![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#81 (permalink) | |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,813
OS: WinXP and Vista
|
Re: MS Windows XP will not load when connected to internet
Hi,
No--do not update to SP2 yet as the infection may corrupt the install. Very good question. Online scanners, AVG A-S, SDFix, ComboFix will scan the system globally, but scans with dss.exe and the HijackThis log produced are only scanning the account that it is run on. It would be a good idea to run dss.exe on the other accts on this sytem after completing the fix below. Panda is reporting mostly unwanted cookies--which we'll run ATF Cleaner to take care of those. We'll take out the one registry entry it is reporting--the others with no location are orphaned registry entries. With no file associated with them, they are harmless and it's better to just leave them than to go rooting around the registry looking for them and risking irrepairable damage to your system. Please copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions. *************************************************** Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. Close the Registry Editor now. Open notepad and copy/paste the entire text in the quotebox below: (don't forget to copy and paste REGEDIT4) Quote:
It should look like this: ![]() Double click on the delete.reg file and choose Yes to merge/add it to the registry. You may delete the file afterwards. ---------------------------------------------------- Delete these folders: C:\337100427 C:\WINDOWS\System32\14981 C:\WINDOWS\System32\3D64363D C:\WINDOWS\System32\7AAECFBC C:\WINDOWS\System32\86C67981 C:\WINDOWS\System32\9147A101 C:\WINDOWS\System32\9947BC72 C:\WINDOWS\System32\9ACA5390 C:\WINDOWS\System32\DF21552E C:\WINDOWS\System32\openopenopenopen --------------------------------------------------------- Double-click ATF-Cleaner.exe to run the program.
-------------------------------------------------------------------- Reboot your system and go into Safe Mode to run SDFix once again. -------------------------------------------------------------------- I realize the online scans are time consuming, but I'd like to see if Kaspersky sees anything further: Please perform an online scan with Internet Explorer at Kaspersky Online Scanner Answer Yes, when prompted to install an ActiveX component.
------------------------------------------------------------ Please include the following in your next reply: C:\SDFix\Report.txt Kaspersky results main.txt for each acct on this system Is this computer networked to any others? |
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#82 (permalink) |
|
Registered User
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP
|
Re: MS Windows XP will not load when connected to internet
Easy answers first while I am doing the other things that will take some time. I don't mind doing them if it will lead to a cure in the end.
Regarding SP2 install, I had read that somewhere on this site to not upgrade if infected, so that is why I stopped before going too far. Regarding network, yes in an simple way. I was getting to that point after cleaning up this one. Both systems are plugged into a netgear ethernet hub. I did not get past this system in setting up a network. The other system is slow, but running. Would you like a scan of that one just to see if it is infected? I will be busy doing the other tasks for awhile. |
|
|
|
|
#83 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,813
OS: WinXP and Vista
|
Re: MS Windows XP will not load when connected to internet
Yes, please run dss.exe on the other system and post that here as well. I think it would be prudent given the circumstances.
|
|
|
|
|
#84 (permalink) |
|
Registered User
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP
|
Re: MS Windows XP will not load when connected to internet
I was scrolling through the posting and saw this under the
-- Files created between 2007-02-24 and 2007-03-24 ----------------------------- Section. This is on the other system as well and looks weird, like it does not belong. It did not show up here, but there is a smile face in it, scroll down to see. You can not miss is. 2007-03-17 2122 0 --a------ C:\Documents and Settings\robyn\Application Data\wklnhst.dat having problems with Kaspersky downloading and installing, will try to work through it and will ask for assistance later if I can not access the scan. |
|
|
|
|
#85 (permalink) |
|
Registered User
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP
|
Re: MS Windows XP will not load when connected to internet
I have pasted but could not attach results from the dss scans. An observation - I was running dss and the system froze up on me, or I was not
patient enough to wait it out, but i did not hear anything and I waited about two minutes before hitting the x to close the window. The end program window came up and I let it finish. I then saw the file that is attached come up. It was named snm.exe. I am now also getting a rundll error and have saved a copy of the printscreen in paint but can not attach to the thread. I don't know why. Only the right third of the page header is displayed. This happened around page three and just recently came back. Results of dss scans on each user account on the infected PC. Duane Deckard's System Scanner v20070318.32 Run by Duane on 2007-03-24 at 13:23:14 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- HijackThis (run as Duane.exe) ----------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 1:23:22 PM, on 3/24/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\avgav.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\alg.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\Program Files\iTunes\iTunesHelper.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE C:\Program Files\Micro Innovations\Mouse\mouse32a.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\WINDOWS\System32\icqmlib.exe C:\WINDOWS\System32\ocxloader.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\BigFix\BigFix.exe C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\iPod\bin\iPodService.exe C:\Documents and Settings\Duane\Desktop\dss.exe C:\PROGRA~1\HIJACK~1\Duane.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1846C0B3-8272-4FB3-A455-8F99FC0C0AF8} - C:\WINDOWS\System32\pqkuaaau.dll O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: (no name) - {85382E07-2F7E-4910-89AD-16F2E97FC152} - C:\WINDOWS\System32\ssqnllk.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: (no name) - {C3B48746-C8C5-42DB-B803-F164DDEC1E55} - C:\WINDOWS\System32\pqkuaaau.dll O2 - BHO: (no name) - {E0887CD0-9049-4F2E-920E-9296B905C66D} - C:\WINDOWS\System32\geedb.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com O16 - DPF: Video Poker - http://download.games.yahoo.com/game...s/y/vpt0_x.cab O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/game...ts/y/at1_x.cab O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/game...ts/y/xt0_x.cab O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/game...ts/y/jt0_x.cab O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/game...ts/y/kt4_x.cab O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/game...ts/y/ct2_x.cab O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game...ts/y/it1_x.cab O16 - DPF: Yahoo! Dice - http://download.games.yahoo.com/game...s/y/dct4_x.cab O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/game...ts/y/zt3_x.cab O16 - DPF: Yahoo! Klondike Solitaire - http://presence.games.yahoo.com/yog/y/ks12_x.cab O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/game...s/y/pyt1_x.cab O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/14939218...p/RdxIE601.cab O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab O20 - Winlogon Notify: geedb - C:\WINDOWS\System32\geedb.dll O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: ssqnllk - C:\WINDOWS\SYSTEM32\ssqnllk.dll O23 - Service: avgav.exe (AVG) - Unknown owner - C:\WINDOWS\avgav.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - C:\WINDOWS\alg.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe -- Files created between 2007-02-24 and 2007-03-24 ----------------------------- 2007-03-24 13:22:45 1997 --a------ C:\jishhs.exe 2007-03-24 13:22:30 26697 --a------ C:\WINDOWS\System32\pmnoonm.dll 2007-03-24 12:39:22 52674 --a------ C:\WINDOWS\System32\setup_56846.exe<SETUP_~1.EXE> 2007-03-24 12:34:45 26697 --a------ C:\WINDOWS\System32\fcccddd.dll 2007-03-24 12:09:27 280676 ---hs---- C:\WINDOWS\System32\mljjj.dll 2007-03-24 12:08:29 1208018 ---hs---- C:\WINDOWS\System32\bdeeg.ini2<BDEEG~1.INI> 2007-03-24 12:03:47 280676 ---hs---- C:\WINDOWS\System32\ssqrq.dll 2007-03-24 12:03:22 11264 --a------ C:\WINDOWS\System32\ocxloader.exe<OCXLOA~1.EXE> 2007-03-24 12:03:22 348160 --a------ C:\WINDOWS\System32\ocxapi.dll 2007-03-24 12:03:22 0 --a------ C:\WINDOWS\System32\ierplc.dll 2007-03-24 12:03:22 80 --a------ C:\WINDOWS\System32\iepref32.dll 2007-03-24 12:03:17 4608 --a------ C:\WINDOWS\System32\ips.dll 2007-03-24 12:03:14 53248 --a------ C:\WINDOWS\System32\icqmlib.exe 2007-03-24 12:01:15 280676 ---hs---- C:\WINDOWS\System32\sstqo.dll 2007-03-24 11:59:00 123972 --a------ C:\WINDOWS\System32\sqvyswsn.dll 2007-03-24 11:58:59 0 d-------- C:\Documents and Settings\Duane\Application Data\SearchToolbarCorp<SEARCH~1> 2007-03-24 11:58:50 132116 --a------ C:\WINDOWS\System32\pqkuaaau.dll 2007-03-24 11:58:46 0 d-------- C:\Program Files\VSAdd-in 2007-03-24 11:58:43 88340 --a------ C:\WINDOWS\System32\dyghasfc.exe 2007-03-24 11:58:42 1206759 ---hs---- C:\WINDOWS\System32\bdeeg.bak1<BDEEG~1.BAK> 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\WINDOWS 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Symantec 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\InterTrust<INTERT~1> 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Adobe 2007-03-24 11:58:21 280676 ---hs---- C:\WINDOWS\System32\geedb.dll 2007-03-24 11:58:21 1048576 --ah----- C:\Documents and Settings\Master Account\NTUSER.DAT 2007-03-24 11:53:13 596 --a------ C:\WINDOWS\System32\qmopt.dll 2007-03-24 11:52:57 26697 --a------ C:\WINDOWS\System32\ssqnllk.dll 2007-03-24 08:46:40 0 d-------- C:\WINDOWS\System32\Kaspersky Lab<KASPER~1> 2007-03-24 08:38:51 86016 -r-hs---- C:\WINDOWS\alg.exe 2007-03-24 08:38:42 69 --a------ C:\WINDOWS\System32\i 2007-03-21 21:17:04 52674 -r-hs---- C:\WINDOWS\avgav.exe 2007-03-20 20:18:18 0 d-------- C:\avenger 2007-03-19 21:14:12 0 d--h----- C:\WINDOWS\PIF 2007-03-13 20:51:18 136 --a------ C:\WINDOWS\System32\dgjun.bat 2007-03-12 18:20:25 491768 --a------ C:\ie6setup.exe 2007-03-11 22:17:35 0 d-------- C:\WINDOWS\System32\ActiveScan<ACTIVE~1> 2007-03-11 09:25:11 0 d-------- C:\Program Files\Java 2007-03-11 09:25:11 0 d-------- C:\Program Files\Common Files\Java 2007-03-11 09:24:21 0 d-------- C:\Documents and Settings\Duane\Application Data\Sun 2007-03-10 11:31:19 0 d-------- C:\Rustbfix 2007-03-08 19:33:08 49152 --a------ C:\Documents and Settings\Duane\vfind.exe 2007-03-08 19:33:08 79360 --a------ C:\Documents and Settings\Duane\swxcacls.exe 2007-03-08 19:33:08 123904 --a------ C:\Documents and Settings\Duane\swsc.exe 2007-03-08 19:33:08 140800 --a------ C:\Documents and Settings\Duane\swreg.exe 2007-03-08 19:33:08 8192 --a------ C:\Documents and Settings\Duane\RestartIt.exe<RESTAR~1.EXE> 2007-03-08 19:33:08 6914 --a------ C:\Documents and Settings\Duane\Qoo.bat 2007-03-08 19:33:08 971 --a------ C:\Documents and Settings\Duane\Purity.bat 2007-03-08 19:33:08 39184 --a------ C:\Documents and Settings\Duane\Ntrights.exe 2007-03-08 19:33:08 5074 --a------ C:\Documents and Settings\Duane\NTPBack.exe 2007-03-08 19:33:08 42887 --a------ C:\Documents and Settings\Duane\ntp.exe 2007-03-08 19:33:08 26112 --a------ C:\Documents and Settings\Duane\nircmd.exe 2007-03-08 19:33:08 38400 --a------ C:\Documents and Settings\Duane\moveex.exe 2007-03-08 19:33:08 2304 --a------ C:\Documents and Settings\Duane\Look2Me.bat 2007-03-08 19:33:08 117379 --a------ C:\Documents and Settings\Duane\LIST-C.bat 2007-03-08 19:33:08 181776 --a------ C:\Documents and Settings\Duane\handle.exe 2007-03-08 19:33:08 73728 --a------ C:\Documents and Settings\Duane\FDSV.EXE 2007-03-08 19:33:08 51200 --a------ C:\Documents and Settings\Duane\dumphive.exe 2007-03-08 19:33:08 319415 --a------ C:\Documents and Settings\Duane\Creg.reg 2007-03-08 19:33:08 28672 --a------ C:\Documents and Settings\Duane\catchme.exe 2007-02-24 21:33:14 53248 --a------ C:\WINDOWS\System32\Process.exe 2007-02-24 21:33:08 0 d-------- C:\SmitfraudFix<SMITFR~1> -- Find3M Report --------------------------------------------------------------- 2007-03-24 13:23:16 0 d-------- C:\Program Files\Hijack This<HIJACK~1> 2007-03-21 22:56:19 0 d---s---- C:\Documents and Settings\Duane\Application Data\Microsoft<MICROS~1> 2007-03-21 20:38:09 0 d-------- C:\Program Files\Picasa2 2007-03-21 20:36:13 0 d-------- C:\Program Files\Messenger<MESSEN~1> 2007-03-21 20:31:05 0 d-------- C:\Program Files\iTunes 2007-03-21 20:29:54 0 d-------- C:\Program Files\Google 2007-03-21 20:27:24 0 d-------- C:\Program Files\BigFix 2007-03-08 19:47:09 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1> 2007-02-24 22:08:44 3762 --a------ C:\WINDOWS\System32\tmp.reg 2007-02-24 10:40:37 0 d-------- C:\Documents and Settings\Duane\Application Data\AVG7 2007-02-21 21:42:31 129 --a------ C:\fix.bat 2007-02-21 18:24:56 0 d-------- C:\Program Files\backups 2007-02-20 21:14:12 0 d-------- C:\Program Files\Shockwave.com<SHOCKW~1.COM> 2007-02-13 21:29:11 0 d-------- C:\Program Files\Common Files\Sandlot Shared<SANDLO~1> 2007-02-10 20:00:13 14201 --a------ C:\Program Files\hijackthis.log<HIJACK~1.LOG> 2007-01-28 22:13:42 0 d-------- C:\Program Files\LG Software Innovations<LGSOFT~1> 2007-01-28 22:05:20 0 d-------- C:\Program Files\CloneDVD 2007-01-28 21:28:17 14 --a------ C:\WINDOWS\System32\systeminfo3.dll<SYSTEM~1.DLL> 2007-01-28 21:26:56 0 d-------- C:\Documents and Settings\Duane\Application Data\Vso 2007-01-28 21:26:55 34 --a------ C:\Documents and Settings\Duane\Application Data\pcouffin.log 2007-01-28 21:26:41 47360 --a------ C:\Documents and Settings\Duane\Application Data\pcouffin.sys 2007-01-28 21:26:41 1144 --a------ C:\Documents and Settings\Duane\Application Data\pcouffin.inf 2007-01-28 21:26:41 7176 --a------ C:\Documents and Settings\Duane\Application Data\pcouffin.cat 2007-01-28 21:26:41 81920 --a------ C:\Documents and Settings\Duane\Application Data\ezpinst.exe 2007-01-21 15:08:15 14612 --a------ C:\Program Files\CWSHREDDER.EXE-2D092FD4.pf<CWSHRE~1.PF> 2007-01-21 15:03:52 532480 --a------ C:\Program Files\cwshredder.exe<CWSHRE~1.EXE> 2007-01-13 14:32:20 0 --a------ C:\WINDOWS\System32\00BDDB65 2007-01-12 18:19:57 0 --a------ C:\WINDOWS\System32\vb2en16.dll 2007-01-12 18:19:50 1235 --a------ C:\WINDOWS\System32\openopenopen<OPENOP~2> 2007-01-12 18:19:34 0 --a------ C:\WINDOWS\System32\99239519 2007-01-11 16:35:52 1 --a------ C:\WINDOWS\System32\kr_done1 2007-01-11 16:35:33 12800 --a------ C:\WINDOWS\System32\svchost.exe 2007-01-11 16:33:19 0 --a------ C:\WINDOWS\System32\3718845C 2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\ps.dat 2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\cookie.dat 2007-01-07 13:16:52 25600 --a------ C:\WINDOWS\System32\helper.dll 2007-01-04 22:35:41 10660 --a------ C:\WINDOWS\mozver.dat 2007-01-03 20:49:11 5037072 --a------ C:\Program Files\spybotsd14.exe<SPYBOT~1.EXE> 2007-01-01 12:02:40 507 --a------ C:\WINDOWS\EReg077.dat 2006-12-25 16:33:11 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi<PLAINO~1.XPI> -- Registry Dump --------------------------------------------------------------- [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "Microsoft Works Update Detection"="c:\\Program Files\\Microsoft Works\\WkDetect.exe" "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe" "Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe" "HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe" "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"" "HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP" "OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE" "FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe" "PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot" "SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SoundService"="rundll32.exe \"C:\\WINDOWS\\System32\\sqvyswsn.dll\",setvm" "icqmlib.exe"="icqmlib.exe" "ocxloader.exe"="C:\\WINDOWS\\System32\\ocxloader.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" "{85382E07-2F7E-4910-89AD-16F2E97FC152}"="" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnllk [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 *newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_LANMANDRV -- End of Deckard's System Scanner: finished at 2007-03-24 at 13:23:55 --------- Cody Deckard's System Scanner v20070318.32 Run by Cody on 2007-03-24 at 13:26:09 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- HijackThis (run as Cody.exe) ------------------------------------------------ Logfile of HijackThis v1.99.1 Scan saved at 1:26:10 PM, on 3/24/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\avgav.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\alg.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\System32\wuauclt.exe C:\WINDOWS\system32\userinit.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\Program Files\iTunes\iTunesHelper.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE C:\Program Files\Micro Innovations\Mouse\mouse32a.exe C:\PROGRA~1\Sygate\SPF\smc.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\BigFix\BigFix.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe C:\Program Files\HP\hpcoretech\soln\HPOSM.exe C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe C:\Documents and Settings\Cody\Desktop\dss.exe C:\PROGRA~1\HIJACK~1\Cody.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/ R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file) O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1846C0B3-8272-4FB3-A455-8F99FC0C0AF8} - C:\WINDOWS\System32\pqkuaaau.dll O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: (no name) - {85382E07-2F7E-4910-89AD-16F2E97FC152} - C:\WINDOWS\System32\ssqnllk.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: (no name) - {C3B48746-C8C5-42DB-B803-F164DDEC1E55} - C:\WINDOWS\System32\pqkuaaau.dll O2 - BHO: (no name) - {E0887CD0-9049-4F2E-920E-9296B905C66D} - C:\WINDOWS\System32\geedb.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe O4 - HKCU\..\Run: [nvcdllx] C:\WINDOWS\System32\cstatvmq.exe O4 - HKCU\..\Run: [kdmmcvs] C:\WINDOWS\System32\gmonstml.exe O4 - HKCU\..\Run: [cmds] rundll32.exe C:\WINDOWS\System32\geedb.dll,CreateProtectProc O4 - Startup: .protected O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinpoeb.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com O16 - DPF: Video Poker - http://download.games.yahoo.com/game...s/y/vpt0_x.cab O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/game...ts/y/at1_x.cab O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/game...ts/y/xt0_x.cab O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/game...ts/y/jt0_x.cab O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/game...ts/y/kt4_x.cab O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/game...ts/y/ct2_x.cab O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game...ts/y/it1_x.cab O16 - DPF: Yahoo! Dice - http://download.games.yahoo.com/game...s/y/dct4_x.cab O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/game...ts/y/zt3_x.cab O16 - DPF: Yahoo! Klondike Solitaire - http://presence.games.yahoo.com/yog/y/ks12_x.cab O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/game...s/y/pyt1_x.cab O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/14939218...p/RdxIE601.cab O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab O20 - Winlogon Notify: geedb - C:\WINDOWS\System32\geedb.dll O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: ssqnllk - C:\WINDOWS\SYSTEM32\ssqnllk.dll O23 - Service: avgav.exe (AVG) - Unknown owner - C:\WINDOWS\avgav.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - C:\WINDOWS\alg.