Solved

My computer closes down when I use virus scanners such as AVG or itunes

Posted on 2009-06-28
208
2,160 Views
Last Modified: 2013-11-22
When I use virus scanners they automatically close my computer and if i download podcasts on my ishuffle when the computer has been used for an hour or so then the computer closes.


AVG has not in the last months sucessfully completed a scan it continously gives the following message:

"The Scan log is corrupted (scan has not finished properly)

When I run Spybot it tells me I have Malware.SBI and MalwareC.sbi and I have downloads a Active Scan from Bleeping computer ( http://www.pandasecurity.com/homeusers/solutions/activescan/) and the computer closes in 5 seconds once I start to run it.Can you help?
0
Comment
Question by:SeanPOBrien
208 Comments
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 24733046
Download and run ComboFix by sUBs:( Just rename it first before saving the file to your desktop so any rootkits won't block it)
Also attach the logfile please.

Combofix by sUBs:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..


Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
 

If needed, here's the Combofix tutorial which includes the installation of the Recovery Console:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
 
0
 
LVL 13

Expert Comment

by:JeremySBrown
ID: 24733420
Try running Malwarebytes' Anti-Malware and Dr. Web Anti-Virus.
http://www.malwarebytes.org/mbam.php
http://www.freedrweb.com/
0
 

Author Comment

by:SeanPOBrien
ID: 24777217
Hello Master,

In response to your suggestion 3 see below , I only copid part of it as it did not make sense to me.

