antoenche | 25.09.2013 22:35 | Combofix Logfile: Code:
ComboFix 13-09-24.02 - Werner 25.09.2013 22:40:39.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.2939.1059 [GMT 2:00]
ausgeführt von:: c:\users\Werner\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\DealPly
c:\program files\DealPly\DealPly.crx
c:\program files\DealPly\DealPly.xpi
c:\program files\DealPly\DealPlyIE.dll
c:\program files\DealPly\DealPlyIE64.dll
c:\program files\DealPly\DealPlyUpdate.exe
c:\program files\DealPly\DealPlyUpdateRun.exe
c:\program files\DealPly\DealPlyUpdateVer.exe
c:\program files\DealPly\icon.ico
c:\program files\DealPly\uninst.exe
c:\windows\Installer\$PatchCache$\Managed\EFF96A4D6F7B6B24CA3FF332F8A9628D\18.2.0\ssekonf.ini2
c:\windows\security\Database\tmp.edb
c:\windows\system32\pt
c:\windows\system32\pt\toscdspd.cpl.mui
c:\windows\system32\roboot.exe
c:\windows\wininit.ini
.
.
((((((((((((((((((((((( Dateien erstellt von 2013-08-25 bis 2013-09-25 ))))))))))))))))))))))))))))))
.
.
2013-09-25 20:51 . 2013-09-25 20:51 -------- d-----w- c:\users\Werner\AppData\Local\temp
2013-09-25 20:51 . 2013-09-25 20:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-09-25 08:12 . 2013-09-25 08:12 -------- d-----w- C:\FRST
2013-09-25 00:04 . 2013-09-25 20:37 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2013-09-24 23:48 . 2013-09-24 23:48 -------- d-----w- c:\users\Werner\AppData\Roaming\Avira
2013-09-24 23:40 . 2013-09-24 23:40 -------- d-----w- c:\programdata\AskPartnerNetwork
2013-09-24 23:40 . 2013-09-24 23:40 -------- d-----w- c:\program files\AskPartnerNetwork
2013-09-24 23:39 . 2013-09-24 23:39 -------- d-----w- c:\programdata\APN
2013-09-24 23:37 . 2013-09-24 23:35 88840 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-09-24 23:37 . 2013-09-24 23:35 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-09-24 23:37 . 2013-09-24 23:35 136672 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-09-24 23:37 . 2013-09-24 23:38 -------- d-----w- c:\programdata\Avira
2013-09-24 23:37 . 2013-09-24 23:37 -------- d-----w- c:\program files\Avira
2013-09-24 19:40 . 2013-09-11 02:28 271256 ----a-w- c:\program files\Mozilla Firefox\browser\components\browsercomps.dll
2013-09-24 09:28 . 2013-09-24 09:28 -------- d-----w- c:\users\Werner\AppData\Roaming\UpdaterEX
2013-09-24 09:28 . 2013-09-24 20:51 -------- d-----w- c:\program files\LyriXeeker-1
2013-09-24 09:27 . 2013-09-24 20:24 -------- d-----w- c:\users\Werner\AppData\Roaming\Systweak
2013-09-22 20:28 . 2013-09-22 20:28 -------- d-----w- c:\programdata\DealPlyLive
2013-09-22 20:28 . 2013-09-22 20:28 -------- d-----w- c:\program files\DealPlyLive
2013-09-22 20:28 . 2013-09-22 20:28 -------- d-----w- c:\users\Werner\AppData\Roaming\Dealply
2013-09-22 20:28 . 2013-09-22 20:28 -------- d-----w- c:\programdata\BitGuard
2013-09-11 19:47 . 2013-08-01 10:20 759296 ----a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2013-09-09 22:52 . 2013-09-21 09:19 -------- d-----r- c:\users\Werner\Dropbox
2013-09-09 22:40 . 2013-09-09 22:41 -------- d-----w- c:\program files\Dropbox
2013-09-09 22:39 . 2013-09-21 09:19 -------- d-----w- c:\users\Werner\AppData\Roaming\Dropbox
2013-09-03 13:53 . 2013-09-03 13:53 187248 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2013-09-03 08:13 . 2013-09-03 08:13 -------- d-----w- c:\windows\CheckSur
2013-08-30 09:44 . 2013-08-02 04:09 1548288 ----a-w- c:\windows\system32\WMVDECOD.DLL
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-19 23:25 . 2012-04-04 07:58 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-19 23:25 . 2011-05-30 16:28 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-07-17 19:41 . 2013-08-14 11:41 2048 ----a-w- c:\windows\system32\tzres.dll
2013-07-10 09:47 . 2013-08-14 11:41 783360 ----a-w- c:\windows\system32\rpcrt4.dll
2013-07-09 12:10 . 2013-08-14 11:41 1205168 ----a-w- c:\windows\system32\ntdll.dll
2013-07-08 04:55 . 2013-08-14 11:41 3603904 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-07-08 04:55 . 2013-08-14 11:41 3551680 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-07-08 04:20 . 2013-08-14 11:41 172544 ----a-w- c:\windows\system32\wintrust.dll
2013-07-08 04:16 . 2013-08-14 11:41 98304 ----a-w- c:\windows\system32\cryptnet.dll
2013-07-08 04:16 . 2013-08-14 11:41 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2013-07-08 04:16 . 2013-08-14 11:41 992768 ----a-w- c:\windows\system32\crypt32.dll
2013-07-05 04:53 . 2013-08-14 11:42 905664 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{c9508125-4747-4733-b048-e4b82dc9716d}"= "c:\program files\PHPNukeDE\tbPHPN.dll" [2009-07-02 2215960]
.
