PDA

View Full Version : Possible malware?



thanostse
2008-12-21, 01:55
Hello ,
I've been possibly infected by something, i've got popups randomly and yesterday when i
tried to run msconfig (from start -run) i had i pop up from windows saying that it could not find it(this i fixed it by copying msconfig.exe from C:\Windows\PCHealth\HelpCtr\Binaries\MSConfig.exe to C:\Windows\system32)
Anyway here is the HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:36:53 πμ, on 21/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\VIA\VIAudioi\EnvyADeck\EnMixCPL.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\utorrent\utorrent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.gr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB001" /M "Stylus C46"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [EnvyHFCPL] C:\Program Files\VIA\VIAudioi\EnvyADeck\EnMixCPL.exe 1
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AVerQuick.lnk = C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
O4 - Global Startup: NCProTray.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1214ABC4-1B68-4503-B742-E2E38EE36CF0}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{1214ABC4-1B68-4503-B742-E2E38EE36CF0}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{1214ABC4-1B68-4503-B742-E2E38EE36CF0}: NameServer = 192.168.1.1
O17 - HKLM\System\CS3\Services\Tcpip\..\{1214ABC4-1B68-4503-B742-E2E38EE36CF0}: NameServer = 192.168.1.1
O17 - HKLM\System\CS4\Services\Tcpip\..\{1214ABC4-1B68-4503-B742-E2E38EE36CF0}: NameServer = 192.168.1.1
O17 - HKLM\System\CS5\Services\Tcpip\..\{1214ABC4-1B68-4503-B742-E2E38EE36CF0}: NameServer = 192.168.1.1
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CardBusService - Unknown owner - C:\Program Files\Common Files\AVerMedia\Service\CardBusService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MSSQL$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: SQLAgent$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlagent.EXE (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 6157 bytes

shelf life
2008-12-26, 05:31
hi,

your post is 4 or 5 days old. due to a lack of replies I dont post any directions. if you still need help simply reply back.

thanostse
2008-12-31, 00:49
Any help is appreciated!

shelf life
2008-12-31, 04:40
hi,

ok we will start with combofix. There is a guide you need to read through before using it. Lots of pictures. Follow the combofix prompts and post the log in your reply.

the guide:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

thanostse
2008-12-31, 09:54
O.K. Here is the Combofix log:

ComboFix 08-12-30.02 - THANOS 2008-12-31 9:42:33.18 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1253.1.1033.18.2046.1572 [GMT 2:00]
Running from: c:\documents and settings\THANOS\Desktop\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-31 )))))))))))))))))))))))))))))))
.

2008-12-24 15:36 . 2008-12-24 15:36 <DIR> d-------- C:\ExtendedDB
2008-12-21 01:36 . 2008-12-21 01:36 <DIR> d-------- c:\program files\Trend Micro
2008-12-20 03:10 . 2008-12-20 03:10 361,344 --a--c--- c:\windows\system32\dllcache\TCPIP.SYS
2008-12-20 02:38 . 2008-12-20 02:38 <DIR> d-------- c:\windows\ServicePackFiles
2008-12-20 02:36 . 2006-12-29 00:31 19,569 --a------ c:\windows\003154_.tmp
2008-12-20 02:28 . 2008-04-14 05:42 169,984 --a------ c:\windows\system32\msconfig.exe
2008-12-20 01:59 . 2008-12-20 01:59 <DIR> d-------- c:\program files\Common Files\Adobe
2008-12-20 01:51 . 2008-12-20 02:08 <DIR> d-------- c:\program files\NOS
2008-12-20 01:51 . 2008-12-20 02:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
2008-12-17 15:33 . 2008-09-08 12:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-12-17 15:33 . 2008-06-13 13:05 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-12-17 15:33 . 2008-08-14 12:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
2008-12-17 15:32 . 2008-10-16 22:38 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-12-17 15:32 . 2007-04-17 11:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-12-17 15:32 . 2008-09-15 14:12 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-12-17 15:32 . 2007-03-08 07:10 991,232 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-17 15:32 . 2008-10-16 22:38 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-12-17 15:32 . 2008-10-16 22:38 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-12-17 15:32 . 2008-10-16 22:38 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-12-17 15:32 . 2008-10-16 22:38 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-12-17 15:32 . 2008-10-16 22:38 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-17 15:32 . 2008-10-16 15:11 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-12-17 15:31 . 2008-08-14 12:11 2,189,184 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-17 15:31 . 2008-08-14 12:09 2,145,280 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-17 15:31 . 2008-08-14 11:33 2,066,048 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-17 15:31 . 2008-08-14 11:33 2,023,936 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-17 15:31 . 2008-09-04 19:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-12-17 15:31 . 2008-04-11 21:04 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-12-17 15:31 . 2008-10-24 13:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-17 15:31 . 2008-10-15 18:34 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-12-17 15:31 . 2008-05-01 16:33 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2008-12-17 15:31 . 2008-05-08 16:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2008-12-17 14:59 . 2008-12-17 14:59 <DIR> d-------- c:\program files\CCleaner
2008-12-17 14:55 . 2008-12-17 14:56 <DIR> d-------- c:\program files\Yahoo!
2008-12-14 14:26 . 2008-12-14 14:31 <DIR> d-------- c:\program files\Nero
2008-12-14 02:53 . 2008-12-14 02:53 1,700,352 --a------ c:\windows\system32\gdiplus.dll
2008-12-11 00:00 . 2008-12-11 00:00 <DIR> d-------- c:\program files\Common Files\ATI Technologies
2008-12-10 23:58 . 2008-12-10 23:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\ATI
2008-12-10 23:56 . 2008-12-10 23:57 <DIR> d-------- c:\program files\ATI Technologies
2008-12-10 23:56 . 2008-10-28 21:05 593,920 --------- c:\windows\system32\ati2sgag.exe
2008-12-10 23:55 . 2008-12-10 23:55 <DIR> d-------- C:\ATI
2008-12-10 01:23 . 2008-12-10 01:23 <DIR> d-------- c:\windows\system32\xlive
2008-12-10 01:23 . 2008-12-10 01:47 <DIR> d-------- c:\program files\Microsoft Games for Windows - LIVE
2008-12-08 01:03 . 2008-12-08 01:03 <DIR> d-------- c:\windows\system32\XPSViewer
2008-12-08 01:03 . 2008-12-08 01:03 <DIR> d-------- c:\program files\MSBuild
2008-12-06 12:56 . 2006-12-29 00:31 19,569 --a------ c:\windows\003153_.tmp
2008-12-06 12:44 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
2008-12-06 12:42 . 2008-12-06 13:11 <DIR> d-------- c:\windows\SxsCaPendDel
2008-12-06 12:42 . 2008-12-06 12:42 <DIR> d-------- c:\program files\Reference Assemblies
2008-12-06 12:42 . 2008-07-06 14:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2008-12-06 12:42 . 2008-07-06 14:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2008-12-06 12:42 . 2008-07-06 12:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2008-12-06 12:42 . 2008-07-06 14:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2008-12-06 12:42 . 2008-07-06 14:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2008-12-06 12:42 . 2008-07-06 14:06 117,760 --------- c:\windows\system32\prntvpt.dll
2008-12-06 12:42 . 2008-07-06 14:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2008-12-03 02:08 . 2008-12-03 02:11 <DIR> d-------- c:\program files\UltraISO
2008-12-03 02:08 . 2008-12-03 02:08 <DIR> d-------- c:\program files\Common Files\EZB Systems
2008-12-01 15:12 . 2008-12-01 15:12 <DIR> d-------- c:\program files\Alcohol Soft
2008-12-01 15:10 . 2008-12-01 15:10 717,296 --a------ c:\windows\system32\drivers\sptd.sys
2008-11-30 14:41 . 2008-07-12 08:18 3,851,784 --a------ c:\windows\system32\D3DX9_39.dll
2008-11-30 14:41 . 2008-07-12 08:18 1,493,528 --a------ c:\windows\system32\D3DCompiler_39.dll
2008-11-30 14:41 . 2008-07-31 10:40 509,448 --a------ c:\windows\system32\XAudio2_2.dll
2008-11-30 14:41 . 2008-05-30 14:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-11-30 14:41 . 2008-07-12 08:18 467,984 --a------ c:\windows\system32\d3dx10_39.dll
2008-11-30 14:41 . 2008-07-31 10:41 238,088 --a------ c:\windows\system32\xactengine3_2.dll
2008-11-30 14:41 . 2008-05-30 14:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll
2008-11-30 14:41 . 2008-07-31 10:41 68,616 --a------ c:\windows\system32\XAPOFX1_1.dll
2008-11-30 14:41 . 2008-05-30 14:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-11-30 14:41 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2008-11-24 14:23 . 2008-11-24 14:23 <DIR> d-------- c:\windows\SHELLNEW
2008-11-24 14:23 . 2008-11-24 14:23 <DIR> d-------- c:\program files\Microsoft ActiveSync
2008-11-24 14:22 . 2008-11-24 14:22 <DIR> d-------- c:\program files\Microsoft.NET
2008-11-20 09:52 . 2008-12-05 01:01 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-20 09:52 . 2008-11-20 09:52 <DIR> d-------- c:\documents and settings\THANOS\Application Data\Malwarebytes
2008-11-20 09:52 . 2008-11-20 09:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-20 09:52 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-20 09:52 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-03 12:55 . 2008-11-03 12:55 <DIR> d-------- c:\documents and settings\THANOS\Application Data\Apple Computer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-31 07:41 --------- d-----w c:\documents and settings\THANOS\Application Data\uTorrent
2008-12-22 23:05 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-20 02:03 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-20 01:10 361,344 ----a-w c:\windows\system32\drivers\TCPIP.SYS
2008-12-14 12:37 --------- d-----w c:\documents and settings\THANOS\Application Data\Nero
2008-12-14 12:35 --------- d-----w c:\program files\Common Files\Nero
2008-12-14 12:26 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2008-12-12 23:19 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-10 21:58 --------- d-----w c:\documents and settings\THANOS\Application Data\ATI
2008-12-10 07:20 --------- d-----w c:\program files\BitComet
2008-12-06 12:00 361,344 ----a-w c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2008-11-17 17:11 --------- d-----w c:\program files\Classic PhoneTools
2008-11-12 12:32 --------- d-----w c:\program files\eMule
2008-11-10 22:43 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-10-29 03:10 3,341,824 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2008-10-29 01:18 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2008-10-28 12:56 --------- d-----w c:\program files\ESET
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-11-23 203720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus C46 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I0T1.EXE" [2004-01-13 99840]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-08-20 949376]
"EnvyHFCPL"="c:\program files\VIA\VIAudioi\EnvyADeck\EnMixCPL.exe" [2008-06-04 532480]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AVerQuick.lnk - c:\program files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe [2008-04-24 618496]
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2008-05-30 49220]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.dvsd"= pdvcodec.dll
"msacm.ac3filter"= ac3filter.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 20:24 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Classic PhoneTools\\Phontool.exe"=
"c:\\Program Files\\utorrent\\utorrent.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\SpybotSD.exe"=
"c:\\Program Files\\VIA\\VIAudioi\\EnvyADeck\\EnMixCPL.exe"=
"i:\\Games\\Dead Space\\Dead Space.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25185:TCP"= 25185:TCP:μtorrent TCP
"25185:UDP"= 25185:UDP:μtorrent UDP
"6627:TCP"= 6627:TCP:eMule TCP
"6630:UDP"= 6630:UDP:eMule UDP

