Удаление вирусов и троянов. Защита компьютера. › Помощь в удалении вирусов, троянов, рекламы и других зловредов › как удалить с компа winibluesoft › Re: Re: как удалить с компа winibluesoft
Logfile of random’s system information tool 1.06 (written by random/random)
Run by Юрий at 2009-05-07 02:03:47
Microsoft® Windows Vista™ Ultimate Service Pack 1
System drive C: has 48 GB (20%) free of 238 GB
Total RAM: 2046 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:03:49, on 07.05.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal
Running processes:
C:Windowssystem32Dwm.exe
C:Windowssystem32taskeng.exe
C:WindowsExplorer.EXE
C:WindowsRtHDVCpl.exe
C:Program FilesCyberLinkPowerDVDPDVDServ.exe
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe
C:Program FilesA4TechMouseAmoumain.exe
C:WindowsSystem32rundll32.exe
C:WindowsWindowsMobilewmdSync.exe
C:Program FilesJavajre6binjusched.exe
C:Windowsehomeehtray.exe
C:Windowsehomeehmsas.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesMedia KeyMagicKey.exe
C:Program FilesMedia KeyOSD.exe
C:Windowssystem32SearchFilterHost.exe
C:UsersЮрийDesktopRSIT.exe
C:Program Filestrend microЮрий.exe
R1 — HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yandex.ru/?clid=40488
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 — HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 — HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 — HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 — HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName =
R3 — URLSearchHook: (no name) — — (no file)
R3 — URLSearchHook: ICQToolBar — {855F3B16-6D32-4fe6-8A56-BBB695989046} — C:Program FilesICQ6ToolbarICQToolBar.dll
O1 — Hosts: ::1 localhost
O2 — BHO: Adobe PDF Reader Link Helper — {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 — BHO: RealPlayer Download and Record Plugin for Internet Explorer — {3049C3E9-B461-4BC5-8870-4C09146192CA} — C:Program FilesRealRealPlayerrpbrowserrecordplugin.dll
O2 — BHO: Groove GFS Browser Helper — {72853161-30C5-4D22-B7F9-0BBC1D38A37E} — C:Program FilesMicrosoft OfficeOffice12GrooveShellExtensions.dll
O2 — BHO: FieryAds advertising module v1.5.0 — {CF272101-7F6E-4CF2-9453-B4C5D2FC32C0} — C:PROGRA~1FieryAdsFieryAds.dll (file missing)
O2 — BHO: Java(tm) Plug-In 2 SSV Helper — {DBC80044-A445-435b-BC74-9C25C1C588A9} — C:Program FilesJavajre6binjp2ssv.dll
O2 — BHO: MyCentria Internet Mate v2.0 — {FFFC57DB-1DE3-4303-B24D-CEE6DCDD3D86} — C:PROGRA~1MYCENT~1InfoBarMYCENT~1.DLL (file missing)
O3 — Toolbar: ICQToolBar — {855F3B16-6D32-4fe6-8A56-BBB695989046} — C:Program FilesICQ6ToolbarICQToolBar.dll
O4 — HKLM..Run: [RtHDVCpl] RtHDVCpl.exe
O4 — HKLM..Run: [QuickTime Task] «C:Program FilesQuickTimeQTTask.exe» -atboottime
O4 — HKLM..Run: [NeroFilterCheck] C:Program FilesCommon FilesAheadLibNeroCheck.exe
O4 — HKLM..Run: [RemoteControl] «C:Program FilesCyberLinkPowerDVDPDVDServ.exe»
O4 — HKLM..Run: [LanguageShortcut] «C:Program FilesCyberLinkPowerDVDLanguageLanguage.exe»
O4 — HKLM..Run: [Lingvo Launcher] «C:Program FilesABBYY Lingvo 12Lvagent.exe» /STARTUP
O4 — HKLM..Run: [TkBellExe] «C:Program FilesCommon FilesRealUpdate_OBrealsched.exe» -osboot
O4 — HKLM..Run: [WheelMouse] C:Program FilesA4TechMouseAmoumain.exe
O4 — HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:Windowssystem32NvCpl.dll,NvStartup
O4 — HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:Windowssystem32NvMcTray.dll,NvTaskbarInit
O4 — HKLM..Run: [Adobe Reader Speed Launcher] «C:Program FilesAdobeReader 8.0ReaderReader_sl.exe»
O4 — HKLM..Run: [nod32kui] «C:Program FilesEsetnod32kui.exe» /WAITSERVICE
O4 — HKLM..Run: [Windows Mobile-based device management] %windir%WindowsMobilewmdSync.exe
O4 — HKLM..Run: [SunJavaUpdateSched] «C:Program FilesJavajre6binjusched.exe»
O4 — HKLM..Run: [WinPatrol Russian v.2] C:Program FilesBillP StudiosWinPatrolwinpatrol.exe
O4 — HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 — HKCU..Run: [AGEIA PhysX SysTray] C:Program FilesAGEIA TechnologiesbinTrayIcon.exe