Kind Regards

Sean





PKÆtÜ6Àl$#Û8!HijackThis.exeìûgTS_ô6`&¤N¨!ÔP¤7é½$Hé½ ¤7© (((UA` å!¥ JTTÎæÿÞóÞ{Ïùp?ÝwR»ÇÈX;Ùk¯¹Ö,Ï|æÚ;Ö.yZB~NN .Èÿ:ô ÿx~ð~ !´"éZMÆØQ¤pb@¸W(ÊÇ+,RòöC&G ¡ÂPFx;T(Ñ×ÃÂÂ(þÿcÚyТXã!ßÿùá¨æ+Û9¾°½#\õ?ßm’|O¯ÿ_ç`c XAi!ê&ÿço+V(¬@<ÁUµ@Á0²B¤¸ IVDlOWÇ64ÿkÝ`ó?íÿº"û®m¹ÿóûÿ|aûmÿwó?×{nHËé 8.×Cèÿó3Qç üíp°qVøxpmÿ{Bÿ{ÿëHWö;û?_Nuqº~ºÿ[?=°&SîsúåT_§:j[÷ÿ÷}zÿËäÿÿãÿ7ERÒ©xÆ°Sa¬Ý¾#öóÚ²fð DÚùÔ®\IÈêIÖÝ< ¹dkÙ~yÔsƦGÙAIvþ'×Ë&Íímà`ß«ÎÂy¿*¢Y¥8õ,tÞ.϶Ïá[IN £¸d'_`Xwåè*\xÈ5GP#|ܵнÔý&dz|1Ó9~7á°ða Óº>¿xù¬ ­"aî A8:~J·¼N1S>:ÇîÆè¼øÆkzl¬ùS ÿÄTø^,ü é ñl¤^Ö°è_Ê"Ù¥4Ä(vÒTÏûÚ}â¥uXXø^aamR8Ùidå¶XåKØñßÈ |ë"¨â!ê}¸ ÿ’W±fqAßÄOÔÆLýfIvI ¯X?ÐNiKZTÍ}Ã}¸"Ròè]S ²é±ö6¤-ÓHk£Òºz¦¯ {×·æq7 &oÜìÊn`ܾò¸RSZ,<]ò.|m4¿¤¿t¤¶ÜTc9¤V!U5_Ü/ ­Ú:¨:É)¿2á4ðpðXÜST÷¢ù&ðxÚ+ð 9®ë90!lJ¯à¨ö¯/¾îÓGm"êS:Üþ==1?+(³t 8»$¼ñá|«X@Ù×a°Á²!L.Ëz÷"Er±âòg§ýa*è߬û~ebö9*¾bÉ <í üʾyüê0¨îíüÉ6 ºsÆÕÆy·t=æý²PA"úm¨-ºå/¿áÀùߺ·ugù+Vj}uW ¦é4À|6nÐuF°ë¨üÑbö"+xßÿÛ;ÈöOI{¢ösÿɏÿ`ÉG=ãvEó"¬!çaokÓ#CC"ÅDÝÒÝvâ98/ÿúäN`Ò¡¼hµ9LÊÂÊ )æfÜ`õm3Üóq_MÌ6+ëR$Û¶6 ÁîCêy¹=M¨áfçaàß¡ÞZÓ**%~¨Vú$J2¡9R]Ò&ëÓ3²£ªr¹ ·Ü°àÇÌ’F3ÅV (S­ì³>»¤x¦vÍ(¹+Ϋ»A:ô*ìBÒ*kï7b.=¤S]êʵñX5ݬ²ú¬µ’AuLu:®âö®¾Î34®*ñ¬X³ N \Í´c]{vÔÄaÁFô[y’¢«&C!Õ29ZüÒywG§(ð|"â¢}×x=ÿ± }¬Öù9+ñó¥H@2æý¥)BS|«\-´ÃÒ C¯¼2.4:ç?W1:°*¦Ea»QÂ&YÖp(rá{q’®£Ð ­Á :͸ö¬º®Î|Sb3\¢É¬ÏZ÷«g=6`éðÄá{`~بANÞꮨVÆé¸<óÐêýú^õñ¯ú>"~ý>HøڏÝ/[¶ovöFP1êÜE¬ìüÒFͼvÞó ’î>àZ'ø_×[²%oÞx}ì;Í!±.ÚYÿÛÕÚ{¾`ÆZ'p²>¶¤Ódiþ×9ßÜßUÕtR98cv î²|{ǬRúxo²lnx Ò¹õ²Âfbç S  #¶ýõqྯ|ôGk`mzýÀu`[¶Õ|Fgb£ç«7»:7¤`7)9ïônQ4üÄÃâ{¿÷УÒnÜ^²_Ö*Û~^~µâèÿAò#0A©\X-´[s>¯ý¥\¶Î¾aÃö¤3ÁúÿjͲ9W`·bÞ²dÚ¶ýcqÇüÌ®ÃhëZC|îÛõÓ_­÷³­²,¿’÷Õ^³øqÕü0¼íÀì(ÃôgºÉié4ãß©FÇ)`!_  þ&éÿÛhÍßuþS0À¸@é"¥¢Ðz{aÅyÎ/íÖ{ºWô}@6(Çoó &qñml¹9é.;w«Å 0¬ ·qøëĺáÿÔQº!½Gßàx_ÙâH?N!+¥ÆJsaRX¸k¹Nq­yü³Á¡ ßöxÏðqSG×¾UñË ¨}i; Ò¹$ø«Z’4Iáûý/MU3¾È÷¡ñkÚáçlÛWBváf¨(6á%KüAÌC¤ Ë(z¼Õ *M,BüOÄÉÜR4^¸9î¤tà,¥¦/JcXd¬Ú_Úº²ïýäA.ÜÿN'ÏXJ=(¾RÆ<9ªØÐÆ)ëx±ø³RÜ¢é»Jµ r-;&è9'j¥_I'hU9Tå¡ÎE5U ¬WXS³¢ÜjìÕv@R`1&á¼®3¼ub}½4}§µ"ÂcÁ¬Áº.©óãÀ¤÷~:­ó_߶röLe)C_Ùê#c@Úä¤Õ´5fJð¢Ùîª9eþD¡?9ÕÚSë0Ü`6z_ß9DOl¥`{lC¬ê"aLBÚ÷`îÀóßµbLtm *Û0 B¥ÜeÖÌ mjHo8ÒÁ ¯gÏ×4*ìQ1ñÐ!Í8Ü:û·>;ºpèsQRÎÕÆ-öÜKkM¾Ñ~þeµóÌ3UÁAaÁþAªt!¯*¡­ó:`a^£ÊIþü_ù« d *"§7r^»lb1ê>&ÃxºõÍåØ°8õ+ ñª ©øD@7"5¥lâ0h¹9Uu:í(] Ð{ }õÐS¥}n¡v~í:7,ÇÄ:7ߪñHÍÇð~lÜ~'tÜÆ`ºiR$X\0¶ÎÇ"ÞzSQXv£ô,÷ÛRû="ÙUeøÖyÇ;w!«ËkZç ª{Ú÷"kÏÕý1ÖÁ·<xÕK1aÜɤÉ#&yÁÙ<’<};J<²ÈPx2P婝.53ÀÄíy"Ø`éT¦Ã<RâûxxôÞW9µ:x¸Pb¬Àv¸ÐFä-44ÚH¬<+9z}ÚRàC ½=eøçg­×â'*Ú¶ÚL¤98úþxxÜÒÀ4®7ýðæaýë|z’G£úCö¦¯ÔiÎ`³|KûS¾"ÿóÊãÇñ©­çÀUµIµwÜÜuv]©ðoxD?ÍøHîã~ ëéÖU1q¸öìJòÜÀßçC`Sö^üqÞÜ:تUÎÞc%ø¿¨Á㫯Ä+ÿRÆG[@:·+TÛ×NÎoÕç+ÌUMûޝ]´¶%¥ÐâûÞSÑ:T¦? ¥[$06AªÑVKîÀÉ Fû2ÜyÐÉ+¼þ°¬MæSÿÑ~ <üxpaºð«~éY¥Ô10ºÖÊï´Æ’ñ[ú)|Pn]·Æf+zãIþç¨/kä) åWä×»Úh±ÊI~M¬kA§¸}ûüε’åÊÃ"ÀÙáˏ¥k?½ ÉüV=3¿ó÷¸Wöøý'!R'õÊßT8&Wp^¸é¤ãDj®Yûit.JA³öJó«¿°| ë±b¦DX 3¯o&ä À£pagÎW:x{*G®æ÷Üù ¹Zã~’X@¼ßÙ½ÂÊGø&G ÔìB~éþØÓí¬¿?|· @è$> óôtÂÐréxví($ò?S¤9NbëST’öºx-·5´Eç¦H gKçq DÊ°ÈZ2Ýa§/ãÜ÷ÿÆ̪k9êS-OÆP¯)pseßËYJ<¬äî°Ê`ÄlÝ:9Ó¤Æ~v`hxAyïG !+®VaÛ¥>S¯ñøªºº4k§*:vÐc ØG^.­µ}~XW:S(ôOVïÃèhÌÆUäk"p"5$¬'k1ÊQ× &¨ø5M |j%ïT&vÍÖ2q®Ü좣¤C2Ð6¡9ö¦Öa'Ð3õÞÇÙx ²ªê2: PdReüªùÁÚ_ã ç#ûåÚè±¥’x¸`ÚÜ0¸¦}@åÆZLã£þÙ4S4õ@ùFýø¤âZPG`Y¼9·0×Yg·ñË)B&ò’b+S)@#Û9û?$~^*Åc¡ªº!~½°c (§§j¢/väàç0@jå[ëaÜýò}c;DLEáæSË%ðâZVÅ ¸’ô)ú«ãÿ2;`N¬Ó04«sJÁÄ:ß,®~,ô?X{kxAÐEä@¹lõb¡«¼:~ÍH¤NàîâÒàx*a¦ÁHÓYù0]Õ¾ÏÓ{s’aæ×Ø7;rª¢4ZÆÌ<ø!’gbQ¬Q|ÉódDìDÛR°!Ï£fÒ1:ßrQé¢w¡l ¿§»ì¸3±­.|FCdrk °¬Äz½s~øTz9'ìß^¸+"x69æ]"²maÜ.rÓâh$0UWÊ!([W¤våvëÄcиªsêsÅR".Vs|R1Áíæ¡ApWnÄTl4õ¿\ü¬Ùö}Þ YUi?HK:?0½v£æöóQ¥"Ød@ýThÜyùGò ±d|TMÀP=3fËs$ ½x¼jg¸³8«üª/¶ô_:¹Ë 8´öÐñH¯µ4å2µIÕ@÷-ôÛsF@Þn!ÈD¯9nʬë]JPL¦IÂ#neuè:Á¬usã&¸!ý¶³ ¬®$¯S1ëøÆ%ÝÂUl¬Uô¾Ùù95!Æ Y`m̾öÔ¬Îùà_Êø`Ìëõ¶ìvï 7j(7 ì%_Òm¬!õ`SÚ ¢­}Â÷µ©Ië:A»äxË}ÃNÀÀ0©2ntïîYûáusîEwu¼A©]x¥Ë wOðd¿Ämß+óٺѷCÏÝß å6n4 ßæcK`ºdà¾ÌáÙ0%Q£WùÂvÞ)Ò}KwoHáïæmÆ«ç¶"¹¥NÍçvÿ¥w TS¢~º©Wè÷ÞaDâSߣnÆîUhÿM(údYR¦})Q·Oø¦@U"«Üâ'Nv©x8ôƵ>:|Þ©l3ÚÃvÒY[¡äA6ÀeݾùÆhQÀìÿt*ÖT(Û_èÿC=Ð~P¬Ò9½:p&íc;  çÖÜ^ÜïY9y¿u®ì_«_Û7´¦=Q¸ñýgM| Æ*å_NïÅÞ«Ü?