ComboFix 10-06-29.02 - Brian 30-06-2010 0:58.12.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.31.1043.18.1790.927 [GMT 2:00] Gestart vanuit: c:\users\Brian\Desktop\ComboFix.exe gebruikte Opdracht switches :: c:\users\Brian\Desktop\CFScript.txt..txt SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} FILE :: "c:\programdata\Google\Google Toolbar\Update\gtb7C1.tmp.exe" . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\FindyKill c:\programdata\Google\Google Toolbar\Update\gtb7C1.tmp.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_ASWFSBLK -------\Legacy_ASWSP -------\Service_aswFsBlk -------\Service_aswSP (((((((((((((((((((( Bestanden Gemaakt van 2010-05-28 to 2010-06-29 )))))))))))))))))))))))))))))) . 2010-06-29 23:05 . 2010-06-29 23:08 -------- d-----w- c:\users\Brian\AppData\Local\temp 2010-06-29 23:05 . 2010-06-29 23:05 -------- d-----w- c:\users\Public\AppData\Local\temp 2010-06-29 23:05 . 2010-06-29 23:05 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-06-29 17:06 . 2006-09-18 12:12 843776 ----a-w- c:\windows\vsnpstd3.exe 2010-06-29 17:06 . 2007-03-30 15:43 61440 ----a-w- c:\windows\system32\vsnpstd3.dll 2010-06-29 17:06 . 2006-09-18 12:12 843776 ----a-w- c:\windows\system32\vsnpstd3.exe 2010-06-29 17:06 . 2010-06-29 17:06 -------- d-----w- c:\program files\VGA USB Camera 2010-06-29 17:06 . 2007-03-30 09:12 10199296 ----a-w- c:\windows\system32\drivers\snpstd3.sys 2010-06-29 17:06 . 2006-12-27 12:33 172032 ----a-w- c:\windows\rsnpstd3.dll 2010-06-29 17:06 . 2005-11-23 11:55 53248 ----a-w- c:\windows\system32\csnpstd3.dll 2010-06-29 17:06 . 2004-11-29 17:43 458752 ----a-w- c:\windows\amcap.exe 2010-06-29 12:25 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr 2010-06-28 19:22 . 2010-06-28 19:22 388096 ----a-r- c:\users\Brian\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2010-06-27 12:26 . 2010-06-27 12:26 -------- d-----w- c:\users\Brian\AppData\Local\Adobe 2010-06-23 15:48 . 2009-11-08 08:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll 2010-06-23 15:48 . 2009-11-08 08:55 49472 ----a-w- c:\windows\system32\netfxperf.dll 2010-06-23 15:48 . 2009-11-08 08:55 297808 ----a-w- c:\windows\system32\mscoree.dll 2010-06-23 15:48 . 2009-11-08 08:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe 2010-06-23 15:48 . 2009-11-08 08:55 1130824 ----a-w- c:\windows\system32\dfshim.dll 2010-06-23 15:47 . 2010-04-16 16:43 28672 ----a-w- c:\windows\system32\Apphlpdm.dll 2010-06-23 15:47 . 2010-04-16 14:39 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2010-06-22 00:09 . 2010-06-23 14:59 -------- d-----w- c:\program files\URUSoft 2010-06-21 20:59 . 2006-12-27 12:33 172032 ----a-w- c:\windows\system32\rsnpstd3.dll 2010-06-21 20:32 . 2007-02-03 18:29 129824 ----a-w- c:\windows\system32\lvci1051.dll 2010-06-21 20:32 . 2003-02-21 12:42 348160 ----a-w- c:\windows\system\msvcr71.dll 2010-06-21 17:03 . 2007-03-18 19:37 65602 ----a-w- c:\windows\system32\cook3260.dll 2010-06-21 17:03 . 2006-09-29 11:26 176165 ----a-w- c:\windows\system32\drv23260.dll 2010-06-21 17:03 . 2006-09-29 11:25 208935 ----a-w- c:\windows\system32\drv33260.dll 2010-06-21 17:03 . 2006-09-29 11:24 217127 ----a-w- c:\windows\system32\drv43260.dll 2010-06-21 17:03 . 2002-12-10 01:20 102439 ----a-w- c:\windows\system32\sipr3260.dll 2010-06-21 17:03 . 2006-05-11 18:21 626688 ----a-w- c:\windows\system32\vp7vfw.dll 2010-06-21 17:03 . 2006-05-20 15:16 1184984 ----a-w- c:\windows\system32\wvc1dmod.dll 2010-06-21 17:03 . 2010-06-21 17:03 -------- d-----w- c:\program files\VSO 2010-06-19 20:27 . 2010-06-19 20:27 -------- d-----w- c:\users\Brian\AppData\Local\Hyves 2010-06-14 23:43 . 