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe -- Files created between 2007-02-24 and 2007-03-24 ----------------------------- 2007-03-24 13:22:45 1997 --a------ C:\jishhs.exe 2007-03-24 13:22:30 26697 --a------ C:\WINDOWS\System32\pmnoonm.dll 2007-03-24 12:39:22 52674 --a------ C:\WINDOWS\System32\setup_56846.exe<SETUP_~1.EXE> 2007-03-24 12:34:45 26697 --a------ C:\WINDOWS\System32\fcccddd.dll 2007-03-24 12:09:27 280676 ---hs---- C:\WINDOWS\System32\mljjj.dll 2007-03-24 12:08:29 1208018 ---hs---- C:\WINDOWS\System32\bdeeg.ini2<BDEEG~1.INI> 2007-03-24 12:03:47 280676 ---hs---- C:\WINDOWS\System32\ssqrq.dll 2007-03-24 12:03:22 11264 --a------ C:\WINDOWS\System32\ocxloader.exe<OCXLOA~1.EXE> 2007-03-24 12:03:22 348160 --a------ C:\WINDOWS\System32\ocxapi.dll 2007-03-24 12:03:22 0 --a------ C:\WINDOWS\System32\ierplc.dll 2007-03-24 12:03:22 80 --a------ C:\WINDOWS\System32\iepref32.dll 2007-03-24 12:03:17 4608 --a------ C:\WINDOWS\System32\ips.dll 2007-03-24 12:03:14 53248 --a------ C:\WINDOWS\System32\icqmlib.exe 2007-03-24 12:01:15 280676 ---hs---- C:\WINDOWS\System32\sstqo.dll 2007-03-24 11:59:00 123972 --a------ C:\WINDOWS\System32\sqvyswsn.dll 2007-03-24 11:58:59 0 d-------- C:\Documents and Settings\Duane\Application Data\SearchToolbarCorp<SEARCH~1> 2007-03-24 11:58:50 132116 --a------ C:\WINDOWS\System32\pqkuaaau.dll 2007-03-24 11:58:46 0 d-------- C:\Program Files\VSAdd-in 2007-03-24 11:58:43 88340 --a------ C:\WINDOWS\System32\dyghasfc.exe 2007-03-24 11:58:42 1206759 ---hs---- C:\WINDOWS\System32\bdeeg.bak1<BDEEG~1.BAK> 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\WINDOWS 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Symantec 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\InterTrust<INTERT~1> 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Adobe 2007-03-24 11:58:21 280676 ---hs---- C:\WINDOWS\System32\geedb.dll 2007-03-24 11:58:21 1048576 --ah----- C:\Documents and Settings\Master Account\NTUSER.DAT 2007-03-24 11:53:13 596 --a------ C:\WINDOWS\System32\qmopt.dll 2007-03-24 11:52:57 26697 --a------ C:\WINDOWS\System32\ssqnllk.dll 2007-03-24 08:46:40 0 d-------- C:\WINDOWS\System32\Kaspersky Lab<KASPER~1> 2007-03-24 08:38:51 86016 -r-hs---- C:\WINDOWS\alg.exe 2007-03-24 08:38:42 69 --a------ C:\WINDOWS\System32\i 2007-03-21 21:17:04 52674 -r-hs---- C:\WINDOWS\avgav.exe 2007-03-20 20:18:18 0 d-------- C:\avenger 2007-03-19 21:14:12 0 d--h----- C:\WINDOWS\PIF 2007-03-13 20:51:18 136 --a------ C:\WINDOWS\System32\dgjun.bat 2007-03-12 18:20:25 491768 --a------ C:\ie6setup.exe 2007-03-11 22:17:35 0 d-------- C:\WINDOWS\System32\ActiveScan<ACTIVE~1> 2007-03-11 09:25:11 0 d-------- C:\Program Files\Java 2007-03-11 09:25:11 0 d-------- C:\Program Files\Common Files\Java 2007-03-11 09:24:21 0 d-------- C:\Documents and Settings\Duane\Application Data\Sun 2007-03-10 11:31:19 0 d-------- C:\Rustbfix 2007-03-08 19:33:08 49152 --a------ C:\Documents and Settings\Duane\vfind.exe 2007-03-08 19:33:08 79360 --a------ C:\Documents and Settings\Duane\swxcacls.exe 2007-03-08 19:33:08 123904 --a------ C:\Documents and Settings\Duane\swsc.exe 2007-03-08 19:33:08 140800 --a------ C:\Documents and Settings\Duane\swreg.exe 2007-03-08 19:33:08 8192 --a------ C:\Documents and Settings\Duane\RestartIt.exe<RESTAR~1.EXE> 2007-03-08 19:33:08 6914 --a------ C:\Documents and Settings\Duane\Qoo.bat 2007-03-08 19:33:08 971 --a------ C:\Documents and Settings\Duane\Purity.bat 2007-03-08 19:33:08 39184 --a------ C:\Documents and Settings\Duane\Ntrights.exe 2007-03-08 19:33:08 5074 --a------ C:\Documents and Settings\Duane\NTPBack.exe 2007-03-08 19:33:08 42887 --a------ C:\Documents and Settings\Duane\ntp.exe 2007-03-08 19:33:08 26112 --a------ C:\Documents and Settings\Duane\nircmd.exe 2007-03-08 19:33:08 38400 --a------ C:\Documents and Settings\Duane\moveex.exe 2007-03-08 19:33:08 2304 --a------ C:\Documents and Settings\Duane\Look2Me.bat 2007-03-08 19:33:08 117379 --a------ C:\Documents and Settings\Duane\LIST-C.bat 2007-03-08 19:33:08 181776 --a------ C:\Documents and Settings\Duane\handle.exe 2007-03-08 19:33:08 73728 --a------ C:\Documents and Settings\Duane\FDSV.EXE 2007-03-08 19:33:08 51200 --a------ C:\Documents and Settings\Duane\dumphive.exe 2007-03-08 19:33:08 319415 --a------ C:\Documents and Settings\Duane\Creg.reg 2007-03-08 19:33:08 28672 --a------ C:\Documents and Settings\Duane\catchme.exe 2007-02-24 21:33:14 53248 --a------ C:\WINDOWS\System32\Process.exe 2007-02-24 21:33:08 0 d-------- C:\SmitfraudFix<SMITFR~1> -- Find3M Report --------------------------------------------------------------- 2007-03-24 13:26:09 0 d-------- C:\Program Files\Hijack This<HIJACK~1> 2007-03-21 20:38:09 0 d-------- C:\Program Files\Picasa2 2007-03-21 20:36:13 0 d-------- C:\Program Files\Messenger<MESSEN~1> 2007-03-21 20:31:05 0 d-------- C:\Program Files\iTunes 2007-03-21 20:29:54 0 d-------- C:\Program Files\Google 2007-03-21 20:27:24 0 d-------- C:\Program Files\BigFix 2007-03-08 19:47:09 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1> 2007-02-24 22:08:44 3762 --a------ C:\WINDOWS\System32\tmp.reg 2007-02-21 21:42:31 129 --a------ C:\fix.bat 2007-02-21 18:24:56 0 d-------- C:\Program Files\backups 2007-02-20 21:14:12 0 d-------- C:\Program Files\Shockwave.com<SHOCKW~1.COM> 2007-02-13 21:29:11 0 d-------- C:\Program Files\Common Files\Sandlot Shared<SANDLO~1> 2007-02-10 20:00:13 14201 --a------ C:\Program Files\hijackthis.log<HIJACK~1.LOG> 2007-01-28 22:13:42 0 d-------- C:\Program Files\LG Software Innovations<LGSOFT~1> 2007-01-28 22:05:20 0 d-------- C:\Program Files\CloneDVD 2007-01-28 21:28:17 14 --a------ C:\WINDOWS\System32\systeminfo3.dll<SYSTEM~1.DLL> 2007-01-21 15:08:15 14612 --a------ C:\Program Files\CWSHREDDER.EXE-2D092FD4.pf<CWSHRE~1.PF> 2007-01-21 15:03:52 532480 --a------ C:\Program Files\cwshredder.exe<CWSHRE~1.EXE> 2007-01-13 14:32:20 0 --a------ C:\WINDOWS\System32\00BDDB65 2007-01-12 18:19:57 0 --a------ C:\WINDOWS\System32\vb2en16.dll 2007-01-12 18:19:50 1235 --a------ C:\WINDOWS\System32\openopenopen<OPENOP~2> 2007-01-12 18:19:34 0 --a------ C:\WINDOWS\System32\99239519 2007-01-11 16:35:52 1 --a------ C:\WINDOWS\System32\kr_done1 2007-01-11 16:35:33 12800 --a------ C:\WINDOWS\System32\svchost.exe 2007-01-11 16:33:19 0 --a------ C:\WINDOWS\System32\3718845C 2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\ps.dat 2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\cookie.dat 2007-01-07 13:16:52 25600 --a------ C:\WINDOWS\System32\helper.dll 2007-01-04 22:35:41 10660 --a------ C:\WINDOWS\mozver.dat 2007-01-03 20:49:11 5037072 --a------ C:\Program Files\spybotsd14.exe<SPYBOT~1.EXE> 2007-01-01 12:02:40 507 --a------ C:\WINDOWS\EReg077.dat 2006-12-25 16:33:11 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi<PLAINO~1.XPI> -- Registry Dump --------------------------------------------------------------- [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup" "DeluxeCommunications"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe" "nvcdllx"="C:\\WINDOWS\\System32\\cstatvmq.exe" "kdmmcvs"="C:\\WINDOWS\\System32\\gmonstml.exe" "cmds"="rundll32.exe C:\\WINDOWS\\System32\\geedb.dll,CreateProtectProc" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe" "Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe" "HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe" "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"" "HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP" "OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE" "FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe" "PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot" "SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SoundService"="rundll32.exe \"C:\\WINDOWS\\System32\\sqvyswsn.dll\",setvm" "icqmlib.exe"="icqmlib.exe" "ocxloader.exe"="C:\\WINDOWS\\System32\\ocxloader.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" "{85382E07-2F7E-4910-89AD-16F2E97FC152}"="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"=dword:00000001 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnllk [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 *newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_LANMANDRV -- End of Deckard's System Scanner: finished at 2007-03-24 at 13:26:49 --------- Molly Deckard's System Scanner v20070318.32 Run by Molly on 2007-03-24 at 13:41:48 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- HijackThis (run as Molly.exe) ----------------------------------------------- HijackThis failed to provide a log after three minutes; running clone instead. -- HijackThis Clone ------------------------------------------------------------ Emulating logfile of HijackThis v1.99.1 Scan saved at 2007-03-24 13:44:49 Platform: Windows XP Service Pack 1 (5.01.2600) MSIE: Internet Explorer (6.0.2800.1106) Running processes: C:\WINDOWS\system32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\avgav.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Grisoft\AVG7\avgamsvr.exe C:\Program Files\Grisoft\AVG7\avgupsvc.exe C:\Program Files\Grisoft\AVG7\avgemc.exe C:\WINDOWS\alg.exe C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\monitor.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Grisoft\AVG7\avgcc.exe C:\Program Files\Micro Innovations\Keyboard\KBDAP32A.EXE C:\Program Files\Micro Innovations\Mouse\mouse32a.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\WINDOWS\system32\icqmlib.exe C:\WINDOWS\system32\ocxloader.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\AWS\WeatherBug\Weather.exe C:\Program Files\BigFix\BigFix.exe C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe C:\WINDOWS\explorer.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Molly\Desktop\dss.exe C:\Program Files\Hijack This\Molly.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file) O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1846C0B3-8272-4FB3-A455-8F99FC0C0AF8} - C:\WINDOWS\system32\pqkuaaau.dll O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: (no name) - {85382E07-2F7E-4910-89AD-16F2E97FC152} - C:\WINDOWS\system32\ssqnllk.dll O2 - BHO: (no name) - {9273199F-9FC8-495F-B7FF-F15568877CFa} - C:\WINDOWS\system32\pqkuaaau.dll O2 - BHO: (no name) - {95F1789F-CDC6-401B-8A19-DBA1532F86Bb} - C:\WINDOWS\system32\pqkuaaau.dll O2 - BHO: (no name) - {97104B0B-8837-4EEE-ABE1-21842271B712} - C:\WINDOWS\system32\geedb.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar3.dll O2 - BHO: (no name) - {C3B48746-C8C5-42DB-B803-F164DDEC1E55} - C:\WINDOWS\system32\pqkuaaau.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar3.dll O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1 O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe" O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~2\bar\1.bin\mwsoemon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe O4 - HKCU\..\Run: [ymmsddlop] C:\WINDOWS\system32\vssmnptc.exe O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe O4 - HKCU\..\Run: [WinMedia] C:\DOCUME~1\Molly\LOCALS~1\Temp\257000.exe O4 - HKCU\..\Run: [BraveSentry] C:\Program Files\BraveSentry\BraveSentry.exe O4 - HKCU\..\Run: [gdxapimn] C:\WINDOWS\System32\jgdepgc.exe O4 - HKCU\..\Run: [nvcdllx] C:\WINDOWS\System32\cstatvmq.exe O4 - HKCU\..\Run: [csmhtop] C:\WINDOWS\System32\sdmmlmn.exe O4 - HKCU\..\Run: [ddsysmns] C:\WINDOWS\System32\scmdcon.exe O4 - HKCU\..\Run: [ncsmmlg] C:\WINDOWS\System32\ctlmems.exe O4 - HKCU\..\Run: [kdmmcvs] C:\WINDOWS\System32\gmonstml.exe O4 - HKCU\..\Run: [fcqlep] c:\windows\system32\fcqlep.exe fcqlep O4 - Startup: .protected O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinpoeb.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1 O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...p=ZUxdm080YYUS O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing) O9 - Extra 'Tools' menuitem: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing) O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra 'Tools' menuitem: (no name) - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: Video Poker () - http://download.games.yahoo.com/game...s/y/vpt0_x.cab O16 - DPF: Yahoo! Backgammon () - http://download.games.yahoo.com/game...ts/y/at1_x.cab O16 - DPF: Yahoo! Bingo () - http://download.games.yahoo.com/game...ts/y/xt0_x.cab O16 - DPF: Yahoo! Blackjack () - http://download.games.yahoo.com/game...ts/y/jt0_x.cab O16 - DPF: Yahoo! Checkers () - http://download.games.yahoo.com/game...ts/y/kt4_x.cab O16 - DPF: Yahoo! Chess () - http://download.games.yahoo.com/game...ts/y/ct2_x.cab O16 - DPF: Yahoo! Cribbage () - http://download.games.yahoo.com/game...ts/y/it1_x.cab O16 - DPF: Yahoo! Dice () - http://download.games.yahoo.com/game...s/y/dct4_x.cab O16 - DPF: Yahoo! Go Fish () - http://download.games.yahoo.com/game...ts/y/zt3_x.cab O16 - DPF: Yahoo! Klondike Solitaire () - http://presence.games.yahoo.com/yog/y/ks12_x.cab O16 - DPF: Yahoo! Poker () - http://download.games.yahoo.com/game...ts/y/pt3_x.cab O16 - DPF: Yahoo! Pyramids () - http://download.games.yahoo.com/game...s/y/pyt1_x.cab O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/downlo...367/wmavax.CAB O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/downlo...22/wmv9VCM.CAB O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} () - http://software-dl.real.com/14939218...p/RdxIE601.cab O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get...nt/swflash.cab O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab O18 - Protocol: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll O20 - Winlogon Notify: geedb - C:\WINDOWS\system32\geedb.dll O20 - Winlogon Notify: igfxcui - C:\WINDOWS\System32\igfxsrvc.dll O20 - Winlogon Notify: ssqnllk - C:\WINDOWS\System32\ssqnllk.dll O23 - Service: avgav.exe (AVG) - Unknown owner - "C:\WINDOWS\avgav.exe" O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgemc.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - Microsoft Corp., Veritas Software - C:\WINDOWS\System32\dmadmin.exe /com O23 - Service: Google Updater Service (gusvc) - Google - "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - "C:\WINDOWS\alg.exe" O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\Smc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe" O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - "C:\WINDOWS\wanmpsvc.exe" -- Files created between 2007-02-24 and 2007-03-24 ----------------------------- 2007-03-24 13:38:32 86016 --a------ C:\WINDOWS\System32\setup_44644.exe<SETUP_~2.EXE> 2007-03-24 13:36:47 1997 --a------ C:\jishhs.exe 2007-03-24 13:36:19 26697 --a------ C:\WINDOWS\System32\ssqqono.dll 2007-03-24 13:22:30 26697 --a------ C:\WINDOWS\System32\pmnoonm.dll 2007-03-24 12:39:22 52674 --a------ C:\WINDOWS\System32\setup_56846.exe<SETUP_~1.EXE> 2007-03-24 12:34:45 26697 --a------ C:\WINDOWS\System32\fcccddd.dll 2007-03-24 12:09:27 280676 ---hs---- C:\WINDOWS\System32\mljjj.dll 2007-03-24 12:08:29 1208018 ---hs---- C:\WINDOWS\System32\bdeeg.ini2<BDEEG~1.INI> 2007-03-24 12:03:47 280676 ---hs---- C:\WINDOWS\System32\ssqrq.dll 2007-03-24 12:03:22 11264 --a------ C:\WINDOWS\System32\ocxloader.exe<OCXLOA~1.EXE> 2007-03-24 12:03:22 348160 --a------ C:\WINDOWS\System32\ocxapi.dll 2007-03-24 12:03:22 0 --a------ C:\WINDOWS\System32\ierplc.dll 2007-03-24 12:03:22 80 --a------ C:\WINDOWS\System32\iepref32.dll 2007-03-24 12:03:17 4608 --a------ C:\WINDOWS\System32\ips.dll 2007-03-24 12:03:14 53248 --a------ C:\WINDOWS\System32\icqmlib.exe 2007-03-24 12:01:15 280676 ---hs---- C:\WINDOWS\System32\sstqo.dll 2007-03-24 11:59:00 123972 --a------ C:\WINDOWS\System32\sqvyswsn.dll 2007-03-24 11:58:59 0 d-------- C:\Documents and Settings\Duane\Application Data\SearchToolbarCorp<SEARCH~1> 2007-03-24 11:58:50 132116 --a------ C:\WINDOWS\System32\pqkuaaau.dll 2007-03-24 11:58:46 0 d-------- C:\Program Files\VSAdd-in 2007-03-24 11:58:43 88340 --a------ C:\WINDOWS\System32\dyghasfc.exe 2007-03-24 11:58:42 1206759 ---hs---- C:\WINDOWS\System32\bdeeg.bak1<BDEEG~1.BAK> 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\WINDOWS 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Symantec 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\InterTrust<INTERT~1> 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Adobe 2007-03-24 11:58:21 280676 ---hs---- C:\WINDOWS\System32\geedb.dll 2007-03-24 11:58:21 1048576 --ah----- C:\Documents and Settings\Master Account\NTUSER.DAT 2007-03-24 11:53:13 596 --a------ C:\WINDOWS\System32\qmopt.dll 2007-03-24 11:52:57 26697 --a------ C:\WINDOWS\System32\ssqnllk.dll 2007-03-24 08:46:40 0 d-------- C:\WINDOWS\System32\Kaspersky Lab<KASPER~1> 2007-03-24 08:38:51 86016 -r-hs---- C:\WINDOWS\alg.exe 2007-03-24 08:38:42 71 --a------ C:\WINDOWS\System32\i 2007-03-21 21:17:04 52674 -r-hs---- C:\WINDOWS\avgav.exe 2007-03-20 20:18:18 0 d-------- C:\avenger 2007-03-19 21:14:12 0 d--h----- C:\WINDOWS\PIF 2007-03-13 20:51:18 136 --a------ C:\WINDOWS\System32\dgjun.bat 2007-03-12 18:20:25 491768 --a------ C:\ie6setup.exe 2007-03-11 22:17:35 0 d-------- C:\WINDOWS\System32\ActiveScan<ACTIVE~1> 2007-03-11 09:25:11 0 d-------- C:\Program Files\Java 2007-03-11 09:25:11 0 d-------- C:\Program Files\Common Files\Java 2007-03-11 09:24:21 0 d-------- C:\Documents and Settings\Duane\Application Data\Sun 2007-03-10 11:31:19 0 d-------- C:\Rustbfix 2007-03-08 19:33:08 49152 --a------ C:\Documents and Settings\Duane\vfind.exe 2007-03-08 19:33:08 79360 --a------ C:\Documents and Settings\Duane\swxcacls.exe 2007-03-08 19:33:08 123904 --a------ C:\Documents and Settings\Duane\swsc.exe 2007-03-08 19:33:08 140800 --a------ C:\Documents and Settings\Duane\swreg.exe 2007-03-08 19:33:08 8192 --a------ C:\Documents and Settings\Duane\RestartIt.exe<RESTAR~1.EXE> 2007-03-08 19:33:08 6914 --a------ C:\Documents and Settings\Duane\Qoo.bat 2007-03-08 19:33:08 971 --a------ C:\Documents and Settings\Duane\Purity.bat 2007-03-08 19:33:08 39184 --a------ C:\Documents and Settings\Duane\Ntrights.exe 2007-03-08 19:33:08 5074 --a------ C:\Documents and Settings\Duane\NTPBack.exe 2007-03-08 19:33:08 42887 --a------ C:\Documents and Settings\Duane\ntp.exe 2007-03-08 19:33:08 26112 --a------ C:\Documents and Settings\Duane\nircmd.exe 2007-03-08 19:33:08 38400 --a------ C:\Documents and Settings\Duane\moveex.exe 2007-03-08 19:33:08 2304 --a------ C:\Documents and Settings\Duane\Look2Me.bat 2007-03-08 19:33:08 117379 --a------ C:\Documents and Settings\Duane\LIST-C.bat 2007-03-08 19:33:08 181776 --a------ C:\Documents and Settings\Duane\handle.exe 2007-03-08 19:33:08 73728 --a------ C:\Documents and Settings\Duane\FDSV.EXE 2007-03-08 19:33:08 51200 --a------ C:\Documents and Settings\Duane\dumphive.exe 2007-03-08 19:33:08 319415 --a------ C:\Documents and Settings\Duane\Creg.reg 2007-03-08 19:33:08 28672 --a------ C:\Documents and Settings\Duane\catchme.exe 2007-02-24 21:33:14 53248 --a------ C:\WINDOWS\System32\Process.exe 2007-02-24 21:33:08 0 d-------- C:\SmitfraudFix<SMITFR~1> -- Find3M Report --------------------------------------------------------------- 2007-03-24 13:41:50 0 d-------- C:\Program Files\Hijack This<HIJACK~1> 2007-03-24 13:36:38 0 d-------- C:\Documents and Settings\Molly\Application Data\WeatherBug<WEATHE~1> 2007-03-21 20:38:09 0 d-------- C:\Program Files\Picasa2 2007-03-21 20:36:13 0 d-------- C:\Program Files\Messenger<MESSEN~1> 2007-03-21 20:31:05 0 d-------- C:\Program Files\iTunes 2007-03-21 20:29:54 0 d-------- C:\Program Files\Google 2007-03-21 20:27:24 0 d-------- C:\Program Files\BigFix 2007-03-08 19:47:09 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1> 2007-02-24 22:08:44 3762 --a------ C:\WINDOWS\System32\tmp.reg 2007-02-21 21:42:31 129 --a------ C:\fix.bat 2007-02-21 18:24:56 0 d-------- C:\Program Files\backups 2007-02-20 21:14:12 0 d-------- C:\Program Files\Shockwave.com<SHOCKW~1.COM> 2007-02-13 21:29:11 0 d-------- C:\Program Files\Common Files\Sandlot Shared<SANDLO~1> 2007-02-10 20:00:13 14201 --a------ C:\Program Files\hijackthis.log<HIJACK~1.LOG> 2007-01-31 19:15:42 0 d-------- C:\Documents and Settings\Molly\Application Data\WinAntiVirus Pro 2006<WINANT~1> 2007-01-31 17:25:32 0 d-------- C:\Documents and Settings\Molly\Application Data\SearchToolbarCorp<SEARCH~1> 2007-01-28 22:13:42 0 d-------- C:\Program Files\LG Software Innovations<LGSOFT~1> 2007-01-28 22:05:20 0 d-------- C:\Program Files\CloneDVD 2007-01-28 21:28:17 14 --a------ C:\WINDOWS\System32\systeminfo3.dll<SYSTEM~1.DLL> 2007-01-21 15:08:15 14612 --a------ C:\Program Files\CWSHREDDER.EXE-2D092FD4.pf<CWSHRE~1.PF> 2007-01-21 15:03:52 532480 --a------ C:\Program Files\cwshredder.exe<CWSHRE~1.EXE> 2007-01-13 14:32:20 0 --a------ C:\WINDOWS\System32\00BDDB65 2007-01-12 18:19:57 0 --a------ C:\WINDOWS\System32\vb2en16.dll 2007-01-12 18:19:50 1235 --a------ C:\WINDOWS\System32\openopenopen<OPENOP~2> 2007-01-12 18:19:34 0 --a------ C:\WINDOWS\System32\99239519 2007-01-11 16:35:52 1 --a------ C:\WINDOWS\System32\kr_done1 2007-01-11 16:35:33 12800 --a------ C:\WINDOWS\System32\svchost.exe 2007-01-11 16:33:19 0 --a------ C:\WINDOWS\System32\3718845C 2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\ps.dat 2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\cookie.dat 2007-01-07 13:16:52 25600 --a------ C:\WINDOWS\System32\helper.dll 2007-01-04 22:35:41 10660 --a------ C:\WINDOWS\mozver.dat 2007-01-03 20:49:11 5037072 --a------ C:\Program Files\spybotsd14.exe<SPYBOT~1.EXE> 2007-01-01 12:02:40 507 --a------ C:\WINDOWS\EReg077.dat 2006-12-25 16:33:11 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi<PLAINO~1.XPI> -- Registry Dump --------------------------------------------------------------- [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "Microsoft Works Update Detection"="c:\\Program Files\\Microsoft Works\\WkDetect.exe" "Weather"="C:\\PROGRA~1\\AWS\\WEATHE~1\\Weather.exe 1" "WhenUSave"="\"C:\\Program Files\\Save\\Save.exe\"" "MyWebSearch Email Plugin"="C:\\PROGRA~1\\MYWEBS~2\\bar\\1.bin\\mwsoemon.exe" "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe" "DeluxeCommunications"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe" "ymmsddlop"="C:\\WINDOWS\\system32\\vssmnptc.exe" "Windows update loader"="C:\\Windows\\xpupdate.exe" "WinMedia"="C:\\DOCUME~1\\Molly\\LOCALS~1\\Temp\\257000.exe" "BraveSentry"="C:\\Program Files\\BraveSentry\\BraveSentry.exe" "gdxapimn"="C:\\WINDOWS\\System32\\jgdepgc.exe" "nvcdllx"="C:\\WINDOWS\\System32\\cstatvmq.exe" "csmhtop"="C:\\WINDOWS\\System32\\sdmmlmn.exe" "ddsysmns"="C:\\WINDOWS\\System32\\scmdcon.exe" "ncsmmlg"="C:\\WINDOWS\\System32\\ctlmems.exe" "kdmmcvs"="C:\\WINDOWS\\System32\\gmonstml.exe" "fcqlep"="c:\\windows\\system32\\fcqlep.exe fcqlep" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe" "Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe" "HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe" "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"" "HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP" "OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE" "FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe" "PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot" "SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SoundService"="rundll32.exe \"C:\\WINDOWS\\System32\\sqvyswsn.dll\",setvm" "icqmlib.exe"="icqmlib.exe" "ocxloader.exe"="C:\\WINDOWS\\System32\\ocxloader.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" "{85382E07-2F7E-4910-89AD-16F2E97FC152}"="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"=dword:00000001 "Wallpaper"="C:\\WINDOWS\\desktop.html" "DisableRegistryTools"=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoActiveDesktop"=dword:00000000 "ForceActiveDesktopOn"=dword:00000001 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnllk [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 -- End of Deckard's System Scanner: finished at 2007-03-24 at 13:45:27 --------- End of Posts Last edited by cul8rman; 03-24-2007 at 04:38 PM. |
