Apua! Kone sammuilee itsekseen, örkkejä!

Discussion in 'Virukset ja haittaohjelmat - HijackThis -logit' started by Mikko76, Nov 26, 2007.

  1. Mikko76

    Mikko76 Member

    Joined:
    Jul 3, 2006
    Messages:
    39
    Likes Received:
    0
    Trophy Points:
    16
    Jos joku vois jeesata, ollu nyt sen pari viikkoa seuraavaa kun ei apua löytynyt aiemmin! Aiemmat viestit:



    Konees tuntus olevan jotain ylimääräsiä juttuja.



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:42:34 AM, on 11/14/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\Program Files\F-Secure\Common\FSMB32.EXE
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\F-Secure\Common\FCH32.EXE
    C:\Program Files\F-Secure\Common\FAMEH32.EXE
    C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\Program Files\F-Secure\Common\FNRB32.EXE
    C:\Program Files\F-Secure\Common\FIH32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\smtsvc.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = lnet.lut.fi
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = lnet.lut.fi:80
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Mario Forever Toolbar Helper - {8036D4D7-AAD3-4793-AB49-329E437155A8} - C:\Program Files\Mario Forever Toolbar\v2.0.0.4\Mario_Forever_Toolbar.dll
    O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
    O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
    O3 - Toolbar: Mario Forever Toolbar - {463DF6D5-BEC1-4d67-B217-59DB692DFC53} - C:\Program Files\Mario Forever Toolbar\v2.0.0.4\Mario_Forever_Toolbar.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL
    O4 - HKLM\..\Run: [System Terminal Storage] smtsvc.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: &Lataa FlashGetillä
    - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: &Lataa kaikki FlashGetillä
    - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
    O9 - Extra button: ICQ 4 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
    O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.medion.com/
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Monopoly%20Here%20and%20Now/Images/stg_drm.ocx
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {53B8B406-42E4-4DD3-96E7-9DEC8CEB3DD8} (ICQVideoControl Class) - http://xtraz.icq.com/xtraz/activex/ICQVideoControl.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Mes...nt.cab31267.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Mes...nt.cab56907.cab
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Monopoly%20Here%20and%20Now/Images/armhelper.ocx
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3AC96CDF-025C-4E73-B131-95792FE8E411}: Domain = lnet.lut.fi
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = lnet.lut.fi,cc.lut.fi,lut.fi
    O17 - HKLM\System\CS1\Services\Tcpip\..\{3AC96CDF-025C-4E73-B131-95792FE8E411}: Domain = lnet.lut.fi
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = lnet.lut.fi,cc.lut.fi,lut.fi
    O17 - HKLM\System\CS2\Services\Tcpip\..\{3AC96CDF-025C-4E73-B131-95792FE8E411}: Domain = lnet.lut.fi
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = lnet.lut.fi,cc.lut.fi,lut.fi
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: F-Secure Automatic Update (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
    O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE

    --
    End of file - 11490 bytes
    [ + lainaa]
    Mikko76
    Newbie
    _ 15. marraskuuta 2007 @ 17:38 _ Linkki tähän viestiin Muokkaa viestiä
    Joo eli, kone jumittaa välillä jonku verran, ku käynnistää uudestaan ni system32-kansiossa olevat prosessit services.exe (ei enää, ku estin pysyvästi) ja toi smtsvc.exe yrittää päästä nettiin! Tota en pysty poistaan, ku en löydä sitä sieltä vaik laitoin piilotiedostotki näkyviin! Ja lisäks sellanen kiva juttu, että AVG:n ja Escanin skannaukset ei onnistu, edellisen kohalla kone käynnistyy uudestaan! F-securen skannaus ei löytäny mitään. Et jos joku vois jotain vinkkiä heittää?!
     
  2. Etzo

    Etzo Regular member

    Joined:
    Feb 8, 2007
    Messages:
    489
    Likes Received:
    0
    Trophy Points:
    26
    Öö...services.exe on laillinen Windowsin tiedosto.

    Mutta tuo toinen on örkki. Lataa SDFix by AndyManchesta ja tallenna se työpöydällesi.

    Käynnistä koneesi vikasietotilaan ja valitse tavallinen käyttäjätilisi:[[*]Käynnistä tietokone
    [*]Kun kuulet koneen piippaavan, paina F8, kuitenkin ennen Windowsin logon esiintuloa
    [*]Seuraavaksi pitäisi ilmestyä valikko
    [*]Valitse valikosta vikasietotila.

    [*] Kun vikasietotilassa, pura tiedoston SDFix.zip sisältö (SDFix.exe) työpöydälle. Tuplakilikkaa työpöydälle ilmestynyttä sdfix.exe tiedostoa. Tiedosto purkaantuu ja asentaa itsensä siihen levyasemaan, minne on käyttöjärjestelmä on asennettu ja juureen ilmestyy kansio SDFix, ESIM C:\SDFix
    [*] Avaa SDFix-kansio ja tuplaklikkaa tiedostoa RunThis.bat käynnistääksesi ohjelman.
    [*] Paina Y käynnistääksesi skriptin.
    [*] Työkalu puhdistaa troijalaisen palvelut ja tekee myös joitakin korjauksia rekisteriin. Lopuksi se pyytää käynnistämään koneen uudelleen, "Press any key to Reboot".
    [*] Paina mitä tahansa näppäintä ja kone käynnistyy uudelleen.
    [*] Käynnistyminen kestää normaalia kauemmin sillä SDFix puhdistaa konetta.
    [*] Kun kone on käynnistynyt ja työpöytä latautunut, SDFix kertoo että puhdistus on suoritettu, "Finished".
    [*] Paina sitten mitä tahansa näppäintä sulkeaksesi skriptin ja ladataksesi pikakuvakkeet työpöydälle.
    [*] Lopuksi avaa SDFix kansio ja kopioi & liitä tiedoston Report.txt sisältö viestiketjuusi uuden HijackThis lokin kera.
     
  3. Mikko76

    Mikko76 Member

    Joined:
    Jul 3, 2006
    Messages:
    39
    Likes Received:
    0
    Trophy Points:
    16
    Joo, siitä services.exe en ollukaan ihan varma, estin varmuuden vuoks.
    Tehty toimenpiteet ja tässä logit:


    SDFix: Version 1.115

    Run by Mikko Lehtinen on 11/26/2007 at 11:38 AM

    Microsoft Windows XP [versio 5.1.2600]

    Running From: C:\SDFix

    Safe Mode:
    Checking Services:


    Restoring Windows Registry Values
    Restoring Windows Default Hosts File

    Rebooting...


    Normal Mode:
    Checking Files:

    No Trojan Files Found





    Removing Temp Files...

    ADS Check:

    C:\WINDOWS
    No streams found.

    C:\WINDOWS\system32
    No streams found.

    C:\WINDOWS\system32\svchost.exe
    No streams found.

    C:\WINDOWS\system32\ntoskrnl.exe
    No streams found.



    Final Check:

    catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-11-26 11:54:52
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden services & system hive ...

    scanning hidden registry entries ...