R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-08-20 15424]
R3 Envy24HFS;ICE Envy24 Family Audio Controller WDM;c:\windows\system32\drivers\Envy24HF.sys [2008-06-04 673600]
S1 M9207;DTV-DVB M9207 USB DVB-T / TV BOX;c:\windows\system32\DRIVERS\M9207BDA.sys [2008-04-21 37248]
S2 CardBusService;CardBusService;c:\program files\Common Files\AVerMedia\Service\CardBusService.exe [2008-04-24 188416]
S3 AVerFx2hbtv;AVerMedia USB SW Hybrid Tuner;c:\windows\system32\drivers\AVerFx2hbtv.sys [2008-04-24 220672]
S3 DTV-DVBM9205;DTV-DVB USB Hybrid Analog/Capture;c:\windows\system32\Drivers\M9205.sys [2008-04-21 70272]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.gr/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
TCP: {1214ABC4-1B68-4503-B742-E2E38EE36CF0} = 192.168.1.1
FF - ProfilePath - c:\documents and settings\THANOS\Application Data\Mozilla\Firefox\Profiles\jwyzczjh.default\
FF - plugin: c:\program files\Yahoo!\Common\npyaxmpb.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-31 09:46:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
EnvyHFCPL = c:\program files\VIA\VIAudioi\EnvyADeck\EnMixCPL.exe 1?????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL*  r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Owner=S-1-5-21-436374069-2025429265-839522115-1003
"*"=dword:00000004

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL* r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Owner=S-1-5-21-436374069-2025429265-839522115-1003
"*"=dword:00000004

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL*  r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL* r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004

[HKEY_USERS\S-1-5-21-436374069-2025429265-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*NULL*]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-436374069-2025429265-839522115-1003
@Allowed: (Full) (S-1-5-21-436374069-2025429265-839522115-1003)
@Allowed: (Full) (S-1-5-21-436374069-2025429265-839522115-1003)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)

[HKEY_USERS\S-1-5-21-436374069-2025429265-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*NULL*\Certificates]
@Security="Inherited"

[HKEY_USERS\S-1-5-21-436374069-2025429265-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*NULL*\CRLs]
@Security="Inherited"

[HKEY_USERS\S-1-5-21-436374069-2025429265-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*NULL*\CTLs]
@Security="Inherited"

[HKEY_USERS\S-1-5-21-436374069-2025429265-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Electronic Arts\N*NULL*e*NULL*e*NULL*d*NULL* *NULL*f*NULL*o*NULL*r*NULL* *NULL*S*NULL*p*NULL*e*NULL*e*NULL*d*NULL*"! *NULL*P*NULL*r*NULL*o*NULL*S*NULL*t*NULL*r*NULL*e*NULL*e*NULL*t*NULL*]
@Security="Inherited"
"Order"=hex:08,00,00,00,02,00,00,00,d0,02,00,00,01,00,00,00,05,00,00,00,8c,00,\
00,00,00,00,00,00,7e,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,6c,00,32,\
00,48,00,00,00,76,37,17,b6,20,00,43,48,45,43,4b,46,7e,31,2e,55,52,4c,00,00,\
42,00,03,00,04,00,ef,be,76,37,17,b6,76,37,17,b6,14,00,00,00,43,00,68,00,65,\
00,63,00,6b,00,20,00,66,00,6f,00,72,00,20,00,75,00,70,00,64,00,61,00,74,00,\
65,00,73,00,2e,00,75,00,72,00,6c,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,\
00,00,00,1c,00,00,00,00,00,00,00,00,00,98,00,00,00,01,00,00,00,8a,00,00,00,\
41,75,67,4d,02,00,00,00,01,00,00,00,78,00,32,00,84,00,00,00,76,37,17,b6,20,\
00,45,4c,45,43,54,52,7e,31,2e,55,52,4c,00,00,4e,00,03,00,04,00,ef,be,76,37,\
17,b6,76,37,17,b6,14,00,00,00,45,00,6c,00,65,00,63,00,74,00,72,00,6f,00,6e,\
00,69,00,63,00,20,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,61,00,74,00,\
69,00,6f,00,6e,00,2e,00,75,00,72,00,6c,00,00,00,1c,00,0e,00,00,00,0a,00,ef,\
be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,9c,00,00,00,02,00,00,00,8e,00,\
00,00,41,75,67,4d,02,00,00,00,01,00,00,00,7c,00,32,00,fe,05,00,00,76,37,17,\
b6,20,00,4e,45,45,44,46,4f,7e,31,2e,4c,4e,4b,00,00,52,00,03,00,04,00,ef,be,\
76,37,17,b6,76,37,17,b6,14,00,00,00,4e,00,65,00,65,00,64,00,20,00,66,00,6f,\
00,72,00,20,00,53,00,70,00,65,00,65,00,64,00,22,21,20,00,50,00,72,00,6f,00,\
53,00,74,00,72,00,65,00,65,00,74,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,\
00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,78,00,00,00,\
03,00,00,00,6a,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,58,00,32,00,63,\
02,00,00,76,37,17,b6,20,00,52,45,41,44,4d,45,7e,31,2e,4c,4e,4b,00,00,2e,00,\
03,00,04,00,ef,be,76,37,17,b6,76,37,17,b6,14,00,00,00,52,00,65,00,61,00,64,\
00,20,00,4d,00,65,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,\
ef,be,00,00,00,00,1c,00,00,00,00,00,00,00,00,00,8c,00,00,00,04,00,00,00,7e,\
00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,6c,00,32,00,fc,02,00,00,76,37,\
17,b6,20,00,54,45,43,48,4e,49,7e,31,2e,4c,4e,4b,00,00,42,00,03,00,04,00,ef,\
be,76,37,17,b6,76,37,17,b6,14,00,00,00,54,00,65,00,63,00,68,00,6e,00,69,00,\
63,00,61,00,6c,00,20,00,53,00,75,00,70,00,70,00,6f,00,72,00,74,00,2e,00,6c,\
00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,\
00,00,00,00,00,00

[HKEY_USERS\S-1-5-21-436374069-2025429265-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Nero\΄ΜΒ *NULL*ΑΓΔ]
@Security="Inherited"
"Order"=hex:08,00,00,00,02,00,00,00,d8,02,00,00,01,00,00,00,04,00,00,00,b6,00,\
00,00,00,00,00,00,a8,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,96,00,32,\
00,11,03,00,00,e7,38,e2,a9,20,00,4e,45,52,4f,42,55,7e,31,2e,4c,4e,4b,00,00,\
6c,00,03,00,04,00,ef,be,e7,38,d9,a9,f4,38,14,4a,14,00,00,00,4e,00,65,00,72,\
00,6f,00,20,00,42,00,75,00,72,00,6e,00,69,00,6e,00,67,00,20,00,52,00,4f,00,\
4d,00,20,00,5b,00,92,03,bf,03,ae,03,b8,03,b5,03,b9,03,b1,03,20,00,c3,03,c4,\
03,b1,03,20,00,91,03,b3,03,b3,03,bb,03,b9,03,ba,03,ac,03,5d,00,2e,00,6c,00,\
6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,\
00,00,00,00,00,ae,00,00,00,01,00,00,00,a0,00,00,00,41,75,67,4d,02,00,00,00,\
01,00,00,00,8e,00,32,00,fa,02,00,00,e7,38,e2,a9,20,00,4e,45,52,4f,45,58,7e,\
31,2e,4c,4e,4b,00,00,64,00,03,00,04,00,ef,be,e7,38,d9,a9,f4,38,14,4a,14,00,\
00,00,4e,00,65,00,72,00,6f,00,20,00,45,00,78,00,70,00,72,00,65,00,73,00,73,\
00,20,00,5b,00,92,03,bf,03,ae,03,b8,03,b5,03,b9,03,b1,03,20,00,c3,03,c4,03,\
b1,03,20,00,91,03,b3,03,b3,03,bb,03,b9,03,ba,03,ac,03,5d,00,2e,00,6c,00,6e,\
00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,00,00,00,\
00,00,00,00,b2,00,00,00,02,00,00,00,a4,00,00,00,41,75,67,4d,02,00,00,00,01,\
00,00,00,92,00,32,00,3e,03,00,00,e7,38,e2,a9,20,00,4e,45,52,4f,53,4f,7e,31,\
2e,4c,4e,4b,00,00,68,00,03,00,04,00,ef,be,e7,38,d9,a9,f4,38,14,4a,14,00,00,\
00,4e,00,65,00,72,00,6f,00,20,00,53,00,6f,00,75,00,6e,00,64,00,54,00,72,00,\
61,00,78,00,20,00,5b,00,92,03,bf,03,ae,03,b8,03,b5,03,b9,03,b1,03,20,00,c3,\
03,c4,03,b1,03,20,00,91,03,b3,03,b3,03,bb,03,b9,03,ba,03,ac,03,5d,00,2e,00,\
6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,1c,00,00,\
00,00,00,00,00,00,00,b6,00,00,00,03,00,00,00,a8,00,00,00,41,75,67,4d,02,00,\
00,00,01,00,00,00,96,00,32,00,51,03,00,00,e7,38,e2,a9,20,00,4e,45,52,4f,57,\
41,7e,31,2e,4c,4e,4b,00,00,6c,00,03,00,04,00,ef,be,e7,38,d9,a9,f4,38,14,4a,\
14,00,00,00,4e,00,65,00,72,00,6f,00,20,00,57,00,61,00,76,00,65,00,20,00,45,\
00,64,00,69,00,74,00,6f,00,72,00,20,00,5b,00,92,03,bf,03,ae,03,b8,03,b5,03,\
b9,03,b1,03,20,00,c3,03,c4,03,b1,03,20,00,91,03,b3,03,b3,03,bb,03,b9,03,ba,\
03,ac,03,5d,00,2e,00,6c,00,6e,00,6b,00,00,00,1c,00,0e,00,00,00,0a,00,ef,be,\
00,00,00,00,1c,00,00,00,00,00,00,00,00,00

[HKEY_USERS\S-1-5-21-436374069-2025429265-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL*  r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-436374069-2025429265-839522115-1003
@Allowed: (Full) (S-1-5-21-436374069-2025429265-839522115-1003)
@Allowed: (Full) (S-1-5-21-436374069-2025429265-839522115-1003)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
"*"=dword:00000004

[HKEY_USERS\S-1-5-21-436374069-2025429265-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL* r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-436374069-2025429265-839522115-1003
@Allowed: (Full) (S-1-5-21-436374069-2025429265-839522115-1003)
@Allowed: (Full) (S-1-5-21-436374069-2025429265-839522115-1003)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
"*"=dword:00000004

[HKEY_USERS\S-1-5-21-436374069-2025429265-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL*  r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004

[HKEY_USERS\S-1-5-21-436374069-2025429265-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL* r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004

