ComboFix 12-10-25.01 - jonas 2012.10.25 12:44:11.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8126.5631 [GMT 3:00]
Running from: c:\users\jonas\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\jonas\AppData\Local\.#
c:\users\jonas\AppData\Local\.#\MBX@1038@23F2020.###
c:\users\jonas\AppData\Local\.#\MBX@1038@2722020.###
c:\users\jonas\AppData\Local\.#\MBX@1180@302020.###
c:\users\jonas\AppData\Local\.#\MBX@1188@24B2020.###
c:\users\jonas\AppData\Local\.#\MBX@123C@2872020.###
c:\users\jonas\AppData\Local\.#\MBX@135C@25A2020.###
c:\users\jonas\AppData\Local\.#\MBX@161C@3A2020.###
c:\users\jonas\AppData\Local\.#\MBX@1704@24F2020.###
c:\users\jonas\AppData\Local\.#\MBX@198C@2A12020.###
c:\users\jonas\AppData\Local\.#\MBX@19D8@8A2020.###
c:\users\jonas\AppData\Local\.#\MBX@1B84@8F2020.###
c:\users\jonas\AppData\Local\.#\MBX@1E00@3F2020.###
c:\users\jonas\AppData\Local\.#\MBX@2018@23A2020.###
c:\users\jonas\AppData\Local\.#\MBX@274@2322020.###
c:\users\jonas\AppData\Local\.#\MBX@28AC@1002020.###
c:\users\jonas\AppData\Local\.#\MBX@2908@2852020.###
c:\users\jonas\AppData\Local\.#\MBX@2970@F02020.###
c:\users\jonas\AppData\Local\.#\MBX@298C@21A2020.###
c:\users\jonas\AppData\Local\.#\MBX@384@2E2020.###
c:\users\jonas\AppData\Local\.#\MBX@3B54@332020.###
c:\users\jonas\AppData\Local\.#\MBX@6FC@2812020.###
c:\users\jonas\AppData\Local\.#\MBX@888@312020.###
c:\users\jonas\AppData\Local\.#\MBX@898@25D2020.###
c:\users\jonas\AppData\Local\.#\MBX@BB0@892020.###
c:\users\jonas\AppData\Local\.#\MBX@BE0@3F2020.###
c:\users\jonas\AppData\Local\.#\MBX@C80@2892020.###
c:\users\jonas\AppData\Local\.#\MBX@D50@26E2020.###
c:\users\jonas\AppData\Local\.#\MBX@E0C@21C2020.###
c:\users\jonas\AppData\Local\.#\MBX@E18@892020.###
c:\users\jonas\AppData\Local\.#\MBX@F3C@8D2020.###
c:\users\jonas\AppData\Local\.#\MBX@F78@2372020.###
c:\windows\SysWow64\sysmwwod.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-09-25 to 2012-10-25 )))))))))))))))))))))))))))))))
.
.
2012-10-25 09:48 . 2012-10-25 09:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-10-24 13:57 . 2012-10-24 13:57 -------- d-----w- c:\program files\Ventrilo
2012-10-24 13:13 . 2012-10-24 13:13 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2012-10-24 12:27 . 2012-10-24 13:18 696760 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-23 20:29 . 2012-10-23 20:29 -------- d-----w- c:\users\jonas\AppData\Roaming\Malwarebytes
2012-10-23 20:29 . 2012-10-23 20:29 -------- d-----w- c:\programdata\Malwarebytes
2012-10-23 20:29 . 2012-10-23 20:29 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-10-23 20:29 . 2012-09-29 16:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-10-23 20:09 . 2012-10-23 20:09 -------- d-----w- c:\users\jonas\AppData\Roaming\SUPERAntiSpyware.com
2012-10-23 20:09 . 2012-10-23 20:27 -------- d-----w- c:\program files (x86)\Google
2012-10-23 20:09 . 2012-10-23 20:09 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-10-23 20:09 . 2012-10-23 20:09 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2012-10-23 14:21 . 2012-10-23 14:21 -------- d-----w- c:\programdata\ATI
2012-10-23 14:13 . 2012-10-23 14:13 -------- d-----w- c:\program files (x86)\AMD APP
2012-10-23 14:13 . 2012-10-23 14:13 -------- d-----w- c:\program files\Common Files\ATI Technologies
2012-10-23 14:13 . 2012-10-23 14:13 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies
2012-10-23 14:12 . 2012-10-23 14:13 -------- d-----w- c:\program files\ATI Technologies
2012-10-23 14:04 . 2012-10-23 14:04 -------- d-----w- c:\users\jonas\AppData\Roaming\Nitro PDF
2012-10-23 14:03 . 2012-10-23 14:03 -------- d-----w- c:\programdata\Nitro PDF
2012-10-23 14:03 . 2012-10-23 14:07 -------- d-----w- c:\users\jonas\AppData\Roaming\DRPSu
2012-10-23 13:18 . 2012-10-12 07:19 9291768 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{71234E7A-14A0-4517-BA53-4CA6AD33FE08}\mpengine.dll