|
|
|
|
#86 (permalink) |
|
Registered User
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP
|
Re: MS Windows XP will not load when connected to internet
last post was too long - part 2
Robyn Deckard's System Scanner v20070318.32 Run by Robyn on 2007-03-24 at 14:33:53 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- HijackThis (run as Robyn.exe) ----------------------------------------------- HijackThis failed to provide a log after three minutes; running clone instead. -- HijackThis Clone ------------------------------------------------------------ Emulating logfile of HijackThis v1.99.1 Scan saved at 2007-03-24 14:36:54 Platform: Windows XP Service Pack 1 (5.01.2600) MSIE: Internet Explorer (6.0.2800.1106) Running processes: C:\WINDOWS\system32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\avgav.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Grisoft\AVG7\avgamsvr.exe C:\Program Files\Grisoft\AVG7\avgupsvc.exe C:\Program Files\Grisoft\AVG7\avgemc.exe C:\WINDOWS\alg.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\explorer.exe C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\monitor.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Grisoft\AVG7\avgcc.exe C:\Program Files\Micro Innovations\Keyboard\KBDAP32A.EXE C:\Program Files\Micro Innovations\Mouse\mouse32a.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\BigFix\BigFix.exe C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe C:\Documents and Settings\Robyn\Desktop\dss.exe C:\Program Files\Hijack This\Robyn.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file) O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {0EB01745-660A-479E-883F-68353CB8F306} - C:\WINDOWS\system32\pqkuaaau.dll O2 - BHO: (no name) - {1846C0B3-8272-4FB3-A455-8F99FC0C0AF8} - C:\WINDOWS\system32\pqkuaaau.dll O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {5AA3E953-FCEB-4BB9-898A-BB688352DD01} - C:\WINDOWS\system32\geedb.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: (no name) - {85382E07-2F7E-4910-89AD-16F2E97FC152} - C:\WINDOWS\system32\ssqnllk.dll O2 - BHO: (no name) - {9273199F-9FC8-495F-B7FF-F15568877CFa} - C:\WINDOWS\system32\pqkuaaau.dll O2 - BHO: (no name) - {95F1789F-CDC6-401B-8A19-DBA1532F86Bb} - C:\WINDOWS\system32\pqkuaaau.dll O2 - BHO: (no name) - {A42B8C8C-4323-4B95-8E98-1A302D7F6959} - C:\WINDOWS\system32\pqkuaaau.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar3.dll O2 - BHO: (no name) - {C3B48746-C8C5-42DB-B803-F164DDEC1E55} - C:\WINDOWS\system32\pqkuaaau.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar3.dll O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe O4 - HKCU\..\Run: [lsmdwinr] C:\WINDOWS\System32\vstldmem.exe O4 - HKCU\..\Run: [winksddm] C:\WINDOWS\System32\jvmmods.exe O4 - HKCU\..\Run: [gdxapimn] C:\WINDOWS\System32\jgdepgc.exe O4 - HKCU\..\Run: [nvcdllx] C:\WINDOWS\System32\cstatvmq.exe O4 - HKCU\..\Run: [csmhtop] C:\WINDOWS\System32\sdmmlmn.exe O4 - HKCU\..\Run: [ncsmmlg] C:\WINDOWS\System32\ctlmems.exe O4 - HKCU\..\Run: [ddsysmns] C:\WINDOWS\System32\scmdcon.exe O4 - HKCU\..\Run: [kdmmcvs] C:\WINDOWS\System32\gmonstml.exe O4 - Startup: .protected O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinpoeb.exe O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing) O9 - Extra 'Tools' menuitem: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing) O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra 'Tools' menuitem: (no name) - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: Video Poker () - http://download.games.yahoo.com/game...s/y/vpt0_x.cab O16 - DPF: Yahoo! Backgammon () - http://download.games.yahoo.com/game...ts/y/at1_x.cab O16 - DPF: Yahoo! Bingo () - http://download.games.yahoo.com/game...ts/y/xt0_x.cab O16 - DPF: Yahoo! Blackjack () - http://download.games.yahoo.com/game...ts/y/jt0_x.cab O16 - DPF: Yahoo! Checkers () - http://download.games.yahoo.com/game...ts/y/kt4_x.cab O16 - DPF: Yahoo! Chess () - http://download.games.yahoo.com/game...ts/y/ct2_x.cab O16 - DPF: Yahoo! Cribbage () - http://download.games.yahoo.com/game...ts/y/it1_x.cab O16 - DPF: Yahoo! Dice () - http://download.games.yahoo.com/game...s/y/dct4_x.cab O16 - DPF: Yahoo! Go Fish () - http://download.games.yahoo.com/game...ts/y/zt3_x.cab O16 - DPF: Yahoo! Klondike Solitaire () - http://presence.games.yahoo.com/yog/y/ks12_x.cab O16 - DPF: Yahoo! Poker () - http://download.games.yahoo.com/game...ts/y/pt3_x.cab O16 - DPF: Yahoo! Pyramids () - http://download.games.yahoo.com/game...s/y/pyt1_x.cab O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/downlo...367/wmavax.CAB O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/downlo...22/wmv9VCM.CAB O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} () - http://software-dl.real.com/14939218...p/RdxIE601.cab O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get...nt/swflash.cab O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab O18 - Protocol: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll O20 - Winlogon Notify: geedb - C:\WINDOWS\system32\geedb.dll O20 - Winlogon Notify: igfxcui - C:\WINDOWS\System32\igfxsrvc.dll O20 - Winlogon Notify: ssqnllk - C:\WINDOWS\System32\ssqnllk.dll O23 - Service: avgav.exe (AVG) - Unknown owner - "C:\WINDOWS\avgav.exe" O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgemc.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - Microsoft Corp., Veritas Software - C:\WINDOWS\System32\dmadmin.exe /com O23 - Service: Google Updater Service (gusvc) - Google - "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - "C:\WINDOWS\alg.exe" O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\Smc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe" O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - "C:\WINDOWS\wanmpsvc.exe" -- Files created between 2007-02-24 and 2007-03-24 ----------------------------- 2007-03-24 14:15:41 72192 --a------ C:\snm.exe 2007-03-24 14:15:34 26697 --a------ C:\WINDOWS\System32\urqoljk.dll 2007-03-24 13:38:32 86016 --a------ C:\WINDOWS\System32\setup_44644.exe<SETUP_~2.EXE> 2007-03-24 13:36:19 26697 --a------ C:\WINDOWS\System32\ssqqono.dll 2007-03-24 13:22:30 26697 --a------ C:\WINDOWS\System32\pmnoonm.dll 2007-03-24 12:39:22 52674 --a------ C:\WINDOWS\System32\setup_56846.exe<SETUP_~1.EXE> 2007-03-24 12:34:45 26697 --a------ C:\WINDOWS\System32\fcccddd.dll 2007-03-24 12:09:27 280676 ---hs---- C:\WINDOWS\System32\mljjj.dll 2007-03-24 12:08:29 1208018 ---hs---- C:\WINDOWS\System32\bdeeg.ini2<BDEEG~1.INI> 2007-03-24 12:03:47 280676 ---hs---- C:\WINDOWS\System32\ssqrq.dll 2007-03-24 12:03:22 11264 --a------ C:\WINDOWS\System32\ocxloader.exe<OCXLOA~1.EXE> 2007-03-24 12:03:22 348160 --a------ C:\WINDOWS\System32\ocxapi.dll 2007-03-24 12:03:22 0 --a------ C:\WINDOWS\System32\ierplc.dll 2007-03-24 12:03:22 80 --a------ C:\WINDOWS\System32\iepref32.dll 2007-03-24 12:03:17 4608 --a------ C:\WINDOWS\System32\ips.dll 2007-03-24 12:03:14 53248 --a------ C:\WINDOWS\System32\icqmlib.exe 2007-03-24 12:01:15 280676 ---hs---- C:\WINDOWS\System32\sstqo.dll 2007-03-24 11:59:00 123972 --a------ C:\WINDOWS\System32\sqvyswsn.dll 2007-03-24 11:58:59 0 d-------- C:\Documents and Settings\Duane\Application Data\SearchToolbarCorp<SEARCH~1> 2007-03-24 11:58:50 132116 --a------ C:\WINDOWS\System32\pqkuaaau.dll 2007-03-24 11:58:46 0 d-------- C:\Program Files\VSAdd-in 2007-03-24 11:58:43 88340 --a------ C:\WINDOWS\System32\dyghasfc.exe 2007-03-24 11:58:42 1206759 ---hs---- C:\WINDOWS\System32\bdeeg.bak1<BDEEG~1.BAK> 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\WINDOWS 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Symantec 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\InterTrust<INTERT~1> 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Adobe 2007-03-24 11:58:21 280676 ---hs---- C:\WINDOWS\System32\geedb.dll 2007-03-24 11:58:21 1048576 --ah----- C:\Documents and Settings\Master Account\NTUSER.DAT 2007-03-24 11:53:13 596 --a------ C:\WINDOWS\System32\qmopt.dll 2007-03-24 11:52:57 26697 --a------ C:\WINDOWS\System32\ssqnllk.dll 2007-03-24 08:46:40 0 d-------- C:\WINDOWS\System32\Kaspersky Lab<KASPER~1> 2007-03-24 08:38:51 86016 -r-hs---- C:\WINDOWS\alg.exe 2007-03-24 08:38:42 71 --a------ C:\WINDOWS\System32\i 2007-03-21 21:17:04 52674 -r-hs---- C:\WINDOWS\avgav.exe 2007-03-20 20:18:18 0 d-------- C:\avenger 2007-03-19 21:14:12 0 d--h----- C:\WINDOWS\PIF 2007-03-13 20:51:18 136 --a------ C:\WINDOWS\System32\dgjun.bat 2007-03-12 18:20:25 491768 --a------ C:\ie6setup.exe 2007-03-11 22:17:35 0 d-------- C:\WINDOWS\System32\ActiveScan<ACTIVE~1> 2007-03-11 09:25:11 0 d-------- C:\Program Files\Java 2007-03-11 09:25:11 0 d-------- C:\Program Files\Common Files\Java 2007-03-11 09:24:21 0 d-------- C:\Documents and Settings\Duane\Application Data\Sun 2007-03-10 11:31:19 0 d-------- C:\Rustbfix 2007-03-08 19:33:08 49152 --a------ C:\Documents and Settings\Duane\vfind.exe 2007-03-08 19:33:08 79360 --a------ C:\Documents and Settings\Duane\swxcacls.exe 2007-03-08 19:33:08 123904 --a------ C:\Documents and Settings\Duane\swsc.exe 2007-03-08 19:33:08 140800 --a------ C:\Documents and Settings\Duane\swreg.exe 2007-03-08 19:33:08 8192 --a------ C:\Documents and Settings\Duane\RestartIt.exe<RESTAR~1.EXE> 2007-03-08 19:33:08 6914 --a------ C:\Documents and Settings\Duane\Qoo.bat 2007-03-08 19:33:08 971 --a------ C:\Documents and Settings\Duane\Purity.bat 2007-03-08 19:33:08 39184 --a------ C:\Documents and Settings\Duane\Ntrights.exe 2007-03-08 19:33:08 5074 --a------ C:\Documents and Settings\Duane\NTPBack.exe 2007-03-08 19:33:08 42887 --a------ C:\Documents and Settings\Duane\ntp.exe 2007-03-08 19:33:08 26112 --a------ C:\Documents and Settings\Duane\nircmd.exe 2007-03-08 19:33:08 38400 --a------ C:\Documents and Settings\Duane\moveex.exe 2007-03-08 19:33:08 2304 --a------ C:\Documents and Settings\Duane\Look2Me.bat 2007-03-08 19:33:08 117379 --a------ C:\Documents and Settings\Duane\LIST-C.bat 2007-03-08 19:33:08 181776 --a------ C:\Documents and Settings\Duane\handle.exe 2007-03-08 19:33:08 73728 --a------ C:\Documents and Settings\Duane\FDSV.EXE 2007-03-08 19:33:08 51200 --a------ C:\Documents and Settings\Duane\dumphive.exe 2007-03-08 19:33:08 319415 --a------ C:\Documents and Settings\Duane\Creg.reg 2007-03-08 19:33:08 28672 --a------ C:\Documents and Settings\Duane\catchme.exe 2007-02-24 21:33:14 53248 --a------ C:\WINDOWS\System32\Process.exe 2007-02-24 21:33:08 0 d-------- C:\SmitfraudFix<SMITFR~1> -- Find3M Report --------------------------------------------------------------- 2007-03-24 14:33:54 0 d-------- C:\Program Files\Hijack This<HIJACK~1> 2007-03-21 20:38:09 0 d-------- C:\Program Files\Picasa2 2007-03-21 20:36:13 0 d-------- C:\Program Files\Messenger<MESSEN~1> 2007-03-21 20:31:05 0 d-------- C:\Program Files\iTunes 2007-03-21 20:29:54 0 d-------- C:\Program Files\Google 2007-03-21 20:27:24 0 d-------- C:\Program Files\BigFix 2007-03-08 19:47:09 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1> 2007-02-24 22:08:44 3762 --a------ C:\WINDOWS\System32\tmp.reg 2007-02-21 21:42:31 129 --a------ C:\fix.bat 2007-02-21 18:24:56 0 d-------- C:\Program Files\backups 2007-02-20 21:14:12 0 d-------- C:\Program Files\Shockwave.com<SHOCKW~1.COM> 2007-02-13 21:29:11 0 d-------- C:\Program Files\Common Files\Sandlot Shared<SANDLO~1> 2007-02-10 20:00:13 14201 --a------ C:\Program Files\hijackthis.log<HIJACK~1.LOG> 2007-01-28 22:13:42 0 d-------- C:\Program Files\LG Software Innovations<LGSOFT~1> 2007-01-28 22:05:20 0 d-------- C:\Program Files\CloneDVD 2007-01-28 21:28:17 14 --a------ C:\WINDOWS\System32\systeminfo3.dll<SYSTEM~1.DLL> 2007-01-26 17:12:29 0 d-------- C:\Documents and Settings\Robyn\Application Data\SearchToolbarCorp<SEARCH~1> 2007-01-26 17:07:02 0 d-------- C:\Documents and Settings\Robyn\Application Data\Ultimate Cleaner<ULTIMA~2> 2007-01-21 15:08:15 14612 --a------ C:\Program Files\CWSHREDDER.EXE-2D092FD4.pf<CWSHRE~1.PF> 2007-01-21 15:03:52 532480 --a------ C:\Program Files\cwshredder.exe<CWSHRE~1.EXE> 2007-01-13 14:32:20 0 --a------ C:\WINDOWS\System32\00BDDB65 2007-01-12 18:19:57 0 --a------ C:\WINDOWS\System32\vb2en16.dll 2007-01-12 18:19:50 1235 --a------ C:\WINDOWS\System32\openopenopen<OPENOP~2> 2007-01-12 18:19:34 0 --a------ C:\WINDOWS\System32\99239519 2007-01-11 16:35:52 1 --a------ C:\WINDOWS\System32\kr_done1 2007-01-11 16:35:33 12800 --a------ C:\WINDOWS\System32\svchost.exe 2007-01-11 16:33:19 0 --a------ C:\WINDOWS\System32\3718845C 2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\ps.dat 2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\cookie.dat 2007-01-07 13:16:52 25600 --a------ C:\WINDOWS\System32\helper.dll 2007-01-04 22:35:41 10660 --a------ C:\WINDOWS\mozver.dat 2007-01-03 20:49:11 5037072 --a------ C:\Program Files\spybotsd14.exe<SPYBOT~1.EXE> 2007-01-01 12:02:40 507 --a------ C:\WINDOWS\EReg077.dat 2006-12-25 16:33:11 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi<PLAINO~1.XPI> -- Registry Dump --------------------------------------------------------------- [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe" "DeluxeCommunications"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe" "lsmdwinr"="C:\\WINDOWS\\System32\\vstldmem.exe" "winksddm"="C:\\WINDOWS\\System32\\jvmmods.exe" "gdxapimn"="C:\\WINDOWS\\System32\\jgdepgc.exe" "nvcdllx"="C:\\WINDOWS\\System32\\cstatvmq.exe" "csmhtop"="C:\\WINDOWS\\System32\\sdmmlmn.exe" "ncsmmlg"="C:\\WINDOWS\\System32\\ctlmems.exe" "ddsysmns"="C:\\WINDOWS\\System32\\scmdcon.exe" "kdmmcvs"="C:\\WINDOWS\\System32\\gmonstml.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe" "Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe" "HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe" "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"" "HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP" "OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE" "FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe" "PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot" "SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SoundService"="rundll32.exe \"C:\\WINDOWS\\System32\\sqvyswsn.dll\",setvm" "icqmlib.exe"="icqmlib.exe" "ocxloader.exe"="C:\\WINDOWS\\System32\\ocxloader.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" "{85382E07-2F7E-4910-89AD-16F2E97FC152}"="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableRegistryTools"=dword:00000000 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnllk [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 *newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_LANMANDRV -- End of Deckard's System Scanner: finished at 2007-03-24 at 14:37:23 --------- ************** Master Account Deckard's System Scanner v20070318.32 Run by Master Account on 2007-03-24 at 12:36:18 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- HijackThis (run as Master Account.exe) -------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 12:36:25 PM, on 3/24/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\avgav.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\alg.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\Program Files\iTunes\iTunesHelper.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE C:\Program Files\Micro Innovations\Mouse\mouse32a.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\WINDOWS\System32\icqmlib.exe C:\WINDOWS\System32\ocxloader.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\BigFix\BigFix.exe C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe C:\Program Files\iPod\bin\iPodService.exe C:\Documents and Settings\Master Account\Desktop\dss.exe C:\PROGRA~1\HIJACK~1\MASTER~1.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/ O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1846C0B3-8272-4FB3-A455-8F99FC0C0AF8} - C:\WINDOWS\System32\pqkuaaau.dll O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: (no name) - {2D295940-2ADE-4BD2-82DC-A7390260E459} - C:\WINDOWS\System32\geedb.dll O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: (no name) - {85382E07-2F7E-4910-89AD-16F2E97FC152} - C:\WINDOWS\System32\ssqnllk.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: (no name) - {C3B48746-C8C5-42DB-B803-F164DDEC1E55} - C:\WINDOWS\System32\pqkuaaau.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com O16 - DPF: Video Poker - http://download.games.yahoo.com/game...s/y/vpt0_x.cab O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/game...ts/y/at1_x.cab O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/game...ts/y/xt0_x.cab O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/game...ts/y/jt0_x.cab O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/game...ts/y/kt4_x.cab O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/game...ts/y/ct2_x.cab O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game...ts/y/it1_x.cab O16 - DPF: Yahoo! Dice - http://download.games.yahoo.com/game...s/y/dct4_x.cab O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/game...ts/y/zt3_x.cab O16 - DPF: Yahoo! Klondike Solitaire - http://presence.games.yahoo.com/yog/y/ks12_x.cab O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/game...s/y/pyt1_x.cab O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/14939218...p/RdxIE601.cab O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab O20 - Winlogon Notify: geedb - C:\WINDOWS\System32\geedb.dll O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: ssqnllk - C:\WINDOWS\SYSTEM32\ssqnllk.dll O23 - Service: avgav.exe (AVG) - Unknown owner - C:\WINDOWS\avgav.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - C:\WINDOWS\alg.