[HKEY_USERS\S-1-5-21-436374069-2025429265-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*NULL*]
@Security="Inherited"
"??"=hex:55,97,97,8f,d7,06,a8,ff,39,48,e0,2f,76,4e,0d,84,63,f2,9f,70,28,4f,1f,\
7b,84,d8,d4,34,1c,24,c6,6f,b7,84,1c,ad,6f,42,9f,19,13,f3,7b,48,07,40,76,10,\
8a,19,2d,09,94,51,5a,71,19,2b,31,08,1d,a7,89,60,eb,14,41,5b,c5,ec,34,c7,6e,\
e3,be,d1,f6,19,18,fd,4b,a8,c7,ed,fe,3c,8a,0e,f6,d4,f2,7b,ae,89,aa,69,27,0e,\
31,72,c7,74,65,b1,c2,42,31,62,df,17,81,81,9d,42,35,53,24,1e,08,fe,cc,a5,61,\
1e,15,11,0e,5e,29,85,43,df,f0,cc,ec,9c,bd,c1,58,1e,37,93,82,c4,08,60,15,8c,\
7b,4f,26,2f,66,41,a8,47,4d,ac,ad,59,1d,61,de,65,ff,fa,40,d0,1d,bd,31,b9,de,\
04,4b,13,cb,31,b9,6e,dc,f4,08,7d,e2,ef,46,92,f3,94,9b,e9,1f,b1,09,dc,df,20,\
01,21,96,14,5a,2a,63,25,fd,36,96,f6,2f,e3,4f,fb,24,09,ea,12,23,f2,46,b2,01,\
df,ee,bf,20,8f,eb,03,86,ce,de,56,ab,03,ff,57,b2,06,e0,55,b9,87,74,b2,6d,9f,\
0d,27,b9,44,51,97,5e,23,8d,d9,a1,78,d0,a0,86,65,09,51,3a,3d,e3,4c,9b,b4,12,\
fa,17,31,98,62,99,8b,2b,7d,1b,a6,cb,0e,df,27,3d,98,b3,fb,b5,56,5b,fa,f6,d8,\
c8,57,87,3a,8a,3b,b7,0b,92,b8,6c,99,31,44,9c,89,ab,70,07,bc,23,99,6d,fb,80,\
ec,01,06,3f,c3,de,2d,b6,0e,ef,75,c1,7f,12,51,d2,48,e0,36,1c,dc,01,74,86,bd,\
ee,0f,33,95,4a,f3,cd,f5,10,bc,99,7b,40,b9,f6,0f,97,27,a1,e3,96,e0,77,70,13,\
dd,5c,1e,51,ae,f9,6c,c7,5a,6f,62,55,09,bf,50,ec,cb,c6,8d,a6,75,24,c5,30,88,\
29,2b,84,d0,7d,4d,9d,01,76,9b,67,b3,0b,4e,0c,82,07,1f,c0,36,6d,5c,1f,f8,b6,\
c5,27,de,a1,6f,de,f5,c6,72,d5,9c,47,a2,9e,a3,4b,ba,67,28,db,56,1e,9d,13,4c,\
4f,74,ef,3d,e1,60,92,1b,f3,e3,78,8b,e1,d8,f1,ad,96,0b,c5,96,e4,a9,c8,8b,f7,\
29,7e,0a,e5,db,5e,86,e5,02,06,1a,ad,3a,17,d1,5d,13,95,38,bb,c6,26,c4,2b,96,\
7f,4f,4a,4b,ce,77,67,22,26,04,07,44,c3,92,87,fe,83,a3,69,2f,41,6a,a1,0d,6e,\
c7,c8,89,64,b3,7d,13,e2,e1,10,2d,de,15,df,1e,ff,83,a8,e7,66,15,7f,d0,c3,f5,\
bc,19,2d,3a,42,81,ec,4d,94,86,eb,08,03,8f,6d,e2,ac,54,2e,f2,f3,b6,cd,12,b8,\
ff,b9,cc,f3,83,35,63,85,de,c2,cb,07,7e,61,a8,1a,49,d4,b7,16,ae,b8,bc,9f,cd,\
0e,8a,95,ce,ea,bf,b7,7c,e2,b1,2a,d3,21,37,11,ef,30,46,5b,d5,e4,7c,9c,6c,c5,\
34,06,fa,25,9e,58,ab,8a,ad,ba,9d,84,63,04,17,94,86,c4,4c,68,e8,21,8a,31,1d,\
3b,6b,34,95,52,93,ce,e1,ab,87,92,f4,25,a8,1f,52,14,dc,0b,74,e7,c3,33,e7,8f,\
81,a1,90,59,1a,29,cd,38,21,1c,d2,36,86,d5,d4,3f,75,8d,0d,97,16,61,43,ce,e7,\
05,b9,86,54,9a,4d,d8,8c,82,aa,f5,10,9e,65,8c,81,4d,cb,d4,f9,0b,d8,61,65,b4,\
10,0f,f6,51,48,7d,73,bd,c0,94,e9,36,b6,71,b5,9d,b4,1f,54,f6,ac,56,8b,10,a2,\
75,f4,84,4d,81,06,2f,a7,26,44,26,60,7f,48,1f,f4,45,2d,b2,9e,a7,68,db,37,c7,\
1b,d3,e1,85,d3,f0,a2,9d,e3,d7,c8,68,e1,c3,55,a0,c5,ef,0d,ac,52,04,de,cc,f2,\
51,0e,99,a4,40,57,e5,01,a1,67,78,34,e8,66,6e,ab,2b,af,fe,d5,b7,2c,94,1e,84,\
19,e6,8a,81,18,b9,99,85,e2,8f,91,f9,12,97,79,eb,9e,91,d2,36,fd,58,62,11,fc,\
e4,5e,fe,c0,6c,d4,03,34,e9,5d,8e,e3,f6,4d,6c,2d,9b,41,d9,10,03,b2,8a,10,26,\
9e,63,84,12,98,af,c4,66,6d,30,23,45,4f,73,e1,b7,50,c7,25,e1,12,f7,76,7f,84,\
ad,eb,41,74,a9,25,2a,ad,e6,f0,56,cf,3c,b1,05,3b,2c,b2,67,b1,1b,0a,62,e3,15,\
ee,4b,f6,2a,07,b4,ea,97,00,f4,4d,0a,85,7b,71,3b,49,a3,06,bc,cc,6f,86,9c,22,\
c7,b6,15,31,9d,77,83,b6,5c,1b,af,76,3f,00,20,f8,3f,b0,8a,80,87,47,0f,7e,9f,\
bb,fc,a5,0b,d2,78,b1,43,97,4b,5a,3a,17,0e,35,31,ba,d4,44,98,d1,49,3f,e6,9c,\
8d,b5,47,84,e0,c7,2b,52,3a,b2,28,bc,98,92,18,80,60,d7,ef,be,c5,01,c4,05,3b,\
cb,2f,95,c5,84,f6,75,ae,47,df,ae,c7,5f,08,83,c6,90,02,62,cb,f3,8b,f3,e5,16,\
e5,08,9e,03,65,81,f9,62,38,35,78,97,75,0c,17,82,a1,cb,a5,58,4a,34,1a,e1,b6,\
a6,0d,63,ba,3a,f0,a4,4c,8b,e9,dd,26,de,84,b7,71,0a,e7,2c,cf,3e,2d,91,b1,ee,\
fe,75,fa,45,dd,1d,e1,93,e8,6a,f3,4e,8f,d8,7c,5f,e3,e9,6d,82,82,a3,a3,71,a6,\
ed,b8,81,49,79,ff,55,12,67,6e,bf,5a,8a,bb,4c,11,7b,61,40,f9,a9,92,7b,d3,61,\
09,63,7a,3f,cb,c9,88,92,46,a0,e5,ad,88,4c,76,0d,3a,ab,20,bc,76,02,d6,05,10,\
22,7d,35,2c,40,d2,a3,da,0e,4a,b2,0e,2c,cd,ac,23,54,83,96,e5,98,7f,76,dd,f7,\
73,79,64,65,2c,49,24,6d,71,8f,b9,34,3f,5e,4f,20,31,ba,2d,e5,0f,16,5e,3a,14,\
dc,f3,cf,f3,9a,59,9f,7f,39,81,f3,51,15,5c,30,cb,2d,8d,c7,52,35,49,28,b7,bc,\
40,bf,7a,aa,ed,d5,ff,81,91,1b,91,ce,22,3b,2e,e2,50,57,19,c4,cf,27,c8,13,10,\
de,55,76,f9,54,85,c6,8f,f6,00,28,ec,a4,1b,d6,71,16,67,a8,0f,87,8d,b2,55,ba,\
bc,75,e5,e6,94,4f,f9,7d,09,0c,cd,c2,24,3c,5f,65,52,94,4a,bf,39,a4,91,e4,4c,\
42,8a,18,90,5a,a8,e3,31,f6,0b,3a,25,d1,35,6d,b4,d5,48,e6,62,b8,46,e2,c8,60,\
c5,73,95,30,ae,61,ec,ef,2e,e1,e4,0b,91,65,20,a3,36,b6,4e,67,6a,96,44,35,dd,\
c1,81,5c,14,fc,20,b7,0e,09,5c,ee,24,66,87,c0,28,a9,0a,c6,60,eb,bd,b2,ad,53,\
da,54,0a,58,d7,e9,fb,4b,66,cf,5a,7a,e5,d1,8c,b2,57,be,03,27,87,11,4e,8f,0c,\
49,46,ee,8a,51,3b,83,ce,0c,20,bc,9c,a9,6f,95,2a,38,a2,73,7d,2e,73,ea,08,15,\
38,7a,e4,7e,d6,a4,e1,1a,35,32,28,8c,85,b0,bb,30,1c,5b,de,b4,f3,6e,a0,c6,ba,\
63,ae,d6,b0,97,2d,00,51,d0,19,31,f1,af,a4,84,4f,36,23,03,5b,00,b7,79,f6,09,\
b5,69,75,6b,fb,7f,ae,4a,42,90,9a,17,15,1c,d5,10,a6,97,a5,e5,ae,87,69,39,07,\
eb,10,2a,28,96,32,3f,34,69,ac,5e,47,cf,69,4c,4d,f3,e4,54,1d,3a,3e,7a,6e,4f,\
61,bf,be,9e,97,71,f7,e8,f9,83,42,84,39,ef,2a,86,2c,6f,67,e2,83,80,16,d9,65,\
50,8b,83,53,05,74,51,20,94,17,28,b8,0d,8d,fb,d5,3c,09,0c,a9,15,4d,29,b6,e6,\
c2,1a,ec,de,8c,9b,98,a0,5a,90,fc,fa,33,5b,d9,e4,1e,75,43,30,de,35,fa,d1,87,\
9f,5e,a5,0e,99,a4,6f,d1,37,3c,2f,f5,81,40,0c,46,fe,8d,fe,78,c0,54,38,ff,8b,\
fe,3d,47,71,f3,d2,77,1b,72,2b,5e,1c,14,61,1a,e5,33,1e,f6,86,74,3e,a2,ab,47,\
56,52,16,65,3a,9d,a4,cb,77,21,03,b3,96,2b,b2,22,6b,04,27,af,be,c8,9c,05,7c,\
1a,f1,e9,8d,52,58,0c,e1,50,24,56,6b,13,16,c1,2b,30,4a,e0,b2,0b,62,60,c1,ef,\
3a,e3,ab,47,5f,16,61,36,e1,c6,92,6a,6e,70,9c,43,7f,60,49,0b,e9,3a,69,89,d1,\
07,bd,2b,28,96,2b,eb,5c,47,68,cd,7e,ec,83,19,cc,bc,bf,cb,0b,11,04,d0,b1,81,\
61,0b,dc,7a,79,35,c6,1e,b6,a0,38,06,f1,8e,20,13,4a,72,db,a3,c3,58,6a,f0,e1,\
