Start a Conversation

Unsolved

This post is more than 5 years old

4372

August 23rd, 2010 13:00

filecure cant get it off my computer

short cuts on my desktop changing, filecure still on my computer after I deleted the thing.. Ran trend house call and says no problems..Will not let me open Hijackthis as Admin and cant save a log..I have Vista..Thank you for your help..

10.4K Posts

August 25th, 2010 18:00

Can you Boot into Safe Mode with Networking and run Hijackthis from there?

August 25th, 2010 21:00

Thank you, I worked with a paid dell tec today, I have the filecure issue taken care of but still having many other issues. The dell tec said I didnt need HiJack this on my computer.. I Have McAfee and it shows I still have 1 Trojan and 25696 Tracking Cookies..  I dont know what to do, computer still running slow.. Sorry not sure why but couldnt use nightsparrow so I am responding using another acount I set up Nightsparrow1. Thank you for your Help..

10.4K Posts

August 26th, 2010 06:00

Can you run and post a Hijackthis log now?

August 28th, 2010 09:00

BAMAJIM, Thank you for your help. Sorry I have been working and couldn't respond sooner. I re installed HighJackThis,I hope this is how to copy the log.l still get an error when scaning with HighJackThis and it will not allow me to run as administrator. When I right click to try and bring up the option to run as administrator it  does not show up.

 

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:36:42 AM, on 8/28/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Digital Line Detect\DLG.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Dell\MediaDirect\PCMService.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Windows Live\Toolbar\wltuser.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.zoomtown.com/webedge/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://broadband.zoomtown.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20100519012304.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files (x86)\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [Dell PC TuneUp Startup] "C:\Program Files (x86)\iolo\Common\Lib\ioloLManager.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
O4 - HKCU\..\Run: [Google Update] "C:\Users\Tammy\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files (x86)\Digital Line Detect\DLG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Unknown owner - C:\Windows\system32\AERTSr64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\615\g2aservice.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files (x86)\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files (x86)\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Usbpau - Unknown owner - (no file)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

--
End of file - 11611 bytes

August 28th, 2010 09:00

I will try and re in stall HighJackThis and post a log. Thank you

10.4K Posts

August 30th, 2010 12:00


nightsparrow1

1. Go HERE and download FileLister.
  • Save it to your Desktop
  • Rt Click ->> Extract all ->> And extract it to your Desktop
  • Additional help on extracting zip files can be found HERE
  • Open the File Lister Folder.
  • Note: Leave the FileLister.vbe file in the folder and run it from there.

user posted image
  • Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
  • When the program is fnished it will produce a log for you Files.txt
  • Which will be located in the default location from which FileLister was run(the FileLister folder)

Copy and paste the contents of that log in your reply.

August 31st, 2010 09:00

Thank you BAMAJIM, I hope I did this right, after I opened  Notepad came up I hope thats the log you are talking about. I copied and pasted it below..

 

