ComboFix 10-09-24.05 - Thomas 25.09.2010 13:20:58.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.47.1044.18.3069.1946 [GMT 2:00] Kjører fra: c:\users\Thomas\Music\Downloads\ComboFix.exe SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Andre slettinger ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\data c:\data\Headsup.exe c:\data\set.exe c:\users\Thomas\AppData\Roaming\download2 c:\users\Thomas\AppData\Roaming\Microsoft\Windows\Recent\Support.url Infisert kopi av c:\windows\system32\drivers\smb.sys ble funnet og desinfisert Gjenopprettet kopi fra - Kitty had a snack :p . ((((((((((((((((((((((((((( Filer Opprettet Fra 2010-08-25 til 2010-09-25 ))))))))))))))))))))))))))))))))) . 2010-09-25 11:36 . 2010-09-25 11:38 -------- d-----w- c:\users\Thomas\AppData\Local\temp 2010-09-25 11:36 . 2010-09-25 11:36 -------- d-----w- c:\users\TEMP\AppData\Local\temp 2010-09-25 11:36 . 2010-09-25 11:36 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-09-25 11:36 . 2010-09-25 11:36 -------- d-----w- c:\users\Gjest\AppData\Local\temp 2010-09-25 11:36 . 2010-09-25 11:36 -------- d-----w- c:\users\aage\AppData\Local\temp 2010-09-25 11:36 . 2010-09-25 11:36 -------- d-----w- c:\users\aage.aage-PC\AppData\Local\temp 2010-09-24 19:00 . 2010-09-24 19:00 8975800 ----a-w- c:\users\Thomas\AppData\Roaming\Azureus\tmp\AZU8769088483655109042.tmp\Vuze_4.5.0.4c_win32.exe 2010-09-20 12:53 . 2010-09-20 12:53 -------- d-----w- c:\windows\Ny mappe 2010-09-19 08:21 . 2010-09-19 08:21 -------- d-----w- c:\program files\1C 2010-09-18 19:06 . 2010-09-18 19:08 -------- d-----w- c:\program files\GameSpy Arcade 2010-09-18 18:05 . 2010-09-18 18:05 -------- d-----w- c:\program files\Activision 2010-09-12 12:44 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-09-12 12:44 . 2010-09-20 13:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-09-12 12:44 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-09-11 19:14 . 2010-09-11 19:14 -------- d-----w- c:\users\Thomas\AppData\Roaming\download 2010-09-11 19:14 . 2010-09-11 19:14 48650 ----a-w- c:\users\Thomas\AppData\Roaming\download\svcnost.exe 2010-09-10 21:06 . 2010-09-10 21:06 52480 ----a-w- c:\users\Thomas\AppData\Roaming\AnVi\Uninstall.exe 2010-09-10 21:06 . 2010-09-10 21:06 53760 ----a-w- c:\users\Thomas\AppData\Roaming\AnVi\avtext.dll 2010-09-10 21:06 . 2010-09-12 13:54 -------- d-----w- c:\users\Thomas\AppData\Roaming\AnVi 2010-09-10 20:43 . 2010-09-10 20:43 -------- d-----w- c:\users\Thomas\AppData\Roaming\YoudaGames 2010-09-10 20:43 . 2010-09-10 20:44 -------- d-----w- c:\windows\Help32 2010-09-10 20:42 . 2010-09-10 20:43 -------- d-----w- c:\windows\system32\weber 2010-09-10 20:42 . 2010-09-10 20:42 -------- d-----w- c:\program files\Youda Games 2010-09-03 19:42 . 2010-09-03 19:42 -------- d-----w- c:\programdata\Stentec 2010-09-03 19:42 . 2010-09-03 19:42 -------- d-----w- c:\program files\Stentec 2010-09-03 17:44 . 2010-09-03 17:50 -------- d-----w- c:\program files\German Truck Simulator 2010-09-03 16:21 . 2010-09-03 16:21 413696 ----a-w- c:\windows\system32\wrap_oal.dll 2010-09-03 16:21 . 2010-09-03 16:21 110592 ----a-w- c:\windows\system32\OpenAL32.dll 2010-09-03 16:21 . 2010-09-03 16:21 -------- d-----w- c:\program files\OpenAL 2010-09-03 15:51 . 2010-09-03 16:20 -------- d-s---w- c:\program files\RigNRoll 2010-09-03 15:43 . 2010-09-03 15:44 -------- d-----w- c:\program files\DAEMON Tools Lite 2010-08-31 12:39 . 2010-09-02 12:49 -------- d-----w- c:\users\TEMP.aage-PC.005 2010-08-28 21:34 . 2010-08-28 21:34 -------- d-----w- c:\program files\NVIDIA Corporation 2010-08-28 21:32 . 2010-08-28 21:32 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2010-08-28 21:05 . 2010-08-28 21:05 -------- d-----w- c:\program files\2K Games . (((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-09-25 11:26 . 2008-06-07 01:57 673610 ----a-w- c:\windows\system32\perfh01D.dat 2010-09-25 11:26 . 2008-06-07 01:57 198154 ----a-w- c:\windows\system32\perfc01D.dat 2010-09-25 11:26 . 2008-06-07 01:49 689710 ----a-w- c:\windows\system32\perfh014.dat 2010-09-25 11:26 . 2008-06-07 01:49 159098 ----a-w- c:\windows\system32\perfc014.dat 2010-09-25 11:26 . 2008-06-07 01:41 511432 ----a-w- c:\windows\system32\perfh00B.dat 2010-09-25 11:26 . 2008-06-07 01:41 161470 ----a-w- c:\windows\system32\perfc00B.dat 2010-09-25 11:26 . 2008-06-07 01:33 539156 ----a-w- c:\windows\system32\perfh006.dat 2010-09-25 11:26 . 2008-06-07 01:33 157958 ----a-w- c:\windows\system32\perfc006.dat 2010-09-25 11:00 . 