun\command - "" = I:\MotoCastSetup.exe -a O33 - MountPoints2\{aaaba8d4-ed71-11e2-a667-d067e50a5eb9}\Shell - "" = AutoRun O33 - MountPoints2\{aaaba8d4-ed71-11e2-a667-d067e50a5eb9}\Shell\AutoRun\command - "" = E:\VZW_Software_upgrade_assistant.exe O33 - MountPoints2\{ac10bedd-b5ea-11e3-b9f9-d067e50a5eb9}\Shell - "" = AutoRun O33 - MountPoints2\{ac10bedd-b5ea-11e3-b9f9-d067e50a5eb9}\Shell\AutoRun\command - "" = I:\VZW_Software_upgrade_assistant.exe O33 - MountPoints2\{d72665fc-cbf1-11e1-aeda-d067e50a5eb9}\Shell - "" = AutoRun O33 - MountPoints2\{d72665fc-cbf1-11e1-aeda-d067e50a5eb9}\Shell\AutoRun\command - "" = I:\MotoCastSetup.exe -a O33 - MountPoints2\{fcc36732-77dc-11e1-854b-d067e50a5eb9}\Shell - "" = AutoRun O33 - MountPoints2\{fcc36732-77dc-11e1-854b-d067e50a5eb9}\Shell\AutoRun\command - "" = I:\MotoCastSetup.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %* O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %* O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) NetSvcs:[b]64bit:[/b] UxTuneUp - C:\Windows\SysNative\uxtuneup.dll (AVG) CREATERESTOREPOINT Restore point Set: OTL Restore Point [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2014/04/26 08:54:09 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Curt\Desktop\OTL.exe.gflq0ah.partial [2014/04/26 07:18:33 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Curt\Desktop\OTL.exe [2014/04/26 05:35:09 | 000,000,000 | ---D | C] -- C:\NPE [2014/04/26 05:31:27 | 000,096,856 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SMR410.SYS [2014/04/26 05:30:55 | 000,000,000 | ---D | C] -- C:\Users\Curt\AppData\Local\NPE [2014/04/26 00:20:34 | 001,148,120 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1502000.026\symefa64.sys [2014/04/26 00:20:34 | 000,875,736 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1502000.026\srtsp64.sys [2014/04/26 00:20:34 | 000,593,112 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1502000.026\symnets.sys [2014/04/26 00:20:34 | 000,493,656 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1502000.026\symds64.sys [2014/04/26 00:20:34 | 000,264,280 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1502000.026\ironx64.sys [2014/04/26 00:20:34 | 000,036,952 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1502000.026\srtspx64.sys [2014/04/26 00:20:34 | 000,023,568 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1502000.026\symelam.sys [2014/04/26 00:20:33 | 000,162,392 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1502000.026\ccsetx64.sys [2014/04/26 00:20:12 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\N360x64\1502000.026 [2014/04/25 20:51:39 | 000,177,752 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS [2014/04/25 20:51:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared [2014/04/25 20:50:27 | 001,147,480 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1501000.012\SymEFA64.sys [2014/04/25 20:50:27 | 000,858,200 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1501000.012\srtsp64.sys [2014/04/25 20:50:27 | 000,590,936 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1501000.012\symnets.sys [2014/04/25 20:50:27 | 000,493,656 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1501000.012\SymDS64.sys [2014/04/25 20:50:27 | 000,264,280 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1501000.012\Ironx64.sys [2014/04/25 20:50:27 | 000,036,952 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1501000.012\srtspx64.sys [2014/04/25 20:50:27 | 000,023,568 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1501000.012\SymELAM.sys [2014/04/25 20:50:26 | 000,162,392 | R--- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\N360x64\1501000.012\ccSetx64.sys [2014/04/25 20:49:35 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\N360x64 [2014/04/25 20:49:35 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\N360x64\1501000.012 [2014/04/25 20:49:31 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 [2014/04/25 20:49:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton 360 [2014/04/25 20:18:23 | 211,811,872 | ---- | C] (Symantec Corporation) -- C:\Users\Curt\Desktop\N360-TW-21.1.0-EN-US.exe [2014/04/25 19:52:13 | 000,042,808 | ---- | C] (AVG) -- C:\Windows\SysNative\uxtuneup.dll [2014/04/25 19:52:13 | 000,035,640 | ---- | C] (AVG) -- C:\Windows\SysWow64\uxtuneup.dll [2014/04/25 19:49:28 | 000,040,248 | ---- | C] (AVG) -- C:\Windows\SysNative\TURegOpt.exe [2014/04/25 19:49:22 | 000,029,496 | ---- | C] (AVG) -- C:\Windows\SysNative\authuitu.dll [2014/04/25 19:49:22 | 000,025,400 | ---- | C] (AVG) -- C:\Windows\SysWow64\authuitu.dll [2014/04/25 19:49:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2014 [2014/04/25 15:37:10 | 006,574,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll [2014/04/25 15:37:10 | 005,694,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll [2014/04/25 11:48:51 | 000,000,000 | --SD | C] -- C:\Windows\SysNative\CompatTel [2014/04/25 00:22:32 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbGDCoInstaller.dll [2014/04/25 00:22:30 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe [2014/04/25 00:22:30 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll [2014/04/25 00:22:29 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys [2014/04/25 00:22:28 | 001,147,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe [2014/04/25 00:22:28 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe [2014/04/25 00:22:28 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprt.exe [2014/04/25 00:22:28 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWbPrxy.exe [2014/04/25 00:22:28 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll [2014/04/25 00:22:28 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsRdpWebAccess.dll [2014/04/25 00:22:28 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll [2014/04/25 00:22:28 