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\\x00ffc\xd3w\2]
    "b049C053C7D38EE4AB9A00CB3B5D2472"="C?\Program Files\Common Files\Microsoft Shared\Web Folders\PUBPLACE.HTT"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache\WU]
    "FlushCacheFiles"=str(7):"\x6264\2\x24b8\xffg\0\xff88\xffff\x6b6e \x9da2\xcb37\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xfd0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x7972\x535f&\0\x317b\x3335\x3032\x3036\x2d37\x3031\x3130\x312d\x3338\x2d31\x3031\x3030\x312d\x3831\x3935\x3939\x3735\x3231\x7d33\x6e61\xff88\xffff\x6b6e \x9da2\xcb37\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x1158\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\4\0&\0\x457b\x3642\x3332\x3737\x2d36\x3934\x4132\x342d\x4332\x2d41\x3539\x3137\x332d\x4141\x3933\x3546\x3538\x3033\x7d42\0\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\n\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6d73\x435f\x7461\xfff8\xffff\x2318\xff\xfff8\xffff\x2d38\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1B\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s3+\xff88\xffff\x6b6e \x3b48\xcb35\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xf0a8\xfe\xf020Z\xffff\xffff\0\0\0\0&\0\4\0(\0&\0\x357b\x4338\x3046\x3443\x2d38\x4633\x3542\x362d\x3237\x2d30\x3546\x3745\x322d\x4441\x3636\x4637\x3739\x3630\x7d43\v\xfff8\xffff\x2e70\xff\xfff8\xffff\x2ea0\xff\xfff8\xffff\x1268\xff\xfff8\xffff\x1310\xff\xffe0\xffff\x6b76\6\16\0\xf7f8\xfe\1\0\1\2\x6572\x6f62\x746f\xff\xff88\xffff\x6b6e \xd8ee\xcb32\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x1a18\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x4449\xfe&\0\x307b\x3945\x3235\x4446\x2d46\x3032\x4145\x312d\x3144\x2d30\x4433\x3332\x312d\x3246\x3038\x4546\x4246\x3845\x7d39\xff\xfff0\xffff\x6020\x101\xe020\x101\x2b6e\xff\xfff8\xffff\xd48\xff\xfff8\xffff\x780\xff\xff88\xffff\x6b6e \xfffc\xcb39\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2d18\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0b/&\0\x307b\x3138\x4139\x3644\x2d31\x4545\x3535\x322d\x3633\x2d38\x3145\x4237\x362d\x4639\x3534\x3432\x3742\x3042\x7d37\x6d69\xff88\xffff\x6b6e \xfffc\xcb39\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2d20\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0ng&\0\x317b\x3830\x3042\x3836\x2d30\x4338\x4444\x322d\x4239\x2d43\x3337\x4235\x352d\x4346\x3536\x3334\x4132\x4332\x7d37p\xff88\xffff\x6b6e \xfffc\xcb39\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2d28\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\0\0&\0\x317b\x3830\x3345\x3930\x2d41\x3242\x4335\x302d\x4334\x2d41\x3032\x3932\x362d\x3132\x3030\x3932\x3238\x3738\x7d42\0\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x4146\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x4373\x4146\x3631\xff88\xffff\x6b6e \x6256\xcb3c\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2d30\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\0/&\0\x317b\x3934\x3836\x3046\x2d41\x3341\x3233\x332d\x3644\x2d38\x4438\x3946\x342d\x3833\x3432\x3131\x4130\x3139\x7d432\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\f\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6d73\x4d5f\x6961\xff88\xffff\x6b6e \x6256\xcb3c\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2ed0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0nd&\0\x317b\x3837\x3338\x3437\x2d33\x3536\x3736\x332d\x4636\x2d41\x3833\x3831\x352d\x3732\x3134\x3441\x4630\x3139\x7d34\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x6e65\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761soc\xff88\xffff\x6b6e \x6256\xcb3c\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2ed8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0Ty&\0\x317b\x3042\x3333\x3243\x2d31\x3331\x4645\x372d\x3043\x2d44\x3536\x3137\x302d\x3342\x3038\x4139\x4336\x4633\x7d42\0\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x7865\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\1\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x5373\x6174\x7574\xfff8\xffff\x2868\xff\xffe0\xfffftext/plain\0\xff\x6f78\xff\xff88\xffff\x6b6e \x6256\xcb3c\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2898\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x7472\x6946&\0\x317b\x4245\x3544\x3939\x2d37\x4344\x3245\x302d\x3535\x2d45\x3939\x4539\x352d\x3836\x3246\x3243\x4238\x4435\x7d30\x6961\xff88\xffff\x6b6e \x6256\xcb3c\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2ee0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\4\0&\0\x327b\x4130\x3035\x3641\x2d30\x4142\x3335\x352d\x4637\x2d30\x3833\x4641\x362d\x3843\x3646\x3743\x3745\x3741\x7d364\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\17\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6d73\x545f\x6d69\xff88\xffff\x6b6e \x6256\xcb3c\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2ee8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0003b&\0\x327b\x3134\x3335\x4231\x2d43\x3139\x3933\x322d\x3436\x2d35\x3832\x3131\x362d\x4532\x3632\x4632\x4142\x3735\x7d370\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xf5\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6d73\x2933\xff\xff88\xffff\x6b6e \x6256\xcb3c\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xf3b0\xfe\xf020Z\xffff\xffff\0\0\0\0&\0\4\0M=&\0\x327b\x3041\x4431\x3332\x2d33\x3630\x3544\x342d\x3838\x2d33\x4145\x3335\x342d\x3731\x3543\x3244\x3338\x3430\x7d46\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x6d61\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sen\xff88\xffff\x6b6e \x6256\xcb3c\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2bd8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\xf6y&\0\x327b\x3041\x4244\x3230\x2d37\x3230\x3144\x322d\x3344\x2d36\x3836\x3038\x302d\x4136\x3335\x4434\x4442\x3436\x7d45_\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\21\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6d73\x515f\x6575\xfff8\xffff\x2ba8\xff\xfff8\xffff\xf888\xfe\xfff0\xffff3be85\0\xff88\xffff\x6b6e \xfffc\xcb39\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2348\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\xf3b0\xfe&\0\x467b\x4544\x4236\x3539\x2d36\x3842\x4130\x342d\x3735\x2d38\x4139\x3031\x342d\x3243\x3634\x3930\x3134\x4632\x7d31\xff\xff88\xffff\x6b6e \xfffc\xcb39\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xfd8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0mp&\0\x317b\x3841\x3333\x3330\x2d41\x3643\x3435\x372d\x4643\x2d42\x3743\x4135\x312d\x3431\x3745\x3838\x4146\x3030\x7d42\x6f6c\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x7272\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\f\xfff8\xffff\x1340\xff\xfff8\xffff\x1370\xff\xfff8\xffff\x2640\xff\xfff8\xffff\x26e8\xff\xffe8\xffff\x6b76\0H\0\x460\xff\1\0\0\x97e\xff88\xffff\x6b6e \xfffc\xcb39\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\xfe0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0 t&\0\x347b\x3346\x3941\x3136\x2d30\x3141\x3543\x332d\x3638\x2d37\x4243\x3233\x312d\x4435\x3233\x4543\x3030\x4339\x7d39k\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1c\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sck\xff88\xffff\x6b6e \xfffc\xcb39\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2400\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0(\0&\0\x357b\x3930\x4236\x3145\x2d30\x3431\x3237\x342d\x3046\x2d30\x4141\x3845\x332d\x3734\x3138\x4233\x4331\x3632\x7d37\21\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x6575\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\22\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x6e61\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\r\xfff8\xffff\x2790\xff\xfff8\xffff\x2838\xff\xfff8\xffff\x29b0\xff\xfff8\xffff\x2a58\xff\xffe8\xffff\x6b76\0N\0\x958\xff\1\0\0\x100\b\0\x768\xff\xffe8\xffff\x6b76\0N\0\xff40\xfe\1\0\0\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xc3\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x2398\xff\xff88\xffff\x6b6e \x3b48\xcb35\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x2fd0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\08\0&\0\x357b\x4646\x3235\x3842\x2d41\x3232\x4539\x332d\x3935\x2d39\x3231\x4342\x352d\x4631\x3038\x4539\x3239\x4442\x7d45\x7265\xfff8\xffff\xf1c8\xfe\xffe0\xffff\xcc70\x100\xcca0\x100\xccd0\x100\xccf8\x100\xcd28\x100\xcd50\x100\x646e\x7865\xfff8\xffff\x13b0\xff\x6268\x6e69\x3000\xff\x3000\0\0\0\0\0\0\0\0\0\0\0\xff88\xffff\x6b6e \xb072\xcb4a\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5aa0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0fi&\0\x347b\x4339\x4232\x4139\x2d34\x3730\x3144\x312d\x3645\x2d46\x4235\x3036\x342d\x3934\x3736\x3536\x3134\x3335\x7d306\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1.\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s.a\xff88\xffff\x6b6e \xb072\xcb4a\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5aa8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0CD&\0\x357b\x3130\x3741\x3741\x2d42\x3433\x3142\x322d\x3043\x2d37\x4532\x3137\x362d\x4332\x3334\x3434\x4333\x3743\x7d39n\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1i\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sLa\xff88\xffff\x6b6e \xb072\xcb4a\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6648\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0CD&\0\x357b\x3830\x4144\x3541\x2d37\x3646\x4235\x342d\x3737\x2d38\x4434\x3941\x302d\x3944\x3535\x3737\x4331\x4330\x7d355\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\21\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6d73\x515f\x6575\xff88\xffff\x6b6e \x12cc\xcb4d\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6650\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\4\x8000&\0\x357b\x4133\x3345\x3432\x2d30\x3136\x3343\x312d\x3844\x2d32\x3431\x4246\x372d\x3443\x3643\x3036\x4239\x3935\x7d33\0\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x656d\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\1E\xff88\xffff\x6b6e \x12cc\xcb4d\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6658\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\4\x8000&\0\x357b\x3038\x3541\x4545\x2d45\x3844\x3032\x312d\x4135\x2d45\x3833\x4532\x342d\x3036\x3742\x3731\x4643\x3244\x7d46\xffff\xfff8\xffff\x43b8\xff\xfff8\xffff\x53c8\xff\xfff8\xffff\x5470\xff\xfff8\xffff\x5518\xff\xfff8\xffff\x4558\xff\xff88\xffff\x6b6e \xebbe\xcb45\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x34f0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0ak&\0\x327b\x4237\x3136\x4445\x2d43\x4431\x4642\x352d\x4244\x2d31\x3646\x4241\x302d\x3634\x3034\x4637\x3631\x3344\x7d37b\xff88\xffff\x6b6e \xebbe\xcb45\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x34f8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x4446\x5f4d&\0\x327b\x3841\x4642\x4243\x2d34\x3441\x3936\x372d\x4138\x2d36\x3846\x3231\x372d\x4534\x3237\x3842\x4344\x4334\x7d30u\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\0011\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\16\xfff8\xffff\x3fa0\xff\xfff8\xffff\x4150\xff\xfff8\xffff\x4ef8\xff\xfff8\xffff\x5778\xff\xffe8\xffff8,0,24,0\0\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1.