Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 03-23-2007, 08:51 PM   #81 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,813
OS: WinXP and Vista


Re: MS Windows XP will not load when connected to internet

Hi,

No--do not update to SP2 yet as the infection may corrupt the install.

Very good question. Online scanners, AVG A-S, SDFix, ComboFix will scan the system globally, but scans with dss.exe and the HijackThis log produced are only scanning the account that it is run on. It would be a good idea to run dss.exe on the other accts on this sytem after completing the fix below.

Panda is reporting mostly unwanted cookies--which we'll run ATF Cleaner to take care of those. We'll take out the one registry entry it is reporting--the others with no location are orphaned registry entries. With no file associated with them, they are harmless and it's better to just leave them than to go rooting around the registry looking for them and risking irrepairable damage to your system.


Please copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

***************************************************

Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. Close the Registry Editor now.

Open notepad and copy/paste the entire text in the quotebox below: (don't forget to copy and paste REGEDIT4)

Quote:
REGEDIT4

[-HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ntio256]

[-hkey_classes_root\FunWebProducts.DataControl.1]
Save the file as "delete.reg". Make sure to save it with the quotes. Choose to "Save type as - All Files"
It should look like this:

Double click on the delete.reg file and choose Yes to merge/add it to the registry. You may delete the file afterwards.

----------------------------------------------------

Delete these folders:

C:\337100427
C:\WINDOWS\System32\14981
C:\WINDOWS\System32\3D64363D
C:\WINDOWS\System32\7AAECFBC
C:\WINDOWS\System32\86C67981
C:\WINDOWS\System32\9147A101
C:\WINDOWS\System32\9947BC72
C:\WINDOWS\System32\9ACA5390
C:\WINDOWS\System32\DF21552E
C:\WINDOWS\System32\openopenopenopen

---------------------------------------------------------

Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

--------------------------------------------------------------------

Reboot your system and go into Safe Mode to run SDFix once again.

--------------------------------------------------------------------

I realize the online scans are time consuming, but I'd like to see if Kaspersky sees anything further:

Please perform an online scan with Internet Explorer at Kaspersky Online Scanner

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply

------------------------------------------------------------

Please include the following in your next reply:

C:\SDFix\Report.txt
Kaspersky results
main.txt for each acct on this system


Is this computer networked to any others?
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 03-23-2007, 09:58 PM   #82 (permalink)
Registered User
 
cul8rman's Avatar
 
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP


Re: MS Windows XP will not load when connected to internet

Easy answers first while I am doing the other things that will take some time. I don't mind doing them if it will lead to a cure in the end.

Regarding SP2 install, I had read that somewhere on this site to not upgrade if infected, so that is why I stopped before going too far.

Regarding network, yes in an simple way. I was getting to that point after cleaning up this one. Both systems are plugged into a netgear ethernet hub. I did not get past this system in setting up a network. The other system is slow, but running. Would you like a scan of that one just to see if it is infected? I will be busy doing the other tasks for awhile.
cul8rman is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-23-2007, 10:15 PM   #83 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,813
OS: WinXP and Vista


Re: MS Windows XP will not load when connected to internet

Yes, please run dss.exe on the other system and post that here as well. I think it would be prudent given the circumstances.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-24-2007, 09:50 AM   #84 (permalink)
Registered User
 
cul8rman's Avatar
 
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP


Re: MS Windows XP will not load when connected to internet

I was scrolling through the posting and saw this under the
-- Files created between 2007-02-24 and 2007-03-24 ----------------------------- Section. This is on the other system as well and looks weird, like it does not belong. It did not show up here, but there is a smile face in it, scroll down to see. You can not miss is.

2007-03-17 2122 0 --a------ C:\Documents and Settings\robyn\Application Data\wklnhst.dat

having problems with Kaspersky downloading and installing, will try to work through it and will ask for assistance later if I can not access the scan.
cul8rman is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-24-2007, 04:36 PM   #85 (permalink)
Registered User
 
cul8rman's Avatar
 
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP


Re: MS Windows XP will not load when connected to internet

I have pasted but could not attach results from the dss scans. An observation - I was running dss and the system froze up on me, or I was not
patient enough to wait it out, but i did not hear anything and
I waited about two minutes before hitting the x to close the window.
The end program window came up and I let it finish. I then saw the
file that is attached come up. It was named snm.exe.

I am now also getting a rundll error and have saved a copy of the printscreen in paint but can not attach to the thread. I don't know why. Only the right third of the page header is displayed. This happened around page three and just recently came back.

Results of dss scans on each user account on the infected PC.

Duane

Deckard's System Scanner v20070318.32
Run by Duane on 2007-03-24 at 13:23:14
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Duane.exe) -----------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 1:23:22 PM, on 3/24/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\avgav.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\System32\icqmlib.exe
C:\WINDOWS\System32\ocxloader.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Duane\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\Duane.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1846C0B3-8272-4FB3-A455-8F99FC0C0AF8} - C:\WINDOWS\System32\pqkuaaau.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {85382E07-2F7E-4910-89AD-16F2E97FC152} - C:\WINDOWS\System32\ssqnllk.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {C3B48746-C8C5-42DB-B803-F164DDEC1E55} - C:\WINDOWS\System32\pqkuaaau.dll
O2 - BHO: (no name) - {E0887CD0-9049-4F2E-920E-9296B905C66D} - C:\WINDOWS\System32\geedb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Video Poker - http://download.games.yahoo.com/game...s/y/vpt0_x.cab
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/game...ts/y/at1_x.cab
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/game...ts/y/xt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/game...ts/y/jt0_x.cab
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/game...ts/y/kt4_x.cab
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/game...ts/y/ct2_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game...ts/y/it1_x.cab
O16 - DPF: Yahoo! Dice - http://download.games.yahoo.com/game...s/y/dct4_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/game...ts/y/zt3_x.cab
O16 - DPF: Yahoo! Klondike Solitaire - http://presence.games.yahoo.com/yog/y/ks12_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/game...s/y/pyt1_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/14939218...p/RdxIE601.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab
O20 - Winlogon Notify: geedb - C:\WINDOWS\System32\geedb.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ssqnllk - C:\WINDOWS\SYSTEM32\ssqnllk.dll
O23 - Service: avgav.exe (AVG) - Unknown owner - C:\WINDOWS\avgav.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - C:\WINDOWS\alg.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


-- Files created between 2007-02-24 and 2007-03-24 -----------------------------

2007-03-24 13:22:45 1997 --a------ C:\jishhs.exe
2007-03-24 13:22:30 26697 --a------ C:\WINDOWS\System32\pmnoonm.dll
2007-03-24 12:39:22 52674 --a------ C:\WINDOWS\System32\setup_56846.exe<SETUP_~1.EXE>
2007-03-24 12:34:45 26697 --a------ C:\WINDOWS\System32\fcccddd.dll
2007-03-24 12:09:27 280676 ---hs---- C:\WINDOWS\System32\mljjj.dll
2007-03-24 12:08:29 1208018 ---hs---- C:\WINDOWS\System32\bdeeg.ini2<BDEEG~1.INI>
2007-03-24 12:03:47 280676 ---hs---- C:\WINDOWS\System32\ssqrq.dll
2007-03-24 12:03:22 11264 --a------ C:\WINDOWS\System32\ocxloader.exe<OCXLOA~1.EXE>
2007-03-24 12:03:22 348160 --a------ C:\WINDOWS\System32\ocxapi.dll
2007-03-24 12:03:22 0 --a------ C:\WINDOWS\System32\ierplc.dll
2007-03-24 12:03:22 80 --a------ C:\WINDOWS\System32\iepref32.dll
2007-03-24 12:03:17 4608 --a------ C:\WINDOWS\System32\ips.dll
2007-03-24 12:03:14 53248 --a------ C:\WINDOWS\System32\icqmlib.exe
2007-03-24 12:01:15 280676 ---hs---- C:\WINDOWS\System32\sstqo.dll
2007-03-24 11:59:00 123972 --a------ C:\WINDOWS\System32\sqvyswsn.dll
2007-03-24 11:58:59 0 d-------- C:\Documents and Settings\Duane\Application Data\SearchToolbarCorp<SEARCH~1>
2007-03-24 11:58:50 132116 --a------ C:\WINDOWS\System32\pqkuaaau.dll
2007-03-24 11:58:46 0 d-------- C:\Program Files\VSAdd-in
2007-03-24 11:58:43 88340 --a------ C:\WINDOWS\System32\dyghasfc.exe
2007-03-24 11:58:42 1206759 ---hs---- C:\WINDOWS\System32\bdeeg.bak1<BDEEG~1.BAK>
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\WINDOWS
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Symantec
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\InterTrust<INTERT~1>
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Adobe
2007-03-24 11:58:21 280676 ---hs---- C:\WINDOWS\System32\geedb.dll
2007-03-24 11:58:21 1048576 --ah----- C:\Documents and Settings\Master Account\NTUSER.DAT
2007-03-24 11:53:13 596 --a------ C:\WINDOWS\System32\qmopt.dll
2007-03-24 11:52:57 26697 --a------ C:\WINDOWS\System32\ssqnllk.dll
2007-03-24 08:46:40 0 d-------- C:\WINDOWS\System32\Kaspersky Lab<KASPER~1>
2007-03-24 08:38:51 86016 -r-hs---- C:\WINDOWS\alg.exe
2007-03-24 08:38:42 69 --a------ C:\WINDOWS\System32\i
2007-03-21 21:17:04 52674 -r-hs---- C:\WINDOWS\avgav.exe
2007-03-20 20:18:18 0 d-------- C:\avenger
2007-03-19 21:14:12 0 d--h----- C:\WINDOWS\PIF
2007-03-13 20:51:18 136 --a------ C:\WINDOWS\System32\dgjun.bat
2007-03-12 18:20:25 491768 --a------ C:\ie6setup.exe
2007-03-11 22:17:35 0 d-------- C:\WINDOWS\System32\ActiveScan<ACTIVE~1>
2007-03-11 09:25:11 0 d-------- C:\Program Files\Java
2007-03-11 09:25:11 0 d-------- C:\Program Files\Common Files\Java
2007-03-11 09:24:21 0 d-------- C:\Documents and Settings\Duane\Application Data\Sun
2007-03-10 11:31:19 0 d-------- C:\Rustbfix
2007-03-08 19:33:08 49152 --a------ C:\Documents and Settings\Duane\vfind.exe
2007-03-08 19:33:08 79360 --a------ C:\Documents and Settings\Duane\swxcacls.exe
2007-03-08 19:33:08 123904 --a------ C:\Documents and Settings\Duane\swsc.exe
2007-03-08 19:33:08 140800 --a------ C:\Documents and Settings\Duane\swreg.exe
2007-03-08 19:33:08 8192 --a------ C:\Documents and Settings\Duane\RestartIt.exe<RESTAR~1.EXE>
2007-03-08 19:33:08 6914 --a------ C:\Documents and Settings\Duane\Qoo.bat
2007-03-08 19:33:08 971 --a------ C:\Documents and Settings\Duane\Purity.bat
2007-03-08 19:33:08 39184 --a------ C:\Documents and Settings\Duane\Ntrights.exe
2007-03-08 19:33:08 5074 --a------ C:\Documents and Settings\Duane\NTPBack.exe
2007-03-08 19:33:08 42887 --a------ C:\Documents and Settings\Duane\ntp.exe
2007-03-08 19:33:08 26112 --a------ C:\Documents and Settings\Duane\nircmd.exe
2007-03-08 19:33:08 38400 --a------ C:\Documents and Settings\Duane\moveex.exe
2007-03-08 19:33:08 2304 --a------ C:\Documents and Settings\Duane\Look2Me.bat
2007-03-08 19:33:08 117379 --a------ C:\Documents and Settings\Duane\LIST-C.bat
2007-03-08 19:33:08 181776 --a------ C:\Documents and Settings\Duane\handle.exe
2007-03-08 19:33:08 73728 --a------ C:\Documents and Settings\Duane\FDSV.EXE
2007-03-08 19:33:08 51200 --a------ C:\Documents and Settings\Duane\dumphive.exe
2007-03-08 19:33:08 319415 --a------ C:\Documents and Settings\Duane\Creg.reg
2007-03-08 19:33:08 28672 --a------ C:\Documents and Settings\Duane\catchme.exe
2007-02-24 21:33:14 53248 --a------ C:\WINDOWS\System32\Process.exe
2007-02-24 21:33:08 0 d-------- C:\SmitfraudFix<SMITFR~1>


-- Find3M Report ---------------------------------------------------------------

2007-03-24 13:23:16 0 d-------- C:\Program Files\Hijack This<HIJACK~1>
2007-03-21 22:56:19 0 d---s---- C:\Documents and Settings\Duane\Application Data\Microsoft<MICROS~1>
2007-03-21 20:38:09 0 d-------- C:\Program Files\Picasa2
2007-03-21 20:36:13 0 d-------- C:\Program Files\Messenger<MESSEN~1>
2007-03-21 20:31:05 0 d-------- C:\Program Files\iTunes
2007-03-21 20:29:54 0 d-------- C:\Program Files\Google
2007-03-21 20:27:24 0 d-------- C:\Program Files\BigFix
2007-03-08 19:47:09 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1>
2007-02-24 22:08:44 3762 --a------ C:\WINDOWS\System32\tmp.reg
2007-02-24 10:40:37 0 d-------- C:\Documents and Settings\Duane\Application Data\AVG7
2007-02-21 21:42:31 129 --a------ C:\fix.bat
2007-02-21 18:24:56 0 d-------- C:\Program Files\backups
2007-02-20 21:14:12 0 d-------- C:\Program Files\Shockwave.com<SHOCKW~1.COM>
2007-02-13 21:29:11 0 d-------- C:\Program Files\Common Files\Sandlot Shared<SANDLO~1>
2007-02-10 20:00:13 14201 --a------ C:\Program Files\hijackthis.log<HIJACK~1.LOG>
2007-01-28 22:13:42 0 d-------- C:\Program Files\LG Software Innovations<LGSOFT~1>
2007-01-28 22:05:20 0 d-------- C:\Program Files\CloneDVD
2007-01-28 21:28:17 14 --a------ C:\WINDOWS\System32\systeminfo3.dll<SYSTEM~1.DLL>
2007-01-28 21:26:56 0 d-------- C:\Documents and Settings\Duane\Application Data\Vso
2007-01-28 21:26:55 34 --a------ C:\Documents and Settings\Duane\Application Data\pcouffin.log
2007-01-28 21:26:41 47360 --a------ C:\Documents and Settings\Duane\Application Data\pcouffin.sys
2007-01-28 21:26:41 1144 --a------ C:\Documents and Settings\Duane\Application Data\pcouffin.inf
2007-01-28 21:26:41 7176 --a------ C:\Documents and Settings\Duane\Application Data\pcouffin.cat
2007-01-28 21:26:41 81920 --a------ C:\Documents and Settings\Duane\Application Data\ezpinst.exe
2007-01-21 15:08:15 14612 --a------ C:\Program Files\CWSHREDDER.EXE-2D092FD4.pf<CWSHRE~1.PF>
2007-01-21 15:03:52 532480 --a------ C:\Program Files\cwshredder.exe<CWSHRE~1.EXE>
2007-01-13 14:32:20 0 --a------ C:\WINDOWS\System32\00BDDB65
2007-01-12 18:19:57 0 --a------ C:\WINDOWS\System32\vb2en16.dll
2007-01-12 18:19:50 1235 --a------ C:\WINDOWS\System32\openopenopen<OPENOP~2>
2007-01-12 18:19:34 0 --a------ C:\WINDOWS\System32\99239519
2007-01-11 16:35:52 1 --a------ C:\WINDOWS\System32\kr_done1
2007-01-11 16:35:33 12800 --a------ C:\WINDOWS\System32\svchost.exe
2007-01-11 16:33:19 0 --a------ C:\WINDOWS\System32\3718845C
2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\ps.dat
2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\cookie.dat
2007-01-07 13:16:52 25600 --a------ C:\WINDOWS\System32\helper.dll
2007-01-04 22:35:41 10660 --a------ C:\WINDOWS\mozver.dat
2007-01-03 20:49:11 5037072 --a------ C:\Program Files\spybotsd14.exe<SPYBOT~1.EXE>
2007-01-01 12:02:40 507 --a------ C:\WINDOWS\EReg077.dat
2006-12-25 16:33:11 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi<PLAINO~1.XPI>


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Microsoft Works Update Detection"="c:\\Program Files\\Microsoft Works\\WkDetect.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe"
"PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot"
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SoundService"="rundll32.exe \"C:\\WINDOWS\\System32\\sqvyswsn.dll\",setvm"
"icqmlib.exe"="icqmlib.exe"
"ocxloader.exe"="C:\\WINDOWS\\System32\\ocxloader.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{85382E07-2F7E-4910-89AD-16F2E97FC152}"=""

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnllk

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_LANMANDRV


-- End of Deckard's System Scanner: finished at 2007-03-24 at 13:23:55 ---------

Cody

Deckard's System Scanner v20070318.32
Run by Cody on 2007-03-24 at 13:26:09
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Cody.exe) ------------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 1:26:10 PM, on 3/24/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\avgav.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
C:\PROGRA~1\Sygate\SPF\smc.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\HP\hpcoretech\soln\HPOSM.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Documents and Settings\Cody\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\Cody.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1846C0B3-8272-4FB3-A455-8F99FC0C0AF8} - C:\WINDOWS\System32\pqkuaaau.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {85382E07-2F7E-4910-89AD-16F2E97FC152} - C:\WINDOWS\System32\ssqnllk.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {C3B48746-C8C5-42DB-B803-F164DDEC1E55} - C:\WINDOWS\System32\pqkuaaau.dll
O2 - BHO: (no name) - {E0887CD0-9049-4F2E-920E-9296B905C66D} - C:\WINDOWS\System32\geedb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [nvcdllx] C:\WINDOWS\System32\cstatvmq.exe
O4 - HKCU\..\Run: [kdmmcvs] C:\WINDOWS\System32\gmonstml.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\WINDOWS\System32\geedb.dll,CreateProtectProc
O4 - Startup: .protected
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinpoeb.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Video Poker - http://download.games.yahoo.com/game...s/y/vpt0_x.cab
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/game...ts/y/at1_x.cab
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/game...ts/y/xt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/game...ts/y/jt0_x.cab
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/game...ts/y/kt4_x.cab
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/game...ts/y/ct2_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game...ts/y/it1_x.cab
O16 - DPF: Yahoo! Dice - http://download.games.yahoo.com/game...s/y/dct4_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/game...ts/y/zt3_x.cab
O16 - DPF: Yahoo! Klondike Solitaire - http://presence.games.yahoo.com/yog/y/ks12_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/game...s/y/pyt1_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/14939218...p/RdxIE601.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab
O20 - Winlogon Notify: geedb - C:\WINDOWS\System32\geedb.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ssqnllk - C:\WINDOWS\SYSTEM32\ssqnllk.dll
O23 - Service: avgav.exe (AVG) - Unknown owner - C:\WINDOWS\avgav.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - C:\WINDOWS\alg.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


-- Files created between 2007-02-24 and 2007-03-24 -----------------------------

2007-03-24 13:22:45 1997 --a------ C:\jishhs.exe
2007-03-24 13:22:30 26697 --a------ C:\WINDOWS\System32\pmnoonm.dll
2007-03-24 12:39:22 52674 --a------ C:\WINDOWS\System32\setup_56846.exe<SETUP_~1.EXE>
2007-03-24 12:34:45 26697 --a------ C:\WINDOWS\System32\fcccddd.dll
2007-03-24 12:09:27 280676 ---hs---- C:\WINDOWS\System32\mljjj.dll
2007-03-24 12:08:29 1208018 ---hs---- C:\WINDOWS\System32\bdeeg.ini2<BDEEG~1.INI>
2007-03-24 12:03:47 280676 ---hs---- C:\WINDOWS\System32\ssqrq.dll
2007-03-24 12:03:22 11264 --a------ C:\WINDOWS\System32\ocxloader.exe<OCXLOA~1.EXE>
2007-03-24 12:03:22 348160 --a------ C:\WINDOWS\System32\ocxapi.dll
2007-03-24 12:03:22 0 --a------ C:\WINDOWS\System32\ierplc.dll
2007-03-24 12:03:22 80 --a------ C:\WINDOWS\System32\iepref32.dll
2007-03-24 12:03:17 4608 --a------ C:\WINDOWS\System32\ips.dll
2007-03-24 12:03:14 53248 --a------ C:\WINDOWS\System32\icqmlib.exe
2007-03-24 12:01:15 280676 ---hs---- C:\WINDOWS\System32\sstqo.dll
2007-03-24 11:59:00 123972 --a------ C:\WINDOWS\System32\sqvyswsn.dll
2007-03-24 11:58:59 0 d-------- C:\Documents and Settings\Duane\Application Data\SearchToolbarCorp<SEARCH~1>
2007-03-24 11:58:50 132116 --a------ C:\WINDOWS\System32\pqkuaaau.dll
2007-03-24 11:58:46 0 d-------- C:\Program Files\VSAdd-in
2007-03-24 11:58:43 88340 --a------ C:\WINDOWS\System32\dyghasfc.exe
2007-03-24 11:58:42 1206759 ---hs---- C:\WINDOWS\System32\bdeeg.bak1<BDEEG~1.BAK>
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\WINDOWS
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Symantec
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\InterTrust<INTERT~1>
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Adobe
2007-03-24 11:58:21 280676 ---hs---- C:\WINDOWS\System32\geedb.dll
2007-03-24 11:58:21 1048576 --ah----- C:\Documents and Settings\Master Account\NTUSER.DAT
2007-03-24 11:53:13 596 --a------ C:\WINDOWS\System32\qmopt.dll
2007-03-24 11:52:57 26697 --a------ C:\WINDOWS\System32\ssqnllk.dll
2007-03-24 08:46:40 0 d-------- C:\WINDOWS\System32\Kaspersky Lab<KASPER~1>
2007-03-24 08:38:51 86016 -r-hs---- C:\WINDOWS\alg.exe
2007-03-24 08:38:42 69 --a------ C:\WINDOWS\System32\i
2007-03-21 21:17:04 52674 -r-hs---- C:\WINDOWS\avgav.exe
2007-03-20 20:18:18 0 d-------- C:\avenger
2007-03-19 21:14:12 0 d--h----- C:\WINDOWS\PIF
2007-03-13 20:51:18 136 --a------ C:\WINDOWS\System32\dgjun.bat
2007-03-12 18:20:25 491768 --a------ C:\ie6setup.exe
2007-03-11 22:17:35 0 d-------- C:\WINDOWS\System32\ActiveScan<ACTIVE~1>
2007-03-11 09:25:11 0 d-------- C:\Program Files\Java
2007-03-11 09:25:11 0 d-------- C:\Program Files\Common Files\Java
2007-03-11 09:24:21 0 d-------- C:\Documents and Settings\Duane\Application Data\Sun
2007-03-10 11:31:19 0 d-------- C:\Rustbfix
2007-03-08 19:33:08 49152 --a------ C:\Documents and Settings\Duane\vfind.exe
2007-03-08 19:33:08 79360 --a------ C:\Documents and Settings\Duane\swxcacls.exe
2007-03-08 19:33:08 123904 --a------ C:\Documents and Settings\Duane\swsc.exe
2007-03-08 19:33:08 140800 --a------ C:\Documents and Settings\Duane\swreg.exe
2007-03-08 19:33:08 8192 --a------ C:\Documents and Settings\Duane\RestartIt.exe<RESTAR~1.EXE>
2007-03-08 19:33:08 6914 --a------ C:\Documents and Settings\Duane\Qoo.bat
2007-03-08 19:33:08 971 --a------ C:\Documents and Settings\Duane\Purity.bat
2007-03-08 19:33:08 39184 --a------ C:\Documents and Settings\Duane\Ntrights.exe
2007-03-08 19:33:08 5074 --a------ C:\Documents and Settings\Duane\NTPBack.exe
2007-03-08 19:33:08 42887 --a------ C:\Documents and Settings\Duane\ntp.exe
2007-03-08 19:33:08 26112 --a------ C:\Documents and Settings\Duane\nircmd.exe
2007-03-08 19:33:08 38400 --a------ C:\Documents and Settings\Duane\moveex.exe
2007-03-08 19:33:08 2304 --a------ C:\Documents and Settings\Duane\Look2Me.bat
2007-03-08 19:33:08 117379 --a------ C:\Documents and Settings\Duane\LIST-C.bat
2007-03-08 19:33:08 181776 --a------ C:\Documents and Settings\Duane\handle.exe
2007-03-08 19:33:08 73728 --a------ C:\Documents and Settings\Duane\FDSV.EXE
2007-03-08 19:33:08 51200 --a------ C:\Documents and Settings\Duane\dumphive.exe
2007-03-08 19:33:08 319415 --a------ C:\Documents and Settings\Duane\Creg.reg
2007-03-08 19:33:08 28672 --a------ C:\Documents and Settings\Duane\catchme.exe
2007-02-24 21:33:14 53248 --a------ C:\WINDOWS\System32\Process.exe
2007-02-24 21:33:08 0 d-------- C:\SmitfraudFix<SMITFR~1>


-- Find3M Report ---------------------------------------------------------------

2007-03-24 13:26:09 0 d-------- C:\Program Files\Hijack This<HIJACK~1>
2007-03-21 20:38:09 0 d-------- C:\Program Files\Picasa2
2007-03-21 20:36:13 0 d-------- C:\Program Files\Messenger<MESSEN~1>
2007-03-21 20:31:05 0 d-------- C:\Program Files\iTunes
2007-03-21 20:29:54 0 d-------- C:\Program Files\Google
2007-03-21 20:27:24 0 d-------- C:\Program Files\BigFix
2007-03-08 19:47:09 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1>
2007-02-24 22:08:44 3762 --a------ C:\WINDOWS\System32\tmp.reg
2007-02-21 21:42:31 129 --a------ C:\fix.bat
2007-02-21 18:24:56 0 d-------- C:\Program Files\backups
2007-02-20 21:14:12 0 d-------- C:\Program Files\Shockwave.com<SHOCKW~1.COM>
2007-02-13 21:29:11 0 d-------- C:\Program Files\Common Files\Sandlot Shared<SANDLO~1>
2007-02-10 20:00:13 14201 --a------ C:\Program Files\hijackthis.log<HIJACK~1.LOG>
2007-01-28 22:13:42 0 d-------- C:\Program Files\LG Software Innovations<LGSOFT~1>
2007-01-28 22:05:20 0 d-------- C:\Program Files\CloneDVD
2007-01-28 21:28:17 14 --a------ C:\WINDOWS\System32\systeminfo3.dll<SYSTEM~1.DLL>
2007-01-21 15:08:15 14612 --a------ C:\Program Files\CWSHREDDER.EXE-2D092FD4.pf<CWSHRE~1.PF>
2007-01-21 15:03:52 532480 --a------ C:\Program Files\cwshredder.exe<CWSHRE~1.EXE>
2007-01-13 14:32:20 0 --a------ C:\WINDOWS\System32\00BDDB65
2007-01-12 18:19:57 0 --a------ C:\WINDOWS\System32\vb2en16.dll
2007-01-12 18:19:50 1235 --a------ C:\WINDOWS\System32\openopenopen<OPENOP~2>
2007-01-12 18:19:34 0 --a------ C:\WINDOWS\System32\99239519
2007-01-11 16:35:52 1 --a------ C:\WINDOWS\System32\kr_done1
2007-01-11 16:35:33 12800 --a------ C:\WINDOWS\System32\svchost.exe
2007-01-11 16:33:19 0 --a------ C:\WINDOWS\System32\3718845C
2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\ps.dat
2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\cookie.dat
2007-01-07 13:16:52 25600 --a------ C:\WINDOWS\System32\helper.dll
2007-01-04 22:35:41 10660 --a------ C:\WINDOWS\mozver.dat
2007-01-03 20:49:11 5037072 --a------ C:\Program Files\spybotsd14.exe<SPYBOT~1.EXE>
2007-01-01 12:02:40 507 --a------ C:\WINDOWS\EReg077.dat
2006-12-25 16:33:11 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi<PLAINO~1.XPI>


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"DeluxeCommunications"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe"
"nvcdllx"="C:\\WINDOWS\\System32\\cstatvmq.exe"
"kdmmcvs"="C:\\WINDOWS\\System32\\gmonstml.exe"
"cmds"="rundll32.exe C:\\WINDOWS\\System32\\geedb.dll,CreateProtectProc"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe"
"PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot"
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SoundService"="rundll32.exe \"C:\\WINDOWS\\System32\\sqvyswsn.dll\",setvm"
"icqmlib.exe"="icqmlib.exe"
"ocxloader.exe"="C:\\WINDOWS\\System32\\ocxloader.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{85382E07-2F7E-4910-89AD-16F2E97FC152}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000001

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnllk

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_LANMANDRV


-- End of Deckard's System Scanner: finished at 2007-03-24 at 13:26:49 ---------

Molly

Deckard's System Scanner v20070318.32
Run by Molly on 2007-03-24 at 13:41:48
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Molly.exe) -----------------------------------------------

HijackThis failed to provide a log after three minutes; running clone instead.
-- HijackThis Clone ------------------------------------------------------------

Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-03-24 13:44:49
Platform: Windows XP Service Pack 1 (5.01.2600)
MSIE: Internet Explorer (6.0.2800.1106)

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\avgav.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\alg.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\monitor.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Micro Innovations\Keyboard\KBDAP32A.EXE
C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\system32\icqmlib.exe
C:\WINDOWS\system32\ocxloader.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Molly\Desktop\dss.exe
C:\Program Files\Hijack This\Molly.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1846C0B3-8272-4FB3-A455-8F99FC0C0AF8} - C:\WINDOWS\system32\pqkuaaau.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {85382E07-2F7E-4910-89AD-16F2E97FC152} - C:\WINDOWS\system32\ssqnllk.dll
O2 - BHO: (no name) - {9273199F-9FC8-495F-B7FF-F15568877CFa} - C:\WINDOWS\system32\pqkuaaau.dll
O2 - BHO: (no name) - {95F1789F-CDC6-401B-8A19-DBA1532F86Bb} - C:\WINDOWS\system32\pqkuaaau.dll
O2 - BHO: (no name) - {97104B0B-8837-4EEE-ABE1-21842271B712} - C:\WINDOWS\system32\geedb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar3.dll
O2 - BHO: (no name) - {C3B48746-C8C5-42DB-B803-F164DDEC1E55} - C:\WINDOWS\system32\pqkuaaau.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar3.dll
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~2\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [ymmsddlop] C:\WINDOWS\system32\vssmnptc.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [WinMedia] C:\DOCUME~1\Molly\LOCALS~1\Temp\257000.exe
O4 - HKCU\..\Run: [BraveSentry] C:\Program Files\BraveSentry\BraveSentry.exe
O4 - HKCU\..\Run: [gdxapimn] C:\WINDOWS\System32\jgdepgc.exe
O4 - HKCU\..\Run: [nvcdllx] C:\WINDOWS\System32\cstatvmq.exe
O4 - HKCU\..\Run: [csmhtop] C:\WINDOWS\System32\sdmmlmn.exe
O4 - HKCU\..\Run: [ddsysmns] C:\WINDOWS\System32\scmdcon.exe
O4 - HKCU\..\Run: [ncsmmlg] C:\WINDOWS\System32\ctlmems.exe
O4 - HKCU\..\Run: [kdmmcvs] C:\WINDOWS\System32\gmonstml.exe
O4 - HKCU\..\Run: [fcqlep] c:\windows\system32\fcqlep.exe fcqlep
O4 - Startup: .protected
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinpoeb.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...p=ZUxdm080YYUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)
O9 - Extra 'Tools' menuitem: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra 'Tools' menuitem: (no name) - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Video Poker () - http://download.games.yahoo.com/game...s/y/vpt0_x.cab
O16 - DPF: Yahoo! Backgammon () - http://download.games.yahoo.com/game...ts/y/at1_x.cab
O16 - DPF: Yahoo! Bingo () - http://download.games.yahoo.com/game...ts/y/xt0_x.cab
O16 - DPF: Yahoo! Blackjack () - http://download.games.yahoo.com/game...ts/y/jt0_x.cab
O16 - DPF: Yahoo! Checkers () - http://download.games.yahoo.com/game...ts/y/kt4_x.cab
O16 - DPF: Yahoo! Chess () - http://download.games.yahoo.com/game...ts/y/ct2_x.cab
O16 - DPF: Yahoo! Cribbage () - http://download.games.yahoo.com/game...ts/y/it1_x.cab
O16 - DPF: Yahoo! Dice () - http://download.games.yahoo.com/game...s/y/dct4_x.cab
O16 - DPF: Yahoo! Go Fish () - http://download.games.yahoo.com/game...ts/y/zt3_x.cab
O16 - DPF: Yahoo! Klondike Solitaire () - http://presence.games.yahoo.com/yog/y/ks12_x.cab
O16 - DPF: Yahoo! Poker () - http://download.games.yahoo.com/game...ts/y/pt3_x.cab
O16 - DPF: Yahoo! Pyramids () - http://download.games.yahoo.com/game...s/y/pyt1_x.cab
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/downlo...367/wmavax.CAB
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} () - http://software-dl.real.com/14939218...p/RdxIE601.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get...nt/swflash.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab
O18 - Protocol: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O20 - Winlogon Notify: geedb - C:\WINDOWS\system32\geedb.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\System32\igfxsrvc.dll
O20 - Winlogon Notify: ssqnllk - C:\WINDOWS\System32\ssqnllk.dll
O23 - Service: avgav.exe (AVG) - Unknown owner - "C:\WINDOWS\avgav.exe"
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - Microsoft Corp., Veritas Software - C:\WINDOWS\System32\dmadmin.exe /com
O23 - Service: Google Updater Service (gusvc) - Google - "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - "C:\WINDOWS\alg.exe"
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\Smc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe"
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - "C:\WINDOWS\wanmpsvc.exe"


-- Files created between 2007-02-24 and 2007-03-24 -----------------------------

2007-03-24 13:38:32 86016 --a------ C:\WINDOWS\System32\setup_44644.exe<SETUP_~2.EXE>
2007-03-24 13:36:47 1997 --a------ C:\jishhs.exe
2007-03-24 13:36:19 26697 --a------ C:\WINDOWS\System32\ssqqono.dll
2007-03-24 13:22:30 26697 --a------ C:\WINDOWS\System32\pmnoonm.dll
2007-03-24 12:39:22 52674 --a------ C:\WINDOWS\System32\setup_56846.exe<SETUP_~1.EXE>
2007-03-24 12:34:45 26697 --a------ C:\WINDOWS\System32\fcccddd.dll
2007-03-24 12:09:27 280676 ---hs---- C:\WINDOWS\System32\mljjj.dll
2007-03-24 12:08:29 1208018 ---hs---- C:\WINDOWS\System32\bdeeg.ini2<BDEEG~1.INI>
2007-03-24 12:03:47 280676 ---hs---- C:\WINDOWS\System32\ssqrq.dll
2007-03-24 12:03:22 11264 --a------ C:\WINDOWS\System32\ocxloader.exe<OCXLOA~1.EXE>
2007-03-24 12:03:22 348160 --a------ C:\WINDOWS\System32\ocxapi.dll
2007-03-24 12:03:22 0 --a------ C:\WINDOWS\System32\ierplc.dll
2007-03-24 12:03:22 80 --a------ C:\WINDOWS\System32\iepref32.dll
2007-03-24 12:03:17 4608 --a------ C:\WINDOWS\System32\ips.dll
2007-03-24 12:03:14 53248 --a------ C:\WINDOWS\System32\icqmlib.exe
2007-03-24 12:01:15 280676 ---hs---- C:\WINDOWS\System32\sstqo.dll
2007-03-24 11:59:00 123972 --a------ C:\WINDOWS\System32\sqvyswsn.dll
2007-03-24 11:58:59 0 d-------- C:\Documents and Settings\Duane\Application Data\SearchToolbarCorp<SEARCH~1>
2007-03-24 11:58:50 132116 --a------ C:\WINDOWS\System32\pqkuaaau.dll
2007-03-24 11:58:46 0 d-------- C:\Program Files\VSAdd-in
2007-03-24 11:58:43 88340 --a------ C:\WINDOWS\System32\dyghasfc.exe
2007-03-24 11:58:42 1206759 ---hs---- C:\WINDOWS\System32\bdeeg.bak1<BDEEG~1.BAK>
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\WINDOWS
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Symantec
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\InterTrust<INTERT~1>
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Adobe
2007-03-24 11:58:21 280676 ---hs---- C:\WINDOWS\System32\geedb.dll
2007-03-24 11:58:21 1048576 --ah----- C:\Documents and Settings\Master Account\NTUSER.DAT
2007-03-24 11:53:13 596 --a------ C:\WINDOWS\System32\qmopt.dll
2007-03-24 11:52:57 26697 --a------ C:\WINDOWS\System32\ssqnllk.dll
2007-03-24 08:46:40 0 d-------- C:\WINDOWS\System32\Kaspersky Lab<KASPER~1>
2007-03-24 08:38:51 86016 -r-hs---- C:\WINDOWS\alg.exe
2007-03-24 08:38:42 71 --a------ C:\WINDOWS\System32\i
2007-03-21 21:17:04 52674 -r-hs---- C:\WINDOWS\avgav.exe
2007-03-20 20:18:18 0 d-------- C:\avenger
2007-03-19 21:14:12 0 d--h----- C:\WINDOWS\PIF
2007-03-13 20:51:18 136 --a------ C:\WINDOWS\System32\dgjun.bat
2007-03-12 18:20:25 491768 --a------ C:\ie6setup.exe
2007-03-11 22:17:35 0 d-------- C:\WINDOWS\System32\ActiveScan<ACTIVE~1>
2007-03-11 09:25:11 0 d-------- C:\Program Files\Java
2007-03-11 09:25:11 0 d-------- C:\Program Files\Common Files\Java
2007-03-11 09:24:21 0 d-------- C:\Documents and Settings\Duane\Application Data\Sun
2007-03-10 11:31:19 0 d-------- C:\Rustbfix
2007-03-08 19:33:08 49152 --a------ C:\Documents and Settings\Duane\vfind.exe
2007-03-08 19:33:08 79360 --a------ C:\Documents and Settings\Duane\swxcacls.exe
2007-03-08 19:33:08 123904 --a------ C:\Documents and Settings\Duane\swsc.exe
2007-03-08 19:33:08 140800 --a------ C:\Documents and Settings\Duane\swreg.exe
2007-03-08 19:33:08 8192 --a------ C:\Documents and Settings\Duane\RestartIt.exe<RESTAR~1.EXE>
2007-03-08 19:33:08 6914 --a------ C:\Documents and Settings\Duane\Qoo.bat
2007-03-08 19:33:08 971 --a------ C:\Documents and Settings\Duane\Purity.bat
2007-03-08 19:33:08 39184 --a------ C:\Documents and Settings\Duane\Ntrights.exe
2007-03-08 19:33:08 5074 --a------ C:\Documents and Settings\Duane\NTPBack.exe
2007-03-08 19:33:08 42887 --a------ C:\Documents and Settings\Duane\ntp.exe
2007-03-08 19:33:08 26112 --a------ C:\Documents and Settings\Duane\nircmd.exe
2007-03-08 19:33:08 38400 --a------ C:\Documents and Settings\Duane\moveex.exe
2007-03-08 19:33:08 2304 --a------ C:\Documents and Settings\Duane\Look2Me.bat
2007-03-08 19:33:08 117379 --a------ C:\Documents and Settings\Duane\LIST-C.bat
2007-03-08 19:33:08 181776 --a------ C:\Documents and Settings\Duane\handle.exe
2007-03-08 19:33:08 73728 --a------ C:\Documents and Settings\Duane\FDSV.EXE
2007-03-08 19:33:08 51200 --a------ C:\Documents and Settings\Duane\dumphive.exe
2007-03-08 19:33:08 319415 --a------ C:\Documents and Settings\Duane\Creg.reg
2007-03-08 19:33:08 28672 --a------ C:\Documents and Settings\Duane\catchme.exe
2007-02-24 21:33:14 53248 --a------ C:\WINDOWS\System32\Process.exe
2007-02-24 21:33:08 0 d-------- C:\SmitfraudFix<SMITFR~1>