#@~^/msAAA==vANrD+9P!2z81z8!@#@&}wOrKxPAaw^kmbO@#@&}x,2.DG.,In/!h+,1naD@#@&9rsPG4NoUr@#@&fb:PkYMok^+Uls+@#@&Gk:,G4Nsk Cs@#@&fb:~W8%wWsN.FBPG8NsWs[D+~,G(LoKV9+D2~,G4NsGV9+.*BPW(%sKVN.X~,W(LoWs[D~,G4NsGs9+D{S,W8LwG^NnM%BPW(LwGV9+.,BPG8N0W^[+MF!B~G4NsKV[+.q8@#@&fbhP1WsobV+d@#@&fr:,dDD/K:aEYD@#@&fb:~ktj4VV@#@&fb:PK8%sbV@#@&frh,NOHKUY4bLG@#@&frh,W8Lq\&~~1W^wDKmd//SPK4%2MWmd/@#@&fbh~/!46WsNn.@#@&9ks~/DDFnHnlO4BPdYMFXKmY4F~,/D.|XKlDt+S,/YMF+HnlD4f@#@&fb:~W]nT~~W"no8~~G"+o+S,W]+Tf@#@&9b:,lDM?!8|Xd~,l..UE40nXkF~,C.DUE(|nXd+BPCDMdE(3nzk&~~CMDdE(VXdW~,lDM?!8|Xd*@#@&9rsP/!83X~,j;40+HFSPj;(3nXySPUE8FX&S~UE8|zW~~UE(|+H*@#@&fb:~Yk~~]o3z~,YYB~]+T|Xq@#@&9b:~/`Uk /OC^VnCO4~~/z2a1Cs+@#@&fb:,d?!4V+H~~CUE40nXk~PMn2WMYBPdY.^K:hl [~,W8%q/tj4Vs~,r Y.1~,/YM|znmY4bBP))BPb~SPzZ~,)9@#@&fb:~AVnH@#@&fbhPK4% tq?n.7k^+B~1Ws&Y:/BPK8L&Yn:@#@&9rsPrwrV~PK8%sbVFSPG8NsrV+~,W8%wkVnfBPG4NobVnW~,/YMZ!.DxO?7mdS,/YMj\1~PkO.1KY;E.DnUD~~/D.VbxnS,mWsrD+h/8S,fOgWS@#@&Gks~ZKVq~,ZGsy~P;GV2~P;GscBP;Ws*S~;WsGB~ZKV0S,ZWs1BP/W^qZ~~;W^FF@#@&Gr:,/^sbVn@#@&fks~?DD2 -SPbxDZGEUO@#@&9ks~lMD#C^E+HCs+d~,CMD#mV!+1m:dFBP-l^EnUm:+8SP7lV!nUls+@#@&9kh~mInoB~4"+LS,mInLBP[IL@#@&9b:,b2BPzo~,b!~,buS,b9B~bn~PzJSPzHBP)1S~zn@#@&Gr:,/O.n+XKCDt*~,dDDFXhlY4*B~/DDF+HnCO4v~,G4Nsk^nqF@#@&GkhPuoBPODB~IoFnH ~~^KV6?dBPG(L}?~,IdE^Yq@#@&frh,ZW^rY:/yS~W(LA62VG.DSPbUY_W.r.WxOC^~~k Oj+.Dk1lV@#@&Gr:,ji~,/)2ajxbU/DlV^S~W"+TcSPdOM|nXhCY4GS~mDD#C^En1mh/*BP~b~,A~SP7lsExChcPE#?,FR8 +@#@&fb:~W]nT*SPkODn+zKmYt0S,l.DjC^Engls+/l~,/bBP/ABP-C^E+ C:*PE#jP8R8R+@#@&9b:~/D.sglhnBPjor^+~Bjj,F 8R2@#@&E'{x'{'x'{'xx{''{x'{''{xx'{'{'x'xx{'x'{x';rHj:Ij/PU@#@&ZKUkY~_|;IP{PLu%Z!T!Z!T~EC|Ae{;SbUj3?|I}rP@#@&/KxdY,u|;j~x,[C0TZ!T!Zq,Bun2I{Z`I"31:{i?AI@#@&;WxkOP_|St~xPLCR!T!TTZ ~B_F2I{J6;bSm\zZuqg3@#@&/KxkYP_|`~P{P'CR!TTZ!!2~B_|2Imi?AIU@#@&ZGUkY~Cn/Z,'~'_%!TTZ!T*,v_|3I{;jI"2gP{;rHs&M@#@&@#@&B{x'{''{xx'{'{'x'x~G2/Sz]b:q6HU@#@&dOMZG:a;D+.,',JRr@#@&v'{'x'{'xx{''{x'{''h.GoM+k/~AC.,.jP8 FcF@#@&U+Y~G(L H&jD-bmP',MOr(LnmD`E bx:ThYk)-'E~[,/DD/Wh2!YnD,'Pr-.GKY-^rs\+J*@#@&?nDP1WV&Yh/yPxPK4% tq?.\bm+c3a+1p!+.XcEU+s+1OPCPo.K:P r &+{Gnk3OKwtWxbYK.J*@#@&sKD~3mmt,G4NqYh~k P1WsqOns/+@#@&~P,PrUDCW.r.WUYms,'~K4NqY:cjmM+nxqk[O4@#@&,~P,kxD#nDDk1lsPx~K4%qDn:c?^.+xunbo4Y@#@&g+aD@#@&@#@&U+D~W(L36aVG.DP{~ZM+lDn64N+1Y~{@#@&,P~PvEq Yn. +Y3aaVGD.cb2aVbmlDkKUJ*@#@&@#@&W8%A6w^GDDRgC-kTlD+~JC8KEO)(sl 3E~,P@#@&G(L36asKDnMR:WW^Am.P{PT@#@&W8%A6w^GDDRUOCY!/~l.Px~Z@#@&W(%2XwsGM+D J0OP{~vkUDCKDk.W Ol^PRP2!Tb,zPy@#@&K4LAa2VKDD KG2,'~`bUYj+.Obmls~ Pq!Zb,z~y@#@&W4N2X2VKDnDcr[DtP{~&Z!@#@&G8LA6aVGDn.cCnkT4Y,'~qZ!P@#@&K4%2X2^W.Dc.kkk(s+,'~F,P~~,PP,~P,PP@#@&@#@&K4N2awsGM+.RGGm!:nUDRAG[HRjYHsR/!DkWD,',EhmkOJ@#@&@#@&K4LAaw^WD. fKm!:nxO :kOV~',Jor^+SrdD+.J@#@&K4%A6aVWM+M fKm;:xO ~WNH q x+MuPHdP{PEsrsSr/DnD,kd~MExUr o Pr~|@#@&,P,P[,J:4kkPhkTtO~Dl3~/\+MCsPsk EO+d~DW~mKhw^+OncJ@#@&v{'x'{x{'x{'{''{'{x'{'x'@#@&[OtWxD4bTWP{~9lD+zN[`Ehr~~OySPgWAb@#@&fOHKh~',~gWA@#@&@#@&?Y,G4Nsjr,'~/M+lDnr(L+1OcJUmMk2YrUTRok^n?H/Onsr4%n1YE#@#@&@#@&dDDwkV1mh+,'~JwksnkRYXOJ@#@&@#@&^GxkY,sGD]nmNrxT~',F@#@&@#@&?nO,dtk4Vs,',/1Db2YcZ.+mYn6(L+1O`r/1.rwDRUtnVsE*@#@&A0nX,'~ kt?4n^V IL"+C9`rC|A5|/j"I31:{ijAI-UG0DhlMnwHbmMWdWWO'rx9Ghk-/;MD+UOj+./bG -3Xw^WDD'JWTWUP`/n.,1lsnJ*@#@&@#@&v'{'{'x'xx{'x'{x'{PP3oKPo(d2~Z"3zK(}1@#@&q6PvG4NsdWcsrs26bdYk`?D.ok^+glh+bb,K4+ @#@&i?nO,W4%obxCV,x,W8NsUrR}wUK6OsbVncUYDwrV1lsnSPy#@#@&3Vdn@#@&7?OP}4%obxls~{PG4NokW }wxK6Dok^+c?DDor^+1mh+BP B~EKMEJb@#@&3 N~q6@#@&@#@&G8NskUC^RADbOSr +,JJ@#@&K8LwkUl^RA.bY+drxPJ3QQ_3_3_Q_QQ3_Q_3Q_3_QQ3__QE@#@&G4NobxC^RSDkD+drxPE_,srsPSbdYDP,#nDkkKx~F qcc~P,~P,P~~,PP~~,P~P,~,P~3J@#@&W(LwrxmV hMkOndkx~J3PP,~~P,P,P~P~~,P~P,~P,P~~,PP~~,P~P,~,P~,P,PP,P,~P,P~P,P~~,PP,~P,PP3E@#@&K4NsrxCsch.kDnSbxn~r_P$z,4C:m%b:~JPUwXSlMnCm:h+MR^GsP_r@#@&K4LwrUl^RSDrYnJbxnPrQ_3_QQ3__QQ3_Q_3Q3_Q3_3__3_r@#@&K4%sbxCschDbO+dkx~EJ@#@&E$MTxx{'x'{x'{P9CD+PsGTPAlk~MEU@#@&K4Lwk CVc.kD+Jr +Pr]+aWDD~.l PKx~ORR@*@*@*P,EPLP[OgWh@#@&@#@&v'{x{'x{'{''{'{x'{'x'{'xx{''{x'{''{xx'{'"EUxrUTPKDK^+k/nd,./~qc! F@#@&K4%wk lVcMrYSrxPEE@#@&W(%sbxl^  DbYSrxn~r'x'{x',I;U kxL~hDGmdk+d,'{''{'r@#@&K4%sbxCscDbO+dkx~EJ@#@&@#@&j+O~1WsqDn:kPx~K4L \&?nD7r1+ A6mp!+Mz`r?nVmO~CP0MG:,k f+{hDKmn/dEB~*%*@#@&@#@&oGMP2C^4PG4N(D+h,k PmKV&O+s/@#@&iW8%wkxmsRSDkDnsk +,W8L(O: 2Xnm!YC8^+nCO4@#@&1aD@#@&E'{''{'{x'{'x'{'xx{''{x'{''{xx'{'{'x'x$_rv?@#@&dK4%obxls SDrYsbxnrJ@#@&?Y,GIoq'V+O6(L+1O`rhk hL:D/= r:2nM/GxmOkKxJn7+VxrswnDkG lO8e--rPL~{,@#@&P,P~dDDZKhw!Y+M~'Pr-MWGYw[0CE^O)UY[]on.G7Jb@#@&~@#@&dDDn+XhlD4F,'~JUroPqbIAwHbmDKdG0D-qkUNGAk-/EM.+ Y#nM/kGU'+aw^GM+.'AMWhk+M~CV2+MP68N+mDdJ@#@&@#@&jnY,ktdtns^PxPqdmMk2OcZDnCD+64Nn1YcrkmDbwD ?4+sVr#@#@&@#@&?OPKI+TqxMY}4%+^OvJAk hosYdlPk:2nM/GxmObWUd+7+V{ks2+M/GxmYnNe--r~[,{P@#@&~P,PkY.ZGhaEO+M~[,Jw.KWYw[0CE^O=?O9IonMW7E#@#@&~@#@&/O.n+XhCY4FP{~E?}s:)I3wtk^DKdW6Yw bxNGAk-/EM.xOj+M/kKx'n6aVGDDw$MWhknD,C+^2nD,r(LnmOdr@#@&W(%sbxCschDrOVrxcr'x{'{'P~C}v/,'x'{'xE*@#@&@#@&W"+o8 3x!:n+zP~unS\~,dYM|nzhlY4qBPCDMj!4VXk@#@&,P,7P6W.Pl^4,/E(V+HPk ~CDM/!4V+zd@#@&3DM Z^+C.@#@&b)~{P /4j4+s^R"+o"+m[`rCFSt-j6wKz]2'Hk1.G/K0D- kU[Khd-;;DM+UOj+DdrKxw+X2^W.D'ADKhknD,CnVa+.~}4L^YkJPL~E-rPLPdE8VX~[,E-r#@#@&b0P)),'~Jr~:C3gP@#@&bzP{~Jv16Pgb\3*J@#@&3x9Pqw@#@&@#@&b~PxP d4?4+^sR"+L]lNcE_|JH'j}sPqb"2-;Vmd//wZd?(9rP[,E-rP[,jiAn2IP'PEwrP'Pr(xaDG^U+D-nM&+J,',Jwr#@#@&P@#@&iG4NsrxmV AMkYsk +Pr$ur=PrP'P)),[~J,RPrP'~UjAF3IP'Pr~ PE,[,bA,[,-41Ds0@#@&HnXY@#@&v'{''{xx'{'{'x'xx{'x',6Y4+.~kX/OnsPrx6G,.d,FcFR8&@#@&W(Lok ls SDkDnSbx+,Ex'{'{'~?zdD+hPnnXkP~ckW:n~StrYsb/ON,kY:k~hbVsP WO~(+Pk4WSx#{xx'{'r@#@&dG8NsrxmsRSDrOSkUn,JE@#@&9b:~GbBPf~~,9ZBP9fBP93BPfwSPGM~,9u@#@&B{'x'xx{'x'{x'{'xx{s @#@&Gb~', ktj4+^VR"+T]+mNcJ_|J\'?W6OhmD+'\rmMWkWWYw bx[WSdPgKw/!DDnUD.nDkrKxwqk VWTW wjk+.k kOE*@#@&,~P&0PG)~@!@*PrJ~K4n P@#@&iG4NsrUmVRA.bYnVbUPEqk VWTW wjk+.k kO~{PJ,'PGb@#@&3UN,q6@#@&Bxx{'x'{x'{'xx{''xxw @#@&G$,'~q/4?tV^ Io]+mNcE_|Stw?K0YSC.+'Hbm.WdG6YwbUNKhd~gK-/;MDnxD#DdbW -bx^GoKxw?4+ssr#@#@&~P,q0,9$P@!@*,JEPP4x~@#@&7W(Lor lV AMkO+^r +~rbxVKoKU-UtnV^Px~rP[,9A@#@&2 [~q6@#@&Bx'xx{'x'{x'{'xx{''of@#@&9Z,x,d4?4+V^R"no"+CNvJuF;j-UG0DhlMnwHbmMWdWWO'rx9GhkPHP'ZE..xO..kkG -qkx9WSd-^WCNr#@#@&,PP&WPGZP@!@*~JrP:tnx~@#@&dG4Nok ls SDkOn^kU+,EqkU9WS/-dWm[P{PEPLP9/@#@&2 [P&0@#@&vx'{'{'x'xx{'x'{x'{sf@#@&ff~x,dtU4VscIoIl9cJ_|/j'?GWDhlMn-tkmMGdW6Y'rx[GS/~1:wZ!D.n Y.n.kkGx' bx[Khk-D!xrb@#@&P~P&0~9GP@!@*~JrPK4nUP@#@&iW8Lor lsRS.kD+sr +PE bx[WSd'D; P{PJ,[,9f@#@&3x9P(W@#@&B{x'{''{xx'{'{'x'xT+@#@&fA~',d4Ut+sscIno"nmNcrCnZj'?KWYSl.+'nGsbmkd-tkmMGdW6Y'qUYn+OPAaw^W.nM-IndDDrmDrKxdr#@#@&P,P&WPG2~@!@*PEE,KtUP@#@&dK8%sbxmV h.rD+sk nPrq3w"+/O.bmOkKUkPx,J,[PG2@#@&2 N~q6@#@&v{''{x'{''{xx'{'{'TG@#@&Gs~', /4?4n^VR]nTInl9crCF;j'?W6YSCD-\k1DGdK0Y' k NWSdwZ!DM+UY#nM/rW wnKVr^b+/wjH/O+sE*@#@&,P,q0,fw~@!@*PEJ,K4n P@#@&7W(LsbUCVchMkO+sr +~JhGVbmrnk-?zdD+hP{~rP',fw@#@&Ax9~q6@#@&B{'xx{''{x'{''{xx'{!y!@#@&9!,'~k4?4+sscI+L]l[`runS\'?}sKqb"3-tk^DK/GWD-bUNKh/,HP-;EMDnxO#DdkKU-qkU[Kh/w)aw(xbO|fJd/r#@#@&q6~fVP@!