0% found this document useful (0 votes)
138 views

Combo Fix

This document provides a summary of files created on a SERVER computer between August 4, 2013 and September 4, 2013. It lists the date and time each file or folder was created, as well as its name and location on the server's hard drive. The files include system files, program installers and files for various software applications.
Copyright
© Attribution Non-Commercial (BY-NC)
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
138 views

Combo Fix

This document provides a summary of files created on a SERVER computer between August 4, 2013 and September 4, 2013. It lists the date and time each file or folder was created, as well as its name and location on the server's hard drive. The files include system files, program installers and files for various software applications.
Copyright
© Attribution Non-Commercial (BY-NC)
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
You are on page 1/ 12

ComboFix 13-09-02.02 - SERVER 03/09/2013 22:57:20.3.

4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.51.3082.18.2726.1610 [GMT -5:00]
Running from: c:\users\SERVER\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619E
FD8BF}
FW: Norton Internet Security *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B46268
9202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2013-08-04 to 2013-09-04 )))))))
))))))))))))))))))))))))
.
.
2013-09-04 04:04 . 2013-09-04 04:04
-------d-----wc:\users
\Default\AppData\Local\temp
2013-09-03 01:24 . 2013-09-03 01:24
-------d-----wc:\progr
am files\Common Files\DESIGNER
2013-09-03 01:23 . 2013-09-03 01:23
-------d-----wc:\progr
am files\Microsoft.NET
2013-09-03 01:23 . 2013-09-03 01:23
-------d-----wc:\progr
am files (x86)\Microsoft SQL Server
2013-09-03 01:22 . 2013-09-03 01:22
-------d-----wc:\progr
amdata\regid.1991-06.com.microsoft
2013-08-30 23:13 . 2013-08-30 23:13
-------d--h--wc:\windo
ws\PIF
2013-08-29 23:08 . 2013-08-29 23:08
-------d-----wc:\progr
am files\ReviverSoft
2013-08-29 22:49 . 2013-08-29 22:50
-------d-----wc:\progr
am files (x86)\USB Guardian
2013-08-27 22:18 . 2011-04-20 08:03
120320 ----a-wc:\windows\syste
m32\E_ILMHJB.DLL
2013-08-27 22:18 . 2011-03-15 08:03
83968 ----a-wc:\windows\syste
m32\E_ID4BHJB.DLL
2013-08-27 02:17 . 2013-08-27 02:17
-------d-----wC:\Adjus
tment Program
2013-08-26 21:56 . 2013-04-30 14:33
29704 ----a-wc:\windows\syste
m32\nitrolocalmon2.dll
2013-08-26 21:56 . 2013-04-30 14:33
17928 ----a-wc:\windows\syste
m32\nitrolocalui2.dll
2013-08-26 21:55 . 2013-08-26 21:55
-------d-----wc:\progr
am files\Common Files\Nitro
2013-08-26 21:55 . 2013-08-26 21:55
-------d-----wc:\progr
am files (x86)\Common Files\Nitro
2013-08-23 16:18 . 2013-08-23 16:18
-------d-----wc:\users
\SERVER\AppData\Roaming\PandoraRecovery
2013-08-18 00:07 . 2013-08-28 03:42
-------d-----wC:\Drive
rs
2013-08-17 04:48 . 2013-08-17 04:48
-------d-----wc:\progr
am files (x86)\SmartDCT4Calc v1.1.7
2013-08-17 04:46 . 2013-08-17 04:47
-------d-----wc:\progr
am files (x86)\usr
2013-08-17 01:38 . 2013-08-17 03:56
-------d-----wc:\progr
am files (x86)\WorldUnlock Codes Calculator
2013-08-17 00:37 . 2013-08-17 00:37
-------d-----wc:\users
\SERVER\AppData\Roaming\Apple Computer
2013-08-15 22:55 . 2013-08-15 22:56
-------d-----wc:\users
\SERVER\AppData\Local\Nokia
2013-08-15 22:55 . 2013-08-15 22:55
-------d-----wc:\users

\SERVER\AppData\Roaming\PC Suite
2013-08-15 22:55 . 2013-08-15 22:55
-------d-----wc:\progr
amdata\PC Suite
2013-08-15 22:55 . 2013-08-22 00:34
-------d-----wc:\progr
amdata\Nokia
2013-08-15 22:54 . 2012-10-17 19:53
26112 ----a-wc:\windows\syste
m32\drivers\pccsmcfdx64.sys
2013-08-15 22:54 . 2013-08-15 22:54
-------d-----wc:\progr
am files (x86)\PC Connectivity Solution
2013-08-15 22:54 . 2013-01-23 15:31
57856 ----a-wc:\windows\syste
m32\nmwcdclsX64.dll
2013-08-15 22:52 . 2013-08-15 22:55
-------d-----wc:\progr
am files (x86)\Nokia
2013-08-15 22:32 . 2013-08-15 22:32
-------d-----wc:\progr
am files\DIFX
2013-08-15 22:32 . 2013-08-15 22:54
-------dc----wc:\windo
ws\system32\DRVSTORE
2013-08-15 22:32 . 2012-02-12 02:25
28528 ----a-wc:\windows\rlt87
23a_chip_bt40_fw_asic_rom_patch.dll
2013-08-15 22:32 . 2013-08-15 22:32
-------d-----wc:\progr
am files (x86)\REALTEK
2013-08-15 22:32 . 2013-08-15 22:32
-------d-----wc:\users
\SERVER\AppData\Roaming\WinBatch
2013-08-15 21:55 . 2013-08-15 21:55
-------d-----wc:\progr
amdata\Mobile Master
2013-08-15 21:53 . 2013-08-15 21:53
-------d-----wc:\users
\SERVER\AppData\Roaming\Jumping Bytes
2013-08-15 21:00 . 2013-08-15 21:00
-------d-----wc:\users
\SERVER\AppData\Local\Wondershare
2013-08-15 21:00 . 2013-08-15 21:00
-------d-----wc:\progr
am files (x86)\Common Files\Wondershare
2013-08-15 21:00 . 2013-08-16 01:17
-------d-----wc:\progr
am files (x86)\Temp
2013-08-15 21:00 . 2013-08-15 21:00
-------d-----wc:\progr
am files (x86)\Wondershare
2013-08-15 16:26 . 2013-08-15 16:26
-------d-----wc:\users
\SERVER\AppData\Local\ApplicationHistory
2013-08-15 15:19 . 2013-08-15 15:19
-------d-----wc:\progr
am files (x86)\Your Uninstaller! 7
2013-08-15 15:19 . 2013-08-15 15:19
-------d-----wc:\users
\SERVER\AppData\Roaming\URSoft
2013-08-15 15:11 . 2013-08-15 15:11
-------d-----wc:\progr
am files (x86)\VS Revo Group
2013-08-14 00:52 . 2013-09-03 05:14
-------d-----wc:\users
\SERVER\AppData\Local\CrashDumps
2013-08-14 00:04 . 2013-08-14 00:04
-------d-----wc:\users
\SERVER\AppData\Roaming\Iminent
2013-08-14 00:04 . 2013-08-14 00:04
-------d-----wc:\progr
amdata\Iminent
2013-08-14 00:03 . 2013-08-14 00:03
-------d-----wc:\progr
am files (x86)\Common Files\Umbrella
2013-08-13 23:59 . 2013-08-13 23:59
-------d-----wc:\users
\SERVER\AppData\Roaming\Progeny
2013-08-13 23:53 . 2013-08-14 00:46
952
--sha-wc:\programdata\K
GyGaAvL.sys
2013-08-13 23:53 . 2004-12-07 12:11
258352 ----a-wc:\windows\SysWo
w64\unicows.dll
2013-08-13 23:53 . 2013-08-13 23:53
-------d-----wc:\progr
am files (x86)\Common Files\Progeny
2013-08-13 23:53 . 2013-08-31 04:36
-------d-----wc:\progr

am files\TLM Professional
2013-08-13 23:52 . 2013-08-13 23:52
-------d-----wc:\progr
am files (x86)\Common Files\InstallShield
2013-08-13 23:11 . 2013-08-14 01:13
-------d-----wc:\users
\SERVER\AppData\Roaming\CmapTools
2013-08-13 23:11 . 2013-08-14 14:47
-------d-----wc:\users
\SERVER\CmapToolsLogs
2013-08-13 23:09 . 2013-08-14 14:48
-------d-----wc:\progr
am files\IHMC CmapTools
2013-08-13 23:09 . 2013-08-13 23:09
-------d--h--wc:\progr
am files\Zero G Registry
2013-08-13 23:08 . 2013-08-13 23:08
-------d--h--wc:\users
\SERVER\InstallAnywhere
2013-08-13 14:53 . 2013-08-21 19:52
-------d-----wc:\users
\SERVER\AppData\Roaming\Skype
2013-08-13 14:53 . 2013-08-13 14:53
-------d-----wc:\progr
am files (x86)\Common Files\Skype
2013-08-13 14:53 . 2013-08-13 14:53
-------d-----rc:\progr
am files (x86)\Skype
2013-08-13 14:52 . 2013-08-13 14:53
-------d-----wc:\progr
amdata\Skype
2013-08-11 16:16 . 2013-08-11 16:19
-------d-----wc:\users
\SERVER\AppData\Roaming\Corel
2013-08-11 16:16 . 2013-08-11 16:16
-------d-----wc:\progr
amdata\Protexis64
2013-08-11 16:11 . 2013-08-11 16:11
-------d-----wc:\progr
am files (x86)\Microsoft SDKs
2013-08-11 16:10 . 2013-08-11 16:14
-------d-----wc:\progr
am files (x86)\Microsoft Visual Studio 9.0
2013-08-11 16:10 . 2013-08-11 16:10
-------d-----wc:\progr
am files (x86)\Common Files\Intel
2013-08-11 16:08 . 2013-08-11 16:08
-------d-----wc:\progr
am files\Common Files\Corel
2013-08-11 16:07 . 2013-08-11 16:07
-------d-----wc:\progr
am files\Common Files\Protexis
2013-08-11 16:07 . 2013-08-11 16:07
-------d-----wc:\progr
amdata\Corel
2013-08-11 16:02 . 2013-08-11 16:02
-------d-----wc:\progr
am files\Corel
2013-08-11 14:36 . 2013-08-14 14:26
-------d-----wc:\users
\SERVER\AppData\Roaming\Movdap
2013-08-08 21:38 . 2013-08-08 21:39
-------d-----wc:\users
\SERVER\AppData\Roaming\SmileysWeLove
2013-08-08 21:38 . 2009-09-12 16:21
1831424 ----a-wc:\windows\Netwo
rkCfg.exe
2013-08-08 21:38 . 2013-08-09 01:50
-------d-----wc:\progr
amdata\Anyplace Control 4
2013-08-08 11:59 . 2013-09-04 02:56
-------d-----wC:\servi
dor1.585b-Sin-Publi
2013-08-08 01:51 . 2013-09-03 08:47
-------d-----wc:\users
\SERVER\AppData\Roaming\Nitro PDF
2013-08-07 19:39 . 2013-08-26 22:33
-------d-----wc:\users
\SERVER\AppData\Roaming\Nitro
2013-08-07 19:39 . 2013-08-07 19:39
-------d-----wc:\users
\SERVER\AppData\Roaming\FileOpen
2013-08-07 19:39 . 2013-08-07 19:39
-------d-----wc:\progr
amdata\FileOpen
2013-08-07 19:37 . 2013-08-07 19:37
-------d-----wc:\progr
amdata\Nitro
2013-08-07 19:37 . 2013-08-07 19:37
-------d-----wc:\progr

am files (x86)\Nitro
2013-08-07 19:36 . 2013-08-26 21:54
-------d-----wc:\users
\SERVER\AppData\Roaming\Downloaded Installations
2013-08-07 19:24 . 2013-08-07 19:24
-------d-----wc:\users
\SERVER\AppData\Roaming\SolidDocuments
2013-08-07 19:23 . 2011-10-04 07:33
12800 ----a-wc:\windows\syste
m32\solidlocalui.dll
2013-08-07 19:23 . 2011-10-04 07:33
24576 ----a-wc:\windows\syste
m32\solidlocalmon.dll
2013-08-07 19:23 . 2013-08-07 19:23
-------d-----wc:\progr
am files (x86)\SolidDocuments
2013-08-07 19:22 . 2013-08-07 19:22
-------d-----wc:\progr
amdata\SolidDocuments
2013-08-07 02:07 . 2002-01-12 15:30
3567
----a-wc:\windows\SysWo
w64\drivers\PortTalk.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))
)))))))))))))))))))))))))))))))
.
2013-08-21 17:23 . 2013-07-31 06:21
71048 ----a-wc:\windows\SysWo
w64\FlashPlayerCPLApp.cpl
2013-08-21 17:23 . 2013-07-31 06:21
692104 ----a-wc:\windows\SysWo
w64\FlashPlayerApp.exe
2013-08-01 22:01 . 2013-08-01 19:30
82816 ----a-wc:\users\SERVER\
AppData\Roaming\pcouffin.sys
2013-08-01 04:19 . 2013-07-31 17:34
175736 ----a-wc:\windows\syste
m32\drivers\SYMEVENT64x86.SYS
2013-07-31 23:03 . 2013-07-31 23:03
52992 ----a-wc:\windows\syste
m32\drivers\KSafeDISK.sys
2013-07-31 23:03 . 2013-07-31 23:03
33024 ----a-wc:\windows\syste
m32\drivers\BTOWSFF.sys
2013-07-31 23:03 . 2013-07-31 23:03
59648 ----a-wc:\windows\syste
m32\drivers\BTOWSVF.sys
2013-07-31 06:22 . 2013-07-31 06:22
1199175 ----a-wc:\windows\unins
002.exe
2013-07-31 06:22 . 2013-07-31 06:22
1198049 ----a-wc:\windows\unins
001.exe
2013-07-31 06:20 . 2013-07-31 06:20
709719 ----a-wc:\windows\unins
000.exe
2013-07-31 06:12 . 2013-07-31 06:12
972712 ----a-wc:\windows\syste
m32\deployJava1.dll
2013-07-31 06:12 . 2013-07-31 06:12
312232 ----a-wc:\windows\syste
m32\javaws.exe
2013-07-31 06:12 . 2013-07-31 06:12
1093032 ----a-wc:\windows\syste
m32\npDeployJava1.dll
2013-07-31 06:12 . 2013-07-31 06:12
189352 ----a-wc:\windows\syste
m32\javaw.exe
2013-07-31 06:12 . 2013-07-31 06:12
188840 ----a-wc:\windows\syste
m32\java.exe
2013-07-31 06:12 . 2013-07-31 06:12
108968 ----a-wc:\windows\syste
m32\WindowsAccessBridge-64.dll
2013-07-31 06:11 . 2013-07-31 06:11
867240 ----a-wc:\windows\SysWo
w64\npDeployJava1.dll
2013-07-31 06:11 . 2013-07-31 06:11
789416 ----a-wc:\windows\SysWo
w64\deployJava1.dll
2013-07-31 06:11 . 2013-07-31 06:11
96168 ----a-wc:\windows\SysWo
w64\WindowsAccessBridge-32.dll
2013-06-26 23:20 . 2013-07-31 06:22
131072 ----a-wc:\windows\SysWo

w64\AiORuntimes.dll
2013-06-10 00:53 . 2013-06-10
w64\mfcm110u.dll
2013-06-10 00:53 . 2013-06-10
w64\mfcm110.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110fra.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110deu.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110esn.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110ita.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110rus.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110enu.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110jpn.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110kor.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110cht.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110chs.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110u.dll
2013-06-10 00:53 . 2013-06-10
w64\mfc110.dll
2013-06-10 00:53 . 2013-06-10
w64\atl110.dll
2013-06-09 20:59 . 2013-06-09
m32\mfcm110u.dll
2013-06-09 20:59 . 2013-06-09
m32\mfcm110.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110fra.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110deu.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110esn.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110ita.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110rus.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110enu.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110u.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110jpn.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110kor.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110cht.dll
2013-06-09 20:59 . 2013-06-09
m32\mfc110chs.dll
2013-06-09 20:59 . 2013-06-09

00:53

83024

----a-w-

c:\windows\SysWo

00:53

83016

----a-w-

c:\windows\SysWo

00:53

74832

----a-w-

c:\windows\SysWo

00:53

74832

----a-w-

c:\windows\SysWo

00:53

73808

----a-w-

c:\windows\SysWo

00:53

72784

----a-w-

c:\windows\SysWo

00:53

70736

----a-w-

c:\windows\SysWo

00:53

65104

----a-w-

c:\windows\SysWo

00:53

53840

----a-w-

c:\windows\SysWo

00:53

53328

----a-w-

c:\windows\SysWo

00:53

46160

----a-w-

c:\windows\SysWo

00:53

46160

----a-w-

c:\windows\SysWo

00:53

4456520 ----a-w-

c:\windows\SysWo

00:53

4421192 ----a-w-

c:\windows\SysWo

00:53

164424 ----a-w-

c:\windows\SysWo

20:59

90192

----a-w-

c:\windows\syste

20:59

90184

----a-w-

c:\windows\syste

20:59

74832

----a-w-

c:\windows\syste

20:59

74832

----a-w-

c:\windows\syste

20:59

73808

----a-w-

c:\windows\syste

20:59

72784

----a-w-

c:\windows\syste

20:59

70736

----a-w-

c:\windows\syste

20:59

65104

----a-w-

c:\windows\syste

20:59

5619784 ----a-w-

c:\windows\syste

20:59

5592648 ----a-w-

c:\windows\syste

20:59

53840

----a-w-

c:\windows\syste

20:59

53328

----a-w-

c:\windows\syste

20:59

46160

----a-w-

c:\windows\syste

20:59

46160

----a-w-

c:\windows\syste

20:59

192584 ----a-w-

c:\windows\syste

m32\atl110.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))
)))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{EE932B49-D5C0
-4D19-A3DA-CE0849258DE6}]
2013-08-28 00:19
277560 ----a-wc:\program files (x86)\Common Fi
les\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explor
er\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2012-10-02 01:38
1720976 ----a-wc:\progra~2\MICROS~2\Office15\GR
OOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explor
er\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2012-10-02 01:38
1720976 ----a-wc:\progra~2\MICROS~2\Office15\GR
OOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explor
er\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2012-10-02 01:38
1720976 ----a-wc:\progra~2\MICROS~2\Office15\GR
OOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateChecker"="c:\program files (x86)\Squeaky Chocolate" [X]
"ToolwizCareFree"="c:\program files (x86)\ToolwizCareFree\ToolwizCares.exe" [201
3-07-31 5191936]
"EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\x64\3\E_IATIHJB
.EXE" [2012-02-29 283232]
"USB Guardian"="c:\program files (x86)\USB Guardian\USB Guardian.exe" [2013-06-1
9 457216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusch
ed.exe" [2013-03-12 253816]
"EEventManager"="c:\program files (x86)\Epson Software\Event Manager\EEventManag
er.exe" [2010-08-30 979328]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [20
13-05-10 958576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\win
dows]

"LoadAppInit_DLLs"=1 (0x1)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c
:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft
.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:
\program files (x86)\Skype\Updater\Updater.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\driver
s\dmvsc.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\
Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engi
ne\OSE.EXE [x]
R3 PortTalk;PortTalk;c:\windows\system32\Drivers\PortTalk.sys;c:\windows\SYSNATI
VE\Drivers\PortTalk.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\dri
vers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RtkBtFilter;Realtek Bluetooth Filter Driver;c:\windows\system32\DRIVERS\RtkBt
filter.sys;c:\windows\SYSNATIVE\DRIVERS\RtkBtfilter.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\S
YSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\te
rminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATI
VE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD
.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATI
VE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\driver
s\rdvgkmd.sys [x]
S0 BTOWSVF;BTOWSVF;c:\windows\System32\Drivers\BTOWSVF.sys;c:\windows\SYSNATIVE\
Drivers\BTOWSVF.sys [x]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\
DRIVERS\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\
DRIVERS\iaStorF.sys [x]
S0 iusb3hcs;Controlador del conmutador de la controladora de host Intel(R) USB 3
.0;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hc
s.sys [x]
S0 KSafeDISK;KSafeDISK;c:\windows\System32\Drivers\KSafeDISK.sys;c:\windows\SYSN
ATIVE\Drivers\KSafeDISK.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1309010.00E\SYMD
S64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1309010.00E\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1
309010.00E\SYMEFA64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1309010.00E\SYMEFA64
.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7
}\NIS_19.1.0.28\Definitions\BASHDefs\20130715.001\BHDrvx64.sys;c:\programdata\No
rton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\2
0130715.001\BHDrvx64.sys [x]
S1 BTOWSFF;BTOWSFF;c:\windows\System32\Drivers\BTOWSFF.sys;c:\windows\SYSNATIVE\
Drivers\BTOWSFF.sys [x]
S1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drive
rs\NISx64\1309010.00E\ccSetx64.sys;c:\windows\SYSNATIVE\drivers\NISx64\1309010.0
0E\ccSetx64.sys [x]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7
}\NIS_19.1.0.28\Definitions\IPSDefs\20130903.001\IDSvia64.sys;c:\programdata\Nor
ton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\201
30903.001\IDSvia64.sys [x]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1309010.00E\I

ronx64.SYS;c:\windows\SYSNATIVE\drivers\NISx64\1309010.00E\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx
64\1309010.00E\SYMNETS.SYS;c:\windows\SYSNATIVE\Drivers\NISx64\1309010.00E\SYMNE
TS.SYS [x]
S2 EPSON_EB_RPCV4_04;EPSON V5 Service4(04);c:\program files\Common Files\EPSON\E
PW!3 SSRP\E_S50STB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.E
XE [x]
S2 EPSON_PM_RPCV4_04;EPSON V3 Service4(04);c:\program files\Common Files\EPSON\E
PW!3 SSRP\E_S50RPB.EXE;c:\program files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.E
XE [x]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\
Engine\19.9.1.14\ccSvcHst.exe;c:\program files (x86)\Norton Internet Security\En
gine\19.9.1.14\ccSvcHst.exe [x]
S2 NitroDriverReadSpool8;NitroPDFDriverCreatorReadSpool8;c:\program files\Common
Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe;c:\program files\Common Files
\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe [x]
S2 PSI_SVC_2_x64;Protexis Licensing V2 x64;c:\program files\Common Files\Protexi
s\License Service\PsiService_2.exe;c:\program files\Common Files\Protexis\Licens
e Service\PsiService_2.exe [x]
S2 SCPDFReadSpool;SolidConverterPDFReadSpool;c:\program files (x86)\SolidDocumen
ts\Solid Converter PDF\SCPDF\SolidConverterPDFServicex64.exe;c:\program files (x
86)\SolidDocuments\Solid Converter PDF\SCPDF\SolidConverterPDFServicex64.exe [x]
S2 SProtection;SProtection;c:\program files (x86)\Common Files\Umbrella\umbrella
.exe;c:\program files (x86)\Common Files\Umbrella\umbrella.exe [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\S
ymantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common Fil
es\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
S3 IntcDAud;Sonido Intel(R) para pantallas;c:\windows\system32\DRIVERS\IntcDAud.
sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 iusb3hub;Controlador del concentrador Intel(R) USB 3.0;c:\windows\system32\DR
IVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Controlador de la controladora de host Intel(R) USB 3.0 eXtensible;c
:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sy
s [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controlle
r;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64
.sys [x]
S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\D
RIVERS\rtwlane.sys;c:\windows\SYSNATIVE\DRIVERS\rtwlane.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2013-09-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-31 17
:23]
.
.
--------- X64 Entries ----------.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258D
E6}]
2013-08-28 00:19
336952 ----a-wc:\program files (x86)\Common Fi
les\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2013-03-22 172016]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2013-03-22 399856]
"Persistence"="c:\windows\system32\igfxpers.exe" [2013-03-22 442352]

.
------- Supplementary Scan ------.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://start.iminent.com/?appId=1A40E0A8-A0C5-4D8D-B0FA-513C323397
9D
mDefault_Page_URL = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
mStart Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/i
ndex.jsp?lg=es&pid=NIS&pvid=19.9.1.14
mSearch Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage/
IE: E&xportar a Microsoft Excel - c:\progra~2\MICROS~2\Office15\EXCEL.EXE/3000
IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plu
gins\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\program files (x86)\Common Files\DVDVideo
Soft\plugins\freeytmp3downloader.htm
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258
DE6} - c:\program files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtn
s.dll
TCP: Interfaces\{5D718E17-9FF4-4DF8-904B-C63219A308DA}: NameServer = 200.48.225.
130,200.48.225.146
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x8
6)\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\SERVER\AppData\Roaming\Mozilla\Firefox\Profiles\siec
c966.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.
aspx?ctid=CT1055551&CUI=UN41145102021057831&UM=1&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - StartWeb
FF - prefs.js: browser.startup.homepage - hxxp://start.iminent.com/?appId=1A40E0
A8-A0C5-4D8D-B0FA-513C3233979D
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT10
55551&SearchSource=2&CUI=UN41145102021057831&UM=1&q=
FF - ExtSQL: 2013-07-31 12:34; {BBDA0591-3099-440a-AA10-41764D9DB4DB}; c:\progra
mdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPlgn
FF - ExtSQL: 2013-07-31 13:19; {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}; c:\progra
mdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn
FF - ExtSQL: 2013-07-31 14:25; {ACAA314B-EEBA-48e4-AD47-84E31C44796C}; c:\progra
m files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF - ExtSQL: 2013-08-29 17:50; {da30eff8-ccc6-4162-a20d-67402a26a215}; c:\users\
SERVER\AppData\Roaming\Mozilla\Firefox\Profiles\siecc966.default\extensions\{da3
0eff8-ccc6-4162-a20d-67402a26a215}
FF - user.js: extensions.delta.tlbrSrchUrl FF - user.js: extensions.delta.id - 96787de600000000000024ec992a7f8b
FF - user.js: extensions.delta.appId - {C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
FF - user.js: extensions.delta.instlDay - 15918
FF - user.js: extensions.delta.vrsn - 1.8.22.0
FF - user.js: extensions.delta.vrsni - 1.8.22.0
FF - user.js: extensions.delta.vrsnTs - 1.8.22.013:58
FF - user.js: extensions.delta.prtnrId - delta
FF - user.js: extensions.delta.prdct - delta
FF - user.js: extensions.delta.aflt - babsst
FF - user.js: extensions.delta.smplGrp - none
FF - user.js: extensions.delta.tlbrId - base
FF - user.js: extensions.delta.instlRef - sst
FF - user.js: extensions.delta.dfltLng - es
FF - user.js: extensions.delta.excTlbr - false
FF - user.js: extensions.delta.ffxUnstlRst - true
FF - user.js: extensions.delta.admin - false
FF - user.js: extensions.delta_i.babTrack - affID=119293&tsp=4961
FF - user.js: extensions.delta_i.babExt FF - user.js: extensions.delta_i.srcExt - ss

FF - user.js: extensions.delta.autoRvrt - false


FF - user.js: extensions.delta.rvrt - false
FF - user.js: extensions.delta.newTab - false
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\19.9.1.14\
ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\E
ngine\19.9.1.14\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS --------------------.
[HKEY_USERS\S-1-5-21-1532567802-1278036875-2389465876-1000\Software\Microsoft\Wi
ndows\CurrentVersion\Shell Extensions\Approved\{0367A24F-8ED2-C5F9-5DA3-550E09CF
AC5C}*]
"iamfpdcllfkalpkdem"=hex:69,61,67,6e,67,68,66,65,68,61,70,67,64,6c,68,6d,65,6a,
00,00
"hacgjnpffkiidlmf"=hex:69,61,67,6e,67,68,66,65,68,61,70,67,64,6c,68,6d,65,6a,
00,00
"hapipgbckhjimgif"=hex:66,61,6b,6d,61,6d,61,64,66,69,61,6a,00,00
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66
}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800
_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66
}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66
}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66
}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C
9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C
9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C
9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800
_94_ActiveX.exe,-101"

.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"

.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B
0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B
0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B
0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actio
ns\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0
]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\Actio
nsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2013-09-03 23:06:28
ComboFix-quarantined-files.txt 2013-09-04 04:06
ComboFix2.txt 2013-08-31 02:42
ComboFix3.txt 2013-08-28 03:50
.
Pre-Run: 115,292,651,520 bytes libres
Post-Run: 115,239,292,928 bytes libres
.
- - End Of File - - 691A458865AD4F691091BB7C6980A784
A36C5E4F47E84449FF07ED3517B43A31

You might also like