-- Find3M Report ---------------------------------------------------------------

2007-03-24 13:41:50 0 d-------- C:\Program Files\Hijack This<HIJACK~1>
2007-03-24 13:36:38 0 d-------- C:\Documents and Settings\Molly\Application Data\WeatherBug<WEATHE~1>
2007-03-21 20:38:09 0 d-------- C:\Program Files\Picasa2
2007-03-21 20:36:13 0 d-------- C:\Program Files\Messenger<MESSEN~1>
2007-03-21 20:31:05 0 d-------- C:\Program Files\iTunes
2007-03-21 20:29:54 0 d-------- C:\Program Files\Google
2007-03-21 20:27:24 0 d-------- C:\Program Files\BigFix
2007-03-08 19:47:09 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1>
2007-02-24 22:08:44 3762 --a------ C:\WINDOWS\System32\tmp.reg
2007-02-21 21:42:31 129 --a------ C:\fix.bat
2007-02-21 18:24:56 0 d-------- C:\Program Files\backups
2007-02-20 21:14:12 0 d-------- C:\Program Files\Shockwave.com<SHOCKW~1.COM>
2007-02-13 21:29:11 0 d-------- C:\Program Files\Common Files\Sandlot Shared<SANDLO~1>
2007-02-10 20:00:13 14201 --a------ C:\Program Files\hijackthis.log<HIJACK~1.LOG>
2007-01-31 19:15:42 0 d-------- C:\Documents and Settings\Molly\Application Data\WinAntiVirus Pro 2006<WINANT~1>
2007-01-31 17:25:32 0 d-------- C:\Documents and Settings\Molly\Application Data\SearchToolbarCorp<SEARCH~1>
2007-01-28 22:13:42 0 d-------- C:\Program Files\LG Software Innovations<LGSOFT~1>
2007-01-28 22:05:20 0 d-------- C:\Program Files\CloneDVD
2007-01-28 21:28:17 14 --a------ C:\WINDOWS\System32\systeminfo3.dll<SYSTEM~1.DLL>
2007-01-21 15:08:15 14612 --a------ C:\Program Files\CWSHREDDER.EXE-2D092FD4.pf<CWSHRE~1.PF>
2007-01-21 15:03:52 532480 --a------ C:\Program Files\cwshredder.exe<CWSHRE~1.EXE>
2007-01-13 14:32:20 0 --a------ C:\WINDOWS\System32\00BDDB65
2007-01-12 18:19:57 0 --a------ C:\WINDOWS\System32\vb2en16.dll
2007-01-12 18:19:50 1235 --a------ C:\WINDOWS\System32\openopenopen<OPENOP~2>
2007-01-12 18:19:34 0 --a------ C:\WINDOWS\System32\99239519
2007-01-11 16:35:52 1 --a------ C:\WINDOWS\System32\kr_done1
2007-01-11 16:35:33 12800 --a------ C:\WINDOWS\System32\svchost.exe
2007-01-11 16:33:19 0 --a------ C:\WINDOWS\System32\3718845C
2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\ps.dat
2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\cookie.dat
2007-01-07 13:16:52 25600 --a------ C:\WINDOWS\System32\helper.dll
2007-01-04 22:35:41 10660 --a------ C:\WINDOWS\mozver.dat
2007-01-03 20:49:11 5037072 --a------ C:\Program Files\spybotsd14.exe<SPYBOT~1.EXE>
2007-01-01 12:02:40 507 --a------ C:\WINDOWS\EReg077.dat
2006-12-25 16:33:11 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi<PLAINO~1.XPI>


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Microsoft Works Update Detection"="c:\\Program Files\\Microsoft Works\\WkDetect.exe"
"Weather"="C:\\PROGRA~1\\AWS\\WEATHE~1\\Weather.exe 1"
"WhenUSave"="\"C:\\Program Files\\Save\\Save.exe\""
"MyWebSearch Email Plugin"="C:\\PROGRA~1\\MYWEBS~2\\bar\\1.bin\\mwsoemon.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"DeluxeCommunications"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe"
"ymmsddlop"="C:\\WINDOWS\\system32\\vssmnptc.exe"
"Windows update loader"="C:\\Windows\\xpupdate.exe"
"WinMedia"="C:\\DOCUME~1\\Molly\\LOCALS~1\\Temp\\257000.exe"
"BraveSentry"="C:\\Program Files\\BraveSentry\\BraveSentry.exe"
"gdxapimn"="C:\\WINDOWS\\System32\\jgdepgc.exe"
"nvcdllx"="C:\\WINDOWS\\System32\\cstatvmq.exe"
"csmhtop"="C:\\WINDOWS\\System32\\sdmmlmn.exe"
"ddsysmns"="C:\\WINDOWS\\System32\\scmdcon.exe"
"ncsmmlg"="C:\\WINDOWS\\System32\\ctlmems.exe"
"kdmmcvs"="C:\\WINDOWS\\System32\\gmonstml.exe"
"fcqlep"="c:\\windows\\system32\\fcqlep.exe fcqlep"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe"
"PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot"
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SoundService"="rundll32.exe \"C:\\WINDOWS\\System32\\sqvyswsn.dll\",setvm"
"icqmlib.exe"="icqmlib.exe"
"ocxloader.exe"="C:\\WINDOWS\\System32\\ocxloader.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{85382E07-2F7E-4910-89AD-16F2E97FC152}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000001
"Wallpaper"="C:\\WINDOWS\\desktop.html"
"DisableRegistryTools"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"=dword:00000000
"ForceActiveDesktopOn"=dword:00000001

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnllk

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0



-- End of Deckard's System Scanner: finished at 2007-03-24 at 13:45:27 ---------

End of Posts

Last edited by cul8rman; 03-24-2007 at 04:38 PM.
cul8rman is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-24-2007, 04:48 PM   #86 (permalink)
Registered User
 
cul8rman's Avatar
 
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP


Re: MS Windows XP will not load when connected to internet

last post was too long - part 2

Robyn

Deckard's System Scanner v20070318.32
Run by Robyn on 2007-03-24 at 14:33:53
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Robyn.exe) -----------------------------------------------

HijackThis failed to provide a log after three minutes; running clone instead.
-- HijackThis Clone ------------------------------------------------------------

Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-03-24 14:36:54
Platform: Windows XP Service Pack 1 (5.01.2600)
MSIE: Internet Explorer (6.0.2800.1106)

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\avgav.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\alg.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\monitor.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Micro Innovations\Keyboard\KBDAP32A.EXE
C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Documents and Settings\Robyn\Desktop\dss.exe
C:\Program Files\Hijack This\Robyn.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0EB01745-660A-479E-883F-68353CB8F306} - C:\WINDOWS\system32\pqkuaaau.dll
O2 - BHO: (no name) - {1846C0B3-8272-4FB3-A455-8F99FC0C0AF8} - C:\WINDOWS\system32\pqkuaaau.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5AA3E953-FCEB-4BB9-898A-BB688352DD01} - C:\WINDOWS\system32\geedb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {85382E07-2F7E-4910-89AD-16F2E97FC152} - C:\WINDOWS\system32\ssqnllk.dll
O2 - BHO: (no name) - {9273199F-9FC8-495F-B7FF-F15568877CFa} - C:\WINDOWS\system32\pqkuaaau.dll
O2 - BHO: (no name) - {95F1789F-CDC6-401B-8A19-DBA1532F86Bb} - C:\WINDOWS\system32\pqkuaaau.dll
O2 - BHO: (no name) - {A42B8C8C-4323-4B95-8E98-1A302D7F6959} - C:\WINDOWS\system32\pqkuaaau.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar3.dll
O2 - BHO: (no name) - {C3B48746-C8C5-42DB-B803-F164DDEC1E55} - C:\WINDOWS\system32\pqkuaaau.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar3.dll
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [lsmdwinr] C:\WINDOWS\System32\vstldmem.exe
O4 - HKCU\..\Run: [winksddm] C:\WINDOWS\System32\jvmmods.exe
O4 - HKCU\..\Run: [gdxapimn] C:\WINDOWS\System32\jgdepgc.exe
O4 - HKCU\..\Run: [nvcdllx] C:\WINDOWS\System32\cstatvmq.exe
O4 - HKCU\..\Run: [csmhtop] C:\WINDOWS\System32\sdmmlmn.exe
O4 - HKCU\..\Run: [ncsmmlg] C:\WINDOWS\System32\ctlmems.exe
O4 - HKCU\..\Run: [ddsysmns] C:\WINDOWS\System32\scmdcon.exe
O4 - HKCU\..\Run: [kdmmcvs] C:\WINDOWS\System32\gmonstml.exe
O4 - Startup: .protected
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinpoeb.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\Icq.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)
O9 - Extra 'Tools' menuitem: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra 'Tools' menuitem: (no name) - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Video Poker () - http://download.games.yahoo.com/game...s/y/vpt0_x.cab
O16 - DPF: Yahoo! Backgammon () - http://download.games.yahoo.com/game...ts/y/at1_x.cab
O16 - DPF: Yahoo! Bingo () - http://download.games.yahoo.com/game...ts/y/xt0_x.cab
O16 - DPF: Yahoo! Blackjack () - http://download.games.yahoo.com/game...ts/y/jt0_x.cab
O16 - DPF: Yahoo! Checkers () - http://download.games.yahoo.com/game...ts/y/kt4_x.cab
O16 - DPF: Yahoo! Chess () - http://download.games.yahoo.com/game...ts/y/ct2_x.cab
O16 - DPF: Yahoo! Cribbage () - http://download.games.yahoo.com/game...ts/y/it1_x.cab
O16 - DPF: Yahoo! Dice () - http://download.games.yahoo.com/game...s/y/dct4_x.cab
O16 - DPF: Yahoo! Go Fish () - http://download.games.yahoo.com/game...ts/y/zt3_x.cab
O16 - DPF: Yahoo! Klondike Solitaire () - http://presence.games.yahoo.com/yog/y/ks12_x.cab
O16 - DPF: Yahoo! Poker () - http://download.games.yahoo.com/game...ts/y/pt3_x.cab
O16 - DPF: Yahoo! Pyramids () - http://download.games.yahoo.com/game...s/y/pyt1_x.cab
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/downlo...367/wmavax.CAB
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} () - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} () - http://software-dl.real.com/14939218...p/RdxIE601.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get...nt/swflash.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab
O18 - Protocol: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O20 - Winlogon Notify: geedb - C:\WINDOWS\system32\geedb.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\System32\igfxsrvc.dll
O20 - Winlogon Notify: ssqnllk - C:\WINDOWS\System32\ssqnllk.dll
O23 - Service: avgav.exe (AVG) - Unknown owner - "C:\WINDOWS\avgav.exe"
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - Microsoft Corp., Veritas Software - C:\WINDOWS\System32\dmadmin.exe /com
O23 - Service: Google Updater Service (gusvc) - Google - "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe"
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - "C:\WINDOWS\alg.exe"
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\Smc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - "C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe"
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - "C:\WINDOWS\wanmpsvc.exe"


-- Files created between 2007-02-24 and 2007-03-24 -----------------------------

2007-03-24 14:15:41 72192 --a------ C:\snm.exe
2007-03-24 14:15:34 26697 --a------ C:\WINDOWS\System32\urqoljk.dll
2007-03-24 13:38:32 86016 --a------ C:\WINDOWS\System32\setup_44644.exe<SETUP_~2.EXE>
2007-03-24 13:36:19 26697 --a------ C:\WINDOWS\System32\ssqqono.dll
2007-03-24 13:22:30 26697 --a------ C:\WINDOWS\System32\pmnoonm.dll
2007-03-24 12:39:22 52674 --a------ C:\WINDOWS\System32\setup_56846.exe<SETUP_~1.EXE>
2007-03-24 12:34:45 26697 --a------ C:\WINDOWS\System32\fcccddd.dll
2007-03-24 12:09:27 280676 ---hs---- C:\WINDOWS\System32\mljjj.dll
2007-03-24 12:08:29 1208018 ---hs---- C:\WINDOWS\System32\bdeeg.ini2<BDEEG~1.INI>
2007-03-24 12:03:47 280676 ---hs---- C:\WINDOWS\System32\ssqrq.dll
2007-03-24 12:03:22 11264 --a------ C:\WINDOWS\System32\ocxloader.exe<OCXLOA~1.EXE>
2007-03-24 12:03:22 348160 --a------ C:\WINDOWS\System32\ocxapi.dll
2007-03-24 12:03:22 0 --a------ C:\WINDOWS\System32\ierplc.dll
2007-03-24 12:03:22 80 --a------ C:\WINDOWS\System32\iepref32.dll
2007-03-24 12:03:17 4608 --a------ C:\WINDOWS\System32\ips.dll
2007-03-24 12:03:14 53248 --a------ C:\WINDOWS\System32\icqmlib.exe
2007-03-24 12:01:15 280676 ---hs---- C:\WINDOWS\System32\sstqo.dll
2007-03-24 11:59:00 123972 --a------ C:\WINDOWS\System32\sqvyswsn.dll
2007-03-24 11:58:59 0 d-------- C:\Documents and Settings\Duane\Application Data\SearchToolbarCorp<SEARCH~1>
2007-03-24 11:58:50 132116 --a------ C:\WINDOWS\System32\pqkuaaau.dll
2007-03-24 11:58:46 0 d-------- C:\Program Files\VSAdd-in
2007-03-24 11:58:43 88340 --a------ C:\WINDOWS\System32\dyghasfc.exe
2007-03-24 11:58:42 1206759 ---hs---- C:\WINDOWS\System32\bdeeg.bak1<BDEEG~1.BAK>
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\WINDOWS
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Symantec
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\InterTrust<INTERT~1>
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Adobe
2007-03-24 11:58:21 280676 ---hs---- C:\WINDOWS\System32\geedb.dll
2007-03-24 11:58:21 1048576 --ah----- C:\Documents and Settings\Master Account\NTUSER.DAT
2007-03-24 11:53:13 596 --a------ C:\WINDOWS\System32\qmopt.dll
2007-03-24 11:52:57 26697 --a------ C:\WINDOWS\System32\ssqnllk.dll
2007-03-24 08:46:40 0 d-------- C:\WINDOWS\System32\Kaspersky Lab<KASPER~1>
2007-03-24 08:38:51 86016 -r-hs---- C:\WINDOWS\alg.exe
2007-03-24 08:38:42 71 --a------ C:\WINDOWS\System32\i
2007-03-21 21:17:04 52674 -r-hs---- C:\WINDOWS\avgav.exe
2007-03-20 20:18:18 0 d-------- C:\avenger
2007-03-19 21:14:12 0 d--h----- C:\WINDOWS\PIF
2007-03-13 20:51:18 136 --a------ C:\WINDOWS\System32\dgjun.bat
2007-03-12 18:20:25 491768 --a------ C:\ie6setup.exe
2007-03-11 22:17:35 0 d-------- C:\WINDOWS\System32\ActiveScan<ACTIVE~1>
2007-03-11 09:25:11 0 d-------- C:\Program Files\Java
2007-03-11 09:25:11 0 d-------- C:\Program Files\Common Files\Java
2007-03-11 09:24:21 0 d-------- C:\Documents and Settings\Duane\Application Data\Sun
2007-03-10 11:31:19 0 d-------- C:\Rustbfix
2007-03-08 19:33:08 49152 --a------ C:\Documents and Settings\Duane\vfind.exe
2007-03-08 19:33:08 79360 --a------ C:\Documents and Settings\Duane\swxcacls.exe
2007-03-08 19:33:08 123904 --a------ C:\Documents and Settings\Duane\swsc.exe
2007-03-08 19:33:08 140800 --a------ C:\Documents and Settings\Duane\swreg.exe
2007-03-08 19:33:08 8192 --a------ C:\Documents and Settings\Duane\RestartIt.exe<RESTAR~1.EXE>
2007-03-08 19:33:08 6914 --a------ C:\Documents and Settings\Duane\Qoo.bat
2007-03-08 19:33:08 971 --a------ C:\Documents and Settings\Duane\Purity.bat
2007-03-08 19:33:08 39184 --a------ C:\Documents and Settings\Duane\Ntrights.exe
2007-03-08 19:33:08 5074 --a------ C:\Documents and Settings\Duane\NTPBack.exe
2007-03-08 19:33:08 42887 --a------ C:\Documents and Settings\Duane\ntp.exe
2007-03-08 19:33:08 26112 --a------ C:\Documents and Settings\Duane\nircmd.exe
2007-03-08 19:33:08 38400 --a------ C:\Documents and Settings\Duane\moveex.exe
2007-03-08 19:33:08 2304 --a------ C:\Documents and Settings\Duane\Look2Me.bat
2007-03-08 19:33:08 117379 --a------ C:\Documents and Settings\Duane\LIST-C.bat
2007-03-08 19:33:08 181776 --a------ C:\Documents and Settings\Duane\handle.exe
2007-03-08 19:33:08 73728 --a------ C:\Documents and Settings\Duane\FDSV.EXE
2007-03-08 19:33:08 51200 --a------ C:\Documents and Settings\Duane\dumphive.exe
2007-03-08 19:33:08 319415 --a------ C:\Documents and Settings\Duane\Creg.reg
2007-03-08 19:33:08 28672 --a------ C:\Documents and Settings\Duane\catchme.exe
2007-02-24 21:33:14 53248 --a------ C:\WINDOWS\System32\Process.exe
2007-02-24 21:33:08 0 d-------- C:\SmitfraudFix<SMITFR~1>


-- Find3M Report ---------------------------------------------------------------

2007-03-24 14:33:54 0 d-------- C:\Program Files\Hijack This<HIJACK~1>
2007-03-21 20:38:09 0 d-------- C:\Program Files\Picasa2
2007-03-21 20:36:13 0 d-------- C:\Program Files\Messenger<MESSEN~1>
2007-03-21 20:31:05 0 d-------- C:\Program Files\iTunes
2007-03-21 20:29:54 0 d-------- C:\Program Files\Google
2007-03-21 20:27:24 0 d-------- C:\Program Files\BigFix
2007-03-08 19:47:09 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1>
2007-02-24 22:08:44 3762 --a------ C:\WINDOWS\System32\tmp.reg
2007-02-21 21:42:31 129 --a------ C:\fix.bat
2007-02-21 18:24:56 0 d-------- C:\Program Files\backups
2007-02-20 21:14:12 0 d-------- C:\Program Files\Shockwave.com<SHOCKW~1.COM>
2007-02-13 21:29:11 0 d-------- C:\Program Files\Common Files\Sandlot Shared<SANDLO~1>
2007-02-10 20:00:13 14201 --a------ C:\Program Files\hijackthis.log<HIJACK~1.LOG>
2007-01-28 22:13:42 0 d-------- C:\Program Files\LG Software Innovations<LGSOFT~1>
2007-01-28 22:05:20 0 d-------- C:\Program Files\CloneDVD
2007-01-28 21:28:17 14 --a------ C:\WINDOWS\System32\systeminfo3.dll<SYSTEM~1.DLL>
2007-01-26 17:12:29 0 d-------- C:\Documents and Settings\Robyn\Application Data\SearchToolbarCorp<SEARCH~1>
2007-01-26 17:07:02 0 d-------- C:\Documents and Settings\Robyn\Application Data\Ultimate Cleaner<ULTIMA~2>
2007-01-21 15:08:15 14612 --a------ C:\Program Files\CWSHREDDER.EXE-2D092FD4.pf<CWSHRE~1.PF>
2007-01-21 15:03:52 532480 --a------ C:\Program Files\cwshredder.exe<CWSHRE~1.EXE>
2007-01-13 14:32:20 0 --a------ C:\WINDOWS\System32\00BDDB65
2007-01-12 18:19:57 0 --a------ C:\WINDOWS\System32\vb2en16.dll
2007-01-12 18:19:50 1235 --a------ C:\WINDOWS\System32\openopenopen<OPENOP~2>
2007-01-12 18:19:34 0 --a------ C:\WINDOWS\System32\99239519
2007-01-11 16:35:52 1 --a------ C:\WINDOWS\System32\kr_done1
2007-01-11 16:35:33 12800 --a------ C:\WINDOWS\System32\svchost.exe
2007-01-11 16:33:19 0 --a------ C:\WINDOWS\System32\3718845C
2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\ps.dat
2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\cookie.dat
2007-01-07 13:16:52 25600 --a------ C:\WINDOWS\System32\helper.dll
2007-01-04 22:35:41 10660 --a------ C:\WINDOWS\mozver.dat
2007-01-03 20:49:11 5037072 --a------ C:\Program Files\spybotsd14.exe<SPYBOT~1.EXE>
2007-01-01 12:02:40 507 --a------ C:\WINDOWS\EReg077.dat
2006-12-25 16:33:11 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi<PLAINO~1.XPI>


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"DeluxeCommunications"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe"
"lsmdwinr"="C:\\WINDOWS\\System32\\vstldmem.exe"
"winksddm"="C:\\WINDOWS\\System32\\jvmmods.exe"
"gdxapimn"="C:\\WINDOWS\\System32\\jgdepgc.exe"
"nvcdllx"="C:\\WINDOWS\\System32\\cstatvmq.exe"
"csmhtop"="C:\\WINDOWS\\System32\\sdmmlmn.exe"
"ncsmmlg"="C:\\WINDOWS\\System32\\ctlmems.exe"
"ddsysmns"="C:\\WINDOWS\\System32\\scmdcon.exe"
"kdmmcvs"="C:\\WINDOWS\\System32\\gmonstml.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe"
"PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot"
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SoundService"="rundll32.exe \"C:\\WINDOWS\\System32\\sqvyswsn.dll\",setvm"
"icqmlib.exe"="icqmlib.exe"
"ocxloader.exe"="C:\\WINDOWS\\System32\\ocxloader.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{85382E07-2F7E-4910-89AD-16F2E97FC152}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnllk

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_LANMANDRV


-- End of Deckard's System Scanner: finished at 2007-03-24 at 14:37:23 ---------

************** Master Account

Deckard's System Scanner v20070318.32
Run by Master Account on 2007-03-24 at 12:36:18
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Master Account.exe) --------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 12:36:25 PM, on 3/24/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\avgav.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\System32\icqmlib.exe
C:\WINDOWS\System32\ocxloader.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Master Account\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\MASTER~1.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.emachines.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1846C0B3-8272-4FB3-A455-8F99FC0C0AF8} - C:\WINDOWS\System32\pqkuaaau.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {2D295940-2ADE-4BD2-82DC-A7390260E459} - C:\WINDOWS\System32\geedb.dll
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {85382E07-2F7E-4910-89AD-16F2E97FC152} - C:\WINDOWS\System32\ssqnllk.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {C3B48746-C8C5-42DB-B803-F164DDEC1E55} - C:\WINDOWS\System32\pqkuaaau.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Video Poker - http://download.games.yahoo.com/game...s/y/vpt0_x.cab
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/game...ts/y/at1_x.cab
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/game...ts/y/xt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/game...ts/y/jt0_x.cab
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/game...ts/y/kt4_x.cab
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/game...ts/y/ct2_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game...ts/y/it1_x.cab
O16 - DPF: Yahoo! Dice - http://download.games.yahoo.com/game...s/y/dct4_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/game...ts/y/zt3_x.cab
O16 - DPF: Yahoo! Klondike Solitaire - http://presence.games.yahoo.com/yog/y/ks12_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/game...s/y/pyt1_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/14939218...p/RdxIE601.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab
O20 - Winlogon Notify: geedb - C:\WINDOWS\System32\geedb.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ssqnllk - C:\WINDOWS\SYSTEM32\ssqnllk.dll
O23 - Service: avgav.exe (AVG) - Unknown owner - C:\WINDOWS\avgav.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - C:\WINDOWS\alg.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


-- Files created between 2007-02-24 and 2007-03-24 -----------------------------

2007-03-24 12:35:09 1997 --a------ C:\jishhs.exe
2007-03-24 12:34:45 26697 --a------ C:\WINDOWS\System32\fcccddd.dll
2007-03-24 12:09:27 280676 ---hs---- C:\WINDOWS\System32\mljjj.dll
2007-03-24 12:08:29 1208018 ---hs---- C:\WINDOWS\System32\bdeeg.ini2<BDEEG~1.INI>
2007-03-24 12:03:47 280676 ---hs---- C:\WINDOWS\System32\ssqrq.dll
2007-03-24 12:03:22 11264 --a------ C:\WINDOWS\System32\ocxloader.exe<OCXLOA~1.EXE>
2007-03-24 12:03:22 348160 --a------ C:\WINDOWS\System32\ocxapi.dll
2007-03-24 12:03:22 0 --a------ C:\WINDOWS\System32\ierplc.dll
2007-03-24 12:03:22 80 --a------ C:\WINDOWS\System32\iepref32.dll
2007-03-24 12:03:17 4608 --a------ C:\WINDOWS\System32\ips.dll
2007-03-24 12:03:14 53248 --a------ C:\WINDOWS\System32\icqmlib.exe
2007-03-24 12:01:15 280676 ---hs---- C:\WINDOWS\System32\sstqo.dll
2007-03-24 11:59:00 123972 --a------ C:\WINDOWS\System32\sqvyswsn.dll
2007-03-24 11:58:59 0 d-------- C:\Documents and Settings\Duane\Application Data\SearchToolbarCorp<SEARCH~1>
2007-03-24 11:58:50 132116 --a------ C:\WINDOWS\System32\pqkuaaau.dll
2007-03-24 11:58:46 0 d-------- C:\Program Files\VSAdd-in
2007-03-24 11:58:43 88340 --a------ C:\WINDOWS\System32\dyghasfc.exe
2007-03-24 11:58:42 1206759 ---hs---- C:\WINDOWS\System32\bdeeg.bak1<BDEEG~1.BAK>
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\WINDOWS
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Symantec
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\InterTrust<INTERT~1>
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Adobe
2007-03-24 11:58:21 280676 ---hs---- C:\WINDOWS\System32\geedb.dll
2007-03-24 11:58:21 1048576 --ah----- C:\Documents and Settings\Master Account\NTUSER.DAT
2007-03-24 11:53:13 596 --a------ C:\WINDOWS\System32\qmopt.dll
2007-03-24 11:52:57 26697 --a------ C:\WINDOWS\System32\ssqnllk.dll
2007-03-24 08:46:40 0 d-------- C:\WINDOWS\System32\Kaspersky Lab<KASPER~1>
2007-03-24 08:38:51 86016 -r-hs---- C:\WINDOWS\alg.exe
2007-03-24 08:38:42 68 --a------ C:\WINDOWS\System32\i
2007-03-21 21:17:04 52674 -r-hs---- C:\WINDOWS\avgav.exe
2007-03-20 20:18:18 0 d-------- C:\avenger
2007-03-19 21:14:12 0 d--h----- C:\WINDOWS\PIF
2007-03-13 20:51:18 136 --a------ C:\WINDOWS\System32\dgjun.bat
2007-03-12 18:20:25 491768 --a------ C:\ie6setup.exe
2007-03-11 22:17:35 0 d-------- C:\WINDOWS\System32\ActiveScan<ACTIVE~1>
2007-03-11 09:25:11 0 d-------- C:\Program Files\Java
2007-03-11 09:25:11 0 d-------- C:\Program Files\Common Files\Java
2007-03-11 09:24:21 0 d-------- C:\Documents and Settings\Duane\Application Data\Sun
2007-03-10 11:31:19 0 d-------- C:\Rustbfix
2007-03-08 19:33:08 49152 --a------ C:\Documents and Settings\Duane\vfind.exe
2007-03-08 19:33:08 79360 --a------ C:\Documents and Settings\Duane\swxcacls.exe
2007-03-08 19:33:08 123904 --a------ C:\Documents and Settings\Duane\swsc.exe
2007-03-08 19:33:08 140800 --a------ C:\Documents and Settings\Duane\swreg.exe
2007-03-08 19:33:08 8192 --a------ C:\Documents and Settings\Duane\RestartIt.exe<RESTAR~1.EXE>
2007-03-08 19:33:08 6914 --a------ C:\Documents and Settings\Duane\Qoo.bat
2007-03-08 19:33:08 971 --a------ C:\Documents and Settings\Duane\Purity.bat
2007-03-08 19:33:08 39184 --a------ C:\Documents and Settings\Duane\Ntrights.exe
2007-03-08 19:33:08 5074 --a------ C:\Documents and Settings\Duane\NTPBack.exe
2007-03-08 19:33:08 42887 --a------ C:\Documents and Settings\Duane\ntp.exe
2007-03-08 19:33:08 26112 --a------ C:\Documents and Settings\Duane\nircmd.exe
2007-03-08 19:33:08 38400 --a------ C:\Documents and Settings\Duane\moveex.exe
2007-03-08 19:33:08 2304 --a------ C:\Documents and Settings\Duane\Look2Me.bat
2007-03-08 19:33:08 117379 --a------ C:\Documents and Settings\Duane\LIST-C.bat
2007-03-08 19:33:08 181776 --a------ C:\Documents and Settings\Duane\handle.exe
2007-03-08 19:33:08 73728 --a------ C:\Documents and Settings\Duane\FDSV.EXE
2007-03-08 19:33:08 51200 --a------ C:\Documents and Settings\Duane\dumphive.exe
2007-03-08 19:33:08 319415 --a------ C:\Documents and Settings\Duane\Creg.reg
2007-03-08 19:33:08 28672 --a------ C:\Documents and Settings\Duane\catchme.exe
2007-02-24 21:33:14 53248 --a------ C:\WINDOWS\System32\Process.exe
2007-02-24 21:33:08 0 d-------- C:\SmitfraudFix<SMITFR~1>


-- Find3M Report ---------------------------------------------------------------

2007-03-24 12:36:19 0 d-------- C:\Program Files\Hijack This<HIJACK~1>
2007-03-24 11:59:31 0 d-------- C:\Documents and Settings\Master Account\Application Data\Mozilla
2007-03-24 11:59:17 0 d-------- C:\Documents and Settings\Master Account\Application Data\AVG7
2007-03-21 20:38:09 0 d-------- C:\Program Files\Picasa2
2007-03-21 20:36:13 0 d-------- C:\Program Files\Messenger<MESSEN~1>
2007-03-21 20:31:05 0 d-------- C:\Program Files\iTunes
2007-03-21 20:29:54 0 d-------- C:\Program Files\Google
2007-03-21 20:27:24 0 d-------- C:\Program Files\BigFix
2007-03-08 19:47:09 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1>
2007-02-24 22:08:44 3762 --a------ C:\WINDOWS\System32\tmp.reg
2007-02-21 21:42:31 129 --a------ C:\fix.bat
2007-02-21 18:24:56 0 d-------- C:\Program Files\backups
2007-02-20 21:14:12 0 d-------- C:\Program Files\Shockwave.com<SHOCKW~1.COM>
2007-02-13 21:29:11 0 d-------- C:\Program Files\Common Files\Sandlot Shared<SANDLO~1>
2007-02-10 20:00:13 14201 --a------ C:\Program Files\hijackthis.log<HIJACK~1.LOG>
2007-01-28 22:13:42 0 d-------- C:\Program Files\LG Software Innovations<LGSOFT~1>
2007-01-28 22:05:20 0 d-------- C:\Program Files\CloneDVD
2007-01-28 21:28:17 14 --a------ C:\WINDOWS\System32\systeminfo3.dll<SYSTEM~1.DLL>
2007-01-21 15:08:15 14612 --a------ C:\Program Files\CWSHREDDER.EXE-2D092FD4.pf<CWSHRE~1.PF>
2007-01-21 15:03:52 532480 --a------ C:\Program Files\cwshredder.exe<CWSHRE~1.EXE>
2007-01-13 14:32:20 0 --a------ C:\WINDOWS\System32\00BDDB65
2007-01-12 18:19:57 0 --a------ C:\WINDOWS\System32\vb2en16.dll
2007-01-12 18:19:50 1235 --a------ C:\WINDOWS\System32\openopenopen<OPENOP~2>
2007-01-12 18:19:34 0 --a------ C:\WINDOWS\System32\99239519
2007-01-11 16:35:52 1 --a------ C:\WINDOWS\System32\kr_done1
2007-01-11 16:35:33 12800 --a------ C:\WINDOWS\System32\svchost.exe
2007-01-11 16:33:19 0 --a------ C:\WINDOWS\System32\3718845C
2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\ps.dat
2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\cookie.dat
2007-01-07 13:16:52 25600 --a------ C:\WINDOWS\System32\helper.dll
2007-01-04 22:35:41 10660 --a------ C:\WINDOWS\mozver.dat
2007-01-03 20:49:11 5037072 --a------ C:\Program Files\spybotsd14.exe<SPYBOT~1.EXE>
2007-01-01 12:02:40 507 --a------ C:\WINDOWS\EReg077.dat
2006-12-25 16:33:11 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi<PLAINO~1.XPI>


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe"
"PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot"
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SoundService"="rundll32.exe \"C:\\WINDOWS\\System32\\sqvyswsn.dll\",setvm"
"icqmlib.exe"="icqmlib.exe"
"ocxloader.exe"="C:\\WINDOWS\\System32\\ocxloader.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{85382E07-2F7E-4910-89AD-16F2E97FC152}"=""

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnllk

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0



-- End of Deckard's System Scanner: finished at 2007-03-24 at 12:36:57 ---------

******* Others

Deckard's System Scanner v20070318.32
Run by Others on 2007-03-24 at 14:21:43
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Others.exe) ----------------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 2:21:50 PM, on 3/24/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\avgav.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
C:\PROGRA~1\Sygate\SPF\smc.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\System32\icqmlib.exe
C:\WINDOWS\System32\ocxloader.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Others\Desktop\dss.exe
C:\PROGRA~1\HIJACK~1\Others.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0EB01745-660A-479E-883F-68353CB8F306} - C:\WINDOWS\System32\pqkuaaau.dll
O2 - BHO: (no name) - {1846C0B3-8272-4FB3-A455-8F99FC0C0AF8} - C:\WINDOWS\System32\pqkuaaau.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5AA3E953-FCEB-4BB9-898A-BB688352DD01} - C:\WINDOWS\System32\geedb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {85382E07-2F7E-4910-89AD-16F2E97FC152} - C:\WINDOWS\System32\ssqnllk.dll
O2 - BHO: (no name) - {9273199F-9FC8-495F-B7FF-F15568877CFa} - C:\WINDOWS\System32\pqkuaaau.dll
O2 - BHO: (no name) - {95F1789F-CDC6-401B-8A19-DBA1532F86Bb} - C:\WINDOWS\System32\pqkuaaau.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {C3B48746-C8C5-42DB-B803-F164DDEC1E55} - C:\WINDOWS\System32\pqkuaaau.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Startup: .protected
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinpoeb.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Video Poker - http://download.games.yahoo.com/game...s/y/vpt0_x.cab
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/game...ts/y/at1_x.cab
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/game...ts/y/xt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/game...ts/y/jt0_x.cab
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/game...ts/y/kt4_x.cab
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/game...ts/y/ct2_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game...ts/y/it1_x.cab
O16 - DPF: Yahoo! Dice - http://download.games.yahoo.com/game...s/y/dct4_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/game...ts/y/zt3_x.cab
O16 - DPF: Yahoo! Klondike Solitaire - http://presence.games.yahoo.com/yog/y/ks12_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/game...s/y/pyt1_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/14939218...p/RdxIE601.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab
O20 - Winlogon Notify: geedb - C:\WINDOWS\System32\geedb.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ssqnllk - C:\WINDOWS\SYSTEM32\ssqnllk.dll
O23 - Service: avgav.exe (AVG) - Unknown owner - C:\WINDOWS\avgav.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - C:\WINDOWS\alg.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


-- Files created between 2007-02-24 and 2007-03-24 -----------------------------

2007-03-24 14:15:41 72192 --a------ C:\snm.exe
2007-03-24 14:15:34 26697 --a------ C:\WINDOWS\System32\urqoljk.dll
2007-03-24 13:38:32 86016 --a------ C:\WINDOWS\System32\setup_44644.exe<SETUP_~2.EXE>
2007-03-24 13:36:19 26697 --a------ C:\WINDOWS\System32\ssqqono.dll
2007-03-24 13:22:30 26697 --a------ C:\WINDOWS\System32\pmnoonm.dll
2007-03-24 12:39:22 52674 --a------ C:\WINDOWS\System32\setup_56846.exe<SETUP_~1.EXE>
2007-03-24 12:34:45 26697 --a------ C:\WINDOWS\System32\fcccddd.dll
2007-03-24 12:09:27 280676 ---hs---- C:\WINDOWS\System32\mljjj.dll
2007-03-24 12:08:29 1208018 ---hs---- C:\WINDOWS\System32\bdeeg.ini2<BDEEG~1.INI>
2007-03-24 12:03:47 280676 ---hs---- C:\WINDOWS\System32\ssqrq.dll
2007-03-24 12:03:22 11264 --a------ C:\WINDOWS\System32\ocxloader.exe<OCXLOA~1.EXE>
2007-03-24 12:03:22 348160 --a------ C:\WINDOWS\System32\ocxapi.dll
2007-03-24 12:03:22 0 --a------ C:\WINDOWS\System32\ierplc.dll
2007-03-24 12:03:22 80 --a------ C:\WINDOWS\System32\iepref32.dll
2007-03-24 12:03:17 4608 --a------ C:\WINDOWS\System32\ips.dll
2007-03-24 12:03:14 53248 --a------ C:\WINDOWS\System32\icqmlib.exe
2007-03-24 12:01:15 280676 ---hs---- C:\WINDOWS\System32\sstqo.dll
2007-03-24 11:59:00 123972 --a------ C:\WINDOWS\System32\sqvyswsn.dll
2007-03-24 11:58:59 0 d-------- C:\Documents and Settings\Duane\Application Data\SearchToolbarCorp<SEARCH~1>
2007-03-24 11:58:50 132116 --a------ C:\WINDOWS\System32\pqkuaaau.dll
2007-03-24 11:58:46 0 d-------- C:\Program Files\VSAdd-in
2007-03-24 11:58:43 88340 --a------ C:\WINDOWS\System32\dyghasfc.exe
2007-03-24 11:58:42 1206759 ---hs---- C:\WINDOWS\System32\bdeeg.bak1<BDEEG~1.BAK>
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\WINDOWS
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Symantec
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\InterTrust<INTERT~1>
2007-03-24 11:58:22 0 d-------- C:\Documents and Settings\Master Account\Application Data\Adobe
2007-03-24 11:58:21 280676 ---hs---- C:\WINDOWS\System32\geedb.dll
2007-03-24 11:58:21 1048576 --ah----- C:\Documents and Settings\Master Account\NTUSER.DAT
2007-03-24 11:53:13 596 --a------ C:\WINDOWS\System32\qmopt.dll
2007-03-24 11:52:57 26697 --a------ C:\WINDOWS\System32\ssqnllk.dll
2007-03-24 08:46:40 0 d-------- C:\WINDOWS\System32\Kaspersky Lab<KASPER~1>
2007-03-24 08:38:51 86016 -r-hs---- C:\WINDOWS\alg.exe
2007-03-24 08:38:42 71 --a------ C:\WINDOWS\System32\i
2007-03-21 21:17:04 52674 -r-hs---- C:\WINDOWS\avgav.exe
2007-03-20 20:18:18 0 d-------- C:\avenger
2007-03-19 21:14:12 0 d--h----- C:\WINDOWS\PIF
2007-03-13 20:51:18 136 --a------ C:\WINDOWS\System32\dgjun.bat
2007-03-12 18:20:25 491768 --a------ C:\ie6setup.exe
2007-03-11 22:17:35 0 d-------- C:\WINDOWS\System32\ActiveScan<ACTIVE~1>
2007-03-11 09:25:11 0 d-------- C:\Program Files\Java
2007-03-11 09:25:11 0 d-------- C:\Program Files\Common Files\Java
2007-03-11 09:24:21 0 d-------- C:\Documents and Settings\Duane\Application Data\Sun
2007-03-10 11:31:19 0 d-------- C:\Rustbfix
2007-03-08 19:33:08 49152 --a------ C:\Documents and Settings\Duane\vfind.exe
2007-03-08 19:33:08 79360 --a------ C:\Documents and Settings\Duane\swxcacls.exe
2007-03-08 19:33:08 123904 --a------ C:\Documents and Settings\Duane\swsc.exe
2007-03-08 19:33:08 140800 --a------ C:\Documents and Settings\Duane\swreg.exe
2007-03-08 19:33:08 8192 --a------ C:\Documents and Settings\Duane\RestartIt.exe<RESTAR~1.EXE>
2007-03-08 19:33:08 6914 --a------ C:\Documents and Settings\Duane\Qoo.bat
2007-03-08 19:33:08 971 --a------ C:\Documents and Settings\Duane\Purity.bat
2007-03-08 19:33:08 39184 --a------ C:\Documents and Settings\Duane\Ntrights.exe
2007-03-08 19:33:08 5074 --a------ C:\Documents and Settings\Duane\NTPBack.exe
2007-03-08 19:33:08 42887 --a------ C:\Documents and Settings\Duane\ntp.exe
2007-03-08 19:33:08 26112 --a------ C:\Documents and Settings\Duane\nircmd.exe
2007-03-08 19:33:08 38400 --a------ C:\Documents and Settings\Duane\moveex.exe
2007-03-08 19:33:08 2304 --a------ C:\Documents and Settings\Duane\Look2Me.bat
2007-03-08 19:33:08 117379 --a------ C:\Documents and Settings\Duane\LIST-C.bat
2007-03-08 19:33:08 181776 --a------ C:\Documents and Settings\Duane\handle.exe
2007-03-08 19:33:08 73728 --a------ C:\Documents and Settings\Duane\FDSV.EXE
2007-03-08 19:33:08 51200 --a------ C:\Documents and Settings\Duane\dumphive.exe
2007-03-08 19:33:08 319415 --a------ C:\Documents and Settings\Duane\Creg.reg
2007-03-08 19:33:08 28672 --a------ C:\Documents and Settings\Duane\catchme.exe
2007-02-24 21:33:14 53248 --a------ C:\WINDOWS\System32\Process.exe
2007-02-24 21:33:08 0 d-------- C:\SmitfraudFix<SMITFR~1>


