Computing.Net > Forums > Security and Virus > need help getting back to normal

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

need help getting back to normal

Reply to Message Icon

Name: timmay
Date: October 23, 2007 at 17:00:29 Pacific
OS: windows Xp service pack 2
CPU/Ram: 1024mb
Product: gateway
Comment:

about a month back i got a virus called tuvspnk.dll and it was removed, so i thought nothing of it and recently none of my icons worked, then i found a way to run most


ive been using bitdefender (since now only online scanners work for me) and the spyware xscan that ive noticed in other pars of this site, xcleaner fixed a lot of registry keys and bitdefender finds about 50 viruses per week and removes all except tuvspnk.dll dnlsvc.exe, spoolsv.exe and those are the only ones i can remember

task manager still works, and it has about 28 process where it used to be 40+, and when i click on shortcuts and such a window will say "windows cannot open this file because it needs to know what created it" or something like that... i can then open the files by clicking select the program from a list then browse and finding that exact program and using that to open itself

system restore in both safe and normal hasnt worked

i guess what i need is a way to fix my desktop and program files so that they run properly, i can run them now but it can be a pain to find the exact file and use that over and over again

note: i can use hijackthis and xraypc
i also tried using exefix and importing it into the registry, but that didnt work



Sponsored Link
Ads by Google

Response Number 1
Name: jabuck
Date: October 23, 2007 at 17:21:53 Pacific
Reply:

Please download and install the latest version of HijackThis v2.0.2:

Download the HijackThis Installer from this link: HijackThis

1. Save " HJTInstall.exe" to your desktop.
2. Double click on HJTInstall.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Click "Save log" to save the log file and then the log will open in Notepad.
7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
8. Paste the log in your next reply.
9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.


0

Response Number 2
Name: timmay
Date: October 23, 2007 at 19:18:43 Pacific
Reply:

the log doesnt open in notepad... i can only open programs it seems my other programs cant open anything but themselves

is there a way i can open the log manually trough a blank notepad?


0

Response Number 3
Name: timmay
Date: October 23, 2007 at 19:33:36 Pacific
Reply:

also when i was looking at the registry, under HKEY_CURRENT_CONFIG when i went to look at the permissions i saw Account Unknown(S-1-5-32-547)


0

Response Number 4
Name: jabuck
Date: October 23, 2007 at 19:48:01 Pacific
Reply:

Go to this link http://www.dougknox.com/xp/file_assoc.htm then for these:

COM File Association Fix

EXE File Association Fix

Folder File Association Fix

INF File Association Fix

TXT File Association Fix

URL File Association Fix

VBS File Association Fix

ZIP Folder Association Fix

One at the time double click the blue part of the line> click open> double click the .reg file taht appears> click run.

Please download ComboFix to the desktop from this link:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Double-click combofix.exe
Follow the prompts.
(Don't click on the window while the program is running, it may cause your system to hang.)

Please post the log it produces.

Then see if you can post a Hijack This log.



0

Response Number 5
Name: Jennifer SUMN
Date: October 24, 2007 at 10:45:45 Pacific
Reply:

You may be better off backing up your data and reloading your machine.... Just a thought.

Life's more painless for the brainless.


0

Related Posts

See More



Response Number 6
Name: timmay
Date: October 24, 2007 at 13:07:29 Pacific
Reply:

ok ill try that jabuck thanks

i really dont want to do that since it seems like gateways have a really bad track record at that
also the recovery cds were createdyears ago... id prefer no to lose everything
still thanks for the suggestion


0

Response Number 7
Name: timmay
Date: October 24, 2007 at 13:29:08 Pacific
Reply:

i had to download each to the desktop since no option to open came up from the site
none of the files were succesfully imported except for folder_reg.reg
it said some keys were open by the system

should i run combofix anyway?


0

Response Number 8
Name: jabuck
Date: October 24, 2007 at 14:05:39 Pacific
Reply:

Yes, run Combofix if you can.


0

Response Number 9
Name: timmay
Date: October 24, 2007 at 14:31:27 Pacific
Reply:

when i run it it says windows cannot open this file cmd.exe, so then i select select the program from a list, find the file and use it to open itself... it comes up as command prompt with C:\ComboFix>, then i am prompted to open nircmd.exe and another cmd.exe which i do, but nothing seems to happen


0

Response Number 10
Name: timmay
Date: October 24, 2007 at 14:58:47 Pacific
Reply:

when i run it it says windows cannot open this file cmd.exe, so then i select select the program from a list, find the file and use it to open itself... it comes up as command prompt with C:\ComboFix>, then i am prompted to open nircmd.exe and another cmd.exe which i do, but nothing seems to happen


0

Response Number 11
Name: jabuck
Date: October 24, 2007 at 15:39:19 Pacific
Reply:

Open notepad (Start Menu > Run > Type notepad and press "ok".

Copy and paste everything into notepad between the x's making "Windows Registry Editor Version 5.00" the very top line.
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"


XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

Go to File on the top bar and choose" Save As", Change the "Save As Type" to All Files, Name it Fix.reg then save it to your desktop.

Double click Fix.reg (or right click and choose Merge) and it will ask if you want to merge the contents into the registry, choose Yes.

Then quickly try to run Combofix from the red X on your desktop. If it still will not run reboot the computer and try it again.



0

Response Number 12
Name: timmay
Date: October 24, 2007 at 18:17:12 Pacific
Reply:

this is what i got when i opened notepad... i didnt load any files this is just the way it came up, although it opens other text files normally

MZ   ÿÿ ¸ @ à º ´ Í!¸LÍ!This program cannot be run in DOS mode.

$ ì…[¡¨ä5ò¨ä5ò¨ä5òkë:ò©ä5òkëUò©ä5òkëhò»ä5ò¨ä4òcä5òkëkò©ä5òkëjò¿ä5òkëoò©ä5òRich¨ä5ò PE L Ã|A à  
x ¦ s           @  O  €      v È ° X‰ P  ¨ @ P Ð  H .text Hw  x  `.data ¨   | @ À.rsrc X‰ ° Š „ @ @°–AX ·–Ae ¶–Aq Œ–A~ Œ–A‹ §–A– ´–A£  ´–A° —–Aº ¸–AÄ comdlg32.dll SHELL32.dll WINSPOOL.DRV COMCTL32.dll msvcrt.dll ADVAPI32.dll KERNEL32.dll NTDLL.DLL GDI32.dll USER32.dll ÈoÝwðkÝw}ßwýÕßwƒxÝwvÝwÌ×Ýw íÒ=w #Yòw4ôw±[òw¦lñw¦jòwtñwÏøòw25ôwy°ñwè|ñw¢@ôw|êówñ_ñw#ƒñw¢Xñwº‹ñw;jñwõ{ñw ]ñw•ñw¶ãòw_äòw÷¨ñw Yñw 7—€|¬’€|¤€|ÁÉ€|ÀŸ€|y|‚|Õ„‚||‚ |…|ž“€|å€|€|
à€|†|w€|)µ€|î€|/þ€|r|]™€|½™€|9š€|!.‚|N£€|ˆ-‚|æ’‡|w›€|츀|€|v |#¨€|N™€|(¬€|ûl|J|×ï€|áð€|Ôµ€|Y¨€|ô—€|w¸€||#‚|1‘|Ÿ|@‘|Ç €|±â|G‚|à-|Pø|=÷|C™€|ü·€|­œ€|·€|Š+†| ¢?§|îü¡|7¢£|ëø¥| VµÔw¨ÆÔwm†Ôw—†ÔwgÕw€SÕw<ÄÔwå±ÔwfæÔwÓ×wÞÔÔw®ÄÔwŠÄÔwëÔwªÔw6œÔw-7Õw¸çÔw)®Ôw¤BÕwi›ÔwêûÖwÕÕw»×Ôw@ÆÔwt!ÕwÞºÔwëíÖwÞ­ÔwdÀÔw€÷ÔwdŸÔwx’ÔwÔÄÔwÒÕwŸbÖwýÉÔwuÔwÕÔw´ÔwÔÙw\ÃÔwe…Öw¸ÅÔwfÅÔwü'Öwb·ÔwFçÔwqÕwåîÔwíÍÔw÷îÔwŸtÖw<üÔwZ5Õw¾êÖwaÙwñÞÔw~ˆÔw¤RÕwÜåÔw0'Öwb¨Ôw@kÕwÉlÕw×µÔwDåÖwÙ‰Ôw΋Ôw=”Ôw>çÖw£ŒÔw£‘ÔwÓãÖw ` sS sIW s ÖH=v–†<v)=v©Ä<v†;ve|<vʆ<vÎ <vó|<v ®-ÂMšžÂMΞÂM£®ÃM=«ÃM¶žÂM6ÐÀM”\ÂMwÎÀM/€ÃM ûÂM~žÂM¬ÅMëîÀMgÂMuÖÃMØ#ÅM¤ñÀMÛñÀM|SÂM/îÃMk€ÃM Ã|A  $ ð ð  ê  ê  ë % d N p E n c o d i n g D i a l o g t x t * . t x t RegisterPenApp notepad.chm i W i n d o w P o s D Y i W i n d o w P o s D X i W i n d o w P o s Y i W i n d o w P o s X f M L E _ i s _ b r o k e n i M a r g i n R i g h t i M a r g i n L e f t i M a r g i n B o t t o m i M a r g i n T o p s z T r a i l e r s z H e a d e r l f F a c e N a m e f S a v e W i n d o w P o s i t i o n s S t a t u s B a r f W r a p i P o i n t S i z e l f P i t c h A n d F a m i l y l f Q u a l i t y l f C l i p P r e c i s i o n l f O u t P r e c i s i o n l f C h a r S e t l f S t r i k e O u t l f U n d e r l i n e l f I t a l i c l f W e i g h t l f O r i e n t a t i o n l f E s c a p e m e n t S o f t w a r e \ M i c r o s o f t \ N o t e p a d L u c i d a C o n s o l e O u t o f R C s t r i n g s p a c e ! ! D E V E r r o r ! S l i p U p A c c / . S E T U P / P / P T * . * / W / A E d i t M a i n A c c c o m m d l g _ h e l p c o m m d l g _ F i n d R e p l a c e . t x t ÿÿÿÿÈU ÌU  é  é ! è  è