\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6573DO\xfff8\xffff\x5b30\xff\xfff8\xffff\x6618\xff\xfff8\xffff\x3450\xff\xfff8\xffff\x3ec8\xff\xfff8\xffff\x3f70\xff\xffe0\xffff4.70.0.1155\0\x3478\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\0016\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\16\xff88\xffff\x6b6e \x8964\xcb43\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3608\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0(\0&\0\x357b\x3933\x4144\x4530\x2d30\x3437\x3741\x312d\x4431\x2d39\x3639\x3936\x302d\x3038\x3230\x3030\x3943\x3641\x7d36\20\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x726f\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x3728\xff\xfff8\xffff\x35d8\xff\xfff8\xffff\x36a0\xff\xfff8\xffff\x36d0\xff\xfff8\xffff\x6458\xff\xff88\xffff\x6b6e \x8964\xcb43\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3610\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\1\0&\0\x437b\x3145\x3538\x3732\x2d30\x3335\x3541\x312d\x4431\x2d39\x3639\x3936\x302d\x3038\x3230\x3030\x3943\x3641\x7d36\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sli\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\24\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x5f73\x6f54\x6174\xfff8\xffff\x45f8\xff\xfff8\xffff\x4628\xff\xffe8\xffff\x6b76\0$\0\xc870\x100\1\0\0\xff\xff88\xffff\x6b6e \x39da\xcb54\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6940\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0fi&\0\x467b\x4646\x3046\x3030\x2d33\x3030\x3130\x312d\x3130\x2d41\x3341\x3030\x302d\x3030\x3030\x3030\x3030\x3030\x7d306\xff88\xffff\x6b6e \x39da\xcb54\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6948\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\00074&\0\x467b\x4344\x3143\x3135\x2d38\x4136\x3336\x312d\x4431\x2d39\x4141\x3843\x392d\x4531\x3543\x3445\x3739\x3137\x7d36_\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1i\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sri\xff88\xffff\x6b6e \x39da\xcb54\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6950\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0/f&\0\x457b\x3244\x3445\x4242\x2d35\x3036\x4145\x342d\x3236\x2d34\x4439\x3245\x392d\x3839\x3445\x3134\x3643\x3939\x7d42.\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1a\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s64\xff88\xffff\x6b6e \x39da\xcb54\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6958\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0000\0&\0\x467b\x4646\x4646\x4646\x2d46\x4333\x3831\x342d\x3741\x2d45\x3241\x4439\x452d\x3432\x3846\x4234\x3937\x4642\x7d31\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\23\xff88\xffff\x6b6e \x9c34\xcb56\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5388\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x696f\x746e&\0\x397b\x3730\x4136\x3131\x2d46\x4535\x3641\x342d\x3641\x2d37\x4442\x3945\x382d\x3344\x3743\x3443\x3335\x4144\x7d43\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\23\xff88\xffff\x6b6e \x9c34\xcb56\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5390\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0P\&\0\x397b\x3043\x3032\x3836\x2d39\x4146\x4437\x342d\x3844\x2d44\x4542\x4537\x442d\x3243\x3336\x3937\x4331\x3242\x7d39\31\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x6f6c\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x3478\xff\xff88\xffff\x6b6e \x9c34\xcb56\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5398\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x526c\x7465&\0\x417b\x3446\x4333\x3639\x2d41\x3132\x4436\x372d\x3744\x2d41\x4641\x3136\x302d\x3130\x4338\x3036\x3136\x4444\x7d30\x676e\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x7273\x754e\x626d\xff88\xffff\x6b6e \x9c34\xcb56\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x53a0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x3228\xff&\0\x337b\x3530\x4630\x4434\x2d38\x4436\x3236\x312d\x4331\x2d45\x4641\x3136\x452d\x3331\x3033\x3439\x3630\x3933\x7d32\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x3990\xff\xff88\xffff\x6b6e \x9c34\xcb56\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x53a8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0H\0&\0\x457b\x3543\x3631\x3935\x2d44\x3237\x4631\x342d\x4243\x2d46\x4339\x4145\x352d\x3745\x3637\x3844\x4339\x4145\x7d39L\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\1\xff\xff88\xffff\x6b6e \x9c34\xcb56\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6fd8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0000\0&\0\x307b\x3746\x3743\x4330\x2d46\x3039\x3633\x332d\x4242\x2d38\x3135\x3345\x312d\x4345\x3736\x3136\x3033\x3339\x7d33\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\v\xff88\xffff\x6b6e \x9c34\xcb56\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3e30\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x6e6f\x754e&\0\x317b\x3639\x4642\x3038\x2d43\x3744\x3341\x352d\x3941\x2d30\x4546\x3234\x322d\x4239\x3535\x3744\x3446\x3631\x7d37\x6f6c\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x7273\x754e\x626d\xfff8\xffff\x3e00\xff\xffe8\xffff\x6b76\0N\0\x8158\xff\1\0\0\xa70f\xff88\xffff\x6b6e \xebbe\xcb45\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3500\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x746e\x6946&\0\x367b\x3541\x4246\x4232\x2d30\x3139\x4334\x302d\x3939\x2d45\x3735\x3143\x362d\x3344\x3737\x3543\x3436\x3932\x7d32A\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\0011\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\r\xff88\xffff\x6b6e \xebbe\xcb45\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3508\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0(\0&\0\x367b\x4339\x4535\x3436\x2d30\x4642\x4637\x352d\x4336\x2d35\x4431\x3231\x342d\x3236\x3641\x3841\x3946\x3237\x7d44\20\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x6f6c\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x8073\4\0\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x626d\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x8073\xb3fb\x2d5\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\1\xff\xfff8\xffff\x3fd0\xff\xfff8\xffff\x4120\xff\xffe0\xffff\x6b76\b\x8a\0\x4790\xff\1\0\1\xff\x4f43\x4544\x4142\x4553\xff88\xffff\x6b6e \xebbe\xcb45\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3480\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0001\&\0\x397b\x4332\x4636\x3635\x2d30\x4638\x4436\x312d\x4431\x2d39\x3639\x3936\x302d\x3038\x3230\x3030\x3943\x3641\x7d36\xff\xff88\xffff\x6b6e \xebbe\xcb45\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x4000\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\4\0&\0\x437b\x4233\x4232\x4632\x2d30\x3436\x3630\x312d\x4431\x2d39\x3639\x3936\x302d\x3038\x3230\x3030\x3943\x3641\x7d36\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sA~\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1L\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\0\xff\xffd8\xffffShockwave Flash\0\x5710\xff\xffd0\xffff\x6b76\24\xa8\0\x4480\xff\1\0\1\xff\x7551\x6569\x5574\x696e\x736e\x6174\x6c6c\x7453\x6972\x676e\x59e8\xff\xffd0\xffff\x6b76\21\30\0\x3510\xff\1\0\1\xff\x6552\x7571\x7269\x7365\x4549\x7953\x4673\x6c69\x5e65\xff\x5e40\xff\xffa8\xffff\x6b6e \xf10a\x8e3d\x33a7\x1c5\0\0\x2b88w\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3358\xff\xf020Z\xffff\xffff\0\0\0\0\22\0\4\0\x3f90\xff\a\0\x7753\x6c46\x7361h\xfff8\xffff\x53b0\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x7573\x626d\x7265\xff88\xffff\x6b6e \x12cc\xcb4d\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6660\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x5640\xff&\0\x357b\x3943\x4341\x3742\x2d32\x4230\x3245\x332d\x3535\x2d36\x3530\x4630\x362d\x4545\x3433\x3342\x4641\x4231\x7d44\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x3b10\xff\xff88\xffff\x6b6e \x12cc\xcb4d\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3338\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x3f40\xff&\0\x377b\x3030\x3943\x3730\x2d39\x4346\x3144\x322d\x4343\x2d37\x3538\x3646\x332d\x3735\x3241\x3742\x4538\x4246\x7d35S\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xc3\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\xc420\x102\xff88\xffff\x6b6e \x12cc\xcb4d\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3340\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0P\0&\0\x377b\x3237\x4336\x3533\x2d46\x3445\x4439\x362d\x3530\x2d46\x3932\x3130\x322d\x4531\x3341\x3730\x4233\x3731\x7d34\v\xfff8\xffff\x55c0\xff\xfff8\xffff\x6670\xff\xfff8\xffff\x6718\xff\xfff8\xffff\x67c0\xff\xff50\xffffRunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\swflash.inf,DefaultUninstall,5\0ut\xffd8\xffff\x686c\4\x2bf0w\xfead\xa758\x2c78w\x2d94\x4fe8\xdad0\x12b\x4ac1\x98a\x4208\xff\xf6f0\x4c4\xffd8\xffff\x6b76\t\4\x80001\0\1\0\0013\x6e49\x7473\x6c61\x656cd1D-\xff88\xffff\x6b6e \x8964\xcb43\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3618\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0ak&\0\x357b\x3530\x3930\x4638\x2d44\x4435\x3136\x342d\x4342\x2d32\x4239\x3238\x462d\x3639\x4439\x4530\x3339\x4132\x7d32s\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1m\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sla\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1e\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761ser\xfff8\xffff\x5930\xff\xff88\xffff\x6b6e \x4c78\x9081\x33a7\x1c5\0\0\x7a40d\3\0\0\0\x49a8\xff\xffff\xffff\2\0\x2790\xa7\xf020Z\xffff\xffff&\0\0\0\36\0\f\0005F&\0\x447b\x3732\x4443\x3642\x2d45\x4541\x4436\x312d\x4331\x2d46\x3639\x3842\x342d\x3434\x3535\x3533\x3034\x3030\x7d30-\xffd8\xffff\x6b76\17\4\x8000\0\0\4\0\1B\x7953\x7473\x6d65\x6f43\x706d\x6e6f\x6e65t\xffd8\xffff\x6b76\t\f\0\x51b8\xff\1\0\1f\x6e49\x7473\x6c61\x656crDis\xff98\xffff\x6b6e \xb102\xab03\x4a0e\x1c6\0\0\x4660\xff\0\0\0\0\xffff\xffff\xffff\xffff\2\0\xcb68\xa9\xf020Z\xffff\xffff\0\0\0\0\20\0\x8c\00049\23\0\x6f44\x6e77\x6f6c\x6461\x6e49\x6f66\x6d72\x7461\x6f69n3F\xff70\xffffhttp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab\0\0\xff98\xffffC:\WINDOWS\Downloaded Program Files\swflash.inf\0ib\xffa0\xffff\x6b6e \xd810\xab0a\x4a0e\x1c6\0\0\x4660\xff\0\0\0\0\xffff\xffff\xffff\xffff\2\0\x1d10\xab\xf020Z\xffff\xffff\0\0\0\0\30\0<\0-8\20\0\x6e49\x7473\x6c61\x656c\x5664\x7265\x6973\x6e6f\xffd8\xffff\x6b76\f<\0\x4910\xff\1\0\1\0\x614c\x7473\x6f4d\x6964\x6966\x6465DO\xffc0\xffffTue, 10 Jan 2006 23:31:43 GMT\0\xffa8\xffff\x6b6e \x4c78\x9081\x33a7\x1c5\0\0\x4660\xff\0\0\0\0\xffff\xffff\xffff\xffff\0\0\xffff\xffff\xf020Z\xffff\xffff\0\0\0\0\0\0\0\00008\b\0\x6f43\x746e\x6961\x736e\xffd8\xffff\x686c\3\x4950\xff\x437f\x64e6\x4728\xff\x17a\xe584\x4888\xff\x5736\x6a1ctwar\xff88\xffff\x6b6e \x9c34\xcb56\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6fe0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\00072&\0\x337b\x3030\x3445\x3430\x2d37\x4534\x3934\x322d\x4431\x2d30\x3637\x3444\x352d\x3937\x3032\x3232\x3441\x3846\x7d343\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1W\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\v\xff88\xffff\x6b6e \x9c34\xcb56\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6fe8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x656dD&\0\x337b\x3845\x3242\x3242\x2d32\x3337\x4143\x332d\x3142\x2d37\x3532\x3539\x352d\x3841\x3533\x3041\x3945\x4433\x7d32w\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x4c73of\xff88\xffff\x6b6e \x8688\xcb81\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6ff0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0ra&\0\x377b\x3630\x4139\x3337\x2d43\x3631\x4545\x332d\x4238\x2d44\x3631\x3146\x342d\x3537\x3645\x3333\x3138\x3745\x7d34_\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\1S\xff88\xffff\x6b6e \x8688\xcb81\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6ff8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0ng&\0\x377b\x3438\x3538\x3042\x2d41\x3236\x4544\x362d\x3031\x2d45\x4132\x3239\x352d\x3837\x3536\x3438\x4342\x4242\x7d35p\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1e\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761swm\xff88\xffff\x6b6e \x8688\xcb81\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x4d18\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x7449\x6d65&\0\x377b\x4338\x3241\x4234\x2d45\x3446\x3434\x372d\x3630\x2d41\x3832\x3332\x332d\x3330\x3442\x4233\x4539\x3735\x7d33E\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1.