-- Find3M Report ---------------------------------------------------------------

2007-03-24 14:21:44 0 d-------- C:\Program Files\Hijack This<HIJACK~1>
2007-03-21 20:38:09 0 d-------- C:\Program Files\Picasa2
2007-03-21 20:36:13 0 d-------- C:\Program Files\Messenger<MESSEN~1>
2007-03-21 20:31:05 0 d-------- C:\Program Files\iTunes
2007-03-21 20:29:54 0 d-------- C:\Program Files\Google
2007-03-21 20:27:24 0 d-------- C:\Program Files\BigFix
2007-03-08 19:47:09 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1>
2007-02-24 22:08:44 3762 --a------ C:\WINDOWS\System32\tmp.reg
2007-02-21 21:42:31 129 --a------ C:\fix.bat
2007-02-21 18:24:56 0 d-------- C:\Program Files\backups
2007-02-20 21:14:12 0 d-------- C:\Program Files\Shockwave.com<SHOCKW~1.COM>
2007-02-13 21:29:11 0 d-------- C:\Program Files\Common Files\Sandlot Shared<SANDLO~1>
2007-02-10 20:00:13 14201 --a------ C:\Program Files\hijackthis.log<HIJACK~1.LOG>
2007-01-28 22:13:42 0 d-------- C:\Program Files\LG Software Innovations<LGSOFT~1>
2007-01-28 22:05:20 0 d-------- C:\Program Files\CloneDVD
2007-01-28 21:28:17 14 --a------ C:\WINDOWS\System32\systeminfo3.dll<SYSTEM~1.DLL>
2007-01-21 15:08:15 14612 --a------ C:\Program Files\CWSHREDDER.EXE-2D092FD4.pf<CWSHRE~1.PF>
2007-01-21 15:03:52 532480 --a------ C:\Program Files\cwshredder.exe<CWSHRE~1.EXE>
2007-01-13 14:32:20 0 --a------ C:\WINDOWS\System32\00BDDB65
2007-01-12 18:19:57 0 --a------ C:\WINDOWS\System32\vb2en16.dll
2007-01-12 18:19:50 1235 --a------ C:\WINDOWS\System32\openopenopen<OPENOP~2>
2007-01-12 18:19:34 0 --a------ C:\WINDOWS\System32\99239519
2007-01-11 16:35:52 1 --a------ C:\WINDOWS\System32\kr_done1
2007-01-11 16:35:33 12800 --a------ C:\WINDOWS\System32\svchost.exe
2007-01-11 16:33:19 0 --a------ C:\WINDOWS\System32\3718845C
2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\ps.dat
2007-01-07 18:21:40 1 --a------ C:\WINDOWS\System32\cookie.dat
2007-01-07 13:16:52 25600 --a------ C:\WINDOWS\System32\helper.dll
2007-01-04 22:35:41 10660 --a------ C:\WINDOWS\mozver.dat
2007-01-03 20:49:11 5037072 --a------ C:\Program Files\spybotsd14.exe<SPYBOT~1.EXE>
2007-01-01 12:02:40 507 --a------ C:\WINDOWS\EReg077.dat
2006-12-25 16:33:11 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi<PLAINO~1.XPI>


-- Registry Dump ---------------------------------------------------------------


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"DeluxeCommunications"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe"
"PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot"
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SoundService"="rundll32.exe \"C:\\WINDOWS\\System32\\sqvyswsn.dll\",setvm"
"icqmlib.exe"="icqmlib.exe"
"ocxloader.exe"="C:\\WINDOWS\\System32\\ocxloader.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{85382E07-2F7E-4910-89AD-16F2E97FC152}"=""

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqnllk

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_LANMANDRV


-- End of Deckard's System Scanner: finished at 2007-03-24 at 14:22:26 ---------

End of Posts
cul8rman is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-24-2007, 04:49 PM   #87 (permalink)
Registered User
 
cul8rman's Avatar
 
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP


Re: MS Windows XP will not load when connected to internet

SNM.exe

MZ   ÿÿ ¸ @ Ð º ´ Í!¸LÍ!This program cannot be run in DOS mode.