2010-06-14 23:43 -------- d-----w- c:\program files\Runtime Software 2010-06-10 10:30 . 2010-05-01 14:13 2037248 ----a-w- c:\windows\system32\win32k.sys 2010-06-07 20:00 . 2010-06-07 20:01 -------- d-----w- c:\programdata\PCPitstop 2010-06-04 00:01 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll 2010-06-03 21:19 . 2010-06-03 21:19 691696 ----a-w- c:\windows\system32\drivers\sptd.sys 2010-06-03 21:18 . 2010-06-03 21:18 -------- d-----w- c:\programdata\DAEMON Tools Lite . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-06-29 23:07 . 2010-04-05 18:07 143509 ----a-w- c:\programdata\nvModes.dat 2010-06-29 23:06 . 2010-04-05 11:14 12 ----a-w- c:\windows\bthservsdp.dat 2010-06-29 22:51 . 2010-04-02 20:38 -------- d-----w- c:\users\Brian\AppData\Roaming\uTorrent 2010-06-29 22:49 . 2010-05-22 18:08 -------- d-----w- c:\users\Brian\AppData\Roaming\vlc 2010-06-29 17:14 . 2008-01-21 06:47 667114 ----a-w- c:\windows\system32\perfh013.dat 2010-06-29 17:14 . 2008-01-21 06:47 126648 ----a-w- c:\windows\system32\perfc013.dat 2010-06-29 17:06 . 2008-05-08 18:14 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-06-28 20:57 . 2010-05-02 19:26 165032 ----a-w- c:\windows\system32\aswBoot.exe 2010-06-28 20:37 . 2010-05-02 19:26 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2010-06-28 20:37 . 2010-05-02 19:26 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys 2010-06-28 20:33 . 2010-05-02 19:26 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2010-06-28 20:32 . 2010-05-02 19:26 50256 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2010-06-28 20:32 . 2010-05-02 19:26 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2010-06-28 18:52 . 2010-04-09 16:51 -------- d-----w- c:\users\Brian\AppData\Roaming\Vso 2010-06-28 18:04 . 2010-04-17 16:50 -------- d-----w- c:\programdata\DVD Shrink 2010-06-28 16:35 . 2010-04-15 19:44 -------- d-----w- c:\users\Brian\AppData\Roaming\dvdcss 2010-06-23 14:58 . 2010-04-03 14:17 -------- d-----w- c:\program files\Common Files\Logishrd 2010-06-21 20:53 . 2010-04-03 14:17 -------- d-----w- c:\programdata\Logitech 2010-06-21 20:53 . 2010-04-03 14:17 -------- d-----w- c:\programdata\LogiShrd 2010-06-21 17:03 . 2010-04-09 16:51 47360 ----a-w- c:\users\Brian\AppData\Roaming\pcouffin.sys 2010-06-21 17:03 . 2010-04-09 16:51 47360 ----a-w- c:\users\Brian\AppData\Roaming\pcouffin.sys 2010-06-16 13:32 . 2010-05-04 11:18 -------- d-----w- c:\users\Brian\AppData\Roaming\FrostWire 2010-06-10 11:12 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2010-06-10 10:41 . 2008-05-08 19:03 -------- d-----w- c:\programdata\Microsoft Help 2010-06-07 14:53 . 2010-04-08 12:32 -------- d-----w- c:\programdata\CanonIJPLM 2010-06-04 20:52 . 2010-04-02 22:38 -------- d-----w- c:\program files\Microsoft Silverlight 2010-06-03 23:34 . 2010-04-19 19:11 -------- d-----w- c:\users\Brian\AppData\Roaming\ImgBurn 2010-05-26 17:06 . 2010-06-10 10:31 34304 ----a-w- c:\windows\system32\atmlib.dll 2010-05-26 14:47 . 2010-06-10 10:31 289792 ----a-w- c:\windows\system32\atmfd.dll 2010-05-26 10:58 . 2010-04-04 18:17 -------- d-----w- c:\program files\Microsoft 2010-05-22 18:08 . 2010-05-22 18:08 -------- d-----w- c:\program files\VideoLAN 2010-05-15 15:29 . 2010-05-15 15:29 -------- d-----w- c:\users\Brian\AppData\Roaming\Convivea 2010-05-11 23:31 . 2010-05-11 23:31 -------- d-----w- c:\programdata\Malwarebytes 2010-05-04 05:59 . 2010-06-10 10:31 916480 ----a-w- c:\windows\system32\wininet.dll 2010-05-04 05:55 . 2010-06-10 10:31 109056 ----a-w- c:\windows\system32\iesysprep.dll 2010-05-04 05:55 . 2010-06-10 10:31 71680 ----a-w- c:\windows\system32\iesetup.dll 2010-05-04 04:31 . 2010-06-10 10:31 133632 ----a-w- c:\windows\system32\ieUnatt.exe 2010-05-02 21:43 . 