\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\1\xff\xfff8\xffff\x4ce8\xff\xff88\xffff\x6b6e \x8688\xcb81\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x4dc8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x7449\x6d65&\0\x307b\x3541\x4631\x3844\x2d44\x3836\x3533\x342d\x3132\x2d32\x3742\x3639\x412d\x4346\x3432\x3446\x3144\x3830\x7d41\x7074\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\n\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6d73\x435f\x7461\xfff8\xffff\x4d98\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x7a73\x4d65\xff\xfff8\xffff\x3e38\xff\xff88\xffff\x6b6e \x4e18\xcb48\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x4008\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0ak&\0\x347b\x3035\x4439\x4243\x2d44\x4238\x3030\x342d\x4233\x2d34\x3841\x3334\x342d\x4335\x4134\x4631\x4637\x3343\x7d44e\xff88\xffff\x6b6e \x4e18\xcb48\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3488\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0e5&\0\x307b\x4136\x3243\x3842\x2d30\x3131\x3637\x352d\x3731\x2d30\x3439\x3444\x332d\x3241\x3730\x4331\x4133\x3232\x7d34w\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6173\x6567\xff\xffe8\xffff\x6b76\0N\0\x93d0\xff\1\0\0\xff\xff88\xffff\x6b6e \x8964\xcb43\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x4fb8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x4446\x5f4d&\0\x357b\x4638\x3543\x3145\x2d37\x3231\x3034\x372d\x4145\x2d36\x4646\x3142\x342d\x3531\x3738\x4335\x3739\x3337\x7d39\x664f\xfff8\xffff\x34b8\xff\xffc0\xffffhttp://www.chesstechno.com\0\0\0\0\xffc0\xffffhttp://www.chesstechno.com\0\0\0\0\xffc8\xffffinquire@chesstechno.com\0\0\0\xffc0\xffff\x1ad0_\x1b58_\x1bd8_\x1c30_\xc2e8a\xc310a\xcd18a\xcd40a\x9590\xac\xfb38\xd9\x1af8_\x9758\xac\xfb90\xd9\xcd68a\0\0\xffa8\xffff\x6b6e \xa56e\x598b\x1e2f\x1c7\0\0\xbe58y\0\0\0\0\xffff\xffff\xffff\xffff\20\0\xc178\4\x1e0\0\xffff\xffff\0\0\0\0"\0r\0 2\b\0\x424b\x3239\x3435\x3638\xfff8\xffff\x6ad0\xff\xff88\xffff\x6b6e \x8964\xcb43\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3700\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0h\0&\0\x317b\x3331\x3131\x3131\x2d31\x3531\x3135\x312d\x3636\x2d31\x3731\x3137\x302d\x3030\x3030\x3030\x3030\x3030\x7d30\x6b20\xfff8\xffff\x6868\xff\xfff8\xffff\x6910\xff\xfff8\xffff\x6d78\xff\xfff8\xffff\x6e20\xff\xfff8\xffff\x6ec8\xff\xfff0\xffffMSICD\0\xffb8\xffffC:\WINDOWS\System32\msjava.dll\0\0\0\0\xffd8\xffff\x6b76\vT\0\x1440\x129\1\0\1\x6692\x6944\x7073\x616c\x4e79\x6d61\x3f65\xe37e\x271f\xffd8\xffff\x6b76\17r\0\x1498\x129\1\0\1\xe55d\x6e55\x6e69\x7473\x6c61\x536c\x7274\x6e69\x2c67\xfff0\xffff\x8200\x127\x8360\x127\0\0\xffa8\xffff\x6b6e \x4c56\x98fd\x9f6e\x1c6\0\0\x1698)\0\0\0\0\xffff\xffff\xffff\xffff\2\0\xa460\xfa\xf150Z\xffff\xffff\0\0\0\0\32\0\x228\0\xffff\xffff\b\0\x424b\x3139\x3433\x3634\xffd8\xffff\x6b76\r\x228\0\x1dd0\x120\3\0\1\x3543\x6c53\x776f\x6e49\x6f66\x6143\x6863\x6b65\0\xffe0\xffff\x6b76\a\4\x8000\0\0\4\0\1x\x6843\x6e61\x6567d\xffa8\xffff\x6b6e \x4ae8\x991c\x9f6e\x1c6\0\0\x1698)\0\0\0\0\xffff\xffff\xffff\xffff\2\0\xc4c0\xfa\xf150Z\xffff\xffff\0\0\0\0\32\0\x228\0\xffff\xffff\b\0\x424b\x3139\x3533\x3038\xffe0\xffff\x6b76\a\4\x8000\0\0\4\0\1\x6553\x6843\x6e61\x6567d\xfff8\xffff\x3a10\xff\xfff8\xffff\x3ab8\xff\xfff8\xffff\x3b60\xff\xfff8\xffff\x3c08\xff\xfff8\xffff\x3cb0\xff\xffe8\xffff\x6b76\0N\0\x7ff0\xff\1\0\0\x2c15\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\0\0\xff88\xffff\x6b6e \x12cc\xcb4d\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3348\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x102\0&\0\x377b\x3441\x3134\x4338\x2d35\x3530\x3037\x312d\x3134\x2d30\x3346\x3039\x312d\x3336\x3543\x3242\x4542\x3236\x7d44/\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1b\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sne\xff88\xffff\x6b6e \x12cc\xcb4d\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3350\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0ar&\0\x377b\x3446\x4237\x4332\x2d35\x4239\x4134\x312d\x3636\x2d35\x3536\x4236\x312d\x4246\x3231\x4643\x3839\x3045\x7d32n\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1n\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761ses\xff88\xffff\x6b6e \x12cc\xcb4d\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x4460\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x6d61e&\0\x317b\x3131\x3131\x3131\x2d31\x3131\x3131\x312d\x3131\x2d31\x3131\x3131\x312d\x3131\x3131\x3131\x3431\x3534\x7d37S\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1t\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sn\\xff88\xffff\x6b6e \x12cc\xcb4d\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x4468\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0pg&\0\x317b\x3131\x3131\x3131\x2d31\x3131\x3131\x312d\x3131\x2d31\x3131\x3131\x362d\x3131\x3131\x3131\x3339\x3534\x7d37\x7865\xffe0\xffff\x6b76\3`\0\x4820\xff\1\0\1\xff\x4e49F\x31f8\xff\xff88\xffff\x6b6e \x4e18\xcb48\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3490\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x7449\x6d65&\0\x307b\x3537\x3531\x3942\x2d41\x3831\x3141\x332d\x3036\x2d46\x4443\x3741\x352d\x4545\x3130\x3637\x3344\x4144\x7d35\xff\xff88\xffff\x6b6e \x4e18\xcb48\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3498\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\4\0&\0\x307b\x4342\x3837\x4331\x2d31\x4231\x3539\x342d\x3143\x2d38\x4545\x3730\x352d\x4639\x3541\x4641\x4430\x3444\x7d45\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\1\0\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\25\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x5f73\x7345\x6974\xfff8\xffff\x57a8\xff\xfff8\xffff\x58e0\xff\xfff8\xffff\x5ba0\xff\xff88\xffff\x6b6e \x4e18\xcb48\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x57d8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0ak&\0\x317b\x3134\x3338\x3035\x2d45\x3842\x3530\x372d\x3342\x2d34\x3132\x3430\x312d\x3435\x3738\x4646\x4538\x3031\x7d42b\xff88\xffff\x6b6e \x4e18\xcb48\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x57e0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x4446\x5f4d&\0\x317b\x4135\x3245\x4138\x2d32\x3035\x3738\x372d\x3742\x2d31\x3731\x4630\x332d\x3642\x3332\x3243\x3231\x3335\x7d46u\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\0011\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\16\xfff8\xffff\x59c0\xff\xfff8\xffff\x5a68\xff\xfff8\xffff\x69f0\xff\xfff8\xffff\x6a98\xff\xffe8\xffff\x6b76\0000\0\x96d8\xff\1\0\0\x1ead\xff88\xffff\x6b6e \x4e18\xcb48\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5910\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x4446\x5f4d&\0\x317b\x3141\x3231\x4331\x2d38\x3139\x4635\x312d\x3433\x2d35\x3437\x3032\x322d\x4638\x3633\x3632\x4538\x3137\x7d33\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\16\xff88\xffff\x6b6e \xb072\xcb4a\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5918\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0(\0&\0\x317b\x3642\x3537\x3437\x2d45\x3834\x3342\x342d\x4433\x2d44\x3836\x3841\x312d\x4136\x3734\x4233\x4441\x3637\x7d33\20\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x726f\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x5bb8\xff\xfff8\xffff\x6c08\xff\xfff8\xffff\x3098\xff\xfff8\xffff\x3140\xff\xfff8\xffff\x3710\xff\xff88\xffff\x6b6e \x8964\xcb43\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3708\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\1\0&\0\x387b\x4231\x4339\x3035\x2d36\x3634\x3344\x342d\x3636\x2d37\x3039\x3831\x332d\x3644\x3735\x4335\x4342\x3430\x7d36\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sli\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\24\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x5f73\x6f54\x6174\xfff8\xffff\x5b60\xff\xfff8\xffff\x65e8\xff\xffe8\xffff\x6b76\0N\0\xc950\x100\1\0\0\xa70f\xff88\xffff\x6b6e \xe8e2\xcb83\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5c30\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0fi&\0\x457b\x3234\x4137\x3735\x2d46\x4131\x3439\x302d\x4642\x2d43\x4436\x4137\x362d\x4344\x3132\x3934\x3634\x4441\x7d346\xfff8\xffff\x4dd0\xff\xff88\xffff\x6b6e \xe8e2\xcb83\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5ce0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0/H&\0\x427b\x3142\x3542\x3630\x2d34\x3431\x3639\x342d\x3445\x2d30\x3841\x4430\x452d\x4646\x4337\x4135\x3539\x4133\x7d36_\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1t\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sna\xfff8\xffff\x5cb0\xff\xff88\xffff\x6b6e \xe8e2\xcb83\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5d90\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\00031&\0\x357b\x3436\x4345\x3636\x2d45\x4135\x4231\x352d\x4431\x2d33\x4431\x3042\x352d\x3830\x4330\x3338\x4144\x4534\x7d42s\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1n\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761san\xfff8\xffff\x5d60\xff\xff88\xffff\x6b6e \xe8e2\xcb83\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5e40\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x7449\x6d65&\0\x357b\x3436\x4345\x3636\x2d45\x4135\x4231\x352d\x4431\x2d34\x4431\x3042\x352d\x3830\x4330\x3332\x4144\x4534\x7d42\x6174\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x7473\x3f31\xc3\xfff8\xffff\x5e10\xff\xff88\xffff\x6b6e \xac28\xcba7\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5ef0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x170\0&\0\x317b\x4443\x3934\x4344\x2d39\x4446\x3838\x342d\x4631\x2d41\x3842\x3239\x342d\x4537\x3330\x3237\x3736\x3444\x7d35\x1c5\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xffff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\0\0\xfff8\xffff\x5ec0\xff\xff88\xffff\x6b6e \xac28\xcba7\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5fa0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x7449\x6d65&\0\x367b\x3431\x3836\x3432\x2d35\x3341\x3334\x432d\x3246\x2d37\x3433\x3235\x342d\x4434\x3446\x3736\x4239\x4644\x7d31u\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\0011\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\f\xfff8\xffff\x5f70\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\1\0\xfff8\xffff\x5fa8\xff\xfff8\xffff\x6110\xff\xfff8\xffff\x61b8\xff\xfff8\xffff\x6260\xff\xfff8\xffff\x6308\xff\x6268\x6e69\x6000\xff\x1000\0\0\0\0\0\0\0\0\0\0\0\xff88\xffff\x6b6e \xac28\xcba7\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5fd8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0cd&\0\x377b\x4632\x3246\x4132\x2d31\x4238\x3146\x312d\x4431\x2d35\x4139\x4433\x302d\x3030\x3230\x3431\x3635\x3241\x7d37l\xff88\xffff\x6b6e \xac28\xcba7\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5fe0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x7570\x4674&\0\x457b\x3045\x4232\x3939\x2d42\x4431\x3535\x342d\x6238\x2d63\x3842\x4244\x362d\x3934\x3441\x4332\x3445\x4635\x7d36a\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sso\xff88\xffff\x6b6e \xe82\xcbaa\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5fe8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\4\0&\0\x347b\x3243\x3632\x3333\x2d36\x3034\x3233\x342d\x3938\x2d46\x3639\x3437\x362d\x4537\x3437\x3232\x3935\x3937\x7d42\0\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\1\0\xff88\xffff\x6b6e \x3422\xcbd0\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5ff0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\4\x8000&\0\x317b\x3131\x3131\x3131\x2d31\x3131\x3131\x312d\x3131\x2d31\x3131\x3131\x312d\x3731\x3130\x3833\x3330\x3437\x7d38\x4248\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1p\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\1\xff\xff88\xffff\x6b6e \x3422\xcbd0\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5ff8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\4\x8000&\0\x327b\x4635\x3144\x3931\x2d39\x4638\x3142\x332d\x4234\x2d46\x4637\x3943\x352d\x3434\x3741\x3332\x4443\x4643\x7d38\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1n\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sti\xff88\xffff\x6b6e \x967c\xcbd2\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x63e0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0.w&\0\x337b\x3634\x4139\x3245\x2d46\x3930\x3437\x332d\x3545\x2d39\x4237\x3030\x312d\x3230\x3346\x4630\x3933\x3833\x7d30\x726f\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\16\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x5f73\x7250\x6365\xfff8\xffff\x63b0\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\1\0\xfff8\xffff\x63e8\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\17\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x5f73\x6553\x6f63\xfff8\xffff\x6420\xff\xffe0\xffff\x6b76\5N\0\x7f98\xff\1\0\1\xff\x7041\x4970\x7544\xff\xff88\xffff\x6b6e \xebbe\xcb45\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x34e8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x7461\x6f69&\0\x307b\x3944\x3935\x4530\x2d38\x3444\x3945\x342d\x3238\x2d32\x3539\x4234\x372d\x3438\x4443\x4641\x3439\x3246\x7d44\xff\xff88\xffff\x6b6e \xebbe\xcb45\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5b90\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x5274\x7365&\0\x337b\x4136\x4645\x3032\x2d41\x4542\x3146\x312d\x3632\x2d32\x3944\x4241\x322d\x3741\x3138\x3842\x3142\x4646\x7d32\xff\xfff8\xffff\x6f28\xff\xff88\xffff\x6b6e \xebbe\xcb45\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5b98\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\1\0&\0\x357b\x3139\x3934\x3844\x2d36\x3039\x3635\x352d\x3230\x2d46\x4243\x4641\x372d\x3230\x3444\x3633\x4637\x3042\x7d38\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sdn\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1.\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x8073\1\0\xfff8\xffff\x31e8\xff\xfff8\xffff\x3290\xff\xfff8\xffff\x4268\xff\xfff8\xffff\x4310\xff\xfff8\xffff\x6fc0\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1t\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761ste\xff88\xffff\x6b6e \x7526\xcb4f\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x4470\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0x\0&\0\x317b\x3131\x3131\x3131\x2d31\x3131\x3131\x312d\x3131\x2d31\x3131\x3131\x362d\x3131\x3131\x3131\x3339\x3534\x7d38e\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1t\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sc/\xff88\xffff\x6b6e \x7526\xcb4f\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x4478\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0(\0&\0\x317b\x3131\x3131\x3131\x2d31\x3131\x3131\x312d\x3131\x2d31\x3131\x3431\x352d\x3131\x3531\x3535\x3339\x3634\x7d39\v\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x696f\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x8073\0\0\xff88\xffff\x6b6e \x7526\xcb4f\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5190\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0H\0&\0\x347b\x3333\x3133\x3131\x2d31\x3131\x3131\x312d\x3131\x2d31\x3131\x3131\x362d\x3131\x3131\x3131\x3539\x3236\x7d32L\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\1\xff\xff88\xffff\x6b6e \x7526\xcb4f\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5198\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x80\0&\0\x347b\x3235\x3133\x3131\x2d31\x3131\x3131\x312d\x3131\x2d31\x3131\x3131\x312d\x3131\x3131\x3131\x3331\x3534\x7d38\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\17\xfff8\xffff\x6ef8\xff\xfff8\xffff\x3818\xff\xfff8\xffff\x38c0\xff\xfff8\xffff\x3968\xff\b\0\x6ce8\xff\xfff0\xffff\x5de0\x128\x6e20\x128\x2df8\xff\xff88\xffff\x6b6e \xb072\xcb4a\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5920\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\1\0&\0\x327b\x3142\x3032\x4244\x2d35\x3536\x4230\x322d\x3233\x2d44\x3531\x4344\x352d\x3435\x3236\x3746\x3238\x4330\x7d43\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x62d0\xff\xff88\xffff\x6b6e \xb072\xcb4a\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5928\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x6880\xff&\0\x327b\x3446\x4531\x3734\x2d38\x3536\x3537\x322d\x3739\x2d43\x3239\x4341\x332d\x4531\x3042\x3243\x4346\x4344\x7d42\x726f\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\n\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6d73\x435f\x7461\xfff8\xffff\x6b60\xff\xffe8\xffff\x6b76\0\n\0\x8ae8~\1\0\0\xff\xff88\xffff\x6b6e \xb072\xcb4a\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6ac8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0ou&\0\x337b\x4533\x4642\x3646\x2d37\x4230\x4138\x372d\x4334\x2d39\x3035\x3043\x362d\x4538\x3537\x3142\x4243\x3042\x7d46t\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1h\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s0a\xff88\xffff\x6b6e \xb072\xcb4a\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x5a98\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0000a&\0\x337b\x3037\x3030\x4143\x2d42\x3030\x3736\x362d\x3137\x2d46\x4645\x4134\x362d\x3037\x3438\x3233\x4233\x3131\x7d362\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1k\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s20\xff88\xffff\x6b6e \xb072\xcb4a\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6ce0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0th&\0\x347b\x3434\x3636\x4333\x2d34\x3942\x4542\x312d\x3841\x2d30\x4632\x3341\x312d\x3333\x3736\x4437\x3332\x4138\x7d41 \xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1b\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s.m\xfff8\xffff\x6cb0\xff\xffe8\xffff\x6b76\0N\0\x80a0\xff\1\0\0\x7a69\xff88\xffff\x6b6e \x7526\xcb4f\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x51a0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0et&\0\x327b\x3232\x3232\x3232\x2d32\x3232\x3232\x322d\x3232\x2d32\x3434\x3434\x352d\x3636\x3636\x3831\x3838\x3538\x7d38\\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1t\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s t\xff88\xffff\x6b6e \x7526\xcb4f\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x51a8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0ic&\0\x437b\x4146\x3043\x4130\x2d34\x3945\x3745\x342d\x3441\x2d30\x3739\x3441\x312d\x3845\x3838\x3342\x4644\x4130\x7d36c\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1S\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761stt\xff88\xffff\x6b6e \x7526\xcb4f\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x51b0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0hi&\0\x357b\x3131\x3946\x3133\x2d36\x3737\x4231\x342d\x3539\x2d33\x3241\x3836\x312d\x3343\x4436\x3641\x3736\x4546\x7d39t\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1r\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761smp\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6173\x6567\xff\xffe8\xffff\x6b76\0.\0\xe728\x100\1\0\0\x101\xff88\xffff\x6b6e \x8964\xcb43\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6fb8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x4446\x5f4d&\0\x367b\x3645\x4141\x4336\x2d37\x4444\x3330\x342d\x4233\x2d46\x3642\x4533\x442d\x3743\x4241\x3643\x3746\x3331\x7d44\x664f\xfff8\xffff\x3530\xff\xffe8\xffff\x6b76\0$\0\xc8c8\x100\1\0\0\xff\xfff8\xffff\x3d58\xff\xfff8\xffff\x4a48\xff\xfff8\xffff\x4af0\xff\xfff8\xffff\x4b98\xff\xfff8\xffff\x4c40\xff\x6268\x6e69\x7000\xff\x3000\0\0\0\0\0\0\0\0\0\0\0\xff88\xffff\x6b6e \x1d08\xcc1a\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7f20\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x5f65\x7453&\0\x347b\x4232\x4331\x3037\x2d44\x3839\x3332\x342d\x4631\x2d37\x3138\x4130\x362d\x3238\x4144\x3932\x4434\x3638\x7d38\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1d\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sce\xff88\xffff\x6b6e \x1d08\xcc1a\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7f28\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0.m&\0\x317b\x3131\x3131\x3131\x2d31\x3131\x3131\x312d\x3131\x2d31\x3131\x3131\x312d\x3131\x3131\x3131\x3331\x3534\x7d38G\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1K\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\xed0\xff\xff88\xffff\x6b6e \x5ee\xcc64\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7f30\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\0\0&\0\x387b\x3638\x4444\x3345\x2d35\x3545\x3538\x312d\x4431\x2d30\x3741\x3730\x302d\x3030\x3030\x3530\x3132\x3539\x7d38\0\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x342d\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x3673\x7d44\0\xff88\xffff\x6b6e \x6848\xcc66\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9af8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x7449\x6d65&\0\x307b\x4331\x3731\x4143\x2d35\x3844\x3336\x342d\x4532\x2d44\x3842\x4444\x432d\x4533\x3233\x4135\x3232\x3445\x7d45\x6f68\xfff8\xffff\x85a8\xff\xfff8\xffff\x8650\xff\xfff8\xffff\x86f8\xff\xfff8\xffff\x87a0\xff\xfff8\xffff\x8848\xff\xfff8\xffff\xa0a0\xff\xfff8\xffff\x88f0\xff\xfff8\xffff\x9d68\xff\xfff8\xffff\x9e10\xff\xfff8\xffff\x9eb8\xff\xfff8\xffff\x9f60\xff\xfff8\xffff\xa188\xff\xff88\xffff\x6b6e \xb80c\xcdfb\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9fc0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0.l&\0\x347b\x3142\x3543\x3336\x2d41\x4430\x3644\x342d\x3633\x2d32\x4134\x4343\x372d\x3443\x3545\x4643\x3635\x4630\x7d46m\xff88\xffff\x6b6e \xb80c\xcdfb\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9fc8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0ro&\0\x347b\x3843\x3930\x4439\x2d45\x4234\x3139\x372d\x3238\x2d44\x3833\x4144\x302d\x4233\x3537\x3734\x3844\x4234\x7d365\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1a\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761spg\xff88\xffff\x6b6e \x1a66\xcdfe\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9fd0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0um&\0\x367b\x3031\x3533\x3342\x2d30\x3046\x3831\x332d\x4545\x2d33\x3045\x3539\x312d\x3242\x3332\x3235\x4638\x3842\x7d35t\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761scM\xff88\xffff\x6b6e \x1a66\xcdfe\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9fd8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x7972\x495f&\0\x367b\x3834\x3531\x3445\x2d34\x3231\x4142\x312d\x3844\x2d33\x3846\x3530\x352d\x3639\x3637\x3746\x3844\x3134\x7d43\x7574\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x5f73\x6552\x7361\xff88\xffff\x6b6e \x1a66\xcdfe\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9fe0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x7449\x6d65&\0\x367b\x4644\x3430\x3838\x2d43\x3333\x3831\x372d\x3836\x2d37\x3131\x3943\x362d\x4630\x3430\x4333\x4230\x4237\x7d33\x6d69\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6973\x656c\x616e\xff88\xffff\x6b6e \x1a66\xcdfe\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9fe8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x4446\x5f4d&\0\x367b\x3745\x3341\x3437\x2d30\x4638\x4446\x362d\x3830\x2d37\x3032\x3146\x352d\x4441\x3745\x4144\x3639\x3839\x7d35c\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1S\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761stt\xff88\xffff\x6b6e \x4006\xce24\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7758\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0e_&\0\x377b\x3630\x3144\x4134\x2d34\x3733\x3441\x342d\x4444\x2d45\x3241\x3231\x302d\x4645\x3241\x3630\x4430\x3735\x7d35\x726f\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1c\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sll\xfff8\xffff\x7728\xff\xff88\xffff\x6b6e \x4006\xce24\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7808\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\1\0&\0\x377b\x4144\x4330\x4430\x2d36\x3046\x3831\x332d\x3542\x2d33\x3032\x3734\x302d\x3946\x3135\x3333\x4531\x3936\x7d45\x6c61\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xffff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x4c73\x6665t\xfff8\xffff\x77d8\xff\xff88\xffff\x6b6e \x4006\xce24\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x78b8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\4\x8000&\0\x307b\x3531\x3346\x3939\x2d38\x3537\x4536\x372d\x4330\x2d38\x3243\x4138\x342d\x4439\x3136\x3734\x3235\x3331\x7d35\0\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\1\xff\xfff8\xffff\x7888\xff\xff88\xffff\x6b6e \x4006\xce24\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7968\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x5f4c\x6f4c&\0\x307b\x4333\x3034\x4646\x2d43\x3933\x3041\x332d\x3337\x2d42\x3236\x4235\x302d\x3939\x3242\x3732\x4139\x3139\x7d30\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\x7265\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x7b20\xff\xfff8\xffff\x7938\xff\xff88\xffff\x6b6e \x65a6\xce4a\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7a18\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0ia&\0\x307b\x4134\x3334\x4146\x2d30\x4645\x4539\x332d\x3030\x2d41\x4234\x4632\x352d\x3543\x3439\x3143\x3734\x4439\x7d45\0\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761st\0\xfff8\xffff\x79e8\xff\xff88\xffff\x6b6e \x89d8\xce8f\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7ac8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0fi&\0\x307b\x3936\x3535\x4542\x2d41\x4342\x3630\x352d\x4233\x2d46\x3341\x3837\x322d\x3937\x3242\x3046\x4236\x3345\x7d388\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1i\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761so.\xfff8\xffff\x7a98\xff\xff88\xffff\x6b6e \x89d8\xce8f\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7b78\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\0t&\0\x307b\x3439\x3436\x4332\x2d34\x4634\x3443\x342d\x4545\x2d39\x4345\x4343\x332d\x4233\x3235\x4141\x3242\x3644\x7d37b\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1e\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761sgl\xfff8\xffff\x7b48\xff\xff88\xffff\x6b6e \x89d8\xce8f\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7c28\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0an&\0\x307b\x4339\x4437\x3139\x2d31\x3346\x3444\x322d\x3642\x2d30\x3836\x4332\x372d\x3943\x3139\x3035\x3431\x3143\x7d33r\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\0010\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6b76\24\xfff8\xffff\x7bf8\xff\xff88\xffff\x6b6e \x89d8\xce8f\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7cd8\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x6f44\x656e&\0\x307b\x4441\x4134\x4338\x2d39\x3643\x4544\x332d\x3043\x2d39\x3639\x3137\x332d\x4530\x3730\x4439\x3943\x3439\x7d41\x626d\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x7473\x7731\xff\xfff8\xffff\x7ca8\xff\xff88\xffff\x6b6e \xeac4\xceb0\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7d88\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0x\0&\0\x307b\x3244\x4439\x4541\x2d42\x3339\x4541\x362d\x4441\x2d39\x4246\x3232\x332d\x3537\x3344\x4446\x4436\x4236\x7d39\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1~\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\L\xfff8\xffff\x7d58\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\31\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6f73\x6e77\x6f6c\xfff8\xffff\x7d90\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\20\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x6f73\x6e77\x6f6c\xfff8\xffff\x7dc8\xff\xff88\xffff\x6b6e \x7a6\xd4d4\x396c\x1c5\0\0\x9798\2\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x24d0\xff\xf020Z\xffff\xffff\0\0\0\0\0\0\f\0\x7708\xff&\0\x447b\x3839\x4138\x3944\x2d39\x3341\x4633\x342d\x6239\x2d62\x4439\x3838\x362d\x3538\x3142\x4445\x3943\x3830\x7d46\xff\xff88\xffff\x6b6e \x967c\xcbd2\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x6418\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x7538\xff&\0\x357b\x3142\x4441\x3337\x2d33\x4536\x3831\x302d\x4334\x2d46\x3832\x4643\x372d\x3030\x3545\x3739\x4642\x3638\x7d43\xff\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x7c80\xff\xfff8\xffff\x7098\xff\xfff8\xffff\x7140\xff\xfff8\xffff\x71e8\xff\xffa0\xffff\x6b6e \xb6ae\xd503\x396c\x1c5\0\0\x9798\2\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x3620\xff\xf020Z\xffff\xffff\0\0\0\0\n\0N\0007D\t\0\x6369\x6f6f\x2e75\x4c44Lin\0\xffa8\xffff{D988AD99-A33F-49bb-9D88-685B1EDC908F}\0e\{\xffa8\xffff{00020424-0000-0000-C000-000000000046}\0\x6f6f\x2e75\x4349\xffa8\xffff\x6b6e \xe5da\xd67d\xe7ee\x1c7\0\0\x9600\xff\0\0\0\0\xffff\xffff\xffff\xffff\2\0\x7710\xc1\x1e0\0\xffff\xffff\0\0\0\0\16\0N\0\x743c\xd5a3\a\0\x7954\x6570\x694cb\xffa8\xffff{DB797681-40E0-11D2-9BD5-0060082AE372}\0002E-\xffa0\xffff\x6b6e \xe5da\xd67d\xe7ee\x1c7\0\0\x8e0\xff\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x4e00\xff\x1e0\0\xffff\xffff\0\0\0\0\0\0N\0\xbe4e\xd4e7\16\0\x7250\x786f\x5379\x7574\x4362\x736c\x6469\0\xffa8\xffff{00020424-0000-0000-C000-000000000046}\0OPr\xffe8\xffff\x6b76\0$\0\x81c8\xff\1\0\0s\xffd8\xffffIXceedCompression\0\xff88\xffff\x6b6e \xd02e\xd6a8\xe7ee\x1c7\0\0\x5ca0,\3\0\0\0\xe968\x100\xffff\xffff\1\0\xeab0\x100\x1e0\0\xffff\xffff \0\0\0\0\0000\00062&\0\x347b\x3843\x3633\x3135\x2d31\x4242\x3037\x312d\x4431\x2d32\x3541\x3741\x302d\x3130\x3530\x3941\x3943\x4331\x7d362\xffa0\xffff\x6b6e \x4834\xd680\xe7ee\x1c7\0\0\x81f0\xff\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x95e8\xff\x1e0\0\xffff\xffff\0\0\0\0\0\0N\0\xffff\xffff\20\0\x7250\x786f\x5379\x7574\x4362\x736c\x6469\x3233\xfff0\xffffBoth\0\xbbb6\xffe8\xffff\x6b76\0N\0\x2020\x100\1\0\0O\xffe8\xffff\x6b76\0N\0\xd220\x100\1\0\0S\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\4\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x5ff0\xff\xff88\xffff\x6b6e \x6848\xcc66\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9b00\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\x5e8\0&\0\x347b\x3932\x3445\x3642\x2d30\x4333\x4345\x342d\x4333\x2d33\x3541\x4233\x352d\x3130\x3243\x4635\x4637\x4635\x7d44O\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\x6300\xff\xff88\xffff\x6b6e \x2b8e\xcc8a\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9b08\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0oc&\0\x377b\x3936\x4437\x3942\x2d36\x4435\x3341\x342d\x4634\x2d32\x4342\x3739\x412d\x3344\x4535\x4635\x4334\x4445\x7d43\0\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\xffff\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\30\0\xff88\xffff\x6b6e \x8c7a\xccab\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x9b10\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\xe8\0&\0\x397b\x3431\x4338\x4136\x2d35\x4635\x4131\x342d\x4531\x2d43\x3342\x3243\x382d\x3338\x4146\x4639\x4332\x4142\x7d43\xfe\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1\0\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761\x7273\x3233t\xff88\xffff\x6b6e \x8c7a\xccab\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7290\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0s\&\0\x337b\x3532\x3333\x4638\x2d30\x4541\x3044\x342d\x6635\x2d36\x3041\x4144\x422d\x4235\x3930\x3645\x3041\x4537\x7d44:\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1D\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s3F\xff88\xffff\x6b6e \x7560\xccf5\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x7298\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0\0\0&\0\x347b\x3431\x4235\x3939\x2d38\x3536\x3131\x342d\x6436\x2d65\x3841\x3337\x462d\x3144\x4244\x3044\x3335\x3631\x7d34\0\xffd0\xffff\x6b76\23\4\x8000\x400\0\4\0\1b\x6f43\x706d\x7461\x6269\x6c69\x7469\x2079\x6c46\x6761s\0r\xff88\xffff\x6b6e \x7560\xccf5\x851e\x1c7\0\0\x24b8h\0\0\0\0\xffff\xffff\xffff\xffff\1\0\x72a0\xff\xf020Z\xffff\xffff\0\0\0\0&\0\4\0C5&\0\x337b\x3530\x4630\x4434\x2d38\x4436\x3236\x312d\x4331\x2d45\x4641"