O4 — HKCU..Run: [msnmsgr] «C:Program FilesWindows LiveMessengermsnmsgr.exe» /background
O4 — HKCU..Run: [QIP.Online] C:Program FilesQIP.Onlineqiponline.exe auto_start
O4 — HKCU..Run: [DAEMON Tools Lite] «C:Program FilesDAEMON Tools Litedaemon.exe» -autorun
O4 — HKCU..Run: [AlcoholAutomount] «C:Program FilesAlcohol SoftAlcohol 120axcmd.exe» /automount
O4 — HKCU..Run: [WMPNSCFG] C:Program FilesWindows Media PlayerWMPNSCFG.exe
O4 — HKUSS-1-5-19..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-19..Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User ‘LOCAL SERVICE’)
O4 — HKUSS-1-5-20..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User ‘NETWORK SERVICE’)
O4 — Startup: ubisoft register.lnk = C:Program FilesUbi SoftRegisterschedule.exe
O4 — Startup: Вырезка экрана и программа запуска для OneNote 2007.lnk = C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
O4 — Global Startup: Media Key.lnk = C:Program FilesMedia KeyMagicKey.exe
O8 — Extra context menu item: &Перевести с помощью ABBYY Lingvo… — res://C:Program FilesABBYY Lingvo 12Lingvo.exe/3000
O8 — Extra context menu item: &Экспорт в Microsoft Excel — res://C:PROGRA~1MICROS~2Office12EXCEL.EXE/3000
O9 — Extra button: Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — C:PROGRA~1MICROS~2Office12ONBttnIE.dll
O9 — Extra ‘Tools’ menuitem: &Отправить в OneNote — {2670000A-7350-4f3c-8081-5663EE0C6C49} — C:PROGRA~1MICROS~2Office12ONBttnIE.dll
O9 — Extra button: Research — {92780B25-18CC-41C8-B9BE-3C9C571A8263} — C:PROGRA~1MICROS~2Office12REFIEBAR.DLL
O9 — Extra button: ICQ6 — {E59EB121-F339-4851-A3BA-FE49C35617C2} — C:Program FilesICQ6.5ICQ.exe
O9 — Extra ‘Tools’ menuitem: ICQ6 — {E59EB121-F339-4851-A3BA-FE49C35617C2} — C:Program FilesICQ6.5ICQ.exe
O13 — Gopher Prefix:
O16 — DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) — http://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 — DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) — http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 — Protocol: grooveLocalGWS — {88FED34C-F0CA-4636-A375-3CB6248B04CD} — C:Program FilesMicrosoft OfficeOffice12GrooveSystemServices.dll
O18 — Protocol: skype4com — {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} — C:PROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O22 — SharedTaskScheduler: Windows DreamScene — {E31004D1-A431-41B8-826F-E902F9D95C81} — C:WindowsSystem32DreamScene.dll
O23 — Service: NBService — Nero AG — C:Program FilesNeroNero 7Nero BackItUpNBService.exe
O23 — Service: NOD32 Kernel Service (NOD32krn) — Eset — C:Program FilesEsetnod32krn.exe
O23 — Service: NVIDIA Display Driver Service (nvsvc) — NVIDIA Corporation — C:Windowssystem32nvvsvc.exe
O23 — Service: Cyberlink RichVideo Service(CRVS) (RichVideo) — Unknown owner — C:Program FilesCyberLinkShared filesRichVideo.exe
O23 — Service: ServiceLayer — Nokia. — C:Program FilesPC Connectivity SolutionServiceLayer.exe
O23 — Service: StarWind AE Service (StarWindServiceAE) — Rocket Division Software — C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindServiceAE.exe
—
End of file — 7794 bytes
======Registry dump======
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper — C:Program FilesCommon FilesAdobeAcrobatActiveXAcroIEHelper.dll [2006-10-23 62080]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer — C:Program FilesRealRealPlayerrpbrowserrecordplugin.dll [2008-06-26 308856]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper — C:Program FilesMicrosoft OfficeOffice12GrooveShellExtensions.dll [2007-08-24 2212224]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{CF272101-7F6E-4CF2-9453-B4C5D2FC32C0}]
FieryAds advertising module v1.5.0 — C:PROGRA~1FieryAdsFieryAds.dll []
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper — C:Program FilesJavajre6binjp2ssv.dll [2009-03-09 35840]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{FFFC57DB-1DE3-4303-B24D-CEE6DCDD3D86}]