ÈûW*ÿêý%TWXrÊ«ëtú%HíêL.ÔÒ7Äò Ðhc q=ch´XYcpsLüØ9{×Z<0úy¨Ií8`}?æA¯aÚÊFTÆ ~¶<qøÑ0ÞçuÅ|¨åg¬ ~0weT³¼*7^@LY]Û°ø!«¯ Gç¬ï~ÞÒ)ÛRí9z2êÈ}ö ø¦¼_ÑxÿxI¼ f’âÆçÑ_3Íbp[ÇL:lú¤r¶v1´=ëÊ! ¬ /ÝNàÇÅ? ÆGGS`Ç1Rs@þÙzRSíË$¸0ªÅö9 oÏbIÍ Dªf¸IDåøÍ+&jÄÒAQôn¾çj¤ èúRøäÌ׍ö¼:CÁée³ À»×9`R¢k) ØNí"ËìS¸uþ>îÇÊO’Ò{-Ç5ÂÍA-!)MH} W}ÎQ"Hg7&êÕ[`ͬöñ>¨yæ:öÆkAî<t :ÀS:ÁWxÁÒ H¤"µ° Ùè}:È¥¤ü;-i9cíJ:"{¥°Ìrèg8PE6¬rð\·%×^¸ß!éþ=xÖ:!iè/öPíÈÂðjì2[åùxâ}wìzm ܽÇlV}·¹pÛßÒrZaï"ýï!£¬¾ca«°°*f-m )å!&=,-4"gæƬr¸Ç"i* *´£gæ #êla¯Õ2 ¸Yã8ãD+ < Ü -S &¼fé¬ÜËm/öäù×îy_ÝÍ "ø\´VÅQÏl£|T|pãÑiÜÃ=õR øÖ_Ú`½D½"Å7(aÖùZ6nKg·iª3æ øu¬[í/î¯ ¦% sîÁgÍ0»ÇùÛÙr_{ò¥(+@kèé3ääR&U]:R¥%СÉ)"e`À¬¤ 9¤N¦ Wù­BzkgÆËWÊE%$ØÓOTÖ`(kiÖô~ù5¬xÞz. Üíò£Ê|«fxÉ~<²8ª8á'zâ¨!Mg笺)¡Âväå«’Ë· ÁaªÆS|âôH°BÌ¥R­9Ý6¾}T9Ry¨!QW¬s_¨µº]¯+R{|{º1¾²Ñ÷¿¦1«=HÆEøü¥UÏáãZÝÑs¸q$¯ K¯É:þi§oªeª }ËKêºQ:1»hÝøû þÛÞo¼/|zµ<æ¥úx&À:<£q` <\ýù:urç`G©Päµ;0$35S¸NÞ®}cæ:&»Ë7o®¶¬>¬#ðö\]ß¾reáÐRÈRX~rem ׬jr~í{NÏïüÕ|ç»v lqMö½fý5ÝgK Ü+= Sðþ+}+cë\ø×Ú?´|,$äzSÖÜk×ÜÞ?/Û0ßÐRÇa&í$Xù2øpµÃú;0©: }øúû{6ká?SÖD¤Tçãù^4’ސ$è¸#ø Ù ùw"9,E9!SЬ3Þ^{¬ñP~¶ÞTú¾«~òñ£Y}oTÏjXsîªövýU,íøPzÎèû§Û=OÈø ì<Ê0h©3Ñi¾²­fæè!ï-:F&àâmÈÑ|Eÿ·sÆpj¬ ­ùÉlÉ<Ù2À÷ ¨cØjÀzdÿ`¸b<ÖfÙõç=mËÞ5Ûhã[eíC«mÖÖ¿ôzd+ò©ÓÏWðNá×A >DëüQäÒ~LEZýn0K)®"`÷"ZçéÜhW"û£jnq -·~úîêúötü:’©³ñ[Ð3õ>Ü9RYX«Pr:Ù{©Ye¯¼¡ç:ÃÓM0`ßlÆxhhDô¸·â®0þ ,ðJ0rát&ÆáaH°nLÅúX¢løQNsû&'h®åñwN"E§N _5¤tÇèîù}å2êaw5ô}åÊuò§¸{{¾÷öØÿb¬vzÐ`ÊÓ|°­¿©c¢ÃÞ Uó `Mi?³ñßå!Óä}í &&Kïۍ04Ô±Gý>}qi¤ el®@ .9#r)ÆþGb¼ 6çqÎÿl Vkvdå1t~î'Õw=s{B­ppæ)¼F³ÛVd-ce=U§ØøBö"})!«HHÊ{³ڍµwpÔ³/ì&:^ÿëç©-¯mç~Zz¼97ðäøìóõ±e]JÝ ¨©ÊÁ!pöÎD¬òÔîálPrá7¹aÑÀRôÄÆùXà% &é¤n0R£~í÷Õ§Æ/Uæ °kmÊgÇWÛ¬T±Ê ùâ§â Ì éCÏ×WJñd&© òôÇóoöË"_bo¥4í 3 õ¿3 ±äÓrLåÄÜn:ÍyÎóKâܺÍ|X9ÀÓ;Q­ó ü ¤ßlX='èÚÜÿâ\8¨¬²÷KJ bËÚb"µä¼3+·¾(ÕþòüP¡þÑR!z°’\ x}Y~ú"gò½>h¾º_¦ÔçQµ/Íë 5ùùõß&èQ:ÏNT¶ ãO9TöÐÔº7x±t;`ÕvgåT×'Æ]-;Ê)yËÍoû*É2zïëõo·Á`ÚèRÚ¯mÜ­è96?Xf¾ã¬w§ ? üqíXè 2åS#Ã6P}ºÉÿ[SɤcùÇåµê_°xØùPμìTñÊ7O´~)7«ÜýCA[ehÀùÖäÐþd¢C~î)"Ôu~n\+ÓwS..[l;¿Mf(¥}|ÅxÉe|qºx¦ÌtÆ< JÆÃY¬· ðÓ\°ð Î{:ñú²ÉÝêb·8}ÜÑ9oÂøö¸\oÅùhï:WüÑZL¬ 70ù à0ÍsM,ê´DT¬Éô=¯¬Í(ÏÈW1äÌWQàò`pJL@!J~ò¾Ó÷ÊXðý FPýSB¯¦@¼ /þäC"»ÁRoöW~ð+à 'vl"$§äz¬ u|âȬcEÎÙ\NÈï¹·°/%Ú6±Á÷ËVRÒ!!F"v¼Ä`¨äZwìð¢=ÖT+ã¥ø¤ûNxMLñÉtéÈ¢ÁÆ\LË(¼¿FÞÖq¯¬Íhat&6|õÞ[a·|Àät¥´ab ôÈYv%# °À¤Äáí#AN·VØ.§BÕTþäG3å9§ZKy¿¥=±pÅ[åæ§aÜ{öAjQê%OqUNã&OÆUh¼V0 Í] âQé’àsi":ò`´)´êð¦êÉ3êwrJÌ_5`ÀÁ QøR£ 1ãaܱ ¥rÝ|SÑ´ÃÎ ù?[§Öæ/}-|bÀ(üjy(`¥6±Q°?¸dýj¢ö0¤ðPÿ|$¥gm«Ï:¬ñýÒ.d¶Mù|º6´ÝÐǽ}ÿk-0äõ£~|ü½Ã¸#~c:né×Y'à­37X»Rcsî´ýÕ¾ÎvAø&»KIX¤·>/»Xgäªä>õx¾ÛýO§:êÉîY´~ø20½FÞmK!¦ ܸ |póÛdíîóùÇ~6A'ßás"XR¢?5(`Î& å ò&® ´&xS¹uá’.L0uZ;¨þlÆÕE0k |Ct&ÖôÂ0Y ¤ ÿ’ /Æ.&CÉ© ø"ÐÝ`ÍLi0"HL®£)fѧÉaÙ8Æ9$þÔå Þ}ñ¸¼pJo¼c¯dûÇÍj~±^¹ÉéôBlbûRuìéX´»û#×»¹j»:ù’×g8@ªé¤ù9ó¾g®¨Rè¤?ÅÙÆü;:E  Æ©¶Ou`k~UÝz0fê­ÇÜ=ï7®ß΁±U¯h3`0Â’ßÖ÷¾?¬]tB® ÏTwíºâU՝çÉý/_T@ëÁ¶XÙ=ÚûÞ5Êeë0uëíEîDÛ£Y¾åK+{:ë/å«í:6;ÁȝHéxr60ü±²@詨`·[Oá ¯¯Õ³ ÷Ú7Ö~¼!övÀÜBxh£' Ǹû$.%QÉûåïwOX7ÖÞç÷ Ìa)§p0ô xnúà?Qu 9»!ªeø§Ï_´ Rx¿T-Û~~ÃO`J^¥S#&Ë&üc_6S:ÓroÞ~Z^×Ò©6sjXNÖÙ¬>Pß¿sÄáy h’'ÇçÞ% ü=vÁ8cRiÄØZëÜá¿Ê§¹;϶$x ¨RÊzVäRpS܁ÏBËv§XOIÉ-»Qk[û+Äup²·Ó>}³­~BµcùôZèãSϏý´qpf]§íHN^ØXQz<÷î3ò+Ë&mT)+ÙÆ­Bj¥ Ïö&³]ëÍshi\MWáX,T/W~oa&T<ù§àñ{oð !<4ñôA.þJ,±,0WE¯(ku!U¿½ñ8%üòO3$½öÞ¬÷Â?GÐ?vï’Uð Ad)³óªi9j¥ëÓ_öÕ4Ü5=ÍA¾ä7 ŲF¸_pL¾b|K;é3pn-¨BYñ`εÿ¨£OÖhty»z}µÅõ ·§4ô?x¼5§6¿SÀhp R>yãðcAø(×~¦1E«VÊi-E{wax:á×{3Âî*Øë­kHº:[VlI `«¨¥³ö³G Øú+`}Öä>T¿È}<­ =HtÇ$_ç"xO·êÐ)ER¶ ¡AûKNSbéõÖðýQ½¼ \¢ÍJ"ÇÓÝ`e ¿º«æA«Õ$8cð×J' ó=Þß)èC’r¿JmÜÆ{T! Æcõ{Z?xÿgsÑQè`- (vèì =õGE>âS)Qáß:¿ybsñÒ©·Ü|!ºìFµ¿äcíºÇõv§uÃÄÿa1Àî7Tå,ÆÆ©¢×úñ°k®7oàF"ªþ>¬Étßâ ÕÍ1}åüÜa·=GçÜ`Ù8IÌ='à¿ý£’reì"û±×aOCï8¢VP~Ô\ÚëæÈSZÃV¿p¥"¬\"ېݲPQ¿éS#Xã\_MR¦Âä¯ÿÜAJ¾ô0Ò|·e£&fêã£ô´Xeáë]ÁÇ0¿´Ñèì»Od[ÁÆ­Zj[ýÅUÜ¥SÔ¬! }A^íWÝj X5ûð9#¸ºP²7öÛpåêûç9¸É031"£ û[ì·OËûxx®Íû¸--Uå}OûÆíÒ-JcÌðS¤Þ:ë)' ÎõÑÏaC¬GÇNxÍ"õbª¦(P×7[~!Ò¨6ÀqMö0nÙîÎJÏ#0­¤}"’ÇÏø"7aøY¸'A xÆ:[¯TC;J½KÑÎTT¼ÃÅ~V·q8;Ðypy÷êwA×" »rFZǐjÞ3Üú}dÿ¥)B¢ëé×4b}j.ófç­RªùB¶Ê(Ëu}S*«Zñw$ÇètK.×|ß!Ï%¨¢'V$ߨ.