@*,JE~:t~@#@&dW(%ok l^RADrOVrx~Jzw2( kYm9dSdP{~rP',fV@#@&Ax9~q6@#@&B{'xx{''{x'{''{xx'{!y!@#@&9u,'~k4?4+sscI+L]l[`runS\'?}sKqb"3-tk^DK/GWD-bUNKh/,HP-;EMDnxO#DdkKU-qkUsKoWUwgWOk6zr#@#@&q6Pf_P@!@*PrJ~K4+U~@#@&dK8Lwkxms hMkD+skUn,JHWDr0HPx~rP[~9_@#@&2 [,qW@#@&K4Lwk CVch.kD+Jr +PrE@#@&B'{xx'{'{'x'xx{'x'{x',CFJtPIiH,2pn}]:@#@&iW(LsbxmsRSDrYSrUPJ{x'{'',uFSt-?-]EU~n+z/,x'{'xxr@#@&7G(Lok C^RAMkD+Sbx~Jr@#@&d@#@&G8Nsk CVcDbOnSbxPECFJt-jrwPzI3wtkm.GkWWY' bx[Khk-Z!DMnxD.nDkkGU'IE E@#@&W4NorxmVc.kOndkU+,EJ@#@&jnDPd4ktnV^~{P kmMkwDR;.+mYnr(Ln^D`JqdmMkwD jtV^Jb@#@&~@#@&j+D~W"+LxV+Y68N+^YvESkUsosY/= bhwDdW lOrKxS-+^'ks2nDkW lO+NZ'-EPL~{,@#@&~,PPdOMZG:a;D+.,[,J-MWKO-9+Wl!VOlUYN"nohDW7Eb@#@&P@#@&dY.FXKlD4P{PEj}sK )"2wHb^MWdK0D-bx9Ghk-/EMDnUD.+MdkKx-";UJ@#@&,@#@&W]nTR3x!h.mV;nkPCFJt~~/D.n+zhlDt~,lM..mV;+glhnk@#@&,@#@&wWD,3Cm4P7lsEnUm:nP&UPmD.#mVEnHm:n/@#@&&0~7l^E+ lsnP@!@*~JrPP4x@#@&3DMRZ^nCD@#@&zZ~'~ ktjtsVcInL"+l[crCFStwUro:zI2'Hb^DK/G0D- r NWSd-;EDMnUYj+M/rWUw"EU-r~[,\Cs!+xCh#@#@&@#@&,P~,W(LsbxmsRqDrYSrUPJ]EPLP\ms;+ ls+~[~EYJ~[,EP{PE~LPb/@#@&P~PU9Pr6@#@&PP,P,~P,1n6D@#@&G(LsbUl^RhMrO+dk +~JE@#@&Bx'{x'{'xx{''xx{'x'{x,CF;j,IjgPApn}IP@#@&@#@&G(LsbUl^RMrO+dk +~Jxx{'x',u|;jw='IEU~n+z/,x{'x{'r@#@&K4Nok lsRqDrOSk nPrJ@#@&jnY,W"+L x!Y64NnmD`EAbx:LhD/l bha+.kW lYbW J+7+s'b:2nM/W CY8"'wEPLP|P@#@&~~,PdYM/Wsw;ODP'~r-.WKO'Nn6l!VY=?D[IoKDK\Eb@#@&P,@#@&KI+T+ 2 Es.CV;nkPu|;i~,/O.n+XKCDtSPm.M.C^E1ls+kq@#@&P@#@&wW.~Alm4~\mVEUC:F,qUPC.M.CV!n1m:nd8@#@&(W,\CV!n lhF,@!@*,Jr~K4+U@#@&2..cZVCD@#@&bG~xPq/4?4+sscIno"nl9`EunZjwj}sPz]A-\bmMW/K0Dwbx[WS/w/!DDUYj+DkrGx'I!xwJ~',\CV!nxm:nq*@#@&@#@&,P~PK8Nsr l^RMkDnSbxnPr$E~LP\msExlsnqPLPrTEP'~rPxPr~[,b9@#@&PP~n N~k6@#@&P~,P,PP,1aY@#@&v'{'xx{''{x'{''{xx'{'{'91j~&1or,#?cPq ZR%~ctr9qw(Af~j?,RP8R8 &*@#@&@#@&W8%wkxmsRSDkDnJk +,JE@#@&7K4%sbUl^RA.bY+Jr +~J{x{'x{PG1?,q WW,`JkkY~hmXP(nP:wDzbP{'{'x'E@#@&W8LwrxmV AMkYnJbxnPrE@#@&@#@&?YPmILP{P!+Dr8%mYvEhbx:ThO/= b:2+.dKxCYbGxd+-n^'kh2DdW CD+Ne-'JPLP|~@#@&P~P,/O.;W:a;YDPL~E-MWKYwNnWmEsY=jY9InLhDW-E*@#@&@#@&dDDFXhlY4&,xPr?z/D+hw;EDMnxDZW O.W^?Yw?n.7k^+kwK1wr2'nl.Cs+O+Md'qUD+M0l1+kE@#@&@#@&l"+L AxEsF+HPCnJ\~,/DDF+zKmY4&B~lMDj;(3+zd8@#@&P,~iPWKD,+l1t,dE(3nX8PrU,lDMjE(3+Hdq@#@&@#@&b3Px~q/4?4nV^R]nTI+C[vJu|d\'?zkY:-;EM.+ Y/W Y.G^?+Dw?D\b^n/'K1wrwwKmDC:O+M/w( Y+.Wmmn/r~LPE'J,[PkE(V+HF~[,JwE*@#@&@#@&2MDR;snlM@#@&boPx~q/4?4nV^R]nTI+C[vJu|d\'?zkY:-;EM.+ Y/W Y.G^?+Dw?D\b^n/'K1wrwwKmDC:O+M/w( Y+.Wmmn/r~LPE'J,[PUj~F2IF~[,JwE,[PrHls+?.-+MJ*@#@&P~~&0~bw~@!@*PEE,KtnU,@#@&W(%wkUmVchDbYJk +~J_|3e|Sr;)S|Hb;u(1AJ,[~JwE,[~J;/?'UwE,[Pji~|358~LPE'J,[PrP,Hls+j+M\n.{PJ,'Pzs@#@&nUN,k6@#@&1naD@#@&W(%sbxCschDrOSrx~rJ@#@&B{''{'{x'{'x',ZGUDDW^j+D!!8@#@&@#@&?Y~4]nTPxPVnY}4%n1Y`EAbxhosOk)`b:a+DkW CYbWUS\ns{k:anDkWxmOn8e-'J~[~m,@#@&P,~PkY./K:w;OD~[,E'DGKY'N+6l!sY=?ON"+LKMW\rb@#@&@#@&kO.|XhlOt*~{PE?HdY:w/KxY.G^?nYZT8-jD7km/'Pmak2-hl.Cs+Y./'qxDn.0mm/E@#@&@#@&4]+T 2 EhFXPuFdHSPkOM|nHnmYtW~,CDM?;40+zdy@#@&,~PiP0K.~+mm4PdE8VX+PbUPmD.d!43nzk @#@&@#@&zM~{Pq/tUtsVcIno"+C[vJCnJH'?XkOn:'ZKxODGsU+O!Zq-U+.-bm+dw:m2kawhl.m:Y+M/'(xD+.0mmndrP[,E-rP[,d;40+H ~[~E'Jb@#@&@#@&AD. ;V+C.@#@&)C,x,d4?4+V^R"no"+CNvJuFdH-Uz/D+:'/GxDDKVj+OTZFw?.\bmnd'Km2ra-KlMCs+ODk-q Y.0mmn/rP'~r-J,'PUjAn3e ,[,JwJ~',JHlsn?D-nMJ#@#@&,P~q6~zC~@!@*,JJ,K4nx,@#@&@#@&dG8Nsk CVchDbOnSbxPECF3I{Jr;)S|H)/_q13E,[~J'E,[~rZU!!8-?wJ,[~?`AF3I PL~J'JPL~EP,1m:n?n.7+.',EPLP)u,[P-81Ds0@#@&Ax[,k6@#@&g+XO@#@&Bx'{'xx{''{/W YDKsj+D!Z @#@&@#@&U+OP1]+TPx~V+Y68N+^YvESkUsosY/= bhwDdW lOrKxS-+^'ks2nDkW lO+NZ'-EPL~{,@#@&~,PPdOMZG:a;D+.,[,J-MWKO-9+Wl!VOlUYN"nohDW7Eb@#@&@#@&/ODFnHnCY4XP{PEjH/Ynh'ZGxD.KVjYZ! '?.\bmn/'K^2bw-hCDm:+Dn./'q YnDWC1+dJ@#@&@#@&m]nTR2U;s|nX,unS\BPkYDn+HKlDtX~,l..UE40nXk&@#@&~~PiP6W.PnC1t~/!83Xf~bxPC.M/;40nH/f@#@&@#@&bxP{~ktjtVs "+o"nl9`J_FJH'?H/O+hw;WUYMGVU+OTZ -jnM\rmd'K^aka-nmDmh+D+./'qUOD0m^+kJPL~E-rPLPdE8VXfPL~J'Jb@#@&@#@&3.MR/VCM@#@&z|,'Pq/4jtVsR"+L]lNvECnSH'jz/D+s-/WUOMWs?O!Z wjD\r^/wK12bwwhlMl:Y./'qUYDWC1+/r~[,J-r~'PUj~|35f~LPE-r~[,JHCs+?n.7+.J*@#@&P~,q6PbnP@!@*PrJ~K4+U~@#@&@#@&7W(LsbUCVchMkO+Jr +~J_F2I{J6;bSm\zZuqg3rP',J'JPLPr/?Z!+-?-E~LP?`$|A5&,'~J'J,[~J~~glh+UnD7+.x,JP'~z|~[,-(m.^0@#@&2 N,r0@#@&H+XY@#@&E''{x'{''{xx'{'{'x'x/KxODKs?YTT2@#@&@#@&U+OP9]o~{PV+Y}4NnmD`EhbxhLsY/=`ksw+MdGxmYbWUSn-Vxks2+M/GUmY+NZ'-EPL~|P@#@&P,PPkYM/Wsw;YD~',J-MGWD-NWCE^Y=?ON]nTn.W7E#@#@&@#@&kYDFnHnCY4,'~r?H/Y:'/W Y.W^?nOZ!&'j+M\k1nd-:mak2-KCMlh+DnDk-(UD+DWC1+dJ@#@&@#@&["+TR2 EsF+HPu|dHS~kYDnnXhlY4SPmDM?;4VnH/*@#@&~P,d~WKDPnC1t~/!80+zWPbxPmDMdE(3nXkc@#@&@#@&bd~',/4j4+^VcIno]nmNcJ_FSt-jzkY+hw;WUYMG^?nD!Z&-U+M-k1+d-:m2ra-nm.ls+Y.d-&xD+.0C^/EPL~J'J~',/E8VX*PL~r-E*@#@&@#@&ADM Z^+CD@#@&)\,'PqdtUt+^s Io"+CNcE_|JH'jXkYnh'ZWUOMWs?OZ!f'?D\bmd-:m2ka-KCMl:O+M/-&UO+M0mmn/E~LPE-r~[,?i$n25*~LPE-r~LPEgls+?D7nDr#@#@&,P~(6Pbt~@!@*PJr~Ptx,@#@&@#@&7K4%sbUl^RA.bY+Jr +~J_FA5mdr;bS|Hz/C&13J,[~E'JPL~J;?!ZfwU'J,[~?i$n2ec,'Pr-E~LPJ~~glh+UnM\nM',JPLPz\PLP-41DsW@#@&2 [Pb0@#@&Hn6D@#@&Bx'xx{'x'{x'{'xx{''xx{'x'{x{'x{'{'',b9[kDkGxmV~9g?PbU0KP.k~qR8R8&x@#@&9b:~f&SPKInL+~PdOM|nXhCDt1BPmDDjl^;+glh+kvS~7lV!nxm:++@#@&@#@&?Y~W]nTvxMOr(Ln^D`JAr :L:Dd= rswD/KxmOkKxJ+7+sxb:w./KxlDnN"'-rP'Pm~@#@&~P,~/DD/GswEOnMP'PrwMWGD-9+0mE^O)UY[IoK.K\J*@#@&kYDnnznmY4,~'~EU5jKA\-;E..xY/G Y.W^jYwU+M\k1+kwK1wrw'nC.m:+DnDkJ@#@&@#@&W"+TR3x;hjlsEdP_|J\BP/O.n+znmO4,S,lMD.mV!n1m:n/+@#@&~@#@&sK.PAlm4~-l^ExC:n,qUPm.Djls;1lhnkv@#@&&W,\C^Exls++~@!@*PEJ,K4n @#@&G(P{Pk4jtV^R]+L]l[`ru|dHwjI?K3\'Z;DMn Y/KxDDW^?O-U+.\bmnd'Kmarw'nlMCh+D+M/wJ~',\CV!nxm:n*@#@&(W,f(P@!@*,JE,K4+x,@#@&7W(Lok ls SDkDnSbx+,-CV!+ lh+~LPEP{~J,[~9&@#@&3U9P(0@#@&Ax[,q6@#@&g+XO@#@&Bx'{'xx{''{x'{''{xx'{'{'x'xx{'x'{x'@#@&7G(LsrUmV hMrD+JbxPJr@#@&7W(Lok ls SDkDnSbx+,Ex'{'{'~sGs9+./,Cx9Por^+/~WMWhPrEu-ErPmxN,JrY-qkUNKhdErPZMnlD+N,JC/DP+!~fCzkPx'{x'{J@#@&iW4%obxCVcAMkOSbx+,Jr@#@&E'x'{'xx{''{x'{''{xx'{'{'x'xx{'x'{xb,s6JG2Ij@#@&?4WSj!4WKV9+DkPK8Lw?6RV+OoKVN.`r-J*@#@&?!4,?4WAj!4oW^[+M/coKVNn.*@#@&P,~,sGMPAlm4PU;46WsND~r PsKsNDRU;8sKV9+./@#@&,P~P&WPUj$o}Sf3]cfCY/M+CD+9P@*,ND\W Y4bTW~P4+x@#@&P,PPiG8Lwk lsR .bYnPk;46Ws[DR9CD+/DCD+[,[,JP,P,E@#@&P~P,dG8Nsk CVcDbOnPkE(0GV[nMRdk.nPLPE~,PPE@#@&P~P,~,P~K4Nsk l^ PSDrYVrUP?!80KVN. nmY4@#@&P~~,P~P,jtKhj;(sWs[DdPU;(0G^ND@#@&P,~P,P~PAx[~&s@#@&~P,P1aO@#@&2 N~?;8@#@&v'{x'{'xx{''xx{'x'{x{'x{'{''{'{x'{b~s&S3j@#@&?OPK4LwGsND8PxPG8Nsjrc!+DsGs9+DcE'Jb@#@&jY~1W^FP{PK8LwWsNDq wkVd@#@&sWM~3l1t,W8Lor^+~k ~mKVq@#@&dqW~K4%sbsR9mYZDlDnN,@*~NDHGUDtbTGP:t+ @#@&@#@&dK4%srUmV MrYPG8NsksncfCY/M+CD+9P[,J,~P,J@#@&iW8%wkxmsRqDkDn~W(Lwks+ dbynPL~J,P~~r@#@&7G(Lok C^R MkD+PK4Nok^+ lDY.r(EYdPLPJ,~~Pr@#@&dG4%obxCVc DbYnJbx+~G(Lok^n@#@&3 N,k0@#@& n6D@#@&B{'xx{''{x'{''{xx'{'{'x'xx{'x'{x'{'$~wrS93"?