  hhctrl.ocx CLSID\{ADB880A6-D8FF-11CF-9377-00AA003B7A11}\InprocServer32 ÿÿÿÿ*u >u  H –    RSDSø®yö¾ÊD´Ëĵ-w$ notepad.pdb ºu ¡¨¤ …ÀV‹5Ô tPÿÖ¡¬¤ …ÀtPÿÖƒ%¨¤  ƒ%¬¤  ^ÃÌÌÌÌÌ‹ÿU‹ìQjEüPj
h  Çä¤ c_ Çì¤  ÿØ fƒ}ü1u ¸è £Ð¤ £Ø¤ ǰ¤   ¸î ë¸Ä £Ð¤ £Ø¤ ǰ¤ 
  ¸Ð £Ì¤ £Ô¤ ÉÃÌÌÌÌÌ‹ÿU‹ìjj ÿ58˜ ÿ$ ¡@˜ ‹M ÷ØÀ#ঠj+ÈQÿuj j ÿ58˜ ÿ  ] ÌÌÌÌÌ‹ÿU‹ìQQ‹E ƒèSV„ ƒè(„¾ -• t(H… j j hG h ÿuÿ< £(¥ éþ ‹5< SWÿ5´ »C j S¿ WÿuÿÖÿ5¸ j SWÿuÿÖÿ5¼ j SWÿuÿÖÿ5À j SWÿuÿÖ¡0 ‹
´ £(¥ HtHt Hu‹
À ë‹
¼ ë‹
¸ QjÿhM WÿuÿÖ_[ëo‹u9uu(EøPÿ8 EøPÿuÿ4 ÿuüÿuøÿuÿ0 ‹ðVÿ, = t= u*hl j
ÿ5t Vë.‹uÿv ÿ, = t = t3Àëhl j ÿ5t ÿv ÿ( 3À@^É ÌÌÌÌÌ‹ÿU‹ì‹EV‹5@ j HPh» ÿ58˜ ÿÖƒøÿt PPh± ÿ58˜ ÿÖj j h· ÿ58˜ ÿÖ^] ÌÌÌÌÌ‹ÿU‹ì‹EV3ö3Éë&fƒù tfƒù u…ötfƒù"u 3É…ö”Á‹ñPÿD f‹f…ÉuÒ^f‹fƒù tfƒù u@@ëí] ÌÌÌÌÌ‹ÿU‹ìì  ¡– SV‹5@ W‰Eü…ôþÿÿP…øþÿÿPh° ÿ58˜ ÿÖj ÿµøþÿÿhÉ ÿ58˜ ÿÖ‹øj GGÿPh» ÿ58˜ ÿÖ‹øþÿÿ+ØCƒ} u;$– u;= – t9SWÿ5Ȑ …üþÿÿjPÿ ¡4˜ fƒeú ƒÄ…ÀtüþÿÿQjh  PÿÖ‹Mü‰= – _^‰$– [è4T É ÌÌÌÌÌj èÿÿÿ ÌÌÌÌÌ‹ÿU‹ìV‹u3Éf‹f…ÉW‹þ‹Æt#fƒù:tfƒù\u‹øPÿD f‹f…Éuã;þtGG‹Ç_^] ÌÌÌÌÌ‹ÿU‹ìƒìƒeø SVWÿ50˜ ÿd ‹ØEðPEôPh° ÿ58˜ ÿ@ ‹Mô‹5` 3À;Mð”ÀPh  jS‰EüÿÖ‹=\ Pÿ×ÿuüh jSÿÖPÿ×ÿuüh jSÿÖPÿ×j jjSÿÖPÿX ƒøu9Eüu j jPSÿÖPÿ×ÿuÿT …ÀtjÿP ‰EøÿL 3À9Eø”ÀPh jSÿÖPÿ×j j jÿ58˜ ÇEü ÿ@ …Àtƒeü ÿuüjjSÿÖPÿ×ÿuüjjSÿÖPÿ×3À9P˜ •ÀPjjSÿÖPÿ×j j hÆ ÿ58˜ ÿ@ 3É…À”ÁQjjSÿÖPÿסP˜ ÷ØÀƒàPj jSÿÖ‹=H Pÿס@˜ ÷ØÀƒàPjjSÿÖPÿ×_^[É ÌÌÌÌÌ‹ÿU‹ì‹M‹EWj_ëf‹f‰f‹ÇÏf…Òtf‹f;« uâV‹u …ötë
3Àë'f‰Ç÷3Òf‹f…ÒuïƒÁ^f‹f‰ÇÏf…Òuñ3À@_] ÌÌÌÌÌ‹ÿU‹ìƒ} V‹5ä Wt ÿuÿÖ‹øë3ÿÿuÿÖǍD Pj@ÿà ‹ð…öt'VÿuÿuèNÿÿÿÿuÿu Vÿuÿh V‹øÿÜ ëÿuÿu ÿuÿuÿh ‹ø‹Ç_^] ÌÌÌÌÌ‹ÿU‹ìì” ¡– ‰Eüÿà …Àtc3É3Ò;‚ ‘ u‹Š¤‘ ‹ ƒÂƒú@rè…Éu"Pÿ5¨ …lþÿÿhÇ Pÿ ƒÄlþÿÿfƒ9 th ÿ5T Qÿ50˜ ÿh 3À@‹MüèÏP ÉÃÌÌÌÌÌ‹ÿU‹ìƒìSVÿ5¥ ‹5ä ÿÖÿ5¥ ‰EðÿÖ‹5@ ‰EüEôPEøPh° ÿ58˜ ÿÖ3ÛSSh½ ÿ58˜ ÿÖ;ÉEì„¿ WPÿð ‹ø;û„¬ ‹Mô‹Eø+È;Mü…’ 9š t%ÿuüGPÿ5¥ ÿ ƒÄ …Àt09š uh‹EøÿuüGPÿuüÿ5¥ h h  ÿì ƒøu@ÿ5¥ jh ÿ58˜ ÿÖ‹Eø‹MðÈQPh± ÿ58˜ ÿÖ9]tSSh· ÿ58˜ ÿÖÿuìÿè _^[É ÌÌÌÌÌ‹ÿU‹ììÔ ¡– ‹U‹MS‹]‰Eü‹E ƒèSVW„  ƒè(„‡ -• „í H…› ·ÂHt!Ht
-  …‡ ë jSÿˆ 3À@év jd…4ÿÿÿP¾ VSÿ„ jd…4ÿÿÿPjÿPh€ ÿô …4ÿÿÿPÿ  ‹=@ Yj £”« HPh» ÿ58˜ ÿ×3É9
”« vƒøÿtQëˆQÿ5¬ ÿ5° Sÿh j j hº ÿ58˜ ÿ×P…4ÿÿÿh˜ Pÿ€ ƒÄ …4ÿÿÿPVSÿ| Sÿx éµ ¾ VSÿt ‹øjðWÿp 
PjðWÿl ‹=@ …,ÿÿÿP…0ÿÿÿPh° ÿ58˜ ÿ×j ÿµ0ÿÿÿhÉ ÿ58˜ ÿ×@P…4ÿÿÿh˜ Pÿ€ ƒÄ …4ÿÿÿPVSÿ| Sÿx éªþÿÿh„ j
ÿ5t Rëh„ j ÿ5t ÿq ÿ( 3À‹Mü_^[è³M É ÌÌÌÌÌ‹ÿU‹ìW‹} 3ÀƒÿvRV‹u·ùï» t4ùÿþ tùþÿ t WVèÞL …Àt3À@ë"WVèvL ÷ØÀƒàëjë
ƒÿv €~¿ujX^_] ÌÌÌÌÌ‹ÿU‹ì3À9E u¸W €ë-‹UV‹uf‹f…Ét f‰
BBFFÿM uìƒ} ^uJJ¸z €fƒ" ] ÌÌÌÌÌ‹ÿU‹ìì ¡– S‹]‰Eü‹E ƒèNV‹uW‹}‰µðùÿÿ„h ƒè„2 ƒè(„À -• t&H…V j j hG h Vÿ< £0 é7 ÿ5´ »C j S¿ WV‹5< ÿÖÿ5¸ j SWÿµðùÿÿÿÖÿ5¼ j SWÿµðùÿÿÿÖÿ5À j SWÿµðùÿÿÿÖ¡0 H‹
´ tHt Hu‹
À ë‹
¼ ë‹
¸ QjÿhM WÿµðùÿÿÿÖé¤ ;óu0…äùÿÿPÿ8 …äùÿÿPVÿ4 ÿµèùÿÿÿµäùÿÿVÿ0 ‹ØSÿ, = t = …W hl j
ÿ5t Sÿ( 3À@é= ÿw ÿ, = t = …  hl j ÿ5t ÿw 룦ýÿÿ… …ôýÿÿPh he VÿŒ Pÿ@ …ÀŽÚ »h˜ S…ôýÿÿPÿ …À„¿ 3ÿWh€ jWjh €…ôýÿÿPÿ ƒøÿ‰…ìùÿÿ„‘ WðùÿÿQh  ôùÿÿQPÿ  …À~f9½ðùÿÿt^ÿµðùÿÿ…ôùÿÿPèüüÿÿ‹
´ £0 HtHt Hu‹
À ë‹
¼ ë‹
¸ QjÿhM h Vÿ< …ôýÿÿPSÿü ÿµìùÿÿÿø 3À‹Mü_^[èAJ É ÌÌÌÌÌ‹ÿU‹ìì ¡– SVW‰Eü3Û3Àf‰ôýÿÿ¹ ½öýÿÿó«3öF9 f«‹=@ ‰µðýÿÿtSSjÿ58˜ ÿ×…À„œ SSh¸ ÿ58˜ ÿ×…À„} 9 ¡@ ¿ © u‹Ç‹M÷ÙɁá  ·ÉƒÉ3QPÿ5< ‰5T˜ ÿ5T ÿ50˜ è©÷ÿÿƒø‰…ðýÿÿ‰T˜ …" 9 thÌ ë#¡0 SWÿ50˜ £(¥ è¬& …Àt‹Æéý W…ôýÿÿPÿü ‹=ä »€¦ ë@ÿ5œ¦ …ôýÿÿPÿü V…ôýÿÿPÿ50˜ è`& …À…ôýÿÿ…½ h © Pÿü …ôýÿÿ£œ¦ ¡ S‰5T˜ ‰5˜¦ Ǽ¦ Ä ÇŒ¦ @¥ ÇĦ ( ÇȦ   Ç´¦ fˆˆ £°¦ ÿ×…À…bÿÿÿÇ…ðýÿÿ ÿà …Àth ÿ5T ÿ5L ÿ50˜ ÿh ƒ%T˜  3Àƒ½ðýÿÿ•À‹Mü_^[è2H É Ph © ÿü ¡(¥ £0 ëÆÌÌÌÌÌ‹ÿU‹ìƒì VWÿ hØ j)‹øÿ Pÿ 3ö;ƉEütjjÿÐÿuWètòÿÿPÿu ÿuèå …Àu‰uèé° SVVÿ  Ph V¸ € PPÿ¬ ‹=¨ ‹Øë_ƒ}äPuVVh€ ÿ50˜ ÿ¤ ¡<˜ ;ÆtMàQPÿ  …Àu.EàPÿ5ئ ÿ50˜ ÿœ …ÀuEàPÿ˜ EàPÿ” VVEàVPÿ×…Àu”èïÿÿÿ5Œ« ÿÜ ;ÞtSÿ [9uütVjÿUü‹Eè_^É ÌÌÌÌÌ‹ÿU‹ììÈ ¡– fƒ¥üþÿÿ V‹uWj?‰EüYÿ5@ 3À½þþÿÿó«Vf«ÿ( …Àuÿ5@ …üÿÿh6 Pè]ùÿÿëfVÿ$ …8øÿÿPVÿ  ‹øƒÿÿt"…døÿÿP¾ V…ˆúÿÿPè&ùÿÿWÿ ëV¾ V…ˆúÿÿPè
ùÿÿV…üÿÿP…ˆúÿÿPÿÔ jjÿ5Ȑ …üþÿÿjPÿ ¡4˜ ƒÄ…À_^tüþÿÿQjh  Pÿ@ ÿ5D …üÿÿPÿ …üÿÿPÿ50˜ ÿð ‹MüèÉE É ÌÌÌÌÌ‹ÿU‹ìì` ¡– ‹USVW‰Eü3ö3Àf‰µôýÿÿ¹ ½öýÿÿó«f«·} ƒÿ@‰•ðýÿÿù „Û ƒÿÎ „ì ƒÿt „  O„ø O„ Ot
Ot23Àé^ 95 ¡0 £(¥ uVh © ÿ50˜ è" …À…0 95 ‹=0 …ôýÿÿ£œ¦ ¡ £°¦ Ç´¦ fˆˆ ÇȦ   ÇĦ ( ÇŒ¦ @¥ Ǽ¦ Ä » …ôýÿÿu Sh © Pÿ×ë hÌ Pÿü 3À@h€¦ £T˜ £˜¦ ÿä …Àt3j…ôýÿÿPÿµðýÿÿèÐ! …Àt S…ôýÿÿPh © ÿס(¥ £0 ëèîòÿÿ‰5T˜ éZ Vèüùÿÿ…À„L ‹0 …ôýÿÿhÌ P£œ¦ ÿü ¡Œ h€¦ £°¦ ÇŒ¦ ॠǼ¦ Ä Ç´¦ dˆ ǘ¦  ÇȦ   ÇĦ R$ ÿØ …ÀtS‹=€¤ Vh€ jVjh €…ôýÿÿPÿ ÿ50 £€¤ …ôýÿÿPè²# …À…˜ ‰=€¤ ‰0 é‡ ‰0 èòÿÿéw jè ék ‹=Ä » ¤ ë,ÿà =  t=  t=  uÂè ëÿÿ‰5¬¤ ‰5¨¤ Sÿ×…ÀtÍ‹5ü h@£ h࣠ÿÖh£ h0¤ ÿÖé ƒït;Ot(ƒï„÷ O…ŽýÿÿVVhÇ ÿ58˜ ÿ@ éØ VVjRÿ¤ éÈ Vè¦? é½ ƒÿf „U ƒï„ô O„“ Ot^O…2ýÿÿÿ50˜ ÿd ‹=@ VVjÿ58˜ ‹Øÿ×PVh± ÿ58˜ ÿ×VVh· ÿ58˜ ÿ×jjjSÿ` Pÿ\ é= Vh¦! ÿ50˜ jÿ5€« ÿ˜ …À… ÿ5”« èBìÿÿé  ¡<˜ ;Æt Pÿx éö h ¥ Ç ¥   Ç¥  § fÇ¥ € Ç¥  ¨ fÇ¥ € ÿÜ £<˜ é± f95 ¨ th ¨ èƒ) é™ ¡<˜ ;ÆuŽh ¥ Ç ¥   ‰5¥ f‰5¥ Ç¥  ¨ fÇ¥ € ÿÈ ëžVèü> éN j[+û„÷ ƒï„ O…ÑûÿÿVÿ” ‹Ø;Þ„" ‹…ðýÿÿhÐ jZ¿ « SÇ… ýÿÿ< ‰…¤ýÿÿ‰½¬ýÿÿÿ` Pÿ5 ÿ, S÷ØV£ « Ç…´ýÿÿA ‰µ¸ýÿÿ‰µ¼ýÿÿ‰µÀýÿÿ‰µÄýÿÿ‰µÈýÿÿ‰µÌýÿÿfÇ…Ðýÿÿ ‰µÔýÿÿ‰µØýÿÿÿ … ýÿÿPÿÐ …À„ ÿ5„« ‹Œ ÿÓWÿd ‹ø;þt.ÿ5|« ÿh jWj0ÿ58˜ ‰=|« ÿ@ ‹…°ýÿÿ£ ÿ5ˆ« ÿÓé) ¡P˜ ÷ØÀ%   PPèê) …Àt3À95P˜ ”À£P˜ ëj0ÿ5T ÿ5l ÿ50˜ ÿh 95P˜ tP¡@˜ ;Æ£D˜ tVSh ÿµðýÿÿÿ@ ÿ50˜ ÿd V‹5` S‹øjWÿÖPÿH jSjWÿÖé?ýÿÿÿ50˜ ÿd VSjPÿ` Pÿ\ 95D˜ „^ VSh ÿµðýÿÿéiüÿÿ…àýÿÿPÿ50˜ ÿˆ 95@˜ t7Vÿ54˜ ‰5@˜ ÿ° ‹…ìýÿÿ+…äýÿÿP‹…èýÿÿ+…àýÿÿPèxçÿÿéú ‹…ìýÿÿ+…äýÿÿ3öP‹…èýÿÿ+…àýÿÿFP‰5@˜ èKçÿÿVè§éÿÿjÿ54˜ ÿ° é¹ VVhè ÿä Pè@ é¡ ƒÿAtvÿÿ Ž.ùÿÿÿ ~ÿ t9ÿ …ùÿÿ…ÜýÿÿP…ðýÿÿPh° ÿ58˜ ÿ@ ‹…ðýÿÿ;…ÜýÿÿtGÿè ‹
8˜ ;Át;0˜ u/VVWQéSûÿÿjÿ5€« ÿì Ph” ÿ5T ÿ50˜ ÿ€ 3À@‹Mü_^[èÒ= É ÌÌÌÌÌ‹ÿVW‹=€¤ 3öVèóÿÿ…Àt@Vh€ jVjh €¾(– Vÿ ƒøÿ£€¤ uVè` ë jÿVè¯ …Àu‰=€¤ _^ÃÌÌÌÌÌ‹ÿU‹ìV‹5x j j jÿÿuÿÖ…Àth h(– j ÿuÿÖÿu ÿœ èhÿÿÿÿuÿt ^] ÌÌÌÌÌ‹ÿU‹ìQQV‹u ƒþWjZ‡A „· ;ò‡í „Û ‹ÆHH„Ç ƒètaHtH…\ ÿ50˜ ÿ¸ …Àu?ÿ58˜ ë1fƒ}tfƒ}u)ÿ50˜ ÿ¸ …Àu‹5´ ÿÖ;0˜ u ÿÖPÿx 3À_^É ‹E3ö+ÆtHtIHué‹=@ VVjÿ54˜ ÿ׿ujYv™÷ùƒMüÿ‰EøEøPjh ÿ54˜ ÿ׿EPVèÈäÿÿë£ÿujjé­ j ÿô ëÿuÿuRéÁ ‹ÆƒètIHtƒè „nÿÿÿév 3ö95T˜ t"‹=¬ Vÿ×Vÿ×h  ÿ5T ÿ5” éŠ jèˆñÿÿé3ÿÿÿè¨ 3öVèvñÿÿ…À„ÿÿÿVjÿ5t ÿ50˜ ÿ( …Àuh ÿ5T ÿ5L ÿ50˜ ÿh ÿ54˜ ‹5¨ ÿÖÿ50˜ ÿÖÿ5|« ÿh é¿þÿÿ3ö9ut@¡\˜ ;Æ‹