2012-10-23 13:10 . 2012-10-23 13:10 -------- d-----w- C:\Intel
2012-10-23 13:00 . 2012-10-23 13:00 -------- d-----w- c:\program files\ATI
2012-10-23 11:43 . 2012-10-23 12:59 -------- d-----w- C:\AMD
2012-10-23 11:30 . 2012-10-23 11:30 -------- d-----w- c:\windows\SysWow64\searchplugins
2012-10-23 11:30 . 2012-10-23 11:30 -------- d-----w- c:\windows\SysWow64\Extensions
2012-10-21 21:48 . 2012-10-24 23:56 -------- d-----w- c:\users\jonas\AppData\Roaming\vlc
2012-10-21 21:21 . 2012-10-21 21:21 -------- d-----w- c:\users\jonas\AppData\Local\Geckofx
2012-10-21 21:21 . 2012-10-21 21:21 -------- d-----w- c:\programdata\Graboid Inc
2012-10-21 21:20 . 2012-10-21 21:47 -------- d-----w- c:\program files (x86)\Graboid
2012-10-17 18:00 . 2012-10-17 20:11 -------- d-----w- c:\users\jonas\AppData\Local\DirectDownloader
2012-10-15 20:07 . 2012-10-24 13:23 -------- d-----w- C:\NTTGame
2012-10-14 07:30 . 2012-10-14 07:30 -------- d-----w- c:\users\jonas\AppData\Local\Downloaded Installations
2012-10-14 07:29 . 2012-10-14 07:28 38400 ----a-w- c:\windows\system32\suhlp64.exe
2012-10-14 07:27 . 2012-10-14 07:27 443760 ----a-w- c:\program files (x86)\Common Files\InstallShield\UpdateService\_isusres.dll
2012-10-14 07:27 . 2012-10-14 07:27 -------- d-----w- c:\users\jonas\AppData\Roaming\Macrovision
2012-10-14 07:27 . 2012-10-14 07:27 -------- d-----w- c:\users\jonas\AppData\Roaming\FLEXnet
2012-10-14 07:27 . 2012-10-14 07:27 -------- d-----w- c:\windows\DPDrv
2012-10-14 07:27 . 2012-10-14 07:27 -------- d-----w- c:\users\jonas\AppData\Local\Programs
2012-10-14 07:25 . 2011-11-05 03:44 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2012-10-14 07:25 . 2011-11-05 03:44 99328 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2012-10-14 07:25 . 2011-11-05 03:44 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2012-10-14 07:25 . 2011-11-05 03:43 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2012-10-14 07:25 . 2011-11-05 03:43 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2012-10-14 07:25 . 2011-11-05 03:43 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2012-10-14 07:25 . 2011-11-05 03:43 7936 ----a-w- c:\windows\system32\drivers\usbd.sys
2012-10-14 07:24 . 2011-09-18 01:59 48640 ----a-w- c:\windows\system32\wwanprotdim.dll
2012-10-14 07:24 . 2011-09-18 01:59 229888 ----a-w- c:\windows\system32\wwansvc.dll
2012-10-14 07:24 . 2011-07-15 05:24 983936 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2012-10-14 07:24 . 2011-07-15 05:24 265088 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2012-10-14 07:22 . 2011-02-25 06:25 296320 ----a-w- c:\windows\system32\drivers\volsnap.sys
2012-10-14 07:21 . 2011-01-14 06:23 163840 ----a-w- c:\windows\system32\umpo.dll
2012-10-10 23:43 . 2012-10-10 23:43 -------- d-----w- c:\program files (x86)\Skype
2012-10-10 23:43 . 2012-10-10 23:43 -------- d-----w- c:\program files (x86)\Common Files\Skype
2012-10-10 04:56 . 2012-08-31 18:19 1659760 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-10-10 04:56 . 2012-08-30 18:03 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-10-10 04:56 . 2012-08-30 17:12 3968880 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-10-10 04:56 . 2012-08-30 17:12 3914096 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-10-10 04:54 . 2012-08-24 18:05 220160 ----a-w- c:\windows\system32\wintrust.dll
2012-10-10 04:54 . 2012-08-24 16:57 172544 ----a-w- c:\windows\SysWow64\wintrust.dll
2012-10-10 04:54 . 2012-09-14 19:19 2048 ----a-w- c:\windows\system32\tzres.dll
2012-10-10 04:54 . 2012-09-14 18:28 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-10-10 04:54 . 2012-08-11 00:56 715776 ----a-w- c:\windows\system32\kerberos.dll
2012-10-10 04:54 . 2012-08-10 23:56 542208 ----a-w- c:\windows\SysWow64\kerberos.dll