$ søkØ7™‹7™‹7™‹´… ‹6™‹7™‹4™‹7™‹2™‹U†‹2™‹ß†‹6™‹Rich7™‹ PE L öùF à    Ã#  @     @        L@ P     à   à  0   à.data  @   à ÓßB$…£Å€òíy…ŽéÑgOoÅ#t;ë†Û$µÈнìŠé©~ŒË }rÊî‘*ªÊÖ¥ ( Øõhíø–ÕŒÍsÓz!Þ±ä&´€µB”°åŸŸì¦úðH´úC}bóøÿô´6öïB¡Ñ˜nÙœ@‚þ׎½ÚÑ´¼
I2f¹Ç–Ý$ÅÂÓkÑ™}®Ÿð‰b#ÿ—ÎÊäóÌ®èß©‰cïÉÊ£Ã8øˆ'x¡¶iÅ#Ï ÅÇé6Fònï-ì¤ÍpåžîÕ6Œh‹Ä*ë×p¦…a¦ïH*.£´‡Aцæ#–‚ùi¶ñBˆŠ ¹ûšKÇÀ6@'µ‹ô’Ù°ßÉ n¶Í:àc €óÏùšÍجkåÔ–¢±Ê¶¦å3X\eôùvÔsÎú.6Í'ïH›‰NÃaøìÚÄÐKã…5ÀøþH¾¦·6ËÆëíÆäò $’õ7-ºîˆeÌÅÆòŽž”)o´IËÙ½·Ú"¨9û@©XAä5óÈþ¼ÁÄŒ‹ÓuʘTmœÀ†Œ†‘æ¶“H˜\ÌȶÇÔéžpé´aoÄ`°ÕÕ âOq
öÊ
Òã鶉¤+ܧÖLØ/Y.
²íÑ‚lÃx½Ñû°Ç8GΧhÉÂωX¹BÌçúø@¤ù½oMí ‚#ŽK¦îyÆÜ‡«0xŸì\vôUŒ&…½‚ÉÈPÕ ÃE©»I¢ªÊ÷‘K~®·ÜŽÛ?UI¦n¦S|è'„±¡ µ ¾‰E€N¥sÛw‚¡©Ÿ ôu6æv˜¢gÆjs‚Ö&ʵT{ßÿ„ÏڣϿ*Âá±’‚«$}4£°ÐïºóŠkLp{Ö™,“ÂÍèNs‹ÀL™Ö†ÓìàªÒ°æ¦*Xý§Žâ2QùÂrÔkŽ—úᥠU¨·,"Þy–Š!Œº«@ùû.ÝÊUfŠRÕÓ€:þèBúÃ3Gk„Ò4 ¤òˆBÉó¡9Mg‘N‡£ŸDEÆ…òw]¥Àu#Õ̵4Ÿ~Zªv¼3ËøƒÑ“ŒÆÞ…ŽôW[j€4¼RJׂâúÑ*v\U£ÃÔé'ƒVŠ^²í®À?^ ¤+H"±À„µúêF•ç…ë@•zà;IEÏ‚,déh¡IRÒ:øÔ_m`Œkt@qfÕv“âVæ…ÖÌAó¾=É€qsšC”ãvìI$ޤÚô¤>ì“A…nÂóœwåéT¡æ|×›c¿©Ä‚…Õåo”.¯u²›qôÅ=rš§ìÀ9à þåÝœšò1EK™ú®ð£¦ëXÎ$ãÓ„‡´í:²ÉÖ¹¡ïfºæíš‹ÊhkLDRG,O ƒü¯è-lĤÕ@Iœ
™6ÝDz`uïD€Z‹¨?Jyñ¡ÜwÁ¯ƒØšvÝž7ÿäÙÆDÅJ]%EàǤìîK‚ *Íî„àéœô\½íèNž:ŽÖ9Ë`ù£‰•\¨¿²¿ô¼%ݼ¾mfóîl÷‰€–ZǘŸâ
Ý©s¾—m{Ì SV÷º³Ó›àÌâ"~‡ȾŒÛ€h•Ê߻ٽRÎ80Oj]ÑD5Ì“˜9Œžfí2ˆÅ$Œ“›‘*Õ…°Ûûü‡e«êÄBš~ÅÂÑ-€…Þúm_¸¶Šùª%¼4´H×bÀð%*MþƒO>NchòÀ2ƒåWÑ’‰J›õN%ºþì AüCùÀÞ û¢m'²›E¯»3JíÁµÐyê«Æ‡ç‘#…e.Ox ð¸ížf„äM|…϶€àü¡—§@(åÈ‚´HŽÃ&l&Ö+
ŸÐþdˉÊ~äòÿ–£Åq$ᾇýg«).ÒÊN´b G\(æãu‘ÑmëÄ£e
y/Îû4Jë“pïBýÌ»vÊM˜PûaM´É•ñŒäUÖÅŠAXÿšÕÁbÇÜÃjÝ襱 ¥ô*nHµ¢:ÐhéM]`û‰„Ó”¹ÚBÒõƒBÕO¸è*`f ëÑ“Îù#ƒ;í‡÷…4åÝè‘4ÒÍÿ|ª‹5Rå¯é7ü–ðêÀÌñGìòû”#!ŠÓFnê–w°óB“ž«ït¬òìŠéÁ§ù¹‡í‹vÆÄÍ¢”…=ˆˆéOÌÓ;=¦ªšN|´‚E§¦ì›@ÈJ4€w«Àz;Å‚*ã/ŠVäíÝàL´z¦Åxºyà+…*ÎŽN–X…¾•×ùôrdb´JʉjmÛK
$}ôx¤¾wViJ0'˜Ìó@Þ;D˜ü±Äú£Ônc[ölPíVR‘øöÇñ³tÜ‚ÑÉ¡’lºõÐvmŸÇ,[Þ4®C
âÔlf´5fn19›“ÏÅù#Ž™çÿ‚õéuýºñdz§âÞYyÇ9Øt9ÌŸÛDHã7Z¨¶ñG´¤¸,ó)µc*àdb-v‡p›lÖ½Ëcƒ}&Q” c
ÊSn²K¾Ûóc»jp¾é}*ÌŽ’•Y)È 6˜Zuú€Xì'ÈÅ;
òFEû¸="®à¯W¢¢,½S`yï––µ&Ä–dùÍ+oÄðy›‡a˜õ‹Ú‰\ÊÂÁËôòH!{øáЫ÷ãM‡þi**.þCBüŽ)¡î鈂¶
 ޹ò\;ÌÖYxãH/åâéîäŒyE^¨dØ"øþ|#˜¦SEÞ‹¹(üÚõPxŠZ^í××î¸ó"úÙ²Y´ô+üáà*
»à3üg^jyYÛÇÄ)nt<ØfHo‚¯ :˜êè²Sû(çÒ¼þM)ü—3.¸ç «x:މ؞˜aÅ,e)9rÅSì¹à ÊžEh®òʈííÂhÿhnH%~Ùær»Gž¹r8î¾)«çšµoþžâó$Ú0¨°Šf?tH®h‚™X
¬ÉöèA83™rx_sŽrËó˜ûI#Œxƒy±Ú®ÍØ
b˜íh-xŸÙ€h)B‰]ù>¡
×£·_,ñ>_¢-ï/ieHèÏv¹¤ÇCh Â) zZ©¡<Ckáòˆ?Ô(ÉL&R jÛ« B‹îï @A OA ]A pA A A žA ¬A ºA ÊA ØA èA ì@ @ ù@ @ A $@ A ,@ A 4@ (A <@ 4A D@ kernel32.dll user32.dll advapi32.dll oleaut32.dll gdi32.dll shell32.dll wininet.dll VirtualAlloc VirtualFree GetModuleHandleA GetProcAddress ExitProcess LoadLibraryA MessageBoxA RegCloseKey SysFreeString CreateFontA ShellExecuteA  InternetSetOptionA 
'óH í R6ß(ä:l¦³Ðà™#Ãʈ(70Ð0%ˆT¥‡ˆz 
X‰ç] KCÏV÷ð [ýÕþnq>º8‚1U;:‘r"ä0[ ã0 Œ¾"´Í®!ÌØÀ’»êó. Ö"u±›Ÿ¼Më&Nlÿ épÀ®P,;ñ0èƒûtJìüþÇé?bÎÀÆ;ð×_Ö–é' äžó®‡wúÀ|O‚èâ*JF<ßöLœUXcп˜PCeQè!ÜÍç<jó¶§
ÁæOèTH
V^_ÔöÖ¨36Ë0ª49G;û†8–S¸^Š÷Ùé”A¿þ¥ÈÏè
JôƒÄÁï˜#’¤–ð…m ‹óè#ü©1* öØSD=‚W óéˆ8LZG FCF³W=Kö’Å™É?䣯¦„
¤ò ˆój²c‚°p>="] &Pf³åPé"Xì_|R*ëÿ¤
ù-¨'$P‘¸6ã
mì!鈀µ˜váB»úôŒ)è€|kÇì‚TŒ3õ Æå +1R€‹ó†'8ÝÀs«WZXöŠxDÛ^]f¬^*‚óù ÒÁÀªçK}Êþ÷ÞéÀ¶îD•‡‰+ «‰1€÷Ç«ÀÞl‘Œ¾Ô-ç€ñö¹÷Ó‘?ƒ·Ø;ÙèñU*ÌïòAR¬#Ïí¡BÚ &Ì~xÏþÃ(}Ösg˜i—åÁ0Î96-0Íkjw‰,S$›~HBæ ¿p¥é¾ì :fÿq=+ÌþÂJÀ`öÕ¦Dg$¿ù_d\€PÐÍ Áfƒî˜÷Ãiº–öј¨Á}ÇŒ‘mw ÷ß’ÎàÀoü†Á$î))ˆžÃÀ:Û›+Cô;ø‰1Ž
3„`Åþðy³f2=F$É`=QY[ÉäÈ‚¦…Í‚ââ)šŠ`?¼ØTæóþSʉ*¸ûP#ÔëÔN*$Äj¶0…ȼ›(Åcp.˜º&On¹I ãøäö¦‘AiÕ@±èÙÖhˆ0%†JZý¦ÉÍÀ®ÒNú÷ ÖëíâèF¦‚O«û$E…Ô@@—#ÌŽ “{ΚÜ;*Bé&+,&aWÄÊP01
ƒ0
é¿o“• T0¼*l$ÜzDÈA ¾…ÒA#î8¨[ä˜Ã™Úˆ ܑĞè–q¤3
ˆï~Ä KP[ D0_ŸÈ)¬ò¤ £Á
"áà ÷˜#e
}NF ÌA˜šé›ÆM»L:3ï;dàÒXü)¨bÀæH£èSù ŸÍ]½ ¿i¸ß‚ãfˉD?UZ[Ò·Þ‹ÃlÏHÛúEÂ뉋èÛ@^Lº¯Skñ& •sDClP"ŒG†ª¶ã„<ÿ”‚Ëè‚p_/0Áú
j\›XN0Ž*oöTÞJ°¦˜ 1µ@yèúTþS]Î .P^Yô¦« ÉúÁÂq ·LV"3Ï?àᘴ_„·Qò‹ð1P<Ð_€ô æ—#Ü;è£_ÅJ¶‹ðÀ 1÷Šãëdž¤îuÉf’Ë ïL9ƒäÇ ~TZ^Ë“à°è0NJi&»çõÕöÚÌ<¦7 Ô)Îθ ¢ò•ºÏå%‘Ìvèz^o9Ù ¼ëP>ã|Â>pðüS ‰\v
Y^@
• +ó0)ÉWÊHŠØµ£ö#|5{dR¿‹?÷Ù˜çé T[Xïö×Fü»¡Ð#7:…Ö`ÇÀhÆ_q{]AAšO7îâ;
ÔBà6%N0ÀŒ&õûñ0¶Î%|"*HAŽÇÁ'"ãD¤X¦z/ó;÷ƸÃ(Ï\òHÖN!ù“Å3ê DȽ,1ò€~
÷è{öì÷Äè¸æ<éêvºñûz³àçrDî±(_Eúwl]˜ŽЗf—Ôd7À ΄´lo(rgiáî7„+`HÔNìíX>Ùæ+j ¢r¼æ{é¹>#¨óœé~àÝñåe Ž*Uä¤ä…Òþlq`vb£üuEZôÓ*šÑiZÙó}c„²³úBbY¨Š4ãnL÷ݵà"Laî݄鳨8YµïÌ^Œ?^w¦ãX…Ðá´¦(¡üÌÜ ~jrâ!°§¼1²´¨‰¶_\¼Çäø®}ÉÞŽh„,ùl»€äÏÔIt¡- Ë•UK#!ð·R{•‹jr¥XEÜ\€^¬T‡ƒ®vL>ÍT_ám~µ9!£æ†Ìô÷|Çñï?h‚¿“…Ï ㄃
`û8úá/}‚ýRn€ÿËMa—02QÛRè¯uEâ·XM·ìe°Ê @î{]¿çc•„öÕ[0è©þ÷ÉàS`¥~ Ø*lLT`/Ìít• 0„û‡·ƒ_Ua³´E£5ÉÓ'YÓÏí)8o˜‰‚ŸE¿w¸õ…ˆø `ívå/Š4[ǸÖ(á¹@ £X%ñ“yÿP Àl¿1¼—KÜ;å=$«tÅ~ ¸*LvÈÁ\Ø9£±ÂùE nŠÎç 3˜£<þ‚g¯Ÿ‚8ùùÀ…áOÉ®-M¨,¤õ9ê<Ã5÷2伄´&xéînñá>Š
ƒ å [6ñ%` (Iô$3ÉpÑ0ëŒ «5‚þñõYøA*
ü‘p|ã+Q䥷ómvé·ÞíµXdéi˜iÙßJ÷$™§²-‚h-$nY”pxø¶!âKwL2´t
ëŽËÔ’hú#ÉKQ?‡Ü
p
ñ¡xâåäMËÇ *û;8Gâ…)žß³"”&ØÌø–±ãùaªº#x—4RØÇí NÈiÜŒ{€;²
“*áù1¬=-…ü‡JHæ1ýÎØ0sœ´5Ù¯„Ø&ÁŠãN
?¹DvU7Ï V:úbõÄï[§7ÇWðG›Ãômîzýï¨{¿anâüúq9@üGò f¶©t¹™·s÷ÓÑý÷‚uvt÷Y{>¤ºì|>šà&è
šæ{(Ã*É`@üñyÜùöÌ“_ #_˜#¸ƒºº¯üíplYH©F Ðmâ²÷бS”½»ã?hšR!Y˜ë.\£" ‰ž¶;cÂ`—sÜU~®B *€xÛ¼õm@ ùêø.'8–(ã°ú”
†êA
5 VEúxF¶îúƒ§èç‡:-6ä5ÒqE“wnqPå6
ö†ŒÚ|¥±=víÎBñ Ysm/f‡Pî’Ûºãqäàd y²'e‡ÿsÿ?øÅi™ALëEíHè¥ÖóTp»Ä‚‚7`ãqhùJÐg%cÇžŽRõ¼üT!̹D¶:IE?ÛŒW1ÛóL˜†ž~-8„áJÚðÛX¨£lÛƒ+Zu½ ÈØA—ÀäÑöJ‚Àvëîbû“N%‘](R«þïv·H— PÏ¿µEÕW±sùKÈ$`-ƒPÑ¢Œ}"Šf;I¹¥ž âsýD0Añ„¦…@ší¢p´Ðý7CŽÈ OɺoÝÃÜyõËî('/%áÿ—u°‡èY[¡gDDËBŒæÒ3- µ)[ ”r÷CSuÑ¿°²8úŠÌà bUÄÓ+–¾hÇÄlÚÕ»îq
%C”cs~kí“y/¥í üõò+ªúèòŸuñ]*NR"¬ÍГ¦Î”ÖpËË¡r€O>ü®VÀvµ:ؒ͹l“Ý|5.dÐK•ÇûK2‘PB;™Äs/uƒ »—y—Œäâ 3Ô®ù«?ÚAŠ®((sD¡ØöšIa¨Ö aµ8ØàÚCj ͉™Å_‚ ¹„hv`™4{?óÉïñìG׃¼‚é 1Wk#lß d+4±¿sÅÖè»\Œ+ÎF‚¿lDuE€4 ά:ötÿ5óYûÒÛ›-CZiî„fNl¶é×7mÉN—yÅ¨ÍØ÷Ë ögAL@ñ¶wúô8¶§….Ýy Ð Ê ˜sl<ëßÝd-4öcø&Hä´·åGr:9W¼ r<4ñ7Ž|_‘¬×iÂp’÷lÏõ[¶¦ñGrS©ÓðàYžÙ`-Îà$•¤Â´ì GRTT#Z¼x^ÿc°Ü`5~uδscþ¨`v,áºxYÅU ýâs@àù2:4hTǼb
¾ÂĈE“k1ÂÒi•¹L…u^>=JêR^?{˜!+¼œ£Üy(í’u0sÏi,ô¾Aøf…í]À1ðmkŒ9ž`
s&… å©Û`*ôýµXd=-LËEýŸë ¼rbÒ|ù34‹mÇXâ2R6i&2÷äÏÿñŒqÜ…R_äb8
£3òÞ4·¶ŠOa’ìæüóà›sÎóU pl*៼í©üÏxuü¥ý89åQ€ø.wÖy¥qá÷Ùs
x¢Ö€íè˜kåµÌùá8hŬŒé¨ÃòUWðc·þZÍ6JúgËsÇ‚ŸøÎ4»ÃnKùcz}VÍ]
æ=h]”×W§8Ôm%‚\ÇákÈ}ö¡Ç:IW•t"í!Gy›ùmè{ðó9Ì\dƒ/Ð(Ô©ó—Õ©—ìYªª „š(àX¡ò’onºTÂ-:æàÿ*C»º@uî 6½¥%(^Z®áe!P¬¬!á oñáÇÍWØ·Üáu6ø¹uË.p}_õbÀ„6wö+JÀ°¶2oüœl^Œh§
%̪(7|I¥ryÚWd}óq· “<…íëu3Ò{Wc0öM3#pº¼`÷ûØâ£€ƒ7-
6dnáa~xq°oÇGõŒ"}1I2çmÞ‚u™B¨´êõUíô' oü—3™?Ÿâô¿£ªXš%§@u»ê]XOè@’rðÝtÔaÄ;¬R^x»K(äù ùÃu0¹|ôu W¨ôóÿÁ16iù¢ð÷ÎMl7¡sRÁ%™Xùj`5ÔB ‹Rª^ÑÇÊÍøñ´¢{-Ë?MðÕ—Ù!}NôÇ
û.}Ô¦6ÏÐð”cwÔk‘qm)ÔJ0ÂuKq'ˆÁ<½e£ZÎde¹ñl+q°ì$<øÄv•»ŽÿG{#•Já‹ñ«òå%S©Ã[&ô"Å}c‹CTË8Ù‡P“ÔhX«J§„%òÚ{Kñ-}Kõ(‹òM®|ø´
ô½=lej¶´eR´äý{ó
ÿiøÁkøÀ²™mûw«ÃÁ˜òç¿>!ï“ÖQ >æÁq{yÈn¹%’2Ãë(æÍ÷ã•CL¬A2“¯Ø âíÿt£ b†—@QLùÿÏÅvTŸ&ÎÒžç'Õ]«9üi±MεWùªeö¬]#äªUb‚·âõŽ |’õìTÚ{Ä]–e þ©…TÝ î_¥Ó²¿ßå „p˜A“Lî ¾„ßä™v¨r•Ûu¬À¥YÙÐC:8øÆ"s${ç–ÞÔò*ÇÕ}ÓúäèQ†cu‘N|ÃùÙ„žîÜä!Ê_n>¨7 ¿Í]ÞŒ|€ŒfˆâÖ·O–A´§óªì…&áªGý[ý0ʵ®þe[+óÐ >Ì··7¸2ío•vÚ*UA»?ó¿b;æv°¯\G£N˜R¼n±{ÎY'Çóo{±îƒ9±!›@®ìXØ»¦ó4휴ø œæ„{1©÷@æ~øÒˆ$¹¹ î¿ …èíJùö•Ayžƒ”o6ÊÕ#ü´šÙy* &(„¢÷}en© 龜¥¸áU 06úbLAÛ%GܶÿŽ
¦ËZ§™ ˜ÝuñËÚlA…Ëìxc±mÞf À°ô IjÚy™ÍÙÕllÿ2ô~}ì^ó¬ã€«û÷KŠÊï}‡Ùl»âˆ¦ªšMæïpFÔóo‚o¶òoÊϯAÊæ¨ÍªÚÅ!*m¬Tz’0ÏÇšMYø{Y
*™¢(¾Ìó <ÁËÌðHhoà¦ÿ"d®lŠr0Wß(ƒ*óð 1qìU ùñ~âþèñEñójï/UfÓ•4‘xÄÿóåS\¤9InÓ£¨þÇÕýl¡
.ºPÌn•7žïØ<VÛì½® )t.m±÷*Œ´¶äkùeð¥Ï]óÒ-$·ZÇŽr!ùÂì.ûD€…°…A%2é /VnD»d¾KZ³s»öÜŒÌÕšrj^¦šõ™âÜ‚Õ/wÃÚØÂ7h"I4ï7Ý»=Z5ê¤Rrqv]›þë¤^%,þŒ ¶ „î
¡kÁ¥ *WSÔ¥Umü,ñlNãžè2ðeø¾oi,.{§!tÆÿOeõT Jaˆ¨oÁÃP]þ)߀‰¤Z Ó ÈX,á§:Âaõ”nêk/óo€ßã²Â…0¤äùÉŽòƒ™Äw=Ÿt‚wä¤å:>S'P±“n1Ët +GtŒ9Â;ðdYy/´YÌk% –þ†”$(àÔI 8¦M9… ì%ñ>ó7/üÂÅ›¢`Vi
XÄ‚HÛ ™’gŸ‹
Út»<£VÝ–êT[·qܰg÷‘€ãôpõ‡‡ ƒ3ÄäI¡bv€¬Ï pÿЊªëÃ( ·.XXÜÿ±t$€S¨’hñÁ'äÛÆó– Ðn(ReãQ`¥ìŒ`[ZM3DEó˜Ï 0š0ô „ÈÌdˆøVúUrŠä•*üŽ8}ÊÖ€ŒÞTÙö^èO7Ò=õ³5\]‘ßy
b‹wa*Dt˜äõ&(ŒUPýx*oèûeÒÏ¥$ø“¿yšLû¨$lŠëƒ›z kýEüsñœf£†Ðãç'ÜE%QªôQ– ÉÌ´û„è@ˆdj(~ëwOæ"Ñü]À!ð½Bg%º×x,õ\£*qíó”>ê É˰û ëÀT8¦™Oÿ`U?
ÍV«{ßÜpºíU‡ÕU§Àï |´`ã Îùÿû÷XŽ„üϰ·—q4k@ v±zM6jÐ)¿ \=ê½éàpÀ!ÅDù×Ò¶j£¯g 8+Ž4šç`yžÂ>€´ì‹ë4ª•IbîñYÔ®!©L¶<åpƒî«:÷ÇñEër$…²ÛO#Ôi¡ªú$Y¥ËL²ÚÏ´-¸£?Φ\âôxq$ WL-ùY3És(}ã0Á¤\jgkï*d:$š(°ç¤w»Ÿ5RÙ9ŠNǹJ‚{Ã]Äòs"è“£‘•
dÇ]D†ììáéy~ A¿A·µâôK*H%6~ˆj¾MÿyÕMǾˆ4!Aå[ÀÏ•êìrnýºëüŠŒªs•}G4‘+}f{€2dž_îÒ\´çoÙ¹¢Ïúk˜‰ñy„ë]!Íd'ÚvÑ2Å?nÛ÷—Z%5¡9ë æ ˜Äìä8ƒv.µ'…âþ:¤ó[Žíbü¢hС ´s’¯üë8^v6ìG_ °o´ t‡{;ø·¿ÈègmŸhñý)LYeØöçìty1eÇ!²P?³Óÿl¬Ì3”¨®äVîtvÛ±pgˆ)RQòGM ¯LôXtÀëiHI5ÉÀ«ÒVKï†éFbû9í ^*7mB’KxÌŸÑHðgGÁlÞ(£|™\‰Nqv`<ADæ+Ïñ »çÝä<à²242¨PchÙ‘¶
P†µ{ÁUþì°·ˆ[\PÝs)à[†;)$©tîèñ÷ŸE6q»Üìû^J'àó¨¯G£G—ã`Ä9âksq^ˆµO f ’ nR "XJ¹”ŠŽ}ÜV(ƒ@ïŸÁ¿ðDh’5ñ׺ðAHk•rè;³cO<£ç"ðFj¿â¥\×äE„—œu ×µ5󃟢m›Û~§Ù” ç—wZ¶?…ßUéZÛK7
ê<ØŽ ïcý´ v™+æ[*o<¬Z§à¹Í
7%•@ç•TKmŽmµ3|ú CŠr³ý’’Þ ÷;¤7HÞ:Îðvr¯^GeêSkü’ý‘µA½|®cÞG<HU‘£!45Ø‚nu&¯ðÝ)0³Ù…Ç™ð€ØY *n…Ò—.îXÞÁ0:ügkp\ zå.i4 ùϾ©’öI§:œ
2 Ã+Œ´ž‘ŒùtÎïæÿñ÷’`øñ´p,ró±ê
¥ÚÂʈÏT}{^Èì™@s,Gâ\&y¢„„YšalË<®÷áÛ¾X‡½Ôû\˜‹QmÉLŠyÇ»L—íÔ>,_MHn÷„sOnÈÞuAñ_1W“oQD
¾3'ƒ©{²„àÉCáû*¾;Ml> 0í/Fï¡(^ðµ9U²ˆœ†m÷£x€Õ¢³ Eð¡,\½†b¦(…‚xÒ|Úæ¸ç!Ë0|y$Öµƒþ¦_úTÂõ¥°Fo(rcÿïþ¬§óÞ¤ûÓ‚äè?åêìŠ0Ï<Et5Bøb¥ŠHÅ'éèêÂãó†õ“9ü‡)ÒéŸr*ô Y¢Ã{»§åtö¡*õmn‚ŽL|B(Ö¼X17šYPàzõÙµ%Ho¡'B,éC
ü—äÉ3Œ
wŠ’$`zà¿x~öáyÓ{)ëû5|ËEŸß ÓÏ Ñ™ê/Ñ
sQq{K;Õ€(ã|ÉÿàŽ×Ûý¶ù¹ExXW}!Ü&+Ÿå÷ŒŽ7=,ýƇÁ¡d{Îò¦2í%£«
3¿}ÉÙ/Œ}·‹¾º~0 ¤pº°@‘vÝåHœq%pÞ9Y’ã*H;Õ± ³\k¥H]TÉ6…,g5S¨Î¹ƒèÉÄgh î[¡´?ŒäœYÖ“3ðÏlm{ýõ{éæ7¦x¨ÞZò~¼ëKú¼üÙ<_¿I¡Pý°ëhþgΈ Ã"Qa–Æš—Âðm{îlö¢hÅQê˜a†u8ÉæÀ°õ”L‹%Œ‰ÍÇ,ñ‘Dš«ÓÉ/‘Àiú†`ÂóøkYü…(còÚ˜ŒT v¨j]ÂþœŸè¤x_¨æ{Y£W*©sXÖéç÷HñgEà)ȼ’pN˜¼ê»õæ •¦ÓQÖŽ+b¯"èu{%YªµÈÌâµ^)ñ)S+¿b\T>ê+"Á·‹IÉÿboÉ fD×3¢÷Yè4„Ãõ¶÷\rÄòlh0®s.-ö 8´p÷ìY›1 qÞ²óéÇ{¬”XUù‘U0ߦ×Ås,ËÊl xbþ–q[öõ˶œ¶ü L$Üè¢ÛùGåþD=ø ‚sÍ-Œ†„—sAYå¾¹¦õZîüZo-!+UÀà–Ôáÿ#‹ºÏ¥mÏKžGþ{ˆ©¯ãEηR˜ZuÑþ³EÌö
Òaí÷×bm€`§tHø7(p_}Ûë‘PÞ¹ïL΄øªCj”>&ÌÖö 5Jó”~¤È*£+ß·È@íÑ{þ”R0h&]ù²+_£v>ÚcÄ€§Ï,€HÅ“Â'LŠvãË^Pi*åíõŸp¥pŠã5ôPq#²:ï””¾C—+çðC¨·Çq@zhyö«}z5 Êù&_”ýJ} gä²äº”–GbžÊr‰÷)šVÅ:Ó~Ãþ%pSCàv×~4b©†vîËU¤iu5åo+$õP\wP’4ƒ¯yG‡yxpCŠäwÆ™L~¢·ê#á"D$cëV'¶ô¿Ô Fó
as& øÜ“Ö`P¹8 VN9¨!=6}?€b(ê «Næ ²Nâ ¤Nþ ¦Nú ¥Nö£¶õ›¯M §.w[üå*%x/8>õËùs?õ}4I%°“-xÙЪ@;«JÕDUj*$2ñ /À¤d}í~‡Ì
_Ày?ô‹eM \Åuúêx+Ü+X%\ê>±)wçXäpøgoŒ8dç7«6¢ˆHRíYZшXìX9—W˜lß=¨øØ)¡Fw}2û¾DÉ/ Jœa%™ŠàuŠ ÙÉæ ü>ÅõÞBƒ0eæXL«+ÕtV¸…®Ét—xž×úªQ b§Žõ7ùã¢
$®æ8 Ãçɉ¸âäEIAäÂ[;Ñj´ÄÑ! 3wQßðλL¥oÍWÑÑHHË)íãAÖ³óa5×|½ؘi^Ö-³N×l„#2° ϬÑyYÑë8EyÆQMøú4ScâÃå§Q½#VÆåMÀsš‚Úöå÷ÐG ±pÒlI¢.±àx¥vÛë©æ{Ø9hE$L¸¾ÎÇÀò(„à@0óšxöäf-ÀÂÌÚ¼¬¨-àQgPãÆDuödA%w&¸6âHãæ¥4‰I¸$*dn¯Kˆëʦg|Ï{Ûd„„ ‡²¶Þz„} *¯4P€º¿’j⮸Ÿe¢ÏÏ
5úÃê©p õ4xNƒµÆA¹—1 ˆ¿FOw*n‰2לˆ1þôöÏÇ ¤B¹ )AûÝ
Qˬuµêö›tð]£>ý]î&”¾‚ßÿ.}piŽ`y©¤¤séª<>w¸d9Ÿóƒ~—ûz)dÐáŒf½µk¶¼1´WöÉ(ýýèrõĨf4æÜ\͆Úw±öz"ÀêÌ3A¾ÇîÇ”5”zg…‚Äcë òïqƧŒS3#¼!`¡ ¼ÒUåÃC‹©LÕ&º5W“sqçºÅ)²aTÂA2X(IhgLrØ‘jŠÏFÜŸî{Ùˆ¦‘éEœ5Å æôAx™¨Ó”V¸ÎÖ“û›V<Ø¥J …í# ™€³«p“(Ì}ºâ^ã¤lH6ý”͉#îÉ^>°Ëkx}úÎz¨G$k\“ÖM|óÉh‰uc 62¿:sÜÔàX¹yávùþ÷bSðø
sŒ› ©®¼#æ| S(qá‡ø“Å5^¨“ÔK{÷¬¥Õû»M„6
®  ,I·G„²¼^q¨ì8Õè1÷¥ý»Kó/rlø‚U¹Ò©€Ó<0ìXÔ%9Hý쬥…ÛËïr¨ÇdAm@ŠSC xlˆ‰ûŒó0UY£vŽHVÀ3¼wíÃ,Š”ŠréôCªèδåéšî'tÌy·€Ë %’Õâj™çEßÉ(Wñhû…Ÿ7%ª ~G6ùm‰ÑþÌõ2ÏÎT`dñ.Yþwt…¡õÝCHU¥+Ëq¡ ò)ˆ4B
ªr]€|iÞ„‡R˜uÃ7¯üâ¯jqÈö0'!¿±.SbWÆVÑ×”ŽÜœO4Œ Æ*g ì°².tŒÅ+(cÚ
÷LA!Ï{:%ûLËåOï.‡È.€ÙÅàÚ¡äѬwÆ@Æà][Êí+²*}jTÝv Pì0
¸Ïÿ²ð ”¡Ÿ¥õت”U`¹NAP×Q[–ܱkÐíæRçêþsqÄëtâí~*óLF†tV]ÌÛþƒú¥íC`=< y0ìd×ÒIý6$0ñ&ÕVéÍAõ!Lõ€,Ž÷|}Œ2ólÁõÒCô`ásNHšVn÷pÿµ ËñEÇzl‘`óC÷GÄÁo-}L5ý¤ð¸ÿu `Ù)Tôh²¥ *Ë÷ŸURï÷µ‘ãÇ`ñâ$àÊð×y•¯A>*xJ ä:Õi îòã?÷B—|Ùóµ„ZÓè$VÐøð°o¨„ü|Ç
€:ߥé- ¸«`kXÖƒITshÈ
“p0øÖá8®=õâ*— äãjÏùä\É( +“[×åÄBkáN¢M~ „Ã5(K
¬UâøuÌ—6l82lÿXûìqvLÄæ²9|¬ àÇ•ûq”ëé"øu6̪§ïQ}Ãèö¿áIÐEA ä[†æÞ˜m¥b{
E°§gUÙ‡å}ˢýã'øZÕþgc0)’$CòÝäô‹ãmë¬ÍJ= ²ˆP—`ñxz„½‹9ÛÅÝ%Èå=çÊéeqÄö3U…ö”[ñ'—*‘\É&á{ª„*ë½à+˜Œü`ú~P s¨Ë >Í(Wëœa{~Òp_2 ð%È2Ê´õô>Ü5éçô,!ο«—àM°ƒ¼«n¬–à»&|)Ï$¿€¥‚çZCŒüEÓõc #ùöéUwváæµôøtÊÖ®n¥•šôͺã¼ée;ÏváÇ×##j|õ¾›0#}õ/ñ°+Ù]Û)åÀKñ}û}ãkgÂ7o`»µ\
]ÑÆÈ/A¸‹Ž¯öÁfb_Šˆ&ó|í?”çâT¾ ÿ œ “*â[:~ѿϗ!<|à£Â«l¤E>› BmCQÅgt<þk°Yýµ”BõV<j1K»ë-É^&mBºÀΫ;kºF‰tµËâhRÍ…ç¶.G³m¦t›~]+0´öë¸v*„ª\ÏŒz—«À DQnˆŽ8ïzõî¯.tm|m®8Ý«]b
á·âñÉì5’ú^ûúbüúXýúOþú1ÿ[Eáùf¹òœ¢w™
Êj—L‚óB8átüÁl  Nu¥ã©‚¤Évˆûä Ðò†Ûukn?pÝ’•Åúi4ÕýûOt5 1üc4²ôªÂ´7‹Rsø`¦ò= 3W¥áÓ—`Š ÏM·Ùëºí,ÒÙ8X¬n
ªi÷÷šOÚ%ÿAÇííÆ}ô*¿‚©ë4÷œ”¡1 ÃŬužÏ7
Ù«Nßï®VÊîlªÂ%Ù²Ó_^Âí—"³åxáÚMEù@
áDK) w°¦È
RìˆyÚhôfG£çLè0m= ñj ò´õ3ñ¶t
Ù&™Iû¾ q¦mî\v5çy~ƒúg…HÐÖØÑýA±Å5”úê,\¸ÃHyúpYQBõm
x³ú/*è,‚ä¯L®¬«« ó—tác8Ø‹?„áhO(àõ'Ífb‘ñ‚Ó~ rÿ0@î4-3§HQÚ G)1Ö~Xy64W¥O Ò¼B¨Í¡mITô_ÖÇBŒ
dÈ~DÿbhÀë¾/ãúôþñ*87>÷1bÔämsþ©¤t[t¥(wí«lÛÆ[£ñŠ@R*|½’’à^´IàˆMø^Á£1(žÏ ƒ–îFµ~E âú}ø
¼{ï‚KKb ès…ð"£¹Nñ&Q1ò6»øÝ™ëyE®ÍÓ-äCÙñ9åÔIØ>`ÉÌ|,>8àôþÎÃõÈHÀòmvë}=ß :¾õËø@43 7’tŸª…(à’X-ÍÖwOtñÿÍóäе%Töü˜ƒáDŒ˜fùš{¹ô~ó‚nÞª‚óÑ^H~Ð+[ Á{äeháÏöOñ"ºöÔã,ñ²”ÿváT<”ÛN£ïòG 7áö›˜Õ~= Ë<ôÍ«%Š<ÃtšõG
ñ’I€*Åt .a1‘Âe{‡GôÞÿ‚ÓŸIæáD ̳XqI }¢œý¥*˜,-ùÓʹƒªJðá(-hù}üoÍé?úh#¦?tá:9Ë[ë+få ÉùÙâÇÇ ¡¤ëñ´}¥Ò-úc? ß0{3 tkó€šÜw™õÌ)ù÷·¨uÍéöÓó$(isš„Ø™RÄâïxöù¬3É›^NžûL+F8ËDjúÙ2³„Êû§Jö3Ç3|õ·€è¹£Æá]sƸÃYùu妧8:C—}ù®„|×͹Ah´(Aá°õ“PRN÷u›Š‘c`>&RQšÄh®¤XÔc¿h9ଠµÄì¤*ø&Qã÷ÐxfYã
Îr3 Ûyàºj—ví\wá+ˆÍBž}óÊ5o¦Sß|sJî”pĈï# šFÜ©í]„úV/—í °âpžp¾á÷ßånëõFú]—]¹öçz÷œSõãüó¬’“ÀPqî¹)p‰ñÂf5¸úuaÔ¡¤äÒxœ»ùaÄu]_êO_ËBª&—JÚ¸‡‰,nmt¯Eþhñ¬iôümòFNjü1)ÿˆæ±Ê«êÑ[åæƒ DH–gB%‚Å‹E}#/xÔ³
’»_6å×Û'c„³²}T½4mµE0/žjÎÛçxÙó4>ˆ¢Ûÿhã‚°Î,_ÃÁO ÅÕ`¿º™ÅAK«‘Š>Á=ÅÏÆẪëËkZòÚ¾IÍg2v¥!øYíÔ YHèW;3¯ûëd*¶·°‡¶I¡§B˦ìÙu±âƒÔÀ“R|ö3Œ{ž+:íÕRmˆ+ü†·GEŸ‰2 †áa¾ø]±ó4±4‚-dSà„Fc2F6¢’-ê(;žˆ‡ÜñœQUÑ4#Ñå˜+˜sÑ5Wn´R{1Nìó”éÊbÞ³aw”x3V]'²/9‚Ké¨$ùáü’†\aDN*5ãZÌø¹ŽÂ(ó(NÒ0ÏÑ$1Ez·`é¨ÚÂQ§óÍ}Ý£¯HÃü´´Æ«\ˆYêtë ü ´(#LBë¿ï[þ¯Êæ7‰ËÉ_¹÷”Ñ…±Œ”‹áC³¦QqÝô¯" …sËz`¬œ£bò ¥°´
¹¹ šžh}”ÿé1RAÂévüäц{½!.‘è´ –“ h‚‚€Õ¢†.j/(ŠzÄB`bU*žô”mT6¨À˜H±Q•>ÁɃ{(¯=‚*YƒÀqx–dZ:à\Y@J”Ð0×’»rÁì÷ÉC'H_SèšŶ³ Õ÷ô@VJËKu&ä5ßš†³®h2õÞn|ü.OYµ c¨dô5‰³ñ÷Ëî)õ…îgYizÒÊ1ãË-¾‰;
6ÔåC&–›µ$é& #ú^
¨/t†ö. -Û³P“y-ÿB°È ò€?ÚµrY–}¨ÍÊ<D©”âä½Ü¿ßÇØßìß¿ÉC6kÑ,õØ>Îõ?$8<C®¡ÿÀ/Êi0áq6Œ÷{„ .aô«lÖT$uùçÂÅc
Ç!}llr ©@€?sz¢ôШ¬Å@Ím*fl yÍ@ŸH÷:ÆÉ•˜%ï’C£Ny½žwX*H¯8¹¯£g¦UvT¡@×êb•Ð6¯¨†„¯`dQH³æsè5·ãÏõëî—Ëå»Ó%Ñz”ódAxTJO$Ðt•Loá?øÐˆ.½ƒ.Ž:oÌ¢0Ä'ooB˜ºá˜ED@AW” åß^RÕÂÀÊdâh}ÝöðöëzŠã
мĝôð—)ÅÈ¿îη±s.s/^Ò×ÞÝ
xâpi<á7Øá‘`_t´j+½³ó
ó“JŠÍ®èßÔí6éѯlºTp¡ ŒYQDV¾E‘ÖM0aø”l'Æßëý"¤i›S‹ÊþºŸPîМåÊZcÃF³Ýå³³œéQÝìòL/Ç|ƒàê ¿¤ôø¹êËZm8Phôe¿WŒï ÉFIƒö§ 8ÖÿÚ0Jë'É}æ #@dä S¾¥‚½ˆtž\#ÜèÀíþëøà=™¶Im5ÚŹõ 7!·0µtb10QxÂgöðDV‡ä‘¡;mÁ1©—f(4¾ Ð;šs$8·˜A‚§E1ìï:ë€i/ñèΈa ´í;ÝÉ+`Íe´ÌÀ¥Ø¤˜d.ð\ï7%ìÃòNìÂh]0x#R_•#Vsй~´ÔÓGí‘8w˜Eϵ©§Û|œ©o…yìò’ø³69\„~ l*ø_?,b£o¹ÀKt“°¥œFw€½ž\FnSk#E ëuyónÔû4)aÃ^!„P^¦ØoM9׳?FFÏÏoôË€Ã%™è#©YÈ“ñ,·(J„¿Ë€ ¥øûÉ`ý~ ‰*v‹Á…{
Þ‡ i;ôÓÇÎÓíè8˜ê‚EììòN¶…•ºÁ
0AtNÄ‘˜/“í •*0"û¯‡·3_Üa1´Þ?ÐÉ=`Ò~ *-v¢Á/¼{1Þ¾3i;ÍÓ"íÏ8 ˜Á‚.EÃì,òN<ı˜>/³í@•Í0Bûχ·S_¼I _¾a_´°]²É[`´~ Â*OvÜD0#éZÈŸñl´(JˆõˆZNÊøú/*)ö³8ÔŸlŽ2óô»éÅ´,õd·]uLˆçl€“fž»6] ‘KÐ÷^¡£z™Œö`s0¢4l‘—ÒRÛwÄU)_aÚ4Ø]Ñ0ë9F…”–ªdŸ•5¸òh\¬×IHH€aǵ®ÔM{{H‹ÁQ`‹Ö(|.uoôë±¼õeú?¸Q ¸5ФŽíì¥nÛÈ‹XN¦<¦‰ÖƒH>¼éݱŒ¹$ÁŒ¤cÑ{¼µ£†¥SKâ™$œ$($³?ýbç¼[‘‰lvÄP^°<QG3÷%üvt¿‘Ó –‹~™“ôW¬/ôíÐ]¡9ãpD¨/ºåwœQòqÌ`’|ø½†'e`”¨vy`ß$QÄDQ ¿rA”¯Ë›«'ÈË`Z$™`M]¹9n‘RþkËQ^3i„¨tA}ïŒ\žƒØPŽw+P@<²x„uus!·fƒù•_»•»ëÁ9ù[ñ¿€N J$”“€°„UBiKèijý¢?fJ¢Ìƒ(ö(S A<ŵUq÷9H“—ôz±Ä€Þ‹‡º[é½ ÈŒ¡3rA<ô,{µžlpì«H$Kü¼CÜh$µã/}‘„Ãqòìa¬ Œ¡or-ù—8}sŒµw‹fQ¢¼.8Vœ†ÿõ*hìê™PÄ`U°<UAÛì/8unÌâë]˶†Xf”u´^Œ‡Îuå£à1þf9)•ìz\ZW™(»¥ÑúE„=dKjo¤Þ Íĺĺ€]¾vDy£ôo•ð1€0qö'ÇÓx`§m4ï/pƒ€)Oœ¾y•€ÅX1Íýƒ
"}3-</ž0¤¾È÷
lo¯TøPºöÈoRšû©ª,ÎðQKýÐ;dªµC,õøôô…ðl)¡dvCSË"ïxÀ¶ñ¦*ž ç@ y‘*V×}I¶$tÀ ð| 0žrþ(Yi¢Ì$±©uö$Å×PXÿ_Á5‹ø `±3F{óëlxñ*|÷
%SÙ\Æ÷}!WL & ôÕfC…Œ¼×93§\ÿp“^5— ÀnœþìÃÿ][T8¬í”†p(ºOÊ2HE'ʦ
WôÚrpJˆü½ËìyháTt9ׄým¹‘Sy•³8-øA&(%¢Èb÷BâòÞT>ô‰»GÇð×,Ð…ƒêÅL5w_~cGÿz'(4~’/âzЮãEÔ3Þ¾01ò¼P;s»X;¢³4;ˆô!Â\wŒh_yØs¨^€¢çÜ„µï”\«%”û¨Ro2â\WøCt¡ý.$^¼µ º$”z¸˜²ãP”QÊMKÆôîßä,¸Û¥ýbægɰĨ-¥47YjÈ›$) Ö/?>Zò˜Tƒ¬ÙƒþõÜgöñä¹á£°G+<é!í`ÇO|ÊÛ~žö¨Œw. ίÝüÕÌ·OÒÌn!BiDŸàŒ©{1Ähtü”–£Ø÷g îRÀõ\nekÚWú®ÆÌ¼6C¢9])Õ˜^ÎÆɨ|•É€«N©¬I€éõ8äû'¬Ýví”
äÝC‡ ò›f‰‹æF|âó)°ÕÇ^e3ÿ—WUÁÓIþ» e¶°pIäÔƒ· ó—]‹j)ñÃ;Ьú¶É»2 !y*Ù›ži©žÇ¿°@Y"Ö¬ŽOó t¯± ¯P+„â±}°ÕâI?âËAÁµ,Á•rÐé’ð¨!âå}}²Œ[aïˆ+¬€éŒ2K}èŒþ¼„Ž»g”[ ±ñGÞ 1bÏéP‚1t—˜Æ¢ŒEêßõü÷ð¾áƾþrw+Á7ÔŠ t'
ô§»Ô!M`Û¸ò»0
(ãI§¶*–1=í uKýê`´îi YXüNj©À¥]Üÿ Õ:ÜÐMªŠ¬°î>ÙP¼«ÄšHVUÎ ßÛ;ˆ—M±ôUÁ¯Û‘ àá%ºüà‹+_I‡W#*µ ɪfÉæ„È—5¯Ž+Ü*é¹#Ê ´€Á,0Œ9Ö'*¤ssHÙRQo$>&Lm9füöÖ'kV»¶k6»í8o î'IðöÍ3+†Å77XÃ}Æ15‘•záŠê ÜÇx4|`ú»bÀè
\s„<Ðm¡´=Oh›, hÈþ¬e>SM:¼øk慠âäbõ?§öNÊ6Øû-·\C(z
ƒî9òï‘ûD¹wÚºZWzáK}Þc¬žÍ3½îß‘¼* 6ã`ÖÌ"ZâÇ Ì¢á"¢nx´ÌοW“ï·Xy#Tß§÷pB£#gÞsjüaËãgö#¼Ã~È| ªozL+ܨ´‚ŸMê3©f)Þão
µ±ñþìˆ{Ñý "“q77÷
¥Ì ZZõ6|ì¿"ñ)•_«áSKšeÄFòáz›óÝÖ Ý;Ðý!¿ÖÅ1]v‘À_Â\Õ—èä˜0`Ý'ÜÀÄ*Ô)PÕ‘’¤X¢ePGŒÒA¸|zòÖ§‰ ³Ÿúh¶‹ôæ*A„Cû_)ëc¹ÐsÖVÓhŠúµÈ>„+Ž©lg—ÿÉzÛV¥éL{Í`E~׎•`qË„Fþ¼3Ib$à›Î-,„Üü¯õƒÐàpyè$
Öû)}¤b¶×qã1_* ,Gî`µ ‰…ëñ=. zÂl±|-Ôr9l`ºßùn:–þ´ ÏvË+gÆõl6·]m‹î®Cîû^á¢Ü)‡OO«4)±í@¤=Ù6žóåe¨}’Ë/,íÿóБé'Ùç·‰»OÐK»À ì
vdjél8²m…é ÏeWñ"Á€÷0eÚöÖUd?ô•º©øað£hùxiÞ}3Csk°ÿ1ñ‘‹$¯+Owyùó689ÆôH\Èn¥ðö´âÍYXÉ+¡ -?ùó’€AÐÆ1~ÁŠ+ßS1'sŠéwûûV ÌZ8Bؼ˪ V‡!*T¿`àj½uƒ6LÜ…ÐΟ°Ñx3Š ÎVЦ,C9¦ZOæÞR•€ar¾ñ ~•ÂOϨ= 6/r~µDIò¡’äýG/Ç‹Dmºô_nÛ‰§Q02‘Y³d%Í0…ü=Ååc@ªõþ+,]&]Íd„Ñ@öÄã´,JpõûÔ¡³¬²X \&†žš$NêT_"ò¿'ʶ7ΩdD9Hó®Ú£îó´a.Ø%* Ÿ=_ž…kõ)“O0”æ§…ƒ)󗟱Ó÷ü pýX@cí
w6”²«
ÉÙR¹×î¯ÝFÞ¶¹ª#²«~ÜÝBQ4R=/CèUØ‹D jùÒ½êÓ·â¦ëZVR¯ ’ñܾu³ Lbrĺ’'½rïûµ1ï¯Wk£·CEte¡›PÊ—}rÞau:í«Ñ¬‹è¯SL8âÖôhõêÉvfðšz¹Ý¦ü(UæôéZu,€iNþF*ú0”ô³¼5
üÀ~îÿäÖ0e„Q®ÍÉ$ÎÊYeG‰-GoŒò eÔ
F9u„6Ü]p÷ùqOtû7w×–a”o*¼ÝìÕf@FÔš˜3¹ ôwÊ¢ØhË׬äå
u}ï$ïV õÿ†ËÝ5zc0à”·*}õ0D®Z`¥°”ÝÄ®Ö Qã0y&*÷ýeñ“ûôuïO•2F™~ºt¹`”PÅ!hÌüõ45l Ë:k·Ä|ÐUcø‡òM:®EG¶Þ=\ïóWLÌqëß1“óÝM)v’Q1ݲҼBü˜~suè®Rv©Ö‰Î*X3zþ@>`ú( f¸>„„ð€ë tÁo¸J–L?÷Ï8ñØq-lØ€[î» jEìöl¿®v•¹éÍpDÌIŸg?xI›.ÌLzºÜåO²wݺ#êÐ;‚ Ù†â•y³lÌÜ#dmâÚÎ’A¨åy/4Ékx?\p®»’,ý~éÈš
‡Æ ”¸À’`_nÆpZurºp±’…&oÛçþ3qXý•áïãos
úß·‘íoZñjà’ÝŒ_aé^yBz@ý„ùGX£ÏXåfÊh}îpáéÌ
‡LWþì'P³ùަ%×ý9Ay|lÛÎvëÃVIò@!ÇÅnT”ÚÎ($ê“‘Nõ©§ š¯U Åûa ÇÎF'Ê6D¿ãÇoªõ‹ÃÏõ '’I²ÝÁ¨ÍÇ%ïÑõ¹MÔ¡öžiäõ•¿‘°ñèíµo'fn€2ÂN€ 4A©÷’^–:”ms`ñuˆŽrd1ó§äË!?oœ$÷+ÉQ²±¼Éàªò1µIŒíZý™'˜ÐsÐ<`žú(oWlÓM×b¤Êk:ŸÿV_ L Ü=Ë“¶" /’”Ü+äÆ 0œçƒ´Í›‘¹ç¼á*˜–â
9hËì—ü NÉZm„zóôtp÷è2à^B2Üë3¹údƒÿ”[‰Œc<6ºMþ3ˆê‚pôE~ h– Í!Á‚Š¢XâZÕÏe(ä×ø ð**c°È;õ±Åð/ 3®7ç™=*ùÉ9«L¾ãÌ©öî*tPS‘&Eôê˜v¤Š"8vDuàt ¬
9Ølu
ŒøÃÚ¦QÉ@ýÓCQ~éý”Ž@õCrÛÔ`XG‘²˜ÖmpóHÍQ
íì*Sû/#‹!-øe¡Õó|Ö1üÅ+ý¯p(Ùbßî'³-ÿ’R¹òsâɃ´
5X@)y+ÑÑMM¬
} }«o
Ù/ºY÷üYÏ‹£Le£*G,où…¨*4ÊÊ®ûK.:ž”¯¥ÖAbdû/¤k¿&áÓöƶC Iµzùâ&œóÂõgCx»¬*À=Þ/² 1dœ
à(ä>ŽÊN£=Ã5‹ÿu®ƒ(r^ì¢è
„L§E¾KŒ¿œ·†”µÞ‚ÏVè¹àk(Úv}ÞxIvÓ¹Õ` oóš‚ÿeúrEˆý³À wöÁƒ‚ŸquüòÃÿõ7/GU¶þ‚~’ò4H`™rz\ç
¬©‚H¸W—ÆÜª~@{&å©i¤`Џ6{6’ÂÇ“fûÛ<’AØ<ðŒ+Êúf/çî ñ+3Š-Úâ¡k¡Ûzïé‘a%xµPƒ„áÏ)(`?šìfÏ…ø …íÝñTøÂžCg ÔôÃ'PìWîÈæ”In1ýÎ?×Tüïƒ|àáp”¡<Ãm/dD»ùâÂâõ’! 0aµó÷/à†M¶* àK„a@ä\Á
qÍ3òd æq*—T÷L;æì
µË‡ôù–寥~v”žYqSP:ãÛ2i1#qPF'–ŒBA”ÔVÑÚ#VGÿ ¼õCQœqµ½éò¹bA·µ7ïÜ.,T¬mXÄž ¬]$õ¾4 ŸboŠ/ÞA¼|-¾X„ŽÅbÜl{œìiÙg<âš8höünef}¿ÁjL?¾WDüµ¸´¶W¸¾@ø¦ê÷ Ɉö“g"PiyB*0ŽÃ—YÃáYMN>Éî«¥ú³©õX0C÷´¡Eì5’”·döÇ£xöÕF)dîjb øš²ÆÀ5!}ri«,’åûùBnIŠ\W—Q½«˜¨¶V8B~2yÑ×)±ôy¹¿  ˜½’̲ùŸ ÈàÝ÷ xÁÔµ®?ƒźêá+ÓãÄÙ³A¿ë*¡o`ž¶G¡æÈŽnlž‚F”ÊV<'ŸKÆ~·TͯG$îw\šì (†^ ˜5ñ³ú8AþM©)ý!ÚÍYÄŒ |ó>1$GVÎÓÿø›2(‰…ê §T†„¾yÇÍ®âÅ?`Á…ÕBz
ïÀÀU/ÿÌ{…2åK–BàGcÐÍhùîQà "veƒt|lÜT.n¥0Ðê”l%Gþ‚ˆ9U\IìÔŠ¯V×—Žà2q@”¸N×
¨¹˜©í²Ë/Ì·m|å@Š#åpš$5t©÷5zUÛ0%t£öz¥Ø»¸*ÓËn†`Zñnx_ïTá•.Æ,záɆÃ1Ô$MŒ~²¥h ĨIï!J¹wWÑcÞ ™°Y£xº `Ûô`ªyÓÌx_²×,aX¬ZÒÃÃk³i¥ÄaTw»åˆ*
ºí ýšäUÍÎ7£Ñê‘Å.kã‡ôEÅ`Cxä1 ¸×«ð›t ¬ M…îûLÊ“þk´ÂÝI\H`{Â;p%åÓ‹(½ ùI Óm8ËN„ý)½ñ¤vš³bÈÔf5¥>“À备ôðܤw"ÊM™ Ï¥ZéÝHÕ-,{ùèß üEüzÞœÜh 4›ÌtïPx褣+U*ë€àWfÆ] ñÚ{ è+øÿV0³ LO‹ÿ µä‘ZÁôžmà‘`Šÿ$â¦dý¾ XK†-Lü‘¾
ñ’r™Ç×Þâ¹äŒb~ëY¾Ò9¸Ô…dzôVCó½`n¢´ü
ØÉý§
2ÊP6Ý3Ú-Ø•÷¨†, x÷áçêýÍXF~
ǦšûñŒ KXY¸´9³*ý´3g&æ’`´èc’ô¾l–ÝÕî”’´©U|Óû¸¨N³SfY5Mš÷ºñóu"mÔ&ÌDÇ[»¬MÂ…¢¬KxÇ÷Ôqmà*K'ØäXyC2Viý$AâÑË”_Ÿý¾éÚ¤ƒEÀ*Ç™7†Só6¡¶4B’Þµ¾”ãFøí½§*
a½Ú Ú © }rˆ, ³)RÊúyë²n6+ÐôKíÁÖW½»áPÐ_úML↔¤'qÍyሴ8a>ÅÚj6> ðv¬Õ‡‚‰Yn«!
*DP™*Úæ'ùãùµ¦O¡É¼Ã4áËuH#Q÷ÂYpSs®¨LMN´g¼ðfL´•Xm ì4›“¤+L ÕwEZ¹v3—ˆÜC.3Ѓ*_Cm…ˆ´gŽÑŠI˯t-âëØ7ÝíГì{«
jQ†BRÑTs*‘Xóz¾ô¼¢â“Nôz‘iûc7ÒbÕ¬Ú¹<{g¦ÒÀ²ÁXtp\žª%¢ÀÛÍ…Š€Î3ÏOèÝžwœŽNEÀ£[Ž^ü+¯[Í[•RN/ˆÓ.*W\ÏÐÂ].òÀÆ Iù.¾>@ä‘pŸƒË%A”)™×Ps|éu]e£1 ¢‚&¦Žv¯w:+;s÷èŒâñ¤œòö˜u2âÓ¡ýqi ø°éi‚ü„ƒqtÁ¤XÜeû a€ÄÑÃx³ {êt*døÃ©En ©¯&):KüMúõÔxdfÀZbÎjÙ-dÂù÷6p
j{â Pi wêÌÕWdö_bxƒñ ô"h›WN4‡Š>çî“—º¤ Áw¾àÚj6w~ë'žÚkzõNü_Œ×&µÍÔXÚØ÷WêÜèQq×y"¹LÏ
–dñ… rùûH5™‚0Ÿ¦iÛ(1¼
ö¬RÙ ï(˽¶²œ[韛Nî5:¡˜,y+ TÔV´d—
ˆ/©j&3
¿6¿Û
…6ɱ\À* ºÍ<N{‚Puö/¥#@o _ŽËOîÇ;!Åk?!øñ—&4—úŒ(@äÊ”ãz øálÐï< ûfp ýãræŒìpTl{y„ê³›’N'ø oì÷»uíDÕÐ@î]Ò~lVŽB‡ID¿€Š‹óäv¸èéhµ0*Ñ ØKƒÿ$»`‡ËÈàë®PBnù˜HsŒ¥Tú$gc§÷©A˜$@%sftßm–Ä[w3}l¡eÉI°‚\ ðÂñÈ ûrŒc§lÂ#0Ý8Íû~V4Ú/lK<šV¼ ê.ݧ¶s6ÚôM\F0ÅUñ€àŶª‚D—ê™d/äC¬wàÁP#Ø;XÖèòfì ¥ØÁ`±å’ êmžan÷³ós’W©‚<>Úf+§5º4Ì1 vƒé d¾ô
E‚ëº÷v%ƒÅÆ}PG\x°`©ðLÞsN*P”:œèðÝɲD£kÑŸ)` CÐ(Pö5ÿæä§›¸Â˜Óejñd%ŒF¿Í¨”&ï$2‹(0S•ümÞ+ý¨í^H“p1‘ÆÐ¯,*ûÛ8vômºXg‡ßRÿðuÕ«8€™y±(1mO“_€ò
ˆ«ý[ߥ@(`PvQï~ϰë} ù:nz0ìe¶sòøú¶u3BÓOl•6*te4\ùÆxM°Ï0Œá®,äfÕeã× ·sª<T‘P$”“ÖÁQD`Á`¦]5Y+uø¶¬X§d…÷¹,üÂÒOÜD¨*Ø uZìñøû˜~÷ä^üüK«-ÇɵÅ!Ìñ7ü5n
niãÉz>=tû.0‹šT©ÓwbŠuâmvÀf)´ê\{ieMÜ)Zðg õ®ÿÀ¦’ ¨ãÎ ô
ƒ£ß6Áòî÷Ë/V,_Ü쾉ͯ:D»èÛä16¨Žr-zÔµ5à+H¹YÈ£kWïíwácD"3«"@- CàLT Òm(:f*ë}Æi¢‚àϸe|êv@ÓÜkKúÓ“Œéõëmþ<¯ä:`}F©7>#×ô³xÔF,*QU¶Â'„ñË}{å“]
) »(¹ |,½fåEˆÏ8
Øø{þÑ>š²öˆ¦ÕžtïÕ9J‘S‹À´‘QxDþ¼°i
Ÿ[Ë4tg—Aü,F@EíO—ö7sñ— z£K!»¬Úæ¤{ê¤ôLnÕÈ[a‰°în·|²w°§BíÉI…½´¡5Ï*ôc~÷vÕbà€0œ /€õÁp°TÎõ3 é”hIù%mMâæ^á3‹Œ!õDZl–ògÄóèË‹Úòð8â'zȘfLçþÂqt]ÃAi^âÆ{Ù9ûås!u@0'÷èkã!œ€¼´¸¦•cˆIvúø@
HÛT³¶ÉÍ)"÷` ÿr¿ín[/
ë
§Á¿Ä3ujélov °¥A§°’‰„uDm#Þ ™B—ü‚*å:Q`´9²½Ñ<–dF©hs½!xê(œ<J&@4åôU®šãŒÚ³n0eOÞÛVYj¹‚U#öJçÃÔ“Ø›/i@…Â…ZRÎŽäÔìC:•ß] h*5np4nFtJ¬hê,¬´‘¥ÈŒ±í׃·kˆ|Æfů#V S«Ì AàNpxû¯±’¬•-Õ=sR;¸äËÆímgƒzEþôÉÆÌdÕC«}÷˜«tÇÍ&JúÙ>`b´Õàcô!;<¼ýUa"Ûl±x¨
dÅ\=”3&Ñ…%3…@ÊÍ3Ù]bd”wNÙôK^!îí)ÙHsX<à„MÙÛ)<_ä+R§ªätÃ8˜,˜/ò”Üö:õÅ]¸LÜ Îè4Ø´*!#r)Ï 0*õ¤lÃ0…ýJ¡ †[+’ÉeÑ÷ˆ#H{µ”è¤Û'^ú_xöܽbpÝ*Ëø1!–Y~Æã¤ˆ†e z³õaárd߃/®€·$d3ä\mÜ{”•å^hspN€·0aUÃÂx|£y)ì¦1YHµlÿÀ\xˆ!FÇUcËÇ”`£ÉÇé H(©ìäÆyô”WcHI{\X-ʈCËÑô”ª²Ü¥³Ñ´”¢ÓDác®¸…ö½vH³Iã® (U‘8Uó£z›¡Îà´ h“
9Fˆ±ÙEua2ö ËoL(¤òá¸YÿÙ×öü˜/m½ ]¢€±áÿ4¹iÃ=¡ãŸ^PíXhÐì(¸~Ôxõ(-p¯ ˜ˆÕ8ˆ€Ã$A˜~ô(õ¨-¨«¼ nì˜Á¯Nmá§ZyÁ£DYy×n]ÔÏ4aÇVåpn±Ô÷4õaïK¡ÁïæI‘»m“˜Ö¸q–e1ÙF}åxþ¸ª1I¶0Ø…”M½ƒ-¯pÕy0(n¬Eü3õm¼Ã¬‚UÕpÅÕN-8ÃÈ{4Âh{t'YÂëÀ,,ÕX±Õ·NDÃH{@Éè]8KèÌ/Ô˜l:žNØÅÜN|ÅàZ4ë^‘û耴ûì€\«…y›0xn$Eœcõ=¼ëü€@«Xuyó0ˆnÄE¸“õ!¼× €l«pey?0-˜nÜEüƒõ5¼Ã€\«(Uy“0°l˜{ÌÂ`<ü õkrrnõ÷ŒºÄº±hîkáw›YæûáyƒÎ\%bÒŇnsrº¸Ó¾_í[Ià.Øñ>=Ñåôà¶PRkex\He²º^>¤clAuv0cXØ¥)»òô
„Ũ¿·ë´*„¢ÜQc{Ò²´©kw(xƒ %(¥ì4¥O8Õ'Rlã°ß&¯E¹ßü]}btŠÝ¦}z°¢ñÁ%ô, Ÿn´Ëaü4*ÀÓÔ ³˜¬>´;záì7}Ž£ š¢ŸË«j<d
9{ªÄ„ç€Â±ˆÍ.ƤÈî(M³È,V š#h9C¨øuõŠç_[—0=лmgç …¿×cH¾’’68(,´õžx«£¨ž¢®Od¼IQEÑ»álá$tÇtÐêìÕ ½5Ã.Tö4Pg/¬…°£=Šw¾„f¡ÂÀº¤Adµ¼È¹qßNXvb«+-îÆ}ïrÈ{†©Xt¹à^µ=ÓºMÔZ2Xý/>¢¦%[b«À’k$äö½V|E&Šï àÆ} É[AruQ¸Ë) Ìeƒ¯ëFѶ⸠•|pΕ*ƒ(œõe¥:\ÄØ®À àÉΫu;³*" ³7P‰o€UNèÎ7/5j@µ6kkù…B®ØhÀ™ (õÏ©‚'µ9´*v+‹ÂXêñTó]sŒ‘¸/”ˆì &Xà}ÙÙrñdôÉüÔõ"ôÃq¯»Â®˜Ë’rgÕjW;"»ã¸³´)€½’ö5€{ÖùÚ¶oèHHAó ÝT…×fÌŽ ì
9Ý*»ØŠÝ êöÓ©‹$üæ©W‘ÄÍ@¥©Ð–¶ÎoÈät…äwº£êí>vn¤°ðMƒÇ¬1t«ªè«ãûs¸9¤Á:Šõt|Jvˆ¸&œ
wµ0Jæd Ì© 5èã“–ìÆ‰f9y«ÞíÿÂcdÒýEþÆdì/bxêïb‡³Çô´Ç+ì¥b*ÒwhëÐöh´OÉá\ó—8ÿV+&îzuÌ€›~l?}&‚?Z3–)%KJ„͚̔Ë
‚…µŸ†8žì^sãý”â«Êf¢asÝÐ
eþ(úœæk:×ÛóP,¯ö {ö}Û8HÈa"7c<]‹ù샳›Ä^Þö]TTÁ#ÖÛT³ÝüÞÜ£/(¾Ë+>µ¦2ÑÌ-*Ï 7Ðk?#b¯eážö{drú*|—k|µ¦zelLˆ…±‰Á‘+†™kZ„ÎÑ-T “(‚ÿDÆ©sW¢ÿoC¹f¦&,4†Á° ¡tž-ðÐw6ž3I®ëÄþ¡-`°ÂnGƒhõ߬P î©„ŸîÐò ½¿2Hsj°0+²¾÷è•”a¶Ïæ4ÛR™w«®’¸»’3ïB}âó
ñe¶·]žƒ\áÙ¤ûÞï£Xºõæ; øîdôùb}óz*Ä)y½4nòÖaMìù]MòÄr>ãáAÓÞM0Á¼ù@Je¿ÁàÒ-
† µYÒTK'^ͱPù^ÓGh_„GÍO†®B舯'_£á‚÷ûª(] h¯µi2‚(;Råè³>U^cózRM©v›n“Yh¦í—Rvòîe&ýáºLùÒwÃ(Œjt+±q¼èðÂu5ŸIw<"ÍåТaq/l 7¨q°_Vú×»B[ìff.`*XV)ùû#ùË÷ýùp?ù ލŒqž]9{
† ê^?·ô•G¬…ÀÚ N6ÀåMøÕmgcþ³–À›–4ܱ[2.‰4Ux
tæ£0¯£6h\· }¸O{\ží}`·@üåßf€ž+hh´°j„µl3¶´…gÍðiˆ§ }ø‚kãö~¼p×o{ö99Þg4Ôpï´q—aɇ`Q~ ,*¸v<ÁÈL{ØÞ\èi;» Lõ i;áÓíÑ87˜Á‡ß˜±^¤ÀXÀñ»” N¬‘!\³ñɋᥞ24dæá9_µ·Ÿòž)Ç€Zxï_ua“´a‡QÉ·`A~ <*ÈvLÁØ\·z_3¡…%”Þߥ¹¬Æ+“»_ÿ7îÔZ¬Zµ_ÆÈàòÕ¹æØÁ½ƒLpÊ€g”´Ò>Í£ç!¼/À÷¦KJÝݰ_I¸}«}QËg’å]¸Y£ÃvI|â¼T-Ï9ÇʈY)P=Ùº^&4Ñ™ÝÀ%A]a§ÆdÈdWõ»3_Ì0FKkƒö
7+xFä&H¦w|òèó pV;oêZOÿi:+XB²ùGAIàý|øT}âê]>æ_¤üìòÌú¨¥üEéÿ€'ƒ€öoUÇÞŸ»)¿´E^sH`RR;|ò U•±_Ð@`–°m²ÞÈP‰Ó¤à”`+x|à_Ôµÿcôžµ°N5
Í6•ÌÙÿYÝÈ}µl§ŽÈåà ¿•hOÚ®t
š›2óÁm>õ ²© æ£{ˆÜ—HƒI¹ôº*à=¤â¼g 2ö“8Š‹âpvÎÀAq¢nC6óÝqš³â†:*ïB%]îË£Û,cÆ;áîyVÙ“™<À/76P/'éÒò²Ò•hZíA*×stºë½0$±}{W1‡kQlß?-ñ“adí~c§\ôp…ôK˜•Åv¯%1cÁ.µÛÐ/IˆÔ^ì sk ܸ²¥–‘ÌQðÛpHUEÿ¼}ñ”sმ¤†¤k~ö–gôù#À9†‚
¶v|zÄçÀ[gtà"uî½ín™iÅ"w®üç ‰zá:xà;"¹y—æzlÃwYºÖ+ÉýîsŠ&…±ÿö¼¦û§Î ÎÀà#´GÄZñÙÍ{§Î;÷Î*°Ðoµq¦nj÷Ù „"åÓͺe
RUõÌEÖà4èšHzê/r ÏórH°ÆºIs~M—QZòò¦ª²‰«ICBÿ<!åÈ5ëº}"§õuÔû\[3 8Þÿ‚´£ÝƒH…ý¤ãÈ7h–u£D9˜³3µ·¬^}Z¹½Ãݱ£{[M;¢ã†¿Ðµ©¡‡…cp„õ㳃ù¬4³S]vGKq†(.‹Œ‰æ0{¾äuâüY\VFV޻輜æf†©µ“dÝà”qàuèøOlYÿ’<‚**—kølˆL¨â%læàxþö²Îðpµ^Õ)ýà€]øél¡óÛ6§¦¾Ôxâ¨|C•.Ž1cOvwWøª½ÀªüÛÑÇQ©þÄ@KÄGiÌ1”õ>n€ìlÒ£UsA^P¶@c ÿ›€ ÎÚMìkeÛ ®¾GÏ¥ÙËñLHËüFjJàUç=ÓôÝòö“h€õe1Áâ÷l8ëlƒ8ïm‡å
}ÝÒn XýHÁüaƒÅéWc¢þ_ÆÎp_æZbÌP¥òp.k8
[r¥!xí;«Ìé»5â @4ùëúEm¢ánæòWàýÞåÇcŸTd0™¹ìæ‘N@äõîæû[jw°¹–ôOÎÆ% ðhoæÁ•ÿW™„yEû4Ñ+žRòtI<¥ «$ʨЇfÔ÷€ßBïdd”¬I«„Þ¶ (4Ÿ° çA" ã” Ÿk¿±ˆUÀÊŠ½é&ÐÀÅI51K)¿l‹ö—hˆÿø0˜ûÿÌà _ÏW„Êc£~eõŸØc'0lœî=ÇäºÝÓ O¸Ó$ÂCÀ"?õ±¾>**ÿ‰®ÓÏ*Îkº97¤p +Ü )à]m»5°·íÆY_…2‡ºJàâ’ÇøZ½³æ¿»‚¦øÉäâÓŒ¡‰ùèâVówö;³üEú=òûy¶×Ô>pÇye¡„ÇyÑhg„Ïr¬-÷ í#ŽqËy¸«º>p×y·'»õ„Óy+áÄìbˆßyc–äôif%Ì?yJ‰Añ§y(øS5 „¹€3Ä“
’ÂbÿJR³F¿uAø™›Þ<ºú'Æ t7nT”ӺϺ ›i¡½"/Û]rš 8ʹ!åzZÊàÛ’Òª§“TàÌSßt<b£ó _cGÏd yˆF¤ft«
8¯îJZ¸yï=]ft¯&àKütfWÿ«‹ wê©ýŸc0zõ
hSµˆøA– à\Ñ;çñS€¦töâ*2¥èÜ€'#惼ÍñBtt›pm>0
¨[ôeØÔ`§¾ˆ–iŽJìü¨î¸xÔ~×v+ô†ádJ÷VD|5~Küß™h>ð2u#úö YØ6Œ¯¾ Y(¢B˜›æŽØvi»\ŠuŽ>€[÷Œ™ìs™U’Ø›†i2["Q
Kæ‡j™
íù93 w@¥žÙoxu
‡0 ΨЌ<»~WÒ›8›É׆ñä›ÞŒL;•ò*¥4›ÌÌ7Z6“–ÒÊô^ ûQzµt.?ÊJ“<Pgw#³]v¿ðÕñ²"}`0~®Ós׳ÿø;u }h²o0Ptv¿åcªªW%R•Jøàð†îÅühÓË!î/šˆæ¼øÚñº*Ttb'#æ§FŽORt5}`P÷®cl•üîä¤}_ScˆÉ•Fm¦©øý0þw£±‹g<Ý+´toâÛ°ÇÛÛ0VЇ˜#Ìúâtx-ñÛD”Q\?zºŽ«×·p“˜9?°@ŽÍ´„b¬ã>ºoç»Jàæd*µ€ry÷×Äåd÷,]ä ì‘(;¥÷Tr x¨õïtƒjÛXBùl'`CŠå…‡È6&”œF
ÔŒÜ@†Õƒ(
²ùM¼¹>ùn̬2æ1 !yì‘Bt](
ÐMHHKoJ Íñ[³‡úµn)¯éü”p: XD6BÇ „ÕÏ´ì0‰sœþ½‚àæ3wA$¬£Ù™à»\
Vð’ßYXÅÃ¥{%(Cx@F çÞ¥ìÄ8Å´KV&´SÔ j1óŠë)oܦ{Òƒö¦%׌.ÕCÁò¯uŠ8<í²wÓ‘¼£Ê[ø>S^Ç›Mn©Y·¹»hÕN¼a0Ðx–ظ¶Å O!J V޹û^¼éÙë2;¼N>br m³n xÔ¤VÜb„äXîà ÁGïŒÉ{´M¬
º·‘Ä+Ü’uÿؽv5¾oPåvÑ …üàïÔ<–3]dX^
ò×÷]4ä« ,öi÷T|U–ÁM#¬Àçã Jšï5×?$á2„ÔÈÐ<#S8)xÕO ÄÒJ>ÈÞ=Kð¤8L¶ 4C»ç0D¾·-[£³,\
¿IPª •-yb
jnÆ”Àl +}ûç«®Êó`õl›OF*„ìyÀx[¬×+dàrÑäèðoJ<޼û<27‘ËÎÆmÖIWäk{2(ï4vÑ•ø‘¸‡Ûnßa£i'ähT%yz¤8÷ãeG›1DM.ãæ |×z÷Ä_—<–7á]øáj°0Æãœ'ÛâÈqîÓ[sÝå„tö»¡Q‚…u¥DÀþœF¤ ›#¦ö¥P\Ȭ’öÍ:»çƒ|"®:šþûsŒb½@
Œÿ/Ðÿ£Æ‚•ÿ)ê¢ ÒjÊŠW1^ËД {Z ~ŸÚhWɹåøÓx¸TôWV(¸¥/X‡®Tàp€åÌõ^ô ]OJ'¥?Ãr&ð“MÈâ5}î+ „¬Â+/û¦Úiî©c
ƒõ[k1Sd¹ž©!äæ¡çgž@ªhâõ_‹®¸%^wsl {'Ä}øÖ Û”ì·? 4+ÍÕp8O†&Fèüè󢎣úì¾¶*W¹G=J·E[]ln¬A¤ïð”(¡Ö^zsÆj—d,£"† c|r®§¡ë¤À™ßˆ‡zñ}ƒ”Kް„ÍïìzÈdnpµÌÿ¹’§Õµ;C5¼L@æ÷Ìõ1~sn62
â -Rm</\ý>÷;í è=ú[Còžù  ž`®D}›Õ܇©îBÏ*‡ÆAÛëI
4ìT¬†XyÙEmø}
´´`ÝøF™Ž¾ i=vñ%Y‰2¸O—ˆ*àÆc³ëô
œcž&¤`ùȦZL”ý–[JÖÙágKãºá 'å@3´í9Ãûú7à} @ü
ä®—þ;ùñVsìØã]'\“W¶zwS,÷ñb±—útN_» êÞc{–aXRpŸIfžä˜í8õßð9úW%˜È\õ~·¶í‚ï¦ò ;ÁÆ-ùBæþÄ|•pLzúûìŠïÖeB‚Ošç ã0샄âîµhÃŽV®u@ÿn wðg¯Rw^Ô¯XïÛ³q%øa®Í:_=Ñ÷GÉÎôs†1BÛäåtN8EäïáØå#5õýâ»Læo*¾m¤I1èÓÊ‚ÖyöÖ ˆ°Æÿ„óáàvj2Ðåd„Íßèvÿ|¥fõr-e*zº1؈©MßЩ„Õlµ™ö:骃þ¡ñNµqÖn³8áýìF²ùháˆ44*ðyhXüͧéã À[Ô…2èw•¥—lÞ,'ܯkפ“Þ6¨^ÝÞ f„|2oš‡9\èâ€U‘ffBl4”dßÁÖE÷C\2õè‡ùì2æn·1~ï†a~ûÆ£j¯—‚°<tX´ÄÇÛ þƈîÃ뀼ï9
}ƒªu9нCÀÔù"~Õ¦êoà˜ëõW?³‡Ú«€ãØm»°g³^vˤøiø¢uÎKÇm€¸ã®SKÞl d÷í¼«H(hR-Eø”q @f!Ê,šâxÔäÃÉÛ3qm¹z*#â®p(ìë'ü<ÙýG70ð‰Ô•òÔtH漄&›z÷—”qE†Ÿ„ê
¶Ü0‡rÙ–Ó‘Löt¡£‚ ìpŠÜówÌQ5ñŽï:2®w=ãÃ=œC©ñÆ{Á@¼‡î÷pG'uìá‚rXh©4®ôH–höñ°ãúŸw7óŽ÷2O%s]…wsg(|£hEq˜àHþè-©ò |k%ô
ä[|ıÍ8Ï`‹†}Ô…³]݉ÇxälµðãrÍFûX‹†yÔ…rø(êO

