Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Trojan help


  • This topic is locked This topic is locked

#1
sgil

sgil

    New Member

  • Member
  • Pip
  • 8 posts
I know my computer is infected, I have run a virus scan with McAfee (though my actual antivirus software is not working)

The following were detected,

SMc1d9.exe - FakeAlert-SecurityMasterAV.b
SMc1d9_302.exe - FakeAlert-SecurityMasterAV.b
d8f7e1f8.exe - GEneric Dropper.p
Fn1.exe - Downloader-CEW.b

Plus WINDOWS\system32\drivers\etc\hosts - FakeAlert-LivePCGuard!hosts

Any antvirus software I download will not run, I cannot launch task manager to delete/stop any of the processes and am getting pretty desperate.

I have downloaded HiJackThis (before reading you recommend a different software) what information would you need from this?

Thanks in advance for any help.

Edited by admin, 08 August 2010 - 06:03 PM.

  • 0

Advertisements


#2
BlackOxide

BlackOxide

    Trusted Helper

  • Malware Removal
  • 1,976 posts
Hi, sgil! Welcome to GeeksToGo! My name is BlackOxide and I will be assisting you with your Malware/Security problems. Please make sure you read all of the instructions and fixes thoroughly before continuing with them. If you have any queries or you are unsure about anything, just say and I'll help you out :)

It may well be worth you printing/saving the instructions throughout the fix, so you have them to hand just incase you are unable to access this site.

Please note:
  • I am currently in training, so my replies will need to be quickly checked before I post them to you, so there may be a small delay in between.
  • Remember to post your logs, not attach them. So, any logs from any programs we run, should be just 'copied & pasted' into your reply.
  • Please only run the tools that I request. I know malware can be frustrating but running other tools in the meantime and between posts, only makes it harder for us to analyse and fix your PC in the long run.

OK, lets start :)


Please try the following which should produce some logs for me :)


Note: If using Firefox right-click on any download links and choose Save As

Please download OTH to your desktop
Please download OTL to your desktop
Please download the attached file Scan.txt to your desktop
Attached File  Scan.txt   934bytes   344 downloads


Double click the OTH file to run it and click Kill All Processes, your desktop will go blank.

Posted Image

Then select Start OTL. OTL will now run

  • Double-click on the Custom Scans box and a message box will popup asking if you want to load a custom scan from a file
    Select Scan.txt that you downloaded
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Click the Internet Explorer button, post these logs in your Virus Removal topic.


In your next reply
Please post the contents of...
OTL.txt
Extras.txt

  • 0

#3
sgil

sgil

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Thank you for your help and responce,

however when I try to run OTH, notepad opens with the following, what am I doing wrong? (sorry if I am being stupid)


MZP    @     !L!This program must be run under Win32
$7 PE L ^B*  r   @    
    @    t

{ |
D CODE
   PEC2O ` .rsrc 0
"  M Pd5 d% 3PECompact2 /@~3JQwMSjs>}?^Syvf޴g% _Um1wh
^&v8#PbL%[EЪ/| `Dz2ʻ~C/+)'0ާD5g-O4$O,MM56>;
i~yڍlԴ*/>EMjHۢn85(7^lJZ)4 P7xD*{價Wc)8~Xǣſ]_ߠQ?*6r_kaRndU>1Wc]屮q w䓵%磧KkTI5Ҳ蒁w:aQPfQb<;Z5}3؊r O䶦X8Wۡz>w8'@m=\>qeҘI?׃7.IFdt{?O9|al-AL%3G]X#XdN e&y^VEyo ~qgª1u5K,PsN!S JGE zE;n@d[$ $Qj:}3
$_C6J`~/&ALY?L,n:;\\`_=`0y6PQc,r{/ԡE
;dKu1o-s.uN_Vc1*g`aÍ@r8I`.zs+9SJ4brO<kjCOOiJf %vޡ4 NK큕=}n
,8$W;Txo>!L.`[6-"e c$cra4|[_V -]
f#qUvcfYDTDEEʫ1kYA]n17ݛW6@(@&*Ȃ%|aC
QQhX=7;k+d,`W@u{;

֨ô> TJq("avDAW9v(g1xAx)>C1d:0~$ 3Uܔ멶*K'kzmJ8 8^~ˏ;F ͹6>Oq34-@7n=女 0˿ 1[ZQtovI2΍%QD8hk]6m$-\"fr. #DMH@5Q-:@T‡7ZCu;8SlNTjG*(3?&Rv=MRAE(h3sd',zhu(?ՖFH3Xgi.1-aKo6@zXDX^=:Tr6͆ MԐ~m$$P@ EEH
9z>IL,hPFi6F#^#8u@E~ĬRkߡdl[՜xn6[V@ʘ?t?oZs,S2`m<՟}r%7{xk,*`r+@{]>s-s'H_p̟ G
S7hBJOYHYH:J6mJ @
BːeW4Bd&ўr\8g6WU_9,毝9ac ;$x#R9(LAɣW`3bSNN<|@=k<\p*.6~W5p
Np6k]ylS~go[4" ♇%.K%xemRh%iճֿa k͎X`T{^ Vm~pWan4zѮӒG*e9Dao xi$Y6>|hH<yf!FHƒ}q `W~̓}P\z?P%oaQ5̮R(JjЄ<d9G 4aM:@D6U RP ? P̛1?!<*cOefZ-&>!d1\$N)Ļ-_5z-҃XE'ŕ$Q&w1"yG4 Br;?ze[-K<wTt6N*i-ةjjX\4>Lݿ>-vqMq#Cѥrw|)2h , xǿY_>˲
?Nud}c-m@Jm:,QeK룃>fMa jdJ]lUEOȰOjbBal4Р|&]"瀊
J<lMN~h˶1tΐc
簦+
;ϰ[ʰmiOM=!0^boQg0++ث2INy὿9|9Q%!eJ?UPjY`4N>9z$V*W5S:)Ҷ[ҚR9߼$@zʃvf~9bL4<wBEN
7A,׹vt'[ĚXfOȐ=+h[F}BssHlwٓ"`>4ZrFX q>5b?$((b ۯ \&N%w=@D('%耊~<ö16H9C!ar[]ϒ墡{h 0 \|,^*v`k4|oj?
|F`d8h`v0)VWju &zgXE+QO)i@`[(䒽^ 61>CMx#v|ӹѪןSjan`q и@L}NW,)hu`Hs:jZ]"q7j.aC  lBwH
9yc_
joAJz,4aX}
pƗ Ӝ JQ!V
PtTea)`[glqfDRn=~0iWvJ! H_2 \_5D4<lq%X!8
,mFrH_D'`n#}=!˿9g+ ~8"Frq %y7I62 osо;ۗO}HCՊhѦM4Kk`Cxo!c'%˝}[e ׬uC<e렶&K%
8iBRuZ<,[ DML/`yr6Fn_4e0q!(|K}Id@9HaRc
h8p|Ng h՜.#\@CO+~6cp{}vfn^Hv\3OO{)9u"hNByFjٻ"?d7 }wflzxrE@F͡ezC>{<tLaճo)CaY_.r%S7q~ ;;ng15s5_Z@U{HfS(U$ E"@'nf%lĠ&@3@ ߽<eXʤ_8vU0׆~ :,ڭ=0ǛGhP6\ "gsH9yR&(,?)X4"tgT~Inw K '<N޹(향/(g8ݰ/r
o`DqdO Z4aCs*-Hkm&m(5j,@8lTeKEcS#amS"I K/GNoCVn7x$C>Ju_ >rJK\KAxot ᑐ?p- wuY|URj+
xO
CFX/grN@|%s( ^(6`~*!zBZ7y6Ԣ|Os L/oʋs9Qȇ
|U'_)3a{[MFDn';%ObQ¡ĖJ,6
|TDX`v }%r 1]udPl'emQ·Q24sfIրi>XgKTRVtJO|%W=.:] /;PzK5Xh#z0t CVU Fxt~[f &L:8p-(JlQ D]*# B9;
&z^sL*-Wf|43! SzhP
yQb{\q9A]~Xev`8}|Y+Q9zn{Pe
DDcB` Ҟuz J@A,,_O7zʣ9֗l ŏ]}Yόڔa!}DX+ QRέa>uZ<!XZz-Omg34kLE=k{ DCfO6j j?,;Co}xHLKe]{6ZMEE2CB_(]hF:Z7zDDUDX'VR?C>g+2c!KyIi̇1{ZS& 8p6^a-$2]a5‘UzrGO/Vܫ$_0 @duUF.ܵ"j0Jer{t{p^iALŎbE z݅P u:G'#^0--/ni]hhYƿ!kۡ,hlx>Y&I|GF)@ ㈽juR}C;nĖbcIz:i it
oe _ʮp{hY15O&<S-fV^ِ@u<AMՈzSGCMxN\ڨ<Mٕ G6y,_
Aaaq赠$JYc$ ۑ`r
oV)Ӏ"-,hD~%fNJTw+Q"֍*ZZun\V5VRvtE$ڱB܌f'r42T|QρkL%0OVǴ0<_<Hr~\W]rM HPzy]߀Ys;!R@2ͺ%Lhpm4VU1u}eiU$4:̺g|)X#&|<'莢b_FH:*JIr'f<@dyP#R)v4L4lIh _U$9s4! n^0Q&$u,V`,>U@SepQ*M7-ߜMqN\g@H*6m&oK4_1^o߫Nb! tg=m@
ɻ[ka
si[u7x79U+MqN}#qp"St(p 9+0EsG\.'esZ2񪆥qBGLy
بg5@Y!iݮ^"+Xz*!8mNMzb2x_X#rrBuB{l@܁xky
JOQc590n,VVgAWf Z1fdfpJM?W5ADĂ$$kJ|TZ8AzۭWjjȀY04YtjAچϦY>?kRlfhx5;ߍToW6ɝ5 לAkO~$\†GT)UgS i,4^oH$;A#"]p Ŝ*h_{44Q<z{_Z@Zb$~Љ5JUwҧ/fKĬJB]ҎAa[K <aI?ȍ w]̅KnƼKpɯJ!ՁSJkp
p焗Vn;nzg`Rtz{")Hq>A-ԵW{s&6oͱs4u xx 5ŀ RbݜsCc
1BDppߞY B4[IS׆ϥ]GJi\is"mԋR D'5b"N))y^0qPχÜ#-Q<W](<|IjW{lzRM ;މӵYU僗r2`{9+wWճPo*R*͓#Oڢ <X3 S$yIjJeM1RW<rԉ*̨E9 <Kfw3sn_%14y-Bpnn5i,5̡O8)2y,Y-y`ߦˇ~V/ (&lx[FǪm
U_q|xyQ/rojI6~- L yāGڕe{x}+aL uL1hXs@;
ӂK03RhX\F¼Iég5{aBӓ2hxC"\@&x7L%zY@lhUW}۟Iw uY4
tۢ]tg/c??u,P7٨lg^0O:n-T.1">Vqr%qcQͧ9y$^*R{o0Va?LgYBL3mv}bX< \HSg##0~}׍oLj7i
aUd!z%ߟ͸pS ʺ唖؂wIJE&-v8
8,sc `my h?6frR4ONc"2$(mt@aٞj0b<Ē@@OT-
f%[`.&RK+[$8qze4aA
M<660-Ҋ3>b啗Բ @?zfW f(lكbJձ&Yj(4gfpDTUJD&~IrVޏfBk&M<E Yr57S։e|Eȍ׶ٍ8m)r%n7+@fx;B杖<
CjG2
kVbrwTY}{<:ⶓ
/D-¶|<Ǡ١-9n ` [.#]*1,Sc֮
TLq:/Gz72ɂncyL'J;.Z{=6yǃ#4ŗ ;@swmYxg.~z
id:6ջу0.ZKKݎ?d$rjb)YvtDy
,fh}S.VH0-_DzGxD [D5'Qxࢗr}&Q[B1vl6-Qy8a*ݓQu;K fw͊&*s5zuo/:\:F58.\VPQϭgY1hy)^x82nN?;Fڈ'(/!.W9" ۺGngNu|Xg^JwqWޱ8 #wo, V4OI)L~6"&'R<Il#Wo
fF4y%E &+=:Ls:Xn>HvcU]SH~#WS㱻Tuvn&5ֻǣ*RauK4M7p<۷X[ْ+ =M7ա+h^\/%v{q8 P֞HVdOddFdFɵ햜4e1OgIZTՔ_u&V~k NOeظHz@FFľWaKMjxtݶ4-13k.2=qn=ny<4PP]9Qr+}ZwcfR&.J-!gr}*HWqw3;f%T2oAǎo }!5P1,{YN/
$J#WUGj΂<%;$HHS eEb<ȾXݙȴ{RYnjU?c?]H:v`*Ab l
,3@ytإmo8!CVݦ|_y'%2͖ :=&;ybp6'^bsIw]tYEeTz764a99M~FB%% MHdkMr33ԪAA?
E"&:hnXb/6^`v7PiFa4hMNMr'K`t:>VRR'X 4fchI z W |sGe)wiYTy^sҏZNisʇ gmX./ʤn9^gdug‚@udW8#K{ER>|07BO]-gai!q_ޤ.D7缟;z /d|ŪKY0eMTHoDDZ
ǃZ-UZvb1[eF
#aiwUD/y2$I@P0dQH]skE8jr\) ,"yQ A<kj!_;ox2& ̨@=_2=HOt5M̗* @Ǻp(¼D9;mAm!nIHK*ʰXPh,݃?C*3ã4XdZ LKޯXƵR=ş2dM]-!ϙ{-Lsh@_H=Md++
L?_|e.P36.]L {O';l?EM_lVۋM

Qq
C" KK}Zn`*pDze5O`ԥRXn6HZ.ۅGwm6'qrp-t)Y&봟( tAT çH}h8+Ujd @3ӝpm' mV% phq*Fr9UG$T(]O GII/&H Vj#5 ,N$;ҪлvU3KGS 3D)2KL)ᓌ'Ć
nW&(:_
| 8}
n!s!M?IQ@ֹRh@ i(E˴y 9 &$f0J{Kt.^GtAk$C>iڱZ,!DclGLӤ;JQiBhW GuL1g|X|`D3pyYBs[ #Y %):_>.9M}E4RoT] ʤbr@PH78$WIQ:eBhM<ݶI
Br!y7isHvE쫅2\ʬ^(!
\"Xr2<<&#oJ"p/LGA,{eli2(
ס=RpHk;EurB܆^)Zk>f>=cnaܻD$W(.
{
&ͤjXNeѦRBjCμK8$װ2 ? I%-NQL?K
NKLWd3Fh#pݧ|FX(^bs[u;`򅁸P2*-) 7CäcMYn *TQ {À>kT7`v{\p)ea|q{<-Ń}N o$?oN'fWɧu)fq<g ј`'8>ĢHѮ5ujy]F%Wj}AJxd9.[,"nӵ;rS{F_sj"IO1SY$V 3ضB3ᠥ)T5p
N$:Zk 1vI #kqq͞Y v}%?_Z<r>
/֛OR(nI+M
4vl`EV}SP5SBQAcqlfJUc${.7l"9M=ztW.
#5.0˲WGzw ]
<xsw^Y] k0y]ɾ$~]XӹFx]2Ezf>C]f4F>g/ >Ѓ\#=9וT u3@j psqS[Acْ.V14j~ ZΔ\CH# 7 M_!`uƧZ?Xd<9T!ºY^dN<g(a&UQP@qnRkna+J~[EƩKњ f+ n#ɟ=%<4c5P:^ݜR1
"az rK V[;š{Dkc4
>ʵ2
ͦZ *=_h$Q޽b%VJ0w=W˓T) GuR:G<
FvF5˲Dh_/
X TlXIM b:ŗmp[4L$)En\;]kK'c[iJb "bp*;BE{0

Ftḃ#Mt@ ҙm
/cW{BouFKaXz%| _}
L"rK啥V@(,Sv\-L5:Ag!92ϖDhC䊽Shs ":9*19L8TL fB](FkǬA5Nɒ _p߫.ǝ4̄><Uif)n JFV<T[N] {Qp(Es8QGX!nG^!fk Vce$;D 2jz9! ˦Y<0Lσh&&Vӯ ]i$ gpI]LTm։il|0ch%Z-H
j"^jsF?Ldēj20ڶ]D ZŖ u[2_hIj]Պ-p<y/s
jtJ? cZdh
bEJKV߁0Wk!<mJX` m^!Qc3a(!6UŨNWO>;O?wAp ;|%NȤ>0J=M'`M6.E^;1ERw߸Qy{HkA@>׵V 3#˻LSے=ML1D漚fDQOdsScY֕-mG@d.23<q(C"p/`x«kXעg4R"=7?H.4L>C#@V6Py:CL8? GLj~vE#b]ɈNuj꩸H4Rk,PRۄY_6#ڥ!!vpFi>1 5u>eiz\fαyIЧo ,sN`1{K>thD܌%#esj[j
ǮD
;s]*ɰZUXh)
!e`f4$\pnء4 r#==lAs\r|F#mk犻Z4+F8Cf {wD pA\;nb·D„&DĥPp
mk)_*k϶x4
Pw-#_.|?|X:l؜
<LA4Vm gUb۠6Ib<$vW@hǒ$Wr&7Ao2tPn҉%0ݴW7zeToHŀiƇ҃3:~TE3Fk"
ALlVQ欧iҷkB*VV'%uү*drR:ˡr]:-U (CiET!z),BLZq69 gm
:zoİr;~ȱSO/"
祚,& \ CxFW/F2 ;krŮfY~26HsFk=t] sf%<(5T+]P9\2<PKvtvEZh%w;8e)<cFf \HʒY0zf;HΙ
u:r)ˎ@4 =\(}2aTꮟz\) AYϣuUaK0%3YτypO=BRϳPC| rfԋ׹$[NSDwHgأƢRI@*疮_܍=ue
t9]rg 5k\ǚGa:-mFT‡nзV(n{>[ %xܖ_)'jrEOC3)?Nk~C뺋iU ui`a{x xv*Ӈj.?vN"B6
~^Y8b).
\orVo©C["%%hby$¬6HBSwaqcmCѶ*׸VA w-!bJz.\pB#6d"%. g-@$u()</Ӟ My8rڑ+RNÎ%(2JQJ8`Zx>dV_PP|"īY+zJGٖj(- F&CPB@,1sR?g5F,R
\#a/緊27S%unvl#L@ Jnp[׆ˤ1zg1|LYt~KgP3bs2t w-4,\h-䳊,m
,Cޚ%(Rߥqc
&jă[js_9( Պ
>{n:n_6>d uGgY±4m> Ơ%͕
)OND 5gm
A5)5G`z܃RwH xc|@Gn J:hjީOad)u6Qfugx+CROt ʯzG[{BvΖ=B*:%w!H[w-Z+X#(Th2RLܣao[ RPK kD^HZl |_'I /5j?6.(J[";u ?-A0Umxyq)|<z*RuAy񙼸\cX?>q!=
UNKHj43(x?wxet&y=
'<M\^͐ \ؐ%Pg7t3qf0a Yě]GPg[j3Vu@ܒW;51d 냝ݡ|YԱߗ[ZJ7~OЕG`$S+ر3AS"Y<[yt%҃iÿT
[YQRə^_z(Z+C\9\'mSG`_Iݙ|z[Tǩrg"S~iq|Ty`r'cv\#'vr6 C]~ĶT?VyU/Ww28SLg"M@v~b^Z:YvFF=MtJZ0[M[IQ#:Q Bh)㾴[ N"ʝ`h vwdHzS \q.3f~$Gׇ{ FH1Sl($DdWixቘbcsqZ =S%iDѣ~d0җHDX K--Low} G ks
6UU=.q0"_J9sO'!zVRiȾ҇b %aE_ņ;,7e_",+ڰլ״,*
})pSeHæӰ{gwQK:6q?  v(b<dKf}r),`ո > H.~*wP0@K+pt4 Q:
HyejQrLPjA@󔁆8%1qi&A6ἂ<_?2ʕ4;ʝ9D.V]}:Kd3f+^]Ij$ q.LtV';el|QW\7㖮ߘpzȢJ݁
e7mԓPB<wt &Mn{lcFp KP|wWYݝ wA`WA+,GcR tivV
gcmF2L%Ҭd@H8?>Ӊ_A,bދO3^4i~*4 `{;3`)cyWΞ Ș49_P%uIC ;S8R

?`wY54ПL E{;¿
ḁ֏b
cemy,ϭhu$&)*t>k4s0aUWz:.$p,0,<NG bϾ+>Hx|T:MJқ(&:Sm>nhKQ8-LCL}ҼG2` ؾo@
pv1ӿNw Qt`Pd^jj\Jq4bSG}ny5,8L"澙Ln^#>]gSCL7iθ.TO6EPy?Q!cǴg4[-a>oE?,ʽ:m匷H}Zc
r @ 566BEJglb,2KkLˎ4og5,dG?KTX2K*ǜZ97XX+fX| aڥz+srv+ 5WR5+ER5Qvq]`gHkڍ5a}&k5-] Y#BA_h7TDZh]muSf^[gOY&f<z+KROg^IG暘 ǵ`7N$M9[D\ȇJʟ5Rxcɟ4Mu(k# Nl:c]JWP5~[̈ZQ/Gzls(%sIZF}iLF6N?v
Kq=J(t'
1i
)q u@&6VIl1oe(I]6
a>lGmQSn{NJqu_u43 &Y:l8 a\X' lG!z.9uip9*ƒ^T k#?-sOgVn$/8Yԋ
v6sT4/?kK':

{O$h<ͷe/HUVRwP{Mh_kJm<>D\{; ml覉M,0T<5%0x-Rƚ ^;u1&rees6N`)MꜝH<Zz6 :n'g1G}M}/x2u.=b#ԻDiқ8ϒZ/a 3&Tޣ Zؿ+c>l6us[2(XƠoCg5
kqp5?#Y𸲌ħqTm"ty/xg4{u~xy mweچZ"''/jK̈-cM.7JvD}8fQcj_C!?!(՝X1bY
Wλ<vrFs. B=`tZWbwE<N8K-4=.\2Epճi@[P^w
HS_4OGζHE]S*
,[oCO6?Ǽc X
5%A6|W@D^>OUOIQǞkv\Tpﱎ9w*YsmԲonĢGϔEd̯M=庨22[\=Sh+o9@BD/NX05.2aElB\GQO{rO£czaOf_z
$E,K-zU
$Nڌo޻ك æ6Ѻ]!4h%cJ_I|?a")iLն皮pS}:{S6: 9Geۆ:rJK-`VF*s1r^6[Wrw,e![<lf[p(g0==6XͦTP1v؜=D kAkWrJ5cE>Z]=D# /y}؜+:JuP}'/pdĿ(ԢRfEѵ.!&@DeJO
@(Q݄N`1&Ƥk5-`T
#fO9$C[͎,b V̾wQ>Vgյm1WhqTTӥ58ui˪6PO_E<0d0=JLgYV$Q,}?mlōZ$.KSL*|I`DK^FD# ̹`&kj
}/&dKу>ZizCv[fJYv^懖9Z|Br2P9 lwz't-qv9ZC6NRC@_R=Q H(;I=ԏts!:DM?)E}mO?McekU&Yèה bqȾ"w^ "nƹUW|Q\l(9sCT]rmtW붯Um޺ґ wBp$ dGŽӎǩHocU`JE ۂSuuwݫyϩ!N$
W
0@[R^T賕W5LhDŽ+U}|jʣ>#jzZn]Kɏ\
Aӳh\ =K)Io?~ HKBT"@q:ũGbWpV$_PQ:cy7 f.}5vSjl
[L9<1Jp/S<9H2ʅ(UL2cDoKeZXڭay~΅eo a(g'.L:$.',~I}p|l! ?<vBq9&2)Kr( H-vn(Z#Ն64!]/umb0v
PP@Q4[aa2|OO8I\ŵJnNswY4UAW<,gk4Bv64%"bC 4$Q,6,-3KV
`w3loIJh&.r1
n2S8]-2-狑Y@*h%*ڕº=[oI_+(6,er* [=ZFȊa"h:PI6C-3D_@ƗU)`OGRqG*҉hn1cjsXb9l4Z9h:8ēm
±m򣽌Y:v8U#FV2[v yQx-gtD^y)[~66#ގtdOF)6%Ƥq!AuvaQ4(C<ӧ^5aY3:aYjD1PZ*AV2⦉,["?:mH֧|[JJ^x.#A5cZqٗ)ns~2qo:8G ff`mMh@)q.K!:/U+*~ ֛,q VAVo*dU(RߊlQn1; YytHh q:s;fOD nq8k0]

Wnw/U#gTǓ]-1}-?R7
aSbY:7
t B%Jneُxѫ(.J>XVXLYoL
& -7)$ Py\n0Op}mW2|ԻbYÑՉM?J"K}圹6ȽrFu)npIVIrPtT_j1PDBjx;6%m\.?xW0Ya\܆(V L
Jz~/kDC Px o.γ[ [t)m[rcG!,x{_jhkay8悵f~He}@Y$'lJ/b(c6ur1mgq7PI5h9';13K 5ZUC,7YŊYeLc,ސ ӕ!.0CaZ&|*sYe=r7`+ocʗỖlG4/:I3]
_=y_˪qm<cGI_|eG)>0FUu6wSwW'Ldi0t脻6!bjˈIG'srz729=bi)I yV*S{$k=\" ^71gBoA^$XE/^`[.0l#sS'1jv%OcCbhua\I
/X֩LhWY7[g)Rf
xQ,)l,G
܉<iV[ƃ!0c6kտiK*%RBA+BHpn| آ ĭmI)ػmL|4Z'MA~):nW)| ^"-6w1S~:#Ź1 '͕la|RڙiTݴZS@Kpf`!f}@ (U\r=i$bS}Q7@1+\܎l=%zh}~m_>G@X˭љ:b2u7*!DhW}n6T[?-Ik9lH^;"|)J<= tg'LX.{[` C=Ar\;uYh@3o ~iu@~D/Wfo ;DThW^9S'f>vpRyY'f/n? {5EyZ}/,b+Z{0PiT0ԩ5>Tx>_0;H޲\#;"$g<}ڞX{Jt
"TKſPeK>U^ע3 zÎ<,q'i]
0_LdĞ>y$UعxR;G-#OM8DKe,7i=~Rr._;RH1?BIIqTpoϥι1oF@PBjeT1^,t'c~; ..U;Q{-D2
Z̎F{'e\G 8'`g}l4A 2IVe^K7,, fWH>!wV r&}A9s.4Ō &C >`OneCY&a榫G1 (
=?#14U91|_m<mg1f'Ǹ۵Dك?}ۈ(Dp?2R:EsP0a;]cjEsLo
B=ҘH oΟOxA^,l{
qӦmc5/%2iѡ~d*^Dr(TωWkInwzd.T ~gL[y#擨:~^Ŵ~3R&BU2{o/7EI11İ{w*kWԓ^?;OO2jtL2G{ 9פwKyq;BU[. 4Dz|WƗ&B >|S˯W5:_V!VjL+{|hqkxrltE#n,),vP\Ų>
0@}x*!}B.YbՓȓFno Ƥ-}Jl8>y)#.ݦ`C& N1Oga9r’r8ڹḵ:"!@)׋-9XFV1[d`(qkn/G_jg60xUY] t2c4q;JM6qsjRO`= %U7e
s:T*mx eT->Zit/AxsXDK{ئȳG
t 6,:me=Ƥ[Gq?W-rG;J9EaeCvMҧsE0.lR!Ē2;-&]srN{Aj6O4 $Lv`YiyJ-ȏ\M\eri+_e+nxyf6&6Sqqm. *l1dj2zH
PJ͍"<*)Umnrp,׶ANt\ {f`"/r1@o>mt!O#}Eѧ
sPl.$Ze|xjP$Puqޟ.#-:x<$}yRk>@`ө}f5F`?71^~5fE9
zQIȭX=e $yѡrݝԟqD,`=]jlHlff6+p4~C, D`>&#~6M/aZ&Zz.ava^S-[/QB$R:8bZQ4sMʙpbB΂β4LZW$7L׷'Ks/Oj } "nW˺ %Gv^W3}/5ZeZvp;`Ĉ P{pŚEio3H)\Ƣ.M;t4k߆&V鯍*jl
\UM0m³_jS90 OFX!S7
`!e2w+.JVwMu ԕ3[$7RA,Km~Yˢ,ߗ™}|D0-?xӴ<Iи+΄C h ^<!ITo2
R "d&W
*!TE!qG<r5|F[+'١{aMTlJIGZ 6h$ENzru怲6g0 oä1W;+UEcfw
ƛ-
t`:tT Vf3rg#qq);o1{BQ* 3hٹo3)ӽ(YDɜ3aAkIuOqOYF9${5 2)dC8EG8mtH63ؒ5iAaatT14oO7CVτH?Uz_.2"KM}xa@!or*Ƣڟa]zCB%l)
[Mkbx"=>izpPEU'L66fPC]d).,16**#e^T۞Q^,%@}bmy
Z%|pCDZ-rmpN7
[3\!duw) j =iJI, 财tKʏ*V{koA+ ]muLGC{x!}>f:lht*&UM[gcD*X@ ̒C .Vnds]S7qy=e3(fCz< >pI 0 ,8-D&wV iQbc{uUz<[<?ܴ9Tqgtqe'R/Kh99uw5'@ 4 /Jal۪3.YϓQt2Ÿ6 eIC󁱇S(NJz =+77 6~@a\P?RBR>Ŋp
h2VD(8df/h.|4qJ]f$2z~ ǐbAPbVj1;Vg_w yt.C$
=6K tZN
hɑ,,H̚ ʵ0Mwn
e1 4ڴ2\c}GR?÷`D !UX̪R7FmC`v4iE:ڀ<*gh|=1?q<#! P&^ f]"'0?&V ?=Nm:9!"v,枸Ɉ+ܿY#Rw{դ
ms0>ߩզN&1sS#7mwz6 /
rN\[yO1tuYkh[dkG*qcCMde052<,16NW<먃Fs r-lWcJU*/#Xy
%B玁dR"?Bߔ?YCll5CiL
05`p?&}
8\()c 0w WjR"-f!$67~A/RWu422+1~@J( GLӶ0yV^C]:!p="{4n;b:hMr76^k<l?}?vW!֬9}*<Cr1UES`y $xfLiKNW莢Ts^CedI.u^u**si<ĘFMpF~ѺsE:K X&b(2 5]wN)Gd65:C8>PaR^>
U5uLϸTj]h3Ho-īFzz#)J{'c'RA
 =7eEH'rJEؿx}28JCR?1LiJPXhi5 ^N)pުf2-r*r.${XNc]Uύ
Eڜ͚ת 2Di+8
!k]h2 jCb"D3$>NHp
U]KrIrWSԞ3[FC#N2ڈh ِ+12ghFst7(]n%eq8x 1%U@^x2 VZ䩴ͺWOοvbrp%~o
qFڙE2t
"N[j+ S;\5Am 4b<9KT*u{`R#˫R P+dJ[7āki'g@Sq**Ε S.9Ae
5$%GH9Gbc
WͧB 3Q','B5ըir 5CE6҉Lt
à(o
$Hyal󽟳EgO$]Xhקg}k?.0 %~0MS(Tgcd4*\+PǿfX!|YhdD<x0Yu t]r aB-
_
ңtE/sNxc ch+yai%oE&Ul.˩hR4Ju*O
O輎T ԅ}'{S4#'
3on =iܑD3 LIEK4d[n5n: O1 vʱc'K24g3d!/tr
uM2> {fj6X͜}WLx0I횣G ks"K ^
Y)i|k3&`-(ׯt}dř(xu(A^]Zuk%,N?582|ÎOT 5xR̊D3'ۛWuHIg]t~ ED+ \ئǽ,\ܓuЕ2 埀)Fc8s-BTlQ ߮{Gǽh>=ii?Avz#)30w4XzxR/sf,܎CV$
ԙ Atxac(6 /;胗"Y38T:aLI4GUxkjmIcFi "iC9Ĵ'K_+~qXdԡZ9['5e\߿/ A,oWOg [$}´h_hڌkGlA-JquoаSQCkɦ
IG}K<#£q}$'>q-8o6ٻcN2STg}vj <º\"4'yi3eJ?)(w{iA43]IWo0g;SA)]ӂm=ù5 3k+YebYs
<
HCq}0,HП "[-'[S%&W}0'Puv3jy[[<d|]ީG
BJԥG 0$C& (Ά8iq=4nns-"+;ܙLu:78JfP)BqS\#1x?Y dI0,[7{_,+% zxuf͢l>bb֣ iJdTxpx
6*
24򸠾Rji' IR4BLbpʜ+q'}o%ӆ9fH9Q}WD>Jg=_㺔m8ul1بEx **}N/6o hBaD!D;eySR/}ǝ)3~|iw@ _8]-h[!xc D3pVi r#. tc)Mv ~VMpqwHi“˸;$<X
t (h9JFl#B,A(pe(m8Β@P'6vKЄ7
~
0v1x7B$<F0:x||a@::](sɝ~X<WTfH6ʀ +T뉶?osq,yD]H9lg& R4gkvkl_EW8oJ)&q<#=8K5
uŵe ,.m:Yt0k޺IرumN
Tq*@6tc
_MSب:l0_J rHe0LN1u<| c
<^'(y&lߴ
goF9mJ|e*&N!K+EܶE/9g͉ p 55ZꓹH<e{}m zHxhTK?> f@I}HsbM*nO)Q9ZVPQ@)o6d#?Lzܠ¸8}dtzΎo
Ub;{ 7 Ǐ)>>>blfұWF(pu/|}Qm{ ΢wGNwv/P&l4[w%jXᠲzT<.xH2;p (j$&
?D aǍ^
O^T
uL
'&%1zlݠxbϲu>-n֠?%<mUgki|hE7+0Ǎ|ViB0@q=a +Ww^;l*tDKQ(bd/ dQ\ázk7a:/Q٪ QOX38mFV8Wc8F`$ _g (BQ;s}>9SAuO;\ߠdl #+wD-aicC3[{`)PSWȭ[&&D>5%Yc K\\B=S+^~5|ON\OgDxp$TF3m4.C[5,cmg$jHrh`Ǐ[ˬ~p[HMՈ
ԗEĦ{xֽߌ{@)"m?" Lv+U@G xxOD,8 %\/?p|̤ $ZS4.1ô2\"\
bs(&$mkYhF`kʴ;N_s!54)
S/- x,Yb
0zˊDUI z$ì\,r{gOZdFۤ-N!+c#') Sܭa$N3+h#!ym*ONiM{3*=ՂsD.)}L6"AIinL;sUq}]b: 4=ؕ}&Lͼ
UzFee|*xVŚs_n'7j".od#F'Q =`G9JU{
R0dBXi zKLu/._f’20Ǻ%l1;6vhAÁ%#rm5g4AoT?hdv9`_TPjk4"ZYKFl!
)j>G%m(upk n+ ȺnDtlWwƵ}jThAw3D[:k]q)FML4ܢ5櫗K9<43bcX|zN`EN}{
ʑpaJVNìFzq Q
:w-Kv ߔ!';d\%^8 =piU9K#J9;AFn%:#$htDMl2] e^_ {/O0)I@P<n̢Ὁ[ooSUv͗#3j&TxOpl#!cJ/UMOXjpk>G aWr
N/7cg 5 .S 70j4o'"} J-PAV`  Kx#T4}yTƣvzVG1(v!ޗJROf!p1.X<e=`R|'o j۲xxf1N#5oq> PG+nX&eѤ.Ͻ;]C47]AX\fR^Eo=rZVK~D\vFkZZJ"C~hH9^N'ޕ&Xq,6zg'ҶPn)h^]yoX|Yщﰧrpj*&9FTxђ;Kͯ|lĊO7q7I=zOxhl}rf$n7CeRR-|)
E >nBY='[!IfЌ
q#g{SiSզSrWsEv΂%B삖 'TapѦf˱ @_gJ-\l0Iw)neA} 0 
1ϐ-ڨw+* lhY]< r:}&rs{F3^Ò6P\G!X !b \%Rtu/"1CafL⃌E&Y},8N=h},)|V)v]x_IMc$9^MK{Эs::"F:TAzD- WHBdHVG5B\
uKcS2r` ̓q/z8
$CϏ> =v~JSoh27lV"Qʲx~ vzEGa fw&)+)qX
+a=y͠31~]m{&@>Qˋ5PdP#U #X*l h!pib&i犀=Q=,Z~gI\"UX'g.X$kƻmvЙtߟzI69@L3ds3<8J]#;yAі
:^
r /]qC)f҅bX 1y4XUeDZ9KɩDlZRD3.N
KuͥVpO/YgA' ɬJE ;[UtP;+ :lLշЇ\Ə#\<ݪǧؘ$VaPKw;IUX
ZZd`>|p_6s).~M>KbLIM
5k̙kY $]mh4+M\mjg TB2Ck Cg$~,-rhvu>OTD ؞ܒ;Yx: V5.9/}dQ[#]'rGxG.sp4Xi%*xK笭B/?Pؑ2!BGvJUӠCe@ּ?.),)4z`"NA&a
Y'T%'ȹ:%&{wFCy<V 1N1&^lhÃq[Ag^&O>7A,D5S2Tn
iU̔NN`]jW'~6`w͊
ހs[~`#x-uR~OW.*ѭ*0.󜄺"viakl ?X! ق*C†0TdC.5LntBxx 14KfX2XqL^è }RIAI>Ao4NDj*/ og4@&oD[i]*W=:;$jWhtC(mcY/QkMmPFD/Iu($V1x80c<my !#xKWՊb.Yv2,h8ukǺפڼes;{sbbsOϲ"c)m !h @Uq\g+Q,\ 窯f{uhVHl]87LiBl zRk3MFX[iF;[T!43s!ƚM."DP~ordliF#(V}SfD!U o4]o]yqLG {x2|Cݿ 87;kaC@-3'12|@_<EـMb9_3O%Q,zJ(#ȝJ}Y`wKUA'Ӝ}qEmbZ#s 6hVC^G}lݖva_
l\8
r@@hx_Ֆ@Esz2˳3Y
c_gWH)AZl7STʂCjGv *@6 տ\e͊^1r1aƼM ]8hR~m[U8* <&(>\UZ 258D@ϛ`l,ȵ/pY2_ /a{5$x 5*7\.ƢXma^ ywڿhM5ZO5hڭ0vHxQ-]~1CT
Q4ܛח=F_dIjG3CBHQ?-FGOulx'"Y
<`$Bj2zد1T%g8]3NZ3$-u{<zSes /'0X#SYqt>PK,26;ia̎[4vљyYtEtкҬ:~$#S-`?H:&N"g_.}kDtXUn(oExhwIs(,}m݉irvڧoxlX
;9‚8H`yge}~G; jЮXL7mEWaEHC+4tSmBŧ0Ye'+i-WD Woo~40XKفZj ktX5UHa4 p<{!d?"* I4weHrDsC 0_zo%+KErfDfiջYyl|A§Gi]b`ȡ4
Y!LLAD|Z(3_ުZ
cb V ӕ1J@S5SCPh墕L]=;H;:"3-;( @铃v3>WT=4i Oa>$kB dݯ6h3h>-i03En
N#qϭ@Ct6>#."Sx4[Z}0EjO}nGwOeTd#M l`&&ת#y<͸L!f*¯B/:; Q3M;f5
s#?xѤ"FTLI]bh014셕|@+_J{s #@Ij#|`SNЩCP5=#SŠ
WסƆX$
]AIES_J+čM!6(I Gi
&ql9hܧ7d1".)w9pᩖev!ޓ= ,TP6|CّXjq)86"9vW !bu nmU\
# '>LzN j_+?X i6Ä.2'k};~g=`]^t ͨП?ZQFkzWWAݻE+76(CI0FV &pFDU<wogOQjE]ql1MP,45\Q4B̜W@ZXfE"W Nh'{G7S`:C*XMrNAod_-+2{wtrmbAj/z@]GfCxV~`y`+\/ ݀Zj
fiupzh9a;KV ށZQK'tAM?0\>wJc 5A G>QEQ_s7TF Vi
O4ψ"hNS7%Z:$s4
pKz_(fg4kkIRW{S <rhk9UԸ_XY)djS;Bj8VsbDo-7_K[&|W4Pq'lԠthE3h
_mt]k9֜H`\r`e
9Fވpy ;_|A WlbS^{L.r)BkiBYuw?M)v ;%L,͝W1ϥrvLIP[97Wn CoԮ $-; R|rzyСVtUoQ7GUH0SLk:Xum#>lDk2Yr2.19Uis uF.r AG~ ;h~q4@g kt92x
n\ a9f>)&)\'mJ1hb]Bg^ȼ
IӈԼ7Oh/#9Ϛ\
KE[1w( iq]~ƹJ:Du8cR}[\Sby3YAѮ9S#<uLz8[m\Ԥ# ` "qS6@]]%Nrl޿ZnGI슀=ir2E>mr.uɓx7^YXk̙fPSPrY&Zsh`F4Z{1.y5 h;R1h*BZLF,:{2O.|$ [OttB
n]hJB4AmX{,9_ozO^Q`&\
W_D޹f@!~e|RPb=v@K5_|0t U aRfJHѿxXuF[59EmP3),;!:Qջ=Wed]<.Ks%RgSEQvhg
/ր^D =2M԰3  Qc:t<߫2j{ۚwjoFK+|Ak(/)("֣U$8ݹ s!vHͮxcvf{lTe1C\"36`ߚfDŒB uI!jsE#e+Wʗ_d8m Ӱ_VjkL"Im}F|*
F΋o$]?]J<:rGֻD`V{Gk"+{ PLn~%Y2s!G_)O*sBuc8L噗>KB"}uL Vb=5~`
Y,U%
@X<iԬp-8K&XEḳo;ΕUK4vzL/p1/ OdޚP;lz׈(9%nìǵ䖈na!ڕKƒ46pZGYqm_9t7S [Utf_8>vY&zWUt樿^*%^0eز Ff}'e,
9Yrְ:5o"uIt H6Ն(G
@Tb`2ch>_}w`P)Ya0 ֞4o/c0eO4f9Wur/|)]Y @~8QsM ~G\-`gD(ZO翢2^PuURC)7娋 9e:&mGA,Yu\G-t`Ga13gj@oz
h:$'
"6XYoYh3B$$=N5fsKPe7qA;cF7€ϛd\n54U}n" w]|c"WYM0fN]LÞ}
3bR߀bL?Gci.? 8؟tf FԭHE29q_T٪7g* $✳jc"G W~!ASx_xf.UJ2 m]B}+(?t`0u>}(h_(4+9D>qjIfXNf9Uzá*=DW /0vjiXG.E,V4nw)ӱ\S?x{\Sm v0"w/hik|zyW"4O?]? 9,]wèoG} WlS5/`tfw.7,}u0"U}MjWH\Zt;Oa=TGUsl/sT’#_RuvW9`K̇J&/o9|.5[(iӐ!Ld6C#ǕNpTWA+(4bv\J_E\M_zsPZ}Tdots4f9M\},]E1xX (Z,RR<-G=GNoaˊ{Z,&1MDQ/gt/ѲGpuҢ;3F"a2ҽךJ)[FXw8[&Ѿ  ?B7C.GWz&q23ZSHib=F?ֱ9(1&$f@oF]'Sy7eRqUo@ʈ 7Z*l+7i!YE1Si\_!sj|nHqeB\c &My?A'™[aJoƐHf
K8w4 CX,OՃRaM?-gȏzZ4l?_UAYh)}EiӍY\uѱfOT@<z %6 \` d/z[78n*J5tv]+Bx5> %LÒZf$^Ă%Nu q}uB*`k_FS(K{iA{K4˜.xm"a2L8(WB5͆9_EDB-cPJ# "Ň#\ѩV`WIߪJ
3
mAVIgMnߥ]VlJCY0M 1{Te.t&Q2QKF2_#.Qp y`7ƶD*&07|[oY30?n]#x&ݓXТWdei穲5K?O=jz 4Ն7հneNN}
𜙽Tʕ7 Gv/z'ܗ}oQJ^s D0M<T *6ۀ3-9eD+Z,LZL!C"B
\%)JYunΫ}ND]Q%V3lD{r Ԟ2Nw֛ӹLWs&#ܗV$&W>^ Ash7#* #/s):4} Mts .h9bz| |O>IXTi*^ Et'-8x|,­>nW!Ү
LGrFa 7d/̨9;GrI~A7P
Ҳ8M -r0L>nQrV4Î*3wšj\-<!,NQC]xKB$],7Ŭ0[ΌEq#y/}u#e(|Ѯ>cWJ$J?Vu UuFJҕd|
[CXf@g'TۚpI*g]<*VP#]
i'T.#sCuA]|$<=\ʇ[5$:`M垇Gd[^ø!1Aw HM
1֞0Km6|O ۯuV(qe3/Np~eu2lU~ǁVN&T~-z?)O|k#rD*$3M?䳷bo:4*Dt?VYΩB۪7I RcqN1rv}
f}=ϘHpPM3'͓ouN^e@?{G*&E}"g2 n~+uAddSփ8YL@>:~680J2屓 Sϣ^5% ܕ,ptJB6? T-{,Rɣ1&$l
x@"8JDEΚ0ﴱFl];*2؂$8V @1w Ni!-l&ubuvs<fӸx"_=:b>y\'kb^,#M+mJa\_~Fms/F 7-Y**5l7Z6|T$fu`Q×
5+ߏ-3D̟c':CNY1GX缊9\a?qe\^5[ٜ%;I''T:VQ}xurJ
HV)뭫8
u.u 1^`EP:NV)dp+x< _?_) Y*pNuUzŠ,\{>D!7%>rFj?SSVīVW
*Z aӜ:a
VQGhFD[7/_UC
J=ƃ6͹\fUeY+DE!V|4?.э\0c)Ζ0x8zoC })Ij蔻GЈ3@;%ӲX߽^PxNkv'_Z N5.GB;>eHklv8KAJ7Z~W
0 3swHd 抴'S{1*[TD7H}y BR mIU!'sҩUz.ۛǤMYq{`ZRZzp{(?_f>&aUg6z(F^K}3"PPdmr〰+(2'
߭SZXcvv2H [⍝Εc@5WGM8z
heڃ.!ܜF^#Z55
Nb{ܑXo>2Ao%cACz כ$(ef+c=2aY¼|kD9[x %~bOV<֊"rW[UQ&wJ qb*Ҹ5hs`3[ ;cZvkVzvCya)$<FyB$W9뒭|"C302 b#XzFVoL t7xiRw,1W~wW#wq[Q"= L5,KvfDmz +qSO 26}_h3a'l\z%
?ܰSAiSRQʲ$3xx )
}xR}n7"a?} {Fdf+A,Oyk J.aҌzU!jO=瓫3e7 56,DkjJ`l
U׷ /=~Md°kW$㹐nO/
z Cq`_ɼ8 =`?'' ?Vw{X=^I3!MJU>|@JrGZZ./30uIc>m v$#qFde8 2ZM/C[/7Uw/I`\ M۞aX^QrfL?yn>,O6MR8'ZDeƿ>GrQ6
W,]@SSPxN
ӹ`^lԐ.
&׃`3܀HrbShMɘnw;۲bs3%&X[+4 Rdt6xo筊@ggW

U{gl)7-gpE di2ޔYA@yi:ӽi&cQÜ{mb5a˃=w԰;)ң.Rv_jG]z:ղ]m!߯ qhRb ۄp [5("~i5OCM k-ϱ =Ě
Z_l6QcV4Sػs$ĥϵWcx$;8Ww8Nu ES\+yq4<>
,J2K:E[bߒ[<eֺ)ke<dZ=o".1+nJ/)3DKױ

X<n)6UBDw֙ؾ,']ZH/W ܂PSU'VϮfV9!K.!hcDVZLWKډ +PZayGm+<LA{`r"}*JJ-tѡ[.l D1sE3y9Dv)3 0n kp6I;{Cs+_KsGj< }n4
ux7*j
YRo!B|
3:]N`ahmA-ήz~-=+|v`F ɭsk1a L1fYOn{W.RXv Lnd&1ع!&`Qg7l،[N0E7 S+w>BN‘}>v`qlK/?(0[4$$v F!%Ca4R^]+w
H
:tl&KͲeHʷ_uC C(Ol"irΉ^ӊUo+]ffm$Pus 0:U^y3w6%4/3~}ӃgyƩI,iN9v<~mi%3 5h#r##\bلeg&E0ѝr= tpĽWP%b=h6:Hh 9I:oد
+PD`%L|fBА^1+LOQJ(eP zdAƸi~hPĝu4_1z.z?l#'ݐ|*0
:)xRy1ǀDY3Jب /@c\d7g(=KboW!S_
?ZWsOYֱܷ
@
Z0,]CUEh'vج[
[`OA mJ=:pL2®]{-CTM
i "aǘQ;swNlS+ydg,(maO gT0Nʆ5c -\Օ0m&j^OHpƚFʹ$ Y<<紶v
TNkOkd(TmbE\. ͅh?OJ74rtPjYn"ZW)le\ۜ~pZGDodž揎\cɗIf?~__k1p)7ܶSbڴm=Jh&G2=Ox߈&w"<,<?.UBKѴtHPI=GK!o1
U2R9|b ^a:JXC-t2Je(_h\GuZwց<ud{M~PVl3m{_I[IH* bR &XL^#I^o$ ?{Pftz dxOPJJ J+3z}6Jݼd(H0bgxl%jw{"mas1 H
K_ ?[r<
*#S W` Ǧ= rAxot^􂛪5)W0,q۴UÆ Gm]0xubbm@16CgfrB5K &霤⚚f.djzt{ ϰ$|| orX dx$,=KLǞ:RIjH:_li\o^ #S80љX ~[sS_ObԡLNh;ZK|bzZ4H!
23Ic}{ 6Es)$|ܞ
b*W~)=1#%JhbUI MFpāl(Έ t9|F`3?|N@m~{Ek \c;JYQq5|(r˻9ԵelKzHQfDJF;4x*834j)5N>Ё KOkqh?{16XJuG_=:9Lꪬp柙NDsBcN"?RJ ۹ 0S)Y4k<J[h!p
F[ZYh{g?ߏ~[G*#h A4OPs 9@Q~=/^)DWt#{֗ pٵ1Tl[PkFob Nszr)oOz苩VDƸw܍f[\q[YA9`a,RuI]W4mLABb7U橢\?_MSu级]x@U ,kg%I*Zz_@O.@@Ǻ zfI( o-i
q(]J+h^S^83&[ܱ{7)U;#sd1y
4W7L+"@J(7؈"DͦFaCwlR'O&VxPLf'\GL+lDҢ55dVuWG~&ݢ޾e1zT+۟UP_%@;bOAג3}%ޅ (ޑ)EE·eڣΦx8JTyD蟞̉v=s9oδC -튁<yZK$RWR.d
UQ(\
4KԠK 42yJCc~~$
l%nbBA!aWuA^1u A|' K'%w_.,_"
WN { u>كzhU7d<ftH
~4hIKg܁)J-`yZ_ڃ \a/9{-5G}f錮ovn6}+ LEERY]/Ҿgkb_!kz8al;YJ2JUzU2D<Xd-4GbvtX`zwM)^WWhl>AFzFGX ۖfg͉V=>GU@\duAlh디@׬7Z^l`e躪XlksEnn8%jC`夲64Mh ܪ%YJZ=;J 9٠M`My-Q C`fjIGv( N˟+]!iȡ?6<8ȥ߬Lhʛ|f%mLk
8א "k^Ӭ)0Q65PdB"/mA~> {$Jgg( nf=