2010-04-02 21:10 -------- d-----w- c:\program files\Alwil Software 2010-05-02 19:26 . 2010-05-02 19:26 -------- d-----w- c:\programdata\Alwil Software 2010-05-02 17:45 . 2008-05-08 18:45 -------- d-----w- c:\programdata\CyberLink 2010-05-02 17:45 . 2010-05-02 17:45 -------- d-----w- c:\users\Brian\AppData\Roaming\CyberLink 2010-04-28 18:11 . 2010-04-05 17:43 680 ----a-w- c:\users\Brian\AppData\Local\d3d9caps.dat 2010-04-23 14:13 . 2010-05-26 10:57 2048 ----a-w- c:\windows\system32\tzres.dll 2010-04-20 17:50 . 2010-04-20 17:50 411368 ----a-w- c:\windows\system32\deployJava1.dll 2010-04-19 20:46 . 2010-04-19 20:46 970504 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2010-04-16 16:43 . 2010-06-23 15:47 173056 ----a-w- c:\windows\AppPatch\AcXtrnal.dll 2010-04-16 16:43 . 2010-06-23 15:47 458752 ----a-w- c:\windows\AppPatch\AcSpecfc.dll 2010-04-16 16:43 . 2010-06-23 15:47 542720 ----a-w- c:\windows\AppPatch\AcLayers.dll 2010-04-16 16:43 . 2010-06-23 15:47 2159616 ----a-w- c:\windows\AppPatch\AcGenral.dll 2010-04-12 18:33 . 2010-04-02 20:21 102424 ----a-w- c:\users\Brian\AppData\Local\GDIPFONTCACHEV1.DAT 2010-04-12 17:51 . 2010-04-12 17:51 56 ---ha-w- c:\programdata\ezsidmv.dat 2010-04-09 16:51 . 2010-04-09 16:51 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys 2010-04-05 17:01 . 2010-06-10 10:31 67072 ----a-w- c:\windows\system32\asycfilt.dll 2010-04-05 15:42 . 2010-04-05 15:42 46080 ----a-w- c:\windows\system32\TSWbPrxy.exe 2010-04-05 15:42 . 2010-04-05 15:42 44544 ----a-w- c:\windows\system32\MsRdpWebAccess.dll 2010-04-05 15:42 . 2010-04-05 15:42 36864 ----a-w- c:\windows\system32\tsgqec.dll 2010-04-05 15:42 . 2010-04-05 15:42 223232 ----a-w- c:\windows\system32\wksprt.exe 2010-04-05 15:42 . 2010-04-05 15:42 130560 ----a-w- c:\windows\system32\aaclient.dll 2010-04-05 15:42 . 2010-04-05 15:42 12800 ----a-w- c:\windows\system32\wksprtPS.dll 2010-04-05 15:42 . 2010-04-05 15:42 1033728 ----a-w- c:\windows\system32\mstsc.exe 2010-04-05 15:42 . 2010-04-05 15:42 2689024 ----a-w- c:\windows\system32\mstscax.dll 2010-04-03 16:27 . 2010-04-03 16:27 985704 ----a-w- c:\windows\system32\nvsvc.dll 2010-04-03 16:27 . 2010-04-03 16:27 13683816 ----a-w- c:\windows\system32\nvcpl.dll 2010-04-03 16:27 . 2010-04-03 16:27 129640 ----a-w- c:\windows\system32\nvvsvc.exe 2010-04-03 16:27 . 2010-04-03 16:27 110696 ----a-w- c:\windows\system32\nvmctray.dll 2010-04-03 14:33 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat 2010-04-03 14:19 . 2010-04-03 14:19 53248 ----a-r- c:\users\Brian\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-03-04 21:38 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] "Google Update"="c:\users\Brian\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-04-03 136176] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184] "RtHDVCpl"="RtHDVCpl.exe" [2008-03-26 5369856] "Acer Empowering Technology Monitor"="c:\program files\Acer\Empowering Technology\SysMonitor.exe" [2008-04-25 319488] "EmpoweringTechnology"="c:\program files\Acer\Empowering Technology\Framework.Launcher.exe" [2008-04-25 319488] "eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896] "BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-06 34040] "WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104] "Skytel"="Skytel.exe" [2007-11-20 1826816] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304] "Zesko_McciTrayApp"="c:\program files\Thuishelp\Zesko\Thuishelp.exe" [2008-04-14 1455104] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768] "CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152] "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472] "OpwareSE4"="d:\program