@#@&U4Khj!46WV9+MdPK4%sUr !YsKsND`rw k NKhdJb@#@&?;4,jtKhj;(sWs[Dd`wG^NnM#@#@&P,P,oWMP3l1t~j!40KsNDPbU~sKV9+.Rj;(sGV9nDk@#@&~,PP(W,?iAw6df3"RGlYZMnlD+[P@*P[OtWxD4bTWP:4nx@#@&,P~P7G(Lok CVc.rD+Pd;(0GV9nMR9mYZDlDnN,[~J,P~~r@#@&,~P,dW(%ok l^R DrOPdE(WW^Nn.c/k"n,[~J,~,PE@#@&,PP,P,~PK4%sbxCscPhMrYVk n~?!46WsNn.cnCY4@#@&,P~~,PP~j4WA?!8wWs9+M/PUE(WW^NnD@#@&~~,PP,~PAxN,(o@#@&P,P~1naD@#@&2 [PUE8@#@&B'xx{'x'{x{'x{'{''{'{x'{'x'{'xx{''{xA,sqd3j@#@&?Y~W8%wWsN. ,'~G(Lsj6cMnYwG^NnM`r-bx9GhkJb@#@&?nO,mW^+P{PW(%oW^ND+Ror^+d@#@&oWMP3C1tPG8NsrV~bx~1W^ @#@&d&WPK4%sbVn GlY/DlY[~@*,NDHGxO4zoGP:4+ @#@&@#@&dW8%wkUl^ qDrD+,W4Nsbs+cfCYZ.nmY+9~[,JP,~~J@#@&iW8Lor lsRq.kD+~G(LsrsRdk.n,[~rP,PPr@#@&7W(Lok ls qDkDnPK4Lwrs+clDY.k8;D+dPL~J,P~~r@#@&7G(Lok C^R MkD+Sbx~W(Lok^+@#@&AxN,r0@#@&xaO@#@&B{'x'xx{'x'{x'{'xx{''xx{'x'{x{'x{'{'Z,s}JfAIj@#@&?4GS?E(WW^N+Md~W(Lw?6R!nDsGV9nDvJw bxNGAk-jXkO:fyJ*@#@&UE(~?4WA?!4oG^N+Md`wWV9n.#@#@&,P~PoGMP3l14PUE8WKVNn.,kUPwG^NnMRUE4wW^[+M/@#@&,P~~&0PUiAwrSG3]RGlD+/DnCD+[P@*~NDHGUDtbLG,K4+ @#@&P~,PiW4NsbUl^R DbYn~kE46GV9+Dc9CYZM+CYn[,[~J,~P,J@#@&,PP~7K4%sbUmV qDbY+,/!80KV[+MRdr.+PL~J,PP,E@#@&,P,P~P~~K4%sbUl^R~AMkYnsbxnPU;(0G^NDRhlD4@#@&P~P,P~~,?tKA?!4sKs[+M/,?;4WG^NnD@#@&P,P~~,PP3U9P(s@#@&,P~,16Y@#@&AUN,?;4@#@&vx{''{x'{''{xx'{'{'x'xx{'x'{x'{'xx{'Z~o&S3?@#@&U+O,W(LsKV9nD2PxPK4%oUrRVnYwWV9n.`r-qkUNGAk-jXkO+s&+E*@#@&jnDP^W^f,'~K4NsW^N.&csrV/@#@&wWD,3l1tPK8%sbVPrx~^KVf@#@&7q6PG8NsksncfCY/M+CD+9P@*,ND\W Y4bTW~P4+x@#@&@#@&dW(%ok l^R DrOPG4Nok^+ 9mY+/.lO+9~LPE,P,PJ@#@&iG4NsrxmV  MkY~W(LsbsnRkk.+~[~E,P~Pr@#@&iW8%wkxCsc.kDn,W8NsbV+clDODb4;Y/~',JP,~Pr@#@&iG8Lwk lsR .bYnSbU+,W8%wkVn@#@&2UN,(6@#@& +XY@#@&B{x'{'x'{'xx{''{x'{''{xx'{'{'x'xx{'x'{x'{f~o&S2j@#@&W8Lwr lscMkYSbU+rJ@#@&K4%obxl^ MkYJrxPr'x'xx{PEJ')NskUrkYDCOKD~[,)^V~`/D/'?DCDDE2JrPJCkYP+TPGlXkxx'{'{J@#@&G8NsrxmsRqDrOSkUnrJ@#@&@#@&U+O,W(LsKV9nDWPxPK4%oUrRVnYwWV9n.`r-GW^Ehn YdPmUN,?nODkxLd'b[:bUb/OMlDWD'?DCDDP\+ EwKMWoMC:k-?DC.Y!wr#@#@&jnDP^W^*P{PG8NsWs[D*Rwr^+d@#@&wWD,2m^t,W8Lwksn,kx,^W^c@#@&7(0,W(LoksncfCY/DlOn9P@*~[DHGxD4zoG,K4+x@#@&@#@&dK4%sbxCscDbO+,W4NorVRGlO+/.lO+9~[,J~~,PJ@#@&iW8Lwr lscMkYPK8Lwks+c/r"P[,EP,PPr@#@&dK4NsrxCsc.kDnPK4%obV+ CDY.k(;D+d,[,JP,P,E@#@&dG4NsrUmVRq.kD+SbUnPK4NsrVn@#@&2UN,r0@#@&HnXY@#@&v{'x'{x{'x{'{''{'{x'{'x'{'xx{''{x'{''{xx'APwqJ2j@#@&W8LwrxmV  MkYnJbxnJr@#@&@#@&U+DPW(LwGV9+.*,'~G(LsU6RV+YwGsNDvJwfG^!:nxDdPmx[~U+YOr od-zs^Pik+M/-UYm.Y,Hnx!-K.KoDmh/'?Ym.OEaJ*@#@&?nO,mGVl~',W8%wWV[nM* sbs/@#@&sKDPAl14PK4%sbVn~bxP1GVl@#@&i(WPK4NsrVn GlO+;.+mYn[,@*P[OtWUY4)TW~:tx@#@&@#@&7W(Lok ls qDkDnPK4Lwrs+cfmYnZ.nmYnN,'PrP~~,J@#@&7K4%sbUmV qDbY+,W(%sbVnRkk"n,[Pr~P,PJ@#@&7W(LwkUls qDrY~W(Lor^+RCODDr4!O/~LPrPP,Pr@#@&iW8LwkUC^RMrYSk n~W(Lwks+@#@&Ax[PbWd@#@&UnXY@#@&v{'x'{x{'x{'{''{'{x'{'x'{'xx{''{x'{''{xx'wPwrJf3]U@#@&W(%sbxCscDrOSrxEr@#@&K4Nsk l^ MkO+dkUn,J'{x'{'PrEwnMWTDC:~obVn/rEPdldO,v!~9mXd'{x{'xr@#@&W4NsbUl^R DbYnJbx+rE@#@&@#@&UnOPK4NsGV[nMFTP{~W(Loj}RMnOwWsN.vJwhDKoDm:,ok^+dJ*@#@&jYP1GV8!P{~G4NsKV[+.qZRok^n/@#@&oGMP2C^4PG4NobVn,k PmKV8T@#@&d(0,W8%wkV fmY+;.nlD+9P@*P[OtWUY4)oKPP4x@#@&@#@&dG4NobxC^RqDkD+,G4NsrVR9CD+ZMnlD+N,'~J,P,PE@#@&7K4%sbUl^R .bY+~G(Lok^nc/r.+,[PrP,~Pr@#@&dK4%obxl^ MkY~G4NsbVnRCODDr4!O+kP'~rPP~~r@#@&dK8Nsr l^RMkDnSbxnPK4%obV+@#@&2 NPbW7@#@&x6O@#@&@#@&?nY,G4NsGs9+Dqq,'~W(%w?6cMYsKV9nDvJwnMWL.m:PwrV/J*@#@&?Y,mGVqq,'~W(%sKV[nMFF j!4WW^[Dd@#@&,PP,sK.PAl^t,?;86WV9nD,kx,^GV8F@#@&~P~~&0~?`$s}S93"RfCOZ.+mON~@*P9YHKxD4bTW~K4+U@#@&PP,~dK4LwrUl^RqDrYn~kE80KsND 9mY+/.lO+9~LPE,P,PJ@#@&,~P,dG4NsrUmVRq.kD+Pk;80KV9+.Rdr.+~[,EP,P~E@#@&P~~,P~P,G(LobxmVR,hMrYVrxPj;(0W^[+MRnmO4@#@&P,P~P~~,2UN,(s@#@&~~,P1naD@#@&@#@&v{'x{'{''{'{x'{'x'{'xx{''{x'{''{xx'{'{'xM~o&S3?,9Db\n.kPHG[b0r+9~j/~8R8R @#@&K8LwkUl^R .bY+drxJJ@#@&G4NsbxCV  MkO+drxPEx{''xxrJ9Db-DdrJ,HW9k6r+9PJlkY~ZPfmz/{''{xxJ@#@&K4%srUmV MrYSrUJJ@#@&@#@&j+D~K4%wW^N+MG,xPK4%sUr !YsKsND`rw k NKhd-jzkYn:2+-9Dr-D/Eb@#@&j+D~1WsFP{PW(LwGV9+.Gcsrs/@#@&oWMP2m^4PK4NsrVn~bx~mKsG@#@&7(6PW8%wks+c9mYndlkYHKNbWkN~@*,NO\KxY4)oKPK4nU@#@&@#@&dG4%obxCVc DbYn~K4Lor^+ fmOZ.lD+N,[,EP,P~J@#@&7G(LsbUl^RMrO+,W(Loksnc/ry~[,J~~,PJ@#@&iW8Lwr lscMkYPK8Lwks+clOOMk4!O+kP[,E~P,Pr@#@&dG8NsrxmsRqDrOSkUn,W8Lwr^+@#@&2 NP&0@#@&x6O@#@&Bxx{''{x'{''{xx'{'{'x'xx{'x'{x'{'xx{''xx_Poqd3U@#@&K4Nsk l^ MkO+dkUnrJ@#@&G4Nsk CsRqDbYnSrUPE'{x'{'~obV+d~G+s+Dn9P; NDPrJuP+swYJrPxx{''{E@#@&W4NorxmVc.kOndkU+rE@#@&/O.Ax\~x,JwjknM/wrPLP4n+H~[,Jwbaw9CDl-dGmmV-:nhwr@#@&/OD3U7PxPqdtktns^R2a2mx[2 -bDG :xYUYMrxT/cJuYnha]J*@#@&bxY1G;xDP{PT@#@&@#@&?nY,G4N0Gs9+D0~{PG4NoUr V+DsW^N.`kY.2 \b@#@&?+D~mKV%,x~W(LwWsNn.RRok^n/@#@&oGMP+C^4PG4NobVn,k PmKVR@#@&}x~2MDG.,I+k;:P1aO@#@&P,P~W8%wks+c[+^+On,@#@&~~,PrxD/KEUDP{Pk Y;GE Y~_8@#@&H6Y@#@&W(LsbUCVcMkO+Jr +~k OZKEUO,[PE~wks+k~9+sYNJ@#@&@#@&B{'x'{'xx{''{x'{''{xx'{'{'x'xx{'x'{x'{'xxVPs6JG2]?@#@&K4%wk lVcMrYSrxJE@#@&W4Nok lVc .kD+dkU+~E{'x'{xJrbss,j/n.k-)wasbmCDkKxPGlDCJrPJlkY~ZPfmz/{''{xxJ@#@&K4%srUmV MrYSrUJJ@#@&@#@&@#@&U4Khj!46WV9+MdPK4%sUr !YsKsND`rw9W1Es+UYd~mx[PUnYDkULk-bss,jd+Md'b2aVbmlDkKUPGlOlr#@#@&UE4,jtKh?!8oW^NDd`oG^NnD*@#@&,P~~wWD~3mm4PU;(0G^NDPbx,oW^NnDc?;8wWV9nDk@#@&,~~P&0,?iAo6df3Ic9lD+/.lYn[,@*~ND\KxO4bTWP:tU@#@&P~P,dG8Nsk CVcDbOnPkE(0GV[nMR9lDnZM+CONP'~rP~P,E@#@&~,P,dW(LwrxmV MkOn,/E(WW^N+M dk.+,[~J~~,PE@#@&~P,P~~,PW8%wkUl^ ,h.bYVk +,jE(0GV9+. hlY4@#@&,PP,~~P,?4WA?;8wWsN./,?;86WV[nM@#@&P,~,P~,PAxN,qw@#@&,P~Pg+aO@#@&2 [PUE4@#@&v'{'{'x'xx{'x'{x'{'xx{''xx{'x'{x{'x{'{''{M,oqd2j@#@&?nO,W4NoW^N+M1~',W(Lo?6 V+OsKsNDcE'fW^;s+UYk~mx[,?YYbxTd-zVsP`/n.k-ba2VbmlDrGx,fmYCJb@#@&?nY,^W^,~x,W4%oKV[+M1csr^+k@#@&wWM~2mm4PK4%obV+,rx,mW^1@#@&iq6PG4%obVnRGCYZ.nmY+[~@*P[YtG Y4zoKPK4+ @#@&@#@&7W(Lor lVc DbY+,G8Lwk^+ fCOZ.+mO+9P'~rPP~~r@#@&dK8Nsr l^RMkDnPK4%sbVn kky~[,JP,~~J@#@&iW8Lor lsRq.kD+~G(LsrsRCYD.b4;D+kP[,J,~P,J@#@&iW8%wkxmsRqDkDnJk +,W8Lor^+@#@&AUN,qW@#@&1+aO@#@&v'{x{'x{'{''{'{x'{'x'{'xx{''{x'{''{xx'{'{'x'x~Z qBk~\kPq 8R @#@&iW8Lwr lscMkYVbU+,JE@#@&dG8Nsk CVcDbOnVbxPE'xx{'xP_FSt-=wUt+ssU+.\b^r8N+1YfVmzSKl['{'xx{J@#@&7W(LsbUCVcMkO+sr +~Jr@#@&i@#@&jYPG]o*'VnDr8N+1Y`rhbU:T:O/= rha+DkGxmYkKUJ+7+^'r:2nM/GxmO+)"wwrP[~m,@#@&P,~,/OMZK:w!Y.PLPE-MWGO'N+6CE^Y)UO[IohDG\Eb@#@&~@#@&dYM|nzhlY4{,'~JUG6YAmD-HbmMG/K0O-qkU[Kh/'/EMD+ O#+M/bWU-j4Vs?.\bmn6(L+^OG+slHJKl[r@#@&@#@&KILcc2UEs.Cs!+/,u|dH~,dODn+HnCY4{BPCDM#l^EnHm:+d*@#@&~@#@&oKD~Al1tP7l^;+ lh+WP(U,lDM#l^E+gCh+kc@#@&(0~-mV;+ C:c~@!@*PJE~:tnx@#@&AD.cZ^+lM@#@&$b,'~ktj4VVc]+TI+m[cJ_|dHw?GWDhCDwHbm.GkW0OwqkUNKAk-/!DM+xD../bWU-Utns^?+M-k1+r(%nmDfVCXJGmNwJ,'P7ls;xlhnW#@#@&&W,A),',JJ,K_31,@#@&AzPx~r`1}~1zH2*E@#@&Ax9P(s@#@&@#@&$A,xPq/4j4+Vs "+LIC9`E_|dH-UrwPzI3-;VCdk+/'/SUqfr~'Pr-rP'P$),[~J'EPLPE( wDG^U+.\.2 E,[,J-r#@#@&P@#@&7W(Lor lVc DbY+drU+,\mV;+UCs+*PL~J,O~E,[P$),[~J,R,J~LP~APLP78mMVW@#@&@#@&3 NP&W@#@&1+XO@#@&E'{'x'xx{'x'{x'{'xx{''xx{'x'{x{'x{'{''{',T yP#?,F qc @#@&7W(LsbUCVcMkO+sr +~Jr@#@&iW8%wkxCsc.kDn^kUPr''{'{xP_|JH'Uwj4lD[Km/3U^4+9E^+.'xx{'xJ@#@&dK4%obxls qDrYsbxn,Jr@#@&i@#@&j+DPGIoXxV+Y}8LmYvEAk :T:O/l`b:2+MdW lOrKxSn-Vxks2DdKxmY+)"'wJ,[~{,@#@&~,PPkOD;W:a;O+MPLPE-.GKYwNWl!VOlUYN]nTn.W7E*@#@&,@#@&/YM|znmY4%,'~EUW0DAlM+-tr^DK/K0O- r NGhkwZ!D.n Y.n.kkGx'3XwsKDD-Utm.+9KC/0?^4NE^nDr@#@&@#@&GIolR3x;hjlsEdP_|J\BP/O.n+znmO4%S,lMD.mV!n1m:n/l@#@&~@#@&sK.PAlm4~-l^ExC:nX,qUPm.Djls;1lhnk*@#@&&W,\C^Exls+l~@!