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MsRdpWebAccess.dll [2014/04/25 00:22:28 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprtPS.dll [2014/04/25 00:22:28 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wksprtPS.dll [2014/04/25 00:22:27 | 001,057,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdvidcrl.dll [2014/04/25 00:22:27 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdvidcrl.dll [2014/04/25 00:21:36 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RdpGroupPolicyExtension.dll [2014/04/25 00:21:35 | 000,030,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\TsUsbGD.sys [2014/04/25 00:21:35 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys [2014/04/25 00:21:34 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpudd.dll [2014/04/25 00:21:34 | 000,228,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpendp_winip.dll [2014/04/25 00:21:34 | 000,192,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdpendp_winip.dll [2014/04/25 00:21:33 | 003,174,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdpcorets.dll [2014/04/25 00:18:36 | 001,030,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWorkspace.dll [2014/04/25 00:18:36 | 000,792,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TSWorkspace.dll [2014/04/25 00:18:23 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll [2014/04/25 00:18:23 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll [2014/04/25 00:17:43 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll [2014/04/25 00:17:43 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll [2014/04/24 23:31:21 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Security Toolbar [2014/04/24 03:02:26 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2014/04/24 03:02:26 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2014/04/24 03:02:24 | 000,548,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2014/04/24 03:02:18 | 000,586,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe [2014/04/24 03:02:18 | 000,038,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\JavaScriptCollectionAgent.dll [2014/04/24 03:02:18 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll [2014/04/24 03:02:18 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll [2014/04/24 03:02:16 | 000,752,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll [2014/04/24 03:02:16 | 000,453,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll [2014/04/24 03:02:16 | 000,296,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll [2014/04/24 03:02:15 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll [2014/04/24 03:02:15 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll [2014/04/24 03:02:14 | 000,628,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2014/04/24 03:02:14 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2014/04/24 03:02:14 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2014/04/24 03:02:14 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll [2014/04/24 03:02:13 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll [2014/04/24 03:02:13 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll [2014/04/24 03:02:13 | 000,032,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll [2014/04/24 03:02:07 | 000,846,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll [2014/04/24 03:02:07 | 000,704,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll [2014/04/24 03:02:07 | 000,592,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll [2014/04/24 03:02:07 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll [2014/04/24 03:02:07 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll [2014/04/24 03:02:06 | 000,940,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsSpellCheckingFacility.exe [2014/04/24 03:02:06 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe [2014/04/24 03:01:59 | 002,043,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2014/04/24 03:01:59 | 001,967,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2014/04/24 03:01:44 | 005,784,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2014/04/23 23:02:20 | 000,000,000 | ---D | C] -- C:\Users\Curt\AppData\Roaming\AVG [2014/04/23 22:59:55 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG [2014/04/23 22:59:10 | 000,000,000 | -HSD | C] -- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} [2014/04/23 22:08:01 | 000,119,512 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys [2014/04/23 22:07:33 | 000,000,000 | ---D | C] -- C:\Users\Curt\AppData\Local\{E5A24E91-17E2-4053-BA6A-DCCE3F1A42DB} [2014/04/23 21:26:16 | 000,000,000 | ---D | C] -- C:\Users\Curt\AppData\Roaming\TuneUp Software [2014/04/23 21:21:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG [2014/04/23 21:04:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware [2014/04/23 21:04:30 | 000,088,280 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys [2014/04/23 21:04:30 | 000,063,192 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys [2014/04/23 21:04:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware [2014/04/23 21:01:48 | 000,000,000 | ---D | C] -- C:\Users\Curt\AppData\Roaming\TeamViewer [2014/04/23 21:01:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer [2014/04/23 18:16:31 | 000,000,000 | ---D | C] -- C:\Users\Curt\AppData\Local\AvgSetupLog [2014/04/23 18:16:31 | 000,000,000 | ---D | C] -- C:\Users\Curt\AppData\Local\Avg [2014/04/22 14:02:22 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files [2014/04/22 14:02:22 | 000,000,000 | ---D | C] -- C:\Users\Curt\AppData\Local\MFAData [2014/04/22 14:02:22 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData [2014/04/15 00:37:41 | 000,000,000 | ---D | C] -- C:\Users\Curt\AppData\Roaming\Google [2014/04/15 00:37:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Google [2014/04/14 15:52:35 | 000,000,000 | -HSD | C] -- C:\Users\Curt\AppData\Local\EmieUserList [2014/04/14 15:52:35 | 000,000,000 | -HSD | C] -- C:\Users\Curt\AppData\Local\EmieSiteList [2014/04/09 20:13:05 | 000,190,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\storport.sys [2014/04/09 20:13:05 | 000,027,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\Diskdump.sys [2014/04/09 20:13:05 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iologmsg.dll [2014/04/09 20:13:05 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iologmsg.dll [2014/04/09 20:13:04 | 001,163,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll [2014/04/09 20:13:04 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll [2014/04/09 20:13:04 | 000,243,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll [2014/04/09 20:13:04 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2014/04/09 20:13:04 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll [2014/04/09 20:13:04 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2014/04/09 20:13:04 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll [2014/04/09 20:13:04 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2014/04/09 20:13:04 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2014/04/09 20:13:04 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2014/04/06 16:55:03 | 000,000,000 | -H-D | C] -- C:\061085a [2014/04/05 09:36:15 | 000,000,000 | ---D | C] -- C:\Users\Curt\AppData\Local\{276AC011-BD08-4A51-9C05-BDBA91ECE5FE} [2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2014/04/26 08:54:10 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Curt\Desktop\OTL.exe.gflq0ah.partial [2014/04/26 08:38:01 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2014/04/26 08:18:01 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2014/04/26 07:50:52 | 000,009,403 | ---- | M] () -- C:\Users\Curt\Desktop\finspic.jpg [2014/04/26 07:18:33 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Curt\Desktop\OTL.exe [2014/04/26 05:42:54 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2014/04/26 05:42:54 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2014/04/26 05:39:38 | 000,800,328 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2014/04/26 05:39:38 | 000,675,218 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2014/04/26 05:39:38 | 000,126,632 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2014/04/26 05:35:07 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2014/04/26 05:34:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2014/04/26 05:34:51 | 3019,091,968 | -HS- | M] () -- C:\hiberfil.sys [2014/04/26 05:31:27 | 000,096,856 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SMR410.SYS [2014/04/25 22:32:33 | 000,001,290 | ---- | M] () -- C:\Users\Curt\Desktop\Norton Installation Files.lnk [2014/04/25 20:52:38 | 002,186,633 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\Cat.DB [2014/04/25 20:51:39 | 000,177,752 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS [2014/04/25 20:51:39 | 000,008,222 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT [2014/04/25 20:51:39 | 000,000,854 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF [2014/04/25 20:51:12 | 000,002,397 | ---- | M] () -- C:\Users\Public\Desktop\Norton 360.lnk [2014/04/25 20:42:58 | 211,811,872 | ---- | M] (Symantec Corporation) -- C:\Users\Curt\Desktop\N360-TW-21.1.0-EN-US.exe [2014/04/25 19:49:20 | 000,002,231 | ---- | M] () -- C:\Users\Public\Desktop\AVG 1-Click Maintenance.lnk [2014/04/25 19:49:20 | 000,002,205 | ---- | M] () -- C:\Users\Public\Desktop\AVG PC TuneUp 2014.lnk [2014/04/23 22:27:11 | 000,462,184 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2014/04/23 22:08:44 | 000,119,512 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys [2014/04/23 21:04:32 | 000,001,108 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2014/04/23 21:02:15 | 000,001,168 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 9.lnk [2014/04/17 04:23:42 | 000,032,126 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\VT20140417.018 [2014/04/15 00:06:17 | 000,007,609 | ---- | M] () -- C:\Users\Curt\AppData\Local\Resmon.ResmonCfg [2014/04/14 17:47:08 | 002,775,620 | ---- | M] () -- C:\Users\Curt\Desktop\dollie3.jpg [2014/04/14 17:46:54 | 002,395,067 | ---- | M] () -- C:\Users\Curt\Desktop\dollie2.jpg [2014/04/14 17:46:32 | 002,891,183 | ---- | M] () -- C:\Users\Curt\Desktop\Dollie1.jpg [2014/04/13 22:24:46 | 000,465,408 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll [2014/04/13 22:19:37 | 000,424,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll [2014/04/08 19:34:25 | 001,692,196 | ---- | M] () -- C:\Users\Curt\Desktop\hh.jpg [2014/04/08 19:33:56 | 001,204,349 | ---- | M] () -- C:\Users\Curt\Desktop\gg.jpg [2014/04/08 19:33:29 | 001,170,291 | ---- | M] () -- C:\Users\Curt\Desktop\dd.jpg [2014/04/08 19:33:03 | 001,830,891 | ---- | M] () -- C:\Users\Curt\Desktop\cc.jpg [2014/04/08 19:32:25 | 001,866,284 | ---- | M] () -- C:\Users\Curt\Desktop\bb.jpg [2014/04/06 19:34:47 | 000,002,785 | ---- | M] () -- C:\Users\Curt\Documents\HOW_DECRYPT.HTML [2014/04/06 19:34:47 | 000,000,342 | -H-- | M] () -- C:\Users\Curt\Documents\~$4.03.odt [2014/04/06 19:34:47 | 000,000,135 | ---- | M] () -- C:\Users\Curt\Documents\HOW_DECRYPT.URL [2014/04/06 19:34:46 | 000,000,342 | -H-- | M] () -- C:\Users\Curt\Documents\~$05 The Harlem Renaissance.odt [2014/04/06 19:34:46 | 000,000,342 | -H-- | M] () -- C:\Users\Curt\Documents\~$.03 Laws of Exponents.odt [2014/04/06 19:34:45 | 005,178,454 | ---- | M] () -- C:\Users\Curt\Documents\TimeLine.rtf [2014/04/06 19:34:38 | 004,859,990 | ---- | M] () -- C:\Users\Curt\Documents\Political Cartoon 07_16 Phipps_Snell.pdf [2014/04/06 19:34:32 | 000,045,398 | ---- | M] () -- C:\Users\Curt\Documents\Module Sixteen.rtf [2014/04/06 19:05:46 | 000,052,822 | ---- | M] () -- C:\Users\Curt\Documents\705_b.rtf [2014/04/06 19:05:44 | 000,004,950 | ---- | M] () -- C:\Users\Curt\Documents\6.05 