2012-10-10 04:54 . 2012-06-02 05:41 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2012-10-10 04:54 . 2012-06-02 05:41 140288 ----a-w- c:\windows\system32\cryptnet.dll
2012-10-10 04:54 . 2012-06-02 05:41 1464320 ----a-w- c:\windows\system32\crypt32.dll
2012-10-10 04:54 . 2012-06-02 04:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2012-10-10 04:54 . 2012-06-02 04:36 1159680 ----a-w- c:\windows\SysWow64\crypt32.dll
2012-10-10 04:54 . 2012-06-02 04:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2012-10-07 10:58 . 2012-10-07 10:58 -------- d-----w- c:\users\jonas\AppData\Roaming\Hewlett-Packard Company
2012-10-07 10:54 . 2012-10-07 10:54 -------- d-----w- c:\program files (x86)\Common Files\Telespree
2012-10-04 19:26 . 2012-10-04 19:28 -------- d-----w- c:\users\jonas\AppData\Roaming\Bug Doctor
2012-10-04 19:26 . 2012-10-04 19:26 -------- d--h--w- c:\programdata\Common Files
2012-10-04 18:45 . 2012-10-04 19:08 -------- d-----w- c:\users\jonas\AppData\Roaming\RegistryTool
2012-10-04 11:08 . 2012-10-04 11:08 7680 ----a-w- c:\windows\system32\drivers\en-US\bthport.sys.mui
2012-10-04 11:08 . 2012-10-04 11:08 44032 ----a-w- c:\windows\system32\drivers\en-US\tcpip.sys.mui
2012-10-04 11:08 . 2012-10-04 11:08 3584 ----a-w- c:\windows\system32\drivers\en-US\portcls.sys.mui
2012-10-04 11:08 . 2012-10-04 11:08 3072 ----a-w- c:\windows\system32\drivers\en-US\hidbth.sys.mui
2012-10-04 11:08 . 2012-10-04 11:08 3072 ----a-w- c:\windows\system32\drivers\en-US\ataport.sys.mui
2012-10-04 11:08 . 2012-10-04 11:08 2560 ----a-w- c:\windows\system32\drivers\en-US\serscan.sys.mui
2012-10-04 11:08 . 2012-10-04 11:08 2560 ----a-w- c:\windows\system32\drivers\en-US\BTHUSB.SYS.mui
2012-10-04 11:08 . 2012-10-04 11:08 2048 ----a-w- c:\windows\system32\drivers\en-US\bthenum.sys.mui
2012-10-04 11:08 . 2012-10-04 11:08 2048 ----a-w- c:\windows\system32\drivers\en-US\amdide.sys.mui
2012-10-04 11:07 . 2012-10-04 11:07 2560 ----a-w- c:\windows\system32\drivers\en-US\scfilter.sys.mui
2012-10-04 10:46 . 2012-10-04 10:46 -------- d-----w- c:\windows\system32\EventProviders
2012-10-04 05:45 . 2012-05-04 11:00 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-10-04 05:45 . 2012-05-04 09:59 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-10-03 15:15 . 2012-10-06 22:29 -------- d-----w- C:\Fraps
2012-09-29 17:43 . 2012-09-29 17:44 224016 ----a-w- c:\windows\system32\TABCTL32.OCX
2012-09-28 12:37 . 2012-09-28 12:37 221696 ----a-w- c:\windows\system32\clinfo.exe
2012-09-28 12:36 . 2012-09-28 12:36 75776 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-09-28 12:36 . 2012-09-28 12:36 65536 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-09-28 12:36 . 2012-09-28 12:36 63488 ----a-w- c:\windows\system32\OVDecode64.dll
2012-09-28 12:36 . 2012-09-28 12:36 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-09-28 12:36 . 2012-09-28 12:36 32635904 ----a-w- c:\windows\system32\amdocl64.dll
2012-09-28 12:32 . 2012-09-28 12:32 27341824 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-09-28 12:28 . 2012-09-28 12:28 54784 ----a-w- c:\windows\system32\OpenCL.dll
2012-09-28 12:28 . 2012-09-28 12:28 50176 ----a-w- c:\windows\SysWow64\OpenCL.dll
2012-09-28 10:19 . 2012-09-28 10:19 -------- d-----w- c:\users\jonas\AppData\Local\ArcSoft
2012-09-27 20:56 . 2012-09-27 20:56 -------- d-----w- c:\users\jonas\AppData\Roaming\Free MP3 WMA Cutter
2012-09-27 20:45 . 2002-01-05 13:37 344064 ----a-w- c:\windows\SysWow64\msvcr70.dll
2012-09-27 20:45 . 2002-11-06 12:12 360448 ----a-w- c:\windows\SysWow64\NCTWMAFile.dll
2012-09-27 20:45 . 2000-12-05 21:00 209608 ----a-w- c:\windows\SysWow64\Tabctl32.ocx
2012-09-27 20:45 . 2002-11-13 08:14 1703936 ----a-w- c:\windows\SysWow64\NCTAudioFile.dll
2012-09-27 20:45 . 2002-09-06 08:36 233472 ----a-w- c:\windows\SysWow64\lame_enc.dll