`˜ u;΄¡þÿÿ‹=@ QPh± ÿ58˜ ÿ×VVh· ÿ58˜ ÿ×éxþÿÿ‹=@ h`˜ h\˜ h° ÿ58˜ ÿס\˜ ‹
`˜ ;Áu±‰5\˜ ‰5`˜ é;þÿÿ‹}‹Æ- „5 H„ê ƒè„Ô H„™ - „~ -æ „O -è| „ ;5ˆ¤ …ö ‹E‹H ‹Á‹ñÁî÷Ѓàƒæ„Ê£”š ‰5š tÿ5„« ‹5Œ ÿÖëöÁt,ÿ5„« ‹5Œ ÿÖjè[éÿÿh ¨ è" ÿ5ˆ« ÿÖé‚ýÿÿöÁ tw3ö;Æt‰5”š Sÿ5„« ‹Œ ÿÓ‹=@ VVh± ÿ58˜ ÿ×Vè éÿÿh ¨ èÌ! …Àuìÿ5ˆ« ÿÓVVh± ÿ58˜ ÿ×VVh· ÿ58˜ ÿ×jè‘äÿÿ[éýÿÿöÁ@„ýüÿÿƒ%<˜  éñüÿÿÿuÿuVÿuÿ¤ éÞüÿÿ3öVÿ  f%ÿf= uFVjhØ ÿ58˜ ÿ@ é¯üÿÿ‹ÇÁèf%ÿf= …¦ j jÿuèZóÿÿé‹üÿÿÿuÿuèŸûÿÿé{üÿÿƒ=L˜  „nüÿÿ‹EÁèf…À„_üÿÿjh ð ÿ5ܦ ÿ\ éGüÿÿÿuèõäÿÿé:üÿÿƒ=L˜  ‹Et!= ð „#üÿÿ=@ð „üÿÿ=Pð „
üÿÿÿuPh ÿuÿ¤ éöûÿÿ;=8˜ uL‹EÁèf= tf=u:ƒ=H˜ uÇH˜  éÄûÿÿh ÿ5T ÿ5L ÿ50˜ ÿh é¢ûÿÿWÿuÿuè`òÿÿ…À…ŽûÿÿWéšþÿÿÌÌÌÌÌ‹ÿU‹ìjEPjj ÿu ÿuÿ ] ÌÌÌÌÌ‹ÿU‹ìÿuÿä D Pÿujj ÿu ÿuÿ ] ÌÌÌÌÌ‹ÿU‹ìƒì ƒeü ƒ} ÇEø ÇEô t$EôPEøPEüPj ÿu ÿuÿ  …Àuƒ}üt‹Eë‹EøÉ ÌÌÌÌÌ‹ÿU‹ìV‹uöƒ} W‹}‰ut!EPWEPj ÿu ÿuÿ  …Àuƒ}t‹Î‹u‹ÁÁéó¥‹Èƒáó¤_^] ÌÌÌÌÌ‹ÿU‹ìƒì0EüPh¤ h €ÿ …À…. ÿ5(« hˆ ÿuüèÊþÿÿÿ5,« hl ÿuüè·þÿÿÿ50« hX ÿuüè¤þÿÿ¶4« PhD ÿuüèþÿÿ¶5« Ph, ÿuüèzþÿÿ¶6« Ph ÿuüèeþÿÿ¶7« Ph  ÿuüèPþÿÿ¶8« Phà ÿuüè;þÿÿ¶9« PhÀ ÿuüè&þÿÿ¶:« Ph¬ ÿuüèþÿÿ¶;« Phˆ ÿuüèüýÿÿÿ5 hp ÿuüèéýÿÿÿ5P˜ hd ÿuüèÖýÿÿÿ5@˜ hP ÿuüèÃýÿÿÿ5„š h$ ÿuüè°ýÿÿh<« h  ÿuüèÂýÿÿh࣠hø ÿuüè°ýÿÿh0¤ hä ÿuüèžýÿÿÿ5Ф hÌ ÿuüègýÿÿÿ5ؤ h° ÿuüèTýÿÿÿ5̤ h˜ ÿuüèAýÿÿÿ5Ô¤ h| ÿuüè.ýÿÿÿ5X˜ h\ ÿuüèýÿÿEÐPÿ50˜ ÇEÐ, ÿ¼ …ÀtHÿuìhD ÿuüèðüÿÿÿuðh, ÿuüèàüÿÿ‹Eô+EìPh ÿuüèÌüÿÿ‹Eø+EðPhô ÿuüè¸üÿÿÿuüÿ ÉÃÌÌÌÌÌ‹ÿU‹ìƒìd¡– VWj‰EüÿX 3ÿ;Çt
M Qj\Pÿ\ EœPh¤ h €ÿ …Àt‰}œÿu¨‰=$« hˆ ÿuœèüÿÿÿu¬£(« hl ÿuœèˆüÿÿÿu°£,« hX ÿuœèsüÿÿ£0« ¶E´PhD ÿuœè\üÿÿ¢4« ¶EµPh, ÿuœèEüÿÿ¢5« ¶E¶Ph ÿuœè.üÿÿ¢6« ¶E·Ph  ÿuœèüÿÿ¢7« ¶E¸Phà ÿuœè üÿÿ¢8« ¶E¹PhÀ ÿuœèéûÿÿ¢9« ¶EºPh¬ ÿuœèÒûÿÿ¢:« ¶E»Phˆ ÿuœè»ûÿÿj h<« hÜ h  ÿuœ¢;« èòûÿÿjdhp ÿuœèŽûÿÿWhd ÿuœ£ è{ûÿÿ£P˜ WhP ÿuœèhûÿÿWh$ ÿuœ£@˜ èUûÿÿj(£„š ¸à£ PPhø ÿuœèûÿÿj(¸0¤ PPhä ÿuœèyûÿÿÿ5Ф hÌ ÿuœèûÿÿÿ5ؤ £Ð¤ h° ÿuœèùúÿÿÿ5̤ £Ø¤ h˜ ÿuœèáúÿÿÿ5Ô¤ £Ì¤ h| ÿuœèÉúÿÿ¾ €Vh, ÿuœ£Ô¤ è±úÿÿVhD ÿuœ£|š èžúÿÿVh ÿuœ£xš è‹úÿÿVhô ÿuœ£tš èxúÿÿWh\ ÿuœ£pš èeúÿÿ9}œ_£X˜ ^t ÿuœÿ ‹Müè2 ÉÃÌÌÌÌÌ‹ÿU‹ìQSVW‹ù‹Øf‹f…Àt'‹5À ·ÀPÿÖ‰Eü·GGCPCÿÖf9Eüuf‹f…Àuß3À_^[ÉÃ3À@ëöÌÌÌÌÌ‹ÿU‹ììT ¡– S‹]V‹u ‰Eüf‹f=" W‹Ëtf=' th VSÿ0 ë+3ÒF‹øFëf;Çtú sf‰AABFF3Àf‹f…Àuáfƒ! ‹=  …¬ýÿÿPSÿ׃øÿuSè²
…¬ýÿÿPSÿ׃øÿtPÿ ‹Mü_‹Æ^[è 1 É ÌÌÌÌÌ‹ÿU‹ìQSVW¾ h0 ë?3ÿ3Û‹½è Vÿuüÿ0ÿuÿÄ Nÿ;Á}
Gƒÿ-\|ÙÿuüÿÜ ƒÿ-}ö6Pj@ÿà …À‰Eüu²ë‹Ã_^[É ÌÌÌÌÌ‹ÿU‹ìÿuè€ÿÿÿ…À„Š VÀPj@ÿà ‹ð…ötwSVÿ4 ‹ØÑëu3ÀëdW¿è ‹SVÿ0ÿuÿÄ ‹@;É14FIƒÇ+؁ÿœ‘ |Ø‹50 j(ÿ5x h࣠ÿÖj(ÿ5| h0¤ ÿÖ¡p f‹ f£« 3À@_[^] j h0 hü j ÿh 3ÀëáÌÌÌÌÌ‹ÿU‹ì‹Ef‹fƒù tfƒù u@@ëí] ÌÌÌÌÌ‹ÿU‹ìQSV‹uW3ÿ‹Æ¹\ ‰}üè‘ýÿÿ…À…( Wÿ50˜ ÇL˜  ÿÌ hH ÿ5€« £Ü¦ ÿÈ h ý jðÿ50˜ £Ø¦ ÿl ƒÆVèiÿÿÿf98„Ì P¾ © VèsýÿÿW»€ SjW‹= jh €Vÿ׃øÿ£€¤ …„ ÿ8 HHt9ƒèj1Vt)ƒèvtÿ54 ÿ5T ÿ50˜ èôÜÿÿ‰EüëHÿ5d ëâÿ5œ ëÚj3Vÿ58 ÿ5T ÿ50˜ èÅÜÿÿƒø‰Eüuj Sjj jh ÀVÿ×£€¤ ƒ=€¤ ÿtÿ5€š Vè› jX9EütjXë3À_^[É ÌÌÌÌÌ‹ÿU‹ìQV‹uW‹Æ¹t ÇEü è5üÿÿ3ÿ…ÀuƒÆVèTþÿÿ‰}üë‹Æ¹l èüÿÿ…À…  ƒÆVè2þÿÿ‹ðf9>„ø ÿu ÿ50˜ ÿ° V¾ © Vè+üÿÿ@@9}üuJf98„Í Pèöýÿÿfƒ8"…½ @@3Òëfƒù"túÿ sf‰ U@¡ B@@3Éf‹f;ÏuÝf‰<U@¡ Wh€ jWjh €Vÿ ƒøÿ£€¤ uJÿ8 HHt$ƒètƒè<tƒè:t¡4 ë¡d ë ¡œ ë¡8 j0VPÿ5T ÿ50˜ èHÛÿÿëÿ5€š VèC
9}ütjëjè* 3À@ë3À_^É ÌÌÌÌÌ‹ÿU‹ìS‹]V‹5ü Wÿ5„ SÿÖ‹=ä Sÿ׍\ChÌ SÿÖSÿ×ÿ5ˆ \CSÿÖSÿ׍\Ch| SÿÖSÿ×fƒdC _^[] ÌÌÌÌÌ‹ÿU‹ì‹EŠ@‹MˆA3À] ÌÌÌÌÌ‹ÿU‹ìƒì0Wj)ÇEÐ0 ÿ ÷ØÀ P3ÿWÿØ jV‰Eìÿì WjjjjV‰EèÿÔ ‰EüEÐPÇEô ‰uäÇEø  ÇEØ)4 ÇEð ‰}Ô‰}܉}àÿÐ f÷Ø_À÷ØÉÃÌÌÌÌÌ‹ÿU‹ìì¨ ¡– SV‹uW‹=ø ‰Eü‹EhÌ ‰u¬‰E°ÿ×3Û;㈤ „  h° ÿ×;ㄤ „÷ Sÿ” ;ÉE¸„å Vèëúÿÿ…À„× j)ÿ ‹=Ø ÷ØÀ PSÿ×h S£ˆ« ÿ×h  V£„« ÿÈ 9„« £Ø¦ „ ;Ä… 9] u
è¤þÿÿ…À„s ‰5€« Ç ¤ T ‰¨¤ ‰¬¤ ‰5ܤ èûÒÿÿè+öÿÿSVSSÿ5pš ¾” ÿ5tš ÿ5|š ÿ5xš h Ï Vh  Sÿà ‹Ð;Ó‰0˜ ‰¤¤ „þ ¸ €9tš tb9pš tZ3Àj Y½Xÿÿÿó«¡xš ‹
tš ‰…tÿÿÿÁ‹
pš ‰…|ÿÿÿ¡|š ‰…xÿÿÿÁ‰E€…XÿÿÿPRÇ…Xÿÿÿ, ÿÜ ‹0˜ jRÿ| ‹=ˆ E„Pÿ50˜ ÿ׋ESÿu¬ƒÀœjÿ50˜ PÿuŒ¡P˜ ÷ØSÀS% ðÿ0PPVh” h  ÿà ;ã8˜ „* ¡@˜ ÷Øh ÿ50˜ À% V
€DPÿ  ;ã4˜ „÷ jè„ÔÿÿE”Pÿ54˜ ÿ׋E +E˜j£à¦ ‹Eœ+E”Y@™÷ù‹5@ ƒM¨ÿ‰E¤E¤Pjh ÿ54˜ ÿÖSÿ5P˜ hÈ ÿ58˜ ÿÖ9P˜ t ÿ50˜ ÿd jjjPÿ` Pÿ\ hÐ jZÿu¸ÿ` Pÿ5 ÿ, ÷Ø¿ « W£ « ÿd Pÿu¸£|« ÿ„ ‰E´E¼Pj ÿu¸ÿH ÿu´ÿu¸ÿ„ h<« E¼Pÿ …Àt,Wh»D h<« ÿu¸ÿT ÿ5|« ÿh Wÿd £|« Sÿ5|« j0ÿ58˜ ÿÖÿu¸Sÿ jjBf‰ ¨ ÿà SShÅ ÿ58˜ £Œ« ÿ¤ ÿ5@ è*áÿÿÿuÿ50˜ ÿ° ÿ5ˆ« ÿŒ ÿu°è,øÿÿƒ
€š ÿ¹Œ ‹øèëõÿÿ…Àu‰€š ë#‹Ç¹„ èÓõÿÿ…Àu
Ç€š  ƒ=€š ÿt ƒÇWèá÷ÿÿ‹øWèý÷ÿÿ;Ãtƒø…í 3À‹Mü_^[èŒ' É ÿuWè1ùÿÿ…ÀtSSjÿ50˜ ÿ¤ éw f9„± W¿ © Wè£õÿÿSh€ jSjh €Wÿ ƒøÿ£€¤ uxÿ8 ƒøuFj3Wÿ58 ÿ5T ÿ50˜ è4Õÿÿƒø„iÿÿÿƒøu<Sh€ jSjh ÀWÿ £€¤ ëWè² ÿ5@ èÜßÿÿÿ5@ Wÿü ƒ=€¤ ÿt ÿ5€š WèÞ hॠè³ùÿÿh@¥ è©ùÿÿ‹0˜ jY3Àj
¿€¦ ó«‹E¬Y£ˆ¦ 3À¿ ¥ ó«E°PE´Ph° ÿ58˜ Ç€¦ X ‰„¦ Ç ¦  Ç ¥ ( ‰¥ ÿÖÿu°ÿu´h± ÿ58˜ ÿÖSSh· ÿ58˜ ÿÖSÿ  f%ÿf= ujjhØ ÿ58˜ ÿÖ3À@éPþÿÿÌÌÌÌÌ‹ÿU‹ìV‹u…öv‹E ‹MSf¶P3ÛŠ83Óf‰AA@@Nuë[^] ÌÌÌÌÌ‹ÿU‹ìƒìS3Û9]u3À@éŽ } éý ‰]ütEô‰EüV‹5D WÿuüSSSÿuÿuÿuÿu ÿÖ‹ø;ûtGPj@ÿà ;ÉEøu jÿ@ 3Àë9ÿuüSWPÿuÿuÿuÿu ÿÖ‹ð;ótSEðPWÿuøÿuÿ< ‹ðÿuøÿÜ ‹Æ_^[É ÌÌÌÌÌ‹ÿW3ÿ9=P˜ tN9=X˜ V‹5@ t jè-Ïÿÿë&hˆš hŒš h° ÿ58˜ ÿÖWWh± ÿ58˜ ÿÖWWhÈ ÿ58˜ ÿÖ^_ÃÌÌÌÌÌ3À9P˜ tD9X˜ t h Pèz ÃV‹5@ PjhÈ ÿ58˜ ÿÖÿ5ˆš ÿ5Œš h± ÿ58˜ ÿÖ^ÃÌÌÌÌÌ‹ÿU‹ìS3Û9]tSèýÙÿÿ…À„© V‹5@ Wh” Sj ÿ58˜ ÿÖÿ5@ ¿ © Wǐ  ÿü WèÝÿÿSSh± ÿ58˜ ÿÖSSh· ÿ58˜ ÿÖjjÿ5Œ« ÿH ;Ãt£Œ« ÿ5Œ« ÿð f‰ÿ5Œ« ÿè Sÿ5Œ« h¼ ÿ58˜ ÿÖ_f‰ ¨ ^[] ÌÌÌÌÌ‹ÿU‹ìV‹uVÿä  Fëƒú\tƒú:t;Îv
II·ƒú.uèfƒ9.tƒÀ= w hô Vÿ ^] ÌÌÌÌÌ‹ÿU‹ìì ¡– V‹uj ‰Eüh  …üýÿÿPÿP ·ÀPÿ8 Pj h  ÿL …Àj0tÿ5T …üýÿÿPÿ50˜ ÿh ëVÿ54 ÿ5T ÿ50˜ èÔÐÿÿ‹Mü^è¢" É ÌÌÌÌÌ‹ÿU‹ìƒìV3ö9uVh€ j‰uðVujëjh Àÿu ÿ ƒøÿ£€¤ tÿ8 3É=· •Áƒ=€¤ ÿ‰Mìu j0ÿu ÿ5h ÿ5T ÿuèSÐÿÿ3ÀéÚ 95P˜ tèýÿÿSW‹=@ VVjÿ58˜ ÿ×VVh½ ÿ58˜ ‹Øÿ×;ƉEô„I Pÿð ;ƉE„7 ¡(¥ H„ë H„š HuVEüPjhà‘ ÿ5€¤ ÿ< ƒ=(¥ tÿ\ ‰EøEð¿  ë 3ÀÇEøéý 3ÿPVVVSÿuWÿuøÿD 9uðu;Þt(;Æu$j1ÿu ÿ5  ÿ5T ÿuèpÏÿÿƒø„© 3ÿSÿuWÿuøÿ5€¤ è{ûÿÿëx‹=< VEüPjhè‘ ÿ5€¤ ÿ×SÿuÿuèûÿÿVEüPPÿuÿ5€¤ ÿ×Sÿu‹øÿuèýúÿÿë0‹=< VEüPjhä‘ ÿ5€¤ ÿ×VEüPPÿuÿ5€¤ ÿ׋ø;þueÿ5ˆ« ÿŒ ÿu ènýÿÿÿ5ˆ« ÿŒ ÿ5€¤ ÿø ƒ
€¤ ÿ9uôt ÿuôÿè 9uìt ÿu ÿX 95P˜ tè±ûÿÿ3À_[^É ÿ5€¤ ÿT ¡(¥ VVh¹ ÿ58˜ £0 ÿ@ ÿu è!Ùÿÿÿ5€¤ ‰5 ÿø ÿuôƒ