ZajdA5ht\0UaLP0M )o?5%kXk(7)Ss&#Ԙ6s0gDWk/QNSG;Ȗ
~n{TG} R0T~
A|pLp@bڍ _WemV 1 /"uǣ }^jb;.,&{0=|F@ 3bKphx⚜&7lխ|+0=)xN\N>aFj1cd+@4r'Ț}mqOJi==^n!7IYc"!]D|12aN?;M҃jMtTռq+r,x߆FޤT]g\Wy1迚72 :P-K{
Fձjp;3;ӡ¶j35T" [tAd&k u+kuպRv=L.Iy)}k o`
<޲6lMOP0-vљw&7ϑe hq5ԙvf%n73D7CfyOo526z'#x],#>!w;i5ȶjG*C]Z|c-o#/&6u.:iG2.gO[MZ?;S'=
FC&O;yQSPb#M ' m4RZ>N85/3\h_q@{c.-XC7~+^3ij }
o\{Qbm̨b|(jG]ídώ6c9HGToIPFA]xjsZL \Ԓsh hذ3HCje0g <P%,];N p+~jBKCK KSCl3((' vq M&iS'A0e4oMPEDEWg4*nl-- Lci;6Ҷ-Gˢ7íCf[2Hy@mG&IYٽ͎vKP).GE[l*^]:]Re|g0G+/<Nwޞ[x$* uᐿ6 W1
~Y~\#!Ĵa47^ Rf88|"u
mc@+iu.PgYE dĦT)SskJ);9loWgɕq,Z5^ֲ&"L!gp۱?h +5yE!BGA 1  8]ysX„{ĩSk
!2cR|@ ҵMNR<nQjR\ZU C+\mo1۫$<Ħ.UGy¢$SٙB]E$@
Yd4bN
Ǜ<;.!|琻4VNņ%~ͨG.k`}ȂOe԰^`&+ՀrQRwrd>ai5 1Q#v/98ce<ԫ!dvKAK y?bt){U?0EK h.G-c^v|oz%X<W}7 B 9-eʆԳ=Gids1B.B"׃w3X6U;T/HLa)ºm?1<P$+W
v!k+U櫻d9':<3l˜N5`q0(k7y 6s m"b.iK UP+'kq+9.-~HɕE&u)}F68/s!l~T'zKv
2(,b ё5GҐ/Aʝ9+(f6dm5 |˪_(~W旮I}p
iȚnts T1/QZΒXal͊ł GKes=c A_VV:Œ&/ң*Se(t)"EtKJęMg&guc;S!|Ƭ Q\P*u gzB,`$O(f̪6Bk%T8m碷ZkTCPuQL]FLڲR7}=@ηkČ
Cȸ"irU:"^CtO-2֜s7^o2l1L. KuCӎ*'\Xqm>O=un&(½q,* D#"F
"pa}tXq-9}8g=B 'QVI1Ǔz) ݕ(3*h)%vYS)Hmq7oTBߡ}t#&A޸[Zq v*hfӒ6FΓAQ;F64{&bo \C(^W[&yŎ&0f$j.񫺎ǪY#
B?ĩF@mUWa)UhN%<:)ew?G%Vp^F~^.fFH
B"58SDw)Pey  D"Xƴ ɷËىu(aQ߆섽Puo39^WgsEcgh^mGfGY7]>#|^N~LIi\|
Đh^2H .]Rt)t'[g#I t!g,kd`EG! &F+:1@N;R}w
LEVc1}D߅@Go྘:Ld&s / V'5_b#s:W`5E¿j?Pr̤`#8*qt=>a[QBlXz E-UE{1S%"ks0}#<rlk?D+C_:FF?ku>,Sza1i`X/:ڳ±;: 2jb2+w|:0LOG 7c<jxel?u"`Y\Zl4ax"#, ^(+!ZB /cvɰ"[lSDBS X8e}o9'ۦn"Rvî0"P RS
[!Q0;֧xq_
J!6 S.tHI6b
bS6Ibt& N<qOGR{ISQYBq Z"JqV+tKUSյOZV*i#cg
2j$|Ci'pW%Q:)Wgbu%r_zreUDžL 9 H۹3#ܛr
>OHc,Q#ѷ.Lmz鏎 Ȁ=p.8iplA݄Ŕm`XK.M9k3i=5rT7^Yz<p̒DŽD~~; 'S|ܘ`ښvAX0sB9gl 4cwsrYs5 G xP<\AT(wp$1H,V&`g$1~w`Q:ao}T//CA*#jGN5LJ7il޽A\=Z Lu1/'<
v<9[/-Y:M-V)ߖBZwP<?tX
1>,L75xMDĿ[A󵬜&S0N[]5W_/Ȯ M>*Є&:ҎKD".,_RN,nݪ5[<QL:m0ѪBэU
KNcqw @>J/Xi8oac, bQ|~n"V-}MyM
k:uvc:%t>[~Uv\-l԰VRM'[)x^ nޝηVb˃ƌ>d>-!tߐ@AAϑ+P "ֵq٥&O
kC gd7ɼ! w1
aC͂8 !b!V>ޤ<NaiHW3Lǐ=Ys^wu,bL:.r!20xKd0g,NcY 7T[4N<'Vch`4L6Wf¦f:~8#<PwvND &@fg(v%m'9^hġ Z>%GEgl l9e >ȽfI^'X*^Lw`hEbI `4MzB{A& mBC C'0Is ;h2(q~b)7_??9?ǟO~/mPnی*Ae'3H 47@/"?5`Ln9Ѯґo\O`֌ )IEB׶n|sef;Bw T ŻB˵7 $6G@R- A7]$ tC}J4DHrDQNѤ*Dt
)xg;&OYOcAVLy cE4f{/J'skN_BI7wB[s)vZ^i5bvƊXXos1BKՅa $њ/\>4177+NT`
e6lƿ(l>;'-y7Q2naW spW5HcpiM3\τ'ieGw]z
q=I=.8p,1$Kn5^<!} Ѥg++Uqzc`K2zjer=K3R;V^JUZP(wWV(lXW
"OYb% <@j&kK|'FP?~ﳻir )ݯ!0o38)",=jW!VK~O*<z2Rrnyx$l5|ZFG/x"ЁL0#F<%:(q] )׶r
"_ϝ-hF彿+
]CUAHv\j5 Dɐ2IŅ0cQߖd%'Q%C%2$C8h(ᇝ.aK4-?6S]?$ǹC,^E]ge|TmX'6(}$;joD@E
hV_2몌g/Sӕp(f{E7@P.&@B:^.1ҿЖ(;u4:/ڙ*-F
S:g{- O'dSqW
iጷA?>3ꡭh4АqE(z!IO4
‹WZ2M<Op2ȗ*0}S$
xRP`ֿ˫_{@](9Q!i&n'\Q{|[Aot'!z'CL(*PܟIVR p&hŦŗ^
t?VlAEtZ@x(Ʈ>L!aޙ)ش)6 ☑Xg^h3
BPs8$vO3&?3G\olZ􆏊upN8f!J<fQBħw)SwqSdV^'*Sf1tv.?vBE$)OI|
0E*K@ͦ12: 2cc{B`Aw繨K%o_Ḫ?-8zd \
C qYBNA3qu\;:\̃Px.֌?I Q`%›ݝM:Ӄ!-<? D81g.Ȟ4c!(R$Ҏh֞wPT%O~ B)&f3yaR.mR׫bGUGabP*ݛJRn/NZF[P!z;<?ƺZ&@Yf߰~V:($Lcmcrn>yjt.h>K+l'Ix%IO/kzxE-N^e6~21ӶCy?|gP홬t陵u^3G]^ NnI.ff)1ҺbN-2_s0O8{IAf#cd'JGn]=PϊҥƵ~ B
!WC.ΩmM۩ a>6moG҅[ 3ObHƶhn/46vX|OLk]-\ (Α Q[hsěiˌ$]u0l-
ּ+I
OzͨJ)!agVy#̼A^Mq
}a\iĵ4d}w-j}gTb2b(B=Iԣ"o&FoW@$\-:cmU"@s~C8{n}g)%&Gs_b>"/R*Y\h*n)̕jBv8v-uC{T\bп$} aKdRFSQl%wmR2D3/7 x>???aؓzs g;69Uxգ 9&ѐU "CCKLH
ʰJD9-pdӛs6LWϔJ.%Ik2%i|MCkX2Qši1_E[

Թ}!uRhɍ΀ATisܶF6
O,51QƛD>9
@m*>aoqv=Ψbzsqv= +(0wgrx 6&Ak= ڮpsgC08d9
)P!%Ww~N3|ևnO$R$e9_{f ȼL".NxP){6M9 Ŷ%bgdAEv_
P驧&Q:ulSckހbAbySV.;>l9LPy312
M4DO6jjPbJ:ʆ(cj{1+,&*DBO|/Fj@ ܖG+c5ba8?Z9
vc:H,EC:4bGJ_`?+Rnu D6]
u/釿^̀ݠL:$6ރjzz;jPQ`%n1JW̩B𵷆m<d Q^ _a#+&h4³1mO^$q5&;_aӷV:Ae^#{#4Z.CeoHH2`^pht *7?NC`\H(^{C箧ZArUxP ]twu#kLh+>EeKq<po
d}?b4h^4xb$& QoՂS
(-ϔ&T/jmt23 b[YM9T9Wv
lǡi%~Ҵ3(=^E:)Y lM Yz 6Jޙ:B!=sgx?P<nqc\ԡnF;qz?Dl;lDWLY_fIs_F%W)]+/&הnOr6>_;PY/8xD@ ,3qN:X6~cH0-<(veؐB:X7?6}
0g@
j9'V.~A@u BA*~j3:7BH7,M=OZ8bC`/Ҏ~UwT2%g]. .њ'6ùQ7Ny Qkpm
>=U'K `EgvC܀vA1A0
̗0i5MxY(M 4@TS}Z=g|n&H~Ո4"4Kg5ӊie교)=N_V'g; zP-dU_<Fvz-L!"Tā>~hOre2(/%kLo03)&E ?+5X=iʛ3ܑ
%8zjTX
#_3;
z2e}OLkY!D֪61kuO!*ObZNmd
;xJ&Y!`߮&`1^K95r11&2
{Θ 2$x9Vs d1YFǺ01agXJx)sY
!Obȕ0Y WV7/c
Rp
4 6pfupsYѵ %oٯӁRKNTrgMa4*T/k$7 (K^ƂLP f7PD_l<.(oC?1Nd[eK*!zqIpC#>dMR .3{2jY-l$Zd
q^n!Lѹ=J~9OB+}L%>i
ԃx/#<bmUrg*'{iUOaC3U'Ye._Ly ,Ü7\Yd)组O8 CpUYp,|_gG$Y^}!Degr 5,)Ǫ.u*ǝ`dxHU#{\dV@KdND;`׀(ADi fUJmK^oWQ> )+xhw=C2 [
;Sܕ==A`sL 8pd _47H#Ax&ZAQ>;lYV/y:VPIKD,oqjxF&Pʔ(,ʔafK^UbOVPT,_FL…}Oػw
d~U|{},6X@Cžn+z 2Ĭ
s&]u!H2aVžB[LNDhJgEk>,]?1AqYK*K4Yz<b/9 ?$e7.ˠdJ 6!̤x1lW,j9;9x@u&Y2Aj=Q[d],Xv>`a2&i`T)vGFK4tjRy
/
FZ6#YxC8djCLj+B[6'|g#4;I4+wS$NN/%7-o9ܶ>Wޢ : PX{C08\
UZ(|6)MRGSFd wfYB8J*tuZkW4 f6rx<=x4+_8"zz*Nzc3<\&Vo'^9}Пf8kEhYtq.h[QmtP;[ۇRk&`e =f=AcWmHQy@#7}V.[;iL $oc_d-˩T&wBϴMv
jX~KJ@bipľ2/Cvwpy;cϋN֍"̅>Esr,UL
"4Ѭ*4u<HDG85NoмF=5@炶w~Oڶz!/
E}olm fɃY o#3>
;{-+a&|X$|Є=FOO UHRK]wtzza߬]r}h{-H#J >ҧ?t3:WP?< v*%TxĚ
:Zz_{mh^K|@_ЊA*ZW X*$ؖKykyOE~_f^#@)F4#x%㻘JN"SAD 0+C4F5D7q
t]4_^K书ڏRhL_nRO!
y)ɻ1r3cou? V]
WH ko_$h;}>vPk]C$d
X TTW1N)x}jM.2n.:fIPj= $5ɵC㚚HC.`eIG߬"<%Ѕwjэ9aL=&T15-8}̼88ukK3:7iؠ!c=+72*yAC=P\OS [3aa[F5AnVT\wBt@˿x9I(R7/'
lպ +>g4 )i!A!j^~%Vh`T``͗Wg\8SӎHg co5WgpPȅ%1,]-_k~vUO1i4H#pc9gCD6mdv8цw # Ǭo^)|,OW4"~D.gvG(*;-;nfH}7[`
3s"HϕWC`x},K[#-iF֚SN싉pGx|lRm oZ;#Jp`?znSjZB5鎒C=pS{LGj U%N"bZEXeZDs"]23T/R:
5$оVDzSlhB j5S E-@sd]ja 'Hmʂ"3UX;Kf
4ju#W'U(Bu桍ݑ!=ngk/H7!)+][q3 d<>e:=v>Z#7^QY6]$A{pm>;@{x,!mމ}g47 W=k/G N7VKXQXo1%E{}+'PPPD8`%K-؆Cv+kW&<ULr5
P$<%Lw+h3~v˰?'M C1M Vq2}Mc;57X¶1NF$b7w/ ]T e8
h5k'4=͋jѡ$mVXJlӠ'*jMh!j 1s )
—pTzc]w\Si$SXel`TKgNԝ (ND-7X?v ُW@8fgު9 @c O{)~ *iggÒmTū6bU%8(t$km22;-Z EW[X n^o(0aG
5uZDi<.aӧrz'=%sص4 L&EWsi[c='(v;?1` -a'8(*ʢϘ
DO5S=#$2,vB~Eqp鵜i b$CUth^{%{PNeΞ}" |pNjG^;cZ#ȇ&8=Y!pzIBR2@ycpŠeˊś=%Qn?ac^u%*;k ԿӇ

Qn'oZ愷dT(!|61-W9. )
A@ſ`^&y{l6ӾH/CktտK@vV<9>@U!wyMYXIk82}t˵*cwf.[*v~*aЫG\ߺ?tƽ*7
A׽S7!/HMEww!!٤ǎ{& ?N`Ӹkы7+GOnr
<{A!ܾeJL4BRͰG=jP-*U4Y)5ިu~n`Adp%?^5٩b8#H4p⣴$w ȝAFvNlԨ Zf>"[s1GbH]dXx`MScrta9
+HBgqzm?VB_]!hA{6w 0m7D_CBdus*"Z1G?O)| WcgJtWzNJwQ6m>~]zs~6FoK@kֈS5b(^9_2>j
5_㌳Q_k'+Zz'hc.l8LbE=If,H"ۇΞQx7+
g~J<1Kf=m`޴]Xu43zoId4 5oFLKoۯUA9?VX cX3Ǎb:g!ŸVQa щ[
z

N
 tHo%>,\F²T)V߀5tF~y0j,q쓎Dcr`:/fRCHiTf/إ62duG0zĀG\Ԁ7 B3g7ͥrvȉj0Wj6Q,0XBߘNB2R!T٢LX?1܌d?xu ٻ]PJ5H
 l,]w}p-A\ǯ<yw.AӖs_O *Tʞ$T c9=|eG_w
JAnZxdo%rK~h=
># X6`dnIE@cA߭k'A"sUO7^og$u79L,f 9bmSxk
G+5%ӝ[\wz2T=gDh7ag/L>ܑO~.PV -rxBI/+cOkzuDwm֊g3]#"G \;،3g"'JPϏ W\Ћ6E
G1OhGxd fFvͬoWIl+`<kLײYNxdmH+]+mўPGs3ee.aAAˬrk KQ<!6@Ƿ+\#5"JK&)P=Y aI L#D"`|Z%9S#u~ٶL^m2K'3EeT!
KGt 1Zu&V>'`WK/M<ǷTՎT\
M)o6^M]U#)X%&R5t TW%me۝HRNq <eRBiVgttnKՁ/8'h^B%B2`
łȈ8Ĩxam@
&;?ҔDUtu[[S復}5h`=?LM,LZZM.A(d.C$n-J1V es3Ѝ3L߱!b 1i[ WxLQ=L4+Z`I1Jo]Y)9{7M5v.]
ޓAH_Od.֝H%G\vy; ]_~2GpO)b?M;l+)Ӳ+AHULIh=\g+8"'q[Jwq Ko[!fR[~V
yl,VNEz?#Tӏ{Fl .
>'67T(xXoi~"!0ote$/nJD|/PrWOT&;,`;ʬ\E}Wrp"~
GUP4=h{GH]~f"gU> G '<Q k!"2
*# U쮹p71Tiq8Ϻ4ECdv ?;pR" YS{MC|/lQwcnamh8Qf+b%]q/
-cBœ3VD>$0AK1:uJ&)Nw ^dR#%Zg'm \9GA}W *Ij=-7f@TW|N%ϋw7h[٪P
6zfT@W*ψӵ7 lD }j
/Œ'75 ;~[#fهWo hM:{}#]TǬX,sph2U*.¬ Z
xd-Y )V0]emqBH40rul}
.tVo^8\>'
یbA[=!/d7h]WXN=Kw sѴ͌9tn]t7ijB >X9v/EӺT_ğ2!P(JY^ Q? Ėh~ S߁Ұ
v+LEė|[PTG[EZw깐9?8<%wPt)]:3{1ǀW#WGԱ.HǗLpjǒ!HQE0NCd-Ng7г bϙQt9]^:DRUzRk
!BY
FcQKZLwe.!ד dЈSI/RE"+GdMyXª
}Tg+u_pzýni32AIMTu Ymo72 iQb9r0ʬk.JxYEQ(ov[Eg@ciS+jaZͫ}5ymLw̤L,/mo"rm7d_m z97>lx|K*Q)<ˆűx`AH B+{CB͝"Z;3]b v\zޥ'a|i"qhز55v|2ZoIкFK0O[=bFHD>0N
5 *f<2momjJ<=i9և4[Gkn,w RV
n!-Ҡg궭kR0Plj42]Ţ
/D%dT 1鏰>NH{\#>/ |!؈L$CM;4CU*lg"@MfS0aSg]hEi!MZF?&ag|O=ߟ|OOxI2znGem$
{BumD8HRyOO7?9Q% T]3^ !Hqu'":W>%QD$G[`ާ9ℽ{s
d J'°lcaX\e|9Kr <dr(rMIm B {3@E /'N:e׈^u*:I1q/$:HN eV8aT;WDnU3U[&%H )X3]/c8wSco9fI;%#&3F#\3ɷ"]~:Nch_@Qw_+8]c9 3z]u{ ;w!na˫VSٷ{Դ'(Px"ZIzEfL sϼQ%^^r:m7YϘ?Wʒ'v(?ĩ&Z=\e<*^)]MJ *)hcalj,% 99WWx H5i\GڙkyKOf$ocȲV
APܯ)Q' f:)AUyD!O/l%\67"읦Pß>cWT= y/Q)0 %!<m
Y=V$|U[KB/M]cqJ?{֒e%8^r!)[ pa٢J YV@d8Z C>崱HGKc4frˇtEn 嚒k[owV+h}Nw͍.J*ׇ.*0;+qt A N!RP߷RsB$P:І5U :FD%h޹[3֣n{~"}^o("v =Oko%! A`rXo*Ga{20/ֺecEuC>pǜ/HIϪu&kD2%Ś3SSn͠Oz
rЌ*Wxmȥ.9Nt?zo]4!D ͫ/v [X? ?\fX B[Go ˸XČ= ݬ'. Y }sc@$j.+bSu)4fV1 %κ :5d9 "e}He&<H~ikB"R-frΘ/r1D<:rp+"\[-JaebR#_? 2nrශ-ƻN{w+BP+>ɞ`6o!)0W`JiMN0€:><fQ&F`ml)wO<u׀L@vRKO,PῘKr#3
rQtаT~<C+<u5
uu[~4}#C|*k`O^H^A)wn|k
sO;_'z%qy q5'Ƙb3TM
xJuY6VXvQwMFa^*^ L'ew@vĕ -b# [ws0ũ?ouzE!yuwFQv2$˯;pn˔6<\W PI^ώ2D@m]ܣ/2g :stk; \k"{oRWpyB>w,<4:Q7
͑~[
T&<;Re0r0v03Vי!߶뢰mE{.,$d<!'Fh"҆;1d~:\p:^dƚzGh\Q.sUEeͽP<<+=%'F ;]\ƾk<-/mRQ1`ʱW@nN9
KQF;@Ie2j
jJ2>DJq VlD}\kP2,-`EXtU5i`xO '91RHϧ'/=Giǧ6?9&X^Ь'3EݚtYVow«ƕ9;
@"+Z&cT׻"N?pweAsQJŚO@MjR`y0_qp![r0vO inHYtOqrfU;yF3
~(;EFvB1") q`9fs˾͔^'{Oz:l>k.&O:
l}$bl~Rf1쎎PNsA>^_Fo%cvm2}])ŞL2|bB{wvQ"1~g'b͕c qC3 l8 kQu]ff0.j*] z}x ;J4=3ߴńjq__`AmBknd9ÌJXq
)6(hYy}|'|XA=m4T\ 1z-ANh-E?Eg4qig+Dà q]o"N/%9\~ZC Kev ֑_1k)؅{2,
M0cyR*;oX1ly5mo|Aw9
Hh7'mh^I'.]LBV7+oӜ
9{axf=ֹc RQ?HM$9@bīAڦĵSU`:ƾ̜NheO㻖l@I?>,
Obَ`kwG Yr'} AvZ-kXhȯ=6#@{o&ݺQݮBD*|
R+_M9}WWsc&>M2!qhHa+jϭTO&1su_@PQ[Z2(h:)r=vA ^ʳ+ф5sY+lAI<tVq059Ұ g:hs*I/Q I OInS^3KpVxc}
JnVYNć`(F..t2Ji6 aҨ[#Duzuj;pl|yTn߬vGez2#aŢЫU|5n?rXc:+‚!,Ӆp D^`HX{3 tr=KTrI/l*w-
/3 P;^
WHU:P'rǶ`N3հN4WjU
OC c2KaXT eQPNe]{C20^4Uy(cjv8gSSl
NV`it#ivm5V|2C`厷XPrfB{_k{ueu'WbCBZ^"yqsaDIիS"=H·`ЃcW&눈:LcCRLє/܁"|ݾp5Z +f$
Xv
°9/ s2<0v PsO槴4* ߯_ƾHgpp/(W:4ncy/q=aV.4a\ BBh;5VD'!\7B.e0䨿wPJ?= PŚFwŷS)|kTO q8V4ۃ/h0xZʢIP$6[ 0(b_5L Zxuڭ-)B <9@@°,# ^ 3haO`[ˑ&[wEoi)ع÷zFeNZ& UB\j\Y#!y^JHw&oaT?bPV76xN(YJݔ3RH W$l 82c~XGKXdN5N 3Ia0''x*:rK0sXF(T6Ȣ'
)Uu"CX>2,ݦHҪ_ô1g 2wh{
qZL$ks# /Vuࣇj51`
@S5wR.))ퟑիWl,gRv_A_gGRC6;ޡ9rKJ\黁
}~8z"X ́>^N՛}*rjw&U[mqTܠ):$}75Vn铜:V.LznN_R
s|Ø?K ;B4S {M%$8_RXLS–; 8jEujFhu^ڛN=rMCZķmIY:hl2(#/C+,C)1!;k8VU>pu o?)+ vetT
D Dǂ;R[g~m㠘u㝊ɝ TGpi&wQ|va驟?UTS3ErJMoeEL-9@yTO?w__Բ
zC7݉" #o+ig J0Rp8lggvh4Q$<̀g- o֗UO6šBe OH(Kd|שB SFa1`,stH]¿PXB1
)z.ң
t*7:009N?2[ K'z0Hk;l.S'8 h4Eh_@_@,nO~L6&d`AG5DC,l EBo͵]!u
l;JFk`a$t<8 zfGZĭ?vGEY "X\NA4_J/
<1x؂1T<Yy~Tpg}i ّ.mšTO'C9j8>]J&MS͢j*VoZxg(6k
&P4Sь>1]ᤖ'Ф5UT+XP$oja窜zt<>d&ѡk5],=;Dxl'ycS\/Y3Q
I@xL^@!v{[vtַ
Y=e5ixcnD2gg'<kd67ȹDFALz}nQ"t0x[erh= .ch%qŗ{_;;CR"2cL'opQH.Ԣ*S鏻nJsܬ?,2>M3P6nt=8dlƷ[ס+W ŝjNdlx;9PTԢ]*.p"Ԑ+\Y{V 핁Օȟ:$o#'saDyll ^e,. {ou6xwx[CMgdj?6,)(q]fn$/e?-ﵮ^rH&WLDOTcDZN꼋>jAί$Er[KyoSQN7,aFWZ1]
CWc;R2
&Ȫ{f6w!b1NVTg )C
ރ,㓰l!Y_g~wc!hlo1r02"Zlljbi͡ЀZ=LIq9ks ?va0խO% αBe1oMBJ^tWC15U 0oc,HWpJ8yh_#-#GxS'ĩ)fFg?1
pb.]L-zXO :CQ%8Ф
U{uxfL}q/8ЁV#MU]q`?_Zbx,Je,b# cxkZM[j=*z_%.tcؓA<DwcN zl߳ЭDzzI:WM }#$C0KM,Z˺8dW'#ލvA𞪮(;Ejd׷;h'Hfj{'֠iqu;ogsL*;,-斘y<\]XX=%yJbƗq): \!eX//pTT<_#`(Y$M ԟk6t@0lۄ'G&o[ TU栋ycwܒTCZ6oн3q8r 5f:-sk2 ?xm#:Шad6q6h,n2ۋw5*8b=ibj

ekw! ylCksyԏrAg f>VOTłj,YdВZLe#Dـ;u2 - N2X+49:O\^֓m`4*q T|'<yi҂ր9
:w oBdDc1rXn*5fy" ez>)B2)k`}c\?CU')#oZܰԋam2Kd)v'zMbaøP'A;¿×qܚԥIX 4Y΅f}ԌƼdĹshF QB`{uOp~yGim6qޙ5o[; orem? o~云*8A
Y
/*F04vsWi$_Ser˙(b̀0Z>$J+mԁ0@Lh1Ķ |G,isQT]'mʷYZVq<ͷubv26od"gl;|yN坤[0 6&/J$N3$}"\ 9
YmےIU)p<sރss&d '<q;ږfb=l`򅁁_2ױ Uu륷GhϲNs/ʂ)z&ۼ7r:=~G"mKBTLA~^I<_Ve=Zb;8͢!#8ݽ?pKt?ȿ]8akfT3K&BKG\,q
SB]CXPڃO:'2ݤ*kg
\iF
P+AlRAvgGj|3.9IkIߨ\$}zqh1j7q:"ʖ
nqL*RE}ICwUL2x?SQ55
˰ EV7B1bTu+"Q-a,`zk]K]2~AP
fb
pCpaXFD $_
I
`d
.
imم[K'[ncB%aAajezd!!}N[v3B, Mz1ZMS{7w,}e*:E
HY; cGj^ӿ{QO|X*?~Щ^IkA-)z[ꃹop<iJ "{"܌oQ=2̎)Zh3 q|\Bυ">B_.@\k~
ƪ)Ppe}~
a@>A(*ȀR0Cg
~ oSeK {rQq8:(L})irQmȺO ىT+тFave9W|MPg.wA# J 1.k;ףv=!7Wғ/7&"õ@ꄛICKnb !~o8u%u0&8E}|э+Ne=ڑ?JdurV2%w#_:5f^8M_^:hB/Ed6wG?GeGd78xoHkT؎-_wT}j!FRA&4I)k=)S%OJ']hti?KNy%}(,!!nO)=F<2UJb(_ а"m&9gAU 1e.J\
)-<XteXb{
Hӳ-LXd0&?^{R{U-n7-\XRww`sو>XFⴖڕwǘe ;
9Sm~6
G)EMTBξ<
B\l'[~Q2'ZvbFKΩ8m%tbлMqįl`\7'&
fms ,$סgG|`o#?;$Z}lЄg"9sU۳{kA
+ "`/7l?4i_7]Z`yM-@CO"M->ە7
",V\@ӾjʣF[3Hנ#ދ
`W9wF5ƵIE"? I
S&s8% W4f*Y]D8{~Ђ.?B
nU)
f Vx]K=# 
%\n;AZ?qWL9uJ<iL?#U!86լ`εy.OV55 ,;y]^s%̇mu6F~+
:km'fm%C0MxQ LG>rƯ%-M#EŐ'Ma,Z/waѯNjc /ܺN&(;odFܑ9',Z(kdJRWeIH/_\5E04w_)Lg"N$Hdaiӕ7ϝbl 6䟃G;/oQs-8͘
R-奣ujuXz2L6_iIק2rl;|3qI[ ²V=0
Qie#. +~ eq4k48@,h
o?;44Vk:%Z/L &}Yvke(۹r
"1
Q'hWa{oqiz2]#Qo. $ƀߧ&z(D!͡=&NE>v 4gAv= D_ψAfi<G!ldhdPjsStH5ǧ`q=%
: &/1p3,eDzEX75*6SПtenY(G0wB7:R'R+#zȯ_R`gQݽA,G_=_hKر P%EhWʰD*
r]܍_&w1|Ț]ZդS0<ss5TcT{u76ޘ"ȗcoO\±<{+ȨC!{L Y(9`枫;U pLi'Qƌp+)(2S%_⤙}V)Jg.N~j/8SSi3b9O ,&qE,Y.4# 6TFkxGhooSd<)f{ eHN<Su1ZIx2}1訫66l]oJ@3{o,rtHo3@KK).ߡqcf@x(]j䯞fEZaޔ=}ޭ(WmzuM
պƟ\J x0b XR6J*&DOZ\!T+HXa'06c
B4ᙣnۍXrZg=1٬lCX
sSѬ>}iNB:ul®6}8yK>M/?y{㱏Ӥ@r9k@𦕾@yث$8S/Az{g67Ĥg62eC^ߵ߻a۸Jzq
^s<`vX2}Ͷb|aF6,HjBȹ2uDۍ6/tAt|
dIHX\!8 [,xf #vP@lC Nyyk*Nx
27:jOczc؍OR04rX U{aUA)EZ)uaq2{NB}:AI?0K(s9︂]g,$<+MvxcO@tLT:2O@4
<p#'*ŴJ'0
@Ⱦg]bigP7+ 53gzA5 fҍhA͑q7hVKRUd#FB\5ɹWiod#"ِ[sfo;*Τ͕b2,-'X8T* B[Ӈ 9gU^jyJq~RL_[cn^Q$S4]2 qkWl9wҦHGZnmeɰ8 Z /*@qa<^B
@RfS)O-jWAƎW߽gRc
ơ4w,%$h5,f|/lF dCo8z (˙֝Y +1fV=7O_19_߳ܜZ&?ʢ31CğWmu<1b$!eҝk0܈[Nܶh{3 <VZA]Gh.eUs5
GRU0)#,LS2mHԐvIvvzY?z>E={62AitT$\)ټ.=6n^њ@|Vji$NMŊ$liL+w[e/i<-aqv92-/U$RT{G:] jaRW4LWǮs $ԭbL)Dcta0Ƌx5s۠"6A%kҧUE|4`롎h+;{gEAVu ŌUl 3J<ك!)d#E[%~T
s4KUf Ej{|?9EDi(<@'@lqsE/i`y&(`_ezVGN.ҷWu`sFF˓ܰ^tFR:#0I1qjme&[}
\
aBJiy)nHjP>c{IgwGoD؊xn\z:oU7'c/6Θq Xx+{m"cƠ$pϔ9Kؿw2mt 'ˋ<

"M|1GA)<W움HE~^2UEoZ+I 19 DSȐ Gfzz
dw[?jmF'b ”0BBve'0lyS?
EZa@"! C%ܝK}| uV?aKRVsۢ[CdqŽa"E]4VWg礖
78snp 7oS<,d4;*Qn^$GD9}HJ#/)_ҪF[%vj}{k-9?/˸7r
(\yZLL=[Nk TD70b櫈YuN
ǫ0<z%uWA$4EH<Aڣb z72%p
BZD=؝^LhgI6~T ?!NڍLAVk0 *3|ѦnϕETW}詌A7'ܛ,7E>VE閯Ԥ^]2b;wSf.541ejl҇b)lt4?$g|EC"(x7PHt!B^waWdΝ O##.~Ӥ>Y= PC|λg!<%F>1&Y@!0.mǟ,EAk^|bev]8!B3" m_ST0w"b<>ӫwKKx4"e.?a:?ŚyQv~_Lۢ'9A_M!z'TX)XZgso#mu:ʯ Z15VѥakүD<B$\]3ÞiYhvb`W$3#ڴიW6MKQH9\d UU'Vś'{쵂(Px ,}De}L/qt@^bxYV:"s8Vm˷yv7p@j9Rq"OgpNT7vuo+|Q}?{ P2y؜+S7xEFzAV͎QTk Z,!1:\q?ViU:
$g݄$[_WLJR
PW]nifItU[/q5rP^V+Z[7B yweB܏'@gNWR CPl7Q@u"N\>gljS7ib$&dH7 {МovO4_"pju T?M46, X5H*+Tj0/*
ohh-΋WiJܖ{j"×)9 ^=W|<\#HAe% VI\o7TĪ&5G -R=XxbЗ]`21^uC,{Z7D..}KE+܅6鑵CJ[9!ñw

nAK2[UВQ<T4,{vɠnϿew`0љ {Scx.Jx3@?|aQ\FgY?91bVD+b&pOfoq #Es'szNZ&tw+dKÕ@B0ࢊr(kE /,wm4}ZLY8>sCr7?{|܉4 ͏AwhG^2FK'Xo(6 GYoP$1mU7P0 DKgll5y pGϤ阨zgR-%=@O\pI J^ q/P m@ǰ[Gm4mm3`+ꉿŸw>{}Q;+>"u3;I =3H@ z@cs]1o <˚@id[@ڑ:Hfڱ Tʒz{|*`-s]T\RPSSz0
pk߈?5GwyV.^e4c'*<& )8iBg Җ~cS} ٕ7pNg3X\֒C ph2lP v7\ j/CZKqQh{ Dpkࠥ{F
Q uaء`I1LJ&"w'KdFje5EmuC(m'S CCެ$ԕ3uvi}貋Bن1s텪Ao}•O ޓTQF +p8?&H^κPt'uս=JCceȝG9mMOM"RGQ]RR" T ޒ$j=I5@OyVdJY6>Q.UPo1]^$L%KU3Of҉ֵ6ʀL%P\J7_X50q@잚=IXgSav45dН۰qˉqYPjD/&Կ[fC^X5? ^3\}׋ΉO
&6-ү|s1ɹ-i1tw^ѳ~W]m.6{dSYCb݉bR;wa? D]6oT+4 3'ib
}l ; fkD?ljcI@V -@p*H?lrRǒxJ`2[=BRij ss6,t_<pef‘B~MzjcGT
G[8 PP+]֒G?|\Q/FbkOsӖ8]('Z4l^"gHHZH@-Ud2p{dVIbd`hYz/Y#>pPt#!
CoE<S,@W/-ZK
DDJas3r R'V=|)i^
C&R1wɰ@s["1o5nUH5I;>; xpwϖ
<m\{Nc ͂yKx)bX<> ʛ~V"'#VdWql+ KGdלʺ4ҴkM *Mv"ظk}WRsi@ v^GdD'eh$_pJ ">{@سkL?/\ER+,BVP3b=dfx$Od =FuvK_]0wN&1I閄w[V\/#qcm#F @
uLlҟp]PQ~u }vU-#S ̋4>ei-Y.%G .17
ۺ41A n))|E*̬,Ǎ5hK,N+L|'RЕ7,[I[|_|2 +W* {dCdJA97szVd0ѴoiOLJCأZa/u7_PTpPʋ%5 ̈F_V4ws
5.H| >l ~J_=`8sKMyi3Gv"qŝB@t&/CFZb1H&" 4aU pb\W&\^E+H@s?%wfAׇhiM^R܄ݒ_ww t/R
7(z9<P=YI}&9TX靵ѓ{v7iAoR)ax3dz@~3ScE2f_wil'YAIs;58Q"9nA{^A~_AᰘfF(G4U ABCP~{:(Yӧ|;8X){rѵ <hs=IX?kzX0^O%]z::@
U*CnI!Pv{S2FN7Ocu[{q猙ý1k5an}a؛#LeM]u)SZq*4P_̡h['&b7-i]
hjΆr_Ύs\7R'"d~ z8qW>=3fƚOg!u(Uhѧr]wqʝ8W5-<$Y2aƂiGsכ|<EojT,ٰ q%]}iz6y.u7o2O{LgiXi؞ՒQL E. K]N9`#F2G=z(t8LJlP @]\fB&=}b#)?CpPef1IZ YMR F4
*+TؿV RE*B<xH#Y׆|XR[oD "!QbbinÍ7o3Rcj!Q$GM;bԉjA
NBj-Vo'&
e-ŨBѣ;Eog;*<2\b8"N9~bXIr~0ݬ0h(3$.
}BЏmK<ZkKz$F'BW Zxb4L=%?,:9v1<EVH+n;/&ec óB & 0J{#NE]Mض[^=,ƾtB.@.w`Ҵ02!/vhNH(o<_Kcw::0$9)jŞzHmy#?%Z>u-5Y }AmQ,u ?ũ~Sb <yo'CPvry\U&v%p6s$0%4^D1soxë
y3wW^+j/*ͣ$!-X;"NGS0v=bam2 ٻTUEd&%7\֜_jτW)Gu ʻ_'ŋ]i+Lj(WW%oZ_3O};ei| 8T rAκwɓoP]G9pVli.z/>Mӥ,e=
%>PtU<7M:vtGtc7؀vLqi:'e/kTNymY 7ҳ6ih]5{Iv$>ˎ1he7m<h[8qDhjmސǹj@/[kϢ?7=s_9"DtxԅbS
X+,"\3Bn\ړPt񨗷Q,
M;^X Oat =
_ U]
GL*_(y_Ԡ7W L~ Ma]}1ݨL01
+DEۋX7v3y YERWjp;f
; "$Z%hY[YbW7Z0XvPH_fە@¦]fZB kuO#( j2H_ĿGԱKj%"Æ 2dV:`h+D#kVȿ~9& u8Zc# TKHm8sК\ګVEm3q63nqٱJ_4(AƱĖ Ri
(r\\5 '.kkI*3veYqi{yyW eo䀫W6iϜ8oĐd+
#`O
@b!Xi;|wbꛞ1,_2V 6  jHОN#xqE">MJ<l2>ݬ,&-|E 1JsLVģe"\2B$gD"|䛨V6m#%0K'
5 ̪+6_T~Zz'B 8!ҋ(7ULXJnhݰ)B|LȝQQHmZctnRKX=0&K?\|*ӧbRuv$ vDXRrf >w+դw` x
c 婜Iဦ}Pen_>r{P!|=X\%LVMIJFKA_ZXjOM3<X8 xroRѣ;+,<tpSj+}ꯟCu&X/ MeA&$QK#M7sdY;
҅&ݰ"=b:N
@IP2\i/EqYmёVVXg+otl8ŨЍz,׸a>yld{#0R2T=ytt:N, S@$?~Mm=O;Y.,T 0)٬Y QEQ=;JLޕ&H5jP:=]-5l&*l.BCzu&g[€JA kcM'>ւ[dA黭KeB6~Dx >MV9T#½o0/*ϭg^5քSkoY߁^(M~`Mjehm,+dsu@ 9Q/d~,-i Qt$A !<N0x, ;3ŽHI "tAw*d`[T.򄀱߮V3UӔ@ ȡ}{y ;*5421\]GjlH\^HC߻WfHҬ\p[uF) ꍢAl~b.l*ma(W n7ySD(h_H_O5̴<$@hl:|&[쑹hZ߇ni|{)$2;>qڞyhW:139[#
cb~ #;X*l6m5hl}P:j 0vЅ R 6KDVhRwyԾ7//sYMeUyGT W):@;w:dR=K⫶Fj"esxPg(yٍ)(! ;`bN-uu1B,hXoQcw998. )BƐUjwV0[.M
Ui
K!Nŀtdc!<}(Fz,&![çD+ F0 2) 3't:j5ԕT#@FBS_v$4zv쉰̔C
Еc|2vQ0'mlcsog2?{wW rWOB%X,:yoq^5a. s5>i3.ŕE{__q65vSD=7wr۴bI!K1遐d&mLjFl++dHY]r0 ~gQR?
+b\^O *6K_MgM,P~-?$&9т7Kyb gങX Y&㿤pV4Z0UzY'nƲ. 1A]tW%'QtFcNU([>lfh+A3ܾn"9 dPyMUlrJ]4YOmǔ 8˷|8tnɞ04x(PfuYe~:@ a@N-"湙I1HE:mF>BKS
_p!T~EAfmt`5x: ,L0`)`OC& N0Ɔcਲ਼,(LAh#x=[P2q[`9 F0`Xu4~XԘL"kn@Lx٬#*<N2kre?ͯӀ1$_BAyش7z yF7/^:DóY ]fY ඏ
-Mw~~+.O
{'#c~#,Oۺ0&U6*«~`h[7Ȩ?0,&[QTJËsxda
u+BƅDDki.4ۆ$ˎkyՂ>ٛڝ-S _Hx+ʿႪ#8S>7'u1aa\c
;:Ư1\<E۠ajs
7`}b˲j"G{tcsk{Hs{{-mBH]Κ]:+4N]?OŲ2QAֵ'za!X*Cײ=U=O; dT¯uBѝOy
3N`|Jδ>+s7dwSZv:F \AМx7?< 6k|2) WLV\|_hGXIdLUc>zm
%WtXtGdZ,,X woѸOzLPI=ǃFU\+\wV ƈ B0srBNGTIsr#&oLJ9DΉ7S}dmcKnFMea3a5ȈS(7dVHLY4׮5!:Ѿe)(lW 550qD̬72fkS)
LZ/ԡ@1n4f5C)3kG
5<8Fi}+CՊ"^!V-B?AXe9cj4u)PWԼLك,&Q/~DLȿ(6.Ɔ>J;DA>(3}<Ep
g;
ND``Dӊj~]/$({&,en6yn 2نknK+v "J:do#f/),Ԟ>PBZi?MNzze8{@?뇚x+
<M|P%!B}t,֘xWvn HDʣ9מ6T9#!XO{ܯq %Nӝm\
T ňβ}H- _Iׇ{ah/#}H2Y$ɫ|5Rǽ`4D<Rm_⑺֙-lDYEر\gVMo BD*3|tsۤNCk<"1b ً.UYHuDָyFBrBG3vMvlO"!6A4UHۋ^eP_9> g_;,sW}P u䋲GM? rBÒz.u2ɖoItwlXπ0&[IxmӓuH?p~}M/< 9QF&-a5;{g n2\MΦh)9K L˫9-RHܺ[KLk3i~k(?^oPX =8ƹbR7QoeX{hG^Oi)kzb"ϜlV%6ˬ<qqvCX,3wj,Yܮ4o! 1ҘҒifO لW䙖`+N)_PVẓz6 ^z~l y^tQHA(_s >?Y
k>Ԉ|9^lG5a?B*{x ԬYC̆ǫb ޑFlESfZ"r{ߒ$KQJ줌 N3ďf%$gHM$ tJا.aDA9ZcH-n8Mh0<, J pdohw!ۤ:D㝯S$0zU3ħVwh?B
GU[(&$ys@SW >z8-bUt$ՉŞUZF%hϯ}P E4qZlIPnpƖT/Av33
86!WC./g
гrިT,UH".DQ"i^ExeRt9:<1x~53w$F{r
06VN­ 2)OW.)l(ќlKsiyYK7p 1qr\éN=ݗȎm bu`ǥCҫ3hi/Xs" }s[XpBnR.n дPvb!<! m_M^#nM~xO!]ǭڭڀA{ö7A/JUj[<xdA
e[ImWhYrC0K)fnO`Xu%B0=wR+|+^Hל2<P
:DxUwp!3+SkIbsnFbhP.?+r_uܢ<p
} ^ ,,j,-:Q[we`*0:'5w,<vKW&`ْ/9J ߅>6+nۚӣR7 A-ڎ+_@@~95.x o
An m,j۴Cޔ!:sAsX8u c-v[ʲSAOsP
,*}Seq2&o'mnqWǨ?ϙ
dX9#}4:-hC;vdID^rOuVXwt-Чv((x_
{0 ,FHk,5zcOE"ﯵ y+[;X0멗k.\X剅q`' NR .k9S+2O0@]/ Xȫt3>]uTq *&\Rq# ċ8qR],;-n,YkɭXlj qo^enuHCչR9.6"34*LSB5<コ%w nzN%--A/.t,(moIH1u}ea-<Z1{GbI
~iwK.Ix!<a1k"İmN.VnYRHʄ .엮YYґ#]jvx {oLwv"/inb+I-脟uh|f:GZ z
$~bm,(E-AO64esxUza1j" !.<[X;1NUcG48jm7>+0
Cқ%?y_t\=O~CAr3x|[㪢c&&S卾U
fKTx_A^[ebFa;AȐe
4vUr/Ձmfp|y.ȝr>'p" !Z0㽯B~<V"D8[[X;W,+;Rse`)ݞO'pJy/gZB`XR—++qsWf!qgz?8
TO1e)pהMJ ѶՑ?zQm,X뾌!u
F: K1ZLm76XVfl
nhwJY_K]ap4̤͊Č=a\<Q
tB3oɋr
2e^nbY`
ⳞڬU8~lzLrt h
ٲ:/KOZ l"2LETEؓ<tLػFn˴'Ž8nl6Q@-U:'(Dghpwc[>T#6l|SHF ߭${@D!ᓢĦ5$!mNb<d\ɗH/gGMH%(#׮m13e^Gtz/ [mw#ǬѾ
ߒ;:|W1~|K6PCbs Eq-ai]iQ"%SreJ^!b"mrTZ|_wG
g2I: %oXeµՙ:߳Im_ʘ`6uC=|Fsn-COfuy(W+­}o}
$?c< "kZz**ڸzF3$ ̐[{rȬzbX#MZv|D<= F_8M <tzZr~ [H`kHyMj]ǂqe4:F'Ḟf#)($?s;6ͬ(?:lULns[ 19G~i(J"t 5asV-.ŽW68|`\dNzW F%)'4 4f(VwOf%5ܚ> 4m TGs.,/1e"Aa^.ؿ)qaP 6tCF$06ᰔV1 bpHt{YZk΢sICߦX{!Cf5@(H^ [_Ƣ0dcn9Y~ܶۜqW,;=Myva |'V_ C#Jp _hhƳz&Q;ʯΠb Kj4`D<l^®
^(S?Y
, .pDZZKT[d5TdYX G!aŊ<:r96AHI4X0uE1:ǝ]s35WnoL,O$ 5["H⥐H$bp5Y)N)O5"y< n&]$ oC3KY {$-wf:)L:BW\Ώ~ Nb KT8PTx">=)j-V& E
"B)D?H]g~A7hr$1x Њڢ<F|']tgSBYƊKi1 qPjS>DN#'443lgxj`x-@WpQfȃg4i_ 2gNQ:;wxozӡܖC`Qe~x
y}<V~aC)vR~rOOr;wxFYo)+jѣfEL>+=`իxWos(òZ5#ܱnP`v:+ҝ}-\U
7I⯨_bD/އ!MM6eM]*ӹʯ:)ᅰ.0¶{
:UV#ڲZ]H!nQCDb|۶heDB
_`1ݸf!ؽ@ruSoj=<"/ CuksF'/1?U:EEo&܏HdjGl3p |ּÖG[eɁ G踫#ھNd+Eby|
UTA%pI@@咦01T{X
[NZ:,PX}0LCÕA8!7Db%s}6Ї-5֝sSD[QRd47D=\v&@܆%Xu6YJzvxVq,QehK)>[ u&4
/aO{i=^x0GkZ{Ũ ,XptĽJ&LBN^I? mc]): FftRٝ~V-u1i@,Ѯ7bGEPT4#Iǟd̷
m~-lnƯj:tL Eߠ0+ G