2009-08-23 16:17 -------- d-----w- c:\users\Thomas\AppData\Roaming\DNA 2010-09-24 20:39 . 2009-11-20 12:39 -------- d-----w- c:\users\Thomas\AppData\Roaming\MP3Rocket 2010-09-24 19:26 . 2009-09-25 20:58 -------- d-----w- c:\users\Thomas\AppData\Roaming\Azureus 2010-09-23 12:41 . 2010-08-05 20:14 -------- d-----w- c:\users\Thomas\AppData\Roaming\Spotify 2010-09-19 18:26 . 2009-06-18 19:04 7620 ----a-w- c:\users\Thomas\AppData\Local\d3d9caps.dat 2010-09-14 16:57 . 2009-10-31 12:55 -------- d-----w- c:\users\aage\AppData\Roaming\mp3rocket 2010-09-14 16:57 . 2010-06-29 00:43 -------- d-----w- c:\program files\Steam 2010-09-14 16:08 . 2010-06-29 00:43 -------- d-----w- c:\program files\Common Files\Steam 2010-09-03 15:44 . 2009-03-22 18:08 -------- d-----w- c:\program files\DAEMON Tools Toolbar 2010-09-03 15:44 . 2009-03-22 17:55 691696 ----a-w- c:\windows\system32\drivers\sptd.sys 2010-09-03 15:43 . 2009-03-22 18:08 -------- d-----w- c:\programdata\DAEMON Tools Lite 2010-08-28 21:34 . 2009-10-04 13:48 -------- d-----w- c:\program files\AGEIA Technologies 2010-08-25 17:54 . 2010-08-25 17:34 99 ----a-w- c:\users\Thomas\jagex_runescape_preferences2.dat 2010-08-25 17:47 . 2010-08-25 17:31 46 ----a-w- c:\users\Thomas\jagex_runescape_preferences.dat 2010-08-25 17:34 . 2010-08-25 17:34 0 ----a-w- c:\users\Thomas\jagex__preferences3.dat 2010-08-17 18:02 . 2010-07-20 16:28 2855 ----a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\World of Tanks closed Beta\World of Tanks closed Beta on the Web.pif 2010-08-17 01:03 . 2009-03-12 15:04 -------- d-----w- c:\program files\Microsoft Works 2010-08-16 17:54 . 2008-06-07 03:25 -------- d-----w- c:\program files\Common Files\Symantec Shared 2010-08-16 01:15 . 2008-06-07 03:25 -------- d-----w- c:\programdata\Symantec 2010-08-16 01:00 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2010-08-16 00:42 . 2010-08-16 00:42 -------- d-----w- c:\program files\Vuze_Remote 2010-08-16 00:42 . 2010-08-16 00:42 -------- d-----w- c:\program files\Conduit 2010-08-15 23:54 . 2010-06-30 18:44 -------- d-----w- c:\programdata\McAfee Security Scan 2010-08-15 23:43 . 2010-08-15 23:43 -------- d-----w- c:\users\Gjest\AppData\Roaming\ATI 2010-08-15 23:43 . 2010-08-15 23:43 66760 ----a-w- c:\users\Gjest\AppData\Local\GDIPFONTCACHEV1.DAT 2010-08-15 23:43 . 2010-08-15 23:43 -------- d-----w- c:\users\Gjest\AppData\Roaming\DigitalPersona 2010-08-06 15:53 . 2009-09-26 15:51 -------- d-----w- c:\program files\Ubisoft 2010-08-05 20:14 . 2010-08-05 20:14 655360 ----a-w- c:\users\Thomas\AppData\Roaming\Spotify\Gracenote\gnsdk_sdkmanager.dll 2010-08-05 20:14 . 2010-08-05 20:14 282624 ----a-w- c:\users\Thomas\AppData\Roaming\Spotify\Gracenote\gnsdk_musicid_file.dll 2010-08-05 20:14 . 2010-08-05 20:14 208896 ----a-w- c:\users\Thomas\AppData\Roaming\Spotify\Gracenote\gnsdk_dsp.dll 2010-07-27 15:40 . 2010-07-21 23:12 -------- d-----w- c:\program files\Opera 2010-07-23 22:25 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat 2010-07-02 19:30 . 2010-07-02 19:30 6142 ----a-w- c:\windows\system32\ealregsnapshot1.reg 2010-06-29 22:13 . 2010-08-05 19:20 52224 ----a-w- c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\1x0rxcef.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll 2010-06-29 22:13 . 2010-08-05 19:20 101376 ----a-w- c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\1x0rxcef.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll . (((((((((((((((((((((((((((((((( Oppstartspunkter I Registeret ))))))))))))))))))))))))))))))))))))))))))))) . . *Merk* tomme oppføringer & gyldige standardoppføringer vises ikke REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}] 2010-06-13 17:10 2734688 ----a-w- c:\program files\Vuze_Remote\tbVuze.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\tbVuze.dll" [2010-06-13 2734688] [HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{BA14329E-9550-4989-B3F2-9732E92D17CC}"= "c:\program files\Vuze_Remote\tbVuze.dll" [2010-06-13 2734688] [HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664] "BitTorrent DNA"="c:\users\Thomas\Program Files\DNA\btdna.exe" [2009-11-20 323392] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-02 39408] "RegistryBooster"="c:\program files\Uniblue\RegistryBooster\launcher.exe" [2010-07-20 67448] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-17 1033512] "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504] "DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-03-13 699456] "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-05-15 