€¤ ÿÿè 95P˜ tèHûÿÿÿ5ˆ« ÿŒ 3À@ëˆÌÌÌÌÌh€ h  èà# ¡– ‰Eä‹}‰½Àýÿÿ3Û‰Ìýÿÿ‰°ýÿÿ‰Èýÿÿ‰¸ýÿÿ‰Ðýÿÿ¡€¤ ƒøÿuWé× pýÿÿQPÿ° ‹µ”ýÿÿ‰µ¬ýÿÿ;Ãu Wè3üÿÿéï þ @ƒÉ 9ýÿÿ…½ ÿ5„« ÿŒ ;ótD3ÿ‰½ÄýÿÿSVSjSÿ5€¤ ÿ´ ‰…¤ýÿÿ;Ãt9VSSjPÿh ‰…Äýÿÿÿµ¤ýÿÿÿø 덅´ýÿÿ‰…Äýÿÿf‰´ýÿÿ‹½Äýÿÿÿ5€¤ ÿø ƒ
€¤ ÿ;ûuÿ5ˆ« ÿŒ ÿµÀýÿÿè{ûÿÿéJ ‰]ü‰½¼ýÿÿ‹E ƒøÿ…² ·=ï» t<=ÿþ t$=þÿ u[Ç…Èýÿÿ Ç…Ôýÿÿ ‹ÞÑëé0 3À@‰…Èýÿÿ‰…Ôýÿÿëæƒþv(€¿u"Ç…¨ýÿÿ Ç…Ðýÿÿéý jX‰…Ôýÿÿé˜ VWèx ‰…Èýÿÿ;ÃtÇ…Ôýÿÿ ‹ÞÑëéÏ VWèü ‰…¨ýÿÿ;Ä Ç…Ôýÿÿ Ç…Ðýÿÿéý ‹Øýÿÿ3À9…Èýÿÿu PPVÿµ¼ýÿÿPÿµÐýÿÿÿd ‹Ø‰Øýÿÿ3ÀPPj ÿ58˜ ‹5@ ÿÖj j h± ÿ58˜ ÿÖj j h· ÿ58˜ ÿÖjDPÿ5Œ« ÿH ‰…¸ýÿÿ…À…, ÿµÀýÿÿ…ÜýÿÿPÿü 3ÛSèàøÿÿÿ5ˆ« ÿŒ j0…ÜýÿÿPÿ5P ÿ5T ÿ50˜ è%Ëÿÿ…´ýÿÿ;øtWÿ` SSj ÿ58˜ ÿÖƒMüÿéƒ H„ˆ HteHt‰Ôýÿÿ‰ÐýÿÿéðþÿÿÇ…¨ýÿÿ Ç…Ðýÿÿéý jX‰…Ôýÿÿƒþ†Êþÿÿf?ï»…¿þÿÿ€¿…µþÿÿO‰¼ýÿÿ+ð‰µ¬ýÿÿéŸþÿÿ3À@‰…Èýÿÿ‰…Ôýÿÿ‹ÞÑ뉝Øýÿÿf?þÿë3À@‰…Èýÿÿ‰…Ôýÿÿ‹ÞÑ뉝Øýÿÿf?ÿþ…aþÿÿK‰ØýÿÿéUþÿÿPÿð ‰…Ìýÿÿƒ½Èýÿÿ tFf‹fùÿþuwëfùþÿu
SOQPèþõÿÿëG‹÷ ‹ø‹ÁÁéó¥‹Èƒá󤋽Äýÿÿ‹5@ ë$SPÿµ¬ýÿÿÿµ¼ýÿÿj ÿµÐýÿÿÿd ‹Ø‰Øýÿÿ‹…Ìýÿÿ‹Ôýÿÿ‰
0 ƒMüÿë>3À@Ëeèj0ÿµÀýÿÿÿ54 ÿ5T ÿ50˜ è‚Éÿÿ3ÛƒMüÿ‹½Äýÿÿ‹5@ ‹…Ìýÿÿ´ýÿÿ;ùt
Wÿ` ‹…Ìýÿÿ3ÿ;ÇtR‹È;ßv‹Óf99ufÇ AAJuñf‰<Xf‹@@fƒù.u&f‹@@fƒùLuf‹@@fƒùOufƒ8GÇ…°ýÿÿ t‰½°ýÿÿ9½¸ýÿÿtÿµ¸ýÿÿÿè ‹…¸ýÿÿ£Œ« ÿµÀýÿÿh © ÿü ÿµÀýÿÿè¥Óÿÿ‰= ÇH˜  Wÿ5Œ« h¼ ÿ58˜ ÿÖƒ=H˜ uIÿ5ˆ« ÿŒ ‰=H˜ j0ÿµÀýÿÿÿ5P ÿ5T ÿ50˜ èbÈÿÿWèëõÿÿWjj ÿ58˜ ÿÖéÎ ‰=H˜ WWhÅ ÿ58˜ ÿ¤ 9½°ýÿÿt%SSh± ÿ58˜ ÿÖWWh· ÿ58˜ ÿÖjè¤ 3ÛCSWh¾ h ÿ58˜ ÿÖPSÿ50˜ ÿ  WSj ÿ58˜ ÿÖSWÿ58˜ ÿ$ ÿ58˜ ÿü ÿ5ˆ« ÿŒ ‹Ãë/j0Wÿ5P ÿ5T ÿ50˜ èÇÿÿÿ5€¤ ÿø ƒ
€¤ ÿ3À‹MäèI è  Â ÌÌÌÌÌ‹ÿU‹ìQQSV‹u·WPÿÀ ‰Eü·Pÿ ‹=ä V‰Eøÿ׋] …Û‰Eu\‹]Sÿ׍CëQKKƒ} f‹tf;ë
f;Eütf;Eøu5ƒ} tÿuVSÿ ƒÄ …ÀëÿuVÿuSh h  ÿì ƒøt ;]uª3Àë‹Ã_^[É ÌÌÌÌÌ‹ÿU‹ìQSV‹u WVÿä ‹Ø·PÿÀ ‰E ·Pÿ ‹}‰EüëBƒ} tf;u5SVWÿ ƒÄ …Àë#f;E tf;EüuSVSWh h  ÿì ƒøt
GGf‹f…Àu¶f‹f÷ØÀ#Ç_^[É ÌÌÌÌÌ‹ÿU‹ìƒì$‹ES3Ûf9‰]è‰]ìu3ÀéË V‹5@ WEðPEüPh° ÿ58˜ ÿÖÿ50˜ ÿd Sj3ÿGWP‰EÜÿ` PÿX ;Çu ‰}ì‰]ð‰]üSSh½ ÿ58˜ ÿÖ;ÉEàt
Pÿð ‹ø;ûu3ÀéQ 9”š tsSÿuühÉ ÿ58˜ ÿÖSPh» ÿ58˜ ‰EøÿÖ‹Mø‰Mø‹Müë$ƒ}ø ‹Eô‰EätPÿMøj ÿuøh» ÿ58˜ ÿÖ‹Mäÿ5š  Oÿu‰EôGQPè´ýÿÿ‹Ø…Ût½ëÿ5š ‹EðÿuGPèDþÿÿ‹Øÿuàÿè …ÛuIö ¥  …¢ ÿ5ˆ« ‹5Œ ÿÖ‹ø¡<˜ …Àu¡0˜ j@h ¨ ÿ5H ÿ5T Pè©ÄÿÿWÿÖëfÿu+ßÑû‰]üÿä EüPÿuüh± ÿ58˜ ÿÖ3ÿ9}ìtWjjÿuÜÿ` Pÿ\ ö ¥  uWWh· ÿ58˜ ÿÖjèÁÿÿÇEè ‹Eè_^[É ÌÌÌÌÌ‹ÿU‹ìƒì8S‹Œ V‹uWÿ5„« Áîƒæ‰uôÿÓ3ÿ;÷‹5@ ‰EøtjèÀÿÿWWhÈ ÿ58˜ ÿÖWWh¸ ÿ58˜ ÿÖW÷ØWÀjÿ58˜ ÷؉EèÿÖ‰EðD Pjÿà ;ljEüu9}ôtWjhÈ ÿ58˜ ÿÖÿuøÿÓéð EÈPÿ50˜ ÿˆ ÿuüÿð P‰Eì‹Eð@Pj
ÿ58˜ ÿÖWÿ5€« jÿ50˜ ÿuÔÿuÐWWÿuh” h” h  ÿà ;ljEuÿuøÿÓ9}ôtrWjhÈ ÿ58˜ ÿÖë`jìÿ58˜ ÿp 
 Pjìÿuÿl jÿ5|« j0ÿuÿÖÿuìWj ÿuÿÖ…Àu<ÿuøÿÓ9}ôtWjhÈ ÿ58˜ ÿÖÿuÿ¨ ÿuüÿè ÿuüÿÜ 3Àé» ÿuüÿè ÿ58˜ ÿ¨ ‹E£8˜ ¡Œ« ;ÇtPÿÜ ‹EüWWhÅ ÿ58˜ £Œ« ÿ¤ jÿ50˜ ÿ° Wÿuèh¹ ÿ58˜ ÿÖÿ58˜ ÿx ÿuøÿÓ9=@˜ t8EØPÿ50˜ ÿˆ ‹Eä+EÜP‹Eà+EØPèa¼ÿÿjè¼¾ÿÿjÿ54˜ ÿ° 3À@_^[É ÌÌÌÌÌ‹ÿU‹ìƒìV3öë?jVVVEäPÿ …Àt4¡8¡ ;ÆtMäQPÿ  …ÀuEäPÿ˜ EäPÿ” 954¡ t¹3À954¡ ^”ÀÉ ÌÌÌÌÌ‹ÿU‹ìV‹5` W‹}jWÿÖj
W£èš ÿÖjZW£äš ÿÖjnW£àš ÿÖjoW£Üš ÿÖjpW£Øš ÿÖjqW£Ôš ÿÖ_£Ðš ^] ÌÌÌÌÌ‹ÿU‹ìƒìT‹¬¤ …ÒSV‹5Ä W»ûÿÿuf
°¤ €h ¤ ÿÖ!°¤ ‹¬¤ 3ÀjY}¬ó«¡0˜ ‰E°¡¨¤ ƒÏÿ…ÀÇE¬T ‰}øÇEÀ „ t‰E´…Òt‰U¸E¬PÿÌ …Àu@ƒ}ütƒ}üu4ë‹}¼ƒ=¨¤  uf
°¤ €h ¤ ÿÖ!°¤ ‹E´£¨¤ ‹E¸£¬¤ ‹Ç_^[ÉÃÌÌÌÌÌjÿ50˜ ÿ  ÿ58¡ ÿ¨ ƒ%8¡  ÃÌÌÌÌÌ‹ÿU‹ìQQ‹E HHVW„ì ƒèQ„» ƒè(t\-• …ô ‹5< Sj_»à£ j j'hÅ WÿuÿÖSWÿuÿ| ƒÃPGû0¤ ~Úh ' j h± jÿuÿÖ3À@[é¥ ‹u9uu(EøPÿ8 EøPÿuÿ4 ÿuüÿuøÿuÿ0 ‹ðVÿ, ƒø|gƒø!bh  j
ÿ5t Vÿ( 3À@ëK‹uÿv ÿ, ƒø|8ƒø!3h  j ÿ5t ÿv ëÍj_¾@£ j(VWÿuÿ„ ƒÆPGþ£ ~ç3À_^É ÌÌÌÌÌ‹ÿU‹ìì$ ¡– SV‰EüW‹}3ۍ…Üýÿÿ3öP‰½ðýÿÿF‰àýÿÿ‰äýÿÿ‰èýÿÿÿø …ÜýÿÿPÿü YYf‹f;Ë„ÿ ¡€ ë4fƒù&tIƒ…ðýÿÿ‹ÞiÛ ”µàýÿÿ‹:ßf‰ ] › ‹ðýÿÿ· G‰:f…É‹ä uÁ‹ðýÿÿfƒ9&…— ƒ…ðýÿÿ‹ðýÿÿf‹ f;„ù f;H„ï f;H„4 f;H„* f;H„Ï f;H
„Å f;H „Ž f;H„„ fƒù&u?Œµàýÿÿ‹zÿ ‰½ìýÿÿ
 ‹þiÿ ú‹•ìýÿÿfÇ} › & ‰éì f;Ht1f;Ht+f;Htf;Htf;Ht
f;H…Ä 3öé½ j^éµ 3öFé­ hð‘ ÿӍ¼µàýÿÿ‹ú ‰•ìýÿÿƒ Phð‘ ë+hø“ ÿӍ¼µàýÿÿ‹ú ‰•ìýÿÿV Phø“ ‹ÆiÀ ÁE › Pÿ@ ‹…ìýÿÿƒÄ é( ƒ…ðýÿÿ‹…ðýÿÿ3ÿfƒ8+u,ë‹…ðýÿÿ· ¿|JÐ@@‰…ðýÿÿ· jPÿ …ÀYYuÖ¡¼š ÇP…ôýÿÿh˜ Pÿ€ ƒÄ …ôýÿÿP¼µàýÿÿÿÓ‹È‹ȁù },ôýÿÿQ‹ÎiÉ ȍM › Pÿü …ôýÿÿPÿÓ‰ƒ­ðýÿÿëyƒ=  …ôýÿÿuh Ph © ÿÔ ë
ÿ5@ Pÿü …ôýÿÿP¼µàýÿÿÿÓ‹È‹ȁù },ôýÿÿQ‹ÎiÉ ȍM › Pÿü …ôýÿÿPÿÓ‰¡€ ƒ…ðýÿÿ‹ðýÿÿf‹ f…É…ýÿÿ_^3ɍ…àýÿÿ[‹Ñfƒ$U ›  Á ƒÀù ~â‹Müè(
É ÌÌÌÌ̃=¬¤  u@€
±¤ h ¤ ÿÄ €%±¤ ûƒ=¬¤  uj0ÿ5T ÿ5˜ ÿ50˜ ÿh ƒÈÿÃVWÿ5¬¤ ‹=¨ ÿ׋
¨¤ ‹ð3À…ÉtQÿ×P·FFj P·FPÿ@ ÿ5¬¤ ‹5¬ ‹øÿÖ¡¨¤ …ÀtPÿÖ…ÿuj0ÿ5T ÿ5˜ ÿ50˜ ÿh ƒÈÿë‹Ç_^ÃÌÌÌÌÌ‹ÿU‹ìQQSW3ÛSEüP¿@¡ Wè„ …ÀuƒÈÿé¨ VEøPSSjSÿuüèZ ÿuøj@ÿà ‹ð;óu
ÿuüè5 ƒÈÿëwEøPÿuøVjSÿuüè) …Àu VÿÜ ëÓ€
±¤ h ¤ ÿÄ €%±¤ ûSSWÿ6ÿ@ V‹øÿÜ ÿuüèÛ
;ûuj0ÿ5T ÿ5˜ ÿ50˜ ÿh 놋Ç^_[ÉÃÌÌÌÌÌ‹ÿU‹ì‹E - t2Htƒèt3Àëhjh`ð ÿ5˜š ÿ\ ëPÇ4¡  è2ùÿÿë?j ÿuÿÌ ƒ=  £˜š t¡@ ë
h © èõ¶ÿÿPjÿuÿ| ÿuÿx 3À@] ÌÌÌÌÌ‹ÿU‹ìQQSV‹u ¶Áà€à£ 3Ûf9u3Àéë Pèúÿÿ;óu¡Ìš ë¡äš +0¡ +Èš f9 › ‹5ä ‰E Wt¿ › WÿÖPWÿu ÿ5Äš ÿuÿL f9 tKEøP» SÿÖPSÿuÿ< ¡èš +Àš SÄš ™+‹ø‹Eø™+ÂÑøÑÿ+øÿÖPSÿu WÿuÿL fƒ=Ÿ  t8EøP»Ÿ SÿÖPSÿuÿ< ‹=èš +=Àš S+}øÿÖPSÿu WÿuÿL 3À@_^[É ÌÌÌÌÌ‹ÿU‹ììÈ ¡– SV‹u3ÛWÿ5„« ‰Eü‰µÈüÿÿ‰¬üÿÿ‰Àüÿÿ‰¼üÿÿ‰°üÿÿ‰Äüÿÿ‰4¡ ‰8¡ ÿŒ Vè<öÿÿ¾ðš Vÿ˜ ÿœ ¿ Whð‘ SVjP‰…¸üÿÿÿ  Whø“ SVSÿµ¸üÿÿÿ¤ ¡à𠝐 jY¾ « ½Ìüÿÿó¥™¹0ýÿÿ÷ùjÿµÈüÿÿ‰Ðüÿÿ‹€ ‰…ÌüÿÿÿÓj ÿ5Øš ÿ5Üš ÿµÈüÿÿÿ| j ÿ5¸¤ ÿ5´¤ ÿµÈüÿÿÿx ¸ ¡ ‹ø¾Ì¤ ¥¥¥j¥‹µÈüÿÿPVÿt 3ÿGWVÿÓ‹d …ÌüÿÿPÿÓ…À‰…´üÿÿ„É PVÿ„ …À‰…Àüÿÿ„³ WVÿp …8üÿÿPV‹5l ÿÖ…À„“ ö…oüÿÿurÿµÀüÿÿÿµÈüÿÿÿ„ Pÿh jY3À½èüÿÿ󫍅ÌüÿÿPÿÓ…À‰…´üÿÿ„M PÿµÈüÿÿÿ„ …À‰…Àüÿÿ„2 …8üÿÿPÿµÈüÿÿÿÖ…À„ 3ÿG‹…8üÿÿ‹Hüÿÿ‹ ¡ È‹…LüÿÿÁà£<¡ ¡Ôš +Ð3Û;Ó‰
0¡ ‰Äš ‰Äš ‹èš +Üš (¡ Â;ãÀš ‰Àš ¡$¡ ‹К +Â;ã̚ ‰Ìš ¡äš ‹ð+5Øš 5,¡ Ö;ӉȚ ‰Èš +Èš +Ìš ™÷ùf9࣠tHf90¤ tH;ÃŽ' h£] ÿµÈüÿÿÿD ‹ð;óŒŽ SSh½ ÿ58˜ ÿ@ ;É…¬üÿÿ„  Pÿð ;É…Äüÿÿ„÷ h …(ýÿÿPÿ50˜ ÿ Sÿ50˜ ÿ  ShËe ÿ50˜ j ÿ5€« ÿ ;ã8¡ „« …(ýÿÿSÇ…ˆüÿÿ ‰…Œüÿÿ‰üÿÿ‰”üÿÿ‰˜üÿÿÿ@ …ˆüÿÿPÿµÈüÿÿÿP …À
ÿ8 ‹ðé¹ 3À‰½°üÿÿ‰=¼š ½œüÿÿ«««‹
0¡ «¡Äš ‰…œüÿÿ¡èš +Àš 3ö‰…¤üÿÿ¡Ìš ‰… üÿÿ¡äš +Èš f95࣠‰¸üÿÿ‰¼üÿÿ‰…¨üÿÿt üÿÿf950¤ t+Á‰…¨üÿÿÿµÄüÿÿÿä jìÿ58˜ ‹Øÿp öÄ t
Ç…¸üÿÿ  954¡ …ú …ÛŽò ÿ5¼š …0ÿÿÿÿ5Đ jdPÿ ƒÄ…0ÿÿÿPjÿ58¡ ÿ| ‹µÈüÿÿj Vèúÿÿ3À½tüÿÿ«««««¡<¡ VÇ…tüÿÿ ‰…xüÿÿÿ8 …ÀŽ# …tüÿÿP‹…¸üÿÿ