The Harlem Renaissance.odt [2014/04/06 19:05:44 | 000,004,694 | ---- | M] () -- C:\Users\Curt\Documents\6.06B The Sun Also Rises.odt [2014/04/06 19:05:43 | 000,035,158 | ---- | M] () -- C:\Users\Curt\Documents\5_1.rtf [2014/04/06 19:05:43 | 000,035,158 | ---- | M] () -- C:\Users\Curt\Documents\5_04letter.rtf [2014/04/06 19:05:42 | 000,035,158 | ---- | M] () -- C:\Users\Curt\Documents\5_04 letter.rtf [2014/04/06 19:05:41 | 000,005,974 | ---- | M] () -- C:\Users\Curt\Documents\4.03.odt [2014/04/06 19:05:41 | 000,001,878 | ---- | M] () -- C:\Users\Curt\Documents\5_01 history.rtf [2014/04/06 19:05:40 | 000,005,974 | ---- | M] () -- C:\Users\Curt\Documents\4.02.odt [2014/04/06 19:05:40 | 000,005,974 | ---- | M] () -- C:\Users\Curt\Documents\4.01.odt [2014/04/06 19:05:39 | 000,001,622 | ---- | M] () -- C:\Users\Curt\Documents\2_07.rtf [2014/04/06 19:05:39 | 000,000,342 | ---- | M] () -- C:\Users\Curt\Documents\2.05 crabby.rtf [2014/04/06 19:05:38 | 000,000,854 | ---- | M] () -- C:\Users\Curt\Documents\1_05.rtf [2014/04/06 19:05:38 | 000,000,342 | ---- | M] () -- C:\Users\Curt\Documents\2.02hms.rtf [2014/04/06 19:05:37 | 111,258,966 | ---- | M] () -- C:\Users\Curt\Documents\1_03marine.rtf [2014/04/06 19:03:39 | 000,052,822 | ---- | M] () -- C:\Users\Curt\Documents\16_07 RACT.rtf [2014/04/06 19:03:37 | 000,004,694 | ---- | M] () -- C:\Users\Curt\Documents\06.03 Laws of Exponents.odt [2014/04/06 19:03:37 | 000,000,342 | -H-- | M] () -- C:\Users\Curt\Desktop\~$window.rtf [2014/04/06 19:03:37 | 000,000,342 | ---- | M] () -- C:\Users\Curt\Documents\1.08 e n g.rtf [2014/04/06 19:03:36 | 000,141,910 | ---- | M] () -- C:\Users\Curt\Desktop\PGRInsuranceIDCard.pdf [2014/04/06 18:40:46 | 000,194,390 | ---- | M] () -- C:\Users\Curt\Desktop\KyleGuffeySSP.pdf [2014/04/06 18:40:46 | 000,076,630 | ---- | M] () -- C:\Users\Curt\Desktop\lance.jpg [2014/04/06 18:40:45 | 000,371,542 | ---- | M] () -- C:\Users\Curt\Desktop\KyleContact Rx.jpg [2014/04/06 18:40:44 | 000,328,790 | ---- | M] () -- C:\Users\Curt\Desktop\insurance.png [2014/04/06 18:40:42 | 002,909,526 | ---- | M] () -- C:\Users\Curt\Desktop\front3.jpg [2014/04/06 18:40:38 | 002,382,166 | ---- | M] () -- C:\Users\Curt\Desktop\front2.jpg [2014/04/06 18:40:35 | 002,651,990 | ---- | M] () -- C:\Users\Curt\Desktop\front1.jpg [2014/04/06 18:40:31 | 001,222,998 | ---- | M] () -- C:\Users\Curt\Desktop\f.jpg [2014/04/06 18:40:31 | 000,089,686 | ---- | M] () -- C:\Users\Curt\Desktop\Fins.jpg [2014/04/06 18:40:31 | 000,018,518 | -HS- | M] () -- C:\Users\Curt\Desktop\Folder.jpg [2014/04/06 18:40:29 | 001,177,942 | ---- | M] () -- C:\Users\Curt\Desktop\e.jpg [2014/04/06 18:40:26 | 001,396,822 | ---- | M] () -- C:\Users\Curt\Desktop\DolphinsWallpaper.png [2014/04/06 18:40:24 | 001,388,374 | ---- | M] () -- C:\Users\Curt\Desktop\d.jpg [2014/04/06 18:40:22 | 001,913,174 | ---- | M] () -- C:\Users\Curt\Desktop\c.jpg [2014/04/06 18:40:19 | 001,978,966 | ---- | M] () -- C:\Users\Curt\Desktop\b.jpg [2014/04/06 17:20:03 | 000,012,374 | -HS- | M] () -- C:\Users\Curt\Desktop\AlbumArt_{C7D08B9D-713F-41C6-A091-75BDA1A2FD51}_Small.jpg [2014/04/06 17:20:02 | 000,066,902 | -HS- | M] () -- C:\Users\Curt\Desktop\AlbumArt_{C7D08B9D-713F-41C6-A091-75BDA1A2FD51}_Large.jpg [2014/04/06 17:20:01 | 000,004,694 | -HS- | M] () -- C:\Users\Curt\Desktop\AlbumArt_{C39055FC-EBF8-4B54-AC40-4F7944B19C07}_Small.jpg [2014/04/06 17:20:00 | 000,018,518 | -HS- | M] () -- C:\Users\Curt\Desktop\AlbumArt_{C39055FC-EBF8-4B54-AC40-4F7944B19C07}_Large.jpg [2014/04/06 17:19:59 | 000,027,734 | -HS- | M] () -- C:\Users\Curt\Desktop\AlbumArt_{4C316633-E1DD-4E50-A1C6-4FCCFBAF7FF1}_Large.jpg [2014/04/06 17:19:59 | 000,008,022 | -HS- | M] () -- C:\Users\Curt\Desktop\AlbumArt_{4C316633-E1DD-4E50-A1C6-4FCCFBAF7FF1}_Small.jpg [2014/04/06 17:19:57 | 000,009,814 | -HS- | M] () -- C:\Users\Curt\Desktop\AlbumArt_{3F80348E-203F-4E85-9805-5221A2E9211F}_Small.jpg [2014/04/06 17:19:56 | 000,041,814 | -HS- | M] () -- C:\Users\Curt\Desktop\AlbumArt_{3F80348E-203F-4E85-9805-5221A2E9211F}_Large.jpg [2014/04/06 17:19:55 | 000,004,694 | -HS- | M] () -- C:\Users\Curt\Desktop\AlbumArtSmall.jpg [2014/04/06 17:19:54 | 001,950,294 | ---- | M] () -- C:\Users\Curt\Desktop\a.jpg [2014/04/06 17:19:49 | 000,002,785 | ---- | M] () -- C:\Users\Curt\AppData\Roaming\HOW_DECRYPT.HTML [2014/04/06 17:19:49 | 000,000,135 | ---- | M] () -- C:\Users\Curt\AppData\Roaming\HOW_DECRYPT.URL [2014/04/06 17:10:41 | 000,002,785 | ---- | M] () -- C:\Users\Curt\AppData\Local\HOW_DECRYPT.HTML [2014/04/06 17:10:41 | 000,000,135 | ---- | M] () -- C:\Users\Curt\AppData\Local\HOW_DECRYPT.URL [2014/04/06 16:57:15 | 000,002,785 | ---- | M] () -- C:\ProgramData\HOW_DECRYPT.HTML [2014/04/06 16:57:15 | 000,000,135 | ---- | M] () -- C:\ProgramData\HOW_DECRYPT.URL [2014/04/05 11:59:50 | 000,006,656 | ---- | M] () -- C:\Users\Curt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2014/04/03 17:01:12 | 004,927,488 | ---- | M] () -- C:\Users\Curt\Desktop\A4220397329.xlt [2014/04/03 10:33:42 | 000,063,192 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys [2014/04/03 10:33:34 | 000,088,280 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys [2014/04/03 10:33:30 | 000,025,816 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2014/03/31 07:21:06 | 000,040,248 | ---- | M] (AVG) -- C:\Windows\SysNative\TURegOpt.exe [2014/03/31 07:20:58 | 000,042,808 | ---- | M] (AVG) -- C:\Windows\SysNative\uxtuneup.dll [2014/03/31 07:20:58 | 000,035,640 | ---- | M] (AVG) -- C:\Windows\SysWow64\uxtuneup.dll [2014/03/31 07:20:58 | 000,029,496 | ---- | M] (AVG) -- C:\Windows\SysNative\authuitu.dll [2014/03/31 07:20:58 | 000,025,400 | ---- | M] (AVG) -- C:\Windows\SysWow64\authuitu.dll [2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2014/04/26 07:51:39 | 000,009,403 | ---- | C] () -- C:\Users\Curt\Desktop\finspic.jpg [2014/04/26 