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0


    Remaining Services:
    ------------------



    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
    "C:\\Program Files\\ICQLite\\ICQLite.exe"="C:\\Program Files\\ICQLite\\ICQLite.exe:*:Enabled:ICQ Lite"
    "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
    "C:\\Documents and Settings\\Mikko Lehtinen\\Omat tiedostot\\utorrent.exe"="C:\\Documents and Settings\\Mikko Lehtinen\\Omat tiedostot\\utorrent.exe:*:Enabled:æTorrent"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\backWeb-7681197.exe"="C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\backWeb-7681197.exe:*:Disabled:backWeb-7681197"
    "C:\\Program Files\\FlashGet\\flashget.exe"="C:\\Program Files\\FlashGet\\flashget.exe:*:Enabled:Flashget"
    "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    Remaining Files:
    ---------------


    Files with Hidden Attributes:

    Wed 4 Jan 2006 14 A..H. --- "C:\klttd323.dll"
    Sat 3 Feb 2001 48,640 A..H. --- "C:\Program Files\BabasChess\timeseal.exe"
    Thu 10 Mar 2005 52,224 ..SHR --- "C:\Program Files\Chess Opening Trainer\Setup.exe"
    Tue 13 Nov 2007 10,752 ..SHR --- "C:\WINDOWS\system32\smtsvc.exe"
    Mon 27 Oct 2003 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
    Mon 27 Oct 2003 4,348 ...H. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\K„ytt”oikeuden varmuuskopio\drmv1key.bak"
    Mon 27 Oct 2003 20 A..H. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\K„ytt”oikeuden varmuuskopio\drmv1lic.bak"
    Tue 2 Sep 2003 312 ...H. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\K„ytt”oikeuden varmuuskopio\drmv2key.bak"
    Mon 27 Oct 2003 1,536 A..H. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\K„ytt”oikeuden varmuuskopio\drmv2lic.bak"
    Mon 27 Oct 2003 4,348 ...H. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\License Backup\drmv1key.bak"
    Thu 10 Feb 2005 20 A..H. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\License Backup\drmv1lic.bak"
    Tue 2 Sep 2003 312 A.SH. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\License Backup\drmv2key.bak"

    Finished!






    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:21:54 PM, on 11/26/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\Program Files\F-Secure\Common\FSMB32.EXE
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\F-Secure\Common\FCH32.EXE
    C:\Program Files\F-Secure\Common\FAMEH32.EXE
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\F-Secure\Common\FNRB32.EXE
    C:\Program Files\F-Secure\Common\FIH32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\WINDOWS\system32\smtsvc.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = lnet.lut.fi
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = lnet.lut.fi:80
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Mario Forever Toolbar Helper - {8036D4D7-AAD3-4793-AB49-329E437155A8} - C:\Program Files\Mario Forever Toolbar\v2.0.0.4\Mario_Forever_Toolbar.dll
    O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
    O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
    O3 - Toolbar: Mario Forever Toolbar - {463DF6D5-BEC1-4d67-B217-59DB692DFC53} - C:\Program Files\Mario Forever Toolbar\v2.0.0.4\Mario_Forever_Toolbar.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL
    O4 - HKLM\..\Run: [System Terminal Storage] smtsvc.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: &Lataa FlashGetillä
    - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: &Lataa kaikki FlashGetillä
    - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
    O9 - Extra button: ICQ 4 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
    O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.medion.com/
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Monopoly%20Here%20and%20Now/Images/stg_drm.ocx
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {53B8B406-42E4-4DD3-96E7-9DEC8CEB3DD8} (ICQVideoControl Class) - http://xtraz.icq.com/xtraz/activex/ICQVideoControl.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Monopoly%20Here%20and%20Now/Images/armhelper.ocx
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3AC96CDF-025C-4E73-B131-95792FE8E411}: Domain = lnet.lut.fi
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = lnet.lut.fi,cc.lut.fi,lut.fi
    O17 - HKLM\System\CS1\Services\Tcpip\..\{3AC96CDF-025C-4E73-B131-95792FE8E411}: Domain = lnet.lut.fi
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = lnet.lut.fi,cc.lut.fi,lut.fi
    O17 - HKLM\System\CS2\Services\Tcpip\..\{3AC96CDF-025C-4E73-B131-95792FE8E411}: Domain = lnet.lut.fi
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = lnet.lut.fi,cc.lut.fi,lut.fi
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: F-Secure Automatic Update (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
    O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE

    --
    End of file - 11600 bytes


    Siellähän toi smtsvc.exe-örkkipirulainen näyttää vielä lymyilevän, tällä kertaa ei yrittänyt ottaa yhteyttä nettiin. Ja on varmaa muutaki roskaa vielä?
     
  4. Mikko76

    Mikko76 Member

    Joined:
    Jul 3, 2006
    Messages:
    39
    Likes Received:
    0
    Trophy Points:
    16
    Joo, siitä services.exe en ollukaan ihan varma, estin varmuuden vuoks.
    Tehty toimenpiteet ja tässä logit:


    SDFix: Version 1.115

    Run by Mikko Lehtinen on 11/26/2007 at 11:38 AM

    Microsoft Windows XP [versio 5.1.2600]

    Running From: C:\SDFix

    Safe Mode:
    Checking Services:


    Restoring Windows Registry Values
    Restoring Windows Default Hosts File

    Rebooting...


    Normal Mode:
    Checking Files:

    No Trojan Files Found





    Removing Temp Files...

    ADS Check:

    C:\WINDOWS
    No streams found.

    C:\WINDOWS\system32
    No streams found.

    C:\WINDOWS\system32\svchost.exe
    No streams found.

    C:\WINDOWS\system32\ntoskrnl.exe
    No streams found.



    Final Check:

    catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-11-26 11:54:52
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden services & system hive ...

    scanning hidden registry entries ...

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0


    Remaining Services:
    ------------------



    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
    "C:\\Program Files\\ICQLite\\ICQLite.exe"="C:\\Program Files\\ICQLite\\ICQLite.exe:*:Enabled:ICQ Lite"
    "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
    "C:\\Documents and Settings\\Mikko Lehtinen\\Omat tiedostot\\utorrent.exe"="C:\\Documents and Settings\\Mikko Lehtinen\\Omat tiedostot\\utorrent.exe:*:Enabled:æTorrent"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\backWeb-7681197.exe"="C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\backWeb-7681197.exe:*:Disabled:backWeb-7681197"
    "C:\\Program Files\\FlashGet\\flashget.exe"="C:\\Program Files\\FlashGet\\flashget.exe:*:Enabled:Flashget"
    "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:mad:xpsp2res.dll,-22019"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:mad:xpsp3res.dll,-20000"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    Remaining Files:
    ---------------


    Files with Hidden Attributes:

    Wed 4 Jan 2006 14 A..H. --- "C:\klttd323.dll"
    Sat 3 Feb 2001 48,640 A..H. --- "C:\Program Files\BabasChess\timeseal.exe"
    Thu 10 Mar 2005 52,224 ..SHR --- "C:\Program Files\Chess Opening Trainer\Setup.exe"
    Tue 13 Nov 2007 10,752 ..SHR --- "C:\WINDOWS\system32\smtsvc.exe"
    Mon 27 Oct 2003 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
    Mon 27 Oct 2003 4,348 ...H. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\K„ytt”oikeuden varmuuskopio\drmv1key.bak"
    Mon 27 Oct 2003 20 A..H. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\K„ytt”oikeuden varmuuskopio\drmv1lic.bak"
    Tue 2 Sep 2003 312 ...H. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\K„ytt”oikeuden varmuuskopio\drmv2key.bak"
    Mon 27 Oct 2003 1,536 A..H. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\K„ytt”oikeuden varmuuskopio\drmv2lic.bak"
    Mon 27 Oct 2003 4,348 ...H. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\License Backup\drmv1key.bak"
    Thu 10 Feb 2005 20 A..H. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\License Backup\drmv1lic.bak"
    Tue 2 Sep 2003 312 A.SH. --- "C:\Documents and Settings\Mikko Lehtinen\Omat tiedostot\Omat musiikkitiedostot\License Backup\drmv2key.bak"

    Finished!

    (poistin tuosta hidden registry entries niitä merkkejä kun oli niin tuhottomasti ja kesti tämän vastauksen lataus!)






    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:21:54 PM, on 11/26/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\Program Files\F-Secure\Common\FSMB32.EXE
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\F-Secure\Common\FCH32.EXE
    C:\Program Files\F-Secure\Common\FAMEH32.EXE
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\F-Secure\Common\FNRB32.EXE
    C:\Program Files\F-Secure\Common\FIH32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\WINDOWS\system32\smtsvc.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = lnet.lut.fi
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = lnet.lut.fi:80
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Mario Forever Toolbar Helper - {8036D4D7-AAD3-4793-AB49-329E437155A8} - C:\Program Files\Mario Forever Toolbar\v2.0.0.4\Mario_Forever_Toolbar.dll
    O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
    O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
    O3 - Toolbar: Mario Forever Toolbar - {463DF6D5-BEC1-4d67-B217-59DB692DFC53} - C:\Program Files\Mario Forever Toolbar\v2.0.0.4\Mario_Forever_Toolbar.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL
    O4 - HKLM\..\Run: [System Terminal Storage] smtsvc.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: &Lataa FlashGetillä
    - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: &Lataa kaikki FlashGetillä
    - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
    O9 - Extra button: ICQ 4 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
    O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.medion.com/
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Monopoly%20Here%20and%20Now/Images/stg_drm.ocx
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {53B8B406-42E4-4DD3-96E7-9DEC8CEB3DD8} (ICQVideoControl Class) - http://xtraz.icq.com/xtraz/activex/ICQVideoControl.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Monopoly%20Here%20and%20Now/Images/armhelper.ocx
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3AC96CDF-025C-4E73-B131-95792FE8E411}: Domain = lnet.lut.fi
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = lnet.lut.fi,cc.lut.fi,lut.fi
    O17 - HKLM\System\CS1\Services\Tcpip\..\{3AC96CDF-025C-4E73-B131-95792FE8E411}: Domain = lnet.lut.fi
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = lnet.lut.fi,cc.lut.fi,lut.fi
    O17 - HKLM\System\CS2\Services\Tcpip\..\{3AC96CDF-025C-4E73-B131-95792FE8E411}: Domain = lnet.lut.fi
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = lnet.lut.fi,cc.lut.fi,lut.fi
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: F-Secure Automatic Update (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
    O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE

    --
    End of file - 11600 bytes


    Siellähän toi smtsvc.exe-örkkipirulainen näyttää vielä lymyilevän, tällä kertaa ei yrittänyt ottaa yhteyttä nettiin. Ja on varmaa muutaki roskaa vielä?
     