ØIïÚÖÍÂxïÿ*W.»qæ&üßÅ"0 ·`WÖX´à*ÜbÚçÞÿv§ v~ÕUydo¦­÷iñúçù«ç]7¬ "ä5~²¸aG£³S·yAø)Gë¤ßS~qWº"£2§a¾F¬gÉÃÑÓ÷âîÿ©%ם>^HaU©¯oÔxR3oóÐÖ}õtçýgBӍ äð}íW«x4·Ü°;Ôõ¿:qó:»keFkWåýYÎÇDAü&. Ù7`òë xV»÷4p·Ínëízë½ÍêÏÃö¢-ÜÍcûmØ)¶¹VÃéÀìû-naÞѬÑ"Ë^Êõ’~À:uõsì£Í1lr 3¬A[ÝäC$¾9a<ÿûZ¦`ýÍ|»ù®z÷;#P1»nàs¼´ÕdÌ ~wÏ` ö xúf%6}ÐÍS˨ý%ò.ÃR  ý/NWÆ'frJc$ñO3jïÆ-0"ì ¸Ü`(ÿcÊsóܲ2Ü6"7çi?æ+ó’ «0ãÞô7a5O’wÁL"ì&á94äùå +­"ø.ß¾:ôÂ1¸`Z¬KLÊÎ,¢6rYP¬`õw>Õ¼E¨ä!¤ä_ *ʏL+WphQ@µâåûÓ®:®bw6¶AB0xÚ(z£}±¶¶rè1©a±R*Õ°&«jK*Mê(2@ÕéÎ~ñ r§0vºS>C=%`Rg"͍!çãJ'ÈJ"ÊËD"kªv#5E÷NT+%kR%kê0k^Ð×ЏEWkÜùËÍèt % /¯YkÙsѸ½y^Û:ÂôÁÜæ¹þ&ÃBP>:Ózº- Ý®xu̧gTsëÕÁà×<¬åELÓ«ÄÙÝR±2Új»z[ÞÞ m;z¬ mòéô¥HÓXóRòb9J E-­­ïâ¦u*àÃÎÆF`jþYe+Õ<ËÚêç\'"agóaý>7êèºKèÂèٍÜm3¸;ÒÆX 0r7Ïàôd/÷}mü½?>Þ bÄ}>ísøJm¬iÄÜ{$3.ìSØ¡ó8%q:WKüAöà5&h伧\i’ ùp·R¾­LEA[±Ô’~SÃ:@ͳù§O$ÙÃäÍý@`sûÉÛo,D0COK{]¹UΫCmy¹@¤R#-"»¬& Áu¬·*¬ÏåB°DÔxðåÑ¥}IGéð!ïñåäw ãj°D>¹GíÅÜ'æF sËKX0ïål¿`:¢ÒÖ±é8ÜØÊëp½Ô=Íhó`~Üõ’óß\®ØJs0¹¸÷WÎÄ'’®+ú¨>Oö=ðÅLd]Ê ^9¡ê«EUtS§pñá'K"!H,uýàcUWrÊL*²i¼%½-L~ÌiìfN`jÝHÛàN·R9»Åxq!Ê"9EÐÁ¡® _³BÿBÆ]Rï/­¬ jßË¡õg@¡IA`H_+£Uþ.gòäæyrÁ¡{0bIûmô|¹oüm½»Ð»©÷_xeþ¹ß×öÌpj)|h>_9þHܧl©ô)Ç¹í&-^Âê ×_Ç9l·ÚM[$Ùm©oxxRâÒÈ#:ÛÆA!Pè~¨ëjÑ}ÂQ¤1`’G´¼éH>'ð¬<õ’NRlåR6vA°­\ê\ÓG5zm!pÓ×6 !µyH yÜÊú&oa×}sÒãOëúJÕ!'Rìz÷öÃcË'ß°å¹b`w¸8êF9Ún½»ÝL]!LmöÝqËG¦lL%¦ÌÆþx¦GWòw"C2±uLÎbx}1˾qL¼bλûWæ?kÙõ#âÄv÷ý`ÿð¶ X­a£~a`¿×(9UÝ@|aÒp·EÈõï»õ}{úaö´V>ç­H5ûÆ1w¹bk°-¼VÅãG~JLѦ"9kO\{é`±\â:âf$35ÎB{Ê/[#;-ÒâS<þý «Ý ¦^æâ]W­Æ®NQïVø/¦?uqv¦rËGWø2Ü b(-)&&cEWÌËQª)’Ükïø'ÂäK&q½åOÇÝZ©LCåZ%¶¾£½¬%éÓy×4xÕã®"¥Ü½®g/¶;})5kj# ²Ì=fÒ>¦R0ÕüìÝUÖJdRKÌmG"9e3±µônuG00g!8Ï2Æåã¥Å} !t  p¼ØSé ul ìÂ}æÁÝYaÁ|áü!r6~9<¥{t¯RÑWº×nkÜÃ!ò$Nº")O!ÚÎ"¡w¼kËÃ&pè¶Þxz^ÁfääþhEºóöO«éß.~bNZ/5@ͽ|BN_ò899é¬yBUñ9- ùȬQþÊS)îY[ÉÃ¥àD°’Q¾Ï`àoUÞ:MüC¥[þTöNfH=ÄsºmÓáÞ®0TÉ¿VKÿðPc+} bîækäND%ô­0 ñ"@DéÄN âô:RmDï³ÐÊ :g%wþ¦Õx30Fê4'Ðkè&S½_tDÙ"XºhÍ,xSº5`ÌÑñþå?²_8ÊJP  ¥ éÊõ}ñÝID £Ñ?â&Ôd"q<é¤.¹’ÆaRÑÑ@¬u$!"HÞ!ùoá}Xpx ÊÀÈ+Âÿ)<ƬRTPP#'øÓ`Ì­mð¶öú8{õ xRzÐ8ØÙ£ õmMö­. àúFþÏn={ L¹RQöx69fc[k»ÿÎmùxC<³¹½9# o·pÃÅÌow2Ç"òÜa§i­pÎ37äaË iºÐjÍ5dпe|±¿OX¾ýÄ åÂeWjïtqa ÇS1£7·»RT³2Á^0YîHÀö<·Çw'¡Yb2g[@¶5¯mú Cy^ߍ»ù¢Û+ïîÆ*0`²é·éíEÙ=v47rpyðûáüDVß!RÃÜŸ+Ø ÎNý^;L[ßÞÆXÇD0¶ù’<ò&Þ ÜpÆr{v²1ô¡¹}áwû!’ÌEÜ»"¤Hr¬tÎ9)G+"bâ¶ôöÒ½|*ÌtH¼S.Ðñâ}¾(_á§äʏ´26 tb^§;âUM½)*½µöLÅu ·[ä°ÐTlMê Ö?¤¬ô§·×É"Ü\ëÆjÎ6W°»r#Ï+èH=9ßûIzPÆxgc³riá’gÛìs|ü6¿Ô00n¨m@:B>ïa¶÷üp'ÿÍ&N³äZqo#V`$2½(õ»`êÖ°40Ê:§f,lnó]õaÉÅçÌm¯ n¿@=4K5ë!ïplD"sai¼do ZfµSÞ!þ3lÎ5sIçuÓ¢ Y[?}oÔÏp|¹ Õx#ç xi\ßÄþÍÆ!·×Rag¶Ý|'!§ú8#0ígæþ% 2 ÅÜBc ι*9\³gI7xÁyÍ2i89¹Éæ@" ÕÅ{@~!£¼||üH^aR(¢?*"pßs"9Â/<RùÏÇÌ7( ô$²ÚV!"SY¹!YoçDhw J:AnOF&&ûEûÌooþ#D’¢üä"4Éþ¶^Þí ú-yr$×u0û7b8ÿ,üõ"DÄÈû¿BRÆá_J¯Reû!+1ãK¤Æ^¾¼AâÓ}+U®â`ÿwýî4Op¨ß]c`rìr2>\" ä Q 1áA:¼L½"¡ÄCÿx¹[¬Ë1é7­êÛXÂ]þ!(´âå;`:?]Ê&a$}[*±d/&¡Üðà()&$~}*ÛÁ§?=¿a 1W_?Wi"øÊW;`F:~ÚÚ&Ù$ 9Ó%³*èúÎ ðí¢ÈÄ`£ùÒBïyÞîDt2¤½é«a!ðøDDz²µ±¤£H&¤àý<’ãÜöÄïaZ5xÏ÷Zôqa$© ôl0ÜS9 £dRV@WYH7F^íÞù4Là&:GÝ9<§õ?aá(}]¯úEÈ%È-cîM`ÌI`4¯¾!uÈí¯ýnPvé áøÔ`w(_Ôå8Êvò*¹Âµ4ÏZë{^Þ§7°¶êõ(?W×^!RîÊù3ÑÃrc$³ÆöÕ«î¡^;Áåx /ñ*!¿ Ë+ñÑ~µC|¬êe@ÆF©4§)HZ:üC"°Î>"eí´ÀYY-1éZrBbÜ­¬HS·¢|$ Ù?2ÿO,r aÑÀsùØßRì'©l®ìÅüÊ "p·¿êKÞÅÐ@M¯ã¢ïG߬Ò+)Ü"tuþ^ñOýfà<â|½ö|¼L_}y"Gè6¤\ t »¢êæî¡ W«}|Õ"}f@1ÄÝå­¥x°ñêfÓÒ%õGd[= ¦»£ÿ¼Þ'¶^ÜTêÅ?¦þ§¯Ü}û )Î0æ³"éHÎÊæwÔ?x¦C^[ ÷Óö,/ÄV9s¹KxûIËØ’S¬K²¬%£Çþs¼Óïø:u·I8DÁ`*ñ=Æ·¸Ý:Iõ!ÀØ¢cÏøõ~¾:¿ETl"%R<ÔÏT92ø'Ú¹êëò}SÌÛßJððî7h9NHüþ’¤°øaÜñz=R¸æjÀªá¹ãýðÊË»S¬3’sW4j¤;#c)´ºïux£È´øý´òù# UbºAR)áâ¡Ö@Imh xr%ì:F!T É(Ê z9Ú*"ÆËIô¯åÒ®2÷jêø¹¥êR|ÄÄRôçRZíÖ°^I W`ý;|.= êm­çE3@;&LÎzª¸¤Í©15®|~.-¶{N¾î)e¥ô2`F`ü¬Ì ç{}ìͼÃ\í¼ïÔ] s·&Ä'·} NÀÞíÉWh"d ´ÆÜ9b3ȺI¾T띸6ÔÖ@à¬3±'Þrð"÷n’ßô{@`äVtuó¬Ë Rä&®ÿGJ}ðJ-ùÄþ&ååÖSz@!DÀ(³5/ì:ß!Èď>T¿gú@öäz7°ï«îõ`êÏKøZ!ÄRÀÅ; Ü÷géZ&6HÜBg{&òCyÓRÏv&%¦¨ F}´!xQÈLÏ7I{£Þp²;xÅâ_;/Í<+ý>«ú¢SSîàÚL;ÙÙ&Ã;Yó¦ L¥'æDF`éAaìÉ9Èv"äcH"’o¡ù´?ñu^}ä²âï@R¡Ö÷%¯ÜÞê³îÁ} ÂI&VÝÝý5:Efô 0üJ]nºÿü]ß£,úéXmD«ºïÐYWªÈTj9pîºÌf’:ä«(«at)/íßÊ>eê¡¿ÈϦ%اM§Ó0:$o®0°¨Ü#äθIãøSì³Ú0©åÞÕÍά0’ÞÓod¬Ô:P¶S÷¸%Öô\m?¯÷Æ`O®Û`Ö åD?aw¥&Õ/!Ü_(>Ì»¿¬Â¥OòµÉðj»þ~RR½(¢Æê²Pãó¥ºíY:~~.ÜßÁw!òà*£0ò ""9|óº(Ëå10½"Ã¥µô Üiî顬ôÍ°Û}¸K ¥ÌgãÏW<6*¸ Kr~X gdy»x3li69Ó$ñÊX}ä- ¼âRÎáÿJwÿeüÌ|?9ñT¾`ǯTçæë­xBEÝnïCñ¶V669V` ¦föʷγº¸Û"¸¬&9ÚÖ˝ÿêokhÖkþPÊf.rÛҍåÓÜя¸©0V7!!hãÕ:òe¨7 ¿Rpë<ÑGQ¯ÿ|l{&¾u!]9ÔNµ¾ô_WcËÿHVSÞßþàÄ0ã¸öd¸Ùñê]²ã´¾¨W:R°µhbáÐkdg/ ¦"Ü&aúGß"4vJñ5¢Cäv éâ±7a0ªÅ¼¤ùy¬ÕR0%aºaBñ&ôßaA’Æ_" Ù£~¸¸4"©ìQ\9~ß]Üï<±¥¿L×ðîiÓ ëý}`jm¡sbÿ!Rcë¿`Âe4ß1Íâbg&wÖ+ñHýrÏc¹,®ÀÛ!¼?¦?|þ¦á¸ßq´_$NS0á÷»±âòN:Â6÷úå/c½iõ^OX=="Ùr¡WÐKña\y_â:ÓÏ }¼l°Æ>»ÞÒÀä4æ;+ÞñeT©n¹ÙîÜ´ ²ïS1:v³ô £yd ¤¡Ý9o&Ö~OÅÅÁ(éýxK:÷ØøBÝ~­9¡z´ÓK.Avn?pp½KP¨û0Ò­£Í#yã’xÅ$Góò"Mó7º&4õ?’âÂÝóÆaI mkxûËÌúrþhÔÐr5`äOÈ<¶ã?6>JlHSªÆI íGñ#D9h)"`RcpªQ-cªï0³¶¼Ç%Wÿ"reSV«~U»¤þÒÜrÁôý!Z'Ó ôÆ1)WUÝ׺ãÌÇì0ñzw¸ðaçÁñ¬éK¿ÙÐuw ¬{¶Odc^|bp{Ï9z¼:ÝÑz]_·L#¾gêÏçÃp@GB~ä0öûèS(Ù’Rfµ /`:ñ~g|¼õ?ózRefrcGÏ5õì’Ï4ª³ù*¬±¿SLþÝÊnûôn8@N`ËØv«Ã1ÆOÍxÓ÷­»í%¥_NùF@s ¥´¼;«(Üy^U¸üqXhϱÿ²TÍ©MÎÜ|Ub2áöeí-ÕZ¹gt]ÄÆ&ÔöâYH >B~ã’ë~w!ê¤qÕô òsxÿ ùê¤F¿k¶û9¨3«U3äJZ Ðb0Â>Îs¨±}¦ëövé¾äüñÙ`¿1ëaªÙ~ý0*U`×ËK°AÐÂ:oùyQäÀÆÆBÁÇ$M,ÁDc>c9»Üx½|°¥ËÜDÏ«_¢Z?à¿·Õñãã0¾uükåO¶'Nù`C"/¢!x4Taî±¹ÖFÙ4ÿRã0} ÖD’»C/æ/[vbæ-ªÏËÞí0¸"SÛèd¤ßh8â%StqDhÇò-ýÁُ¿g^ßR*Á"w&&Ü9âEu}+Í|3¡X°Û$gù¹êÌ;éyß89y@Ûr9ÑtÔ÷ѲÙ.+aµtoÐ4=Mîé#õÑk_kü­[Ø".E¾%©´0sùØtEü ´tmï 8]°9ø!3¨·¡Èi&åc9]:yÜ°WdαCÔ¤¤wŧ j<§n4Ðî ý¬½f.gð6AË=|ro_}ª³ÆÌZê8÷_éæÜ<ë&-½×¡¿x¥¡¬¢,EmuÓ=Ót} }dEY¯·÷;;]û@»";ïxcHÆÍcLPQÄ(*ª¡Îjè:h÷:Ç|&ôèßXõùm¢o+ÍJ»¦Ê0ZCuÑÐÛ=®^ù"Á(«¥5òeo#0òû!c÷ÒèôeÅ#÷VÆ,aNRFFvÒ¼AÜÒ[.Råî >AkÝ62´©Õ9P?7&!0FÒrWè¼Ïäø ñÊñjCµìèðôx"f^È»ûhæeb ^A¸µ¨0]3_(a$E+±.2Kû3aÄA^Mᬏ´ÔYi~ax5{Ö*·]ý!ËAÛWæeo´" 2 äÓa5rBFtbÉtxV»Þ°:}¿4åi¬ìÿ~Z1ñR嵐â`Ú@’É8yo6ÕWüEp~ûyî<5©ëðº¤$G* ¿]«PHÖ'sÓ9¯L]wÑÕlÔxÊgÞF´JS8+yU©":H;Ç_&8=Ë'ë¿U ÛªÇ&2ÆÒÆ fk [²r\¸$_:9«·T«¡ÜÜíÚ½þÌ&¢/ùüÒU!mAn¯]7³I 2r̳<é¤c¡ý’jܪÙI@ÆÎÌM¡®Av¤ ýs ë-&ÐHpë'×_ ¯´ ½ÛjJLLßà&iÂZ` {~- FQöø?*º7v!í±ðÚï +øåÂ㥯úËÌ~¦:&G¶8«a 1k°?79ǏVHf2ÛJù5ÚÐ"~´øÆà¿ÙÜãx,Òÿàí¨è=`Ì´MHÆbB&dzRWÌ&è "g6õ êÚ9xKx7r+À{V`µ9r&=ó{Kl¼ÎÀ ðÜ}ªI¼h{X~¦=3©Øä\ 0 Ýà³Üò =à±û·¯·øÌèð6]/0<Ó O:úé­TRÃ|5zÜ\e9®^ð#è\Ãn9ó`ì1:ÈÓe0¨ÿZ²¶¡¸z&ìeç8㣻ï ðÐïËû¦:ë^PÆ`sLޏaVù¾rPª`©ãH¢|î0liÿ2Mi¦ÃêE°ê¾!¢ Ü+Féäh¨x^Óø¬=4`¤ñïV¶ZþQtÁò~MsÖÚ/¨Òè)29ßÃ")é3/®a=ÿ8ÚÈAÁ0ª¶Hñ²_:óIûg ²¡& a!ÉSØÙ©+éÆRß³øO*é 4Ä /Í m4 çß#¯¢"Ê )¿d/"ǬóÕïË«ý»,Y¢Ǐ(Pv(Ä[ Ö ²q×ÜA`K@ÀÙL" N µÓ±¬ä<"¾ïJ`|cvÕxýɶC+±0ñ(/Õ £Sv&¯æ°ÞûcäÄ0fúHÔMsËÚ^øX.APï3 ] ÑBí£½Õ2ía³ÈrVh=A·:GúºØv} Ý_fJ­¶B6p[Pa¯ ¤«`ÛS-»¥ð ÿáÞÁ úµ’¨ï®L»ü îQ§p%[o-t¿mR#© wx)ÏPç30t½n^S']"\å°}aÖÖ{× fnÛ:¬¡Â¿ £¢$uô̱3SL'¡ ñþm¢TóyuÑxÿ¡NÐRï:3 O~R S¥;³Z:’?ÐÐ×Öçõ}²Pp[x7K؝ný G}±´¿´©Ó®ß¡;}1@?¬bYÜ~ý@ïy½}UðW^t4PQ"ٍÆ&3î0ÞGTõýø=ÆQS¾Ê0B£úųBúni¨o)x):'&f"P:sa~òð!7¢áïI¬Àá0ïoWñòÜ_³K£¤:0ý xD&}÷¬­TÏP£Êô ì·"p­¤¸º!ͬ ~ò$Æ*¾È˪]^^~® y×""" Yƪ°ÆXÒqNCÃ`®îÌ k¸âþ×(I\[’/f¨þ¨(/Ïnôåí§»/PYéJN§hó¶&Χ\}9&[;\Óú+kï¶4)\ð #uÍwmÌèÏ¿¶@¾Úuñ^Æ"÷£d¤ÎÇÑ­|ù±sÕaS¿ë «ÇÜ Û´ÄÚço ömõTÜ9_£ R`¾É8 ¼bÉäáIdÒä¦j÷vdÇy6¼*Á ±ñ` 3{°SfI ¸µÌ¥Î¤í0ìV8×Cel ¤¯¬]@¿ßµa%ôYâ~ Fcwí¯°/R}ö¥b9ÎQÛXÚã×ê bÆÌ;±"®ñFýcccopñ~q5Qá~%Ø\ßÎë=kqýØʨð1óÀع~,aïÉsó÷þµaÌ Ob zt½!0ð+AÃjè® |Ç}Zâ.{D_´yÞ^Û&bã$ñ§/*fLÜ/w GýD¡LÜÃÃS&í"11Â"È°Á!³&ʵŰÌCöByÚèârþ@O~°)¿"¬6¢&ÃUä¿Ææ-ÇUZÆe`W Nb®D9«!+K ÑÔ:r](ØRåµ&6  QÇ$¶úÃ=bÆÆZüÌF&-Mrò±ñma ÐâE\X }ÙûNêy®ÂÒjî NtßoUÇ ÎtßjèÝ.ì²0Ô¥ÜÑàÄ­QKÏ1õ#,µ}ãGýËJ$þåhAyma$úRʵÿ;9ÂâæÒÊ ÞüǁSvÅ"í+åÆqx9Ë#n`ñ9²Ã§BÑUXü`9yçm×­F,~ÍS fÌÎêe6¶éº«Îç|c]ÅéjF#¶l’C×Ü'Þ`Oö¨®ZxB×aÃxñ»ãÚiï}?p½5×W ?±ø?ÎZ VÞð:{ôÔR0F{X[Q¯÷¬\ÃY/ÓAÏnÄ4á»>«x×Ú/(d°á´ú0}vd,"ÃRóE²¶Á«Ñ?#°ÂTr¨/_¬KÍËGS£à¹ 8êÜßëì oÍáo×X¤¾»ûDõñ,QʁÿYX¸±¸ÔÁ*TÛ/4aÅ î>9¬_Drâkxw¶ÜÁUcw¥ÎÒM2`6ùs¶Oº, 1Fg3ý [©°®H¿§}±R"á§Ô©ÕÔéí µ*òß(Ð{h£0ûèª7;h½pᮐ·Fà" ] ®oÁV͹jæ’Fï®Õùâ|¬Tèf¢UtÈÛk6`xÏ`ÌSS´Wyêq%êÎÊÆsbX©ÙFå]×’`´þFÝN?è)cZ~Aßg54~ð¾Aù*iÄÆamæÖ*wÃÓÔýæ~âüO5O`~_ê6`bø}JÂñ"¹[ÎÍâ¥v¤°£æÜÜ°¨aÝVcìÓ"T¬í#óì6x Ôï"\ä"Êgµ1r«f ؾµSKùâK*´Aë/øî~vç]9 P²rÏÝÇ;iï>ÉSßñÞ;Õ¼r10B¼Xé |÷;ô²¢ÈÒ'©O0¸ËÔxàäuR>át4~¬­ýñªª±ì}½æÕ÷1¦ðO]àØਥóúËøÀìß5·¶õ"qéon¬Ì4ÒûkÂå6ö^I³ÑÄaº+jdo@þbñ§CqÉα0Û}]æ¥bqîkâx+A)ä£gï¸ð0ÎêØܦë> SåË@ÅýûfLºâ4"áû&î¼_lp"R®á¢Ñ±sKm»È  ö+ü/ ò3E]« ÿó/#râõÒ¶Ó?®¼Zøü’fS:z Ì*(­jxú`¦[0%" ~åW4t½Ü:}syë°Åy:J^ÓÔþt¯°ØÌ:§oyÞmî:Y=}ooï/ã6BütƳ:Î~§C'dߺßzú«þ0wßÏ$ÖþîÀNPtHÆ»ò’åæ¨|æÅbÌæ6D³LWßI?z×µ!WïZ!±x-øÚäKÃ07õ(ËWó²/:SÛõ;vY°¡â,üĨ3yÛéÅ¡!ù]>úÆ.´;y­gm6±¼Ô¹Ñca+q3ÜS¹óê2äõ[Rkçtó) IífÒkZkTÃ@~¼iü’&<)æø²SĪrWV·/¢Se«Ãqëð=.áTî}zãP'ñôÆ-­v±"~®¦Zíâ`ÉïÛ)û²fíÔ ©Oië<ï:FZRsëà}ag;£èäf!4®æöV ßaP]qżë4Éô-ҝ?NÐÐîhÄòSñy× ßû¬¸öï ¶9 Ò ó£7v{ôÇè%ÖÌ$¥bÜ)Ï?uMíËfZ»Ûx("èIÏÖ?ñ¦« ËàÏuQM¨ °øãRwÜ-W­ú"`1Ð]´j}ôV]å`»OÛèT!úFôaŶSj¥W "¸ZG00+ÁÅ¥xß®Y½l¶¦tÙ"Î6V&Æ<&½EÆãwº6ÓoÐÑ·rÕÃí9*¶]éMâr[HÆÄaÔ$'}Rz~î˶/Á0ã£ï}ÛVØÄZÁv¡µ`§D£¾ß(P'Î"P#7~QÌrø=¬½Röô L8Ewõ¨Owæ}N+,äVÆrñ0êy×¾TaºDY£Î:®\7\áÐÑè?(S»x'ì͝UgD±d"’Ól_9xímç³!PÝNE[O þ®0Ë]Ö6ibÁËÚO É ÅxßÐS¯²»V’íÛ`×00¬9xÙ[4!tO`åP]kþjöø âdÆNz ô5N/oYÏâÝïÜ9]z[°²Z¹Á§ GÁw6£§|îí´]éí]p¨Õ_’¶z`×ÔÈÕPlâsw¬k(MÞʝÿÂA¹Â¯¹CR»Õa¢Îwßô¹5$3Õ÷ýq*=ØiØi3¢Ósê:m=M0÷ Åå|~²z}C¦oaRÄé¬'÷>ÍeyÛS| Ì0ÐíÃ0A½->a’~û{-Ãr£¸ýX¾/ÓfY% æ:­Äa k¾>%Ü"åÐú©Ü _,57 xXn/×íÌ!x(*~práª^~XæÃG0ËHmÜ1£Ô¤¤mQC2^òçÿïq"9 9öØD¦&)Ûª0!¯Ü~kE1ϐ6¿! x^íqR§R[+_ûbN©Luwc{í³rîlûÁ¾ëìOfx(P¾ç[CrÇþËfv¯ÊªùÞ$[o)ÚjÌ*çúÊÄn¶}4Múúçd’»¹¨»? ùq4õ×m^n-9TºR¸3Z:ÍGm/[Þ*³¾ÿeS¯Né¨Eì¦ØÍ~ .WÎ'§gJÝq²¿ºEa4_ ­J ´x}Êî1ñ±µÇBøäËÇòÇÍ*±ÓzVÜ_$¾[q¯þ6ÝvÛlßÊæÛ¦rÒhc~ñíþùÀÊ·ßpªÁæïJd¾C+'³£±£òc5þ&8Û¿«|'r¦3¯zóÿ£Ý  k·ã{z²í=¡gz9åÜ­¶­øÌùON¬¡oý³©CHÛð7é¹x><02«J(ê0¶ì*e¥ØÁnáô}`ðn¹þS´ï¾âì¿N%ûÿ~UQ:tR¾M¥Rþð=·ïî\®Õ?ùÒ¡F;Rå.Nñ¬úúgj×UzÜ]}V°ÑÜWÖ·oQ1_¢ïÑ-/]ÓàÓ(9è¡/Ìk¦+7Jí)HB²¼)Ãæ-döMB* ÔÑ|¾-½EQzD¸¯ïòYñBî¶!ÑO_÷1I£2û4W󺺶~Ò±:6J_È®Ms´9çô¹¢FÆn2-9{ðk ìIT¾¹koºûnªìN«}×F¡pßÜô`û:û<Ù»Í|¹ÊrÉZbË'¥ZaIA±­#ТÂWèØb¬ìl 7ü")o¿#Iì!%4Ák"(læâOÛJBؼ¬Côýí>4#ê}GRT<úFvvþÐ&QRR"c@¤ Íä ¢*ªOöµ¿0ï¢ØW=µ7píx&ù¬1(<CVÜ"mºíôÙ0## !Ï}6=ÂtááÜ 0M!Øó»ïÝE#ê ïpX-ÎÜ$xH¢Â܍ì£#ÆaÉÍ"~!x]8Þ=«EAR:ë}¾ú`n´Ëv¼#iaðx!{axUmb£ø}MQ}J Û¡0k¿aH0^íKÈ®9SóV<!nAm0`1TÍÑÿe\û>æ² Ñ}¦ÿЍÆÃ,RJõú×C%ãlð«¢Ñ¼úf="ÎÈ7`:)Þ&gß0\8¸)ìR0åÖrÏ9 l³õ9%¤÷3Üt¬©£ÖC 9ë (S4öv "líZ^×Æ>áÉ°²E°:f ÕTôÙb²òrüþ´¬c½(8ï¹WggrõÆ>ªRMÍÌÂþ|ä+w­ æbCÍT[Ã!£!Sà!¹ÝUý(#6@8Àó¼ V:Õ:Ê:=.næÔüÈù ¶&>gGÏ˨ø÷ÈÑÎaF`Æ~d±-<Â`×ÖG¯ÎÓ00Kô{±r/bÆè%xÉÂ/Õp¡tÑU(Ï#"¿6ï"ÈJha?[H ¬5 ­,lX¡W$¿±1bH¤ M´ÒWB2SR.0Àú;R>ý~̯¬Æ¦Q÷ý×!Nãÿô¶Så&-&ô´"Îߨ©;*B[Æ0}¿ÉÍÇwÉT[{/oýøιÚUÕf¸û¬_f8:àa¤¬æÏ"#bÆSö¶^ÕÅxnê:qÂ=ƽ Æn^ÎûìX3°ØÜH/¼·ä:7v?õ ¥ Ê4x?F;ÍjÃÏTrƤ_å÷ç áxí©É",Mz*`6¥!J}G¼(^ÉÞ3nvW9"&_ð¹©yùF O|¿æu_Iã9&_«výVÐ~1ÆÑ’ÿì>37ÉðïÇ}Óºwy"ú#hNVÅuºúC9E©ü ü9Ì#´áû·ó2\QR×\GÅÙû"VD§b?23aw WÉ)x )lcµC¡0Ö¼&9[ê£iV`zØLâ=î÷ÝÔÏU>1J-÷Õ³2:ùõÊk ®-7®Ü¥n#ìS}¢PEJ4ÔÒÃñ7ú¹ÓÜòõ}cÜü1­J0´!7G?wK//$¨®¥Î`x΁6Î!?3ùk§rË}þ0H9ÅE>1aaYÃìU]ýa@éjxµ3óDô\}¿è¿&Ín~$vË÷Æü×<³¿ÐÌ@mÅxìÏHÇÓØÈ;Û[D£KËH'§ ­õ: {éôBMhÆÊrFqF:諯WÈH"E ×Ñîd\:èyÀpñJå¾ÿ/^:CÜFïëUÅFdÆÓÆ8 § }»cÆC¿ Úïíp1&¢CÊ:ZÔk ͦђÒrÍ4ñ欯¯MIg0õ¨6 w®Ó¤£¹’QÐOø¾:Ô¨peD3¸âÆì:}f³¡E=Uú öRÜ^v$ «ohηªÑÒµUý°E¾8¬¸yìÞ3¤®mx#6WkTZc,q@{»>oMüµ)¸Sóã[±ØÂBoÊt&#;AO3®ý"ªXñL,÷ýü6¤-*è|ñ¦-­¬Æ9 º­æïFkâ6t¬!0yyqfýÜ<ÚpÅÌx9"ܵ3èpË¥SjÛ°ÊÉ : ~9ß°³’òÅ,$ú¸èÙÆ H¼ô³S©þö¢¯¼­Ph¥®b{Á~ÐhâÌ 1ÆPX;+Ò}Ó©-Ü (¬>9çßÒ,¥¦öзÿèÒÌÈ;×(öðíSS Îhbî’«UÖæS¾â%90àmsúG6Åz³o.Üùh3"p¾ è>¨§[¹åVöxRo#ç}},±üeîa³g±$Bñ;coÞ³Væ µ / ¨Ã¤ËؤÛì `¤\P¥á¤èÄ¡òRW}&ºÙ;Ä’õïôÂ[Pή891s u/Ét{,Î æËËÌgìßqºn ¾eU_ìzã2¨úr,òÎy½Æ*Wá@¨þ qj X;¼|TçßÖ\UçÞ"g>Ê}^f’#eKRnýÆH¬-)n¼"WÈÜÆu ¿.IïyɁUfâ]¨ºæyò U-Ný]ÆþÀ3Ä:37ÃU^¬QbC/ëØ §éÕ¯°Da0Wí0!¨ÖÝ;Æ"°½3¡8Å9:F¶âÙÝȏöû¾7sµÖÄi׬Ri 'x¼º=S9qV»`ä ï"°ÐKNRb½Ï2Jýþ§xí¹þa×#.áý¿#L¹y=kKK&.EI'>,;®ïÙÔö^ß®uç²cÇH48?43× «ëÔ4&srD*&GY/yQÀýSÂ9&èXÙÜ3Äë Í9Af"ú}Ò½: ö  × Ô]¹´þ °æ:)ªÊ| N,ÜÈÕ6ª¹ÊµjÀ F]Ä ·ññ ÿlöCܐmý|YzíÆ2;|!AQ0¯é\rû1Ñ·9ï,®ïaÍN!ÊF:%G~y ³u°"u0Ò7G°,Ûx ë tÆ.´Å*È»@ÕTù2×3°ÉQ·È`"ÉÌÁ Ç)¢È¬q8qÀ׬Y8SR¡ktbà!Í Ïk:Ô¶¯©LEëd>óh(ãrUej¶P¤xa\x0á¾þ°8ÇTÝEÝ8Hf<:þêÝc}­+!#qü~Þc(KfâÊ2êÚyGÏÞ0é¡"5.WP¶Ì8­ûÀ3Wm¹ØG\7ÐÒy)å$  í&Îï &Wñ¥wÍëíixe&Ç:?»1û%à%³MÆYА}±ÚcÖÁ’ ±!+ím ÷?^O&öª³åÝÝ¡ÄR-Qï9ë}"AíZDÐØ5ìöZ)F4ñD)qC Áòa~]6¦KÌX qpÉßëZhhm̨·9Pw" Fözþ#~V0öâ6s¦[¾=VGx7_µ/ÕϧKíoeÆ?\»Á~ôÊxÆËoVÅ çSÌ1OìÿqÌ­`V^gsàqöÃ^ÿëÆHDDÚ¹ÚÇÁ>L/Æ~OúÖ¶ây~Å0ëRÁ8 IhËØû) ¸öÃsõ]$6~"þ,äi’u>'³eÆf;Ý®¦÷Î×ÆáÝsøÿ$ÿE¡øQÍ&{ñ 'ôah9LÙ_Øã¢ã­¡m²þ dV"¶ö¦#’%}8ýPØ¿!RÓþaRÌák@>¹â íÈX}bìrüÜ XÍÌ Úî1NÚÆÂÄgÄxÆ­q=ÕX2¬ndô°YéqÍÃú»L=¢¹2 @?áLõ¦ÏþÌçd¿Í°wRBRR´ ó"0Â=µ© `QRs\"ãi現Ð* ¯ËeãSöy°*}âîËÛ2Ü’ä:«!ÖÐ ô/HªXá~`|Ë"+5Ç"ëëÛibZÌÆ¿8d|ç7ýµH;¬v'$» B5~B¬Iëw¦¸mïß)/Öæ«£³f..ríáw¤ý¨Éí÷X[óg¬ýÎÆ90|mÎ&@åj¢]½*² µóÒÆXV Á-;¿cz'N’Aµ >§ßæëUuÌ ¿P[ìü°ÇÄÀ.PK´2o+fA°äJä^2¶%¥ðg¯î|ª@g+à»f$¬,¨¬íi9fn$Ü V`p\®~ûiVÙìOBû%ÑùÅCÀ¬he?'ƺ­0$»øƬVQècrN»Qîë).t+T´\ùîÍ\×S~áK ¼¤iÅ0Q3j@ñå¤èÿ. ¸FÌ}ùò:ÏxdQ\*û¢äxÓ~s *3 O©  Ú=w#ÁÛ§Xî9´³î_±~io¯ï"ï)GææÆûÖ5"ûlceØ>~ý*Xõ/vJð\ì+ô!£R.Ã4ö½oUWe<´Ôxn|«\ê ;e^}ÍT&¦»JÏS&*Ük%\\÷æ=@c}t«ÜX~wiH*E³F¯°40I"Þ«ø¨Ð¥ØÝ!"2>R¡plxð.f4V30øÖ~Ô¡9Ex;Õþ¹R­ ±xìÁ zì­ ®;ôÚðÛY$-í#åv£¬Ô­î¦ú<Þ¦xù3̵ÚØlNÆg_§(üÌwíÅDN LB<~¦Íh’í¥ÁmïPë°SÜ1du­*ú2©XÃŤvb{ìBÚcÃa)³GÆjôûM9ÂJþªm/®;bc)¬ gõÒôB{s0Í8E7Ñ-dÜ/<АWf»õE`búÜ#ETõ5îl'>S_±î@~Á"æïïxÅd6%"õa®¹fB}ËáÑÏsܪ©OÑ4,{ÜMáeßÌ×K:`)d/ë.(+Õg#®1xVD’ÎþYùnð %6·’µqÉ · Ê`÷{'ïZ&b¸y´Â!QÜ=ï¦:!d²`3§iÔ[Ît)N8Z!’¢Ýo,+m¢UÏ"¾IøwÝìòêrÌÅI¦]=B1Rþ ¬:ýÜØêÚ¶{iËLPÁG£¡C´½Z1³¹rÃLÆX}؍!°ÿR PÎUn&þ#NÅê«ÚèèÒ9nô¹ÞNèRÀo9bª#Åã#ÚÏÌëi¼Pµµ&w²_­êNÿØà£Õ¬a"æ½EXç4Ù"l  . x"|¹²¨4Yê’+KͨÞ}/§ß5xÕU«t0©^xKÝt"\îyû!6;&4ÃU[©ßYXg!<ÜvÃxÚº`& °R:Ã?V1Á¢}§Ã~Ò+eÊ5/øØÔ}3¬¶D3èS%cú~~DuùÙ¡Y£õàÚxÛÝS¬àç1rÔ’¯Ë«, ^ØÀRl6¾:I§6²}øXaÄÐÒw=|¹Ò&Ä, í õ5&ÚÚá=Û,1<'Rg7Z2ÂÏ}»o0¬yÂ43G»û!câãj"¼ú`Þó°À:ga¡»ÞÍÜÎDî§×Sïf½sÅF&Ø gZL:&ÜR¾î¦e^\}ÿãsÙQ®Iã°AÐHå<©;%ã,a¦ á˪Ì:&¨¸ÊÍҁm]þ·i¬ 6«ä±¢Ê-09Á­L9 n H Öõá_>X\n3\pdY¦::á`Á8ªü¹·ôÜ|«uïúx^3ÆÉ>Û±WéþWÅ>±»éBÑC~w>>ñÕµ5Õ¬)ª6+¡¨PaÕUoîpåîöíJr1<¾ÿãI’ÏUúÚî]§8yR7Os.ùâè !fMÚÅ-%0kªÎ¨Ý.³`h%aL!MßÃ÷p_#V?ræ´í<á©3ÄÄPñÆô:ES#799,¢3¬:ܺá2æÁû9hM ØT!«ÒûAZAZS7ís¸|m8^"L"L$­VþTa)VYe F¥8Ü[ôàA¡V5ïvl"Ñm30TȪçX«Z¾XH»+É橨RÓ©«Ê£­ÕêQ)A £½V¢²Y6Õ«Ü°º#SÌÕÉj°U?Ø c­ÂN«uY4Zµ@úGfÔêûEÏûÂ"½$`Z͵míu¬=Â]Ü{=møª¥w¢q$è&}»üâ×ì/¢cmÅ#®ì`1H¦'0¦b"ûÏ·Y¥)´0A¢ïål~LRn 0©a}Ó93µtÚOÏ f53 ÿÆæÆ8Blþzï¯.:7ê!fMæA'ùÈ`ida¸±N}fjïLûÏé"d*ã3a-xn:n·;<×0^ftåN°Q"/iÖHûÊ"S-¹1V ÞÑÍö©ÜxóH}ZOCÙ¡E5ó¬D^u7jøª tpsÍÀåÚrF­Ñ¬úièxì!YõÖûNµ)$CE%B9SË#CäjØ ¬S¼ o1ÈOxˍ &¯æÑáJõÏDÏòòë yDiæ5c£ÂÜÍDÞ:Ø*âÕßTg  ÐF]OÁKÆ$x®êyÀRs5Õ×íjYxO;ÐÄâ9}V kGaµxéG¬Ü¤ðp¬M»RºLÀ%\á«ø0d¶ÚÀ~#y®ÿó"@±i’Ù®¼¼,³9^g{Îàþ¡Ä"ÎÜÊõW`¸z£D?ã±³Ûã#¦Êì;of"óó&>Ø0l"!9ʸQìL` ùïVj6g!ò´RÆÑ:Êþ+µËMìÁ­ ±!~µ9t0¥<~ZûÍ:ã)Íï!ÊÄЩR0£þøeNÓ B.Õ &Ó©Õ"Ä"Î"&¾t¤=ê ¯§éè¯TòøSW?õV Ý㸸pIáÐD©p¤pTBçÒ§}SE ¬6@î/£±}r×":sCÅ\&Ðd'¹ cï¡êÒE¥"àR>xC0²¤Ý º sZÜ£¤#«^T¬uÊë dýâWŨò~f&·tG}Ö8)îY÷Ë¥> m^Üh%Xy! £:bþ­É&~b´éÀq3r7¹ïq1SC˵X¯¤ýÏjf&Å CM;ÿãH’sf¬Z\±K;¾õ·oe° '1)7KJ9dZOVqTN¨§¸~dHý}â9¨Çx@S&Ä´0æ&¨û%²ô~L.¯*f ½Æ=M(2w2çè8~T@4(@ò8®É³8 #6TëÇe¸RzÎÅ·å@6Ù!9Z9s-×BG }S+ÎoÑ£í}¯? ÏÅ:9&ø¶¦ï7Ë1µóüqu«Ûn08D¯=b#3Æááxt«Sv{ÁtîÆ0¼+-+Fóxm#I>&õßkR¸ [a¯|R(’:Æ>a@KZ ÖÙS ¹:Ø!«äb>`ñ Õ" `õ#aËtHaâa·ËÐ)5ì}ÔSzzt’¬!0ÜÎQ{ux Ü`'Äc¢xQÒª1þÅ;B©ìÜ#ßXòÅo(Z!º µ¹m NÉˬCìÚ_;}ZcäI¡áƬzY¬§ÌR+ÐÌôÛ¨6Ü[pì9zÕ&#&½ &GÝ6Ôºjî4u³~Dr®v¢80 YêP¬¯}ðbt Lɝ±HHÍH=×FûM² pLF@j[Å&iS²aãÞRîÌIj¾ ^´é=Ï¿úK 6raYË ]Ä;Q÷Îk±»8ÒÝ~´Q:îÉÈÚ#Ê15LôÛE·:[F·!Ü2Q¤x0\¬,ákjJvà´¦¾ÌÊ _µ õ9Sö"?mØ"’îF-ÛEyÃlw~w\K>¹ù³ÃÍ3ÀÚéRlG»Z³m²Ú+¸ÎMa`n0 $|1ÓbÛSِ½Ú¥W9¸ù<9+AΐÖÖTÓÐÜgyZYìo b½J<ü$¥ÑÜ0|xÕ"ÚçV~^¼k-F ¡u÷á°Æ&¹,¯vFAÈ 8/!ñeU.1 UüYDa%æ0¢2ÿþ`-aG7\6R¼ :ÆáµÄFLêà -´¼Ü\~,\3d­'eݶ3Á}³Û²Ã’R/9;oÆE-xeÝxÒ¿ ¿l4b0(vÕÊSUF¨¨ Æ$ÔÔg¢é½§Øi¯`rmDÆÊ ÕgQ´ÕUw.øxã/:Å3z;° îZô]æ]HfàìSèﺿA.Õ4{3äE¥uÝ»'TËBrMä¢möN±( e¬a  "Z:¯Î°"ü4úX_~Ôoñ®ðKéä&íÆdF}xƳ,fZ¬yNëìf(¼h§ÕBM{ åƧfxÁÚdÄS?Èû£UG!û­d}¼&3 =6uÍçÜr3ٝY¬táêíb")8SZRÜÌÏî abâÅ&¬"ûVé:t¨tµv÷ÓxÜaa#¦xf<4øàmªõñZ¥#åر=#£´§\·ÿÀÈY ,D-n`³(µ:¢­Àbr¯¥Õ[ciPÇ}²Ú¦Û},¼`Ð0¥àPÊ>©þ½&M/ë¬ìtÓ¬ ÈZþ[<ÆÊZGhþlÙK£ÑìI¬HV²Ivge*ôG ²6CÆ / 2ÂÖ=ÈLÕPçS^ÞKYÀÜZ¤SX¡#ݸðæÐ9ó«ÄâÅBgÆî:×g[ ô:Æß±Q/s9VƐ}C%!å|m<©~¸9e]æÐ89µ^¹zçë&§ÔÑo~ oÕ¯åe7ÀÀ~#¸`"Õ52òR,:g;Zèi?|0^n|¤çShÙº ÐÔéKì~ô͵(çÚ"#¥LVÔ C,­'´WëEݹÅôX2Ü»_T¼ 6íYSÀN GÍN¹i5Á /Rg=¹FzW« ::,ÕÇÄ`¦Ã}V _,Ø5X}Qtl£.7dÆÑxÐf0`ûb%fahÔT¢»/RÓM-º-ª®3ĦÛX6ÒJ.ße£çYn=úïS`)¦Vù"µMÆaÙÍR7N²©ÊÙÛ. >N´Qíf  GçÕg¼5eÅR^m&o²!HdÌýx´ÂÌüóØ³U,/=Sk¯¶Õa æcúaGÁ Vм)0KTI*’4R׬Öj ¸þð<ñ0Ï0=÷pyï~ôí£møêxÆRɵ5Jq¸R¸E÷®©0Ocÿ4B͵é9¯ÄªÑµ;CßrLȯÆr~%fî'¬Æ£¸R/½ÑÓÚÀ7÷Gòú>½òPRË0öl,ì ø2éC£¯f¡#¦:õ¹Çjª¢ ,²OV⥏ ; ï´ÆëRÒD\XFäCÆã×YWc«SáJ 1ã)ãÎú}´×UÍ8=Hy/myÝ|fXøhá¸ùÝw!