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe -- Files created between 2007-02-24 and 2007-03-24 ----------------------------- 2007-03-24 12:35:09 1997 --a------ C:\jishhs.exe 2007-03-24 12:34:45 26697 --a------ C:\WINDOWS\System32\fcccddd.dll 2007-03-24 12:09:27 280676 ---hs---- C:\WINDOWS\System32\mljjj.dll 2007-03-24 12:08:29 1208018 ---hs---- C:\WINDOWS\System32\bdeeg.ini2<BDEEG~1.INI> 2007-03-24 12:03:47 280676 ---hs---- C:\WINDOWS\System32\ssqrq.dll 2007-03-24 12:03:22 11264 --a------ C:\WINDOWS\System32\ocxloader.exe<OCXLOA~1.EXE> 2007-03-24 12:03:22 348160 --a------ C:\WINDOWS\System32\ocxapi.dll 2007-03-24 12:03:22 0 --a------ C:\WINDOWS\System32\ierplc.dll 2007-03-24 12:03:22 80 --a------ C:\WINDOWS\System32\iepref32.dll 2007-03-24 12:03:17 4608 --a------ C:\WINDOWS\System32\ips.dll 2007-03-24 12:03:14 53248 --a------ C:\WINDOWS\System32\icqmlib.exe 2007-03-24 12:01:15 280676 ---hs---- C:\WINDOWS\System32\sstqo.dll 2007-03-24 11:59:00 123972 --a------ C:\WINDOWS\System32\sqvyswsn.dll 2007-03-24 11:58:59 0 d-------- C:\Documents and Settings\Duane\Application Data\SearchToolbarCorp<SEARCH~1> 2007-03-24 11:58:50 132116 --a------ C:\WINDOWS\System32\pqkuaaau.dll 2007-03-24 11:58:46 0 d-------- C:\Program Files\VSAdd-in 2007-03-24 11:58:43 88340 --a------ C:\WINDOWS\System32\dyghasfc.exe 2007-03-24 11:58:42 1206759 ---hs---- C:\WINDOWS\System32\bdeeg.bak1<BDEEG~1.BAK> 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\WINDOWS 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Symantec 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\InterTrust<INTERT~1> 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Adobe 2007-03-24 11:58:21 280676 ---hs---- C:\WINDOWS\System32\geedb.dll 2007-03-24 11:58:21 1048576 --ah----- C:\Documents and Settings\Master Account\NTUSER.DAT 2007-03-24 11:53:13 596 --a------ C:\WINDOWS\System32\qmopt.dll 2007-03-24 11:52:57 26697 --a------ C:\WINDOWS\System32\ssqnllk.dll 2007-03-24 08:46:40 0 d-------- C:\WINDOWS\System32\Kaspersky Lab<KASPER~1> 2007-03-24 08:38:51 86016 -r-hs---- C:\WINDOWS\alg.exe 2007-03-24 08:38:42 68 --a------ C:\WINDOWS\System32\i 2007-03-21 21:17:04 52674 -r-hs---- C:\WINDOWS\avgav.exe 2007-03-20 20:18:18 0 d-------- C:\avenger 2007-03-19 21:14:12 0 d--h----- C:\WINDOWS\PIF 2007-03-13 20:51:18 136 --a------ C:\WINDOWS\System32\dgjun.bat 2007-03-12 18:20:25 491768 --a------ C:\ie6setup.exe 2007-03-11 22:17:35 0 d-------- C:\WINDOWS\System32\ActiveScan<ACTIVE~1> 2007-03-11 09:25:11 0 d-------- C:\Program Files\Java 2007-03-11 09:25:11 0 d-------- C:\Program Files\Common Files\Java 2007-03-11 09:24:21 0 d-------- C:\Documents and Settings\Duane\Application Data\Sun 2007-03-10 11:31:19 0 d-------- C:\Rustbfix 2007-03-08 19:33:08 49152 --a------ C:\Documents and Settings\Duane\vfind.exe 2007-03-08 19:33:08 79360 --a------ C:\Documents and Settings\Duane\swxcacls.exe 2007-03-08 19:33:08 123904 --a------ C:\Documents and Settings\Duane\swsc.exe 2007-03-08 19:33:08 140800 --a------ C:\Documents and Settings\Duane\swreg.exe 2007-03-08 19:33:08 8192 --a------ C:\Documents and Settings\Duane\RestartIt.exe<RESTAR~1.EXE> 2007-03-08 19:33:08 6914 --a------ C:\Documents and Settings\Duane\Qoo.bat 2007-03-08 19:33:08 971 --a------ C:\Documents and Settings\Duane\Purity.bat 2007-03-08 19:33:08 39184 --a------ C:\Documents and Settings\Duane\Ntrights.exe 2007-03-08 19:33:08 5074 --a------ C:\Documents and Settings\Duane\NTPBack.exe 2007-03-08 19:33:08 42887 --a------ C:\Documents and Settings\Duane\ntp.exe 2007-03-08 19:33:08 26112 --a------ C:\Documents and Settings\Duane\nircmd.exe 2007-03-08 19:33:08 38400 --a------ C:\Documents and Settings\Duane\moveex.exe 2007-03-08 19:33:08 2304 --a------ C:\Documents and Settings\Duane\Look2Me.bat 2007-03-08 19:33:08 117379 --a------ C:\Documents and Settings\Duane\LIST-C.bat 2007-03-08 19:33:08 181776 --a------ C:\Documents and Settings\Duane\handle.exe 2007-03-08 19:33:08 73728 --a------ C:\Documents and Settings\Duane\FDSV.EXE 2007-03-08 19:33:08 51200 --a------ C:\Documents and Settings\Duane\dumphive.exe 2007-03-08 19:33:08 319415 --a------ C:\Documents and Settings\Duane\Creg.reg 2007-03-08 19:33:08 28672 --a------ C:\Documents and Settings\Duane\catchme.exe 2007-02-24 21:33:14 53248 --a------ C:\WINDOWS\System32\Process.exe 2007-02-24 21:33:08 0 d-------- C:\SmitfraudFix<SMITFR~1> -- Find3M Report --------------------------------------------------------------- 2007-03-24 12:36:19 0 d-------- C:\Program Files\Hijack This<HIJACK~1> 2007-03-24 11:59:31 0 d-------- C:\Documents and Settings\Master Account\Application Data\Mozilla 2007-03-24 11:59:17 0 d-------- C:\Documents and Settings\Master Account\Application Data\AVG7 2007-03-21 20:38:09 0 d-------- C:\Program Files\Picasa2 2007-03-21 20:36:13 0 d-------- C:\Program Files\Messenger<MESSEN~1> 2007-03-21 20:31:05 0 d-------- C:\Program Files\iTunes 2007-03-21 20:29:54 0 d-------- C:\Program Files\Google 2007-03-21 20:27:24 0 d-------- C:\Program Files\BigFix 2007-03-08 19:47:09 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1> 2007-02-24 22:08:44 3762 --a------ C:\WINDOWS\System32\tmp.reg 2007-02-21 21:42:31 129 --a------ C:\fix.bat 2007-02-21 18:24:56 0 d-------- C:\Program Files\backups 2007-02-20 21:14:12 0 d-------- C:\Program Files\Shockwave.com<SHOCKW~1.COM> 2007-02-13 21:29:11 0 d-------- C:\Program Files\Common Files\Sandlot Shared<SANDLO~1> 2007-02-10 20:00:13 14201 --a------ C:\Program Files\hijackthis.log<HIJACK~1.LOG> 2007-01-28 22:13:42 0 d-------- C:\Program Files\LG Software Innovations<LGSOFT~1> 2007-01-28 22:05:20 0 d-------- C:\Program Files\CloneDVD 2007-01-28 21:28:17 14 --a------ C:\WINDOWS\System32\systeminfo3.dll<SYSTEM~1.DLL> 2007-01-21 15:08:15 14612 --a------ C:\Program Files\CWSHREDDER.EXE-2D092FD4.pf<CWSHRE~1.PF> 2007-01-21 15:03:52 532480 --a------ C:\Program Files\cwshredder.exe<CWSHRE~1.EXE> 2007-01-13 14:32:20 0 --a------ C:\WINDOWS\System32\00BDDB65 2007-01-12 18:19:57 0 --a------ C:\WINDOWS\System32\vb2en16.dll 2007-01-12 18:19:50 1235 --a------ C:\WINDOWS\System32\openopenopen<OPENOP~2> 2007-01-12 18:19:34 0 --a------ C:\WINDOWS\System32\99239519 2007-01-11 16:35:52 1 --a------ C:\WINDOWS\System32\kr_done1 2007-01-11 16:35:33 12800 --a------ C:\WINDOWS\System32\svchost.exe 2007-01-11 16:33:19 0 --a------ C:\WINDOWS\System32\3718845C 2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\ps.dat 2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\cookie.dat 2007-01-07 13:16:52 25600 --a------ C:\WINDOWS\System32\helper.dll 2007-01-04 22:35:41 10660 --a------ C:\WINDOWS\mozver.dat 2007-01-03 20:49:11 5037072 --a------ C:\Program Files\spybotsd14.exe<SPYBOT~1.EXE> 2007-01-01 12:02:40 507 --a------ C:\WINDOWS\EReg077.dat 2006-12-25 16:33:11 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi<PLAINO~1.XPI> -- Registry Dump --------------------------------------------------------------- [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe" "Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe" "HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe" "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"" "HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP" "OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE" "FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe" "PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot" "SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SoundService"="rundll32.exe \"C:\\WINDOWS\\System32\\sqvyswsn.dll\",setvm" "icqmlib.exe"="icqmlib.exe" "ocxloader.exe"="C:\\WINDOWS\\System32\\ocxloader.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" "{85382E07-2F7E-4910-89AD-16F2E97FC152}"="" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnllk [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 -- End of Deckard's System Scanner: finished at 2007-03-24 at 12:36:57 --------- ******* Others Deckard's System Scanner v20070318.32 Run by Others on 2007-03-24 at 14:21:43 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- HijackThis (run as Others.exe) ---------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 2:21:50 PM, on 3/24/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\avgav.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\alg.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\Program Files\iTunes\iTunesHelper.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE C:\Program Files\Micro Innovations\Mouse\mouse32a.exe C:\PROGRA~1\Sygate\SPF\smc.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\WINDOWS\System32\icqmlib.exe C:\WINDOWS\System32\ocxloader.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\BigFix\BigFix.exe C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Documents and Settings\Others\Desktop\dss.exe C:\PROGRA~1\HIJACK~1\Others.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/ R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file) O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {0EB01745-660A-479E-883F-68353CB8F306} - C:\WINDOWS\System32\pqkuaaau.dll O2 - BHO: (no name) - {1846C0B3-8272-4FB3-A455-8F99FC0C0AF8} - C:\WINDOWS\System32\pqkuaaau.dll O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {5AA3E953-FCEB-4BB9-898A-BB688352DD01} - C:\WINDOWS\System32\geedb.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: (no name) - {85382E07-2F7E-4910-89AD-16F2E97FC152} - C:\WINDOWS\System32\ssqnllk.dll O2 - BHO: (no name) - {9273199F-9FC8-495F-B7FF-F15568877CFa} - C:\WINDOWS\System32\pqkuaaau.dll O2 - BHO: (no name) - {95F1789F-CDC6-401B-8A19-DBA1532F86Bb} - C:\WINDOWS\System32\pqkuaaau.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: (no name) - {C3B48746-C8C5-42DB-B803-F164DDEC1E55} - C:\WINDOWS\System32\pqkuaaau.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe O4 - Startup: .protected O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinpoeb.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com O16 - DPF: Video Poker - http://download.games.yahoo.com/game...s/y/vpt0_x.cab O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/game...ts/y/at1_x.cab O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/game...ts/y/xt0_x.cab O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/game...ts/y/jt0_x.cab O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/game...ts/y/kt4_x.cab O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/game...ts/y/ct2_x.cab O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game...ts/y/it1_x.cab O16 - DPF: Yahoo! Dice - http://download.games.yahoo.com/game...s/y/dct4_x.cab O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/game...ts/y/zt3_x.cab O16 - DPF: Yahoo! Klondike Solitaire - http://presence.games.yahoo.com/yog/y/ks12_x.cab O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/game...s/y/pyt1_x.cab O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/14939218...p/RdxIE601.cab O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab O20 - Winlogon Notify: geedb - C:\WINDOWS\System32\geedb.dll O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: ssqnllk - C:\WINDOWS\SYSTEM32\ssqnllk.dll O23 - Service: avgav.exe (AVG) - Unknown owner - C:\WINDOWS\avgav.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - C:\WINDOWS\alg.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe -- Files created between 2007-02-24 and 2007-03-24 ----------------------------- 2007-03-24 14:15:41 72192 --a------ C:\snm.exe 2007-03-24 14:15:34 26697 --a------ C:\WINDOWS\System32\urqoljk.dll 2007-03-24 13:38:32 86016 --a------ C:\WINDOWS\System32\setup_44644.exe<SETUP_~2.EXE> 2007-03-24 13:36:19 26697 --a------ C:\WINDOWS\System32\ssqqono.dll 2007-03-24 13:22:30 26697 --a------ C:\WINDOWS\System32\pmnoonm.dll 2007-03-24 12:39:22 52674 --a------ C:\WINDOWS\System32\setup_56846.exe<SETUP_~1.EXE> 2007-03-24 12:34:45 26697 --a------ C:\WINDOWS\System32\fcccddd.dll 2007-03-24 12:09:27 280676 ---hs---- C:\WINDOWS\System32\mljjj.dll 2007-03-24 12:08:29 1208018 ---hs---- C:\WINDOWS\System32\bdeeg.ini2<BDEEG~1.INI> 2007-03-24 12:03:47 280676 ---hs---- C:\WINDOWS\System32\ssqrq.dll 2007-03-24 12:03:22 11264 --a------ C:\WINDOWS\System32\ocxloader.exe<OCXLOA~1.EXE> 2007-03-24 12:03:22 348160 --a------ C:\WINDOWS\System32\ocxapi.dll 2007-03-24 12:03:22 0 --a------ C:\WINDOWS\System32\ierplc.dll 2007-03-24 12:03:22 80 --a------ C:\WINDOWS\System32\iepref32.dll 2007-03-24 12:03:17 4608 --a------ C:\WINDOWS\System32\ips.dll 2007-03-24 12:03:14 53248 --a------ C:\WINDOWS\System32\icqmlib.exe 2007-03-24 12:01:15 280676 ---hs---- C:\WINDOWS\System32\sstqo.dll 2007-03-24 11:59:00 123972 --a------ C:\WINDOWS\System32\sqvyswsn.dll 2007-03-24 11:58:59 0 d-------- C:\Documents and Settings\Duane\Application Data\SearchToolbarCorp<SEARCH~1> 2007-03-24 11:58:50 132116 --a------ C:\WINDOWS\System32\pqkuaaau.dll 2007-03-24 11:58:46 0 d-------- C:\Program Files\VSAdd-in 2007-03-24 11:58:43 88340 --a------ C:\WINDOWS\System32\dyghasfc.exe 2007-03-24 11:58:42 1206759 ---hs---- C:\WINDOWS\System32\bdeeg.bak1<BDEEG~1.BAK> 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\WINDOWS 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Symantec 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\InterTrust<INTERT~1> 2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Adobe 2007-03-24 11:58:21 280676 ---hs---- C:\WINDOWS\System32\geedb.dll 2007-03-24 11:58:21 1048576 --ah----- C:\Documents and Settings\Master Account\NTUSER.DAT 2007-03-24 11:53:13 596 --a------ C:\WINDOWS\System32\qmopt.dll 2007-03-24 11:52:57 26697 --a------ C:\WINDOWS\System32\ssqnllk.dll 2007-03-24 08:46:40 0 d-------- C:\WINDOWS\System32\Kaspersky Lab<KASPER~1> 2007-03-24 08:38:51 86016 -r-hs---- C:\WINDOWS\alg.exe 2007-03-24 08:38:42 71 --a------ C:\WINDOWS\System32\i 2007-03-21 21:17:04 52674 -r-hs---- C:\WINDOWS\avgav.exe 2007-03-20 20:18:18 0 d-------- C:\avenger 2007-03-19 21:14:12 0 d--h----- C:\WINDOWS\PIF 2007-03-13 20:51:18 136 --a------ C:\WINDOWS\System32\dgjun.bat 2007-03-12 18:20:25 491768 --a------ C:\ie6setup.exe 2007-03-11 22:17:35 0 d-------- C:\WINDOWS\System32\ActiveScan<ACTIVE~1> 2007-03-11 09:25:11 0 d-------- C:\Program Files\Java 2007-03-11 09:25:11 0 d-------- C:\Program Files\Common Files\Java 2007-03-11 09:24:21 0 d-------- C:\Documents and Settings\Duane\Application Data\Sun 2007-03-10 11:31:19 0 d-------- C:\Rustbfix 2007-03-08 19:33:08 49152 --a------ C:\Documents and Settings\Duane\vfind.exe 2007-03-08 19:33:08 79360 --a------ C:\Documents and Settings\Duane\swxcacls.exe 2007-03-08 19:33:08 123904 --a------ C:\Documents and Settings\Duane\swsc.exe 2007-03-08 19:33:08 140800 --a------ C:\Documents and Settings\Duane\swreg.exe 2007-03-08 19:33:08 8192 --a------ C:\Documents and Settings\Duane\RestartIt.exe<RESTAR~1.EXE> 2007-03-08 19:33:08 6914 --a------ C:\Documents and Settings\Duane\Qoo.bat 2007-03-08 19:33:08 971 --a------ C:\Documents and Settings\Duane\Purity.bat 2007-03-08 19:33:08 39184 --a------ C:\Documents and Settings\Duane\Ntrights.exe 2007-03-08 19:33:08 5074 --a------ C:\Documents and Settings\Duane\NTPBack.exe 2007-03-08 19:33:08 42887 --a------ C:\Documents and Settings\Duane\ntp.exe 2007-03-08 19:33:08 26112 --a------ C:\Documents and Settings\Duane\nircmd.exe 2007-03-08 19:33:08 38400 --a------ C:\Documents and Settings\Duane\moveex.exe 2007-03-08 19:33:08 2304 --a------ C:\Documents and Settings\Duane\Look2Me.bat 2007-03-08 19:33:08 117379 --a------ C:\Documents and Settings\Duane\LIST-C.bat 2007-03-08 19:33:08 181776 --a------ C:\Documents and Settings\Duane\handle.exe 2007-03-08 19:33:08 73728 --a------ C:\Documents and Settings\Duane\FDSV.EXE 2007-03-08 19:33:08 51200 --a------ C:\Documents and Settings\Duane\dumphive.exe 2007-03-08 19:33:08 319415 --a------ C:\Documents and Settings\Duane\Creg.reg 2007-03-08 19:33:08 28672 --a------ C:\Documents and Settings\Duane\catchme.exe 2007-02-24 21:33:14 53248 --a------ C:\WINDOWS\System32\Process.exe 2007-02-24 21:33:08 0 d-------- C:\SmitfraudFix<SMITFR~1> -- Find3M Report --------------------------------------------------------------- 2007-03-24 14:21:44 0 d-------- C:\Program Files\Hijack This<HIJACK~1> 2007-03-21 20:38:09 0 d-------- C:\Program Files\Picasa2 2007-03-21 20:36:13 0 d-------- C:\Program Files\Messenger<MESSEN~1> 2007-03-21 20:31:05 0 d-------- C:\Program Files\iTunes 2007-03-21 20:29:54 0 d-------- C:\Program Files\Google 2007-03-21 20:27:24 0 d-------- C:\Program Files\BigFix 2007-03-08 19:47:09 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1> 2007-02-24 22:08:44 3762 --a------ C:\WINDOWS\System32\tmp.reg 2007-02-21 21:42:31 129 --a------ C:\fix.bat 2007-02-21 18:24:56 0 d-------- C:\Program Files\backups 2007-02-20 21:14:12 0 d-------- C:\Program Files\Shockwave.com<SHOCKW~1.COM> 2007-02-13 21:29:11 0 d-------- C:\Program Files\Common Files\Sandlot Shared<SANDLO~1> 2007-02-10 20:00:13 14201 --a------ C:\Program Files\hijackthis.log<HIJACK~1.LOG> 2007-01-28 22:13:42 0 d-------- C:\Program Files\LG Software Innovations<LGSOFT~1> 2007-01-28 22:05:20 0 d-------- C:\Program Files\CloneDVD 2007-01-28 21:28:17 14 --a------ C:\WINDOWS\System32\systeminfo3.dll<SYSTEM~1.DLL> 2007-01-21 15:08:15 14612 --a------ C:\Program Files\CWSHREDDER.EXE-2D092FD4.pf<CWSHRE~1.PF> 2007-01-21 15:03:52 532480 --a------ C:\Program Files\cwshredder.exe<CWSHRE~1.EXE> 2007-01-13 14:32:20 0 --a------ C:\WINDOWS\System32\00BDDB65 2007-01-12 18:19:57 0 --a------ C:\WINDOWS\System32\vb2en16.dll 2007-01-12 18:19:50 1235 --a------ C:\WINDOWS\System32\openopenopen<OPENOP~2> 2007-01-12 18:19:34 0 --a------ C:\WINDOWS\System32\99239519 2007-01-11 16:35:52 1 --a------ C:\WINDOWS\System32\kr_done1 2007-01-11 16:35:33 12800 --a------ C:\WINDOWS\System32\svchost.exe 2007-01-11 16:33:19 0 --a------ C:\WINDOWS\System32\3718845C 2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\ps.dat 2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\cookie.dat 2007-01-07 13:16:52 25600 --a------ C:\WINDOWS\System32\helper.dll 2007-01-04 22:35:41 10660 --a------ C:\WINDOWS\mozver.dat 2007-01-03 20:49:11 5037072 --a------ C:\Program Files\spybotsd14.exe<SPYBOT~1.EXE> 2007-01-01 12:02:40 507 --a------ C:\WINDOWS\EReg077.dat 2006-12-25 16:33:11 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi<PLAINO~1.XPI> -- Registry Dump --------------------------------------------------------------- [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "DeluxeCommunications"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe" "Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe" "HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe" "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"" "HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP" "OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE" "FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe" "PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot" "SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SoundService"="rundll32.exe \"C:\\WINDOWS\\System32\\sqvyswsn.dll\",setvm" "icqmlib.exe"="icqmlib.exe" "ocxloader.exe"="C:\\WINDOWS\\System32\\ocxloader.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" "{85382E07-2F7E-4910-89AD-16F2E97FC152}"="" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnllk [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 *newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_LANMANDRV -- End of Deckard's System Scanner: finished at 2007-03-24 at 14:22:26 --------- End of Posts |
|
|
|
|
#87 (permalink) |
|
Registered User
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP
|
Re: MS Windows XP will not load when connected to internet
SNM.exe