34,22,af,92,a2,b2,45,8f,8b,23,1c,50,56,b0,45,f9,06,38,a4,7c,f5,f6,54,0d,65,\
92,39,ac,3d,8f,7c,1e,28,97,9e,fd,01,64,31,e4,d0,44,1d,f8,b3,42,9d,1d,10,94,\
f4,bc,38,5b,6c,49,24,d3,62,86,e4,1a,69,49,df,55,e7,c3,a4,e5,4b,9b,d7,2f,63,\
0e,70,ad,05,b2,43,20,75,1a,8a,f2,5a,e5,16,97,0f,cb,23,c1,1b,40,f4,a0,7b,a1,\
49,9c,76,12,27,5a,60,22,25,e2,fe,82,7d,31,0a,09,20,4b,1d,02,a2,87,9c,62,cc,\
cf,f9,72,73,12,82,b6,c9,95,b6,d5,0a,0f,a0,d3,d6,7d,08,ce,29,fb,30,61,e9,68,\
79,02,1b,1b,d1,f3,6c,8e,6f,68,09,5e,c4,5d,4e,ac,b6,94,e0,49,3d,da,1d,f3,74,\
ab,6a,4e,d2,2b,53,75,e2,e9,dc,76,bb,75,28,9d,ca,06,df,09,cd,ce,23,9b,d1,d7,\
4b,d9,97,f1,e5,33,03,92,a0,39,c9,3f,31,1f,5d,ad,d4,48,f7,4e,08,63,b3,45,3f,\
08,02,99,5f,13,27,1c,fb,7f,17,3e,32,09,de,40,4a,a4,46,e0,f1,3e,ee,51,3d,ae,\
12,42,86,f2,fd,24,2d,bf,06,aa,d3,00,47,c2,12,33,f2,a6,10,a2,9e,36,9a,6b,9d,\
65,31,32,f3,6d,77,2d,65,a9,4f,67,df,f8,ff,1f,ba,3d,f9,c6,81,d8,38,ae,c9,93,\
0e,2a,39,45,82,61,14,ea,ac,65,82,45,77,a2,72,91,19,e7,3f,54,8d,92,1e,ff,d7,\
db,db,9f,0d,9e,d5,ee,37,fa,60,b2,27,ac,0f,3b,f3,12,c8,fc,96,29,7b,b8,a2,0b,\
08,af,51,d2,ed,54,13,6f,05,00,bb,eb,c7,88,d8,40,f6,b5,52,3a,61,5c,12,bd,ca,\
50,77,e9,7f,74,f5,b0,c6,5f,ac,25,ad,55,ce,62,4e,e4,a0,1b,fc,86,3e,00,ab,ea,\
dc,9e,56,e4,1c,fa,94,59,02,42,8d,7c,20,6d,da,45,0a,a2,9d,b1,e2,1a,96,5a,32,\
5d,49,c5,bd,61,1f,f5,4b,23,9e,28,32,8e,d9,de,d7,91,71,ba,6d,96,43,12,1b,be,\
e1,ca,5e,f1,80,2e,b7,57,23,37,9f,dd,57,5e,e4,db,bb,d9,8a,64,08,05,de,92,0e,\
65,76,d3,11,a3,30,f9,72,ed,34,89,8a,5a,b5,06,08,08,08,0e,16,bb,18,f8,96,22,\
68,40,6d,aa,53,f7,ae,77,eb,13,2c,51,50,3d,f3,60,0c,68,bd,2e,fe,02,14,1d,85,\
ba,6e,62,3c,06,97,4f,8c,d8,bd,d2,01,6d,6d,2e,13,49,8e,97,1b,7c,22,4a,35,1c,\
36,69,62,74,29,6c,ff,c5,2e,72,af,c4,82,28,f9,9c,7e,6b,c4,59,ce,b9,46,45,03,\
97,8f,14,a4,e4,27,73,aa,2e,e7,3e,b0,17,75,b1,ff,c4,cd,a5,cc,e3,4c,ec,64,d7,\
ba,46,61,f1,03,73,c4,cf,e5,44,1b,cc,e4,76,5f,77,4f,2e,e6,d5,da,c5,8c,fd,7d,\
e5,7b,aa,45,09,63,92,94,43,18,47,f2,dd,a3,53,27,9b,07,eb,c1,94,53,9e,6c,2b,\
11,ac,4d,46,82,6c,95,8b,c2,59,59,a5,7d,96,28,b6,3e,01,20,d9,5d,84,f9,b0,1b,\
d7,86,2f,79,73,61,f5,e5,a6,a4,c3,fc,59,64,be,0e,bf,84,36,77,e6,3f,95,7a,b8,\
55,05,4d,22,31,4e,ae,f9,e8,ba,0b,43,83,34,47,ee,7b,a4,f1,fb,a2,c7,e3,a3,8f,\
67,da,d3,72,47,ea,c0,b5,09,6c,b5,3b,2f,f3,1f,5a,23,61,84,9b,0c,aa,14,4d,f3,\
19,b4,50,3c,eb,16,64,f1,0f,84,5b,50,70,48,13,c6,78,31,c8,2b,7d,66,cb,0b,a8,\
de,26,d2,0b,35,fe,ed,a1,d8,45,b0,0a,93,3e,67,b6,43,56,e1,31,9b,89,86,f1,29,\
63,3e,e5,f2,2f,30,b8,0f,d6,f9,0d,1a,bc,18,7d,00,90,a3,22,ea,8d,4d,90,4f,fc,\
12,8f,d0,1c,97,99,3e,24,ab,ee,e7,af,90,99,ed,8d,4d,06,a1,4f,7e,32,04,de,27,\
18,85,4c,82,b6,82,f7,d5,1b,a5,f5,37,38,57,5a,a8,91,26,0e,1d,65,94,5d,40,79,\
ce,95,62,d1,8e,a3,8a,bf,a7,db,53,4b,14,6a,b0,4f,23,3a,00,05,47,f1,22,a7,77,\
07,f2,2a,8e,a9,2f,29,66,55,27,2d,58,60,51,5c,88,43,2e,66,ca,d0,18,0e,c7,0a,\
0e,46,ec,1b,99,0a,e3,bd,92,ce,d9,4b,ba,37,80,58,43,57,1a,a5,1b,01,bb,8d,fc,\
52,8a,39,f9,23,d0,86,cc,0f,19,70,ac,4f,8e,25,30,15,50,85,52,09,37,75,05,76,\
f7,d2,99,34,50,ba,43,28,9b,63,ea,d1,db,ad,7a,da,31,69,c9,70,0c,42,e1,00,c4,\
21,34,dc,46,38,f7,84,79,21,d7,73,33,63,6f,40,54,c0,7d,dc,81,d0,65,35,2c,c7,\
67,10,8a,b6,5c,6c,67,cb,2f,8f,31,27,7a,9c,96,e7,b0,eb,52,92,a5,b7,61,37,7b,\
b6,f3,cb,15,90,15,7a,d2,f1,f8,fc,b5,9c,c9,59,48,b9,c1,be,71,f9,61,3b,76,f5,\
a0,a5,76,c5,e9,30,c2,b8,69,40,62,56,17,e5,ba,9c,67,71,34,ce,e4,e8,1f,de,58,\
0f,bf,1d,9c,9f,eb,a9,e8,7d,3c,38,e1,35,fc,70,40,93,83,5d,5a,47,6e,1e,f4,f5,\
90,3e,71,82,e0,ae,7d,e0,f4,1f,5a,7f,04,8a,3c,c4,7c,78,fb,94,00,a0,c2,a4,88,\
a2,14,4f,d1,e8,55,1a,79,fc,44,30,31,6c,7f,4f,58,f5,5e,53,69,fb,16,a0,dc,0b,\
e9,f2,bf,15,cb,7f,bc,8d,c8,9b,da,1a,ad,ce,04,d0,fd,9e,db,2f,36,0e,b7,09,12,\
e6,2d,c9,2e,82,44,7c,73,19,3e,61,be,ac,d7,e6,cf,09,7e,63,2b,33,90,7c,d8,a3,\
4c,56,87,46,bd,1e,c2,47,55,9a,bc,e7,a3,a2,c5,a9,5d,8a,28,9a,62,4e,ab,c5,a6,\
a7,c1,fe,56,27,47,72,0c,06,ea,65,cf,f6,c3,10,cb,e6,b8,a0,8c,9e,07,ac,5b,c3,\
d8,5a,fe,24,b3,57,9a,f1,6c,4c,30,95,51,74,65,5b,21,85,32,79,e0,1c,95,6c,dd,\
4b,fd,f5,bb,92,97,e7,f6,4c,5d,cf,48,4e,2d,0b,bc,6e,5a,e4,0d,2a,6a,8b,ab,e5,\
6d,89,45,e0,44,8b,17,6c,33,53,5c,92,a4,2e,00,fc,9b,87,cb,a2,66,f6,98,9b,f1,\
ac,e1,e9,b1,6f,32,48,47,36,f7,ae,16,da,9d,d4,f2,a5,5d,8e,be,d2,4f,92,1a,2c,\
8f,98,6b,d0,76,b2,4d,d2,45,47,ef,bf,16,c7,d6,27,d5,24,99,f3,62,d3,1d,36,51,\
50,f1,05,d3,fd,bc,8c,98,c1,14,30,3f,ed,ad,00,1c,46,5c,9e,ea,9b,be,8f,f0,b5,\
c8,79,dd,24,a6,92,cc,63,47,bd,e3,88,f8,7e,a5,28,c1,25,c0,02,50,82,60,f6,a5,\
bf,c9,ac,ce,74,4e,8c,e0,b1,36,ca,c9,47,7d,e4,63,d2,3a,ef,0c,43,bd,22,74,a4,\
20,e5,f3,6e,57,2e,6e,b0,a1,e9,24,35,cd,be,f4,40,79,28,a2,07,13,86,c9,5d,2b,\
4c,7b,73,07,3f,4a,80,a1,2f,6d,55,3b,da,6f,3d,f3,07,bb,de,22,b3,53,7d,6b,e4,\
e7,1b,f8,49,e6,48,30,4e,51,83,a8,1e,0c,19,c4,bd,06,b6,09,9a,cf,64,1f,bb,42,\
cc,13,1c,9c,23,93,16,1b,1a,6b,a3,6c,83,9d,cb,fc,8b,fd,be,66,32,cc,b3,10,2c,\
4b,fb,e0,4b,60,ad,f9,cf,54,e0,19,fb,4d,20,ce,ae,c7,cf,4e,25,8c,06,41,48,e8,\
2e,a7,42,24,bb,6b,8f,59,a3,5e,7e,90,8a,3e,f1,c5,9c,d1,5a,9f,93,53,91,d6,f0,\
17,ec,8f,70,71,d3,a7,03,88,15,a3,b8,ad,92,c6,60,51,06,5d,f5,7c,99,db,d9,5b,\
86,4c,d0,1a,fa,79,03,d2,04,71,c7,5e,f4,2a,cd,17,7f,71,5c,46,7f,c0,13,b3,1c,\
84,90,e6,fa,6f,39,0d,ba,ce,6e,d7,84,c5,a8,40,fc,14,aa,cd,4a,df,5c,b8,75,18,\
44,31,eb,08,ff,f4,5e,3a,98,b5,42,0f,c9,96,da,12,0d,9d,2a,bb,d8,58,e9,fb,9c,\
d2,a8,ec,a6,0c,09,a3,a8,07,83,ad,77,c6,b2,0b,42,07,7e,6a,a9,d5,25,3f,a9,13,\
45,8f,ba,69,49,f9,a4,d7,e3,d4,2f,49,fc,f2,8f,c4,c6,a1,44,5d,ce,b3,59,c1,04,\
5f,e8,53,00,20,52,0d,90,ec,6b,69,98,d0,66,51,6f,ef,fc,a8,ab,fe,eb,35,94,78,\
e8,ed,b1,1c,3d,0f,f4,29,9c,cb,d5,f3,54,1a,cf,7a,34,f3,b6,01,b6,0d,26,d4,7f,\
7b,8f,ef,83,b9,44,ac,4c,01,ae
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50