P( P…œüÿÿPSÿµÄüÿÿ3ÿGV‰½¼üÿÿÿ WVè®ùÿÿVÿ( …ÀŽÜ ƒ¥¼üÿÿ ‹…„üÿÿÿ¼š …À„ž ‹Äüÿÿ A+؃=4¡  ‰Äüÿÿ„ÿÿÿ3ö3Û9ÀüÿÿtÿµÀüÿÿÿµÈüÿÿÿ„ ÿµ´üÿÿÿh 9Äüÿÿt ÿµ¬üÿÿÿè 9¼üÿÿtÿµÈüÿÿÿ( …À ;óuÿ8 ‹ð9°üÿÿt\94¡ ÿµÈüÿÿt8ÿ, ëF3Ûj0ÿ5T ÿ5¤ ÿ50˜ ÿh Sÿ@ ÿ8 ‹ðéRÿÿÿÿ0 …À ;óuÿ8 ‹ðÿµÈüÿÿÿ4 ètñÿÿÿ5ˆ« ÿŒ 94¡ u‹ÆëjýX‹Mü_^[èY É ÌÌÌÌÌ‹ÿU‹ìVÿ5„« ‹5Œ ÿÖ‹Eƒè tHHtè öÿÿë èÐöÿÿëèCðÿÿƒøÿu ÿ5ˆ« ÿÖ3ÀëPè2ùÿÿ^] ÌÌÌÌÌ‹ÿU‹ìì$ ¡– Vÿu‰Eüèÿÿÿ‹ð…ö„ ƒþþ„„ ƒþýtƒþüujp^ƒþûuj^ƒþÿuÿ8 ‹ð…öt^j h …ÜüÿÿPÿP ·ÀPVj h  ÿL …À‹
` tÜüÿÿƒ=  ¡@ u¸ © j0PQÿ5T ÿ50˜ èr°ÿÿ‹Mü^è@ É ÌÌÌÌÌ‹ÿU‹ììè ¡– SVW‰Eü3Ûf‰hýÿÿ3À¹¤ ½jýÿÿó«3öf«F‹þÿœ %ÿ f;Ætf=
t3ö…üÿÿPÿ˜ ;ó‹5 t.jìÿ58˜ ÿp öÄ …hýÿÿt
j!_hD ëj_h@ PÿÖjP…(üÿÿPS…üÿÿPW¿  Wÿ  jP…ÈüÿÿPS…üÿÿPjWÿ¤ 9]¿8 t
W…hýÿÿPÿ֍…ÈüÿÿP…hýÿÿPÿÖh4 …hýÿÿPÿ֍…(üÿÿP…hýÿÿPÿÖ9]t
W…hýÿÿPÿ֍…hýÿÿPjh ÿ58˜ ÿ@ ‹Mü_^[è÷ É ÌÌÌÌÌ‹ÿU‹ìV3ö3ÉF3Ò9M ~5‹EŠ„Ày3ö…Òu<€rÐàB„ÀxùJtë$À<€uJA;M |Ó…Òw…öt3Àë3À@^] ÌÌÌÌÌ‹ÿU‹ìQƒMüÿEüPÿu ÿuÿ  É ÌÌÌÌÌ‹ÿU‹ìƒì¡– …Àt=@» uMVEøPÿ¸ ‹uü3uøÿ  3ðÿŒ 3ðÿ 3ðEðPÿ” ‹Eô3Eð3Æ%ÿÿ ^u¸@» £– ÷У – ÉÃÌÌÌÌÌ;
– u ÷Á ÿÿuÃé ÌÌÌÌÌ‹ÿU‹ìì0 W‰…Øýÿÿ‰Ôýÿÿ‰•Ðýÿÿ‰Ìýÿÿ‰µÈýÿÿ‰½ÄýÿÿfŒ•ðýÿÿfŒäýÿÿfŒÀýÿÿfŒ…¼ýÿÿfŒ¥¸ýÿÿfŒ­´ýÿÿœ…èýÿÿÇ…(ýÿÿ  ‹E‰…àýÿÿE‰…ìýÿÿE‹@ü‰…ÜýÿÿjY3À½Ðüÿÿó«Ç…Ðüÿÿ  À‹E‰…Üüÿÿ…Ðüÿÿ‰Eø…(ýÿÿ‰Eü¡– ‰… ýÿÿ¡ – ‰…$ýÿÿj ÿÄ EøPÿl h ÿÀ Pÿ¼ _ÉÃÌÌÌÌÌ‹ÿU‹ìQQVEüPh  3öVhT h €ÿ …Àu0EøPÿuÇEø VVh ÿuüÿ …ÀuFÿuüÿ ‹Æë3À^É ÌÌÌÌÌ‹ÿU‹ìì ‹
¨š …É¡– S‹] VW‹}‰EüuI9
¤š uA…øþÿÿPèbÿÿÿ…À‹5È t…øþÿÿPÿÖ£¨š ‹
¨š …ÉuhH ÿ֋ȅɉ
¨š t¡œš …Àu jQÿ …À£œš uǤš  3Àë
ÿuÿuSWÿЋMü_^[è×ýÿÿÉ ÌÌÌÌÌÌÿ%¸ ÌÌÌÌÌÌÿ%´ ÌÌÌÌÌÌÿ%¼ ÌÌÌÌÌjph˜ è¿ 3ÛS‹=Ì ÿ×f8MZu‹H<ȁ9PE u·A=  t=  t‰]äë'ƒ¹„ vò3À9™ø ëƒytvâ3À9™è •À‰Eä‰]üjÿ8 Yƒ
œ« ÿƒ
 « ÿÿ4 ‹
¸š ‰ÿ0 ‹
´š ‰¡, ‹ £¤« è§ 9– u hôu ÿ( Yèw h h  è] ¡°š ‰E܍EÜPÿ5¬š EÔPEÐPEÌPÿ  ‰EÈh h  è' ƒÄ$¡ ‹0‰uà€>"u:F‰uàŠ:Ãt<"uò€>"uF‰uàŠ:Ãt< vò‰]¬E€PÿÐ öE¬t·E°ë€> vØF‰uàëõj
XPVSSÿ×Pè%´ÿÿ‹ð‰uÄ9]äuVÿ ÿ  ë-‹Eì‹‹ ‰MØPQè‹ YYËeè‹u؃}ä uVÿð ÿô ƒMüÿ‹ÆèA ÃÌÌÌÌÌhºu d¡ P‹D$‰l$l$+àSVW‹Eø‰eèP‹EüÇEüÿÿÿÿ‰EøEðd£ ËMðd‰
Y_^[ÉQÃÌÌÌÌÌÌÿ% ÌÌÌÌÌÌÿ%ì ÌÌÌÌÌÌÿ%$ ÌÌÌÌÌh  h  è YYÃÌÌÌÌÌ3ÀÃÌÌÌÌÌÿ%< Ì̐y ÿÿÿÿÿÿÿÿ¬z Ä @x ÿÿÿÿÿÿÿÿúz t €y ÿÿÿÿÿÿÿÿ:{ ´ ìv ÿÿÿÿÿÿÿÿ^{  ¸y ÿÿÿÿÿÿÿÿv| ì Ìv ÿÿÿÿÿÿÿÿ}  Xw ÿÿÿÿÿÿÿÿì€ Œ ôv ÿÿÿÿÿÿÿÿ^‚ ( Tx ÿÿÿÿÿÿÿÿ<‡ ˆ ¢| ¶| Ä| Ô| ä| ø| | H{ Ё ā º ® ځ Ё ~ ò ^ ¢ æ P > 0 
 ú€ ‚ ‚ ‚ *‚ <‚ P‚ n $€ € ú ê Ô Â ° ¢ ’ t ^ :€ T€ h€ ˜€ ¶€ Æ€ Ú€ } $} 6} B} P} \} j} |} ˆ} –} ¤} °} ¼} Ê} Ö} ì} þ} ~ ~ (~ :~ P~ \~ f~ r~ ~~ Ž~ š~ ª~ À~ Ð~ â~ þ~   & 8 N |€ Èz Öz èz ºz $… 4… @… L… T… f… x… Œ… ž… ®… … Î… ä… ð… † † "† 6† F† Z† h† v† Œ† … ö„ ê„ Ø„ ¼… ž† ¸† Ȇ ؆ æ† ö† ‡ ‡ *‡ Ä„ h‚ v‚ ˆ‚ ”‚ ¤‚ ¼‚ ΂ Þ‚ ô‚ ƒ ƒ ƒ 2ƒ Pƒ `ƒ pƒ ‚ƒ ƒ šƒ ¨ƒ ºƒ ̃ Úƒ æƒ øƒ „ „ "„ .„ @„ T„ h„ €„ ”„ ¤„ ²„ { { *{ zz ^z žz Pz @z Šz jz z ,z Ü{ Ô{ Ê{ Â{ ¶{ ê{  { Œ{ „{ z{ l{ ô{ ü{ | | "| 6| F| V| d| ‚| ¬{  CommDlgExtendedError GetSaveFileNameW  GetFileTitleW  ChooseFontW  FindTextW  ReplaceTextW  PageSetupDlgW
GetOpenFileNameW  PrintDlgExW comdlg32.dll ShellAboutW  DragFinish # DragQueryFileW  DragAcceptFiles SHELL32.dll  ClosePrinter x GetPrinterDriverW ~ OpenPrinterW WINSPOOL.DRV  CreateStatusWindowW COMCTL32.dll ä_snwprintf /wcsncmp t_wtol í _except_handler3 Æiswctype 0wcsncpy Ôlocaltime time Å _c_exit ö _exit N _XcptFilter È _cexit exit ¨ _acmdln m __getmainargs ;_initterm š __setusermatherr ¶ _adjust_fdiv € __p__commode … __p__fmode ˜ __set_app_type msvcrt.dll Ö _controlfp ûRegSetValueExW îRegQueryValueExW ÊRegCloseKey ÐRegCreateKeyW 9IsTextUnicode íRegQueryValueExA ãRegOpenKeyExA ADVAPI32.dll ñGlobalFree lGetLocaleInfoW KLocalFree GLocalAlloc ´lstrlenW QLocalUnlock 8 CompareStringW MLocalLock ê FoldStringW 1 CloseHandle ®lstrcpyW £ReadFile R CreateFileW «lstrcmpiW <GetCurrentProcessId —GetProcAddress
GetCommandLineW ¥lstrcatW Ì FindClose Ó FindFirstFileW YGetFileAttributesW ¨lstrcmpW cMulDiv ±lstrcpynW PLocalSize hGetLastError ‹WriteFile SetLastError ~WideCharToMultiByte NLocalReAlloc ì FormatMessageW ×GetUserDefaultUILanguage ýSetEndOfFile ‚ DeleteFileW ö GetACP ZUnmapViewOfFile dMultiByteToWideChar WMapViewOfFile Q CreateFileMappingW ZGetFileInformationByHandle üGlobalUnlock õGlobalLock ÓGetTimeFormatW @GetDateFormatW ÕGetUserDefaultLCID jGetLocalTime ‘QueryPerformanceCounter ÑGetTickCount >GetCurrentThreadId ½GetSystemTimeAsFileTime FTerminateProcess ;GetCurrentProcess WUnhandledExceptionFilter 2SetUnhandledExceptionFilter ALoadLibraryA uGetModuleHandleA ¬GetStartupInfoA KERNEL32.dll  DeleteObject = CreateFontIndirectW kGetDeviceCaps —GetObjectW ¥GetStockObject Î EnumFontsW »GetTextFaceW SelectObject / CreateDCW µGetTextExtentPoint32W OTextOutW Œ DeleteDC – EndDoc AbortDoc ˜ EndPage HStartPage FStartDocW SetAbortProc ½GetTextMetricsW SetBkMode ËLPtoDP BSetWindowExtEx >SetViewportExtEx +SetMapMode GDI32.dll éMoveWindow “InvalidateRect ÓWinHelpW GetDlgCtrlID < ChildWindowFromPoint 1ScreenToClient GetCursorPos 7SendDlgItemMessageW @SendMessageW , CharNextW 9 CheckMenuItem B CloseClipboard ŸIsClipboardFormatAvailable óOpenClipboard 7GetMenuState  EnableMenuItem YGetSubMenu ,GetMenu ãMessageBoxW SetWindowLongW oGetWindowLongW GetDlgItem VSetFocus TSetDlgItemTextW ÙwsprintfW GetDlgItemTextW Æ EndDialog EGetParent ¬UnhookWinEvent ¢ DispatchMessageW ªTranslateMessage ¨TranslateAcceleratorW ¢IsDialogMessageW PostMessageW >GetMessageW ~SetWinEventHook ]GetSystemMetrics ‡SetWindowTextW ¼LoadIconW GetFocus GetDesktopWindow ’ShowWindow ÿ GetClientRect MSetCursor *ReleaseDC GetDC Ÿ DialogBoxParamW CSetActiveWindow "GetKeyboardLayout  DefWindowProcW ™ DestroyWindow ÛMessageBeep PostQuitMessage GetForegroundWindow ¦IsIconic sGetWindowPlacement 7 CharUpperW ÉLoadStringW ´LoadAcceleratorsW \GetSystemMenu RegisterClassExW ¾LoadImageW ºLoadCursorW ‚SetWindowPlacement a CreateWindowExW (RegisterWindowMessageW »UpdateWindow oSetScrollPos ) CharLowerW þPeekMessageW Ä EnableWindow ¾ DrawTextExW V CreateDialogParamW zGetWindowTextW USER32.dll Ôp  x  N o t e p a d ÿÿÿÿ       