8L]xVPwD}-i,ghbNj #Mp: 6raSw3;Ȼ7qyKrY' 28lJ_Z.S\s<a!EDwAȳ+X
6$Vbe6n@~2 :eKhr2ϖϸ.r|A*$sf~TD& />> m0v-nGg
l^u@vRf
3*.ԿcoHB OGrd0[5d4d
B ,TW>?Nl@c87U&@bZZ܃貶Oב+E,ơ&el$؉Ev. J@t8=7[\0o>^:!6"R&8}<%|6g]Qep`(}#PVVf?<Ͽy{w̴_b<PGu<
[{oe&<֑`.
Ljy̸s=z_FwVfE9AWOUɎ+
4cˢL[Q`>$̧"[㟙#JDf|3-ڝ!dja?EXq#5%fѓ3Rq ,| GLۊ䗲qZGSD{Ed3Z_XObzBLLcuXG5>[:1TSc=hi#ʝPTx;Ɨ/6j3-\Gׅ@̙=ӌ;i{_*aH&5%OZf396Q+kw3&($;[Va2>^k})ܺױglMW;}(q1~娤T&`,nAHp-8Tbee83DIK<z"߯i{ݻ-㤌THA\M8|6Ŕ_| F&vTx??C'QI GɳEN}746;OAT
f[BݍT Vr]Iާcw̐{6~ҋGXŠO(,y
*&nd=H x2]'#F`\T]ȀrQyB)qn,܍eH</ѴtlP]P9l޵IpP5&YBVO7|q3r_M ^}RBq)ul8 4ALovu
t},R\ID >UZ3o8bGgwdh
=}P03dVdMfԪ*՜a.V_
ۨKH抑:}݅Oe2]~xkt2UHgqԽے@q0>vH:8 * Y 5UjJJ,nt/p
y}pu#})崊 ܢųq`ZLOolaBozOȻ«eqakϢwҸ1ȧ/M +
H*v" EZڠeZ<'' E;
)gyvo_>.#gGXEOUKAӒYT]MP1r+{Y/uIx dl7$ dߪ*,7#V25reU@Z׆/}qe 9oMo|싛xÂ=hy E=ZI?;"{E8JasqW*}evWa0 ?}>U"d6mAz
}E/&&~_ܻPmw21\Bo5^`KdM yĈIԄLYk v?cdžGiiXdk L7  E3%öBl>m;H}PHJqv=mtU nB8RCw|E~>zm"0,nֹ\= PI\gER
]ϵ1~kRqh&{8;GCC 6Bҭ43Ft8(2/97(Mlbљ,Z
͓aKK;!n(?FEx8:7WW6yK`6|mM
8*D3[/9T`+$/3fX5o-?ipόmzz̃y1b*Tݵ%ACPVguρU==?,-aK{ ݯw 2-MorAYE̚NQh{EMS [L۫Y'cg?%H(X%e>E#/
ø|[y
8<q5tS䉁YKE/avp1x\a٧3؞$ 6jm(e}Clw`S+ql^wZ;ҁI}ֺoSnbv s7%fZLzLZ u.$Cu/}0x?} ;.FF<ֆmWa)PL\cxpuFE+ZѼ_gm+umG:n+%IH|hdNBZ|ET\!P| u"&<ǵ7xg)%z$MRA)sd޽ůP8GrԘuqTH|pD<)=pl3Gk1,k|9
$+ &WٟW|Yq3U͆hd 8.8/ّH$%⮸WVBg*N!=ͷyFS 3Vm>;85<vL⨷{! l~T)aoyp]۰tAʜ-3XGQ6vL U q1S\sHT[oQBԍ%sqzL?ҸOO5t6 !Z~C(elhNT$#X>+l7Ʌ2ѱKkL$^VL9]3 uP[lpAYm\%`OheYlwqJ 8o[džIY l9kt~H5Cb7A:*.~Neq"z/G׾KDvB)p0;kq| >o^:Kۻ̚r oQ#~RpɣQXrA9];E*bZ|
g`A jvד7Qt>
4+iz5iC i>9l fRoL]OtT{K`/J`SZFΐv.d;B1mި尹i/ݝւ.f1PyҶMQ@k0CiQW@qVE۠Ju03c5N]TT{+2<%/G`KXWU1Y0Qr_5Op`X&Cؽ&ϔtkgl"
kşܽts1gΗV<I
Y| %XVWޖ<tІ +SLW #Bj߁ywp$ trZdtd4.Q]tJK~5Pr`/?AxJE[GN]huo,˯ "~)g Cz?KM C@= ]V7P9h! ,Kp Gw+A)~JUٸ:j>E\ydt}07R| AUu]; ϶[W3d"j|`;im $9>
}If.1O߽JH qŝ~?̦eMk鐢RJV $Z@NBвh?(ʂ;V^HwzwP(1 ~W͞_4B>zadyFF~RFWAG셳$ª;)Y&Z8%/ LD,gşUP(O? LNӘ ^"!3/MD톡}qaZ((oV@'
?# F܋9OҾAd@ݜ`)ʁlJٲd4Uy]z})2./MH>] ̱e
<t3G8,!AГGJ/=ydEm%r3- ];т
) ď?4iA-%]l;.veg3vk*6vDXs%J$U^36 H]z/FrRyr
:ߑing$j?/U99Ï'XWL4bp
F/S3eE׾SEMSi?,u1{"lsp hwVT6D|/|omU倓UaJ#48M6 ${iZ؜O# ?)㐆y7[$"ï04gAFphzA [4ퟎUP=7]{ӸCeZ
RQvsyflyGYegޑF<XBhJ˥Euy3!   PbdB $:滤3?%6|l G<y˕8YiJ}Y
#M,\]4\{='-PH=_b5֭ h)9kr# +D`YqgSF('3V"2yɴh׀Gل,PRY‹>iwmrB,s^\ܙ˿dA,O V?~&;}-rfp<dGMcJw5=${*{<2[Ťi[n߬0Xr-$a_3o%NTMC<
B=t0AM
u[Z
P J˃0[(&Gp
ml3~'~QvD]z\G+}h-!RH{A<qb;&aV
tV߈0N5zCZJws)e
t.y@S*bԀaVGeYGuM^Y46s w
di #
Db`?d_`lX2p&1K'ZE6#R<v7`vMD<M#$+]bXN$vYmuj 0̰x`#Ws3kVU˔G0Ta/A$ \LGk捊j+*IR"8
@bRḡHW?!StD;Z2_eN\K$M.ksVC)}gkP;r6~(qqg9NΪf!>_XbLiV:NF fqO_G"AXLOن<
<cDQP, ʧ)ml%3S׃wɱib1@ੌMƀðlR;ټ_t &hbͦ*m/HjiZpt81b9b^o qԘ><˱"i6Ix~p( Ȼ#0h:a\oB\Zs:m9/$ٿ 2>!juGt9|ǛϠkN}CQEj _[!VrjF?ѰIҼ=Eg
^dnb }?V-Υy Wͨϓp: C(,P'Ep"1Pâ
*̕$  }8FBv^vPAa4|W/
as`=.("4 f- f\w輸#.2O'oYif+Z&s;6$z2TN IAc$*7v 2H'þi<Q@L 3M - !74]
:{KKn:OSY|[Qw1jz+U'F^#ܧ흨S0=s嘣HdQ2
l LxG/g{ݮu;]-u C7&5b^Aj}f +ݻ3K:6搚<D}`X/ @,1 Ovqzt݂P"n7_sf1sm3UKwa,5 skӣܮɪCX)b-C7]| cA)npPhiEC߫UN..ge /g=]I@`MDў[J~Gy5>B,6yGژo܊460h0^[xuB8tVާ9a YmoYÁ^$2~ar϶q
=1xúqT;ٺ;Gr;E;7" O2iEmaDVjAd.|,LAR\b+ySxd)N{<x~s"WbWUñGs1HzaP7>jڞ\3[P%o=#G{qM['EA7Wy`.NCٍ[<
#_rO p JG
y@`W܃uy56,/kyII䯿E?Yn|<#PnHU,;q }MM .إ,ec]s}=.hf9:F#{rO|7H)Ugj-kč;f(2
A.tiE-@en Pꤽ f X'TOX&8+5<J .dFuX weV8?bһfF#(B[ !8D/$@ߑeL>:!% *i q. hϜ & tQ*Sw`HU8N1Grї*
檪"7
۠0hojR4 ɄYʂ90M`,ʍq.wpD48͞U݊{҉prI~%'7Lg`^Km.>{8Ր779F04{X
'[9VBt%ѿ?z,!xŧaV\tΚ š}-Vn),w&\:^LcY<5Bk1:SJzVXE,1_ڣOZ%$ΒtojJ%2kg5..ى+Xxekfdó#c{9635s؎DĀ)%rDy(َp_~_]0F R[ol09v١2]¡2oM 0:VaJ7ܹ)#x7G IKK[(^S=ey}/)s+K "Y܉4l0XYPfX
I]',!0H0%1:s&/Px!HhFfߥa5A5VgOoQc"RT,D`+A`lJ rwp5`uQܬŐIDmusڴO+F22 h]n\¶8u5Qwcx?7_4׮5Cks۹cl 5

gÂxHbpdux˿!ӛu 0K׻nSґ]\vـ
1O5w™m fE*>}/'ڱ?NJ&SɁ}v,zCh#%:#3:B#೶g*IñXly}ӪSa7i 2Uc⁌+~]M)Bhٺn@cJ@kID.k?yn``LN.5+RS
2kV3h,ܢ'-?T4K}Oˡ<lxLr6&gEa
{,Xmu +0p%8sg.ufya&8 ?vD);m瀍1,8Ȱ2)Mv?4T 6=Ϋ_oZ~DH6ΤIDR3 K|Hl
~xvVHs8kTܖiٖ* |1XuAvk|U yuļu]@6v*\DYӔtKHJ+5WN aTLe7{xPxQ3~'=* D-|$0HP7/,ob
f!Q֦Z[8-t]LHhKm Uɔc)pM춖l4,};!2gBYKvkZ^Ub *Ra:_!k0q5`Mg
k?E.BXg؝ $rѣ c~֑:)ѷNCu>&MnC"Z
e8hBLuNck性_
W<-&@S#] U-O"&q"l|Oj0߬˒_]K8N#y$s,AYI*r@m`
-cdњ [ (i8p.\QlK7'x [=5kh(x(V !%' 0L)JGa5"k>tHK Zl-zr'=18: <VX7?bw܈Ej `s~Rw@M{F y˹gH#>^dbѰ3˯xe)`w҅!(pɟquϰBǫ+3ԕqt7ۆ,CbpN:W? %yXcފ"ٝ64rIwBfV
!;$ Ήsy]PP&@،qA !\ω7"2$?lZxy2T>7e 4/W}r)
ێx̂,?BlSj'Ucy=h\XIޑJF
gpUUR+5P*![!)}?/Yl|9kh{wJӸ o_1c\|v |Wt)p>5F6`{DF$bUw@Rg`[g>ӽLl1JQq)U)`(]qqf 1V"6щ.xl=HPAV<9l>feCRDhn{Cd֦Yߎp
Zn߷J54q9ŗчQ扊1m8,_Xla;le$A>fH)Kwj<aaК1Q 72تE;~TnB76*FlCc'αŤbLIU,o
+|/آ;`˖:x&1 9Y[w/]u@ 1p,b+v&:0b Xx͵{{ I/L?;-)7bYȽ-`jQu7?gP 'Z?#zT [_JT6d+//i<GjPy۸sl#TF?%gADÖ6
t3fO9$$_H,~a ȏ_8|51pK/WVq9 aV퇈ÎK}\;qx;pޒjzJϯp6a-h{rPJlO(XXܙs̱bsZ{)@oŐ+@TpKA{&64:aB ,誓-y{K6KmrxCbxLQ)ߪ8p`7~O_ ?݀wt4T"bQR=}aYAK^3!<1}GiTZx5qE2-,+ʥkCmMek/]6Z-,,AEw|7W]EJ6ZR)m1dh=MS?Cp7^{"'3I◓ewaN
,ngr5^qɚ*@2إ8rfJ<N.
5$3` }
h>7h x~n9?[ycLg4wT@C5_QQv4*,^y|Fh噀>$]` Jzy+4J4+rNf> qc}J ʴ2]a 0q+Vţ6<fBYZ>1Hx1\J>|bd1!r髕DX^]%;$ ~◤#i
4Kwח?1<XɉL
%u@(,яn*1Msu)ZVW#A1Vcul\QF2y92+ T+Gm_ި{\9<؜8Gh-n䚙֗36].?]1
Pvw6"oYP#-a$7cqV
D/^dx\ZY⽧Pf#"{Q am!ގ^ l+M0Q- GOj0pA 0'= ~xtEýlLk
dѦ }`$b ggtZ\e+>
kO\}c pRfHiB>g!4ĤQe1
a]B"9}f|n\sH-lMhd>&XnBP/ N `5XeHJ(he FAVf:z2O'f[z;A\S*r1?gJ`'Qy㯭ߝ+?GEԁ.:|옎&u,|YՅ+Kq مmM"YsQz^5c%SƜ/ޒ*6w}!beJÜAjQ[5
2|JTL#'g
mؘ@pj,BE2GZBI*JmTK\{4L Wv 8vLW"87a:͚3./Z m%tQ
jA<c05Y?΀#0ʮAU_H(4FAyA{N(ظVHr' 6%˯Q 8X K(d"o~%ൽ^ӄy픦oفe{^ePuE5LDþz̙k77SWJ-IIn;i42h9Otcle #y<a)o|l;^Cí bJC+sW?Πl?cF.21['ۓ1=K̀vҿztI֞ch:
W dBAB(:q/*e-L>@CЪ~M?6lq-cٙL3A𨇈@ۀs$.Kuh¥Dm0ﮋ"UeN^y܉Ԛs3?ɓ_i(so~ɓ/D0MXG#IJD_nv.+ڲn}Q e$佮◗G>{"`
K)O8b+闃oZŌAZXaY?9E/i}ml[-au;ˮK3yrD&j_zusH6C^,F)]PSM, j.5j6Ь]Fg)~gh<?K)DТZYŷ;@3*B,>פΓRxߛHT(<[wY oBFs184"Ecco2HػЃXhMe?k&kH¢->38&E%8? QD&ZD/\R^HENc]1} 19?f=|aCHft<"a s_vqYUGfT˄MB2U1 "J:[0bKA ܹCB^%vy/ρx
sK111im&z8 -}j{Jh Mt]EKA;L+%@Ie}{uapMsv;-oO羺*Vb'!+m=mi2H9'Ċ/xA^,G/F8#[tf`
< ȕ,'6Ae_(`>[.Hxvд; /u6K'k{x)w|ݕHdI;/9:r}[MBeE'45d<;RLM!?8rϨ/UI|@]=s p/Tbaf'~=ma*yPTRXǥ&$Zs$ZL2@½|Qģ a41~;9[[qa 3<=$^0~
/Я0l+3d܂Pn6㝩ϓj҃-“[JzEjS#
:vz%I]ۉ> =~W(NU|ՙ.]%α@䉖,jVπ'^Gݻ݆0gtix*BH읽i1kKq˖5X^~n E?|sB-
ک;qO.aFFQ+}hJc_#~w=.,є M6b UK?zFjAw"=rA}Vф4s'hZ8
R-lc 1K>~(FӸ p3 N -7+i鹗cM7- 6UxdpFlvr1m[sfx
vdWO# 0V.ᅤ)P4}Wx_( s⎷y9g Ֆ ]qR[oG2y9c/X(>sa\!=eUͳCl^0UR7K_Q._O\>ɳYi->?CnF^ )J|D
lN}M{ߎ%O g;/LD̽ V\)rq S{ӻ>~ر>JQ3gU-tυ #&l4ؙ|Sѭ#:7dkz11`bf#d߸<'$<UʰǢxZxʼD;+PX,
/J,)[ r*ܴ?ZrdBMq-wD!ݣ5Po9x0gA?n&Fκ ;,
u`7iiy]h Tڰqp,~!m*@ftq2WN鬒?2.f8Hz64!y>Ӟk~
n~Y͠d%RFBܮ ۯ菪)
=3u_9r4~,Y ̺薼
d<y R}W΀J" &*niijK+5QZ3z|U"ő8رuA Zj+;j8qLJqFvbL CdrI c^=!v]O,|}5,op_L^Z UsA04|G5"'b]tAH: #gftފ'2Yuu9Plsl` IeVb;cNM]hAxoh ۳3>K\2ZK<H[i16fv՞]7L@gp'jJrf]`Bibs}Ȼv|ac3TRu:P r٘`[dTGtwaQ~?+~$;X&e)]>\.ۣJe'Ut7,g襨ZB=}0FqdR=r wE%qnqqNi;0={٭v+%82:{& rQ"Mbǡ'>%ܫ}'w<Uwgu(7V96x>,$Q7UN!^r.C)U\oNiAՏ
cfax l3>4ea*aOFRBTjN\q|Yەi:z|m7Hl
K.;g?-V'Y*^~n82ZW%\䃃FȡYԬu ms6;xR-V'V)Bk]R4ԫۚjC!j߈_VSt 0Нe >$3ŤiĜ㎾;ە0byjk\Wݙ&>
*
@3̙ Q @[@nqx1umԀ.8~<T2܆cO 
HP?3
2NzDȽOwIpPZe/@)\WS+ ~K |n6kܵ \ӧN=G5BJ-p*OPQhS,"&p" MMHFoR8yVdjk]&$X=tQK .'jc(-^4oa]$Gۊs3XO[\э%eČJ#%]nhQ_]p
wLUxt3I 5rb"AUr}@0:%BvU]eQ\I"s3sca%`Hu_p
炮$7k[G PAඉ z0Ql( ,8ڎ<;V
ILE†3G,edˡuյŀTYSYBN~wǻlj[UOj2ɫ/v?h Ũȭ<ҝыyJIXȣە8=H6XB}RZb@W_)LeS"E6#Y=2b}.mvjkr%ĮS3B24"1taza MqJJXNʘp,U_ŧb 4 &<%먉
%^ԇ>RieOvfP&*G^jIN>"|/(X jҚLPR,X/?Q0+aL g #:t>_:M >t"K~1 k)gmq`c zR){/2pEWyH1*Cx]>"뵭X;6*j-8ʄM~jj5jź%^^V$7M|8tsR y@Z9kʯA<8O/* ]Uki7>*I__0
Zn=z7H~12Js&X;jUjQd20I (cn(ōx>wŌH"aCxVK]BU#E0z)򁙘E#S4v{6|ʋǠ>F w{-  Gʆ#SW*b$=@rrt6.v3h5]Yr f.L7匟FH} wYˁ һGJR o;+E;Esz,4%8nO
K %}\$<#ퟫΒV! Lehx3j Pa'/aK"+FNܝ"<k")dhz->l t܅?TcWǓK5֞dNbd%"]*vjLc83I[7^#@xsp:IrXv׮u֐l+5IHnkD.CZ L/p9-b:
whNg
f͕V6˘W;L9y'L~\W}=c@_ՅFŒ%Q__Ů&e?q…is+<fUI7yvaKR?Yggp*wnp N@Б-Hh%Sb1MA1 a4T@Sǭ;w
'+p;DEKqCrMP/|%6{ -ܙCBdZC^Ex
>(
.8dQ fnS ]h`3LX'
b1N\&87կ+v4; 8fI^v/rb\*E1jgjRߞG@?c:,! YɆZu&ujiI^#MM=P) Ԣ'mg. ܞyyΛIk̯P
!]q`xO\'HNffϹ ndyk%$[ܐk)rzM<aM=d*A AK$4% '681]:>uEx?=X%hY F_`]
Zi OXW ʺ 8Ѓ89 hSVbPgInW0j1/oP+IVZeM
+5T2woѵ1RoڑXRTc0 uNtmB7lTKJglQ=@GΔQ!Wlݒ7>/bp\0?a
> rXH KF.L/>mZi.%yrBfkRzf]
JiaLa\]5#%yy V&=nƂq
de_~cF(=$x˕MV$tK1>τKWQQϞI*-VO
"-B뻔dѴ8>O]N*pna*9ߖE %J&lڦ'5mOVv!Ytk Zbpgynd0уLzBܾZo7Rqe2Nn8aQ+(1#
қ
::>&gY DKO\T:?BXd&6WEe
>!.cd(
#z-A{TBm\C;SPgk)Q01 ju2F6
Ybr1@`]'" gּGT:=V빗WZ٭z=7!f.l{' ):DŽ(و<U\Mw;
: USlxq(lismjZf*6j{ھHh#[P/Ϭy5'ɥ2Í@ֆ4]>XojvbvK4 <YI܂{^/}OVaRqӵXwuA{?N%Y_M
{FA\8S Z}ъ/s(bgeiTα!BS`K3~$ϊ%)"Li&@im@ՇoO?%{7GʺS>a:f
LxhDAzMnfT踌qL
{9wd-'T;nh V>Wҟ0C@!ٍ(_kP
tPjRUʍ/0:Q/zۊ\+מt qj[\quCMYX,..T;AȢ0Krbs?!HJd<;"X|XX,=-!P]=G4Wi{@R==WށIyb$vcIZ ԇi0*|bj4d"|ꇊGeyS|PruF|iPK볕;H]~]<LKN#s8i( ?.<^Ւ1@
?-~Vu9gG(Q=ѐFe
ND}M,Q7{I C*Y>TiH 1Vy7y4z;mfp)$V !$jAdFn/:Qy=9\B'E6P͹";?L˂sRnG^L?m^?'Atqё|L󫞐-ZNBtUٯ{8w *Ѫ*%ON[1@/fV/t$h Ov1, UEh&o1r 9Nx#
rĒ= ׉bMVS_+r"m앻YEGAzٮO>y;b <D <hi[ڵDH;Uw'[N"
tL(Y
-oØ$S=ZEVq"@ 4W(ޗ(t2OWr刯7α^.KHo
LiM;T3 `OQ? /aJuٞJ%SVm5@$
ŻA8g%J%RV9xmi +?&hZq2ߩlM]ui&` 4(NЫ礣 ~fb5ƇeeIt] {nl|36Nt
9JiBA|-ڳ.8traSSo8 F8?U$Hd+uoĘ(@hn1o9t`|"am<G4 ok,zcw]#͂mKPWCfaFZ*~&: =X<WƖ:&:QS [
*8vi"vl<'eaoR)+
H|whQ GFk7m[0T֮(|c$U2o42
״඀bfO31ح/ߕ{Bb\'TM5^.Ǵwc 6+n6tS3O;Oj&^lVINRl!ԒPLY*۳d~5"b5*(tMƨ 4טSˤ'.&+>ΤrORޕ~6~"iZe~M

\}&q[P?`OfY%0ꂥFy##,WI>jI47oW`͋4}bwМA]x?{b]VLq
oт&3g75fxQ)4/YHP)zb,&DQMmx4``t8?ACh?!b ɳ\а9's]Qg=$.<x*+T >)2&LEId=+ߚ
܍Klt
>$9:D# D4 V`"k<g== 7Hx>}3R
Ik̑.!#RylrWdreQ+ R6:jJ76Ya!U E3*hP/̳|轗3#6ЃJ]s^g\$XAY)OwRK:7<20G… /򊗄xPN{mdsW6XUV*#ŝM$Eg!:Fړ3 eZ5(O(flhyjt9p93+@F 6
`
7`>4l8:4+OٌVRv߬ޢX13EӢ.˜$qkIPhիu*E`$\
bZXVju}_m):,X礱<Bl& ?= - o;:)6hBώJ5=*eC-
uOA-L.9_vS2\.hQX+SkcrI2D.
½ݸu77.]Fݐ)f~ͼj2+PKa$+9l4Us]6}9pd{}ajpq?[Gќt(0HVf^+&#4 tNzqyU5g2 Q+@9=>iK`اL~oh <mu
n֥6d)>!>T~i{SIl[Qgel@/
D[EXŮ^8d֨2 [eX;PmjD# VfН(]_T# CE`HL|%Twmx*%IE jRt$1t"Ϣ{`G>+c
pFtfZP P Mi~ epaRG
[M&~e^@ N|sKbјEc'kCZ"]9A.uְeyt{c$1*2&q8rT~8Od#9d
ُT)5̗f/kjot\kL<AX^+ẅ́-x7(lk6oZl^S vZ"qu*l+T+YZK*}u~Av8 d1j&:v>Rrm&yQXq/>8WP;mP2y4G5~SKd55[)ӜlS tL w&3$=!p zw7e_IDM_`#C :<ĸc+'_̎؉hbMEI*JCFKr"/A٫m.h|EYst@-
oPߡmWђ"
U[U23X Dm
ۅ&$9P'Eĵl
{Adzd2/Ve;vN`[|ejVF/]t̉<!!`/pGJYBֻs u( $cM{fe |H7Z_q˔
GCK ڑ ދ|pmD G5<_4 ~JQ;j\#pŖ.n9>(픰LQQl1*I99$7KP)vy/a8}DX~ZrQT;EdF(>L 86M#@q<C
U;RpD]7#X P 7xN0#j7a Jk1y¹)‘wա"[uED=
Y^F 1R*Oq:Fvu_}1-yfDglIBX=/,
F< UrMA;ՋS/Y4[YʀT2+apͨ"ټAYYX y?z%?[1ӗo6߃Ƞ4#n<D[+}Ԫu͘kigk)a9c>겶.
{PI{lHуQpqamotM`s 0#14;n6BVf ?u/Dq/U3WJR#3x*cGC^6- WuA{ jTS9PjV^+P)ʄtgwk x7\zU0ur h3є]<ϫzi w^РS|fZϬL 7\U:)>J77,_@w}cH%Miil
FSnզyZ%gjj^?81A1ӢCaI|,L>OWLeGiۻPz5"}W9":1=YLC&Ȅ31x([4@
&\yү϶(DUڑ K<ٽ}]EpJxn^βYF 9qP^qsVQ̯ܰhE_tp{g}s,XtdI4F_q#HZe >ލ'M<כV$j.RkeZj7@ÑBq F PM0P6؄q7eˬpEsÁekI.ߨe B#BmЅH7
U Fc)5Y'P
\ <`P31Z0c Z>K#" q8_}gSD.N\bGYwDbT jrt.nuqR}(&TuԏVWAr 3ot9fc_ }Ńqo#|
zPlYn4>gdY')l!˒%#<1x־_5@4 @&DSe0nHo~{ls`ZH[>'r
l9 A9tk=0UYD`jZY~(ZfL؄^;ouc_d5&B"x(U
"kJw9"523@\`GUM^5awp^bϷ(hATy
vh⮴?kCfAU. 
y~pp7x 8hՈ6ZmpgԊ4#@aKvs4,_md5dP&QpYC1ƷˍVC/z[(qq&c ̨_ǽ \v $SHwpy 0 !HyFW`#dea>19s+vrNqy#%gxƹ "Y@^"NE(lCg8G('K'9Ԉ/jV1B:g.tmgIJWobG8kb9zz@ 9N2 2~Aƒᰟ%k8h;>L4#% [5Ҭ]˱߼8֡Ř)nmyܥ ݐbl4եiĸ>sjM
̄'6͘};v$\t#U 4ٯHqbrj#ݮ\P}Xoirp'"SSqJL b
k4 ][_g4o~ak'4L1ԭeKZX tA*HXS$ aawo[f2+ɦ'@1k8'=bsjT
qC
#<twTL-<1:($=sͦTwI Dq w˓p>𩖕P68Wl>NX?7F&_#dA*?'S?:~V
v(;+1eP 6DM-"1Ҕ1axô$
J@UӍlTfuQŝ$fz<>nqX˱\|/Fv=Nf~qk *2#8a•4ܴRd5mn4w|dIB;i]ߎ}7II+4)l(HSA~-JncOF|i?#d|dvt$:Z+r-͇n.y~BNN- ߰=f,EJi6o e L܊=MC[[G]%SGP?fjZ{x@cJY5`]~j 2<ٔ1b|-]$VP^LBUw7ތ>Bk8
xlpVQpV#=ҵi_Y.G3
ݚM؅^CPLq7֜U1 ~u:=0SYEC AL$MH ?sc4}9u|vIh"g|*@€Irc%5zE0#:hsE14ݜLD!Ŝd/+v[}j[.J@x/؉AgZtC+1geFMs,I9o f'uF*>Wlu!:j:
yX)
ӠrXK;@BK氏{
5Txp">)R=c;4}s4:) d0`(ܛ0lQIdTeTP{B49_{ T$
/}}a;QeBԶhyRrw7 H2x{ڥQ9Ĝ'CꝐ(GrxC6xɘ-H28 0-/u?\0A՘_>-c'әPoiĴ=~7a> SHY_b5Kl^B:djcEh&`]6:-[6mފ~_vsZמ;D39 kJK#S1%=Cj0+DF\z.ܲ7jJ06ǡsǏ`-Ur {3=%RNF/}'ҜwDJ*OOwX~$3
)Pugm]7U&NInv4\iULdc-Q]MB2 /^-T(l\"߁,/+e, O4z Hں-z)]M=yEIhRwT+]iFX?8"Ұ1 !guGЋ qwo˲rJb^]g. RSI-JcSqf~^6 8y*{wO nuڢ.9 ፲KYK#?lVrNl=8sSDiE ldTsH~bl3ҕaϒKr]3U<sUbuikaNxeP|)'j'暖A9j@lmr6PICϴҴ=ƍ
vp 4۰*2S"_w%^폪/"WF앹4q^#/ w#ڜ,NI3
ߟ Ӆ^TITSl^]qDNj8,+`kvAB@n!f}8/Ÿ31qNܡ}0(vpb'DŽ*qڋaN)\#5QjT>фM/ @Tn 
x| > ׏A\?/ 8[QۊD~wx U4|+M #
y,c20iF<Lu1: Jt) `=u22zKi"bgZAȶۓ~dkU揲MtZ5%89Ȼj12?KXcr *Rh7]!xEB#9i|@|N5|[oGD @]-J?2%*ӄ~Ҽ$㈴DW-Fa(U _( tjY` 5H$&5[Ej D'N1γLF3Ȋ3w#E^T Ne
#4(wV^2ݔN
1!*}"On3lpEjDaԾIsVb3S`T0=A4I`)#(o#b"h" gM\lűwa>Z/[+i/~D\#]{{NWBM
Q]1pEIjEpLC*j/#ڤQ! )͍i,LJ( g+mpuOt.t:^\µNie`z
H#d,1˽
) B׾K"z;VMmL';b \d%_zw|/࣮(?ǫźVxz'I:xZz,4hZzeJwC޴wQaDv*)
M
TNv ^*Mp<a{ CkRjWư5
Ĉ "j ''BڭfcŽhI`o]/et*}V)X.!Yu>{ .Hg_
:!i0>p1d?u[}
pRzۇC c!2n#Y-S!syUY(*fYCP@(C th\3ǿ)uNұf0H5t 4pG9hZNi nZ
H]d>'*}Kތ]ĐQD):\Jo0cWR7WИ7ڟ•UZ<B 9?ߋ#A2D} aOEW_DMG#3˻>z]Ѣh6о ٌK-eK}d ;ѷuSX} < 6l4s蛃o.ڴzKklvvVOE~H-C
($%aVᅕm5'
m7]%$WoN[b5=u>@,4k!5Lezf{^̄4x)&9~i0#lEc/|$qC!jVu}U͒eí;wKٔF6ۼr<<S }diaQ^hܚt|u]Py2ą Ky!h-5!$-4\vYJʙ% +w\alpwuCjEP8Mu03z-\U]X@yF JFA'O &
Zᨗ
|lolD*)7syuLz'>]H64Ĉ n)6}C~4rƘt ~zup;I]dOPAZ(ٰ7GxiE秒Z+gM44BZ(*= OCYl3efũ$Y F@S[A $7YW$6iq(Ċj{j &jIϾ-==g7@!:ͷ*qli
?#׸Ai4>‡
gLʬIȵ) ^ ue9Շa#"'pHN+=%)No]4tAFX}F;gFsmAi1ӁU`߭:־ e˵$ۊB-]4~}< ɂd_j@MU!T |9kuE (&vaUj.eG}ӈ$
=DW<jJY2䫺97<8;VlzK `N778l"1w~BVfl/tB2 KQl_8g2$HĿ^|A9l@ڋiBU}
&YhBx`X7VA]/J@)TvXO4d8+oQ$/^P7Eta7)ߞXѢ/Ă(A xcB׾HqK$6t"2F!1(IiM_|n;4 Bā7U B(ߨYz;rDz =4(AFl QEZaYqw崈9Bq>6d,dTs^'95P)O\ l-o`/zT( 9N^be3{r6Bo m0I.9)9-_эl  %f~#1B3TSl<qߗݼ 5 -LQ>]o%;L5Qߣ _BCfOmdpItȥN4^a<2-Bl%rՅKzKfMowDjBIvobsqt)-$\g9=tz鼎(q<Q>DTyR{$o8+T.tЎ"RNI!
&|{r$Ա7bj (>_mC•Տ h}L0fPg:s~J)ZF4R.f.bYa!fK;s[v#l6*)x5^plHOaR8|oI(!I]>oi@x {
:pVf>3V>?;C6g~<q[ҁRkn[@Wrt
ڈc <ܴ:F$T-wh+#^j$;f{>WrS
UK4s`
Vtx bM"wM~2dwQb''G#]!{'QʣC}L[.vl' wY`qS߆uUrrLx<3=TSxTA`Ofc
p)
#^$hhϹ~+U1OѣݭݎNq"d(4:)sZ]c u(lR`
`9#^!RcΪ ~|T`}CP1I-#EIS$GܺFL/E%a2GJ;E?&7dch^ːucF
RS}sp֡\ŝ1aZ9O+O jfG} >Sڑ? V޻yӉ1\
X/*Fٱզ%FS'{R!3ciqֹax;םVY$vQE7Jc]ݑ}-xeVzȑ?U |zL]^77 ki+ rk:e'+vpa{
i!hes9VikF?2;09`: Y/`!@x3K+M3'aލ<9{uuɵi*Ww袪$QK(}>
")!mJlIv]x
oaO ME=Z |v& rӠɅHl[u58غ1_&B|O a۵eKvҼU//2)W>tq=y\ŏGpr`r-D/Y 13["4q@?0tB 8#Pry
0s{Q7ʂjeGt`CӱYEgd@>(os a.&+9@D=mac93`.g8wu7Ep&|8tt~ 4GFu3?(9`yu4w [m 81 U yW`6r{Qs TpF
dYL,unY
HNDWC߲8~az)%9q?ALAۼ=
`-VQA"sVA׋''ѳL.$UP2"^d;n248bd) ɀ PH䈞&@w
e<Tnۃ\E8 3s{vbnD1ǝ7"[hoVqSVmvW#<{9*EV
꺧uHt5@kYLaRVHAgnѩ&koEui>߳}K(Al =32\VW5K,շ6 9ܠNM|v*?tlp<GHe0L{tYݦjR,ȢI/TC=CUY${< 0Wʇ#Be;MZ3NM:f=7tɈHkO>zp@µʘ*]nHiǡo3e
<Z?f9kIW¥ۘҪt+1F"
Χ[HcC$eZwPGbơ^S,D=(>^I⨫8{v C.+_Z>"8m@T81O*ʺJ)jnqNYSObI!ئE`h1N)
TOue}TaD &7cvDt(HJ Y3s@;D[ݶFG$Vh`)[vazMIU,]l˪65J<n!Gstt ȅFTVӝ93.q:+VA~miIy #e݄Hۄy|SQڂozӪ W&Ĭه:6s,<9&:Zjɵؑrf_v7e
vNIV'tLE+O[/n*9;x@E:\:'W0O+ew*GR|M Zh<K?N>V/%q>>tgT]Po:M6
= LGWȚJe^c)>um'PJ 9h"U)!0׷誻m.c?0@fKO|~2x8|m6ޮ" `b+qkU3`S5qk,Aj!SY0.L@s\9KC4:QHV
$FH8hٔ9
_AC qݪvpfIy|/hZ^CYܙeP&jK5)v=-Hm}_U;k,B+Gej)B$*; r^V`ΛpXLaYV9~Yʡd͋ydzZ'i rڊfI7q o.i {}HF2& 4\ɰ? qm!EW]-;
vKo)&wfHWV\d^o~OU2b]X7]e.ceoݤzH#%'oz>rroڃ ;8نM>q
yTPHy,Amuu%ЃDsQIjͭFػ}.;m^ ez M>'R|QnPה8K6mLYb (Iib$dR)F$)ݠT(Xm+
LVI)at~5FT- sIzj*>98L'uu@ W;Hj,+9y$l#>s }f`(flmi"Q0U$GH0;2$3 ΂/e1{s; %<({iG'M'B+!ILb3FSfmw0 F񗪜CF3.πRT|!D ƁWS<=W" A>7^f䗡L/qwӣ`-.v:IЉܼtl;fhx#'ȣTS;φ
PEb~e
E)r^Sqz<,hWJGݾ?D VՏ5Um<.XA*TpM6?6Fg3VO{ͶRE!7Z߈bq}lԹdRPᦩ|^rX
 כՐBSa mHϝOP4H
^RRyQ|s^0"uk> Wd_&
\I?OooԵiiyccny)A)oK& xڝ@[vS?g e%P"x+`$ޜ3I,K\RoMAl^ SCRBp.hFϓlR
b<agC$cŸ
HGNՌYPmgXߪPܷ{Tε >`*?VR ev6U"pT dGHpHhLT@FHhcY~l)AP[e$OgL> ;iQ9ƨtp.%z,z8 iyrjLs{Xd)ä)RF ZBGe`I|XǶxXJ :s-;(}lY÷< h(aAӁAҭ4XDS,N8MK~Z+ ^4G׷2g fZ VV哅A<sl-WE@cr- 7. xp~8h'7_J=hqmMw1~XϖxB.;1S\HDt[.8+y>
(uc1-WC11\Kz@S4vů!eZmⰄַLܮ6q 1F\qT
AL^&uqLnr!R} 
6y`'XEo `襤>o̫q8 %7;ϙz kjQ4
΄<(2XJ$x˺FsӖ#vܳB!6Epi&+=-Ii`SJe{Wߤ\.Uk %'R9Ny1 i԰.)X>Tbttg-iRuGJAJU7~3_Qۨ/[F3~g%
?x"M6 [F;V[4Zn&/*egV)cm.|Hga1I#Z4x=<H]S8s4n8%合R-C'UҰ۠Ω(u2NqӖy ʹP><8!0ƌk3azbKGM|mDvm7ȏ,`+FؕAV8J ߝptY [G!$|n֊>|{(=!iyߑU yk1ډ@p1 ,nN5[pTqsCF8|"nPA6or/_&<+W'PN5]/ynK [oh2 &ok`3S+/]F_~0Qв9:%
TdM_X4,G'7 Nd'g{8٢~ʍ.HPTO?4{̙[2}Y|ʿj!SEe7y
+p*Jz,:w,V=+Wx[Nxm쓧0O[x^o3JэM2VU#Q!xRMB| _7 gU&dHa*a-(" zx6Νަ
,}x#z2U3zͣrS'vN!lRΝX6߇I/( 6] $s ukZf3+Ri"tFo|Oxp`MC)3↏4 RcWO2{g{%*$àbc,q6CdIZ9;QR\npMn)er94&<
KwѕĜ$S\^HP$ibpbCp ܍.|eohjmm" Por[q
0v$a'|ɾկA/
joy 5׉;[vט0Nx :\QTO.rMԛ2وRnE.h^ MWKF# U'
M5ӼΎ@^j
Q&|GI;SiѠ0ղvKyo:F#3#j#v fHxTahF&ٷRP0,i]w`%>
sE" @KJ[xbn[
TmAc{n0TWrc
/Ig-5̑v{:Sz9026>}!5Lv[؏ V!tg1maj4b)YX=t z#ItO8>[vڲ+>FZ{篝uX㵦t&$m6@$7N7OjI6g:cF\KX=Rjrke#;rFzR⨖EnᗊlRo"˗< *i [&K+#g8^]Ӗe2Zi(F_ 0`4o{-]h/C4MGARgֲK0O3]i԰/\).-9xԺD ٦
gertgi. ]=*K 'h䵱"5ɖ4!fb5R/ZSw,DB
N-J<K2@e}z8Z|5V)졇(F>0lr=w"K0h|:cR<
rߝqJ+#4D cwyt <,_yt!X"kr䗢=V+1C\Gp'jڙ_@SvqR'9
B
 #6"J^JdM3=C5<4TR[`EaϨˣH(lpS ֹO5.}!ss$@E_ 5r}/"MS@ ;xcl@_>Y&b!ܳH/a"~?Vojnr(F Ã}ya~<zHAPQ2ehZ #b4y' #xJFM2>"xZ;ėvݖ%&!Cm--F,zjxH3 w:%?eqw?zlx>e ;|5 %6],c3#~I?rCV[GCF
˯m~"jG: r֐{迦7mkIfy`N䳭
w
OxeYRx٪"}s5-`v銙/
9A
}Rvj4u|RL)-fp #7wT
V٩X{c!޷R!7Z
/pb5`΅1,/1Ʊ2gOV8ciӉM/^c5W*رM2Dq$V ( PB*=n)2sĆ"]wy1%/:dӘЉ`oMVsUj)ś뙪UP,Y%xY TA"tT#9THgH 'aJ@u-| u7G0<jW 饷lLFM҆Qź/m5%7Yw%Q(t(q )葃5!9B޻w™p+X^'A
CB
p'8 2 +x5MYqN}/exj mvǀAwmwN)?,7^)֨2podCqBw9@{1IK+\ZṒa$]`e+Z 5}ǤKHD8猚-NOD0u}Cx;Zymh'CH`
ތQ3)#N-ӇZd13=@>VoT;2nvLE+, Z~p!kS%Q VњJeSJoMKyɯ W=~.㑺v п#[iG43nOXA2+e1t;'<% e4t'~JI$S8I9j=zԋjLOVr\8n@Y[F
,1yb~)Ϲƪ7N-yh0<뗆C4"%#0?_ ǂtAB8,Y1%Z[6T["m<m:C}ӷbVoƣ<Q5j9Zr1tPVxqޱSNQ$/7.'ׂ\KPM芭CтJjqpQ%z-j) `>jD|~el=QKJACC:PBT`LbT7+,ΉH)]-CrX?Lf>m򷑥qO<J$s5x?]'cs
V' ANytԥpgp{R[
N6&ћ~p5r<Fny+" ]X; q:>Bb6n$}^OfZM pGxf-9PsPJVR ͕Lv˥GFQ{m|z4;R7Wi1QU֠%-ԒGO.?@iP3z:]CQeY1;eU~r.8|C/!P
ht{r'&0ZANfHMkcqlnV|*neFШnpJ6IP^<]Y
c"E>|}LڀZN3s[V3/<;zBU_ p63._3LhIgHJ*;U["lqqiԀiGOUBV7|tgF3w-D 6p$ɸRP+AU}jՆ _]ET)6Ih $fqX3kl,ZF9ŁԀ Q/_lT!
7V^YuqW 32 8AdW1>8+{ˮ`mrfu}L. K 8Mѕ`dpюڠht-'/Feq\
d]VC({A7JxGwE:7Ԕcs 'HIs~dHàDv)\Qjr`78 ;ޤ*~gˬ::) 0C;VkT[’<zGeo/nbj1H4i8bt^h}4LXJB JE* 5ofP"!@܋jT,h8 D:L c0´9 |*7>w<tabB%[C/_]Lh! Mؘy:/{*w>'h2oUX k?dAPi!A&B1l^z8]chsde34'`κ͌a\$شs@ؕMEb[sm$kwItyS>Ʉ:, 5sC`gZdCŎ)8/n25PMac!7?X [8sbzB

,*py-{ml^~<ҸDlס`ྙɅint/ _lxx96W`Dp

t.^XɞjK=wMN[Ģ.Hs{ã,БVW4GK07fuqN$Z&CQH>99HE4@O"oZsROf ҕ{t[;?'AĞ^czh'V3QonrBWScާiQ]4(׽ z#wtÒBjxHe
Oi?1Cވ:Eiu2ɷ@Ng݁ފቡ EEJ[+ܘH,Mx;,`Noy/n=,E1zI fh]Xp%JPV㦕AKոR cg&^89j0?Q+߬iẦ#"6f gl͏HE)=d8 xhr4@XKd懷{
|All!d<8|Q9;k:QD[. n1p=9A֫5=b94݃F|k#J~?9ͭ״l;\͛S0>*FՆ"YO;^X
(|
\XPp{7/fۃP$N/Cw;r~co׋B+#2I]a (SlAyCװ;l-X7!й܋IdxkeoزgPw~tx/fcWXfV 4E6Q
|-3Ff޺}}{E!*#_ppzRz; U+9MF}"ʿ`?A0CF|W`"oyLd?2 1+1%ݍhQSxw~z 5\hjλ!MS{,]M27u´ aCf_IHY6QAi9D}dQA.Acp٘_;j%ZYT!;_4ޙ^YqZj^>7ǂ^5um;6ޅo9vV(S@<3M6h3j\+?vO^2- jZ aۯZ*
DE<ŝRzRjZ?iP ]|PY&gGh~\!N#Yz*6"
|–\Ќjmeb$vܗo:gBʮ< C'ziM6>BED&1VEm_3yVcO`8rFOG0%Dg=SڞJ.JC6qAtWyP[F%o3^<RZ._I;v=Fd3Z3ޔ'!c,I72{]WV2q;K
$>JVT]3G9&YVwtg2>B.<'uM05 Sg{Ld1㱜H}}F7i8(
5$ s^<H
נt6cxҳJybK ^`*V:.uψ:4i#c~+{4z\qn!%~8:@졟ѸFk&9\v}
yA6 ? -,%Bhn_ĿWE/+5E|ʪݧgYa 6neWD8JuD_2{+jyp(;*]:JX2*\1w$ rWq_zaW5[@ob}. \xdk<#Nf-*ؖ<=TRBnP7i`V8{ؔ9b ֶNlgf!3 ~ܯ l{79E[>*LUp09 "׼9YH,\[&YCK`Lj6-B Mwɂn䂖!IMm8u28(~*H7}$(>́Ad/
p\s
6AQG./Sc- .?^Ӆxm*{,8uD6:DgYQwy&kPӎ;H*i^ؿxa 3h9Cd<;:"_mj !sak SJ`S"/}Sv66Ohw# GX'u$n۞?;Ӕw/\ z]H87g*k!lKZZ$|.Tf4|P2
S&1ZyKܵֈ<)LX܆xdk&n:q;xgu `-\TBaG;YzZӴ8e-]0v/i &?(`װϼMlYPn+n'g;! \f0CNӞfRGG@JqYdiv!
+ U)C"ETX2Sm]'V+
zKb$׭̔1W fnsY%v[MP3Ω]"BF_rQ>rΜ Iz#>`
GIoq[ B4JJ(<[;<oNIK&\ӱ?H<$ nv%܉\ = VM-gW sY;ZlV^9C
G owvɕ8
a.
밬glDEp!y
rm;^CxF+ġ]䰋'7?ߦ?|6XuO8W2F~`x
fYb{zzm6C^P{W=
HY5#;74سͱpDsyp W;cө
u,x%s{4BUb, s}:.LO>fqWX,0qŐ e b\ 3 0M@"NUDsd)se
I+MT]~ oIaZ͇Y6Z+)R2e 2 JًϬҬ686+]
t۔|[<,tdlŢ$"Jq#paRK8B&]|~y
)Daو\ 5X]b9[Vz'P
-%7
R#: ]\3/2
!8,IUm% Ĥ1 =nn<Ue
UlIsV^ʁ$y
.-4%'-_Ippl..ٴ26%%顉ՈJzWݩ“`
\6S[Kb7LYvs~l=ׁY)]'GƱ.WA+ s0z!r{&hcRp5j@PC_tq>(t MlmЉ0#(oATo?
DٷRZ
j׼BVX/Azr<L=.kD$pTPs!@XQ
k#yP%滋G\ǐ*[[3B7-`䛈8ÅXARS-5Kl=.
dt lq-ӥ 2-mPGyI![5S?|EZи ZT78p\4Ƅ)36)G#ڔWV:;;R,(e+֠D:w7,ayOPۑ,MDd|q=Myw ì92_m$kc-a,)J̸XGej%>A y8{m}> z<;'6bO4K"OANE:_(Z`[YJdkʃϱR@%?k5Zp9je7hfYXI
w`L4.[i$puǸOs2JY.7m0-+Ԋj0nYܝ!s&0vd0ڄ~,D'&=hpKK/+'R7nXf 1kDU}2
?a캩z!aX([L*h,W6uY?3
!O8O6p,Sʕzȕ[L2
6d^p5)e]""zNiX8݆\׽ r;H?<׻RD[|PZJ _ޖ ;!)؄э T Th:(DîuKԃ@nL&(`
(wv}.Mw9r,MiKS#ۿH6}9"%Q}<OdD$U+R7,Ӯ;/gxC؍wQfp0W,3ͅf̖} ~5E]† m]LR$h;neSZJAz}t,rx:S¿/Ԙҭ$/eC*3:A{c'dG? 0"^tI&Q 9Qزi4$-1QO%ۓ Vۓ}a$Lzgn v>ѕc
";hv݃1\(HO3˗bvW}:}++X#UC
bT/d+|Ev$F],.BsMh"Nl 6\76߷47_s-f$6C,G٩݉$f&3 X+%M!i;"<
sg}>qwL=anTqБ
8^cx>x|grch6䝗gU+'v61<9~j[]WXHx-mR2\vwEv_?Tie
bQ!)eP< &® 9S "a(F}4`*zѽ:))@_)q!ꄇ/#* jE6}=]ľn ھqpc~) idCX׶\4`GW
z1؏n:8q0CT 2Bk1+^|:AGRdxl^pF#o;IL`Z{qfج12(
d 9O_XY;
* sR:W_Jո~ 
P/JZ}en'La֩?,"odv5@0%FN{WX^hF"ECI@!}\}]?Mk͗#MwI =K D
<Y9GGQG&Q8 ^1|i=|'woKwz(ŠApU8=B ya%[T*Il!r{ͤƍ3^o4 @|z=^_
g, O8E<x=T35˒ȸtVٮ8 St)@ c72b"p[~ ̑8_)f/L>y)U [&]]Aq'`J5.t,&*B+UrPŷ2 p!D|'cE~_I۸j*.Lg)!m6T"CIGչ@thR ^%ZT cM'cU;)o |]fќ$8Aο75Rhu
1zRՙ}H*d7s%⿿󢳀Hl4X@Yk&jl x9J
B,rG<mYlbi*=~ϼpȐoN/ DZ'/ճpmkP``4}Pϧ~&{L>s \l9!c^*{\j's5+SD;3yP1Ͱ+b) ̽nd!7m~FpŻ!'2!;P Un,FGNUSm#/[c7EFUΤ
#* +(q]h [})T_M!ЎuF?
z OLj+"27Ym! FN<Dfy^Ax@򉃇n+R(P8^Cizt׸[+0r%4R~[t<X,niL"nƣ긏yOnݤe)5 ~0
\uZq.gBcn 6#&ut4.9|6X
LDswvT=v0@ĭ`lZظW&Ȇq-8\GYk[VJ*Hfikhm*nDryPq
]}RI_wLQa?8mTzFFy*Z-\: &s6bEW涊1ۮ->ZdQr~5)e?_dw¤Mi_qZytύ%A74M25Pk
_ #C