@*PEJ,K4n @#@&A.DcZVC.@#@&ZzPxP d4?4+^sR"+L]lNcE_|JH'dK0OSlM+-tk1.WkWWY'rU9WhkwZ!DDUO.DkkGxw3XwsWMnD'?4CM+NPCk3jm4n9EsD'JPLP7CV!+Uls+Xb@#@&q6~ZzP',EEP:CA1~@#@&/zPxPrc1}PH)t2#E@#@&2UN,(w@#@&@#@&;AP{PqdtUtnV^R]nTI+m[`rC|d\w?}s:)I3w;VC/kn/'ZJj&fJ~',JwJ,',\C^Exls+l~[,JwJ,[~E&xwMGmU+D7n.&yJ,[~JwE*@#@&@#@&7W(Lor lV AMkO+^r +~;b,[PrP ~J,[~\mV;n l:XPLPJ,R~J,[,Z$P'~74^D^W@#@&2U[,k0@#@&g+aY@#@&E'x{'{''{'{x'{'x'{'xx{''{x'{''{xx'{'{'x'\j;rHs&!@#@&/O.n+XKCDt+P{~r?G6YSlD-srmMWdW6Ywd4lD[PDWW^dw:kmKxWkLwkYCDD;wM+LE@#@&@#@&jY~W"nT xV+Dr4N+1O`rhrxsohOk)-'EPLP/D./Wsw!YnD~',JwDKGY'NnWmEVOlUY[ILhDG7J*@#@&@#@&K]+T  2 EhFXP_FSt~PkO.|XhlOt+S,l.DU;4n+zdl@#@&@#@&iW8Lwr lschMkYVbU+vJx'{'xx_|StwU':/1GU0bo'/Ol.O!w.+Tx'{'xxr#@#@&7K4%sbUmV SDbY+^k nPrJ@#@&wW.~Alm4~/!4|zXP&x,l.Dj;(|nXkX@#@&@#@&3MDR/sl.@#@&)gPx,kt?4+^sR"+LIl[crC|d\-UW0DACD-sk^DGdK0O-k4lM+[~DWWsd':dmKU6kL'/DlDDEa.+TJ~[,JwE,[Pk;40+Xl~'Pr-r#@#@&@#@&zn~', /4?4n^VR]nTInl9crCFdH'?W6YSCD-hk1DGdK0Y'dtmD+9~OWKVk-h/^G 0ro'dYmDO;aD+LE,[~J'E,[~kE(3+H*,'Pr-EPLPE/K::mUNr#@#@&~~P,P,PG4%obxCVcADbYnsbx+~E_|JHr~LPE'J,[PkYMF+HnCY4 ~',J-r~[,/E(VnXl@#@&1n6O@#@&W8LwrxmV AMkYnsbxnPrE@#@&v{'{''{'{x'{'x'{'xx{''{x'{''{xx'{'{'x'xxU+.\b^+kP#d,FRT 2@#@&W(%wkUmVchDbYsk +cJ{'xx{'PUnD7kmd~`,?D-k^nkPOtmOPmDn~qtkOn^kdY[,l.P WY,/4Gh #~'{'xx{J#@#@&dK4LwrUl^RSDrYnsbxnPrE@#@&@#@&dDDsrs1C:~{PEk\1FR9lDE@#@&?nY,W8%w?r,xP;D+mOnr(LmO`Ej1DrwDrxTRor^+?zdD+hr(%mOr#@#@&?Y,6sbVnP{PG8Ns/K ra+x:naYwk^+c?O.wks+gC:~~+BPJP.!+E#@#@&kY.;WswED+M~',J J@#@&@#@&U+Y,G4NH&jnD7k1+~'~!Y64NnmD`EAbx:LhD/l-'E,[~kYMZWsw!O+MP'Pr-.GKY-;(Hj J*@#@&P,PU+OP^G^qO+sdP{PG8NH(jD-k1nc2am5E+MXvE?AS3Z:PM~wIrt~bx&ymjXkY:9Dr-DE#@#@&@#@&P~~wWD~3mm4PK8NqO:,qx,mKsqD+h/@#@&~~,PP,6sbV+c .kD+^kU+cJ;ld+vG4NqOnsR1Ch#b@#@&~,P~,@#@&1+XY@#@&@#@&?nY,W8%qHqUnD7km~xPV+Dr8Ln^D`EhbU:T:Od=--E~LPdYM/K:2!YDPLPrwDKWO-;q\#yJ#@#@&P,P?O~mKV&Yn:d~{PG4N H&?n.7kmn A6nm5;DzvJU2SAZ:~e,s]rtP r & |j+M\k1nE#@#@&@#@&~P~oKD~2m^t,W8%&Y+h~&x~mKs&Yns/@#@&P,P,~P}srVR .bY+^rx`S;Cd+vW(L(Ynhc1C:b#@#@&~~,PP@#@&g+aY@#@&@#@&6wk^+R;VKd+@#@&@#@&U+O~K4LwrVFP{~G4NsUr r2n Kn6Dok^+cEk\mA4DR[lDEBPoKD"+l9k L#@#@&dYMZ;.M+xDj\1/P{~G4NsbVnF ]l[b^s@#@&W8%wkVnqcZsWkn@#@&@#@&?YPK4Nok^++P{PG8Ns?} ra+x:naYwk^+cJd-1F NmOJBPoGMI+C[bxL#@#@&GW~`xDkV,W(%sbVn cbO3 Nr6jYM+ls@#@&P,P,/ODj-1PxPK8LwksnyRInC9Srx@#@&P~,P&0P&xUODv/OD;E..xYU-mk~PkO.?7m*PxPT~:tnx@#@&P,P~~,PPdOM1GY;;MDn Y,'PkYMHWDZ;DM+UO,[PkODU\m,'~\(ZMSW@#@&~,P~2 [P&0@#@&dWW2@#@&@#@&W(%wks cZVK/@#@&@#@&j+DPG8Nsk^n&,'PK8%sUrcZ.+COKn6Dok^+cEGk0W 9lOJ*@#@&W8NsbV+2Rq.kD+Jk +~dDD1KOZ!DDUO@#@&W(Loksn2R/VKd+@#@&@#@&U+Y~G(Lok^nWPx,W(LsUrc6wxP+XYor^+`r9k60R9COJBP8#@#@&7vkY.SbU+,'~G(Lsrsc IC9Sr +@#@&dGW,ixDksPK4%obV+W bD2x96W?DDlh@#@&dDDsk nP{PG8NsksnWR]+m[dkU@#@&@#@&U+D~mKVrY:dq,'PK8LqHqUn.\bmR36n^5EnDHcJU+sn1YPM~6DG:, bxfy{UX/D+s9Db\nD,h4nM+PgC:'Br~'PkYMVrxn~LPEBrb@#@&@#@&oKDP3C1t~W(%&YnsPbxP1W^rY:dF@#@&~~,PP,~P,PP,~64NsbxCV  MkO+^rx`G8NqYnhc1C:~LPE,`rP[,W(%qD+hRGkd2^lXgC:P[,EbO,J,[~W8%&Yn:cKlDtHCs+#~',J~O,E,[~K4NkY:cjYmDOHKNn~LPJJEPLPW(%(Y:c?OlOn@#@&7@#@&H+XY@#@&^WW27@#@&G4NWbVnWR1VWk+@#@&@#@&Bx'{'xx{''{x'{''{xx'{'{'x'xx{'x'{x'{'xx{j1(HUK)Sd~dqj:'{''{'{~HKNr0b+[~j/P8 Fc @#@&7G4NsbxCV AMkO+^rxPEE@#@&dG8Nsrxmsch.bYVk +,E'{'x'{PiUbx/DCV^PSbdOP{'{'x'E@#@&dG4Nok ls SDkOn^kU+,Er@#@&kYMs1m:~',Ji1&ROaDJ@#@&j+DPjwrs+,',W8LodKR6wUK6OobV+cjDDo1mh~~y~,JKMEE#@#@&j+DPG]o&,xPV+Y}8%+1YvJAkUhT:O/=w-rP'm@#@&/O.1Whw!OD~LJ'DWKY'[+6l;VD)jO9I+TKDK\J*@#@&@#@&/`xrxdOmVsnmOt,'~EUrsP zI3-tr1DGkW6Y-qk [WS/wZ!D.n Y../bWx'iUk /DlsVwE@#@&@#@&K]+T& 3 E:FnHPu|d\BPd`xbx/Dl^snmY4~,lj;(3+Hd@#@&@#@&wG.PAl1t~/j;(3nX,(x,lj;(3+zd@#@&~P,~KInT&cM+D?D.k o#l^En~_|StSPkjxbUdYmV^nCY4~L{~@#@&~P,P~~k?E8VXSPri kUkYmVVUYMrxTJSPkb22`xk dYmVV@#@&@#@&&0,/)w2i kU/DCV^P@!@*,JJ~P4+U@#@&i`Px,kt?4+^sR"+LIl[crC|d\-Urs: )IA-tk^DGdK0O-qrx9WAd'ZE..xO..kkG -`xk /DCV^-EPLPdj!4|zPLPJ'E~[,JGkdwsCH1C:E#@#@&v3 NP(W@#@&~P,iwksRqDkD+^rxPij@#@&3U9Pk6@#@&g+6D@#@&jwk^+ msGk+@#@&}8LwkUC^Rh.rD+sk n,J),0bV+,xmh+9Pvjgq OXYB,AlkPmMnCYN,lUN~dm\nN,OWr@#@&6(LsrUmV hMrD+sbxPJwk^nSb/O+M/~[0l!sY,VW1COkKxcPKWdO,Y4+,.+kEsOkPkW~M+5EdD+[cJ@#@&B{'{x'{'x'{'xx{''{x'{./,q !cc,IC:~r 0G@#@&9ksP^G^/+OObxL/B~K4%1WswED+M@#@&}4%sbxCschDbO+^kx~EJ@#@&}4%srUmV hMrYVrUPJxx{'x'{x,rO4+MPq 0K~'{'x'{'xE@#@&r(%sbxl^ ADbYVrxn~rJ@#@&@#@&?Y~^KV?nODkUok~{PG(LqHqU+M-k1+ 2X+^}!+DHcJU+V^OPCP6DG:~ bxf |/Wsw;OD?zdD+hJ*@#@&sGMPAlm4PK8L;Whw!Yn.,kx,^W^?+DOrxT/@#@&~P~~,r8LwrxmV AMkYnsbxnPrP}K)dPhC5Uq;)S,I)H=PE~LPIK;x9``K8%ZK:aEO+. :WOl^KtH/r^mVHnhKDzz8TZ!TZ!*~!*PL~J,H$J@#@&@#@&g+6D@#@&}4LwrUl^RqDrYnJbxnPrE@#@&Bxx{''xx{'x'{x{'x{'{'@#@&B,x'{'x'{'~8KWY,rx6WP7d~Fc!c,@#@&68NsrxmsRqDrOSkUn,J$WKO,qU6Wr@#@&}4Nok lsRqDrOSk nPrJ@#@&(WPvW(Lo?6 wks+AakkYdcr-4GGDRrxbE*#~:tx@#@&?OPDD~',W8%6/Wc6wxKaOsbV`E-8GKY k rJBPoGMI+C[bxLPBomVd#@#@&fKP!UYbV~YMR)OAxN}W?DD+mh@#@&"+T3nX+~{PODc]+mNCs^@#@&JGKw@#@&D.cmsK/@#@&@#@&}8LwkUl^R .bY+^rxPP"nL3Xy@#@&2U[,qW@#@&v'{'xx{''~6UP(x6G,.d,Fc!RO@#@&@#@&U+OP1Ws6U+/,xPK4Lq\(?D7k^+ 3X+^p!nDH`EjV+^O,e~0MGsP bx2 {}w.lDkUoUXdO:J*@#@&wWD,3Cm4PK4%rj~bx~mKsrU+d@#@&PP68Nsrxmsc.bYVk +,ErUPPXa+l~,JPL~W(LrU /laYbWUPvHm:n@#@&~P}4%obxls qDrYsbxn,J~Ek^N=~PrP'PK4%6UR../bWx,v#+M/bWUP'~(ErV9@#@&,P68NskUC^R DbOVr +,J?D7rmPKl13l~,JPL~W(LrU j+M\bmnnC^0HCLK..DdrKxP'~rREPL~|@#@&,P,W4NrU ?D-k1+KC13HbUWM.+MdrW @#@&r8Lor lsRq.kD+sr +PEE@#@&H+XO@#@&@#@&B{''{'{x'{'x'{'xx{''{#/,FRZ 0P_k9Nnx~WbVn/,c:KNrWb+N~-kPqR8 2#@#@&r(LsbxmsRSDrYVrUPJ{x'{'',orV/,hrY4~_k[NUPzYO.b4EOnk'x'{x{J@#@&@#@&@#@&E?OPq/4/4+ss,'PqdmMkwD /DlD+64%n1YcJqdmMk2Oc?tns^Jb@#@& ktj4+^VR"E cJuZ6HUn3/uPz1~21tW,ekPGq"Pwe 9dS~-C 2o2~wCR?ej,-MRG):PwCR;rH,-C qgs~-CR(H&PzU~zzCPJ$@*CbN9+UROaDJb@#@&@#@&K4%obxls qDrYsbxn,Jr@#@&}4Nok lsRSDrOVk nPrbP6rs+,xm:nN~v_k[NURD6Ov,hld~1DnlDn9PC N,/l7+9~YKJ@#@&}4%obxl^ hMkYsrxPrsrVnJb/O+MdP9+WC!VY~sKmCYbG R~hWkYPDt~D/;VD/~r6PD5E/Y[ J@#@&}4%srUmV hMrYVrUPJE@#@&r8Lwr lschMkYVbU+,Jx'Ax[~K0P"nwKDY{xE@#@&hkm.k2Oc/s+2PW!TT@#@&@#@&v{'x'{x{'x{'{''{'{x'{'x'hDGL//,8lMP.U~qR8R8@#@&W8%A62VK.+MR9G1E:nUDR$W9zcqU +MCKtS,xPrfGxR~),VWT~kkP4rUo,wMW[E^n9J@#@&@#@&W(L3aaVW.nMR9W1;s+UDR~WNHRUOX^+ Z!DdGMP',EN0l!sOJ@#@&@#@& /^.bwORUs+w~XZ!!@#@&@#@&G4N3XwsKDDR5EbO@#@&Bx'{'xx{''{x'{''{@#@&ktUtnVs "EUPrYhbx[rM]-UGD+2l9~rP',J'sk^+k YXYE@#@&@#@&v{''{x'{''{xx':2tn~s(JAP92d3KA@#@&G(L0dGcNnVO0r^+,J/7m8 NmYE@#@&W8%6/Wc[+^+YWrVPrfr0W 9lOJ@#@&BK4%WkWR[n^+O+6r^+~rCbNNxcO6DJ@#@&E'xx{''{x'{''{~/SAbgPin@#@&@#@&j+D~ktj4VV~x,xGY4r o@#@&?YPK4No?}PxP WO4bxo@#@&?YPK]no,',xGY4r o@#@&UnY,W]nTFPxWOtbUT@#@&U+DPW"+T+P{PUWDtrUT@#@&UnY,WILfP{P WOtrUT@#@&?OPK4%oKVNn.,'~xKO4kUT@#@&?+DPK8LwWsNDq~{PxKOtbxo@#@&j+DPK4%sGs9+. ,xP WO4bxo@#@&U+OPK8NsG^ND&,',UWDtrxT@#@&jYPK8LwWV9n.c,',xGY4r o@#@&UnY,W8%wWV[nM*~',UKY4bxT@#@&U+D~W(LoW^Nn.+P',UWDtk L@#@&U+DPG4%oKV[+M{P{PUGDtkUL@#@&j+D~K4%wW^N+M%,xP WOtbxL@#@&?+D~W(LsKs[+M,,'~xGO4kUo@#@&?Y~OkP'~UKY4k L@#@&jY,YY,',HWDtrxT@#@&jYPK8LqHqUn.\bmPxPUGDtrxT@#@&U+O~1WV(O:dP{~ WO4k o@#@&?OPK4%qD+h~{PxKOtbxowpgfAA==^#~@