      -             ! " # $ % & ' ( ) * + , 4 8 < @ L H D P T X \ ` d h l p t „ ˆ Œ  ” ˜ œ   ¨ ¤ ¬ ° ´ ¸ ¼ À Đ x | Ȑ ̐ А Ԑ ؐ ܐ à ä € ” ÿÿ L  X 
\  L  L  ˜  L  œ‘  ÿþ þÿ Y Y ¿Dÿÿ@»    P € ¨ € À € ð €  € @ € X € p €  ˆ €   € ¸ € Ð € è €  €  € 0 € H €   ` €   D €x €  € ¨ € À €   Ø € ð €  €  €   €8 €0 €P €   h €   € €   ˜ €   °   À   Ð   à   ð            0   @   P   `   p   €          °   À   Ð   à   ð       ¸ h x¾ è `Á ( ˆÂ ¨ 0Ñ ¨ ØÙ h @ß ¨% è ¨  h € B Ð ~ ø Ö P  > $ Þ è/ þ à(  è7 0 9 : È ˆ P ¨ ø „ p% p pµ ž  M A I N A C C S L I P U P A C C  N P E N C O D I N G D I A L O G <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
name="Microsoft.Windows.Shell.notepad"
processorArchitecture="x86"
version="5.1.0.0"
type="win32"/>
<description>Windows Shell</description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="x86"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
( 0 `   € €€ € € € €€ ÀÀÀ €€€ ÿ ÿ ÿÿ ÿ ÿ ÿ ÿÿ ÿÿÿ  ˆˆˆˆˆˆˆˆˆˆˆˆˆˆˆÿÿÿÿÿÿÿÿÿÿÿÿÿÿ÷€ÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ€wwwwwwwwwÿÿÿÿÿÿ€ˆˆˆˆˆˆˆˆˆçççççç€wwwwwwwwwÿÿÿÿÿ€wwwwwwwwwwÿÿÿÿÿ€ wwwwÿÿÿÿÿ€ffffffffffff`ˆˆˆˆ~~~~~€gwwwwwwwwwwww`wwwwÿÿÿÿÿ€n~~~~~~~~~~~~vwwwÿÿÿÿ€nççççççççççççvwwwÿÿÿÿ€n~~~~~~~~~~~~w`ˆˆˆŽ~~~~€nççççççççççççç`wwwÿÿÿÿ€î~~~~~~~~~~~~vwwwÿÿÿÿ€çççççççççççççvwwwÿÿÿÿ€n~~~~~~~~~~~~w`ˆˆˆ~~~~€nççççççççççççç`wwwÿÿÿÿ€î~~~~~~~~~~~~vwwÿÿÿ€çççççççççççççvwwÿÿÿ€n~~~~~~~~~~~~w`ˆˆŽ~~~€nççççççççççççç`wwÿÿÿ€î~~~~~~~~~~~~vwwÿÿÿ€çççççççççççççvwwÿÿÿ€n~~~~~~~~~~~~w`ˆˆ~~~€nççççççççççççç`wwÿÿÿ€î~~~~~~~~~~~~vwÿÿ€çççççççççççççvwÿÿ€n~~~~~~~~~~~~w`ˆŽ~~€nççççççççççççç`wwÿÿ€î~vfffffff~~~vwÿÿ€ççà çççvwÿÿ€n~~~~~~~~~~~~w`ˆŽ~€nççffffffffççç`wÿ€î~ ~~~vwÿ€çççççççççççççvwÿ€n~~~~~~~~~~~~w`wÿ€nççççççççççççç`w€î~~~~~~~~~~~~v€çççççççççççççv€n~~~~~~~~~~~~w`xnfîænîfîænîfîæ`pÿfoöfÿfoöfÿfoˆˆˆˆˆˆˆˆˆÿÿÿÿÿÿ ÿÿ€  ÿÿ  ÿþ ÿþ ÿþ ÿþ ÿþ ÿþ À € € € À À à à ð ð ø ø ü ü þ þ ÿ ÿ ÿ€ ÿ€ ÿÀ ÿÀ ÿà ÿà ÿð ÿð ÿø ÿø ÿü  ÿü  ÿþ  ÿÿ„! ÿÿÿÿÿÿ ÿÿÿÿÿÿ ( @   € €€ € € € €€ ÀÀÀ €€€ ÿ ÿ ÿÿ ÿ ÿ ÿ ÿÿ ÿÿÿ  ˆˆˆˆˆˆˆˆˆÿÿÿÿÿÿÿÿ÷€‡wwwwwÿÿÿÿ€‡wwwwwÿÿÿ€ ˆˆŽ~~~€ffffffffwwÿÿÿ€nwwwwwwww`wwÿÿÿ€nçççççççç`ˆˆççç€n~~~~~~~~vwÿÿ€ççççççççvwÿÿ€î~~~~~~~w`ˆŽ~~€nçççççççç`wwÿÿ€n~~~~~~~~vwÿÿ€ççççççççvˆçç€î~~~~~~~w`wÿ€nçççççççç`wÿ€n~~~~~~~~vŽ~€ççççççççvwÿ€î~~~~~~~w`wÿ€nç çç`ˆç€n~~~~~~~~v€çà çv€î~~~~~~~w`w€nçççççççç`w€n~~~~~~~~v€ççççççççv€æînæînæîg`oföoföoföˆˆˆˆÿÿÿÿÿø ÿð ÿà ÿÀ ÿÀ À € € € À À à à ð ð ø ø ü ü þ þ ÿ ÿ ÿ€ ÿ€ ÿÀ ÿä’Oÿÿÿÿ(    € €€ € € € €€ ÀÀÀ €€€ ÿ ÿ ÿÿ ÿ ÿ ÿ ÿÿ ÿÿÿ  wwwwpÿÿÿÿp wîpffffÿpn~~~~~pnçççç`pî~~~p~pççççæpn~~~wpnçççç`pà ~ppççççv n~~~ç`n‡‡‡‡affffüwwø wwø wwÀ ÿ€€ çç çç ˆˆ€ 瀀 ~~À ~~À wà ÿ€à ççð ççðwøÿ€( 0 `   xft ˆ yZi ÎÄÉ «›  Q^ «‹‘ §u| Ì®² ªdh ±sw Ö®° ΰ± °UV ½wy ¸aa ¿vv Ñ¡¡ Ù©© Ó§§ óåå wvv YXX ÌŽ åÆÅ Ò±¯ ⾺ ›0 iWQ ÙyL ©jO Ô~ Ë­Ÿ ýŽV öŠU êˆV õ”d Çh ý¸” ¬|e ø‘[ Å}W ú¦x ÉŒe {eX ¶Y Òi! Ò•j Гe ךk ÿͧ çy ÿظ яT Ô’V Õ•Y Ø—[ Ûže ךe w` æ3 æ•E Ûœ^ é¬q ߦn ä² _\Y Ý›T àŸX ã£[ ç©e á¤e ñ³m å¨i ¦Šl ÿëÕ ƒ{r è¦T ã£T ç¨^ ì¯f ÿÀu ÿÁx ÿÂx öºt Фq œn ÿÚ¬ ÿãÁ ê©V ì¬Z É’M ð°^ ԝS ÿ½e ó´` þ¾j ð³e ÿÀq ÿÆ{ ÿÉ‚ š‡o ÿèË ÿöê {v ð°S ô³V ø·Y ÁŽH ÿÁe ÷ºf ÿÐŽ ÿÔ™ ÿèÆ ÿýú ÕŽ þ½U ³†? þ¾\ ù»\ ÿÁ` å¯V ÿÄe ÿÅj ò½h ÿÈp ÿÈs ÿËv þÌ{ ÿÎ ÿÓŠ ÿÜ£ ò¹P »A ÏŸI Ý©P ǘI ÿÑ„ ÿÕŽ þÖ‘ ÿØ– ÿÛœ ÿᬠÿã² ÿæ¸ ÿᨠÿêÀ ÿüö ÿýù w]$ á¯G ÙªI åºY õÉl ÿìÅ ÿíÈ å¶I ë½N ìÁ[ ðÎy ñԏ ÿîÅ ÿûñ ¬Œ5 êÇf ëÊo ÿñÌ ýôÛ Áž9 º™9 õä¯ Ð¯8 É©8 ±”5 Ö·N éÑz Õ¸<  ‰. Ù»C Ú¾L èÓ„ éÙ“ ʲ/ µŸ. œŠ( ×ÃW ëߟ º¦* ¥”& ½®% ­ž% µ: ØËg —Œ Áµ, ƺB ®¦ ÖÏr ¼¸7 ÖÒx ÂÂJ ÅÇW ××… º½G ÄÊb ÄÐl ¥·7 åí» ¼Îd åï Á×{ Ìë´ žÜ€ åöÞ òûð ©æœ ¾ì´ ™â eÖZ ÏòË åøã rÙk Ýx ŒáŠ ™ä— TÓR eØd Óæ ÄÜ $Íã 3ÃÝ ©Ï $›¸ /¯Í J½Þ ~ « c±Ì „¯Á ÉÝæ ^‡ Gx• ®ÉÙ ¬±¸ ’™¨ ÿÿÿ ‘‘‘ ‰‰‰ ‚‚‚ zzz sss lll ddd ^^^ RRR úúúùù÷ ÷úúúúúúùø÷ö %#$*-Cýýüûúùø÷ &*$#$$#$*-Cýüüúùø÷ ×õs”L5'%""#"$-ýýüûùø ãâãáÙÜ£££L5'?)"""#-ýýû õõ×ÜáßââßÚÔ¨ÚÔ¨Y3+)"""#û õõs•””££ÜÙÚãââÚØÔ¨¨¨rX+%"/ü áÜÝ•””£Lep„ÕÙÔØßÛâÞÕÔЧ§ü ÙáÞâãßÚµ}ccc¯™dp„‘›ÒÙÕÞâÛ–û õõs•”ÜÙ¯À½®¸˜oaaaa_ep„¢þüû õõs•””LRI?9\²²¹²¹©˜z_____/VK<-ýüû âÞáÙÜ”XRG???¤m988m†¤¹¤®ªˆ4TTTTTAWK-û õÝÜØàãÏÀ®ª‰^®‰999877766mv.,0A@UTTTUû õõs•”hRU‡‰ª½Â½®†‰8877666.,,,&&&1TUù Üõs•”YRIPPPFª‡^‰ª®¹Â¹¤¤m\.1,,,,,2TW÷ àãâãÞÍ™ˆPPPPª‡FFEEEDD‰†¤¹.111,,,@Tf õõs•Ö}¯­¿¿¿¸¿©‡OFFEEEDDDD.111111RUù õõs•gRa``]]z¸¸©¿½¿¿ª©‡DDD.;;;11ATW÷ àáÙÜ„Ro```]]­˜[[[Zˆ‡©ª½½½.:;;;;ITf ÜÜáàÌǾ¾¬¬——­˜][[[ZZZNNOO/HH::;UUù õõs¨Rcyx¬­Åż¼­­˜˜ZZZNN/HHHHJTW÷ õõsYR|nyywwx¬lj—¬­¼¿¿¿¸©/GGGHITf ããã̯´ŸŸnyyw±xlllkkkjj—˜/QGGGRT õõ£}Ÿ™´ÄÃÃÃþ·…lllkkkjj/bbQQTV÷ õõgRd€€~~||·³±±Ã¾¾¾¾¬¬——4bbbUTK ÙܶR‚Š‚€€~±ž{yywwu…±¬·toobRTi ááÄÀÉÌÉʺº¥¥ÄŸ||{yywuuuuu4oooTV÷ õ¨ReŒ‹ƒ ¦¥ººÇÇÇÀÀ±³³žžuuu4nncTK õ5RpŒ‹ƒŠŠ‚º¥€~ŸŸ´³±ÃþtnnTTi ã̯ȵµµŒŒ‹ƒƒº¦‚€€~~||{yy4naTV÷ h}¦¶ËÈÈÍÍÊÊÊÌÊÁÁ¦¦€€~||{4ncTK YSq’„„ŽŽÁÁ°ÁÁÁÉÉÌÉÄÄ´=TTi ¡S’„„ŽŽÆµŒ‹ƒƒŠŠ‚€š¥=TV÷ ÄÄÓÓÓÓÓËË˶¶ÎµŒ‹ƒƒŠŠ‚€=dTK Sq›““‘«»»¶ËËÎÑÎÎÑÍÍÍÁÁÁ¦¦=dTi S›››““‘‘‘Ë¶„„ŽŽŽ¡µ°°ÁÁ>TVø S¨›››œ›“››››Ë»’ŽŽŒ}>TK Sœ›››Ë’’’’’’’’’’’>TM Sñ蜜èð››è ’’ôï’’’>Tù ꜜœòè›êð’’ñè ’’èîø (éðåôéê’ïé÷ Bóð
äóä
åéðå íçêæç äìçê<êíóêíî äó ðé !ííK íæç óæäæê ëåäë êêìæ óæó òî ëæí ÿÿÿÿÿÿ øÿÿÿÿ ð ÿÿÿÿ ð ÿÿÿ à ?ÿÿ à ÿÿ à ÿÿ à ÿ à ÿ à ÿ à ?ÿ à ÿ à  à ? à ? à ? à ? à  à  à  à ÿ à ÿ à ÿ à ÿ à ÿ à ÿ à ÿ à ÿ à ÿ à ÿ à ÿ à ÿ à ÿ à ÿ à ÿ à ÿ à ÿ à ÿ à ?ÿ à ?ÿ à ?ÿ à ?ÿ à ?ÿ ð ÿ ø0 ÿ ü1‚ÿÿ ÿÿÇ8ÿÿ ÿÿÿÿÿÿ ( @   yx Œ‹• —•š ’…‘ | Ï— ȝ¡ Ç–™ Ï–™ Ì•– Á…… É”” Ÿ‘‘ æ|x Á€~ È”’ Ç“‘ ÍŽ‹ ¾wq ‰xv Óš 裔 ĉ~ ¾ˆ} Á‹ Áˆz ‰{ ÿÐÅ Àˆy ™\D ð”i ÐwL ݇] ¹rP ø£w z]O  ybW igf è…O ȃ] ćd »Œ ´f7 Í‘h ѯ— ѐ` ÷¸‰ øÂ™ õÉ© Ѻ© Öšg Ò—i ŠoX Äw1 Þ›^ ê¥e è§l Ý¡i ä¨p à¢e â¦l Оo xmb ÿþý ߍ1 Ó†5 ò¦U ë¦\ Í‘S è¬i ûÕª ø×³ ª ó°] ÞŸV å¦^ ú»r ë°l ò¸t ç³u Ó¤l ·”l Ÿ| ë›4 ç©U ÄŽJ û¹b ê­[ ÕœS ú·c û¾n ò¶k þÅ{ Ú«p Ë¢n ¬Š^ «l —‰w ê©H Þ¡G ýº[ ÷¸Z öÀs ÷ËŽ usp Ê”B ý½U ò´S Û¤M ½F ËšL ì²Y ߬X î¹b ýÆq åΨ ‘: ¹‹> ÷½S ë´Q â­R ÷Á^ ûÊt üËy õÈv ûÒ‹ íʏ ïÔ¥ ìµM É›C Û©K ä²P íº[ ÷Çi þìÈ ØªD ã´I ÄœA ¿—@ ë¹P xc5 ñÌy òц ùÙ– ýß¡ ÿä© ùæ» Ä›: ´‘8 ˤA é¼M ݳL îÂZ õÒ ôÕ‹ èÙ´ Òª: É£9 Òª@ Û³D ä¼I Ô®J ìÇc ¡8 ¹™7 á»E ªŽ4 ã¿T èÈg ݾc éÊm àÄn íÒ€ îא ýñË Ù´: ®’3 ݽI ܾU óᦠó㪠ٺB âÇb âÊj äÐ| §’, Õ¼E ÞÈe ãÏs íޝ Ê´/ «/ ÖÅa äÕ„ æÚ” Íʹ äÙ‹ ñíÏ ÎÃR ÖÎq ØÒz ×Ô„ ÝÛ‘ Ûßœ åè½ ÊÔ… ÎÞ‘ ÂÖ ©Ôr Ïç´ óõñ ³Ú™ ³ã— ¾ë§ ¢äˆ »Ìµ Úï× ÐôÌ çøå «è¦ ÇíÄ ­åª ¸ê· ÛöÚ ˜ë— ªìª {â} ¡ç¢ §í© ÉôÊ ¬í¯ ïýð ¨ñ¯ ‰“ •ÅÅ g©± MÎæ X¼Ð {¸Å ;«Å G¥º 4•® 9Áì R•ª vˆŽ e—ª nx| ¥¯´ –§ ŒŒŒ ‰‰‰  yyy üþüü" "6&@þûü3221# ""$'jýüåâèàÓӝIQ#! ,$&&' ÔéÜÞãæãèäâӝ210(üàÛááÜ”ÄÒÖÖØââ×ÓÍ ÚàååÖ«„r£†^‘¿ÐØØŽ'
ÚÜAAÇspo¨–Œƒezst^(a6@@jýßæÝèÏrZ8oWFFWwwvvC:QQQRa' ÔéÜÛ­„‹Œ»²ŒWFFFFW,)---<^ýÞçÛÎhYMM‹pZƒ¦–––w,)-**>Rü ÞãèÏ™—Ÿ—¦‹nLLLLZk7/5--Pb
ÚéAH[qzz¥¥—¥••‹ƒk7/4/;PTàêÖ´¡¡…q „YVVnn—•78;4O`ü ÔéÎs†Š¡ÁÁž ‰‰„„eC8>=Pb àèˆ{{{{¡‚gyЉžžŸCMGGPc
ÚÛ­©©³··À±Š‚‚‚mmdBEO]_ü
ÜÇ^}}|tt³¢˜§±±±±žBK]NSàÑ´½½¸¸¤¼©š{{flx‚UK\PTÔ‘~œ¬¬ÈÈ´´³³§§±Uft_üÕº¯œ½¬}|‡‡šš˜Uf^SI~¯ÄÃÊÉÉȹ¹ª¤¤¤šUX^c
€µ¶µ’’’º®œ®¾¹½¸´d\Qü«ÊÍÌÌÌÆÆÊÊÃî®››|DNbi”ˆ””¶µ¿ËËÆÃú¾¾½VNc1ˆ°ˆˆˆˆÍ¶“““’‘‘DR
0ð°”úì°uÙ“IÅ”“H9aüó3IùñÅ ò%õð“.÷öü? ñò ò
òùó?ïîòïïõø÷íó íñöõ+ùíëíöðïJïîöôðàÿÿÿÀÿÿÀ ÿÀ ÿÀ ÿÀ ÿÀ ÿÀ À À À À À À À À À À ?À ?À ?À À À À ÿÀ ÿÀ ÿÀ ÿÀ ÿÀ ÿà ÿñÿÿÿÿÿ(    ‹‰‘ –Œ’ »šœ Ý™Š ›Œ —}v Žtl —І ”n` dZ ®“Š ˜vi “~u ˍi §z\ à­‹ Ã|H ÕŠQ Üžj è¨r Û o Ú«… ЉI ¿“m Ò·Ÿ Ò¸¡ Ý¥l Ü˺ Û”I ñ²p Û¥l §–ƒ ßͺ æH ÊŠ@ ƍG ê¨] þÀt —wQ ½™o çÌ« ÍÀ° ōC þ»d ñ¹q ßq ѯ„ ~h ¥—… ÌÁ² ô¬I þ·R ÂŒ? ز| ôÕª ¦™‡ ÌÀ® ÍÁ° ÌÁ± Íô ’‹ Ü¥J Í›I È–H Ø¢P â°a Ìõ ÌÄ· ͘? Ö¤I Õ¢I »Ž@ ½‘A á«? Õ¡> â®J ã¯L ʝE ɝH ç´@ çµF ê¸K Û«G í»R ë»W ðÁ^ Ñ«V æ¿j Þʝ ܰC ϦB ÓªD Ç A î¾O ìÀV íÄ^ ïÉk ñÌs ˜Žw äºG ç¼M ëÆ_ êÆd ìÌt Û¼l óÒ| îÓ† Ú´B â½K íÓ„ öݏ òä¸ áÁU âÄ] äÊj çÐ{ íØ óߘ ôæ¸ úîà æÎq áΆ àÌp äÓ~ ìÜ– ãÕ… íß“ èÜ” ÛÎz âÕ„ çߟ èâ¡ ØÔ˜ àßž ÔÖ~ Ü㣠×ߣ Ûᯠ½À¶ ×ê° ¿ä‘ Çë Ñë² ÔíÁ Ò÷Ï ÅöÉ É÷Ð ÉúÒ ÑûÚ ÏÿÚ  ©¨ Ÿ·» R¹Ò eŠœ —¡© ˆ‹’ 
ŠY/ <–’ŒŽˆ…6
9“BOWi‡'=*•‰AIH$+#0:”z>]N?@58;‘XL\[FGE.CUTlZMSK(.D†V`mdRQJ"& 2~hbrq_^P3-.nuk{safe4.ƒ}‚|tyg,1pxw„€voj%1›!˜—)‹7c1 ™œ™ ™™šƒÿ€?Ýè€Z8€FF€wv€:Q€Ra€€ €ÜÛ€‹Œ€ŒW€FF€)-€<^ÿÿ( 0 `  MMMMMM MMMMMMAMMMNMMMKMMMFMMM@MMM7MMM,MMM!MMMMMMMMMMMM
MMMMMMMMMMMMMMMMMM MMMMMMMMM9MMMxMMM˜MMM—MMM”MMMMMM…MMMrMMM`MMMRMMMFMMM:MMM.MMM"MMMMMMMMMMMM MMMMMMMMMMMMMMMMMM MMMÃC)X“gQccUN¢SOMÆMMMÇMMMÈMMMÌMMMÉMMM¾MMM´MMMªMMMMMMŒMMMyMMMfMMMVMMMKMMM@MMM2MMM%MMMMMMMMMMMM MMMMMMMMMMMMMMMMMM ïŠV¿vvÿÓ§§ÿêˆVðõŒVýç‡VüÂyT÷žkRõy^OòTPMìMMMèMMMäMMMÞMMMÔMMMÈMMM¼MMM±MMM¦MMM–MMMMMMjMMMXMMMLMMMAMMM4MMM%MMMMMMMMMMMM MMMMMM Ô~ÿ¿vvÿÓ§§ÿ¶tSÕÉ|T÷éˆVþöVÿêˆVþëˆVþ÷Wÿè‡VþÀxSýœkQûx]O÷TPMñMMMíMMMéMMMãMMMÚMMMÍMMM¿MMM³MMM§MMM˜MMMƒMMMkMMMXMMMLMMMBMMM2MMMMMM
MMM Ô~ÿ¿vvÿÓ§§ÿòüòÿÿÿþÿÿýúÿÿûöÿÿæÖÿÿѶÿü±‹ÿüšjÿþXÿüŒVÿú‰SÿýŒUÿï‡RÿÒxKþ¨eIüx]OøSOMóMMMîMMMêMMMäMMMÛMMMÎMMMÀMMM³MMM©MMM™MMMzMMMKMMMMMMMMM Ô~ÿ¿vvÿ