[HKEY_USERS\S-1-5-21-436374069-2025429265-839522115-1003\Software\SecuROM\License information*NULL*]
@Security="Inherited"
"datasecu"=hex:52,cc,83,a6,d0,c3,ac,0d,0b,5f,5e,cb,dc,31,a1,bf,d8,ab,55,ce,eb,\
2d,ab,96,5d,21,2a,80,e8,1a,1e,69,7c,32,ac,a9,58,19,e6,dd,33,cf,e6,2a,3c,9e,\
11,27,7e,d6,98,1e,a7,91,6f,2e,96,16,5e,b9,ec,1a,52,2d,28,b8,d3,c6,7e,0a,60,\
46,19,6b,7e,90,c4,b9,00,2f,e3,57,22,b5,8e,a5,71,75,dc,5a,31,04,82,be,82,af,\
54,e0,8b,21,63,a6,6e,69,b8,a7,bd,c2,c2,97,d3,3a,c1,a9,b2,ce,4f,ae,15,e2,91,\
bd,68,48,57,ec,bc,e8,05,d9,93,1f,45,f9,25,89,2d,8f,4c,e7,5a,e9,85,25,02,6e,\
fc,b1,02,b3,e9,d9,25,22,0c,41,dc,f4,db,92,a2,16,5d,75,f1,41,1c,09,9b,d9,41,\
e9,d9,9b,b9,1c,41,c2,49,97,86,96,d4,3d,4f,2b,13,95,d7,ad,c7,02,bf,f0,fc,97,\
2d,b2,25,bb,1e,fb,ec,59,71,e0,47,3d,a1,f0,fa,c6,76,48,89,9f,ef,aa,f9,3e,e1,\
0f,d3,e1,d2,34,b6,26,90,18,f0,01,a2,99,ec,48,cb,aa,5e,3e,7b,d5,07,f4,ea,e1,\
19,74,c0,6a,85,93,aa,3c,73,0a,b0,3e,9f,fa,3f,64,18,f9,ca,54,50,e0,ad,45,47,\
50,c9,79,3b,1a,be,a7,10,c5,35,b6,df,b9,76,f2,36,8b,d3,32,be,68,a9,b4,c8,b8,\
61,6e,55,ca,28,95,c6,c6,54,91,e1,fe,d6,6d,1e,78,38,e8,05,f6,9b,c9,ba,85,15,\
79,58,25,ad,64,e2,ce,56,fa,3a,f3,e3,fd,c3,78,72,c1,e0,55,9c,bb,f1,b9,0a,8d,\
23,5d,44,5a,a7,09,cd,3e,91,09,c3,19,fe,5d,3b,01,29,64,78,8a,da,5d,6e,0a,5c,\
89,63,1d,e4,35,aa,fc,fc,a2,eb,2c,c7,7a,56,a0,71,c1,2e,a0,a0,d3,05,f9,d4,c8,\
39,be,11,60,36,a9,c5,73,77,dd,9c,7e,d2,85,78,25,93,95,ae,7f,bd,22,cc,4f,a6,\
c0,16,c0,71,83,ec,20,08,1e,a4,e2,5b,ac,c8,ec,96,c6,26,f0,64,71,27,90,99,00,\
bc,26,2a,96,04,77,2c,2f,a8,b9,df,db,e4,5b,21,29,ea,30,2f,73,b5,30,65,b9,95,\
07,ac,51,cb,2a,11,18,ad,35,57,27,d2,98,84,5a,d0,f0,22,56,75,7e,b4,1e,1f,6f,\
50,ff,74,e5,a4,6e,2f,55,c7,be,78,8d,2f,21,60,86,bd,cf,65,ec,df,3b,d4,62,5b,\
31,d3,85,71,c9,f5,48,7c,e9,b8,ee,c8,f4,0f,b9,f8,01,f4,c6,80,5c,30,05,11,69,\
97,67,15,17,e6,16,bb,63,60,37,92,75,2b,9c,1a,be,dd,b8,79,b7,fc,4e,2c,c9,ca,\
a3,f4,f5,51,cb,b6,cb,48,3d,4f,2e,e9,6c,8d,73,a6,d9,5c,bb,14,be,61,86,97,41,\
0f,30,43,02,02,84,52,60,7c,bf,29,ab,e2,25,db,48,7b,44,07,ef,7a,8e,c8,f9,7f,\
3f,a4,f5,a4,68,5c,c0,72,dd,0f,32,e6,b2,ea,f9,02,bc,68,87,50,8e,b1,04,65,91,\
2d,c8,d7,56,53,bc,27,46,0f,7d,aa,85,d4,f2,10,e6,dc,78,c4,e3,83,3c,f3,ed,0d,\
3c,f1,5a,fc,bc,18,a3,3f,7d,0a,6b,85,37,da,ed,cc,bd,5b,b3,14,af,53,b1,59,64,\
d6,f3,79,7d,ea,aa,aa,23,60,aa,1b,56,c0,7b,ce,8b,d3,dc,ad,16,f0,34,fc,30,07,\
40,b1,53,b8,80,75,96,17,ac,e5,d7,06,c4,6f,42,dc,fa,fb,ce,8d,6c,85,50,7e,3d,\
16,cd,5e,e9,d7,42,48,6c,4c,a2,c7,1d,09,4d,ab,11,dd,94,39,55,f7,67,be,72,69,\
5e,2c,41,37,66,88,9b,20,a7,43,20,73,0e,1a,61,f0,dc,0a,14,6a,55,2b,36,67,82,\
5d,51,a5,5a,d3,c2,d7,51,9b,5e,a4,67,a8,e5,65,03,e4,4c,c6,0c,4b,30,53,f4,4b,\
fb,ca,88,5f,67,95,ed,24,5e,60,a0,49,c6,0c,5f,a7,4d,73,a0,ad,f5,c0,e6,4d,ba,\
a1,3d,2a,d8,f3,72,05,7b,d4,a0,cf,d3,46,07,ba,98,2d,ac,f6,3d,7d,31,57,47,2e,\
da,69,fb,21,ec,cb,ac,0b,ea,dc,84,10,82,1b,8c,29,01,9b,43,2a,fb,74,f0,7e,2b,\
0f,89,83,79,13,66,a9,c0,25,9c,fb,d8,b9,00,82,35,c1,70,c6,ce,4f,85,7c,8c,c8,\
cb,00,5d,4f,9a,ea,60,8d,d1,d1,dd,5a,69,f5,91,9b,04,93,79,04,e2,e4,0c,9a,cd,\
d1,58,88,03,2d,e0,1a,95,e6,b5,40,e9,67,f9,85,76,dd,85,38,4b,30,9a,cf,03,1c,\
ca,c3,e2,15,9a,c3,6d,fe,56,51,2a,c4,e6,6a,71,59,4f,08,6c,08,91,8f,85,d2,09,\
0e,fc,90,dd,46,81,77,31,37,3a,ac,4d,b0,0e,29,78,de,29,5d,ab,2a,13,e1,05,d5,\
1e,93,c3,e5,a9,7a,50,19,a1,bc,8e,fc,7c,17,68,7e,4f,1f,a0,ad,9a,c5,93,56,bc,\
43,e9,63,83,9e,ae,33,12,6b,f3,64,01,1b,b9,aa,ba,01,49,0c,76,54,2b,d1,33,0e,\
fe,2c,bb,b3,4f,60,f6,57,ac,88,e1,ea,0b,a3,20,e0,f2,41,4c,31,35,44,c9,67,24,\
99,7e,6d,54,5e,13,f9,3b,ae,41,19,57,48,d1,22,6b,4a,76,81,58,d2,36,96,c7,b7,\
af,dd,f2,ba,97,a8,9a,96,cf,8e,31,78,95,e8,58,70,d7,73,a7,8d,7f,31,46,e1,f6,\
66,bb,19,ee,b2,6a,83,24,53,b5,4f,e1,41,d7,90,86,da,24,73,3d,c3,dc,1e,0b,95,\
58,c4,8f,64,50,48,b6,47,e6,6f,30,4e,65,f5,af,b7,73,ef,5d,e6,6d,5d,a5,64,f7,\
4f,da,47,b5,2f,39,e2,11,29,c0,87,76,4d,00,c6,18,3b,b0,b2,a4,d9,e0,3f,e3,f2,\
2f,a3,0a,8a,af,d7,6c,8d,0e,df,44,ff,d7,00,bd,15,cd,0d,7a,47,c5,0a,95,d5,6c,\
82,71,d0,dd,1f,fe,23,a1,46,c4,57,fb,2a,a8,18,98,b7,fe,6b,0e,27,a3,ec,a2,5d,\
b4,7c,14,44,bf,d6,cc,ee,d6,b4,be,64,b4,8d,82,f6,82,6a,5e,4a,a6,21,0b,9e,29,\
0d,c6,2c,11,3c,bf,79,15,f5,f5,24,00,d5,ea,89,16,6f,c7,d7,44,8f,21,39,d3,5d,\
50,10,5a,b5,34,4c,69,52,3c,3b,cf,83,cb,5d,ca,5c,10,08,ff,1c,e0,25,f6,e5,a7,\
4a,56,e1,78,c4,cf,2c,63,e6,38,76,91,f5,ab,e7,64,b2,2b,02,87,b0,86,55,f8,ea,\
4b,3d,52,c2,72,72,e5,19,78,7e,ef,9a,bd,0a,9b,86,c2,0e,c3,cf,f4,bf,d7,02,5f,\
61,4e,88,9c,42,43,c0,55,ae,13,2d,19,72,b3,4c,ed,db,9d,e0,21,c1,e3,43,59,9e,\
a3,fc,4a,86,69,c2,ed,73,4b,a8,df,92,3c,e7,48,d5,7c,d4,e2,14,dd,50,2a,07,c1,\
a5,d8,06,34,f7,1d,25,b3,78,c8,88,51,95,0e,08,8f,60,fd,3c,b3,95,73,bd,2e,6c,\
db,7c,dc,92,6f,09,0a,3c,6e,7c,3b,e6,3a,17,5c,95,05,0f,01,6e,df,1b,36,29,c1,\
e3,4f,2c,05,9d,fe,70,6f,73,28,fb,e5,90,da,03,b5,6c,a0,e8,6d,ad,af,08,d0,d7,\
5c,a4,a6,04,42,ce,74,b6,a4,a4,d0,42,a3,ac,21,1d,a9,8e,73,e2,6b,f3,20,75,6a,\
55,62,84,b5,d5,67,98,c1,0b,1b,36,c4,c3,fa,96,6c,05,73,ca,de,92,c2,7e,a6,ad,\
f6,1e,b3,92,d7,7c,03,d6,b0,5a,5b,8c,6d,f4,42,a3,b5,37,af,f5,2e,8d,75,8a,ad,\
25,25,fb,80,d6,8a,47,cd,91,26,53,ac,8b,e2,e8,96,bb,6e,67,a4,14,a7,5e,05,ce,\
5b,04,2b,bb,5a,a9,02,0b,d4,e3,a3,34,11,67,fd,d6,1a,ad,f0,7d,50,6a,42,6d,8c,\
f7,8a,6f,ed,e1,02,eb,6b,b7,ef,21,b9,9d,e3,0b,f3,81,ee,99,03,71,7d,08,86,69,\
cd,75,47,e7,ea,ae,03,0e,88,25,19,9c,39,73,de,9f,ec,60,96,d6,99,06,7a,97,2d,\
9b,16,a1,be,02,27,bb,f2,2d,9e,d1,f1,89,d4,fd,8e,05,a4,9a,1d,d3,95,c1,86,b9,\
c5,03,a4,40,2d,f4,54,0c,8c,39,dc,48,c3,9e,5a,df,ce,16,cb,70,b0,9f,df,1d,4a,\
f3,54,d5,e8,8b,02,88,26,d6,d2,66,6e,6e,30,a0,3a,92,42,e0,f4,d3,2b,3f,89,da,\
4f,1d,5a,02,3a,08,09,a7,96,43,9d,7e,99,5d,a2,8e,dc,d8,14,43,1c,94,2c,6b,8b,\
21,63,76,f0,78,7a,12,12,00,e4,2c,47,6d,27,b9,67,47,58,4a,49,dd,90,83,45,91,\
b0,8e,ec,ec,72,bc,f0,21,61,a7,ad,9c,f9,75,c4,8e,28,68,80,47,89,ff,72,1c,42,\
46,8f,7c,d7,4e,36,18,e3,5b,51,ac,99,4e,bc,78,bd,f1,04,d2,81,a6,0b,5e,04,70,\
34,e4,9b,04,20,2e,96,48,c2,ff,e2,66,ba,c9,34,67,fc,1f,ae,bb,cc,43,de,7d,ba,\
06,4a,0c,b2,17,e0,e9,c3,65,30,62,c6,d4,42,d3,81,d2,c5,fa,cb,36,68,3d,0c,c9,\
45,eb,f1,ee,24,71,e4,4b,75,e7,f7,91,5c,36,5d,a2,df,7f,01,a0,c8,ff,be,08,78,\
48,86,21,5d,ab,42,90,53,59,b5,62,d5,77,ae,ba,8e,c9,0b,11,da,3a,80,89,b6,3f,\
1a,3c,e5,a6,20,45,49,11,46,ac,7c,e9,f6,b4,e4,aa,3e,e3,26,e5,df,94,2b,59,0d,\
26,d3,c2,c8,fa,dc,37,da,9b,fd,67,8a,ea,11,69,b2,c7,26,9d,ec,f4,8b,47,1a,59,\
35,45,ff,57,7c,87,82,aa,ad,7c,d6,e8,1e,74,16,6b,8c,d7,66,27,3b,f2,fb,d2,e6,\
ee,3a,ca,fb,4e,6f,f9,fc,f9,38,a5,c2,39,14,ba,34,b1,cf,c6,96,20,ae,59,36,9a,\
11,9c,71,3e,2e,39,7e,74,25,89,da,61,79,54,6d,72,df,50,da,a1,af,30,1e,8c,28,\
21,51,7f,0c,f6,ae,8b,8d,7d,b1,dd,37,69,31,f0,62,83,82,a5,fb,4e,47,8c,2b,05,\
6e,5b,06,cf,18,19,32,45,b4,e5,62,0c,17,88,4c,38,05,03,13,90,16,89,e1,10,15,\
1c,40,58,95,9a,39,53,da,86,eb,8d,2b,ad,e2,37,96,78,9c,08,38,0f,26,88,df,94,\
f8,1b,7a,0e,07,94,fd,9b,df,37,3e,2d,b0,16,b2,bb,db,e8,ca,73,f8,33,20,fe,1a,\
45,a6,6a,21,58,30,4d,12,6a,3e,f1,b9,df,4c,1b,90,d5,55,0a,6d,49,2e,2e,27,36,\
90,4b,01,03,0e,c5,85,04,08,14,7b,9e,3c,88,17,55,99,9a,e8,f0,fc,ba,50,54,77,\
45,4c,81,df,31,bb,eb,d3,db,f5,44,ee,48,0b,31,fe,f1,a5,43,08,bc,19,c7,b3,0b,\
c8,f0,0f,3d,7d,42,18,3b,b8,47,f5,e3,f6,56,1a,ab,09,0b,5f,d3,56,8f,a2,38,cc,\
0c,39,21,e3,32,76,3e,a7,a6,16,f0,8d,c5,78,3a,b3,10,1f,60,08,a1,81,10,52,44,\
03,c4,c8,c3,da,00,be,49,35,29,53,19,bb,ef,73,94,b0,0b,69,a8,ed,2d,59,a1,3c,\
8f,3a,7f,e7,57,e6,3a,a8,db,0d,90,ac,54,12,24,fd,4f,10,3a,1d,ec,a6,f2,ef,92,\
73,ea,87,50,37,18,9a,e5,10,b1,d7,95,05,41,03,62,02,70,30,7f,4b,69,47,e8,2c,\
42,6f,55,ff,de,35,05,8f,01,1f,4b,e5,8e,52,de,97,2f,50,4f,ee,d8,bf,b8,ab,9b,\
00,12,3b,79,63,8b,03,cf,56,92,99,e0,31,40,48,ba,bb,84,47,3f,a6,82,be,57,52,\