10.4K Posts

August 31st, 2010 10:00

Actually no. You opened the contents of the FileLister program itself.

Do this Double Click ->> FileLister.vbe->> and it shuld run

August 31st, 2010 10:00

Think I have got it this time.  Notepad pages came up, files, Hidden and UNI Notepad. not sure which to post so I am posting all. I hope that is all right.

 


+++++++++++++++++++++++++++
+ File Lister  Version 1.1.4                       +
+                                                                  +
+ By bamajim / SpywareHammer.com +
+++++++++++++++++++++++++++

Report ran on --->>>  8/31/2010 12:11:21 PM

====== Running Processes ======

C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RAVCpl64.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files (x86)\Digital Line Detect\DLG.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files (x86)\Dell\MediaDirect\PCMService.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Windows\splwow64.exe
C:\Program Files (x86)\internet explorer\iexplore.exe
C:\Program Files (x86)\internet explorer\iexplore.exe
C:\Program Files (x86)\Windows Live\Toolbar\wltuser.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10i_ActiveX.exe
C:\Program Files (x86)\internet explorer\iexplore.exe
C:\Windows\System32\CScript.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe

====== BHO's ======
BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL

BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20100517215847.dll

BHO: (NO NAME) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

BHO: (NO NAME) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll

====== System Keys  (some whitelisted items will not be shown)======

Winlogon\Userinit = C:\Windows\system32\userinit.exe,
Winlogon\Shell = explorer.exe

====== HKLM\~\Run Keys ======

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

[Windows Defender] = %ProgramFiles%\Windows Defender\MSASCui.exe -hide
[RtHDVCpl] = RAVCpl64.exe
[Skytel] = Skytel.exe
[IgfxTray] = C:\Windows\system32\igfxtray.exe
[HotKeysCmds] = C:\Windows\system32\hkcmd.exe
[Persistence] = C:\Windows\system32\igfxpers.exe
[Dell DataSafe Online] = "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m

====== HKCU\~\Run Keys ======

[Sidebar] = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
[msnmsgr] = "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
[ehTray.exe] = C:\Windows\ehome\ehTray.exe
[Speech Recognition] = "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
[Google Update] = "C:\Users\Tammy\AppData\Local\Google\Update\GoogleUpdate.exe" /c

====== DNS Info (List may be empty) ======


ICSDomain = mshome.net
SyncDomainWithMembership = 1
NV Hostname = Tammy-PC
DataBasePath = %SystemRoot%\System32\drivers\etc
ForwardBroadcasts = 0
IPEnableRouter = 0
Hostname = Tammy-PC
UseDomainNameDevolution = 1
EnableICMPRedirect = 1
DeadGWDetectDefault = 1
DontAddDefaultGatewayDefault = 0
DisableUserTOSSetting = 0
EnableWsd = 1
QualifyingDestinationThreshold = 3
TcpWindowSize = 256960
DefaultTTL = 64
EnablePMTUBHDetect = 0
EnablePMTUDiscovery = 1
Tcp1323Opts = 1
SackOpts = 1
MaxDupAcks = 3
DhcpDomain = ZoomTown.com
DhcpNameServer = 192.168.200.1

====== Folders and Files from "%\" and "%\Windows" Created Last 60 Days ======

8/25/2010 11:31:10 AM    0    C:\iolo
8/25/2010 11:31:10 AM    0    C:\iolo\Installers
8/25/2010 10:55:26 AM    574    32    C:\cleanup.bat
8/25/2010 11:49:30 AM    159    32    C:\SetupLCVI.log
8/25/2010 10:55:26 AM    135168    32    C:\zip.exe
8/25/2010 9:48:27 AM    46080    C:\Windows\pss
8/25/2010 10:55:26 AM    112    32    C:\Windows\cldll.txt
8/25/2010 11:52:06 AM    75    7    C:\Windows\CT4CET.bin
8/25/2010 10:56:58 AM    26818    32    C:\Windows\PFRO.log
8/25/2010 12:25:24 PM    0    32    C:\Windows\setupact.log
8/25/2010 12:25:24 PM    0    32    C:\Windows\setuperr.log
8/25/2010 11:41:10 AM    23464    32    C:\Windows\System32\elrawdsk.sys
8/25/2010 11:49:21 AM    57656    0    C:\Windows\System32\FilterPC.bmp
8/25/2010 11:49:21 AM    24995    0    C:\Windows\System32\FilterPC.jpg
8/11/2010 5:18:01 PM    70656    32    C:\Windows\System32\ie4uinit.exe
8/11/2010 5:18:02 PM    459776    32    C:\Windows\System32\iedkcs32.dll
8/11/2010 5:18:04 PM    12473344    32    C:\Windows\System32\ieframe.dll
8/11/2010 5:18:02 PM    252416    32    C:\Windows\System32\iepeers.dll
8/11/2010 5:18:02 PM    72192    32    C:\Windows\System32\iernonce.dll
8/11/2010 5:18:04 PM    2335744    32    C:\Windows\System32\iertutil.dll
8/11/2010 5:18:01 PM    77312    32    C:\Windows\System32\iesetup.dll
8/11/2010 5:18:01 PM    132096    32    C:\Windows\System32\iesysprep.dll
8/11/2010 5:18:01 PM    219136    32    C:\Windows\System32\ieui.dll
8/11/2010 5:18:01 PM    162816    32    C:\Windows\System32\ieUnatt.exe
8/25/2010 11:41:09 AM    105312    32    C:\Windows\System32\IncContxMenu.dll
8/11/2010 5:18:01 PM    1538560    32    C:\Windows\System32\inetcpl.cpl
8/25/2010 11:41:07 AM    45056    32    C:\Windows\System32\iolobtdfg.exe
8/11/2010 5:18:01 PM    31744    32    C:\Windows\System32\jsproxy.dll
8/11/2010 5:18:02 PM    706048    32    C:\Windows\System32\msfeeds.dll
8/11/2010 5:18:02 PM    71680    32    C:\Windows\System32\msfeedsbs.dll
8/11/2010 5:18:00 PM    12288    32    C:\Windows\System32\msfeedssync.exe
8/11/2010 5:18:05 PM    9250816    32    C:\Windows\System32\mshtml.dll
8/11/2010 5:18:00 PM    1638912    32    C:\Windows\System32\mshtml.tlb
8/11/2010 5:18:02 PM    1062912    32    C:\Windows\System32\mstime.dll
8/11/2010 5:17:55 PM    1869824    32    C:\Windows\System32\msxml3.dll
8/11/2010 5:18:38 PM    4697992    32    C:\Windows\System32\ntoskrnl.exe
8/11/2010 5:18:02 PM    243712    32    C:\Windows\System32\occache.dll
8/25/2010 12:22:09 PM    53760    32    C:\Windows\System32\pwrshplugin.dll
8/11/2010 5:19:37 PM    50688    32    C:\Windows\System32\rtutils.dll
8/11/2010 5:17:53 PM    343040    32    C:\Windows\System32\schannel.dll
8/2/2010 6:38:51 PM    12898816    32    C:\Windows\System32\shell32.dll
8/25/2010 11:41:07 AM    10240    32    C:\Windows\System32\smrgdf.exe
8/11/2010 5:18:02 PM    1487360    32    C:\Windows\System32\urlmon.dll
8/25/2010 12:22:04 PM    84992    32    C:\Windows\System32\wecapi.dll
8/25/2010 12:22:04 PM    232960    32    C:\Windows\System32\wecsvc.dll
8/25/2010 12:22:04 PM    113152    32    C:\Windows\System32\wecutil.exe
8/25/2010 12:22:04 PM    113152    32    C:\Windows\System32\wevtfwd.dll
8/11/2010 5:19:38 PM    2752000    32    C:\Windows\System32\win32k.sys
8/11/2010 5:18:02 PM    1147904    32    C:\Windows\System32\wininet.dll
8/25/2010 12:22:01 PM    201184    32    C:\Windows\System32\winrm.vbs
8/25/2010 12:22:07 PM    51200    32    C:\Windows\System32\winrs.exe
8/25/2010 12:21:59 PM    370688    32    C:\Windows\System32\winrscmd.dll
8/25/2010 12:22:08 PM    24064    32    C:\Windows\System32\winrshost.exe
8/25/2010 12:22:20 PM    2048    32    C:\Windows\System32\winrsmgr.dll
8/25/2010 12:22:18 PM    13312    32    C:\Windows\System32\winrssrv.dll
8/25/2010 12:22:01 PM    4675    32    C:\Windows\System32\wsmanconfig_schema.xml
8/25/2010 12:21:59 PM    348672    32    C:\Windows\System32\WSManHTTPConfig.exe
8/25/2010 12:21:59 PM    352768    32    C:\Windows\System32\WSManMigrationPlugin.dll
8/25/2010 12:22:00 PM    180736    32    C:\Windows\System32\WsmAuto.dll
8/25/2010 12:22:18 PM    13312    32    C:\Windows\System32\wsmplpxy.dll
8/25/2010 12:22:08 PM    13824    32    C:\Windows\System32\wsmprovhost.exe
8/25/2010 12:22:05 PM    54272    32    C:\Windows\System32\WsmRes.dll
8/25/2010 12:21:59 PM    2050048    32    C:\Windows\System32\WsmSvc.dll
8/25/2010 12:22:01 PM    2426    32    C:\Windows\System32\WsmTxt.xsl
8/25/2010 12:22:00 PM    310272    32    C:\Windows\System32\WsmWmiPl.dll