MZ ÿÿ ¸ @ Ð º ´ Í!¸LÍ!This program cannot be run in DOS mode. $ søkØ7™‹7™‹7™‹´…‹6™‹7™‹4™‹7™‹2™‹U†‹2™‹ß†‹6™‹Rich7™‹ PE L öùF à Ã# @ @ L@ P à à 0 à.data @ à ÓßB$…£Å€òíy…ŽéÑgOoÅ#t;ë†Û$µÈнìŠé©~ŒË }rÊî‘*ªÊÖ¥ (Øõhíø–ÕŒÍsÓz!Þ±ä&´€µB”°åŸŸì¦úðH´úC}bóøÿô´6öïB¡Ñ˜nÙœ@‚þ׎½ÚÑ´¼ I2f¹Ç–Ý$ÅÂÓkÑ™}®Ÿð‰b#ÿ—ÎÊäóÌ®èß©‰cïÉÊ£Ã8øˆ'x¡¶iÅ#ÏÅÇé6Fònï-ì¤ÍpåžîÕ6Œh‹Ä*ë×p¦…a¦ïH*.£´‡Aцæ#–‚ùi¶ñBˆŠ ¹ûšKÇÀ6@'µ‹ô’Ù°ßÉ n¶Í:àc €óÏùšÍجkåÔ–¢±Ê¶¦å3X\eôùvÔsÎú.6Í'ïH›‰NÃaøìÚÄÐKã…5ÀøþH¾¦·6ËÆëíÆäò$’õ7-ºîˆeÌÅÆòŽž”)o´IËÙ½·Ú"¨9û@©XAä5óÈþ¼ÁÄŒ‹ÓuʘTmœÀ†Œ†‘æ¶“H˜\ÌȶÇÔéžpé´aoÄ`°ÕÕâOq öÊ Òã鶉¤+ܧÖLØ/Y. ²íÑ‚lÃx½Ñû°Ç8GΧhÉÂωX¹BÌçúø@¤ù½oMí‚#ŽK¦îyÆÜ‡«0xŸì\vôUŒ&…½‚ÉÈPÕ ÃE©»I¢ªÊ÷‘K~®·ÜŽÛ?UI¦n¦S|è'„±¡ µ ¾‰E€N¥sÛw‚¡©Ÿôu6æv˜¢gÆjs‚Ö&ʵT{ßÿ„ÏڣϿ*Âá±’‚«$}4£°ÐïºóŠkLp{Ö™,“ÂÍèNs‹ÀL™Ö†ÓìàªÒ°æ¦*Xý§Žâ2QùÂrÔkŽ—úᥠU¨·,"Þy–Š!Œº«@ùû.ÝÊUfŠRÕÓ€:þèBúÃ3Gk„Ò4 ¤òˆBÉó¡9Mg‘N‡£ŸDEÆ…òw]¥Àu#Õ̵4Ÿ~Zªv¼3ËøƒÑ“ŒÆÞ…ŽôW[j€4¼RJׂâúÑ*v\U£ÃÔé'ƒVŠ^²í®À?^ ¤+H"±À„µúêF•ç…ë@•zà;IEÏ‚,déh¡IRÒ:øÔ_m`Œkt@qfÕv“âVæ…ÖÌAó¾=É€qsšC”ãvìI$ޤÚô¤>ì“A…nÂóœwåéT¡æ|×›c¿©Ä‚…Õåo”.¯u²›qôÅ=rš§ìÀ9à þåÝœšò1EK™ú®ð£¦ëXÎ$ãÓ„‡´í:²ÉÖ¹¡ïfºæíš‹ÊhkLDRG,O ƒü¯è-lĤÕ@Iœ ™6ÝDz`uïD€Z‹¨?Jyñ¡ÜwÁ¯ƒØšvÝž7ÿäÙÆDÅJ]%EàǤìîK‚ *Íî„àéœô\½íèNž:ŽÖ9Ë`ù£‰•\¨¿²¿ô¼%ݼ¾mfóîl÷‰€–ZǘŸâ Ý©s¾—m{Ì SV÷º³Ó›àÌâ"~‡È¾ŒÛ€h•Ê߻ٽRÎ80Oj]ÑD5Ì“˜9Œžfí2ˆÅ$Œ“›‘*Õ…°Ûûü‡e«êÄBš~ÅÂÑ-€…Þúm_¸¶Šùª%¼4´H×bÀð%*MþƒO>NchòÀ2ƒåWÑ’‰J›õN%ºþì AüCùÀÞ û¢m'²›E¯»3JíÁµÐyê«Æ‡ç‘#…e.Ox ð¸ížf„äM|…϶€àü¡—§@(åÈ‚´HŽÃ&l&Ö+ ŸÐþdˉÊ~äòÿ–£Åq$ᾇýg«).ÒÊN´b G\(æãu‘ÑmëÄ£e y/Îû4Jë“pïBýÌ»vÊM˜PûaM´É•ñŒäUÖÅŠAXÿšÕÁbÇÜÃjÝ襱 ¥ô*nHµ¢:ÐhéM]`û‰„Ó”¹ÚBÒõƒBÕO¸è*`fëÑ“Îù#ƒ;í‡÷…4åÝè‘4ÒÍÿ|ª‹5Rå¯é7ü–ðêÀÌñGìòû”#!ŠÓFnê–w°óB“ž«ït¬òìŠéÁ§ù¹‡í‹vÆÄÍ¢”…=ˆˆéOÌÓ;=¦ªšN|´‚E§¦ì›@ÈJ4€w«Àz;Å‚*ã/ŠVäíÝàL´z¦Åxºyà+…*ÎŽN–X…¾•×ùôrdb´JʉjmÛK $}ôx¤¾wViJ0'˜Ìó@Þ;D˜ü±Äú£Ônc[ölPíVR‘øöÇñ³tÜ‚ÑÉ¡’lºõÐvmŸÇ,[Þ4®C âÔlf´5fn19›“ÏÅù#Ž™çÿ‚õéuýºñdz§âÞYyÇ9Øt9ÌŸÛDHã7Z¨¶ñG´¤¸,ó)µc*àdb-v‡p›lÖ½Ëcƒ}&Q” c ÊSn²K¾Ûóc»jp¾é}*ÌŽ’•Y)È6˜Zuú€Xì'ÈÅ; òFEû¸="®à¯W¢¢,½S`yï––µ&Ä–dùÍ+oÄðy›‡a˜õ‹Ú‰\ÊÂÁËôòH!{øáЫ÷ãM‡þi**.þCBüŽ)¡î鈂¶ ޹ò\;ÌÖYxãH/åâéîäŒyE^¨dØ"øþ|#˜¦SEÞ‹¹(üÚõPxŠZ^í××î¸ó"úÙ²Y´ô+üáà* »à3üg^jyYÛÇÄ)nt<ØfHo‚¯ :˜êè²Sû(çÒ¼þM)ü—3.¸ç «x:މ؞˜aÅ,e)9rÅSì¹àÊžEh®òʈííÂhÿhnH%~Ùær»Gž¹r8î¾)«çšµoþžâó$Ú0¨°Šf?tH®h‚™X ¬ÉöèA83™rx_sŽrËó˜ûI#Œxƒy±Ú®ÍØ b˜íh-xŸÙ€h)B‰]ù>¡ ×£·_,ñ>_¢-ï/ieHèÏv¹¤ÇCh Â) zZ©¡<Ckáòˆ?Ô(ÉL&R jÛ« B‹îï @A OA ]A pA A A žA ¬A ºA ÊA ØA èA ì@ @ ù@ @ A $@ A ,@ A 4@ (A <@ 4A D@ kernel32.dll user32.dll advapi32.dll oleaut32.dll gdi32.dll shell32.dll wininet.dll VirtualAlloc VirtualFree GetModuleHandleA GetProcAddress ExitProcess LoadLibraryA MessageBoxA RegCloseKey SysFreeString CreateFontA ShellExecuteA InternetSetOptionA 'óH í R6ß(ä:l¦³Ðà™#Ãʈ(70Ð0%ˆT¥‡ˆz X‰ç] KCÏV÷ð [ýÕþnq>º8‚1U;:‘r"ä0[ã0 Œ¾"´Í®!ÌØÀ’»êó. Ö"u±›Ÿ¼Më&Nlÿ épÀ®P,;ñ0èƒûtJìüþÇé?bÎÀÆ;ð×_Ö–é' äžó®‡wúÀ|O‚èâ*JF<ßöLœUXcп˜PCeQè!ÜÍç<jó¶§ ÁæOèTH V^_ÔöÖ¨36Ë0ª49G;û†8–S¸^Š÷Ùé”A¿þ¥ÈÏè JôƒÄÁï˜#’¤–ð…m‹óè#ü©1* öØSD=‚W óéˆ8LZGFCF³W=Kö’Å™É?䣯¦„ ¤òˆój²c‚°p>="] &Pf³åPé"Xì_|R*ëÿ¤ ù-¨'$P‘¸6ã mì!鈀µ˜váB»úôŒ)è€|kÇì‚TŒ3õ Æå+1R€‹ó†'8ÝÀs«WZXöŠxDÛ^]f¬^*‚óùÒÁÀªçK}Êþ÷ÞéÀ¶îD•‡‰+ «‰1€÷Ç«ÀÞl‘Œ¾Ô-ç€ñö¹÷Ó‘?ƒ·Ø;ÙèñU*ÌïòAR¬#Ïí¡BÚ &Ì~xÏþÃ(}Ösg˜i—åÁ0Î96-0Íkjw‰,S$›~HBæ¿p¥é¾ì :fÿq=+ÌþÂJÀ`öÕ¦Dg$¿ù_d\€PÐÍ Áfƒî˜÷Ãiº–öј¨Á}ÇŒ‘mw ÷ß’ÎàÀoü†Á$î))ˆžÃÀ:Û›+Cô;ø‰1Ž 3„`Åþðy³f2=F$É`=QY[ÉäÈ‚¦…Í‚ââ)šŠ`?¼ØTæóþSʉ*¸ûP#ÔëÔN*$Äj¶0…ȼ›(Åcp.˜º&On¹I ãøäö¦‘AiÕ@±èÙÖhˆ0%†JZý¦ÉÍÀ®ÒNú÷ ÖëíâèF¦‚O«û$E…Ô@@—#ÌŽ “{ΚÜ;*Bé&+,&aWÄÊP01 ƒ0 é¿o“• T0¼*l$ÜzDÈA ¾…ÒA#î8¨[ä˜Ã™ÚˆÜ‘Äžè–q¤3 ˆï~ÄKP[D0_ŸÈ)¬ò¤ £Á "áà÷˜#e }NFÌA˜šé›ÆM»L:3ï;dàÒXü)¨bÀæH£èSù ŸÍ]½¿i¸ß‚ãfˉD?UZ[Ò·Þ‹ÃlÏHÛúEÂ뉋èÛ@^Lº¯Skñ& •sDClP"ŒG†ª¶ã„<ÿ”‚Ëè‚p_/0Áú j\›XN0Ž*oöTÞJ°¦˜1µ@yèúTþS]Î .P^Yô¦« ÉúÁÂq ·LV"3Ï?àᘴ_„·Qò‹ð1P<Ð_€ô æ—#Ü;è£_ÅJ¶‹ðÀ 1÷Šãëdž¤îuÉf’Ë ïL9ƒäÇ ~TZ^Ë“à°è0NJi&»çõÕöÚÌ<¦7 Ô)Îθ¢ò•ºÏå%‘Ìvèz^o9Ù ¼ëP>ã|Â>pðüS ‰\v Y^@ • +ó0)ÉWÊHŠØµ£ö#|5{dR¿‹?÷Ù˜çé T[Xïö×Fü»¡Ð#7:…Ö`ÇÀhÆ_q{]AAšO7îâ; ÔBà6%N0ÀŒ&õûñ0¶Î%|"*HAŽÇÁ'"ãD¤X¦z/ó;÷ƸÃ(Ï\òHÖN!ù“Å3ê DȽ,1ò€~ ÷è{öì÷Äè¸æ<éêvºñûz³àçrDî±(_Eúwl]˜ŽÐ—f—Ôd7À ΄´lo(rgiáî7„+`HÔNìíX>Ùæ+j ¢r¼æ{é¹>#¨óœé~àÝñåeŽ*Uä¤ä…Òþlq`vb£üuEZôÓ*šÑiZÙó}c„²³úBbY¨Š4ãnL÷ݵà"Laî݄鳨8YµïÌ^Œ?^w¦ãX…Ðá´¦(¡üÌÜ~jrâ!°§¼1²´¨‰¶_\¼Çäø®}ÉÞŽh„,ùl»€äÏÔIt¡- Ë•UK#!ð·R{•‹jr¥XEÜ\€^¬T‡ƒ®vL>ÍT_ám~µ9!£æ†Ìô÷|Çñï?h‚¿“…Ï㄃ `û8úá/}‚ýRn€ÿËMa—02QÛRè¯uEâ·XM·ìe°Ê @î{]¿çc•„öÕ[0è©þ÷ÉàS`¥~ Ø*lLT`/Ìít• 0„û‡·ƒ_Ua³´E£5ÉÓ'YÓÏí)8o˜‰‚ŸE¿w¸õ…ˆø`ívå/Š4[ǸÖ(á¹@ £X%ñ“yÿP Àl¿1¼—KÜ;å=$«tÅ~ ¸*LvÈÁ\Ø9£±ÂùE nŠÎç 3˜£<þ‚g¯Ÿ‚8ùùÀ…áOÉ®-M¨,¤õ9ê<Ã5÷2伄´&xéînñá>Š ƒ å [6ñ%` (Iô$3ÉpÑ0댫5‚þñõYøA* ü‘p|ã+Q䥷ómvé·ÞíµXdéi˜iÙßJ÷$™§²-‚h-$nY”pxø¶!âKwL2´t ëŽËÔ’hú#ÉKQ?‡Ü p ñ¡xâåäMËÇ *û;8Gâ…)žß³"”&ØÌø–±ãùaªº#x—4RØÇíNÈiÜŒ{€;² “*áù1¬=-…ü‡JHæ1ýÎØ0sœ´5Ù¯„Ø&ÁŠãN ?¹DvU7ÏV:úbõÄï[§7ÇWðG›Ãômîzýï¨{¿anâüúq9@üGòf¶©t¹™·s÷ÓÑý÷‚uvt÷Y{>¤ºì|>šà&è šæ{(Ã*É`@üñyÜùöÌ“_ #_˜#¸ƒºº¯üíplYH©F Ðmâ²÷бS”½»ã?hšR!Y˜ë.\£" ‰ž¶;cÂ`—sÜU~®B *€xÛ¼õm@ ùêø.'8–(ã°ú” †êA 5 VEúxF¶îúƒ§èç‡:-6ä5ÒqE“wnqPå6 ö†ŒÚ|¥±=víÎBñ Ysm/f‡Pî’Ûºãqäàd y²'e‡ÿsÿ?øÅi™ALëEíHè¥ÖóTp»Ä‚‚7`ãqhùJÐg%cÇžŽRõ¼üT!̹D¶:IE?ÛŒW1ÛóL˜†ž~-8„áJÚðÛX¨£lÛƒ+Zu½ ÈØA—ÀäÑöJ‚Àvëîbû“N%‘](R«þïv·H— PÏ¿µEÕW±sùKÈ$`-ƒPÑ¢Œ}"Šf;I¹¥žâsýD0Añ„¦…@ší¢p´Ðý7CŽÈ OɺoÝÃÜyõËî('/%áÿ—u°‡èY[¡gDDËBŒæÒ3-µ)[ ”r÷CSuÑ¿°²8úŠÌà bUÄÓ+–¾hÇÄlÚÕ»îq %C”cs~kí“y/¥í üõò+ªúèòŸuñ]*NR"¬ÍГ¦Î”ÖpËË¡r€O>ü®VÀvµ:ؒ͹l“Ý|5.dÐK•ÇûK2‘PB;™Äs/uƒ »—y—Œäâ 3Ô®ù«?ÚAŠ®((sD¡ØöšIa¨Ö aµ8ØàÚCj ͉™Å_‚ ¹„hv`™4{?óÉïñìG׃¼‚é 1Wk#lß d+4±¿sÅÖè»\Œ+ÎF‚¿lDuE€4 ά:ötÿ5óYûÒÛ›-CZiî„fNl¶é×7mÉN—yÅ¨ÍØ÷ËögAL@ñ¶wúô8¶§….Ýy Ð Ê ˜sl<ëßÝd-4öcø&Hä´·åGr:9W¼r<4ñ7Ž|_‘¬×iÂp’÷lÏõ[¶¦ñGrS©ÓðàYžÙ`-Îà$•¤Â´ì GRTT#Z¼x^ÿc°Ü`5~uδscþ¨`v,áºxYÅU ýâs@àù2:4hTǼb ¾ÂĈE“k1ÂÒi•¹L…u^>=JêR^?{˜!+¼œ£Üy(í’u0sÏi,ô¾Aøf…í]À1ðmkŒ9ž` s&… å©Û`*ôýµXd=-LËEýŸë ¼rbÒ|ù34‹mÇXâ2R6i&2÷äÏÿñŒqÜ…R_äb8 £3òÞ4·¶ŠOa’ìæüóà›sÎóUpl*៼í©üÏxuü¥ý89åQ€ø.wÖy¥qá÷Ùs x¢Ö€íè˜kåµÌùá8hŬŒé¨ÃòUWðc·þZÍ6JúgËsÇ‚ŸøÎ4»ÃnKùcz}VÍ] æ=h]”×W§8Ôm%‚\ÇákÈ}ö¡Ç:IW•t"í!Gy›ùmè{ðó9Ì\dƒ/Ð(Ô©ó—Õ©—ìYªª„š(àX¡ò’onºTÂ-:æàÿ*C»º@uî 6½¥%(^Z®áe!P¬¬!á oñáÇÍWØ·Üáu6ø¹uË.p}_õbÀ„6wö+JÀ°¶2oüœl^Œh§ %̪(7|I¥ryÚWd}óq· “<…íëu3Ò{Wc0öM3#pº¼`÷ûØâ£€ƒ7- 6dnáa~xq°oÇGõŒ"}1I2çmÞ‚u™B¨´êõUíô'oü—3™?Ÿâô¿£ªXš%§@u»ê]XOè@’rðÝtÔaÄ;¬R^x»K(äù ùÃu0¹|ôuW¨ôóÿÁ16iù¢ð÷ÎMl7¡sRÁ%™Xùj`5ÔB‹Rª^ÑÇÊÍøñ´¢{-Ë?MðÕ—Ù!}NôÇ û.}Ô¦6ÏÐð”cwÔk‘qm)ÔJ0ÂuKq'ˆÁ<½e£ZÎde¹ñl+q°ì$<øÄv•»ŽÿG{#•Já‹ñ«òå%S©Ã[&ô"Å}c‹CTË8Ù‡P“ÔhX«J§„%òÚ{Kñ-}Kõ(‹òM®|ø´ ô½=lej¶´eR´äý{ó ÿiøÁkøÀ²™mûw«ÃÁ˜òç¿>!ï“ÖQ>æÁq{yÈn¹%’2Ãë(æÍ÷ã•CL¬A2“¯Ø âíÿt£ b†—@QLùÿÏÅvTŸ&ÎÒžç'Õ]«9üi±MεWùªeö¬]#äªUb‚·âõŽ |’õìTÚ{Ä]–e þ©…TÝî_¥Ó²¿ßå „p˜A“Lßä™v¨r•Ûu¬À¥YÙÐC:8øÆ"s${ç–ÞÔò*ÇÕ}ÓúäèQ†cu‘N|ÃùÙ„žîÜä!Ê_n>¨7 ¿Í]ÞŒ|€ŒfˆâÖ·O–A´§óªì…&áªGý[ý0ʵ®þe[+óÐ>Ì··7¸2ío•vÚ*UA»?ó¿b;æv°¯\G£N˜R¼n±{ÎY'Çóo{±îƒ9±!›@®ìXØ»¦ó4휴øœæ„{1©÷@æ~øÒˆ$¹¹ î¿…èíJùö•Ayžƒ”o6ÊÕ#ü´šÙy* &(„¢÷}en© 龜¥¸áU06úbLAÛ%GܶÿŽ ¦ËZ§™˜ÝuñËÚlA…Ëìxc±mÞf À°ôIjÚy™ÍÙÕllÿ2ô~}ì^ó¬ã€«û÷KŠÊï}‡Ùl»âˆ¦ªšMæïpFÔóo‚o¶òoÊϯAÊæ¨ÍªÚÅ!*m¬Tz’0ÏÇšMYø{Y *™¢(¾Ìó <ÁËÌðHhoà¦ÿ"d®lŠr0Wß(ƒ*óð 1qìUùñ~âþèñEñójï/UfÓ•4‘xÄÿóåS\¤9InÓ£¨þÇÕýl¡ .ºPÌn•7žïØ<VÛì½® )t.m±÷*Œ´¶äkùeð¥Ï]óÒ-$·ZÇŽr!ùÂì.ûD€…°…A%2é /VnD»d¾KZ³s»öÜŒÌÕšrj^¦šõ™âÜ‚Õ/wÃÚØÂ7h"I4ï7Ý»=Z5ê¤Rrqv]›þë¤^%,þŒ¶ „î ¡kÁ¥*WSÔ¥Umü,ñlNãžè2ðeø¾oi,.{§!tÆÿOeõTJaˆ¨oÁÃP]þ)߀‰¤Z ÓÈX,á§:Âaõ”nêk/óo€ßã²Â…0¤äùÉŽòƒ™Äw=Ÿt‚wä¤å:>S'P±“n1Ët+GtŒ9Â;ðdYy/´YÌk% –þ†”$(àÔI 8¦M9…ì%ñ>ó7/üÂÅ›¢`Vi XÄ‚HÛ ™’gŸ‹ Út»<£VÝ–êT[·qܰg÷‘€ãôpõ‡‡ ƒ3ÄäI¡bv€¬Ï pÿЊªëÃ( ·.XXÜÿ±t$€S¨’hñÁ'äÛÆó– Ðn(ReãQ`¥ìŒ`[ZM3DEó˜Ï 0š0ô„ÈÌdˆøVúUrŠä•*üŽ8}ÊÖ€ŒÞTÙö^èO7Ò=õ³5\]‘ßy b‹wa*Dt˜äõ&(ŒUPýx*oèûeÒÏ¥$ø“¿yšLû¨$lŠëƒ›zkýEüsñœf£†Ðãç'ÜE%QªôQ– ÉÌ´û„è@ˆdj(~ëwOæ"Ñü]À!ð½Bg%º×x,õ\£*qíó”>êÉ˰û ëÀT8¦™Oÿ`U? ÍV«{ßÜpºíU‡ÕU§Àï |´`ã Îùÿû÷XŽ„üϰ·—q4k@v±zM6jÐ)¿ \=ê½éàpÀ!ÅDù×Ò¶j£¯g 8+Ž4šç`yžÂ>€´ì‹ë4ª•IbîñYÔ®!©L¶<åpƒî«:÷ÇñEër$…²ÛO#Ôi¡ªú$Y¥ËL²ÚÏ´-¸£?Φ\âôxq$WL-ùY3És(}ã0Á¤\jgkï*d:$š(°ç¤w»Ÿ5RÙ9ŠNǹJ‚{Ã]Äòs"è“£‘• dÇ]D†ììáéy~ A¿A·µâôK*H%6~ˆj¾MÿyÕMǾˆ4!Aå[ÀÏ•êìrnýºëüŠŒªs•}G4‘+}f{€2dž_îÒ\´çoÙ¹¢Ïúk˜‰ñy„ë]!Íd'ÚvÑ2Å?nÛ÷—Z%5¡9ë æ ˜Äìä8ƒv.µ'…âþ:¤ó[Žíbü¢hС ´s’¯üë8^v6ìG_°o´ t‡{;ø·¿ÃˆègmŸhñý)LYeØöçìty1eÇ!²P?³Óÿl¬Ì3”¨®äVîtvÛ±pgˆ)RQòGM ¯LôXtÀëiHI5ÉÀ«ÒVKï†éFbû9í ^*7mB’KxÌŸÑHðgGÁlÞ(£|™\‰Nqv`<ADæ+Ïñ »çÝä<à²242¨PchÙ‘¶ P†µ{ÁUþì°·ˆ[\PÝs)à[†;)$©tîèñ÷ŸE6q»Üìû^J'àó¨¯G£G—ã`Ä9âksq^ˆµO f’ nR"XJ¹”ŠŽ}ÜV(ƒ@ïŸÁ¿ðDh’5ñ׺ðAHk•rè;³cO<£ç"ðFj¿â¥\×äE„—œu ×µ5󃟢m›Û~§Ù”ç—wZ¶?…ßUéZÛK7 ê<ØŽ ïcý´ v™+æ[*o<¬Z§à¹Í 7%•@ç•TKmŽmµ3|úCŠr³ý’’Þ ÷;¤7HÞ:Îðvr¯^GeêSkü’ý‘µA½|®cÞG<HU‘£!45Ø‚nu&¯ðÝ)0³Ù…Ç™ð€ØY *n…Ò—.îXÞÁ0:ügkp\ zå.i4 ùϾ©’öI§:œ 2 Ã+Œ´ž‘ŒùtÎïæÿñ÷’`øñ´p,ró±ê ¥ÚÂʈÏT}{^Èì™@s,Gâ\&y¢„„YšalË<®÷áÛ¾X‡½Ôû\˜‹QmÉLŠyÇ»L—íÔ>,_MHn÷„sOnÈÞuAñ_1W“oQD ¾3'ƒ©{²„àÉCáû*¾;Ml> 0í/Fï¡(^ðµ9U²ˆœ†m÷£x€Õ¢³Eð¡,\½†b¦(…‚xÒ|Úæ¸ç!Ë0|y$Öµƒþ¦_úTÂõ¥°Fo(rcÿïþ¬§óÞ¤ûÓ‚äè?åêìŠ0Ï<Et5Bøb¥ŠHÅ'éèêÂãó†õ“9ü‡)ÒéŸr*ôY¢Ã{»§åtö¡*õmn‚ŽL|B(Ö¼X17šYPàzõÙµ%Ho¡'B,éC ü—äÉ3Œ wŠ’$`zà¿x~öáyÓ{)ëû5|ËEŸßÓÏ Ñ™ê/Ñ sQq{K;Õ€(ã|ÉÿàŽ×Ûý¶ù¹ExXW}!Ü&+Ÿå÷ŒŽ7=,ýƇÁ¡d{Îò¦2í%£« 3¿}ÉÙ/Œ}·‹¾º~0 ¤pº°@‘vÝåHœq%pÞ9Y’ã*H;Õ± ³\k¥H]TÉ6…,g5S¨Î¹ƒèÉÄgh î[¡´?ŒäœYÖ“3ðÏlm{ýõ{éæ7¦x¨ÞZò~¼ëKú¼üÙ<_¿I¡Pý°ëhþgΈ Ã"Qa–Æš—Âðm{îlö¢hÅQê˜a†u8ÉæÀ°õ”L‹%Œ‰ÍÇ,ñ‘Dš«ÓÉ/‘Àiú†`ÂóøkYü…(còÚ˜ŒTv¨j]ÂþœŸè¤x_¨æ{Y£W*©sXÖéç÷HñgEà)ȼ’pN˜¼ê»õæ •¦ÓQÖŽ+b¯"èu{%YªµÈÌâµ^)ñ)S+¿b\T>ê+"Á·‹IÉÿboÉfD×3¢÷Yè4„Ãõ¶÷\rÄòlh0®s.-ö 8´p÷ìY›1 qÞ²óéÇ{¬”XUù‘U0ߦ×Ås,ËÊl xbþ–q[öõ˶œ¶üL$Üè¢ÛùGåþD=ø ‚sÍ-Œ†„—sAYå¾¹¦õZîüZo-!+UÀà–Ôáÿ#‹ºÏ¥mÏKžGþ{ˆ©¯ãEηR˜ZuÑþ³EÌö Òaí÷×bm€`§tHø7(p_}Ûë‘PÞ¹ïL΄øªCj”>&ÌÖö5Jó”~¤È*£+ß·È@íÑ{þ”R0h&]ù²+_£v>ÚcÄ€§Ï,€HÅ“Â'LŠvãË^Pi*åíõŸp¥pŠã5ôPq#²:ï””¾C—+çðC¨·Çq@zhyö«}z5 Êù&_”ýJ} gä²äº”–GbžÊr‰÷)šVÅ:Ó~Ãþ%pSCàv×~4b©†vîËU¤iu5åo+$õP\wP’4ƒ¯yG‡yxpCŠäwÆ™L~¢·ê#á"D$cëV'¶ô¿ÔFó as& øÜ“Ö`P¹8 VN9¨!=6}?€b(ê «Næ ²Nâ ¤Nþ ¦Nú ¥Nö£¶õ›¯M §.w[üå*%x/8>õËùs?õ}4I%°“-xÙЪ@;«JÕDUj*$2ñ /À¤d}í~‡Ì _Ày?ô‹eM\Åuúêx+Ü+X%\ê>±)wçXäpøgoŒ8dç7«6¢ˆHRíYZшXìX9—W˜lß=¨øØ)¡Fw}2û¾DÉ/ Jœa%™ŠàuŠ ÙÉæ ü>ÅõÞBƒ0eæXL«+ÕtV¸…®Ét—xž×úªQ b§Žõ7ù㢠$®æ8 Ãçɉ¸âäEIAäÂ[;Ñj´ÄÑ! 3wQßðλL¥oÍWÑÑHHË)íãAÖ³óa5×|½Ø˜i^Ö-³N×l„#2° ϬÑyYÑë8EyÆQMøú4ScâÃå§Q½#VÆåMÀsš‚Úöå÷ÐG ±pÒlI¢.±àx¥vÛë©æ{Ø9hE$L¸¾ÎÇÀò(„à@0óšxöäf-ÀÂÌÚ¼¬¨-àQgPãÆDuödA%w&¸6âHãæ¥4‰I¸$*dn¯Kˆëʦg|Ï{Ûd„„ ‡²¶Þz„} *¯4P€º¿’j⮸Ÿe¢ÏÏ 5úÃê©põ4xNƒµÆA¹—1 ˆ¿FOw*n‰2לˆ1þôöÏǤB¹ )AûÝ Qˬuµêö›tð]£>ý]î&”¾‚ßÿ.}piŽ`y©¤¤séª<>w¸d9Ÿóƒ~—ûz)dÐáŒf½µk¶¼1´WöÉ(ýýèrõĨf4æÜ\͆Úw±öz"ÀêÌ3A¾ÇîÇ”5”zg…‚Äcë òïqƧŒS3#¼!`¡ ¼ÒUåÃC‹©LÕ&º5W“sqçºÅ)²aTÂA2X(IhgLrØ‘jŠÏFÜŸî{Ùˆ¦‘éEœ5Å æôAx™¨Ó”V¸ÎÖ“û›V<Ø¥J…í# ™€³«p“(Ì}ºâ^ã¤lH6ý”͉#îÉ^>°Ëkx}úÎz¨G$k\“ÖM|óÉh‰uc62¿:sÜÔàX¹yávùþ÷bSðø sŒ›©®¼#æ| S(qá‡ø“Å5^¨“ÔK{÷¬¥Õû»M„6 ® ,I·G„²¼^q¨ì8Õè1÷¥ý»Kó/rlø‚U¹Ò©€Ó<0ìXÔ%9Hý쬥…ÛËïr¨ÇdAm@ŠSCxlˆ‰ûŒó0UY£vŽHVÀ3¼wíÃ,Š”ŠréôCªèδåéšî'tÌy·€Ë%’Õâj™çEßÉ(Wñhû…Ÿ7%ª ~G6ùm‰ÑþÌõ2ÏÎT`dñ.Yþwt…¡õÝCHU¥+Ëq¡ ò)ˆ4B ªr]€|iÞ„‡R˜uÃ7¯üâ¯jqÈö0'!¿±.SbWÆVÑ×”ŽÜœO4ŒÆ*g ì°².tŒÅ+(cÚ ÷LA!Ï{:%ûLËåOï.‡È.€ÙÅàÚ¡äѬwÆ@Æà][Êí+²*}jTÝvPì0 ¸Ïÿ²ð”¡Ÿ¥õت”U`¹NAP×Q[–ܱkÐíæRçêþsqÄëtâí~*óLF†tV]ÌÛþƒú¥íC`=< y0ìd×ÒIý6$0ñ&ÕVéÍAõ!Lõ€,Ž÷|}Œ2ólÁõÒCô`ásNHšVn÷pÿµ ËñEÇzl‘`óC÷GÄÁo-}L5ý¤ð¸ÿu `Ù)Tôh²¥ *Ë÷ŸURï÷µ‘ãÇ`ñâ$àÊð×y•¯A>*xJä:Õi îòã?÷B—|Ùóµ„ZÓè$VÐøð°o¨„ü|Ç €:ߥé- ¸«`kXÖƒITshÈ “p0øÖá8®=õâ*—äãjÏùä\É( +“[×åÄBkáN¢M~„Ã5(K ¬UâøuÌ—6l82lÿXûìqvLÄæ²9|¬ àÇ•ûq”ëé"øu6̪§ïQ}Ãèö¿áIÐEA ä[†æÞ˜m¥b{ E°§gUÙ‡å}ˢýã'øZÕþgc0)’$CòÝäô‹ãmë¬ÍJ= ²ˆP—`ñxz„½‹9ÛÅÝ%Èå=çÊéeqÄö3U…ö”[ñ'—*‘\É&á{ª„*ë½à+˜Œü`ú~P s¨Ë >Í(Wëœa{~Òp_2ð%È2Ê´õô>Ü5éçô,!ο«—àM°ƒ¼«n¬–à»&|)Ï$¿€¥‚çZCŒüEÓõc #ùöéUwváæµôøtÊÖ®n¥•šôͺã¼ée;ÏváÇ×##j|õ¾›0#}õ/ñ°+Ù]Û)åÀKñ}û}ãkgÂ7o`»µ\ ]ÑÆÈ/A¸‹Ž¯öÁfb_Šˆ&ó|í?”çâT¾ ÿœ “*â[:~ѿϗ!<|à£Â«l¤E>› BmCQÅgt<þk°Yýµ”BõV<j1K»ë-É^&mBºÀΫ;kºF‰tµËâhRÍ…ç¶.G³m¦t›~]+0´öë¸v*„ª\ÏŒz—«ÀDQnˆŽ8ïzõî¯.tm|m®8Ý«]b á·âñÉì5’ú^ûúbüúXýúOþú1ÿ[Eáùf¹òœ¢w™ Êj—L‚óB8átüÁl Nu¥ã©‚¤Évˆûä Ðò†Ûukn?pÝ’•Åúi4ÕýûOt5 1üc4²ôªÂ´7‹Rsø`¦ò= 3W¥áÓ—`Š ÏM·Ùëºí,ÒÙ8X¬n ªi÷÷šOÚ%ÿAÇííÆ}ô*¿‚©ë4÷œ”¡1ÃŬužÏ7 Ù«Nßï®VÊîlªÂ%Ù²Ó_^Âí—"³åxáÚMEù@ áDK)w°¦È RìˆyÚhôfG£çLè0m= ñj ò´õ3ñ¶t Ù&™Iû¾ q¦mî\v5çy~ƒúg…HÐÖØÑýA±Å5”úê,\¸ÃHyúpYQBõm x³ú/*è,‚ä¯L®¬««ó—tác8Ø‹?„áhO(àõ'Ífb‘ñ‚Ó~ rÿ0@î4-3§HQÚG)1Ö~Xy64W¥O Ò¼B¨Í¡mITô_ÖÇBŒ dÈ~DÿbhÀë¾/ãúôþñ*87>÷1bÔämsþ©¤t[t¥(wí«lÛÆ[£ñŠ@R*|½’’à^´IàˆMø^Á£1(žÏƒ–îFµ~Eâú}ø ¼{ï‚KKb ès…ð"£¹Nñ&Q1ò6»øÝ™ëyE®ÍÓ-äCÙñ9åÔIØ>`ÉÌ|,>8àôþÎÃõÈHÀòmvë}=ß :¾õËø@437’tŸª…(à’X-ÍÖwOtñÿÍóäе%Töü˜ƒáDŒ˜fùš{¹ô~ó‚nÞª‚óÑ^H~Ð+[ Á{äeháÏöOñ"ºöÔã,ñ²”ÿváT<”ÛN£ïòG 7áö›˜Õ~= Ë<ôÍ«%Š<ÃtšõG ñ’I€*Åt .a1‘Âe{‡GôÞÿ‚ÓŸIæáD ̳XqI }¢œý¥*˜,-ùÓʹƒªJðá(-hù}üoÍé?úh#¦?tá:9Ë[ë+få ÉùÙâÇÇ¡¤ëñ´}¥Ò-úc? ß0{3 tkó€šÜw™õÌ)ù÷·¨uÍéöÓó$(isš„Ø™RÄâïxöù¬3É›^NžûL+F8ËDjúÙ2³„Êû§Jö3Ç3|õ·€è¹£Æá]sƸÃYùu妧8:C—}ù®„|×͹Ah´(Aá°õ“PRN÷u›Š‘c`>&RQšÄh®¤XÔc¿h9ଠµÄì¤*ø&Qã÷ÐxfYã Îr3 Ûyàºj—ví\wá+ˆÍBž}óÊ5o¦Sß|sJî”pĈï# šFÜ©í]„úV/—í °âpžp¾á÷ßånëõFú]—]¹öçz÷œSõãüó¬’“ÀPqî¹)p‰ñÂf5¸úuaÔ¡¤äÒxœ»ùaÄu]_êO_ËBª&—JÚ¸‡‰,nmt¯Eþhñ¬iôümòFNjü1)ÿˆæ±Ê«êÑ[åæƒDH–gB%‚Å‹E}#/xÔ³ ’»_6å×Û'c„³²}T½4mµE0/žjÎÛçxÙó4>ˆ¢Ûÿhã‚°Î,_ÃÁO ÅÕ`¿º™ÅAK«‘Š>Á=ÅÏÆẪëËkZòÚ¾IÍg2v¥!øYíÔ YHèW;3¯ûëd*¶·°‡¶I¡§B˦ìÙu±âƒÔÀ“R|ö3Œ{ž+:íÕRmˆ+ü†·GEŸ‰2 †áa¾ø]±ó4±4‚-dSà„Fc2F6¢’-ê(;žˆ‡ÜñœQUÑ4#Ñå˜+˜sÑ5Wn´R{1Nìó”éÊbÞ³aw”x3V]'²/9‚Ké¨$ùáü’†\aDN*5ãZÌø¹ŽÂ(ó(NÒ0ÏÑ$1Ez·`é¨ÚÂQ§óÍ}Ý£¯HÃü´´Æ«\ˆYêtë ü ´(#LBë¿ï[þ¯Êæ7‰ËÉ_¹÷”Ñ…±Œ”‹áC³¦QqÝô¯" …sËz`¬œ£bò¥°´ ¹¹ šžh}”ÿé1RAÂévüäц{½!.‘è´–“h‚‚€Õ¢†.j/(ŠzÄB`bU*žô”mT6¨À˜H±Q•>ÁɃ{(¯=‚*YƒÀqx–dZ:à\Y@J”Ð0×’»rÁì÷ÉC'H_SèšÅ¶³ Õ÷ô@VJËKu&ä5ßš†³®h2õÞn|ü.OYµc¨dô5‰³ñ÷Ëî)õ…îgYizÒÊ1ãË-¾‰; 6ÔåC&–›µ$é&#ú^ ¨/t†ö. -Û³P“y-ÿB°Èò€?ÚµrY–}¨ÍÊ<D©”âä½Ü¿ßÇØßìß¿ÉC6kÑ,õØ>Îõ?$8<C®¡ÿÀ/Êi0áq6Œ÷{„ .aô«lÖT$uùçÂÅc Ç!}llr©@€?sz¢ôШ¬Å@Ím*fl yÍ@ŸH÷:ÆÉ•˜%ï’C£Ny½žwX*H¯8¹¯£g¦UvT¡@×êb•Ð6¯¨†„¯`dQH³æsè5·ãÏõëî—Ëå»Ó%Ñz”ódAxTJO$Ðt•Loá?øÐˆ.½ƒ.Ž:oÌ¢0Ä'ooB˜ºá˜ED@AW”åß^RÕÂÀÊdâh}ÝöðöëzŠã мĝôð—)ÅÈ¿îη±s.s/^Ò×ÞÝ xâpi<á7Øá‘`_t´j+½³ó ó“JŠÍ®èßÔí6éѯlºTp¡ŒYQDV¾E‘ÖM0aø”l'Æßëý"¤i›S‹ÊþºŸPîМåÊZcÃF³Ýå³³œéQÝìòL/Ç|ƒàê ¿¤ôø¹êËZm8Phôe¿WŒïÉFIƒö§ 8ÖÿÚ0Jë'É}æ #@däS¾¥‚½ˆtž\#ÜèÀíþëøà=™¶Im5ÚŹõ 7!·0µtb10QxÂgöðDV‡ä‘¡;mÁ1©—f(4¾Ð;šs$8·˜A‚§E1ìï:ë€i/ñèΈa´í;ÝÉ+`Íe´ÌÀ¥Ø¤˜d.ð\ï7%ìÃòNìÂh]0x#R_•#Vsй~´ÔÓGí‘8w˜Eϵ©§Û|œ©o…yìò’ø³69\„~ l*ø_?,b£o¹ÀKt“°¥œFw€½ž\FnSk#E ëuyónÔû4)aÃ^!„P^¦ØoM9׳?FFÏÏoôË€Ã%™è#©YÈ“ñ,·(J„¿Ë€ ¥øûÉ`ý~ ‰*v‹Á…{ Þ‡i;ôÓÇÎÓíè8˜ê‚EììòN¶…•ºÁ 0AtNÄ‘˜/“í •*0"û¯‡·3_Üa1´Þ?ÐÉ=`Ò~ *-v¢Á/¼{1Þ¾3i;ÍÓ"íÏ8 ˜Á‚.EÃì,òN<ı˜>/³í@•Í0Bûχ·S_¼I _¾a_´°]²É[`´~ Â*OvÜD0#éZÈŸñl´(JˆõˆZNÊøú/*)ö³8ÔŸlŽ2óô»éÅ´,õd·]uLˆçl€“fž»6] ‘KÐ÷^¡£z™Œö`s0¢4l‘—ÒRÛwÄU)_aÚ4Ø]Ñ0ë9F…”–ªdŸ•5¸òh\¬×IHH€aǵ®ÔM{{H‹ÁQ`‹Ö(|.uoôë±¼õeú?¸Q ¸5ФŽíì¥nÛÈ‹XN¦<¦‰ÖƒH>¼éݱŒ¹$ÁŒ¤cÑ{¼µ£†¥SKâ™$œ$($³?ýbç¼[‘‰lvÄP^°<QG3÷%üvt¿‘Ó–‹~™“ôW¬/ôíÐ]¡9ãpD¨/ºåwœQòqÌ`’|ø½†'e`”¨vy`ß$QÄDQ ¿rA”¯Ë›«'ÈË`Z$™`M]¹9n‘RþkËQ^3i„¨tA}ïŒ\žƒØPŽw+P@<²x„uus!·fƒù•_»•»ëÁ9ù[ñ¿€N J$”“€°„UBiKèijý¢?fJ¢Ìƒ(ö(S A<ŵUq÷9H“—ôz±Ä€Þ‹‡º[é½ÈŒ¡3rA<ô,{µžlpì«H$Kü¼CÜh$µã/}‘„Ãqòìa¬Œ¡or-ù—8}sŒµw‹fQ¢¼.8Vœ†ÿõ*hìê™PÄ`U°<UAÛì/8unÌâë]˶†Xf”u´^Œ‡Îuå£à1þf9)•ìz\ZW™(»¥ÑúE„=dKjo¤Þ Íĺĺ€]¾vDy£ôo•ð1€0qö'ÇÓx`§m4ï/pƒ€)Oœ¾y•€ÅX1Íýƒ "}3-</ž0¤¾È÷ lo¯TøPºöÈoRšû©ª,ÎðQKýÐ;dªµC,õøôô…ðl)¡dvCSË"ïxÀ¶ñ¦*ž ç@ y‘*V×}I¶$tÀ ð| 0žrþ(Yi¢Ì$±©uö$Å×PXÿ_Á5‹ø`±3F{óëlxñ*|÷ %SÙ\Æ÷}!WL &ôÕfC…Œ¼×93§\ÿp“^5— ÀnœþìÃÿ][T8¬í”†p(ºOÊ2HE'ʦ WôÚrpJˆü½ËìyháTt9ׄým¹‘Sy•³8-øA&(%¢Èb÷BâòÞT>ô‰»GÇð×,Ð…ƒêÅL5w_~cGÿz'(4~’/âzЮãEÔ3Þ¾01ò¼P;s»X;¢³4;ˆô!Â\wŒh_yØs¨^€¢çÜ„µï”\«%”û¨Ro2â\WøCt¡ý.$^¼µº$”z¸˜²ãP”QÊMKÆôîßä,¸Û¥ýbægɰĨ-¥47YjÈ›$) Ö/?>Zò˜Tƒ¬ÙƒþõÜgöñä¹á£°G+<é!í`ÇO|ÊÛ~žö¨Œw. ίÝüÕÌ·OÒÌn!BiDŸàŒ©{1Ähtü”–£Ø÷g îRÀõ\nekÚWú®ÆÌ¼6C¢9])Õ˜^ÎÆÉ¨|•É€«N©¬I€éõ8äû'¬Ýví” äÝC‡ ò›f‰‹æF|âó)°ÕÇ^e3ÿ—WUÁÓIþ» e¶°pIäÔƒ· ó—]‹j)ñÃ;Ьú¶É»2 !y*Ù›ži©žÇ¿°@Y"Ö¬ŽOó t¯± ¯P+„â±}°ÕâI?âËAÁµ,Á•rÐé’ð¨!âå}}²Œ[aïˆ+¬€éŒ2K}èŒþ¼„Ž»g”[±ñGÞ1bÏéP‚1t—˜Æ¢ŒEêßõü÷ð¾áƾþrw+Á7ÔŠt' ô§»Ô!M`Û¸ò»0 (ãI§¶*–1=íuKýê`´îi YXüNj©À¥]Üÿ Õ:ÜÐMªŠ¬°î>ÙP¼«ÄšHVUÎßÛ;ˆ—M±ôUÁ¯Û‘ àá%ºüà‹+_I‡W#*µ ɪfÉæ„È—5¯Ž+Ü*é¹#Ê ´€Á,0Œ9Ö'*¤ssHÙRQo$>&Lm9füöÖ'kV»¶k6»í8o î'IðöÍ3+†Å77XÃ}Æ15‘•záŠêÜÇx4|`ú»bÀè \s„<Ðm¡´=Oh›, hÈþ¬e>SM:¼øk慠âäbõ?§öNÊ6Øû-·\C(z ƒî9òï‘ûD¹wÚºZWzáK}Þc¬žÍ3½îß‘¼* 6ã`ÖÌ"ZâÇ Ì¢á"¢nx´ÌοW“ï·Xy#Tß§÷pB£#gÞsjüaËãgö#¼Ã~È| ªozL+ܨ´‚ŸMê3©f)Þão µ±ñþìˆ{Ñý "“q77÷ ¥ÌÂZZõ6|ì¿"ñ)•_«áSKšeÄFòáz›óÝÖ Ý;Ðý!¿ÖÅ1]v‘À_Â\Õ—èä˜0`Ý'ÜÀÄ*Ô)PÕ‘’¤X¢ePGŒÒA¸|zòÖ§‰ ³Ÿúh¶‹ôæ*A„Cû_)ëc¹ÐsÖVÓhŠúµÈ>„+Ž©lg—ÿÉzÛV¥éL{Í`E~׎•`qË„Fþ¼3Ib$à›Î-,„Üü¯õƒÐàpyè$ Öû)}¤b¶×qã1_* ,Gî`µ ‰…ëñ=.zÂl±|-Ôr9l`ºßùn:–þ´ ÏvË+gÆõl6·]m‹î®Cîû^á¢Ü)‡OO«4)±í@¤=Ù6žóåe¨}’Ë/,íÿóБé'Ùç·‰»OÐK»À ì vdjél8²m…éÏeWñ"Á€÷0eÚöÖUd?ô•º©øað£hùxiÞ}3Csk°ÿ1ñ‘‹$¯+Owyùó689ÆôH\Èn¥ðö´âÍYXÉ+¡-?ùó’€AÐÆ1~ÁŠ+ßS1'sŠéwûûVÌZ8Bؼ˪ V‡!*T¿`àj½uƒ6LÜ…ÐΟ°Ñx3Š ÎVЦ,C9¦ZOæÞR•€ar¾ñ~•ÂOϨ= 6/r~µDIò¡’äýG/Ç‹Dmºô_nÛ‰§Q02‘Y³d%Í0…ü=Ååc@ªõþ+,]&]Íd„Ñ@öÄã´,JpõûÔ¡³¬²X \&†žš$NêT_"ò¿'ʶ7ΩdD9Hó®Ú£îó´a.Ø%*Ÿ=_ž…kõ)“O0”æ§…ƒ)󗟱Ó÷ü pýX@cí w6”²« ÉÙR¹×î¯ÝFÞ¶¹ª#²«~ÜÝBQ4R=/CèUØ‹DjùÒ½êÓ·â¦ëZVR¯ ’ñܾu³Lbrĺ’'½rïûµ1ï¯Wk£·CEte¡›PÊ—}rÞau:í«Ñ¬‹è¯SL8âÖôhõêÉvfðšz¹Ý¦ü(UæôéZu,€iNþF*ú0”ô³¼5 üÀ~îÿäÖ0e„Q®ÍÉ$ÎÊYeG‰-GoŒò eÔ F9u„6Ü]p÷ùqOtû7w×–a”o*¼ÝìÕf@FÔš˜3¹ ôwÊ¢ØhË׬äå u}ï$ïV õÿ†ËÝ5zc0à”·*}õ0D®Z`¥°”ÝÄ®ÖQã0y&*÷ýeñ“ûôuïO•2F™~ºt¹`”PÅ!hÌüõ45lË:k·Ä|ÐUcø‡òM:®EG¶Þ=\ïóWLÌqëß1“óÝM)v’Q1ݲҼBü˜~suè®Rv©Ö‰Î*X3zþ@>`ú(f¸>„„ð€ë tÁo¸J–L?÷Ï8ñØq-lØ€[î» jEìöl¿®v•¹éÍpDÌIŸg?xI›.ÌLzºÜåO²wݺ#êÐ;‚Ù†â•y³lÌÜ#dmâÚÎ’A¨åy/4Ékx?\p®»’,ý~éÈš ‡Æ”¸À’`_nÆpZurºp±’…&oÛçþ3qXý•áïãos úß·‘íoZñjà’ÝŒ_aé^yBz@ý„ùGX£ÏXåfÊh}îpáéÌ ‡LWþì'P³ùަ%×ý9Ay|lÛÎvëÃVIò@!ÇÅnT”ÚÎ($ê“‘Nõ©§ š¯U ÅûaÇÎF'Ê6D¿ãÇoªõ‹ÃÏõ '’I²ÝÁ¨ÍÇ%ïÑõ¹MÔ¡öžiäõ•¿‘°ñèíµo'fn€2ÂN€ 4A©÷’^–:”ms`ñuˆŽrd1ó§äË!?oœ$÷+ÉQ²±¼Éàªò1µIŒíZý™'˜ÐsÐ<`žú(oWlÓM×b¤Êk:ŸÿV_ L Ü=Ë“¶" /’”Ü+äÆ 0œçƒ´Í›‘¹ç¼á*˜–â 9hËì—üNÉZm„zóôtp÷è2à^B2Üë3¹údƒÿ”[‰Œc<6ºMþ3ˆê‚pôE~h– Í!Á‚Š¢XâZÕÏe(ä×øð**c°È;õ±Åð/3®7ç™=*ùÉ9«L¾ãÌ©öî*tPS‘&Eôê˜v¤Š"8vDuàt ¬ 9Ølu ŒøÃÚ¦QÉ@ýÓCQ~éý”Ž@õCrÛÔ`XG‘²˜ÖmpóHÍQ íì*Sû/#‹!-øe¡Õó|Ö1üÅ+ý¯p(Ùbßî'³-ÿ’R¹òsâɃ´ 5X@)y+ÑÑMM¬ } }«o Ù/ºY÷üYÏ‹£Le£*G,où…¨*4ÊÊ®ûK.:ž”¯¥ÖAbdû/¤k¿&áÓöƶCIµzùâ&œóÂõgCx»¬*À=Þ/²1dœ à(ä>ŽÊN£=Ã5‹ÿu®ƒ(r^ì¢è „L§E¾KŒ¿œ·†”µÞ‚ÏVè¹àk(Úv}ÞxIvÓ¹Õ`oóš‚ÿeúrEˆý³ÀwöÁƒ‚ŸquüòÃÿõ7/GU¶þ‚~’ò4H`™rz\ç ¬©‚H¸W—ÆÜª~@{&å©i¤`Џ6{6’ÂÇ“fûÛ<’AØ<ðŒ+Êúf/çî ñ+3Š-Úâ¡k¡Ûzïé‘a%xµPƒ„áÏ)(`?šìfÏ…ø…íÝñTøÂžCg ÔôÃ'PìWîÈæ”In1ýÎ?×Tüïƒ|àáp”¡<Ãm/dD»ùâÂâõ’! 0aµó÷/à†M¶* àK„a@ä\Á qÍ3òd æq*—T÷L;æì µË‡ôù–寥~v”žYqSP:ãÛ2i1#qPF'–ŒBA”ÔVÑÚ#VGÿ ¼õCQœqµ½éò¹bA·µ7ïÜ.,T¬mXÄž¬]$õ¾4 ŸboŠ/ÞA¼|-¾X„ŽÅbÜl{œìiÙg<âš8höünef}¿ÁjL?¾WDüµ¸´¶W¸¾@ø¦ê÷ Ɉö“g"PiyB*0ŽÃ—YÃáYMN>Éî«¥ú³©õX0C÷´¡Eì5’”·döÇ£xöÕF)dîjb øš²ÆÀ5!}ri«,’åûùBnIŠ\W—Q½«˜¨¶V8B~2yÑ×)±ôy¹¿˜½’̲ùŸÈàÝ÷xÁÔµ®?ƒÅºêá+ÓãÄÙ³A¿ë*¡o`ž¶G¡æÈŽnlž‚F”ÊV<'ŸKÆ~·TͯG$îw\šì (†^ ˜5ñ³ú8AþM©)ý!ÚÍYÄŒ|ó>1$GVÎÓÿø›2(‰…ê §T†„¾yÇÍ®âÅ?`Á…ÕBz ïÀÀU/ÿÌ{…2åK–BàGcÐÍhùîQà "veƒt|lÜT.n¥0Ðê”l%Gþ‚ˆ9U\IìÔŠ¯V×—Žà2q@”¸N× ¨¹˜©í²Ë/Ì·m|å@Š#åpš$5t©÷5zUÛ0%t£öz¥Ø»¸*ÓËn†`Zñnx_ïTá•.Æ,záɆÃ1Ô$MŒ~²¥h ĨIï!J¹wWÑcÞ™°Y£xº `Ûô`ªyÓÌx_²×,aX¬ZÒÃÃk³i¥ÄaTw»åˆ* ºí ýšäUÍÎ7£Ñê‘Å.kã‡ôEÅ`Cxä1 ¸×«ð›t¬ M…îûLÊ“þk´ÂÝI\H`{Â;p%åÓ‹(½ ùI Óm8ËN„ý)½ñ¤vš³bÈÔf5¥>“À备ôðܤw"ÊM™ Ï¥ZéÝHÕ-,{ùèßüEüzÞœÜh 4›ÌtïPx褣+U*ë€àWfÆ] ñÚ{ è+øÿV0³LO‹ÿµä‘ZÁôžmà‘`Šÿ$â¦dý¾XK†-Lü‘¾ ñ’r™Ç×Þâ¹äŒb~ëY¾Ò9¸Ô…dzôVCó½`n¢´ü ØÉý§ 2ÊP6Ý3Ú-Ø•÷¨†,x÷áçêýÍXF~ ǦšûñŒ KXY¸´9³*ý´3g&æ’`´èc’ô¾l–ÝÕî”’´©U|Óû¸¨N³SfY5Mš÷ºñóu"mÔ&ÌDÇ[»¬MÂ…¢¬KxÇ÷Ôqmà*K'ØäXyC2Viý$AâÑË”_Ÿý¾éÚ¤ƒEÀ*Ç™7†Só6¡¶4B’Þµ¾”ãFøí½§* a½Ú Ú© }rˆ, ³)RÊúyë²n6+ÐôKíÁÖW½»áPÐ_úML↔¤'qÍyሴ8a>ÅÚj6> ðv¬Õ‡‚‰Yn«! *DP™*Úæ'ùãùµ¦O¡É¼Ã4áËuH#Q÷ÂYpSs®¨LMN´g¼ðfL´•Xm ì4›“¤+L ÕwEZ¹v3—ˆÜC.3Ѓ*_Cm…ˆ´gŽÑŠI˯t-âëØ7ÝíГì{« jQ†BRÑTs*‘Xóz¾ô¼¢â“Nôz‘iûc7ÒbÕ¬Ú¹<{g¦ÒÀ²ÁXtp\žª%¢ÀÛÍ…Š€Î3ÏOèÝžwœŽNEÀ£[Ž^ü+¯[Í[•RN/ˆÓ.*W\ÏÐÂ].òÀÆIù.¾>@ä‘pŸƒË%A”)™×Ps|éu]e£1 ¢‚&¦Žv¯w:+;s÷èŒâñ¤œòö˜u2âÓ¡ýqi ø°éi‚ü„ƒqtÁ¤XÜeûa€ÄÑÃx³{êt*døÃ©En©¯&):KüMúõÔxdfÀZbÎjÙ-dÂù÷6p j{âPiwêÌÕWdö_bxƒñ ô"h›WN4‡Š>çî“—º¤ Áw¾àÚj6w~ë'žÚkzõNü_Œ×&µÍÔXÚØ÷WêÜèQq×y"¹LÏ –dñ…rùûH5™‚0Ÿ¦iÛ(1¼ ö¬RÙ ï(˽¶²œ[韛Nî5:¡˜,y+ TÔV´d— ˆ/©j&3 ¿6¿Û …6ɱ\À* ºÍ<N{‚Puö/¥#@o_ŽËOîÇ;!Åk?!øñ—&4—úŒ(@äÊ”ãzøálÐï< ûfpýãræŒìpTl{y„ê³›’N'ø oì÷»uíDÕÐ@î]Ò~lVŽB‡ID¿€Š‹óäv¸èéhµ0*ÑØKƒÿ$»`‡ËÈàë®PBnù˜HsŒ¥Tú$gc§÷©A˜$@%sftßm–Ä[w3}l¡eÉI°‚\ ðÂñÈ ûrŒc§lÂ#0Ý8Íû~V4Ú/lK<šV¼ ê.ݧ¶s6ÚôM\F0ÅUñ€àŶª‚D—ê™d/äC¬wàÁP#Ø;XÖèòfì ¥ØÁ`±å’ êmžan÷³ós’W©‚<>Úf+§5º4Ì1vƒé d¾ô E‚ëº÷v%ƒÅÆ}PG\x°`©ðLÞsN*P”:œèðÝɲD£kÑŸ)` CÐ(Pö5ÿæä§›¸Â˜Óejñd%ŒF¿Í¨”&ï$2‹(0S•ümÞ+ý¨í^H“p1‘ÆÐ¯,*ûÛ8vômºXg‡ßRÿðuÕ«8€™y±(1mO“_€ò ˆ«ý[ߥ@(`PvQï~ϰë} ù:nz0ìe¶sòøú¶u3BÓOl•6*te4\ùÆxM°Ï0Œá®,äfÕeã× ·sª<T‘P$”“ÖÁQD`Á`¦]5Y+uø¶¬X§d…÷¹,üÂÒOÜD¨*ØuZìñøû˜~÷ä^üüK«-ÇɵÅ!Ìñ7ü5n niãÉz>=tû.0‹šT©ÓwbŠuâmvÀf)´ê\{ieMÜ)Zðgõ®ÿÀ¦’ ¨ãÎô ƒ£ß6Áòî÷Ë/V,_Ü쾉ͯ:D»èÛä16¨Žr-zÔµ5à+H¹YÈ£kWïíwácD"3«"@- CàLT Òm(:f*ë}Æi¢‚àϸe|êv@ÓÜkKúÓ“Œéõëmþ<¯ä:`}F©7>#×ô³xÔF,*QU¶Â'„ñË}{å“] ) »(¹ |,½fåEˆÏ8 Øø{þÑ>š²öˆ¦ÕžtïÕ9J‘S‹À´‘QxDþ¼°i Ÿ[Ë4tg—Aü,F@EíO—ö7sñ— z£K!»¬Úæ¤{ê¤ôLnÕÈ[a‰°în·|²w°§BíÉI…½´¡5Ï*ôc~÷vÕbà€0œ /€õÁp°TÎõ3 é”hIù%mMâæ^á3‹Œ!õDZl–ògÄóèË‹Úòð8â'zȘfLçþÂqt]ÃAi^âÆ{Ù9ûås!u@0'÷èkã!œ€¼´¸¦•cˆIvúø@ HÛT³¶ÉÍ)"÷`ÿr¿ín[/ ë §Á¿Ä3ujélov°¥A§°’‰„uDm#Þ ™B—ü‚*å:Q`´9²½Ñ<–dF©hs½!xê(œ<J&@4åôU®šãŒÚ³n0eOÞÛVYj¹‚U#öJçÃÔ“Ø›/i@…Â…ZRÎŽäÔìC:•ß]h*5np4nFtJ¬hê,¬´‘¥ÈŒ±í׃·kˆ|Æfů#VS«Ì AàNpxû¯±’¬•-Õ=sR;¸äËÆímgƒzEþôÉÆÌdÕC«}÷˜«tÇÍ&JúÙ>`b´Õàcô!;<¼ýUa"Ûl±x¨ dÅ\=”3&Ñ…%3…@ÊÍ3Ù]bd”wNÙôK^!îí)ÙHsX<à„MÙÛ)<_ä+R§ªätÃ8˜,˜/ò”Üö:õÅ]¸LÜ Îè4Ø´*!#r)Ï0*õ¤lÃ0…ýJ¡ †[+’ÉeÑ÷ˆ#H{µ”è¤Û'^ú_xöܽbpÝ*Ëø1!–Y~Æã¤ˆ†e z³õaárd߃/®€·$d3ä\mÜ{”•å^hspN€·0aUÃÂx|£y)ì¦1YHµlÿÀ\xˆ!FÇUcËÇ”`£ÉÇé H(©ìäÆyô”WcHI{\X-ʈCËÑô”ª²Ü¥³Ñ´”¢ÓDác®¸…ö½vH³Iã® (U‘8Uó£z›¡Îà´h“ 9Fˆ±ÙEua2ö ËoL(¤òá¸YÿÙ×öü˜/m½ ]¢€±áÿ4¹iÃ=¡ãŸ^PíXhÐì(¸~Ôxõ(-p¯ ˜ˆÕ8ˆ€Ã$A˜~ô(õ¨-¨«¼ nì˜Á¯Nmá§ZyÁ£DYy×n]ÔÏ4aÇVåpn±Ô÷4õaïK¡ÁïæI‘»m“˜Ö¸q–e1ÙF}åxþ¸ª1I¶0Ø…”M½ƒ-¯pÕy0(n¬Eü3õm¼Ã¬‚UÕpÅÕN-8ÃÈ{4Âh{t'YÂëÀ,,ÕX±Õ·NDÃH{@Éè]8KèÌ/Ô˜l:žNØÅÜN|ÅàZ4ë^‘û耴ûì€\«…y›0xn$Eœcõ=¼ëü€@«Xuyó0ˆnÄE¸“õ!¼×€l«pey?0-˜nÜEüƒõ5¼Ã€\«(Uy“0°l˜{ÌÂ`<ü õkrrnõ÷ŒºÄº±hîkáw›YæûáyƒÎ\%bÒŇnsrº¸Ó¾_í[Ià.Øñ>=Ñåôà¶PRkex\He²º^>¤clAuv0cXØ¥)»òô „Ũ¿·ë´*„¢ÜQc{Ò²´©kw(xƒ %(¥ì4¥O8Õ'Rlã°ß&¯E¹ßü]}btŠÝ¦}z°¢ñÁ%ô, Ÿn´Ëaü4*ÀÓÔ ³˜¬>´;záì7}Ž£ š¢ŸË«j<d 9{ªÄ„ç€Â±ˆÍ.ƤÈî(M³È,V š#h9C¨øuõŠç_[—0=лmgç …¿×cH¾’’68(,´õžx«£¨ž¢®Od¼IQEÑ»álá$tÇtÐêìÕ½5Ã.Tö4Pg/¬…°£=Šw¾„f¡ÂÀº¤Adµ¼È¹qßNXvb«+-îÆ}ïrÈ{†©Xt¹à^µ=ÓºMÔZ2Xý/>¢¦%[b«À’k$äö½V|E&Šï àÆ} É[AruQ¸Ë) Ìeƒ¯ëFѶ⸠•|pΕ*ƒ(œõe¥:\ÄØ®À àÉΫu;³*"³7P‰o€UNèÎ7/5j@µ6kkù…B®ØhÀ™(õÏ©‚'µ9´*v+‹ÂXêñTó]sŒ‘¸/”ˆì &Xà}ÙÙrñdôÉüÔõ"ôÃq¯»Â®˜Ë’rgÕjW;"»ã¸³´)€½’ö5€{ÖùÚ¶oèHHAó ÝT…×fÌŽì 9Ý*»ØŠÝ êöÓ©‹$üæ©W‘ÄÍ@¥©Ð–¶ÎoÈät…äwº£êí>vn¤°ðMƒÇ¬1t«ªè«ãûs¸9¤Á:Šõt|Jvˆ¸&œ wµ0Jæd Ì© 5èã“–ìÆ‰f9y«ÞíÿÂcdÒýEþÆdì/bxêïb‡³Çô´Ç+ì¥b*ÒwhëÐöh´OÉá\ó—8ÿV+&îzuÌ€›~l?}&‚?Z3–)%KJ„Ì”ÍšË ‚…µŸ†8žì^sãý”â«Êf¢asÝÐ eþ(úœæk:×ÛóP,¯ö {ö}Û8HÈa"7c<]‹ù샳›Ä^Þö]TTÁ#ÖÛT³ÝüÞÜ£/(¾Ë+>µ¦2ÑÌ-*Ï 7Ðk?#b¯eážö{drú*|—k|µ¦zelLˆ…±‰Á‘+†™kZ„ÎÑ-T “(‚ÿDÆ©sW¢ÿoC¹f¦&,4†Á° ¡tž-ðÐw6ž3I®ëÄþ¡-`°ÂnGƒhõ߬P î©„ŸîÐò ½¿2Hsj°0+²¾÷è•”a¶Ïæ4ÛR™w«®’¸»’3ïB}âó ñe¶·]žƒ\áÙ¤ûÞï£Xºõæ;øîdôùb}óz*Ä)y½4nòÖaMìù]MòÄr>ãáAÓÞM0Á¼ù@Je¿ÁàÒ- † µYÒTK'^ͱPù^ÓGh_„GÍO†®B舯'_£á‚÷ûª(] h¯µi2‚(;Råè³>U^cózRM©v›n“Yh¦í—Rvòîe&ýáºLùÒwÃ(Œjt+±q¼èðÂu5ŸIw<"ÍåТaq/l7¨q°_Vú×»B[ìff.`*XV)ùû#ùË÷ýùp?ù ލŒqž]9{ †ê^?·ô•G¬…ÀÚ N6ÀåMøÕmgcþ³–À›–4ܱ[2.‰4Ux tæ£0¯£6h\·}¸O{\ží}`·@üåßf€ž+hh´°j„µl3¶´…gÍðiˆ§}ø‚kãö~¼p×o{ö99Þg4Ôpï´q—aɇ`Q~ ,*¸v<ÁÈL{ØÞ\èi;»Lõ i;áÓíÑ87˜Á‡ß˜±^¤ÀXÀñ»” N¬‘!\³ñɋᥞ24dæá9_µ·Ÿòž)Ç€Zxï_ua“´a‡QÉ·`A~ <*ÈvLÁØ\·z_3¡…%”Þߥ¹¬Æ+“»_ÿ7îÔZ¬Zµ_ÆÈàòÕ¹æØÁ½ƒLpÊ€g”´Ò>Í£ç!¼/À÷¦KJÝݰ_I¸}«}QËg’å]¸Y£ÃvI|â¼T-Ï9ÇʈY)P=Ùº^&4Ñ™ÝÀ%A]a§ÆdÈdWõ»3_Ì0FKkƒö 7+xFä&H¦w|òèópV;oêZOÿi:+XB²ùGAIàý|øT}âê]>æ_¤üìòÌú¨¥üEéÿ€'ƒ€öoUÇÞŸ»)¿´E^sH`RR;|ò U•±_Ð@`–°m²ÞÈP‰Ó¤à”`+x|à_Ôµÿcôžµ°N5 Í6•ÌÙÿYÝÈ}µl§ŽÈåà ¿•hOÚ®t š›2óÁm>õ²© æ£{ˆÜ—HƒI¹ôº*à=¤â¼g2ö“8Š‹âpvÎÀAq¢nC6óÝqš³â†:*ïB%]îË£Û,cÆ;áîyVÙ“™<À/76P/'éÒò²Ò•hZíA*×stºë½0$±}{W1‡kQlß?-ñ“adí~c§\ôp…ôK˜•Åv¯%1cÁ.µÛÐ/IˆÔ^ì skܸ²¥–‘ÌQðÛpHUEÿ¼}ñ”sმ¤†¤k~ö–gôù#À9†‚ ¶v|zÄçÀ[gtà"uî½ín™iÅ"w®üç ‰zá:xà;"¹y—æzlÃwYºÖ+ÉýîsŠ&…±ÿö¼¦û§Î ÎÀà#´GÄZñÙÍ{§Î;÷Î*°Ðoµq¦nj÷Ù „"åÓͺe RUõÌEÖà4èšHzê/rÏórH°ÆºIs~M—QZòò¦ª²‰«ICBÿ<!åÈ5ëº}"§õuÔû\[3 8Þÿ‚´£ÝƒH…ý¤ãÈ7h–u£D9˜³3µ·¬^}Z¹½Ãݱ£{[M;¢ã†¿Ðµ©¡‡…cp„õ㳃ù¬4³S]vGKq†(.‹Œ‰æ0{¾äuâüY\VFV޻輜æf†©µ“dÝà”qàuèøOlYÿ’<‚**—kølˆL¨â%læàxþö²Îðpµ^Õ)ýà€]øél¡óÛ6§¦¾Ôxâ¨|C•.Ž1cOvwWøª½ÀªüÛÑÇQ©þÄ@KÄGiÌ1”õ>n€ìlÒ£UsA^P¶@c ÿ›€ ÎÚMìkeÛ®¾GÏ¥ÙËñLHËüFjJàUç=ÓôÝòö“h€õe1Áâ÷l8ëlƒ8ïm‡å }ÝÒnXýHÁüaƒÅéWc¢þ_ÆÎp_æZbÌP¥òp.k8 [r¥!xí;«Ìé»5â @4ùëúEm¢ánæòWàýÞåÇcŸTd0™¹ìæ‘N@äõîæû[jw°¹–ôOÎÆ% ðhoæÁ•ÿW™„yEû4Ñ+žRòtI<¥ «$ʨЇfÔ÷€ßBïdd”¬I«„Þ¶(4Ÿ° çA" 㔟k¿±ˆUÀÊŠ½é&ÐÀÅI51K)¿l‹ö—hˆÿø0˜ûÿÌà _ÏW„Êc£~eõŸØc'0lœî=ÇäºÝÓ O¸Ó$ÂCÀ"?