00:20:38 | 000,032,126 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\VT20140417.018 [2014/04/26 00:20:34 | 000,009,939 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\symelam64.cat [2014/04/26 00:20:34 | 000,008,196 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\srtspx64.cat [2014/04/26 00:20:34 | 000,008,194 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\symefa64.cat [2014/04/26 00:20:34 | 000,008,192 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\symnet64.cat [2014/04/26 00:20:34 | 000,008,192 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\srtsp64.cat [2014/04/26 00:20:34 | 000,008,188 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\symds64.cat [2014/04/26 00:20:34 | 000,008,184 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\iron.cat [2014/04/26 00:20:34 | 000,003,433 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\symefa.inf [2014/04/26 00:20:34 | 000,002,852 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\symds.inf [2014/04/26 00:20:34 | 000,001,440 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\symnet.inf [2014/04/26 00:20:34 | 000,001,437 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\srtsp64.inf [2014/04/26 00:20:34 | 000,001,420 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\srtspx64.inf [2014/04/26 00:20:34 | 000,001,098 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\symelam.inf [2014/04/26 00:20:34 | 000,000,767 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\iron.inf [2014/04/26 00:20:33 | 000,008,202 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\ccsetx64.cat [2014/04/26 00:20:33 | 000,000,855 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\ccsetx64.inf [2014/04/26 00:20:12 | 000,030,068 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\symvtcer.dat [2014/04/26 00:20:12 | 000,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\1502000.026\isolate.ini [2014/04/25 20:51:40 | 002,186,633 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\Cat.DB [2014/04/25 20:51:39 | 000,008,222 | ---- | C] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT [2014/04/25 20:51:39 | 000,000,854 | ---- | C] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF [2014/04/25 20:51:12 | 000,002,397 | ---- | C] () -- C:\Users\Public\Desktop\Norton 360.lnk [2014/04/25 20:50:05 | 000,003,433 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\SymEFA.inf [2014/04/25 20:50:05 | 000,002,852 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\SymDS.inf [2014/04/25 20:50:05 | 000,001,440 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\SymNet.inf [2014/04/25 20:50:05 | 000,001,437 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\srtsp64.inf [2014/04/25 20:50:05 | 000,001,420 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\srtspx64.inf [2014/04/25 20:50:05 | 000,001,098 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\symELAM.inf [2014/04/25 20:50:05 | 000,000,855 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\ccSetx64.inf [2014/04/25 20:50:05 | 000,000,767 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\Iron.inf [2014/04/25 20:49:39 | 000,014,818 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\SymVTcer.dat [2014/04/25 20:49:36 | 000,009,939 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\SymELAM64.cat [2014/04/25 20:49:36 | 000,008,202 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\ccSetx64.cat [2014/04/25 20:49:36 | 000,008,196 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\srtspx64.cat [2014/04/25 20:49:36 | 000,008,194 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\SymEFA64.cat [2014/04/25 20:49:36 | 000,008,192 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\symnet64.cat [2014/04/25 20:49:36 | 000,008,192 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\srtsp64.cat [2014/04/25 20:49:36 | 000,008,188 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\SymDS64.cat [2014/04/25 20:49:36 | 000,008,184 | R--- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\iron.cat [2014/04/25 20:49:35 | 000,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\N360x64\1501000.012\isolate.ini [2014/04/25 19:49:20 | 000,002,231 | ---- | C] () -- C:\Users\Public\Desktop\AVG 1-Click Maintenance.lnk [2014/04/25 19:49:20 | 000,002,205 | ---- | C] () -- C:\Users\Public\Desktop\AVG PC TuneUp 2014.lnk [2014/04/25 19:49:19 | 000,002,217 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2014.lnk [2014/04/23 21:01:45 | 000,001,180 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk [2014/04/23 21:01:45 | 000,001,168 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 9.lnk [2014/04/15 00:06:17 | 000,007,609 | ---- | C] () -- C:\Users\Curt\AppData\Local\Resmon.ResmonCfg [2014/04/14 17:47:08 | 002,775,620 | ---- | C] () -- C:\Users\Curt\Desktop\dollie3.jpg [2014/04/14 17:46:54 | 002,395,067 | ---- | C] () -- C:\Users\Curt\Desktop\dollie2.jpg [2014/04/14 17:46:32 | 002,891,183 | ---- | C] () -- C:\Users\Curt\Desktop\Dollie1.jpg [2014/04/08 19:34:17 | 001,692,196 | ---- | C] () -- C:\Users\Curt\Desktop\hh.jpg [2014/04/08 19:33:55 | 001,204,349 | ---- | C] () -- C:\Users\Curt\Desktop\gg.jpg [2014/04/08 19:33:19 | 001,170,291 | ---- | C] () -- C:\Users\Curt\Desktop\dd.jpg [2014/04/08 19:32:55 | 001,830,891 | ---- | C] () -- C:\Users\Curt\Desktop\cc.jpg [2014/04/08 19:32:24 | 001,866,284 | ---- | C] () -- C:\Users\Curt\Desktop\bb.jpg [2014/04/06 19:34:47 | 000,002,785 | ---- | C] () -- C:\Users\Curt\Documents\HOW_DECRYPT.HTML [2014/04/06 19:34:47 | 000,000,135 | ---- | C] () -- C:\Users\Curt\Documents\HOW_DECRYPT.URL [2014/04/06 17:19:49 | 000,002,785 | ---- | C] () -- C:\Users\Curt\AppData\Roaming\HOW_DECRYPT.HTML [2014/04/06 17:19:49 | 000,000,135 | ---- | C] () -- C:\Users\Curt\AppData\Roaming\HOW_DECRYPT.URL [2014/04/06 17:10:41 | 000,002,785 | ---- | C] () -- C:\Users\Curt\AppData\Local\HOW_DECRYPT.HTML [2014/04/06 17:10:41 | 000,000,135 | ---- | C] () -- C:\Users\Curt\AppData\Local\HOW_DECRYPT.URL [2014/04/06 16:57:15 | 000,000,135 | ---- | C] () -- C:\ProgramData\HOW_DECRYPT.URL [2014/04/06 16:57:14 | 000,002,785 | ---- | C] () -- C:\ProgramData\HOW_DECRYPT.HTML [2014/04/06 15:25:05 | 001,222,998 | ---- | C] () -- C:\Users\Curt\Desktop\f.jpg [2014/04/06 15:24:44 | 001,177,942 | ---- | C] () -- C:\Users\Curt\Desktop\e.jpg [2014/04/06 15:24:32 | 001,388,374 | ---- | C] () -- C:\Users\Curt\Desktop\d.jpg [2014/04/06 15:24:12 | 001,913,174 | ---- | C] () -- C:\Users\Curt\Desktop\c.jpg [2014/04/06 15:24:01 | 001,978,966 | ---- | C] () -- C:\Users\Curt\Desktop\b.jpg [2014/04/06 15:23:44 | 001,950,294 | ---- | C] () -- C:\Users\Curt\Desktop\a.jpg [2014/04/04 21:52:24 | 000,328,790 | ---- | C] () -- C:\Users\Curt\Desktop\insurance.png [2014/04/04 07:19:49 | 000,141,910 | ---- | C] () -- C:\Users\Curt\Desktop\PGRInsuranceIDCard.pdf [2014/04/03 17:00:50 | 004,927,488 | ---- | C] () -- C:\Users\Curt\Desktop\A4220397329.xlt [2014/03/30 12:44:10 | 002,909,526 | ---- | C] () -- C:\Users\Curt\Desktop\front3.jpg [2014/03/30 12:43:55 | 002,382,166 | ---- | C] () -- C:\Users\Curt\Desktop\front2.jpg [2014/03/30 12:43:45 | 002,651,990 | ---- | C] () -- C:\Users\Curt\Desktop\front1.jpg [2014/03/29 19:53:36 | 000,027,734 | -HS- | C] () -- C:\Users\Curt\Desktop\AlbumArt_{4C316633-E1DD-4E50-A1C6-4FCCFBAF7FF1}_Large.jpg [2014/03/29 19:53:36 | 000,008,022 | -HS- | C] () -- C:\Users\Curt\Desktop\AlbumArt_{4C316633-E1DD-4E50-A1C6-4FCCFBAF7FF1}_Small.jpg [2014/03/27 16:33:04 | 000,018,518 | -HS- | C] () -- C:\Users\Curt\Desktop\AlbumArt_{C39055FC-EBF8-4B54-AC40-4F7944B19C07}_Large.jpg [2014/03/27 16:33:04 | 000,004,694 | -HS- | C] () -- C:\Users\Curt\Desktop\AlbumArt_{C39055FC-EBF8-4B54-AC40-4F7944B19C07}_Small.jpg [2014/03/27 16:32:54 | 000,066,902 | -HS- | C] () -- C:\Users\Curt\Desktop\AlbumArt_{C7D08B9D-713F-41C6-A091-75BDA1A2FD51}_Large.jpg [2014/03/27 16:32:54 | 000,012,374 | -HS- | C] () -- C:\Users\Curt\Desktop\AlbumArt_{C7D08B9D-713F-41C6-A091-75BDA1A2FD51}_Small.jpg [2013/11/22 19:49:28 | 000,006,656 | ---- | C] () -- C:\Users\Curt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2013/10/18 20:32:25 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll [2013/10/03 04:28:52 | 000,602,112 | ---- | C] () -- C:\Windows\SysWow64\xvid.dll [2013/07/26 12:10:03 | 000,322,988 | ---- | C] () -- C:\Users\Curt\AppData\Local\9f2c10a0-f56c-464d-b90f-23109eb5be53 [2013/03/04 14:36:29 | 000,108,320 | ---- | C] () -- C:\ProgramData\wwkmyvuoezuezha [2012/12/13 22:50:54 | 095,023,320 | ---- | C] () -- C:\ProgramData\AB75.pad [2012/12/03 20:06:04 | 095,023,320 | ---- | C] () -- C:\ProgramData\97B442D1sm.pad [2012/09/23 13:35:38 | 000,384,844 | ---- | C] () -- C:\Users\Curt\AppData\Local\funmoods-speeddial.crx [2012/01/08 14:59:34 | 000,010,224 | -HS- | C] () -- C:\Users\Curt\AppData\Local\647w8y7f5547 [2012/01/08 14:59:34 | 000,010,224 | -HS- | C] () -- C:\ProgramData\647w8y7f5547 [2012/01/02 15:44:32 | 000,010,952 | -HS- | C] () -- C:\Users\Curt\AppData\Local\020qb55rv70j00614350kirkhx0o338ikc6yh13544v [2012/01/02 15:44:32 | 000,010,952 | -HS- | C] () -- C:\ProgramData\020qb55rv70j00614350kirkhx0o338ikc6yh13544v [color=#E56717]========== ZeroAccess Check ==========[/color] [2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 "" = C:\Users\Curt\AppData\Local\Temp\sunxpsr\srbwtds\wow64.dll [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2013/07/25 22:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 21:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 23:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] [color=#E56717]========== LOP Check ==========[/color] [2013/01/09 18:03:33 | 000,000,000 | -HSD | M] -- C:\Users\Curt\AppData\Roaming\7A6357 [2014/04/23 23:02:20 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\AVG [2012/11/12 06:25:20 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\Bedodu [2013/07/15 18:14:58 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\Blackboard [2012/08/13 09:58:27 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\Catalina Marketing Corp [2012/11/12 06:25:20 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\Deahbu [2014/04/06 17:17:25 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\DVDVideoSoft [2012/03/11 01:06:34 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\EMX [2014/04/06 17:17:30 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\EPSON [2012/03/07 20:15:12 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\Fingertapps [2012/01/08 15:20:39 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\ID Vault [2011/12/31 19:12:00 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\Leader Technologies [2011/12/17 18:29:38 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\Leadertech [2014/04/23 20:04:23 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\MotoCast [2014/04/23 19:07:06 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\Motorola [2013/05/11 11:23:38 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\Motorola Mobility [2012/01/01 20:12:44 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\Namco [2014/04/06 17:18:56 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\PCDr [2013/08/13 21:12:17 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\SearchProtect [2014/02/16 23:58:22 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\SoftGrid Client [2014/04/23 21:01:48 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\TeamViewer [2012/01/08 15:20:23 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\Tific [2012/01/13 23:46:06 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\TP [2014/04/23 21:26:16 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\TuneUp Software [2012/11/12 06:25:33 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\Ukoge [2014/04/06 