3:虩E% %P5]q+Gy]mO7~Of9;L۵ YE ۇMZ:/.`B7TdG+S* Q;{[%;j),bj$og 7"r-h*" {lg{P.<jiA]wkgs*G̃w0tvcuxd[DAMEve2xnOa m=J{N9 $,d9**KO>7œUq.$y#ŪdcU{UY'+悤Ɋ>6q8`\ sug Z_&WeȲA6NF'gd|؎/Tţ
32ٔu?䚂n>syLΗSSd?aZ*7HyQh?B x[rٽ>ң"d/?ڲ,V]B}?"z5rӲɇ
G
.,gEE@4no87f).ݔ(߇ H>õy@t#ϛ 8R+D8_Bǣ6~^bm]"/'-,O70~RqldEm3*)]9,\}UDAh:_[;T˾ ڳ 3oOؽV6XW iOEk,U~A )&/W-T^GvB [:|]=3~mVI\EPJ\kꖂ\\tAڌV%[)48ײ߫NdY"bϴ{Tw9ldWQ~爬iG-{r;)P3f0ƧXBs1uvׄ52CnjA[V
S]X С.kK..ŝPMyaD]!goUҞuuE~--@ƪG W MT"Cc>Xs8a'v(NG~[pZ ݺIW%HIy1dLz8kY}𝗛گg\/?u/8e/J/Y?4 8ln6,ޡɔ-lA`Q?cu0:Ԡ쥾@QsxH ?J8'G$NrE?w2s"Xj dL
k/g*#fGy Z%o 2ye܎Ȑw]/hXG5gK,VBg"<CvK<V&+z,-&Cˏ3L=t~N H(me#pb; 23c0qϮRA2n#켺m'Hƞc)`^ObQo ,LG}Wj_Vn$I^3DnجfktqPvQ1;`}z r@̸8c$ƌ%Q :QikZ]]vh<9KZ[ eE D1G8v,~D%&cIm`܄ddR/$c@UAf4%DCy`hj&@(sf ?͇:l k%tߤcA#Y9@xqKٸҩF
XkM)K2NN(l_4'FhE*b9
_-a؅̶}6j[ea<MEݭ;0oI~0wZϹT)`Ks9W^k/V<_DcA-쫌R#!+eWUk[:HR[NDmJbQV%"BCtteKU$}wþeYחzKmw1}qh*Ө:򠫄}]R].q*>i[PTgk󥋚&qS&X2A43Q#_8 %X1g*9V?J
).:=҃c)V,;,߸習!6uxMiK_|JUS)k|hTnLCt:
¸1JBZ0ߣ
w`1o(vߴlj{ xbMQ ޠ:U`"
J:4msL
闓ˋIuG%Li%:S=Bvc{iSB'׶NeSGņvϺdPC.nʀI!:Ru Il_pb
oEg[bNR񙖷W/=LtON7ӯOXk<W>y(Kx
{Z*ٔ8%]":ǵ`H0E4c A! CPHLvό: K;Vş"(63XǎЈ1v hA'(]x5A>%
'ڹ-ZdzZz\Iͭa8!Gk1VtU]B\sث
: {
yPQ{o9t42×p)
.1MPs6Nx:0GrI᪋;tREDG0O
8u'xdƣvҵ(*aQ +$>v%|@]Y `҆%:cHVwx/cNdI+UOt}mA"%%*u/\
}jI.3kP۱RBf΄<E6y>wp;( N]۱%*nLfef"v#*y$<uED5`ԙ.$
y9.\=LvQȏ#7u{E\;kcmX`"
-Ua5"٣t'; FkjxQ7ѥE!B$ M[ShAap[|5F;ZSjߚ>Kϼ`4Hrdxj?ZX 2<^]3%+;*a&؆9sFNMg^X^}x3z2|/ Pď)+( #p &88n䆕B߼&,];^hD<9.Oi-S!l(
v+d9 \aQ.ۖ]#+eiĈ׎.)CDP͍HmT"è.<rLO-{3ê W깐5TZ`L>7%# cHǵ-zd+<6>T3 KM(TÑ~5
GA>3Tk_
K6\{hNHz'h[Oˋ\̃ p@Vu[D26D"B̓c$17et! PxK0#J0Uce1!a[M/Jݐ4Į^;р C!EQ&wRRɕP,&Zpòl/<e<:gԮk/I9F~gx glv%,e~9߸4YS?(J8E[r,R@&mDQ^ԮȞ`SN9[ x<%:rĿ%bb?] m28|^)2w)+r_nr0'($ј$I=č#:?bo<m BLae珬Fb01$;e95b_>b-t-߯4 e7Ѿ"-H
hqtY8k8C}~`[mzqG,1hgGJ#`zg|$lG]q4GH@Zv~.˭mu4/,}T8`hJfkf3R{7ߛ"ѴCMfI_^k]Oº )F9_xv+ {xoA+)?=M`Y"T8TTeْ1aDi<;j6E/b1ފՀ{xa)KLJ[Fə!A#l]=msV475n'o~~:Q5J3ʣVD6&vNS)չ9;- }-vrE2y;9vW:eNIE+CFrQ|2pD6/pN{[i1OL?3C Jqh]U']p#\5!%^ 9\*#VFd=kObU^mtMf0p\Oxaai?P90(1*\Y/Q٦ R/'x&,dC#4
J=К}-ƨ$ABVAl2(%ET,͓ewPDMsk+'q:cF0Z\r#`MU^G
40puM
0%鷬D,jVUKP}%zZ-$eXI.mdʹ2&2 K8/?(3?ɻ`?Ob
ec{
nN.Cȧ*}8-1\fxsA7۰dO WjRDaN}v\~ǵU.Í>& ˮ!Y.i׿jo!Fq 8ǭߺWVȲ# xe<$/ -iveWMRg͞8O狥`rr@QSux%讅\Q̓%v/t<n{
GS6~|]9jWͩcFPR d
-4lGX[p\¦)d}x/A 6ie;Uf}I)l!$$|dֶ+-P"oV=KQq> 5Xg6-Lɪ0mBpj}w!j܁$+^u*]Do]!o
mm.),֕]}*#EpJ=$8D]QnNϪ׍^:ޖ1ZYG\͹$8Eol;B0_u@z|A^@w(oJvD|Ӵ=Km(ox
7nrM PĴwιԃJ15wUo&sbiȉ~Rȹ
H' Z)w+ֳ 9+^›)l>4*Hl~G8L=V@x`6߄xx)<r_(g}@sͅ- z-Z͹qˊQq1ӹe

| 2i!)v ջ[ѻVv®׷5*F_{7aD)<Po{?n8F+XjQͱV>?b:=a)^? 9nvv 0C?ۑgCcUyMdyoPUxu}!᪟hdxow=2M-!ut'|0V9x>m`̿WYtd|wm
?nicsCl7$ [X.=K\Qrf~0ٓQLw=Sr# ,ݧN0pgٛx~]NCǢ,jYA܎ϊ̈
Џ =iP(@2Kbka 52 ^@\I$C159-QJh~Dž Nv^u?@! }$ A$%AyGd''gR
<W^GKH马6F؎R .YD2jxMF9A~ٗ 0qg>( Dv$:KLNWa;x :;)nſȱpv9] $T7fFGVC92"5Nvhh褊-9,
"/z$'}f̠z=iҾl\, 5d^dƴQ!tAsʼn7[|xoǣt
:)w!=yEB D$~_%𡊵@9Tf0 W3|ǃCaz2@Uc1љ[G^QڵF & c"R[5=b(f]g Ckz;%%s iO
< #vJwנ_@ctR"a#tAe$$@*~w{i퀖(_8w@yZDo|8^`24h
(|J_9CXfNmH+rֆ_@$$UOBJ
 |xbQtڃs&&'׹}ě` a ^(VZucl9
3^c/NoUHz*Jl+]uXBZ> $I(ig6ڐ]+jĚ ꑢkҖ>C7*tc'X+9Hy3
2wB)J.5ն;8Pr`>ٱ[ւE-gQ^j F7t,'nljë{weo 6&à1CPrL+ԲoHc$s1PG+SqwƕW7}q8Ն.T鈬k.KV !*KڷǓ2.}#혖/]i0lґ&j}+W#n/ȶvG=^f~IYnSFj?k:GE.hIM%d3npX Jxe -IU0
˞)
VK> Ð7]KTqޗRvv3Gl9q78V޵\vP(o6Ho0%-^\kxDRfL7Alz"^&#k# 35b+"q4h-tHUg7(Rß7 g4fl 9k済0H0f/?kVL$HPիMޗBPrn<Kd#G;! D,vu b}۸m4'*YXM`vt#ed[`JY:׽ІZ.3~- GjZ&<w"BR̺]qcwSD;FBbs% blkse5yqJy(urYo{|S>]g92` .U

5d<2,y)zovqI*@3X<'LJGφ
؋V;=KT'tzȱ+ϝ2Sp94 334 ݗ
Iy5*H7vdA
`sB8Tj y[Pk:;Iz'B(' `T婚9_aSS ,6S[WCCR!dOe&HXaXwF#hgV{(vRm8Q*}a8|vd 6HuLr~s%V=}tN.lyÑ>K)ξRyN5'OĽ'㟦^B W&C&o1E/%raB(&T>ƔG
LUa9}iS }7֯J2ؐ1ˣ,<9݂r{[%i])B۰0@Pp℁;=?}kWaZr0wu[7QoB6K}-9 _eA b׊<2O+`©S+QuaBAGn瑨l8P/ }_./fwkD׵Q;ĔxxynQ{ec*Þ5A
2p3ko +4Fy`2m[\!]0/ yAȕLgT3 y[jHD!@>ui:Can ] (}|v}. xCk%At”fFȟmlJc
^CDbZ:XPSc lC5om&vD>ӵ j`,? tF^ةiw7 B>),w?F2pAB`XsE2_C+dDwٗ/JQjt>Ϻėa|h1yNDeORkZhf;g;K~,^c $HUTl{5,kw՟7Sv'1XG(8 m-^[J.r)0,9\,ๆ^aN1 NRIh:*wUt롔h72YBpCV}p6U>=wɓxݺiL+RvpOX>F\kKn8:DPZwB
I|{>acmRJ
DŽK !I_}c޾:v?ְn8x~`J@K,ʗSOkG!ـaQDYҭW¦/ ~ā: 05dQ"ދjj#"E
dj
ۮ85N8A
W,#+74tFY0BSX59bDC֊p̲ѶBX@y<AYzcNIHgXA=tcaU4Lf{mj ሬ_(yРi[yV2hF<ڦ;]~k ߹MDe
l-
k
)M
2"x9C'Jm3ߒ-4ٲig\؛jDFq]ƴ/"Iv
PdŶX|u ϱɼUb`h:NsĴ;D} ArNv-iZߑӪ`BƲP4s OAYSOx]QִR$^fN zSg܍ֆHFR$U=%MÇ Q޴70<^I_!x$C3t{1\^6K^OA=I+R$a_&YhaYͰF8?e.dv"I '<D9..) Y!n>ziw=4 $OWb
n蕡Y4[ƶ@oR$`N]kd"|-|xRȨ%&]#QIl =\,mN ,(w 1Gsr
FSiT*o[w؛͐XGÕy1m
en"0*aAZ0H |*^ ?K)^6؂,
ʍ9EO_΃kaM}I*v](qblJibsVSU)TާyB5؊!ҶK3;mDI'̍`o+f2:`vG+ҭȯ՟IE?ܳ!8lkt>@o# L<SCT[dֿȃKds2zDd fAHЀXp|Ċ ArS
j D' ~%H>JUV0l>і!mK3*Nꎉȯ>Kկx3jDU_s8$y,qev4[;M(ưcL89N +u_jQT9a'&qI&A!7飇GZ-eM$ſn<N$6^萖AeB#df=x* jfI^6ǵO =hV NϾ!
4T>f:ib(&GHh`ĂبHN?(㎙e'zՇa]wvvAk67a5DRf88 n(,~_o:dMjW<*q+9
 .ʜm>cH5gGmML<}=1Sz!Y&Y(r!WT)_nw>^<;eORlPTVpm.ijT-ofx!*u1LɛLK1h8XN
N(X!rui]kL xްnB=R t&OޠlUAџ˯L/ˈMgeƇ?y3Ƭ<myCbj^~q¼
܂uӤ$%V /"r1$5=b$BqHVbArؘM N'qŦOi&sQ<j~}_<w4qEF]#40hxѭ@wY1|T|%Y)+eqy4}x(BԦ0sި'=gepWYUgzRPQ*OPW/|tϠ*
v//=`WX<8z\Zj|Cfy&,a"]Fl۳ 3 {ԝ/)s#!
ڙ&ˣAE>
S#d= 6颦'YB%ڏ ^К8M]4*|RV
{"d,WC|E@z\ޞ2竏I okr8y@rH۴ 0vԱ)0nHFTw07EJ:20v
|,<
3tft7<[=ɲ#
N7W[Kǵ|Y1 \[JPr>& `E[@
[icp1
=0,i2OՁ(tuzxc|'b셀3x|JZ(k0pܯ}xfifdVDti PͼS%bal{]~Bj %.S6PL`>1ԆMr!7 |tN'%UbUko%=Ls_ 7>1ŧ C`3ʈ(fC/OypݵH؇ fH
/C))br;m0S`>w5`~-_
u
3/;/O6nxDžoiR]DaAh9>OqoB܏TB2ƣF[du<DF&,,V
sW-Ƙ*p'`9b! :oh SZ۩ɠWagE(ebŹJʺ>Ҳcy;4=~Ln42I;3mVYӍM\#ofI0`!m!u⠪|'`,"v*0V)F̾G@M[{iIngHӊŚ5_,g&'6Ϩ(ak͸`èUUf *D^bwxj',aUUx3*G'B 4KƮM[$oİ_"7^fw,(kf7B+1~!iuqFe#DL$u6!m!7s3bGLo٢<,3 Ο<2Cv*#E)Ǔ42/q;2 ΈkթZ|W+5AW EC͔u~w(W{#;n]mdϲwL,vjF#{4!Ȗۥ\,FZ1L)EEGds( v]WQ\>\XZmsIq3Ѻ=|f*>!l$u`Fx%g6ۥ0>4Z0J%+?oy`bi n-VJ-4ďR#Hl7;${}J34p璇0|=j'`}dË6aqq=k}G۰i
bN XVלm?d
! b"8''wSNh@ wZxn{EpۿF ת*k)7-
@$i-$;QdqzP󊼱~I,Av;@.}ċLJ#+<-|*K7@%K<p;/66YʣM|ٟ@*dJ/`+[s\oǾ:Yt^Yi,+'z'|OK_ Ҽ8Z`!SA􀵿zrwk`ޣܿD O^A{Ő)
ĩwE?dCd 29LWsWwIј?цN ŕt`ۺh1GMXN\B=2Uq K@k8xW& Q;ft dK[D[)mGEstL7d[0HimTw \WfhiRSnS8ͣnMyjqQQWev STH1 9@'`{nQ0iFg2N䣏? nU7Lgpo0M/J"Рg l$8YN[R-
u-fKnU1
rL/{1m\a%l6]VRߪWfKE1./SuGN͆ຣ0 1(a 8e⎸?|g?ȶ'BFH3wH!V~yIN5vA i/
-"5W.l&,z="\mvm
=;(+0(n~gGd A
rzofNaZ@uf5BͯN[ݠƓ!A&†w ӏ{9 n9.Gj8{'f! 
5`t,ه
%eH@:.FI >v7dX o2lGIYNi6N뜯@()`-yJϮ`
!|l!1:+G;40K(,zmqaҰ^ALX"<|Mz rNl2o>
^ y\ 7j%t<P1@xI SC ٻ$~R@&!n:󫊋 ~H,yl\5Sw#yL/rM>ͻ o_D)(BD5{Hc0YKF
Rfn·y0GX9W(RH1s3A޻)ԗ)["o-Ȅ-^m\nU#̀DЩܵrYk,ݱa8bGO5 oe8TPm pI]h6≰T}U@Q,EVN*8* W A>
嗺@ٵc>ײ6%,<ж*]@Op5xaglɎMQпPeVE (%wLd?Ent 5YZ(Kk^:d?o$\zp/\93 e^Q RtFm*h2yhq~CP% 3}BۏFΰ$2y5M DžGQh#%c+IdtTso@g2"2\c+)>quC 0E$Y]ȓjTr4Z1\@h`<c8,OknEF6 *u<d}O*ۨyX2zN|^8cL;H+D-J[7÷yq.\iBC}?qF3X?TQ1{;erc(%z}b=bw^"Q%֍֊xIj8oPe qb}\kdv"rb{.1BM憵 (-D6I >4<?ߐ0}\³{̙L96,b3WÊ5ձczkq=àzh沔T Jc1(GCeb3cד d^VyYM2;@(K3|S􀓢ˇ0\e/l%6L>gJ>{o,<kӞۇ!mlJH^Zs$)]i:@&ྭ/~5趹@I@!JRrCeVjː%9c:NVwbF6$|59ע'=>+$=(gQ0kY݁4V ^
ܓԍ5ʮ E/av;*T ~3䐲'͜R6@V'H6TX@h##=;/ѭjX5y.ވ) sXJ$"=OXz.
P)O\m.s
fNŠO4J|Sh2 FM5s N9&7ga2HEq%֛}}6ŌCȬ BYGY :cyQ'?2!+] T?> %k2f iP'av2Gnر[ =2M&F&l@6;9ʐܟBvAZ+%:KPARx%cYV\)bÏ):RuN _Fd5U!q6ti|JhC2G-4jw@ 4w+Ag|WȦl{ӓƸ1iIo[dO?DkE}w!_aMi+`<[.
A\1\uo/*;aEM}YhpTm}D:VD<| y8T`t
6'^k#aJ+0Z Rj he]H YD\w
کe #*w//Y-hTҹ3k_zlTǙ2^zҗL zk9btT.K3DϨODڰshH58d F"y*e7UMNۇzXS-_;5XlYYUPDFh">(ԇ2ݹ*RR =$ٕyFjJP._ #fnZ eOCpb3JZȨm;dNJ $Hy"&
Uʚ{grcfh>!;vyS:o˟sN ɢO+b5$p `EÓ Ix
~ BC.J{z$ 8 ?rl(&umB5C:{|jHJ
Vᅍͮy޲_ QCe,
XӈKvwf0'¥R^Em(
j1֦ՊI^
V2\=e̶mN<.L;\`* }g4@L"nm?pȎD׼1,#2 *-ͣ*J~oN-9k*ʟ')UQ:)r=,SrEJ~ǴOOI"T*t)v
 ׉01$[JE.$pzua`}"anK`0Nt Y4 >j'"Yض jÎĚ ; Ww67gzZɬu?]Pb }լRuXsy54rQ<կVpoR%U˯l 3؞\nZgGp=h<
ᆎ**Ⱦ$cO9HI4NO'iKa>ama#C;8f0GsMb
Qvh*"?צ\, A@6R&yC CskSѝfFGlǮ9P_R3 q{ C(\OIp@IC\YNc'607(m&*1'゚bxR߹f!S<dݢn)/J\
.(Xu kWj@Gs
VzI:y r&=WjN ,\FAw9V4M+xLU.3R
8 %l2f((x )Sڳ]3̔t:ox:vGV_Mee2m@aKW@Ob;^E-CY6< sd/`G+ g4]2twM8kwxЈ$5@A|O|K|Ri՜j
-.{c߯ Ŧ>ϫ_me-&bQf׵RA*6Yz50aI)u<CGtFmb=b sr@9!mtj a2
rPwQH *<PojǸ |$x: (jִp酓iT%h{
>PKE7?:Z'˸zBrm:O ǿy0To~C(Y'J
.n~O.zZ Rq sYK-}nёsIQ#3%ۭ16}$Z)F\dXp dt?$C7wC]V cy&)Hdy7'<,T9(h"D[Bb

JD5#0w
&4a0o{fӡ~_ϜDQW.'ѯy.Nțtb7K EV8P e/3UIr6a.O86
rQϹ@͂-+s6[Z ki
rWy jA $^lZ &E,T}Po4ȫ\qό4ى!3D
}V@
HߜdGȔ84Bj$X(/;#E^u{k]8t_@
IrBdLg2},=RjKk`u42D2"<`[{fT@|B޳uMGaD*u< XPcjɩt! %Xtm]!WJKwaq# ><ț
hergsa˙(,YfD_6V$ -3h9kNCEc6b4RcK%{0F3)ܱ.׈ T L%Ķ%| cVq5˥괒/˜n1([ӪQc7Gɮ,aWR_QʢT)O`Wu{R0ۺ942vC~a? Ul郱R'!:"@]4B#<& @} c;GoH;ݶJxZЈ ɚ`>:ʽzw7wd՘iһ9 &qy͏ȼ4<0)ϚBvXwHPWמfžCB>J<sz
ljDŽ(GE=9=a(WeAC2e:"W-~{}Ib۴gF}G{ԃa9F '>ܦhI\P&5cN($:l~4\&-~qso}{:E{uaJ/6)JHn;;W4?A&E= d s(;bbBmDQQ,}:WXQ؟ЧꞢAUKKVtϪUp*r
Ek!N;A^'F7q>h:uꯢ2dƕ'qp1=mfռlbd~A($Ê6CR)Z<8='kG̒BE¡aZ46S]c4>D
<`v]#5 n8$?Y
ZLyu?lHnnS|iσ8U &-CD~u[5 $Ӊ /m J#U;[|,bAT]vYO7[A2m
vU]y/
Տ׷eE)L7=:%n
85R&FLqls.ݓKg?*[z,Z@!LqZ4ѩđ WYI^3KL6Z_E>=@I_/2 ,$ӟ 5|
$:ֱN&r^_؈>xB? =K.3 +bV>V'dU%Hf2g
Rnڼg0Ti;!0^Ng%Kou9 M%}!hW8\ov T{,en Rw+]pi}ZȲ={qG*D$q;1 4V{2uě?w+a
P 3vljKٺʼnʶuۂ 8+ٖD4xF 04qƘ"C3vSs}C%5\:/g+$uք{E%Nkk;ZxaeJ:`oCJ"F'?SDgvq9l2 Ey`5w@6<ŸdAFp^XvlRi@6'G
S Y(bA1/Լf
ϗ^|%M<Y\B_p񂊵1NYDUEAb[rth+קK?N^w.x$+3[b|?!^(I s(~ 6=x<|H$
aBh~!֫^v fF)YGe7 #Ri["&DD6-{K(]G{Sqvt_UyL2Aj4RNώZ^8&CkDyV"B>ge+38T3f20ϭ3^+9Xc<o3-WAs.)y_Ѓ %N%eG8PV
f3Rjo?'v6XOzg;5&9sbu Pōs1<R]
4WZRZ"Lw=grV_aM18=7j*A1-1"0,~<Wh9i@;&^ʹF?
X44.p _
< Ox}~ ŔЙrp=L.HEnQ+#
"1L;bg*9KW_D4:ܳ\2 MЫCvRs1ny+Gfe5Sگ(옊Իsշ4gҺ侓` pofGGan=E
^:.D63a@ i[Nt)opV:}F+AyK[8ͭ)#Igbm{h\)㽗7(cR>Tx:1zZ]j&oC]A@عî9wIQ׫ 1%++Y;[ rvsq$ZRAwޥ5r<^AD'ּ7sa.9Դ޵qKIN= )w97]%fCt^٬Y`uQo#]m@I Y{T>(eV򹣴WtLJulfVClď!t}ҿNexo%^EG- #k
J3Qhw0^ @d.R|$ѵ
^R[\T'×f[Mޟ&:)Ѽà!ne|QjiˍˁjK6fQm0qSU|B?Pb7%ݒoɒICQtM-0zI>d b)k%f]"5m+a];Q+B˼.Q SDլ[,e 꾠!ɉMljldžJja4yσV&Vla7
l
<bJ5R8F,}T35LxAL[qg`87 'EyP`q9Stڇ_qܱȞ7
G 6긛͛ =,}Ow6_T;͡q51gw' <3͓ځrʓ
aE;63u_<îaYP[. )5]:/yȶHW \
 yGm?{H\mY4dֱU(DUW<dl)QX \|K˼
y
%M\bTɟ;x%5Mۜeţ0^8:bcnsqL%
%(6Gi{`H'Zw9$¼N)\n.ҿ
NH o6`:[}8d+"#'ݬ*wVJ- c/uSm}?op(|23q5Be˦Ί%^L!;Lbqpy=[e},+o- [7-q?/DzQA $&Mu4KdKs)scf7|7éx,6sS7-_ %2/ zؖC_ A[{SHUu2%U~f
6܋"л'&Vu @][Al'-x^= %LSvyʇFW0~(k!Fy@KPP.ՃOm?,"BgUoVؿX]EXkS>E70z-Aǐ5y[iqmŹ2|qb;VUs; L&gjl,gaFpګ_sz~¬&21$wcԼ _#P
7")ܼG_KXrvFN3 %ȩBkZ
E쩛G_ +14wdQ Bfn-%2.
g G>ڌ8u/%B/")ʾbX&[c<:) g,K7<;$]1HT 6^^s*[QG%DeuڂeC}0E6%neY.E11`XtM.Zwz/YGYkz:L,ؒ3uϙQIXT*DyF52
P.=1ֹ)&$Z}Ry$.֋Ɵ=0яsD:ztgJrlA?JxȓBQ(!!ܣHy=U W6
t2=4vڪRK w۾2:m96C  RAcqf8\7y̮!z8{B(.¿{yFbwHk?udťX/ZL*'fstazګ9ŕnlY9~|[rVc^(Х
-B"KРu.Gq5~r=o<k25mR֤/:+Rql|bv7 :o-9<vVgu!VN
,L [6ёϯd]8]eܝH}&2 A7Aօ6%26o}>qBTҋ[vy|c+z2ܰ\sA!ά]QvOc{xDt05Ǐ"^UgOf%ǷJ]Y%a.FG\Z>,M]1SLĿQȌ);LI1 z7~
T4 ";$w/FA\nenT c8)'6Y; K{2H24_PUZgKfɥ쌱nsgHwr!9V 2iO xY`ỼFP ŸFtFLª(sϙEtn{HX bn/n$w/ r0|LuV:" >d 8 8wuQfbxX0ߌU),$1X*T
@i
!Qal^XU:WaQ|*m},1gy@Gs,LV#FX!u19\5^,]['unw'2VFTr;!XU 1" X`փU[c<i3؎͵؋wX`-B@D EU6W%8vDߨ˩ۙZ/M)OɪҞMπ?k\q˴Q07 u^u!q f>0G`epr4gLg_"b%3 K |fѠpb[xBvݗb?$#2(J,9j
ͱ*KR8;#{2Za²4oLhwӽ< I:G7cQKb8Y˷:<g5rPd3"RvҋQ}RK.Q&=8y3&˒}zW1!dPu8>
^t0))vi{aveFiÅo'u͔8_247YAp8\ X5p*{I HaL^y>N awQr;?^4$$G}D$RLa$u u.UiiLًGk~Ҹfr5 ;՘p4*^;M+‡<w'p! MIPA6|qcʻDE"wZAM
cYJM{^20늓F6itWFZd:p7kTQ (l2j>unqF
6w%4V|IjA4F$WbNosXgp(A!lgJsaT=^f[iBӬ_G\aNIIk%IX" [}۔Ru5 -kTwO Du~'p/rJ^P8XJ4KALۗ2nOiՈZRN<v M7d&aֶ߅WAd!{rйթEt.Ή|ҲUذ l?^\X)o]DIPtUux5R(8j>԰bV^q+<w_(fȋ㫃3 gE
ZKP(!.* eu{ zuN=iK>4#-h?uϩ"%ީ}/*J W|o*N:"v{mad چ$ҩQdXNe֓b95k\RbӉǜlEMb v
(bA إ RjЙij[cMS~MwW̱RABhQ~JS1sj՚vopwkR@oT6\|ZKMn‹$#;n `.Y՜| ߯_ qyof41hN@y

8^hZyĻ8|svd؄lmZ܏pmQ9Y5y]y4gG+?H߻ o#2T'6ZI
G I=*E24ϴދIՕ۝q[>u?P/.>b(T y`O4HS89!JED6jb ^8pD_A~ wX,(`L矵D`wSfK%4e.jCg.yq
E:ٓr{`|n7̐Ǔ ':xӨ3n]"b KTv`PyQq#IĞ'kSҨ^5d Ȯ=%
4buP䑑e"MxNalپ
a`G7ba?c6Ǯ͇?8 } )hv=r@=B;-oWOP$
G<s)oA|I(ΑGl3RcM=~2e@гvbҝf[ B؀PeR)Os)V &>U
ͷֻhPtUŔ:ϰ! , TNKF+zw6Խd_z|S3zGr?APiR({KQKw'ioÕTh͎3SR:CȽh]*Mj#0@pHgMw%p%9*nf}ݨi+CRS'oq@1֣Zڻ̢݊&#MO8$ըI聾^(D&igC
۶if(zRd,^$Όn1dkڏj$6pEQ!Sm:LE0{R;ű8\SͿxa} e}nEDT/eD9Sq݊櫌7ĮO9ERmA;tmܤUVBŁRacH'ǚ= 4Ag,ɰ3a'[Bv֙8N>UN4FaYIc91yT-!gVKjWUG c۟'sX,)h( >>KPjl]1m1uuH4 ,M~ijn}AodAQEAX\}F%z9鲊%AŊ/M (THC[sHiTL,ث]?dzf_"SՕ,+A]k|ygpIK&>'(6`e0
9$9Pa(dv+,#whJ3hk:qG!y>X ;b`n>ͮi/1 䟙8ST$hKh-6Ƿ<AԦE8Z5L4>C;tU@'-0+϶n?,IJҬ6IƆ&N~iX!Zc L=#MF`7D$wPѮ 3Ms\JG_|bmʔ2_KƳIl`PONm܀D%U6f +DͶԤ n8b5<ȑY$.Y4FZ8{L WaLN8!p+sh+g𴴄-w0ZY[oog[>, L޿aډ! XOYd3N1Q 钏pMIJw]ج{ݖ{9&ߑUs]E6V&")
r;J܊=iNjkdb]],*; gÉLE5{̚GJ0)@);7pZRyg}@%
o`W^L˜E;!P`i 0P}ۍ 2RKS&OG\ʹ͢ x19<EXqo6ui97{[gzT?c<t[%=o/W>AFƝt^jj"Zpf`YfK%f< nq'R, q8cˏrc\Pۖ1Hȼus@|@LVڜMlJ # B{{)0=!C< ߬<mZ[|Ld:s۾wI@
>Qԩ=Jϗe= \-YKY- 64 {=`VyHΆ=h 0ٴ8\i)~Īof#`[%?v׼pl,)!"7\J}$"KdU
BtZqGV; vCP5X,'X NچIao%R
$|tu\aI$~?mjߛ;
r^&q`{4!oi!ۯaD߾og`͌9[UEo0lGQoQVN
bytũ4gIa
jP3tn@b:q+ D]3YX-! 1"Ugu8q6J90m8o9㔮D7<GwOMl{ȉ?̖ Q賯V12&lXތϬyKwI ָ3ok^ 5litn~Y:iV(2;Odf޵cH![).xٹGZ@
G~Εj[_ ="n%孔Ż&2Wlw*Z>o@U *KOgߢƣ6/ۛ,.Jו jU3YI0|]>U5Q&X=%Wr6brҨp醚]a2z!;3GE`^)\&mhO *YDgN1_xTzq &LU$BJh,Bx[ @R)VY
fW Wyʖ5֬g&AgXY}M
c|ƂXIke)+."hˁ]mCiHO{:Ӣoڑ`tU}]7ճ:cx(Lu^0gM%Fj< TMm)(EE&TM̞3"RHz:!z4$'Zqx( %h0Wra79.%<epkJ+b Yw2̃NgӬQQ
d^NK $X^9,Duh½긮/i
LjңJ"MP~p"Hɯ_c.叡/&8_ <  ޼b"/#fHy>EYyjʹ 9¶1gsɧUe
r|282RJ#)U8Q;"ƒc5V-
T9o?;vӀk wBݿc&V^tn(AKoVFq#/ r赿޲XbO(?c(>dD"GXj
Q$iFUJ7[T' us~8Z5JzFᲨsݥ
mK
LˍY"Ly+M*+5u.dYr!\/A:g_ +WTU6eTr ATk <kp`DZ]ymqƷwЀs@^u$>,S  assDg|wy5{o.4`
!%g97[M h"p0-a"8!W xGˡEגm\q<F&zgzlgܲ0'H|&dQG|I~g\s$%㑬=hqυ/e!fPtۓ > $Gy'nVKQ1W}iLw @ ӟ-W×:5r8XEid>%-DGld4PH4A^"v7b8Co3yo},ߜŽ[ m+n2uIW&b>>DY"[hF޸׈C
Yj-®н[
Gvv 2j
u{vgu)i2`RlbH[GppZCu Q&PRG4Zʲv@QXt$<d38'b>Ebk<)0ĥ(~D$Ń"U5+Ą0Y'h+t%CF?
,O(&wJ\<j-Vs2[ &'^qSI Cm$7EH4
vA+NJ0r12bx3^ݮ_'NXuBxiHPજ
!^ZKlS`1#{1bhzE0k=T/ ]*x[[Bù"V
MC)Zw#>Hjx}sUt+Evk +!Lb ~k$`U<>oQLA:nHES_z2r,f5Ϩf;;.S\4gd0o~σCѰ [>cȥL<ЕqlJ{' %֪3|9(bjUAf{s|/3+ݞ|1,d2W]IZ%(rBtz' G3-fp{ CC~K
a"MO]-'Ʈ܏E!TRaXsp ΐ{ߋMqTF3jLcQ>)_UזX)ɱuD 5ɚ(H"tHVaa*F)e]3Sf2DI'FXgۆ"  6TSV Y}p -TYi.0'h`PVipWD>]=_=VwU{g 6iNf{I>d=qt<
WVvv^Y0Xjf^̃9AtW(o|]N"b1EQQ\]Ol[4:(ze]R~ QFdlyhy}I
X86vzlgd`E!PI-Z
u4$!rS~Y$e_9B Χh A
7"6}YrRg/op =Mt>5zm8vHnMkY[*,ޅny?nVE$+fQonDeM%$+ķ9:w7qnJ/q?[^nM%Hu<Ղ+$W5vťz/0AI#A\ABk*ЖlB`zF
[*ꒀK6ƕ#˺TG
+}-tfdkKW38F|1#eѼ>e@[Pd7X+epuenxz{t*F6r^4|j'p)AEV;LUztX'*#3V4|~2;t8$M6΁
!4 = VC ґ>n*
D
_/$r,I?nkbBهXd .;eUDmN<y[= 0t`?Ogvr=t\ ,á_g`xS} .uUA<volb޼RpcV ﻓy|Ňϒ'hi De82u|dUA7iU%h`I`=Q-bk]8fD#I8[ٍRK; y?qVVR%C%L(vHd?ҰvyDiú}O# </N0
Ft:
lw57ڱј=
a{9mL)6`CWh'_BЏ!
ngAORL!w2*z!‰<\}vZx
rITDzMJ(lv}`B(27b[@_HTYe2Ai"!IԪ =~ d~E'ZOGlaxXP.gNgS`9s軜zN.FtM,W[2_b[<[Lռ*emXn
[ރ-BRջ2zxK{ˎ0"ݛ])(ap
0'
>0y1jYwt]y3JeU?v
![y<G{ݭؗ
pdCI9ɦ j g5##:ǃ]xW|cWnm& aaĕf@, &^A2֤fhU`+H2ԗea pg%UN֮ ;PUE>x5ƄuE, "ܬ}ޒ$
bGL!]ِ/A}aDptyZu"ѵaUMwזN17B38q* NP>;O.\%<=b8
DEFoKŊ
;!1-L R/}W9*}~p#',FUPk *x2yHpMveѵ)J_Ew5-k6ZWbink/pmlUb1 |{yڧ*+BurѲr/1U%[ dZV)Hjh^V7"-̶GS6#4iܗe N7j)br;)s)a1)#y^嶳 t6_(.ωMLa'nEZO1<B+ =j-=!;C<γHڥロֿȑPQna#. zAIF~/ Lk[GPw1
;p6mG.pLR|(
辒CVS_>SaGC&I?󏯆l<ng3'&p% -(֮ M/{MhTә9yUGZ<E@}’(**34Gzkn95eGuU*U Ǧ>U^"8GU\˪:R\LHxboer CF2ڿd$eQҕj3_9ek [ N~w`d,LqK枮nz^imKgz-PpK <uT_j &Y˸,~ a
&ɭӗ
((b}tz*7{p̷wONbVϞzhsw9u'Jt7'j2Eι
".f٥/(MSg+hSsD&}6L"Rc]Znl]rzycuQ, uwG;B~02\ʠROpyOChﳬI%RYO+D}
d!\AP0<; Zi$Ea{mclaۜS.CӸ}nEJq5T]XX;nyk3ј
K3Be[ؕ}3#_#uPУ/dtNT5E/C`ӛ!6K$"޺/ ڃ`ϟqJX !U <NB#̽
VfwRC#yqӔ/,8ـDNݣiɏ
™%J'8m/y0bd}c*YBTwA2?+slP| &^!Y\Ģ:!J4HPOSW,(jt;UQs9oMuapٶ]kOp@!
oI^wz|s{~ Cz1¿ seJIph~p]-d|"(ꕖ  
B*h2:Uع)kWaOK;d_ M_QjI*+= 6IxNVj=ejd"Li7)&  p%+MF `-#.>4꼊#dj$e.=0 $zhh  *c2 ʽ&œ~Z.&Y7ɔsl)4Z|">-Gb];C!5~ FǙ}ev<)%n_}?'j NSLap@(.{KfR!9u\%gL\eÁ(u.Iؤi(;ϭ=Ɗ+%"(*ϧ͈lP]@ VgtwCݧB%5;CUԷ%YӪ

?
PWLJeL$@$~ְ ȬCѴ_ 6A<)O8
wd.׫C2_K\Z!#|#l %SKߜRHIHH~oC dn
:؅VC28ژ;ÍKȨʼB;ჶWK:&U&Y2LމQr͵gA
'ߛk2!IHK*eĦhDu )?*
\<3N=j7mTk9*tpt)ބ.1fd&ʅJ)xn<E8(&I:#>P7剔mn4%u<ob j !
/u
i5mc3zQt?\ba;3sq@SSB{r-a4J\_881TPIyM0UyJcA$M|
t-^! $$BJ6&L.s Ew"lְ7q퍘r7e꼀l|4D]I73JH?J9-/nK*<9i=Wo4 ޫ1"CnEcjiEx2
b.Q .#]BQI'T_TFRޞ0ϵN;9**ԅ9迎bW
A
GD.Y
cڏU>l(:ʢ2o( 3Cq_x]/o-}k5)%.U{BQ&ua"NL?N.Xj<2zV⢎"7gN3M' ί:pKnrNߡv&$D az7_oUA@!Ua/Dz~E$S;o6El !G):DdQw.poKRO) 4rv=,{SElRFs$!,v. p+/%+]MAK -(ƿe0K3e NŸ jU܄ԗP 2JБV󴭾Bw蕐i['߷z̫ 0 O&mb B렃9r7=`d#<^FLZical.䲟1%Ⲩ R
ۺ;-7ˊw; W:Fҋ '[$+K_p#q~%+|١T!@O
Rnm8CE P&qe93[hum\,M(p1YNFtm s#T.U#]F/q>GA0=
nea=$OO:G|vWbse
Ҍ?/',TRoyP[nE`]SVꪘȗ q$<L;YD3$h'_grVsYֆþƗUA&= 7Z ǡ){;%y)e܍
ـ2­U,$ &hA !jw9pF|ED;C`
ݒ p .K(-?]A5B̃c pJvDO9WfH["} bf}KXY-с< ֞8y%vE) BYOّVgriX&2NGt}
FJicZ Sw"c;w݌W Ҭ^\rhK;ԁ烧7,CO (ړBh-7+.KjMḙ@sKw
&1reqj+1?L=N}cxf9wgKB$#c3@R9M|(TaAHi[A*`%0*UuDS>
uUmAW d,_)dݪ W ֊pңG-kS5K8d2z3QT*;r-fck]Yk=4p2']>q(RTHe1^W" Fʨ^8z-'Έ*b:]{T5SB
}sD.?&?R*̹jk/9ݶjeZohZ&T}u!TLTih
m>9?퇖^q}ɡp،Q; Cuf WE(KkziB22ḚpgROG]sMZNu:iő=oTFfmȅDM\Ъt)7 GX 12U2~rIt n7NXQO :oCi%2lnٰ"BӆO0<Ik4WvO4Yj[ބR5@i0.[[„5@)%!5pV"A3v)kD(=O
R