Ü[|ö%ŸA³ÊÜe
«Xk]ƒf¦L2¤CðoØÐÓá£VklÙ8A"HÈÜ(¡|o™øí\5mNÖy¨µë…Ñ 
ô
Ðl"Þi¦`ís ôk ôÕË{èPŽ2œvAðIùðù#zй"˜ÿ<¿²ð;|é~fGÕ‘†VûþgÓ5Ž…B {wh(ü¨ìG%Tt‚4ƒæ1Mbl!¾2É+{>c£zÕ¾¿.‘{ÆœÍ
“µ‘˵Å+pøNœ|wXG%\x… p]/Zìm@H/D.šZì…•qûÍüôɶÞó$…4‹Ö%v Ä)ÐzÖÈ|£×6ÐÓx o+…u%ú¹¿´Î…x2-ô
¹[|Æðìã‘Î k^KiÆ„Ëâ^E9ô
µ[|÷KŸ uÓ=wd±[~ÅÍôã°…´¬¼?®öØg•'ûôi4ÛÜ(ØxôÖÈRl‰f^òHÈÜ(Úvc±Ÿ:Ï\¼îÏý2,hlíR÷uÓ'Cø(ÿ*ô
¥YtÉ:“4ýÆ{Øî¦ÒTc]Xg6H
:,€¡å͘]Ý
¢[sÆîÐüã‘é d͆àzÞù=ž*s¤¨»Ôî¦íQdŒiíÆ×š˜tñžàÛ2Üãø<k‹]NKÇt”Z
øK¨k£zÐà°LÜû+•E]|æöö²8û[cfÚTvë
ÀÂ}´çñAÀ˳‘¡j¨)ÀJç“àèm¢K/h.šú£SkÌi}ùì;\×|¤¤
¶p
-…6Òì!¾2‰!|ù>§4ÐÀ{ôî¦þPkSŽ}£\E6…àƒÒ¸v[`5r‘‡¡|Ä Ž¡ÿxä
µðZ–¿ÐÓá£km²\÷þuñNðM ßnNMÇP–Úäðño¨HøÙ( |FJ¦ûö3´y‘ø™6{iJ« ‰Oy×ûÙ&š…L› ø1ûH-ñáBGö·íدtÕ¿pô@ÃNËe4ˆ
ußëœÀšë‚Ó[:2¡F¡Cõñòb®Òd´IP=7”òØoJaÞ>äöbÿ»÷‘:B…ò@U9.Õ8SUøÐÔØcØäc | ó ±tIô‰”žpEZ“o[{#šŸzâZ@öä©=8,”)³£WâãõÓïÚÅ?M?Û«,WN;:‚â+âªoðÒ¶C f^îözï'+ðX`O /Ã]¾··µß€ëVÑ ïù”ˆÆïõÌ÷Ñù÷Œ«Üb±¨)¶Å› ÕC®ü´øøÛ+¢pnâáô ìØ¨üކàMù²l˜éõY”œœ¦á]ZY=v¼xñÉJ¬~åR
V<´¾I
ö+cöÄéíç3p¾TH}$Ýϵ8üŠ‹ýé…HãÁäùì¬|Üo•xÔµÁ®‚8ðÆñŒ ½¸Ó©wuõëƒÀÏ訌ÈÑÄYâôÙ¼*1p
v{¯þp )ëk§8áùÖƒèLxsA¹
—ɸ§2|?STðx.:ª,ñöá ˜{´f–ê‡ÐÛúNî™ð>êJVGB<8OéD,ÀžXûì¸áifòY”d¼Eƒ/<”¢ÚÙܱEÿœæ¡e hTê^fr¾@ÀÿËEä'+IK¶®A,™-Èéïí¥Ã.ƒîc{ÿ¹Xø±:]ØÂöçåËp{*R
0Ö¥<f†›à
¸ÿtC²/X x¤pkŠÂøýÎÑv‚޾ Û!ÐùóÙ¯kÏ$@8l+\&Ip#ªµläúÏU\²óö#þ÷o«ÛvBéu4sN ëÔ~Å÷öO×>äeùóþÏ➼ɴj¥³µQxë âÄNùòòjAÞ³ÿã jB#•Ákâ#èÊ£Òtƒå8eܸRªÀt^ö5ñÄ=¶³ã3O(Œ×4¦°>C5óH±¬ðÆ‘‹ÂÒý y¥?—F*±FÞ …Ç*ãŸ@uS&+Ú^ãKþhb}Þ©„3¬Æ®òîu·Š¤þ³´I–Ð:ÈàŒS‹ôV4w‘øÕh*ÉF? UÜ‹öà'ZydòÝ™ëÍð(²o0÷¦i]²
‹/F~Zþð1´],}‰<ˆšÏx°´’ƃhŔʀdÒÂøûT@E”±d|µ¶ÔÝHRóæººÆ3É’¶¹tið~bcJ¢?3¾ÐÎ aÇj9Á@žZúB‡mÜ%½‡uÚ~[DîüMéo@åÀdpž-6
¥É`ùô3¾x84K7{öT6ÇÐò-Ýu>qštµüz®8XdÈ|¾vÕ)üF$ÅËl+–®»Õ{¢4i+w‰[DêdVPÐauaºjRüý_‡D^¼¨;à}wï1²ûd¿S®Ì Ñ2@„Áª„oUO:ÉÜûÇÿbÞ¯å”6Cw•OV+pš§
„Á…ÚGÝŸÍd¥ã(1;
H¾<ßp½#Q‘˜änË«(Y÷>|âA2A>j „rYzî\=TË8Ó‚n ÃÄÚACY÷ËøxsŽQöTøÒ5jï´[¯AJ˜Øÿuɨև°þ·»N#¿BlÉ,àßZyè/×ŊعÄwÌ ´4ìí¦ñµmÂÚ_)9ò¬p͔ԼkÌáŒõ.QNe•ô ß»Lê>µ´z¹oŸ…2ù©ÈråùXQÑJâè”ÐÖæ 9Q´â6ÐLm¤±;
Ãxuæ f7í>;âïXÄä‚_n/Üb$ Gü0v ×[ä´álÞQ┚IÑ ©½’ Åj‹.<3WkNå~ïN¥Þ°ë!76è±èF;/Qx2…aêÄÕÓݶ͜¥ý nyg‚\y_êù\>Ù#ÝYÈÁ˜Ã× _Ònö{õn ž¿><1
„ï]åTó*`ÖuÔ¼ÇÕ=ˆCÆÄ÷Âc˜ ùùĹ?²Ä‰p)в›îÃÔ–®{[ÈüD,>î˜áSA\׊Ìg^^VJ!H‘/(sƒ˜²ÌõUŸDµÅý ·ˆrô_w·*z(DF%n]ÇÐX+»ã-½ÌÓ¨4UW²"½º±&s³Ä+ð*H‹wáÕ°¿-Wÿ_¢Ô#l×9PÍÞ¢5g
+)†„™Ú3ˆ“B da(&¡À`ªjȈ’…—4=Öê¦;'ú *Ï1â¶ÝÁÞ§u9IoE²Låž4ÝeÄ›°J&j/¿åm\¢×rr-?¶÷ÜWγŒx£5%àVü>Fq{$~çÅWìÚ
¡x%ëkʾfvh@¦c[_³ïšbQ!KËNZn0уú`<Ò$”ëöæ³fm}3Ú-üíÞ®Gh’! Õ ôõ,‘hng<Ф ó>ºMÃìHG7X~¶âp-ÿb2ZY÷ ºå<µçÓ#ÊÝ1zýÃå…_ŽìÖ)ùž"å´—ã´â¤qkNâ{âP¶ÕsB-0>I›Ò *q%!lõÖÓ«tË\ØhÞè/zRH²ÖR«æÞ9fêl×ʲ¨,¨ÍúqFh” |ÿ¬K>}`O/uÕ²îÎï¥>ÑçêY¢0©¬
%ØÌÇÉhG u5ÝÑœ‚õø„äÙÁkàÜ¿Á Æ*®_*’úqѹ [:Æx-ñÿc¿Æ·/äuIÐDÈà!ùKD(GBaaâ·’)% y¨Qp=g»øáÑ5y“%Fña¡7Ã’‡6ÄÐC.S/QR]WNÖÙ,’¦&e1*¢±LÿLPlv>@%ìœÙ,Bg¿»¡2èòÙà(šj>áZqõO*¬³8Í!àž4E˜€xwóáö°¹‚Àê(Ž$;Uotk!;]Q5 Á„¤å(8#ò#xH¥³ûÄ–pè]æ(Æ®³+ø6˜m>6D>ýØ•:ÛºÎ?«Yþ¬Ñy(OOt[¥Z‚µª"D¼eyÚc;?ò4í»3àÛ¯0—MÎÕÎLQéøt®&ÚñHh [zÍäì?¦iuU{Dl|,¢Hd#v(“÷´«£°+£ö¬ß Ô³4ø±?Û˜K#FÄÆø¼8áåR;ôTöóâk°樹ŠÜuMÝÔ3ã‡M
„ ù¢f“9ÌÖm¤5@ß*]ÐÍ*ìŸó-ô530‰ÄÂx¤ýª¤pâG $µÄÍ÷¤øf …¸ƒDç5ïÃÓüy\ßûºp|#é MBÀ¢KÄyqSu^iNàµèË_‰*O F‚iZÆs4¯cËœœÂ:¡T°¿pîj'§Þ1õsýgóƒè¡ÁàÁøø’'°F*ƒöoHO¶Y:ý\ÈñúŒÒz‡ '{,ñ]"×–m#K(l¥·ÖŠDö$g_ÝÞseõ7tA·æÐÚx
À—„¹Aq¼b£yDÆ?I 5¹ppni1Ѱ”žÇÔú·j”È€²hìåðà“gº`rƒþÔ'Öx±‰¼å}O
"à <ͰFXêiëz„äµ1Í+ö}³å`\oþÃ5ГzÙ•ñ:c&…ÊEÔí¨T_56\³Ì,ܬÝÔ‘Ø„A‡;its}¾Ê@ñ)¯7´Ïë(·¬iWâÀ“îÅÁs{Y˜6U%t÷
…bÜþ:~ÚT¤G›P¢·k~åyG¼ÆŒÚ=¤ŽékrR°™»ãy9‘*ïkñšº£Q¹ìy×gõa¥4|ù•=9<`vªl¯o9hÒ¿mjZÖ¨ä'í3·»âÝ ê}ÈÍÝ•A‰.<÷ú1z™
Gïá…$H2ÌUÎ-ˆæ´sχõô—Å–)…1'Ë—Êâô¤Ý‚6ß„»'¹‹™¹×>´£~ƒ‘ó(£ª`ï[²ø@'"Vš¶;‰o¹LV.[±ºˆ5ÏypgP¹†z^’©8wÉ›½  –q4ÃáÕO<¶I!úYšï R{k}º€Ô £~_ÄÏ XŸu\¯ À° [tà—¨íb<\ÉZl?Ø&œ…QHk7pÓ`€üŠþÈ0\I¤ÀÅöžû•™[\¹|]óûo¹Ÿ¨žušpÁ—‘nKî,5g˜§wá+jêTŒï|è©W_£1JŠú™<X©©æ}öå›~+§ÄpƒñÝ~…è@ Pã=KËšÎ=ySÂW}ÈY±AØ4Ó$P5‘h¿ŠzŸ{6í·hïþì:nÔ#ÜëÖWÇÛ3Vr[ÔöUñ_¢;µmê‚÷ë \K(Š{u.=þEÕM—2§d óˆð¥IûQa?õTÀç@msÕ~¶ù12/€×t‡X—#D÷ܰüÌÜ.zë93#5è2ÙÎ ê™Â[b/º˜ømühãðPäEæqâå yíÔÑ(B)ó!t¤[†LXNÎI{áÞ·8-Òôder[íIzvu5BM$¥ì+@ªµ1Îç¦õd@Wqd¸¿ŽÊ,ŒdäUg/uù> å“
<-ÛňXÚg(Ëhv{¬ý(åOc$fá9´ñ³GƃÓ6!tÌó>4Ÿ#ÿ÷D*.†p„Ì·RíŒy‘‰²û='s§BG˜ˆ‡2VyÞ<ºÉù&ru?»óÆu`ÅÇìü
µaÇâSNîví(@–ý8•
Öú¶Pé;•Õ.ÒüÕçRÕƒ}²ýè1aÿK¸ãI%ájP%”?/·ÿ1rö;wùÛ婸~žX ¦sN.íwáI70·Å ~õã”ÂÉõ…Щé•ï6ècëòà)ÙRë÷6àµÿ2;¡ã’뉥`¬îÔ@%±@rœ¢ÝÍá©c#mô:zorø;uHõP@rœAÊž¶Æ°¬g¾E ´XÃé«"QN-à5KXê»v._Âl<T µ¨r+„RöåÇ5_ÃÇkòj(„5,"jiŠ/Ýó¼\/½Þ-¾‰4†FK¢’5ÜÛzê¯ïü¯˜K¿RÚ}òC;ªHõ«@rœœÊžsÆ™÷˜K6âFÔÎÐZ;;Kcý%Iv^Âôù¢ ÇhsšˆÉ…£
ˆ»8w‡ÜÃìÿÊÆYøŸòJì¨V™‹Eº&Ä ó%ƒ+¶BbR¥Uüè f|º0òt¨
áŠÓŒ`[óù§¿\’7õç_žsãÀ/÷Äs–*[;ÏÀw‚„·ž©üìÑ+ù³|*Ç‘± ÁÜ_!½í¼Ðÿ+Ÿ½ú)Al`’ŒžÑ:¨Y3ñ
F>%út%6WFþØ@D™+®Üs‘Ê3Hä0Ü™Kë®ÂwÔ¡FjC~WéÂÞÝoŸÐ`²àª=£òrÁÖNNìÄ€c¬Î•vBLÂ>PcÜRØxÜKƤ¯ó@Ô´ÃûvuÏ%ÒÅuO…‰T°’\,ª”´v–á+”~) ꜂'&{uáf0„XM¢þ„ïÝ0t©PlǼ}ú‚Êh„jPLEì ñï+OYÿôád ÿcuJélº"ÚR±Éé
Hó/´d «»ÂtÏŽ]Á¡µøÝ÷"›ñg:÷&(cùyåòq ¦¾mK%2“e3/@ÊÂL"áÛ—^ú!zʶ¤ZCé‡jË´Ø—‰ð…«Kpåÿ 6äf¶Û”‰mk¬K{õWÔØÜ@°†M!Ú%8¦Du÷1WËóv>€úv yó¨¬ê2,øÚØE÷ö•G'õV‰ŒMO|æ—{Ä"æ€Úf£ 7ˆžš™—¨¥lj¡Édò¡ÞY6Љ!1ñhu2WÙ#dTO¶tb:€¦ä¨ùäU.Ÿ)÷u¢„ò)5ƒ‰BŒ#„oß|´5¦‰>±q@ÅÕ"*®64€ˆØFõ_?´ˆUk±ÜP aëí!á}‹va
gb
ÎË~{øuúÐa <jÚ·¹ËüŸxÊg솟*’ˆ„YÍ߃4Zœ{„‚ƒ`FØ‘ƒ¸{•–ùÀû,€ß6ã݇Yõ¼)êæéGÁÖ€E·lAÓ"›4Ý~âþ'Û}° b!p’Cèož•CG,„¬$÷¿ßB—s
g²7†á{ùíÖÝK™q·¨õ Lù™5Æ‚5‚3œ>ïql¨x®þ'VÙEÈŸçTLW¯ )÷
p‰è÷ÙÇúD¼1²¥úÑ&ê›
|á‚Æàœt ˜1 @ó~âÚÆ]™vu2ú×çFÜä—t¤Ú(YäÍFóW¬À&€Iªj¶˜!¸÷äèP
“F…ÉÌ~Etö¤ž{zÞ¾ýN
KzäÌ 4qÐYøß´ï ñ»~ý T˜›KÚÏgh ASGó¯#AqÜíô…nXýwÙZ«ß–|±x±‡f, ÷ö;·0oõÁ<Ÿá¢:Ô¢ø¿òòh7×BÙohÛAeèo9~ô~6'ÅèNùÍù‰É‚²7´‘wQ2wõwgøã4Ü¡z–Hÿ%ɽpž +tV”GÓ÷múáG¨pH>Òõ{G¾µZÑÖ˜¹íjG±á^ñ»3—t`¶©@z¶Ã ë”Í^RÆöY¸ïX9Ëx8y.Q÷ÕX`¯+ZÄÍLy'!%¬Fèö§R9Çr«PqÐNó¯ ËøælC¨¦|Yé_{ö|€ ü”9»õÆ= ìÀ.áÉz8âë$¿™U ú’sŒå¤x8ƒýþŽE<[ùŸ”©ù„ ËlAoä5œ˜å•£ä"àP )ó<;ÌŒ.drLqgî=ÃîU*2Æ/Xçoh-î/٠ߦ/qåhw×v-Ã{”L…Ô¶
Äm8î¨Av+’™…’eán ´ùV€ÁòpÈö8Áù·íUÒ8}‹6IÃee‡ÒîæMVUõ°»Ç^É´+¤€õŒ-”‚áâ“;áîa-Ù¯I˜Ì·\J<ö6 ¦nžÃCqǸhí’Ò@8ºOnº=n¨+ÞIPc n‹Ùu 0ëõâýX(¸Ïí&ÒÑ84´n7¢Ã%Av+ž£ uydnƒÔv4‘ax^¯´JÈ€Kö`øC^uË„àÇÂö¦ ÁH8´
ˆÕùÔeÒîrMå;ú ,N€¼î$-”¯ ˜ŒÅôMdGõ¥â_YÍ—¬ø;láÇ^ƒŠ
£xûøìíÒþ8)×nRÅÃ@A³v6+¡£$VyndÔ“4rae^€´wë€nò±U+]¥ùTõ³â&XÁ¸(íßÒ:8ílàA _x÷î8ån`ÓÃSAËv>+¹£)hyŠ0e‰B›pÈ$Åwîò¬Ø¾élÃßAZ¹8¸HB4POõºŸàµ±=\>ôứ¦íb™*pøAå4õBNóEÙôV-šÕLB׿ÑL'Ì{Ö¾ƒ“Õ~ü]þ>ƒÒ~ÀX Þ4æJdÕÑSÒý?½ÚUÿ/PèË—[üY5”-y&JDÀe6™ žà´ /÷ÝÖV$*A]w%‰ž¶¹¬ÁÄwÏéäÚw0tA#x|¾svÅ“Ö+wz÷èû†ßâƒ-uꈵUƒu^¸¼íVÒ„8n›nàvâ“/yI 6ˆ¯´°á=â¡Çlʬ¤Áà^C¡²N”78îF˜ÆÅNMÞÍõ/âÅX¸ýíÒõ8únzØâ÷Ȫ
D9¤ˆ (~|Ú_"Õ¼‰˜SÜÄeÍ}ñÌIl.(¯…dщ‰Ë (lG˜‰ ^sÊö’,Ö<ÝËØžê÷¤@“7ÕSv¸|ŽC©0h¿ƒ”»J
ôBá§ŒBÜåËãM±… n²•¤h›)dO^“?e±—òg‰Ž“'ck‚ A·,î½æ
³æÉÅ]K—‡ï˜¬ý5pzÎÔ¿(u{T*„ãÛÈÌúÅÊ ŠîC 2Þù–©â^éÉ7.³¿-…)ùN¤Ñ ËØø×©îUSÍ·GwˆáµÙ§Bì½qÚÎh[±
Z!´¥p©£j;CÀQ?àpš]o0Û˜\n'ýè(eÝí8«¥û¶qBÇüÇ*Îã#Ä;ÄÓ>Õ`©ƒ—ñ
üó¨õ> ñù–>ª
Šë¿
“†6Ê{’ÑBÀ9Üt-UÈ w¿4‘ìcáºß2òÀéš¶Câ' ð’»nOÒ{Âu‡¬åÉöŸB‹¾+
Œ,IdW6zå\á”L‰ÈÙ‰‚§±x)8ï8êáí)øø]àÿ‡³ë®"GÆ+ î®H’²°>î|>^™Àb’²°.î|;ž™Êb’·p$î|;ž¢ñ7õ(UIGÝ zÀ¶Ùb@¶éŽON*O ó½éáx‰ó?\Nà™¤ ûýî¹"åøái èuS\BÓ ¢«%ø›ø›ÖÂlY
ñ<T tÝ
Ý£-›Ùª5"cB”Ýɰu#ÂS+Ÿ5ü14kÛ%"> ©ˆ6zR]•ב¯¿ŒÆe›IøFœª;¯ºÞµb÷*
°ccÎó™TdB]›¯vBÕ]Aeè-@Ÿª§.3%qíÉp6 3òlÅ!€%Pãùœ _]ñ”äPñ‰½.^½mJc—CdÛf%[o ß{°‡Ý
-l„Vd³¾½ýdq
᯦Dofn€å묲˵_[øî õ;[ ÿ„ߨ®Ý ` ÞëöSŒx«ì0Û=C#ÂŽ
[û Øþí0¡ðP@…Í’gã]¶`]Ñ“û%ò|M ò¹$€gV´?c‰õÉ&¬È¾®ô7XæÅÈû·ë¦U„2¢™Åc …0ñéŸTH:iN°Ž¢~®À<}‰“Ž•¨Ï
gΗ¬#q.•îÒÁvD2ø|î¦y‡á/`WÃt«“÷—û~*ˆnmuîànãGû‚ÊÇ>ø‚¶çÃi³ñfdøƒò}1Töu"ogàÕÚÀûÇ÷ù=w¥}Ò‡ÖmK&ÿ'}
. Ë|9¥Ï=æwM±å²
…9Uým%SÚT°Í*D³7¡Olš˜ì5JG¤CuÎа8ˆ²²;Jä»÷'eªd9óªlPÀº`Tè*D ˜§ƒöNˆ¤ýáñÆÙW~Ú]¼éSŠÒó… €°a>VöUéOáçõšÁq%Œ.-þ~h á #éÅhÆá‘r©6âà³ ó}âÙôØö*ßýiäsöKWÄ®ôŠõ¶*HÏ#Qö‘Á$©´ÞúÙÔäõÈ–kµ;`w½Þ¤±3ðÚúúé'<¨èƒ\—è:/ˆ¹×ÿpüˆ¿d}®b3ãè}æ{~Ç ïA¯ ®6Älÿùs¢ ˆq#ˆ÷›Yuï2ѳ
é(a\î=ö¶*êö UŠ;TâcÎ?5 Oóƒ§ôS„K—EŠîv{ÑFð½pm(-åo,ô`èo+ú§myèxæ%7–:yY²â¡XS’_ge²óquþOòd‚÷¯oKR´ Ê$0\ ~
³ g|RI ÇPºIù×´úvw3ü½ó†©}8ƒ´%Á¤¢{D¬¤ {á‚}ËO,Æ£šçUø/
`“
“Ò:s¾+ê[䑟B
˜û}H/û|\M¬4J²éèŒ+©<Uí‚¡±¤Tšl»GÔŠ¾±2ê™ò÷'4É÷›ÛGNÑÇ^êå§Â89-f íY|9ÿQ4 ægçîMW_L˜;]H¬û¹Ù†»åmÖf<šp^hã˜sŒeCqÇT_`ð'÷yïƒýq€F-$ )(<0Á‘[ÿ’”L¥
ÂawÔÛ±:³ì®ÔpH”Îר%9 :ª"èpÎòPôÿˮ냺OÂ*CS—\«¿Ä$2å϶~TÀQÔÝÚÌÓe§A[âZò†'_<ŸsŒˆò¦ùä7òcä7°[OCó2ópªÌt±Ø‘F=B””Ã,YIcé
e”ƺBûÓŠN-õút6aFþÅRž½@ÌË+®þr3@
þg¢ŽLyÚNÇåöÔ®Q@7HQ%TšýJÈŽ Þ{rLè¨N"ÖøA"Àíé4Õ7g ŽG9œ,S§å@Ô6ZäØîÞ°tô8+•£›¾¡Sh¨àÜ,YÐæÄ\¿$AEÒ ]Ä™c01˜3>
Rßh¨È⺶¯ó O4„àÚŽEÄ¥8»¼óÄ׃óšmYkFŸýÂ=ºY›%ï:9M,ºtç@šp׿ÚÃl†„Ak×-gäBïJ2I9Ì´ƒLÃØ¥ø¬3ñ¶,Ñ%Yü±^F’úC–¨«D5sËî j¦ÃLŠì¿Z„ê€÷€*üføÒ„×V«×0…ÙAËÙu~/ 3¸}KD“{?-âëmÜeÝ¥öù.9lq¿±¶0ˆì®8.)׿Ûy\´ PAƒ 2àh¢QéÙ»Oé”äÛ·ßí Ò@‡Ûú\U(›{‡þëñD+ˆ)‹*„Ú^—¿0?%¢ÒIë+g¤Y€MݳÊb瘸P™çK‡²²—“×~Rù9ºeK];CÀì•bÀÙ‘Òue>×c·Øï;:º(`Ý]ãø®+
\æ.7±5Æ%=õxcˆöžTŒ–:ïèúãuéÝ“^53ùb}Rx {!ÒÀ…k>R¢ìkàîjžõ¯²Í‚Z‡fLòþb“%”ÄÆt"{ZÜ](IVzö(áo,î½2ºí Y1mà*dLÀzXêíßÙÜwÑ]ñ’mFµtœ¶stR×üH¦‚å„á!â ¨î¬À«ùuÝì´ Ù°Bzn× <êz‹‡–”K£~G¤xI0°ö)ékò³çcJîïCÙ˜ÝNȬ†|¡¢ÝBø`\£åÍ‚³íî-fŒ’“©
¼ãhé7ðæè§Qx xytí¶ ¦-á=v ‰Cß[Œí(“ôKûpÕ@Õ¤0,²¿Y|=Vl àñWsN™òðlýBíjMù™ùUŒ²ãžåæ¸pÿf%¤Öwí\›eú Íëå}«b"óTÚ”Æá}¦ß²' ÀÍMÌN³TÄbãZ€ýÏü K®ðæõ0ýf3ÿÖøWF°&Ç
žŒ{e
nX†%ôõv2¢
´{ò|Ö‹ð£ù{r4Ñ÷æu>Rï“>ƒßeÉà ÛuõïcÃ!sX,ÿš( ⓳E<ù{[“ƒÉ“d6Ú忦Oô”{hÍ«E^ú:DÒá; §4DŽ´ÛçLÖ Ÿ2òÆ3
[ýœ|êF ZUô$R§Êž$åUýAä ˜Û…Ù
Ű· y°~¶’Ç ªèFÀ¡—±xÆè÷ø)UÕz fæS™ýøB.GµÒ ci±Î[ÑÖ’îX©îGe#éûíýGGdi%ìé=ÕmÛ$½é=»ÓB]þ ·i·¯èŒÈP$Ø|í´m¢%|ÓÛW¾Êøf–ñÁp›ê•8²cpa”÷Ðl¦åUøíµ5Îmöerás¤ˆŒ`7/%Sw°#ÑYÁUyíúÏ©ÐÊ/ùòI1ßZíj¨^e]8È/M8ެD¥{FlãàOk÷µ˜gøJ|/¤MÐaÁ3‚è ¨qävÁdž°Ui·—O›‰™÷Ó
«lrå$·¨açOIÀ"n~gÔ=å œ($6°ò Aˆ÷üo…Ó”F”>ra*©íY¦Y„+¤ ÊJäý%ál)síJaû·/ Ô¤Às'rÂÉÀª/)¦Gû¢.@¶4²ß)]e¨2Ûì†K‡ˆm¿r]±«5|µ‘8ø·÷Ìa•„©è±ÇjŒ8¹ºíÔ9UÆ‹ÎóÜ!/¤x÷ít‘þ;€eëu àüf-àóDB±êEsbìÕ`SÐ
»©ÝÃÄÙáFT!²Qw¨7 y}z*¾úö1¥³AÚy6¤¾êˆ .ð
WËS‹íWYÿøÆêžTytEÚŽï·¼öÆ™ˆiTU éán¬ßì£Ð¨«/åÇ¡hÛÖ—¦O¸áëÇJÇU;µœ˜AU`Cø Uñ,œ…é·Í¯0BYK_€ñâÚ
#„,—8e™„‚ìlBTdÉ—W)úã…+¸Ÿä-¨ã
„ñï¿ïâ<wÏè|5ÙH±_r—$ï´³%þaÁbñ\ †sVP‰ä½ïÆhH±vzïïßñžÍò”ÂÞX¹/ØÞ-£‰x°2_wZ÷ËöþžV]
ÛÔÒÉ Ë»@N™¬O„ÏÎn$gjæ¡ì»¾U£\XÃ9éÓ®Õ
¥ïާú°ƒ,têt|ܤB’*Kcîº3£û“tØâûº1¦ÂÍu}. œ>4ft#áttªQT§éöÈÞž³FþØœ@ ‡®Ü{u`þ#f[œüTAùÐ2WÕìEX½ñ6Ùr쉟QŽ}xä* “/¢Ô-ʼn-";Û?c4ÛvœžôävŒÑJßî¯À_4°vÛ¢TõB+;°™ë®jÐl£„•ÞÈ ñ=Ž#¬ ±ðIl±P¨Ù˜ñ‡ଛNß0 ¢ð@6@9²ðÚ7RÛ«r|-4m۔罥}Áˆ±Já¿ÙìixÖr¤¤XY¥¡woŸ·îž=š!ár :€wº³$¬k³Ä‹Çè/w]éTF†2C‹ö$ü¾Wl¿õ)3Ò4)¤Úᤩƒ É>¸k§w‰ÿE*X–ëÝ<\5¢fí»«îï8ÃNæäý”ÖûK¾Åsþâüo¬Ê¾G{Øó;ë7it »«yøí^ô+3æØí$ÿéJJ;WNÕVÑTìl1ä »è^zXÞËs
¨ë½ñò¶Ÿé r ÷ê=€L4PŒ¬mî
_e·¸³¥?ÎbÕ!¾mbdþ‚Pì#Yó„“£|€ &”ÁåÞËtîeL·æt©„/äÙyàï!|ÚxŒ™@[òÛc¯Â™ë¿ à_'åœùBµ<!}²´ I×ÒJÇr"6§Y÷ÄZ×})}®f}¯–Xh7þ=4úDBK—8H…“"aqÂjª8èÚO€©ýý=Œc íä¥f«ýn¸Úk|àkí:’5î¯íöN Òãzèw')Õä@ˆ¹]¯Êåm~áöĈƜ5WÁÜž{Àüÿ ž—¤I\Wì’AÊ4?aMÀùDiUÓìGŸ¬1îhímŠÐK¨B
Σt©‚¨*iÚF¿\|—JõaÆ]‰Ï÷ÜM›ðC9^˜žG5G4m~”Ákx³æø°¬¨Æ½‰U(ºÄLÖ[ýд#V(¨…dÆ¡~€³8UQGY¸_:ù—lç[²Ù‹i™Ž´³F(¨6 ãúMÅf‚Ð’‰u„¸UV½þ®„F˜ÛF†¶åøå\4k >CfSŸKŸÐ;š,—ã_~wò籿TÆÀÂëü±£S\n[ìñúCw„ r½ ”i᛼LøÄø1¬S}üâÆO'ÊóJn'(.2ØÌËeóT_èîY¹Ö*#•ɃêÆnÑ€NÉU×ÎúX¤Ÿ0|ÿ„m‘ÔÉ”îe•N…|¾•”„w†6ãpÐj‡Š;—ª_bçã9Ëá(Þ~,‘9ö‰L¡/'›¥©“»Wnұ߿Ç6'~CJ$ÊgO)ʹ²—†jã–“<IâÉ|eó¼Ö¨«xY~úñh£4'©áÙ-=Y';xÏà§]ÍW4;ü ÊÙßPF/’jpÍgÉ¥„ ¤…qʸõÞÇ
bqF·È-§"«% %¡Ô)¯iéÉ¡_ÐýÙòQ’䤀zY¬°})ûrÀ>Ž_“"¿ÕXìõÊ3t* 3Úƒ º)Fϸ>¬øùΕÛì‘jOí³QÅZºåz( SܤÍP)åÃü¹mãÇeaÓ0–ÄFr¥ÊYl="B8¡Ë¥n ²ã b=ëí"P5SÉ1â©}Ñä^V*`dm„uS3qÎL;$5“j5ذ;W]IÍ´Å´$g|‚uWm3©x·„ÛŸêeñG€Òï
Ï–ëqÖ¤ (àvh0ƒd;ìËÍv¤\ ÔôlÁ8Ï%Ö9z’Žƒ×ã&Ž›V-³×^=°ì€K
ƱÄÒ¥X1éÛdñv¤²ƒ<;´Öˆ?`lý8¯E’eÙþÆŒ™ /(ÍÕ*³ ]Qa»ýáò}Â5X®†^Ú‡X˜”m˜A`4žíépe|³œ-$`lé8—}’;eÜþÆ ™ˆ/ Í(Õª³?]‰acôÝ”0DÝv¤ô*|÷¬Á(–¬`a:Ñ+ìÐ+e‘ü{ðJ8ƦÍ8ÕÜTÿ¸³<ôÍ”ON¥Âƒå1Ió7=ûM´’e~³/Bƒ¹‹ìFÀ½cíþ8 8ì t@Røœ§E”Q)0‘JoDèœRúyMjŽu_NLÕ»c
üÖ=ze±øª_á]ÃߣýíÍÄÖS5µ–Ñd<ü, B³gOÿBM9ôÙˆê§%M†‰\ãå
Ã&K®AÚúâKeKQUYÖKà/x@èi:+»ÑÕ$s¹ÿQDÁ4CùYyZUj2ñ?uxCô°1l|¢~“yaô7þð‡<uø A™ð•Ú¡ðý4Öð¢e£ð¨Cà ù^P…üwÚ“¹sÛƒxžIñ~ZüúOl¶O"UÍ3#Ü4 ú-M«åWí«þ2¶ÆüK{$E‰ÆÎž;æ¤øÜÏìüqó'¤#ñen\`ñDÔ)ïöµ”'§¬¹&G GÕ9ã2ƒeaçë_ïq‹py~ï”P’qix8&Xù±Äßúu}‚„ ö—hìѳ”@ ^ä:´ˆµø…„‘£ ž…ì¤О»Z1Ô¿éxóû$šÉ¾ÈÔ»îW±ã\2€l_µ¤Þ´Ÿ\·ñm,ß(ºO l¬ôêx:…HXOF"¬ö™Û`%IALâä.¸&ˆþ„Gn|Â>zœmɼÁW% [+í¼Š/Xó”ÆQ3{´A*w4üÕ¦ùìä{ÃTÍGË’YR½jQ„áN°lÛlö½^/af9 hô8…²§ÎIÅz@(”£÷Ó:á%MÌ…DaßÐmw÷@µ÷k:=Ñ×%9ê/ðxÄì´4Ë!åvT¥D`l%LîðOÔÆ\PÐý´ÕÃwÂú÷B6òc:Ñÿ%ê#x=ÜûóKÜÓFÍà¤hE‡}ÖnY£1ä|e†÷ù¯Bʺhjòé(ô»8®PõlÖ`ÆÍXòå#Øê_]Ä@N!%{ ¡ùeüèƒà&¿›ßøUÐB*ôBc(ü˜mïùÐøí…˜u "ò…ÿY^°¤‘# ñOÊ cXjJ´TüEÊ(»4]k°i5°ûJµy{G="Sg"àƒ¼+âû3¹^Î?#‰ôPÆ¡þRî3z5 ÑH›à·:&V…mqã\bíšQbŽJW'e»Á¬ôë!óÆ'CÇ:6Hݯ±¼M¦Ž}…åe½ˆl/Ÿ·Bž\aµäÝ^ì
ÀxˆPÙ)šÅ<Y‘€£Ž ÑÝ+¤Ž„†¨y³Â|¢ð.3xW71ÆCøœ´ “Ž'~µ…ïƒR)ŸÅ1h“·•r’O¢Ç"Z‡?D ¿”Aú DKÊ ¨
±·5JÊylß/«]¢û·-"ޤÅ;œˆÁ5EžôƒÐƒ—¹÷$•ˆ5MR• jdH×oz¿3‘»³¦0tÿ¢¢4]Â^]Õ«èç3ª8:c©~Œ
¯q œÑ1›¸Î‡—41xÏ[üIÓ¨;«JT[HŽcö>óЫ]‹6b´Ã¬ 9áeaá}3ÕÉDqÐ% ØP«\;€ŸÓõ’Ç3Õ7ÒÖg ÊBݨµf‘¤yLnµ¹@4¬¨Ä3„&¾cA¸øõYÏ `m…‰åQ˜ öbL¯×!9_€Ø³tþlšÒ$üE’¤øT>kZÞœäí2]p–39•Еm´ pý!·‚A[¦
mª©FØl3m”"-£Ï´'eÄ}«ÐUDKûW¤úZ9gÔyz¸*ô*Ï
µ…°!-ü^Ø.ëNºhî]Ϲ]N½"O·QU€Žà)hãÙ!´èEyœ„è-Ä×·ÑôÂL'ÂÎ_YUÓD‡¿u+YB{ø Äߌ„øWH]³yZ¦Y¤°søc9Âí—KÖô®ÂgÝÅG~*Já*è›Ø\ú„Çyò/EÙWŸú.ÿb&ZðlzA„›ÿáùÔáúéÔ`æÜ¶ÿdª¸4É^Ünó¦[”ª…SßSÅ
¢zçÈ_GYõÉ Wâ¡ßK.r>±^¡Õçɲm×ûmk?ú‹¦¯Ê´7tˆúL‡¦éI…”°ÜÃÂ$ߣRWì ˜WÄmA#A.‰ü— Kíî‰Ilˆóýÿ×Ô’Ù{~ÔnôrM§#K ]/Áu{ßÔûùü³6X<´¾—·t
½ß ç¡!û²dé¡dJ4 &’̶µ~’Ôg{ÒÞ'd_ô
f u
OË < <Œ7¸!zba)ÿP7
7†:aÒßQc¤_ÛIGF´˜Svs ~W‡‘*ýäO/0ÆçÔ&àpˆSÊOS6øêF;»õeÔëDX÷d®I{‚É€$r®¼ÓBæRºo(•]Ÿí*æX¾®TþgWä“ÎmÊåD
”!BÝ¥”e%õàÊ`Vgá"÷¶¡¿ ‚¤FA¥Ì{æÙýp
.ßxˆäù!æïr]°õtŒ´ët¤²h¬®óU̼üs /q$@ðV‰Œ™¼Ï3Øç2|`ËLÔï5Y·^\y¼z ÍÒ./[…³I¥#ÎCóZàÏS«Óëè+ /{@u. Hëä€ÏóÝfÙß5ŠÊÉy@ÞäÚyœ}‹7ß[õêNäîm]ë”ZýGÞ°ý5|2šˆ»dæy(õ÷u€ýºd-ß'HXã” EBÂE . ]] *§¨›bS²¼LåM*®…ìMb°ëõ=rè—°*•ì*·0¥¶ÃÑë42 x¢}ýÎ:—/t0–à`
h&k€´}€EЯg2(’VJåh¤=R*˜Ê½§gïãóÝ °µ4wóÜH˜…ãFÕ½zÛ
,/@áË‘ƒ•Ã-ÂôO(*…jÓÑÅàöýÉa{ì£r~+ ú ck{Î,±yÎ#9ñDþûÍ—6hx²]àÖÆïòåásCm*1Ì hQž´^Œ_Z†Ë @4ωØö©ÊlD2x
{ ª°¹ü¤1‚%‚ÑTWÿäàNýÄ.Z¹ÓÞkY“O¥í!¸A?׳e*'ñV»]µYÁ«fõ5Ô v,úCSQúè…a¬/Ä"†¤}rÆØ(½ÉÃd€ÆÀ6LVÖyujƒ?“È”pzÏGÌ¢Ç_Gõ9ɇŠ/‹U˪ùe„1
íî,_Q£Aªó˜Ç±Ù_߯ºíÐÝ0õLÙ*bíà )õ‚TŒx3¼Gd—Ëñ[|õ¹_ÛêÊtæ¦Ép ÿ`[È9m7ôªU©ÉAlÅÌC—«Mœ*̦®Ôÿ™8 ‚I¦_ññD]HÇ/–Ѳ6±p8ÑTD?mÚ̦uùJã!žß@!hxù1“yjðA8€>4fL¹´¸ÿ]^)»¥”¢Ý²µ¢‰-Ðâ@‹“l 5‘lxëqwú_ –À®JZñGøgÍǃÒrìÁäq2Él3`Ê”úo3{ÑÈ+_÷NœØ›õ-6>ïá´½Ö… ¶†>¿ÒT¨Ðr„:ô ´0è/ôM¹|B°Ud~-ð§ï Ûm¯6u…<t}ÎІ¾›@±n,\«¥Cdí"àT.\^C[CA &VüŬ„WKÃ1¦úÛ?ôßl7cu„œÐè+{Äøâ£Ðµõ…ŽøŽÚ–YP‘²>°a v[ˆÆdx Éñ¹»ºdÆð1ºËÆ{µ‘¸ªeÁ´ß òÏù䄼(Ç*Oe
Ývç¥./ãÄØ6E¼NH}è–Y½”ø—'ÅŸ÷îñS‡©ð_é_ï¯×²ÅJN„åLˆºÄråQ ¥¢Cê›c)ÕjcOÐ!÷æ
Qwóm²Î>NÃè̃cu *ãÉsT£E¢š<‚nò¿Ý*#ѵ8£phú3ùy}OwÕfþƒß}ÚäÇhDdzmTUÒÅä„"‘%ðMâ¤çä• ÉÂôgà$üÈTÀLáÕ5õ{'ôt#¥îêVöT$Zf@dX‹ö—#˜..†>Œ¢[Sš~¦:Fÿ͵t0mHñÎZN?™ežŸíñ×Ýá
ºÎîß54aÞ4¢ ÉuM~»‡ËÝ5}‚gݧȃ'Õ×CIXÌoJy£hÑ$õö;çmžÀ)g-uVã4øÂ ¿#ë½0uø(ÎáßüŠK™
£±:Uª!kW¶ïTûˈUªÅA¤éÞKùÎí¢Wo‹õûZ¦ÙÍc·Qrz>Hí&ØK±é«ô#~Ü›¸ò…ý޶¿…åªÙ…V|¿õù²¼<ëŒ5M^‹kŠÔ\쳓(âsóQ{·î…½Â{•°“Ã2ÞH•skDC¯÷Rô‹•¹úºËÌæ &Ð>fÇ·{E6’uVÊÖ¼]zäÁȵRñ5†î¹Ç¨Ò-‹ÆäˆãìYsÈ9¹ÞêÐÝ&H)Ðà:€K šÊÕiRV¸^ñ¿õuþ¡yÏý}4Ììi%T2ë•Z¨·õ˜F'˜ó$gŸ Ñ$ïâ"3朎SL´¥=ͨ4@E£ó½Î~ 9÷ó--P*ÙóåR»™’û‡•pM4¾bµ É÷ÿP|ú1 pŠä YÑiX…ûˆkH=+rùí¤hÛû½îd¤K&~‚’»G?x|B½Â¤TEQ¢…ºuˆpI•zÉæÞ"4$àì žlJo°ëO»]µ?¤ôl›g⌌+’yþÿVÿù¢LP8X73È E¦ в±ÄðÿËòLUcÔAdŽÈ<ýàf-ëÖ¬fDë*ùãÑùDŒ€êËôeAhˆjœZ®ýPŸQT›ÒQ±Y¡1Õâ}ç·ÎÄÍâû*xlüBž«å¯d±eÂL0Ëþì!À·ÌAªŠu-ÿÈòQ•„ãlãÓñQÑèµß,'M,î;On~DÌ/hÁå§âNöGÀwï¯õ…ê´hŸjú!ÿ“í7ÑWØ!¿’'ê•K5¦©ƒÖZìüÆsgáZ€¥ûÀó¢6vZÈæIÀôDlö×ê^ö ²Aiwtܶ– à;:¡¬aË,7 O}"Ž»ñÄYé'2VöO„Æøa- ÆÃÌò”#ìu—m¶b]iáfID2¶”„º˜eRÞåoà7Q”KZLƒÉ‹s¢Á*äûER~U~Joî/@õ”¤UÁm¶»ZêÝÖrnŒ4/ÐÖºÕè'»6ÿ ûµ|hhAtEbé1ñ@¬ïó ½ËÛí#áÃú¹Wï÷©Kÿf» n¯¡À*¾¤ÓÇ’ˆ¶n°4©—(©„X÷èw2xz:óaN’|îî-h£(@ø‚íyÒfUá4e6Þº8EzKˆÉMÂÚ›åH¢ñë\uwÁíTdætÅx
p“”áâÚÚGf62£Ñ赌Ny ßT®þ4ÈVk2 rÞÞÁóéïXQBü”_\ù.³Iú—|$uGÔõ”{‚ûä©£k¢tU°Z~K`ÀÒïh;8ñpEþ÷Õ*Aí7ä›s”Û Öá=»'À°*ƒ˜`m”ëå%õ™º 9êÚÐfpü˜9èrïláúÙç”a)ž‡IÅ£aw·áÀIZ¨gu-*àaTaqX&¬"»P/¡òid±‚µ¢‰ZvŽv ¶åÑ–íkBŸOÝÔØ ÍBm¨ÑU;d%”ã΀¨bõFC=è£GùN·¤íp‹y^ݘm1÷Ÿ,Ú ÛÑva¡ú„aþ"[᪂^eí% E¤6îó‚íUâ"$H–)4¡@²_Úvö»m(¥Ì”ìÚæõÇBMÜ*Ä~ßÑÔÆ!VJbÉô<OœžD·/\ÊØú«DQUØpµ¾÷¶måNÑ‚¸SÞ±A‘`¼Ðó’EC‡N9¤û®¢ QÌʒǃžuíƒÔ3#L7Q&¬£™„ñŸ…Ç4%KTz^é¶õÚ7õ™¥Ã³8E³ª2`Z±Hÿ節VÖä*%ø”ÝÎêË‘-Uä½U¹J—1®#ó¿ÊH£{£¥Ÿ+ÅB40c6Õ؆Fâ6Cú¾Ì³T êon=TŒ@Ú¨@pQS†þQÜtzñMëÆ˜×˜a¸ `EPé²C}:²[uÕ,0Çr.6¤}+Ì>zí…†GìÄ;K¿>Ò2(Z–`[25íw>GQw2TB0F©F 2 :Á8Õ£|a,©¸ù²ß€¬Â®¹øÿ?ÑÁ¨ûä¢* ¤1CA4±È”ÈËF Šx¹ÙBíóÚSnô‹.0ùa¶¶a4G?!I¥-¸†¶m˳èø#¡ßšN³#YÈá>MIê)µÄ34Ñ€·µ˜Ä1M w,Œxœ8þä*;«2ðRa¨98†²ò-Ñî9ÝÒ¼-(È¢Dµj-¢²«øá~ÙÃ˜Ü K%9à?-çÙEËáµ›a’ø:«Q$ð²÷¯¡¶á\.Æ/×ÇÅS|ÕÁùHí¼à–/+r£ñ—xR¶Éaøß g6Î%¸²¢ß)J·cÃ[Ì(‡ƒ v6Y$G¦2-óRY¿íc×NÚ#²NžÌ–R{(kí¡ì~¼;gí÷à[AÀ4àD.Ô %¶ ¾ò1/$pV¦ÓÄl¼]ra‰¯%û]œ¢—à[vµ×;xQ‡ü…ñ˜eo¡S)úô²¢Ç[~Æ{@ø%€V»–µ¹r
6uŸ}âD¹«Y¡§òʦ®,f§b%§Å@ïïœ_€{5†dNa»LÎ3¿Lµ\Ã)Úþ*¿ó 6è¶±wÁ*’ s 8qÞ*T¿d 6¨;±sO*–á°lçº[O»O©¼Ý7Œ¨ F#N>Þ÷Bi+Và0¶ î‚F÷©B’?Eb$”ƒMó׳¿YE®ñö²íµÛ&’º5ôæêI¼<iÿ¾U¼øld¼VQáX‚¤õ*‹)òž¬¨òt¬¨ (ER,Wdåo·Q8T/m§’$1õªûáÌNâ•òt$½?:Pwï4D.ÄD’“ n½±¾ãZôÀàq/(†æ¨¼‚ f ʺQnÚôÆ1žH@üc‚y ¸¼:dÈ‘ÁðÄc_ºQ(=æ4Œ$ÃVã€K¸r[¶Ò‹y%Š“$1x‰ \ŸX•òŽ ÌîÖVâR ¬ÏÛ’¯zäè °&{Þñg!kâ¢ii Ö[U*—E”ŠëåË…`ÚÐgö@³Á+ü·ëë=d5€©q¡j¬×<Ö" ñïŒKSýÝU×WñiU¨œñ'ÈCû™òBÔK8O>}¬Â㚣}Z¶1 Ž(H¨gÐß—în1ÕäÞï…j*öá@¤¨™üøW'î$!ïh|—ùC4£x ‡ÅþMc[ß¿p‰qÔ·ñ–ù«û]C %ÈR˜·ùná*‚ø{ìMnr¥ÜYå…¿YÇò£R4<!øÄì ,ä%íRæÄ`X’'OŸ%—²©>³Öbë*´Äl£„‰¨ž¶w4‰$øƒ«Él˜«-Ü;¡Lsv¡Áz#®$̸¹«›ÌN«÷€Xó;[*´Ìk”?úÑÃ92ëç•ħýxXX ì´ù` Àå|
sUôûp.³ÄWxð#T<Ñmî›A~Õ²JvuÌÒ1jáé´SJQ€/Ï‘¾Í¹D„³´øþ®Û{M¯L>Zt":[PÎ^û>䩤Íê£íͤüø+¤ÏbK‘öWáÐ(µ$¥"ͯ³Ò³¹ æûÏG²béžÚ _*à
ÐJ¦ÆÍ]—[Äy=¹ùË$¹eêºÕ]ç!NkÆ¡±å²J "͹
6¥èö^è(3h¦|]À…t¥øl‡¥VÜhâ>ð!Æ`&5Ñ!>hQ!*B0½( y²±¸’Ím’#Z_ÈÕÙ;»¢]¾±¤n’`t`¦9_¦Žñlî—{py*Œxëî„kpfÑá”}çiöˆ @~ÇÈù+nÔÑ\^‚à†ž°Ït ˆJ’cè^È?k4éMB°Uåí~‹…w">ûÔÄIà,ã§b$¨j¾ ¨ó],•ï†kxÙ$×Ñ<k–¿J(…Çþu{”a;~¤Ãgr’*á÷ˆÞÛàl±¨PSy3t<;sNJ/±gAU¨9ì¾Ç27Ó¶¾ (®¾>†½¦Iù–>P4*z+RúEÕç²ù&Xδddvã+@ô”ú©È¯¨±½g6 %¸Ä•ßJªc*l̇u½v[Iª¯21%¶¨ì»-+4l´ªLméª_€§«Á„n#Cìhö'?#ÒlûöERAR/[QA;+VÖ·ëÈYÄlÇÊ‚¯k{¼jrf`t®•»]§•sÁ;R/bJPÄmW…“k4tÄ•±l~ÆeU Ö ŒüD’F°bMleÔ0-Æ.ø’zî8™fo.`q„ngÔ˜>á2»ÆÄlT—ø„Qlûƺ ©˜`ã¹’Æ(T·m„n`Ÿ%y¬ûêk(…*ò¦*Ði«#»c$(ñ™ç!’?Ÿau]ßW’cOŸ%ƒ±©RWÃ(ø™˜ÔêµÏ÷&WC‚ 1†¥èp…UÕlžˆekëÄ
NS¤Æl Íl ®Ù K¯t۟੦ø>{o2"‚?æRhfBêÝj¯íluKEMb?V
áN#ûFqaL9Œ B\œÚž#ìRÊÓ÷ù£‹ù·‹` ÞŒçÌA F¤ý[¤Jœ#°iÊcbd´&á÷£Ø‰0(·†Uê½ Ï¥1èu†skŠ’ N޸ݙŒP røÿ…rtÄàÁ' ÖñòÇÁbNY"’ó—*w‰â¢‘åfk’í ‹Åý)͈8G©nJºžò’Ñ]“…ûgìÆ]j2l|ô6“bc|z蕼qõ/â²’}>åQ'ÍB—ÝâÓwuá;„1â2ÓkŸ‰g¶ˆ¾ H¾þ!Vgüf“4¢% r‘‰Äa³‰U~£þ5ªa:k8†¸ ÝÏ—Íw‰ Ž·‰$¼ºÜ—q\ÿbϳíÃ0c8žx vpeháGÏ®%ü®—„·…óî‚úx
în!ï’|aù‰4}x×0´«õTàÜli‚¥ôñ]s%hoìÆxi¤Â-aþ׿°2Ñ“Zú(Œ¨j„5N
RU”IúÓwuáNËúx¼
Qñ’–ô‚
¾ëÇ÷x>“ŒõÈ¥Ƴ—]ìøRÕ¤ Á½ƒe¤k>•#†søms#ºnÎÌ¢Ö3¿6(c¶ýÑÈéþÖ÷=¯&Ò6ÕÁ’R"“E…ðYi|* ¬õ+î’x&¸ÝíBùòag ¬Õ˜jãâˆ4}ƒ]Ñ‹îŒ?ô)™¶*÷黢§Û`(’Á’ѨŽùQ‹ŽñÌg–'š†Ò’*`™P’¹“$Ý™jôY„‰è•±vG
E ¬O_’iåç¨ÁŒOœû²“ (¹“èQÂE³Ü_k”¥ƒæ|’˜“„a„i]½š°cGyÄ“&Åó™hçü£¾+ñŒj**∑åLk¬í ¡Å+)ãŸ8-ßn<dštØ›>œ÷æÆ!~2ц î?ôœ¶7÷é¶¢§Ö`(§Á‰Ñ½‹ùQ€‹ñÌ|–'‰Ò‰*`œP‰Î$ÀœjôL‡‰è•¬vGE ¡O_§iåü¨üŒnÁËÇkÎDØÕ$Ž`×´k)ÐdvuA‰Ë*B**ô ›*È诨)Æ
‡kúì©d.“¤*Š`tø~guohsx³\sTõ“¸3ŠÍm3Š-2E¡‡i´„Vsì“Ù/áa'Ò„öús/·ëVrN$“tËž?§swï¡g.Ćg’äAüé°ý…rÉiš‰µå’¨î"”Å\uôÖ45aªwá`ˆë 9„o
kšœ`÷€`tg‹žÿÒÅ ¿ú~®bé7ì/BFê]S€±_t€–åU«r!tý¯ìËI äý7ræÄªy’µOŸ%Q²©€•RÍpWÓÄlm^ê*(Ø–:H—8ru%7ré½6;Ñ‚˜4Â…JO´Æðb@êrorQ
ù)
UJ>Lõû”Ú& ò¤²ÑŸÓÆ~xƒ¡™á%Ÿ‡sϳõ},ï•÷áœÆo×ÇÅ“|Áùˆí|àÖ+²£1WxÝQ‚ö–¡•Ï÷ ËJŽx,z˜Îh¸:²”ó` )ùB¨Å…î4Œ#4igÛM'‚VgUèw”¶©”mµ¬¥Í”j³™ æûÏGÜꀈ‡’ûëÉ“jr´`t\Ž»]UŽs;R‘bJ¾Äm¥…áCötrŽw~Ž28m¬ÃΩ@`Z8èU†EÛ¨ú’v3Ó%ÍéröP|ÿcè‹È·;|:ºaP€òÕ®ÿê)§jAŒ!fÔ®P;|ýá çàÐþ¸Ü‘g¸‘ez†éÝÌröÞû#ËšciŠº 0UÝä LW%škçïP~‰¥ª5‚D0‹jQLWoõ~‡sÊ$D«H²×D]ÑÀ²4_J"m
Åm@Ë—9œNe‰…ÏãOô nœvõ"áº&¾v“òóó
¬£lâÆIÊ]‚³a!ûrª…ƒ¶]ÜùgTÕfvvó?îiÛ=}Ùdy™äãêÛS€m”Y¤ÅÉ®Z_YS—TnQâw‚°óùv@bßiUòlâ“
¢ƒ
ß×Ù_Iªï`ÂÎêEÞæSÐÀPö½èÌåØÙm2æ% 8Z*¸"Q|-znæþZË4µõÖ)Ù̬ªKmlá‡|P¹Jáèþ&äæ‰Ï¸
G‰Ï8¶·b@ê2O®kJ^ C£Å|±a²-a¯Þ§óô‚´[OOŠ:CË4Xù1©¤3b@Ú ö súØÑÊËT¾Ãcû˜°Ô8_VÍ""¼õãw%8O`_G‹‰8PbÍ"‹ül®u:‡Ë:J2¡B6žCÄôI¹M²š‹oûib (Pbè¦ÂEƳu_k”~èæ{8kObBuOi]Œ_ue¨_o+ ÓMë.Q™˜âRn¥>€ìÄóuG  U
ûºÉ²—¤õxCß=â(oÔÑ·oUå¼£‚[Fy¸÷x–ntû÷X€XÃ;€àßë´rN,•yti?€wït.Äät»±ÁÍlÇs5rö”G9ªœ.¥Iõd¼YGä¤#(7ÏsˆXhóÓ×ä™ÝH¢®S¬žüޏy6 ÉíT ÓâOÛ„ïû¾{lƒÌ /#¨]}šÐj ]*€¢÷!Wv€š)CYâ—Ó•<ñe¦e¨Öáð(",'”±o(ÿÔL©M^™¬Ñý7¬]söÛèD)í¦÷bÚYŽ› âµàZÕ— [IÙ2_,:Øn$Õw1Iü‡uñ°*Ø€8e‘ù,ˆ@öÜZò—^å|å‚òê
0¡P•Ù§ç…<ö è§ãáö¥¼ÈGlkøîô«ô¿:é\vº (ÅÆùïÌ(Hg•EF œXm Š¿Ðù· ìÀ”Åh_Ú5Íùë†
,`
¾€˜1æîð Oô (ãm¡à÷y;ö4/èî8ý4o$qÏn™Ô‡8ñæï´Äðm
Ò›8Eè§fáöb½DÓljtîˆK’VuY´ã\M¡t¹Xæ@!{¸Ð5,«ÄYçß8.FÈj<ZñYž ¿‡õ;ãn„„®tuA³c…è\”‡X ;+´ÀÊ0³ =)§Ñ*>¶,:¢ÖŸ“Îüœ×¯ âÌ}™ á³*d}h„}L2„¦"8[ŽŽ6óèHOE@³uMàgö¾ñôcîb¾íUèÃú!y²›#Âx÷u±¡Å¼èÎX üü+vpñ·*¼àA/õ.1”¯uY¸¿íiÒ8yˆnüxÃìAhvÜ+X£Ì±y'nÁÔ74Ñaáò#}ùÇö„ ô´ta÷^´ÇT€ÀõD'¡Å4M ¿õiâY ‚7øã` ~ *•vËŒ±<$ûPO§ÄœÈ¿¸™ÈL\õt÷ó7ó(ƒÈ¯øÄRáë´Éo`U2#)9(»ð*ĺÈî¾\§ÝDqUžÕ§®˜ìWåHî¼8ìA(vœ \¹„ö,%h> àõd-ЯT˜ÀÅDìâ¯XY¸¿íiÒ8yˆnüxÃìU£Ü¡yWn±Ô'4ÑaqáÄ!ŒëÞv^ð4³µ5R˜„lØTÒkAJ¢®'a“÷**Å•¸]9ÛÞv‚Âî´À tü!élàæî8ѲÁÉí+j-uöñ˜Ä ñå
õá{úèï} úìpþè˜áúnägiçÿe÷ü`îø´Ô"s‚«}m³Z}uaç&¼ ³¼
f×{~Üç]- iþBÍgóýš—I¬“ç•ÿîâ;x<{T_ pO'Jcz>® gÌ0¿ùZ ¸ð™{$H íOéìmàP¼ûÐWAð–Åú.¦Âç¨Óê ˜Ô¶¼ð»Œ#d*‘œçoÉXŒs …|ô.ƒ¿»}ä>“÷A
|øj´)žÜ" àŽ0í±‡©{ÿ–«!Ç5·3x »ù"ŒÉíB†¡°Ò‘B¥ª 9\§I [Ðê
?|;…»£L?êª ,¾AØ[KLÐÈÁF.¶üI'/jh çüS]*4T|_irÆÆÿBÁ0Hy| Øïô ¯U|Ðü!XàÀÜõ ŒˆS¼$¢ðúÈÍÊ¿`ç=Õ†á
Òñ[|)"V%õ6uV|EQz¬X|–Ã3Äá ´u3ˆÓŒÿiÔ fÿä\|š˜Q4ïë œƒí¬„šýȶÒ\&}(׌¾$¬ûrðœÙë&ˆrç+ÍÿºÐ@‚|Y³áâHY÷ ŒoÅõ/ú¡k÷®QÓå¬Ú|‚0$$hBª²)ÝÝ }ð[ßëÀ\¨HUá£C'r¤Íð#** ªÚšç•K>¥gÄ¡|—J¬±= Ýã8ìíäOVð«v£9›qÔÌù
¤= ×÷ôNa|)ü.Y¼˜°Ï4uˆ| $Å–†|Çþ¢Wh.¥3ÙÅüÙ@SÔÞ7ð{4C¾ýPÉGUMçˤœ]¼)s_}äFTÓü¥
$5Í„Þ;ÜH ímò|/+ãÿ,”n û„ŸËƒè7÷X½+s (rímàƒ cÀÒ úVâÍš8 ÿ®ªø` æb÷2áTð°þ;€‰èJeé œbž‘gÝðœ"#n&s*çlź:f/^
ðþ‡³„Ë%WÌiç'k(™ïØQ# Ëðß.û/¨nK°^LçÚÔöRCBÆU|A*ÌqѼüv_6
0‡
±$
æÉ8)—O¼‡žÖ·™ç:…C†·s|µP5,Æ ¢r <ä;ð\ÅòÅS/õä)·Ë]¹!ZΛð½È"ôÏUWçƒÞ2Ö³ÙEl|—)Ëa§.¼Ìõ”çç/„•S||út YáuÿÏçJb‚ô ^ðâþCOrhsHçž§ÛV1ëQ|ki®›ýY© P“ՌƣÒÏ쨎#a>넺-çgs=cÄæY|ˆ«ÁÅÿÌzŸã;¾è&ÉŽ—ð¶2ö ñžm n‚ó`^…„ÚŒ0h5çˆv©ç®'³ÿ
¾%|ºóÞ/—@‹ 懬D·Ž5Òð7º*§,ç&ß)wÖ°s2(Ð/ÉLN¹—Kç¢v?U;à¥r;ìÁ)z%ÆÃÀçﺣAß½ÔâB? |'*U^.³Ã —>_'ŠÏ±ð*ÍòüTdçWfÚÐÂDFc‡ü$¼Öõ½ñæòºQ Åñ˜žMŽ6Ń+"BFAí"ˆ„ou˜OÚU¤}¤ïäÌø‡»Ô/t8²otù:ö,:Ìþè+ù œÙqûn¡Ò×*
H»ìÛÒ/2iuo¢AtÙ[aŽ¡¢tŸ?ct¦ "Q{ÙmÐf†¼{¸2»íÐy°Áùgí…Ò{8¡Dlþ„†ßÁ¡ál ŒOüáòîª ´¥IwÏÌHôï1iÑau[MÛݾ¾+Ç<÷Ü‚#m%;ëT€ˆ*e}ù
94¯0‰É¥h¦ŒøËÔä9 œ×΢GitÂÞHÚ»¨=ü:ôtleÇvppÊ÷Nàk4`+
ùôU<©=À`$Np†4uÄ œ@)íÚÄ`î¦å_MmI_‘ýzÿÄœR#NùÁ¯ 95ÿZµÑƒ¨ÁUnÈ Àçåaá‘Ä0•þ$DpÇEÛz·øGcp¯°:èþl:Áóµé40ô/6)àŽO1ÙN˜à¦ /~3!hWF£k¤T/± €¶Ž¦H¾e1"›¬j(O)”Ö,:ÑËuÇþ ÞpÃYO¤„èwm±Ÿuåi†$TyMÙ×P¤ñ;h*æà3´hÍ tÍÑ›ˆ(ø^íQ““£ÖCϤ
í‘áhÙˆmhʵr\åäU¨-›$I³;êtÁ’p0|Ù\= €Á’otí 3Žˆhø*ÃUMÃÒîžM
ñ<ìÔnH°Ã2A®v+v£à»yYnÃÔ;4çHÇšMâÁõ5â©Xi¸‰í‰Òk8“Vn¾>Ü]ñÕ€þ®aîVYñ£°¨î¯à£øVë8±6n¨˜ù9^ã£`âò“ÕwF1ÌýONá¿ß+2ŒVîac'éze¡!Ñ´mö°Îö3Û:°lá¾_€Æ6*ºˆö&ª®€Š {©ä†žïÛ”Dù
=ݘ5ŽÅ‰;ò
tÔÏ41a*^W´“ú€fõÚ-L¯°˜ÅŠ)ú 8ØnN°Ã(A’v+z£ä§zb}ÏÂïœ/îJuMÐÓõMâ¿Xc¸íÒq8«Dn´&Æ”)m2€šáë0uîîL€Ìõ6 k£N‚îô-R¯Ê˜ ÅœM á<çèmúÀö/7üÅ$Mš›´ ~vâ+\£ÆÇynÿÒã“
ä¯X˜ÆÅ4Mª‹õ‰âsX¡¸]íÅÒ8ñø‹ŒøùÁöñ¥mZ¢ë^y´™ðÁùGí»Ò#8ÝnŽô~ÔÁ41a*^W´“ø€hõÚ-F¯¸˜"é”XnK‚≎xa“÷+ù½8cŠnöhÃÔAHCØeáÚo›l].À³ˆÍ8„ÿ£ªV©/âEOÎ
ª¸

Ùÿ%@‹íN¯›¬×ÌPÏrHPgjI©É†ûe¬ês;“³èbƒ¨à¶Ÿž,§25ž„£ä‹}N^¤A&“ÈÑ|³‘Þ@ ñ+~™(a0•(f½’,ej¥pS•©÷w…3>L/ú„ pýH¢Jëk‚‡µŸ=‡U³3¬.În£Z¨Ç€XŽç'¬’4¾ÏiÑ1bI*[A/BßHÍó¾U±j[ª±1Z8)d°öCÕC[Cf
r:܃,“¨ª3n-³ÙczRÙ9q#j*€«ƒ¯æx¨9.Ÿ.üjÙ †wë„dºXËd*m;`|̬§?aEBbž È•ödŠáMA¹Žg—¯áDYnâY¥*¿¯ö†¾Y§}èÞ4d—AUø¨|*™û5rŒÎFV‰¼š}R]?Ä×ql|„*< £ž×ušà«"] $ôñE`…z»¤¥‡h_“){Òé;?kyÈ:QÉ&>ÉÅ
Pœ¢.KëÃÓNŒBuýNò²]b ÁXb¬ƒ’c£ ŒˆŠ×ƒM½Ü9Ή¤‘Òà€hÞ(ŠhË5;&k»†ÂyrÍ~¿ås¤uÀdåb¶Ek!Å&’j •ºZàBÃFůɆP¾P›Zq¸é:¡«3§B/¢Bî^H´mÂßL1.@G›þi®ÆëOl=¿œuö°Œ5›/¹uÍæ1'¸»Dâ%õv]™Š"ͼ •´d÷«*í¤5‘vAQX´@M¹@Ù†-ˆ*›±}&ZÉó5mæ^µEínYT*pO±ý{VP˜gr—?¤;‹]Ѻ(%gΟsˆè®O椫ñ)?Ñz‹EÄ=1øGìfH¾b nAR¶5œŽ=²
f@BÈ0ÂÁ³‰ƒ‹Ò"/ 勘B@Þä
Îö=q™½ëõã™—8,ž£]ä}(“Íp,§KÝ[‘4V{À·ù „cåŒÚÎ{ß°7CÚ¹6dЦr@“ÒÂ?h(&ˆ´P…‰*ŸdvtjÝ™2šÿ¢yžzt0eÖ’“aD_Mèg[‰¥)–®p:*¯ ¼Í¯PEÂpZ…7&ýC]بêÛíõô[”ÿGi¦yZ÷›[½Ë×›ÌÆ›¯Ù€‚«L¼b
”qÍÅ»¨aŠTn>Ù¼1]dK¬[ƒ–Yµ£j‹ÝØ,uª[Ë—˜^.Ÿ¯'ð®´¾XBÓau.N&õ+"®®û§ªš@g1¾¡0éYÑdÓ´€VÂÆjŠS²±f›@^C·.—äBZD¸.Ûg¯|uS¦Ë¦âF÷:H;°B¥n׆Í(x Š•°±[Â_Aë¹^:¯†0Bñ&W®kÍ×ûžÚ²mŽ›:]ªÃÆ4è\$‚1VÃ(.+dÞ®]‚cy*"{÷5d–@i)×Zb®îoå]Ùñ
Hû.+Î8 ‘UÅ«gUÊn®´pŒ®la3^ÚqéŠcõDœœÞluÎtP3¤–2œm€×/ް€¶+ÐÊ*i–¹Zêé¾kÌ…„PêRâb™§wQ`™bnÛæƒîÂã~ã$
Ø+]%ù×ôážüѱö" NÎÕ*‘µw/¯^¾ñšeöÓ^äì×d•Ô{8• {(•¨{ •{•˜{•Š{þ•z{î•j{Þ•Z{ΕJ{¾•:{®•*{ž•{Ž•
`~8úÀn.êÀ^.ÚÀN.ÊÀ>.ºÀ..ªÀ.šÀ.nÀÚ.^ÀÊ.NÀº.>Àª./ÎûnøÀ .‡ÇÃ:ÆÓŒ‚,×ì³I‘l>ã+þ^š7wj1¢íŠùí}ëíQ×í1»í%”GFñ3áEcóï/cÕïHcªï\c‡ïoc”ïpctï“cCï§c_ïÍc(ïécïçcìÊý˜2´˜{m˜›5˜áóÏš5§Ü šoTК/t™šw{4àgíÔWíÊ=í“Àí450΀EeÉ•E×ÉEýÉrKϬ2h¾`2š¾|2Ǿ .(±=é0õL{Ì•9{¥•!@“ÍEzÉŸEwÒv±‚YÏ‚ÿìïM)lËà=b¬.þéö@RþzÝ9=´»LÓ‚•"{”•{!• {•—{ ûx:¥{ §Lû
•Œ{ø•z{ì•g{ÝŽ¸Ó
.Àç.SÀ(óÒwÀß.3À‡.ìÀY.ÆÀ?. À /Á?‚-ß‚9O9ÇåÙšt™ûÞ_íÄ,í˜u`{uà²2ýÛa.ÃÀ-.—À.cÁ±ÉÙŽöØrGÔ¹…0ºÞ0jÞÚ0JÞ¸0'«pö{â÷ûH•ÍrÑÉJE½É1r*Á€2z³\Nêc
ì ÃØQ‡˜bYEÐÀ/v=¸ù´{‚ƒc‚—‚œˆ‚m“‚x*‚N§‚[Ï‚0ó™ûIal—à•l@àÍl)àúlûÆè[×Ä[7×´[T×…[ˆ×a[‚×J[ÈÑÁK&9²µk8zDÜî7kÆê6o¯àIp×}ˆ¦{ͰwžJž×R[ÆÑúK68"D{&Új0‚ªSɱEkÉŽrIÊn2¢¾P2·¹/_õ؈ÜrÀâ.dÀì.^ÀÙ.QÀ·.,À©.ÀŸ.êÀ[.ÀÀ6-=#&.¢À.’À/b5‚¯j‚Šq¹lH0HÞ¼0>Þ¯0Þ€ýÚeGשMG¿©(G—©Gp©îGo©×GH©¶G"©¦G©–G©†JòÙvšâtfšÒtVšÂuFjºt6š¢t&š’u`µ‹9m¶Ž,}[«×M[»×][Ë×-[Û×=[ëÔ
ï©
w~6úníê^íÚNíÊ>›\•.{ª•{š•{Š•þ{z®îµÉEE£ÔU¼•2{¶•"{¦•{–•u†+À·u…Åï~0Àí0¹ÉýE+ÖÍ0ÉÝE[ÉPEÊÜ7º–;Þ”_Z8\ûlšè©Ì!¯žE1ɧEAÉ·EQɇEaÉ—EqÉgEÉwE‘ÉGE¡ÉWS±ˆ@Á‚7Ñ‚yáƒEOñ|1líè\íØ}¦{È•<{¸•,{¨•P˜ EqÉgEÉwE‘ÉGE¡ÉWE±É'EÁÉ7EÑÉáDEHñGäOc÷ïcÇï!c×ï1b§ÿb·k‚~©dvn<O[½×/[Ù×3[Ñ×;[é×\áyI Ž‚}~N21¾Û2I¾£*Þ«5YWk$.œÀð.dÀä.lÃÜÚxOï¥cWï½c/éÉöDJý,àõHûI
lïàl÷à)l§àAl«àY^i`Ql»àicƒ7¥ˆ@æ©×C[¡×K[¹×S[±×[[É×?[ñÞàJ
×ï[×÷[×ÿ[ÕÇûu×·[Q×»[i׃[a׋[yד[q×o[¡×W[½×_[µ×'[Í×/[Å×7[éÞàK×ë[×ó[×û[)×Ã[!×Û[U׃[a׋[yד[q×›[‰×c[×S[µ×'[Í×/[Å×7[Ý×?YÕ`p1ädíì\íÔTíÜL™ñ8í”í€íˆ ípøíxðílÀí4´í<¬í$¤í,œíˆÎpÞ`.ÐÀX.ØÀP,À4R1bÛ•;€.ÀŒ.üÀt.ôÀ|.ìÀd.äÀ\.°À$.¤À,Ï&0ä”dPÜŒºwt3Ø5íÄDíÌe´4í¼,í˜ôí`èíhàíPØíXÐí@¼í”VG@ù>2ñ¾ Ëã7×o@.´À4-¼©(G¨© G©G„©èGl¾´*9Oµ¥9Wµ½9_• ;”•{€±ìÛx•ø{p•à{h•è{L• {$•¬{•”{•œ{ Ÿ„®Ì…±ÈmB[ν‚#Á‚+Ù‚3ìñ÷ZBÍó[×ûX)Qƒ›Ü£š¸t)š*tš‰týš0tœœbÓ€è%ÀÞ"ÖÖ“JBÔ»š"w=<µ5í½-í¥%í*í•í
í…íýíu4DIôýK¬È6˜Ð˜àùqÚ3¦¦ü©Ü{X¡¶{̈ÝV5Ï/64‚6â‚cbÎÎ]~EæG9f—P{C•Ã{ûs;ä{R•£{ù¶‚•µ{ûw:Ú{@•–{•[qÆGò?(Ħï`c4èÎ0I2'¾ 2_¾ˆ5ƒ°¿ë?‚0Õ‚oÇø2]-©›_þ(0G¥©–Cécîëç `Nl†àfl‘à‡br.—þ}£G©‰JÇÜ)šptó›S†ô9yX;…íEÞAÎþöB*¾Ð2йH½“詘\¸˜l‹˜œ˜ˆa˜…v˜žy˜*N˜¦SÆ…‚&?ÎÉEæÉ]ôàgl5òÉzƒlðà)aÎ[2w“-…Fr˜©B˜×™yt¥Æs‚ž¨¬RôÂhà²p¦ÊÄþOæÔã:³æ•{ˆ•{r•óBUé·¾$2Ú¾:?ÄÖïGb‡µá2.—À /h<‚ú1‚¬W‚€‹‚rÄ%‚Z‚
` ÆìàlÊàHb¸¿y`uâQž•Ÿ{õ~>ú©H.¾£2X»õòʾ¥2D¾´2R¾‡2©¾C2¡¾K2¹¾S7±Õ©¼‚ '”‹SÝŒ»¦•„{ EQôù3 Z÷¥è…ú°t8š¸u0Àž³µQ9»@Ï׃y£œu }5™Ðu»ã•=ÝL1DÀí0´ºxKúNÃŒù·ÝÊàô×ó[ÕÇî™Üý¶‡6kQ‚»%mbÞ 0„Þ %p}ì…&±ä:f_ïµb# ‚7ݨ;Þ‹¸C@ÃP!â{ü©l*ÚÃî!³Bî=9M<•O¯É”EvÖmT0ÉNEºÉYEÁÉ4EÔÉ EäÖBŽ÷Ûn.ìÀ[.ÁË~On‘`Rf2“Š©øG~©äBRÂâ¿c}¶š,t›7ø{á£` l·Pìkàlà•lGà*lOà¥lWê½Òsì
¥»?#·B™\ûl>¼{ô•o{Û•B{Æ•2{¶•"{¦•{–•{†Žòßv ÷%f.ÒÃV›8Ý5ú‹*0ªÞ0šÊެe[ƒ×u[“×E[£×U[³×%[Ã×5[ÓÕï/t†™òÞvíâfíÒV¿šûF•²{6•¢t&ʦï{cï‹cmî›(•«‚M»‚]Ë‚-Û©="0ÞŽ0
é~3ú©_Gî6.ˆ@[íÑÆGD9°µT9vµ”9µö9áÉîR—®û›Œ©h¡³Bòbï 㩪,%rË8©ü›sÜ×g×àÌi×iYʼn\&ÁÎxoËÜ]F³P-ìïrsuÍšJu¿,,7FáóO:ÉÕG0³Þ#.›àƒÔwž{×[x}4
ÅlŸoÝpË53U˜{Ë´4$ôʘûïÖb ¦×9åÌ[ '~ÀJO¼Z˜Ì”E<ËðIuBFϱ"åIÏ»!°'€–ס‚0Ì›‚@ºº'|!`Ñ<Qn%`ûešÇeöoבYv ÷í`é¿èûÜ•V{½•=p¥Šïæb ƒ©èÐ0-ˉ—løÃÐlÞ00PÞš0ÀtÔÁòí‡ëímÅŸÕ.U¹-ÿÀ~ƒê¦"˜Ç¬P0«§àªfT2- ¤w3èuYàfµŽ9qëÓÞG&ÖÑ•ºt :FtoÓÀ9ÓÎÖÛo‘lhÃBþßG¥y4ˆ7²Sjéºã³óBAb·¬£ªEk“ò66Œ7{?•§”ÉñQ·„ÅYoa Þ0CÞ%ÂR»b˜?ñÕ{š»uõàH>µ×8ûO{Ò•ý{x•î{l•Ú{@•ÃF;é¼ã¾>
ÄDZìªë\sÑÞšZuÎàJ<µî9\3Å•XWÙé˜Î¾5
µðqäîo>¢hÞÔAŒu“.•J{¦•챆•‡íÝMšÅoôG~ÎÕ‚ è‚
` Ëòïs…šGt¶›/æ Ì©X Äß½;n.чüÙUßv±1Ør²À6?vÂìâܽı˜ho˜¢#˜ÕÒŽq[ÒÔìåw
e>nÂÄÅ`#Å›c7³ànÔÞ×}y38{p°npd;PÚ«nÓ*U¤M·iiKz^ɹ•c±»Ì©Ð½I]ëÉÂ[°ïN»¤É&åáúNm;v´ƒ-R)<‚PÅ>ßÅÙWr •˜{š€$þqb› ‚c‚k3™ùwäìb ¼,45„ň}Ý‚?Õ¹
lÕ4 UˆpZ–`ÀÐà !ËÓþnò§YM …0—2ô(Â4pup¦LÌ+E™Õs{?lÀÜ,T4V¥bWÕ?TEÉEíóp£ÎÏýb„¯Ú
‚ïn*{Ä•D{Ì•<F´é‚E»·Ï¨. À.À˜Ïþ0€Ëf›2t®ôH`wT›H_™Ë¡vdåÿîH{ý•mPå EÉÆE,ÕΣ_.Ê#Ó°š&w”‘MéJÅô2¾Ï2$¾Õ5KI0q”Þ08î¯?ý¦¼û8ôD°Þ¿•;{Ÿš¥FÊÆ/§.À{.Ï#â'rí+§•íEÛs›0*J¼Š5s‘›ì-f@˜§fg`°a#YѰ]•âIA¾ÛÖB'άúå˜XKö: {.œ«ExÉdE†Õ%8¡@þìØBBf¿2ï5©¥G©G¤u6çt]šßuE]€õ©˜C˜èÙ1´á¼ À¬ZŠkïèì÷Mfl“îu1¤žp1•pAÔ`,ÂÞàjlˆàulià’lBà¤l$øgÄÄÉvXžâpÇËŒ=µ×“’ø˜"J3Cþu«G©ŠJúÑ-š©uûU:û¤ž$\cÎï2c îÉ5`ÞE0±Þ 0]ÞÅ.9¦r?
ÙµF9„@;ÕcõQ.ÛÀAƒîΘôáP3þ³êS¹©úMðWT{.Wh¹úªZÿ¼ EÖx´›\V”iÚUê
Ö§AGrëŒÙª%ÉñXâÀx§p0‡Þß,^ƒ¨{û7ßuG‹à½ì”î‰@QÆíšíýÞC!É×E<ɦ[P±Ã-Þj˜œgv2È9.F Þ=\5DÊH†ÿˆàæG)œìLÔ˜1@˜¥VáÞ+[ÒÔäMÉûY&‘;"þŸ+G*©@™ŸC‹$…cvïc%`?l®à\l†àog’þܳ’¡ZCëdüubM"ì<üáø\DÇ*kŽ¢Y27¾¡2Z¸¸îwP*æí]ÁíèÞD,É0Zº˜p‡Ë2ý•ƒ.û|–×Ç1õî8åG{ú{ë•Y{³•7T¡ÿErÞdv§öûΕJ{Ú;èx·ÚŠhòÛ{l*‡¤ nm7Ò´8aù—õ*G¨2î¹Øäp*rÕ#™º5BÞ;˜êâî? .0À¦.q»¶dÃÜ3lWà±lZàÅl4ïõA‹FÎôë~_m`w×w]sØGên5ê¨jÄ÷5ê†>B9jµ®ÜÑP’T~3‚UM‚„‚TÅ‚`ÆÃù¼-Д%É¢EWÉœX«ü{¶›¹V\Òb8¤¿«øw“¡†˜Ì3[Øq/3Ú.?!fÂÿ
Š^ÜU }>{Å*"æFÛ÷5À³,'4Žç`±@B‹`#ÍvÄÀæN{Ž’*„çÃí(ˆŸ:Ïè{ÀŒJÔ2±¨ÞÚ0BÞº."†Äæ€ëJ{°•:{ž•{Q•Ò{I¬Ã‹Ð6<Ë:Q$1ðÞj,Ã%lhíM¼9 µh9šDûßO}iøÞgq¸È@
Ê|„ùÝ3xó4Œ-bÈ$[»¬rAu©¿M÷¾ßä$A›š®Ê*9..¯Á· {v*ç °]Ýã÷ÚZ}
½˜EáFV[À×;[ïÕù
H“•/G]eìÊõr6‚ÀI¹¡Ô0«Þ$„ãà'?p °F1>ã]ùð¬É Äj¯wl8æ3½h¢Úê`ï„crï®cUïð`ãNØ:ÙÆ+ª—w›_¨Ë˜iEÛÉEÿûæO%7íaιè&µô8ÀHîßì²[)÷7þ¡©@eH@IÑE×Þ F ÆÎ[?•ÃµÞæ0G¿è¢µóŒ'4Õ~°2b¾š2˜¾D2¾¾.=àç*E#¾ÞBV†§œ Q¿wÂ(ÛÞ?uŽÊ#HΜµßÈ[E÷ùÿF×G,²OR.và±Ô(îÿûŸ>{Ô©=Ò–5‡²‹õôÛ7Bþu»BãC^•EôþáB¹ü¤×‚…}¾o¿Ç^t¼›$`Ï*ZËÒf¤9‚Nµ‚>ÿsf,ÎżåaÈÞ„%ßî¾Ç@‚¿{3•»ô9(µÚ90µÒ9¯GðŠ4ulàúløÄÒ”ï× =Õ¯wS…8Hê  æÊI4¨±V‚•2†tM¼ýì›/ÇŽ.•yMq'Èð˜.îF ¥€«zu?3§8àÄÁ¼3¼õGBò^½ÉŒv'ÆàDlàdc˜5Az©ˆ'E¤ÖZ(•#{¥†y5âG. h· gf¥5—pB÷).’Ã
é2j˜áÕ}Ïè‚͵8”1•–ôø‹¸Q,Y¹D íÙ -ÀF„óßyõøì˜ô˜‰˜¬gà8²×7R ¡HÛ×M•£{•„pGöp5αӅÁýÖ-¿Òÿ©huÖÕ’û¬•{ŠŽúÕ`.Ìà ñ˜ÞÍ$¦Ô9íµ9õµ9ýµŽ9xRÀ\2˹0÷‚Wß&,„OÐ%vWà—l)îë2hQf•@{‹•ø{!¼©Šf:î襕R÷TKSÆ•[v×iYœ#*yúûuQQl•2{©•{¬Ý R4c‚6r/UÀ³' sI2›*±š‰ÔÎõ`ñFFëGÒûã HEµ¿9*P¯ûöGF±gaœÞÅ,)ô&Ì•
CKå>7Íi"íù <Cå÷štï›g1no{ß•Wch6ÜÖA¨˜mX˜Ì ™É€æí>È”Y9ø`-Ùâ@R\!$«ÕFûe9õ®€~w×eX[òíbêíj{0ÂøY%±Ñ>À§.Î#þɦB—ì™Ì•k{î•2{’•üGddµcîö°*HN5ny¾ÛGŒ©üBt&Tü8êIWêîÎ9(Ã!©Þ´-Ñ~˜KÐywÔô@øê—˜‹~î3¯2rݯw•‘tTuGÎ’7pÔU–¥F¯B,î`â3×r[’ÔZ̯.Ø6(&òÉÖ5L1 À~.ãq”ép3î¬NËÌc9™ßW} èÜ]qÀ.[w×eYPÇ‹íÿqâÛûq›·¡-Ê)ì ëÿ¾rBΦryÄwç½ ñ«‰øãB EcÞvXŽ’Ÿt6‚Ç'$3Å?š¨tÏ›I€B¯è‰ì'œW÷$Hb¨$“¾fÿµ\tÁ™™ÂÂôM/¹¤= p.ásóa;’uå×.âI:ž†Æy õÉXò¶{b•ÖAúÎt:©F»Ë€Êã,s\ÃQ±WÙÀ]Í_7u¨]àû›UXôÒlm´w{Ǩ=Šˆ‘îʤÇkÂP㯽´û§•/u0©Ú–˜‰D¡`•làôwøK0×§XB@¯ícpû%5À¥. Â}¡ÚÂþ
þ[”ÉÉYÿwµ`-Þ4ÜgbAŠIç$¾Ý%>@Åu3¯èwµÔÊHg¡µF9¹µlŒERtîCntÖËÆX,!ªuiô¿V²É6ø%Rr¥dãìʵ0 M»YÉÄFøžvWÝÕÿÀì‹©Ô1¹ÛS¹»Â,”b¾e"½Õ õ B<c «k¾ d•Ÿîz*ˆ‘'¥2íÈ×üñÀùþ#댎+®‹$rR,"jÉz÷¿ËÔŒQ¤ÉH‡l£àEl³ëUB S}÷Çø.|Àè.lÀØ.\Ãȵj¸èf3µñ9+øë¢æóŒìPùÔ[l$Ün=Ÿìh5ˆñ'M2ÿ0×êô(ùö»ê惌)œ í„xùŒuÚ¬j… ÉèŸÂûà•PqØùÆKë†SY±cY¼›49><8ÍÅP2ý¾2õ¢éo
¾ï7±¿hÀè.`'þGXGØ®PyV,~1×ï<,´4Ec·î]9õ À“afoy3ý›Œ“ÄB¬ƒXU[m¶*wÁ¶«-”€¬Zm9Ckî™ç CHeäɬ1nÁP{¬»•¤{,•œ{à”7HÑŒb#ÿ™b•`ýîñXBˆËYsÄÈ5MâPMÉÄeOâ }ÓEuÕgøIx N0`ÈèH²{·Œ›æ“¶MA=ø€~öê1)OÈvO÷&)’Û‡^òõáõôâWX÷¸/íöÒéà¨'IÄåu¹Ègù)4![‡9§áûRúÿ J `—€‰wì6ÑG…¹à
ØÓíEûNŒ Q)ì) ¤.\ß Æg$
wï 0ìWË|Û{ø–à({E)b£œ_¤œE¦² ûê,aû71·ß91¹Ï2¿¨Ø´œh“œ|•œm9òœè{|—„f÷…zl‹t”è‘õd¬õ8Ãá„nPóT*ÁžßmDшå]Ñ‚o^ÚêœY¶*!`à»äVßЕ
ªBAþàÚM£”l ù«ègäUt¨• öA¬ùº’Äø‹íHـܺ<—5ü9X
ò†Å÷†Å’q{VoOÁ…sœâ-yÅÚí±Q˜þ襀q¦Ì\ÿ<
V/lúεY™OƒÌ• tZ4a™}1ÙÍ*£Žân„Çzfí
ϨÐŒ[ùé?rÿ4`œ>Pq¢Ï ÀjÕÀäm„øªYäƒ
`œj$·Ì±ÔÂz £® ifÜ›í›eŽr"é§…f¢ÙoâCHKàRn;Óý‹•CJ%b±Úß(gØÇÚù„Hݸ~T,æ{ HSié]ÜýÙ †f›”³)€¯2oy„0Çžn*ÎÑ ô)Iý×`õº‹®[ ÛjVqÖ‘kS^E˜³…ÕlV!Øï%å‹61•KIÐ%r ^…O Ù•öµ´¢í¿Yge6Í„.sƒB4©™ôh¿o ¢ÄQáÃô•VåL—Ù*dŠðÚ¥‘ ×kÏÞ°d—½á/KBäóÐŽqkÀD=]ì˜d¡ug+fJ€ØnôÇñm‰jD…y®\bÏZ~º¹Ù9ͲC8ñ*A“ɩۼ]Žj\õ`9c¹Š˜°“+’r‹£Îmó›µ6½ãàå¤ZDî³D$)Æ0aežåÜ·$m†;¤nÒÐ.ª,…MØ)¸Ü0«ZôYÒ‚c-ðúñ ütm>ôÎec“ÁHÚÈ'Mé¶Ntd½*Nuj3¡^]Õ^±0i€A.^’wU~p&ìÂg^rd%N*µ£cÎ+¡Ù.ÄJØ$ÛB”“—ãz[àv€•õò+G ÿX˜ô
6/æA†Ð†ÏÄã§æž¡Û(“v\”e¨W„t¥€ q
¿QpƓڙ<p°ß2<;£)ë*HéþOž‘í4ÎObm¬Ã–ÉKLC-ÅU¤—ÂÝžjÇ ¬RAàÎna•†çCÚƒPC™ƒ¬ƒtÀ\ÊžAQe
/¥;7QÈîJMåk(bä’íïdòȤ
©8E‚¯kl—:%Q8nˆÁý©…0ÍŠLL1ÔöU[(t‘Øë>íC4÷Î{€êÙC¸){¯®’´5ö9ø35ƒÁÛð<ÓeUU¤çZ4¿ß¾‹Ç_|úÔ¥kÝÿµ¯óðÇÏu̺LQq0ûV¼42eH ®NΟj-˜âf'ü ×çBO«`™·¹)üéllÑÃÅ׸M>¹)o™‹eÒµ(E³ˆ¾pÿz Akcmðk¸æñ1¬F¾ºš 1±“„m“ÎW§U•™Â"ˆ÷R´å9’è] m/bÁÆŸíµ™T¼þ^”'zS9†ˆµ°‘óœ®Ìè1\©ÃX¸Å½`½£IEÈ3ÃÈ‹ ³ÕDZåâ4[£¦E|k®1óõM³·ËÅâÔ$¢ÙýдÚ$£Á›â„x’‹ë©õüQÑ¥*b°ó_Lˆ¼ ¸ ‰Àï)Ç„J²ÕUÙËþUåRfègFžÆynS*cuKˆ®N˜r£Ç4U•í]´?ëzcS¶0cîƒ5¿Î9Yæw&û¢… K&~dÿ×
êõSµùÊRòÍgÀ `è ]ƒííÃ# Â=èM!Ô€Àf¾2àºäfΗ5ÎÒR&Fè šƒÄëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>¾ Áæƒì‡Þ‰$÷Æmü½ìúºÿ
€ÏKƾ"M÷Ñóíñì‘÷×뚃à þÀ‰ÂÁâ Rfæ&F€Ò›÷ÆJa9ºèN#ÕfÁæ}÷ÀSul¿Aëšhâ=T4$ Þ [óâ=T‡ÓR„Ãf…óýÔ£Âs€ç
f÷Á)íºêDºïþfÁëè šƒÄ¿ÿÿÿÿƒù •‰ø÷؃è÷ÂÀÁ†ö›âºö©ºöŸf¼÷ÆJ-C뚃Äü‰$€üüfî?fÁî<3Î÷ØÀåÁÁî\÷×á}gA‰î¿ @ ‡÷VW‡$JT$ƒÄÿRºóÁ„àfÎGÓÎf÷ÆÀfÁæ…äºä<³ÆƒÄü‰$fábS¶öfû¸«f×ÇUö7õ¾òËqéºN¾ Áæƒì‡Þ‰$övtpâ¾3h÷ó€ÕÇ,·¬ f÷ÞþËfºDM÷Ù뚃à þÀ‰ÂÁâ R¼ó„ùÖºÍÜþÉÈ
‡dÁæ¬î:ë³&¶ñè šƒÄh @ 4$ @ [ó @ ‡ÓRféT©¶÷f¼ò÷À‘¶Ïaf÷Óf¼Óf¿Y8÷Þëš¿ÿÿÿÿƒù •‰ø÷؃èÑõ᱀ղ÷Þf÷ÆÂµ÷Æ~ï€á/f¼÷;Þëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>ƒÄü‰$»î‹ÜöÕfý¡ð3ðÒˆH
f×Ö÷ƇèøëšUYÁ @ ÿùC:›;¾/šËõöÑéU‚FAÁéb¶ófÁÄü‰$òf¾×ü»Áéq{?öºâÅ€õc€úgö}$¸è šƒÄhÜ f¼ðûx)Û)Øf¹'’fú¿îfÆÜÖfâoÚè šƒÄhÁG ÆÆi‰ ¼Öºç «àºäïºä§¿óf¼Ëëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>,$f÷ßfýÜfÑæÏfÿ®1#ÓÆºøìfð¼ðè šƒÄh ðç|fêo fÁî f÷Á6ŠfºÉ#Í:ñfÁæ)föÜÐëšèm ó5Ö¦fú s°¯fë«ò†¡÷fÁ㠣ыL$Ð@é›Ü·mü‡¸ufÊUçfДºþ€Â¡ëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>hÜ fÁæï÷À}ßdfÁî<þÊöÂfÁꙺ±XÔ«ÞhÁG «ïþÎöÓ×C× €üüºú×f¼À¶,fø°€,$fדÎÀêâÅEjX÷Ã!…ÁókÙ×úfæœjƒÄü‰ $€êüºúnþÊ‹ñöÆô¾ÔaÍýºÿÜfý½Iëšëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>èT ÷Öºþ÷º÷г×þÃÂðK ×VfÁî‰fÁâ{è šƒÄ‹<$ƒÄfÖxâfÁæ“fáË‹;òfã¨÷Æ¥&WÓºþ‹4$ƒÄ÷À³Õ`¸J Ô;úfèñQ¼ÀÀàÊÒ [Cƒì‰4$¶ÊfÐ{f;ó»44;Ó»ÀÀìŒfÉŸçè šƒÄƒì‰<$àt`NÊðÒ 8 èìõðüè#”è§Q€Cëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>‹ŽT Ò»êfð8Ö;ò€ý$fÁâÀטּZdã÷ºè$Áéà$Òº–fú„fà9pfÁè|À„®ó¸f÷À›ëšò¥ ͺøõ×’ã~ºó¨³ÇÀ„(É…Ïf¹‹<$ƒÄÐÝLH*‹Ñ€î$fÀ:ˆf;Þºà¯#ÄÉ”Âè šƒÄ‹4$ƒÄfã¹—:ÿ¶É÷À*üEÎf¼Ï„ĺø™fÐÖNëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>‹^<fÈôûfÈY¿3Æf¼Åð¸³kãþÊ÷Âs¾—RHƒì‰$ºà–ÄfàBXºèÏÅf÷À~|÷ÚöÐfÀ¸"¿\€À{аx@:Ø€üjþÌ£ÈöÜý¬3=ºèÚ‹$ƒÄ…Þè}ï‹ÇЉ¥Áèf¼Áf;ÓàlÊÌU…Âø B9ÂuûèíG–ò´~fðŠU€àK€Å˜÷Ðfðý—fÈè†òøç/ùfÁè‹f¼Ãþ¯Gîtfà6Ñ¿Îf;æè šƒÄƒû „ Àyÿ»¡Äƺà2fÈRLfèû¡¸ð+ Ńì‰4$3À¾ÄþÀ3ÏfÀLf¸Zf÷ÀȨçêÆè šƒÄƒì‰<$f¹ïôðÎý›f¸Ñ¬ºè«ØfþQãfÈm¿ëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>‹Jfè(þÌðÖ³EÁfèÑNf÷ÀMˆýPúb‹öÔè šƒÄz ð üºàáèÐCAfÁà`f÷кø$f¼ÁrºøŒfÁèófÁè7f;éºèU3źèÚfÁàá°—ëšò¤öØ…Á€ÅÖ ÷fÖ„æ”ßïÖÕÅJWfé‹<$ƒÄfö<™fÁ‹ fÎ[κè?÷À,;aöºîgè šƒÄ‹4$ƒÄfÁË΄àÐÒC3f൷÷ÀÿÏIöÙfèvjYBƒÂâúf÷À˜¢ÁG@zèõ€Ä«àºçcfÐÂ3ÃSÿ $‹$ƒÄ;ãÀ=7ù#…åfèƒdðb*„ª÷À;î+f¸;è šƒÄéÝýÿÿð
½ÙãúC›f¼ÃfBºâ»f¼ÄfË ãh  Á$$€ùfá?fÐZ^fë÷»fÁà]ÉÇ äÁà£h Þ fÁëôð%YCò‹ÀÈ¥¨™£âºèˆÁàrf;ñƒì‰4$f˜QþγÃЫMì+ÐȶÄfÁèfÁèKh@ UX$ƒÄÿàE@ñ€fÀÔ3fМ³ø¿ÁfÐ0ïºðÕ‡÷úxB#àׂ)ºï+fÁïw€î€ÀkfÓ‡_‹~<fÃÂ]Àî@þÊúqæ1fÁâ‹€Ê~³Ëfû-Cè šƒÄ‹¼> €ý¢fHÁê-Ã#Éð3«ð_óÀ—P‰÷عGMz(÷öÔfé ôf¸1?È*”û˜fáfκè´fÀ.è šƒÄ‰óºáàKüjª÷ЋÃf÷غáOÈiˆöf¼Àëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>ë @ f¸FÛ;Ëfàíf¼Ãfñ³"ÄÀ>Ð¥öÄþL_Þ3dzèf÷ÀÃRâ±È¤ff…×÷Álw]Äè šƒÄ‹+Æ‹ÃÁàf;íºå¹ÀäfÁèp±šèñíìfH‹Oºæ‡û£!ÇgºæàÁüÓÐà€|åf÷Àݪƒú „× ÷Ðf÷ØÀNKu-f¸JÂ3ÃþÌfÐÃ[ºøí¿ÆòзÂò‰„ÝÈ÷к蒀ÿ”f¸0׺øoºàÊè šƒÄƒÇ÷À§vúðcB)Æ£ÐfðQ†Ð¬#%ݼÀƒéf¼Â÷À|5åGf÷Ø€ÀpfÁàåf÷À;³ÀöÄè šƒÄƒù „íþÿÿf‹è šƒÄƒÄü‰ $¹ Ñèâü‹ $ƒÄëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>ƒàè šƒÄƒøu3f‹%ÿ è šƒÄf¼ÄºøwfÁàt‹Ãf…ãfÈü6€øºø.öÜQÿ $‹ $ƒÄºâ€üRfÈ›fÈE„È÷Ààw€0fÈshHQÿ $‹ $ƒÄfàÊ3¶ÅfÈ„á«ÀȰèúsठNý¼ÆƒÇ¾ÆfÈI÷÷ØÀjƸ¸÷Øf÷ظ…J3äfà2©é¿þÿÿ÷×¹g:ðv»éöÕ€ø¶¼þfËtØþÈ‹ÐfÁëé‹~<+Ôfð…¹Òf¹¥ »ÀfÁàÐðÖ*³f⾋¼>€ fÓ¼wfð7?ÀbólÓfðM.fÁàŒf÷ÂfAI÷ÐV¸C|¸ZE³Á‹Ú£ò ßfã·×€ã_fÀº{ëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>ƒ „½ è šƒÄ‹G ðƒÄü‰$ëšÿ•@ ƒø uè šƒÄG ƒÄü‰$ëšÿ•@ è šƒÄƒ? udëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>ƒ „÷ ƒÄü‰,$UZÿw]õè šƒÄƒ} „Ö ‹M ƒÄü‰$ƒÄü‰$ Éè šƒÄyƒì‰ $ëLè šƒÄƒì‰ $ƒì‰$ëšÿ’ @ ‹$ƒÄ‰E ´{f@f¸hcþD3-®ºâôf÷ÀÙ@€à!¸É4‹$ƒÄƒÅëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>é ÿÿÿ‹,$ƒÄè šƒÄƒÇé9þÿÿ…âÁçáÿfï$%f¼Éf¸r¸Ð[4¥fòñThª; fNJҞל'¶Ö«×f¼ÿfÁêɺ÷¯Vƒì‰,$÷×f÷"ÉfþòfÁç£f÷Ç+f¼ÛÁï6Áïo‹F<fõ‡—ã¨KÛ fÁãf×Ódf¹ÖÓf¼Ì»÷è šƒÄ‹DxÇJp²ÔfÁééfÁçÀ+ÈÇüÆcÁ爻ò¶ÿD(Õ+™Ýføs2£âfí°NfÍ7¦fê΀þÁ‹ þÆé:Ûiçf¹R‰f;ÉfÕÌ÷Å
ãkwfÿYëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>è šƒÄð;Ý×3¶ð*fÁâ:€ÆŠf¼ßºéÉMW*‰…Ƀì‰4$÷sãè×¶Ó3üùÙ/öfá·•f÷ÇAÊf¼üj €ËÓfúbØf÷¸âføŸÎ„Ëf¼ùf¼Íf÷Ójf×±Ífó6× ÿþkß½e½ú¿úªÃ¥@jç¹¥¯Å¿×²«f÷ÑfõèœöÞÍ>%ðºúuè šƒÄƒì‰$f½ :fàÉfÁå‘ÁÓ¶NïÝÊ fó4Cëÿ5`è$ ÿëÍ ‹D$ ƒ€¸ 1ÀÃÀëÿ‰Äaë.êë+ƒ$ë 1Àë…dÿ0ëƒd‰ ëÍ ‰ šd ëÁXaë>‹F<fÑ‹€×I÷ß÷¡åb`ÀíÜ…ÖþÍÁåfïë%è šƒÄ‹D(ÞfÃ»Ž€ÁåÊdµÏÄÁïf…æfMñ‘q;pBðºÿ1Å(áÄfåÓV€ËÃfùàÏ¿w…Ûè šƒÄƒì‰$fÒ fǯfåÿ0ºæ³Å»åýïFŒëšÃU‰åÿu ÿuèF ‹}1É1ÒƒèHt5x3f‹€ûèt€ûét
fûÿ%tAëã)LƒÁƒèë×)TƒÁƒêƒèëÈ] `‹|$$‹t$(ü²€ŠFˆG ÒuŠFÒsï ÒuŠFÒsJ1À ÒuŠFÒƒÖ ÒuŠFÒÀ ÒuŠFÒÀ ÒuŠFÒÀ ÒuŠFÒÀtW)ÇŠ_ˆGë ¸ ÒuŠFÒÀ ÒuŠFÒrêƒèu(¹ ÒuŠFÒÉ ÒuŠFÒrêV‰þ)îó¤^éXÿÿÿHÁàŠF‰Å¹ ÒuŠFÒÉ ÒuŠFÒrê= } s=  rAV‰þ)Æó¤^éÿÿÿƒøwƒÁV‰þ)Æó¤^éÿÿÿŠF1ÉÐètƒÑ‰ÅV‰þ)Æó¤^éèþÿÿ‰ø+D$$‰D$a U‰å‹E‹U ‹MÁé1ƒÂIuø] *** Enigma protector v1.04 *** *** developped by Vladimir Sukhov*** *** e-mail : enigmasoft@mail.ru *** *** site : http://www.enigma.izmuroma.ru/ *** *** THIS PROGRAM PROTECTED WITH ENIGMA PROTECTOR ***  ጠÅD¤ †æÉÈS|«³ i¡ºrD ¾
;&6g ‚of • .µ_° .Ô5 £sb g ©tžê[qÔŒÙÀ² é€ ˜ìøB~†vXŽ@04 ï"ÛPÞ £=i8ËÏRw gþB
eröx·äõ2âéeh7Ã# 0çI0{–r@ 聆ˆ?¥5pî¥q@Â7bý´¬ D’ˆŒ¥( 5 h)ÁJ Ü"ÜbÞ¢Ãã
Ü)
ªûˆ\+ÎÅðeæ  F¹Q £*ÖŸé ž!Õz<è ÒŒV g3FHAUKTî2 BXG79VMYìNtSìCäD}4{2èTÇLX³RWÇÀNB59w7|KQEMX@PLVFWíì9BâTôE?38ãC7³A©42ûy~zH€JN6QWUFAÿ‘5RGÑL¸@RîÁe5HMAõKF ZPW©QäAæU74DKBENHV;9F=W<67QZ9>KæC‹A©MLBþEÕ93YÅBÓ¸TUX:íÅZ¨Šòä8YQD]F9øHKQGP·Ÿ§67·TiA»ò2—.À:Close dcbugSr,Ñanó§'st޼Þ.]PNog~žmwil¯nŽtbVWqd