2012-09-27 20:45 . 2001-03-13 10:51 1066176 ----a-w- c:\windows\SysWow64\Mscomctl.ocx
2012-09-27 20:45 . 2000-08-21 08:22 1388544 ----a-w- c:\windows\SysWow64\temp.001
2012-09-27 20:45 . 2012-10-23 14:07 -------- d-----w- c:\program files (x86)\ACE-HIGH MP3 WAV WMA OGG Converter
2012-09-27 20:45 . 2002-07-09 19:42 140288 ----a-w- c:\windows\SysWow64\Comdlg32.ocx
2012-09-27 20:45 . 2002-06-13 10:50 376832 ----a-w- c:\windows\SysWow64\actskin4.ocx
2012-09-27 20:45 . 2001-08-08 18:00 40960 ----a-w- c:\windows\SysWow64\DGPNorm.ocx
2012-09-27 20:45 . 2000-06-08 14:00 73785 ----a-w- c:\windows\SysWow64\temp.000
2012-09-27 10:05 . 2012-10-04 11:08 -------- d-----w- c:\program files\Windows Journal
2012-09-27 10:05 . 2012-09-27 10:05 -------- d-----w- c:\windows\ShellNew
2012-09-27 10:05 . 2012-09-27 10:05 -------- d-----w- c:\program files\Microsoft Games
2012-09-27 10:00 . 2012-09-27 10:00 -------- d-----w- c:\windows\SysWow64\BestPractices
2012-09-27 09:59 . 2012-09-27 09:59 -------- d-----w- c:\windows\system32\BestPractices
2012-09-27 09:59 . 2012-09-27 09:59 -------- d-----w- C:\inetpub
2012-09-26 07:28 . 2012-08-21 21:01 245760 ----a-w- c:\windows\system32\OxpsConverter.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-25 09:50 . 2012-10-25 09:50 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{71234E7A-14A0-4517-BA53-4CA6AD33FE08}\offreg.dll
2012-10-24 13:18 . 2012-09-17 17:42 73656 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-14 07:28 . 2012-07-04 12:22 1424896 ----a-w- c:\windows\sttray64.exe
2012-10-14 07:28 . 2012-07-04 12:22 442368 ----a-w- c:\windows\system32\AESTEC64.dll
2012-10-14 07:28 . 2012-07-04 12:22 90624 ----a-w- c:\windows\system32\AESTCo64.dll
2012-10-14 07:28 . 2012-07-04 12:21 255488 ----a-w- c:\windows\system32\staco64.dll
2012-10-04 11:07 . 2012-10-04 11:07 2560 ----a-w- c:\windows\SysWow64\drivers\en-US\scfilter.sys.mui
2012-10-04 11:07 . 2012-10-04 11:07 44032 ----a-w- c:\windows\SysWow64\drivers\en-US\tcpip.sys.mui
2012-09-15 16:14 . 2012-09-15 16:13 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-09-15 13:27 . 2010-06-24 19:33 19720 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-08-30 21:43 . 2012-09-18 22:50 64462936 ----a-w- c:\windows\system32\MRT.exe
2012-08-30 13:46 . 2012-08-30 13:46 71680 ----a-w- c:\windows\system32\frapsv64.dll
2012-08-30 13:46 . 2012-08-30 13:46 65536 ----a-w- c:\windows\SysWow64\frapsvid.dll
2012-08-24 11:15 . 2012-09-22 20:21 17810944 ----a-w- c:\windows\system32\mshtml.dll
2012-08-24 10:39 . 2012-09-22 20:21 10925568 ----a-w- c:\windows\system32\ieframe.dll
2012-08-24 10:31 . 2012-09-22 20:21 2312704 ----a-w- c:\windows\system32\jscript9.dll
2012-08-24 10:22 . 2012-09-22 20:21 1346048 ----a-w- c:\windows\system32\urlmon.dll
2012-08-24 10:21 . 2012-09-22 20:21 1392128 ----a-w- c:\windows\system32\wininet.dll
2012-08-24 10:20 . 2012-09-22 20:21 1494528 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-24 10:18 . 2012-09-22 20:21 237056 ----a-w- c:\windows\system32\url.dll
2012-08-24 10:17 . 2012-09-22 20:21 85504 ----a-w- c:\windows\system32\jsproxy.dll
2012-08-24 10:14 . 2012-09-22 20:21 173056 ----a-w- c:\windows\system32\ieUnatt.exe
2012-08-24 10:14 . 2012-09-22 20:21 816640 ----a-w- c:\windows\system32\jscript.dll
2012-08-24 10:13 . 2012-09-22 20:21 599040 ----a-w- c:\windows\system32\vbscript.dll
2012-08-24 10:12 . 2012-09-22 20:21 2144768 ----a-w- c:\windows\system32\iertutil.dll
2012-08-24 10:11 . 2012-09-22 20:21 729088 ----a-w- c:\windows\system32\msfeeds.dll
2012-08-24 10:10 . 2012-09-22 20:21 96768 ----a-w- c:\windows\system32\mshtmled.dll
2012-08-24 10:09 . 2012-09-22 20:21 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-08-24 10:04 . 2012-09-22 20:21 248320 ----a-w- c:\windows\system32\ieui.dll
2012-08-24 06:59 . 2012-09-22 20:21 1800704 ----a-w- c:\windows\SysWow64\jscript9.dll