MyCentria Internet Mate v2.0 — C:PROGRA~1MYCENT~1InfoBarMYCENT~1.DLL []
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} — ICQToolBar — C:Program FilesICQ6ToolbarICQToolBar.dll [2008-12-09 958200]
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
«RtHDVCpl»=C:WindowsRtHDVCpl.exe [2007-01-18 4349952]
«QuickTime Task»=C:Program FilesQuickTimeQTTask.exe [2007-06-29 286720]
«NeroFilterCheck»=C:Program FilesCommon FilesAheadLibNeroCheck.exe [2006-01-12 155648]
«RemoteControl»=C:Program FilesCyberLinkPowerDVDPDVDServ.exe [2005-12-07 30208]
«LanguageShortcut»=C:Program FilesCyberLinkPowerDVDLanguageLanguage.exe [2006-05-18 49152]
«»= []
«Lingvo Launcher»=C:Program FilesABBYY Lingvo 12Lvagent.exe [2006-12-14 258048]
«TkBellExe»=C:Program FilesCommon FilesRealUpdate_OBrealsched.exe [2008-06-26 185896]
«WheelMouse»=C:Program FilesA4TechMouseAmoumain.exe [2007-02-10 241664]
«NvCplDaemon»=C:Windowssystem32NvCpl.dll [2008-09-17 13580832]
«NvMediaCenter»=C:Windowssystem32NvMcTray.dll [2008-09-17 92704]
«Adobe Reader Speed Launcher»=C:Program FilesAdobeReader 8.0ReaderReader_sl.exe [2008-10-15 39792]
«nod32kui»=C:Program FilesEsetnod32kui.exe [2008-12-20 949376]
«Windows Mobile-based device management»=C:WindowsWindowsMobilewmdSync.exe [2008-01-21 215552]
«SunJavaUpdateSched»=C:Program FilesJavajre6binjusched.exe [2009-03-09 148888]
«WinPatrol Russian v.2″=C:Program FilesBillP StudiosWinPatrolwinpatrol.exe [2007-08-06 292152]
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun]
«ehTray.exe»=C:WindowsehomeehTray.exe [2008-01-21 125952]
«AGEIA PhysX SysTray»=C:Program FilesAGEIA TechnologiesbinTrayIcon.exe []
«msnmsgr»=C:Program FilesWindows LiveMessengermsnmsgr.exe /background []
«QIP.Online»=C:Program FilesQIP.Onlineqiponline.exe auto_start []
«DAEMON Tools Lite»=C:Program FilesDAEMON Tools Litedaemon.exe [2008-12-10 216520]
«AlcoholAutomount»=C:Program FilesAlcohol SoftAlcohol 120axcmd.exe [2009-03-17 203928]
«WMPNSCFG»=C:Program FilesWindows Media PlayerWMPNSCFG.exe [2008-01-21 202240]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdobe Reader Speed Launcher]
C:Program FilesAdobeReader 8.0ReaderReader_sl.exe [2008-10-15 39792]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdVantage]
C:Program FilesAdVantageAdVantage.exe []
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregBigDog303]
C:WindowsVM303_STI.EXE [2006-01-24 61440]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGrooveMonitor]
C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe [2007-08-24 33648]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregMsnMsgr]
C:Program FilesWindows LiveMessengerMsnMsgr.Exe /background []
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregWindows Defender]
C:Program FilesWindows DefenderMSASCui.exe [2008-01-21 1008184]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregXerox PanelMgr]
C:WindowsXeroxPanelMgrSSMMgr.exe [2007-03-22 524288]
C:ProgramDataMicrosoftWindowsStart MenuProgramsStartup
Media Key.lnk — C:Program FilesMedia KeyMagicKey.exe
C:UsersЮрийAppDataRoamingMicrosoftWindowsStart MenuProgramsStartup
ubisoft register.lnk — C:Program FilesUbi SoftRegisterschedule.exe
Вырезка экрана и программа запуска для OneNote 2007.lnk — C:Program FilesMicrosoft OfficeOffice12ONENOTEM.EXE
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionexplorerSharedTaskScheduler]
Windows DreamScene — {E31004D1-A431-41B8-826F-E902F9D95C81} — C:WindowsSystem32DreamScene.dll [2007-07-20 233888]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks]
«{B5A7F190-DDA6-4420-B3BA-52453494E6CD}»=C:Program FilesMicrosoft OfficeOffice12GrooveShellExtensions.dll [2007-08-24 2212224]
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesSystem]
«EnableLUA»=0
«dontdisplaylastusername»=0
«legalnoticecaption»=
«legalnoticetext»=
«shutdownwithoutlogon»=1
«undockwithoutlogon»=1
«EnableUIADesktopToggle»=0
[HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesexplorer]
«NoDriveAutoRun»=FFFFFFFF
«NoDriveTypeAutoRun»=36
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{87d7b0a3-1fd5-11de-9861-001bb97660ba}]
shellAutoRuncommand — F:autorun.exe
======List of files/folders created in the last 1 months======
2009-12-14 04:26:03 —-A—- C:Windows2591wormdz5.dll
2009-12-12 02:40:31 —-A—- C:Windowssystem32695csp5zare532.dll
2009-12-08 08:58:49 —-A—- C:Windowssystem3230895h5cktool2bz.exe
2009-12-05 02:17:16 —-A—- C:Windows3395hacktool7bfz.dll
2009-12-01 12:51:35 —-A—- C:Windowssystem3210e95tezl1107.dll
2009-11-28 08:32:18 —-A—- C:Windows16524s9yzfc.dll
2009-11-27 14:45:26 —-A—- C:Windowssystem3217552h9cktool1b5z.dll
2009-11-26 07:18:43 —-A—- C:Windowssystem3224095ow9loadez189.exe
2009-11-25 05:47:27 —-A—- C:Windowssystem323095spy63z.exe
2009-11-24 10:53:55 —-A—- C:Windows9ez4vir2755.exe
2009-11-22 15:20:35 —-A—- C:Windowssystem326641w5zm4a59.exe
2009-11-22 00:21:07 —-A—- C:Windowssystem322652t59eat17835z.exe
2009-11-21 13:46:25 —-A—- C:Windows6d3aztea531309.exe
2009-11-21 04:50:00 —-A—- C:Windows77f3spz5ar92680.exe
2009-11-14 10:32:16 —-A—- C:Windows7bddazdw5re3092.dll
2009-11-09 02:30:04 —-A—- C:Windows3zt59j5e4.exe
2009-11-01 04:56:20 —-A—- C:Windowssystem32765zvi9us56.exe
2009-10-25 15:06:30 —-A—- C:Windowssystem324d509hrzat15659.exe
2009-10-24 11:17:58 —-A—- C:Windows7c7c9ze5l826.dll
2009-10-15 11:34:28 —-A—- C:Windowssystem3221195worm535z.exe
2009-10-14 05:24:02 —-A—- C:Windows3zb5threa912129.exe
2009-10-12 09:25:41 —-A—- C:Windows4b0ddo9nzoad5r1101.exe
2009-10-06 03:47:42 —-A—- C:Windows2b15azdwa9e2215.exe
2009-09-28 03:04:12 —-A—- C:Windows1z188hacktoo915b5.exe
2009-09-24 04:57:26 —-A—- C:Windows2969znot-9-v5rus2d3.dll
2009-09-22 16:54:19 —-A—- C:Windows3a35bac9dzor84.dll
2009-09-21 10:16:33 —-A—- C:Windowssystem325z9athre5t24449.dll
2009-09-20 17:45:14 —-A—- C:Windows5c69spar5e37z.dll
2009-09-20 01:12:13 —-A—- C:Windowsz79cvir25689.exe
2009-09-19 06:24:46 —-A—- C:Windowssystem3269595pz449.exe
2009-09-16 17:35:52 —-A—- C:Windows7z96spars52040.dll
2009-09-15 23:12:16 —-A—- C:Windowssystem3214306not-a5zi9us241.dll
2009-09-10 15:30:16 —-A—- C:Windows8447spa5bot987z.exe
2009-09-10 14:52:29 —-A—- C:Windows48z6vi911825.exe
2009-09-08 20:55:04 —-A—- C:Windows1893zworm5a8.exe
2009-09-08 19:10:18 —-A—- C:Windowssystem3235aedownlozder9559.exe
2009-09-07 03:14:42 —-A—- C:Windows83795pambot981z.exe
2009-09-03 12:21:05 —-A—- C:Windows19915zpy5985.dll
2009-09-03 11:53:17 —-A—- C:Windowssystem324282tzi9f28905.exe
2009-08-26 02:24:32 —-A—- C:Windows1b25add9aze25.exe
2009-08-25 23:50:31 —-A—- C:Windows60fa9pywzre758.dll
2009-08-16 15:17:29 —-A—- C:Windowsz6029troj5045.dll
2009-08-12 05:37:35 —-A—- C:Windowssystem3227585not-59vzrus474.dll
2009-08-11 22:42:05 —-A—- C:Windowssystem3217092zr5j327.exe
2009-08-11 00:50:31 —-A—- C:Windows10502worm95z.exe
2009-08-09 16:06:45 —-A—- C:Windowssystem32224429ot-a-5irus199z.dll
2009-08-09 12:23:05 —-A—- C:Windows19254troz9a.dll
2009-08-06 12:16:22 —-A—- C:Windowssystem329zthreat15649.exe
2009-08-03 12:44:12 —-A—- C:Windows6290v5rus2d5z.exe
2009-08-01 15:05:27 —-A—- C:Windowssystem32cb7thzef2595.exe
2009-07-29 01:49:49 —-A—- C:Windows14497s5ambot59z.dll
2009-07-27 15:21:03 —-A—- C:Windowsz351spywar92875.exe
2009-07-27 12:38:18 —-A—- C:Windows2948thre5t229z4.exe
2009-07-20 12:41:49 —-A—- C:Windows496cthre5t131z4.dll
2009-07-19 23:30:02 —-A—- C:Windows115addware269z.exe
2009-07-17 00:05:56 —-A—- C:Windowssystem32935dowzloader1141.exe
2009-07-16 03:47:34 —-A—- C:Windowssystem3222536z95us4dc.dll
2009-07-09 01:18:48 —-A—- C:Windowssystem321592sparze1419.dll
2009-07-08 07:21:26 —-A—- C:Windowssystem32992avir2745z.dll
2009-07-07 17:52:22 —-A—- C:Windows1eecdownlo5dez1719.exe
2009-07-04 03:55:05 —-A—- C:Windowssystem3229ed9hre5t11049z.dll
2009-07-03 05:25:03 —-A—- C:Windowssystem327f9ftzie9595.dll
2009-06-29 03:48:34 —-A—- C:Windowssystem3219b0sparz52062.exe