jPts#( ?Fk_J r(|FT#F4Zo"`Uy6E%Ӑ{eMg|rVТѧʀ1ۢ܋w 1ƛw
5bT kxlV<Ψ-yD{ hE¶-#F*E\T5DvW6~\tp+K>4WS?p}5IP〞GNyc}]_R#Jj_S=J V@I)L㙺808MjT| ł=>Ls+>')Ri]B=Ʊ(.DVbjv
8k\„RXi
z6M :hP ?YS;^K8XoʤRmPg-\$g0U=^;guB,^ƶ}#ԘJ2 7X4gD&_I#h4qo!uM go,s!`I@+sc6^Ȭ&6 H/A;7-y<NT%$fR,_X\5YK3^S>0"S]M3B'vK&F);ް ]բ~#n y}=,vDo Y 4
1+caZMN$vw:)^یrjDk /3z` mMFgAS("v,Ln{V%95CzlhWD5k PP+
dQ)1wCt)X8e ڡOTzJڻpPϾ[=7AXA~T/#2vǾeDL <[utťa %])IHxv˭nj 4]P5W_!?Ee)m!1,_cW$+ 6nuRCUL04?x'%.?6o)L@ġ {ѕC^ټFTcǘdٳsfH]$:=ۨGOE[Xu1WNefײ 4fkC"ϑ@/oQ|uL
x30.nwg hM22W>r£p+=zu\YNa$wX;0p"Dwk35WY|aٗ8':C :$N ,6]{LY j4j9ǟa> urr8vE?Pٝ*Z% ^/D:Q 4,!'L.v9oɤcEܾA@YOUWH#C>cB=lB)}"e*#0f 6IlK~P_*d
 R}?Pc*m0 nuqE2hr%&Q۹&] "JQZC*7k _L
wP̧nh>?D!"ws,=qrX`'M "8T4#l;~ 8f܉b\@ t 4dRP9co'۳3?wi_Z Z.l  ;.mm~DXY
ҥ4"S)|󑸊UQw\ovB 﫫9jXbSn$>JLkO\P 75$rz6319DϬ  K
ĺqe #-0[j֮;! )Զ9?HdHQw}6ųc7i&BPHl̚ovGH9@ asϔš7JF$~6E fVUH>6ȕܠBXʱ_T:WM%
_4.B Dـ{Iħ}?8gGob,MkՎ\@!ZIks[Q8y9O;TB<lĿ,_J*2fy}-.сp~>otᅣ6
`D++: >'E*a/e|fZO.YUV} NhDZ(4SS@<%r&Zphq{qa3>} F֊&xĂP$שZ76ok%]ZhR:nB۹Fcؑn᚛ [&ۤD>gEuSIA-D&;,{6RȐ4L
&8;¦MB?Ucjet0oe.~;cDtE@xI0Qt[@ =yHLTtLV7B\&8*F8HSKkEޔx66@-՟2*FO̼>Jϕd/'$~=@x\h; BRu|_C!,L"<N3i]O6p
0ς |iYIMc|ntIk朻u3TTv.Of|@âc̈́2o&$MVW%n 1
8\WAa,yDF}Xh̄]h|>kenM
R .}:FxKX~qKrFG
ewm%>Ó閇}
hqҽ+{l"E2D6 y'hBЅWQ??FD3 E`%.k#Cdg
iNNqZnmW(N|-prEgʷļ'tB 8cZTD
0J|J*T-<4z$,/X + mkl-bW\~ݱC/՝O aL뀁VƒRP9m ΰx8KaXH$,fMЎbkk4"lPW//HҌ xZ
̍ EۍՏLf3ʥȆK'RO]IG]an+:S!˴ ª1}fk
t8?WW^C6s6-%V'Ó:IĊ`z({8-O1(3cyebSab%J#,T[(bckWk4oGY4i8}l$J}`dU?1e) )W ۞Al-S3ѓOOP*|f%C]:5/o"\QΘ '*t-߈on ֊ z,_Q&` I%>#nEҩ"Qk2zfItɖESO^`/E5 Dhܡ+N` b:n^m nБBG
F$.˚_:q#r}
!oTg8?̠><
?u{U@ UEp+j6bXr+:ǩ!'{g7vemo3>(*lzPUX'7asPIijS0,A3
8/Ηn~YܨDyΟ1;Xo1c@D{ %i¶2K&TV?<'zMpl+vA9Ov8RXnm"hCvlxҥA&xg2`]Frf!Eb31
TwA vYՇWsj"vsVJpt} @(zR@p<A\GiؕT
⬷R9׬MNdy'̎fO6-94_9=G1چNN{A_1\`9Ğ=6l)TCU =/yDLoonIH3 >MLKk([Kcnx]V|2.|jQ_}
3$Z12
*"QeȎpߩbRUGQ K2oXԚ.kzZqv},n$M!wĄchxEtSI*bR?5t@m-И"0 o)f> =BX7E@$=<@e% A9Eݥe#Щ
݃3iB)s(AjZIPhbpT"%QY?T*OMUv#&+m?/>J1rǁ FX*2ެYwCsdS՜܆:xG,uvb&QvqE86G3.zT#jD+TXƻ ;6O} /9XF:dZ>QY8Ek22,z{e 6}3k8.SfT7{LBMLj/C)Uz
{(^=ޠ&am̑3QƻM MQ>xLb tL,
*qj'W.NNn:m.#
!
P e_{~z'JxLW8m.4>@!aB1ӽX"]-WC3`L]FUg%+ot_#@2R<YXmy']y e=H̙@'9bTVkx>$-7^39s""OjBq(a\RĪ
P@$U?В]8uCϬiC?\2 ωeoQiӉ*Z*t,MR0mMJI Oa6P>8
9u=" H.,煞cVӽP 4
f]P9V%u!"e7ԕ)3џ[)q 4GZJy|)lRF( K=n/
r^ã&Nhd~(*n̕EOJ鐙@ȣgH܁ax +^M%yBKq( aKz|6帟D^ߦT9_ @Sak~Z3%lpӅv1C0vL%q+|` ;ߓu=w2L֭a2&dde~Hؿl$C`W_/
J+p0CqOS(KΣIN~Th3wDvͩ6d)&絘vƄz ƚ?f]O6yE)3&"2@u_T5K􇂴+1[ɞ'%ބ9gVxYrGܗO w͇諲myL՘GgZd;8Q)rv0[e[$,ۅ#_(y֛3%(jTRO;lتIM0B[t14`UF~x>DPrF<8Wj3UoWNgsӓFguQ?C>~`C5`rhg@`0S}(q%Wo٨r8?G1aL!S
#%`}A6~^B(ˉ]*:E`bl*ﰴ}?3I~Lv~)no
]pFSr{S%3>U[2QgJxY`"""!EKH T…-.{q ܛr{P)ɰO%WKr,vܶIz?m'݂|$c$=QvKO_)s.:)R{ШǠ$Z?)KlR6<l@Z
2j@U]—jʗ@r0tQw{Ĝryw-ϷD8 A>'P<E]EzS/uvj
okRdϘdZgxt
Q$ .%䥐 d8JEi*rϵ6T Qy/ɭ=<pHd뭔dР´>:' \8n'
W4A&ɽ>]5D=Hh?#XjD
tTU9^}7#)#2V0|~T=EՋ(pϙ(`7'~!|`"kX9LY1;l7Em_t5:X1BhRH@ 1ґC .b+L;(˳ջT8Pތ&kO<K7vimq~':|] Ø4fε76{߆D~kk+Q䝊QEɅq
T` P~Jx+oNw* WjxҒGG6Fx[2硩tRNnsFCp xZCjaF7xlR T,(\P HR/?=kcK>"^[i! 0zZδM=ٮ$ //u5.J3QRMJvv:a 4NN%`c/ DJKhOKf SAՠFd*L@:/I%KucXXeQOORN냭tZ'mJH@ -ݞ/pJ63- yLJU&>m|(\.r"dim& <U|]gVδ[fZn׭KD]*
Ms27N:hjGllZ>(j%fRQ .%̨p' a? 1#?w/!l!} зAo Av+Ŵ tF2k{ER<u+e"uۻ3z)LE#XJMh-N Z=%Gf:6ܷ6jHkG>ӚBo~EX:[
;'֤fԋAg'/X56]܅i9T[¢;AF:,9= daŷX'<NfǛ_8ʎ3[ю5prmK1&AIx^D ++s@h9|&u (JּK>I넜p$jP33Y$rP{\kTc,*/mrQ-F%kBJڎnpt%WE# oPKe{BL}Sn΃}wuS|~MɉEr׀rܴ;lXbA2M_}MGCZRO^UƻJyӆUyg0){d)r1_DGBv㺭{~s<1„5>;d҉BRɌ>rM"9HǓO
>=] SmmSɂ?X4Zt
k9UtBq Ŀdw17 mqVp4A!Tx2Q#5z;*:|!L%\|tZ-)HAw"L*nʛHmDV(n6%K`T{)\YHrF;Q6RǢ%щѼYKqD]!Tu>78ns
$qҁ"$^pH.EG7 **) PURO4cv]eYEXC|긯QЫ86Ҟ@Xʑۙ T E+U33MVQ8s C3E ʑu ͷ[Ȧ7j:(8Zw:)Vsƴ<q.߯@in5ʱ7߅~݋$~(kYNGk?Uރ[P<U֭颗Δ*%}с1eq7.=/G2j!.ذ!:%HA\;g n['K_[J0FZBDM!<OIAxa=MΨP˜gbD
jx,/Bnٶ־P@oQC ׷i6܎ Tz@/sx2iǧ
7
ʭ9 @*qREE'D@]hL:اӖ풸7Ӝ_r'+~Oahgobo4D?<F?Onq. O{:B^phKr/ 7hTŐ]\, U+;w^)p6pZdάh\Nͧ6ɬDHY*_`셀yTL<p>"z_#KڵҺn#yV=IYߓ# b*ƀI5!T,8/G\R#dqgCI8ep%kt$Eot C{2ubgPcDLW#qI{lפGD \]G ^`u1<ݵwT<)R_zGuQ]dpi?G5kW}6Zzi<@;zlkKϿS0>$bRۊOh(?#V} SB
lt3FZ% I BuTd*1{C?Q:3cB>
Ie895<L-5e x6 6d‡Te8nεY--'Cucrљmn]ߴ1m-!HvccM|Õv<dP"5.Q#C^z4K%IrdQg "`lwHi漺 &>.p`]9U47B3 \^_qUӱ4|([
:\<~~[. JxȭpUt
vP<݉R1b#Yw<K/]Q,6[]@if͵&qH! N-ڴO\fe&k 0kc a]>F
Fac4+b&Ag鮽:97KO.lȲ6G2XO~iS̅4΁ sJ k9PVq)l bԟxÎi{=( WƪR<W0Z(CK[zBkw]'j tԄ{͗rDw$-+VR|qORYy&ӻud Q"x .hm]ȞgU~<׽#o{al;iO!H=7+2 :HGr "197( w
7 ve;a}hRȲH7(wBq62`{!}͕?{E
zO6Mj%>ZHO;+4~ø̺%AVtd),]ܶYb54Fe*ceLAz0ŷ7Me窑gS3ilId)p`NS+斨"z L-<o1X
bWjմ2&IdN;N
Ġ{ːWrq#al` |(h Ү7r+M*VbӃSGnn44S.-r^c*;yOB(9-7%6-4л<]XU
}@N~p
YTɓZB9*(54 5?g =$ě7Ok=H:p0(R06eERSLNj6Y??
m4\F_w5X5Xf伐sGW+q2Y6":e2G}3h"E].
0㡜E`VBwp z3+p队VЯxVh:.PZ &3_PoBRcmkq$܃b3kBT:)`[IS7^7t|v\650
,όMǞ]mctW(ASN &Z7(MKF>:!k'wqؤG/繭 z{]9GTLz@aWoT_ yVgO>RNiL߭P,
")>01󧮓].fd½ce'B%(UM*|;s'D_Ls
Cf&^hf'YVR8E_^ DA
`
/oik~ Ve
zx9-D
 3h#w<NG }I\} qhp"d3YR.?4}Iry#Nlp6YM>8s`9q۾uW:W
ī?20\K
e\7/JȈ#I)*ϰ+s5͊sDcu)oSRK\J,DV
vt-|1LijMǧ_r~nfR<^t‰IX.2[VPy
@9wx^BT`'K[D/)ihySE9c
}ӹ}K׆iUeik>詯%"FM|&k =?ӳiܬ-Hwgh52L
v^h]2Z)es>>KiIxߒlO#IcAq@Dǘ bLJc:;='3{$9S&ӮҠlJȼT>ʌ- ^.7Ⱥ#YŏdnNʹ P;sHyg/N(4z:O.ʖ=tDA_]AW 5hqVk7 @, 2d0zdmk
(巴_8HY{lbM$z.4NMK_4Jtwbq\4 ΞaRu/+DG1KV0>xmɇ0.9"tد[kEYYp_>4/ ZZR\<A`keO<GXaaҹVG< |-3⠇3OB/wA:ЏR,ݵ#zbӲE;+ίCDH;MF0 aUEmj&
m! u|S>ްY*y RH,"gokpK-o —{LeϢlP-#$4z^
ȚU:,Gzs" mŹ4#)PԸ &#ɵj5),]JU%xukp]fS=GWI>ȅ$3(愹=5/dш;3mׇ.lcz@Jg
;E/+guϰGgɆn:ݰ2'QM~RͶ a pT @)r|<kXmH\*ȥs6Zƒ
?2,b'_:)U TlnB M MPi}ulqd7JmaR7 QvY>Gwh^
ٜd2~P[L]QŖ:W׋E9XVWo=EַS̍MJ<
3=E$=eyXϪ ΐ^8[؟:oYE]kp |S58pkμq&= D܍"c
x$ 4'4q,= ;濢vd
x㯚Dv>Ye@4{
ڲ\kQ KQ-vhJlo[?Sn3{<zPm۸qE\\ e7Rs fCġ[ g4/Tw&ԟ7
qZ䅲pK&KӒi>hDڵuF8 ,@Z-d
8rSsWJMX[6}t1l}C#7I<1Ֆ{q?K:"u5ӣp3ei  3MfYMc+ L@/+L]8={`\gOVh (
p9E ;|Y!vQfqyIu׽!GvR1!O 7kHnc OUH ˛F*g Q CRi?s-k6R1.S$Glk *[N@KDz[jv^M4}b?-=x,"Z 'J{bTԟQ-k:M@slQ8ꘚa_r* O?f97 Tdk51x&c♮r(}c@?֚6
;jT@avOBr<=zn
zL30Ag V9M4`
CMSG(ҖumC`4ԈO_⋂Nt@FЫ^ˀ|:V'F*CrD o@ZnAWmKkoQTvH=M¢Śd- ţt NIv($>]=N:i$# '}Vkipɸ&c1\yNrCI2𔦤zA&sQ["<|JG ʣk.bd4Ppb,fˏK q7JX|^sV(<z"JtpMNzw~odlޗ@Gob1^~o6Y?67VAe~R
2QMr}`n躃@QoH1"HÏGrgpѰOd^5VEvQG/ءlJ?1Sľڭ۝![@o>=Y48@Y)2m:FtTCķFEm'݊(a2R5pN_*PW!Y [I+(=aΌJE1͢~G)dgD$#h8
ˡ `Y
F80y"9DX M  .
-K<bNિj&CAFJVbE\<^;@B|$@AEB7A`7inbiѰ[q5+&<eq3"zعa{F(S%%(ݾ–\JG,3}1?w; qٵkvg`:5Yk2g5n֭{%n?$fl=#-zύ~
9%L~Nv;CۜfVRfP QN>wG5'P"-_g] 2'ޙo=6NUc,Zέl Ae1(h`Y }.aIYC^)O\+b$5`F4APZz"{>*e9sω+X4+YMbOx8jhZ{U8٘*/ӭj}6DYO0zzG>~5_`f%6JB.$e v&ʦr*rSVc,1oo`>/.c]rqLA0[<,F z7ϰ,M.}):5t\FX`,$&7c7s\rlPvFlh ĬK8Z\ˋִ%\P8ZbH`<uZw`KvikcM6S>Pq<(c5氆" }h[Kl
:FanZڈM`|=&xy?+x#".9v $Y'Sg#xr mRkKU1;ҵDtAr}8uQxDeUH(qʜaIJ{<0!1pX"zϝfHF̢d`Fɤb9ďڥK4zC\7v Cgz=p!q/wnظ/׳XY<sJ
h) Fr[Q D0LwѕD1l4rϰuivɂ YX/6' Q{9^;+҃Oz0xMn91c,0"^GB+WJNuu׍(}3'$L<5hyDIrYo{0@q4JT=j>(iuwKh )ۊغ,Ǿe&1~;E%#yyelrZ8ߗW4WpX--~M2;SV{+z+Mvҙ԰bxD˒KDHkܱ{
O8qq]3?B(0 ~9 ,l>Lb›v5ZoGT⽍^v[1 S7kd(B4_RBg^M㿌Fr,9eCu+ bUBN)Ēy ,[PAt)l<#MvUo\2=b{W` \^0f s
z(u?Ds̤A/"moh{F8X5ot 7áL5O0!j)A 1MP]7H|.U[\JƪHNL Zא.Y0}gKȕV\/Nҵi҇C5 b%V@bBb DjDP_S0;2y,ne١q6`z\KGbV8WERu0SIވ?1,
_D
~sSj
\uZڻy? ra OxeK
Ἆ/}@_nvL KFHʖOp1M7wpt?+Z<!KQ ,%GM
-pm`zi,lYmCEoU|ՐEˁ03ZP|s
ԉUrW3aq}1"!Þn+ s&S+6 r96:Λik9A† e.kg g(y`ݷ
_Z.EJ4_ρڍ*O$R$]<{> ?5\0VݨUDTF:YsEdG+3c%oPg'ǟtfFVE3&t.BXX͒t-#Ω;T3|:̗%Xy1|~݃,9{ѱQ*s+m\S2Xʼn
Z36ح
_9J2OC"~X-D*[e;lB@*phM}Dn6`"7-,$ KaX8^=+/c*fG"={{#K2[U
y75EFh{+2i;;KIpqBf<+ x=;G&B] *T4*] ˭〵j$n6z,=4nIBGPBS7f̎?)J,\yt@A^@\wø+ 3`6a{%Ly?FH@ӊǤԯ+(GL8YŸ茲 WKP1o rjxh^
ff(ȗ[-en#OL~ζvI"p+:8B}IY"ÆHkՊD\vn\Uy-׶S|]4& "v,
Zwj
#,`HK]rmO aJ!8SJYc<qz~XBJEuGv~۾f=~vX⻫M#źv'H2A
҈q:xi~3M/J{HwVIX3ACZne8 {HOzZ y{4VI)"#o=d>Bn}(p8^W
-p t8B"?%˞I.9j#M]Lg^[:(:W&o
Ϥ{ж:-w{$ .T^9J@hn21}e`]-t֤]2yҿ@v鶑?H=K✞bOc]ܶ34͒I.]kڣzvwV)yW.ت!-Is n2KhY-i_z_X5>u؎QV?iQFb(7w.^Cݼy[mbplwv=&q=9 Z<ZĄ3UY:9>N-l"lG
S*A{dxYY۽2З!϶=Eb[&qhuHۦ 4g-i ܈FKKi(Y|M.@-i cDU uv&cУfylǿl=Vsq`œRHat3z9In nF#H/ORmq{^Mh9;&=?Ǟ]~I@iTϣÄKRQxY˚Y1(m BQ{4/ ',VQ\.&3L#^81ow}[ENt&ivQɈbUJ}lCD/*1qB2HGϜnB~ȳHkuiT $+f0}|૊TIiB׫21GmNW4/8>`SLcQle$~i#N.|۝Y~\ ͫp{)cE"0oB
|&.l\NM4
Յ.(׿uqEö9H ֆ aLEaLܽblKjzzNZ
,[Z2x)VRO&wX).vDMw mJ?/֕9tBB`ȟ$Hb'lBS'xkfQ\g0 Gj0"!h>󶰫zex ˉ
)!JqJИ~ѩP>gt4LQT#&s\|I6?Px_iX~#B% +IQGYSЍD[ T.,YP.G\
wH0YoϺG;fע Mpgx)dOFFvC֊:CZڹL]zzRM~
vxBNCՏGMh[y\Q7e 9fn:z/7ȺDR4B% GHxtD]@K_7]=;,hȭBa,f Bt<o Ʀ 5]&Vˊ]Gc%{ZKcW7uds/)OvLK*$fN)p{Sކj@>-5X.ěPadC֫GqAVBPscA] (7v'ut䈠біУ\7>#i= vF*1sIf<<tY6J܄Tz۬&˫%X=KwXxP)y_Mx Dž hcz$0
0& SfjT2hՇx/⿂QC(lV2;M J+
q\Tg9|n
x/ZWX!RrC24CICfds,Qvr( S-*\dxA?Qhm*T~.%jg@ c!V2?γaP毦?+Pۅg}p-:
{F$O0ۯGbX
Gw,ʵm`F<b=]u5B<2Ȯ_m`ӴJ},*6AE
+v68Rޡ#0ezѿg4pAh ӓ Ѫ3]G; yЭ DRz`6GQ>{Kcx
r l&ʟsʗM0?m^ 3q8m0D%c!kkn^fbZRɮ/jFT2*! - %̢XT?U^ܺgE\ 䐟N2eqSa7Lιq-9MYrXt 1"L_(vgvՑ?4{_e W9g•o>l8-K}:0-+tO&Gϵ$ڟEF4HݐOy{E@TҊe#-zxFQP/ʰՆ9 NjaXM0gRI!;[ L֣<QW~o&"3B-]/mٝHZIi6‚
fHB
(QEl&ڃ?D@G+"P[UE?̱bs[#p(FIחM>?Do>"_#nl
%m ]̵+sir?,6UHmo=@Ez*M@]I#T%K~3֞F#fyLz2=pF"C̾~8#7ETEw
ڤv'@[3@ &aгJmC|֡ ؉3չؚGN>︩lE Q<s+WY]ɳ>>CTϣhtWʕҶ\%_iV|O9P _^DimܢZ ޴bԳ=QR`4f]#
&*H}oXo[?:WIT*Дvץ:FO~ u
=Yec@֮2 " v7F=
yU-'Y,o^V|YhiFAY$sV\,.
wĭ=֧U6oֆhiDxcGbڝbFH3йӼcX5&9a[MiMN ABa6s\uK#OXiT:KSkc$aHrXoftxeʅGSQoafxi|Nܫ6ƺSϩKqx37^
F f!fm 9Y+oDI&l^RAz콉<7p_,.h[|Bn5e*ERvAR1_OzuҠ[<\z.^CN3iN8CGbP\;lK-5ɩH4Ll u!"D ky@=Ed(@BE~VL edqd7
[- Dꅨm `4jy]*^juX9vq_PEU2#^DKm
`R0yЄ9չȭO?%(o\EЛvQ4g
Az\IpoDM
c]&Ke>(ELK'3V0|1å| /p+ q֪wj,q;BX1kCp
T"P&:ߏ4VtI _RI4}2rQm_RN +Fѯ61v%|8'0wx!
L2ek%粏Czp {Ļt&48 }J<ވw m>̺
[̔-dh)r!:4V𧠱tq}8
\|Gn8(7˴.RK_]Z`+tT/W%e,{@[#kĸl\BXԧ]H2UoD(?V't+E>sq1a*+iذSNJtOFd`&FUfOztmbȷ: 3
KXOJdH :)(p
|jE'l/&]-,7=*=s3Nol\cؕi52Veerdh[>z^fK`ͦ䛝9+xX"/_6Gt\M,c05DEN~0e\dr$фXƂa-XR8'2@ҘvkX:tEm<NA"ڲO@}fWԏs5T}.f"Qh`czQSE(eYlZdc
ACEq3JX' {2՟ʋDIY[ˀ6__` V1Z̔t!nr!Mt2(=JB/}9K~ႾX~#
?QuA nG
P6Ur+W b;Yjl9LJΓ+Gi9D+ z]IJip>6< v /~핔(I
)1![yu]i҂UЕ ]hPBa|#^
-dʛv"f/7Àتc_a,tbdhA_)5[u<
]㺜(SC<4j giA.&oby+Cl]GVkRʭV4gr[8B?f1 hJn386t(N;)KTfظ[|ŕ<(t"ٽPÈkt&RU>|IuZq2oκ)л]q]]S0U3L!{ht}A7[n
0`/h[Җ{ C=<. ~G$|u Cǘh5)]@5Z)gyb"2~]f|tp$h 3@BGML9R!z|] nͦ(#emp NeJ]8
{(e{t& RIC*6`M[PL=

L׌v}-Rp Zפ(9su5!БJFdd@= k5s 5j`=b&ؔXD&v C.31lb&OWo'>NJ٧p0ӀiZMo՝أK`w7$L9,#跳ĭԞ?vp961!1Ȏxݟ{\pWsEWr#y"@8mþoW"f*٦[rd_&0f"_pg86O(o=DJhU>O[
Ffi鷿~K 5#7$sTvӫK=pߑ~AHD>H =}9c[ohkKtyHµJKnC ; n
[OP?-(γ0lP>::)U~|Agnh&ympXM&YV&${57퉢N0<WɓG fK5y lG aـ:SMII v{uR&ΗJ;
$PIm%/QP 're"<?áOƝ`30Sj.e)
miZjYy-,j0*XQh*3=K}­ŷ̖ 95N?IZ>;ueG; blN,^ILU\e+Uf] g**0|cT3;}Nh8Dh&Ϸ k6
*saft%IAǐ5WW:?ҔPUڋ,> JYp;_E!z&q]& b94_rL;,`2,3~?qO3?MxϏ-uy7 2,<'IL[菬L|e آ@w
V4-4Yp$
kpNEz!_/:."({]Nbk!H^~?ҭytXI/&*FC> ofm8=sgKcF|?3=0:>"%(ߨRRR/H4ߋz!qIX`tƣpB#dsԥ|2Y HBhSOL*Oe$lkr}Q?;pD\:@G(DA<$|ZmtѕG'/5^)f)_z)ޫs`
6 l5hw8w敐 ʊA^Y!Gk^3N&iC奚:qM,x!j.8wy ^a}9dX<6z*Z KB[>%5F" wmBG*[">&*ϋ d݇HL/Z"$G'V^H0-g|cCW#))swF"
n*-l=8 z^=Czt$I'}讚N/OX>sTEDPλu&}
+kvrĖe~5`%DZtJ6TL[·X =nQP}JBJ/x6Ω=fCD4C8ݐw/_[~8d6l+y~ ca&ϒmp/w5nK}wTJw JT4 +nr7||}|;ǮW l|ߋշ)XFI@xjffJ49_t.cRqU4b|~<y/2Q,"Hv ' j=kxٞm$J%Z]}݆!3DpScS~tzHiql_$mG2-yz/KˢC} PeQFƺ-w r>s:*!ɮ)Ft!\UiRUa IǥhEPXD&HJ4^3mpt q,9k/VWF&d>t~Ȣ{&QԟŝQtP`\Ŀ"v:z㢠7]bn#,ǙC~sRZ]%ٰ Fݨ.-?Ls<r
ΗP1@L3>#4UW+uV'iK_;7qhZZ:8 tFsG5UIB5M"G({ggb^kʩ';PTZʷclۡM@6(
u|_BWX[fDz+j vP$^ $Z+&*!h$Q¬'i51,n̰𽣈R^\\ %3-ejߒU}EXJA{_͘,% a??sWM)̻L' .cvBYU)&6һMJPnMg&'ZUA6SLdq 6i:K S2:aBYTH㪪2$5##|d*o$0!WT94^OͿY.XR2~GhwKj]FpAu'G>f֕,ߖnӵ7
WMR_T+xO!ުÇ
UA}4v.\m
%;J(r k^L$zIN=u&~P:jMۼbulKWUVtK]y#Dd[֩)Cvt>8iK4Km2v6z]piO"^yI+H_!mE>o۷*Sե@<ZZCJKftd(vV2Ŭ ~3_vܤi}9CsbۉȲ94;:kb%M8_F PȶOi/栏|f܁C@XG!&:
B.N)g0/b첲W-gH;{k Z]w"JSK>(Ig-q^*M` f3IPȜ=iPYp!W{RryoRWϯ||U2'a_/y`|"lq'c5*Ha8H2e*_*<$_&1ْ#=dGs㻬In`*yh*Py{\L&%~^xŪsu(+P
z d@u|  J&gN-`p
AP*!GaWwriϾJ+ͬ*3]+|{4\:>9L_Y@95zSWX
Q`]OߎSTI};#ԑBf+p7odNr(P(\kr䂺a--#W,:ur"úbQlFWݿ̱0ob́zB-bEsӇp2`n]қ_YS 9?h?@0}OYZ@T,D;<\&妒<8eS%BM<QE [ܦ-X}K.u-⩺<D5?d͹?+~OЭ63TYZFbF<=08!I
m
)ޯObh .ڮ*o/ MT"7f$
u03HLB\/᭧U_cisnG)$+< '[
n3;XʘoȀ!񻻶Kn`CލŤ
mTER3!LecgYTkchF揾Lq v.G|J$P UVl\X(T30vB@O1aDPU&5:/X7#ϐԲݦE0-:Z[ĀqO^|
֜KbE6 7ֳJsZaJkǻ⡅VZ4]LmF)UnlBߵՠOg6jƬQce +L~Pi[n}%zQZqi)0XeV͝ B޶FC>aV/tg zp]\7x^ VK#4$i+,Op:-S9>]o/b NGۂ5,Ӯl"-0rc]FL==vn|:z~n2o{4ۛYgN,|J;(]@
& URAM>*$%R$ՄUFwl;-
gAz+*҂wDI (?Hp-vޣb.CJXΥSn#BPaSy]_sVF)],W}nHjYa31j`}q+dy)/y.y%?t/Tbs9 c۠gKvox+H8lP *$; KtyHs6?Jzڞ-6_ `< W@""DAE.UT/zrE)hFD+$*. cH1%~\hzX}]O&,K 9dnt6)33ͣh&xϑ@̄
sy5n0cW7ng
b;,-ߴܐڠqۜt3D4Emld$2MV(D2\-A"r
_ +٘'R~=Ȣ c{0u8}W 2D&,7LtR)
ґ2lܸi3'|LU\ճt-
5JP2I)Ki;6CeM)Ƥ]!`\Bi0 `l iQ/9,N.d {
C4hKkAVPf[pXYنS0q<_sX:Lo-pny0+GQi`VD&G 2G

tQŘ"A_bż~gZ>q ٨\yOE̼laPM8qoH^CNi P,Fl, I FwVbj@Y ]GS*?ah' e@"7
v1\2-b{{
֢2gNtg)p)PTC Z%,}=ܐbTʥ;׊H^ ˒NQQl~1f.ulW\"g@Ϥ'NRʄND^0LP(h<ofJ^,
h;
q`k8)u~eȻ޻hM1pԢćPo&D4m[_)GJj-T|la39s
i.觍xς!FU6{9Z")).KM],y4̐Wnr|\r58:MцYqM@a&Se!efꏝnc(.a TӠn4eӵE0 . aנ2r9D[ӣiq)6uEf:E3qG>u!BVÚ?#D}Hu /</ӀngpEwrU$׾w\VX01DbUf$0Ym@"dؿZX
q?-m
hm13t1_O#3BT΁H2I=iFP^]aϽ.Uf{Z,ſtc$A/ #6$ õ, eQ
p<O(]8:ۦPePL[>N"T,ĞKL{/fCi]'** ZY " fN&3$Vg
yn'<g

qm0̣ .6(B*LB NM
@z}/?7@w;I ۑJJZǃK9i6QHĂa6J44ErSW؛"+Y|Wu=nbrM>1blꮹWդukМUlTNRjG*&3AB={#H/PM?nޑ3W9 T ߱
x..}2};Ìj'eʶ'7^>Aכ pGˬ|7ɥ!~Bƪ6GT2u 1_ ?*o
_n@Ypiφp QƅZ(nU+(?9>SLmLQ8ϑ&g+r޽R.'$5_QSU_8^PTM4
?Э8.#O@rv|(*M'c08sccM-66PQoWlt5o$_
9X>#z#R&7"{簡g=ÀoIm0bF/"gX%ʯIB%5kjbLF{J:ٵP Zir,QR+7<qC\;aʼ{IM:TetςOo59w_mwquߏ{e{e>WC/&|)Q9C\0Cd%r::8 rsӄqcʾOdeOU !܄Ǚ0HERQaiR \5|?? w4$zz˴x|ye-9lȻ=7oNCMQh> [1TbJە^RT8c.X_WFaXKe_p&-Dn98li((t|B(2@X lh1y.#'OCƹExUIe2#WTKPK}z=j5[c~f7Б oI$zǂ6W)ɇ=UYKң q DOM ޜ. 7,
ɯ-|e6pa%!,y0q`? Dc}Ug,-y6[3b[Mtr/vd0vA=IAa+5jiZs›I7hgcO[2tΤOCIL
_._utgw\n)rl7|N"vdLFJZeaί 7"SwEd
xdHՔIfp~<$ “E~dIɵؼGj}!njzT͋{h>׮f
)
SCI˙{hV XɃH';X4!'ȝ8l Ht^ +>T4HYPඔL)c]ь Lfl 9Nc;mRG{_RKX#:kd/u>&rWM,K))Ǧ7^ZSB4
HWGi\<
g/$w+u QzY~[v`"@HZuPn\UYl

R >HaR$c3?%X5bz t]lana"F&Èq%ɭ닲[Mm|k[8rƊ7`
4<ZC}*ӻ

S)fln#Vޙi{ +Akɭs
Q3\T,t7}=Mq`*o`86QRZ&BAj h׏Ǣ|~0Cx$R߁6nY"
"2cVWk֛ӋS/'ȝ^U/0 JeyfiR X$<6/Ƙng\ †3ֲ) S˹uVf<vX
IsoCR,7ו0\!Boe)Z('u>B~>
NWeTQ
%HF$3u$um1oRpU>{P|fTZQ`dr&ĽLjy(˜ꥪVqUn:(
Tܸ\s\}#>u~US!XYr䜓h5XebeĐ.lneM<uz:tc1N$"<EQqfk'
i&3X!IB1}`6™
i~Co<ǜSIA7؇MP,U#T%@0./9@> _6/E\3H?DQCp^wgGfv&8ipεV>%}nbx;L'i]V6KTuo? G$ !֥e?/`u+Q\JuSwKgX,4z]&P^Y}C߭*Ӂ4mm`Gi FvEK:䈚Q-ό{2QRD͓L.h7[?oW{

WZ6lovƈGUZ[}VY[ ꐂPLBFњrV8c>aF)
enM3-UR3 ?,zչΈWZXAM@V@ ]|{ZN:(7)bOu Q ?ܧ^2QަB M*5H̫uLooİ
?5&Oƺ3oaNXTue*
fvqgWI9LqnW=^NR<UŢL~ƮM=VrHU!y_(& ¹jT봫ɖ.<7mK|E, FBWBACH?&j'8>~
T6SMCЏ
&Lpqʈ[A^̵Nޭ Y(6ޛGAIZ،bFGw%c%i>jǘzFՖTTr!W:K@gB
).LK@wJE
[T&ttg{gAIf9 Or8Z8!K>89OaOQﵽA`޴ͷd?3cv'XMj  \<Nعϖ骭Q
Adza]XJmRiXV;#osoUX m&$E&_@
+'=VL5 ATna߲=og`i`Ao@d@ł!hm.a_2jE,+e4q𬵄9ڛ0hxoCWwlݶN(S9D&P
Tr`f%vQO2[
$E̺8|ڣY˥€Y}S5_DR Cŏ9uebO+@kSm RRVmyr baPbdj&H_8‹+0BvaBOf5 ])FTiI&g[- 6;r1dxZYx9T_ֽ*a,|L-/<:ZѹۭT?ϦOHK*|@]+ά" wpʰXD^
C_$6.nGb:PiCzjpQhVQ@\owmѐtE/IzQtݾ- Ex0:iZu ro8Aq;q?t%ߤKQ뵒:z(2<$BHMoaWU4 ']jAB ֋~7]k@y _(;뽐Q]r gc Y
HVpc.XRJ`+<[m;$( *H80Nia:lHZ·*%ޙ'D*f4i 'UGڈԞUCdWgAuR"@"#EY{w9}h4Z J~,={ &Ж|l;<w#bK*ÉΛs"xÐF
|34F8\4m ,ꂸ8'bسV"s"AG$
-B@uk u\GCh;_F?xRG
U^~>5N[e}i*}p슴=P86ٶ &=$ ؆_g9y^/MΓ1.ny6@^4HpRPYjqrNÓOZۜ!3rȲ!M2-!rfx*m.?>.Y'f"
³Qa6r07mTHB0U/&d[@C7daCbL oh5 7:)DrCEElw,|Iha7F'6 ˉҐ\X0jr`T!oO0W: ;(%V,"st0I5gY~YF)iu;tr9~eQ"Obī2b](=~Oz+q G <E]%ү==lU:)?wxQro]&Y8m%B>
(ռR
}W"@3 =mʳk+B [+FAZ06vfDMG6f>VVCUSky> aJg&0̇܀~(ci~JJ+#CP!\3d%b z,XnL$%rayR("LY4˒2c'r%tɖg_!\l3H%卄3w<]T_/JeuUDW#pz OO^Xy}$tZʔtxٳ@q4"iM-.E
si>qJǖ5qIf}]Yf}scHK&`: ܱ8s3U^3nq8Ci4vWnIywI5!/ ٚ+P$;iL<+:qd
7C`e Hn$ӰnF_
 tx| QnPRg*(%)QvݏÁ7.)4zDB9:^ O/PCEa oQ
&L% JPNyg}>lG[̜D08ݑ귯< JIQjx>+[1W;p&CCn͸e#49W
Lw'
Qq  /$]JQ7| <akn,bCl]$eNT/<6 r=#3=N(KVd!d8gk@I;.&Zak;'t2b)9nr?abӤGTi9+t?|/Z,kd2zo"2ܜ;K0]fa?گsuieyvҹʚVRo&S\`Ca0u,ϹK4%~Y _cmoӪlzdem[}ilm'yTTF0Ϙx$fCm
Z<nK
˫y>9
B<5U;(+6ix.V|)Ȯ1 `nl}%CͿsCs-dK2xWp!Q^G[" ]ݮi OgOјn=y.khMZm͸?h?{$9 Fw Εu'n ;lο"7Z
+`%_?= ݡmީt'\:!uU$|耊SgVAH`;<@ʧY1Q+'ϙ@L{lH _5 P=GpJWlòz,1|73݉}aT'bF뇛
el|i!lMvS' vu4@P%^QQ^
/L(U'
b36g"d|gS~(Ge<V%|, XMɾƹW1kr=vVhׇ[upWxL1Q?R#"YjG 7A'^ёN 0N)WS[-?f~zR[b):`QTG8*1'/#.9B?2}d2͢Ά&So ំZ!ɺ*F f*M|{!ԗ 7rPtC'G?Jb ins_߲}FCm{0'5]_Z` Q&T?c mpJ}d$2>m:$o~BryApW v5r{p\Ki?Eswš3\N/r1w( 2%Mـ8AU Gx8B <"{n12m̒<\3,!Pq -
\)&(ul,#À`un~҇{wT-Iqrl;:vXuÉ7\ge4NAt %*SU[O)AtJ=.>k`OyT,<<J'_n@$]q!ӿ[Asv#ؤx+PO1:m^wJT~fuh2Ĭ=)o`vJN\(,ҩ$~xĎy|Y׌S:R!k=yԛ#%$}w\1WA4YuA|x(&u f5!j#ra4 [vYt[LgN4wG7yKg+D3T]IЁH푘oLIۣc=H
q]|’~\3|^mf,7dCmaKd )}n:.r=ȡ1*ht9 ĉ@|Lq #LVEY{-qQiãE& P4KtF!5D\*&ĸۨƙ?L|*>'=7Tjγ=)AyqcGCK"
R
Bwka$AIprdM9N*ojM YWTǍXov%
}jY\3YQ“]p:ª%SȍZP{+iZHT?EU;qdY\f`of̸?)TlTs3IT(x:C,X5q@P'|-[
?G@ fs8o$gX6YYnx-὇wCMs~ޣc_02
DL6\Sv#?\a(}L[u4xz(\P|Yɱd<#aQhx`:fyɥCXGE=8vɂ^6JC窘k-7M&Gc9an בzwHd2!t(QfVVLF/ ><._UDߡW}kDL~^~6Y% Zh5K8BI~?@pIBO_? 7ꌢ R!ZaH4+o&#B .- -'{tup}, ?ür/"%F$|nƮVEFR"<vi16wlqOr0m^O~z8K#sof.}Pfabҍpa6ۂj0/sj?f~ W -?T_$~$%(`.ꗞy[\s&
W@ZBN
qS}o,h#eۭ/~|׿3g"9>[/ݶ_IӺy?zR !CV"4zt5Gn0k!OڄM[ה]^IhE5_ܸ
:Guhɓr+ʸ9ʋh,Wӑyp.TxB(G߅.LmP%UȘe!JDx*
!x}k׾&QD
cß7~.ɺFž
a#{?*xmV·E1ca/y]eIUikP Y+U\&"$"ʘ;1
'2$^YbQ]Ym))PO Xs>(b8)Q[pH '2ؑ<nKnf
)eCY5^O.b2iO C ]j#ZZok"R nz*m ӵAimh `j
^kc<\3JH (g 4uF "pǔ|Pi-Qr #iZ4]Bk Ƨzr2O7<J3@Nleڡ W| 2Zΐ7{O_ zZTL+p E;to% *ѩ 1ر֨dMQ.肽>̳$2<Ǽ»/3$ݳ|.a*5#׹c2Եn\VaP%x'y2v dJ'9p!XL' ^:s@ ) ˓z̭6
 `֚QW? I 4"T+HN[{rPR~ A=ȥ*1uBS
[-sLq9
М,[}?|ߝz2tuRuzۍms7[a ӜĬv71,%#1k^~KnGڤ +6rojJ}Z[ iSwf=|0 yLz]n] m6dD_txZ S]*^
R !߸-*\l7&q2!h8.'NzօcZSfKh]y- BJgǮ&m?d~qR
F:?C+SV <~|YyRyv;/&{Ψ#ru3 p9>
kCb|La *:'VϹ
8N>8<a^,͵>3w[eAQ_Q_3 ſk NJ* )0cF39+.N儜G{?n`BsW#7GN blfuEf
{$qa3-z U!h;:{0!r|:
Mwq>Z̚,|~\Q\t@:
aLnճĥ sw=ɤQlcDXƩrr;½&|H
XZ^AUW=~5QΕ|jsoә
ɒcY81QrV}4EGکjlv\"Oɘyͧ]%V &66)36ft1Ay%@ NRXљ!%m
M]KO Y͵&TFK,I4X` I#Ndi EO-cƒ/GC5il/#eypXV,Liu\Q+e(»󪁛 8V>Vu?QuL*dGI2~%Mp/U:&ݩ2#)捚Zffm>pro9A_2o#O?]ې0 i܄brN?D{> O}>O>2U0•[_y;+`sHjbӬp51Z|t31A>2;3 Z;1|l&#[jiK
3ϘFrB'Y¹̣Z!dg-CT,Vdļ/\.Cy
۷`GC@!/F*WR\GJLmNAᱪVK'
|k36(ڮ:)N z8c$
[{A+XͶB7vY) 6dkV[ЇxG P B:O$R5w
"kmtwW@VtFUCa]BM+g >WyYQohq1~^olѤ>s89 )\“<(H\aT3͗!rP熯 ^"XˣQRIdv<Px/誥u%xh5Qc8 Rj / Ν$
Ƿ ΢?KCY~^cu 7ז
D T7?/OÙ6m.sdQ'H
ٸRFX,1V#Qn#h_qqE;
寛,̅\^%RqU0=J8R;d\/sGZC9{ReGBtkIzKHvc&;W| &XVC u %!!VɎN𥄪0`Q4,,& Z]`BʌA XåB.sJ8I:Id:=JJ麺AY\Zz^
2Y_ 0n9 WyE䈝<[)l!`mre嵄~!xB*wzU&V;'U@AԜtEflzΡ+U4Ɍ2W;qIVqYPl=S/^36I ˻Fu ƤCW_N>S$t]lLJ%i +b9g<)۠),!)kdaOctnҠzDv52˽֟j A
.h96
Pu,]E *Tz=Z;Pf֞gCQ]BgSA#
[+@7:[ 9jD`8ٝaj9|tCNJXlʓ]{s# R<{r\3 #)Nh{j)hVC9ŭY,fc; # AƝT^2%n8%kZ<UDX!V%(܋Jy\ϟ- gsy@6RD+If-) #"soTx68]d4vƨs W%\+dDe-5ǵd
yEТ߄
mveS|~# T-톒hi>
١jmn!$42C<d =(&dr΢q\Dtik[`f`va"s_2 j
0/ (`}/i0 _D'غ!/MxuPo~f4C_vSͣ\<ODr 㕫j8[vR}\`Iy ӀrUɨ Vߗj"M>u dp>Huz
dz/XV[pXԜX$l.z}ˀ** /أw rpw{˷7_E!ݹyg mOLy ОYP.~bl*"qȆGXƝceS@_f\Ln|lMG
,< QTxv:Me#Jdն9N> xr/R[C.fօ}aEaӳzi
@ݑ, 4 0 "62 b#&z]ڻF0jJj<2lT?ͪ*Bx9{}GBG,vA+eOXf4fzpG3|`úNvyLXȻ~˒@j-B9IF;2&oy*q{v:zg!Wu#+aT!+&LᩔaUG'푵_O-Rd,gbqZR!`j{()A@j<)P^ډ$*҉HӾZ*ְ )'ҙb|z'Gi22iO?RqNIl շVpU;6"HsN'_xWMz28) mOۭ0+N/. 67ȝYfBw ϧ\ې!1Bk
019 .<C*ff۔
axY2R` A]ۚbΑF(P&EY9H5X8l5l kl4 !cSʃ'$Cd[`2v@+ ΍z6?SPGe|ޢzZQOcKv27fö"䝿A84Z dMt<ex}H :Q@U_KY5&O?Tԡ.g2^sn緭hHf3<P' ˝N2(EQ3K8o.?SEb$1xB%0LF]U<P8?߇hL8cE$B@B>p%V<bcן}.
pQMas)+b'drZ1NyWc~:=vL8)IU4Z`ӽJjg՚}OK|/_: l .RQ bږp ]{;G!Γ%Eη*s2V.Wi_
Y<kgħ_h(?IiдnX;eK]11X`2xܾxba1"B/$e
K-U@\l,pV0)FfB Snn3vKu

}Pј,3j ^vN1DwX}S&fǟdA@`'~7.@@t|̳9*Ya*_Ѕa}
^e DݳR`=RI}g_
=Rs
i
C#=!PE Z9ʚf,_xRaR}{ 5tH^XP><-τ Fn"P Ȟ-I"2܅7w`mWlWZn`)fˌK )4t`gEg`¹ɭCk)_vF=4L/^D|i7)^%#yX<u5y c(
&QZ
=wբR^X̌wƖdk35NRkP|/kEf'+9Q[b?Ͽ 'vtJ>mu4xaGku8A6b0{7'Ubál64v>#5ϭסQ1Үѻp)`'q_
25R#Cvax6ݽn+S( Q)"?b˲W7n(
[q-\4~!Uڲkʆ%h/NvuJ[،YEK'u!raNĈbBi*#E(H *H!QǕ7M- *0_Nh3\{iJQ59|f7ޕfm߸ rBy6BD@Ah:M̀kp&8D؁iQ6' '*GAg±5箻#-[f|f? ҹt0jGXw+>#<
bWʯL''Dv/q@Q1`TPew?B?(` $.s9۠<(g
,9B[v4nY*cXXߞgGR9h>LVgLV}'$)Zz(Z'A'E|} wU/( j }Npm#;Øqlg}e[%iR>0CΠ){Q`NdmL$3 =̋M2|ѐy*x' 6\oI^,rJ>m"b|#H?HPKHU2Snڲ|M]#
5 ь;d^H)SZ5RמuV'2&e.JĜfv&KHDŽl9` bTa v4}sY]Ұ>=Yl.d.5N~G9:[x߈ ~qMZ[Vu}̿y^q[7u28iJtXҙ+5 /xdv2sgwS;Fr~:2V>#:y>ыL@[I[fTO>
>OzO]g 51Q+0`jr?=uY~Xuځ~k{!{]5GG\4
E>p;{&"mh:{VҲD!L܇"UuSX"{ke3&q4 6K?[d-ױfYvmji5SbN,p\ܚ}QnC6[|YQf2Ϣ+f*LmOЃwGN.wdf9)'@ )fXqPeom c]X>|;OXes!$)Dн.xy܆]ޞŅ3N 5K/#(ƩGKƔ
j{2'rW~2QdMq`b{Qλ輠q%78^PEbT0J"ˋ4bZvS0騭;+Tm<K27_Z#0RCGE>O },vRz (h$+es>?2۳*'"`#> EЕ\J~Ny)t1JRrcR+_mvL֋7˹UهF[Ҏr tC!<\ ʓ Mݫ
@m99
 k$"52f-!5%<yy1Ym`džH^{YcȊg\;YB
UPZM1EJ$b xrU;j#x[G0dx %Wԏojއc!_\ <*@yA[U{9j%e ^duJo9q?
"5v9?|-p?N_D Z#*˨BP
51Y"OUE搯ȟҕP,ԁ^H0sk.]/;#l8xm?J[[3qpyv&x E3Awtٵc"QbѶo@pmG}^pC-qb7-b =q\~fd܈j਼2-(212/j@,5a,!:
dpx DAXO/EB\*~+FSrVvcx<mݸ^L.ϪtXrZ9I?
g"WⷚL%tw`{/`M6€ ip4.˽3S;?ocX ;+!<u6T#x{:y 4Ku!˙/cTa#OZns^kow|hǼܤH!N?K?*H"-@O V]8 `t sG+R AgPFl?jE;5Hц+1Isgy i fQyǺ@?B|Fjy@v}=Jiql#ԱDSϵhzN=Ղ={g<u0n (^GTAT^љ0>bD\L(U09.X%dI`2J,޿t6HkCqDE4igdLHA Ws5O=n&f lm|1%
3A-v]tQ]7oU! ʤ@ sNȺt}6AKp1u?[CW
0{X~>I
kEYj p%-nqQ W؎q,7dNѦ C͜;YX&y>+g!O-
U1@ -¦/X&i
c"*unƟhyK1[6!ZX_) 4.Ttx;ϱ孠Ʃ8}*?خ
Xaul\a孖cnKv?B >]f 1٭{Uh2 pƕm@m7d`8^ _3T MS;Ǻ (3kg".y1TY+Xg!Dg|rnÓ92*1s,H8 lv:/l13*l1'N AgYTa4U #%3fqA"$3IQ5 ͩrW])}i٨W-tc"LMc#I=Bz͚.y5
.(>y=deUw,gI8)iHmMmbҦ)E!Poj8B9Nc 46h^hQKgŕmL3WbFϺ'`R܇O\\gA#>l/$.⭤1h"4Y{)b_}DBMU0yFEgYA(8_ W"L]L*Q
z Ͽ\%2lMF2
C͐v-zDj!L۪̬q:t%‘ft_k6~Q'#.. !/+Ɏ;?-o+2*:)iۈr-yj?L-G x-F_#/>(ºgKRf0iH f+*H)iރi<PeaU45F3](6FX(؄ @`FD]YG ܭqϡ7'[QVTþ1eϣ1n;)9B@DBgw,gKI
Ξb>Q/g䮴<#v#]CLC%.-&FOf*dLBnLUS(̴ź(Zrн`Z!U 22TΞ "ћFd~
~od#uښ84r^CW$<0'UrVQ,;&( l^ ޭ4EF~cF
AAݳdؕc
ڪb4Ie NuaѪ8r%~e)'tB*VC)V[ܤ
֞L\ jJwȈ
ggmo45x
H#֗b:M kZȆ%F\4kVZGげ0߾}!#==;si Sũ0m,Vcq"$zVn<y!d֏ՕZ4
.G@<`Bǜ-S,t4!~_yȜumh/j0s3Mv D/+S:. LHFnG B9a?$Pp WF$rde={S g-®JQ6\1 ൊ*,x=g5ZR:DkuVP{=ciT=4 *IC_Al+]h@vFbbBOҠ|iYR
^E4=_y._ZR[rkom5q6*sFꅱƾJ'@ap䓬^@<|wo-]2N\b B4 -*kOAtUXa(<%LE `neHQ:s؄å<f
; bȚ_iu] `8{8-dB1SNl͓@Ѩ\O*k ^kn w.-O-bv_K>O ԃr]LܖӑM̀vGHȬMQnRUf
# >Ao@8wq t~|!bN#b&c؀ԋƷ5-WT3cݘFG'^Q]2 5ۄnb5|VYK
i d١9 yRx@]s^IRRyξ M# ;& ,l}[w6uu=+Е;,>swa<F?66dJTKo[tK(9ߒgFh[ Mm 聐ܗK\窲eMk2?ߦaGJ\
况L"onGfXKJI/.}2ӯ#LT\pzuJ^GoIjl3 흆sսŵ1礙y6%z,K7:̇A
DFi*($!lǷ# ܌gԱ{
|Ǧc7sx^>
$nX2V_TY~*
Ѭ"
hhC^ij9Z,ϊL +Kueò*fZ]Z&qh}T9=?^ !<4#[7vGE=m,.Ks{m@t6v9|ɓR@czh<jP z҆ <ǖus
LɆ>Y tjy D
zk!QA~P8Dܒx _^@ÐC037$<d${coWySvY);{)7)dF3V\D}~ WOd.EpAVTjCvzOMLT^!P:
gAZ`XCW$ZI޵5X@Z֕ñ^ \(l:Ķ/gY0
6<txyaiƱMuJmٳj\[ֹ,>msDhT|ˑR E-A鐸$kd*rزY׿(_岴f=S<x8B)ꓛ 5!_>-4ҋ2̧Ѿ_d ޳J~RpA9: hMJPL@~w??^Z$m8})=Aۥ\:cR?o󬥭)CZ# -i"$?%!hP_23&}*s{)Nv+c͜n6K;g\%Sdhex"WN:I"!&7@cwG7Mco%m ոȻ#7$qGs>@=>f<o{nUD
3 ז&kQfyp2fK3.f}סQYS >;o1P{ْ*IGܝ{验{Au)ºo+N"?پ|։Ujrhp(|qœuU}[b6)@Vu;:EWTgשyGK
oIvildnҊQN3qx1^"vS>x} 8[7,G K^/]#20L]t vrA"Kb.~9Z~lg jpXne4wLOgR-+7p L7`dghߐ+:)>:CGz6ϓNT'v\r|YK <ێ _%:)IFW8U%{qMͬ{`8*?
 \y}RYKX v'g3 ਡUvPK;‚)9'U`ً#g|@l\Kq
Ki!lc!8s*Y=BDsJ'.)yc0 #gYFGظӳF`rp08%N6{\xBxj@_/ G&S OOb
+tU"6r)|~FsYv.%罱5"\<.*ٗ!O[:_ԿyE
O?Ȍ0\WbnAGl449 KkrF o1U[ 8"*acDeGjms/CE̞ GM$ZbeTR 'ˎ5S%ÖG~]ZRxYn&=8aBLc]%N_|4g(
V
"ŚOLrۂ+'P 8q-#-sL~ļ*ux;6LX"5OUJGlsDLV qf˳V.yp\n&&aBת:9׷Ђ ŪN1(/^c\\<qT~#D0􂃨\Y'K8{t& d?ͪ0Og[a(BG~r 1gЅ_(Hgu? &+_iLIz
:y*]x|
>I+&HO)7OL= U.a讴tuT \'v+~Vi_ A]J3ckY
V>)ҿ$?oB!NS83~Me2(e__ q@8Xu}{` \ ǡg|ԏz(G̓b6 Hא
qoD9)N度:+4lnogp\E n8Ϭ)~Pd"|!u Qh0H!1GER
)ޠKݰnj3k+ +3zvEF̛j bQ^zdQRV*N0<K_d.̟2gp>rKRܘB f=At}ՆWQo(Nl~TB`pJXjS=;<|_fL6B&ąq2oh;Nsp4}`h}Z#X )ە3G1Rxr`)H?8AfdSb"#5OpSS0#pخ]+E96)@ݑ$?3LFKy`|r,EE#NNl&^fAgq~r~Ũ|^Ԃ ] t]cx)xk<Ƈ=<2HxD',bρ f@V]!l ymD:敽e;t0˱C OY ۶ dTR>Ii#@yh6sR__Ӹ5S6e-D}-1Z>:AYj?9;2ng>Ա5jV§7gnBQe8I%h3e gb ǖ6˨=D~@}m!9^g(a{$9[>:׶WX.`M-I/=ŝ*Lr(LaוVp:|I|fYы$޿w'S$sdHWlLSi-Kt˭.d
@QA&EH($9;LȒSpPk;<T(WOA?% U R£{`+MK*}_4wtI織 7M}BrRG `\o]֚YSV\ u wv*sq5d&0MwX
-L4
&ƌ;WębUBhX\OS;CiYLq |o`1DO-@Kp™~eIƘ\Q%C{C;優TN;NqY]6d;'!E*#'f|&
Sn3kܓmopq*٨cW_fT!l` }w~^󎘙0-pQ~qh̟såOFt#FՋ(hmvmt9zđz$
בֿg%</"N<DK$oe+ч"LFV`?TRCh{H޵b$
]=>Qvvq7;ő֧kZ\^h^$&BxƄ^:oāw:+ih`v@%]ঌJw PZ i,*GFS= Nڰ3]#d(['2cW֞(gM.Psmf%S+~u&
ɯb<̙#IP`MA (5lú%mjHƒeʻ;&8
D|{ObςY#l0a>ڧc`JNc'!c(i
ByfpD .i@l{`C.A+[9Քpݍ#{,1B';<lB=f}^<Ƈկ}FN;КqΨvsioJ$R>Qn8o{,8@*BX`"A4{!
8Dzlt^_eNyU<mC!p^T_dۋ.H{-vZ& ]=3Ҫo" &T:{/\`}{Qk<L> W%?gᶨīmiwО6-y̪5` Ƣ.X GxX6q > Wu‚Vg NFۙUiDum(k!ˡKMQۣt h"ď^پ4S'A}(_Ny{
nep Ϝ!} ɫ8gUzW/J=e!w KA~ǟm-_[G<#)saAz {afFk gFdG=3D0S;HܸO%gHԲc7[/Ըlz}-xK*Z8(plW
XRbUEl&e߶7w BgK 7fqE:U񸰙zgWw͚7Vt"PQPw]h0o.O YG;L-c32gd%0Nժ#d84ya1 I6cTM|'BRD70Ml*'s@ xJAfjKŒ0:v .-+@1a,OFnhzPze-|?5lid^g{OYadDb;[('o)s%BF)^EY2#>ST \d_P3QT]~.(Z
꒟\pNK $T^z ~e VZ^!mNV !}+(b}*^֝J]nvgY&jdfmⴺv/Uic!nOŀ,,H/eDPB:A r+-uʽw:O}zncS/nѢE$#(2I~!v*VO6Zފ< p҈I <tN^2H
jɀ+G1|N+9n[$ ߒY\t']ښuB/&1zz컻}sUg!"Ua]_1*hTRE}~ m'sV=Ow_ro S'WqJA0еt7Q0.g