0

Response Number 13
Name: timmay
Date: October 24, 2007 at 18:23:23 Pacific
Reply:

and the fix.reg solution didnt work either, it said it could not import it because some keys were open by the system or other processes
what if i go into regedit and make it so the system doesnt have any permissions?


0

Response Number 14
Name: timmay
Date: October 24, 2007 at 18:29:51 Pacific
Reply:

i think i found a hijackthis log in the folder hijackthis under the name of startuplist... any benefit in posting that?


0

Response Number 15
Name: jabuck
Date: October 24, 2007 at 19:34:06 Pacific
Reply:

Maybe, post the Hijack This startuplist.


0

Response Number 16
Name: jabuck
Date: October 24, 2007 at 20:26:54 Pacific
Reply:

Next, please reboot your computer in Safe Mode by doing the following :

Restart your computer

After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;

Instead of Windows loading as normal, a menu with options should appear;

Select the first option, to run Windows in Safe Mode, then press "Enter".

Choose your usual account.

Open notepad (Start Menu > Run > Type notepad and press "ok".

Copy and paste everything into notepad between the x's making "Regedit4" the very top line.
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Regedit4

[HKEY_CLASSES_ROOT\.exe]
@="exefile"
"Content Type"="application/x-msdownload"


XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

Go to File on the top bar and choose" Save As", Change the "Save As Type" to All Files, Name it Fix.reg then save it to your desktop.

Double click Fix.reg (or right click and choose Merge) and it will ask if you want to merge the contents into the registry, choose Yes.

Try running Combofix, Hijack This and your antivirus from safe mode. Post the logs if you are successful.



0

Response Number 17
Name: timmay
Date: October 25, 2007 at 17:08:15 Pacific
Reply:

heres the log and ill try that in a second, thanks

StartupList report, 10/15/2007, 6:41:42 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1125995842\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\mcafee.com\personal firewall\MPFService.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

---------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Owner\Start Menu\Programs\Startup]
*No files*

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.exe
Oemreset(2).lnk = C:\WINDOWS\OPTIONS\OemReset.exe
Oemreset(3).lnk = C:\WINDOWS\OPTIONS\OemReset.exe
Oemreset(4).lnk = C:\WINDOWS\OPTIONS\OemReset.exe
Oemreset(5).lnk = C:\WINDOWS\OPTIONS\OemReset.exe
Oemreset.lnk = C:\WINDOWS\OPTIONS\OemReset.exe

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

---------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

---------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

High Definition Audio Property Page Shortcut = HDAudPropShortcut.exe
ShowWnd = ShowWnd.exe
SoundMan = SOUNDMAN.exe
AlcWzrd = ALCWZRD.exe
Alcmtr = ALCMTR.exe
AVG7_CC = C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
HostManager = C:\Program Files\Common Files\AOL\1125995842\ee\AOLSoftware.exe
MCAgentExe = C:\PROGRA~1\McAfee.com\Agent\bak\McAgent.exe
Symantec NetDriver Monitor = C:\PROGRA~1\SYMNET~1\SNDMon.exe
AOLSPScheduler = C:\Program Files\Common Files\AOL\1125995842\ee\services\safetyCore\ver210_5_4_1\AOLSP Scheduler.exe
sscRun = C:\Program Files\Common Files\AOL\1125995842\ee\SSCRun.exe
MPFExe = C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
Microsoft Works Update Detection = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
MCUpdateExe = C:\PROGRA~1\McAfee.com\Agent\bak\McUpdate.exe
ASM = "C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe" HIDEMAIN
IESet = IExplorer.dll .dbt
SearchIndexer = rundll32.exe "C:\WINDOWS\system32\uwbhthfh.dll",sitypnow

---------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

---------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

---------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

IESet = IExplorer.dll .dbt

---------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

---------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background
swg = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
DriverLoad =
DriverCheck =
SystemDriverLoad =
FDriver =
ADriver =
CDriver =
DDriver =
IESet = IExplorer.dll .dbt
Cpue = "C:\PROGRA~1\SSTEM3~1\netdde.exe" -vt ndrv
ISMModule2 = "C:\Program Files\ISM\ISMModule2.exe"
Qromkkez = C:\WINDOWS\system32\?dobe\r?gedit.exe

---------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

---------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

---------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

---------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

---------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

---------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

---------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
*No values found*

---------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

---------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

---------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

---------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

---------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

---------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

---------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

---------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

---------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

---------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

---------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

---------------------

File association entry for .EXE:
*Registry key not found*

---------------------

File association entry for .COM:
*Registry key not found*

---------------------

File association entry for .BAT:
*Registry key not found*

---------------------

File association entry for .PIF:
*Registry key not found*

---------------------

File association entry for .SCR:
*Registry key not found*

---------------------

File association entry for .HTA:
*Registry key not found*

---------------------

File association entry for .TXT:
*Registry key not found*

---------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{4b218e3e-bc98-4770-93d3-2731b9329278}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf

[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install

---------------------

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

---------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

---------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

---------------------

Checking for EXPLORER.exe instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

---------------------

Checking for superhidden extensions:

.lnk: *Registry key not found*
.pif: *Registry key not found*
.exe: *Registry key not found*
.com: *Registry key not found*
.bat: *Registry key not found*
.hta: *Registry key not found*
.scr: *Registry key not found*
.shs: *Registry key not found*
.shb: *Registry key not found*
.vbs: *Registry key not found*
.vbe: *Registry key not found*
.wsh: *Registry key not found*
.scf: *Registry key not found*
.url: *Registry key not found*
.js: *Registry key not found*
.jse: *Registry key not found*

---------------------

Verifying REGEDIT.exe integrity:

- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

---------------------

Enumerating Browser Helper Objects:

*No BHO's found*

---------------------

Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
At1.job
At10.job
At100.job
At101.job
At102.job
At103.job
At104.job
At105.job
At106.job
At107.job
At108.job
At109.job
At11.job
At110.job
At111.job
At112.job
At113.job
At114.job
At115.job
At116.job
At117.job
At118.job
At119.job
At12.job
At120.job
At13.job
At14.job
At15.job
At16.job
At17.job
At18.job
At19.job
At2.job
At20.job
At21.job
At22.job
At23.job
At24.job
At25.job
At26.job
At27.job
At28.job
At29.job
At3.job
At30.job
At31.job
At32.job
At33.job
At34.job
At35.job
At36.job
At37.job
At38.job
At39.job
At4.job
At40.job
At41.job
At42.job
At43.job
At44.job
At45.job
At46.job
At47.job
At48.job
At49.job
At5.job
At50.job
At51.job
At52.job
At53.job
At54.job
At55.job
At56.job
At57.job
At58.job
At59.job
At6.job
At60.job
At61.job
At62.job
At63.job
At64.job
At65.job
At66.job
At67.job
At68.job
At69.job
At7.job
At70.job
At71.job
At72.job
At73.job
At74.job
At75.job
At76.job
At77.job
At78.job
At79.job
At8.job
At80.job
At81.job
At82.job
At83.job
At84.job
At85.job
At86.job
At87.job
At88.job
At89.job
At9.job
At90.job
At91.job
At92.job
At93.job
At94.job
At95.job
At96.job
At97.job
At98.job
At99.job
McAfee AntiSpyware.job
McAfee.com Update Check (COLLIN-Owner).job
McAfee.com Update Check (YOUR-7B9DABC953-Owner).job

---------------------

Enumerating Download Program Files:

[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtpl...

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/...

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll
CODEBASE = http://go.microsoft.com/fwlink/?lin...

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/...

[McAfee.com Operating System Class]
InProcServer32 = C:\WINDOWS\system32\mcinsctl.dll
CODEBASE = http://download.mcafee.com/molbin/s...

[{556DDE35-E955-11D0-A707-000000521957}]
CODEBASE = http://www.xblock.com/download/xcle...

[BDSCANONLINE Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\oscan8.ocx
CODEBASE = http://download.bitdefender.com/res...

[Windows Live Safety Center Base Module]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\wlscBase.dll
CODEBASE = http://cdn.scan.onecare.live.com/re...

[GameLauncher Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\GAMELA~1.OCX
CODEBASE = http://www.acclaim.com/cabs/acclaim...

[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://www.update.microsoft.com/mic...

[Java Plug-in 1.5.0_07]
InProcServer32 = C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
CODEBASE = http://java.sun.com/update/1.5.0/ji...

[{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
CODEBASE = http://fpdownload.macromedia.com/ge...

[ActiveScan Installer Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\asinst.dll
CODEBASE = http://acs.pandasoftware.com/active...

[Java Plug-in 1.4.2]
InProcServer32 = C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
CODEBASE = http://java.sun.com/products/plugin...

[Java Plug-in 1.5.0_07]
InProcServer32 = C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
CODEBASE = http://java.sun.com/update/1.5.0/ji...

[Java Plug-in 1.5.0_07]
InProcServer32 = C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
CODEBASE = http://java.sun.com/update/1.5.0/ji...

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9c.ocx
CODEBASE = http://download.macromedia.com/pub/...

[Driver Agent ActiveX Control]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\driveragent.ocx
CODEBASE = http://driveragent.com/files/driver...

[McFreeScan Class]
InProcServer32 = C:\WINDOWS\McAfee.com\FreeScan\mcfscan.dll
CODEBASE = http://download.mcafee.com/molbin/i...