2009-06-27 14:57:14 —-A—- C:Windows29427hac5tooz19a.dll
2009-06-27 02:16:58 —-A—- C:Windowssystem3295b5ackdooz25859.dll
2009-06-27 01:23:33 —-A—- C:Windowsfbfdo5z9oader1544.exe
2009-06-25 10:57:37 —-A—- C:Windowssystem324081n9t-a-virus5z05.exe
2009-06-13 23:26:58 —-A—- C:Windows64b49hiz51058.dll
2009-06-13 12:15:25 —-A—- C:Windows1536back5oor8z69.dll
2009-06-12 21:46:47 —-A—- C:Windows51292hacktozl6b1.exe
2009-06-11 08:57:07 —-A—- C:Windowssystem3235z209orm26.dll
2009-06-09 20:14:35 —-A—- C:Windowssystem32283695rojz59.dll
2009-06-09 11:12:20 —-A—- C:Windowssystem329bz05pyware1776.exe
2009-06-08 07:42:21 —-A—- C:Windows2z544spambot493.dll
2009-06-02 19:27:45 —-A—- C:Windowssystem3253bdspar9z1215.dll
2009-06-02 16:37:53 —-A—- C:Windowssystem329934h5cktool356z.exe
2009-05-21 10:19:51 —-A—- C:Windowssystem322a05sp5rse2z969.exe
2009-05-17 21:28:12 —-A—- C:Windows68z6s9y5bc.exe
2009-05-15 18:30:37 —-A—- C:Windows76b8stezl1590.exe
2009-05-12 12:37:06 —-A—- C:Windows267715acktool519z.exe
2009-05-07 02:01:09 —-D—- C:rsit
2009-05-06 23:38:47 —-D—- C:UsersЮрийAppDataRoamingMalwarebytes
2009-05-04 22:20:10 —-D—- C:WindowsERDNT
2009-05-04 21:55:05 —-D—- C:UsersЮрийAppDataRoamingWinPatrol
2009-05-04 21:54:58 —-D—- C:Program FilesBillP Studios
2009-05-04 12:49:59 —-A—- C:Windowsntbtlog.txt
2009-05-04 12:41:20 —-D—- C:Program Filestrend micro
2009-05-04 11:22:15 —-D—- C:ProgramDataMalwarebytes
2009-05-04 11:22:15 —-D—- C:Program FilesMalwarebytes’ Anti-Malware
2009-05-04 09:57:06 —-A—- C:Windowszfe7spar5e969.exe
2009-05-04 09:57:06 —-A—- C:Windowsz9560virus95.dll
2009-05-04 09:57:06 —-A—- C:Windowsz5ecsparse1559.dll
2009-05-04 09:57:06 —-A—- C:Windowsz4b6steal259.dll
2009-05-04 09:57:06 —-A—- C:Windowsz345vi5us25a9.exe
2009-05-04 09:57:06 —-A—- C:Windowssystem32espywar929z25.exe
2009-05-04 09:57:06 —-A—- C:Windowssystem327522hacktz5l1b59.dll
2009-05-04 09:57:06 —-A—- C:Windowssystem327470zot9a-vir5s73.exe
2009-05-04 09:57:06 —-A—- C:Windowssystem327237zpa95e333.exe
2009-05-04 09:57:06 —-A—- C:Windowssystem326a25s9z5l71.exe
2009-05-04 09:57:06 —-A—- C:Windowssystem325638back9oo5z2.dll
2009-05-04 09:57:06 —-A—- C:Windowssystem325402not-a-virusz94.exe
2009-05-04 09:57:06 —-A—- C:Windowssystem324da9dzwnloa5er872.exe
2009-05-04 09:57:06 —-A—- C:Windowssystem324d7cthizf859.dll
2009-05-04 09:57:06 —-A—- C:Windowssystem32425ztroj1c9.exe
2009-05-04 09:57:06 —-A—- C:Windowssystem32415az9ckdoor2395.dll
2009-05-04 09:57:06 —-A—- C:Windowssystem323335szea51950.dll
2009-05-04 09:57:06 —-A—- C:Windowssystem3229822ha9kto5lz66.dll
2009-05-04 09:57:06 —-A—- C:Windowssystem3229755zirus3fb.dll
2009-05-04 09:57:06 —-A—- C:Windowssystem3225178z9y5a2.exe
2009-05-04 09:57:06 —-A—- C:Windowssystem3223zbsparse2595.exe
2009-05-04 09:57:06 —-A—- C:Windowssystem321c819azkdoor2511.dll
2009-05-04 09:57:06 —-A—- C:Windowssystem32158aback9zor2658.dll
2009-05-04 09:57:06 —-A—- C:Windowssystem3215189aczdoor82.exe
2009-05-04 09:57:06 —-A—- C:Windowssystem32149375zr9s6d8.exe
2009-05-04 09:57:06 —-A—- C:Windowssystem321460zhac9tool385.exe
2009-05-04 09:57:06 —-A—- C:Windowssystem3214355viruz479.dll
2009-05-04 09:57:06 —-A—- C:Windows9dd0spyware57z.exe
2009-05-04 09:57:06 —-A—- C:Windows6cz9th9ef5229.exe
2009-05-04 09:57:06 —-A—- C:Windows6015doznl9ader3239.dll
2009-05-04 09:57:06 —-A—- C:Windows5c32s9ywzre3051.exe
2009-05-04 09:57:06 —-A—- C:Windows4z30sp9ware2405.dll
2009-05-04 09:57:06 —-A—- C:Windows498bthzeat94195.dll
2009-05-04 09:57:06 —-A—- C:Windows489095azse3244.dll
2009-05-04 09:57:06 —-A—- C:Windows35d9zteal2571.exe
2009-05-04 09:57:06 —-A—- C:Windows35cc9ownzoad5r499.dll
2009-05-04 09:57:06 —-A—- C:Windows35827zp913f.dll
2009-05-04 09:57:06 —-A—- C:Windows25929t5ojz92.exe
2009-05-04 09:57:06 —-A—- C:Windows2168virus5z39.dll
2009-05-04 09:57:06 —-A—- C:Windows12198s5z38f.exe
2009-05-04 09:57:06 —-A—- C:Windows10zspa5se9929.exe
2009-05-04 09:57:05 —-A—- C:Windowssystem32z4565wor9539.exe
2009-05-04 09:57:05 —-A—- C:Windowssystem32z25asteal9137.exe