^ !+|ZWLF+S܋%W!4O}S$}2`^F-YL9?R#iފng(@ci*>ɢ><.P_%}x2 2RDgcc\1a:uVݹ>`b(ъHw%>#jrD w6'D7Om5*^ce1`"+?Kw{&A0UBu__Y5 -HC=DIA8r˷Yjٲ%۬8 Ce~
N6TAAS:P0i` ޸.Zkު |MQcGW&o6;:$0]H25"lE@! _͜1eYii Ml|CVX'|>٤/m0Mq, gw1l!NtCEHX,'zZqTǨYɑ[x+ŠNl'AEtFŒT4ډ5jxwTzyG7}*t!Pe1-@}P3*R2]Ix{үr/pN0f0
GAߋr:
JnYZ
.`h:9ٯ7BԿN
7;^À+B5\\-5(Fӑ]Z{f7I5u:*Cb<l],%1QJ&J{o@O7}*wON+G"8VK5ًtik {F~JQʙ`Q7TPuVu$&
t2]\+mB.DŽ.F+24샭JEe ;2 !ݒp0E.ߓzVl_}s+yJ1bQ'ja hB
Y'?<v:_I᪞zF!H+3E>*=(4^K.U\>AS &9Qu4 *ҧɳ*0sf<i3g%. "RzÁs /IF17d#7<GPx53vc);6&0>c hz47wxL6uAl K.XVU.($"  ^K> /qT⻨@# T~bjcG,잌hsWw}"e/Z |W`jꢥt [Kɛ$ZdT`͸dο3)φΫkswhL+ 526i..zNNKB
K]}%Q):!O;67]>!f"ʀV;,9#fr> wKQl0PT䝿H3#)KymiVIV!u?GE'D| #j_(hj[<=[GM={ѯu϶ }ΒrWZ'#(h
p v]4eR/@*4잾P}wL+s]A!DY;B,3H…]("{ɥ#Ǿtfv?C{ltkWiK[z9MU1Klfrii!FD|1~i [!tutC&k}Na(ղm$[*D*|~_F)U?)* /-,iA.|~ |8v)v"T.EQLu芮`R3BSgFn~ba8OvM5RՂInSexܷN^ҥs <͕S]{UCB'|pf^Lw0-a=wFuy.rRb0Ц=F|LQV!N\o.c/ɕOF˹@RU`l(ܛ_ ?3Q(
zWve5<pL<spW?0t-|` ȵ&hѴkqb|J1{`D4$;'KV $e<Sj/ó*ݨz<[E 9'W?} TkN +60YIf1YA
6B+usu~
hBek?6`Cη;ln*Kk2My_)_4WNШ3l492,+vo,ؾxM0]tsKj(.ajr.ľ>)sS0y}Jdh&Hl= e֎F
G9XXQ..Tz/;\;'\lho#CrLbIJ=M)ޙi/cp5h0D[BoWou2̤[u ؟ Z? gDb#-Q8DaG<ǜV%q#9}U_|5H+y(G$uS  rȘ/%KHM?)bH)?.T]DK sl 9flo40eTZCes g*:`Խ"rwZX5 NRt*ΌF3)L$0WLb g va֕>.D!('c Wtp;^%bt6>ȵGJ8>)][1Iפ{ƒ<mMX
^?| 9\ ;1Q*83Gc"A؋!'&yAwr=#)\oq%9KF=(ԈUďqP[Jhڵi\dLXEèamZ eckצn=Ths:hp(QDt~X鷏,GJHPb52~pg 4-<Z@Iw!?b-zum.*[aY-
YJbgeYT@Dʼ4P7aIXMn0!V2:/B,Kѭ
ІaRZx&фc0C8|=(ut?Vϐ
aŨ ue:I,).hBM+R,A%t-Wܡl31/aв.9iNTsWhnӛa? l0y*SyI[qrb:`f]HBYfNA^^
"bv|Q1$e_%vMaY~@+mOV)
}9Z!ԆVW1LIe+}epyAu4$Z=U0$<]DW –f3bJe5=90zM|\[nNKn5Ex W@|`)mj(
t\kOoxGJWeE9'2Ü3ָD.{1,AXD`OGN1֦o{ihc!0im Mb;M F(pS$K`T;l:@Z;4Hk8md<rխ g.˫ew֑>Qei|3S7G]xW
~]BL$i%یKfQ F'4c݌Sh݆zzTl?wqr4({wURwC#@@ݱ/LXruߛ4LnX&H]:KzR`p (S^R^%)heҸWOᰐhXgfzK6ѽ肮K㯁:0m*⼮gG(AL( W@SWl! E6`a}'ymxDU@8I .zu"bI![?0#yg4BE\TivPm}_Wqee14EV >䘳{4s=ϡrЕ<R˙Ale!a$<l5z(
]Gg[hfu0G=<zBDՖT
ޮ+:BrۭۭR$ݗFH`N'aRW>}d\DY<00&T9Xɜvڣ"+:-'!!C\C"3K7{%l"sbzm;KPIj Ӟx=,<[v֏tyWh1A:hGz27U_9#ϫh4`j=+Ԭ"R\x3Mlv_~D(r_T~p—RMzI~!OX'j=K'/z(^&]6aẚ[~
 ӹ_durڽi3~4q,׹`NFthP?W0PehƬ[%46Xs)k渆M~<QFIz<HO:tS"?26jA],#p<Ԛ6v՛$63G%v2GB aSOjC緩Ӕ({5's~C/ asehZ .;.fr"1t"vGğYRH\hmE؅V ֪~W!Y+>!*%@H],J0ɩ3+${C3 T]{9he 3{M]
Y?x,;v 0L4
/p߮I^hQe~A!ݚ>؍'怲SEEq_kaΙ-eG}'D׶ .rV%W'R ~^4Y$J2=Z7VKra,9-ԩ.2#ixsUKbͰ
)0L=%MFfGH3rtb2 ڻj
JX넛[$L1oM7rQ· aDzK3
\3|Y 6SHi0*-Y}2Y=wIЖ*1sFm
6,knޏ33V<y%q z,<xsMJ-Fl ]Nl4 z[ڨy_b
0=HxJ#?i[e25¿_  6S+s
{6tA_%)m'iP):4*t C喿(:`TY0bio삁j-E֟Ef% dlq{^g*?l|{4J>neߟ(%Ω9ā1'gOxkW6P|3Lt6$%+R` s 0:[Zt"J`Vxf2nwܼ?zfu^M
/l@\nIn)lޮx4{t_n[P7l>d_@r׵g '8(ESY XpB~"{Ɏ_GmXa $iTdÉ[J%)D"O8PGV57.NC(2-67}|
쏗l1A)JtC(²%bB1j+͕@a @"BIsQHq~8wK[ Y԰omnbR%orUeh%# Ke6vȀf
8uQG- ٓ3 '>~Z`B8~ʓlG9?͢KH&2p'qJ(M5̉?^r[8<V 2Ry@l#6iw5\pk?6P2hJ2&2 =+ c3BB7ckcuAORɅT
:?I]UJ=GH";LY'uŌA`{,)?dj?'Ӈm?ICOX/ d?
=; L
n\~
2bnj ;, Tɸ86"F74&<pf^
x)&%5PBWy%x'VŰ@] /{i
KS/;5E3^V
s"*[# mY.i7.N(GmQF^`e+2^Jrv)vsT
pC/)boȲ@S
t
ֆ#JHh˥G ;k?J
Z%qjD5N#37!A Mh-Bi zɼs%s[H
P96wMSiz8 W?6kmvD.ho{n皱qH~.vr)\wkEu懪OA+
|rT쟷N-{MLZ˦? CO_뿫^d`=+y2+;ߺiiީIUt"օ_Z&7D`gsIQ5(z,'6€;%E79 UMPٿtZ<8sna}zoHd4s{KsK ucv][a@E&:ߒE.ѫϖbjR a%G--q϶el>9B<?)[?
+HT5qܶ\DRY
edpX5z'iP
YGegD@}RJ ֍(wWbr#ފXM0/Ff! /1[$L[jyrO-(z9z!~ wOs“GpC;Yv\'<*H@NW0"(4պ1:wJp3mT|
b P$?1,I!)lQ4FXhŖp\Ǒ֓v*d십 z_H)C2nS=b$
棃B(\ *X6RC} qJȍxQ/hNy#FRclEQpsdʘ-+ .9uY{*N%Xkg0Npf? bX׻6wvRhi.S]1z vg^'IOmpn.$S8(-GcRۡ>#\BtG MPqvrqL#gre=ޟ4j X0+s
@jzH舥 GmS+ >cv>A]yS
q|pt}Ì0oO$脡b5|ӞAo,r1F.#G"
T}CZʕ sFKQ6nj"_IuY+%]DhSl ,ViN
F|g=_V.U8OaqDn[=*F 4隋:w-O/ץ;WstϋLoEh!#fǁt8u@"#׼a4j"# dκ?l/)ȼ 4$} m*f\&Jw? ]2_C;]0 ^
uh'` RJ*b%,^C>mX_ Z-,uHbb"%!-N:9} ,Ncrz`J/ X}S7p媐Jd 5XY'vpJKeHYWy\'cSR뭃`!KJ){\_G[a`urn356 <È΋{CfrWR}į%l;@Yz#:ֽ=h*)*}mF?䀷&l)Q ʸv#ݧmZk"gU}hL K0dp=7} t IN`
G% %yz@+Rkt7y\"YTa[ncAH|C{0w t[d`L ~)nlS{͹4^275ww2XpSf)_נQ%՝ZA)T9U~R0R/.lW}bmL=C ԥEqAZNa!8v5G31\p / + :^~^J0ɬiYk`{{qӱHǵl)xF6SYUo@x)- 4S]8m28EGBZuz,e xÅStɼt(䶆GW,Y&HMQ?=zH^Z q.r]֭1,a/%%w} &3fA_⍤:m
A<z*BK+'>
@JP!/~ߟm{=♺qQj4MuzYd .HՒM@v7V֬b$t5c]q&\C+0yY@9 8p0gbwfEwC'zݡg
\ɋ U`ni0;*dW 8T B2<^.&X^@F5qxZYx%`iРp $ 1
|YwYP0l3i&QcNsjP .3R9a4ʞ0?ΓOCuLnF!)&nJR匄0 uo&ֳE&otv)]GՖlAA0K(~ ^=pRǠ$&a9Ty/Sk$aڄu:MrA_}-GcA}q嬒S`ʲ7ڗO[3iE!f0`D;;ȏvmDvιBmn 庿ZՓV*wG\;9\W\3T EBIꉟdG4@-l#nWwGx>&jDal$3vjkd
V *#HDKmL7OLtN1fqz@'Fz-+iO `B}" 
Ng -zfB8Z|˷UF13\Do~آ@JB˾'*'|yRv}{ \#$/>׫C3٪'๦#2 ] aW:.j!+b^4G9Cv
 mpT- G|P\L 2)=2X f=iwķܒ\: >#no)M(iZe\nxw{r#ADŽa0N;HVE+_ .iҸp0T.S 9 JaB7Mv}*t36+0 m .-#!i{X ='V#8mxb,%%yAQIȫp9f&:Yqҟ;$3;?MCU96
r3.2jB'eFz.nW+;0ҝ =ӉbTϙV*8T֖ +־n @f 9u 9xQ
Oݛ`lT"OmPqM~KH lߚ T.DO<V9PJ??8f$ hUB@3m
q,Dw~cP Q
oSU<f IkE5;$?|
Z~!_{lHQw٦q71w]ЯEPw:R?/=$>hBDԄ|b(r_+/u30U*o M{R¥@AIh)v.&g۩V{m8>>MTF0*R()Q-g7}K=jƈI'J7:P
H@G684c׃4 zE tqq-A_3ýoڸRP C,̞Ռ5Cs NyX36DW(/aλqjf$CLQ# &\W
Pv#`-T|y 6~(Ǐu$4z sҳ(jvrBvP.)/i<fV&k[s<[kHl$# bZԶ_c!  +7&E$ bоK@f"y 9z\
Z|" f"Oڎ/
?3%_0Ta(ΔTx%&C+ ?V01Nӕoo.jН慶܆>2\O3PLRM#@ Dv@ ێuBx|t=uCSڀ+
ڠ:)ܡCpC$N4Fa& ёAB ʨkȴ aMMnҍ,$~@1-R~+l3}&n|6Ab/miFGRL5'`{mNwwmvݖ%,7]h}(e
@N̕A`ʍic^ 4wkNOԑU<ꖇt3O@="h3V芨;zylfHʵ쪺յHӛAz YG[ڕ0A&"s'sy66M>@إB@Ԣ +B:S7(KzsA &830
pˢ9S2W⁕=ް?ﮊZG`@i%ĖUwl*R_:)諅Keͭvq1)1_eԺp! ,d3= XZrfg)69l(>Zr{7E`<xmL\64 rBeX5oxsJAmq02_˞"r#

*78~.sL̾?ƹ`\e$P:򧤻@_Tg@q IG'«vU+΁0YPBR;囲k1r}CH֤r_(Fƌ@V1{fӾ7lp3;7ti{*j 5lLDfOYVMY?AeQ\CqP,Z<NFi)o&}'0DEHQ )&N0iG*#9KSt\r-!Zqx'U)wٲH)6J@8wy)9aGՃ ʠtg~~e XD{5L3_#pE0]vMc3&9r\%us{Q0#]6ЀĤZXBY~JːYzmkRoXsQ}"&A@+,ad2t(kd|yͽ/Hx=@0:o"V,J }y <kr+`3*t})߼kQq .GeRwhͽ5jKEPcgLWz<Z:&i&7y~a&IisЦڏJ!?k6Wd_6SE 6\zM>VLcջ+"\#(CU&Hvqcrjbۈt^3
"Cjшd#w7*nr5R7Ζɇ=W#
;QBʪ"m\Ou9j=y{85 Bؔ ERMF/9*yCa)%6+ޘ<
?o;nu]c1#V@%Oy$-"$Z)͚"6ZKGj,p4d/ OK݉Yӳ<<(IPl%T.Zg;=bb (lp
;#9ZoV(K8㪫(mc?E0c2EpFھ鞑iD\2(HD矼:ǰ9 gI7Ld :"*sw@ (`PT>w@`A;&m-O~6pl0UrTgy`UBPާ)
,:l C]mxzY ,?U?
.<ID_
5^ "8[$=jjL<-&&9ۑт L/wЦ ,33
. &nO;r é(Pxy=\sȲ ,s! MÈomv:v;^s-x}%}>g4D;70N4,MtJhL&S!B׽u6-5(nD
~cm͵u9~k86L- dz9Yo<Y֞Awj9s1 z|ٟ/x.&v'I 4eNߵtj zoxxZJt.qJK?1C7Jpg RZlZ̑)Z+
ژCeS@|-%mǓZ;qrJux=ҽIF,4W Z[h:Ԕ^lYa"ѹ;YbFhz4*z}] 1'VbkW^ZF
@ah>z"U,0{}2ϓ[ ^'lҐ *ԃ[˾vj0G\LU/a9,ȰˌUo{!%}]0WrgE QiCzn@};p4ւR)udOx}r.vd[ޤnC8&b'K\N2 ՙqnMJă
k3~U4{(ӈ<ej1U$(1\ͧ@ib:pU~>nʀ YԈyT1򼇒Ą/}hqf!T;*=
Lɚn>XϛۂroJ@#଩2cqTܠ dQF(82>R'A<a~9+X gۡΏR᧵Ke$Ms@l+:*kqݛ^wR~=#E\gb'95M]=z]
L7D}dv_ζ KeIxkPw%FNVXcR4i$:ic
u{px:~zm&p6`IZQ| RR(\uoDaGNiRja8eSQ<ɺyOE0]ՏఴlڿGG.vv |Ĩe@6[GHY~ҭL{Qݝ; $Qw'UZgLcUŠsBɶ+Aꆗt(!hAAf|9n~8돾nh34Lj3Ý; AVv憃_ Ȁ=&Qvi:ך 5 ?|Lg,غ0z/`Y@S"MrONrttj <SQHJl8o[Jx+5i5+j.?FDvڢi)'e/֘$@dgne׋ [KOgJ5Nu_*M7=(ޘ{ټi@|57ӫaQpOcch??h&:"ʐ?&a7"jFBXEbޔLnC8sy2VDJ V,>hmUU0?D-<=\|[8j؜6)c|O-cQ\iDZlCG!rX*$eÏXQ~jqc
KZжY/Z/w54 Fٙ2dEҾ=ToUDS!<AVv4 IZ-/AD~g$ ^D_dvi(
Cgal)' ]ȗjiG>kխ`Si;{oFPjo>=_w=C8N` W0KExYJ;VhxzxSvޡv ;|ڽ h{pn) n+nI3VpD>,]hEXNPW}jļIrs%u`KSiPT7#o̡qz*m.@cz:xx߹M9{f >WޒEvv19LGXGrC^WٴI"KZ];m0犪Sݓs`AכtBjW\͉EЯvZ@<w
Ob㎯yvBvDA
sEQr%1&k.?L7V
2Y-3sl2
H9X]/}@''C TwYo

#fB]߼R>jIg<%/BK9f{ت$7}Z5=*+@<8f+9.Lȹt"_GT49Q\wFuÃtcI~&݃KzO/*PE4}Gs;gZ"2t +a-N(T&uI^<kYzc1~ǹ%@wˣ
-2I, C
 ؜/,.*ds,.ȹu>q&rߓ{?K 96|C,"-|,$FzR#0yn g%†nt-Mt49Da[ֿ'#5!Qka޿*N#X9\T;[SH'|_G  Π!o!8yb4ض|FElsրHFn4ćos*HYӖVdv StrzUhpU)Ja({esn׊j0 
)<lmnM[%;> e^@2DG)x !RJ\iW˼}#@E׎-Wh٤[bdM>p֎'k(}Ta]HV X$)X|yp6/-ﮔ)gV$͹ko~:蹑ذj<a`rɡ%Rc~=VHv"
>rB< E婈p%(vl8f%\;U{9;9wXUnj%E0Fmf =5UTuUs}Ed?G;4N:
]Jmc,SP46'tsZ{iO6*k;xTөH2MCip0oFˈ,5:>k,`l&odu^v}`z F(u؇_x<~݋<r
Ƕ($-G鲗M|f}w C^ܺYe]/.+&cX -/Abdj~2 Ⱦ.ka&H"9BKq@֝՚Bf!5.DkZxm+|PwbbOʛ: +IH${B+"lby]lI2O3X|0  R럽>DZA&fA$l"mmNn \=@w<X\Y NGv H܎n|'b:,NlN d n=ӿ<C9.ua"E~w00N!)"Xa}`A6;AD"`LY
FN']T4ɤ(,Lsׂ-TÙ&!b
e嗱Ffa 1k%0q/Yd3N[S %8wֽ'7 {5mRPEWT@n*h;b ^=<ڐxT\`<P1v('7ņsɰhU<ۼ[ꖼ#=~[H!
Ijy;gcy'B< A0:WpA*e[/ngpERS87bɔ~M=U; x|OG,\pG)3hj'Av
I~&XU ;wtR ׋i[ 7?4Jc؇,ww$h>36-=:උ*FQ|jT*P @
4үbޭKϷ߄\`2շ;ڄaÐުa72.FL;MxJmF_*6<5ogٿJ49?I9\S.)A4ƪ6/ s?sw}e~S]WKSg1V@
!/eJzk _<~eOfx[d|+{?>QTBH
>TF۽8
V @ nwdV΄xZ@7Sd{[(svb0
y-q#n zs#޹q:>}ސci6 R<J>)HģHy
l]4XvB{Js毨.?Am3S;bA'2uu($Vґ$y|,9ZWzc"RMe!dD2l#O;z;-xv9V*l
Wo`g: MnE =UQ

ʊ)L zhՊXH}c#W^44wGf7QCHFx@H*dм}16-/d4Yj.Ύ~3#UQqY9:Ĺ2^tRHP/WM5G3z)t)~Vegz]&;%Y8M"pTYν漰G!(.NFc}|<.DHi^Izh
Nc7S4Eq'ëyzϗf;{ M}wZ<? ba!;?l|u ^O)B*fI@?kN&}Q{A*׮!Kr\ϕ |֟`rTcmiz" ;NjoK)v+_bE<n?A]`c"e'9I.a+S.,L/;cfCQktPQ[?MRxm]K"$rMFi@鐤-
+ku;36Hik%5א+ܗns^H9s3溥1<R4Mz(]*&+w4ٲ"f >e9!k$nLt  D
U,pf4L
eeH@t%[<L(YZ7,4h;5+!t1&d
t"$?!VH] \HQn".3C,Y3jAw
S"DŽ0;wӂZpM @ ^f\ف;лQW}SZ5a!k颳*9_οl˞9EJ U3Hՠ^@)CJ)rY".:)T0Gǒ*8sN6Iz2!ؿg.a؁5 Ԋέsc*<HY$m<.ׂ?UՃ2¾R@ V: E{PeI6L)j/u J-JjrЇm~&|&.1iO)".zހ%-19MeU͟M)
tMg׶>%xT6~}Ɇ
8f@Qd4
N
MPX4m6msdf-?J_ qͥ=v!1?tO)T
D($6FoO2@NEVΦ/HC$ڨ?0f
flTۿ82g\m{`Li_nЭG
SCXwE%HxBc
3q#d+>'/3\HC5HT=s Ifw(8goqM&x1&qBKDKհW? +Y`Fl;GA 
Z^J= b4m!.6N1Dw"Rr٭H^b!-n廾ζoMy)ENTX?cۗH>F"G&ߨDžJFU:; a,hR>4.sm䗙UGbk*:nP`G!չe/uH\n9FL឴;C}rxgMNDWIT`_5Nz#lt
4<Կř g(}=CHLjiz" PI\A')2wc=Kr5~stKWN;Wma44sF#,%8{ )l|\״x#.;nɗ)S#Ч@~Y/FY[@f)q*mEjD2QmXk
S>ƧdgWqj=V=SX5@J>}ѿwnqSE>.E ViHv (፷>(b31`jKApxM0`Ꭼ{ lMYMy%{3|cv!\xY%_QUͩ]s_V}v
͏!nrN- XPٻyC `!L%v7Rr *qkȔ[,YCwTh;|l}Lgg{ĀcT+#ѰD'MxFCe*W52ș]xKT!ZHV@MgׅG)p'5M317q̝sT`~GjB#FTҍBHDm1+j^
b#w|YtFPHUE2ZhhBq''(a"v
_0xc,;n:* "TWM$[#1Ǣe'Pw;>vOUZW
0~ڞU; jT6zjgX?B) Q[5q|BUN0Ny839]W:l՜ jG7UX΅g-p?dÉ'ǯ`-U"?!F=\.&I^_(rUd| BQ PF,´ yuv=g9!8B#gΈ|!_/^< R0np GMԌs֏ODs1FDrLF5ɮf MxZ_naՓˣCe u!<E+J
!<sy*,'"8pK;畤>팹G鴺AվbTY&EiwbqE24'/8bm;8gjPl %Y✸T! "]ۍp"c08G';L^2נ6`z7D}kek0#j0i
&K|жêvz(Ehw5tlM+%mJǷ2f
7oIͯ/lH{۷;Nm/6evr+cP \{y=ɞ{؆Vbzt!F{̗8 -ŒvD>vrhOD8iW"u>Y:4^a>f᧺́u0 B8H(
Ͷx MR(;@%ޟ
):^wpxBj`7Բ1&X#v{4 ̀K\ZQy>9æv# gn瑋2ɥDݾ&Fk7r{=5wq%ϵ" ڎ/7wR@_t]\cJav8mT5
ǔ}h-yG$c!7AKTm0n!|W!Ia/l~'ȑOy!GtGV!Itbܯc{ 0sXFH)m7kԪuKr2\m yU(̪) ۀj~Iw~Z,"RY)*#EK`:ͫ(u\c@&4nC[*͛r`t&_9p(=>:\3q9⚸
/al#~Mlf7>qfuc
^ZA\uf=}y!UH-֚ZXy+
ϊâ?:w1#c2c N[Az {~ <^&:)u]Ԇ
>n/>bȝlؕA` X3g+19f/U,QG5OaH#CCW'qZtsK۝}헷Jި,ӈSxS([)5Lt Wev)ԃ,~+e#ye|B̙J}
ANyމmC+ &~ H5Fa3٩(`f^iz4=23f @5 {p 0&
ZC]h%ro=Zberxx_Ɋ:PzSA`YqM(p0
iܾՂe]1J!T1 RoAhC\\*L߮Tu3 d|k=ݯ'q,3L2ވZaۉwR:zADE{gYY@ïQ pt殐]Lop`?-FM0b8Yo<_i?#5 lZxMLDH%*Q y\w̚3͙BLOۻQ/e!o}@"g|yM NM
lZJl0M
d?˛K[Jr|j{ Pms\gfąc)Ll߾ӱf}{Q`V3/@uQ
L j$`
j) HpALapVS?/i@h3 nS
Ee[vwIIvD j
ISQ
cu1
`"d5gOT)W٦&?bA3 B צp. L*u+TS!^1I遥DgK
;UJBD
:,M.9ɗZy12/wO1R.aD(}]m ЖERE*"L`ؽCGX$3z幱Ucnq̦E'a ڻWh"(`µ=eW:e%cԒфì6mPYa3hzq t_IJ!QzebՋQB
>F94󨕭<i˧d |8 lSBݠU`ɡ*8Jla^<σ<mPI3,WD|JOj,FGopiᕀ6$W-ȉ7vQ55ꋢ'sv[G98xck `l@7+_8RQ窾{ 6ǰns?%bՄkc3z0rwg kR3_W}CZyy)>Q67t|qZ'Pk 7lά^l[e*~9[R_
<SnY-~s#GeNm
N?u89V%!b] q<PFۚd&u.Yz,"琾@h.P6 ܋CFLf½U
s
RD_y:O'Q@.:`6CK4"P8*
#B`>7<Z:z3*$UYTg?#7\5;MU4:zxn6#.9l2V_Iv6fi8>?_{B7Xo4HfPHYthnXg3y#ט;J+}?K01-R_(q;"ne(%
c2J ;kognz^q'Mߓ2SJbpiBȓE %!gNkZza;`IU)dUn2J$kE,|e*ThM.X)[0 I-&@ßds@GKۧ(xr0oPKr%8Ymi`8Ѓ;Q!3Rܹ
ȋ`R's
_>j,+vXH#>J欷}\9JcLc]{|#^eMJg}=~dEwLG;",ӟ`4P-\bu!:S;A3qʬ=Qxe>DJwq!XbB<>ǐ̷Gd~ZW0 dfY'KZh[ e"µ$7
fNMZf“9L0Q Z#V$RjߥOdRmڣ֙/7++シ7.G${qx`)` -{ݤ"%RIxuf6M_G&,ՂX2GXi-v1)jj&'3I`ӳGHʣ삅<=\\2@mNQO)^UQ9 6e<فѵ<>$۵k}5Žc?#w(7XPZ+醎W^9J]^NQMp"
DV786SKQ蛢Blׯd]jM?_h[<]7D8B 0J{)5)mj1c 7p2"a23wز:o eTFDUgńF
lB6ϝ`GB,5bx`wјM-5nhBfA
SPĨ6c %b(=!#'Xk+b֢{"G< x1[kz0׈eq_wZe hs۬όs@ bF2|
rnRuo ާt$)cp"0`7e {o
wubEvT(b#{{
$*bk+66s՟K$zB;GK<wIŃL̈́C
Ml^ Tlls"PyPm dEQۡ4'g
Gx57[(D
w6nrZι38s Oa7~.m5 3fm Dž] QG%P$|oRJ&ޠN2q㐪:>,̻,q^42z%/ ev+t`,I5ŕf fB[+IR+M%c}Q`0/ Fg6˺ 4oߋ7ϰPbw
˽H
h$qn߾Jo"Ot `Fn>gr hŽį C{
*hݦ04.jU@a
-OK<v^ ] DXv:fmC@l1cl@~#w%@pj_<&Ag.-qRT$&i*ZOΈ!6BI#ϊN>A~?([3tUI%?otU9@9 -}W|&LSU V{6[}Z<ҫHg/WfLT#rūhs u@:7#Q\iJ#.6B3Gx)%as͡"Ih:z{uWauduOw -) ?μiS~k>qW  )q,\Ѓ'<gw!qq£[IXpg76ڄ?^GlͥWq>xQa3rXjoр
5´ <xKJ?혍Wk
PPVyDB9SE!RQϦ1\J8gN?6brA.)y XKwL@4t*&!
4~+=)zpo vYfW$<]NrfyF6>aѴ=h32Avaƽ<U>YK]Aw ϗ)XoWHXX;IQǜpQa1iK0xM;}zzfJ\; xq<䩚q ȢtjqN@ ޟOŸg%TB9{+h;ɪ
"hA-d)~Dd
:"?ʹ;ԫsdq,Qm|W)Uf*8¾=-EE$XY:pL5zBYbԘ2ΌA夿̷uWJ7t
7k^$>6h|2ɉ 0؁'(^"i%TYd 4{J!ɔRO ci*+lᬗܩDMrUPSͷ3؇\dŒo?T~ôs*މġ;fH_$K$ee\j7?܍Ѻ2y@F:Rς `,  ]XOw b26LItjcY>>2jでZjq!f
$<r`u <:!Y0+d]cN$YJ6^ҦpRB-w>Ӓ.&*Qo{)p Ȉ<"3 {![NaއO*C
(=u ci0D?XGI\v~jDϘ)1s G+ab\tNt*S`sFSaDHe1?A8ը(pp6xiMƘ<||:oz @enl|Ú XE ;1CIZ:7 Jw~W"ڀ$) g7ZD
=>tG 텑c]Soz{u{[ZMm,
qR >%}haͦl<< l^wl#+v"Vfmtd*%}ZΦ9C8=-<Ქjρ
XV"esWi)%22iM&BgHvFdƹ̺zmLw~
:J^KL
~3,8^Xu2Af@Ɋ PwAuY]+%i ~d5" K'`Q&BX/!@++9[`**v^3פ_= COxp]
R <IZUDY~nBb5_~{qȩo|+YΡ6=2m6Q*zI*ya+H*_ʃ9k֌<6hwE-;(z?ﮓ#yѮd
,&]T,W'w7Ö\QoYM|j,E"#rǗݹH"n2;%i" p^A+u%'azND-c㾗|2lZ$#HK@ᑹdq#!q3Nb-yhmd+M50 j<  X    p  
0   x   
j<        @  h   j<  `
4 j<  8a
4 j<   pb
4 j<  0 c
4 j<  X d
4 j<   f
4 j<   Pg
4 j<
   @  h       (  8 0 H X `  j<  0 h
 j<  X Xj
 j<   @l
 j<   n
 j<   o
 j<   q
 j<   s
 j<  H Pu
 j<  p w
 j<   x
  B B A B O R T  B B A L L  B B C A N C E L  B B C L O S E  B B H E L P  B B I G N O R E  B B N O  B B O K  B B R E T R Y  B B Y E S j<    j<    P
 j<
 (  P  x          @  h         j<  @ z
 j<  h {
 j<   ~
j<   x
0 j<  
` j<   
 j<  0 (
 j<  X
 j<  
j<  
j<   H
 j<   `
 j<   
 j<   X     j<  p ؘ
 j<  
p j<   X
  D V C L A L P A C K A G E I N F O  T F R M M A I N j<   `         (  P j<  x 
 j<  
 j<   8
 j<   P
 j<   h
 j<  @
 j<  h
 j<  j<   8
  M A I N I C O N j<   j<  
P
 j<   (
j<  @

 ( @    wwwp wwww 333wp 87w wp 8 7w 0;rr wp 8'' 7w 0;"rpwp 38"' 3w ;;"" w 3338 333 ;wp 8 7w 0;ss wp 87707w 0;3spwp 383703w ;;33 w 3338 333 ;wp 8 7w 0; wp 8 7w 0; wp 38 3w ;; w 3338 333 0 8 330   ?        ?        ?              4 V S _ V E R S I O N _ I N F O       ?    S t r i n g F i l e I n f o  0 4 0 9 0 4 E 4 >   C o m p a n y N a m e O l d T i m e r T o o l s *   F i l e D e s c r i p t i o n 0   F i l e V e r s i o n 1 . 0 . 3 . 0 "   I n t e r n a l N a m e &   L e g a l C o p y r i g h t *   L e g a l T r a d e m a r k s *   O r i g i n a l F i l e n a m e "   P r o d u c t N a m e 4   P r o d u c t V e r s i o n 1 . 0 . 0 . 0    C o m m e n t s D V a r F i l e I n f o $  T r a n s l a t i o n <?xml version="1.0" encoding="UTF-8" standalone="yes"?>

<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
language="*"
processorArchitecture="x86" />
</dependentAssembly>
</dependency>

<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="requireAdministrator"
uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
J1 z B  N 6 & 0 ^ . Z   a c ~  c F O Q a  ~ Š N zO zX Pi  R a 2   ^6 B= ? zs zt n 1 r; {   ~ f  



`

`
kernel32.dll LoadLibraryA GetProcAddress VirtualAlloc VirtualFree 0   0XbE+w%J̞̬v H0
Uru4<E9H8eg 3BSVp WA0}yEȸæh?KOu6E >]}U@t2 W7 >jyYu~`U 6 7*Idu9M;w3_^[r#MVT=<s$ȀM0:ʺ應"9> 9u <p+0S7(hu#jY*MF
Bi }lzl@|+PƄ 1,eu0 nEH]uu s^gP҅:1)H+Ƌ0؉TtgxsazHu6" s1NniBg|vU S +2
m Q`ɜ-Ŵ
$Hn#
DCyjN $x2}HESȑTi
\0I_VТ"9hy5DB 슦1)4sҡ[FXCU!sG*DS,u`Q!?U${3RL {~* [b)+Nq(8Vd%`ʧx 2z7T2=H$U^YnboekI FnȄU"%
1 m 3NpED"1Z`Ca&\.q/3X(Ceb@Ay_sT]"QC4ѵ|ۤ.
62H^P>+,"nzogmFrjxY(X9>y#$С.ih$ us@Hp?,a},}p@
C?;9r)
uЍLؑH3G}'&ڹQ `r%f Kn|?}Ck&q;w5B
+ϊJ>>FA.Jt;rus91w頇 3@DuPF Wj Yx_hZ
}C䆤
O) ,PjWÔ8~}Sʃl n~9KP _^pݫHPZX@<p 8d0W
`
Ӥ,bd5u"R$j7j8EWA89c0J T/R:hʠP @ V(8*G({Ҽ! DSWV܀
]L\C
F+vVo&v;/2{HLt^sDq#ߎ{@<X/oiQFߐLN,+K$j@dQ7!'
VXrsl(@$ U34
OfQF Gnt{T͍l
Du:-cWtRQ1P?L &ÀAR>?¦
j*!H1T P7ޑ%u,Cn K@Fv҉ %)WM7qHȢDΦ; F ]^_,[MBI [h?9Q"M!Q`~at?RuXP3EZa?uůn
Т͉fp@IL tVC\5>X<t
H0 P8.UF;u}$*zl@^ 6u;<}4Fk,tȊu*:
fa4E0A^RY5Q 9 4f vRPYI?Wt+A'nPPCIJ2tMsa^}(K'->{3Rч!Z-6;2=2 @uVH0GQRHVܤdT)}&nF+6^ ||FbHRKKr/Qgg@tswFQ)6 Z>;}0u̟@s s}+ԜI^NE @-@_$9\u
t$ϢC`QN 4~!{PW QSeAH#w '8sms9vbupE %АF,NN'Y0sNhNcD Uֳ
nAtDR%' %'#j,.A֞f|Q@eIZLhl5oM$TdQʄ"o*0+6;M @fA:VkIm W@<HH |',`QvP`:Pt,xQY9ce+)
fz"2 %3)ϤwAp licaton er=; /u.The<cd7%s5l.ntb=}a6iwdSDLG 5d,al 3^p*IW5cus32MoOagaBoxAwxtffk8l?ExitPIL6ChHandOpV?GtMSl`|VirtFAcMvL (|fm9 DP<H0z4q  `t$$|$(3ۤm s3d s3[ s#AO su?M +uB (tMH, = } s
swAAųV+^uF3Ar+|$(|$a 

h
l
@ `
d
9 = AT$R +ʉJ3øxV4d USQWVRW= SRj@h  sj KʋZPR3C ‹K C‹KK ʍCPWVZXCRF+VK N׉?= KZ h j WZ^_Y[] M M M M

Attached Files


  • 0

#4
BlackOxide

BlackOxide

    Trusted Helper

  • Malware Removal
  • 1,976 posts
No worries, it looks like the file associations have been changed on the PC by the malware. Can you delete the copies of OTH and OTL that you downloaded and try the instructions below instead. It is the same set of instructions but the links for OTH and OTL are different, so lets see if they work this time :)


Note: If using Firefox right-click on any download links and choose Save As

Please download OTH to your desktop
Please download OTL to your desktop
Please download the attached file Scan.txt to your desktop
Attached File  Scan.txt   934bytes   274 downloads

Double click the OTH file to run it and click Kill All Processes, your desktop will go blank.

Posted Image

Then select Start OTL. OTL will now run

  • Double-click on the Custom Scans box and a message box will popup asking if you want to load a custom scan from a file
    Select Scan.txt that you downloaded
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Click the Internet Explorer button, post these logs in your Virus Removal topic.


In your next reply
Please post the contents of...
OTL.txt
Extras.txt

  • 0

#5
sgil

sgil

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Worked that time, thanks.

OTL.Txt contents -

OTL logfile created on: 02/08/2010 22:52:20 - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\Sarah\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,014.00 Mb Total Physical Memory | 453.00 Mb Available Physical Memory | 45.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 139.24 Gb Total Space | 108.90 Gb Free Space | 78.20% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GILBEZ
Current User Name: Sarah
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/08/02 21:57:21 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\OTL.com
PRC - [2010/08/02 21:56:03 | 000,258,560 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\stap1.com
PRC - [2010/07/01 12:07:20 | 001,361,128 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
PRC - [2010/07/01 12:07:18 | 000,840,936 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2010/04/16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2008/07/11 01:28:06 | 040,999,448 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe


========== Modules (SafeList) ==========

MOD - [2010/08/02 21:57:21 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\OTL.com
MOD - [2010/06/07 18:07:08 | 000,541,928 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\rooksbas.dll
MOD - [2009/12/09 02:19:44 | 000,094,208 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Sarah\Application Data\Dropbox\bin\DropboxExt.13.dll
MOD - [2009/08/07 23:51:14 | 005,812,560 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
MOD - [2009/07/12 02:12:06 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
MOD - [2009/05/24 22:41:34 | 000,304,128 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll
MOD - [2009/04/29 02:13:20 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Sarah\Application Data\Dropbox\bin\msvcp71.dll
MOD - [2008/07/25 11:16:46 | 000,062,968 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfdll.dll
MOD - [2008/04/14 13:00:00 | 000,640,000 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dbghelp.dll
MOD - [2008/04/14 13:00:00 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp60.dll
MOD - [2008/04/14 13:00:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
MOD - [2008/03/04 01:34:38 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Sarah\Application Data\Dropbox\bin\msvcr71.dll
MOD - [2003/02/14 02:31:40 | 000,136,352 | ---- | M] (Autodesk) -- C:\WINDOWS\system32\AcSignIcon.dll
MOD - [2003/02/14 02:31:38 | 000,223,904 | ---- | M] (Autodesk) -- C:\Program Files\Common Files\Autodesk Shared\AcSignCore16.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - File not found [On_Demand | Stopped] -- C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe -- (McSysmon)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/07/01 12:07:18 | 000,840,936 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
SRV - [2010/04/16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/11/21 14:15:41 | 000,054,784 | ---- | M] (Macrovision) [Auto | Stopped] -- C:\WINDOWS\system32\drivers\CDAC11BA.EXE -- (C-DillaCdaC11BA)
SRV - [2009/10/14 14:31:02 | 000,098,304 | ---- | M] (WDC) [Auto | Stopped] -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe -- (WDDMService)
SRV - [2009/06/16 09:58:08 | 000,020,480 | ---- | M] (Memeo) [Auto | Stopped] -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe -- (WDSmartWareBackgroundService)
SRV - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2009/02/27 21:17:00 | 000,382,304 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Dell\Digital TV\Kernel\TV\TVECapSvc.exe -- (TVECapSvc) TVEnhance Background Capture Service (TBCS)
SRV - [2009/02/27 21:17:00 | 000,189,792 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Dell\Digital TV\Kernel\TV\TVESched.exe -- (TVESched) TVEnhance Task Scheduler (TTS))
SRV - [2008/07/11 01:28:06 | 040,999,448 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS)
SRV - [2008/07/11 01:28:06 | 000,369,688 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE -- (SQLAgent$SQLEXPRESS) SQL Server Agent (SQLEXPRESS)
SRV - [2008/07/11 01:28:04 | 000,047,128 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE -- (MSSQLServerADHelper100)
SRV - [2008/07/10 03:49:44 | 000,098,840 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2008/07/10 03:49:34 | 000,258,072 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\System32\Drivers\Mpfp.sys -- (MPFP)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\mfesmfk.sys -- (mfesmfk)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\mferkdk.sys -- (mferkdk)
DRV - [2010/07/01 12:07:30 | 000,166,632 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
DRV - [2010/07/01 12:07:30 | 000,059,240 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportKELL.sys -- (RapportKELL)
DRV - [2009/11/21 14:15:42 | 000,012,464 | ---- | M] (Macrovision Europe Ltd) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CDAC15BA.SYS -- (CdaC15BA)
DRV - [2009/11/17 11:15:28 | 000,063,080 | ---- | M] (McAfee) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\McPvDrv.sys -- (McPvDrv)
DRV - [2009/05/26 03:17:28 | 000,093,952 | ---- | M] (ELAN Microelectronic Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ETD.sys -- (ETD)
DRV - [2009/04/07 00:04:02 | 005,088,896 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (igd)
DRV - [2009/04/07 00:03:12 | 000,110,080 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel®
DRV - [2009/03/31 18:02:00 | 000,272,032 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OA012Vid.sys -- (OA012Vid)
DRV - [2009/03/30 02:31:56 | 000,045,824 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hcw17bda.sys -- (hcw17bda)
DRV - [2009/03/30 02:15:36 | 005,032,448 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/03/30 02:15:28 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009/03/30 02:15:16 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009/03/20 11:54:44 | 000,135,168 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OA012Afx.sys -- (OA012Afx)
DRV - [2009/03/18 22:30:22 | 000,120,064 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2009/03/12 17:36:38 | 000,143,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV - [2009/03/06 08:30:08 | 000,133,632 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OA012Ufd.sys -- (OA012Ufd)
DRV - [2009/02/18 21:13:40 | 001,950,976 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2009/02/13 12:02:52 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2009/02/10 04:54:08 | 000,047,272 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2009/02/10 04:54:04 | 000,037,032 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwmodem.sys -- (btwmodem)
DRV - [2009/02/10 04:53:56 | 000,156,816 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2009/02/10 04:53:52 | 000,037,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2009/02/10 04:53:50 | 000,991,656 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2009/02/10 04:53:44 | 000,534,568 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2008/12/23 21:18:44 | 000,157,696 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTS5121.sys -- (RSUSBSTOR)
DRV - [2008/11/05 02:24:58 | 000,014,248 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\EMSC.SYS -- (EMSC)
DRV - [2008/08/08 14:15:10 | 000,101,376 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008/07/10 03:49:14 | 000,242,712 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\RsFx0102.sys -- (RsFx0102)
DRV - [2008/04/14 13:16:24 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MPE.sys -- (MPE)
DRV - [2008/04/14 13:06:40 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/14 13:06:40 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/14 13:00:00 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008/04/14 00:15:14 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2001/08/18 03:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/18 03:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/18 03:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/18 03:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/18 03:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/18 02:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/18 02:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/18 02:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/18 02:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/18 02:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/18 02:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/18 02:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/18 02:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/18 02:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/18 02:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.uk.msn.com/USCON/2
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.msn.com/sphome.aspx
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://g.uk.msn.com/USCON/2

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USCON/2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/17 08:44:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/30 19:43:31 | 000,000,000 | ---D | M]