17:19:48 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\WildTangent [2011/12/22 21:18:42 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\Windows Live Writer [2014/04/06 17:19:49 | 000,000,000 | ---D | M] -- C:\Users\Curt\AppData\Roaming\WindSolutions [color=#E56717]========== Purity Check ==========[/color] [color=#E56717]========== Custom Scans ==========[/color] [color=#E56717]========== Base Services ==========[/color] SRV:[b]64bit:[/b] - [2009/07/13 21:40:01 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc) SRV:[b]64bit:[/b] - [2013/02/27 01:47:10 | 000,070,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo) SRV:[b]64bit:[/b] - [2009/07/13 21:38:55 | 000,079,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG) SRV:[b]64bit:[/b] - [2010/11/20 23:23:51 | 000,849,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS) No service found with a name of BFE SRV:[b]64bit:[/b] - [2013/09/24 21:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lsass.exe -- (KeyIso) SRV:[b]64bit:[/b] - [2009/07/13 21:40:50 | 000,402,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem) SRV - [2009/07/13 21:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem) SRV:[b]64bit:[/b] - [2012/07/04 18:13:27 | 000,136,704 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\browser.dll -- (Browser) SRV:[b]64bit:[/b] - [2013/07/09 01:46:20 | 000,184,320 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc) SRV - [2013/07/09 00:46:31 | 000,140,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\cryptsvc.dll -- (CryptSvc) SRV:[b]64bit:[/b] - [2010/11/20 23:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch) SRV:[b]64bit:[/b] - [2010/11/20 23:24:00 | 000,317,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp) SRV - [2010/11/20 23:24:09 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp) SRV:[b]64bit:[/b] - [2011/11/17 17:18:02 | 000,183,296 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache) SRV:[b]64bit:[/b] - [2009/07/13 21:40:35 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\eapsvc.dll -- (EapHost) SRV:[b]64bit:[/b] - [2009/07/13 21:41:00 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv) SRV - [2009/07/13 21:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv) SRV:[b]64bit:[/b] - [2009/07/13 21:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess) SRV:[b]64bit:[/b] - [2010/11/20 23:23:48 | 000,501,248 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent) No service found with a name of MsMpSvc No service found with a name of NisSrv SRV:[b]64bit:[/b] - [2009/07/13 21:41:54 | 000,524,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\swprv.dll -- (swprv) SRV:[b]64bit:[/b] - [2009/07/13 21:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS) SRV:[b]64bit:[/b] - [2009/07/13 21:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netman.dll -- (Netman) SRV:[b]64bit:[/b] - [2009/07/13 21:41:52 | 000,459,776 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofm.dll -- (netprofm) SRV - [2009/07/13 21:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\netprofm.dll -- (netprofm) SRV:[b]64bit:[/b] - [2012/10/03 13:44:21 | 000,303,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc) SRV:[b]64bit:[/b] - [2009/07/13 21:41:53 | 000,025,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi) SRV:[b]64bit:[/b] - [2011/11/17 17:18:09 | 000,404,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay) SRV:[b]64bit:[/b] - [2012/02/11 02:36:02 | 000,559,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler) SRV:[b]64bit:[/b] - [2013/09/24 21:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (ProtectedStorage) No service found with a name of EMDMgmt SRV:[b]64bit:[/b] - [2009/07/13 21:41:53 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto) SRV:[b]64bit:[/b] - [2010/11/20 23:24:17 | 000,344,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan) SRV:[b]64bit:[/b] - [2010/11/20 23:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs) SRV:[b]64bit:[/b] - [2010/11/20 23:24:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\seclogon.dll -- (seclogon) SRV:[b]64bit:[/b] - [2013/09/24 21:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs) No service found with a name of wscsvc SRV:[b]64bit:[/b] - [2010/11/20 23:23:48 | 000,236,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer) SRV:[b]64bit:[/b] - [2010/11/20 23:23:55 | 000,370,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection) SRV - [2010/11/20 23:24:03 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection) No service found with a name of slsvc SRV:[b]64bit:[/b] - [2010/11/20 23:24:16 | 001,110,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule) SRV:[b]64bit:[/b] - [2010/11/20 23:24:32 | 000,316,928 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv) SRV - [2010/11/20 23:24:00 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv) SRV:[b]64bit:[/b] - [2009/07/13 21:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes) SRV:[b]64bit:[/b] - [2012/05/01 01:40:20 | 000,209,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc) SRV:[b]64bit:[/b] - [2010/11/20 23:23:55 | 001,600,512 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS) SRV:[b]64bit:[/b] - [2010/11/20 23:24:32 | 000,679,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioSrv) SRV:[b]64bit:[/b] - [2010/11/20 23:24:32 | 000,679,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioEndpointBuilder) SRV:[b]64bit:[/b] - [2010/11/20 23:25:06 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC) No service found with a name of WinDefend SRV:[b]64bit:[/b] - [2010/11/20 23:23:55 | 001,646,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (eventlog) No service found with a name of MpsSvc SRV:[b]64bit:[/b] - [2010/11/20 23:24:48 | 000,580,096 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc) SRV:[b]64bit:[/b] - [2010/11/20 23:24:15 | 