2009-05-04 09:57:05 —-A—- C:Windowssystem329z70backdo5r226.dll
2009-05-04 09:57:05 —-A—- C:Windowssystem326523vz9us52e.exe
2009-05-04 09:57:05 —-A—- C:Windowssystem3252b5ba5kzoor974.dll
2009-05-04 09:57:05 —-A—- C:Windowssystem3236d695eal1z6.dll
2009-05-04 09:57:05 —-A—- C:Windowssystem321d0es5a9ze481.exe
2009-05-04 09:57:05 —-A—- C:Windows7z77b5ckdoor9919.exe
2009-05-04 09:57:05 —-A—- C:Windows799zspambo9795.dll
2009-05-04 09:57:05 —-A—- C:Windows690adownloader759z.exe
2009-05-04 09:57:05 —-A—- C:Windows39539v5rusz05.exe
2009-05-04 09:57:05 —-A—- C:Windows24145szy49.exe
2009-05-02 19:41:51 —-RHD—- C:UsersЮрийAppDataRoamingSecuROM
2009-05-02 19:40:34 —-D—- C:Windowssystem32AGEIA
2009-05-02 19:40:34 —-D—- C:Program FilesAGEIA Technologies
2009-05-02 19:40:27 —-D—- C:Program FilesCommon FilesWise Installation Wizard
2009-05-02 19:08:52 —-D—- C:Program FilesSacred 2 — Fallen Angel
2009-05-02 08:56:05 —-A—- C:Windowssystem325cdspzwar95011.exe
2009-05-01 23:36:48 —-D—- C:Program FilesStardock
2009-04-27 13:21:15 —-D—- C:Program FilesQuickyPlaeyr
2009-04-25 14:25:55 —-A—- C:Windowssystem3235fdown5zader3930.dll
2009-04-25 09:53:14 —-A—- C:Windowssystem32zfcathr9a55601.exe
2009-04-25 00:28:43 —-D—- C:Program FilesCommon FilesSkype
2009-04-25 00:28:41 —-RD—- C:Program FilesSkype
2009-04-24 01:47:55 —-A—- C:WindowsSCUnin.exe
2009-04-24 01:47:18 —-D—- C:Program FilesStarcraft
2009-04-22 19:33:51 —-D—- C:UsersЮрийAppDataRoamingMy Games
2009-04-22 07:56:23 —-A—- C:Windowssystem32905z1spy5ca.dll
2009-04-18 20:51:13 —-D—- C:Program FilesAlien Shooter
2009-04-18 19:33:35 —-D—- C:Program FilesReflexiveArcade
2009-04-18 12:52:17 —-A—- C:Windows4241downloa5erz958.exe
2009-04-16 19:55:53 —-A—- C:Windowssystem324z98v5r9299.exe
2009-04-15 23:06:29 —-A—- C:Windowssystem32winhttp.dll
2009-04-15 23:06:26 —-A—- C:Windowssystem32xolehlp.dll
2009-04-15 23:06:26 —-A—- C:Windowssystem32msdtcprx.dll
2009-04-15 23:06:17 —-A—- C:Windowssystem32rpcss.dll
2009-04-15 23:06:17 —-A—- C:Windowssystem32ntkrnlpa.exe
2009-04-15 23:06:16 —-A—- C:Windowssystem32ntoskrnl.exe
2009-04-15 23:06:15 —-A—- C:Windowssystem32printfilterpipelinesvc.exe
2009-04-15 23:06:14 —-A—- C:Windowssystem32sdohlp.dll
2009-04-15 23:06:14 —-A—- C:Windowssystem32printfilterpipelineprxy.dll
2009-04-15 23:06:14 —-A—- C:Windowssystem32iasrecst.dll
2009-04-15 23:06:14 —-A—- C:Windowssystem32iashost.exe
2009-04-15 23:06:14 —-A—- C:Windowssystem32iasdatastore.dll
2009-04-15 23:06:14 —-A—- C:Windowssystem32iasads.dll
2009-04-15 23:06:10 —-A—- C:Windowssystem32lsasrv.dll
2009-04-15 23:06:10 —-A—- C:Windowssystem32kernel32.dll
2009-04-15 23:06:09 —-A—- C:Windowssystem32secur32.dll
2009-04-15 23:06:09 —-A—- C:Windowssystem32apilogen.dll
2009-04-15 23:06:09 —-A—- C:Windowssystem32amxread.dll
2009-04-15 23:06:03 —-A—- C:Windowssystem32mshtml.dll
2009-04-15 23:06:02 —-A—- C:Windowssystem32ieframe.dll
2009-04-15 23:06:01 —-A—- C:Windowssystem32urlmon.dll
2009-04-15 23:06:00 —-A—- C:Windowssystem32wininet.dll
2009-04-15 23:06:00 —-A—- C:Windowssystem32msfeeds.dll
2009-04-15 23:06:00 —-A—- C:Windowssystem32iertutil.dll
2009-04-15 23:06:00 —-A—- C:Windowssystem32iedkcs32.dll
2009-04-15 23:05:59 —-A—- C:Windowssystem32occache.dll
2009-04-15 23:05:59 —-A—- C:Windowssystem32ieaksie.dll
2009-04-15 23:05:58 —-A—- C:Windowssystem32ieUnatt.exe
2009-04-15 23:05:58 —-A—- C:Windowssystem32ieencode.dll
2009-04-15 23:05:57 —-A—- C:Windowssystem32mstime.dll
2009-04-15 23:05:56 —-A—- C:Windowssystem32jsproxy.dll
2009-04-14 03:48:47 —-A—- C:Windowssystem3219775s5azbot50c.dll
2009-04-11 06:30:18 —-A—- C:Windowssystem32z49fback5oor2574.dll
2009-04-10 23:11:25 —-D—- C:ProgramDataPOP3Profiles
======List of files/folders modified in the last 1 months======
2009-05-07 02:03:48 —-D—- C:WindowsTemp
2009-05-07 02:02:28 —-D—- C:WindowsPrefetch
2009-05-07 02:01:09 —-D—- C:WindowsSystem32
2009-05-07 02:01:08 —-D—- C:Windowsinf