[2010/01/17 20:28:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Mozilla\Extensions
[2010/08/01 21:08:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Mozilla\Firefox\Profiles\17semocl.default\extensions
[2010/06/28 17:30:26 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Sarah\Application Data\Mozilla\Firefox\Profiles\17semocl.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/20 20:40:28 | 000,001,201 | ---- | M] () -- C:\Documents and Settings\Sarah\Application Data\Mozilla\Firefox\Profiles\17semocl.default\searchplugins\winamp-search.xml
[2010/08/01 21:08:05 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/07/16 21:53:39 | 000,002,752 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 74.125.45.100 4-open-davinci.com
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getavplusnow.com
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 94.75.207.108 www.google.com
O1 - Hosts: 94.75.207.108 google.com
O1 - Hosts: 94.75.207.108 google.com.au
O1 - Hosts: 94.75.207.108 www.google.com.au
O1 - Hosts: 94.75.207.108 google.be
O1 - Hosts: 94.75.207.108 www.google.be
O1 - Hosts: 94.75.207.108 google.com.br
O1 - Hosts: 94.75.207.108 www.google.com.br
O1 - Hosts: 94.75.207.108 google.ca
O1 - Hosts: 38 more lines...
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe (Dell)
O4 - HKLM..\Run: [CapsLKNotify] C:\Program Files\CapsLKNotify\CapsLKNotify.exe (Compal Electronics, Inc)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4 - HKLM..\Run: [McPvTray] C:\Program Files\McAfee\Anti-Theft\McPvTray.exe (McAfee)
O4 - HKLM..\Run: [OA012Mon] C:\WINDOWS\OA012Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PersistenceThread] C:\WINDOWS\system32\PersistenceThread.exe (Intel Corporation)
O4 - HKLM..\Run: [TVEService] C:\Program Files\Dell\Digital TV\TVEService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe File not found
O4 - HKLM..\Run: [WSED] C:\Program Files\WSED\WSED.exe (Dell)
O4 - HKCU..\Run: [JDK5SWFMZY] C:\Documents and Settings\Sarah\Local Settings\Temp\Fn1.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (WDC)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WDSmartWare.lnk = C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe (Western Digital)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk = C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe ()
O4 - Startup: C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Sarah\Application Data\Dropbox\bin\Dropbox.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcaf...058/mcfscan.cab (McFreeScan Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 93.188.162.65,93.188.161.205
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.65,93.188.161.205
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igdlogin: DllName - igdlogin.dll - C:\WINDOWS\System32\igdlogin.dll ()
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/Sarah/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O27 - HKLM IFEO\_avp32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\_avpcc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\_avpm.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\~1.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\~2.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\a.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\aAvgApi.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\AAWTray.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\About.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ackwin32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\adaware.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\Ad-Aware.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\advxdwin.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\AdwarePrj.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\agent.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\agentsvr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\agentw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\alertsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\alevir.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\alogserv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\AlphaAV: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\AlphaAV.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\amon9x.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\AntispywarXP2009.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\anti-trojan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\Anti-Virus Professional.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\antivirus.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\AntiVirus_Pro.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\AntivirusPlus: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\AntivirusPlus.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\AntivirusPro_2010.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\AntivirusXP: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\AntivirusXP.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\antivirusxppro2009.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ants.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\apimonitor.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\aplica32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\apvxdwin.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\arr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\Arrakis3.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashAvast.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashBug.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashChest.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashCnsnt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashDisp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashLogV.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashMaiSv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashPopWz.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashQuick.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashServ.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashSimp2.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashSimpl.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashSkPcc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashSkPck.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashUpd.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ashWebSv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\aswChLic.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\aswRegSvr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\aswRunDll.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\aswUpdSv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\atcon.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\atguard.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\atro55en.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\atupdater.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\atwatch.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\au.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\aupdate.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\autodown.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\auto-protect.nav80try.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\autotrace.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\autoupdate.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\av360.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avadmin.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\AVCare.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avcenter.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avconfig.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avconsol.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ave32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgcc32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgchk.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgcmgr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgcsrvx.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgctrl.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgdumpx.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgemc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgiproxy.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgnsx.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgnt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgrsx.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgscanx.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgserv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgserv9.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgsrmax.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgtray.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgui.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgupd.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avgwdsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avkpop.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avkserv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avkservice.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avkwctl9.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avltmain.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avmailc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avmcdlg.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avnotify.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avnt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avp32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avpcc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avpdos32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avpm.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avptc32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avpupd.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avsched32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avsynmgr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avupgsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\AVWEBGRD.EXE: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avwin.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avwin95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avwinnt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avwsc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avwupd.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avwupd32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avwupsrv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avxmonitor9x.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avxmonitornt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avxquar.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\b.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\backweb.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bargains.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bd_professional.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bdagent.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bdfvcl.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bdfvwiz.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\BDInProcPatch.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bdmcon.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\BDMsnScan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bdreinit.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bdsubwiz.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\BDSurvey.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bdtkexec.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bdwizreg.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\beagle.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\belt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bidef.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bidserver.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bipcp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bipcpevalsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bisp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\blackd.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\blackice.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\blink.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\blss.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bootconf.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bootwarn.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\borg2.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bpc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\brasil.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\brastk.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\brw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bs120.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bspatch.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bundle.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\bvt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\c.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cavscan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ccapp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ccevtmgr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ccpxysvc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cdp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cfd.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cfgwiz.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cfiadmin.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cfiaudit.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cfinet.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cfinet32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cfp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cfpconfg.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cfplogvw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cfpupdat.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\Cl.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\claw95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\claw95cf.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\clean.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cleaner.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cleaner3.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cleanIELow.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cleanpc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\click.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cmd32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cmdagent.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cmesys.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cmgrdian.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cmon016.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\connectionmonitor.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\control: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cpd.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cpf9x206.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cpfnt206.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\crashrep.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\csc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cssconfg.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cssupdat.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cssurf.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ctrl.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cwnb181.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\cwntdwmo.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\d.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\datemanager.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\dcomx.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\defalert.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\defscangui.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\defwatch.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\deloeminfs.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\deputy.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\divx.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\dllcache.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\dllreg.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\doors.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\dop.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\dpf.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\dpfsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\dpps2.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\driverctrl.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\drwatson.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\drweb32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\drwebupw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\dssagent.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\dvp95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\dvp95_0.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ecengine.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\efpeadm.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\emsw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ent.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\esafe.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\escanhnt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\escanv95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\espwatch.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ethereal.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\etrustcipe.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\evpn.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\exantivirus-cnet.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\exe.avxw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\expert.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\explore.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fact.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\f-agnt95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fameh32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fast.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fch32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fih32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\findviru.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\firewall.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fixcfg.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fixfp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fnrb32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fprot.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\f-prot.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\f-prot95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fp-win.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fp-win_trial.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\frmwrk32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\frw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fsaa.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fsav.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fsav32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fsav530stbyb.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fsav530wtbyb.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fsav95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fsgk32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fsm32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fsma32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\fsmb32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\f-stopw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\gator.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\gav.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\gbmenu.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\gbn976rl.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\gbpoll.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\generics.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\gmt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\guard.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\guarddog.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\guardgui.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\hacktracersetup.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\hbinst.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\hbsrv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\History.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\homeav2010.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\hotactio.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\hotpatch.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\htlog.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\htpatch.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\hwpe.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\hxdl.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\hxiul.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\iamapp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\iamserv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\iamstats.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ibmasn.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ibmavsp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\icload95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\icloadnt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\icmon.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\icsupp95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\icsuppnt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\Identity.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\idle.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\iedll.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\iedriver.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\IEShow.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\iface.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ifw2000.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\inetlnfo.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\infus.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\infwin.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\init.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\init32.exe : Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\install.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\install[1].exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\install[2].exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\install[3].exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\install[4].exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\install[5].exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\intdel.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\intren.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\iomon98.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\istsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\jammer.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\jdbgmrg.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\jedi.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\JsRcGen.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\kavlite40eng.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\kavpers40eng.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\kavpf.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\kazza.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\keenvalue.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\kerio-pf-213-en-win.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\kerio-wrl-421-en-win.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\kerio-wrp-421-en-win.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\killprocesssetup161.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\launcher.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ldnetmon.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ldpro.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ldpromenu.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ldscan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\licmgr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\livesrv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\lnetinfo.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\loader.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\localnet.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\lockdown.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\lockdown2000.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\lookout.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\lordpe.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\lsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\luall.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\luau.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\lucomserver.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\luinit.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\luspt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\MalwareRemoval.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mapisvc32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mcagent.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mcmnhdlr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mcshield.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mctool.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mcupdate.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mcvsrte.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mcvsshld.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\md.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mfin32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mfw2en.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mfweng3.02d30.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mgavrtcl.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mgavrte.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mghtml.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mgui.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\minilog.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mmod.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\monitor.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\moolive.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mostat.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mpfagent.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mpfservice.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mpftray.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mrflux.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mrt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msa.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msapp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\MSASCui.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msbb.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msblast.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mscache.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msccn32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mscman.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msconfig: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msdm.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msdos.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msfwsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msiexec16.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mslaugh.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msmgt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\MsMpEng.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msmsgri32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msseces.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mssmmc32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mssys.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msvxd.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mu0311ad.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\mwatch.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\n32scanw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nav.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\navap.navapsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\navapsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\navapw32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\navdx.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\navlu32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\navnt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\navstub.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\navw32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\navwnt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nc2000.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ncinst4.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ndd32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\neomonitor.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\neowatchlog.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\netarmor.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\netd32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\netinfo.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\netmon.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\netscanpro.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\netspyhunter-1.2.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\netutils.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nisserv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nisum.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nmain.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nod32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\normist.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\norton_internet_secu_3.0_407.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\notstart.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\npf40_tw_98_nt_me_2k.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\npfmessenger.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nprotect.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\npscheck.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\npssvc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nsched32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nssys32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nstask32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nsupdate.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ntrtscan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ntvdm.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ntxconfig.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nui.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nupgrade.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nvarch16.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nvc95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nvsvc32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nwinst4.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nwservice.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\nwtool16.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\OAcat.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\OAhlp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\OAReg.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\oasrv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\oaui.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\oaview.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\OcHealthMon.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ODSW.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ollydbg.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\onsrvr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\optimize.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ostronet.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\otfix.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\outpost.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\outpostinstall.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\outpostproinstall.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ozn695m5.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\padmin.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\panixk.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\patch.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pav.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pavcl.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pavproxy.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pavsched.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pavw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\PC_Antispyware2010.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pccwin98.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pcfwallicon.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pcip10117_0.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pcscan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pctsAuxs.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pctsGui.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pctsSvc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pctsTray.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pdfndr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pdsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\PerAvir.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\periscope.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\persfw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\personalguard: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\personalguard.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\perswf.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pf2.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pfwadmin.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pgmonitr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pingscan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\platin.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pop3trap.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\poproxy.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\popscan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\portdetective.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\portmonitor.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\powerscan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ppinupdt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pptbc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ppvstop.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\prizesurfer.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\prmt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\prmvr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\procdump.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\processmonitor.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\procexplorerv1.0.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\programauditor.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\proport.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\protector.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\protectx.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\PSANCU.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\PSANHost.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\PSANToManager.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\pspf.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\PSUNMain.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\purge.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\qconsole.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\qh.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\qserver.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\Quick Heal.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\QuickHealCleaner.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rapapp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rav7.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rav7win.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rav8win32eng.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ray.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rb32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rcsync.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\realmon.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\reged.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\regedt32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rescue.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rescue32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rrguard.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rscdwld.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rshell.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rtvscan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rtvscn95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rulaunch.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rwg: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\rwg.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\SafetyKeeper.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\safeweb.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\sahagent.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\Save.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\SaveArmor.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\SaveDefense.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\SaveKeep.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\savenow.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\sbserv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\sc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\scam32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\scan32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\scan95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\scanpm.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\scrscan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\seccenter.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\Secure Veteran.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\secureveteran.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\Security Center.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\SecurityFighter.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\securitysoldier.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\serv95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\setloadorder.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\setup_flowprotector_us.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\setupvameeval.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\sgssfw32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\sh.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\shellspyinstall.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\shield.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\shn.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\showbehind.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\signcheck.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\smart.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\smartprotector.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\smc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\smrtdefp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\sms.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\smss32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\snetcfg.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\soap.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\sofi.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\SoftSafeness.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\sperm.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\spf.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\sphinx.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\spoler.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\spoolcv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\spoolsv32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\spywarexpguard.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\spyxx.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\srexe.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\srng.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ss3edit.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ssg_4104.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\ssgrate.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\st2.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\start.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\stcloader.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\supftrl.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\support.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\supporter5.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\svc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\svchostc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\svchosts.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\svshost.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\sweep95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\sweepnet.sweepsrv.sys.swnetsup.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\symproxysvc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\symtray.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\system.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\system32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\sysupd.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tapinstall.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\taskmgr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\taumon.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tbscan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tca.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tcm.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tds2-98.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tds2-nt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tds-3.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\teekids.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tfak.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tfak5.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tgbob.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\titanin.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\titaninxp.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\trickler.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\trjscan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\trjsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\trojantrap3.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\TrustWarrior.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tsadbot.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tsc.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tvmd.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\tvtmd.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\uiscan.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\undoboot.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\updat.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\upgrad.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\upgrepl.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\utpost.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vbcmserv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vbcons.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vbust.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vbwin9x.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vbwinntw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vcsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vet32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vet95.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vettray.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vfsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vir-help.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\virusmdpersonalfirewall.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\VisthAux.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\VisthLic.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\VisthUpd.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vnlan300.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vnpc3000.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vpc32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vpc42.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vpfw30s.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vptray.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vscan40.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vscenu6.02d30.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vsched.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vsecomr.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vshwin32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vsisetup.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vsmain.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vsmon.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vsserv.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vsstat.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vswin9xe.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vswinntse.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\vswinperse.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\w32dsm89.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\W3asbas.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\w9x.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\watchdog.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\webdav.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\webscanx.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\webtrap.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wfindv32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\whoswatchingme.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wimmun32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\win32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\win32us.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\winactive.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\winav.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\win-bugsfix.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\windll32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\window.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\windows Police Pro.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\windows.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wininetd.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wininitx.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\winlogin.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\winmain.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\winppr32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\winrecon.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\winservn.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\winss.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\winssk32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\winssnotify.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\WinSSUI.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\winstart.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\winstart001.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wintsk32.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\winupdate.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wkufind.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wnad.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wnt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wradmin.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wrctrl.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wsbgate.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wscfxas.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wscfxav.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wscfxfw.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wsctool.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wupdater.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wupdt.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\wyvernworksfirewall.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\xp_antispyware.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\xpdeluxe.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\xpf202en.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\zapro.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\zapsetup3001.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\zatutor.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\zonalm2601.exe: Debugger - svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\zonealarm.exe: Debugger - svchost.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/26 02:45:49 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{65b4fa2e-56ee-11df-9b5c-00265ea185c9}\Shell - "" = AutoRun
O33 - MountPoints2\{65b4fa2e-56ee-11df-9b5c-00265ea185c9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{65b4fa2e-56ee-11df-9b5c-00265ea185c9}\Shell\AutoRun\command - "" = D:\WD SmartWare.exe -- File not found
O33 - MountPoints2\{971071f2-58e7-11df-9b60-00265ea185c9}\Shell - "" = AutoRun
O33 - MountPoints2\{971071f2-58e7-11df-9b60-00265ea185c9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{971071f2-58e7-11df-9b60-00265ea185c9}\Shell\AutoRun\command - "" = D:\AutoRun.exe -- File not found
O33 - MountPoints2\{971071f7-58e7-11df-9b60-00265ea185c9}\Shell - "" = AutoRun
O33 - MountPoints2\{971071f7-58e7-11df-9b60-00265ea185c9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{971071f7-58e7-11df-9b60-00265ea185c9}\Shell\AutoRun\command - "" = D:\AutoRun.exe -- File not found
O33 - MountPoints2\{971071f8-58e7-11df-9b60-00265ea185c9}\Shell - "" = AutoRun
O33 - MountPoints2\{971071f8-58e7-11df-9b60-00265ea185c9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{971071f8-58e7-11df-9b60-00265ea185c9}\Shell\AutoRun\command - "" = D:\AutoRun.exe -- File not found
O33 - MountPoints2\{c79e979a-5910-11df-9b61-00265ea185c9}\Shell - "" = AutoRun
O33 - MountPoints2\{c79e979a-5910-11df-9b61-00265ea185c9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c79e979a-5910-11df-9b61-00265ea185c9}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/08/02 21:57:21 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\OTL.com
[2010/08/02 21:56:03 | 000,258,560 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\stap1.com
[2010/07/30 13:34:34 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/30 13:34:32 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/30 13:34:32 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/30 13:34:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/07/30 12:59:56 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/07/30 12:57:52 | 000,000,000 | ---D | C] -- C:\!KillBox
[2010/07/30 12:53:05 | 000,092,672 | ---- | C] (Option^Explicit Software [email protected]) -- C:\Documents and Settings\Sarah\Desktop\KillBox.exe
[2010/07/30 12:50:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Local Settings\Application Data\Threat Expert
[2010/07/18 20:20:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Local Settings\Application Data\PCHealth
[2010/07/18 19:57:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Desktop\Photos
[2010/07/17 10:00:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\McAfee.com
[2010/07/16 23:12:41 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010/07/16 21:53:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Application Data\Security Master AV
[2010/07/16 21:47:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Citrix
[2010/07/16 21:43:23 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\SMSHYLAV
[2010/07/16 21:42:51 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\c1d9f4b
[2010/07/16 21:42:09 | 000,000,000 | ---D | C] -- C:\Program Files\Citrix
[2010/07/16 21:41:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Local Settings\Application Data\Citrix
[2010/07/15 18:33:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee Anti-Theft
[2010/07/15 18:32:43 | 000,000,000 | R-SD | C] -- C:\Documents and Settings\Sarah\My Documents\McAfee Vaults
[2010/06/09 21:52:37 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Sarah\My Documents\My Dropbox
[2010/06/09 21:50:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Application Data\Dropbox
[2010/05/25 21:29:39 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/05/25 21:29:28 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/05/25 21:28:14 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2010/05/17 19:50:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/05/17 19:39:59 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/05/06 11:38:16 | 000,000,000 | ---D | C] -- C:\spoolerlogs
[2010/05/06 09:17:36 | 000,872,192 | R--- | C] (DiBcom SA) -- C:\WINDOWS\System32\drivers\mod7700.sys
[2010/05/06 09:17:36 | 000,103,168 | R--- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbfake.sys
[2010/05/06 09:17:36 | 000,101,376 | R--- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbmdm.sys
[2010/05/06 09:17:36 | 000,100,992 | R--- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbnet.sys
[2010/05/06 09:17:36 | 000,024,448 | R--- | C] (Huawei Tech. Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewdcsc.sys
[2010/05/06 09:17:07 | 000,000,000 | ---D | C] -- C:\Program Files\Orange Mobile Partner
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2010/08/02 22:17:03 | 000,000,282 | -H-- | M] () -- C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/08/02 22:05:54 | 000,000,754 | ---- | M] () -- C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk
[2010/08/02 22:05:53 | 000,000,280 | -H-- | M] () -- C:\WINDOWS\tasks\d8f7e1f8.job
[2010/08/02 22:05:32 | 000,000,246 | -H-- | M] () -- C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/08/02 22:05:25 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/08/02 22:04:51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/08/02 22:04:49 | 1063,538,688 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/02 21:59:50 | 007,077,888 | -H-- | M] () -- C:\Documents and Settings\Sarah\NTUSER.DAT
[2010/08/02 21:59:50 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Sarah\ntuser.ini
[2010/08/02 21:57:21 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\OTL.com
[2010/08/02 21:56:03 | 000,258,560 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\stap1.com
[2010/08/02 21:34:53 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/07/30 13:52:03 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/30 13:34:38 | 000,000,698 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/30 13:20:44 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\HiJackThis.lnk
[2010/07/30 13:16:10 | 000,007,360 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/07/30 13:12:45 | 000,115,712 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\Doc1.doc
[2010/07/30 12:53:06 | 000,092,672 | ---- | M] (Option^Explicit Software [email protected]) -- C:\Documents and Settings\Sarah\Desktop\KillBox.exe
[2010/07/26 18:32:04 | 000,002,155 | ---- | M] () -- C:\Documents and Settings\Sarah\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/07/18 03:03:20 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/07/16 23:23:24 | 000,000,817 | ---- | M] () -- C:\Documents and Settings\Sarah\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/16 21:53:39 | 000,002,752 | RHS- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/07/16 21:41:43 | 000,103,784 | ---- | M] () -- C:\Documents and Settings\Sarah\GoToAssistDownloadHelper.exe
[2010/07/15 17:27:20 | 000,332,280 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/14 20:57:03 | 000,088,320 | ---- | M] () -- C:\Documents and Settings\Sarah\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/06/24 18:40:07 | 000,629,376 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/24 18:40:07 | 000,532,294 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/24 18:40:07 | 000,104,434 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/06/11 08:16:47 | 000,000,603 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/06/09 21:52:38 | 000,000,996 | ---- | M] () -- C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\Dropbox.lnk
[2010/06/09 21:52:37 | 000,000,996 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\Dropbox.lnk
[2010/05/25 21:30:54 | 000,001,804 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/05/06 09:17:59 | 000,000,840 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Orange Mobile Partner.lnk
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/30 13:34:38 | 000,000,698 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/30 13:12:44 | 000,115,712 | ---- | C] () -- C:\Documents and Settings\Sarah\Desktop\Doc1.doc
[2010/07/30 12:59:57 | 000,002,447 | ---- | C] () -- C:\Documents and Settings\Sarah\Desktop\HiJackThis.lnk
[2010/07/16 23:23:24 | 000,000,817 | ---- | C] () -- C:\Documents and Settings\Sarah\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/16 21:41:40 | 000,103,784 | ---- | C] () -- C:\Documents and Settings\Sarah\GoToAssistDownloadHelper.exe
[2010/07/14 20:33:41 | 000,000,282 | -H-- | C] () -- C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/07/14 20:33:32 | 000,000,246 | -H-- | C] () -- C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/07/14 20:33:28 | 000,000,280 | -H-- | C] () -- C:\WINDOWS\tasks\d8f7e1f8.job
[2010/06/09 21:52:38 | 000,000,996 | ---- | C] () -- C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\Dropbox.lnk
[2010/06/09 21:52:37 | 000,000,996 | ---- | C] () -- C:\Documents and Settings\Sarah\Desktop\Dropbox.lnk
[2010/05/25 21:30:54 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/05/18 20:20:22 | 000,002,155 | ---- | C] () -- C:\Documents and Settings\Sarah\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/05/06 09:17:59 | 000,000,840 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Orange Mobile Partner.lnk
[2010/01/31 11:24:46 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/01/20 21:23:36 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/01/20 21:23:36 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010/01/05 12:38:32 | 000,176,235 | ---- | C] () -- C:\WINDOWS\System32\Primomonnt.dll
[2009/09/11 05:45:42 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll
[2009/09/11 01:32:14 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\igdlogin.dll
[2009/09/11 01:27:49 | 000,001,203 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2009/09/10 23:33:00 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2009/09/10 23:10:01 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2009/09/10 23:09:58 | 000,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2009/09/10 23:09:22 | 000,000,917 | ---- | C] () -- C:\WINDOWS\System32\CLWatson.ini
[2009/09/10 23:07:13 | 000,577,536 | ---- | C] () -- C:\WINDOWS\System32\EMSC.DLL
[2009/07/31 02:58:42 | 000,000,314 | ---- | C] () -- C:\WINDOWS\primopdf.ini
[2008/09/29 20:39:00 | 002,854,976 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2008/04/26 02:42:57 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2007/09/27 16:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 16:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 16:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2005/05/17 01:00:00 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\ernel32.dll
[2005/02/17 18:41:32 | 000,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 18:41:30 | 000,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 19:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

========== LOP Check ==========

[2009/11/21 14:11:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2010/07/16 21:53:39 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\c1d9f4b
[2010/07/16 21:47:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix
[2010/07/16 21:43:23 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\SMSHYLAV
[2010/07/30 13:36:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Temp
[2009/11/10 20:50:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trusteer
[2009/10/02 00:32:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Uninstall
[2009/09/10 23:07:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Vista32
[2009/09/10 23:07:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Vista64
[2010/05/03 21:03:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Western Digital
[2009/09/10 23:14:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\XP32
[2010/05/17 19:51:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/04 17:12:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/11/21 14:17:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Autodesk
[2009/10/04 16:59:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2010/08/02 21:35:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Dropbox
[2010/01/20 21:24:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\iPodtoComputer
[2010/07/14 06:33:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\PrimoPDF
[2010/07/16 21:53:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Security Master AV
[2010/06/14 23:14:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Spotify
[2009/11/10 20:52:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Trusteer
[2010/05/03 21:03:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Western Digital
[2009/09/10 23:04:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Windows Desktop Search
[2009/09/25 08:48:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Windows Search
[2010/08/02 22:05:53 | 000,000,280 | -H-- | M] () -- C:\WINDOWS\Tasks\d8f7e1f8.job
[2010/08/02 22:05:32 | 000,000,246 | -H-- | M] () -- C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/08/02 22:17:03 | 000,000,282 | -H-- | M] () -- C:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/04/26 02:45:49 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/09/25 08:44:01 | 000,000,211 | RHS- | M] () -- C:\boot.ini
[2008/04/26 02:45:49 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/09/11 01:38:01 | 000,004,695 | RH-- | M] () -- C:\dell.sdr
[2010/08/02 22:04:49 | 1063,538,688 | -HS- | M] () -- C:\hiberfil.sys
[2008/04/26 02:45:49 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2008/04/26 02:45:49 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2008/04/14 13:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/04/14 13:00:00 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/08/02 22:04:44 | 1598,029,824 | -HS- | M] () -- C:\pagefile.sys

< %systemroot%\system32\*.wt >

< %systemroot%\system32\*.ruy >

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/04/26 02:45:19 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\system32\spool\prtprocs\w32x86\*.tmp >

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2008/07/06 13:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/09/21 01:00:00 | 000,045,568 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\KU3mY9c.dll
[2007/04/09 13:23:54 | 000,028,552 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/27 01:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.scr >
[2008/12/05 04:55:20 | 000,307,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008/04/25 14:37:49 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2008/04/25 14:37:49 | 001,064,960 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2008/04/25 14:37:49 | 000,901,120 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\user32.dll /md5 >
[2008/04/14 13:00:00 | 000,578,560 | ---- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B -- C:\WINDOWS\system32\user32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/14 13:00:00 | 000,082,432 | ---- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A -- C:\WINDOWS\system32\ws2_32.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\system32\ws2help.dll /md5 >
[2008/04/14 13:00:00 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=9789E95E1D88EEB4B922BF3EA7779C28 -- C:\WINDOWS\system32\ws2help.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-18 02:03:52

========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:A8ADE5D8
< End of report >


Extras.Txt

OTL Extras logfile created on: 02/08/2010 22:52:20 - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\Sarah\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,014.00 Mb Total Physical Memory | 453.00 Mb Available Physical Memory | 45.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 139.24 Gb Total Space | 108.90 Gb Free Space | 78.20% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GILBEZ
Current User Name: Sarah
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"UacDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Dell\Digital TV\TVEnhance.exe" = C:\Program Files\Dell\Digital TV\TVEnhance.exe:*:Enabled:CyberLink TVEnhance -- (CyberLink Corp.)
"C:\Program Files\Dell\Digital TV\TVEService.exe" = C:\Program Files\Dell\Digital TV\TVEService.exe:*:Enabled:CyberLink TVEnhance Resident Program -- (CyberLink Corp.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Dell\Digital TV\TVEnhance.exe" = C:\Program Files\Dell\Digital TV\TVEnhance.exe:*:Enabled:CyberLink TVEnhance -- (CyberLink Corp.)
"C:\Program Files\Dell\Digital TV\TVEService.exe" = C:\Program Files\Dell\Digital TV\TVEService.exe:*:Enabled:CyberLink TVEnhance Resident Program -- (CyberLink Corp.)
"C:\Program Files\Dell Video Chat\DellVideoChat.exe" = C:\Program Files\Dell Video Chat\DellVideoChat.exe:*:Enabled:Dell Video Chat -- (Dell Inc. and SightSpeed Inc.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify -- (Spotify Ltd)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent -- File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Documents and Settings\Sarah\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Sarah\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox -- ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{053E51D3-885D-425C-9586-EA5183C4C688}" = Function Keys
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}" = Dell DataSafe Online
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{166E180E-9A3F-41AE-8B40-22D8FFF4AF87}" = McAfee Virtual Technician
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 17
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2B4C7E1E-E446-4740-ADB5-9842E742EE8A}" = Windows Live Toolbar
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{543A4F31-9590-416A-A621-42CEB4C6A694}" = Battery Meter
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5783F2D7-0201-0409-0002-0060B0CE6BBA}" = AutoCAD 2004
"{58721EC3-8D4E-4B79-BC51-1054E2DDCD10}" = Microsoft SQL Server 2008 Database Engine Services
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{624880EA-7610-47B6-B4A6-40DD83DB1AB4}" = McAfee Anti-Theft
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}" = Live! Cam Avatar Creator
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{78225D0F-D12C-09E4-5D6D-A64D763E8982}" = BBC iPlayer Desktop
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90578106-70AF-4198-B9DE-1924FA83B03A}" = CapsLKNotify
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D6D76A6-4328-49E8-97A7-531A74841DA5}" = Microsoft SQL Server 2008 Setup Support Files (English)
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{B5153233-9AEE-4CD4-9D2C-4FAAC870DBE2}" = Microsoft SQL Server 2008 Database Engine Services
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{B840FAB0-0E67-4DD9-A93C-A92BA7DF9625}" = Dell Box.net Launcher
"{B857D868-F8B0-43EE-BC2B-D9E5ED21F237}" = Microsoft SQL Server VSS Writer
"{BA165460-FCF7-4D6C-A7A2-F2321700720F}" = MobileMe Control Panel
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBC1172F-1253-4844-A50C-B8C9981FE962}" = CyberLink PowerDVD 8.0 SE
"{CD0DC280-2489-4464-A2FC-16104676394A}" = WD SmartWare
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D24E305F-F373-4114-89FD-63CA8883BFB5}" = Multi-Touch Gestures Demo
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{D9D937B0-E842-4130-9588-B948E876904A}" = Microsoft SQL Server 2008 Native Client
"{E4C891D6-6844-41B8-86E8-633CACCC644F}" = Dell Digital TV
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E6CB6126-D120-4FB5-9D1B-E2E19003E66C}" = WSED
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1DC7648-8623-442F-92B7-E118DF61872E}" = Microsoft SQL Server 2008 RsFx Driver
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FEF06E73-A519-4510-8CF3-B66041B91D8A}" = EMSC
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Autodesk Express Viewer" = Autodesk Express Viewer
"BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1" = BBC iPlayer Desktop
"Broadcom 802.11 Application" = Dell Wireless WLAN Card Utility
"CdaC13Ba" = SafeCast Shared Components
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Creative OA012" = Integrated Webcam Driver (1.03.01.0522)
"Dell Video Chat" = Dell Video Chat
"Dell Webcam Central" = Dell Webcam Central
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"Elantech" = ETDWare PS/2-x86 7.0.4.9_WHQL
"ie8" = Windows Internet Explorer 8
"InstallShield_{543A4F31-9590-416A-A621-42CEB4C6A694}" = Battery Meter
"InstallShield_{90578106-70AF-4198-B9DE-1924FA83B03A}" = CapsLKNotify
"InstallShield_{CBC1172F-1253-4844-A50C-B8C9981FE962}" = CyberLink PowerDVD 8.0 SE
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Orange Mobile Partner" = Orange Mobile Partner
"PrimoPDF" = PrimoPDF -- by Nitro PDF Software
"Rapport_msi" = Rapport
"Spotify" = Spotify
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"a3d4a571c1166bcf" = Stroma Code
"Dropbox" = Dropbox

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 30/07/2010 12:08:13 | Computer Name = GILBEZ | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9782266

Error - 30/07/2010 12:08:15 | Computer Name = GILBEZ | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 30/07/2010 12:08:15 | Computer Name = GILBEZ | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 9784891

Error - 30/07/2010 12:08:15 | Computer Name = GILBEZ | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9784891

Error - 30/07/2010 12:13:10 | Computer Name = GILBEZ | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 01/08/2010 15:56:05 | Computer Name = GILBEZ | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 01/08/2010 16:32:19 | Computer Name = GILBEZ | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 02/08/2010 16:35:53 | Computer Name = GILBEZ | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 02/08/2010 17:05:51 | Computer Name = GILBEZ | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 02/08/2010 17:14:35 | Computer Name = GILBEZ | Source = Windows Search Service | ID = 3013
Description = The entry <C:\DOCUMENTS AND SETTINGS\SARAH\MY DOCUMENTS\MY MUSIC\SAMPLE
MUSIC.LNK> in the hash map cannot be updated. Context: Application, SystemIndex
Catalog Details: A device attached to the system is not functioning. (0x8007001f)


[ Application Events ]
Error - 30/07/2010 12:08:13 | Computer Name = GILBEZ | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9782266

Error - 30/07/2010 12:08:15 | Computer Name = GILBEZ | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 30/07/2010 12:08:15 | Computer Name = GILBEZ | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 9784891

Error - 30/07/2010 12:08:15 | Computer Name = GILBEZ | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 9784891

Error - 30/07/2010 12:13:10 | Computer Name = GILBEZ | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 01/08/2010 15:56:05 | Computer Name = GILBEZ | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 01/08/2010 16:32:19 | Computer Name = GILBEZ | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 02/08/2010 16:35:53 | Computer Name = GILBEZ | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 02/08/2010 17:05:51 | Computer Name = GILBEZ | Source = Swapdrive Backup | ID = 0
Description = Swapdrive Backup: Web Service Error: System.Net.WebException: The
remote name could not be resolved: 'wsvcdell.backup.com' at System.Net.HttpWebRequest.GetRequestStream(TransportContext&
context) at System.Net.HttpWebRequest.GetRequestStream() at System.Web.Services.Protocols.SoapHttpClientProtocol.Invoke(String
methodName, Object[] parameters) at Swapdrive.Shared.com.backup.uswsvcdell.Service.GetInfo(GetInfoRequest
req) at Swapdrive.Shared.ActivationWsvcs.GetInfo()

Error - 02/08/2010 17:14:35 | Computer Name = GILBEZ | Source = Windows Search Service | ID = 3013
Description = The entry <C:\DOCUMENTS AND SETTINGS\SARAH\MY DOCUMENTS\MY MUSIC\SAMPLE
MUSIC.LNK> in the hash map cannot be updated. Context: Application, SystemIndex
Catalog Details: A device attached to the system is not functioning. (0x8007001f)


[ System Events ]
Error - 02/08/2010 17:05:52 | Computer Name = GILBEZ | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).

Error - 02/08/2010 17:05:52 | Computer Name = GILBEZ | Source = Service Control Manager | ID = 7034
Description = The Cyberlink RichVideo Service(CRVS) service terminated unexpectedly.
It has done this 1 time(s).

Error - 02/08/2010 17:05:52 | Computer Name = GILBEZ | Source = Service Control Manager | ID = 7034
Description = The SeaPort service terminated unexpectedly. It has done this 1 time(s).

Error - 02/08/2010 17:05:52 | Computer Name = GILBEZ | Source = Service Control Manager | ID = 7034
Description = The SQL Server VSS Writer service terminated unexpectedly. It has
done this 1 time(s).

Error - 02/08/2010 17:05:52 | Computer Name = GILBEZ | Source = Service Control Manager | ID = 7034
Description = The TVEnhance Background Capture Service (TBCS) service terminated
unexpectedly. It has done this 1 time(s).

Error - 02/08/2010 17:05:52 | Computer Name = GILBEZ | Source = Service Control Manager | ID = 7034
Description = The WD SmartWare Drive Manager service terminated unexpectedly. It
has done this 1 time(s).

Error - 02/08/2010 17:05:52 | Computer Name = GILBEZ | Source = Service Control Manager | ID = 7034
Description = The WD SmartWare Background Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 02/08/2010 17:05:55 | Computer Name = GILBEZ | Source = Service Control Manager | ID = 7034
Description = The TVEnhance Task Scheduler (TTS)) service terminated unexpectedly.
It has done this 1 time(s).

Error - 02/08/2010 17:05:56 | Computer Name = GILBEZ | Source = Service Control Manager | ID = 7034
Description = The iPod Service service terminated unexpectedly. It has done this
1 time(s).

Error - 02/08/2010 17:05:56 | Computer Name = GILBEZ | Source = Service Control Manager | ID = 7031
Description = The Bluetooth Service service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.


< End of report >

Attached Files

  • Attached File  OTL.Txt   204.28KB   223 downloads
  • Attached File  Extras.Txt   52.66KB   279 downloads

  • 0

#6
BlackOxide

BlackOxide

    Trusted Helper

  • Malware Removal
  • 1,976 posts
Excellent, lets start removing some of these infections now. Please follow the steps below, in order :)


1)
Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O4 - HKCU..\Run: [JDK5SWFMZY] C:\Documents and Settings\Sarah\Local Settings\Temp\Fn1.exe ()
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 93.188.162.65,93.188.161.205
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.65,93.188.161.205
    O27 - HKLM IFEO\_avp32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\_avpcc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\_avpm.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\~1.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\~2.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\a.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\aAvgApi.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\AAWTray.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\About.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ackwin32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\adaware.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\Ad-Aware.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\advxdwin.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\AdwarePrj.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\agent.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\agentsvr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\agentw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\alertsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\alevir.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\alogserv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\AlphaAV: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\AlphaAV.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\amon9x.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\AntispywarXP2009.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\anti-trojan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\Anti-Virus Professional.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\antivirus.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\AntiVirus_Pro.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\AntivirusPlus: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\AntivirusPlus.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\AntivirusPro_2010.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\AntivirusXP: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\AntivirusXP.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\antivirusxppro2009.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ants.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\apimonitor.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\aplica32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\apvxdwin.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\arr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\Arrakis3.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashAvast.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashBug.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashChest.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashCnsnt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashDisp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashLogV.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashMaiSv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashPopWz.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashQuick.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashServ.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashSimp2.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashSimpl.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashSkPcc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashSkPck.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashUpd.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ashWebSv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\aswChLic.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\aswRegSvr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\aswRunDll.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\aswUpdSv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\atcon.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\atguard.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\atro55en.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\atupdater.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\atwatch.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\au.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\aupdate.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\autodown.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\auto-protect.nav80try.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\autotrace.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\autoupdate.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\av360.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avadmin.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\AVCare.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avcenter.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avconfig.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avconsol.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ave32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgcc32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgchk.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgcmgr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgcsrvx.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgctrl.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgdumpx.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgemc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgiproxy.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgnsx.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgnt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgrsx.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgscanx.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgserv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgserv9.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgsrmax.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgtray.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgui.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgupd.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avgwdsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avkpop.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avkserv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avkservice.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avkwctl9.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avltmain.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avmailc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avmcdlg.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avnotify.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avnt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avp32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avpcc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avpdos32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avpm.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avptc32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avpupd.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avsched32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avsynmgr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avupgsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\AVWEBGRD.EXE: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avwin.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avwin95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avwinnt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avwsc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avwupd.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avwupd32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avwupsrv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avxmonitor9x.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avxmonitornt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\avxquar.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\b.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\backweb.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bargains.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bd_professional.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bdagent.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bdfvcl.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bdfvwiz.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\BDInProcPatch.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bdmcon.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\BDMsnScan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bdreinit.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bdsubwiz.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\BDSurvey.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bdtkexec.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bdwizreg.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\beagle.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\belt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bidef.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bidserver.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bipcp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bipcpevalsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bisp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\blackd.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\blackice.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\blink.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\blss.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bootconf.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bootwarn.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\borg2.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bpc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\brasil.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\brastk.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\brw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bs120.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bspatch.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bundle.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\bvt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\c.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cavscan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ccapp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ccevtmgr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ccpxysvc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cdp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cfd.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cfgwiz.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cfiadmin.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cfiaudit.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cfinet.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cfinet32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cfp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cfpconfg.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cfplogvw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cfpupdat.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\Cl.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\claw95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\claw95cf.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\clean.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cleaner.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cleaner3.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cleanIELow.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cleanpc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\click.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cmd32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cmdagent.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cmesys.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cmgrdian.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cmon016.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\connectionmonitor.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\control: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cpd.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cpf9x206.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cpfnt206.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\crashrep.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\csc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cssconfg.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cssupdat.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cssurf.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ctrl.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cwnb181.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\cwntdwmo.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\d.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\datemanager.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\dcomx.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\defalert.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\defscangui.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\defwatch.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\deloeminfs.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\deputy.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\divx.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\dllcache.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\dllreg.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\doors.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\dop.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\dpf.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\dpfsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\dpps2.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\driverctrl.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\drwatson.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\drweb32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\drwebupw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\dssagent.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\dvp95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\dvp95_0.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ecengine.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\efpeadm.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\emsw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ent.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\esafe.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\escanhnt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\escanv95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\espwatch.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ethereal.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\etrustcipe.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\evpn.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\exantivirus-cnet.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\exe.avxw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\expert.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\explore.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fact.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\f-agnt95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fameh32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fast.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fch32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fih32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\findviru.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\firewall.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fixcfg.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fixfp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fnrb32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fprot.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\f-prot.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\f-prot95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fp-win.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fp-win_trial.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\frmwrk32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\frw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fsaa.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fsav.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fsav32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fsav530stbyb.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fsav530wtbyb.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fsav95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fsgk32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fsm32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fsma32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\fsmb32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\f-stopw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\gator.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\gav.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\gbmenu.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\gbn976rl.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\gbpoll.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\generics.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\gmt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\guard.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\guarddog.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\guardgui.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\hacktracersetup.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\hbinst.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\hbsrv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\History.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\homeav2010.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\hotactio.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\hotpatch.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\htlog.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\htpatch.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\hwpe.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\hxdl.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\hxiul.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\iamapp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\iamserv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\iamstats.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ibmasn.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ibmavsp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\icload95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\icloadnt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\icmon.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\icsupp95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\icsuppnt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\Identity.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\idle.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\iedll.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\iedriver.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\IEShow.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\iface.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ifw2000.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\inetlnfo.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\infus.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\infwin.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\init.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\init32.exe : Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\install.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\install[1].exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\install[2].exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\install[3].exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\install[4].exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\install[5].exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\intdel.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\intren.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\iomon98.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\istsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\jammer.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\jdbgmrg.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\jedi.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\JsRcGen.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\kavlite40eng.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\kavpers40eng.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\kavpf.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\kazza.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\keenvalue.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\kerio-pf-213-en-win.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\kerio-wrl-421-en-win.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\kerio-wrp-421-en-win.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\killprocesssetup161.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\launcher.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ldnetmon.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ldpro.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ldpromenu.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ldscan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\licmgr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\livesrv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\lnetinfo.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\loader.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\localnet.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\lockdown.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\lockdown2000.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\lookout.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\lordpe.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\lsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\luall.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\luau.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\lucomserver.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\luinit.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\luspt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\MalwareRemoval.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mapisvc32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mcagent.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mcmnhdlr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mcshield.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mctool.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mcupdate.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mcvsrte.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mcvsshld.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\md.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mfin32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mfw2en.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mfweng3.02d30.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mgavrtcl.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mgavrte.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mghtml.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mgui.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\minilog.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mmod.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\monitor.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\moolive.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mostat.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mpfagent.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mpfservice.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mpftray.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mrflux.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mrt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msa.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msapp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\MSASCui.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msbb.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msblast.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mscache.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msccn32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mscman.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msconfig: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msdm.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msdos.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msfwsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msiexec16.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mslaugh.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msmgt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\MsMpEng.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msmsgri32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msseces.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mssmmc32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mssys.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\msvxd.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mu0311ad.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\mwatch.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\n32scanw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nav.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\navap.navapsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\navapsvc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\navapw32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\navdx.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\navlu32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\navnt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\navstub.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\navw32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\navwnt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nc2000.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ncinst4.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ndd32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\neomonitor.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\neowatchlog.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\netarmor.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\netd32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\netinfo.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\netmon.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\netscanpro.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\netspyhunter-1.2.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\netutils.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nisserv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nisum.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nmain.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nod32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\normist.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\norton_internet_secu_3.0_407.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\notstart.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\npf40_tw_98_nt_me_2k.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\npfmessenger.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nprotect.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\npscheck.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\npssvc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nsched32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nssys32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nstask32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nsupdate.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ntrtscan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ntvdm.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ntxconfig.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nui.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nupgrade.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nvarch16.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nvc95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nvsvc32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nwinst4.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nwservice.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\nwtool16.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\OAcat.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\OAhlp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\OAReg.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\oasrv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\oaui.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\oaview.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\OcHealthMon.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ODSW.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ollydbg.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\onsrvr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\optimize.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ostronet.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\otfix.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\outpost.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\outpostinstall.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\outpostproinstall.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ozn695m5.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\padmin.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\panixk.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\patch.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pav.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pavcl.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pavproxy.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pavsched.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pavw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\PC_Antispyware2010.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pccwin98.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pcfwallicon.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pcip10117_0.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pcscan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pctsAuxs.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pctsGui.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pctsSvc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pctsTray.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pdfndr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pdsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\PerAvir.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\periscope.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\persfw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\personalguard: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\personalguard.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\perswf.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pf2.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pfwadmin.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pgmonitr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pingscan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\platin.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pop3trap.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\poproxy.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\popscan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\portdetective.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\portmonitor.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\powerscan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ppinupdt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pptbc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ppvstop.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\prizesurfer.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\prmt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\prmvr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\procdump.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\processmonitor.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\procexplorerv1.0.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\programauditor.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\proport.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\protector.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\protectx.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\PSANCU.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\PSANHost.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\PSANToManager.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\pspf.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\PSUNMain.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\purge.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\qconsole.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\qh.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\qserver.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\Quick Heal.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\QuickHealCleaner.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rapapp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rav7.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rav7win.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rav8win32eng.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ray.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rb32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rcsync.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\realmon.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\reged.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\regedt32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rescue.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rescue32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rrguard.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rscdwld.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rshell.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rtvscan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rtvscn95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rulaunch.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rwg: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\rwg.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\SafetyKeeper.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\safeweb.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\sahagent.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\Save.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\SaveArmor.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\SaveDefense.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\SaveKeep.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\savenow.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\sbserv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\sc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\scam32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\scan32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\scan95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\scanpm.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\scrscan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\seccenter.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\Secure Veteran.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\secureveteran.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\Security Center.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\SecurityFighter.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\securitysoldier.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\serv95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\setloadorder.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\setup_flowprotector_us.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\setupvameeval.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\sgssfw32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\sh.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\shellspyinstall.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\shield.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\shn.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\showbehind.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\signcheck.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\smart.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\smartprotector.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\smc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\smrtdefp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\sms.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\smss32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\snetcfg.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\soap.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\sofi.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\SoftSafeness.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\sperm.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\spf.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\sphinx.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\spoler.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\spoolcv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\spoolsv32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\spywarexpguard.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\spyxx.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\srexe.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\srng.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ss3edit.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ssg_4104.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\ssgrate.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\st2.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\start.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\stcloader.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\supftrl.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\support.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\supporter5.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\svc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\svchostc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\svchosts.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\svshost.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\sweep95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\sweepnet.sweepsrv.sys.swnetsup.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\symproxysvc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\symtray.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\system.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\system32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\sysupd.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tapinstall.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\taskmgr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\taumon.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tbscan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tca.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tcm.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tds2-98.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tds2-nt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tds-3.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\teekids.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tfak.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tfak5.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tgbob.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\titanin.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\titaninxp.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\trickler.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\trjscan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\trjsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\trojantrap3.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\TrustWarrior.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tsadbot.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tsc.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tvmd.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\tvtmd.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\uiscan.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\undoboot.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\updat.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\upgrad.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\upgrepl.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\utpost.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vbcmserv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vbcons.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vbust.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vbwin9x.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vbwinntw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vcsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vet32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vet95.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vettray.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vfsetup.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vir-help.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\virusmdpersonalfirewall.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\VisthAux.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\VisthLic.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\VisthUpd.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vnlan300.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vnpc3000.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vpc32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vpc42.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vpfw30s.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vptray.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vscan40.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vscenu6.02d30.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vsched.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vsecomr.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vshwin32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vsisetup.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vsmain.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vsmon.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vsserv.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vsstat.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vswin9xe.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vswinntse.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\vswinperse.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\w32dsm89.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\W3asbas.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\w9x.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\watchdog.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\webdav.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\webscanx.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\webtrap.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wfindv32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\whoswatchingme.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wimmun32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\win32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\win32us.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\winactive.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\winav.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\win-bugsfix.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\windll32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\window.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\windows Police Pro.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\windows.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wininetd.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wininitx.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\winlogin.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\winmain.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\winppr32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\winrecon.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\winservn.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\winss.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\winssk32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\winssnotify.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\WinSSUI.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\winstart.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\winstart001.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wintsk32.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\winupdate.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wkufind.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wnad.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wnt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wradmin.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wrctrl.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wsbgate.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wscfxas.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wscfxav.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wscfxfw.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wsctool.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wupdater.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wupdt.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\wyvernworksfirewall.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\xp_antispyware.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\xpdeluxe.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\xpf202en.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\zapro.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\zapsetup3001.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\zatutor.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\zonalm2601.exe: Debugger - svchost.exe (Microsoft Corporation)
    O27 - HKLM IFEO\zonealarm.exe: Debugger - svchost.exe (Microsoft Corporation)
    [2010/07/16 21:53:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Application Data\Security Master AV
    [2010/07/16 21:43:23 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\SMSHYLAV
    [2010/07/16 21:42:51 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\c1d9f4b
    [2010/08/02 22:17:03 | 000,000,282 | -H-- | M] () -- C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
    [2010/08/02 22:05:53 | 000,000,280 | -H-- | M] () -- C:\WINDOWS\tasks\d8f7e1f8.job
    [2010/08/02 22:05:32 | 000,000,246 | -H-- | M] () -- C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
    [2006/09/21 01:00:00 | 000,045,568 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\KU3mY9c.dll
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done.
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.





2)
Posted Image Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.





3)
GMER Rootkit Scanner
  • Posted Image GMER Rootkit Scanner - Download - Homepage
  • Download GMER
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe.
    Posted Image
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED ...
  • IAT/EAT
  • Drives/Partition other than Systemdrive (typically C:\)
  • Show All (don't miss this one)
    Posted Image
    Click the image to enlarge it
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt"
  • Save the log where you can easily find it, such as your desktop.
**Caution**Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Please copy and paste the report into your Post.



In your next reply
Please post the contents of...
OTL log
MBAM log
GMER log


:)
  • 0

#7
sgil

sgil

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Thanks for that, have performed 1 and 2, however when I ran the GMER programm it crashed my computer, I have attempted again twice but the same has happened on both occasions. Not sure what to do.

The computer does seem to be running better and task manager is now running.