  5. Etzo

    Etzo Regular member

    Joined:
    Feb 8, 2007
    Messages:
    489
    Likes Received:
    0
    Trophy Points:
    26
    Varmistu ensin, että piilotiedostot on näkyvillä.

    Piilotiedostot näkyviin

    Mene --> tänne

    Kun sivu on latautunut, klikkaa Selaa-nappulaa ja etsi seuraava tiedosto ja paina Submit.

    C:\klttd323.dll

    Lähetä skannin tulokset seuraavassa viestissäsi.

    Jos Jotti on ruuhkainen, yritä samaa Virustotalissa: http://www.virustotal.com/flash/index_en.html
    --

    Lataa Killbox Option^Explicitiltä.

    Huomaa: Jos sinulla on jo Killbox, tämä on uusi versio joka sinun tulee asentaa. Poista aikaisempi.

    [*]Tallenna työpöydällesi.
    [*] Tupla-klikkaa Killbox.exe ajaaksesi ohjelman.
    [*] Valitse: [*]Delete on Reboot[*] sitten klikkaa All Files valintaa.
    [*]Kopioi ja liitä alapuolella olevat tiedostopolut leikepöydälle mustaamalla KAIKKI ne ja painamalla CTRL + C (tai, mustaamisen jälkeen, oikea klikki hiirellä ja valitse kopioi):

    C:\WINDOWS\system32\smtsvc.exe

    [*] Palaa Killboxiin, mene File valikkoon, ja valitse Paste from Clipboard.

    [*]Klikkaa puna-valkoista Delete File valintaa. Klikkaa Yes "Delete on Reboot" pyyntöön. Klikkaa OK mihin vain PendingFileRenameOperations pyyntöön (ja anna fixaajan tietää jos jokin tälläinen tulee!).[/list]
    Käynnistä koneesi itse jos se ei sitä automaattisesti tee.

    Jos saat tälläisen viestin: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." Kun yrität ajaa KillBoxia, klikkaa tätä ladataksesi ja ajaaksesi Missingfilessetup.exe;n. Sitten koita KillBoxia uudestaan.
     
  6. Mikko76

    Mikko76 Member

    Joined:
    Jul 3, 2006
    Messages:
    39
    Likes Received:
    0
    Trophy Points:
    16
    Ok tehty noi, tässä skannilogi:


    Antivirus Version Last Update Result
    AhnLab-V3 2007.11.24.0 2007.11.26 -
    AntiVir 7.6.0.34 2007.11.26 -
    Authentium 4.93.8 2007.11.24 -
    Avast 4.7.1074.0 2007.11.25 -
    AVG 7.5.0.503 2007.11.26 -
    BitDefender 7.2 2007.11.26 -
    CAT-QuickHeal 9.00 2007.11.26 -
    ClamAV 0.91.2 2007.11.26 -
    DrWeb 4.44.0.09170 2007.11.26 -
    eSafe 7.0.15.0 2007.11.21 -
    eTrust-Vet 31.3.5327 2007.11.26 -
    Ewido 4.0 2007.11.26 -
    FileAdvisor 1 2007.11.26 -
    Fortinet 3.14.0.0 2007.11.26 -
    F-Prot 4.4.2.54 2007.11.25 -
    F-Secure 6.70.13030.0 2007.11.26 -
    Ikarus T3.1.1.12 2007.11.26 -
    Kaspersky 7.0.0.125 2007.11.26 -
    McAfee 5170 2007.11.23 -
    Microsoft 1.3007 2007.11.26 -
    NOD32v2 2686 2007.11.26 -
    Norman 5.80.02 2007.11.26 -
    Panda 9.0.0.4 2007.11.25 -
    Prevx1 V2 2007.11.26 -
    Rising 20.20.02.00 2007.11.26 -
    Sophos 4.23.0 2007.11.26 -
    Sunbelt 2.2.907.0 2007.11.24 -
    Symantec 10 2007.11.26 -
    TheHacker 6.2.9.142 2007.11.26 -
    VBA32 3.12.2.5 2007.11.23 -
    VirusBuster 4.3.26:9 2007.11.26 -
    Webwasher-Gateway 6.0.1 2007.11.26 -
    Additional information
    File size: 14 bytes
    MD5: 309636351fb7ae5e167e1ac4040e9d66
    SHA1: 0d8993d3df986c5cd5789e8253d9318640ce3876
     
  7. Etzo

    Etzo Regular member

    Joined:
    Feb 8, 2007
    Messages:
    489
    Likes Received:
    0
    Trophy Points:
    26
    Uusi HJT loki sekä Killboxin loki (pitäisi sijaita C:\!KillBox )
     
  8. Mikko76

    Mikko76 Member

    Joined:
    Jul 3, 2006
    Messages:
    39
    Likes Received:
    0
    Trophy Points:
    16
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:37:01 PM, on 11/26/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    C:\Program Files\F-Secure\Common\FSMA32.EXE
    C:\Program Files\F-Secure\Common\FSMB32.EXE
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\F-Secure\Common\FCH32.EXE
    C:\Program Files\F-Secure\Common\FAMEH32.EXE
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    C:\Program Files\F-Secure\Common\FNRB32.EXE
    C:\Program Files\F-Secure\Common\FIH32.EXE
    C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\F-Secure\Common\FSM32.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = lnet.lut.fi
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = lnet.lut.fi:80
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Mario Forever Toolbar Helper - {8036D4D7-AAD3-4793-AB49-329E437155A8} - C:\Program Files\Mario Forever Toolbar\v2.0.0.4\Mario_Forever_Toolbar.dll
    O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
    O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
    O3 - Toolbar: Mario Forever Toolbar - {463DF6D5-BEC1-4d67-B217-59DB692DFC53} - C:\Program Files\Mario Forever Toolbar\v2.0.0.4\Mario_Forever_Toolbar.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL
    O4 - HKLM\..\Run: [System Terminal Storage] smtsvc.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: &Lataa FlashGetillä
    - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: &Lataa kaikki FlashGetillä
    - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
    O9 - Extra button: ICQ 4 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
    O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.medion.com/
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Monopoly%20Here%20and%20Now/Images/stg_drm.ocx
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {53B8B406-42E4-4DD3-96E7-9DEC8CEB3DD8} (ICQVideoControl Class) - http://xtraz.icq.com/xtraz/activex/ICQVideoControl.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Monopoly%20Here%20and%20Now/Images/armhelper.ocx
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3AC96CDF-025C-4E73-B131-95792FE8E411}: Domain = lnet.lut.fi
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = lnet.lut.fi,cc.lut.fi,lut.fi
    O17 - HKLM\System\CS1\Services\Tcpip\..\{3AC96CDF-025C-4E73-B131-95792FE8E411}: Domain = lnet.lut.fi
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = lnet.lut.fi,cc.lut.fi,lut.fi
    O17 - HKLM\System\CS2\Services\Tcpip\..\{3AC96CDF-025C-4E73-B131-95792FE8E411}: Domain = lnet.lut.fi
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = lnet.lut.fi,cc.lut.fi,lut.fi
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: F-Secure Automatic Update (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
    O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
    O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE

    --
    End of file - 11611 bytes




    Pocket Killbox version 2.0.0.648
    Running on Windows XP as Mikko Lehtinen(Administrator)
    was started @ Monday, November 26, 2007, 6:10 PM

    # 1 [Delete on Reboot]
    Path = C:\WINDOWS\system32\smtsvc.exe


    I Rebooted @ 6:13:55 PM
    Killbox Closed(Exit) @ 6:14:24 PM
    __________________________________________________
     
  9. Etzo

    Etzo Regular member

    Joined:
    Feb 8, 2007
    Messages:
    489
    Likes Received:
    0
    Trophy Points:
    26
    Käynnistä HijackThis, klikkaa do a system scan only.
    Sulje kaikki muut ikkunat, merkkaa nämä rivit ja paina Fix checked : (jos löytyvät)

    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [System Terminal Storage] smtsvc.exe


    Loistavaa, lokisi on puhdas! Muista ajella aina silloin tällöin tuolla AVG:llä niin pysyt puhtaana.
    Nyt kun olet puhdas, seuraavaksi pari vinkkiä kuinka pienennetään saastumisriskiä. Kaikista on saatavilla joko suomenkielinen versio sekä/tai suomenkielinen opas.

    -> Taistele vastaan!!-> Malware Complaints
    Sivusto antaa haittaohjelmien uhreille mahdollisuuden kertoa tarinansa ja tehdä valituksen asiasta. Taistellaan yhdessä haittaohjelmien tekijöitä vastaan!

    -> Tyhjennä järjestelmänpalautus -> Ohjeet
    Tyhejnnä järjestelmänpalautuskansio ja luo uusi palautuspiste. Tämä puhdistaa palautuskansion mahdollisista haittaohjelmajäännöksistä.

    -> Käytä CCleaneria -> CCleaner
    Lataa ja asenna CCleaner. Puhdista väliaikaistiedostot ja -kansiot ohjelmalla säännöllisesti.

    -> Käytä Ad-Awarea -> Ad-Aware
    Lataa ja asenna Ad-Aware. Päivitä se ja skannaa konettasi sillä säännöllisesti.
    Opas saatavilla suomeksi! Nimimerkki Ad-Awaren opas

    -> Käytä AVG Anti-Spywarea -> AVG Anti-Spyware
    Lataa ja asenna AVG Anti-Spyware. Päivitä se ja skannaa konettasi sillä säännöllisesti
    Opas saatavilla suomeksi! (Ewido ulkoasulla) Nimimerkki Axelin opas

    -> Asenna SpywareBlaster -> SpywareBlaster
    SpywareBlaster estää haittaohjelmia asentumasta koneellesi. Ei kuluta muistia!
    Opas saatavilla suomeksi! Nimimerkki Ad-Awaren opas

    -> Asenna MVPS Hosts tiedosto -> MVPS Hosts
    Estää koneesi yhteyden haitallisiin sivustoihin.
    Opas saatavilla suomeksi! Nimimerkki Axelin opas

    -> Vaihda selaimesi Firefoxiin -> Firefox
    Firefox on nopeampi, turvallisempi ja parempi selain kuin Internet Explorer.

    -> Pidä järjestelmäsi ajantasalla. -> Windows Update
    Vieraile Windows Updatessa säännöllisesti.

    -> Pidä palomuuri ja virustorjunta ajantasalla
    Päivitä ja skannaa koneesi säännöllisesti virustorjuntaohjelmallasi.

    Pysy puhtaana ;)
     
    Last edited: Nov 26, 2007
  10. Mikko76

    Mikko76 Member

    Joined:
    Jul 3, 2006
    Messages:
    39
    Likes Received:
    0
    Trophy Points:
    16
    Yes, hyvä..Kiitti sulle paljon =) Koitetaan.
     

Share This Page