2009-05-07 02:01:08 —-A—- C:Windowssystem32PerfStringBackup.INI
2009-05-07 01:57:15 —-D—- C:Program FilesMozilla Firefox
2009-05-07 01:55:42 —-AD—- C:Program Files
2009-05-07 01:53:49 —-HD—- C:ProgramData
2009-05-07 01:53:12 —-SHD—- C:System Volume Information
2009-05-07 01:50:33 —-D—- C:Windowssystem32drivers
2009-05-07 01:48:47 —-RSHD—- C:RECYCLER
2009-05-06 23:30:48 —-D—- C:UsersЮрийAppDataRoamingSkype
2009-05-06 23:30:03 —-D—- C:Program FilesPowerArchiver
2009-05-06 23:29:43 —-D—- C:UsersЮрийAppDataRoaminguTorrent
2009-05-06 21:29:00 —-D—- C:UsersЮрийAppDataRoamingskypePM
2009-05-06 19:27:55 —-D—- C:Program FilesRising Force Online
2009-05-05 16:56:53 —-HD—- C:Windowssystem32GroupPolicy
2009-05-04 22:25:00 —-D—- C:Программы установки
2009-05-04 22:20:10 —-D—- C:Windows
2009-05-04 21:39:46 —-D—- C:Windowssystem32catroot2
2009-05-04 21:21:56 —-RD—- C:Users
2009-05-04 20:35:46 —-D—- C:Windowssystem32Tools
2009-05-04 18:51:06 —-SHD—- C:WindowsInstaller
2009-05-04 18:51:05 —-D—- C:Windowswinsxs
2009-05-04 10:38:30 —-D—- C:WindowsLogs
2009-05-04 10:10:52 —-RSD—- C:Windowsassembly
2009-05-03 09:25:03 —-D—- C:UsersЮрийAppDataRoamingICQ
2009-05-02 19:41:50 —-A—- C:Windowssystem32CmdLineExt.dll
2009-05-02 19:40:58 —-D—- C:Windowssystem32catroot
2009-05-02 19:40:27 —-D—- C:Program FilesCommon Files
2009-05-02 19:38:12 —-D—- C:Program FilesCommon Filesmicrosoft shared
2009-05-02 10:21:51 —-D—- C:Program FilesFieryAds
2009-05-01 23:37:46 —-D—- C:WindowsMicrosoft.NET
2009-04-28 00:32:27 —-RSD—- C:WindowsFonts
2009-04-27 23:34:02 —-D—- C:Program FilesLineage II
2009-04-26 17:37:13 —-A—- C:WindowsNeroDigital.ini
2009-04-25 00:28:55 —-D—- C:Windowssystem32Tasks
2009-04-25 00:28:43 —-D—- C:ProgramDataSkype
2009-04-23 00:46:27 —-HD—- C:Program FilesInstallShield Installation Information
2009-04-16 12:13:12 —-D—- C:Windowssystem32wbem
2009-04-16 12:13:12 —-D—- C:Program FilesWindows Mail
2009-04-16 12:13:09 —-D—- C:Windowssystem32manifeststore
2009-04-16 12:13:09 —-D—- C:WindowsAppPatch
2009-04-16 12:13:07 —-D—- C:Program FilesInternet Explorer
2009-04-16 03:04:23 —-D—- C:ProgramDataMicrosoft Help
2009-04-11 14:08:40 —-D—- C:Program FilesUbisoft
2009-04-08 21:34:37 —-D—- C:Program FilesCommon FilesYandex
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Amfilter;A4Tech Mouse Filter Driver; C:Windowssystem32DRIVERSAmfilter.sys [2007-01-24 8704]
R1 cdrbsdrv;cdrbsdrv; C:Windowssystem32driverscdrbsdrv.sys [2008-11-16 33408]
R1 CSC;Offline Files Driver; C:Windowssystem32driverscsc.sys [2008-01-21 350720]
R1 nod32drv;nod32drv; C:Windowssystem32driversnod32drv.sys [2008-12-20 15424]
R1 prodrv06;StarForce Protection Environment Driver v6; C:WindowsSystem32driversprodrv06.sys [2004-08-09 53920]
R2 AMON;AMON; C:Windowssystem32driversamon.sys [2008-12-20 512096]
R2 atksgt;atksgt; C:Windowssystem32DRIVERSatksgt.sys [2008-12-03 278728]
R2 lirsgt;lirsgt; C:Windowssystem32DRIVERSlirsgt.sys [2008-12-03 25416]
R2 SSPORT;SSPORT; ??C:Windowssystem32DriversSSPORT.sys [2006-11-22 5120]
R3 FStarForce;FStarForce; C:Windowssystem32DRIVERSFStarForce.sys [2008-10-24 9216]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:Windowssystem32driversRTKVHDA.sys [2007-01-18 1729632]
R3 kbfiltr;Keyboard Filter; C:Windowssystem32DRIVERSKBFILTER.SYS [2002-07-11 12856]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:Windowssystem32DRIVERSnvmfdx32.sys [2007-11-18 1040544]
R3 nvlddmkm;nvlddmkm; C:Windowssystem32DRIVERSnvlddmkm.sys [2008-09-17 7379872]
S2 DgiVecp;DgiVecp; ??C:Windowssystem32DriversDgiVecp.sys [2006-06-11 41984]
S3 Amusbprt;A4Tech HID-compliant Mouse Driver; C:Windowssystem32DRIVERSAmusbprt.sys [2007-02-10 13824]
S3 avx5cwfi;avx5cwfi; C:Windowssystem32driversavx5cwfi.sys []
S3 azddj1lw;azddj1lw; C:Windowssystem32driversazddj1lw.sys []
S3 drmkaud;Звуковой дешифратор DRM ядра системы; C:Windowssystem32driversdrmkaud.sys [2008-01-21 5632]
S3 GMSIPCI;GMSIPCI; ??D:INSTALLGMSIPCI.SYS []