OTL.Txt below

OTL logfile created on: 03/08/2010 22:45:52 - Run 2
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Documents and Settings\Sarah\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,014.00 Mb Total Physical Memory | 158.00 Mb Available Physical Memory | 16.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 63.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 139.24 Gb Total Space | 110.27 Gb Free Space | 79.19% Space Free | Partition Type: NTFS
Drive D: | 22.25 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 116.75 Mb Total Space | 112.95 Mb Free Space | 96.74% Space Free | Partition Type: FAT
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: GILBEZ
Current User Name: Sarah
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/08/02 21:57:21 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\OTL.com
PRC - [2010/07/01 12:07:20 | 001,361,128 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
PRC - [2010/07/01 12:07:18 | 000,840,936 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
PRC - [2010/06/30 18:47:26 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/05/06 09:17:20 | 000,114,688 | ---- | M] () -- C:\Program Files\Orange Mobile Partner\Orange Mobile Partner.exe
PRC - [2010/04/16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/04/05 08:34:59 | 000,095,232 | ---- | M] () -- C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe
PRC - [2009/11/21 14:15:41 | 000,054,784 | ---- | M] (Macrovision) -- C:\WINDOWS\system32\drivers\CDAC11BA.EXE
PRC - [2009/11/17 11:15:42 | 000,670,312 | ---- | M] (McAfee) -- C:\Program Files\McAfee\Anti-Theft\McPvTray.exe
PRC - [2009/10/14 14:32:46 | 009,085,760 | ---- | M] (Western Digital) -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
PRC - [2009/10/14 14:32:46 | 002,049,344 | ---- | M] (WDC) -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
PRC - [2009/10/14 14:31:02 | 000,098,304 | ---- | M] (WDC) -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
PRC - [2009/07/07 16:23:00 | 001,779,952 | ---- | M] () -- C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
PRC - [2009/06/16 09:58:08 | 000,020,480 | ---- | M] (Memeo) -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
PRC - [2009/05/27 21:24:54 | 000,247,080 | ---- | M] (Dell) -- C:\Program Files\WSED\WSED.exe
PRC - [2009/05/26 03:17:34 | 000,488,960 | ---- | M] (ELAN Microelectronic Corp.) -- C:\Program Files\Elantech\ETDCtrl.exe
PRC - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/04/07 00:04:04 | 000,086,016 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\PersistenceThread.exe
PRC - [2009/04/02 18:00:00 | 000,024,576 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\OA012Mon.exe
PRC - [2009/03/18 00:43:26 | 000,320,808 | ---- | M] (Compal Electronics, Inc) -- C:\Program Files\CapsLKNotify\CapsLKNotify.exe
PRC - [2009/02/27 21:17:00 | 000,382,304 | ---- | M] () -- C:\Program Files\Dell\Digital TV\Kernel\TV\TVECapSvc.exe
PRC - [2009/02/27 21:17:00 | 000,189,792 | ---- | M] () -- C:\Program Files\Dell\Digital TV\Kernel\TV\TVESched.exe
PRC - [2009/02/27 21:16:52 | 000,185,576 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Dell\Digital TV\TVEService.exe
PRC - [2009/02/04 21:26:38 | 000,128,232 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
PRC - [2008/11/05 03:47:38 | 000,623,912 | ---- | M] (Dell) -- C:\Program Files\Battery Meter\BTMeter.exe
PRC - [2008/09/29 20:39:48 | 000,604,776 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2008/09/29 20:39:46 | 001,448,576 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
PRC - [2008/07/11 01:28:06 | 040,999,448 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
PRC - [2008/07/10 03:49:44 | 000,098,840 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2008/05/27 04:19:14 | 000,123,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Desktop Search\WindowsSearch.exe
PRC - [2008/04/14 13:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe


========== Modules (SafeList) ==========

MOD - [2010/08/02 21:57:21 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\OTL.com
MOD - [2010/06/07 18:07:08 | 000,541,928 | ---- | M] (Trusteer Ltd.) -- C:\Program Files\Trusteer\Rapport\bin\rooksbas.dll
MOD - [2009/05/26 03:17:34 | 000,245,760 | ---- | M] (ELAN Microelectronic Corp.) -- C:\Program Files\Elantech\ETDApix.dll
MOD - [2008/09/29 20:38:50 | 000,094,273 | ---- | M] (Broadcom Corporation.) -- C:\WINDOWS\system32\BtMmHook.dll
MOD - [2008/04/14 13:00:00 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\McAfee\MPF\MPFSrv.exe -- (MpfService)
SRV - File not found [On_Demand | Stopped] -- C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe -- (McSysmon)
SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/07/01 12:07:18 | 000,840,936 | ---- | M] (Trusteer Ltd.) [Auto | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe -- (RapportMgmtService)
SRV - [2010/04/16 08:33:40 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/11/21 14:15:41 | 000,054,784 | ---- | M] (Macrovision) [Auto | Running] -- C:\WINDOWS\system32\drivers\CDAC11BA.EXE -- (C-DillaCdaC11BA)
SRV - [2009/10/14 14:31:02 | 000,098,304 | ---- | M] (WDC) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe -- (WDDMService)
SRV - [2009/06/16 09:58:08 | 000,020,480 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe -- (WDSmartWareBackgroundService)
SRV - [2009/05/19 11:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2009/02/27 21:17:00 | 000,382,304 | ---- | M] () [Auto | Running] -- C:\Program Files\Dell\Digital TV\Kernel\TV\TVECapSvc.exe -- (TVECapSvc) TVEnhance Background Capture Service (TBCS)
SRV - [2009/02/27 21:17:00 | 000,189,792 | ---- | M] () [Auto | Running] -- C:\Program Files\Dell\Digital TV\Kernel\TV\TVESched.exe -- (TVESched) TVEnhance Task Scheduler (TTS))
SRV - [2008/07/11 01:28:06 | 040,999,448 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe -- (MSSQL$SQLEXPRESS) SQL Server (SQLEXPRESS)
SRV - [2008/07/11 01:28:06 | 000,369,688 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE -- (SQLAgent$SQLEXPRESS) SQL Server Agent (SQLEXPRESS)
SRV - [2008/07/11 01:28:04 | 000,047,128 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE -- (MSSQLServerADHelper100)
SRV - [2008/07/10 03:49:44 | 000,098,840 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2008/07/10 03:49:34 | 000,258,072 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\System32\Drivers\Mpfp.sys -- (MPFP)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\mfesmfk.sys -- (mfesmfk)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\mferkdk.sys -- (mferkdk)
DRV - [2010/07/01 12:07:30 | 000,166,632 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
DRV - [2010/07/01 12:07:30 | 000,059,240 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportKELL.sys -- (RapportKELL)
DRV - [2009/11/21 14:15:42 | 000,012,464 | ---- | M] (Macrovision Europe Ltd) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CDAC15BA.SYS -- (CdaC15BA)
DRV - [2009/11/17 11:15:28 | 000,063,080 | ---- | M] (McAfee) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\McPvDrv.sys -- (McPvDrv)
DRV - [2009/05/26 03:17:28 | 000,093,952 | ---- | M] (ELAN Microelectronic Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ETD.sys -- (ETD)
DRV - [2009/04/07 00:04:02 | 005,088,896 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (igd)
DRV - [2009/04/07 00:03:12 | 000,110,080 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel®
DRV - [2009/03/31 18:02:00 | 000,272,032 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OA012Vid.sys -- (OA012Vid)
DRV - [2009/03/30 02:31:56 | 000,045,824 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hcw17bda.sys -- (hcw17bda)
DRV - [2009/03/30 02:15:36 | 005,032,448 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/03/30 02:15:28 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009/03/30 02:15:16 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009/03/20 11:54:44 | 000,135,168 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OA012Afx.sys -- (OA012Afx)
DRV - [2009/03/18 22:30:22 | 000,120,064 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2009/03/12 17:36:38 | 000,143,840 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV - [2009/03/06 08:30:08 | 000,133,632 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\OA012Ufd.sys -- (OA012Ufd)
DRV - [2009/02/18 21:13:40 | 001,950,976 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2009/02/13 12:02:52 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2009/02/10 04:54:08 | 000,047,272 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2009/02/10 04:54:04 | 000,037,032 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwmodem.sys -- (btwmodem)
DRV - [2009/02/10 04:53:56 | 000,156,816 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btwdndis.sys -- (BTWDNDIS)
DRV - [2009/02/10 04:53:52 | 000,037,160 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2009/02/10 04:53:50 | 000,991,656 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2009/02/10 04:53:44 | 000,534,568 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btaudio.sys -- (btaudio)
DRV - [2008/12/23 21:18:44 | 000,157,696 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RTS5121.sys -- (RSUSBSTOR)
DRV - [2008/11/05 02:24:58 | 000,014,248 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\EMSC.SYS -- (EMSC)
DRV - [2008/08/08 14:15:10 | 000,101,376 | R--- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008/07/10 03:49:14 | 000,242,712 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\RsFx0102.sys -- (RsFx0102)
DRV - [2008/04/14 13:16:24 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MPE.sys -- (MPE)
DRV - [2008/04/14 13:06:40 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/14 13:06:40 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/14 13:00:00 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008/04/14 00:15:14 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2001/08/18 03:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/18 03:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/18 03:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/18 03:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/18 03:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/18 02:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/18 02:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/18 02:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/18 02:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/18 02:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/18 02:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/18 02:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/18 02:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/18 02:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/18 02:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.uk.msn.com/USCON/2
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.msn.com/sphome.aspx
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://g.uk.msn.com/USCON/2

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USCON/2
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.co.uk/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..network.proxy.no_proxies_on: "*.local"


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/17 08:44:56 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/06/30 19:43:31 | 000,000,000 | ---D | M]

[2010/01/17 20:28:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Mozilla\Extensions
[2010/08/03 22:14:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Mozilla\Firefox\Profiles\17semocl.default\extensions
[2010/06/28 17:30:26 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Sarah\Application Data\Mozilla\Firefox\Profiles\17semocl.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/01/20 20:40:28 | 000,001,201 | ---- | M] () -- C:\Documents and Settings\Sarah\Application Data\Mozilla\Firefox\Profiles\17semocl.default\searchplugins\winamp-search.xml
[2010/08/03 22:14:53 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/08/03 22:17:03 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe (Dell)
O4 - HKLM..\Run: [CapsLKNotify] C:\Program Files\CapsLKNotify\CapsLKNotify.exe (Compal Electronics, Inc)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)
O4 - HKLM..\Run: [McPvTray] C:\Program Files\McAfee\Anti-Theft\McPvTray.exe (McAfee)
O4 - HKLM..\Run: [OA012Mon] C:\WINDOWS\OA012Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PersistenceThread] C:\WINDOWS\system32\PersistenceThread.exe (Intel Corporation)
O4 - HKLM..\Run: [TVEService] C:\Program Files\Dell\Digital TV\TVEService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe File not found
O4 - HKLM..\Run: [WSED] C:\Program Files\WSED\WSED.exe (Dell)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WDDMStatus.lnk = C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe (WDC)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WDSmartWare.lnk = C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe (Western Digital)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk = C:\Program Files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe ()
O4 - Startup: C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Sarah\Application Data\Dropbox\bin\Dropbox.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} http://download.mcaf...058/mcfscan.cab (McFreeScan Class)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igdlogin: DllName - igdlogin.dll - C:\WINDOWS\System32\igdlogin.dll ()
O24 - Desktop Components:0 () - file:///C:/DOCUME~1/Sarah/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/26 02:45:49 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2008/04/23 22:44:40 | 000,114,688 | R--- | M] (Huawei Technologies Co., Ltd.) - D:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2008/09/17 18:12:34 | 000,000,045 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{65b4fa2e-56ee-11df-9b5c-00265ea185c9}\Shell - "" = AutoRun
O33 - MountPoints2\{65b4fa2e-56ee-11df-9b5c-00265ea185c9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{65b4fa2e-56ee-11df-9b5c-00265ea185c9}\Shell\AutoRun\command - "" = D:\WD SmartWare.exe -- File not found
O33 - MountPoints2\{971071f2-58e7-11df-9b60-00265ea185c9}\Shell - "" = AutoRun
O33 - MountPoints2\{971071f2-58e7-11df-9b60-00265ea185c9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{971071f2-58e7-11df-9b60-00265ea185c9}\Shell\AutoRun\command - "" = D:\AutoRun.exe -- [2008/04/23 22:44:40 | 000,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{971071f7-58e7-11df-9b60-00265ea185c9}\Shell - "" = AutoRun
O33 - MountPoints2\{971071f7-58e7-11df-9b60-00265ea185c9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{971071f7-58e7-11df-9b60-00265ea185c9}\Shell\AutoRun\command - "" = D:\AutoRun.exe -- [2008/04/23 22:44:40 | 000,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{971071f8-58e7-11df-9b60-00265ea185c9}\Shell - "" = AutoRun
O33 - MountPoints2\{971071f8-58e7-11df-9b60-00265ea185c9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{971071f8-58e7-11df-9b60-00265ea185c9}\Shell\AutoRun\command - "" = D:\AutoRun.exe -- [2008/04/23 22:44:40 | 000,114,688 | R--- | M] (Huawei Technologies Co., Ltd.)
O33 - MountPoints2\{c79e979a-5910-11df-9b61-00265ea185c9}\Shell - "" = AutoRun
O33 - MountPoints2\{c79e979a-5910-11df-9b61-00265ea185c9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c79e979a-5910-11df-9b61-00265ea185c9}\Shell\AutoRun\command - "" = E:\AutoRun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 90 Days ==========

[2010/08/03 22:15:10 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/08/02 21:57:21 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\OTL.com
[2010/08/02 21:56:03 | 000,258,560 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\stap1.com
[2010/07/30 13:34:34 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/07/30 13:34:32 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/07/30 13:34:32 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/30 13:34:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/07/30 12:59:56 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/07/30 12:57:52 | 000,000,000 | ---D | C] -- C:\!KillBox
[2010/07/30 12:53:05 | 000,092,672 | ---- | C] (Option^Explicit Software [email protected]) -- C:\Documents and Settings\Sarah\Desktop\KillBox.exe
[2010/07/30 12:50:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Local Settings\Application Data\Threat Expert
[2010/07/18 20:20:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Local Settings\Application Data\PCHealth
[2010/07/18 19:57:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Desktop\Photos
[2010/07/17 10:00:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\McAfee.com
[2010/07/16 23:12:41 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2010/07/16 21:47:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Citrix
[2010/07/16 21:42:09 | 000,000,000 | ---D | C] -- C:\Program Files\Citrix
[2010/07/16 21:41:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Local Settings\Application Data\Citrix
[2010/07/15 18:33:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\McAfee Anti-Theft
[2010/07/15 18:32:43 | 000,000,000 | R-SD | C] -- C:\Documents and Settings\Sarah\My Documents\McAfee Vaults
[2010/06/09 21:52:37 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Sarah\My Documents\My Dropbox
[2010/06/09 21:50:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Sarah\Application Data\Dropbox
[2010/05/25 21:29:39 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/05/25 21:29:28 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/05/25 21:28:14 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2010/05/17 19:50:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/05/17 19:39:59 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2010/05/06 11:38:16 | 000,000,000 | ---D | C] -- C:\spoolerlogs
[2010/05/06 09:17:36 | 000,872,192 | R--- | C] (DiBcom SA) -- C:\WINDOWS\System32\drivers\mod7700.sys
[2010/05/06 09:17:36 | 000,103,168 | R--- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbfake.sys
[2010/05/06 09:17:36 | 000,101,376 | R--- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbmdm.sys
[2010/05/06 09:17:36 | 000,100,992 | R--- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbnet.sys
[2010/05/06 09:17:36 | 000,024,448 | R--- | C] (Huawei Tech. Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewdcsc.sys
[2010/05/06 09:17:07 | 000,000,000 | ---D | C] -- C:\Program Files\Orange Mobile Partner

========== Files - Modified Within 90 Days ==========

[2010/08/03 22:38:04 | 000,000,754 | ---- | M] () -- C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk
[2010/08/03 22:31:30 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/08/03 22:31:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/08/03 22:31:20 | 1063,538,688 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/03 22:24:10 | 007,077,888 | -H-- | M] () -- C:\Documents and Settings\Sarah\NTUSER.DAT
[2010/08/03 22:24:10 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Sarah\ntuser.ini
[2010/08/03 22:17:03 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2010/08/02 21:57:21 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\OTL.com
[2010/08/02 21:56:03 | 000,258,560 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sarah\Desktop\stap1.com
[2010/08/02 21:34:53 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/07/30 13:52:03 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/30 13:34:38 | 000,000,698 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/30 13:20:44 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\HiJackThis.lnk
[2010/07/30 13:16:10 | 000,007,360 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/07/30 13:12:45 | 000,115,712 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\Doc1.doc
[2010/07/30 12:53:06 | 000,092,672 | ---- | M] (Option^Explicit Software [email protected]) -- C:\Documents and Settings\Sarah\Desktop\KillBox.exe
[2010/07/26 18:32:04 | 000,002,155 | ---- | M] () -- C:\Documents and Settings\Sarah\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/07/18 03:03:50 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/07/16 23:23:24 | 000,000,817 | ---- | M] () -- C:\Documents and Settings\Sarah\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/16 21:41:43 | 000,103,784 | ---- | M] () -- C:\Documents and Settings\Sarah\GoToAssistDownloadHelper.exe
[2010/07/15 17:27:20 | 000,332,280 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/07/14 20:57:03 | 000,088,320 | ---- | M] () -- C:\Documents and Settings\Sarah\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/06/24 18:40:07 | 000,629,376 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/06/24 18:40:07 | 000,532,294 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/06/24 18:40:07 | 000,104,434 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/06/11 08:16:47 | 000,000,603 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/06/09 21:52:38 | 000,000,996 | ---- | M] () -- C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\Dropbox.lnk
[2010/06/09 21:52:37 | 000,000,996 | ---- | M] () -- C:\Documents and Settings\Sarah\Desktop\Dropbox.lnk
[2010/05/25 21:30:54 | 000,001,804 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/05/06 09:17:59 | 000,000,840 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Orange Mobile Partner.lnk

========== Files Created - No Company Name ==========

[2010/07/30 13:34:38 | 000,000,698 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/30 13:12:44 | 000,115,712 | ---- | C] () -- C:\Documents and Settings\Sarah\Desktop\Doc1.doc
[2010/07/30 12:59:57 | 000,002,447 | ---- | C] () -- C:\Documents and Settings\Sarah\Desktop\HiJackThis.lnk
[2010/07/16 23:23:24 | 000,000,817 | ---- | C] () -- C:\Documents and Settings\Sarah\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/07/16 21:41:40 | 000,103,784 | ---- | C] () -- C:\Documents and Settings\Sarah\GoToAssistDownloadHelper.exe
[2010/06/09 21:52:38 | 000,000,996 | ---- | C] () -- C:\Documents and Settings\Sarah\Start Menu\Programs\Startup\Dropbox.lnk
[2010/06/09 21:52:37 | 000,000,996 | ---- | C] () -- C:\Documents and Settings\Sarah\Desktop\Dropbox.lnk
[2010/05/25 21:30:54 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/05/18 20:20:22 | 000,002,155 | ---- | C] () -- C:\Documents and Settings\Sarah\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2010/05/06 09:17:59 | 000,000,840 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Orange Mobile Partner.lnk
[2010/01/31 11:24:46 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2010/01/20 21:23:36 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010/01/20 21:23:36 | 000,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2010/01/05 12:38:32 | 000,176,235 | ---- | C] () -- C:\WINDOWS\System32\Primomonnt.dll
[2009/09/11 05:45:42 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll
[2009/09/11 01:32:14 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\igdlogin.dll
[2009/09/11 01:27:49 | 000,001,203 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2009/09/10 23:33:00 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2009/09/10 23:10:01 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2009/09/10 23:09:58 | 000,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2009/09/10 23:09:22 | 000,000,917 | ---- | C] () -- C:\WINDOWS\System32\CLWatson.ini
[2009/09/10 23:07:13 | 000,577,536 | ---- | C] () -- C:\WINDOWS\System32\EMSC.DLL
[2009/07/31 02:58:42 | 000,000,314 | ---- | C] () -- C:\WINDOWS\primopdf.ini
[2008/09/29 20:39:00 | 002,854,976 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll
[2008/04/26 02:42:57 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2007/09/27 16:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 16:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 16:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2005/05/17 01:00:00 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\ernel32.dll
[2005/02/17 18:41:32 | 000,000,603 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2005/02/17 18:41:30 | 000,000,593 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/11/14 19:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll

========== LOP Check ==========

[2009/11/21 14:11:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2010/07/16 21:47:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix
[2010/07/30 13:36:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Temp
[2009/11/10 20:50:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trusteer
[2009/10/02 00:32:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Uninstall
[2009/09/10 23:07:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Vista32
[2009/09/10 23:07:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Vista64
[2010/05/03 21:03:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Western Digital
[2009/09/10 23:14:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\XP32
[2010/05/17 19:51:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/04 17:12:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/11/21 14:17:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Autodesk
[2009/10/04 16:59:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2010/08/03 22:37:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Dropbox
[2010/01/20 21:24:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\iPodtoComputer
[2010/07/14 06:33:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\PrimoPDF
[2010/06/14 23:14:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Spotify
[2009/11/10 20:52:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Trusteer
[2010/05/03 21:03:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Western Digital
[2009/09/10 23:04:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Windows Desktop Search
[2009/09/25 08:48:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarah\Application Data\Windows Search

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:A8ADE5D8
< End of report >


Mbam log -

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

03/08/2010 23:02:57
mbam-log-2010-08-03 (23-02-57).txt

Scan type: Quick scan
Objects scanned: 117223
Time elapsed: 9 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 21
Registry Values Infected: 0
Registry Data Items Infected: 12
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aluschedulersvc.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avciman.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avengine.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmscsvc.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcnasvc.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcproxy.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsacore.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcshell.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsysmon.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpfsrv.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavfnsvr.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavprsrv.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psctrls.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psimsvc.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psksvc.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tpsrv.exe (Security.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webproxy.exe (Security.Hijack) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/...q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/...q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-19\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/...q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/...q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-20\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/...q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/...q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/...q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{424b726b-388f-4caa-9215-8433037a136c}\DhcpNameServer (Trojan.DNSChanger) -> Data: 93.188.162.65,93.188.161.205 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{424b726b-388f-4caa-9215-8433037a136c}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.65,93.188.161.205 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5c03bcff-dc9d-4301-bbc1-4dbd34da00a4}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.65,93.188.161.205 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{b4db39d4-bf1c-403a-9028-d3024e28cbd5}\DhcpNameServer (Trojan.DNSChanger) -> Data: 93.188.162.65,93.188.161.205 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{b4db39d4-bf1c-403a-9028-d3024e28cbd5}\NameServer (Trojan.DNSChanger) -> Data: 93.188.162.65,93.188.161.205 -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Attached Files


  • 0

#8
BlackOxide

BlackOxide

    Trusted Helper

  • Malware Removal
  • 1,976 posts
Hey,

Don't worry about GMER crashing, we'll just try an alternative Rootkit scan instead :)

Good to hear it's running better now. We still need to do a couple more scans just to make sure any other malware items aren't lurking elsewhere :)


Please do the following steps...


1)
Download RootRepeal from one of the following locations and save it to your desktop:Link 1
Link 2
Link 3
  • Double click Posted Image to start the program
  • Click on the Report tab at the bottom of the program window
  • Click the Posted Image button
  • In the Select Scan dialog, check:
    • Drivers
    • Files
    • Processes
    • SSDT
    • Stealth Objects
    • Hidden Services
    • Shadow SSDT
  • Click the OK button
  • In the next dialog, select all drives showing
  • Click OK to start the scan

    Note: The scan can take some time. DO NOT run any other programs while the scan is running

  • When the scan is complete, click the Posted Image button and save the report to your Desktop as RootRepeal.txt
  • Go to File, then Exit to close the program
If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.




2)
Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic




3)
Could you try installing an Anti Virus or try getting your original one working, as the infections were previously stopping you doing this. Just let me know if you can now install and run an Anti Virus without any problems. Thanks


In your next reply
Please post the contents of...
RootRepeal log
ESET Online log
Let me know if you are now able to install and use an Anti Virus


:)
  • 0

#9
sgil

sgil

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Steps 1 and 2 completed successfully, reports below. I tried to reinstall McAfee which successfully initialised this time (having not even started before) however it asks me to remove incompatible software which in this case is Security Master AV. I know this is the false security system which probably started the whole thing, does this mean it is still on my computer? How do I remove it? Or can I just continue installing McAfee and Ignore it?

Thanks

RootRepeal -

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2010/08/05 05:36
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF5732000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7BFD000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xEB291000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!

Path: c:\windows\temp\perflib_perfdata_130.dat
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\log\log_424.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\log\log_426.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\log\log_427.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\log\log_428.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: C:\Documents and Settings\Sarah\Local Settings\Apps\2.0\EYKAAHY5.L4H\N3VL0QR6.XW0\manifests\PdfSharp.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Sarah\Local Settings\Apps\2.0\EYKAAHY5.L4H\N3VL0QR6.XW0\manifests\PdfSharp.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Sarah\Local Settings\Apps\2.0\EYKAAHY5.L4H\N3VL0QR6.XW0\manifests\StromaCode.exe.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\Sarah\Local Settings\Apps\2.0\EYKAAHY5.L4H\N3VL0QR6.XW0\manifests\StromaCode.exe.manifest
Status: Locked to the Windows API!

SSDT
-------------------
#: 019 Function Name: NtAssignProcessToJobObject
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf5933e26

#: 037 Function Name: NtCreateFile
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf5934704

#: 062 Function Name: NtDeleteFile
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf5934864

#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf5938086

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf59380b8

#: 098 Function Name: NtLoadKey
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf593821a

#: 116 Function Name: NtOpenFile
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf59347c8

#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf5933f6a

#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf593415c

#: 137 Function Name: NtProtectVirtualMemory
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf593428e

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf5938190

#: 192 Function Name: NtRenameKey
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf59380fa

#: 193 Function Name: NtReplaceKey
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf593812c

#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf593815e

#: 213 Function Name: NtSetContextThread
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf5933dcc

#: 224 Function Name: NtSetInformationFile
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf59348c4

#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf593801e

#: 254 Function Name: NtSuspendThread
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf5933d68

#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf5933cbc

#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf5933d04

Shadow SSDT
-------------------
#: 007 Function Name: NtGdiAlphaBlend
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf593a650

#: 013 Function Name: NtGdiBitBlt
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf593a4e2

#: 227 Function Name: NtGdiMaskBlt
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf593a58a

#: 237 Function Name: NtGdiPlgBlt
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf593a5d8

#: 292 Function Name: NtGdiStretchBlt
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf593a530

#: 298 Function Name: NtGdiTransparentBlt
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf593a614

#: 378 Function Name: NtUserFindWindowEx
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf5934bec

#: 477 Function Name: NtUserPrintWindow
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf593a68c

#: 483 Function Name: NtUserQueryWindow
Status: Hooked by "C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys" at address 0xf5934b60

==EOF==

ESET online scan

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=fb9c404cc75b7a4f965e51f047599f86
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-08-05 05:55:25
# local_time=2010-08-05 06:55:25 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 493937 493937 0 0
# compatibility_mode=8192 67108863 100 0 209 209 0 0
# scanned=66520
# found=6
# cleaned=6
# scan_time=2596
C:\Documents and Settings\Sarah\Application Data\d8f7e1f8.exe a variant of Win32/Kryptik.FIX trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ernel32.dll a variant of Win32/Kryptik.FIX trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\_OTL\MovedFiles\08032010_221510\C_Documents and Settings\All Users\Application Data\c1d9f4b\SMc1d9.exe Win32/Adware.VirusAlarmPro application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\_OTL\MovedFiles\08032010_221510\C_Documents and Settings\All Users\Application Data\c1d9f4b\SMc1d9_302.exe Win32/Adware.VirusAlarmPro application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\_OTL\MovedFiles\08032010_221510\C_Documents and Settings\Sarah\Local Settings\Temp\Fn1.exe Win32/TrojanDownloader.FakeAlert.BBB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\_OTL\MovedFiles\08032010_221510\C_WINDOWS\System32\drivers\etc\hosts Win32/Qhost trojan (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C

Attached Files


  • 0

#10
BlackOxide

BlackOxide

    Trusted Helper

  • Malware Removal
  • 1,976 posts
Ok, no worries, leave the McAfee installation for now, we'll try installing it again shortly. There obviously seems as though there are some remnants that may be left over from Security Master AV. The actual program itself has been removed earlier though. Lets see if we can clear them up, please follow the instructions below :)


Download ComboFix from one of these locations:

Link 1
Link 2


IMPORTANT !!! You need to Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you are still unsure on how to do this, see here
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

Click Yes, to continue scanning for malware. Please be patient and don't use the PC whilst it is scanning.

When finished, it shall produce a log for you. Please copy & paste the contents of this log (also found at C:\ComboFix.txt) in your next reply.


In your next reply
Please post the contents of...
ComboFix.txt
  • 0

Advertisements


#11
sgil

sgil

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Combo fix report below -

I ran the software even though it said I had McAfee installed as currently it is not a programme within my control panel or something I can switch off as it is not fully installed at the mo. Hope that was ok.

ComboFix 10-08-05.02 - Sarah 06/08/2010 18:19:46.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.205 [GMT 1:00]
Running from: c:\documents and settings\Sarah\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\2057\L10NRes.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\CodeRes.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\Compat.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\Dwnload.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\Install.exe
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\McBrwsr2.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\McUtil.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\SelfProtect\Win32\aploader.exe
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\SelfProtect\Win32\mfeapfa.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\SelfProtect\Win32\mfehida.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\SelfProtect\Win32\mfehidin.exe
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\SysCheck.dll
c:\documents and settings\Sarah\GoToAssistDownloadHelper.exe
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\2057\L10NRes.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\CodeRes.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\Compat.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\Dwnload.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\Install.exe
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\McBrwsr2.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\McUtil.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\SelfProtect\Win32\aploader.exe
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\SelfProtect\Win32\mfeapfa.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\SelfProtect\Win32\mfehida.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\SelfProtect\Win32\mfehidin.exe
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\SysCheck.dll
c:\documents and settings\Sarah\Recent\ANTIGEN.dll
c:\documents and settings\Sarah\Recent\CLSV.dll
c:\documents and settings\Sarah\Recent\DBOLE.dll
c:\documents and settings\Sarah\Recent\dudl.drv
c:\documents and settings\Sarah\Recent\eb.sys
c:\documents and settings\Sarah\Recent\energy.drv
c:\documents and settings\Sarah\Recent\fan.drv
c:\documents and settings\Sarah\Recent\gid.tmp
c:\documents and settings\Sarah\Recent\hymt.exe
c:\documents and settings\Sarah\Recent\hymt.sys
c:\documents and settings\Sarah\Recent\kernel32.drv
c:\documents and settings\Sarah\Recent\pal.exe
c:\documents and settings\Sarah\Recent\PE.dll

.
((((((((((((((((((((((((( Files Created from 2010-07-06 to 2010-08-06 )))))))))))))))))))))))))))))))
.

2010-08-05 05:08 . 2010-08-05 05:08 -------- d-----w- c:\program files\ESET
2010-08-03 21:51 . 2010-08-03 21:51 -------- d-----w- c:\documents and settings\Sarah\Application Data\Malwarebytes
2010-08-03 21:15 . 2010-08-03 21:15 -------- d-----w- C:\_OTL
2010-07-30 12:34 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-30 12:34 . 2010-08-03 21:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-30 12:34 . 2010-07-30 12:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-30 12:34 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-30 11:59 . 2010-07-30 11:59 -------- d-----w- c:\program files\Trend Micro
2010-07-30 11:57 . 2010-07-30 11:57 -------- d-----w- C:\!KillBox
2010-07-30 11:50 . 2010-07-30 11:50 -------- d-----w- c:\documents and settings\Sarah\Local Settings\Application Data\Threat Expert
2010-07-26 17:22 . 2008-04-13 23:15 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-07-26 17:22 . 2008-04-13 23:15 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-07-18 19:20 . 2010-07-18 19:20 -------- d-----w- c:\documents and settings\Sarah\Local Settings\Application Data\PCHealth
2010-07-17 09:00 . 2010-07-17 09:00 -------- d-----w- c:\windows\McAfee.com
2010-07-16 22:12 . 2010-07-16 22:13 -------- dc-h--w- c:\windows\ie8
2010-07-16 20:47 . 2010-07-16 20:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Citrix
2010-07-16 20:42 . 2010-07-16 20:42 -------- d-----w- c:\program files\Citrix
2010-07-16 20:41 . 2010-07-16 20:41 -------- d-----w- c:\documents and settings\Sarah\Local Settings\Application Data\Citrix
2010-07-15 17:33 . 2010-07-15 17:33 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Anti-Theft
2010-07-14 04:17 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-06 16:56 . 2010-06-09 20:50 -------- d-----w- c:\documents and settings\Sarah\Application Data\Dropbox
2010-08-05 21:22 . 2010-02-03 20:28 -------- d-----w- c:\program files\McAfee
2010-08-05 06:03 . 2009-09-10 22:27 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2010-07-30 12:36 . 2009-09-10 22:08 -------- d---a-w- c:\documents and settings\All Users\Application Data\Temp
2010-07-30 12:16 . 2010-02-13 10:25 7360 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-17 07:49 . 2010-03-21 16:15 -------- d-----w- c:\program files\McAfeeMOBK
2010-07-17 07:48 . 2010-02-03 20:28 -------- d-----w- c:\program files\Common Files\McAfee
2010-07-15 17:29 . 2010-03-21 15:47 -------- d-----w- c:\documents and settings\Sarah\Application Data\McAfee
2010-07-14 19:57 . 2009-09-25 07:44 88320 ----a-w- c:\documents and settings\Sarah\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-14 05:33 . 2010-01-05 11:41 -------- d-----w- c:\documents and settings\Sarah\Application Data\PrimoPDF
2010-07-01 11:07 . 2010-07-01 11:07 434176 ----a-w- c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\17053\RapportMS.dll
2010-06-28 16:27 . 2009-10-04 15:59 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-14 22:14 . 2009-10-04 16:33 -------- d-----w- c:\documents and settings\Sarah\Application Data\Spotify
2010-06-14 14:31 . 2008-04-26 01:44 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-09 20:51 . 2010-06-09 20:51 89831 ----a-w- c:\documents and settings\Sarah\Application Data\Dropbox\bin\Uninstall.exe
2010-05-17 18:35 . 2010-05-17 18:35 655360 ----a-w- c:\documents and settings\Sarah\Application Data\Spotify\Gracenote\gnsdk_sdkmanager.dll
2010-05-17 18:35 . 2010-05-17 18:35 282624 ----a-w- c:\documents and settings\Sarah\Application Data\Spotify\Gracenote\gnsdk_musicid_file.dll
2010-05-17 18:35 . 2010-05-17 18:35 208896 ----a-w- c:\documents and settings\Sarah\Application Data\Spotify\Gracenote\gnsdk_dsp.dll
2009-09-10 22:13 . 2009-09-10 22:13 75 --sh--r- c:\windows\CT4CET.bin
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Sarah\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Sarah\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Sarah\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-05-26 488960]
"RTHDCPL"="RTHDCPL.EXE" [2009-03-30 17529856]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-04-06 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-04-06 348160]
"PersistenceThread"="c:\windows\system32\PersistenceThread.exe" [2009-04-06 86016]
"OA012Mon"="c:\windows\OA012Mon.exe" [2009-04-02 24576]
"WSED"="c:\program files\WSED\WSED.exe" [2009-05-27 247080]
"BTMeter"="c:\program files\Battery Meter\BTMeter.exe" [2008-11-05 623912]
"TVEService"="c:\program files\Dell\Digital TV\TVEService.exe" [2009-02-27 185576]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2009-02-18 2441216]
"CapsLKNotify"="c:\program files\CapsLKNotify\CapsLKNotify.exe" [2009-03-17 320808]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-07-07 1779952]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-04 128232]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Sarah\Start Menu\Programs\Startup\
BBC iPlayer Desktop.lnk - c:\program files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe [2010-4-5 95232]
Dropbox.lnk - c:\documents and settings\Sarah\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-29 604776]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-10-14 2049344]
WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-10-14 9085760]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-27 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igdlogin]
2009-04-06 23:03 65536 ----a-w- c:\windows\system32\igdlogin.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\Digital TV\\TVEnhance.exe"=
"c:\\Program Files\\Dell\\Digital TV\\TVEService.exe"=
"c:\\Program Files\\Dell Video Chat\\DellVideoChat.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Sarah\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=

R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [10/09/2009 23:07 14248]
R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [01/07/2010 12:07 59240]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [01/07/2010 12:07 166632]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [01/07/2010 12:07 840936]
R2 TVECapSvc;TVEnhance Background Capture Service (TBCS);c:\program files\Dell\Digital TV\Kernel\TV\TVECapSvc.exe [10/09/2009 23:09 382304]
R2 TVESched;TVEnhance Task Scheduler (TTS));c:\program files\Dell\Digital TV\Kernel\TV\TVESched.exe [10/09/2009 23:09 189792]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [14/10/2009 14:31 98304]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [16/06/2009 09:58 20480]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [10/09/2009 23:13 143840]
R3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\drivers\ETD.sys [11/09/2009 01:31 93952]
R3 hcw17bda;Hauppauge SMS1000-based;c:\windows\system32\drivers\hcw17bda.sys [11/09/2009 01:32 45824]
R3 igd;igd;c:\windows\system32\drivers\igxpmp32.sys [11/09/2009 01:32 5088896]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [11/09/2009 01:32 110080]
R3 OA012Afx;Provides a software interface to control audio effects of OA012 camera.;c:\windows\system32\drivers\OA012Afx.sys [11/09/2009 01:32 135168]
R3 OA012Ufd;Creative Camera OA012 Upper Filter Driver;c:\windows\system32\drivers\OA012Ufd.sys [11/09/2009 01:32 133632]
R3 OA012Vid;Creative Camera OA012 Function Driver;c:\windows\system32\drivers\OA012Vid.sys [11/09/2009 01:32 272032]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [11/09/2009 01:31 157696]
S0 McPvDrv;McPvDrv Driver;c:\windows\system32\drivers\McPvDrv.sys --> c:\windows\system32\drivers\McPvDrv.sys [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [11/09/2009 01:31 1684736]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [03/05/2010 21:03 11520]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [11/07/2008 01:28 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [10/07/2008 03:49 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [11/07/2008 01:28 369688]
.
Contents of the 'Scheduled Tasks' folder

2010-07-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\documents and settings\Sarah\Application Data\Mozilla\Firefox\Profiles\17semocl.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
Attached File  combo fix log.txt   20.37KB   328 downloads.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-06 18:31
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(900)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2010-08-06 18:35:57
ComboFix-quarantined-files.txt 2010-08-06 17:35

Pre-Run: 118,033,068,032 bytes free
Post-Run: 117,979,746,304 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

Current=2 Default=2 Failed=3 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - DEB0DB0CB170251840CAD7F49CC16B43
  • 0

#12
sgil

sgil

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Combo fix report below -

I ran the software even though it said I had McAfee installed as currently it is not a programme within my control panel or something I can switch off as it is not fully installed at the mo. Hope that was ok.

ComboFix 10-08-05.02 - Sarah 06/08/2010 18:19:46.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.205 [GMT 1:00]
Running from: c:\documents and settings\Sarah\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\2057\L10NRes.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\CodeRes.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\Compat.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\Dwnload.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\Install.exe
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\McBrwsr2.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\McUtil.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\SelfProtect\Win32\aploader.exe
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\SelfProtect\Win32\mfeapfa.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\SelfProtect\Win32\mfehida.dll
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\SelfProtect\Win32\mfehidin.exe
c:\docume~1\Sarah\LOCALS~1\Temp\McInstallTemp\SysCheck.dll
c:\documents and settings\Sarah\GoToAssistDownloadHelper.exe
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\2057\L10NRes.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\CodeRes.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\Compat.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\Dwnload.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\Install.exe
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\McBrwsr2.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\McUtil.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\SelfProtect\Win32\aploader.exe
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\SelfProtect\Win32\mfeapfa.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\SelfProtect\Win32\mfehida.dll
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\SelfProtect\Win32\mfehidin.exe
c:\documents and settings\Sarah\Local Settings\Temp\McInstallTemp\SysCheck.dll
c:\documents and settings\Sarah\Recent\ANTIGEN.dll
c:\documents and settings\Sarah\Recent\CLSV.dll
c:\documents and settings\Sarah\Recent\DBOLE.dll
c:\documents and settings\Sarah\Recent\dudl.drv
c:\documents and settings\Sarah\Recent\eb.sys
c:\documents and settings\Sarah\Recent\energy.drv
c:\documents and settings\Sarah\Recent\fan.drv
c:\documents and settings\Sarah\Recent\gid.tmp
c:\documents and settings\Sarah\Recent\hymt.exe
c:\documents and settings\Sarah\Recent\hymt.sys
c:\documents and settings\Sarah\Recent\kernel32.drv
c:\documents and settings\Sarah\Recent\pal.exe
c:\documents and settings\Sarah\Recent\PE.dll

.
((((((((((((((((((((((((( Files Created from 2010-07-06 to 2010-08-06 )))))))))))))))))))))))))))))))
.

2010-08-05 05:08 . 2010-08-05 05:08 -------- d-----w- c:\program files\ESET
2010-08-03 21:51 . 2010-08-03 21:51 -------- d-----w- c:\documents and settings\Sarah\Application Data\Malwarebytes
2010-08-03 21:15 . 2010-08-03 21:15 -------- d-----w- C:\_OTL
2010-07-30 12:34 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-30 12:34 . 2010-08-03 21:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-30 12:34 . 2010-07-30 12:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-30 12:34 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-30 11:59 . 2010-07-30 11:59 -------- d-----w- c:\program files\Trend Micro
2010-07-30 11:57 . 2010-07-30 11:57 -------- d-----w- C:\!KillBox
2010-07-30 11:50 . 2010-07-30 11:50 -------- d-----w- c:\documents and settings\Sarah\Local Settings\Application Data\Threat Expert
2010-07-26 17:22 . 2008-04-13 23:15 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-07-26 17:22 . 2008-04-13 23:15 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-07-18 19:20 . 2010-07-18 19:20 -------- d-----w- c:\documents and settings\Sarah\Local Settings\Application Data\PCHealth
2010-07-17 09:00 . 2010-07-17 09:00 -------- d-----w- c:\windows\McAfee.com
2010-07-16 22:12 . 2010-07-16 22:13 -------- dc-h--w- c:\windows\ie8
2010-07-16 20:47 . 2010-07-16 20:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Citrix
2010-07-16 20:42 . 2010-07-16 20:42 -------- d-----w- c:\program files\Citrix
2010-07-16 20:41 . 2010-07-16 20:41 -------- d-----w- c:\documents and settings\Sarah\Local Settings\Application Data\Citrix
2010-07-15 17:33 . 2010-07-15 17:33 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Anti-Theft
2010-07-14 04:17 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-06 16:56 . 2010-06-09 20:50 -------- d-----w- c:\documents and settings\Sarah\Application Data\Dropbox
2010-08-05 21:22 . 2010-02-03 20:28 -------- d-----w- c:\program files\McAfee
2010-08-05 06:03 . 2009-09-10 22:27 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2010-07-30 12:36 . 2009-09-10 22:08 -------- d---a-w- c:\documents and settings\All Users\Application Data\Temp
2010-07-30 12:16 . 2010-02-13 10:25 7360 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-17 07:49 . 2010-03-21 16:15 -------- d-----w- c:\program files\McAfeeMOBK
2010-07-17 07:48 . 2010-02-03 20:28 -------- d-----w- c:\program files\Common Files\McAfee
2010-07-15 17:29 . 2010-03-21 15:47 -------- d-----w- c:\documents and settings\Sarah\Application Data\McAfee
2010-07-14 19:57 . 2009-09-25 07:44 88320 ----a-w- c:\documents and settings\Sarah\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-14 05:33 . 2010-01-05 11:41 -------- d-----w- c:\documents and settings\Sarah\Application Data\PrimoPDF
2010-07-01 11:07 . 2010-07-01 11:07 434176 ----a-w- c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportMS\17053\RapportMS.dll
2010-06-28 16:27 . 2009-10-04 15:59 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-14 22:14 . 2009-10-04 16:33 -------- d-----w- c:\documents and settings\Sarah\Application Data\Spotify
2010-06-14 14:31 . 2008-04-26 01:44 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-09 20:51 . 2010-06-09 20:51 89831 ----a-w- c:\documents and settings\Sarah\Application Data\Dropbox\bin\Uninstall.exe
2010-05-17 18:35 . 2010-05-17 18:35 655360 ----a-w- c:\documents and settings\Sarah\Application Data\Spotify\Gracenote\gnsdk_sdkmanager.dll
2010-05-17 18:35 . 2010-05-17 18:35 282624 ----a-w- c:\documents and settings\Sarah\Application Data\Spotify\Gracenote\gnsdk_musicid_file.dll
2010-05-17 18:35 . 2010-05-17 18:35 208896 ----a-w- c:\documents and settings\Sarah\Application Data\Spotify\Gracenote\gnsdk_dsp.dll
2009-09-10 22:13 . 2009-09-10 22:13 75 --sh--r- c:\windows\CT4CET.bin
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Sarah\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Sarah\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Sarah\Application Data\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2009-05-26 488960]
"RTHDCPL"="RTHDCPL.EXE" [2009-03-30 17529856]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-04-06 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-04-06 348160]
"PersistenceThread"="c:\windows\system32\PersistenceThread.exe" [2009-04-06 86016]
"OA012Mon"="c:\windows\OA012Mon.exe" [2009-04-02 24576]
"WSED"="c:\program files\WSED\WSED.exe" [2009-05-27 247080]
"BTMeter"="c:\program files\Battery Meter\BTMeter.exe" [2008-11-05 623912]
"TVEService"="c:\program files\Dell\Digital TV\TVEService.exe" [2009-02-27 185576]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2009-02-18 2441216]
"CapsLKNotify"="c:\program files\CapsLKNotify\CapsLKNotify.exe" [2009-03-17 320808]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2009-07-07 1779952]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-04 128232]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-04-13 47392]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Sarah\Start Menu\Programs\Startup\
BBC iPlayer Desktop.lnk - c:\program files\BBC iPlayer Desktop\BBC iPlayer Desktop.exe [2010-4-5 95232]
Dropbox.lnk - c:\documents and settings\Sarah\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-29 604776]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-10-14 2049344]
WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-10-14 9085760]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-27 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igdlogin]
2009-04-06 23:03 65536 ----a-w- c:\windows\system32\igdlogin.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\Digital TV\\TVEnhance.exe"=
"c:\\Program Files\\Dell\\Digital TV\\TVEService.exe"=
"c:\\Program Files\\Dell Video Chat\\DellVideoChat.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\Sarah\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=

R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [10/09/2009 23:07 14248]
R1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [01/07/2010 12:07 59240]
R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [01/07/2010 12:07 166632]
R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [01/07/2010 12:07 840936]
R2 TVECapSvc;TVEnhance Background Capture Service (TBCS);c:\program files\Dell\Digital TV\Kernel\TV\TVECapSvc.exe [10/09/2009 23:09 382304]
R2 TVESched;TVEnhance Task Scheduler (TTS));c:\program files\Dell\Digital TV\Kernel\TV\TVESched.exe [10/09/2009 23:09 189792]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [14/10/2009 14:31 98304]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [16/06/2009 09:58 20480]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [10/09/2009 23:13 143840]
R3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\drivers\ETD.sys [11/09/2009 01:31 93952]
R3 hcw17bda;Hauppauge SMS1000-based;c:\windows\system32\drivers\hcw17bda.sys [11/09/2009 01:32 45824]
R3 igd;igd;c:\windows\system32\drivers\igxpmp32.sys [11/09/2009 01:32 5088896]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [11/09/2009 01:32 110080]
R3 OA012Afx;Provides a software interface to control audio effects of OA012 camera.;c:\windows\system32\drivers\OA012Afx.sys [11/09/2009 01:32 135168]
R3 OA012Ufd;Creative Camera OA012 Upper Filter Driver;c:\windows\system32\drivers\OA012Ufd.sys [11/09/2009 01:32 133632]
R3 OA012Vid;Creative Camera OA012 Function Driver;c:\windows\system32\drivers\OA012Vid.sys [11/09/2009 01:32 272032]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [11/09/2009 01:31 157696]
S0 McPvDrv;McPvDrv Driver;c:\windows\system32\drivers\McPvDrv.sys --> c:\windows\system32\drivers\McPvDrv.sys [?]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [11/09/2009 01:31 1684736]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [03/05/2010 21:03 11520]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [11/07/2008 01:28 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [10/07/2008 03:49 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [11/07/2008 01:28 369688]
.
Contents of the 'Scheduled Tasks' folder

2010-07-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\documents and settings\Sarah\Application Data\Mozilla\Firefox\Profiles\17semocl.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
Attached File  combo fix log.txt   20.37KB   328 downloads.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-06 18:31
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(900)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2010-08-06 18:35:57
ComboFix-quarantined-files.txt 2010-08-06 17:35

Pre-Run: 118,033,068,032 bytes free
Post-Run: 117,979,746,304 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

Current=2 Default=2 Failed=3 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - DEB0DB0CB170251840CAD7F49CC16B43
  • 0

#13
BlackOxide

BlackOxide

    Trusted Helper

  • Malware Removal
  • 1,976 posts
Yep you were Ok to run it, no worries :)

There is a slight trace of Trend Micro AntiVirus on your PC. I think the best way to get McAfee to reinstall properly, is to remove all traces of Trend Micro, using their removal software, then get rid of all the traces of McAfee, just in case some of those files which are still there, have become corrupt or misplaced. Then after this, try installing McAfee again. Please follow the steps below to complete these...


First of all, just ensure you have a full McAfee product to install with at the end. It is either provided on a disc with an enclosed license, or you can go here to access your account online where your license key and software should be available to you :)



1)
Remove all traces of Trend Micro
Click here and follow the instructions on Trend Micro's website to remove any leftovers of their software.




2)
McAfee Removal

Download the removal tool from:

http://download.mcaf...atches/MCPR.exe


Click Save and save the file to your Desktop.
Make sure all McAfee windows are closed.
Double-click MCPR.exe to run the removal tool.

Note: Windows Vista users must right-click MCPR.exe and select Run as Administrator.


Restart your computer after receiving the message "CleanUp Successful".




3)
Try reinstalling McAfee again. Hopefully it will now install properly. Let me know how you get on with it :)
  • 0

#14
sgil

sgil

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Ran all steps successfully and McAfee seems to be installed and running.

Does this mean my computer is now clean?

Thank you so much for your help.
  • 0

#15
BlackOxide

BlackOxide

    Trusted Helper

  • Malware Removal
  • 1,976 posts
No probs, you're welcome :)

Yep, your logs now appear clean :)

Please go through the Cleanup section below and have a read of the other information which will help keep your PC protected :)

Just let me know if you have any other queries or problems :)


Thank you for following the procedures, your system now appears free from Malware. Below is a list of steps that are well worth following, they help finalize the fixes we have been doing and will help minimize the risk of a smilar situation happening again by protecting your PC and helping secure it.

Please make sure you follow the Cleanup stage just below.


========== CLEANUP ==========

Remove the Tools used in this cleanup

1)
Tools on the Desktop:
You can now safely remove GMER, RootRepeal, McAfee Removal Tool and Trend Micro Removal Tool from the Desktop (if present)

2)
Remove ComboFix

  • Hold down the Windows key + R on your keyboard. This will display the Run dialogue box
  • In the Run box, type in ComboFix /Uninstall (Notice the space between the "x" and "/") then click OK
    Posted Image
  • Follow the prompts on the screen
  • A message should appear confirming that ComboFix was uninstalled

3)
Clear Old Restore Points
  • Run OTL, copy and paste the following into the Custom Scans/Fixes area at the bottom
    :Commands
    [CLEARALLRESTOREPOINTS]
  • Then Click Run Fix

4)
OTL Cleanup
  • Open OTL
  • Click the CleanUp button at the top, it will ask to reboot your PC, please allow it to do so


========== Anti Malware Protection ==========

Spyware Blaster
Spyware Blaster is an excellent program that creates a huge list of known suspect/dangerous sites and blocks any attempts to visit those sites by embedding the list into Internet Explorer and Firefox. Very useful to have!

MalwareBytes Anti-Malware
This is an excellent Anti-Malware product. It is recommended to periodically run a Quick Scan to keep your PC as clean as possible.

Free Anti-Virus protection...
If you haven't got an AntiVirus or are thinking of changing, my personal recommendations are Microsoft Security Essentials and Avast, both are free to use. Remember though, you can only have one AntiVirus installed at any one given time.
Microsoft Security Essentials
Avast

========== Updates ==========

Keeping your PC updated is vital in the battle against infections and exploits. There are many infections which will exploit loopholes within Windows itself, Java and Adobe Reader. Keeping these updated is a very good habit to get into.

Automatic Updates

Updates to your Operating System are vital in closing loopholes and fixing bugs which some infections exploit.
To keep your Windows updated, ensure that 'Automatic Updates' is enabled on your PC. To do this...
  • In XP,
  • Click the Start button
  • Click Run
  • Type sysdm.cpl into the run dialogue box and click OK
  • Click the Automatic Updates tab
  • Make sure Automatic (Recommended) is selected and click OK

    In Vista,
  • Click the Start button
  • Click All Programs, then click Windows Update
  • In the left pane, click Change Settings
  • Choose Install updates autmatically (recommended), then click OK
Java updates
  • Click the Start button
  • Click Control Panel
  • Double Click Java
  • Click the Update tab
  • Click Update Now
  • Allow any updates to be downloaded and installed
Adobe Reader updates
  • Open Adobe Reader
  • Click Help on the menu at the top
  • Click Check for Updates
  • Allow any updates to be downloaded and installed
========== Alternate Browsers ==========

Using an alternative web browser can help protect your PC from infections which exploit security holes within Internet Explorer. They can also be quicker to load pages and offer more tools and features such as Firefox's huge addon list.

Firefox - My personal choice, easy to use, safer to use than Internet Explorer and a large number of excellent addons that can be installed such as AdBlockPlus and WOT.

Opera - Another efficient browser that works well. Quick and easy to use.


Have fun and stay safe online :)
BlackOxide

  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP