+ 2012-07-27 23:16 . 2012-05-17 16:24 2682368 c:\windows\system32\DriverStore\FileRepository\hpbje1201xps.inf_amd64_neutral_d9d1c935b57a507a\Bonjour64.msi
+ 2009-07-14 04:45 . 2012-08-07 02:05 7113171 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2009-07-14 04:45 . 2012-07-11 01:01 7113171 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2012-08-04 23:34 . 2012-08-04 23:34 2146304 c:\windows\Installer\ff0b9e.msp
+ 2011-04-15 22:46 . 2011-04-15 22:46 4250112 c:\windows\Installer\ff0b93.msi
+ 2011-04-15 22:46 . 2011-04-15 22:46 4175360 c:\windows\Installer\ff0b88.msi
+ 2011-04-15 22:46 . 2011-04-15 22:46 3410944 c:\windows\Installer\ff0b7d.msi
+ 2012-08-04 23:34 . 2012-08-04 23:34 5124096 c:\windows\Installer\ff0b77.msp
+ 2011-09-01 19:55 . 2011-09-01 19:55 6661632 c:\windows\Installer\ff0b6d.msi
+ 2011-04-15 22:46 . 2011-04-15 22:46 1070592 c:\windows\Installer\ff0b5d.msi
+ 2011-04-15 22:46 . 2011-04-15 22:46 1492992 c:\windows\Installer\ff0b4f.msi
+ 2012-08-04 23:33 . 2012-08-04 23:33 3734016 c:\windows\Installer\ff0b2d.msp
+ 2012-08-04 23:33 . 2012-08-04 23:33 2957312 c:\windows\Installer\ff0ae6.msp
+ 2011-04-15 22:46 . 2011-04-15 22:46 8313856 c:\windows\Installer\ff0acc.msi
+ 2012-08-04 23:33 . 2012-08-04 23:33 5868544 c:\windows\Installer\ff0ac7.msp
+ 2012-08-04 23:33 . 2012-08-04 23:33 5535744 c:\windows\Installer\ff0aa9.msp
+ 2012-08-04 23:33 . 2012-08-04 23:33 3312128 c:\windows\Installer\ff0a8e.msp
+ 2011-04-15 22:46 . 2011-04-15 22:46 8332288 c:\windows\Installer\ff0a72.msi
+ 2011-09-01 19:54 . 2011-09-01 19:54 2310656 c:\windows\Installer\ff0a62.msi
+ 2012-08-04 23:33 . 2012-08-04 23:33 1139712 c:\windows\Installer\ff0a5d.msp
+ 2011-04-15 22:46 . 2011-04-15 22:46 4004864 c:\windows\Installer\ff0a51.msi
+ 2012-08-04 23:33 . 2012-08-04 23:33 2932224 c:\windows\Installer\ff0a42.msp
+ 2011-04-15 22:46 . 2011-04-15 22:46 7710720 c:\windows\Installer\ff0a2e.msi
+ 2012-08-04 23:33 . 2012-08-04 23:33 4426240 c:\windows\Installer\ff0a29.msp
+ 2011-04-15 22:46 . 2011-04-15 22:46 9433088 c:\windows\Installer\ff0a1a.msi
+ 2010-11-17 00:28 . 2010-11-17 00:28 3458560 c:\windows\Installer\f2c2e24.msi
+ 2010-10-14 10:11 . 2010-10-14 10:11 6142976 c:\windows\Installer\c16f1.msi
+ 2012-05-10 11:15 . 2012-05-10 11:15 2127872 c:\windows\Installer\8f70c94.msi
+ 2010-09-19 18:49 . 2010-09-19 18:49 2873344 c:\windows\Installer\8f70c8d.msp
+ 2010-09-19 18:49 . 2010-09-19 18:49 3278336 c:\windows\Installer\8f70c8c.msi
+ 2010-09-19 18:49 . 2010-09-19 18:49 3335168 c:\windows\Installer\8f70c83.msi
+ 2010-09-19 18:49 . 2010-09-19 18:49 2067968 c:\windows\Installer\8f70c7b.msi
+ 2010-09-19 18:49 . 2010-09-19 18:49 1374208 c:\windows\Installer\8f70c73.msi
+ 2010-09-19 18:49 . 2010-09-19 18:49 2882560 c:\windows\Installer\8f70c6b.msp
+ 2010-09-19 18:49 . 2010-09-19 18:49 5396480 c:\windows\Installer\8f70c6a.msi
+ 2010-09-19 18:57 . 2010-09-19 18:57 8628224 c:\windows\Installer\8f70c60.msi
+ 2010-09-19 18:49 . 2010-09-19 18:49 1143808 c:\windows\Installer\8f70c56.msi
+ 2010-09-19 18:49 . 2010-09-19 18:49 6151680 c:\windows\Installer\8f70c4e.msp
+ 2010-09-19 18:49 . 2010-09-19 18:49 1615360 c:\windows\Installer\8f70c4d.msi
+ 2010-09-19 18:57 . 2010-09-19 18:57 8134144 c:\windows\Installer\8f70c45.msi
+ 2010-09-19 18:49 . 2010-09-19 18:49 1134080 c:\windows\Installer\8f70c3d.msi
+ 2010-09-19 18:49 . 2010-09-19 18:49 2915840 c:\windows\Installer\8f70c35.msp
+ 2010-09-19 18:49 . 2010-09-19 18:49 1182208 c:\windows\Installer\8f70c34.msi
+ 2010-09-19 18:49 . 2010-09-19 18:49 2312704 c:\windows\Installer\8f70c2c.msi
+ 2010-09-19 18:49 . 2010-09-19 18:49 1850368 c:\windows\Installer\8f70c25.msi
+ 2012-05-21 22:49 . 2012-05-21 22:49 1884160 c:\windows\Installer\255e53.msi
+ 2012-08-06 20:28 . 2012-08-06 20:28 6434816 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.SqlServer#\c91bee7c934f3c9d069fc1537123a78f\Microsoft.SqlServer.Smo.ni.dll
+ 2012-08-06 20:28 . 2012-08-06 20:28 1013760 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.SqlServer#\b09abb7555adf60dd9293641274f9757\Microsoft.SqlServer.WizardFramework.ni.dll
+ 2012-08-06 20:28 . 2012-08-06 20:28 1126912 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.SqlServer#\91dd27c62976473282414893d72408cc\Microsoft.SqlServer.Management.Sdk.Sfc.ni.dll
+ 2012-08-06 20:28 . 2012-08-06 20:28 1502208 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.SqlServer#\4d0d149ce308e704b7a333e89718e653\Microsoft.SqlServer.SqlEnum.ni.dll
+ 2012-08-06 20:28 . 2012-08-06 20:28 1187840 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.SqlServer#\415196eec049cb7d19541196afc56dc7\Microsoft.SqlServer.Dmf.ni.dll
+ 2012-08-06 20:28 . 2012-08-06 20:28 1621504 c:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.DataTrans#\b953d02051187b49c771feb0f971165f\Microsoft.DataTransformationServices.Controls.ni.dll
+ 2012-08-06 20:28 . 2012-08-06 20:28 1385984 c:\windows\assembly\NativeImages_v4.0.30319_32\DTSWizard\f5137034f1a1d2994e28f3bb3e69e8e4\DTSWizard.ni.exe
+ 2012-08-05 00:49 . 2012-08-05 00:49 7025152 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f6cac6d0e82d3714667b5fe78442bb26\WindowsLive.Writer.PostEditor.ni.dll
+ 2012-08-05 00:49 . 2012-08-05 00:49 2193408 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\adb0e58139fd3acff774fafea2b34d5f\WindowsLive.Writer.CoreServices.ni.dll
+ 2012-08-05 00:49 . 2012-08-05 00:49 1346560 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a77dc72d1b8dab87fdbf73252925c3de\WindowsLive.Writer.Localization.ni.dll
+ 2012-08-05 00:49 . 2012-08-05 00:49 1285632 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\2a7f76b6857454c1216089b694d7d72a\WindowsLive.Writer.ApplicationFramework.ni.dll
+ 2012-08-06 18:51 . 2012-08-06 18:51 1126912 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\ef2e160b820dc15535d034202f3cf49e\Microsoft.SqlServer.Management.Sdk.Sfc.ni.dll
+ 2012-08-06 18:51 . 2012-08-06 18:51 1510400 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\d80b56f4acd44fe2572109a4a9eff641\Microsoft.SqlServer.SqlEnum.ni.dll
+ 2012-08-06 18:51 . 2012-08-06 18:51 6120448 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\56651f3a01e88bf51f021533addea5df\Microsoft.SqlServer.Smo.ni.dll
+ 2012-08-06 18:52 . 2012-08-06 18:52 1128448 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\19219a0d25c6890fa6cc1aa6d3dadce5\Microsoft.SqlServer.Dmf.ni.dll
+ 2012-08-06 20:28 . 2012-08-06 20:28 3477504 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\154a844bf1f881a4e55188b2fed698eb\Microsoft.SqlServer.Replication.ni.dll
+ 2012-08-06 20:28 . 2012-08-06 20:28 1603072 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.DataTrans#\4e9124b9455b4a92c83bc2a24c87139e\Microsoft.DataTransformationServices.Controls.ni.dll
+ 2012-08-06 20:28 . 2012-08-06 20:28 2952192 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.AnalysisS#\7745f081442201eefc95ff956c511335\Microsoft.AnalysisServices.ni.dll
+ 2012-08-06 18:48 . 2012-08-06 18:48 1083224 c:\windows\assembly\GAC_MSIL\Microsoft.SqlServer.SqlEnum\10.0.0.0__89845dcd8080cc91\Microsoft.SqlServer.SqlEnum.dll
+ 2012-08-06 18:48 . 2012-08-06 18:48 2860888 c:\windows\assembly\GAC_MSIL\Microsoft.SqlServer.Smo\10.0.0.0__89845dcd8080cc91\Microsoft.SqlServer.Smo.dll
+ 2012-08-06 18:48 . 2012-08-06 18:48 1320792 c:\windows\assembly\GAC_MSIL\Microsoft.AnalysisServices\10.0.0.0__89845dcd8080cc91\Microsoft.AnalysisServices.DLL
+ 2010-11-17 04:06 . 2010-11-17 04:06 12659560 c:\windows\twain_32\HP Officejet 7500 E910\HPScanUI.dll
+ 2012-07-27 23:16 . 2012-06-01 20:27 11714560 c:\windows\system32\spool\drivers\x64\3\HPBPSConverter.msi
+ 2012-07-27 23:16 . 2012-06-01 20:27 11714560 c:\windows\system32\DriverStore\FileRepository\hpbje1201xps.inf_amd64_neutral_d9d1c935b57a507a\HPBPSConverter.msi
+ 2012-04-02 17:29 . 2012-08-14 22:13 11867000 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-06-06 21:25 . 2012-08-15 00:11 61740840 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1579782722-2534579174-2828074957-1000-12288.dat
+ 2011-04-15 22:46 . 2011-04-15 22:46 11846656 c:\windows\Installer\ff0b24.msi
+ 2012-08-04 23:33 . 2012-08-04 23:33 14624256 c:\windows\Installer\ff0b1c.msp
+ 2011-04-15 22:46 . 2011-04-15 22:46 34193408 c:\windows\Installer\ff0af1.msi
+ 2011-04-15 22:46 . 2011-04-15 22:46 13850624 c:\windows\Installer\ff0ab0.msi
+ 2011-09-01 19:54 . 2011-09-01 19:54 22647296 c:\windows\Installer\ff0a96.msi
+ 2012-08-03 01:13 . 2012-08-03 01:13 18900480 c:\windows\Installer\b7989c7.msi
+ 2010-09-19 18:49 . 2010-09-19 18:49 22994944 c:\windows\Installer\8f70c84.msp
+ 2012-06-01 20:27 . 2012-06-01 20:27 11714560 c:\windows\Installer\255e5a.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2011-04-01 04:45 501760 ----a-w- c:\program files\Classic Shell\ClassicExplorer32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-10-17 39408]
"RoboForm"="c:\program files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2012-04-20 109296]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files (x86)\Common Files\Symantec Shared\ccApp.exe" [2010-06-30 115560]
"Intuit SyncManager"="c:\program files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2011-06-15 1532760]
"InstaLAN"="c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" [2011-04-30 1770400]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-15 636032]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
"TkBellExe"="c:\program files (x86)\Real\RealPlayer\update\realsched.exe" [2012-06-16 296056]
"HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2012-04-17 651264]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
AML Device Install.lnk - c:\program files (x86)\AMD AVT\bin\kdbsync.exe [2012-1-31 10752]
Marketsplash Print Software.lnk - c:\program files (x86)\Hewlett-Packard\Marketsplash by HP\HPLocalWebPrintAgent.exe [2010-10-11 93752]
QuickBooks Update Agent.lnk - c:\program files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2011-12-22 984936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp msoidssp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-02 136176]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatch13.exe [2010-07-16 354288]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-02 250056]
R3 AODDriver4.0;AODDriver4.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-01-04 55936]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-02 136176]
R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-11-02 33736]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-25 36928]
R3 npkcft64;npkcft64;c:\windows\SysWOW64\npkcft64.sys [2012-06-14 48960]
R3 npkuft64;npkuft64;c:\windows\SysWOW64\npkuft64.sys [2012-06-14 47936]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 RoxMediaDB13;RoxMediaDB13;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxMediaDB13.exe [2010-07-16 1099248]
R3 RRNetCap;RRNetCap Service;c:\windows\system32\DRIVERS\rrnetcap.sys [2012-04-02 37480]
R3 SureThing Labelflash service;SureThing Labelflash service;c:\program files (x86)\Common Files\SureThing Shared\stllssvr.exe [2010-02-02 74392]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-06-02 1255736]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files (x86)\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-09-19 47128]
R4 SQLAgent$SQLLANSWEEPER2K8;SQL Server Agent (SQLLANSWEEPER2K8);c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLLANSWEEPER2K8\MSSQL\Binn\SQLAGENT.EXE [2010-09-17 370008]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys [2010-08-13 75904]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys [2010-08-13 38016]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-03-19 55856]
S0 Sahdad64;HDD Filter Driver;c:\windows\System32\Drivers\Sahdad64.sys [2009-06-02 27120]
S0 Saibad64;Volume Filter Driver;c:\windows\System32\Drivers\Saibad64.sys [2009-06-02 19952]
S1 SaibVdAd64;Virtual Disk Driver;c:\windows\system32\Drivers\SaibVdAd64.sys [2009-06-02 27632]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [2009-06-03 457200]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-06-30 204288]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2012-02-15 361984]
S2 AODDriver4.1;AODDriver4.1;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2012-01-04 55936]
S2 Belkin Local Backup Service;Belkin Local Backup Service;c:\program files\Belkin\Belkin USB Print and Storage Center\BkBackupScheduler.exe [2010-02-18 181760]
S2 Belkin Network USB Helper;Belkin Network USB Helper;c:\program files\Belkin\Belkin USB Print and Storage Center\Bkapcs.exe [2010-02-09 55296]
S2 BOT4Service;BOT4Service;c:\program files (x86)\Roxio\BackOnTrack\App\BService.exe [2010-07-14 32240]
S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-10 86072]
S2 HPAuto;HP Auto;c:\program files\Hewlett-Packard\HP Auto\HPAuto.exe [2010-08-06 681528]
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-08-06 291896]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-29 94264]
S2 IntuitUpdateServiceV4;Intuit Update Service v4;c:\program files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe [2012-02-07 13672]
S2 lansweeperservice;Lansweeper Server;c:\program files (x86)\Lansweeper\Service\Lansweeperservice.exe [2012-07-04 355840]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-07-06 375208]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2012-06-08 15928]
S2 msoidsvc;Microsoft Online Services Sign-in Assistant;c:\program files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE [2011-09-28 2078112]
S2 MSSQL$SQLLANSWEEPER2K8;SQL Server (SQLLANSWEEPER2K8);c:\program files (x86)\Microsoft SQL Server\MSSQL10.SQLLANSWEEPER2K8\MSSQL\Binn\sqlservr.exe [2010-09-17 42773336]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2012-03-23 87040]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2010-09-28 1119768]
S2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe [2009-12-10 65536]
S2 sxuptp;SXUPTP Driver;c:\windows\system32\DRIVERS\sxuptp.sys [2010-05-21 290824]
S2 TivoBeacon2;TiVo Beacon Service;c:\program files (x86)\TiVo\Desktop\TiVoBeacon.exe [2010-08-25 1104656]
S2 UltiDev Web Server Pro;UltiDev Web Server Pro;c:\program files (x86)\UltiDev\Web Server\UltiDev.WebServer.Monitor.exe [2012-05-10 64512]
S2 UWS HiPriv Services;UWS HiPriv Services;c:\program files (x86)\UltiDev\Web Server\UWS.HighPrivilegeUtilities.exe [2012-05-10 48128]
S2 UWS LoPriv Services;UWS LoPriv Services;c:\program files (x86)\UltiDev\Web Server\UWS.LowPrivilegeUtilities.exe [2012-05-10 44032]
S2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~2\SPEEDB~1\VideoAcceleratorService.exe [2012-01-27 313624]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2011-06-30 9371136]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2011-06-30 309760]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2011-03-30 114704]
S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys [2011-05-18 47616]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2012-08-08 138912]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [2010-11-05 1041760]
S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [2011-08-01 45416]
S3 RRNetCapMP;RRNetCapMP;c:\windows\system32\DRIVERS\rrnetcap.sys [2012-04-02 37480]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-09-03 349800]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-12-22 38456]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-06-20 23:05 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{582610B8-E496-4813-993C-4B027173FE38}]
2008-02-08 17:53 7680 ----a-w- c:\program files (x86)\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-15 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 17:26]
.
2012-08-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-02 17:57]
.
2012-08-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-02 17:57]
.
2012-08-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1579782722-2534579174-2828074957-1000Core.job
- c:\users\garyh\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-29 19:48]
.
2012-08-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1579782722-2534579174-2828074957-1000UA.job
- c:\users\garyh\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-29 19:48]
.
2012-08-14 c:\windows\Tasks\HPCeeScheduleForgaryh.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
2012-08-14 c:\windows\Tasks\HPCeeScheduleForGLH-HPDESKTOP$.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 05:15]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ShareOverlay]
@="{594D4122-1F87-41E2-96C7-825FB4796516}"
[HKEY_CLASSES_ROOT\CLSID\{594D4122-1F87-41E2-96C7-825FB4796516}]
2011-04-01 04:46 625152 ----a-w- c:\program files\Classic Shell\ClassicExplorer64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Classic Start Menu"="c:\program files\Classic Shell\ClassicStartMenu.exe" [2011-04-01 98304]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1873256]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 2417032]
"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2012-06-08 57928]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://professional.wsj.com/home-page
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\system32\blank.htm
IE: Customize Menu -
file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Fill Forms -
file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Save Forms -
file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Show RoboForm Toolbar -
file://c:\program files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
Trusted Zone: GLH-HPDESKTOP
Trusted Zone: intuit.com\ttlc
Trusted Zone: networksolutions.com\www
Trusted Zone: rhapsody.com\rhap-app-4-0
Trusted Zone: rhapsody.com\rhapreg
Trusted Zone: turbotax.com
Trusted Zone: wsj.com\customercenter
TCP: DhcpNameServer = 192.168.1.5
DPF: {7B62F6EE-D046-11D3-9C5E-0060082627F7} - hxxps://emfserver.wpas-inc.com/messenger/download/TWDownload.cab
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{553891B7-A0D5-4526-BE18-D3CE461D6310}"=hex:51,66,7a,6c,4c,1d,38,12,d9,92,2b,
51,e7,ee,48,00,c1,0e,90,8e,43,43,27,04
"{724D43A0-0D85-11D4-9908-00400523E39A}"=hex:51,66,7a,6c,4c,1d,38,12,ce,40,5e,
76,b7,43,ba,54,e6,1e,43,00,00,7d,a7,8e
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=hex:51,66,7a,6c,4c,1d,38,12,df,c1,0b,
27,57,07,ba,54,e4,0e,43,d0,22,fb,89,5b
"{0347C33E-8762-4905-BF09-768834316C61}"=hex:51,66,7a,6c,4c,1d,38,12,50,c0,54,
07,50,c9,6b,0c,c0,1f,35,c8,31,6f,28,75
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{3049C3E9-B461-4BC5-8870-4C09146192CA}"=hex:51,66,7a,6c,4c,1d,38,12,87,c0,5a,
34,53,fa,ab,0e,f7,66,0f,49,11,3f,d6,de
"{449D0D6E-2412-4E61-B68F-1CB625CD9E52}"=hex:51,66,7a,6c,4c,1d,38,12,00,0e,8e,
40,20,6a,0f,0b,c9,99,5f,f6,20,93,da,46
"{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}"=hex:51,66,7a,6c,4c,1d,38,12,c0,08,7b,
68,6e,2b,53,0b,f0,d2,a5,e5,25,9d,9d,3c
"{6EBF7485-159F-4BFF-A14F-B9E3AAC4465B}"=hex:51,66,7a,6c,4c,1d,38,12,eb,77,ac,
6a,ad,5b,91,0e,de,59,fa,a3,af,9a,02,4f
"{724D43A9-0D85-11D4-9908-00400523E39A}"=hex:51,66,7a,6c,4c,1d,38,12,c7,40,5e,
76,b7,43,ba,54,e6,1e,43,00,00,7d,a7,8e
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{9030D464-4C02-4ABF-8ECC-5164760863C6}"=hex:51,66,7a,6c,4c,1d,38,12,0a,d7,23,
94,30,02,d1,0f,f1,da,12,24,73,56,27,d2
"{AA58ED58-01DD-4D91-8333-CF10577473F7}"=hex:51,66,7a,6c,4c,1d,38,12,36,ee,4b,
ae,ef,4f,ff,08,fc,25,8c,50,52,2a,37,e3
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,
b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{EA801577-E6AD-4BD5-8F71-4BE0154331A4}"=hex:51,66,7a,6c,4c,1d,38,12,19,16,93,
ee,9f,a8,bb,0e,f0,67,08,a0,10,1d,75,b0
"{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}"=hex:51,66,7a,6c,4c,1d,38,12,91,fc,ec,
fb,7c,81,45,0a,c2,d4,4d,32,e4,48,ec,42
"{555D4D79-4BD2-4094-A395-CFC534424A05}"=hex:51,66,7a,6c,4c,1d,38,12,17,4e,4e,
51,e0,05,fa,05,dc,83,8c,85,31,1c,0e,11
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}"=hex:51,66,7a,6c,4c,1d,38,12,5f,9d,16,
fb,68,82,40,0b,c0,2d,d5,a9,2c,88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}"=hex:51,66,7a,6c,4c,1d,38,12,11,dd,f9,
b9,57,8c,be,54,c3,fb,43,e0,cc,54,f1,1b
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:f1,e9,fc,c3,22,2b,cd,01
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_270_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_270_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_270.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}]
@Denied: (A) (Everyone)
"Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane\0]
"Key"="ActionsPane"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\SysWOW64\npkcmsvc.exe
c:\program files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\PostgreSQL\8.3\bin\postgres.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe
c:\program files (x86)\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\progra~2\SPEEDB~1\VideoAcceleratorEngine.exe
c:\program files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
c:\program files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
.
**************************************************************************
.
Completion time: 2012-08-14 18:14:58 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-15 01:14
ComboFix2.txt 2012-06-12 18:07
ComboFix3.txt 2011-10-16 21:43
.
Pre-Run: 765,785,079,808 bytes free
Post-Run: 766,216,138,752 bytes free
.
- - End Of File - - ECC318818826CCCF4B446B6450DB6296