2012-08-24 06:51 . 2012-09-22 20:21 1129472 ----a-w- c:\windows\SysWow64\wininet.dll
2012-08-24 06:51 . 2012-09-22 20:21 1427968 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2012-08-24 06:47 . 2012-09-22 20:21 142848 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2012-08-24 06:47 . 2012-09-22 20:21 420864 ----a-w- c:\windows\SysWow64\vbscript.dll
2012-08-24 06:43 . 2012-09-22 20:21 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2012-08-22 18:12 . 2012-09-18 22:13 1913200 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-08-22 18:12 . 2012-09-18 22:13 950128 ----a-w- c:\windows\system32\drivers\ndis.sys
2012-08-22 18:12 . 2012-09-18 22:13 376688 ----a-w- c:\windows\system32\drivers\netio.sys
2012-08-22 18:12 . 2012-09-18 22:13 288624 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2012-08-20 17:38 . 2012-10-10 04:55 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2012-08-02 17:58 . 2012-09-18 22:13 574464 ----a-w- c:\windows\system32\d3d10level9.dll
2012-08-02 16:57 . 2012-09-18 22:13 490496 ----a-w- c:\windows\SysWow64\d3d10level9.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2008-02-01 21898024]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-10-16 5628800]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"QLBController"="c:\program files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" [2011-01-28 299576]
"File Sanitizer"="c:\program files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe" [2011-02-07 12274688]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-01-26 283160]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"HPQuickWebProxy"="c:\program files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" [2011-11-10 169528]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
2011-05-09 23:43 75320 ----a-w- c:\windows\System32\DeviceNP.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ DPPassFilter scecli
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-07-15 137272]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-09-29 676936]
R2 XobniService;XobniService;c:\program files (x86)\Xobni\XobniService.exe [2011-03-07 62184]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-24 250808]
R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [2011-01-07 36000]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [2011-01-07 298144]
R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [2011-01-07 201376]
R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [2011-01-07 55456]
R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [2011-01-07 154272]
R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [2011-01-07 279200]
R3 C7xxUSB;Samsung CMC7xx USB Network Driver;c:\windows\system32\DRIVERS\C7xUSBV6.sys [2009-05-19 52224]
R3 cphs;Intel(R) Content Protection HECI Service;c:\windows\SysWow64\IntelCpHeciSvc.exe [2012-03-19 276248]
R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv64.sys [2011-05-09 64312]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys
R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\SysWOW64\flcdlock.exe [2011-09-05 476728]
R3 hpCMSrv;HP Connection Manager 4 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-05-23 1098296]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-09-29 25928]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-10-11 115168]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-09-18 1255736]
S0 MfeEpeOpal;MfeEpeOpal;
S0 MfeEpePc;MfeEpePc;
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2012-09-15 283200]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2012-10-14 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-10-13 204288]
S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-07 138400]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2011-01-07 53920]
S2 HPDayStarterService;HP DayStarter Service;c:\program files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [2011-01-28 133688]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-04-25 197504]
S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2011-02-07 320000]
S2 hpHotkeyMonitor;hpHotkeyMonitor;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-01-28 281656]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2012-02-28 31000]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-01-26 13336]
S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [2010-11-29 210896]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-09-29 399432]
S2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent;c:\program files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2012-04-05 1323008]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2011-08-11 1128952]
S2 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-03-16 113264]
S2 uArcCapture;ArcCapture;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-01-17 2656280]
S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2012-02-15 2602576]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-10-13 10496000]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-10-13 326656]
S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;c:\windows\system32\DRIVERS\ArcSoftVCapture.sys [2010-11-11 32192]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [2011-01-07 28832]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys [2011-08-31 12306848]
S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2012-10-14 173656]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-20 56344]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2010-12-10 80384]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2010-12-10 181248]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2011-06-10 539240]
S3 SPUVCbv;SPUVCb Driver Service;c:\windows\system32\Drivers\SPUVCbv_x64.sys [2011-02-12 2612728]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
iissvcs REG_MULTI_SZ w3svc was
apphost REG_MULTI_SZ apphostsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-09-17 13:18]
.
2012-10-17 c:\windows\Tasks\HPCeeScheduleForJONAS-HP$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]
.
2012-10-21 c:\windows\Tasks\HPCeeScheduleForjonas.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]
.
2012-10-24 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 34f5d4cb-a0db-470e-ac8f-c8fdb51475ea.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
2012-10-24 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task fa39b443-6477-4257-a185-89b358166e7a.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MfeEpePcMonitor"="c:\program files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe" [2012-04-05 200704]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2012-10-14 1424896]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-31 167704]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-31 392472]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-31 416024]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mDefault_Page_URL = hxxp://www.bing.com?pc=CMNTDF
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\jonas\AppData\Roaming\Mozilla\Firefox\Profiles\jx645sye.default\
FF - prefs.js: browser.startup.homepage -
www.google.ltFF - ExtSQL: 2012-10-14 10:27;
[email protected]; c:\program files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{CAC42510-9B41-42c1-9DCD-7282A2D07C61} - (no file)
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="
v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="
v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2012-10-25 12:53:31 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-25 09:53
.
Pre-Run: 479.570.817.024 bytes free
Post-Run: 479.021.948.928 bytes free
.
- - End Of File - - 41E9DD8293D46640D823BFAD0C35D972