õ±¾>**ÿ‰®ÓÏ*Îkº97¤p+Ü)à]m»5°·íÆY_…2‡ºJàâ’ÇøZ½³æ¿»‚¦øÉäâÓŒ¡‰ùèâVówö;³üEú=òûy¶×Ô>pÇye¡„ÇyÑhg„Ïr¬-÷ í#ŽqËy¸«º>p×y·'»õ„Óy+áÄìbˆßyc–äôif%Ì?yJ‰Añ§y(øS5 „¹€3Ä“ ’ÂbÿJR³F¿uAø™›Þ<ºú'Æ t7nT”ӺϺ ›i¡½"/Û]rš 8ʹ!åzZÊàÛ’Òª§“TàÌSßt<b£ó_cGÏd yˆF¤ft« 8¯îJZ¸yï=]ft¯&àKütfWÿ«‹wê©ýŸc0zõ hSµˆøA– à\Ñ;çñS€¦töâ*2¥èÜ€'#惼ÍñBtt›pm>0 ¨[ôeØÔ`§¾ˆ–iŽJìü¨î¸xÔ~×v+ô†ádJ÷VD|5~Küß™h>ð2u#úöYØ6Œ¯¾Y(¢B˜›æŽØvi»\ŠuŽ>€[÷Œ™ìs™U’Ø›†i2["Q Kæ‡j™ íù93 w@¥žÙoxu ‡0 ΨЌ<»~WÒ›8›É׆ñä›ÞŒL;•ò*¥4›ÌÌ7Z6“–ÒÊô^ ûQzµt.?ÊJ“<Pgw#³]v¿ðÕñ²"}`0~®Ós׳ÿø;u }h²o0Ptv¿åcªªW%R•Jøàð†îÅühÓË!î/šˆæ¼øÚñº*Ttb'#æ§FŽORt5}`P÷®cl•üîä¤}_ScˆÉ•Fm¦©øý0þw£±‹g<Ý+´toâÛ°ÇÛÛ0VЇ˜#Ìúâtx-ñÛD”Q\?zºŽ«×·p“˜9?°@ŽÍ´„b¬ã>ºoç»Jàæd*µ€ry÷×Äåd÷,]ä ì‘(;¥÷Trx¨õïtƒjÛXBùl'`CŠå…‡È6&”œF ÔŒÜ@†Õƒ( ²ùM¼¹>ùn̬2æ1!yì‘Bt]( ÐMHHKoJ Íñ[³‡úµn)¯éü”p:XD6BÇ „ÕÏ´ì0‰sœþ½‚àæ3wA$¬£Ù™à»\ Vð’ßYXÅÃ¥{%(Cx@FçÞ¥ìÄ8Å´KV&´SÔj1óŠë)oܦ{Òƒö¦%׌.ÕCÁò¯uŠ8<í²wÓ‘¼£Ê[ø>S^Ç›Mn©Y·¹»hÕN¼a0Ðx–ظ¶ÅO!J V޹û^¼éÙë2;¼N>br m³n xÔ¤VÜb„äXîà ÁGïŒÉ{´M¬ º·‘Ä+Ü’uÿؽv5¾oPåvÑ…üàïÔ<–3]dX^ ò×÷]4ä« ,öi÷T|U–ÁM#¬Àçã Jšï5×?$á2„ÔÈÐ<#S8)xÕO ÄÒJ>ÈÞ=Kð¤8L¶ 4C»ç0D¾·-[£³,\ ¿IPª •-yb jnÆ”Àl +}ûç«®Êó`õl›OF*„ìyÀx[¬×+dàrÑäèðoJ<޼û<27‘ËÎÆmÖIWäk{2(ï4vÑ•ø‘¸‡Ûnßa£i'ähT%yz¤8÷ãeG›1DM.ãæ|×z÷Ä_—<–7á]øáj°0Æãœ'ÛâÈqîÓ[sÝå„tö»¡Q‚…u¥DÀþœF¤›#¦ö¥P\Ȭ’öÍ:»çƒ|"®:šþûsŒb½@ Œÿ/Ðÿ£Æ‚•ÿ)ê¢ ÒjÊŠW1^ËД {Z ~ŸÚhWɹåøÓx¸TôWV(¸¥/X‡®Tàp€åÌõ^ô]OJ'¥?Ãr&ð“MÈâ5}î+„¬Â+/û¦Úiî©c ƒõ[k1Sd¹ž©!äæ¡çgž@ªhâõ_‹®¸%^wsl{'Ä}øÖ Û”ì·? 4+ÍÕp8O†&Fèüè󢎣úì¾¶*W¹G=J·E[]ln¬A¤ïð”(¡Ö^zsÆj—d,£"†c|r®§¡ë¤À™ßˆ‡zñ}ƒ”Kް„ÍïìzÈdnpµÌÿ¹’§Õµ;C5¼L@æ÷Ìõ1~sn62 â -Rm</\ý>÷;í è=ú[Còžù ž`®D}›Õ܇©îBÏ*‡ÆAÛëI 4ìT¬†XyÙEmø} ´´`ÝøF™Ž¾ i=vñ%Y‰2¸O—ˆ*àÆc³ëô œcž&¤`ùȦZL”ý–[JÖÙágKãºá 'å@3´í9Ãûú7à} @ü ä®—þ;ùñVsìØã]'\“W¶zwS,÷ñb±—útN_» êÞc{–aXRpŸIfžä˜í8õßð9úW%˜È\õ~·¶í‚ï¦ò ;ÁÆ-ùBæþÄ|•pLzúûìŠïÖeB‚Ošç ã0샄âîµhÃŽV®u@ÿn wðg¯Rw^Ô¯XïÛ³q%øa®Í:_=Ñ÷GÉÎôs†1BÛäåtN8EäïáØå#5õýâ»Læo*¾m¤I1èÓÊ‚ÖyöÖˆ°Æÿ„óáàvj2Ðåd„Íßèvÿ|¥fõr-e*zº1؈©MßЩ„Õlµ™ö:骃þ¡ñNµqÖn³8áýìF²ùháˆ44*ðyhXüͧéãÀ[Ô…2èw•¥—lÞ,'ܯkפ“Þ6¨^ÝÞ f„|2oš‡9\èâ€U‘ffBl4”dßÁÖE÷C\2õè‡ùì2æn·1~ï†a~ûÆ£j¯—‚°<tX´ÄÇÛþƈîÃ뀼ï9 }ƒªu9нCÀÔù"~Õ¦êoà˜ëõW?³‡Ú«€ãØm»°g³^vˤøiø¢uÎKÇm€¸ã®SKÞl d÷í¼«H(hR-Eø”q@f!Ê,šâxÔäÃÉÛ3qm¹z*#â®p(ìë'ü<ÙýG70ð‰Ô•òÔtH漄&›z÷—”qE†Ÿ„ê ¶Ü0‡rÙ–Ó‘Löt¡£‚ìpŠÜówÌQ5ñŽï:2®w=ãÃ=œC©ñÆ{Á@¼‡î÷pG'uìá‚rXh©4®ôH–höñ°ãúŸw7óŽ÷2O%s]…wsg(|£hEq˜àHþè-©ò |k%ô ä[|ıÍ8Ï`‹†}Ô…³]݉ÇxälµðãrÍFûX‹†yÔ…rø(êO !ô Ü[|ö%ŸA³ÊÜe «Xk]ƒf¦L2¤CðoØÐÓá£VklÙ8A"HÈÜ(¡|o™øí\5mNÖy¨µë…Ñ ô Ðl"Þi¦`ís ôkôÕË{èPŽ2œvAðIùðù#zй"˜ÿ<¿²ð;|é~fGÕ‘†VûþgÓ5Ž…B {wh(ü¨ìG%Tt‚4ƒæ1Mbl!¾2É+{>c£zÕ¾¿.‘{ÆœÍ “µ‘˵Å+pøNœ|wXG%\x… p]/Zìm@H/D.šZì…•qûÍüôɶÞó$…4‹Ö%v Ä)ÐzÖÈ|£×6ÐÓxo+…u%ú¹¿´Î…x2-ô ¹[|Æðìã‘Î k^KiÆ„Ëâ^E9ô µ[|÷KŸ uÓ=wd±[~ÅÍôã°…´¬¼?®öØg•'ûôi4ÛÜ(ØxôÖÈRl‰f^òHÈÜ(Úvc±Ÿ:Ï\¼îÏý2,hlíR÷uÓ'Cø(ÿ*ô ¥YtÉ:“4ýÆ{Øî¦ÒTc]Xg6H :,€¡å͘]Ý ¢[sÆîÐüã‘é d͆àzÞù=ž*s¤¨»Ôî¦íQdŒiíÆ×š˜tñžàÛ2Üãø<k‹]NKÇt”Z øK¨k£zÐà°LÜû+•E]|æöö²8û[cfÚTvë ÀÂ}´çñAÀ˳‘¡j¨)ÀJç“àèm¢K/h.šú£SkÌi}ùì;\×|¤¤ ¶p -…6Òì!¾2‰!|ù>§4ÐÀ{ôî¦þPkSŽ}£\E6…àƒÒ¸v[`5r‘‡¡|Ä Ž¡ÿxä µðZ–¿ÐÓá£km²\÷þuñNðM ßnNMÇP–Úäðño¨HøÙ(|FJ¦ûö3´y‘ø™6{iJ« ‰Oy×ûÙ&š…L› ø1ûH-ñáBGö·íدtÕ¿pô@ÃNËe4ˆ ußëœÀšë‚Ó[:2¡F¡Cõñòb®Òd´IP=7”òØoJaÞ>äöbÿ»÷‘:B…ò@U9.Õ8SUøÐÔØcØäc | ó ±tIô‰”žpEZ“o[{#šŸzâZ@öä©=8,”)³£WâãõÓïÚÅ?M?Û«,WN;:‚â+âªoðÒ¶C f^îözï'+ðX`O /Ã]¾··µß€ëVÑïù”ˆÆïõÌ÷Ñù÷Œ«Üb±¨)¶Å› ÕC®ü´øøÛ+¢pnâáô ìØ¨üކàMù²l˜éõY”œœ¦á]ZY=v¼xñÉJ¬~åR V<´¾I ö+cöÄéíç3p¾TH}$Ýϵ8üŠ‹ýé…HãÁäùì¬|Üo•xÔµÁ®‚8ðÆñŒ½¸Ó©wuõëƒÀÏ訌ÈÑÄYâôÙ¼*1p v{¯þp)ëk§8áùÖƒèLxsA¹ —ɸ§2|?STðx.:ª,ñöá ˜{´f–ê‡ÐÛúNî™ð>êJVGB<8OéD,ÀžXûì¸áifòY”d¼Eƒ/<”¢ÚÙܱEÿœæ¡ehTê^fr¾@ÀÿËEä'+IK¶®A,™-Èéïí¥Ã.ƒîc{ÿ¹Xø±:]ØÂöçåËp{*R 0Ö¥<f†›à ¸ÿtC²/Xx¤pkŠÂøýÎÑv‚޾ Û!ÐùóÙ¯kÏ$@8l+\&Ip#ªµläúÏU\²óö#þ÷o«ÛvBéu4sN ëÔ~Å÷öO×>äeùóþÏ➼ɴj¥³µQxëâÄNùòòjAÞ³ÿã jB#•Ákâ#èÊ£Òtƒå8eܸRªÀt^ö5ñÄ=¶³ã3O(Œ×4¦°>C5óH±¬ðÆ‘‹ÂÒý y¥?—F*±FÞ …Ç*ãŸ@uS&+Ú^ãKþhb}Þ©„3¬Æ®òîu·Š¤þ³´I–Ð:ÈàŒS‹ôV4w‘øÕh*ÉF? UÜ‹öà'ZydòÝ™ëÍð(²o0÷¦i]² ‹/F~Zþð1´],}‰<ˆšÏx°´’ƃhŔʀdÒÂøûT@E”±d|µ¶ÔÝHRóæººÆ3É’¶¹tið~bcJ¢?3¾ÐÎ aÇj9Á@žZúB‡mÜ%½‡uÚ~[DîüMéo@åÀdpž-6 ¥É`ùô3¾x84K7{öT6ÇÐò-Ýu>qštµüz®8XdÈ|¾vÕ)üF$ÅËl+–®»Õ{¢4i+w‰[DêdVPÐauaºjRüý_‡D^¼¨;à}wï1²ûd¿S®Ì Ñ2@„Áª„oUO:ÉÜûÇÿbÞ¯å”6Cw•OV+pš§ „Á…ÚGÝŸÍd¥ã(1; H¾<ßp½#Q‘˜änË«(Y÷>|âA2A>j„rYzî\=TË8Ó‚nÃÄÚACY÷ËøxsŽQöTøÒ5jï´[¯AJ˜Øÿuɨև°þ·»N#¿BlÉ,àßZyè/×ŊعÄwÌ ´4ìí¦ñµmÂÚ_)9ò¬p͔ԼkÌáŒõ.QNe•ôß»Lê>µ´z¹oŸ…2ù©ÈråùXQÑJâè”ÐÖæ 9Q´â6ÐLm¤±; Ãxuæ f7í>;âïXÄä‚_n/Üb$Gü0v ×[ä´álÞQ┚IÑ©½’ Åj‹.<3WkNå~ïN¥Þ°ë!76è±èF;/Qx2…aêÄÕÓݶ͜¥ý nyg‚\y_êù\>Ù#ÝYÈÁ˜Ã× _Ònö{õn ž¿><1 „ï]åTó*`ÖuÔ¼ÇÕ=ˆCÆÄ÷Âc˜ ùùĹ?²Ä‰p)в›îÃÔ–®{[ÈüD,>î˜áSA\׊Ìg^^VJ!H‘/(sƒ˜²ÌõUŸDµÅý ·ˆrô_w·*z(DF%n]ÇÐX+»ã-½ÌÓ¨4UW²"½º±&s³Ä+ð*H‹wáÕ°¿-Wÿ_¢Ô#l×9PÍÞ¢5g +)†„™Ú3ˆ“B da(&¡À`ªjȈ’…—4=Öê¦;'ú *Ï1â¶ÝÁÞ§u9IoE²Låž4ÝeÄ›°J&j/¿åm\¢×rr-?¶÷ÜWγŒx£5%àVü>Fq{$~çÅWìÚ ¡x%ëkʾfvh@¦c[_³ïšbQ!KËNZn0уú`<Ò$”ëöæ³fm}3Ú-üíÞ®Gh’!Õ ôõ,‘hng<Ф ó>ºMÃìHG7X~¶âp-ÿb2ZY÷ ºå<µçÓ#ÊÝ1zýÃå…_ŽìÖ)ùž"å´—ã´â¤qkNâ{âP¶ÕsB-0>I›Ò*q%!lõÖÓ«tË\ØhÞè/zRH²ÖR«æÞ9fêl×ʲ¨,¨ÍúqFh” |ÿ¬K>}`O/uÕ²îÎï¥>ÑçêY¢0©¬ %ØÌÇÉhG u5ÝÑœ‚õø„äÙÁkàÜ¿ÁÆ*®_*’úqѹ[:Æx-ñÿc¿Æ·/äuIÐDÈà!ùKD(GBaaâ·’)%y¨Qp=g»øáÑ5y“%Fña¡7Ã’‡6ÄÐC.S/QR]WNÖÙ,’¦&e1*¢±LÿLPlv>@%ìœÙ,Bg¿»¡2èòÙà(šj>áZqõO*¬³8Í!àž4E˜€xwóáö°¹‚Àê(Ž$;Uotk!;]Q5 Á„¤å(8#ò#xH¥³ûÄ–pè]æ(Æ®³+ø6˜m>6D>ýØ•:ÛºÎ?«Yþ¬Ñy(OOt[¥Z‚µª"D¼eyÚc;?ò4í»3àÛ¯0—MÎÕÎLQéøt®&ÚñHh [zÍäì?¦iuU{Dl|,¢Hd#v(“÷´«£°+£ö¬ß Ô³4ø±?Û˜K#FÄÆø¼8áåR;ôTöóâk°æ¨¹ŠÜuMÝÔ3ã‡M „ù¢f“9ÌÖm¤5@ß*]ÐÍ*ìŸó-ô530‰ÄÂx¤ýª¤pâG$µÄÍ÷¤øf …¸ƒDç5ïÃÓüy\ßûºp|#é MBÀ¢KÄyqSu^iNàµèË_‰*O F‚iZÆs4¯cËœœÂ:¡T°¿pîj'§Þ1õsýgóƒè¡ÁàÁøø’'°F*ƒöoHO¶Y:ý\ÈñúŒÒz‡ '{,ñ]"×–m#K(l¥·ÖŠDö$g_ÝÞseõ7tA·æÐÚx À—„¹Aq¼b£yDÆ?I 5¹ppni1Ѱ”žÇÔú·j”È€²hìåðà“gº`rƒþÔ'Öx±‰¼å}O "à <ͰFXêiëz„äµ1Í+ö}³å`\oþÃ5ГzÙ•ñ:c&…ÊEÔí¨T_56\³Ì,ܬÝÔ‘Ø„A‡;its}¾Ê@ñ)¯7´Ïë(·¬iWâÀ“îÅÁs{Y˜6U%t÷ …bÜþ:~ÚT¤G›P¢·k~åyG¼ÆŒÚ=¤ŽékrR°™»ãy9‘*ïkñšº£Q¹ìy×gõa¥4|ù•=9<`vªl¯o9hÒ¿mjZÖ¨ä'í3·»âÝê}ÈÍÝ•A‰.<÷ú1z™ Gïá…$H2ÌUÎ-ˆæ´sχõô—Å–)…1'Ë—Êâô¤Ý‚6ß„»'¹‹™¹×>´£~ƒ‘ó(£ª`ï[²ø@'"Vš¶;‰o¹LV.[±ºˆ5ÏypgP¹†z^’©8wÉ›½ –q4ÃáÕO<¶I!úYšïR{k}º€Ô£~_ÄÏ XŸu\¯À° [tà—¨íb<\ÉZl?Ø&œ…QHk7pÓ`€üŠþÈ0\I¤ÀÅöžû•™[\¹|]óûo¹Ÿ¨žušpÁ—‘nKî,5g˜§wá+jêTŒï|è©W_£1JŠú™<X©©æ}öå›~+§ÄpƒñÝ~…è@ Pã=KËšÎ=ySÂW}ÈY±AØ4Ó$P5‘h¿ŠzŸ{6í·hïþì:nÔ#ÜëÖWÇÛ3Vr[ÔöUñ_¢;µmê‚÷ë \K(Š{u.=þEÕM—2§dóˆð¥IûQa?õTÀç@msÕ~¶ù12/€×t‡X—#D÷ܰüÌÜ.zë93#5è2ÙÎê™Â[b/º˜ømühãðPäEæqâå yíÔÑ(B)ó!t¤[†LXNÎI{áÞ·8-Òôder[íIzvu5BM$¥ì+@ªµ1Îç¦õd@Wqd¸¿ŽÊ,ŒdäUg/uù>å“ <-ÛňXÚg(Ëhv{¬ý(åOc$fá9´ñ³GƃÓ6!tÌó>4Ÿ#ÿ÷D*.†p„Ì·RíŒy‘‰²û='s§BG˜ˆ‡2VyÞ<ºÉù&ru?»óÆu`ÅÇìü µaÇâSNîví(@–ý8• Öú¶Pé;•Õ.ÒüÕçRÕƒ}²ýè1aÿK¸ãI%ájP%”?/·ÿ1rö;wùÛ婸~žX ¦sN.íwáI70·Å~õã”ÂÉõ…Щé•ï6ècëòà)ÙRë÷6àµÿ2;¡ã’뉥`¬îÔ@%±@rœ¢ÝÍá©c#mô:zorø;uHõP@rœAÊž¶Æ°¬g¾E ´XÃé«"QN-à5KXê»v._Âl<Tµ¨r+„RöåÇ5_ÃÇkòj(„5,"jiŠ/Ýó¼\/½Þ-¾‰4†FK¢’5ÜÛzê¯ïü¯˜K¿RÚ}òC;ªHõ«@rœœÊžsÆ™÷˜K6âFÔÎÐZ;;Kcý%Iv^Âôù¢ ÇhsšˆÉ…£ ˆ»8w‡ÜÃìÿÊÆYøŸòJì¨V™‹Eº&Äó%ƒ+¶BbR¥Uüè f|º0òt¨ áŠÓŒ`[óù§¿\’7õç_žsãÀ/÷Äs–*[;ÏÀw‚„·ž©üìÑ+ù³|*Ç‘± ÁÜ_!½í¼Ðÿ+Ÿ½ú)Al`’ŒžÑ:¨Y3ñ F>%út%6WFþØ@D™+®Üs‘Ê3Hä0Ü™Kë®ÂwÔ¡FjC~WéÂÞÝoŸÐ`²àª=£òrÁÖNNìÄ€c¬Î•vBLÂ>PcÜRØxÜKƤ¯ó@Ô´ÃûvuÏ%ÒÅuO…‰T°’\,ª”´v–á+”~) ꜂'&{uáf0„XM¢þ„ïÝ0t©PlǼ}ú‚Êh„jPLEì ñï+OYÿôádÿcuJélº"ÚR±Éé Hó/´d «»ÂtÏŽ]Á¡µøÝ÷"›ñg:÷&(cùyåòq ¦¾mK%2“e3/@ÊÂL"áÛ—^ú!zʶ¤ZCé‡jË´Ø—‰ð…«Kpåÿ 6äf¶Û”‰mk¬K{õWÔØÜ@°†M!Ú%8¦Du÷1WËóv>€úvyó¨¬ê2,øÚØE÷ö•G'õV‰ŒMO|æ—{Ä"æ€Úf£7ˆžš™—¨¥lj¡Édò¡ÞY6Љ!1ñhu2WÙ#dTO¶tb:€¦ä¨ùäU.Ÿ)÷u¢„ò)5ƒ‰BŒ#„oß|´5¦‰>±q@ÅÕ"*®64€ˆØFõ_?´ˆUk±ÜP aëí!á}‹va gb ÎË~{øuúÐa <jÚ·¹ËüŸxÊg솟*’ˆ„YÍ߃4Zœ{„‚ƒ`FØ‘ƒ¸{•–ùÀû,€ß6ã݇Yõ¼)êæéGÁÖ€E·lAÓ"›4Ý~âþ'Û}°b!p’Cèož•CG,„¬$÷¿ßB—s g²7†á{ùíÖÝK™q·¨õ Lù™5Æ‚5‚3œ>ïql¨x®þ'VÙEÈŸçTLW¯)÷ p‰è÷ÙÇúD¼1²¥úÑ&ê› |á‚Æàœt ˜1@ó~âÚÆ]™vu2ú×çFÜä—t¤Ú(YäÍFóW¬À&€Iªj¶˜!¸÷äèP “F…ÉÌ~Etö¤ž{zÞ¾ýN KzäÌ 4qÐYøß´ï ñ»~ýT˜›KÚÏgh ASGó¯#AqÜíô…nXýwÙZ«ß–|±x±‡f, ÷ö;·0oõÁ<Ÿá¢:Ô¢ø¿òòh7×BÙohÛAeèo9~ô~6'ÅèNùÍù‰É‚²7´‘wQ2wõwgøã4Ü¡z–Hÿ%ɽpž +tV”GÓ÷múáG¨pH>Òõ{G¾µZÑÖ˜¹íjG±á^ñ»3—t`¶©@z¶Ãë”Í^RÆöY¸ïX9Ëx8y.Q÷ÕX`¯+ZÄÍLy'!%¬Fèö§R9Çr«PqÐNó¯ËøælC¨¦|Yé_{ö|€ ü”9»õÆ=ìÀ.áÉz8âë$¿™Uú’sŒå¤x8ƒýþŽE<[ùŸ”©ù„ ËlAoä5œ˜å•£ä"àP )ó<;ÌŒ.drLqgî=ÃîU*2Æ/Xçoh-î/٠ߦ/qåhw×v-Ã{”L…Ô¶ Äm8î¨Av+’™…’eán ´ùV€ÁòpÈö8Áù·íUÒ8}‹6IÃee‡ÒîæMVUõ°»Ç^É´+¤€õŒ-”‚áâ“;áîa-Ù¯I˜Ì·\J<ö6 ¦nžÃCqǸhí’Ò@8ºOnº=n¨+ÞIPc n‹Ùu0ëõâýX(¸Ïí&ÒÑ84´n7¢Ã%Av+ž£ uydnƒÔv4‘ax^¯´JÈ€Kö`øC^uË„àÇÂö¦ ÁH8´ ˆÕùÔeÒîrMå;ú ,N€¼î$-”¯˜ŒÅôMdGõ¥â_YÍ—¬ø;láÇ^ƒŠ £xûøìíÒþ8)×nRÅÃ@A³v6+¡£$VyndÔ“4rae^€´wë€nò±U+]¥ùTõ³â&XÁ¸(íßÒ:8ílàA _x÷î8ån`ÓÃSAËv>+¹£)hyŠ0e‰B›pÈ$Åwîò¬Ø¾élÃßAZ¹8¸HB4POõºŸàµ±=\>ôứ¦íb™*pøAå4õBNóEÙôV-šÕLB׿ÑL'Ì{Ö¾ƒ“Õ~ü]þ>ƒÒ~ÀXÞ4æJdÕÑSÒý?½ÚUÿ/PèË—[üY5”-y&JDÀe6™žà´/÷ÝÖV$*A]w%‰ž¶¹¬ÁÄwÏéäÚw0tA#x|¾svÅ“Ö+wz÷èû†ßâƒ-uꈵUƒu^¸¼íVÒ„8n›nàvâ“/yI 6ˆ¯´°á=â¡Çlʬ¤Áà^C¡²N”78îF˜ÆÅNMÞÍõ/âÅX¸ýíÒõ8únzØâ÷Ȫ D9¤ˆ (~|Ú_"Õ¼‰˜SÜÄeÍ}ñÌIl.(¯…dщ‰Ë (lG˜‰ ^sÊö’,Ö<ÝËØžê÷¤@“7ÕSv¸|ŽC©0h¿ƒ”»J ôBá§ŒBÜåËãM±… n²•¤h›)dO^“?e±—òg‰Ž“'ck‚ A·,î½æ ³æÉÅ]K—‡ï˜¬ý5pzÎÔ¿(u{T*„ãÛÈÌúÅÊ ŠîC 2Þù–©â^éÉ7.³¿-…)ùN¤Ñ ËØø×©îUSÍ·GwˆáµÙ§Bì½qÚÎh[± Z!´¥p©£j;CÀQ?àpš]o0Û˜\n'ýè(eÝí8«¥û¶qBÇüÇ*Îã#Ä;ÄÓ>Õ`©ƒ—ñ üó¨õ> ñù–>ª Šë¿ “†6Ê{’ÑBÀ9Üt-UÈw¿4‘ìcáºß2òÀéš¶Câ'ð’»nOÒ{Âu‡¬åÉöŸB‹¾+ Œ,IdW6zå\á”L‰ÈÙ‰‚§±x)8ï8êáí)øø]àÿ‡³ë®"GÆ+ î®H’²°>î|>^™Àb’²°.î|;ž™Êb’·p$î|;ž¢ñ7õ(UIGÝ zÀ¶Ùb@¶éŽON*O ó½éáx‰ó?\Nà™¤ ûýî¹"åøái èuS\BÓ ¢«%ø›ø›ÖÂlY ñ<TtÝ Ý£-›Ùª5"cB”Ýɰu#ÂS+Ÿ5ü14kÛ%"> ©ˆ6zR]•ב¯¿ŒÆe›IøFœª;¯ºÞµb÷* °ccÎó™TdB]›¯vBÕ]Aeè-@Ÿª§.3%qíÉp63òlÅ!€%Pãùœ_]ñ”äPñ‰½.^½mJc—CdÛf%[oß{°‡Ý -l„Vd³¾½ýdq ᯦Dofn€å묲˵_[øîõ;[ ÿ„ߨ®Ý ` ÞëöSŒx«ì0Û=C#ÂŽ [û Øþí0¡ðP@…Í’gã]¶`]Ñ“û%ò|Mò¹$€gV´?c‰õÉ&¬È¾®ô7XæÅÈû·ë¦U„2¢™Åc …0ñéŸTH:iN°Ž¢~®À<}‰“Ž•¨Ï gΗ¬#q.•îÒÁvD2ø|î¦y‡á/`WÃt«“÷—û~*ˆnmuîànãGû‚ÊÇ>ø‚¶çÃi³ñfdøƒò}1Töu"ogàÕÚÀûÇ÷ù=w¥}Ò‡ÖmK&ÿ'} .Ë|9¥Ï=æwM±å² …9Uým%SÚT°Í*D³7¡Olš˜ì5JG¤CuÎа8ˆ²²;Jä»÷'eªd9óªlPÀº`Tè*D ˜§ƒöNˆ¤ýáñÆÙW~Ú]¼éSŠÒó… €°a>VöUéOáçõšÁq%Œ.-þ~h á #éÅhÆá‘r©6âà³ ó}âÙôØö*ßýiäsöKWÄ®ôŠõ¶*HÏ#Qö‘Á$©´ÞúÙÔäõÈ–kµ;`w½Þ¤±3ðÚúúé'<¨èƒ\—è:/ˆ¹×ÿpüˆ¿d}®b3ãè}æ{~Ç ïA¯ ®6Älÿùs¢ ˆq#ˆ÷›Yuï2ѳ é(a\î=ö¶*êö UŠ;TâcÎ?5 Oóƒ§ôS„K—EŠîv{ÑFð½pm(-åo,ô`èo+ú§myèxæ%7–:yY²â¡XS’_ge²óquþOòd‚÷¯oKR´ Ê$0\ ~ ³g|RI ÇPºIù×´úvw3ü½ó†©}8ƒ´%Á¤¢{D¬¤ {á‚}ËO,Æ£šçUø/ `“ “Ò:s¾+ê[䑟B ˜û}H/û|\M¬4J²éèŒ+©<Uí‚¡±¤Tšl»GÔŠ¾±2ê™ò÷'4É÷›ÛGNÑÇ^êå§Â89-fíY|9ÿQ4ægçîMW_L˜;]H¬û¹Ù†»åmÖf<šp^hã˜sŒeCqÇT_`ð'÷yïƒýq€F-$)(<0Á‘[ÿ’”L¥ ÂawÔÛ±:³ì®ÔpH”Îר%9:ª"èpÎòPôÿˮ냺OÂ*CS—\«¿Ä$2å϶~TÀQÔÝÚÌÓe§A[âZò†'_<ŸsŒˆò¦ùä7òcä7°[OCó2ópªÌt±Ø‘F=B””Ã,YIcé e”ƺBûÓŠN-õút6aFþÅRž½@ÌË+®þr3@ þg¢ŽLyÚNÇåöÔ®Q@7HQ%TšýJÈŽ Þ{rLè¨N"ÖøA"Àíé4Õ7g ŽG9œ,S§å@Ô6ZäØîÞ°tô8+•£›¾¡Sh¨àÜ,YÐæÄ\¿$AEÒ]Ä™c01˜3> Rßh¨È⺶¯ó O4„àÚŽEÄ¥8»¼óÄ׃óšmYkFŸýÂ=ºY›%ï:9M,ºtç@šp׿ÚÃl†„Ak×-gäBïJ2I9Ì´ƒLÃØ¥ø¬3ñ¶,Ñ%Yü±^F’úC–¨«D5sËî j¦ÃLŠì¿Z„ê€÷€*üføÒ„×V«×0…ÙAËÙu~/Â3¸}KD“{?-âëmÜeÝ¥öù.9lq¿±¶0ˆì®8.)׿Ûy\´ PAƒ 2àh¢QéÙ»Oé”äÛ·ßí Ò@‡Ûú\U(›{‡þëñD+ˆ)‹*„Ú^—¿0?%¢ÒIë+g¤Y€MݳÊb瘸P™çK‡²²—“×~Rù9ºeK];CÀì•bÀÙ‘Òue>×c·Øï;:º(`Ý]ãø®+ \æ.7±5Æ%=õxcˆöžTŒ–:ïèúãuéÝ“^53ùb}Rx {!ÒÀ…k>R¢ìkàîjžõ¯²Í‚Z‡fLòþb“%”ÄÆt"{ZÜ](IVzö(áo,î½2ºíY1mà*dLÀzXêíßÙÜwÑ]ñ’mFµtœ¶stR×üH¦‚å„á!â ¨î¬À«ùuÝì´ Ù°Bzn× <êz‹‡–”K£~G¤xI0°ö)ékò³çcJîïCÙ˜ÝNȬ†|¡¢ÝBø`\£åÍ‚³íî-fŒ’“© ¼ãhé7ðæè§Qx xytí¶ ¦-á=v ‰Cß[Œí(“ôKûpÕ@Õ¤0,²¿Y|=VlàñWsN™òðlýBíjMù™ùUŒ²ãžåæ¸pÿf%¤Öwí\›eú Íëå}«b"óTÚ”Æá}¦ß²' ÀÍMÌN³TÄbãZ€ýÏü K®ðæõ0ýf3ÿÖøWF°&Ç žŒ{e nX†%ôõv2¢ ´{ò|Ö‹ð£ù{r4Ñ÷æu>Rï“>ƒßeÉà ÛuõïcÃ!sX,ÿš( ⓳E<ù{[“ƒÉ“d6Ú忦Oô”{hÍ«E^ú:DÒá;§4DŽ´ÛçLÖŸ2òÆ3 [ýœ|êFZUô$R§Êž$åUýAä ˜Û…Ù Å°· y°~¶’Ç ªèFÀ¡—±xÆè÷ø)UÕz fæS™ýøB.GµÒ ci±Î[ÑÖ’îX©îGe#éûíýGGdi%ìé=ÕmÛ$½é=»ÓB]þ ·i·¯èŒÈP$Ø|í´m¢%|ÓÛW¾Êøf–ñÁp›ê•8²cpa”÷Ðl¦åUøíµ5Îmöerás¤ˆŒ`7/%Sw°#ÑYÁUyíúÏ©ÐÊ/ùòI1ßZíj¨^e]8È/M8ެD¥{FlãàOk÷µ˜gøJ|/¤MÐaÁ3‚è ¨qävÁdž°Ui·—O›‰™÷Ó «lrå$·¨açOIÀ"n~gÔ=å œ($6°òAˆ÷üo…Ó”F”>ra*©íY¦Y„+¤ ÊJäý%ál)síJaû·/Ô¤Às'rÂÉÀª/)¦Gû¢.@¶4²ß)]e¨2Ûì†K‡ˆm¿r]±«5|µ‘8ø·÷Ìa•„©è±ÇjŒ8¹ºíÔ9UÆ‹ÎóÜ!/¤x÷ít‘þ;€eëuàüf-àóDB±êEsbìÕ`SÐ »©ÝÃÄÙáFT!²Qw¨7 y}z*¾úö1¥³AÚy6¤¾êˆ .ð WËS‹íWYÿøÆêžTytEÚŽï·¼öÆ™ˆiTUéán¬ßì£Ð¨«/åÇ¡hÛÖ—¦O¸áëÇJÇU;µœ˜AU`Cø Uñ,œ…é·Í¯0BYK_€ñâÚ #„,—8e™„‚ìlBTdÉ—W)úã…+¸Ÿä-¨ã „ñï¿ïâ<wÏè|5ÙH±_r—$ï´³%þaÁbñ\ †sVP‰ä½ïÆhH±vzïïßñžÍò”ÂÞX¹/ØÞ-£‰x°2_wZ÷ËöþžV] ÛÔÒÉ Ë»@N™¬O„ÏÎn$gjæ¡ì»¾U£\XÃ9éÓ®Õ ¥ïާú°ƒ,têt|ܤB’*Kcîº3£û“tØâûº1¦ÂÍu}. œ>4ft#áttªQT§éöÈÞž³FþØœ@ ‡®Ü{u`þ#f[œüTAùÐ2WÕìEX½ñ6Ùr쉟QŽ}xä* “/¢Ô-ʼn-";Û?c4ÛvœÂžôävŒÑJßî¯À_4°vÛ¢TõB+;°™ë®jÐl£„•ÞÈ ñ=Ž#¬ ±ðIl±P¨Ù˜ñ‡à¬›Nß0 ¢ð@6@9²ðÚ7RÛ«r|-4m۔罥}Áˆ±Já¿ÙìixÖr¤¤XY¥¡woŸ·îž=š!ár :€wº³$¬k³Ä‹Çè/w]éTF†2C‹ö$ü¾Wl¿õ)3Ò4)¤Úᤩƒ É>¸k§w‰ÿE*X–ëÝ<\5¢fí»«îï8ÃNæäý”ÖûK¾Åsþâüo¬Ê¾G{Øó;ë7it»«yøí^ô+3æØí$ÿéJJ;WNÕVÑTìl1ä»è^zXÞËs ¨ë½ñò¶Ÿér ÷ê=€L4PŒ¬mî _e·¸³¥?ÎbÕ!¾mbdþ‚Pì#Yó„“£|€ &”ÁåÞËtîeL·æt©„/äÙyàï!|ÚxŒ™@[òÛc¯Â™ë¿à_'åœùBµ<!}²´ I×ÒJÇr"6§Y÷ÄZ×})}®f}¯–Xh7þ=4úDBK—8H…“"aqÂjª8èÚO€©ýý=Œcíä¥f«ýn¸Úk|àkí:’5î¯íöNÒãzèw')Õä@ˆ¹]¯Êåm~áöĈƜ5WÁÜž{Àüÿž—¤I\Wì’AÊ4?aMÀùDiUÓìGŸ¬1îhímŠÐK¨B Σt©‚¨*iÚF¿\|—JõaÆ]‰Ï÷ÜM›ðC9^˜žG5G4m~”Ákx³æø°¬¨Æ½‰U(ºÄLÖ[ýд#V(¨…dÆ¡~€³8UQGY¸_:ù—lç[²Ù‹i™Ž´³F(¨6 ãúMÅf‚Ð’‰u„¸UV½þ®„F˜ÛF†¶åøå\4k>CfSŸKŸÐ;š,—ã_~wò籿TÆÀÂëü±£S\n[ìñúCw„r½”i᛼LøÄø1¬S}üâÆO'ÊóJn'(.2ØÌËeóT_èîY¹Ö*#•ɃêÆnÑ€NÉU×ÎúX¤Ÿ0|ÿ„m‘ÔÉ”îe•N…|¾•”„w†6ãpÐj‡Š;—ª_bçã9Ëá(Þ~,‘9ö‰L¡/'›¥©“»Wnұ߿Ç6'~CJ$ÊgO)ʹ²—†jã–“<IâÉ|eó¼Ö¨«xY~úñh£4'©áÙ-=Y';xÏà§]ÍW4;ü ÊÙßPF/’jpÍgÉ¥„¤…qʸõÞÇ bqF·È-§"«%%¡Ô)¯iéÉ¡_ÐýÙòQ’䤀zY¬°})ûrÀ>Ž_“"¿ÕXìõÊ3t* 3Úƒ º)Fϸ>¬øùΕÛì‘jOí³QÅZºåz(SܤÍP)åÃü¹mãÇeaÓ0–ÄFr¥ÊYl="B8¡Ë¥n ²ã b=ëí"P5SÉ1â©}Ñä^V*`dm„uS3qÎL;$5“j5ذ;W]IÍ´Å´$g|‚uWm3©x·„ÛŸêeñG€Òï Ï–ëqÖ¤ (àvh0ƒd;ìËÍv¤\ ÔôlÁ8Ï%Ö9z’Žƒ×ã&Ž›V-³×^=°ì€K ƱÄÒ¥X1éÛdñv¤²ƒ<;´Öˆ?`lý8¯E’eÙþÆŒ™ /(ÍÕ*³]Qa»ýáò}Â5X®†^Ú‡X˜”m˜A`4žíépe|³œ-$`lé8—}’;eÜþÆ ™ˆ/ Í(Õª³?]‰acôÝ”0DÝv¤ô*|÷¬Á(–¬`a:Ñ+ìÐ+e‘ü{ðJ8ƦÍ8ÕÜTÿ¸³<ôÍ”ON¥Âƒå1Ió7=ûM´’e~³/Bƒ¹‹ìFÀ½cíþ8 8ìt@Røœ§E”Q)0‘JoDèœRúyMjŽu_NLÕ»c üÖ=ze±øª_á]ÃߣýíÍÄÖS5µ–Ñd<ü, B³gOÿBM9ôÙˆê§%M†‰\ãå Ã&K®AÚúâKeKQUYÖKà/x@èi:+»ÑÕ$s¹ÿQDÁ4CùYyZUj2ñ?uxCô°1l|¢~“yaô7þð‡<uø A™ð•Ú¡ðý4Öð¢e£ð¨Cà ù^P…üwÚ“¹sÛƒxžIñ~ZüúOl¶O"UÍ3#Ü4 ú-M«åWí«þ2¶ÆüK{$E‰ÆÎž;æ¤øÜÏìüqó'¤#ñen\`ñDÔ)ïöµ”'§¬¹&G GÕ9ã2ƒeaçë_ïq‹py~ï”P’qix8&Xù±Äßúu}‚„ ö—hìѳ”@ ^ä:´ˆµø…„‘£ž…ì¤Ðž»Z1Ô¿éxóû$šÉ¾ÈÔ»îW±ã\2€l_µ¤Þ´Ÿ\·ñm,ß(ºO l¬ôêx:…HXOF"¬ö™Û`%IALâä.¸&ˆþ„Gn|Â>zœmɼÁW% [+í¼Š/Xó”ÆQ3{´A*w4üÕ¦ùìä{ÃTÍGË’YR½jQ„áN°lÛlö½^/af9hô8…²§ÎIÅz@(”£÷Ó:á%MÌ…DaßÐmw÷@µ÷k:=Ñ×%9ê/ðxÄì´4Ë!åvT¥D`l%LîðOÔÆ\PÐý´ÕÃwÂú÷B6òc:Ñÿ%ê#x=ÜûóKÜÓFÍà¤hE‡}ÖnY£1ä|e†÷ù¯Bʺhjòé(ô»8®PõlÖ`ÆÍXòå#Øê_]Ä@N!%{ ¡ùeüèƒà&¿›ßøUÐB*ôBc(ü˜mïùÐøí…˜u "ò…ÿY^°¤‘# ñOÊcXjJ´TüEÊ(»4]k°i5°ûJµy{G="Sg"àƒ¼+âû3¹^Î?#‰ôPÆ¡þRî3z5 ÑH›à·:&V…mqã\bíšQbŽJW'e»Á¬ôë!óÆ'CÇ:6Hݯ±¼M¦Ž}…åe½ˆl/Ÿ·Bž\aµäÝ^ì ÀxˆPÙ)šÅ<Y‘€£Ž ÑÝ+¤Ž„†¨y³Â|¢ð.3xW71ÆCøœ´“Ž'~µ…ïƒR)ŸÅ1h“·•r’O¢Ç"Z‡?D ¿”Aú DKÊ ¨ ±·5JÊylß/«]¢û·-"ޤÅ;œˆÁ5EžôƒÐƒ—¹÷$•ˆ5MR• jdH×oz¿3‘»³¦0tÿ¢¢4]Â^]Õ«èç3ª8:c©~Œ ¯q œÑ1›¸Î‡—41xÏ[üIÓ¨;«JT[HŽcö>óЫ]‹6b´Ã¬ 9áeaá}3ÕÉDqÐ%ØP«\;€ŸÓõ’Ç3Õ7ÒÖgÊBݨµf‘¤yLnµ¹@4¬¨Ä3„&¾cA¸øõYÏ `m…‰åQ˜öbL¯×!9_€Ø³tþlšÒ$üE’¤øT>kZÞœäí2]p–39•Еm´ pý!·‚A[¦ mª©FØl3m”"-£Ï´'eÄ}«ÐUDKûW¤úZ9gÔyz¸*ô*Ï µ…°!-ü^Ø.ëNºhî]Ϲ]N½"O·QU€Žà)hãÙ!´èEyœ„è-Ä×·ÑôÂL'ÂÎ_YUÓD‡¿u+YB{ø Äߌ„øWH]³yZ¦Y¤°søc9Âí—KÖô®ÂgÝÅG~*Já*è›Ø\ú„Çyò/EÙWŸú.ÿb&ZðlzA„›ÿáùÔáúéÔ`æÜ¶ÿdª¸4É^Ünó¦[”ª…SßSÅ ¢zçÈ_GYõÉ Wâ¡ßK.r>±^¡Õçɲm×ûmk?ú‹¦¯Ê´7tˆúL‡¦éI…”°ÜÃÂ$ߣRWì ˜WÄmA#A.‰ü—Kíî‰Ilˆóýÿ×Ô’Ù{~ÔnôrM§#K ]/Áu{ßÔûùü³6X<´¾—·t ½ßç¡!û²dé¡dJ4 &’̶µ~’Ôg{ÒÞ'd_ô f u OË < <Œ7¸!zba)ÿP7 7†:aÒßQc¤_ÛIGF´˜Svs~W‡‘*ýäO/0ÆçÔ&àpˆSÊOS6øêF;»õeÔëDX÷d®I{‚É€$r®¼ÓBæRºo(•]Ÿí*æX¾®TþgWä“ÎmÊåD ”!BÝ¥”e%õàÊ`Vgá"÷¶¡¿‚¤FA¥Ì{æÙýp .ßxˆäù!æïr]°õtŒ´ët¤²h¬®óU̼üs /q$@ðV‰Œ™¼Ï3Øç2|`ËLÔï5Y·^\y¼z ÍÒ./[…³I¥#ÎCóZàÏS«Óëè+ /{@u. Hëä€ÏóÝfÙß5ŠÊÉy@ÞäÚyœ}‹7ß[õêNäîm]ë”ZýGÞ°ý5|2šˆ»dæy(õ÷u€ýºd-ß'HXã”EBÂE. ]] *§¨›bS²¼LåM*®…ìMb°ëõ=rè—°*•ì*·0¥¶ÃÑë42 x¢}ýÎ:—/t0–à` h&k€´}€EЯg2(’VJåh¤=R*˜Ê½§gïãóÝ °µ4wóÜH˜…ãFÕ½zÛ ,/@áË‘ƒ•Ã-ÂôO(*…jÓÑÅàöýÉa{ì£r~+ ú ck{Î,±yÎ#9ñDþûÍ—6hx²]àÖÆïòåásCm*1ÌhQž´^Œ_Z†Ë @4ωØö©ÊlD2x {ª°¹ü¤1‚%‚ÑTWÿäàNýÄ.Z¹ÓÞkY“O¥í!¸A?׳e*'ñV»]µYÁ«fõ5Ôv,úCSQúè…a¬/Ä"†¤}rÆØ(½ÉÃd€ÆÀ6LVÖyujƒ?“È”pzÏGÌ¢Ç_Gõ9ɇŠ/‹U˪ùe„1 íî,_Q£Aªó˜Ç±Ù_߯ºíÐÝ0õLÙ*bíà )õ‚TŒx3¼Gd—Ëñ[|õ¹_ÛêÊtæ¦Ép ÿ`[È9m7ôªU©ÉAlÅÌC—«Mœ*̦®Ôÿ™8 ‚I¦_ññD]HÇ/–Ѳ6±p8ÑTD?mÚ̦uùJã!žß@!hxù1“yjðA8€>4fL¹´¸ÿ]^)»¥”¢Ý²µ¢‰-Ðâ@‹“l 5‘lxëqwú_ –À®JZñGøgÍǃÒrìÁäq2Él3`Ê”úo3{ÑÈ+_÷NœØ›õ-6>ïá´½Ö…¶†>¿ÒT¨Ðr„:ô ´0è/ôM¹|B°Ud~-ð§ïÛm¯6u…<t}ÎІ¾›@±n,\«¥Cdí"àT.\^C[CA&VüŬ„WKÃ1¦úÛ?ôßl7cu„œÐè+{Äøâ£Ðµõ…ŽøŽÚ–YP‘²>°av[ˆÆdx Éñ¹»ºdÆð1ºËÆ{µ‘¸ªeÁ´ßòÏù䄼(Ç*Oe Ývç¥./ãÄØ6E¼NH}è–Y½”ø—'ÅŸ÷îñS‡©ð_é_ï¯×²ÅJN„åLˆºÄråQ ¥¢Cê›c)ÕjcOÐ!÷æ Qwóm²Î>NÃè̃cu *ãÉsT£E¢š<‚nò¿Ý*#ѵ8£phú3ùy}OwÕfþƒß}ÚäÇhDdzmTUÒÅä„"‘%ðMâ¤çä• ÉÂôgà$üÈTÀLáÕ5õ{'ôt#¥îêVöT$Zf@dX‹ö—#˜..†>Œ¢[Sš~¦:Fÿ͵t0mHñÎZN?™ežŸíñ×Ýá ºÎîß54aÞ4¢ÉuM~»‡ËÝ5}‚gݧȃ'Õ×CIXÌoJy£hÑ$õö;çmžÀ)g-uVã4øÂ ¿#ë½0uø(ÎáßüŠK™ £±:Uª!kW¶ïTûˈUªÅA¤éÞKùÎí¢Wo‹õûZ¦ÙÍc·Qrz>Hí&ØK±é«ô#~Ü›¸ò…ý޶¿…åªÙ…V|¿õù²¼<ëŒ5M^‹kŠÔ\쳓(âsóQ{·î…½Â{•°“Ã2ÞH•skDC¯÷Rô‹•¹úºËÌæ &Ð>fÇ·{E6’uVÊÖ¼]zäÁȵRñ5†î¹Ç¨Ò-‹ÆäˆãìYsÈ9¹ÞêÐÝ&H)Ðà:€KšÊÕiRV¸^ñ¿õuþ¡yÏý}4Ììi%T2ë•Z¨·õ˜F'˜ó$gŸ Ñ$ïâ"3朎SL´¥=ͨ4@E£ó½Î~ 9÷ó--P*ÙóåR»™’û‡•pM4¾bµ É÷ÿP|ú1 pŠä YÑiX…ûˆkH=+rùí¤hÛû½îd¤K&~‚’»G?x|B½Â¤TEQ¢…ºuˆpI•zÉæÞ"4$àì žlJo°ëO»]µ?¤ôl›g⌌+’yþÿVÿù¢LP8X73È E¦ в±ÄðÿËòLUcÔAdŽÈ<ýàf-ëÖ¬fDë*ùãÑùDŒ€êËôeAhˆjœZ®ýPŸQT›ÒQ±Y¡1Õâ}ç·ÎÄÍâû*xlüBž«å¯d±eÂL0Ëþì!À·ÌAªŠu-ÿÈòQ•„ãlãÓñQÑèµß,'M,î;On~DÌ/hÁå§âNöGÀwï¯õ…ê´hŸjú!ÿ“í7ÑWØ!¿’'ê•K5¦©ƒÖZìüÆsgáZ€¥ûÀó¢6vZÈæIÀôDlö×ê^ö ²Aiwtܶ– à;:¡¬aË,7 O}"Ž»ñÄYé'2VöO„Æøa- ÆÃÌò”#ìu—m¶b]iáfID2¶”„º˜eRÞåoà7Q”KZLƒÉ‹s¢Á*äûER~U~Joî/@õ”¤UÁm¶»ZêÝÖrnŒ4/ÐÖºÕè'»6ÿûµ|hhAtEbé1ñ@¬ïó½ËÛí#áÃú¹Wï÷©Kÿf»n¯¡À*¾¤ÓÇ’ˆ¶n°4©—(©„X÷èw2xz:óaN’|îî-h£(@ø‚íyÒfUá4e6Þº8EzKˆÉMÂÚ›åH¢ñë\uwÁíTdætÅx p“”áâÚÚGf62£Ñ赌NyßT®þ4ÈVk2 rÞÞÁóéïXQBü”_\ù.³Iú—|$uGÔõ”{‚ûä©£k¢tU°Z~K`ÀÒïh;8ñpEþ÷Õ*Aí7ä›s”ÛÖá=»'À°*ƒ˜`m”ëå%õ™º 9êÚÐfpü˜9èrïláúÙç”a)ž‡IÅ£aw·áÀIZ¨gu-*àaTaqX&¬"»P/¡òid±‚µ¢‰ZvŽv ¶åÑ–íkBŸOÝÔØ ÍBm¨ÑU;d%”ã΀¨bõFC=è£GùN·¤íp‹y^ݘm1÷Ÿ,Ú ÛÑva¡ú„aþ"[᪂^eí% E¤6îó‚íUâ"$H–)4¡@²_Úvö»m(¥Ì”ìÚæõÇBMÜ*Ä~ßÑÔÆ!VJbÉô<OœžD·/\ÊØú«DQUØpµ¾÷¶måNÑ‚¸SÞ±A‘`¼Ðó’EC‡N9¤û®¢ QÌʒǃžuíƒÔ3#L7Q&¬£™„ñŸ…Ç4%KTz^é¶õÚ7õ™¥Ã³8E³ª2`Z±Hÿ節VÖä*%ø”ÝÎêË‘-Uä½U¹J—1®#ó¿ÊH£{£¥Ÿ+ÅB40c6ÕØ†Fâ6Cú¾Ì³T êon=TŒ@Ú¨@pQS†þQÜtzñMëÆ˜×˜a¸ `EPé²C}:²[uÕ,0Çr.6¤}+Ì>zí…†GìÄ;K¿>Ò2(Z–`[25íw>GQw2TB0F©F 2 :Á8Õ£|a,©¸ù²ß€¬Â®¹øÿ?ÑÁ¨ûä¢* ¤1CA4±È”ÈËF Šx¹ÙBíóÚSnô‹.0ùa¶¶a4G?!I¥-¸†¶m˳èø#¡ßšN³#YÈá>MIê)µÄ34Ñ€·µ˜Ä1M w,Œxœ8þä*;«2ðRa¨98†²ò-Ñî9ÝÒ¼-(È¢Dµj-¢²«øá~ÙÃ˜Ü K%9à?-çÙEËáµ›a’ø:«Q$ð²÷¯¡¶á\.Æ/×ÇÅS|ÕÁùHí¼à–/+r£ñ—xR¶Éaøß g6Î%¸²¢ß)J·cÃ[Ì(‡ƒ v6Y$G¦2-óRY¿íc×NÚ#²NžÌ–R{(kí¡ì~¼;gí÷à[AÀ4àD.Ô%¶ ¾ò1/$pV¦ÓÄl¼]ra‰¯%û]œ¢—à[vµ×;xQ‡ü…ñ˜eo¡S)úô²¢Ç[~Æ{@ø%€V»–µ¹r 6uŸ}âD¹«Y¡§òʦ®,f§b%§Å@ïïœ_€{5†dNa»LÎ3¿Lµ\Ã)Úþ*¿ó 6è¶±wÁ*’ s 8qÞ*T¿d 6¨;±sO*–á°lçº[O»O©¼Ý7Œ¨ F#N>Þ÷Bi+Và0¶ î‚F÷©B’?Eb$”ƒMó׳¿YE®ñö²íµÛ&’º5ôæêI¼<iÿ¾U¼øld¼VQáX‚¤õ*‹)òž¬¨òt¬¨ (ER,Wdåo·Q8T/m§’$1õªûáÌNâ•òt$½?:Pwï4D.ÄD’“ n½±¾ãZôÀàq/(†æ¨¼‚ f ʺQnÚôÆ1žH@üc‚y ¸¼:dÈ‘ÁðÄc_ºQ(=æ4Œ$ÃVã€K¸r[¶Ò‹y%Š“$1x‰\ŸX•òŽ ÌîÖVâR ¬ÏÛ’¯zäè °&{Þñg!kâ¢ii Ö[U*—E”ŠëåË…`ÚÐgö@³Á+ü·ëë=d5€©q¡j¬×<Ö" ñïŒKSýÝU×WñiU¨œñ'ÈCû™òBÔK8O>}¬Â㚣}Z¶1 Ž(H¨gÐß—în1ÕäÞï…j*öá@¤¨™üøW'î$!ïh|—ùC4£x ‡ÅþMc[ß¿p‰qÔ·ñ–ù«û]C %ÈR˜·ùná*‚ø{ìMnr¥ÜYå…¿YÇò£R4<!øÄì ,ä%íRæÄ`X’'OŸ%—²©>³Öbë*´Äl£„‰¨ž¶w4‰$øƒ«Él˜«-Ü;¡Lsv¡Áz#®$̸¹«›ÌN«÷€Xó;[*´Ìk”?úÑÃ92ëç•ħýxXX ì´ù`Àå| sUôûp.³ÄWxð#T<Ñmî›A~Õ²JvuÌÒ1jáé´SJQ€/Ï‘¾Í¹D„³´øþ®Û{M¯L>Zt":[PÎ^û>䩤Íê£íͤüø+¤ÏbK‘öWáÐ(µ$¥"ͯ³Ò³¹æûÏG²béžÚ _*à ÐJ¦ÆÍ]—[Äy=¹ùË$¹eêºÕ]ç!NkÆ¡±å²J "͹ 6¥èö^è(3h¦|]À…t¥øl‡¥VÜhâ>ð!Æ`&5Ñ!>hQ!*B0½( y²±¸’Ím’#Z_ÈÕÙ;»¢]¾±¤n’`t`¦9_¦Žñlî—{py*Œxëî„kpfÑá”}çiöˆ @~ÇÈù+nÔÑ\^‚à†ž°ÏtˆJ’cè^È?k4éMB°Uåí~‹…w">ûÔÄIà,ã§b$¨j¾ ¨ó],•ï†kxÙ$×Ñ<k–¿J(…Çþu{”a;~¤Ãgr’*á÷ˆÞÛàl±¨PSy3t<;sNJ/±gAU¨9ì¾Ç27Ó¶¾ (®¾>†½¦Iù–>P4*z+RúEÕç²ù&Xδddvã+@ô”ú©È¯¨±½g6 %¸Ä•ßJªc*l̇u½v[Iª¯21%¶¨ì»-+4l´ªLméª_€§«Á„n#Cìhö'?#ÒlûöERAR/[QA;+VÖ·ëÈYÄlÇÊ‚¯k{¼jrf`t®•»]§•sÁ;R/bJPÄmW…“k4tÄ•±l~ÆeU Ö ŒüD’F°bMleÔ0-Æ.ø’zî8™fo.`q„ngÔ˜>á2»ÆÄlT—ø„Qlûƺ©˜`ã¹’Æ(T·m„n`Ÿ%y¬ûêk(…*ò¦*Ði«#»c$(ñ™ç!’?Ÿau]ßW’cOŸ%ƒ±©RWÃ(ø™˜ÔêµÏ÷&WC‚ 1†¥èp…UÕlžˆekëÄ NS¤Æl Íl®ÙK¯t۟੦ø>{o2"‚?æRhfBêÝj¯íluKEMb?V áN#ûFqaL9Œ B\œÚž#ìRÊÓ÷ù£‹ù·‹` ÞŒçÌAF¤ý[¤Jœ#°iÊcbd´&á÷£Ø‰0(·†Uê½ Ï¥1èu†skŠ’ N޸ݙŒPrøÿ…rtÄàÁ'ÖñòÇÁbNY"’ó—*w‰â¢‘åfk’í ‹Åý)͈8G©nJºžò’Ñ]“…ûgìÆ]j2l|ô6“bc|z蕼qõ/â²’}>åQ'ÍB—ÝâÓwuá;„1â2ÓkŸ‰g¶ˆ¾ H¾þ!Vgüf“4¢% r‘‰Äa³‰U~£þ5ªa:k8†¸ ÝÏ—Íw‰ Ž·‰$¼ºÜ—q\ÿbϳíÃ0c8žx vpeháGÏ®%ü®—„·…óî‚úx în!ï’|aù‰4}x×0´«õTàÜli‚¥ôñ]s%hoìÆxi¤Â-aþ׿°2Ñ“Zú(Œ¨j„5N RU”IúÓwuáNËúx¼ Qñ’–ô‚ ¾ëÇ÷x>“ŒõȥƳ—]ìøRÕ¤ Á½ƒe¤k>•#†søms#ºnÎÌ¢Ö3¿6(c¶ýÑÈéþÖ÷=¯&Ò6ÕÁ’R"“E…ðYi|* ¬õ+î’x&¸ÝíBùòag ¬Õ˜jãâˆ4}ƒ]Ñ‹îŒ?ô)™¶*÷黢§Û`(’Á’ѨŽùQ‹ŽñÌg–'š†Ò’*`™P’¹“$Ý™jôY„‰è•±vG E¬O_’iåç¨ÁŒOœû²“ (¹“èQÂE³Ü_k”¥ƒæ|’˜“„a„i]½š°cGyÄ“&Åó™hçü£¾+ñŒj**∑åLk¬í ¡Å+)ãŸ8-ßn<dštØ›>œ÷æÆ!~2цî?ôœ¶7÷é¶¢§Ö`(§Á‰Ñ½‹ùQ€‹ñÌ|–'‰Ò‰*`œP‰Î$ÀœjôL‡‰è•¬vGE¡O_§iåü¨üŒnÁËÇkÎDØÕ$Ž`×´k)ÐdvuA‰Ë*B**ô ›*È诨)Æ ‡kúì©d.“¤*Š`tø~guohsx³\sTõ“¸3ŠÍm3Š-2E¡‡i´„Vsì“Ù/áa'Ò„öús/·ëVrN$“tËž?§swï¡g.Ćg’äAüé°ý…rÉiš‰µå’¨î"”Å\uôÖ45aªwá`ˆë 9„o kšœ`÷€`tg‹žÿÒÅ¿ú~®bé7ì/BFê]S€±_t€–åU«r!tý¯ìËIäý7ræÄªy’µOŸ%Q²©€•RÍpWÓÄlm^ê*(Ø–:H—8ru%7ré½6;Ñ‚˜4Â…JO´Æðb@êrorQ ù) UJ>Lõû”Ú& ò¤²ÑŸÓÆ~xƒ¡™á%Ÿ‡sϳõ},ï•÷áœÆo×ÇÅ“|Áùˆí|àÖ+²£1WxÝQ‚ö–¡•Ï÷ËJŽx,z˜Îh¸:²”ó` )ùB¨Å…î4Œ#4igÛM'‚VgUèw”¶©”mµ¬¥Í”j³™æûÏGÜꀈ‡’ûëÉ“jr´`t\Ž»]UŽs;R‘bJ¾Äm¥…áCötrŽw~Ž28m¬ÃΩ@`Z8èU†EÛ¨ú’v3Ó%ÍéröP|ÿcè‹È·;|:ºaP€òÕ®ÿê)§jAŒ!fÔ®P;|ýá çàÐþ¸Ü‘g¸‘ez†éÝÌröÞû#ËšciŠº 0UÝäLW%škçïP~‰¥ª5‚D0‹jQLWoõ~‡sÊ$D«H²×D]ÑÀ²4_J"m Åm@Ë—9œNe‰…ÏãOônœvõ"áº&¾v“òóó ¬£lâÆIÊ]‚³a!ûrª…ƒ¶]ÜùgTÕfvvó?îiÛ=}Ùdy™äãêÛS€m”Y¤ÅÉ®Z_YS—TnQâw‚°óùv@bßiUòlâ“ ¢ƒ ß×Ù_Iªï`ÂÎêEÞæSÐÀPö½èÌåØÙm2æ%8Z*¸"Q|-znæþZË4µõÖ)Ù̬ªKmlá‡|P¹Jáèþ&äæ‰Ï¸ G‰Ï8¶·b@ê2O®kJ^ C£Å|±a²-a¯Þ§óô‚´[OOŠ:CË4Xù1©¤3b@ÚösúØÑÊËT¾Ãcû˜°Ô8_VÍ""¼õãw%8O`_G‹‰8PbÍ"‹ül®u:‡Ë:J2¡B6žCÄôI¹M²š‹oûib (Pbè¦ÂEƳu_k”~èæ{8kObBuOi]Œ_ue¨_o+ÓMë.Q™˜âRn¥>€ìÄóuG U ûºÉ²—¤õxCß=â(oÔÑ·oUå¼£‚[Fy¸÷x–ntû÷X€XÃ;€àßë´rN,•yti?€wït.Äät»±ÁÍlÇs5rö”G9ªœ.¥Iõd¼YGä¤#(7ÏsˆXhóÓ×ä™ÝH¢®S¬žüޏy6 ÉíTÓâOÛ„ïû¾{lƒÌ /#¨]}šÐj ]*€¢÷!Wv€š)CYâ—Ó•<ñe¦e¨Öáð(",'”±o(ÿÔL©M^™¬Ñý7¬]söÛèD)í¦÷bÚYŽ›âµàZÕ— [IÙ2_,:Øn$Õw1Iü‡uñ°*Ø€8e‘ù,ˆ@öÜZò—^å|å‚òê 0¡P•Ù§ç…<ö è§ãáö¥¼ÈGlkøîô«ô¿:é\vº (ÅÆùïÌ(Hg•EF œXm Š¿Ðù·ìÀ”Åh_Ú5Íùë† ,` ¾€˜1æîðOô (ãm¡à÷y;ö4/èî8ý4o$qÏn™Ô‡8ñæï´Äðm Ò›8Eè§fáöb½DÓljtîˆK’VuY´ã\M¡t¹Xæ@!{¸Ð5,«ÄYçß8.FÈj<ZñYž¿‡õ;ãn„„®tuA³c…è\”‡X ;+´ÀÊ0³ =)§Ñ*>¶,:¢ÖŸ“Îüœ×¯âÌ}™á³*d}h„}L2„¦"8[ŽŽ6óèHOE@³uMàgö¾ñôcîb¾íUèÃú!y²›#Âx÷u±¡Å¼èÎX üü+vpñ·*¼àA/õ.1”¯uY¸¿íiÒ8yˆnüxÃìAhvÜ+X£Ì±y'nÁÔ74Ñaáò#}ùÇö„ ô´ta÷^´ÇT€ÀõD'¡Å4M ¿õiâY‚7øã`~ *•vËŒ±<$ûPO§ÄœÈ¿¸™ÈL\õt÷ó7ó(ƒÈ¯øÄRáë´Éo`U2#)9(»ð*ĺÈî¾\§ÝDqUžÕ§®˜ìWåHî¼8ìA(vœ \¹„ö,%h> àõd-ЯT˜ÀÅDìâ¯XY¸¿íiÒ8yˆnüxÃìU£Ü¡yWn±Ô'4ÑaqáÄ!ŒëÞv^ð4³µ5R˜„lØTÒkAJ¢®'a“÷**Å•¸]9ÛÞv‚Âî´À tü!élàæî8ѲÁÉí+j-uöñ˜Ä ñå õá{úèï} úìpþè˜áúnägiçÿe÷ü`îø´Ô"s‚«}m³Z}uaç&¼ ³¼ f×{~Üç]- iþBÍgóýš—I¬“ç•ÿîâ;x<{T_ pO'Jcz>® gÌ0¿ùZ ¸ð™{$H íOéìmàP¼ûÐWAð–Åú.¦Âç¨Óê˜Ô¶¼ð»Œ#d*‘œçoÉXŒs …|ô.ƒ¿»}ä>“÷A |øj´)žÜ" àŽ0í±‡©{ÿ–«!Ç5·3x »ù"ŒÉíB†¡°Ò‘B¥ª 9\§I [Ðê ?|;…»£L?êª ,¾AØ[KLÐÈÁF.¶üI'/jh çüS]*4T|_irÆÆÿBÁ0Hy|Øïô¯U|Ðü!XàÀÜõ ŒˆS¼$¢ðúÈÍÊ¿`ç=Õ†á Òñ[|)"V%õ6uV|EQz¬X|–Ã3Äá ´u3ˆÓŒÿiÔ fÿä\|š˜Q4ïë œƒí¬„šýȶÒ\&}(׌¾$¬ûrðœÙë&ˆrç+ÍÿºÐ@‚|Y³áâHY÷ ŒoÅõ/ú¡k÷®QÓå¬Ú|‚0$$hBª²)ÝÝ}ð[ßëÀ\¨HUá£C'r¤Íð#**ªÚšç•K>¥gÄ¡|—J¬±= Ýã8ìíäOVð«v£9›qÔÌù ¤=×÷ôNa|)ü.Y¼˜°Ï4uˆ| $Å–†|Çþ¢Wh.