77,d8,55,2c,80,6a,90,52,f1,dd,26,60,6c,f4,7c,99,02,9d,e1,fa,c2,d2,9f,4f,44,\
1c,9f,cb,8b,12,6f,a8,11,b2,ae,0b,9f,72,df,b7,2b,29,f6,c0,35,c6,28,a7,d4,c1,\
a9,ee,7b,f2,75,ad,3a,bd,81,3f,5c,31,f9,2c,16,60,cc,db,14,bd,dd,2b,06,09,f8,\
e3,11,fe,36,08,d9,f6,cb,54,7a,42,b4,41,4f,01,23,54,7e,d4,91,16,1b,7d,09,c2,\
a7,5d,af,86,0b,0d,28,9e,4c,c0,65,56,9b,56,36,62,c0,62,87,44,c6,0d,39,a6,73,\
4c,4d,16,ea,23,1b,3f,aa,20,73,a7,c8,5d,c0,29,12,a7,b9,50,d4,6d,e2,0b,82,fe,\
05,63,38,79,73,5d,ef,38,c3,ba,0a,02,e6,91,74,1b,11,8a,f4,cc,93,41,4c,13,32,\
79,d2,ca,ea,00,63,1e,6d,ae,e2,01,fd,3b,b8,ff,40,4c,c6,d0,a6,89,7e,86,c6,6a,\
15,91,20,8a,cb,72,e5,ad,b6,b8,3a,53,e6,73,07,1d,b9,40,2f,e0,b4,c0,aa,e3,b9,\
f2,e7,cb,29,a1,d6,fa,bf,68,03,4e,7a,59,06,ad,5f,44,f5,ab,9b,cf,de,78,76,42,\
83,b3,11,49,42,b7,a7,cc,1c,92,a5,da,d5,52,86,62,70,a1,c0,ee,31,8f,50,ac,65,\
29,ce,7a,66,04,b0,40,12,49,a5,b8,a7,42,20,bb,80,8c,23,ce,17,47,4b,d3,a8,d9,\
0d,96,28,7b,d0,05,84,ef,0e,40,6d,f2,16,13,06,27,3a,82,87,9c,f1,a7,7b,19,08,\
40,07,39,b1,0d,ad,4e,70,e5,e3,9e,5a,2e,75,a4,c4,1e,ae,12,e7,e7,c2,83,f6,cd,\
01,43,04,ad,89,7d,08,21,d2,8b,9a,8f,00,b0,b0,a8,24,62,80,57,9b,9d,d9,8a,44,\
ec,15,cf,b7,57,54,c3,ba,fd,c3,3c,e8,d5,09,78,5d,de,e0,2f,77,a0,f2,93,5b,da,\
c7,92,a7,12,86,bb,47,0a,65,68,a5,b0,9d,87,2f,bf,60,3d,ef,99,53,bc,71,f7,fb,\
68,d9,86,35,c4,8b,66,69,b5,c1,84,ca,dd,b4,d5,b1,d9,5b,83,a1,56,15,d7,84,ab,\
38,fe,29,04,2d,80,ed,43,68,4a,ce,e8,a0,97,cf,ea,bc,89,70,eb,33,8f,84,a5,5c,\
05,06,08,6e,32,74,e8,2a,6c,86,05,52,a5,b6,36,79,07,0a,46,d0,23,8b,4c,04,d7,\
c3,08,01,66,65,28,99,32,d6,9f,5b,03,9b,9b,34,07,51,28,32,b6,9e,d1,5c,98,eb,\
f8,c3,f1,f2,3b,ca,5b,c7,9c,e4,7d,12,db,60,0a,48,3f,17,5d,f3,a6,1e,2c,b1,9f,\
b9,bc,d7,ad,30,2f,27,ab,66,88,20,d3,ed,83,d4,46,0b,c9,f4,7b,bb,72,6a,47,01,\
49,67,2d,dc,3f,b6,39,47,56,70,85,af,19,0d,02,58,fe,e0,70,d3,df,b6,d5,92,e2,\
0f,a2,8d,8b,de,dd,98,19,59,c7,68,82,e7,2b,1e,45,a7,e0,d4,41,51,93,45,4e,04,\
98,44,29,65,85,22,92,4d,c1,2c,af,d2,1a,cd,a9,58,3f,58,87,7b,c5,1b,ee,8d,ad,\
52,27,b5,ef,c0,70,8b,a3,1c,b4,f0,01,2f,15,bd,29,d1,02,38,98,3d,ca,6c,d3,53,\
33,26,33,33,39,b1,70,5a,ee,f2,4b,f0,b5,95,8d,f2,12,33,bd,6f,a8,c8,ef,56,10,\
d4,43,a8,4f,fd,8c,7c,ff,27,b8,b6,1b,bd,19,51,1a,a8,fe,80,fc,dd,30,cb,70,29,\
9a,f5,08,7e,86,80,f1,83,a8,34,e4,d8,ad,c9,6a,5a,87,65,3f,60,29,a7,bc,b4,34,\
3c,a4,9e,51,07,d0,04,cd,8d,9b,c7,f6,90,63,bb,3e,65,fc,44,dc,c1,7c,28,41,35,\
f2,3d,cb,fd,05,1a,92,38,be,3c,07,0c,d0,31,9b,75,2a,c8,5b,9e,1e,d4,bd,d4,66,\
31,4c,ba,5e,25,33,5e,8e,54,af,45,8c,0f,14,e6,0d,8b,c5,ed,b8,df,2d,12,ec,34,\
ef,8f,9e,0b,86,a9,5c,a2,21,bd,0e,c6,71,b4,40,72,77,fc,f8,77,65,b4,13,a6,97,\
be,7b,b0,2d,d7,c7,bb,3c,02,f1,1b,aa,3a,f5,22,86,c9,6a,cc,31,3a,f9,01,d4,3e,\
fd,ff,f8,01,b3,7c,de,1f,c9,73,a2,2e,ae,3b,68,4d,38,82,c4,a5,1b,4b,c7,e0,8a,\
02,25,84,15,cf,ea,a7,d1,71,f2,89,7f,63,a7,b0,21,4e,b5,aa,58,8b,46,8b,41,55,\
6d,44,31,90,63,d7,2b,93,c3,6e,3c,ee,a8,4d,f8,64,91,28,1c,22,01,96,e5,56,e7,\
9f,a9,5f,78,3a,17,d0,7f,e8,82,96,31,d6,24,de,36,03,58,53,76,96,18,ce,a0,e2,\
8d,8b,91,d2,12,1a,67,d0,37,6d,cb,b9,85,84,1f,7b,75,37,0c,83,6f,ea,a6,d8,e3,\
9c,87,87,f9,86,ff,ac,fd,bc,bf,d1,8e,58,58,c5,84,09,3a,3d,3b,b0,f3,85,ec,65,\
16,73,7b,e4,57,59,fc,5c,04,71,df,a0,a6,4c,06,bd,05,42,37,1f,b8,a7,9e,0b,c1,\
9a,a1,fc,a5,71,58,e5,8c,37,6c,db,04,0b,7b,29,5c,e7,be,72,a8,85,21,e9,e1,8d,\
57,8f,96,67,f6,69,3c,fd,ff,74,13,96,c9,ae,8e,a1,86,2c,c7,15,64,07,2a,5d,54,\
e9,e4,5b,03,7b,42,c0,66,0f,22,90,5d,bd,d3,10,e3,ce,7b,ea,f1,ef,9d,a2,4d,86,\
c4,65,35,83,f6,2f,30,3b,ef,9c,88,05,c0,e9,f7,33,8c,ca,fd,f2,5a,50,90,98,8b,\
87,a8,9e,a7,ed,b3,c4,64,4f,14,8a,86,6f,4c,70,3d,30,4e,36,8e,9d,24,28,e0,c0,\
50,73,87,c6,cc,4d,64,09,03,5d,7a,54,a8,b9,36,b6,09,46,06,29,d4,60,d7,95,d3,\
f3,7a,90,78,7e,48,7a,88,ff,c5,62,1d,a5,99,ce,3f,65,be,23,ca,49,a2,1d,c0,68,\
92,fe,10,ac,7f,c4,2e,45,eb,42,20,e1,77,6e,3b,09,c8,c1,8b,5f,27,52,af,60,b8,\
84,6a,ca,db,4b,3b,ab,8a,af,f2,29,16,aa,a1,21,02,04,9b,ca,d6,36,76,00,4d,29,\
b0,d1,cd,5a,79,f9,af,c0,65,43,08,b1,20,42,15,87,e9,88,c9,d5,62,ba,f0,3e,0f,\
78,b1,d3,d8,2d,37,a4,8c,41,ba,80,3b,13,02,0c,50,32,96,17,19,21,a7,0f,a8,89,\
93,df,9a,ec,e1,ed,2c,de,b2,fc,f4,54,8a,5f,f8,c5,88,e1,76,67,3e,29,17,4f,37,\
e2,d7,ef,11,77,6c,22,4b,14,28,09,64,34,35,cf,75,12,27,6d,15,1e,4a,b9,6b,7e,\
5d,97,fe,19,55,6f,9c,d7,ce,d9,92,40,85,82,1b,1c,d3,08,28,42,e8,a6,bc,b4,2a,\
fa,35,af,d7,c8,eb,4c,87,5d,07,b3,2d,8f,41,5d,15,9d,b6,e9,9a,b6,92,e1,1f,b0,\
6f,57,f5,14,31,db,b2,74,46,7a,20,e2,48,bd,23,5b,60,df,32,d9,50,b8,88,49,cf,\
b2,50,5b,2a,f3,f4,a1,91,a6,48,ce,99,01,9d,6f,42,c5,98,1e,29,e3,a2,87,1a,48,\
b7,c2,0b,ef,ea,c6,dc,5a,23,cb,10,fe,7f,50,9b,00,31,7b,6c,94,e1,d9,9e,97,85,\
a7,64,19,64,86,c1,c3,cc,6f,36,fe,53,ad,9e,0a,74,d9,6d,e8,5c,ca,92,0d,5c,52,\
1c,c6,cf,e7,9d,0a,2a,80,85,93,cc,7a,c5,8e,ef,6e,b5,05,9a,23,69,3d,f4,71,e3,\
61,89,ef,7f,5c,ec,f3,6c,e1,4b,47,27,93,9f,8f,f5,2c,75,69,9a,6d,da,71,31,03,\
29,e4,06,46,1e,36,89,48,ed,ea,ec,0f,83,bc,94,41,4b,56,e0,a9,53,f7,0b,dd,b7,\
b7,39,29,41,3f,b9,5f,38,71,21,81,5a,e9,3d,d0,c8,ea,93,67,5b,4c,4c,a0,06,67,\
28,ad,7b,6e,0a,67,bf,a9,19,12,4a,1d,7d,f2,5c,ff,1f,93,bd,f2,fa,57,cc,c4,84,\
4c,4e,b6,61,26,98,a6,56,3b,09,c2,c8,f7,e4,bb,67,b3,c6,36,de,0c,9c,5c,dd,a2,\
49,ec,65,42,a4,15,20,a2,fc,be,67,cc,04,4e,f3,15,b7,8c,40,37,98,7e,fb,b4,f7,\
36,e3,a0,9b,6b,b2,21,fb,54,61,f0,9f,d3,09,16,ba,26,d4,b1,ae,27,ac,ff,b2,74,\
2d,4f,de,46,9e,1b,f1,7e,48,2e,7e,5c,48,9c,f6,6c,a8,4b,1e,37,62,08,00,46,80,\
b2,19,bb,79,25,b7,c2,16,a2,37,d4,03,a3,11,fb,3c,04,9d,6e,f3,f8,8d,48,18,01,\
2c,f6,66,f6,c1,ba,b1,6d,2b,df,c6,46,ea,40,f3,56,61,4b,ea,8f,20,77,00,54,a9,\
1a,8c,c7,38,a1,32,8e,4a,74,cc,5a,f6,78,64,21,dd,8c,22,82,aa,fc,c1,61,8d,47,\
6e,29,09,e1,0c,03,96,04,e2,3f,d5,ba,35,08,7c,4d,5b,aa,be,2b,9b,a0,84,ac,87,\
35,e4,90,bb,35,51,92,19,88,3b,cd,7e,e5,e8,bd,58,d1,2b,f0,39,94,53,74,99,14,\
b0,ed,3f,5a,df,b7,d7,26,fe,51,cd,d5,f2,d4,ed,ff,1e,51,2d,67,93,ce,eb,40,b9,\
83,d7,fb,1a,3e,ef,0b,d4,16,f2,70,4c,c8,3f,09,84,59,67,58,44,62,62,c7,c5,e5,\
e5,1e,a6,f0,23,e4,cc,cd,d3,31,21,8f,ac,a2,31,49,89,df,a2,40,6b,90,79,42,90,\
bf,9f,eb,da,ef,f3,8c,af,9d,80,93,61,c6,f2,e7,15,5d,6b,4d,cd,6d,41,18,de,20,\
10,e9,89,a2,70,7b,10,2d,ab,ac,e8,61,0b,2d,a3,8e,af,fe,5a,5d,36,11,c4,d7,36,\
c1,ba,8d,de,bc,7a,71,17,bf,53,59,b2,96,10,f0,7c,fd,b2,9d,d7,2e,c5,64,cf,39,\
60,3f,25,ce,c3,75,6f,d0,69,06,04,54,63,28,10,8d,33,a3,37,c7,1a,94,a8,13,e8,\
22,a2,1c,6c,86,c3,f4,bd,aa,b6,2c,83,fa,fd,48,68,6d,da,f1,eb,88,ad,c3,3b,a5,\
5c,11,00,73,32,8b,ef,18,dd,db,00,d1,7b,84,85,f4,be,9c,bc,09,56,c3,54,48,e2,\
9d,21,f4,ba,60,e6,df,d2,63,dd,7e,e8,4e,21,fc,69,9b,dd,dc,5a,c2,fd,d0,39,1f,\
85,68,d2,7e,a3,08,4a,a1,c8,e1,6f,eb,3e,30,a4,3a,97,ac,6a,29,95,28,58,5e,0f,\
56,a1,b3,86,14,31,9a,8c,e2,30,05,b0,d9,3d,a3,40,25,2b,59,9c,82,88,cf,ec,30,\
03,ac,06,b9,1a,f1,d5,6c,f5,53,86,88,16,0a,5d,21,93,4c,78,66,e2,1e,4d,db,a0,\
12,f1,a9,38,1d,d3,1b,f4,1e,2b,65,26,e0,c9,5b,05,d5,1b,ce,c9,c9,73,a7,02,7a,\
b6,7a,aa,ba,95,47,47,f8,87,38,f0,1e,d7,6d,56,9d,78,c8,8b,1c,81,07,cf,31,da,\
44,b4,12,ad,69,42,c4,77,e3,77,f5,9d,56,b3,13,6f,6d,8c,54,63,a5,f0,76,ff,92,\
c7,60,00,8e,c5,c2,27,18,22,e9,1f,67,cc,95,3d,fc,8c,5b,0f,f8,43,e4,53,f8,9a,\
d4,5f,a3,09,5f,6b,85,60,77,32,bd,00,cf,98,81,e8,a8,b0,8e,62,11,c7,89,d4,6b,\
01,8d,46,59,4e,e3,7b,60,fc,74,eb,3f,7e,f7,02,d9,35,9e,c0,3d,82,20,24,1a,cf,\
ce,f4,35,ff,06,64,3b,5f,ab,5b,9a,b8,ab,e9,e9,8f,e0,33,f4,6a,7f,3f,3f,70,3e,\
6f,93,fa,b1,94,90,cc,0e,d9,72,a9,05,47,32,33,e6,7e,e1,e1,59,81,e4,bd,b8,bc,\
d7,fb,0b,af,8e,c7,c8,29,bf,7a,1b,9d,19,9a,45,52,7e,62,74,55,26,3e,10,b8,86,\
d4,a8,95,f7,e2,eb,44,28,6e,5f,0d,6b,92,14,fa,86,2a,fb,f0,d0,9c,92,f8,ef,1b,\
3b,01,fb,3a,4d,56,dd,fa,40,09,62,16,aa,1d,8c,2c,0f,81,14,ef,17,22,47,8e,a8,\
db,f9,a0,64,29,24,c4,89,89,dc,7d,b9,89
"rkeysecu"=hex:e5,09,05,07,96,d6,3b,ce,44,02,56,e2,15,ac,48,81