====== "\Administrator & All Users\Startup" Last 60 Days======

 


====== "\Program Files" Last 60 Days======

6/30/2010 11:12:44 PM    195825    C:\Program Files\Bonjour
8/25/2010 11:21:58 PM    1977032    C:\Program Files\iTunes

======"Drivers" Modified Last 60 Days======


====== Files Deleted under "%Temp%" ======

19 Files deleted

======"All Users\Application Data" Last 60 Days======

 

====== HKLM\~\ShellServiceObjectDelayLoad======

WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll


====== HKLM\~\SharedTaskScheduler======

Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll

======HKLM\~\msconfig\startupreg======

HKLM\Software\microsoft\shared tools\msconfig\startupreg\

====== Services ( Services that are Whitelisted are not shown) ======

adp94xx (adp94xx)- C:\Windows\system32\drivers\adp94xx.sys - Disabled/Stopped
adpahci (adpahci)- C:\Windows\system32\drivers\adpahci.sys - Disabled/Stopped
amdide (amdide)- C:\Windows\system32\drivers\amdide.sys - Disabled/Stopped
arcsas (arcsas)- C:\Windows\system32\drivers\arcsas.sys - Disabled/Stopped
blbdrive (blbdrive)- C:\Windows\system32\drivers\blbdrive.sys - Disabled/Stopped
bowser (Bowser)- C:\Windows\system32\DRIVERS\bowser.sys - Manual/Running
BrFiltLo (Brother USB Mass-Storage Lower Filter Driver)- C:\Windows\system32\drivers\brfiltlo.sys - Manual/Stopped
BrFiltUp (Brother USB Mass-Storage Upper Filter Driver)- C:\Windows\system32\drivers\brfiltup.sys - Manual/Stopped
Brserid (Brother MFC Serial Port Interface Driver (WDM))- C:\Windows\system32\drivers\brserid.sys - Disabled/Stopped
BrSerWdm (Brother WDM Serial driver)- C:\Windows\system32\drivers\brserwdm.sys - Disabled/Stopped
BrUsbMdm (Brother MFC USB Fax Only Modem)- C:\Windows\system32\drivers\brusbmdm.sys - Disabled/Stopped
BrUsbSer (Brother MFC USB Serial WDM Driver)- C:\Windows\system32\drivers\brusbser.sys - Manual/Stopped
CAXHWBS2 (CAXHWBS2)- C:\Windows\system32\DRIVERS\CAXHWBS2.sys - Manual/Running
cfwids (McAfee Inc. cfwids)- C:\Windows\system32\drivers\cfwids.sys - Manual/Running
circlass (Consumer IR Devices)- C:\Windows\system32\drivers\circlass.sys - Disabled/Stopped
CLFS (Common Log (CLFS))- C:\Windows\system32\CLFS.sys - Boot/Running
DfsC (DFS Namespace Client Driver)- C:\Windows\system32\Drivers\dfsc.sys - System/Running
Dot4 (MS IEEE-1284.4 Driver)- C:\Windows\system32\DRIVERS\Dot4.sys - Manual/Running
Dot4Print (Print Class Driver for IEEE-1284.4)- C:\Windows\system32\DRIVERS\Dot4Prt.sys - Manual/Running
dot4usb (MS Dot4USB Filter Dot4USB Filter)- C:\Windows\system32\DRIVERS\dot4usb.sys - Manual/Running
DXGKrnl (LDDM Graphics Subsystem)- C:\Windows\system32\drivers\dxgkrnl.sys - Manual/Running
e1express (Intel(R) PRO/1000 PCI Express Network Connection Driver)- C:\Windows\system32\DRIVERS\e1e6032e.sys - Manual/Stopped
E1G60 (Intel(R) PRO/1000 NDIS 6 Adapter Driver)- C:\Windows\system32\DRIVERS\E1G6032E.sys - Manual/Stopped
Ecache (ReadyBoost Caching Driver)- C:\Windows\system32\drivers\ecache.sys - Boot/Running
ElRawDisk (ElRawDisk)- \??\C:\Windows\system32\drivers\elrawdsk.sys - System/Running
elxstor (elxstor)- C:\Windows\system32\drivers\elxstor.sys - Disabled/Stopped
ErrDev (Microsoft Hardware Error Device Driver)- C:\Windows\system32\drivers\errdev.sys - Disabled/Stopped
FileInfo (File Information FS MiniFilter)- C:\Windows\system32\drivers\fileinfo.sys - Boot/Running
Filetrace (FileTrace)- C:\Windows\system32\drivers\filetrace.sys - Manual/Stopped
gagp30kx (Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms)- C:\Windows\system32\drivers\gagp30kx.sys - Manual/Stopped
HidBth (Microsoft Bluetooth HID Miniport)- C:\Windows\system32\drivers\hidbth.sys - Disabled/Stopped
HidIr (Microsoft Infrared HID Driver)- C:\Windows\system32\drivers\hidir.sys - Disabled/Stopped
HpCISSs (HpCISSs)- C:\Windows\system32\drivers\hpcisss.sys - Disabled/Stopped
HSF_DPV (HSF_DPV)- C:\Windows\system32\DRIVERS\CAX_DPV.sys - Manual/Running
iaStor (Intel RAID Controller)- C:\Windows\system32\drivers\iastor.sys - Disabled/Stopped
iaStorV (Intel RAID Controller Vista)- C:\Windows\system32\drivers\iastorv.sys - Disabled/Stopped
igfx (igfx)- C:\Windows\system32\DRIVERS\igdkmd64.sys - Manual/Running
IPMIDRV (IPMIDRV)- C:\Windows\system32\drivers\ipmidrv.sys - Disabled/Stopped
iScsiPrt (iScsiPort Driver)- C:\Windows\system32\DRIVERS\msiscsi.sys - Manual/Running
iteatapi (ITEATAPI_Service_Install)- C:\Windows\system32\drivers\iteatapi.sys - Disabled/Stopped
iteraid (ITERAID_Service_Install)- C:\Windows\system32\drivers\iteraid.sys - Disabled/Stopped
lltdio (Link-Layer Topology Discovery Mapper I/O Driver)- C:\Windows\system32\DRIVERS\lltdio.sys - Auto/Running
LSI_FC (LSI_FC)- C:\Windows\system32\drivers\lsi_fc.sys - Disabled/Stopped
LSI_SAS (LSI_SAS)- C:\Windows\system32\drivers\lsi_sas.sys - Disabled/Stopped
LSI_SCSI (LSI_SCSI)- C:\Windows\system32\drivers\lsi_scsi.sys - Disabled/Stopped
luafv (UAC File Virtualization)- C:\Windows\system32\drivers\luafv.sys - Auto/Running
ManyCam (ManyCam Virtual Webcam, WDM Video Capture Driver)- C:\Windows\system32\DRIVERS\ManyCam_x64.sys - Manual/Stopped
megasas (megasas)- C:\Windows\system32\drivers\megasas.sys - Disabled/Stopped
MegaSR (MegaSR)- C:\Windows\system32\drivers\megasr.sys - Disabled/Stopped
mfeapfk (McAfee Inc. mfeapfk)- C:\Windows\system32\drivers\mfeapfk.sys - Manual/Running
mfefirek (McAfee Inc. mfefirek)- C:\Windows\system32\drivers\mfefirek.sys - Manual/Running
mfenlfk (McAfee NDIS Light Filter)- C:\Windows\system32\DRIVERS\mfenlfk.sys - System/Running
mferkdet (McAfee Inc. mferkdet)- C:\Windows\system32\drivers\mferkdet.sys - Manual/Stopped
mfewfpk (McAfee Inc. mfewfpk)- C:\Windows\system32\drivers\mfewfpk.sys - System/Running
mpio (Microsoft Multi-Path Bus Driver)- C:\Windows\system32\drivers\mpio.sys - Disabled/Stopped
mpsdrv (Windows Firewall Authorization Driver)- C:\Windows\system32\drivers\mpsdrv.sys - Manual/Running
mrxsmb10 (SMB 1.x MiniRedirector)- C:\Windows\system32\DRIVERS\mrxsmb10.sys - Manual/Running
mrxsmb20 (SMB 2.0 MiniRedirector)- C:\Windows\system32\DRIVERS\mrxsmb20.sys - Manual/Running
msahci (msahci)- C:\Windows\system32\drivers\msahci.sys - Disabled/Stopped
msdsm (Microsoft Multi-Path Device Specific Module)- C:\Windows\system32\drivers\msdsm.sys - Disabled/Stopped
msisadrv (ISA/EISA Class Driver)- C:\Windows\system32\drivers\msisadrv.sys - Boot/Running
MsRPC (MsRPC)- C:\Windows\system32\drivers\MsRPC.sys - Manual/Stopped
NativeWifiP (NativeWiFi Filter)- C:\Windows\system32\DRIVERS\nwifi.sys - Manual/Stopped
nfrd960 (nfrd960)- C:\Windows\system32\drivers\nfrd960.sys - Disabled/Stopped
nsiproxy (NSI proxy service)- C:\Windows\system32\drivers\nsiproxy.sys - System/Running
nvstor (nvstor)- C:\Windows\system32\drivers\nvstor.sys - Disabled/Stopped
OA002Afx (Provides a software interface to control audio effects of OA002 camera.)- \??\C:\Windows\system32\Drivers\OA002Afx.sys - Manual/Running
OA002Ufd (Creative Camera OA002 Upper Filter Driver)- C:\Windows\system32\DRIVERS\OA002Ufd.sys - Manual/Running
OA002Vid (Creative Camera OA002 Function Driver)- C:\Windows\system32\DRIVERS\OA002Vid.sys - Manual/Running
PEAUTH (PEAUTH)- C:\Windows\system32\drivers\peauth.sys - Auto/Running
PxHlpa64 (PxHlpa64)- C:\Windows\system32\Drivers\PxHlpa64.sys - Boot/Running
ql2300 (QLogic Fibre Channel Miniport Driver)- C:\Windows\system32\drivers\ql2300.sys - Disabled/Stopped
ql40xx (QLogic iSCSI Miniport Driver)- C:\Windows\system32\drivers\ql40xx.sys - Disabled/Stopped
QWAVEdrv (QWAVE driver)- C:\Windows\system32\drivers\qwavedrv.sys - Manual/Stopped
R300 (R300)- C:\Windows\system32\DRIVERS\atikmdag.sys - Manual/Stopped
RDPENCDD (RDP Encoder Mirror Driver)- C:\Windows\system32\drivers\rdpencdd.sys - System/Running
RLDesignVirtualAudioCableWdm (Live! Cam Virtual)- C:\Windows\system32\DRIVERS\livecamv.sys - Manual/Running
rspndr (Link-Layer Topology Discovery Responder)- C:\Windows\system32\DRIVERS\rspndr.sys - Auto/Running
RTL8169 (Realtek 8169 NT Driver)- C:\Windows\system32\DRIVERS\Rtlh64.sys - Manual/Running
sbp2port (SBP-2 Transport/Protocol Bus Driver)- C:\Windows\system32\drivers\sbp2port.sys - Disabled/Stopped
sermouse (Serial Mouse Driver)- C:\Windows\system32\drivers\sermouse.sys - Disabled/Stopped
sffdisk (SFF Storage Class Driver)- C:\Windows\system32\drivers\sffdisk.sys - Disabled/Stopped
sffp_mmc (SFF Storage Protocol Driver for MMC)- C:\Windows\system32\drivers\sffp_mmc.sys - Manual/Stopped
sffp_sd (SFF Storage Protocol Driver for SDBus)- C:\Windows\system32\drivers\sffp_sd.sys - Manual/Stopped
SiSRaid2 (SiSRaid2)- C:\Windows\system32\drivers\sisraid2.sys - Disabled/Stopped
SiSRaid4 (SiSRaid4)- C:\Windows\system32\drivers\sisraid4.sys - Disabled/Stopped
spldr (Security Processor Loader Driver)- C:\Windows\system32\drivers\spldr.sys - Boot/Running
srv2 (srv2)- C:\Windows\system32\DRIVERS\srv2.sys - Manual/Running
srvnet (srvnet)- C:\Windows\system32\DRIVERS\srvnet.sys - Manual/Running
Tcpip6 (Microsoft IPv6 Protocol Driver)- C:\Windows\system32\DRIVERS\tcpip.sys - Manual/Stopped
tcpipreg (TCP/IP Registry Compatibility)- C:\Windows\system32\drivers\tcpipreg.sys - Auto/Running
tdx (NetIO Legacy TDI Support Driver)- C:\Windows\system32\DRIVERS\tdx.sys - System/Running
tssecsrv (Terminal Services Security Filter Driver)- C:\Windows\system32\DRIVERS\tssecsrv.sys - Manual/Stopped
tunmp (Microsoft Tun Miniport Adapter Driver)- C:\Windows\system32\DRIVERS\tunmp.sys - Manual/Running
tunnel (Microsoft IPv6 Tunnel Miniport Adapter Driver)- C:\Windows\system32\DRIVERS\tunnel.sys - Manual/Running
uagp35 (Microsoft AGPv3.5 Filter)- C:\Windows\system32\drivers\uagp35.sys - Manual/Stopped
uliagpkx (Uli AGP Bus Filter)- C:\Windows\system32\drivers\uliagpkx.sys - Manual/Stopped
uliahci (uliahci)- C:\Windows\system32\drivers\uliahci.sys - Disabled/Stopped
UlSata (UlSata)- C:\Windows\system32\drivers\ulsata.sys - Disabled/Stopped
ulsata2 (ulsata2)- C:\Windows\system32\drivers\ulsata2.sys - Disabled/Stopped
umbus (UMBus Enumerator Driver)- C:\Windows\system32\DRIVERS\umbus.sys - Manual/Running
usbcir (eHome Infrared Receiver (USBCIR))- C:\Windows\system32\drivers\usbcir.sys - Disabled/Stopped
usbvideo (USB Video Device (WDM))- C:\Windows\system32\Drivers\usbvideo.sys - Manual/Stopped
USB_RNDIS_VISTA (Westell USB Network Interface)- C:\Windows\system32\DRIVERS\usb8023.sys - Manual/Stopped
volmgr (Volume Manager Driver)- C:\Windows\system32\drivers\volmgr.sys - Boot/Running
volmgrx (Dynamic Volume Manager)- C:\Windows\system32\drivers\volmgrx.sys - Boot/Running
vsmraid (vsmraid)- C:\Windows\system32\drivers\vsmraid.sys - Disabled/Stopped
WacomPen (Wacom Serial Pen HID Driver)- C:\Windows\system32\drivers\wacompen.sys - Disabled/Stopped
Wanarpv6 (Remote Access IPv6 ARP Driver)- C:\Windows\system32\DRIVERS\wanarp.sys - System/Running
Wdf01000 (Kernel Mode Driver Frameworks service)- C:\Windows\system32\drivers\Wdf01000.sys - Boot/Running
WmiAcpi (Microsoft Windows Management Interface for ACPI)- C:\Windows\system32\drivers\wmiacpi.sys - Disabled/Stopped
XAudio (XAudio)- C:\Windows\system32\DRIVERS\xaudio64.sys - Auto/Running