¥3ÙÅüÙ@SÔÞ7ð{4C¾ýPÉGUMçˤœ]¼)s_}äFTÓü¥ $5Í„Þ;ÜHímò|/+ãÿ,”n û„ŸËƒè7÷X½+s (rímàƒ cÀÒ úVâÍš8 ÿ®ªø` æb÷2áTð°þ;€‰èJeé œbž‘gÝðœ"#n&s*çlź:f/^ ðþ‡³„Ë%WÌiç'k(™ïØQ#Ëðß.û/¨nK°^LçÚÔöRCBÆU|A*ÌqѼüv_6 0‡ ±$ æÉ8)—O¼‡žÖ·™ç:…C†·s|µP5,Æ ¢r<ä;ð\ÅòÅS/õä)·Ë]¹!ZΛð½È"ôÏUWçƒÞ2Ö³ÙEl|—)Ëa§.¼Ìõ”çç/„•S||útYáuÿÏçJb‚ô^ðâþCOrhsHçž§ÛV1ëQ|ki®›ýY© P“ՌƣÒÏ쨎#a>넺-çgs=cÄæY|ˆ«ÁÅÿÌzŸã;¾è&ÉŽ—ð¶2ö ñžm n‚ó`^…„ÚŒ0h5çˆv©ç®'³ÿ ¾%|ºóÞ/—@‹ 懬D·Ž5Òð7º*§,ç&ß)wÖ°s2(Ð/ÉLN¹—Kç¢v?U;à¥r;ìÁ)z%ÆÃÀçﺣAß½ÔâB? |'*U^.³Ã —>_'ŠÏ±ð*ÍòüTdçWfÚÐÂDFc‡ü$¼Öõ½ñæòºQ Åñ˜žMŽ6Ń+"BFAí"ˆ„ou˜OÚU¤}¤ïäÌø‡»Ô/t8²otù:ö,:Ìþè+ùœÙqûn¡Ò×* H»ìÛÒ/2iuo¢AtÙ[aŽ¡¢tŸ?ct¦ "Q{ÙmÐf†¼{¸2»íÐy°Áùgí…Ò{8¡Dlþ„†ßÁ¡ál ŒOüáòîª ´¥IwÏÌHôï1iÑau[MÛݾ¾+Ç<÷Ü‚#m%;ëT€ˆ*e}ù 94¯0‰É¥h¦ŒøËÔä9œ×΢GitÂÞHÚ»¨=ü:ôtleÇvppÊ÷Nàk4`+ ùôU<©=À`$Np†4uÄ œ@)íÚÄ`î¦å_MmI_‘ýzÿÄœR#NùÁ¯ 95ÿZµÑƒ¨ÁUnÈÀçåaá‘Ä0•þ$DpÇEÛz·øGcp¯°:èþl:Áóµé40ô/6)àŽO1ÙN˜à¦/~3!hWF£k¤T/± €¶Ž¦H¾e1"›¬j(O)”Ö,:ÑËuÇþ ÞpÃYO¤„èwm±Ÿuåi†$TyMÙ×P¤ñ;h*æà3´hÍ tÍÑ›ˆ(ø^íQ““£ÖCϤ í‘áhÙˆmhʵr\åäU¨-›$I³;êtÁ’p0|Ù\= €Á’otí 3Žˆhø*ÃUMÃÒîžM ñ<ìÔnH°Ã2A®v+v£à»yYnÃÔ;4çHÇšMâÁõ5â©Xi¸‰í‰Òk8“Vn¾>Ü]ñÕ€þ®aîVYñ£°¨î¯à£øVë8±6n¨˜ù9^ã£`âò“ÕwF1ÌýONá¿ß+2ŒVîac'éze¡!Ñ´mö°Îö3Û:°lá¾_€Æ6*ºˆö&ª®€Š {©ä†žïÛ”Dù =ݘ5ŽÅ‰;ò tÔÏ41a*^W´“ú€fõÚ-L¯°˜ÅŠ)ú8ØnN°Ã(A’v+z£ä§zb}ÏÂïœ/îJuMÐÓõMâ¿Xc¸íÒq8«Dn´&Æ”)m2€šáë0uîîL€Ìõ6 k£N‚îô-R¯Ê˜ ÅœM á<çèmúÀö/7üÅ$Mš›´ ~vâ+\£ÆÇynÿÒã“ ä¯X˜ÆÅ4Mª‹õ‰âsX¡¸]íÅÒ8ñø‹ŒøùÁöñ¥mZ¢ë^y´™ðÁùGí»Ò#8ÝnŽô~ÔÁ41a*^W´“ø€hõÚ-F¯¸˜"é”XnK‚≎xa“÷+ù½8cŠnöhÃÔAHCØeáÚo›l].À³ˆÍ8„ÿ£ªV©/âEOÎ ª¸ Ùÿ%@‹íN¯›¬×ÌPÏrHPgjI©É†ûe¬ês;“³èbƒ¨à¶Ÿž,§25ž„£ä‹}N^¤A&“ÈÑ|³‘Þ@ ñ+~™(a0•(f½’,ej¥pS•©÷w…3>L/ú„pýH¢Jëk‚‡µŸ=‡U³3¬.În£Z¨Ç€XŽç'¬’4¾ÏiÑ1bI*[A/BßHÍó¾U±j[ª±1Z8)d°öCÕC[Cf r:܃,“¨ª3n-³ÙczRÙ9q#j*€«ƒ¯æx¨9.Ÿ.üjÙ†wë„dºXËd*m;`|̬§?aEBbžÈ•ödŠáMA¹Žg—¯áDYnâY¥*¿¯ö†¾Y§}èÞ4d—AUø¨|*™û5rŒÎFV‰¼š}R]?Ä×ql|„*< £ž×ušà«"] $ôñE`…z»¤¥‡h_“){Òé;?kyÈ:QÉ&>ÉÅ Pœ¢.KëÃÓNŒBuýNò²]bÁXb¬ƒ’c£ŒˆŠ×ƒM½Ü9Ή¤‘Òà€hÞ(ŠhË5;&k»†ÂyrÍ~¿ås¤uÀdåb¶Ek!Å&’j•ºZàBÃFůɆP¾P›Zq¸é:¡«3§B/¢Bî^H´mÂßL1.@G›þi®ÆëOl=¿œuö°Œ5›/¹uÍæ1'¸»Dâ%õv]™Š"ͼ •´d÷«*í¤5‘vAQX´@M¹@Ù†-ˆ*›±}&ZÉó5mæ^µEínYT*pO±ý{VP˜gr—?¤;‹]Ѻ(%gΟsˆè®O椫ñ)?Ñz‹EÄ=1øGìfH¾b nAR¶5œŽ=² f@BÈ0ÂÁ³‰ƒ‹Ò"/勘B@Þä Îö=q™½ëõã™—8,ž£]ä}(“Íp,§KÝ[‘4V{À·ù „cåŒÚÎ{ß°7CÚ¹6dЦr@“ÒÂ?h(&ˆ´P…‰*ŸdvtjÝ™2šÿ¢yžzt0eÖ’“aD_Mèg[‰¥)–®p:*¯¼Í¯PEÂpZ…7&ýC]بêÛíõô[”ÿGi¦yZ÷›[½Ë×›ÌÆ›¯Ù€‚«L¼b ”qÍÅ»¨aŠTn>Ù¼1]dK¬[ƒ–Yµ£j‹ÝØ,uª[Ë—˜^.Ÿ¯'ð®´¾XBÓau.N&õ+"®®û§ªš@g1¾¡0éYÑdÓ´€VÂÆjŠS²±f›@^C·.—äBZD¸.Ûg¯|uS¦Ë¦âF÷:H;°B¥n׆Í(x Š•°±[Â_Aë¹^:¯†0Bñ&W®kÍ×ûžÚ²mŽ›:]ªÃÆ4è\$‚1VÃ(.+dÞ®]‚cy*"{÷5d–@i)×Zb®îoå]Ùñ Hû.+Î8‘UÅ«gUÊn®´pŒ®la3^ÚqéŠcõDœœÞluÎtP3¤–2œm€×/ް€¶+ÐÊ*i–¹Zêé¾kÌ…„PêRâb™§wQ`™bnÛæƒîÂã~ã$ Ø+]%ù×ôážüѱö"NÎÕ*‘µw/¯^¾ñšeöÓ^äì×d•Ô{8• {(•¨{ •{•˜{•Š{þ•z{î•j{Þ•Z{ΕJ{¾•:{®•*{ž•{Ž• `~8úÀn.êÀ^.ÚÀN.ÊÀ>.ºÀ..ªÀ.šÀ.nÀÚ.^ÀÊ.NÀº.>Àª./ÎûnøÀ.‡ÇÃ:ÆÓŒ‚,×ì³I‘l>ã+þ^š7wj1¢íŠùí}ëíQ×í1»í%”GFñ3áEcóï/cÕïHcªï\c‡ïoc”ïpctï“cCï§c_ïÍc(ïécïçcìÊý˜2´˜{m˜›5˜áóÏš5§Ü šoTК/t™šw{4àgíÔWíÊ=í“Àí450΀EeÉ•E×ÉEýÉrKϬ2h¾`2š¾|2Ǿ .(±=é0õL{Ì•9{¥•!@“ÍEzÉŸEwÒv±‚YÏ‚ÿìïM)lËà=b¬.þéö@RþzÝ9=´Â»LÓ‚•"{”•{!• {•—{ûx:¥{ §Lû •Œ{ø•z{ì•g{ÝŽ¸Ó .Àç.SÀ(óÒwÀß.3À‡.ìÀY.ÆÀ?. À/Á?‚-ß‚9O9ÇåÙšt™ûÞ_íÄ,í˜u`{uà²2ýÛa.ÃÀ-.—À.cÁ±ÉÙŽöØrGÔ¹…0ºÞ0jÞÚ0JÞ¸0'«pö{â÷ûH•ÍrÑÉJE½É1r*Á€2z³\Nêc ìÃØQ‡˜bYEÐÀ/v=¸ù´{‚ƒc‚—‚œˆ‚m“‚x*‚N§‚[Ï‚0ó™ûIal—à•l@àÍl)àúlûÆè[×Ä[7×´[T×…[ˆ×a[‚×J[ÈÑÁK&9²µk8zDÜî7kÆê6o¯àIp×}ˆ¦{ͰwžJž×R[ÆÑúK68"D{&Új0‚ªSɱEkÉŽrIÊn2¢¾P2·¹/_õ؈ÜrÀâ.dÀì.^ÀÙ.QÀ·.,À©.ÀŸ.êÀ[.ÀÀ6-=#&.¢À.’À/b5‚¯j‚Šq¹lH0HÞ¼0>Þ¯0Þ€ýÚeGשMG¿©(G—©Gp©îGo©×GH©¶G"©¦G©–G©†JòÙvšâtfšÒtVšÂuFjºt6š¢t&š’u`µ‹9m¶Ž,}[«×M[»×][Ë×-[Û×=[ëÔ ï© w~6úníê^íÚNíÊ>›\•.{ª•{š•{Š•þ{z®îµÉEE£ÔU¼•2{¶•"{¦•{–•u†+À·u…Åï~0Àí0¹ÉýE+ÖÍ0ÉÝE[ÉPEÊÜ7º–;Þ”_Z8\ûlšè©Ì!¯žE1ɧEAÉ·EQɇEaÉ—EqÉgEÉwE‘ÉGE¡ÉWS±ˆ@Á‚7Ñ‚yáƒEOñ|1líè\íØ}¦{È•<{¸•,{¨•P˜ EqÉgEÉwE‘ÉGE¡ÉWE±É'EÁÉ7EÑÉáDEHñGäOc÷ïcÇï!c×ï1b§ÿb·k‚~©dvn<O[½×/[Ù×3[Ñ×;[é×\áyI Ž‚}~N21¾Û2I¾£*Þ«5YWk$.œÀð.dÀä.lÃÜÚxOï¥cWï½c/éÉöDJý,àõHûI lïàl÷à)l§àAl«àY^i`Ql»àicƒ7¥ˆ@æ©×C[¡×K[¹×S[±×[[É×?[ñÞàJ ×ï[×÷[×ÿ[ÕÇûu×·[Q×»[i׃[a׋[yד[q×o[¡×W[½×_[µ×'[Í×/[Å×7[éÞàK×ë[×ó[×û[)×Ã[!×Û[U׃[a׋[yד[q×›[‰×c[×S[µ×'[Í×/[Å×7[Ý×?YÕ`p1ädíì\íÔTíÜL™ñ8í”í€íˆ ípøíxðílÀí4´í<¬í$¤í,œíˆÎpÞ`.ÐÀX.ØÀP,À4R1bÛ•;€.ÀŒ.üÀt.ôÀ|.ìÀd.äÀ\.°À$.¤À,Ï&0ä”dPÜŒºwt3Ø5íÄDíÌe´4í¼,í˜ôí`èíhàíPØíXÐí@¼í”VG@ù>2ñ¾ Ëã7×o@.´À4-¼©(G¨© G©G„©èGl¾´*9Oµ¥9Wµ½9_• ;”•{€±ìÛx•ø{p•à{h•è{L• {$•¬{•”{•œ{Ÿ„®Ì…±ÈmB[ν‚#Á‚+Ù‚3ìñ÷ZBÍó[×ûX)Qƒ›Ü£š¸t)š*tš‰týš0tœœbÓ€è%ÀÞ"ÖÖ“JBÔ»š"w=<µ5í½-í¥%í*í•í í…íýíu4DIôýK¬È6˜Ð˜àùqÚ3¦¦ü©Ü{X¡¶{̈ÝV5Ï/64‚6â‚cbÎÎ]~EæG9f—P{C•Ã{ûs;ä{R•£{ù¶‚•µ{ûw:Ú{@•–{•[qÆGò?(Ħï`c4èÎ0I2'¾ 2_¾ˆ5ƒ°¿ë?‚0Õ‚oÇø2]-©›_þ(0G¥©–Cécîëç `Nl†àfl‘à‡br.—þ}£G©‰JÇÜ)šptó›S†ô9yX;…íEÞAÎþöB*¾Ð2йH½“詘\¸˜l‹˜œ˜ˆa˜…v˜žy˜*N˜¦SÆ…‚&?ÎÉEæÉ]ôàgl5òÉzƒlðà)aÎ[2w“-…Fr˜©B˜×™yt¥Æs‚ž¨¬RôÂhà²p¦ÊÄþOæÔã:³æ•{ˆ•{r•óBUé·¾$2Ú¾:?ÄÖïGb‡µá2.—À /h<‚ú1‚¬W‚€‹‚rÄ%‚Z‚ `ÆìàlÊàHb¸¿y`uâQž•Ÿ{õ~>ú©H.¾£2X»õòʾ¥2D¾´2R¾‡2©¾C2¡¾K2¹¾S7±Õ©¼‚ '”‹SÝŒ»¦•„{EQôù3 Z÷¥è…ú°t8š¸u0Àž³µQ9»@Ï׃y£œu }5™Ðu»ã•=ÝL1DÀí0´ºxKúNÃŒù·ÝÊàô×ó[ÕÇî™Üý¶‡6kQ‚»%mbÞ0„Þ %p}ì…&±ä:f_ïµb#‚7ݨ;Þ‹¸C@ÃP!â{ü©l*ÚÃî!³Bî=9M<•O¯É”EvÖmT0ÉNEºÉYEÁÉ4EÔÉ EäÖBŽ÷Ûn.ìÀ[.ÁË~On‘`Rf2“Š©øG~©äBRÂâ¿c}¶š,t›7ø{á£` l·Pìkàlà•lGà*lOà¥lWê½Òsì ¥»?#·B™\ûl>¼{ô•o{Û•B{Æ•2{¶•"{¦•{–•{†Žòßv ÷%f.ÒÃV›8Ý5ú‹*0ªÞ0šÊެe[ƒ×u[“×E[£×U[³×%[Ã×5[ÓÕï/t†™òÞvíâfíÒV¿šûF•²{6•¢t&ʦï{cï‹cmî›(•«‚M»‚]Ë‚-Û©="0ÞŽ0 é~3ú©_Gî6.ˆ@[íÑÆGD9°µT9vµ”9µö9áÉîR—®û›Œ©h¡³Bòbï㩪,%rË8©ü›sÜ×g×àÌi×iYʼn\&ÁÎxoËÜ]F³P-ìïrsuÍšJu¿,,7FáóO:ÉÕG0³Þ#.›àƒÔwž{×[x}4 ÅlŸoÝpË53U˜{Ë´4$ôʘûïÖb¦×9åÌ['~ÀJO¼Z˜Ì”E<ËðIuBFϱ"åIÏ»!°'€–ס‚0Ì›‚@ºº'|!`Ñ<Qn%`ûešÇeöoבYv ÷í`é¿èûÜ•V{½•=p¥Šïæbƒ©èÐ0-ˉ—løÃÐlÞ00PÞš0ÀtÔÁòí‡ëímÅŸÕ.U¹-ÿÀ~ƒê¦"˜Ç¬P0«§àªfT2-¤w3èuYàfµŽ9qëÓÞG&ÖÑ•ºt :FtoÓÀ9ÓÎÖÛo‘lhÃBþßG¥y4ˆ7²Sjéºã³óBAb·¬£ªEk“ò66Œ7{?•§”ÉñQ·„ÅYoa Þ0CÞ%ÂR»b˜?ñÕ{š»uõàH>µ×8ûO{Ò•ý{x•î{l•Ú{@•ÃF;é¼ã¾> ÄDZìªë\sÑÞšZuÎàJ<µî9\3Å•XWÙé˜Î¾5 µðqäîo>¢hÞÔAŒu“.•J{¦•챆•‡íÝMšÅoôG~ÎÕ‚ è‚ ` Ëòïs…šGt¶›/æ Ì©X Äß½;n.чüÙUßv±1Ør²À6?vÂìâܽı˜ho˜¢#˜ÕÒŽq[ÒÔìåw e>nÂÄÅ`#Å›c7³ànÔÞ×}y38{p°npd;PÚ«nÓ*U¤M·iiKz^ɹ•c±»Ì©Ð½I]ëÉÂ[°ïN»¤É&åáúNm;v´ƒ-R)<‚PÅ>ßÅÙWr •˜{š€$þqb›‚c‚k3™ùwäìb ¼,45„ň}Ý‚?Õ¹ lÕ4 UˆpZ–`ÀÐà !ËÓþnò§YM …0—2ô(Â4pup¦LÌ+E™Õs{?lÀÜ,T4V¥bWÕ?TEÉEíóp£ÎÏýb„¯Ú ‚ïn*{Ä•D{Ì•<F´é‚E»·Ï¨. À.À˜Ïþ0€Ëf›2t®ôH`wT›H_™Ë¡vdåÿîH{ý•mPå EÉÆE,ÕΣ_.Ê#Ó°š&w”‘MéJÅô2¾Ï2$¾Õ5KI0q”Þ08î¯?ý¦¼û8ôD°Þ¿•;{Ÿš¥FÊÆ/§.À{.Ï#â'rí+§•íEÛs›0*J¼Š5s‘›ì-f@˜§fg`°a#YѰ]•âIA¾ÛÖB'άúå˜XKö: {.œ«ExÉdE†Õ%8¡@þìØBBf¿2ï5©¥G©G¤u6çt]šßuE]€õ©˜C˜èÙ1´á¼À¬ZŠkïèì÷Mfl“îu1¤žp1•pAÔ`,ÂÞàjlˆàulià’lBà¤l$øgÄÄÉvXžâpÇËŒ=µ×“’ø˜"J3Cþu«G©ŠJúÑ-š©uûU:û¤ž$\cÎï2c îÉ5`ÞE0±Þ0]ÞÅ.9¦r? ÙµF9„@;ÕcõQ.ÛÀAƒîΘôáP3þ³êS¹©úMðWT{.Wh¹úªZÿ¼EÖx´›\V”iÚUê Ö§AGrëŒÙª%ÉñXâÀx§p0‡Þß,^ƒ¨{û7ßuG‹à½ì”î‰@QÆíšíýÞC!É×E<ɦ[P±Ã-Þj˜œgv2È9.F Þ=\5DÊH†ÿˆàæG)œìLÔ˜1@˜¥VáÞ+[ÒÔäMÉûY&‘;"þŸ+G*©@™ŸC‹$…cvïc%`?l®à\l†àog’þܳ’¡ZCëdüubM"ì<üáø\DÇ*kŽ¢Y27¾¡2Z¸¸îwP*æí]ÁíèÞD,É0Zº˜p‡Ë2ý•ƒ.û|–×Ç1õî8åG{ú{ë•Y{³•7T¡ÿErÞdv§öûΕJ{Ú;èx·ÚŠhòÛ{l*‡¤ nm7Ò´8aù—õ*G¨2î¹Øäp*rÕ#™º5BÞ;˜êâî?.0À¦.q»¶dÃÜ3lWà±lZàÅl4ïõA‹FÎôë~_m`w×w]sØGên5ê¨jÄ÷5ê†>B9jµ®ÜÑP’T~3‚UM‚„‚TÅ‚`ÆÃù¼-Д%É¢EWÉœX«ü{¶›¹V\Òb8¤¿«øw“¡†˜Ì3[Øq/3Ú.?!fÂÿ Š^ÜU}>{Å*"æFÛ÷5À³,'4Žç`±@B‹`#ÍvÄÀæN{Ž’*„çÃí(ˆŸ:Ïè{ÀŒJÔ2±¨ÞÚ0BÞº."†Äæ€ëJ{°•:{ž•{Q•Ò{I¬Ã‹Ð6<Ë:Q$1ðÞj,Ã%lhíM¼9 µh9šDûßO}iøÞgq¸È@ Ê|„ùÝ3xó4Œ-bÈ$[»¬rAu©¿M÷¾ßä$A›š®Ê*9..¯Á· {v*ç °]Ýã÷ÚZ} ½˜EáFV[À×;[ïÕù H“•/G]eìÊõr6‚ÀI¹¡Ô0«Þ$„ãà'?p°F1>ã]ùð¬ÉÄj¯wl8æ3½h¢Úê`ï„crï®cUïð`ãNØ:ÙÆ+ª—w›_¨Ë˜iEÛÉEÿûæO%7íaιè&µô8ÀHîßì²[)÷7þ¡©@eH@IÑE×Þ F ÆÎ[?•ÃµÞæ0G¿袵óŒ'4Õ~°2b¾š2˜¾D2¾¾.=àç*E#¾ÞBV†§œ Q¿wÂ(ÛÞ?uŽÊ#HΜµßÈ[E÷ùÿF×G,²OR.và±Ô(îÿûŸ>{Ô©=Ò–5‡²‹õôÛ7Bþu»BãC^•EôþáB¹ü¤×‚…}¾o¿Ç^t¼›$`Ï*ZËÒf¤9‚Nµ‚>ÿsf,ÎżåaÈÞ„%ßî¾Ç@‚¿{3•»ô9(µÚ90µÒ9¯GðŠ4ulàúløÄÒ”ï× =Õ¯wS…8HêæÊI4¨±V‚•2†tM¼ýì›/ÇŽ.•yMq'Èð˜.îF ¥€«zu?3§8àÄÁ¼3¼õGBò^½ÉŒv'ÆàDlàdc˜5Az©ˆ'E¤ÖZ(•#{¥†y5âG. h· gf¥5—pB÷).’à é2j˜áÕ}Ïè‚͵8”1•–ôø‹¸Q,Y¹D íÙ -ÀF„óßyõøì˜ô˜‰˜¬gà8²×7R ¡HÛ×M•£{•„pGöp5αӅÁýÖ-¿Òÿ©huÖÕ’û¬•{ŠŽúÕ`.Ìà ñ˜ÞÍ$¦Ô9íµ9õµ9ýµŽ9xRÀ\2˹0÷‚Wß&,„OÐ%vWà—l)îë2hQf•@{‹•ø{!¼©Šf:î襕R÷TKSÆ•[v×iYœ#*yúûuQQl•2{©•{¬Ý R4c‚6r/UÀ³' sI2›*±š‰ÔÎõ`ñFFëGÒûãHEµ¿9*P¯ûöGF±gaœÞÅ,)ô&Ì• CKå>7Íi"íù <Cå÷štï›g1no{ß•Wch6ÜÖA¨˜mX˜Ì ™É€æí>È”Y9ø`-Ùâ@R\!$«ÕFûe9õ®€~w×eX[òíbêíj{0ÂøY%±Ñ>À§.Î#þɦB—ì™Ì•k{î•2{’•üGddµcîö°*HN5ny¾ÛGŒ©üBt&Tü8êIWêîÎ9(Ã!©Þ´-Ñ~˜KÐywÔô@øê—˜‹~î3¯2rݯw•‘tTuGÎ’7pÔU–¥F¯B,î`â3×r[’ÔZ̯.Ø6(&òÉÖ5L1À~.ãq”ép3î¬NËÌc9™ßW}èÜ]qÀ.[w×eYPÇ‹íÿqâÛûq›·¡-Ê)ìëÿ¾rBΦryÄwç½ ñ«‰øãB EcÞvXŽ’Ÿt6‚Ç'$3Å?š¨tÏ›I€B¯è‰ì'œW÷$Hb¨$“¾fÿµ\tÁ™™ÂÂôM/¹¤=p.ásóa;’uå×.âI:ž†Æy õÉXò¶{b•ÖAúÎt:©F»Ë€Êã,s\ÃQ±WÙÀ]Í_7u¨]àû›UXôÒlm´w{Ǩ=Šˆ‘îʤÇkÂP㯽´û§•/u0©Ú–˜‰D¡`•làôwøK0×§XB@¯ícpû%5À¥. Â}¡ÚÂþ þ[”ÉÉYÿwµ`-Þ4ÜgbAŠIç$¾Ý%>@Åu3¯èwµÔÊHg¡µF9¹µlŒERtîCntÖËÆX,!ªuiô¿V²É6ø%Rr¥dãìʵ0 M»YÉÄFøžvWÝÕÿÀì‹©Ô1¹ÛS¹»Â,”b¾e"½Õõ B<c «k¾d•Ÿîz*ˆ‘'¥2íÈ×üñÀùþ#댎+®‹$rR,"jÉz÷¿ËÔŒQ¤ÉH‡l£àEl³ëUB S}÷Çø.|Àè.lÀØ.\Ãȵj¸èf3µñ9+øë¢æóŒìPùÔ[l$Ün=Ÿìh5ˆñ'M2ÿ0×êô(ùö»ê惌)œí„xùŒuÚ¬j… ÉèŸÂûà•PqØùÆKë†SY±cY¼›49><8ÍÅP2ý¾2õ¢éo ¾ï7±¿hÀè.`'þGXGØ®PyV,~1×ï<,´4Ec·î]9õ À“afoy3ý›Œ“ÄB¬ƒXU[m¶*wÁ¶«-”€¬Zm9Ckî™ç CHeäɬ1nÁP{¬»•¤{,•œ{à”7HÑŒb#ÿ™b•`ýîñXBˆËYsÄÈ5MâPMÉÄeOâ }ÓEuÕgøIxN0`ÈèH²{·Œ›æ“¶MA=ø€~öê1)OÈvO÷&)’Û‡^òõáõôâWX÷¸/íöÒéà¨'IÄåu¹Ègù)4![‡9§áûRúÿ J `—€‰wì6ÑG…¹à ØÓíEûNŒQ)ì) ¤.\߯g$ wï 0ìWË|Û{ø–à({E)b£œ_¤œE¦² ûê,aû71·ß91¹Ï2¿¨Ø´œh“œ|•œm9òœè{|—„f÷…zl‹t”è‘õd¬õ8Ãá„nPóT*ÁžßmDшå]Ñ‚o^ÚêœY¶*!`à»äVßЕ ªBAþàÚM£”l ù«ègäUt¨• öA¬ùº’Äø‹íHـܺ<—5ü9X ò†Å÷†Å’q{VoOÁ…sœâ-yÅÚí±Q˜þ襀q¦Ì\ÿ< V/lúεY™OƒÌ• tZ4a™}1ÙÍ*£Žân„Çzfí ϨЌ[ùé?rÿ4`œ>Pq¢Ï ÀjÕÀäm„øªYäƒ `œj$·Ì±ÔÂz£® ifÜ›í›eŽr"é§…f¢ÙoâCHKàRn;Óý‹•CJ%b±Úß(gØÇÚù„Hݸ~T,æ{HSié]ÜýÙ †f›”³)€¯2oy„0Çžn*ÎÑ ô)Iý×`õº‹®[ ÛjVqÖ‘kS^E˜³…ÕlV!Øï%å‹61•KIÐ%r ^…OÙ•öµ´¢í¿Yge6Í„.sƒB4©™ôh¿o ¢ÄQáÃô•VåL—Ù*dŠðÚ¥‘ ×kÏÞ°d—½á/KBäóÐŽqkÀD=]ì˜d¡ug+fJ€ØnôÇñm‰jD…y®\bÏZ~º¹Ù9ͲC8ñ*A“ɩۼ]Žj\õ`9c¹Š˜°“+’r‹£Îmó›µ6½ãàå¤ZDî³D$)Æ0aežåÜ·$m†;¤nÒÐ.ª,…MØ)¸Ü0«ZôYÒ‚c-ðúñ ütm>ôÎec“ÁHÚÈ'Mé¶Ntd½*Nuj3¡^]Õ^±0i€A.^’wU~p&ìÂg^rd%N*µ£cÎ+¡Ù.ÄJØ$ÛB”“—ãz[àv€•õò+G ÿX˜ô 6/æA†Ð†ÏÄã§æž¡Û(“v\”e¨W„t¥€ q ¿QpƓڙ<p°ß2<;£)ë*HéþOž‘í4ÎObm¬Ã–ÉKLC-ÅU¤—ÂÝžjÇ ¬RAàÎna•†çCÚƒPC™ƒ¬ƒtÀ\ÊžAQe /¥;7QÈîJMåk(bä’íïdòȤ ©8E‚¯kl—:%Q8nˆÁý©…0ÍŠLL1ÔöU[(t‘Øë>íC4÷Î{€êÙC¸){¯®’´5ö9ø35ƒÁÛð<ÓeUU¤çZ4¿ß¾‹Ç_|úÔ¥kÝÿµ¯óðÇÏu̺LQq0ûV¼42eH ®NΟj-˜âf'ü ×çBO«`™·¹)üéllÑÃÅ׸M>¹)o™‹eÒµ(E³ˆ¾pÿzAkcmðk¸æñ1¬F¾ºš1±“„m“ÎW§U•™Â"ˆ÷R´å9’è] m/bÁÆŸíµ™T¼þ^”'zS9†ˆµ°‘óœ®Ìè1\©ÃX¸Å½`½£IEÈ3ÃÈ‹ ³ÕDZåâ4[£¦E|k®1óõM³·ËÅâÔ$¢ÙýдÚ$£Á›â„x’‹ë©õüQÑ¥*b°ó_Lˆ¼¸ ‰Àï)Ç„J²ÕUÙËþUåRfègFžÆynS*cuKˆ®N˜r£Ç4U•í]´?ëzcS¶0cîƒ5¿Î9Yæw&û¢… K&~dÿ× êõSµùÊRòÍgÀ `è ]ƒííÃ# Â=èM!Ô€Àf¾2àºäfΗ5ÎÒR&Fè šƒÄëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>¾ Áæƒì‡Þ‰$÷Æmü½ìúºÿ €ÏKƾ"M÷Ñóíñì‘÷×뚃à þÀ‰ÂÁâRfæ&F€Ò›÷ÆJa9ºèN#ÕfÁæ}÷ÀSul¿Aëšhâ=T4$ Þ [óâ=T‡ÓR„Ãf…óýÔ£Âs€ç f÷Á)íºêDºïþfÁëè šƒÄ¿ÿÿÿÿƒù •‰ø÷؃è÷ÂÀÁ†ö›âºö©ºöŸf¼÷ÆJ-C뚃Äü‰$€üüfî?fÁî<3Î÷ØÀåÁÁî\÷×á}gA‰î¿ @ ‡÷VW‡$JT$ƒÄÿRºóÁ„àfÎGÓÎf÷ÆÀfÁæ…äºä<³ÆƒÄü‰$fábS¶öfû¸«f×ÇUö7õ¾òËqéºN¾ Áæƒì‡Þ‰$övtpâ¾3h÷ó€ÕÇ,·¬f÷ÞþËfºDM÷Ù뚃à þÀ‰ÂÁâR¼ó„ùÖºÍÜþÉÈ ‡dÁæ¬î:ë³&¶ñè šƒÄh @ 4$ @ [ó @ ‡ÓRféT©¶÷f¼ò÷À‘¶Ïaf÷Óf¼Óf¿Y8÷Þëš¿ÿÿÿÿƒù •‰ø÷؃èÑõ᱀ղ÷Þf÷ÆÂµ÷Æ~ï€á/f¼÷;Þëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>ƒÄü‰$»î‹ÜöÕfý¡ð3ðÒˆH f×Ö÷ƇèøëšUYÁ @ ÿùC:›;¾/šËõöÑéU‚FAÁéb¶ófÁÄü‰$òf¾×ü»Áéq{?öºâÅ€õc€úgö}$¸è šƒÄhÜ f¼ðûx)Û)Øf¹'’fú¿îfÆÜÖfâoÚè šƒÄhÁG ÆÆi‰ ¼Öºç «àºäïºä§¿óf¼Ëëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>,$f÷ßfýÜfÑæÏfÿ®1#ÓÆºøìfð¼ðè šƒÄh ðç|fêo fÁî f÷Á6ŠfºÉ#Í:ñfÁæ)föÜÐëšèm ó5Ö¦fú s°¯fë«ò†¡÷fÁã£Ñ‹L$Ð@é›Ü·mü‡¸ufÊUçfДºþ€Â¡ëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>hÜ fÁæï÷À}ßdfÁî<þÊöÂfÁꙺ±XÔ«ÞhÁG «ïþÎöÓ×C× €üüºú×f¼À¶,fø°€,$fדÎÀêâÅEjX÷Ã!…ÁókÙ×úfæœjƒÄü‰$€êüºúnþÊ‹ñöÆô¾ÔaÍýºÿÜfý½Iëšëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>èT ÷Öºþ÷º÷г×þÃÂðK ×VfÁî‰fÁâ{è šƒÄ‹<$ƒÄfÖxâfÁæ“fáË‹;òfã¨÷Æ¥&WÓºþ‹4$ƒÄ÷À³Õ`¸JÔ;úfèñQ¼ÀÀàÊÒ[Cƒì‰4$¶ÊfÐ{f;ó»44;Ó»ÀÀìŒfÉŸçè šƒÄƒì‰<$àt`NÊðÒ8èìõðüè#”è§Q€Cëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>‹ŽT Ò»êfð8Ö;ò€ý$fÁâÀטּZdã÷ºè$Áéà$Òº–fú„fà9pfÁè|À„®ó¸f÷À›ëšò¥Íºøõ×’ã~ºó¨³ÇÀ„(É…Ïf¹Â‹<$ƒÄÐÝLH*‹Ñ€î$fÀ:ˆf;Þºà¯#ÄÉ”Âè šƒÄ‹4$ƒÄfã¹—:ÿ¶É÷À*üEÎf¼Ï„ĺø™fÐÖNëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>‹^<fÈôûfÈY¿3Æf¼Åð¸³kãþÊ÷Âs¾—RHƒì‰$ºà–ÄfàBXºèÏÅf÷À~|÷ÚöÐfÀ¸"¿\€À{аx@:Ø€üjþÌ£ÈöÜý¬3=ºèÚ‹$ƒÄ…Þè}ï‹ÇЉ¥Áèf¼Áf;ÓàlÊÌU…Âø B9ÂuûèíG–ò´~fðŠU€àK€Å˜÷Ðfðý—fÈè†òøç/ùfÁè‹f¼Ãþ¯Gîtfà6Ñ¿Îf;æè šƒÄƒû „ Àyÿ»¡Äƺà2fÈRLfèû¡¸ð+Ńì‰4$3À¾ÄþÀ3ÏfÀLf¸Zf÷ÀȨçêÆè šƒÄƒì‰<$f¹ïôðÎý›f¸Ñ¬ºè«ØfþQãfÈm¿ëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>‹Jfè(þÌðÖ³EÁfèÑNf÷ÀMˆýPúb‹öÔè šƒÄzð üºàáèÐCAfÁà`f÷кø$f¼ÁrºøŒfÁèófÁè7f;éºèU3źèÚfÁàá°—ëšò¤öØ…Á€ÅÖ÷fÖ„æ”ßïÖÕÅJWfé‹<$ƒÄfö<™fÁ‹ fÎ[κè?÷À,;aöºîgè šƒÄ‹4$ƒÄfÁË΄àÐÒC3f൷÷ÀÿÏIöÙfèvjYBƒÂâúf÷À˜¢ÁG@zèõ€Ä«àºçcfÐÂ3ÃSÿ$‹$ƒÄ;ãÀ=7ù#…åfèƒdðb*„ª÷À;î+f¸;è šƒÄéÝýÿÿð ½ÙãúC›f¼ÃfBºâ»f¼ÄfË ãh Á$$€ùfá?fÐZ^fë÷»fÁà]ÉÇ äÁà£h Þ fÁëôð%YCò‹ÀÈ¥¨™£âºèˆÁàrf;ñƒì‰4$f˜QþγÃЫMì+ÐȶÄfÁèfÁèKh@ UX$ƒÄÿàE@ñ€fÀÔ3fМ³ø¿ÁfÐ0ïºðÕ‡÷úxB#àׂ)ºï+fÁïw€î€ÀkfÓ‡_‹~<fÃÂ]Àî@þÊúqæ1fÁâ‹€Ê~³Ëfû-Cè šƒÄ‹¼> €ý¢fHÁê-Ã#Éð3«ð_óÀ—P‰÷عGMz(÷öÔfé ôf¸1?È*”û˜fáfκè´fÀ.è šƒÄ‰óºáàKüjª÷ЋÃf÷غáOÈiˆöf¼Àëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>ë @ f¸FÛ;Ëfàíf¼Ãfñ³"ÄÀ>Ð¥öÄþL_Þ3dzèf÷ÀÃRâ±È¤ff…×÷Álw]Äè šƒÄ‹+Æ‹ÃÁàf;íºå¹ÀäfÁèp±šèñíìfH‹Oºæ‡û£!ÇgºæàÁüÓÐà€|åf÷Àݪƒú „× ÷Ðf÷ØÀNKu-f¸JÂ3ÃþÌfÐÃ[ºøí¿ÆòзÂò‰„ÝÈ÷к蒀ÿ”f¸0׺øoºàÊè šƒÄƒÇ÷À§vúðcB)Æ£ÐfðQ†Ð¬#%ݼÀƒéf¼Â÷À|5åGf÷Ø€ÀpfÁàåf÷À;³ÀöÄè šƒÄƒù „íþÿÿf‹è šƒÄƒÄü‰$¹ Ñèâü‹$ƒÄëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>ƒàè šƒÄƒøu3f‹%ÿ è šƒÄf¼ÄºøwfÁàt‹Ãf…ãfÈü6€øºø.öÜQÿ$‹$ƒÄºâ€üRfÈ›fÈE„È÷Ààw€0fÈshHQÿ$‹$ƒÄfàÊ3¶ÅfÈ„á«ÀȰèúsà¤Ný¼ÆƒÇ¾ÆfÈI÷÷ØÀjƸ¸÷Øf÷ظ…J3äfà2©é¿þÿÿ÷×¹g:ðv»éöÕ€ø¶¼þfËtØþÈ‹ÐfÁëé‹~<+Ôfð…¹Òf¹¥»ÀfÁàÐðÖ*³f⾋¼>€ fÓ¼wfð7?ÀbólÓfðM.fÁàŒf÷ÂfAI÷ÐV¸C|¸ZE³Á‹Ú£òßfã·×€ã_fÀº{ëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>ƒ „½ è šƒÄ‹GðƒÄü‰$ëšÿ•@ ƒø uè šƒÄGƒÄü‰$ëšÿ•@ è šƒÄƒ? udëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>ƒ „÷ ƒÄü‰,$UZÿw]õè šƒÄƒ} „Ö ‹M ƒÄü‰$ƒÄü‰$ Éè šƒÄyƒì‰$ëLè šƒÄƒì‰$ƒì‰$ëšÿ’@ ‹$ƒÄ‰E ´{f@f¸hcþD3-®ºâôf÷ÀÙ@€à!¸É4‹$ƒÄƒÅëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>é ÿÿÿ‹,$ƒÄè šƒÄƒÇé9þÿÿ…âÁçáÿfï$%f¼Éf¸r¸Ð[4¥fòñThª; fNJҞל'¶Ö«×f¼ÿfÁêɺ÷¯Vƒì‰,$÷×f÷"ÉfþòfÁç£f÷Ç+f¼ÛÁï6Áïo‹F<fõ‡—ã¨KÛ fÁãf×Ódf¹ÖÓf¼Ì»÷è šƒÄ‹DxÇJp²ÔfÁééfÁçÀ+ÈÇüÆcÁ爻ò¶ÿD(Õ+™Ýføs2£âfí°NfÍ7¦fê΀þÁ‹ þÆé:Ûiçf¹R‰f;ÉfÕÌ÷Å ãkwfÿYëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>è šƒÄð;Ý×3¶ð*fÁâ:€ÆŠf¼ßºéÉMW*‰…Ƀì‰4$÷sãè×¶Ó3üùÙ/öfá·•f÷ÇAÊf¼üj €ËÓfúbØf÷¸âføŸÎ„Ëf¼ùf¼Íf÷Ójf×±Ífó6×ÿþkß½e½ú¿úªÃ¥@jç¹¥¯Å¿×²«f÷ÑfõèœöÞÍ>%ðºúuè šƒÄƒì‰$f½ :fàÉfÁå‘ÁÓ¶NïÝÊ fó4Cëÿ5`è$ ÿëÍ ‹D$ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>‹F<fÑ‹€×I÷ß÷¡åb`ÀíÜ…ÖþÍÁåfïë%è šƒÄ‹D(ÞfÃ»Ž€ÁåÊdµÏÄÁïf…æfMñ‘q;pBðºÿ1Å(áÄfåÓV€ËÃfùàÏ¿w…Ûè šƒÄƒì‰$fÒ fǯfåÿ0ºæ³Å»åýïFŒëšÃU‰åÿuÿuèF ‹}1É1ÒƒèHt5x3f‹€ûèt€ûét fûÿ%tAëã)LƒÁƒèë×)TƒÁƒêƒèëÈ] `‹|$$‹t$(ü²€ŠFˆG ÒuŠFÒsï ÒuŠFÒsJ1À ÒuŠFÒƒÖ ÒuŠFÒÀ ÒuŠFÒÀ ÒuŠFÒÀ ÒuŠFÒÀtW)ÇŠ_ˆGë ¸ ÒuŠFÒÀ ÒuŠFÒrêƒèu(¹ ÒuŠFÒÉ ÒuŠFÒrêV‰þ)îó¤^éXÿÿÿHÁàŠF‰Å¹ ÒuŠFÒÉ ÒuŠFÒrê= } s= rAV‰þ)Æó¤^éÿÿÿƒøwƒÁV‰þ)Æó¤^éÿÿÿŠF1ÉÐètƒÑ‰ÅV‰þ)Æó¤^éèþÿÿ‰ø+D$$‰D$a U‰å‹E‹U‹MÁé1ƒÂIuø] *** Enigma protector v1.04 *** *** developped by Vladimir Sukhov*** *** e-mail : enigmasoft@mail.ru *** *** site : http://www.enigma.izmuroma.ru/ *** *** THIS PROGRAM PROTECTED WITH ENIGMA PROTECTOR *** áŒÅD¤ †æÉÈS|«³ i¡ºrD ¾ ;&6g ‚of• .µ_°.Ô5 £sbg ©tžê[qÔŒÙÀ² é€ ˜ìøB~†vXŽ@04 ï"ÛPÞ £=i8ËÏRw gþB eröx·äõ2âéeh7Ã#0çI0{–r@ 聆ˆ?¥5pî¥q@Â7bý´¬D’ˆŒ¥( 5 h)ÁJÜ"ÜbÞ¢Ãã Ü) ªûˆ\+ÎÅðeæ F¹Q £*ÖŸé ž!Õz<è ÒŒV g3FHAUKTî2 BXG79VMYìNtSìCäD}4{2èTÇLX³RWÇÀNB59w7|KQEMX@PLVFWíì9BâTôE?38ãC7³A©42ûy~zH€JN6QWUFAÿ‘5RGÑL¸@RîÁe5HMAõKF ZPW©QäAæU74DKBENHV;9F=W<67QZ9>KæC‹A©MLBþEÕ93YÅBÓ¸TUX:íÅZ¨Šòä8YQD]F9øHKQGP·Ÿ§67·TiA»ò2—.À:Close dcbugSr,Ñanó§'st޼Þ.]PNog~žmwil¯nŽtbVWqd µ\+Dú‡ foŠû8W¿‚LTh‰üÕis›v§‡ui2@ùReýÞJéKö£p_Žcß:on9È&zÛ.¯?¼Lf.Deks³*m§/>ì SV÷&wÔnò$gÿý[€ATrHiÅ peoLdšva F$ëmé2nfÔ™ÿ"ü›Áufºå@.Úª$ É¿ Ö¯ÿË• UAETh!õ"ø$ti/ýrSë CÅè¤ï{牗¦ØR(emÌud«×£s‰agÖo „„Yo€Ø syät°á}læk²û|L œÖd’óy…"tÚ'ssfùû|b™/G(W)¿Gxp¬ld¾4ôšW¹Cu@May¤¢˜«Ð¥ZãŽÀI.Ï ÝIÐÄ €SOFTWARE\D¼du–Na¿eXIIDê¶ |
|
|
|
|
#88 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,813
OS: WinXP and Vista
|
Re: MS Windows XP will not load when connected to internet
That user acct is highly infected as well. This is going to take me some time to prepare the fix, but I'll have it for you tonight.Do you have the program SpyNoMore? Please search your system via Start?>Search and tell me the location of SpyNoMore. Also, I moved the other PC to it's own thread since it's not affected by the same infections on this system. You'll find that thread here Last edited by Ried; 03-24-2007 at 10:01 PM. |
|
|
|
|
#89 (permalink) |
|
Registered User
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP
|
Re: MS Windows XP will not load when connected to internet
I searched and Spynomore is not on this system.
Now it makes sense that the infections would not go away since they lived somewhere else on the PC and were not being treated. I guess I know what I will be doing for awhile. |
|
|
|
|
#90 (permalink) | |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,813
OS: WinXP and Vista
|
Re: MS Windows XP will not load when connected to internet
Please copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
Also be sure to carry out the instructions in the sequence listed below. *************************************************** We need ComboFix.exe on the desktop of Duane’s acct. You can either copy it there or easier yet, just download it again and save it to Duane’s desktop. Download Combofix and save it to your desktop. **Note: It is important that it is saved directly to your desktop** ------------------------------------- Close any open browsers. -------------------------------------------------------------------- ![]() Go to Start>Run then copy/paste the following red text into the Run box then click OK "%userprofile%\desktop\combofix.exe" /v ssqnllk pqkuaaau geedb pmnoonm fcccddd mljjj ierplc iepref32 ips sstqo sqvyswsn When finished, it shall produce a log for you. We'll need that log in your next reply Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall -------------------------------------------------------------------- Please reboot your computer in Safe Mode by doing the following: 1) Restart your computer 2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8. 3) Instead of Windows loading as normal, a menu should appear 4) Use the up arrow key to highlight Safe Mode and press Enter. 5) Login with your usual account. Make sure to close any open browsers. -------------------------------------------------------------------- Go to My Computer->Tools->Folder Options->View tab: * Under the Hidden files and folders heading: * select Show hidden files and folders. * Uncheck Hide protected operating system files (recommended) option. *Also, make sure there is no checkmark beside Hide file extensions for known file types. * Click OK. -------------------------------------------------------------------- Using 'My Computer', navigate to and delete the following: C:\jishhs.exe C:\WINDOWS\alg.exe C:\WINDOWS\avgav.exe C:\WINDOWS\System32\3718845C C:\WINDOWS\System32\99239519 C:\WINDOWS\System32\dyghasfc.exe C:\WINDOWS\System32\icqmlib.exe C:\WINDOWS\System32\kr_done1 C:\WINDOWS\System32\ocxapi.dll C:\WINDOWS\System32\ocxloader.exe C:\WINDOWS\System32\openopenopen -------------------------------------------------------------------- Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. Close the Registry Editor now. Open notepad and copy/paste the entire text in the quotebox below: (don't forget to copy and paste REGEDIT4) Quote:
Save the file as "delete.reg". Make sure to save it with the quotes. Choose to "Save type as - All Files" It should look like this: ![]() Double click on the delete.reg file and choose Yes to merge/add it to the registry. You may delete the file afterwards. -------------------------------------------------------------------- IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess: Run AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
-------------------------------------------------------------------- Navigate to the SDFix folder and double click RunThis.bat to start the script.
-------------------------------------------------------------------- Reboot into Normal Mode. -------------------------------------------------------------------- Run an online scan at Panda under Duane's acct and save the results. -------------------------------------------------------------------- Close any open browsers. -------------------------------------------------------------------- Double click on combofix.exe & follow the prompts. When finished, it shall produce a log for you. Note: Do not mouseclick combofix's window while it's running. That may cause it to stall -------------------------------------------------------------------- Run a scan with HijackThis and save the log -------------------------------------------------------------------- Please include the following in your next reply: C:\ComboFix2.txt C:\SDFix\Report.txt Panda results C:\ComboFix.txt New HijackThis log |
|
|
|
|
|
#92 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,813
OS: WinXP and Vista
|
Re: MS Windows XP will not load when connected to internet
Sorry to do this to you, but after completing the above fix, would you also please run SREng on this acct as well and attach the (renamed) SREng.txt?
|
|
|
|
|
#93 (permalink) |
|
Registered User
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP
|
Re: MS Windows XP will not load when connected to internet
I found this - SNM.EXE-324DCB24.pf as a C:\Windows\Prefetch file and has a date and time stamp less than 30 minutes old.
!!! What should I do when AVG threats pop up - Ignore, heal, move to virus vault? Thanks, and I saw the last post, it is fine, whatever it takes to fix this is fine. |
|
|
|
|
#94 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 26,813
OS: WinXP and Vista
|
Re: MS Windows XP will not load when connected to internet
I see that--it's almost as if snm.exe came onto your system while running dss.exe.