files\canon\OpwareSE4.exe" [2007-02-04 79400] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] "snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-18 843776] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Logitech SetPoint.lnk - d:\program files\SetPoint\SetPoint.exe [2010-4-3 805392] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler] "{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "d:\program files\Fences\Stardock\Fences\FencesMenu.dll" [2009-10-02 128360] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] 2010-04-03 17:24 136176 ----atw- c:\users\Brian\AppData\Local\Google\Update\GoogleUpdate.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMMediaSharing] 2008-01-25 16:49 204908 ----a-w- c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(b):d5,8f,cd,4e,2c,d3,ca,01 R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-04 131072] R3 netr73;Linksys Compact Wireless-G USB Adapter Driver for Vista;c:\windows\system32\DRIVERS\WUSB54GCx86.sys [x] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [x] R3 WSVD;WSVD;c:\windows\system32\drivers\WSVD.sys [2007-12-16 75776] R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-06-03 691696] S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-01-25 269448] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-06-28 50256] S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384] S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-04-25 24576] S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-06 50424] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache bthsvcs REG_MULTI_SZ BthServ . Inhoud van de 'Gedeelde Taken' map 2010-06-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1896332980-1311347652-1581007178-1000Core.job - c:\users\Brian\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-03 17:24] 2010-06-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1896332980-1311347652-1581007178-1000UA.job - c:\users\Brian\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-03 17:24] . . ------- Bijkomende Scan ------- . uStart Page = hxxp://www.google.nl/ mStart Page = hxxp://nl.intl.acer.yahoo.com Trusted Zone: ziggo.nl\thuishelp . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-06-30 01:07 Windows 6.0.6002 Service Pack 2 NTFS scannen van verborgen processen ... scannen van verborgen autostart items ... scannen van verborgen bestanden ... Scan succesvol afgerond verborgen bestanden: 0 ************************************************************************** . --------------------- DLLs Geladen Onder Lopende Processen --------------------- - - - - - - - > 'Explorer.exe'(3652) c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll d:\program files\Fences\Stardock\Fences\FencesMenu.dll d:\program files\fences\stardock\fences\DesktopDock.dll . ------------------------ Andere Aktieve Processen ------------------------ . c:\windows\system32\nvvsvc.exe c:\windows\system32\nvvsvc.exe c:\program files\Alwil Software\Avast5\AvastSvc.exe c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe c:\program files\Canon\IJPLM\IJPLMSVC.EXE c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Common Files\Motive\McciCMService.exe c:\program files\CyberLink\Shared Files\RichVideo.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\WUDFHost.exe c:\windows\system32\wbem\unsecapp.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Voltooingstijd: 2010-06-30 01:13:03 - machine werd herstart ComboFix-quarantined-files.txt 2010-06-29 23:12 ComboFix2.txt 2010-06-29 16:19 ComboFix3.txt 2010-06-23 15:25 Pre-Run: 115.690.250.240 bytes beschikbaar Post-Run: 115.118.419.968 bytes beschikbaar - - End Of File - - 064834E2A2884788D981A7A3F620178C