S3 HdAudAddService;Драйвер функции UAA для службы High Definition Audio (Microsoft), версия 1.1; C:Windowssystem32driversHdAudio.sys [2006-11-02 235520]
S3 k750bus;Sony Ericsson 750 driver (WDM); C:Windowssystem32DRIVERSk750bus.sys [2005-02-11 55216]
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter; C:Windowssystem32DRIVERSk750mdfl.sys [2005-02-11 6576]
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers; C:Windowssystem32DRIVERSk750mdm.sys [2005-02-11 89872]
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers; C:Windowssystem32DRIVERSk750mgmt.sys [2005-03-11 81728]
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers; C:Windowssystem32DRIVERSk750obex.sys [2005-02-11 79488]
S3 KMWDFilter;KMWDFilter; ??C:WindowsSystem32DriversKMWDFilter.SYS [2007-03-29 17024]
S3 MSKSSRV;Представитель служб потоков Microsoft; C:Windowssystem32driversMSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Посредник синхронизации потоков Microsoft; C:Windowssystem32driversMSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Представитель диспетчера качества потоков Microsoft; C:Windowssystem32driversMSPQM.sys [2008-01-21 5504]
S3 MSTEE;Преобразователь потоков Tee/Sink-to-Sink Microsoft; C:Windowssystem32driversMSTEE.sys [2008-01-21 6016]
S3 npkcrypt;npkcrypt; ??C:Program FilesLineage2systemnpkcrypt.sys [2005-03-31 21442]
S3 NTACCESS;NTACCESS; ??D:NTACCESS.sys []
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:Windowssystem32DRIVERSpccsmcfd.sys [2007-09-17 21632]
S3 SetupNTGLM7X;SetupNTGLM7X; ??D:NTGLM7X.sys []
S3 upperdev;upperdev; C:Windowssystem32DRIVERSusbser_lowerflt.sys []
S3 winusb;WinUSB Service; C:Windowssystem32DRIVERSwinusb.sys [2008-01-21 31616]
S3 WUDFRd;WUDFRd; C:Windowssystem32DRIVERSWUDFRd.sys [2008-01-21 83328]
S3 ZSMC303;VIMICRO USB PC Camera (VC0303); C:WindowsSystem32DriversusbVM303.sys [2006-02-23 391300]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:Windowssystem32driverserrdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:Windowssystem32driversmegasr.sys [2008-01-21 386616]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:Windowssystem32driverswmiacpi.sys [2008-01-21 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 CscService;@%systemroot%system32cscsvc.dll,-200; C:WindowsSystem32svchost.exe [2008-01-21 21504]
R2 NOD32krn;NOD32 Kernel Service; C:Program FilesEsetnod32krn.exe [2008-12-20 552064]
R2 nvsvc;NVIDIA Display Driver Service; C:Windowssystem32nvvsvc.exe [2008-09-17 196608]
R2 RapiMgr;@%windir%WindowsMobilerapimgr.dll,-104; C:Windowssystem32svchost.exe [2008-01-21 21504]
R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:Program FilesCyberLinkShared filesRichVideo.exe [2005-08-08 167936]
R2 StarWindServiceAE;StarWind AE Service; C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindServiceAE.exe [2007-05-28 275968]
R2 WcesComm;@%windir%WindowsMobilewcescomm.dll,-40079; C:Windowssystem32svchost.exe [2008-01-21 21504]
S3 AppMgmt;@appmgmts.dll,-3250; C:Windowssystem32svchost.exe [2008-01-21 21504]
S3 Fax;@%systemroot%system32fxsresm.dll,-118; C:Windowssystem32fxssvc.exe [2008-01-21 523776]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:Program FilesMicrosoft OfficeOffice12GrooveAuditService.exe [2007-08-24 68464]
S3 NBService;NBService; C:Program FilesNeroNero 7Nero BackItUpNBService.exe [2006-11-10 774144]
S3 odserv;Microsoft Office Diagnostics Service; C:Program FilesCommon FilesMicrosoft SharedOFFICE12ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:Program FilesCommon FilesMicrosoft SharedSource EngineOSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:Program FilesPC Connectivity SolutionServiceLayer.exe [2008-05-30 572416]
S3 UmRdpService;@%SystemRoot%system32umrdp.dll,-1000; C:WindowsSystem32svchost.exe [2008-01-21 21504]
S3 usprserv;User Privilege Service; C:WindowsSystem32svchost.exe [2008-01-21 21504]
S3 wbengine;@%systemroot%system32wbengine.exe,-104; C:Windowssystem32wbengine.exe [2008-01-21 917504]
EOF