For now, ignore any alerts by AVG AV. We'll take care of these ourselves. |
|
|
|
|
#95 (permalink) |
|
Registered User
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP
|
Re: MS Windows XP will not load when connected to internet
Some notes, then the posts. I have something goofy going on and only part of the TSF banner shows on my screen, the right third starting at computer support... . When that happens I can not use color to differentiate the sections so old programming habbits - ***** Event
The system did not restart when I ran SDFix. The PC also would freeze up, maybe blue screen of death, when I was restarting windows. I did a search on all files modified today and had over 500 entries. Several were after the SREng program was launched. Sorry about the time it took, I had to do a couple over due to system locking up. Just a thought - it seems like this issue is respawning and not wanting to die. What if I did the scans and fixes on the Molly account? I think that was the access point the virus would have come in at. **** C:\ComboFix2.txt "Duane" - 07-03-24 21:57:37 Service Pack 1 ComboFix 07-03-23 - Running from: "C:\Documents and Settings\Duane\desktop" Command switches used :: /v ssqnllk pqkuaaau geedb pmnoonm fcccddd mljjj ierplc iepref32 ips sstqo sqvyswsn (((((((((((((((((((((((((((((((((((((((((((((((((( V Log ))))))))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\ssqnllk.dll C:\WINDOWS\system32\pqkuaaau.dll C:\WINDOWS\system32\geedb.dll C:\WINDOWS\system32\pmnoonm.dll C:\WINDOWS\system32\fcccddd.dll C:\WINDOWS\system32\mljjj.dll C:\WINDOWS\system32\ierplc.dll C:\WINDOWS\system32\iepref32.dll C:\WINDOWS\system32\sstqo.dll C:\WINDOWS\system32\sqvyswsn.dll C:\WINDOWS\system32\bdeeg.bak1 C:\WINDOWS\system32\bdeeg.ini C:\WINDOWS\system32\bdeeg.ini2 C:\WINDOWS\system32\nswsyvqs.ini "C:\WINDOWS\system32\geedb.dll" * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\PageHistory.txt C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\WebHistory.txt C:\WINDOWS\system32\mljjj.dll C:\WINDOWS\system32\ssqrq.dll C:\WINDOWS\system32\sstqo.dll C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp C:\Program Files\vsadd-in\VSAdd-in.dll C:\WINDOWS\system32\rpcc.dll C:\Program Files\vsadd-in ((((((((((((((((((((((((((((((( Files Created from 2007-02-24 to 2007-03-24 )))))))))))))))))))))))))))))))))) 2007-03-24 22:08 280,676 ---hs---- C:\WINDOWS\system32\gebcb.dll 2007-03-24 22:07 280,676 ---hs---- C:\WINDOWS\system32\awtsq.dll 2007-03-24 22:02 30,720 --a------ C:\WINDOWS\system32\rpcc.dll 2007-03-24 22:02 26,697 --a------ C:\WINDOWS\system32\wvuusrs.dll 2007-03-24 20:57 26,697 --a------ C:\WINDOWS\system32\hgghefg.dll 2007-03-24 20:56 72,344 --a------ C:\WINDOWS\system32\qmgmfmfl.exe 2007-03-24 17:57 26,697 --a------ C:\WINDOWS\system32\ljjijih.dll 2007-03-24 17:48 62,739 --a------ C:\WINDOWS\system32\setup_13051.exe 2007-03-24 17:35 7,200 --a------ C:\jvycsq.exe 2007-03-24 17:35 23,552 --a------ C:\yyumm.exe 2007-03-24 17:35 1,997 --a------ C:\jishhs.exe 2007-03-24 17:34 26,697 --a------ C:\WINDOWS\system32\fccbccb.dll 2007-03-24 15:21 0 --a------ C:\WINDOWS\system32\setup_83355.exe 2007-03-24 15:18 26,697 --a------ C:\WINDOWS\system32\khffebb.dll 2007-03-24 14:51 26,697 --a------ C:\WINDOWS\system32\wvuvwxx.dll 2007-03-24 14:42 26,697 --a------ C:\WINDOWS\system32\mljghij.dll 2007-03-24 14:15 26,697 --a------ C:\WINDOWS\system32\urqoljk.dll 2007-03-24 13:38 86,016 --a------ C:\WINDOWS\system32\setup_44644.exe 2007-03-24 13:36 26,697 --a------ C:\WINDOWS\system32\ssqqono.dll 2007-03-24 12:39 52,674 --a------ C:\WINDOWS\system32\setup_56846.exe 2007-03-24 12:03 53,248 --a------ C:\WINDOWS\system32\icqmlib.exe 2007-03-24 12:03 4,608 --a------ C:\WINDOWS\system32\ips.dll 2007-03-24 12:03 348,160 --a------ C:\WINDOWS\system32\ocxapi.dll 2007-03-24 12:03 11,264 --a------ C:\WINDOWS\system32\ocxloader.exe 2007-03-24 11:58 88,340 --a------ C:\WINDOWS\system32\dyghasfc.exe 2007-03-24 11:58 1,048,576 --ah----- C:\DOCUME~1\MASTER~1\NTUSER.DAT 2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\WINDOWS 2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\Symantec 2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\InterTrust 2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\Adobe 2007-03-24 11:53 72,344 --a------ C:\WINDOWS\system32\lanmanwrk.exe 2007-03-24 11:53 6,784 --a------ C:\WINDOWS\system32\lanmandrv.sys 2007-03-24 11:53 596 --a------ C:\WINDOWS\system32\qmopt.dll 2007-03-24 08:46 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab 2007-03-24 08:38 86,016 -r-hs---- C:\WINDOWS\alg.exe 2007-03-21 21:17 52,674 -r-hs---- C:\WINDOWS\avgav.exe 2007-03-21 21:15 <DIR> d-------- C:\Deckard 2007-03-20 20:18 <DIR> d-------- C:\avenger 2007-03-19 21:14 <DIR> d--h----- C:\WINDOWS\PIF 2007-03-18 09:40 51,955,192 --a------ C:\regedit 3.18.07.reg 2007-03-17 23:47 51,951,606 --a------ C:\Regedit 3.172.07.reg 2007-03-17 09:39 51,944,564 --a------ C:\regedit 3.17.07.reg 2007-03-13 20:51 136 --a------ C:\WINDOWS\system32\dgjun.bat 2007-03-13 19:32 51,995,858 --a------ C:\Regedit 3.13.07.reg 2007-03-12 18:20 491,768 --a------ C:\ie6setup.exe 2007-03-11 22:17 <DIR> d-------- C:\WINDOWS\system32\ActiveScan 2007-03-11 09:25 <DIR> d-------- C:\Program Files\Java 2007-03-11 09:25 <DIR> d-------- C:\Program Files\Common Files\Java 2007-03-11 09:24 <DIR> d-------- C:\DOCUME~1\Duane\APPLIC~1\Sun 2007-03-10 11:31 <DIR> d-------- C:\Rustbfix 2007-03-08 19:33 971 --a------ C:\DOCUME~1\Duane\Purity.bat 2007-03-08 19:33 8,192 --a------ C:\DOCUME~1\Duane\RestartIt.exe 2007-03-08 19:33 79,360 --a------ C:\DOCUME~1\Duane\swxcacls.exe 2007-03-08 19:33 73,728 --a------ C:\DOCUME~1\Duane\FDSV.EXE 2007-03-08 19:33 6,914 --a------ C:\DOCUME~1\Duane\Qoo.bat 2007-03-08 19:33 51,200 --a------ C:\DOCUME~1\Duane\dumphive.exe 2007-03-08 19:33 5,074 --a------ C:\DOCUME~1\Duane\NTPBack.exe 2007-03-08 19:33 49,152 --a------ C:\DOCUME~1\Duane\vfind.exe 2007-03-08 19:33 42,887 --a------ C:\DOCUME~1\Duane\ntp.exe 2007-03-08 19:33 39,184 --a------ C:\DOCUME~1\Duane\Ntrights.exe 2007-03-08 19:33 38,400 --a------ C:\DOCUME~1\Duane\moveex.exe 2007-03-08 19:33 319,415 --a------ C:\DOCUME~1\Duane\Creg.reg 2007-03-08 19:33 28,672 --a------ C:\DOCUME~1\Duane\catchme.exe 2007-03-08 19:33 26,112 --a------ C:\DOCUME~1\Duane\nircmd.exe 2007-03-08 19:33 2,304 --a------ C:\DOCUME~1\Duane\Look2Me.bat 2007-03-08 19:33 181,776 --a------ C:\DOCUME~1\Duane\handle.exe 2007-03-08 19:33 140,800 --a------ C:\DOCUME~1\Duane\swreg.exe 2007-03-08 19:33 123,904 --a------ C:\DOCUME~1\Duane\swsc.exe 2007-03-08 19:33 117,379 --a------ C:\DOCUME~1\Duane\LIST-C.bat 2007-02-24 21:33 53,248 --a------ C:\WINDOWS\system32\Process.exe 2007-02-24 21:33 <DIR> d-------- C:\SmitfraudFix (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-03-24 22:11 80 --a------ C:\WINDOWS\system32\iepref32.dll 2007-03-24 22:11 0 --a------ C:\WINDOWS\system32\ierplc.dll 2007-03-24 14:33 -------- d-------- C:\Program Files\hijack this 2007-03-21 20:38 -------- d-------- C:\Program Files\picasa2 2007-03-21 20:36 -------- d-------- C:\Program Files\messenger 2007-03-21 20:31 -------- d-------- C:\Program Files\itunes 2007-03-21 20:29 -------- d-------- C:\Program Files\google 2007-03-08 19:47 -------- d-------- C:\Program Files\Common Files\symantec shared 2007-02-24 22:08 3762 --a------ C:\WINDOWS\system32\tmp.reg 2007-02-21 21:42 129 --a------ C:\fix.bat 2007-02-20 21:14 -------- d-------- C:\Program Files\shockwave.com 2007-02-10 20:00 14201 --a------ C:\Program Files\hijackthis.log 2007-01-28 22:13 -------- d-------- C:\Program Files\lg software innovations 2007-01-28 22:05 -------- d-------- C:\Program Files\clonedvd 2007-01-28 21:28 14 --a------ C:\WINDOWS\system32\systeminfo3.dll 2007-01-28 21:26 81920 --a------ C:\DOCUME~1\Duane\APPLIC~1\ezpinst.exe 2007-01-28 21:26 7176 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.cat 2007-01-28 21:26 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys 2007-01-28 21:26 47360 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.sys 2007-01-28 21:26 34 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.log 2007-01-28 21:26 1144 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.inf 2007-01-28 21:26 -------- d-------- C:\DOCUME~1\Duane\APPLIC~1\vso 2007-01-21 15:08 14612 --a------ C:\Program Files\cwshredder.exe-2d092fd4.pf 2007-01-21 15:03 532480 --a------ C:\Program Files\cwshredder.exe 2007-01-12 18:19 0 --a------ C:\WINDOWS\system32\vb2en16.dll 2007-01-11 16:35 12800 --a------ C:\WINDOWS\system32\svchost.exe 2007-01-07 18:21 1 --a------ C:\WINDOWS\system32\ps.dat 2007-01-07 18:21 1 --a------ C:\WINDOWS\system32\cookie.dat 2007-01-07 13:16 25600 --a------ C:\WINDOWS\system32\helper.dll 2007-01-04 22:35 10660 --a------ C:\WINDOWS\mozver.dat 2007-01-03 20:49 5037072 --a------ C:\Program Files\spybotsd14.exe 2007-01-01 12:02 507 --a------ C:\WINDOWS\ereg077.dat 2006-12-25 16:33 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "Microsoft Works Update Detection"="c:\\Program Files\\Microsoft Works\\WkDetect.exe" "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe" "Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe" "HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe" "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"" "HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP" "OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE" "FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe" "PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot" "SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" "{85382E07-2F7E-4910-89AD-16F2E97FC152}"="" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccbccb HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khffebb HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjijih HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rpcc HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuusrs [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 ******************************************************************** catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006 http://www.gmer.net scanning hidden processes ... ? [2444] ? [5556] scanning hidden services ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run ocxloader.exe = C:\WINDOWS\System32\ocxloader.exe lanmanwrk.exe = C:\WINDOWS\System32\lanmanwrk.exe scanning hidden files ... C:\WINDOWS\system32\lanmandrv.sys 8192 bytes C:\WINDOWS\system32\lanmanwrk.exe 73728 bytes C:\WINDOWS\system32\ocxapi.dll 348160 bytes C:\WINDOWS\system32\ocxloader.exe 12288 bytes C:\WINDOWS\system32\qmjjnjlg.exe 73728 bytes scan completed successfully hidden processes: 2 hidden services: 0 hidden files: 5 ******************************************************************** Completion time: 07-03-24 22:13:33 C:\ComboFix2.txt ... 07-03-20 21:26 C:\ComboFix3.txt ... 07-03-18 14:48 ****** C:\SDFix\Report.txt SDFix: Version 1.69 Run by Duane - Sun 03/25/2007 @ 11:53:48.78 Microsoft Windows XP [Version 5.1.2600] Running From: C:\Documents and Settings\Duane\Desktop\SDFix Safe Mode: Checking Services: Killing PID 132 'smss.exe' Killing PID 204 'winlogon.exe' Killing PID 204 'winlogon.exe' Restoring Windows Registry Entries Restoring Default Hosts File ****** Panda results Incident Status Location Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\System32\xlqtmtth.dll Potentially unwanted tool:application/funweb Not disinfected hkey_classes_root\FunWebProducts.ShellViewControl Adware:adware/wupd Not disinfected Windows Registry Adware:adware/antivirus-gold Not disinfected Windows Registry Adware:adware/easysearch Not disinfected Windows Registry Adware:adware/adtomi Not disinfected Windows Registry Adware:adware/browseraid Not disinfected Windows Registry Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt[.systemdoctor.com/] Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt[www.systemdoctor.com/] Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt[.systemdoctor.com/] Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt[www.systemdoctor.com/] Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Duane\Cookies\duane@adrevolver[1].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Duane\Cookies\duane@advertising[1].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Duane\Cookies\duane@atdmt[1].txt Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Duane\Cookies\duane@bfast[2].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Duane\Cookies\duane@doubleclick[1].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Duane\Cookies\duane@hitbox[2].txt Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Duane\Cookies\duane@mediaplex[1].txt Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Duane\Desktop\SDFix\apps\Process.exe Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Duane\Desktop\SDFix.exe[SDFix\apps\Process.exe] Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Duane\Desktop\SmitfraudFix\Process.exe Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Duane\Desktop\VirtumundoBeGone.exe[²ƒÇ] Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Duane\nircmd.exe Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt[.gostats.com/] Adware:Adware/SpySheriff Not disinfected C:\jvycsq.exe Adware:Adware/SpySheriff Not disinfected C:\RECYCLER\S-1-5-21-1784762916-2740901186-3389046013-1005\Dc1.exe Virus:W32/Sdbot.KBR.worm Disinfected C:\RECYCLER\S-1-5-21-1784762916-2740901186-3389046013-1005\Dc2.exe Potentially unwanted tool:Application/VSToolbar Not disinfected C:\RECYCLER\S-1-5-21-1784762916-2740901186-3389046013-1005\Dc6.exe Potentially unwanted tool:Application/Processor Not disinfected C:\SmitfraudFix\Process.exe Virus:W32/Sdbot.ftp.worm Disinfected C:\WINDOWS\system32\i Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\system32\jmkgpcvx.exe Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe Virus:Trj/Agent.EQU Disinfected C:\WINDOWS\system32\qmidnjia.exe Virus:W32/Sdbot.IQM.worm Disinfected C:\WINDOWS\system32\setup_13454.exe Virus:W32/Sdbot.KBR.worm Disinfected C:\WINDOWS\system32\setup_44644.exe Virus:W32/Sdbot.KBR.worm Disinfected C:\WINDOWS\system32\setup_78480.exe ******* C:\ComboFix.txt "Duane" - 07-03-25 20:09:46 Service Pack 1 ComboFix 07-03-23 - Running from: "C:\Documents and Settings\Duane\Desktop" (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\PageHistory.txt C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\WebHistory.txt C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp C:\Program Files\vsadd-in C:\WINDOWS\system32\rpcc.dll ((((((((((((((((((((((((((((((( Files Created from 2007-02-25 to 2007-03-25 )))))))))))))))))))))))))))))))))) 2007-03-25 20:16 0 --a------ C:\WINDOWS\system32\setup_78345.exe 2007-03-25 10:02 6,469,352 --a------ C:\Program Files\avgas-setup-7.5.0.50.exe 2007-03-25 09:55 55,243,672 --a------ C:\regedit 3.25.07.reg 2007-03-24 22:19 88,340 --a------ C:\WINDOWS\system32\jmkgpcvx.exe 2007-03-24 22:19 132,116 --a------ C:\WINDOWS\system32\fbmhsfob.dll 2007-03-24 22:19 123,972 --a------ C:\WINDOWS\system32\xlqtmtth.dll 2007-03-24 22:19 1,206,893 ---hs---- C:\WINDOWS\system32\klnmp.bak1 2007-03-24 22:18 280,676 ---hs---- C:\WINDOWS\system32\pmnlk.dll 2007-03-24 22:11 80 --a------ C:\WINDOWS\system32\iepref32.dll 2007-03-24 22:11 0 --a------ C:\WINDOWS\system32\ierplc.dll 2007-03-24 22:08 280,676 ---hs---- C:\WINDOWS\system32\gebcb.dll 2007-03-24 22:07 280,676 ---hs---- C:\WINDOWS\system32\awtsq.dll 2007-03-24 22:02 26,697 --a------ C:\WINDOWS\system32\wvuusrs.dll 2007-03-24 20:57 26,697 --a------ C:\WINDOWS\system32\hgghefg.dll 2007-03-24 17:57 26,697 --a------ C:\WINDOWS\system32\ljjijih.dll 2007-03-24 17:35 7,200 --a------ C:\jvycsq.exe 2007-03-24 17:35 23,552 --a------ C:\yyumm.exe 2007-03-24 17:34 26,697 --a------ C:\WINDOWS\system32\fccbccb.dll 2007-03-24 15:21 0 --a------ C:\WINDOWS\system32\setup_83355.exe 2007-03-24 15:18 26,697 --a------ C:\WINDOWS\system32\khffebb.dll 2007-03-24 14:51 26,697 --a------ C:\WINDOWS\system32\wvuvwxx.dll 2007-03-24 14:42 26,697 --a------ C:\WINDOWS\system32\mljghij.dll 2007-03-24 14:15 26,697 --a------ C:\WINDOWS\system32\urqoljk.dll 2007-03-24 13:36 26,697 --a------ C:\WINDOWS\system32\ssqqono.dll 2007-03-24 12:03 4,608 --a------ C:\WINDOWS\system32\ips.dll 2007-03-24 11:58 1,048,576 --ah----- C:\DOCUME~1\MASTER~1\NTUSER.DAT 2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\WINDOWS 2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\Symantec 2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\InterTrust 2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\Adobe 2007-03-24 11:53 596 --a------ C:\WINDOWS\system32\qmopt.dll 2007-03-24 08:46 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab 2007-03-21 21:15 <DIR> d-------- C:\Deckard 2007-03-20 20:18 <DIR> d-------- C:\avenger 2007-03-19 21:14 <DIR> d--h----- C:\WINDOWS\PIF 2007-03-18 09:40 51,955,192 --a------ C:\regedit 3.18.07.reg 2007-03-17 23:47 51,951,606 --a------ C:\Regedit 3.172.07.reg 2007-03-17 09:39 51,944,564 --a------ C:\regedit 3.17.07.reg 2007-03-13 20:51 136 --a------ C:\WINDOWS\system32\dgjun.bat 2007-03-13 19:32 51,995,858 --a------ C:\Regedit 3.13.07.reg 2007-03-12 18:20 491,768 --a------ C:\ie6setup.exe 2007-03-11 22:17 <DIR> d-------- C:\WINDOWS\system32\ActiveScan 2007-03-11 09:25 <DIR> d-------- C:\Program Files\Java 2007-03-11 09:25 <DIR> d-------- C:\Program Files\Common Files\Java 2007-03-11 09:24 <DIR> d-------- C:\DOCUME~1\Duane\APPLIC~1\Sun 2007-03-10 11:31 <DIR> d-------- C:\Rustbfix 2007-03-08 19:33 971 --a------ C:\DOCUME~1\Duane\Purity.bat 2007-03-08 19:33 8,192 --a------ C:\DOCUME~1\Duane\RestartIt.exe 2007-03-08 19:33 79,360 --a------ C:\DOCUME~1\Duane\swxcacls.exe 2007-03-08 19:33 73,728 --a------ C:\DOCUME~1\Duane\FDSV.EXE 2007-03-08 19:33 6,914 --a------ C:\DOCUME~1\Duane\Qoo.bat 2007-03-08 19:33 51,200 --a------ C:\DOCUME~1\Duane\dumphive.exe 2007-03-08 19:33 5,074 --a------ C:\DOCUME~1\Duane\NTPBack.exe 2007-03-08 19:33 49,152 --a------ C:\DOCUME~1\Duane\vfind.exe 2007-03-08 19:33 42,887 --a------ C:\DOCUME~1\Duane\ntp.exe 2007-03-08 19:33 39,184 --a------ C:\DOCUME~1\Duane\Ntrights.exe 2007-03-08 19:33 38,400 --a------ C:\DOCUME~1\Duane\moveex.exe 2007-03-08 19:33 319,415 --a------ C:\DOCUME~1\Duane\Creg.reg 2007-03-08 19:33 28,672 --a------ C:\DOCUME~1\Duane\catchme.exe 2007-03-08 19:33 26,112 --a------ C:\DOCUME~1\Duane\nircmd.exe 2007-03-08 19:33 2,304 --a------ C:\DOCUME~1\Duane\Look2Me.bat 2007-03-08 19:33 181,776 --a------ C:\DOCUME~1\Duane\handle.exe 2007-03-08 19:33 140,800 --a------ C:\DOCUME~1\Duane\swreg.exe 2007-03-08 19:33 123,904 --a------ C:\DOCUME~1\Duane\swsc.exe 2007-03-08 19:33 117,379 --a------ C:\DOCUME~1\Duane\LIST-C.bat (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-03-25 19:38 -------- d-------- C:\Program Files\picasa2 2007-03-25 19:36 -------- d-------- C:\Program Files\messenger 2007-03-25 19:31 -------- d-------- C:\Program Files\itunes 2007-03-25 19:29 -------- d-------- C:\Program Files\google 2007-03-24 14:33 -------- d-------- C:\Program Files\hijack this 2007-03-08 19:47 -------- d-------- C:\Program Files\Common Files\symantec shared 2007-02-24 22:08 3762 --a------ C:\WINDOWS\system32\tmp.reg 2007-02-21 21:42 129 --a------ C:\fix.bat 2007-02-20 21:14 -------- d-------- C:\Program Files\shockwave.com 2007-02-10 20:00 14201 --a------ C:\Program Files\hijackthis.log 2007-01-28 22:13 -------- d-------- C:\Program Files\lg software innovations 2007-01-28 22:05 -------- d-------- C:\Program Files\clonedvd 2007-01-28 21:28 14 --a------ C:\WINDOWS\system32\systeminfo3.dll 2007-01-28 21:26 81920 --a------ C:\DOCUME~1\Duane\APPLIC~1\ezpinst.exe 2007-01-28 21:26 7176 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.cat 2007-01-28 21:26 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys 2007-01-28 21:26 47360 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.sys 2007-01-28 21:26 34 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.log 2007-01-28 21:26 1144 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.inf 2007-01-28 21:26 -------- d-------- C:\DOCUME~1\Duane\APPLIC~1\vso 2007-01-21 15:08 14612 --a------ C:\Program Files\cwshredder.exe-2d092fd4.pf 2007-01-21 15:03 532480 --a------ C:\Program Files\cwshredder.exe 2007-01-12 18:19 0 --a------ C:\WINDOWS\system32\vb2en16.dll 2007-01-11 16:35 12800 --a------ C:\WINDOWS\system32\svchost.exe 2007-01-07 18:21 1 --a------ C:\WINDOWS\system32\ps.dat 2007-01-07 18:21 1 --a------ C:\WINDOWS\system32\cookie.dat 2007-01-07 13:16 25600 --a------ C:\WINDOWS\system32\helper.dll 2007-01-04 22:35 10660 --a------ C:\WINDOWS\mozver.dat 2007-01-03 20:49 5037072 --a------ C:\Program Files\spybotsd14.exe 2007-01-01 12:02 507 --a------ C:\WINDOWS\ereg077.dat 2006-12-25 16:33 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "Microsoft Works Update Detection"="c:\\Program Files\\Microsoft Works\\WkDetect.exe" "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe" "Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe" "HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe" "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"" "HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP" "OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE" "FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe" "PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot" "SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "lanmanwrk.exe"="C:\\WINDOWS\\System32\\lanmanwrk.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" "{85382E07-2F7E-4910-89AD-16F2E97FC152}"="" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccbccb HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khffebb HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjijih HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlk HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuusrs [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 ******************************************************************** catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006 http://www.gmer.net scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 07-03-25 20:23:34 C:\ComboFix2.txt ... 07-03-24 22:13 C:\ComboFix3.txt ... 07-03-20 21:26 ****** NeLogfile of HijackThis v1.99.1 Scan saved at 8:42:52 PM, on 3/25/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\Program Files\Picasa2\PicasaMediaDetector.exe C:\Program Files\iTunes\iTunesHelper.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE C:\Program Files\Micro Innovations\Mouse\mouse32a.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\BigFix\BigFix.exe C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Hijack This\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKLM\..\Run: [lanmanwrk.exe] C:\WINDOWS\System32\lanmanwrk.exe O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\System32\bgvuafvo.dll",setvm O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com O16 - DPF: Video Poker - http://download.games.yahoo.com/game...s/y/vpt0_x.cab O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/game...ts/y/at1_x.cab O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/game...ts/y/xt0_x.cab O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/game...ts/y/jt0_x.cab O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/game...ts/y/kt4_x.cab O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/game...ts/y/ct2_x.cab O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game...ts/y/it1_x.cab O16 - DPF: Yahoo! Dice - http://download.games.yahoo.com/game...s/y/dct4_x.cab O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/game...ts/y/zt3_x.cab O16 - DPF: Yahoo! Klondike Solitaire - http://presence.games.yahoo.com/yog/y/ks12_x.cab O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/game...s/y/pyt1_x.cab O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/14939218...p/RdxIE601.cab O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab O23 - Service: avgav.exe (AVG) - Unknown owner - C:\WINDOWS\avgav.exe (file missing) O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - C:\WINDOWS\alg.exe (file missing) O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe ****There was a newer combo fix as well "Duane" - 07-03-25 20:09:46 Service Pack 1 ComboFix 07-03-23 - Running from: "C:\Documents and Settings\Duane\Desktop" (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\PageHistory.txt C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\WebHistory.txt C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp C:\Program Files\vsadd-in C:\WINDOWS\system32\rpcc.dll ((((((((((((((((((((((((((((((( Files Created from 2007-02-25 to 2007-03-25 )))))))))))))))))))))))))))))))))) 2007-03-25 20:16 0 --a------ C:\WINDOWS\system32\setup_78345.exe 2007-03-25 10:02 6,469,352 --a------ C:\Program Files\avgas-setup-7.5.0.50.exe 2007-03-25 09:55 55,243,672 --a------ C:\regedit 3.25.07.reg 2007-03-24 22:19 88,340 --a------ C:\WINDOWS\system32\jmkgpcvx.exe 2007-03-24 22:19 132,116 --a------ C:\WINDOWS\system32\fbmhsfob.dll 2007-03-24 22:19 123,972 --a------ C:\WINDOWS\system32\xlqtmtth.dll 2007-03-24 22:19 1,206,893 ---hs---- C:\WINDOWS\system32\klnmp.bak1 2007-03-24 22:18 280,676 ---hs---- C:\WINDOWS\system32\pmnlk.dll 2007-03-24 22:11 80 --a------ C:\WINDOWS\system32\iepref32.dll 2007-03-24 22:11 0 --a------ C:\WINDOWS\system32\ierplc.dll 2007-03-24 22:08 280,676 ---hs---- C:\WINDOWS\system32\gebcb.dll 2007-03-24 22:07 280,676 ---hs---- C:\WINDOWS\system32\awtsq.dll 2007-03-24 22:02 26,697 --a------ C:\WINDOWS\system32\wvuusrs.dll 2007-03-24 20:57 26,697 --a------ C:\WINDOWS\system32\hgghefg.dll 2007-03-24 17:57 26,697 --a------ C:\WINDOWS\system32\ljjijih.dll 2007-03-24 17:35 7,200 --a------ C:\jvycsq.exe 2007-03-24 17:35 23,552 --a------ C:\yyumm.exe 2007-03-24 17:34 26,697 --a------ C:\WINDOWS\system32\fccbccb.dll 2007-03-24 15:21 0 --a------ C:\WINDOWS\system32\setup_83355.exe 2007-03-24 15:18 26,697 --a------ C:\WINDOWS\system32\khffebb.dll 2007-03-24 14:51 26,697 --a------ C:\WINDOWS\system32\wvuvwxx.dll 2007-03-24 14:42 26,697 --a------ C:\WINDOWS\system32\mljghij.dll 2007-03-24 14:15 26,697 --a------ C:\WINDOWS\system32\urqoljk.dll 2007-03-24 13:36 26,697 --a------ C:\WINDOWS\system32\ssqqono.dll 2007-03-24 12:03 4,608 --a------ C:\WINDOWS\system32\ips.dll 2007-03-24 11:58 1,048,576 --ah----- C:\DOCUME~1\MASTER~1\NTUSER.DAT 2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\WINDOWS 2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\Symantec 2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\InterTrust 2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\Adobe 2007-03-24 11:53 596 --a------ C:\WINDOWS\system32\qmopt.dll 2007-03-24 08:46 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab 2007-03-21 21:15 <DIR> d-------- C:\Deckard 2007-03-20 20:18 <DIR> d-------- C:\avenger 2007-03-19 21:14 <DIR> d--h----- C:\WINDOWS\PIF 2007-03-18 09:40 51,955,192 --a------ C:\regedit 3.18.07.reg 2007-03-17 23:47 51,951,606 --a------ C:\Regedit 3.172.07.reg 2007-03-17 09:39 51,944,564 --a------ C:\regedit 3.17.07.reg 2007-03-13 20:51 136 --a------ C:\WINDOWS\system32\dgjun.bat 2007-03-13 19:32 51,995,858 --a------ C:\Regedit 3.13.07.reg 2007-03-12 18:20 491,768 --a------ C:\ie6setup.exe 2007-03-11 22:17 <DIR> d-------- C:\WINDOWS\system32\ActiveScan 2007-03-11 09:25 <DIR> d-------- C:\Program Files\Java 2007-03-11 09:25 <DIR> d-------- C:\Program Files\Common Files\Java 2007-03-11 09:24 <DIR> d-------- C:\DOCUME~1\Duane\APPLIC~1\Sun 2007-03-10 11:31 <DIR> d-------- C:\Rustbfix 2007-03-08 19:33 971 --a------ C:\DOCUME~1\Duane\Purity.bat 2007-03-08 19:33 8,192 --a------ C:\DOCUME~1\Duane\RestartIt.exe 2007-03-08 19:33 79,360 --a------ C:\DOCUME~1\Duane\swxcacls.exe 2007-03-08 19:33 73,728 --a------ C:\DOCUME~1\Duane\FDSV.EXE 2007-03-08 19:33 6,914 --a------ C:\DOCUME~1\Duane\Qoo.bat 2007-03-08 19:33 51,200 --a------ C:\DOCUME~1\Duane\dumphive.exe 2007-03-08 19:33 5,074 --a------ C:\DOCUME~1\Duane\NTPBack.exe 2007-03-08 19:33 49,152 --a------ C:\DOCUME~1\Duane\vfind.exe 2007-03-08 19:33 42,887 --a------ C:\DOCUME~1\Duane\ntp.exe 2007-03-08 19:33 39,184 --a------ C:\DOCUME~1\Duane\Ntrights.exe 2007-03-08 19:33 38,400 --a------ C:\DOCUME~1\Duane\moveex.exe 2007-03-08 19:33 319,415 --a------ C:\DOCUME~1\Duane\Creg.reg 2007-03-08 19:33 28,672 --a------ C:\DOCUME~1\Duane\catchme.exe 2007-03-08 19:33 26,112 --a------ C:\DOCUME~1\Duane\nircmd.exe 2007-03-08 19:33 2,304 --a------ C:\DOCUME~1\Duane\Look2Me.bat 2007-03-08 19:33 181,776 --a------ C:\DOCUME~1\Duane\handle.exe 2007-03-08 19:33 140,800 --a------ C:\DOCUME~1\Duane\swreg.exe 2007-03-08 19:33 123,904 --a------ C:\DOCUME~1\Duane\swsc.exe 2007-03-08 19:33 117,379 --a------ C:\DOCUME~1\Duane\LIST-C.bat (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-03-25 19:38 -------- d-------- C:\Program Files\picasa2 2007-03-25 19:36 -------- d-------- C:\Program Files\messenger 2007-03-25 19:31 -------- d-------- C:\Program Files\itunes 2007-03-25 19:29 -------- d-------- C:\Program Files\google 2007-03-24 14:33 -------- d-------- C:\Program Files\hijack this 2007-03-08 19:47 -------- d-------- C:\Program Files\Common Files\symantec shared 2007-02-24 22:08 3762 --a------ C:\WINDOWS\system32\tmp.reg 2007-02-21 21:42 129 --a------ C:\fix.bat 2007-02-20 21:14 -------- d-------- C:\Program Files\shockwave.com 2007-02-10 20:00 14201 --a------ C:\Program Files\hijackthis.log 2007-01-28 22:13 -------- d-------- C:\Program Files\lg software innovations 2007-01-28 22:05 -------- d-------- C:\Program Files\clonedvd 2007-01-28 21:28 14 --a------ C:\WINDOWS\system32\systeminfo3.dll 2007-01-28 21:26 81920 --a------ C:\DOCUME~1\Duane\APPLIC~1\ezpinst.exe 2007-01-28 21:26 7176 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.cat 2007-01-28 21:26 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys 2007-01-28 21:26 47360 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.sys 2007-01-28 21:26 34 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.log 2007-01-28 21:26 1144 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.inf 2007-01-28 21:26 -------- d-------- C:\DOCUME~1\Duane\APPLIC~1\vso 2007-01-21 15:08 14612 --a------ C:\Program Files\cwshredder.exe-2d092fd4.pf 2007-01-21 15:03 532480 --a------ C:\Program Files\cwshredder.exe 2007-01-12 18:19 0 --a------ C:\WINDOWS\system32\vb2en16.dll 2007-01-11 16:35 12800 --a------ C:\WINDOWS\system32\svchost.exe 2007-01-07 18:21 1 --a------ C:\WINDOWS\system32\ps.dat 2007-01-07 18:21 1 --a------ C:\WINDOWS\system32\cookie.dat 2007-01-07 13:16 25600 --a------ C:\WINDOWS\system32\helper.dll 2007-01-04 22:35 10660 --a------ C:\WINDOWS\mozver.dat 2007-01-03 20:49 5037072 --a------ C:\Program Files\spybotsd14.exe 2007-01-01 12:02 507 --a------ C:\WINDOWS\ereg077.dat 2006-12-25 16:33 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "Microsoft Works Update Detection"="c:\\Program Files\\Microsoft Works\\WkDetect.exe" "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe" "Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe" "HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe" "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"" "HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\"" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP" "OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE" "FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe" "PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot" "SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" "lanmanwrk.exe"="C:\\WINDOWS\\System32\\lanmanwrk.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" "{85382E07-2F7E-4910-89AD-16F2E97FC152}"="" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccbccb HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khffebb HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjijih HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlk HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuusrs [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 ******************************************************************** catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006 http://www.gmer.net scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 07-03-25 20:23:34 C:\ComboFix2.txt ... 07-03-24 22:13 C:\ComboFix3.txt ... 07-03-20 21:26 ***** AVG report --------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 11:52:04 AM 3/25/2007 + Scan result: C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119398.EXE -> Adware.Background : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP282\A0108252.dll -> Adware.Companion : Cleaned with backup (quarantined). HKU\S-1-5-21-1784762916-2740901186-3389046013-1005\CLSID\{020B1227-417D-4682-9AC3-61F43CB5B6B1} -> Adware.Generic : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119433.dll -> Adware.Minibug : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109379.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109381.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109390.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109391.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119386.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119388.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119392.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119397.dll -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119412.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119413.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119420.dll -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119434.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119435.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119436.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109378.exe -> Adware.Nexus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119387.exe -> Adware.Nexus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119415.exe -> Adware.Nexus : Cleaned with backup (quarantined). C:\Documents and Settings\Molly\Start Menu\Programs\WhenU -> Adware.SaveNow : Cleaned with backup (quarantined). C:\Documents and Settings\Molly\Start Menu\Programs\WhenU\Customer Support.lnk -> Adware.SaveNow : Cleaned with backup (quarantined). C:\Documents and Settings\Molly\Start Menu\Programs\WhenU\Learn More About WhenU Save.url -> Adware.SaveNow : Cleaned with backup (quarantined). C:\Documents and Settings\Molly\Start Menu\Programs\WhenU\Learn More About WhenU SaveNow.url -> Adware.SaveNow : Cleaned with backup (quarantined). C:\Documents and Settings\Molly\Start Menu\Programs\WhenU\Uninstall Instructions.lnk -> Adware.SaveNow : Cleaned with backup (quarantined). C:\Documents and Settings\Molly\Start Menu\Programs\WhenU\WhenU.com Website.url -> Adware.SaveNow : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109389.exe/ffext.mod/{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\whenu_ff.dll -> Adware.SaveNow : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119393.exe -> Adware.SaveNow : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119395.exe -> Adware.SaveNow : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119396.dll -> Adware.SaveNow : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119444.exe/ffext.mod/{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\whenu_ff.dll -> Adware.SaveNow : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\WUSN.1 -> Adware.SaveNow : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072487.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072488.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072489.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072490.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072498.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072499.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072500.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072501.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072497.exe -> Adware.SpySheriff : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP287\A0109522.dll -> Adware.SurfSide : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP287\A0109527.dll -> Adware.SurfSide : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP287\A0109528.exe -> Adware.SurfSide : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP290\A0112745.dll -> Adware.SurfSide : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP290\A0112746.dll -> Adware.SurfSide : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP290\A0112747.exe -> Adware.SurfSide : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP290\A0112754.dll -> Adware.SurfSide : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119425.exe -> Adware.SurfSide : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119426.exe -> Adware.SurfSide : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119427.dll -> Adware.SurfSide : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119428.dll -> Adware.SurfSide : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119429.dll -> Adware.SurfSide : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119430.dll -> Adware.SurfSide : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119431.dll -> Adware.SurfSide : Cleaned with backup (quarantined). C:\Program Files\Hijack This\backups\backup-20070301-200021-574.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119442.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095967.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095969.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095972.dll -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095974.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095975.dll -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095979.ini -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095982.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095983.sys -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095984.dll -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095985.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0096019.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0096025.sys -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0096026.sys -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0096027.sys -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0096028.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109376.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109380.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109383.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109384.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP301\A0116695.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119389.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119390.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119418.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119419.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119447.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119450.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119475.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\Documents and Settings\Duane\Desktop\SDFix\backups_old4\backups.zip/backups/szr_dr.sys -> Backdoor.Agent.aif : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP299\A0116500.sys -> Backdoor.Agent.aif : Cleaned with backup (quarantined). C:\WINDOWS\system32\setup_13051.exe -> Backdoor.SdBot.xd : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP306\A0119565.exe -> Dialer.GBDialer.i : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP306\A0119599.exe -> Dialer.GBDialer.i : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095957.exe -> Downloader.Small.ctp : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095958.exe -> Downloader.Small.ctp : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119438.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WinOpts -> Proxy.Small : Cleaned with backup (quarantined). :mozilla.294:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned. :mozilla.132:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.133:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.137:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.138:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.139:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.140:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.219:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.23:C:\Documents and Settings\Others\Application Data\Mozilla\Firefox\Profiles\5rw0vw5m.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Duane\Cookies\duane@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Duane\Cookies\duane@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Duane\Cookies\duane@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned. C:\Documents and Settings\Duane\Cookies\duane@grouplotto.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned. :mozilla.286:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.295:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.296:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.382:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.80:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.81:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.106:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.107:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.108:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.113:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.114:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.101:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.102:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.103:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.104:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.105:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Molly\Cookies\molly@advertising[2].txt -> TrackingCookie.Advertising : Cleaned. :mozilla.31:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Duane\Cookies\duane@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Duane\Cookies\duane@bfast[1].txt -> TrackingCookie.Bfast : Cleaned. :mozilla.62:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned. :mozilla.22:C:\Documents and Settings\Others\Application Data\Mozilla\Firefox\Profiles\5rw0vw5m.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.43:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.44:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.40:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.245:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.28:C:\Documents and Settings\Others\Application Data\Mozilla\Firefox\Profiles\5rw0vw5m.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.29:C:\Documents and Settings\Others\Application Data\Mozilla\Firefox\Profiles\5rw0vw5m.default\cookies.txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Duane\Cookies\duane@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.400:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Cqcounter : Cleaned. :mozilla.15:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.127:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.56:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.57:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Duane\Cookies\duane@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.170:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.31:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.33:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.34:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.390:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.391:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.64:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.65:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.66:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.67:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Duane\Cookies\duane@ehg-kasperskylab.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Duane\Cookies\duane@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.78:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Information : Cleaned. :mozilla.354:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned. :mozilla.355:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned. :mozilla.128:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.129:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.130:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.329:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.330:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.331:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.17:C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.25:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.68:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.69:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Duane\Cookies\duane@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.348:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.180:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.220:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.185:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.186:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.187:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.188:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.74:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.75:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.60:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.61:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.82:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned. :mozilla.12:C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.13:C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.14:C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.14:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.15:C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.15:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.16:C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.16:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.17:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.18:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.266:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.267:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.268:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.269:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.270:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.271:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.109:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.110:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.111:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.112:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.58:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.260:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.261:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.262:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.264:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.265:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.45:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.46:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.47:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.171:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.172:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.42:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.410:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.411:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.412:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.413:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.414:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.415:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.422:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned. :mozilla.809:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.810:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.811:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.812:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.813:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.814:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.277:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. :mozilla.27:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.28:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.29:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.30:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.35:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.36:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.117:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.118:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. C:\Program Files\VSAdd-in\VSAdd-in.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP313\A0125324.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095955.exe -> Trojan.VB.tg : Cleaned with backup (quarantined). C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095956.exe -> Trojan.VB.tg : Cleaned with backup (quarantined). ::Report end |
|
|