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}]
@Owner=S-1-5-21-436374069-2025429265-839522115-1003
@Denied: (A 2) (Everyone)
@Denied: (A 2) (S-1-5-7)
@="FlashProp Class"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32]
@Owner=S-1-5-21-436374069-2025429265-839522115-1003
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\Flash9d.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\Programmable]
@Owner=S-1-5-21-436374069-2025429265-839522115-1003

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*NULL*]
@Security="Inherited"
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,1e,40,83,48,1b,\
63,11,1f,2e,e8,e1,00,eb,16,2b,de,a5,51,df,c7,27,e6,54,fe,e2,63,26,f1,3f,c8,\
ff,68,12,b2,b6,e6,a7,5e,91,f0,c8,28,51,af,b0,29,a3,98,2b,1f,44,c4,55,3b,d1,\
3f,63,65,71,58

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*NULL*]
@Security="Inherited"
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,a9,6d,61,e4,f6,\
0a,c8,02,46,47,15,b0,92,4b,c7,ef,ad,7c,ae,22,4c,6e,e4,3f,6a,9c,d6,61,af,45,\
84,18,db,b5,1b,1f,04,6e,c1,a7,71,3b,04,66,8b,46,0d,96,c6,e6,25,58,19,52,84,\
6e,85,db,62,e0