[HKEY_CLASSES_ROOT\clsid\{c9508125-4747-4733-b048-e4b82dc9716d}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
2013-05-20 09:21 231712 ----a-w- c:\program files\Winload\prxtbWin1.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}]
2013-09-24 01:18 12240 ----a-w- c:\program files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{c9508125-4747-4733-b048-e4b82dc9716d}]
2009-07-02 09:18 2215960 ----a-w- c:\program files\PHPNukeDE\tbPHPN.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{c9508125-4747-4733-b048-e4b82dc9716d}"= "c:\program files\PHPNukeDE\tbPHPN.dll" [2009-07-02 2215960]
"{40c3cc16-7269-4b32-9531-17f2950fb06f}"= "c:\program files\Winload\prxtbWin1.dll" [2013-05-20 231712]
"{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2013-09-24 12240]
.
[HKEY_CLASSES_ROOT\clsid\{c9508125-4747-4733-b048-e4b82dc9716d}]
.
[HKEY_CLASSES_ROOT\clsid\{40c3cc16-7269-4b32-9531-17f2950fb06f}]
.
[HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{C9508125-4747-4733-B048-E4B82DC9716D}"= "c:\program files\PHPNukeDE\tbPHPN.dll" [2009-07-02 2215960]
.
[HKEY_CLASSES_ROOT\clsid\{c9508125-4747-4733-b048-e4b82dc9716d}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-06-05 17:17 130736 ----a-w- c:\users\Werner\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-06-05 17:17 130736 ----a-w- c:\users\Werner\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-06-05 17:17 130736 ----a-w- c:\users\Werner\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GMX_GMX Upload-Manager"="c:\program files\GMX\GMX Upload-Manager\DAVSRV.EXE" [2011-11-16 960608]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-11 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-02-24 10025576]
"Skytel"="c:\program files\Realtek\Audio\HDA\Skytel.exe" [2010-11-03 1833576]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdc.exe" [2007-01-24 563080]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2013-01-31 542632]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-09-24 347192]
"ApnTBMon"="c:\program files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe" [2013-09-24 1673680]
.
c:\users\Werner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TerminplanerStart.lnk - c:\program files\Terminplaner.NET\Terminplaner.exe [2011-9-30 2322432]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2013-2-7 575000]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files\TOSHIBA\TRDCReminder\TRDCReminder.exe [2008-3-5 393216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"GMX_GMX Upload-Manager"="c:\program files\GMX\GMX Upload-Manager\DAVSRV.EXE" /hide
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"Skype"="c:\program files\Skype\Phone\Skype.exe" /minimized /regrun
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HotKeysCmds"=c:\windows\system32\hkcmd.exe
"SmoothView"=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
"00TCrdMain"=%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
"TPwrMain"=%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
"Toshiba TEMPO"=c:\program files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"IgfxTray"=c:\windows\system32\igfxtray.exe
"Persistence"=c:\windows\system32\igfxpers.exe
"cfFncEnabler.exe"=cfFncEnabler.exe
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
"HSON"=%ProgramFiles%\TOSHIBA\TBS\HSON.exe
"NDSTray.exe"=NDSTray.exe
"LWS"=c:\program files\Logitech\LWS\Webcam Software\LWS.exe -hide
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
S2 AAV UpdateService;AAV UpdateService;c:\program files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [2008-10-24 128296]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - SSMDRV
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Inhalt des "geplante Tasks" Ordners
.