---------------------

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll
Protocol #12: C:\WINDOWS\system32\mswsock.dll
Protocol #13: C:\WINDOWS\system32\mswsock.dll
Protocol #14: C:\WINDOWS\system32\mswsock.dll
Protocol #15: C:\WINDOWS\system32\mswsock.dll
Protocol #16: C:\WINDOWS\system32\mswsock.dll
Protocol #17: C:\WINDOWS\system32\mswsock.dll
Protocol #18: C:\WINDOWS\system32\mswsock.dll
Protocol #19: C:\WINDOWS\system32\mswsock.dll
Protocol #20: C:\WINDOWS\system32\mswsock.dll
Protocol #21: C:\WINDOWS\system32\mswsock.dll

---------------------

Enumerating Windows NT/2000/XP services

abp480n5: system32\DRIVERS\ABP480N5.SYS (system)
Microsoft ACPI Driver: system32\DRIVERS\ACPI.sys (system)
adpu160m: system32\DRIVERS\adpu160m.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD: \SystemRoot\System32\drivers\afd.sys (system)
Intel AGP Bus Filter: system32\DRIVERS\agp440.sys (system)
Compaq AGP Bus Filter: system32\DRIVERS\agpCPQ.sys (system)
Aha154x: system32\DRIVERS\aha154x.sys (system)
aic78u2: system32\DRIVERS\aic78u2.sys (system)
aic78xx: system32\DRIVERS\aic78xx.sys (system)
Alerter: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
AliIde: system32\DRIVERS\aliide.sys (system)
ALI AGP Bus Filter: system32\DRIVERS\alim1541.sys (system)
AMD AGP Bus Filter Driver: system32\DRIVERS\amdagp.sys (system)
amsint: system32\DRIVERS\amsint.sys (system)
AOL Connectivity Service: "C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe" (autostart)
AOL TopSpeed Monitor: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe (autostart)
AOL Antivirus Update Service: "C:\Program Files\Common Files\AOL\1125995842\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe" (autostart)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
1394 ARP Client Protocol: system32\DRIVERS\arp1394.sys (manual start)
asc: system32\DRIVERS\asc.sys (system)
asc3350p: system32\DRIVERS\asc3350p.sys (system)
asc3550: system32\DRIVERS\asc3550.sys (system)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: system32\DRIVERS\atapi.sys (system)
atksgt: system32\DRIVERS\atksgt.sys (autostart)
ATM ARP Client Protocol: system32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: system32\DRIVERS\audstub.sys (manual start)
Automatic LiveUpdate Scheduler: "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" (autostart)
AVG7 Alert Manager Server: C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe (autostart)
AVG7 Update Service: C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe (autostart)
AVG7 Clean Driver: \SystemRoot\System32\Drivers\avgclean.sys (system)
AVG7 Resident Shield Service: C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe (autostart)
AVG E-mail Scanner: C:\PROGRA~1\Grisoft\AVG7\avgemc.exe (autostart)
AVG Minifilter x86 Resident Driver: \SystemRoot\System32\Drivers\avgmfx86.sys (system)
AVG Network Redirector: \SystemRoot\System32\Drivers\avgtdi.sys (autostart)
Background Intelligent Transfer Service: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Computer Browser: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
cbidf: system32\DRIVERS\cbidf2k.sys (system)
cd20xrnt: system32\DRIVERS\cd20xrnt.sys (system)
CD-ROM Driver: system32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisvc.exe (autostart)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
CmdIde: system32\DRIVERS\cmdide.sys (system)
COM+ System Application: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cpqarray: system32\DRIVERS\cpqarray.sys (system)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
dac2w2k: system32\DRIVERS\dac2w2k.sys (system)
dac960nt: system32\DRIVERS\dac960nt.sys (system)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DHCP Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Disk Driver: system32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
dmio: System32\drivers\dmio.sys (disabled)
dmload: System32\drivers\dmload.sys (disabled)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
MS Software Shadow Download Provider: "C:\DOCUME~1\Owner\LOCALS~1\Temp\dnlsvc.exe" (autostart)
DNS Client: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart)
DomainService: C:\WINDOWS\system32\qwerty12.exe /service (disabled)
dpti2o: system32\DRIVERS\dpti2o.sys (system)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
Intel(R) PRO Adapter Driver: system32\DRIVERS\e100b325.sys (manual start)
EntDrv51: \??\C:\WINDOWS\system32\drivers\EntDrv51.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINDOWS\system32\svchost.exe -k netsvcs (manual start)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Floppy Disk Controller Driver: system32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: system32\DRIVERS\flpydisk.sys (manual start)
FltMgr: system32\DRIVERS\fltMgr.sys (system)
Volume Manager Driver: system32\DRIVERS\ftdisk.sys (system)
GEARAspiWDM: System32\Drivers\GEARAspiWDM.sys (manual start)
Generic Packet Classifier: system32\DRIVERS\msgpc.sys (manual start)
Google Updater Service: "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" (manual start)
Microsoft UAA Function Driver for High Definition Audio Service: system32\drivers\HdAudio.sys (manual start)
Microsoft UAA Bus Driver for High Definition Audio: system32\DRIVERS\HDAudBus.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Human Interface Device Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Microsoft HID Class Driver: system32\DRIVERS\hidusb.sys (manual start)
hpn: system32\DRIVERS\hpn.sys (system)
HSFHWBS2: system32\DRIVERS\HSFHWBS2.sys (manual start)
HSF_DP: system32\DRIVERS\HSF_DP.sys (manual start)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i2omp: system32\DRIVERS\i2omp.sys (system)
i8042 Keyboard and PS/2 Mouse Port Driver: system32\DRIVERS\i8042prt.sys (system)
ialm: system32\DRIVERS\ialmnt5.sys (manual start)
InstallDriver Table Manager: "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" (manual start)
CD-Burning Filter Driver: system32\DRIVERS\imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINDOWS\system32\imapi.exe (manual start)
ini910u: system32\DRIVERS\ini910u.sys (system)
Service for Realtek HD Audio (WDM): system32\drivers\RtkHDAud.sys (manual start)
IntelIde: system32\DRIVERS\intelide.sys (system)
Intel Processor Driver: system32\DRIVERS\intelppm.sys (system)
IPv6 Windows Firewall Driver: system32\DRIVERS\Ip6Fw.sys (manual start)
IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: system32\DRIVERS\ipnat.sys (manual start)
iPod Service: "C:\Program Files\iPod\bin\iPodService.exe" (manual start)
IPSEC driver: system32\DRIVERS\ipsec.sys (system)
IR Enumerator Service: system32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: system32\DRIVERS\isapnp.sys (system)
CA Pest Patrol Realtime Protection Service: "C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe" (autostart)
Keyboard Class Driver: system32\DRIVERS\kbdclass.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Server: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
lirsgt: system32\DRIVERS\lirsgt.sys (autostart)
LiveUpdate: "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.exe" (manual start)
TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
McAfee AntiSpyware Real-Time Scanner: C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe (autostart)
McAfee SecurityCenter Update Manager: C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (manual start)
mdmxsdk: system32\DRIVERS\mdmxsdk.sys (autostart)
Messenger: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
NetMeeting Remote Desktop Sharing: C:\WINDOWS\system32\mnmsrvc.exe (manual start)
Mouse Class Driver: system32\DRIVERS\mouclass.sys (system)
Mouse HID Driver: system32\DRIVERS\mouhid.sys (manual start)
MPFIREWL: System32\Drivers\MpFirewall.sys (system)
McAfee Personal Firewall Service: "C:\Program Files\mcafee.com\personal firewall\MPFService.exe" (autostart)
mraid35x: system32\DRIVERS\mraid35x.sys (system)
WebDav Client Redirector: system32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: system32\DRIVERS\mrxsmb.sys (system)
msdirect: \??\C:\WINDOWS\system32\msdirect.sys (autostart)
Distributed Transaction Coordinator: C:\WINDOWS\system32\msdtc.exe (manual start)
Windows Installer: C:\WINDOWS\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: system32\DRIVERS\mssmbios.sys (manual start)
Macronix MX987xx Family Fast Ethernet NT Driver: system32\DRIVERS\mxnic.sys (manual start)
NaiAvFilter1: system32\drivers\naiavf5x.sys (manual start)
Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: system32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: system32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: system32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\system32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
1394 Net Driver: system32\DRIVERS\nic1394.sys (manual start)
Network Location Awareness (NLA): %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
NT LM Security Support Provider: %SystemRoot%\system32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
nv: system32\DRIVERS\nv4_mini.sys (manual start)
IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.sys (manual start)
OHCI Compliant IEEE 1394 Host Controller: system32\DRIVERS\ohci1394.sys (system)
Intel PentiumIII Processor Driver: system32\DRIVERS\p3.sys (system)
Parallel port driver: system32\DRIVERS\parport.sys (manual start)
PCI Bus Driver: system32\DRIVERS\pci.sys (system)
PCIIde: system32\DRIVERS\pciide.sys (system)
perc2: system32\DRIVERS\perc2.sys (system)
perc2hib: system32\DRIVERS\perc2hib.sys (system)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\system32\lsass.exe (autostart)
WAN Miniport (PPTP): system32\DRIVERS\raspptp.sys (manual start)
PrismXL: C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (autostart)
WUSB54GV2 802.11g USB Driver: system32\DRIVERS\WUSBGXP.sys (manual start)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
QoS Packet Scheduler: system32\DRIVERS\psched.sys (manual start)
Direct Parallel Link Driver: system32\DRIVERS\ptilink.sys (manual start)
ql1080: system32\DRIVERS\ql1080.sys (system)
Ql10wnt: system32\DRIVERS\ql10wnt.sys (system)
ql12160: system32\DRIVERS\ql12160.sys (system)
ql1240: system32\DRIVERS\ql1240.sys (system)
ql1280: system32\DRIVERS\ql1280.sys (system)
Remote Access Auto Connection Driver: system32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: system32\DRIVERS\raspti.sys (manual start)
Rdbss: system32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Terminal Server Device Redirector Driver: system32\DRIVERS\rdpdr.sys (manual start)
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: system32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
Remote Procedure Call (RPC) Locator: %SystemRoot%\system32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\system32\rsvp.exe (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Schedule: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Secdrv: system32\DRIVERS\secdrv.sys (autostart)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: system32\DRIVERS\serenum.sys (manual start)
Serial port driver: system32\DRIVERS\serial.sys (system)
Service: C:\WINDOWS\system32\Service.exe (autostart)
StarForce Protection Environment Driver (version 1.x): System32\drivers\sfdrv01.sys (system)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
SIS AGP Bus Filter: system32\DRIVERS\sisagp.sys (system)
Symantec Network Drivers Service: "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe" (manual start)
Sparrow: system32\DRIVERS\sparrow.sys (system)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
System Restore Filter Driver: system32\DRIVERS\sr.sys (system)
System Restore Service: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Srv: system32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\system32\svchost.exe -k imgsvc (manual start)
Alcor Micro Corp - 9360: \??\C:\WINDOWS\System32\Drivers\sunkfilt.sys (manual start)
Alcor Micro Corp - 3239: \??\C:\WINDOWS\System32\Drivers\sunkfilt39.sys (manual start)
HP && Alcor Micro Corp for Phison: \??\C:\WINDOWS\System32\Drivers\sunkfiltp.sys (manual start)
Software Bus Driver: system32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINDOWS\system32\dllhost.exe /Processid:{63C33B1B-E9A2-4399-8C21-F59FA31488FA} (manual start)
symc810: system32\DRIVERS\symc810.sys (system)
symc8xx: system32\DRIVERS\symc8xx.sys (system)
SymEvent: \??\C:\Program Files\Symantec\SYMEVENT.SYS (manual start)
SYMREDRV: \SystemRoot\System32\Drivers\SYMREDRV.SYS (manual start)
SYMTDI: \SystemRoot\System32\Drivers\SYMTDI.SYS (system)
sym_hi: system32\DRIVERS\sym_hi.sys (system)
sym_u3: system32\DRIVERS\sym_u3.sys (system)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: system32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: system32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
tmcomm: \??\C:\WINDOWS\system32\drivers\tmcomm.sys (autostart)
TosIde: system32\DRIVERS\toside.sys (system)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
TVICHW32: \??\C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS (manual start)
ultra: system32\DRIVERS\ultra.sys (system)
Microcode Update Driver: system32\DRIVERS\update.sys (manual start)
Universal Plug and Play Device Host: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.sys (manual start)
USB2 Enabled Hub: system32\DRIVERS\usbhub.sys (manual start)
Microsoft USB PRINTER Class: system32\DRIVERS\usbprint.sys (manual start)
USB Mass Storage Driver: system32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: system32\DRIVERS\usbuhci.sys (manual start)
VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
VIA AGP Bus Filter: system32\DRIVERS\viaagp.sys (system)
ViaIde: system32\DRIVERS\viaide.sys (system)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: system32\DRIVERS\wanarp.sys (manual start)
WAN Miniport (ATW): system32\DRIVERS\wanatw4.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
winachsf: system32\DRIVERS\HSF_CNXT.sys (manual start)
Windows Management Service: C:\WINDOWS\system32\dmqgy.exe -service (disabled)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WMI Performance Adapter: C:\WINDOWS\system32\wbem\wmiapsrv.exe (manual start)
Windows Media Player Network Sharing Service: "C:\Program Files\Windows Media Player\WMPNetwk.exe" (manual start)
Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Windows Driver Foundation - User-mode Driver Framework Platform Driver: system32\DRIVERS\WudfPf.sys (manual start)
Windows Driver Foundation - User-mode Driver Framework Reflector: system32\DRIVERS\wudfrd.sys (manual start)
Windows Driver Foundation - User-mode Driver Framework: %SystemRoot%\system32\svchost.exe -k WudfServiceGroup (manual start)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Network Provisioning Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


---------------------

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe|||t

---------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll

---------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

---------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

SystemDriver =
FDriver =
ADriver =
CDriver =
DDriver =

---------------------

End of report, 41,534 bytes
Report generated in 0.109 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only


0

Response Number 18
Name: jabuck
Date: October 25, 2007 at 19:12:53 Pacific
Reply:

There is a rootkit on the computer and two other bad viri.

Go to start> control panel> administrative tools> services> scroll down to msdirect: and double click it> click the blue drop down arrow on the far right of "startup type" and select disable> apply > ok.

Restart the computer into safe mode.

Set up the computer to view hidden files by going to start>control panel>folder options>view tab>tick the circle beside "show hidden files and folders" and untick the box beside "hide extensions of known file types" and "hide protected system operating files">apply>ok.

Next, navigate to and dekete this file if found:

C:\WINDOWS\system32\uwbhthfh.dll

Reboot to normal mode.

Run the Doug Knox .EXE file association fix.

Then try to run Combofix.


0

Response Number 19
Name: timmay
Date: October 26, 2007 at 12:50:09 Pacific
Reply:

any way i can get to that without double clicking like through task manager... double clicking doesnt work


0

Response Number 20
Name: jabuck
Date: October 26, 2007 at 14:31:29 Pacific
Reply:

Right click> click "open" until you get to the service "msdirect" then right click> click "properties".


0

Response Number 21
Name: timmay
Date: October 26, 2007 at 15:01:37 Pacific
Reply:

right clicking on it didnt work either


0

Response Number 22
Name: jabuck
Date: October 26, 2007 at 15:41:20 Pacific
Reply:

Go to start> run> type in the following command on at the time and press "ok".

sc stop msdirect

sc delete msdirect

Then continue with response #18.


0

Response Number 23
Name: timmay
Date: October 29, 2007 at 13:08:03 Pacific
Reply:

sorry for the late response
stop msdirect didnt seem to work but delete did
the rest didnt work, but ill try it again


0

Response Number 24
Name: jabuck
Date: October 29, 2007 at 19:28:15 Pacific
Reply:

See if you can run your antivirus and Combofix from safe mode.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: need help getting back to normal

Need help removing virus or trojan www.computing.net/answers/security/need-help-removing-virus-or-trojan/21217.html

I need help getting rid of a virus! www.computing.net/answers/security/i-need-help-getting-rid-of-a-virus/26688.html

AIM Myspace virus HELP www.computing.net/answers/security/aim-myspace-virus-help/20442.html