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*NULL*]
@Security="Inherited"
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,73,33,83,6e,c1,\
64,cd,41,7a,45,05,fd,91,e8,6f,31,c0,e1,fc,a5,60,eb,16,ca,ff,7c,85,e0,43,d4,\
0e,fe,57,68,37,b1,0d,a8,85,d1,25,da,ec,7e,55,20,c9,26,65,5e,f4,df,4a,6a,ff,\
d5,bf,53,74,b5

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*NULL*]
@Security="Inherited"
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,80,99,70,16,b7,\
4c,99,1f,6b,65,49,6a,7e,99,74,f7,84,3e,47,89,9f,90,3b,0b,86,8c,21,01,be,91,\
eb,e7,5e,fe,89,1b,cd,45,ec,3b,86,8c,21,01,be,91,eb,e7,73,c1,55,bb,cd,f6,13,\
6a,5d,3c,fd,33

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*NULL*]
@Security="Inherited"
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,b5,c8,a8,b6,ba,\
1f,cf,47,e9,02,6c,fa,fb,1d,47,57,e6,5e,a4,9f,64,f7,c4,ac,f5,1d,4d,73,a8,13,\
5c,05,0c,99,86,49,13,6d,d0,18,f5,1d,4d,73,a8,13,5c,05,63,be,97,23,db,a6,9e,\
b1,60,62,8e,63

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*NULL*]
@Security="Inherited"
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,7a,56,4a,74,1d,\
68,fe,77,50,93,e5,ab,ec,6a,4e,ab,4a,8b,fd,03,d3,a6,3c,2f,df,20,58,62,78,6b,\
cf,c8,38,50,79,95,e4,bd,88,3b,b0,18,ed,a7,3f,8d,37,a4,c9,f3,53,5f,41,c6,e2,\
17,e6,f2,c3,13

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*NULL*]
@Security="Inherited"
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,3c,03,f2,e3,bc,\
ba,33,80,97,20,4e,9a,c7,f1,35,ee,24,05,12,4e,c4,4d,35,d9,fb,a7,78,e6,12,2f,\
9a,ea,86,a5,45,ef,32,01,63,b0,fb,a7,78,e6,12,2f,9a,ea,c7,9b,8b,30,aa,de,2a,\
ba,7a,ce,db,4e

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*NULL*]
@Security="Inherited"
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,ae,9e,e9,12,39,\
c9,63,3c,aa,52,c6,00,84,3c,26,64,3b,86,9a,f7,dd,ff,19,ed,01,3a,48,fc,e8,04,\
4a,f1,03,cb,4e,ec,54,50,84,c6,83,6c,56,8b,a0,85,96,ab,da,ba,ff,80,4b,3a,fe,\
1d,b0,25,d3,13

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*NULL*]
@Security="Inherited"
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:b2,46,9a,e2,1b,fe,1b,94,d2,83,26,02,15,\
67,43,e9,b2,46,9a,e2,1b,fe,1b,94,84,78,89,f7,47,fe,db,cd,f6,0f,4e,58,98,5b,\
89,c9,91,11,21,13,5a,22,8f,33,f6,0f,4e,58,98,5b,89,c9,8f,1a,6e,eb,1b,11,28,\
2d,b6,d8,3a,af

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*NULL*]
@Security="Inherited"
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,5e,f1,ef,30,53,\
19,48,97,37,a4,aa,c3,a6,15,56,0a,a1,72,75,63,61,da,e1,a1,3d,ce,ea,26,2d,45,\
aa,78,b4,f1,10,a8,d2,f1,24,66,3d,ce,ea,26,2d,45,aa,78,26,57,6d,ec,8c,d7,a0,\
ae,55,86,df,10

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*NULL*]
@Security="Inherited"
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:f8,31,0f,a9,5f,a0,ec,fb,9f,7a,23,75,15,\
82,80,61,f8,31,0f,a9,5f,a0,ec,fb,47,87,a5,dd,7b,82,9b,ad,2a,b7,cc,b5,b9,7f,\
41,e7,11,bf,c7,00,c2,29,34,59,e3,0e,66,d5,eb,bc,2f,6b,62,d7,7c,28,52,9d,0e,\
7c,07,6e,f2,a9

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*NULL*]
@Security="Inherited"
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,34,e4,f8,84,44,\
d1,71,bd,05,73,21,dd,54,d8,4a,c5,3d,72,b8,e4,bd,3c,c1,f1,6c,43,2d,1e,aa,22,\
2f,9c,71,74,5a,d6,3e,81,23,59,fa,ea,66,7f,d4,3b,6b,70,6d,e0,5b,7a,23,2d,e7,\
6d,19,5f,05,0c

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL*  r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Owner=S-1-5-21-436374069-2025429265-839522115-1003
"*"=dword:00000004

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL* r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Owner=S-1-5-21-436374069-2025429265-839522115-1003
"*"=dword:00000004

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL*  r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\h*NULL*a*NULL*u*NULL*s*NULL*a*NULL*u*NULL*f*NULL*g*NULL*a*NULL*b*NULL*e*NULL*n*NULL* r*NULL*e*NULL*f*NULL*e*NULL*r*NULL*a*NULL*t*NULL*e*NULL*.*NULL*d*NULL*e*NULL*]
@Security="Inherited"
"*"=dword:00000004

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\*NULL*ο |*NULL*]
@Owner=S-1-5-21-436374069-2025429265-839522115-1003
"DisplayName"="?\11"
"DeviceDesc"="?\11"
"ProviderName"="?\11???\11\08"
"MFG"="??\09"
"ReinstallString"="8.552.0.0000"
"DeviceInstanceIds"=multi:"c:\\ati\\support\\8-11_xp32_dd_ccc_wdm_enu_70226\\driver\\xp_inf\\cx_70226.inf\00"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\*NULL*u |*NULL*]
@Owner=S-1-5-21-436374069-2025429265-839522115-1003
"DisplayName"="?\11"
"DeviceDesc"="?\11"
"ProviderName"="?\11???\11\08"
"MFG"="??\09"
"ReinstallString"="8.552.0.0000"
"DeviceInstanceIds"=multi:"c:\\ati\\support\\8-11_xp32_dd_ccc_wdm_enu_70226\\driver\\xp_inf\\cx_70226.inf\00"

[HKEY_LOCAL_MACHINE\software\ODBC\ODBCINST.INI\C*NULL*o*NULL*n*NULL*v*NULL*e*NULL*r*NULL*s*NULL*o*NULL*r*NULL* *NULL*d*NULL*e*NULL* *NULL*p*NULL*g*NULL*i*NULL*n*NULL*a*NULL* *NULL*d*NULL*e*NULL* *NULL*c*NULL*Γd*NULL*i*NULL*g*NULL*o*NULL* *NULL*M*NULL*S*NULL*]
@Security="Inherited"
"Translator"="c:\\WINDOWS\\system32\\MSCPXL32.dll"
"Setup"="c:\\WINDOWS\\system32\\MSCPXL32.dll"
"UsageCount"=dword:00000002

[HKEY_LOCAL_MACHINE\software\ODBC\ODBCINST.INI\M*NULL*S*NULL* *NULL*C*NULL*o*NULL*d*NULL*e*NULL* *NULL*P*NULL*a*NULL*g*NULL*e*NULL*-*NULL*b*NULL*e*NULL*r*NULL*s*NULL*e*NULL*t*NULL*z*NULL*e*NULL*r*NULL*]
@Security="Inherited"
"Translator"="c:\\WINDOWS\\system32\\MSCPXL32.dll"
"Setup"="c:\\WINDOWS\\system32\\MSCPXL32.dll"
"UsageCount"=dword:00000002
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(764)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(820)
c:\windows\system32\imon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ESET\nod32krn.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
.
**************************************************************************
.
Completion time: 2008-12-31 9:49:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-31 07:49:11

Pre-Run: 22.448.414.720 bytes free
Post-Run: 22,423,015,424 bytes free

829 --- E O F --- 2008-12-20 01:05:35

shelf life
2008-12-31, 23:56
hi thanostse,

you didnt install the ms recovery console. dont see anything in the combofix log.
You have Malwarebytes antimalware. Is it coming up clean after a scan? what about Spybot?

thanostse
2009-01-01, 13:47
Both Spybot and Malwarebytes' Anti-Malware show that my rig is clear.
Anyway i ran Microsoft Automatic Updates and the removing tool from Microsoft
and also told me that is clear.Thank you for your help.

shelf life
2009-01-01, 16:07
hi,

Well you must have taken care of the problem then. Keep malwarebytes and always check for updates before scanning.
You can remove combofix like this:
start>run and type in;
combofix /u
click ok or enter
Note:there is a space after the x and before the /

if all is good--some tips for you:

Reducing Your Risk To Malware:
The Short Version:

1) Keep your OS (http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us),(Windows) browser (IE, FireFox) and other Software (http://secunia.com/vulnerability_scanning/online/) up to date to "patch" vulnerabilities. Always install Service Packs.

2) Know what you are installing to your computer. Alot of software can come bundled with unwanted add-ons. You may be installing more than you think.

3) Install and keep them all updated: one antivirus and two or three anti-malware applications. If not updated they will soon be worthless.

4) Refrain from clicking on links or attachments you receive via E-Mail, IM, Chat Rooms or Social Sites, no matter how tempting or legitimate the message.

5) Don't click on ads/pop ups or offers from websites requesting that you need to install software to your computer.

6) Don't click on offers to "scan" your computer. Install ActiveX Objects with care. Do you trust the website?

7) Set up and use limited accounts for everyday use, rather than administrator accounts. Limited accounts can help prevent malware from installing.

8) Install a third party software firewall.

9) Consider using an alternate browser and E-mail client. Internet Explorer and OutLook Express are popular targets for malicious code because they are widely used. See also: Hardening or Securing Internet Explorer. (http://www.microsoft.com/downloads/details.aspx?FamilyID=6AA4C1DA-6021-468E-A8CF-AF4AFE4C84B2&displaylang=en)

10) If your habits include: warez, cracks etc or installing files via p2p networks then you are much more likely to encounter malicious code. Do you trust the source? Do you really need another potential malware source?

A longer version in link below

Happy Safe Surfing.