====== Uninstall List ======

A file named 'UNI.txt' was created and saved to
FileListers default location. Post the results if requested.

======== Other Info ========

TOTAL PHYSICAL RAM: 3477 MB

Boot Info

OS Type:  Microsoft® Windows Vista™ Home Premium
Build:  6.0.6002
Service Pack:  2.0

====== Files with Hidden Attributes======

A file named 'Hidden.txt' was created and saved to
FileListers default location. Post the results if requested.

==End of Report==

 

 

under UNI

Conexant D850 PCI V.92 Modem
Monitor Webcam Driver (1.01.02.0804) 
HP Imaging Device Functions 8.0
HP Solution Center 8.0
HP Customer Participation Program 8.0
HP OCR Software 8.0
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Modem Diagnostic Tool
iTunes
HP Officejet J3600 Series
Apple Mobile Device Support
Windows Live ID Sign-in Assistant
64 Bit HP CIO Components Installer
Bonjour
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Dell Dock

 

under Hidden

C:\hiberfil.sys
C:\pagefile.sys
C:\$Recycle.Bin\S-1-5-21-2861493818-4263090491-2562842553-1000\desktop.ini
C:\Boot\bootstat.dat
C:\Program Files\desktop.ini
C:\Program Files\Common Files\Microsoft Shared\ink\TabletLinks\desktop.ini
C:\Program Files\Common Files\Microsoft Shared\Stationery\Desktop.ini
C:\Program Files\Microsoft Games\Chess\desktop.ini
C:\Program Files\Microsoft Games\FreeCell\desktop.ini
C:\Program Files\Microsoft Games\Hearts\desktop.ini
C:\Program Files\Microsoft Games\Mahjong\desktop.ini
C:\Program Files\Microsoft Games\Purble Place\desktop.ini
C:\Program Files\Microsoft Games\Solitaire\desktop.ini
C:\Program Files\Microsoft Games\SpiderSolitaire\desktop.ini
C:\Program Files (x86)\desktop.ini
C:\Program Files (x86)\Common Files\microsoft shared\Stationery\Desktop.ini
C:\Program Files (x86)\Dell\PC TuneUp\unins000.exe
C:\Program Files (x86)\Dell\PC TuneUp\unins000.dat
C:\Program Files (x86)\Skype\desktop.ini
C:\Program Files (x86)\Spybot - Search & Destroy\advcheck.dll
C:\ProgramData\ezsidmv.dat
C:\ProgramData\Macrovision\SafeCast\Product Licenses\B1E98000.dat
C:\ProgramData\Macrovision\SafeCast\Product Licenses\BD6FA000.dat
C:\ProgramData\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\PlayTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\0\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\1\desktop.ini
C:\ProgramData\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\2\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Extras and Upgrades\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC\Desktop.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows PowerShell 1.0\desktop.ini
C:\ProgramData\Sonic\sarlicense9.dat
C:\Users\desktop.ini
C:\Users\All Users\ezsidmv.dat
C:\Users\All Users\Macrovision\SafeCast\Product Licenses\B1E98000.dat
C:\Users\All Users\Macrovision\SafeCast\Product Licenses\BD6FA000.dat
C:\Users\All Users\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{48DE2B25-A3A2-4121-808D-5DD991D9FEBB}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{6C815596-821F-40b3-8A84-643B73A8EB16}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{91CA4D38-EA2B-4f3c-94DE-36C1386182FC}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AF698A5B-24D6-4f78-AE95-204B09EDC7B6}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{AFA7FF39-1DDF-4f70-A2D5-23FCFFF02E5F}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{D1A7F7E0-D4E9-49e8-BF2C-CEAA01D2E670}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\PlayTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\0\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\1\desktop.ini
C:\Users\All Users\Microsoft\Windows\GameExplorer\{E91579C0-4EA9-4a2a-A9B2-04BEF1D6DC29}\SupportTasks\2\desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Extras and Upgrades\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Games\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Tablet PC\Desktop.ini
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Windows PowerShell 1.0\desktop.ini
C:\Users\All Users\Sonic\sarlicense9.dat
C:\Users\Default\NTUSER.DAT
C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6QRTQ4OZ\desktop.ini
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\81XI2VHO\desktop.ini
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GETOZQ30\desktop.ini
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SXXAUYOS\desktop.ini
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Desktop.ini
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
C:\Users\Public\desktop.ini
C:\Users\Public\Documents\desktop.ini
C:\Users\Public\Downloads\desktop.ini
C:\Users\Public\Music\desktop.ini
C:\Users\Public\Music\Sample Music\desktop.ini
C:\Users\Public\Pictures\desktop.ini
C:\Users\Public\Pictures\Sample Pictures\desktop.ini
C:\Users\Public\Recorded TV\desktop.ini
C:\Users\Public\Recorded TV\TempRec\ehscanned.dat
C:\Users\Public\Videos\desktop.ini
C:\Users\Public\Videos\Sample Videos\desktop.ini
C:\Users\Tammy\NTUSER.DAT
C:\Users\Tammy\ntuser.dat_previous
C:\Users\Tammy\ntuser.ini
C:\Users\Tammy\AppData\Local\Microsoft\Feeds Cache\index.dat
C:\Users\Tammy\AppData\Local\Microsoft\Feeds Cache\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Feeds Cache\30V6LY0K\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Feeds Cache\9O8E1PFT\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Feeds Cache\G7NP1A2X\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Feeds Cache\R72YCYMS\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\UsrClass.dat
C:\Users\Tammy\AppData\Local\Microsoft\Windows\UsrClass.dat_previous
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\PlayTasks\0\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\0\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\1\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\GameExplorer\{00D8862B-6453-4957-A821-3D98D74C76BE}\SupportTasks\2\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\PlayTasks\0\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\0\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\1\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\GameExplorer\{205286E5-F5F2-4306-BDB1-864245E33227}\SupportTasks\2\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\History\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
C:\Users\Tammy\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012010082320100830\index.dat
C:\Users\Tammy\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012010083020100831\index.dat
C:\Users\Tammy\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012010083120100901\index.dat
C:\Users\Tammy\AppData\Local\Microsoft\Windows\History\Low\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
C:\Users\Tammy\AppData\Local\Microsoft\Windows\History\Low\History.IE5\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012010082320100830\index.dat
C:\Users\Tammy\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012010083020100831\index.dat
C:\Users\Tammy\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012010083120100901\index.dat
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1JMGGSXI\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7V2JK0SL\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G71K1V7T\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JOGIA34U\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S24439WV\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4KBEDV9X\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D0I2JFOT\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\HZ8NNJSG\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\T2EACH62\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows Mail\Stationery\Desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft\Windows Photo Gallery\Original Images\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft Games\Hearts\desktop.ini
C:\Users\Tammy\AppData\Local\Microsoft Games\Solitaire\desktop.ini
C:\Users\Tammy\AppData\Local\VirtualStore\Windows\SysWOW64\mlfcache.dat
C:\Users\Tammy\AppData\LocalLow\desktop.ini
C:\Users\Tammy\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat
C:\Users\Tammy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
C:\Users\Tammy\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat
C:\Users\Tammy\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low\index.dat
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\Cookies\desktop.ini
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\IECompatCache\index.dat
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\IECompatCache\Low\index.dat
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\IETldCache\Low\index.dat
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\PrivacIE\Low\index.dat
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\SendTo\Desktop.ini
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
C:\Users\Tammy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
C:\Users\Tammy\Contacts\desktop.ini
C:\Users\Tammy\Documents\desktop.ini
C:\Users\Tammy\Downloads\desktop.ini
C:\Users\Tammy\Favorites\desktop.ini
C:\Users\Tammy\Favorites\Links\desktop.ini
C:\Users\Tammy\Links\desktop.ini
C:\Users\Tammy\Music\desktop.ini
C:\Users\Tammy\Pictures\desktop.ini
C:\Users\Tammy\Saved Games\desktop.ini
C:\Users\Tammy\Saved Games\Microsoft Games\desktop.ini
C:\Users\Tammy\Searches\desktop.ini
C:\Users\Tammy\Videos\desktop.ini
C:\Windows\assembly\pubpol1.dat
C:\Windows\assembly\Desktop.ini
C:\Windows\assembly\NativeImages_v2.0.50727_32\index41b.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\index424.dat
C:\Windows\assembly\NativeImages_v2.0.50727_32\index425.dat
C:\Windows\assembly\NativeImages_v2.0.50727_64\index46d.dat
C:\Windows\assembly\NativeImages_v2.0.50727_64\index478.dat
C:\Windows\assembly\NativeImages_v2.0.50727_64\index479.dat
C:\Windows\assembly\NativeImages_v4.0.30319_32\index55.dat
C:\Windows\assembly\NativeImages_v4.0.30319_32\index56.dat
C:\Windows\assembly\NativeImages_v4.0.30319_64\index55.dat
C:\Windows\assembly\NativeImages_v4.0.30319_64\index56.dat
C:\Windows\Media\Desktop.ini
C:\Windows\System32\desktop.ini
C:\Windows\Tasks\SA.DAT
C:\Windows\Temp\Cookies\index.dat
C:\Windows\Temp\History\History.IE5\index.dat
C:\Windows\Temp\History\History.IE5\desktop.ini
C:\Windows\Temp\Temporary Internet Files\Content.IE5\index.dat
C:\Windows\Temp\Temporary Internet Files\Content.IE5\desktop.ini
C:\Windows\Temp\Temporary Internet Files\Content.IE5\52QBPYRS\desktop.ini
C:\Windows\Temp\Temporary Internet Files\Content.IE5\72CXU085\desktop.ini
C:\Windows\Temp\Temporary Internet Files\Content.IE5\ISFR0NYM\desktop.ini
C:\Windows\Temp\Temporary Internet Files\Content.IE5\PY5D95NJ\desktop.ini
C:\Windows\Users\Default\NTUSER.DAT

 

August 31st, 2010 10:00

I try again, Thank you

10.4K Posts

September 7th, 2010 07:00




I don't see any other signs of infection. Let's look at one more thing

Please perform a BitDefender Online Virus and Malware Scan here:
  • * Click Start Scanner.
    * Click I Agree… and Start Here.
    * An ActiveX warning box will appear; click Install.
    * Options displayed are Folders to Scan and Cleaning Options; click Folders to Scan (in most cases it will be C:\).
    * Select folders to be scanned by clicking check boxes; click OK.
    * Click Start Scan.
    * After the scan has completed, click Click here to export the scan report.
    * Save the report to your Desktop.
    * In your next reply, please include the BitDefender log.

No Events found!

Top