468264] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184] "QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032] "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-02 554288] "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840] "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-03-09 37888] "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-16 442433] "jsafesurf"="c:\windows\Help32\safesurf.exe" [2010-09-02 211968] "Malwarebytes Anti-Malware (rootkit-scan)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952] "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536] MP3 Rocket (Minimized).lnk - c:\program files\MP3 Rocket\MP3Rocket.exe [2010-6-30 174080] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli DPPWDFLT [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232] R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-09-03 691696] S0 Amddfltr;Amd Disk Lower Filter Driver;c:\windows\system32\DRIVERS\Amddfltr.sys [2008-01-07 15416] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\aestsrv.exe [2008-02-12 73728] S2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe [2008-01-21 21504] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [2008-03-18 19456] S2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [2008-03-26 341328] S2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-03-27 595248] S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [2008-01-23 52736] S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [2008-04-01 81296] S3 vfs101x;vfs101x;c:\windows\system32\drivers\vfs101x.sys [2008-03-27 40752] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ezSharedSvc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2008-02-26 21:06 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Innholdet i mappen 'Scheduled Tasks' (planlagte oppgaver) 2010-09-25 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-02 18:08] 2010-09-25 c:\windows\Tasks\RegistryBooster.job - c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2010-07-22 14:04] . . ------- Tilleggsskanning ------- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=nb_no&c=83&bd=Pavilion&pf=cnnb mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=nb_no&c=83&bd=Pavilion&pf=cnnb IE: &Søkefunksjon i AOL-verktrylinjen - c:\programdata\AOL\ieToolbar\resources\nb-NO\local\search.html FF - ProfilePath - c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\1x0rxcef.default\ FF - component: c:\program files\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll FF - component: c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\1x0rxcef.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll FF - component: c:\users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\1x0rxcef.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: c:\users\Thomas\AppData\LocalLow\POWERC~1\nppowerloader.dll FF - plugin: c:\users\Thomas\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll FF - plugin: c:\users\Thomas\Program Files\DNA\plugins\npbtdna.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true); c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".no"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); . - - - - TOMME PEKERE FJERNET - - - - WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file) AddRemove-8461-7759-5462-8226 - c:\program files\Vuze\uninstall.exe AddRemove-8461-7759-5462-8226-1 - c:\users\Sebjørn Røssland\Desktop\uninstall.exe AddRemove-Cheat Engine 5.5_is1 - c:\program files\Cheat Engine\unins000.exe AddRemove-Project Torque - c:\program files\AeriaGames\Project Torque\uninstall.exe AddRemove-Superia_is1 - c:\games\Worms Armageddon - New Edition\User\Games\Superia\unins000.exe AddRemove-{909F8EBC-EC7F-48FF-0085-475D818F0F31} - c:\program files\EA GAMES\Need for Speed Underground 2\EAUninstall.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-09-25 13:38 Windows 6.0.6002 Service Pack 2 NTFS skanner skjulte prosesser ... skanner skjulte autostart-oppføringer ... skanner skjulte filer ... skanning vellykket skjulte filer: 0 ************************************************************************** . --------------------- DLL'er Lastet Av Kjørende Prosesser --------------------- - - - - - - - > 'lsass.exe'(760) c:\windows\system32\DPPWDFLT.dll . Tidspunkt ferdig: 2010-09-25 13:41:17 ComboFix-quarantined-files.txt 2010-09-25 11:41 Pre-Run: 5 606 760 448 byte ledig Post-Run: 20 123 209 728 byte ledig - - End Of File - - D5C725826CB05E740270486399D150BB