2013-09-25 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 23:25]
.
2013-09-25 c:\windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job
- c:\program files\DealPlyLive\Update\DealPlyLive.exe [2013-09-22 20:28]
.
2013-09-25 c:\windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job
- c:\program files\DealPlyLive\Update\DealPlyLive.exe [2013-09-22 20:28]
.
2013-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-15 18:25]
.
2013-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-15 18:25]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=AAD40024D29567E9&affID=119357&tt=160913_c3&tsp=5015
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
IE: add to &BOM - c:\\PROGRA~1\\BIET-O~1\\\\AddToBOM.hta
IE: Free YouTube to MP3 Converter - c:\users\Werner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Werner\AppData\Roaming\Mozilla\Firefox\Profiles\o49zp59d.default-1352796946505\
FF - prefs.js: browser.search.defaulturl - hxxp://securesearch.lavasoft.com/?source=f439e2c0&tbp=homepage&toolbarid=adawaretb&v=2_5&u=21655136740E774D2D250D5161E1D858
FF - prefs.js: browser.startup.homepage - hxxp://www.onlinefussballmanager.de/|https://www.facebook.com/|hxxp://www.gmx.net/
FF - ExtSQL: 2013-09-24 03:19; toolbar_AVIRA-V7@apn.ask.com; c:\users\Werner\AppData\Roaming\Mozilla\Firefox\Profiles\o49zp59d.default-1352796946505\extensions\toolbar_AVIRA-V7@apn.ask.com.xpi
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: extensions.delta.tlbrSrchUrl -
FF - user.js: extensions.delta.id - aad45a6e0000000000000024d29567e9
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15972
FF - user.js: extensions.delta.vrsn - 1.8.24.6
FF - user.js: extensions.delta.vrsni - 1.8.24.6
FF - user.js: extensions.delta.vrsnTs - 1.8.24.611:28
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - de
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=119357&tt=160913_c3&tsp=5015
FF - user.js: extensions.delta_i.babExt -
FF - user.js: extensions.delta_i.srcExt - ss
FF - user.js: extensions.delta.autoRvrt - false
FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk - c:\program files\DSL-Manager\DslMgr.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, hxxp://www.gmer.net
Rootkit scan 2013-09-25 22:51
Windows 6.0.6002 Service Pack 2 NTFS
.
Scanne versteckte Prozesse...
.
Scanne versteckte Autostarteinträge...
.
Scanne versteckte Dateien...
.
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
.
**************************************************************************
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3643614194-1483582255-1908189571-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0BB8A46A-F37A-56E1-499D-E507B22FC36A}*]
"paheicjbmpgiglablafjogkmaknejkam"=hex:61,62,6d,69,6b,66,6b,6b,61,64,61,68,6e,
6d,63,69,62,65,6e,66,6b,6f,68,6b,6a,65,70,6f,68,66,62,6b,65,68,00,00
.
[HKEY_USERS\S-1-5-21-3643614194-1483582255-1908189571-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{92C1845F-9629-E837-45B3-5CE2552BF71B}*]
"pahkcmcamhdadjfkagekbgbhjjogehob"=hex:61,62,6d,6f,69,66,6f,69,61,67,66,6d,70,
70,6c,6a,66,61,62,65,69,63,65,69,69,6b,61,6d,69,65,6e,63,62,61,00,00
"pabpckcocccejelfjjnllpmbbponhadi"=hex:61,62,6d,6f,69,66,6f,69,61,67,66,6d,70,
70,6c,6a,66,61,62,65,69,63,65,69,69,6b,61,6d,69,65,6e,63,62,61,00,00
"pahpjcpdjladbnpclaechbfdopiccmef"=hex:61,61,00,02
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Zeit der Fertigstellung: 2013-09-25 22:57:52
ComboFix-quarantined-files.txt 2013-09-25 20:57
.
Vor Suchlauf: 13 Verzeichnis(se), 56.189.202.432 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 55.905.607.680 Bytes frei
.
- - End Of File - - AD9277853D82C723D7EFADD8865D8D6B --- --- ---
5C616939100B85E558DA92B899A0FC36 |