µ\+Dú‡ foŠû8W¿‚LTh‰üÕis›v§‡ui2@ùReýÞJéKö£p_Žcß:on9È&zÛ.¯?¼Lf.Deks³*m§/>ì
SV÷&wÔnò$gÿý[€ATrHiÅ peoLdšva F$ëmé2nfÔ™ÿ"ü›Áufºå@.Úª$
É¿ Ö¯ÿË• UAETh!õ"ø$ti/ýrSë CÅè¤ï{牗¦ØR(emÌud«×£s‰agÖo „„Yo€Ø syät°á}læk² û|L
œÖd’óy…"tÚ'ssfùû|b™/G(W)¿Gxp¬ld¾4ôšW¹Cu@May¤¢˜«Ð¥Zã ŽÀI.Ï ÝIÐÄ €SOFTWARE\D¼du–Na¿eX IIDê¶
cul8rman is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-24-2007, 09:31 PM   #88 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,813
OS: WinXP and Vista


Re: MS Windows XP will not load when connected to internet

That user acct is highly infected as well. This is going to take me some time to prepare the fix, but I'll have it for you tonight.

Do you have the program SpyNoMore? Please search your system via Start?>Search and tell me the location of SpyNoMore.

Also, I moved the other PC to it's own thread since it's not affected by the same infections on this system. You'll find that thread here
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."

Last edited by Ried; 03-24-2007 at 10:01 PM.
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-24-2007, 10:23 PM   #89 (permalink)
Registered User
 
cul8rman's Avatar
 
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP


Re: MS Windows XP will not load when connected to internet

I searched and Spynomore is not on this system.

Now it makes sense that the infections would not go away since they lived somewhere else on the PC and were not being treated.

I guess I know what I will be doing for awhile.
cul8rman is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-24-2007, 10:29 PM   #90 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,813
OS: WinXP and Vista


Re: MS Windows XP will not load when connected to internet

Please copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

Also be sure to carry out the instructions in the sequence listed below.

***************************************************

We need ComboFix.exe on the desktop of Duane’s acct. You can either copy it there or easier yet, just download it again and save it to Duane’s desktop.

Download Combofix and save it to your desktop.


**Note: It is important that it is saved directly to your desktop**

-------------------------------------

Close any open browsers.

--------------------------------------------------------------------



Go to Start>Run then copy/paste the following red text into the Run box then click OK

"%userprofile%\desktop\combofix.exe" /v ssqnllk pqkuaaau geedb pmnoonm fcccddd mljjj ierplc iepref32 ips sstqo sqvyswsn

When finished, it shall produce a log for you. We'll need that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

--------------------------------------------------------------------

Please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Use the up arrow key to highlight Safe Mode and press Enter.
5) Login with your usual account. Make sure to close any open browsers.

--------------------------------------------------------------------

Go to My Computer->Tools->Folder Options->View tab:
* Under the Hidden files and folders heading:
* select Show hidden files and folders.
* Uncheck Hide protected operating system files (recommended) option.
*Also, make sure there is no checkmark beside Hide file extensions for known file types.
* Click OK.

--------------------------------------------------------------------

Using 'My Computer', navigate to and delete the following:

C:\jishhs.exe
C:\WINDOWS\alg.exe
C:\WINDOWS\avgav.exe
C:\WINDOWS\System32\3718845C
C:\WINDOWS\System32\99239519
C:\WINDOWS\System32\dyghasfc.exe
C:\WINDOWS\System32\icqmlib.exe
C:\WINDOWS\System32\kr_done1
C:\WINDOWS\System32\ocxapi.dll
C:\WINDOWS\System32\ocxloader.exe
C:\WINDOWS\System32\openopenopen

--------------------------------------------------------------------

Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. Close the Registry Editor now.

Open notepad and copy/paste the entire text in the quotebox below: (don't forget to copy and paste REGEDIT4)

Quote:
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"icqmlib.exe"=-
"ocxloader.exe"=-

Save the file as "delete.reg". Make sure to save it with the quotes. Choose to "Save type as - All Files"
It should look like this:

Double click on the delete.reg file and choose Yes to merge/add it to the registry. You may delete the file afterwards.

--------------------------------------------------------------------

IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
Run AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
  • Click Scanner
  • Click on the Scan tab
  • Click Complete System Scan to begin scanning.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, **Please ensure it is set to Quarantine then select "Apply all actions"
  • Once finished, click the Save report button, then click Save Report As and save it to your desktop. (make sure to remember where you saved that file, this is important).

--------------------------------------------------------------------

Navigate to the SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt I'll need that in your next reply.

--------------------------------------------------------------------

Reboot into Normal Mode.

--------------------------------------------------------------------

Run an online scan at Panda under Duane's acct and save the results.

--------------------------------------------------------------------

Close any open browsers.

--------------------------------------------------------------------


Double click on combofix.exe & follow the prompts.
When finished, it shall produce a log for you.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall



--------------------------------------------------------------------

Run a scan with HijackThis and save the log

--------------------------------------------------------------------

Please include the following in your next reply:

C:\ComboFix2.txt
C:\SDFix\Report.txt
Panda results
C:\ComboFix.txt
New HijackThis log
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-24-2007, 10:53 PM   #91 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,813
OS: WinXP and Vista


Re: MS Windows XP will not load when connected to internet

Do you see SNM.exe on your system?
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-24-2007, 11:16 PM   #92 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,813
OS: WinXP and Vista


Re: MS Windows XP will not load when connected to internet

Sorry to do this to you, but after completing the above fix, would you also please run SREng on this acct as well and attach the (renamed) SREng.txt?
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-24-2007, 11:24 PM   #93 (permalink)
Registered User
 
cul8rman's Avatar
 
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP


Re: MS Windows XP will not load when connected to internet

I found this - SNM.EXE-324DCB24.pf as a C:\Windows\Prefetch file and has a date and time stamp less than 30 minutes old.

!!! What should I do when AVG threats pop up - Ignore, heal, move to virus vault?

Thanks, and I saw the last post, it is fine, whatever it takes to fix this is fine.
cul8rman is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-24-2007, 11:35 PM   #94 (permalink)
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 26,813
OS: WinXP and Vista


Re: MS Windows XP will not load when connected to internet

I see that--it's almost as if snm.exe came onto your system while running dss.exe.

For now, ignore any alerts by AVG AV. We'll take care of these ourselves.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-25-2007, 11:29 PM   #95 (permalink)
Registered User
 
cul8rman's Avatar
 
Join Date: Aug 2006
Location: Arizona
Posts: 134
OS: XP


Re: MS Windows XP will not load when connected to internet

Some notes, then the posts. I have something goofy going on and only part of the TSF banner shows on my screen, the right third starting at computer support... . When that happens I can not use color to differentiate the sections so old programming habbits - ***** Event
The system did not restart when I ran SDFix. The PC also would freeze up, maybe blue screen of death, when I was restarting windows.
I did a search on all files modified today and had over 500 entries. Several were after the SREng program was launched.

Sorry about the time it took, I had to do a couple over due to system locking up.

Just a thought - it seems like this issue is respawning and not wanting to die. What if I did the scans and fixes on the Molly account? I think that was the access point the virus would have come in at.