000,128,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver) SRV - [2010/11/20 23:24:28 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver) SRV:[b]64bit:[/b] - [2009/07/13 21:41:56 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt) SRV:[b]64bit:[/b] - [2012/06/02 18:19:43 | 002,428,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv) SRV:[b]64bit:[/b] - [2010/11/20 23:24:09 | 000,252,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc) SRV:[b]64bit:[/b] - [2009/07/13 21:41:56 | 000,886,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (Wlansvc) SRV:[b]64bit:[/b] - [2010/11/20 23:24:32 | 000,118,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation) [color=#A23BEC]< %SYSTEMDRIVE%\*.exe >[/color] [2007/11/07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe [color=#A23BEC]< c:\program files (x86)\Google\Desktop >[/color] [2009/07/14 01:08:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT [2009/07/14 01:08:49 | 000,032,554 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT [2012/01/22 10:34:34 | 000,000,890 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job [2012/01/22 10:34:35 | 000,000,894 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job [2013/12/16 15:21:32 | 000,000,830 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job [color=#A23BEC]< c:\program files\Google\Desktop >[/color] [color=#A23BEC]< dir "%systemdrive%\*" /S /A:L /C >[/color] Volume in drive C is OS Volume Serial Number is 5E7A-6357 Directory of C:\ 07/14/2009 01:08 AM Documents and Settings [C:\Users] 0 File(s) 0 bytes Directory of C:\ProgramData 07/14/2009 01:08 AM Application Data [C:\ProgramData] 07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop] 07/14/2009 01:08 AM Documents [C:\Users\Public\Documents] 07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites] 07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\Users 07/14/2009 01:08 AM All Users [C:\ProgramData] 07/14/2009 01:08 AM Default User [C:\Users\Default] 0 File(s) 0 bytes Directory of C:\Users\All Users 07/14/2009 01:08 AM Application Data [C:\ProgramData] 07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop] 07/14/2009 01:08 AM Documents [C:\Users\Public\Documents] 07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites] 07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu] 07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\Users\Curt 12/17/2011 06:25 PM Application Data [C:\Users\Curt\AppData\Roaming] 12/17/2011 06:25 PM Cookies [C:\Users\Curt\AppData\Roaming\Microsoft\Windows\Cookies] 12/17/2011 06:25 PM Local Settings [C:\Users\Curt\AppData\Local] 12/17/2011 06:25 PM My Documents [C:\Users\Curt\Documents] 12/17/2011 06:25 PM NetHood [C:\Users\Curt\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 12/17/2011 06:25 PM PrintHood [C:\Users\Curt\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 12/17/2011 06:25 PM Recent [C:\Users\Curt\AppData\Roaming\Microsoft\Windows\Recent] 12/17/2011 06:25 PM SendTo [C:\Users\Curt\AppData\Roaming\Microsoft\Windows\SendTo] 12/17/2011 06:25 PM Start Menu [C:\Users\Curt\AppData\Roaming\Microsoft\Windows\Start Menu] 12/17/2011 06:25 PM Templates [C:\Users\Curt\AppData\Roaming\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\Users\Curt\AppData\Local 12/17/2011 06:25 PM Application Data [C:\Users\Curt\AppData\Local] 12/17/2011 06:25 PM History [C:\Users\Curt\AppData\Local\Microsoft\Windows\History] 12/17/2011 06:25 PM Temporary Internet Files [C:\Users\Curt\AppData\Local\Microsoft\Windows\Temporary Internet Files] 0 File(s) 0 bytes Directory of C:\Users\Curt\AppData\LocalLow 02/20/2012 08:08 PM PlayReady [C:\ProgramData\Microsoft\PlayReady] 0 File(s) 0 bytes Directory of C:\Users\Curt\Documents 12/17/2011 06:25 PM My Music [C:\Users\Curt\Music] 12/17/2011 06:25 PM My Pictures [C:\Users\Curt\Pictures] 12/17/2011 06:25 PM My Videos [C:\Users\Curt\Videos] 0 File(s) 0 bytes Directory of C:\Users\Default 07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Roaming] 07/14/2009 01:08 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies] 07/14/2009 01:08 AM Local Settings [C:\Users\Default\AppData\Local] 07/14/2009 01:08 AM My Documents [C:\Users\Default\Documents] 07/14/2009 01:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts] 07/14/2009 01:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts] 07/14/2009 01:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent] 07/14/2009 01:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo] 07/14/2009 01:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu] 07/14/2009 01:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates] 0 File(s) 0 bytes Directory of C:\Users\Default\AppData\Local 07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Local] 07/14/2009 01:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History] 07/14/2009 01:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files] 0 File(s) 0 bytes Directory of C:\Users\Default\Documents 07/14/2009 01:08 AM My Music [C:\Users\Default\Music] 07/14/2009 01:08 AM My Pictures [C:\Users\Default\Pictures] 07/14/2009 01:08 AM My Videos [C:\Users\Default\Videos] 0 File(s) 0 bytes Directory of C:\Users\Public\Documents 07/14/2009 01:08 AM My Music [C:\Users\Public\Music] 07/14/2009 01:08 AM My Pictures [C:\Users\Public\Pictures] 07/14/2009 01:08 AM My Videos [C:\Users\Public\Videos] 0 File(s) 0 bytes Total Files Listed: 0 File(s) 0 bytes 51 Dir(s) 384,310,665,216 bytes free [color=#A23BEC]< MD5 for: RPCSS.DLL >[/color] [2010/11/20 23:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=5C627D1B1138676C0A7AB2C2C190D123 -- C:\Windows\SysNative\rpcss.dll [2010/11/20 23:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) MD5=5C627D1B1138676C0A7AB2C2C190D123 -- C:\Windows\winsxs\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.1.7601.17514_none_c7f0e16b547f887d\rpcss.dll < End of report >