**** C:\ComboFix2.txt

"Duane" - 07-03-24 21:57:37 Service Pack 1
ComboFix 07-03-23 - Running from: "C:\Documents and Settings\Duane\desktop"
Command switches used :: /v ssqnllk pqkuaaau geedb pmnoonm fcccddd mljjj ierplc iepref32 ips sstqo sqvyswsn

(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\ssqnllk.dll
C:\WINDOWS\system32\pqkuaaau.dll
C:\WINDOWS\system32\geedb.dll
C:\WINDOWS\system32\pmnoonm.dll
C:\WINDOWS\system32\fcccddd.dll
C:\WINDOWS\system32\mljjj.dll
C:\WINDOWS\system32\ierplc.dll
C:\WINDOWS\system32\iepref32.dll
C:\WINDOWS\system32\sstqo.dll
C:\WINDOWS\system32\sqvyswsn.dll
C:\WINDOWS\system32\bdeeg.bak1
C:\WINDOWS\system32\bdeeg.ini
C:\WINDOWS\system32\bdeeg.ini2
C:\WINDOWS\system32\nswsyvqs.ini
"C:\WINDOWS\system32\geedb.dll"


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\PageHistory.txt
C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\WebHistory.txt
C:\WINDOWS\system32\mljjj.dll
C:\WINDOWS\system32\ssqrq.dll
C:\WINDOWS\system32\sstqo.dll
C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp
C:\Program Files\vsadd-in\VSAdd-in.dll
C:\WINDOWS\system32\rpcc.dll
C:\Program Files\vsadd-in


((((((((((((((((((((((((((((((( Files Created from 2007-02-24 to 2007-03-24 ))))))))))))))))))))))))))))))))))


2007-03-24 22:08 280,676 ---hs---- C:\WINDOWS\system32\gebcb.dll
2007-03-24 22:07 280,676 ---hs---- C:\WINDOWS\system32\awtsq.dll
2007-03-24 22:02 30,720 --a------ C:\WINDOWS\system32\rpcc.dll
2007-03-24 22:02 26,697 --a------ C:\WINDOWS\system32\wvuusrs.dll
2007-03-24 20:57 26,697 --a------ C:\WINDOWS\system32\hgghefg.dll
2007-03-24 20:56 72,344 --a------ C:\WINDOWS\system32\qmgmfmfl.exe
2007-03-24 17:57 26,697 --a------ C:\WINDOWS\system32\ljjijih.dll
2007-03-24 17:48 62,739 --a------ C:\WINDOWS\system32\setup_13051.exe
2007-03-24 17:35 7,200 --a------ C:\jvycsq.exe
2007-03-24 17:35 23,552 --a------ C:\yyumm.exe
2007-03-24 17:35 1,997 --a------ C:\jishhs.exe
2007-03-24 17:34 26,697 --a------ C:\WINDOWS\system32\fccbccb.dll
2007-03-24 15:21 0 --a------ C:\WINDOWS\system32\setup_83355.exe
2007-03-24 15:18 26,697 --a------ C:\WINDOWS\system32\khffebb.dll
2007-03-24 14:51 26,697 --a------ C:\WINDOWS\system32\wvuvwxx.dll
2007-03-24 14:42 26,697 --a------ C:\WINDOWS\system32\mljghij.dll
2007-03-24 14:15 26,697 --a------ C:\WINDOWS\system32\urqoljk.dll
2007-03-24 13:38 86,016 --a------ C:\WINDOWS\system32\setup_44644.exe
2007-03-24 13:36 26,697 --a------ C:\WINDOWS\system32\ssqqono.dll
2007-03-24 12:39 52,674 --a------ C:\WINDOWS\system32\setup_56846.exe
2007-03-24 12:03 53,248 --a------ C:\WINDOWS\system32\icqmlib.exe
2007-03-24 12:03 4,608 --a------ C:\WINDOWS\system32\ips.dll
2007-03-24 12:03 348,160 --a------ C:\WINDOWS\system32\ocxapi.dll
2007-03-24 12:03 11,264 --a------ C:\WINDOWS\system32\ocxloader.exe
2007-03-24 11:58 88,340 --a------ C:\WINDOWS\system32\dyghasfc.exe
2007-03-24 11:58 1,048,576 --ah----- C:\DOCUME~1\MASTER~1\NTUSER.DAT
2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\WINDOWS
2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\Symantec
2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\InterTrust
2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\Adobe
2007-03-24 11:53 72,344 --a------ C:\WINDOWS\system32\lanmanwrk.exe
2007-03-24 11:53 6,784 --a------ C:\WINDOWS\system32\lanmandrv.sys
2007-03-24 11:53 596 --a------ C:\WINDOWS\system32\qmopt.dll
2007-03-24 08:46 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-03-24 08:38 86,016 -r-hs---- C:\WINDOWS\alg.exe
2007-03-21 21:17 52,674 -r-hs---- C:\WINDOWS\avgav.exe
2007-03-21 21:15 <DIR> d-------- C:\Deckard
2007-03-20 20:18 <DIR> d-------- C:\avenger
2007-03-19 21:14 <DIR> d--h----- C:\WINDOWS\PIF
2007-03-18 09:40 51,955,192 --a------ C:\regedit 3.18.07.reg
2007-03-17 23:47 51,951,606 --a------ C:\Regedit 3.172.07.reg
2007-03-17 09:39 51,944,564 --a------ C:\regedit 3.17.07.reg
2007-03-13 20:51 136 --a------ C:\WINDOWS\system32\dgjun.bat
2007-03-13 19:32 51,995,858 --a------ C:\Regedit 3.13.07.reg
2007-03-12 18:20 491,768 --a------ C:\ie6setup.exe
2007-03-11 22:17 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-03-11 09:25 <DIR> d-------- C:\Program Files\Java
2007-03-11 09:25 <DIR> d-------- C:\Program Files\Common Files\Java
2007-03-11 09:24 <DIR> d-------- C:\DOCUME~1\Duane\APPLIC~1\Sun
2007-03-10 11:31 <DIR> d-------- C:\Rustbfix
2007-03-08 19:33 971 --a------ C:\DOCUME~1\Duane\Purity.bat
2007-03-08 19:33 8,192 --a------ C:\DOCUME~1\Duane\RestartIt.exe
2007-03-08 19:33 79,360 --a------ C:\DOCUME~1\Duane\swxcacls.exe
2007-03-08 19:33 73,728 --a------ C:\DOCUME~1\Duane\FDSV.EXE
2007-03-08 19:33 6,914 --a------ C:\DOCUME~1\Duane\Qoo.bat
2007-03-08 19:33 51,200 --a------ C:\DOCUME~1\Duane\dumphive.exe
2007-03-08 19:33 5,074 --a------ C:\DOCUME~1\Duane\NTPBack.exe
2007-03-08 19:33 49,152 --a------ C:\DOCUME~1\Duane\vfind.exe
2007-03-08 19:33 42,887 --a------ C:\DOCUME~1\Duane\ntp.exe
2007-03-08 19:33 39,184 --a------ C:\DOCUME~1\Duane\Ntrights.exe
2007-03-08 19:33 38,400 --a------ C:\DOCUME~1\Duane\moveex.exe
2007-03-08 19:33 319,415 --a------ C:\DOCUME~1\Duane\Creg.reg
2007-03-08 19:33 28,672 --a------ C:\DOCUME~1\Duane\catchme.exe
2007-03-08 19:33 26,112 --a------ C:\DOCUME~1\Duane\nircmd.exe
2007-03-08 19:33 2,304 --a------ C:\DOCUME~1\Duane\Look2Me.bat
2007-03-08 19:33 181,776 --a------ C:\DOCUME~1\Duane\handle.exe
2007-03-08 19:33 140,800 --a------ C:\DOCUME~1\Duane\swreg.exe
2007-03-08 19:33 123,904 --a------ C:\DOCUME~1\Duane\swsc.exe
2007-03-08 19:33 117,379 --a------ C:\DOCUME~1\Duane\LIST-C.bat
2007-02-24 21:33 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-02-24 21:33 <DIR> d-------- C:\SmitfraudFix


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-03-24 22:11 80 --a------ C:\WINDOWS\system32\iepref32.dll
2007-03-24 22:11 0 --a------ C:\WINDOWS\system32\ierplc.dll
2007-03-24 14:33 -------- d-------- C:\Program Files\hijack this
2007-03-21 20:38 -------- d-------- C:\Program Files\picasa2
2007-03-21 20:36 -------- d-------- C:\Program Files\messenger
2007-03-21 20:31 -------- d-------- C:\Program Files\itunes
2007-03-21 20:29 -------- d-------- C:\Program Files\google
2007-03-08 19:47 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-02-24 22:08 3762 --a------ C:\WINDOWS\system32\tmp.reg
2007-02-21 21:42 129 --a------ C:\fix.bat
2007-02-20 21:14 -------- d-------- C:\Program Files\shockwave.com
2007-02-10 20:00 14201 --a------ C:\Program Files\hijackthis.log
2007-01-28 22:13 -------- d-------- C:\Program Files\lg software innovations
2007-01-28 22:05 -------- d-------- C:\Program Files\clonedvd
2007-01-28 21:28 14 --a------ C:\WINDOWS\system32\systeminfo3.dll
2007-01-28 21:26 81920 --a------ C:\DOCUME~1\Duane\APPLIC~1\ezpinst.exe
2007-01-28 21:26 7176 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.cat
2007-01-28 21:26 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2007-01-28 21:26 47360 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.sys
2007-01-28 21:26 34 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.log
2007-01-28 21:26 1144 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.inf
2007-01-28 21:26 -------- d-------- C:\DOCUME~1\Duane\APPLIC~1\vso
2007-01-21 15:08 14612 --a------ C:\Program Files\cwshredder.exe-2d092fd4.pf
2007-01-21 15:03 532480 --a------ C:\Program Files\cwshredder.exe
2007-01-12 18:19 0 --a------ C:\WINDOWS\system32\vb2en16.dll
2007-01-11 16:35 12800 --a------ C:\WINDOWS\system32\svchost.exe
2007-01-07 18:21 1 --a------ C:\WINDOWS\system32\ps.dat
2007-01-07 18:21 1 --a------ C:\WINDOWS\system32\cookie.dat
2007-01-07 13:16 25600 --a------ C:\WINDOWS\system32\helper.dll
2007-01-04 22:35 10660 --a------ C:\WINDOWS\mozver.dat
2007-01-03 20:49 5037072 --a------ C:\Program Files\spybotsd14.exe
2007-01-01 12:02 507 --a------ C:\WINDOWS\ereg077.dat
2006-12-25 16:33 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Microsoft Works Update Detection"="c:\\Program Files\\Microsoft Works\\WkDetect.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe"
"PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot"
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{85382E07-2F7E-4910-89AD-16F2E97FC152}"=""

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccbccb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khffebb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjijih
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rpcc
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuusrs

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0



********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

? [2444]
? [5556]

scanning hidden services ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ocxloader.exe = C:\WINDOWS\System32\ocxloader.exe
lanmanwrk.exe = C:\WINDOWS\System32\lanmanwrk.exe

scanning hidden files ...

C:\WINDOWS\system32\lanmandrv.sys 8192 bytes
C:\WINDOWS\system32\lanmanwrk.exe 73728 bytes
C:\WINDOWS\system32\ocxapi.dll 348160 bytes
C:\WINDOWS\system32\ocxloader.exe 12288 bytes
C:\WINDOWS\system32\qmjjnjlg.exe 73728 bytes

scan completed successfully
hidden processes: 2
hidden services: 0
hidden files: 5

********************************************************************

Completion time: 07-03-24 22:13:33
C:\ComboFix2.txt ... 07-03-20 21:26
C:\ComboFix3.txt ... 07-03-18 14:48


****** C:\SDFix\Report.txt

SDFix: Version 1.69

Run by Duane - Sun 03/25/2007 @ 11:53:48.78

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\Documents and Settings\Duane\Desktop\SDFix

Safe Mode:
Checking Services:




Killing PID 132 'smss.exe'
Killing PID 204 'winlogon.exe'
Killing PID 204 'winlogon.exe'

Restoring Windows Registry Entries
Restoring Default Hosts File


****** Panda results

Incident Status Location

Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\System32\xlqtmtth.dll
Potentially unwanted tool:application/funweb Not disinfected hkey_classes_root\FunWebProducts.ShellViewControl
Adware:adware/wupd Not disinfected Windows Registry
Adware:adware/antivirus-gold Not disinfected Windows Registry
Adware:adware/easysearch Not disinfected Windows Registry
Adware:adware/adtomi Not disinfected Windows Registry
Adware:adware/browseraid Not disinfected Windows Registry
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt[.systemdoctor.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt[www.systemdoctor.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt[.systemdoctor.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt[www.systemdoctor.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Duane\Cookies\duane@adrevolver[1].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Duane\Cookies\duane@advertising[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Duane\Cookies\duane@atdmt[1].txt
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Duane\Cookies\duane@bfast[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Duane\Cookies\duane@doubleclick[1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Duane\Cookies\duane@hitbox[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Duane\Cookies\duane@mediaplex[1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Duane\Desktop\SDFix\apps\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Duane\Desktop\SDFix.exe[SDFix\apps\Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Duane\Desktop\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Duane\Desktop\VirtumundoBeGone.exe[²ƒÇ]
Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Duane\nircmd.exe
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt[.gostats.com/]
Adware:Adware/SpySheriff Not disinfected C:\jvycsq.exe
Adware:Adware/SpySheriff Not disinfected C:\RECYCLER\S-1-5-21-1784762916-2740901186-3389046013-1005\Dc1.exe
Virus:W32/Sdbot.KBR.worm Disinfected C:\RECYCLER\S-1-5-21-1784762916-2740901186-3389046013-1005\Dc2.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\RECYCLER\S-1-5-21-1784762916-2740901186-3389046013-1005\Dc6.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\SmitfraudFix\Process.exe
Virus:W32/Sdbot.ftp.worm Disinfected C:\WINDOWS\system32\i
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\system32\jmkgpcvx.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
Virus:Trj/Agent.EQU Disinfected C:\WINDOWS\system32\qmidnjia.exe
Virus:W32/Sdbot.IQM.worm Disinfected C:\WINDOWS\system32\setup_13454.exe
Virus:W32/Sdbot.KBR.worm Disinfected C:\WINDOWS\system32\setup_44644.exe
Virus:W32/Sdbot.KBR.worm Disinfected C:\WINDOWS\system32\setup_78480.exe


******* C:\ComboFix.txt

"Duane" - 07-03-25 20:09:46 Service Pack 1
ComboFix 07-03-23 - Running from: "C:\Documents and Settings\Duane\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\PageHistory.txt
C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\WebHistory.txt
C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp
C:\Program Files\vsadd-in
C:\WINDOWS\system32\rpcc.dll


((((((((((((((((((((((((((((((( Files Created from 2007-02-25 to 2007-03-25 ))))))))))))))))))))))))))))))))))


2007-03-25 20:16 0 --a------ C:\WINDOWS\system32\setup_78345.exe
2007-03-25 10:02 6,469,352 --a------ C:\Program Files\avgas-setup-7.5.0.50.exe
2007-03-25 09:55 55,243,672 --a------ C:\regedit 3.25.07.reg
2007-03-24 22:19 88,340 --a------ C:\WINDOWS\system32\jmkgpcvx.exe
2007-03-24 22:19 132,116 --a------ C:\WINDOWS\system32\fbmhsfob.dll
2007-03-24 22:19 123,972 --a------ C:\WINDOWS\system32\xlqtmtth.dll
2007-03-24 22:19 1,206,893 ---hs---- C:\WINDOWS\system32\klnmp.bak1
2007-03-24 22:18 280,676 ---hs---- C:\WINDOWS\system32\pmnlk.dll
2007-03-24 22:11 80 --a------ C:\WINDOWS\system32\iepref32.dll
2007-03-24 22:11 0 --a------ C:\WINDOWS\system32\ierplc.dll
2007-03-24 22:08 280,676 ---hs---- C:\WINDOWS\system32\gebcb.dll
2007-03-24 22:07 280,676 ---hs---- C:\WINDOWS\system32\awtsq.dll
2007-03-24 22:02 26,697 --a------ C:\WINDOWS\system32\wvuusrs.dll
2007-03-24 20:57 26,697 --a------ C:\WINDOWS\system32\hgghefg.dll
2007-03-24 17:57 26,697 --a------ C:\WINDOWS\system32\ljjijih.dll
2007-03-24 17:35 7,200 --a------ C:\jvycsq.exe
2007-03-24 17:35 23,552 --a------ C:\yyumm.exe
2007-03-24 17:34 26,697 --a------ C:\WINDOWS\system32\fccbccb.dll
2007-03-24 15:21 0 --a------ C:\WINDOWS\system32\setup_83355.exe
2007-03-24 15:18 26,697 --a------ C:\WINDOWS\system32\khffebb.dll
2007-03-24 14:51 26,697 --a------ C:\WINDOWS\system32\wvuvwxx.dll
2007-03-24 14:42 26,697 --a------ C:\WINDOWS\system32\mljghij.dll
2007-03-24 14:15 26,697 --a------ C:\WINDOWS\system32\urqoljk.dll
2007-03-24 13:36 26,697 --a------ C:\WINDOWS\system32\ssqqono.dll
2007-03-24 12:03 4,608 --a------ C:\WINDOWS\system32\ips.dll
2007-03-24 11:58 1,048,576 --ah----- C:\DOCUME~1\MASTER~1\NTUSER.DAT
2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\WINDOWS
2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\Symantec
2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\InterTrust
2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\Adobe
2007-03-24 11:53 596 --a------ C:\WINDOWS\system32\qmopt.dll
2007-03-24 08:46 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-03-21 21:15 <DIR> d-------- C:\Deckard
2007-03-20 20:18 <DIR> d-------- C:\avenger
2007-03-19 21:14 <DIR> d--h----- C:\WINDOWS\PIF
2007-03-18 09:40 51,955,192 --a------ C:\regedit 3.18.07.reg
2007-03-17 23:47 51,951,606 --a------ C:\Regedit 3.172.07.reg
2007-03-17 09:39 51,944,564 --a------ C:\regedit 3.17.07.reg
2007-03-13 20:51 136 --a------ C:\WINDOWS\system32\dgjun.bat
2007-03-13 19:32 51,995,858 --a------ C:\Regedit 3.13.07.reg
2007-03-12 18:20 491,768 --a------ C:\ie6setup.exe
2007-03-11 22:17 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-03-11 09:25 <DIR> d-------- C:\Program Files\Java
2007-03-11 09:25 <DIR> d-------- C:\Program Files\Common Files\Java
2007-03-11 09:24 <DIR> d-------- C:\DOCUME~1\Duane\APPLIC~1\Sun
2007-03-10 11:31 <DIR> d-------- C:\Rustbfix
2007-03-08 19:33 971 --a------ C:\DOCUME~1\Duane\Purity.bat
2007-03-08 19:33 8,192 --a------ C:\DOCUME~1\Duane\RestartIt.exe
2007-03-08 19:33 79,360 --a------ C:\DOCUME~1\Duane\swxcacls.exe
2007-03-08 19:33 73,728 --a------ C:\DOCUME~1\Duane\FDSV.EXE
2007-03-08 19:33 6,914 --a------ C:\DOCUME~1\Duane\Qoo.bat
2007-03-08 19:33 51,200 --a------ C:\DOCUME~1\Duane\dumphive.exe
2007-03-08 19:33 5,074 --a------ C:\DOCUME~1\Duane\NTPBack.exe
2007-03-08 19:33 49,152 --a------ C:\DOCUME~1\Duane\vfind.exe
2007-03-08 19:33 42,887 --a------ C:\DOCUME~1\Duane\ntp.exe
2007-03-08 19:33 39,184 --a------ C:\DOCUME~1\Duane\Ntrights.exe
2007-03-08 19:33 38,400 --a------ C:\DOCUME~1\Duane\moveex.exe
2007-03-08 19:33 319,415 --a------ C:\DOCUME~1\Duane\Creg.reg
2007-03-08 19:33 28,672 --a------ C:\DOCUME~1\Duane\catchme.exe
2007-03-08 19:33 26,112 --a------ C:\DOCUME~1\Duane\nircmd.exe
2007-03-08 19:33 2,304 --a------ C:\DOCUME~1\Duane\Look2Me.bat
2007-03-08 19:33 181,776 --a------ C:\DOCUME~1\Duane\handle.exe
2007-03-08 19:33 140,800 --a------ C:\DOCUME~1\Duane\swreg.exe
2007-03-08 19:33 123,904 --a------ C:\DOCUME~1\Duane\swsc.exe
2007-03-08 19:33 117,379 --a------ C:\DOCUME~1\Duane\LIST-C.bat


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-03-25 19:38 -------- d-------- C:\Program Files\picasa2
2007-03-25 19:36 -------- d-------- C:\Program Files\messenger
2007-03-25 19:31 -------- d-------- C:\Program Files\itunes
2007-03-25 19:29 -------- d-------- C:\Program Files\google
2007-03-24 14:33 -------- d-------- C:\Program Files\hijack this
2007-03-08 19:47 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-02-24 22:08 3762 --a------ C:\WINDOWS\system32\tmp.reg
2007-02-21 21:42 129 --a------ C:\fix.bat
2007-02-20 21:14 -------- d-------- C:\Program Files\shockwave.com
2007-02-10 20:00 14201 --a------ C:\Program Files\hijackthis.log
2007-01-28 22:13 -------- d-------- C:\Program Files\lg software innovations
2007-01-28 22:05 -------- d-------- C:\Program Files\clonedvd
2007-01-28 21:28 14 --a------ C:\WINDOWS\system32\systeminfo3.dll
2007-01-28 21:26 81920 --a------ C:\DOCUME~1\Duane\APPLIC~1\ezpinst.exe
2007-01-28 21:26 7176 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.cat
2007-01-28 21:26 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2007-01-28 21:26 47360 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.sys
2007-01-28 21:26 34 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.log
2007-01-28 21:26 1144 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.inf
2007-01-28 21:26 -------- d-------- C:\DOCUME~1\Duane\APPLIC~1\vso
2007-01-21 15:08 14612 --a------ C:\Program Files\cwshredder.exe-2d092fd4.pf
2007-01-21 15:03 532480 --a------ C:\Program Files\cwshredder.exe
2007-01-12 18:19 0 --a------ C:\WINDOWS\system32\vb2en16.dll
2007-01-11 16:35 12800 --a------ C:\WINDOWS\system32\svchost.exe
2007-01-07 18:21 1 --a------ C:\WINDOWS\system32\ps.dat
2007-01-07 18:21 1 --a------ C:\WINDOWS\system32\cookie.dat
2007-01-07 13:16 25600 --a------ C:\WINDOWS\system32\helper.dll
2007-01-04 22:35 10660 --a------ C:\WINDOWS\mozver.dat
2007-01-03 20:49 5037072 --a------ C:\Program Files\spybotsd14.exe
2007-01-01 12:02 507 --a------ C:\WINDOWS\ereg077.dat
2006-12-25 16:33 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Microsoft Works Update Detection"="c:\\Program Files\\Microsoft Works\\WkDetect.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe"
"PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot"
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"lanmanwrk.exe"="C:\\WINDOWS\\System32\\lanmanwrk.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{85382E07-2F7E-4910-89AD-16F2E97FC152}"=""

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccbccb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khffebb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjijih
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlk
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuusrs

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0



********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-03-25 20:23:34
C:\ComboFix2.txt ... 07-03-24 22:13
C:\ComboFix3.txt ... 07-03-20 21:26


****** NeLogfile of HijackThis v1.99.1
Scan saved at 8:42:52 PM, on 3/25/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Micro Innovations\Keyboard\kbdap32a.EXE
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [lanmanwrk.exe] C:\WINDOWS\System32\lanmanwrk.exe
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\System32\bgvuafvo.dll",setvm
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: Video Poker - http://download.games.yahoo.com/game...s/y/vpt0_x.cab
O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/game...ts/y/at1_x.cab
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/game...ts/y/xt0_x.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/game...ts/y/jt0_x.cab
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/game...ts/y/kt4_x.cab
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/game...ts/y/ct2_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game...ts/y/it1_x.cab
O16 - DPF: Yahoo! Dice - http://download.games.yahoo.com/game...s/y/dct4_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/game...ts/y/zt3_x.cab
O16 - DPF: Yahoo! Klondike Solitaire - http://presence.games.yahoo.com/yog/y/ks12_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/game...ts/y/pt3_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/game...s/y/pyt1_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/14939218...p/RdxIE601.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {7FE26BE2-B923-4B41-9834-E84DA1CC1F96} (Maid Control) - http://vsp.closetmaid.com/vsp/cmaidc...downloader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/game.../gpcontrol.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/game...ploader_v6.cab
O23 - Service: avgav.exe (AVG) - Unknown owner - C:\WINDOWS\avgav.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft Internet Connection Sharing (Microsoft Windows Internet Connection Sharing) - Unknown owner - C:\WINDOWS\alg.exe (file missing)
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


****There was a newer combo fix as well


"Duane" - 07-03-25 20:09:46 Service Pack 1
ComboFix 07-03-23 - Running from: "C:\Documents and Settings\Duane\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\PageHistory.txt
C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\WebHistory.txt
C:\DOCUME~1\Duane\APPLIC~1.\searchtoolbarcorp
C:\Program Files\vsadd-in
C:\WINDOWS\system32\rpcc.dll


((((((((((((((((((((((((((((((( Files Created from 2007-02-25 to 2007-03-25 ))))))))))))))))))))))))))))))))))


2007-03-25 20:16 0 --a------ C:\WINDOWS\system32\setup_78345.exe
2007-03-25 10:02 6,469,352 --a------ C:\Program Files\avgas-setup-7.5.0.50.exe
2007-03-25 09:55 55,243,672 --a------ C:\regedit 3.25.07.reg
2007-03-24 22:19 88,340 --a------ C:\WINDOWS\system32\jmkgpcvx.exe
2007-03-24 22:19 132,116 --a------ C:\WINDOWS\system32\fbmhsfob.dll
2007-03-24 22:19 123,972 --a------ C:\WINDOWS\system32\xlqtmtth.dll
2007-03-24 22:19 1,206,893 ---hs---- C:\WINDOWS\system32\klnmp.bak1
2007-03-24 22:18 280,676 ---hs---- C:\WINDOWS\system32\pmnlk.dll
2007-03-24 22:11 80 --a------ C:\WINDOWS\system32\iepref32.dll
2007-03-24 22:11 0 --a------ C:\WINDOWS\system32\ierplc.dll
2007-03-24 22:08 280,676 ---hs---- C:\WINDOWS\system32\gebcb.dll
2007-03-24 22:07 280,676 ---hs---- C:\WINDOWS\system32\awtsq.dll
2007-03-24 22:02 26,697 --a------ C:\WINDOWS\system32\wvuusrs.dll
2007-03-24 20:57 26,697 --a------ C:\WINDOWS\system32\hgghefg.dll
2007-03-24 17:57 26,697 --a------ C:\WINDOWS\system32\ljjijih.dll
2007-03-24 17:35 7,200 --a------ C:\jvycsq.exe
2007-03-24 17:35 23,552 --a------ C:\yyumm.exe
2007-03-24 17:34 26,697 --a------ C:\WINDOWS\system32\fccbccb.dll
2007-03-24 15:21 0 --a------ C:\WINDOWS\system32\setup_83355.exe
2007-03-24 15:18 26,697 --a------ C:\WINDOWS\system32\khffebb.dll
2007-03-24 14:51 26,697 --a------ C:\WINDOWS\system32\wvuvwxx.dll
2007-03-24 14:42 26,697 --a------ C:\WINDOWS\system32\mljghij.dll
2007-03-24 14:15 26,697 --a------ C:\WINDOWS\system32\urqoljk.dll
2007-03-24 13:36 26,697 --a------ C:\WINDOWS\system32\ssqqono.dll
2007-03-24 12:03 4,608 --a------ C:\WINDOWS\system32\ips.dll
2007-03-24 11:58 1,048,576 --ah----- C:\DOCUME~1\MASTER~1\NTUSER.DAT
2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\WINDOWS
2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\Symantec
2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\InterTrust
2007-03-24 11:58 <DIR> d-------- C:\DOCUME~1\MASTER~1\APPLIC~1\Adobe
2007-03-24 11:53 596 --a------ C:\WINDOWS\system32\qmopt.dll
2007-03-24 08:46 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-03-21 21:15 <DIR> d-------- C:\Deckard
2007-03-20 20:18 <DIR> d-------- C:\avenger
2007-03-19 21:14 <DIR> d--h----- C:\WINDOWS\PIF
2007-03-18 09:40 51,955,192 --a------ C:\regedit 3.18.07.reg
2007-03-17 23:47 51,951,606 --a------ C:\Regedit 3.172.07.reg
2007-03-17 09:39 51,944,564 --a------ C:\regedit 3.17.07.reg
2007-03-13 20:51 136 --a------ C:\WINDOWS\system32\dgjun.bat
2007-03-13 19:32 51,995,858 --a------ C:\Regedit 3.13.07.reg
2007-03-12 18:20 491,768 --a------ C:\ie6setup.exe
2007-03-11 22:17 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-03-11 09:25 <DIR> d-------- C:\Program Files\Java
2007-03-11 09:25 <DIR> d-------- C:\Program Files\Common Files\Java
2007-03-11 09:24 <DIR> d-------- C:\DOCUME~1\Duane\APPLIC~1\Sun
2007-03-10 11:31 <DIR> d-------- C:\Rustbfix
2007-03-08 19:33 971 --a------ C:\DOCUME~1\Duane\Purity.bat
2007-03-08 19:33 8,192 --a------ C:\DOCUME~1\Duane\RestartIt.exe
2007-03-08 19:33 79,360 --a------ C:\DOCUME~1\Duane\swxcacls.exe
2007-03-08 19:33 73,728 --a------ C:\DOCUME~1\Duane\FDSV.EXE
2007-03-08 19:33 6,914 --a------ C:\DOCUME~1\Duane\Qoo.bat
2007-03-08 19:33 51,200 --a------ C:\DOCUME~1\Duane\dumphive.exe
2007-03-08 19:33 5,074 --a------ C:\DOCUME~1\Duane\NTPBack.exe
2007-03-08 19:33 49,152 --a------ C:\DOCUME~1\Duane\vfind.exe
2007-03-08 19:33 42,887 --a------ C:\DOCUME~1\Duane\ntp.exe
2007-03-08 19:33 39,184 --a------ C:\DOCUME~1\Duane\Ntrights.exe
2007-03-08 19:33 38,400 --a------ C:\DOCUME~1\Duane\moveex.exe
2007-03-08 19:33 319,415 --a------ C:\DOCUME~1\Duane\Creg.reg
2007-03-08 19:33 28,672 --a------ C:\DOCUME~1\Duane\catchme.exe
2007-03-08 19:33 26,112 --a------ C:\DOCUME~1\Duane\nircmd.exe
2007-03-08 19:33 2,304 --a------ C:\DOCUME~1\Duane\Look2Me.bat
2007-03-08 19:33 181,776 --a------ C:\DOCUME~1\Duane\handle.exe
2007-03-08 19:33 140,800 --a------ C:\DOCUME~1\Duane\swreg.exe
2007-03-08 19:33 123,904 --a------ C:\DOCUME~1\Duane\swsc.exe
2007-03-08 19:33 117,379 --a------ C:\DOCUME~1\Duane\LIST-C.bat


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-03-25 19:38 -------- d-------- C:\Program Files\picasa2
2007-03-25 19:36 -------- d-------- C:\Program Files\messenger
2007-03-25 19:31 -------- d-------- C:\Program Files\itunes
2007-03-25 19:29 -------- d-------- C:\Program Files\google
2007-03-24 14:33 -------- d-------- C:\Program Files\hijack this
2007-03-08 19:47 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-02-24 22:08 3762 --a------ C:\WINDOWS\system32\tmp.reg
2007-02-21 21:42 129 --a------ C:\fix.bat
2007-02-20 21:14 -------- d-------- C:\Program Files\shockwave.com
2007-02-10 20:00 14201 --a------ C:\Program Files\hijackthis.log
2007-01-28 22:13 -------- d-------- C:\Program Files\lg software innovations
2007-01-28 22:05 -------- d-------- C:\Program Files\clonedvd
2007-01-28 21:28 14 --a------ C:\WINDOWS\system32\systeminfo3.dll
2007-01-28 21:26 81920 --a------ C:\DOCUME~1\Duane\APPLIC~1\ezpinst.exe
2007-01-28 21:26 7176 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.cat
2007-01-28 21:26 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2007-01-28 21:26 47360 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.sys
2007-01-28 21:26 34 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.log
2007-01-28 21:26 1144 --a------ C:\DOCUME~1\Duane\APPLIC~1\pcouffin.inf
2007-01-28 21:26 -------- d-------- C:\DOCUME~1\Duane\APPLIC~1\vso
2007-01-21 15:08 14612 --a------ C:\Program Files\cwshredder.exe-2d092fd4.pf
2007-01-21 15:03 532480 --a------ C:\Program Files\cwshredder.exe
2007-01-12 18:19 0 --a------ C:\WINDOWS\system32\vb2en16.dll
2007-01-11 16:35 12800 --a------ C:\WINDOWS\system32\svchost.exe
2007-01-07 18:21 1 --a------ C:\WINDOWS\system32\ps.dat
2007-01-07 18:21 1 --a------ C:\WINDOWS\system32\cookie.dat
2007-01-07 13:16 25600 --a------ C:\WINDOWS\system32\helper.dll
2007-01-04 22:35 10660 --a------ C:\WINDOWS\mozver.dat
2007-01-03 20:49 5037072 --a------ C:\Program Files\spybotsd14.exe
2007-01-01 12:02 507 --a------ C:\WINDOWS\ereg077.dat
2006-12-25 16:33 23066 --a------ C:\Program Files\plainoldfavorites-0.5.6-fx-windows.xpi


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Microsoft Works Update Detection"="c:\\Program Files\\Microsoft Works\\WkDetect.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"Ulead AutoDetector"="C:\\Program Files\\Ulead Systems\\Ulead Photo Explorer 8.0 SE Basic\\Monitor.exe"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd2.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"OFFICEKB"="C:\\Program Files\\Micro Innovations\\Keyboard\\kbdap32a.EXE"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Mouse\\mouse32a.exe"
"PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot"
"SmcService"="C:\\PROGRA~1\\Sygate\\SPF\\smc.exe -startgui"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"lanmanwrk.exe"="C:\\WINDOWS\\System32\\lanmanwrk.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
"{85382E07-2F7E-4910-89AD-16F2E97FC152}"=""

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccbccb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khffebb
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjijih
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlk
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuusrs

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0



********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-03-25 20:23:34
C:\ComboFix2.txt ... 07-03-24 22:13
C:\ComboFix3.txt ... 07-03-20 21:26

***** AVG report
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 11:52:04 AM 3/25/2007

+ Scan result:



C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119398.EXE -> Adware.Background : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP282\A0108252.dll -> Adware.Companion : Cleaned with backup (quarantined).
HKU\S-1-5-21-1784762916-2740901186-3389046013-1005\CLSID\{020B1227-417D-4682-9AC3-61F43CB5B6B1} -> Adware.Generic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119433.dll -> Adware.Minibug : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109379.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109381.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109390.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109391.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119386.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119388.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119392.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119397.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119412.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119413.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119420.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119434.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119435.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119436.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109378.exe -> Adware.Nexus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119387.exe -> Adware.Nexus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119415.exe -> Adware.Nexus : Cleaned with backup (quarantined).
C:\Documents and Settings\Molly\Start Menu\Programs\WhenU -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Molly\Start Menu\Programs\WhenU\Customer Support.lnk -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Molly\Start Menu\Programs\WhenU\Learn More About WhenU Save.url -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Molly\Start Menu\Programs\WhenU\Learn More About WhenU SaveNow.url -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Molly\Start Menu\Programs\WhenU\Uninstall Instructions.lnk -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Molly\Start Menu\Programs\WhenU\WhenU.com Website.url -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109389.exe/ffext.mod/{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\whenu_ff.dll -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119393.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119395.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119396.dll -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119444.exe/ffext.mod/{BEE3E87E-E1C6-4bfe-BE9D-48E84271AB34}\components\whenu_ff.dll -> Adware.SaveNow : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WUSN.1 -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072487.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072488.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072489.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072490.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072498.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072499.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072500.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072501.dll -> Adware.SpyMarshal : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP261\A0072497.exe -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP287\A0109522.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP287\A0109527.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP287\A0109528.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP290\A0112745.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP290\A0112746.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP290\A0112747.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP290\A0112754.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119425.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119426.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119427.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119428.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119429.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119430.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119431.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\Program Files\Hijack This\backups\backup-20070301-200021-574.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119442.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095967.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095969.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095972.dll -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095974.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095975.dll -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095979.ini -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095982.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095983.sys -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095984.dll -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095985.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0096019.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0096025.sys -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0096026.sys -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0096027.sys -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0096028.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109376.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109380.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109383.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP283\A0109384.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP301\A0116695.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119389.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119390.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119418.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119419.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119447.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119450.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119475.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\Documents and Settings\Duane\Desktop\SDFix\backups_old4\backups.zip/backups/szr_dr.sys -> Backdoor.Agent.aif : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP299\A0116500.sys -> Backdoor.Agent.aif : Cleaned with backup (quarantined).
C:\WINDOWS\system32\setup_13051.exe -> Backdoor.SdBot.xd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP306\A0119565.exe -> Dialer.GBDialer.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP306\A0119599.exe -> Dialer.GBDialer.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095957.exe -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095958.exe -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP304\A0119438.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WinOpts -> Proxy.Small : Cleaned with backup (quarantined).
:mozilla.294:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.132:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.133:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.137:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.138:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.139:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.140:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.219:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.23:C:\Documents and Settings\Others\Application Data\Mozilla\Firefox\Profiles\5rw0vw5m.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Duane\Cookies\duane@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Duane\Cookies\duane@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Duane\Cookies\duane@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Duane\Cookies\duane@grouplotto.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.286:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.295:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.296:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.382:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.80:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.81:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.106:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.107:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.108:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.113:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.114:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.101:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.102:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.103:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.104:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.105:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Molly\Cookies\molly@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.31:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Duane\Cookies\duane@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Duane\Cookies\duane@bfast[1].txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.62:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.22:C:\Documents and Settings\Others\Application Data\Mozilla\Firefox\Profiles\5rw0vw5m.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.43:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.44:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.40:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.245:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.28:C:\Documents and Settings\Others\Application Data\Mozilla\Firefox\Profiles\5rw0vw5m.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.29:C:\Documents and Settings\Others\Application Data\Mozilla\Firefox\Profiles\5rw0vw5m.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Duane\Cookies\duane@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.400:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Cqcounter : Cleaned.
:mozilla.15:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.127:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.56:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.57:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Duane\Cookies\duane@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.170:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.31:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.33:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.34:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.390:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.391:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.64:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.65:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.66:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.67:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Duane\Cookies\duane@ehg-kasperskylab.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Duane\Cookies\duane@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.78:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Information : Cleaned.
:mozilla.354:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.355:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.128:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.129:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.130:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.329:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.330:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.331:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.17:C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.25:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.68:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.69:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Duane\Cookies\duane@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.348:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.180:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.220:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.185:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.186:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.187:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.188:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.74:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.75:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.60:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.61:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.82:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned.
:mozilla.12:C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.13:C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.14:C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.14:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.15:C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.15:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.16:C:\Documents and Settings\Cody\Application Data\Mozilla\Firefox\Profiles\o4r7omoo.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.16:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.17:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.18:C:\Documents and Settings\Duane\Application Data\Mozilla\Firefox\Profiles\wchylb0m.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.266:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.267:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.268:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.269:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.270:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.271:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.109:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.110:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.111:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.112:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.58:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.260:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.261:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.262:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.264:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.265:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.45:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.46:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.47:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.172:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.42:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.410:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.411:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.412:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.413:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.414:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.415:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.422:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.809:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.810:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.811:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.812:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.813:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.814:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.277:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.27:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.28:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.29:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.30:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.35:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.36:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.117:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.118:C:\Documents and Settings\Molly\Application Data\Mozilla\Firefox\Profiles\ayzs70gt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\VSAdd-in\VSAdd-in.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP313\A0125324.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095955.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7EDB5A9C-466C-4274-AEC3-C534983AC7C7}\RP273\A0095956.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).


::Report end
cul8rman is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!