©É·Õþ^vñ uAÀX~1éÊè¼"¦õ.ÒµÄÔ `Åíºc,Ü/·8Û9îRvaÝWzB0!Ýá}.Ïë¬ãË/¸zXgBÿ ¹Ñgü3Ä6{>ÒdGy½Ò&Û÷´á¦ vC~èÇM{« faw ó±cÙ²(}Åb·ÕÞõ&¯ð²O}¥ù`ËÑG¶ 1!xCÍGa«dDÊó{:l­°ªBnÓæ7"W>ÐrꤺHðÆ 4?ñb9`c̾Üxë s! ,Üú(oõÿ!¬)3æN¥ÃúRÙ ÓRøÏÊõU #*áoS³Î~(JSMþh±|Ü xíE"ìÚã«$:%åÏÀÆvvÙ&r´­®{vÎô ±^ü÷ 6 ñ>^ÖïËм(¢Jë°ÿ0ýCg¥noå ZØà"ySáÂKýÆrÆpa"ÇH¡ê¹rÚäÁ¬¦Å¦ñe×QMòÑTê¯Yä ü5"Í"ñk¦;´øÉÝç1¶ú:oDFb¿?ÆíÊÂí Þ´}&E^"^Þ Gºj4Yù­Ô9©,x'Å<Æ/ݏ:cÆ_Y*}tÆíÞLkÞPmäi;:/½IÓi÷¢^ÒÙ' 7a)4OÌàt-U¯Ä ô;ËË·æD~¹zâ! 7fS¬ÆP¢£Ùg(z'÷ðC=®ïùJ~Ë¡|)µCÓ0$¼ï} ÑèøKεcZQÍÅ®^Gè<*ÎRÍ`Ñ'/_Ä¡å¯Á`rÞ = 0"ìhSnç´ÆB5Þ=[ç°b­Koô8zú’Z&5Ûç60¹(1ø´)F­JÜ¡´cávó21A:&7OT®¢ bòÕdÛ'ÅwS÷:§mú´ÑéÊ#¦H5 yR9ÛÝXJ΢åRÍê¾~!H¹æªÊS}PR¶M-aÌ8K15"¤:}Ð;WqÃÆwUZà!ÇYÐrZ’u7¹ôSÐÆHãi¨P¢AV³Êqú(Mí=¿´aeÅ&P¡rI»tSk]q"C±-ªOýªW·(Ùæ³åΧõC3MV÷I,&Ó¤©X]Ý’\v"}Þt¤xé"j5Z-Rñ:Ý£âB×~·~¢<"«·ÊFàa^íæfÇ9:Áz²JKxûâÇ 6}ããÅîs6¶$Þ>ò[÷²r ßcêR>Þg_ÒdønÆ­xßMð!Á,§½.p²·î©WÏ({Ê[O§pO]b!gÈâÓ,Ækama÷e¹/EºajÉ ô:ex7Q"ÀÎÙ»auôBÂu©LgÐT})qÝêCÒÿ.ÁÉ榝Щ¹!}(qUs49oç9f¢{ÿü=®úåÎh`ýy i!ò¼4÷H-2̿ې}¿°ºYÕ3a"ÎÄÏr#¿&²ºlìâÀ«»\Ï0I:v¡´ðãî«aQ&5'°4’"³v6iIüTò¬ç:ÌÔ#YZ{;±ÀQ«jv¼±}%½³G'Zp4ÛUoQÉìCÛz%dI}³}p»£:M;C¸yMÇ«óá ÙLdÝÑ:nfm፴¨ØZVTDjÂ~Äo ZAr/Ê"Í¡»$àÚÎÑ/:k;Ø/RþqÄ)M§D"ÃÍÆZØz¥)0Rä5»C0Ͻ0YIGz:S²Ós} ÍÂϹÝhÄÆ´!òã·gæ"ÃÿÑÞ`¦ãXN} 3ÖM=`zÈäÕÝ-q®Ñ%kGÚñ¦²þÚ_C¯kûJÆU9ÑIqö¨Ê"HƏøñùW{µé zÛ§~Õ(é!-jÉý×úÐÎ)¹Jã&Ùn´LbÇN"ã ½×ÖDû_!mßÝ{DkÞ"ÛDïøù$¤UÄÀûÌl*SÉ´O¿{Ù¥sg3p£u²NÒu)É(q<`n¯C$û47®Ñ80U¢lóL`+m¢}bÅB >ß;O;~Z%®djð&ÁõAF®Ò!SR§öè,æßçVW#à¡í²¸À}â?TSi.ÀÖ]RxxyèlR·®éRùs¡Uëf'ÖËAÛ\ÅL Lx«- 4¹Ts¢årìò:m)ú£ÐÄ¥Tþ~ÜÜ`¦hȁ±I±"´=Ìú»9;ÙÍ`3$mDU~xSSüÚSdøҏ{ b§ÏÛ;Í~7 Âf9m!xS H8ló,!}HKשSäûíYnf"haT'spPl.¿¨ú8æéâ®=bzi mpa°~£ôDúϐ¥pïjêX?5ùÞ@`í6L åΒ˪®"Zµ03°ÄaÊÛGß7YÝÎØñ)½á!;ëI¿BÁÀ«]ɹgõróODÙ»$M·¦,cם.ZÑ8VÌî_K}` j&/éaðS«l îÉ"ÜDÌvxí¯:§ôi v^§8"-ª±Ðè÷o<¹1Ø\&± îD¡8IÛ`ÃUa+¤þÖtÓ"×½ BÉbÜÕÐ4UIÎ À¿"ç0/`ۍ@_à±U’'ê¥}] &ËèÒR}v&9 4KÞüw5u9Éì )KsÀ¡­bF»P.yNII§ah4©IÌ.P%}è"ÂaÆQheN¢ Eh%NJ½¤=çJk3|^íF¦Í±-Eò4ç~á» .Æ:º}P/&Àa¬êÃSLN/§èBÔ]öÊî` ôUÇûÖn[xDy{ß)KÞaÄu0=÷/DãÌ"!Âk˪öäSx ÉVß_¢g[ÒølöÖ¼~>:ÜRK×ÈgäWøãPÒhm9 ó¥òvg¸)xè!Ç|GàZlÔÔ÷_ô0"= CIÆayË]<’[mލõ½É³¥ÉS?óÑ D¢"¬°’·j /³ÇÆzÔÖM;ÇÁs}a.¥±Fm{J5µéF¤húíá\A:B®WDaj»O b¬ÅwåQ Y&úñs_ak[«Ð ³ØC,Ñ/Ì á9mòh±a`³øWágðl,tÛç±S c9§+ËÑs+¯íÏ'6©ßwÓ(g¶~>úÙW¥ öĶbØ2qé÷x’ÖÔG­VÎøÿÊ>h>~a6¦Æ¶-N"¦áåü§,8£/ H&<áãÍ*{^Ê9$­Ë`"òº:0£ZþÐAFñanûhßPDtεrx8á½’)Å_J·Pt&oÀUçà ³f 0&ÖóNR¶ çOƬDð5Õ.vuÌy䢰îL»/9H§Mêö3]yØ_¯Eµµ¼óå kz3ÛF«éTP¯¢°ÿö&§Þ"ä>Wñaýæ®pÒ%ûÇ-Í>²mÒÛ²ÌÆÉlubû"ݨþÄí"«Û9ºA±6K"Úf*¶Á9-²¢Î`&ɱØÓR¶&"RN` ãO'W«göï3£_0amJ ªM=ÓÚCrw"¥ùy0pó/^ï÷Ç/$¼a!Ë î~ Üòʵc£w&^ï9w!KüzFS(`¤ÏÊãĝaËÞ'LùøFÔ ÒôjÑl¾,ðu £ &³ñ¸¨"ôü&a]"9Yh-ÒÅd¯°BEjëý,p¢ À!H¹¦Ù{Ë} ¾A¡60F¹ÎOè®)Þ#Rl²Õ9ÜS!¥ «"\Vw¬Ü¢Ð9ðf¹ ìEWTHÅ YpØY»è/ó< ÚÆ÷ÑVná­ÜìÄ·°¬0wÙçö:;Ë;E0¡lJé8Û"kwiU)'Q.uÜt¹SfÌOÍZåZÙyy% «Bú¢iBXU w~Q$Üù/Xx!91:VЮ>:åp¼ÀáåmSás¦xëîèéònähUËÅÏÇ¡uXE´üáÑ}Ò’3öýÏ¥ó.{- YWÃ"vSi£Ü"m«MáÜ*OSòe[ÏI«h0pít¶ÿ<¢³0Xts°ëL¬¦å|ÉÒýÂN°¤#·¬wú%ÜÑ:×?»ôÑ&Ä)ÚåÖãÈ¡lë~ä»+BLkÆ~x9ÒY¾F æÓfhk¾ò÷^^oâ-l~&½Q ^×Êye"îBÏîJúj.ì~Ø<<h)b©Ç"5WÜkTÌÛ¨w_[ kTSEFÉò¶ P\\ÆZ’Ç£fÿ #L~g=*ÄaIS0xXÒ~"4÷È&+7D¯Jª3¼%=¸OZ&ÊÅ Ó³3_º£9Åf9¯"XD~¼ë÷Sªü;N:³9rɬ|è:ö'ïÒp®®TȹÚIi~c|»ª»dqá·ïn˶ªõ`öÞMÙYÕ;6kzÛø,ÆÞ&xtS1u·s×&9¢ÝrñKAz,¦$á(ÝWôQ¬­aé«îx0£uu@^Qaø¸soþò,`úOxCÆP^0aZ½¯Z$ªr¥~×f¿2þ?0dÆøg G0°@©® %7C ®UûQÕ¼ |}3Æô eê=§Î¹`:adqa¶8gÚè¦ÇØ°xÉoüKoE/;sލÁÙ¬<£Dþ©÷Ç¡ïý5ßìÕÐ"jg_¢'ÔcW4jçbw8K¬èÇHé+¿þT({?f5JDmócÌk­s}Rhi©%¯âÿ©IJ÷¿ÈÚñîRèÛ½Å°ÊÀeã¬but7Eø)QUòÑ5õ6:²xt=R Á¥ß }7&Mk¦Û0jDs¯xS´§ÛßÏ1û 8T¸{bz¯"¾DFÝSkÕiev¸¾º@Q`M7ÆÝE/ã>KCIë.öÓ óc\êîî/-RâçHöÑ<¿¸Âñ!²72~fcW’qBÏÔ?[Ô)¨íE4ñ(ðxH«íúÜå±U¼'×ِ»}¬"DºôvÆϏÀ°æ=«GlG$7â*Í ÐìÒÇÊò ÚäÜéo+ÎÏæäTqÞB"¢¶9BZPøÑ2HR¯ûà³( F-~k"HÇ%­F§&*Ú`¯(ÕíÍ[­J+òÞqRÓ~w飢¦ÂRåÊ"sé¦H¥ç0a¯#X(ÍüxïèiêK^Â&_’@ ¨ú¦V7kÕVÕt ïK,ÒÜè**^ÝyæT«Oc¾¨^¿ óBs*¦×ÙwA¾OaN6¯ Áõ``DT/ajÏn'¾|ö²JNWAÆe"Xó zÜZõÙì}©¬a" l«ÂÞÊÓ WC,Q®é33PúÔùó)yW!Õw:;®]º ñWW ï©HÈþ}ûíH¡§Å9¼ÒÆøì5ñ£½ÜEa~F!~GçÈÚ* hÓ´7"ÆÙ´|7`U¢pθ`þ3·¿¾`ÈX5!pêºT:ÂÎû×'wG^:-QËçtè"Zfµð£¯wìä }ʏªÛ麻b dk*h~ÛeÑhªÆS")å&U¸0©þ9üÌÆÕèp´5Å»Æò¸H¢ÁqÓv2Xa3O^}7gSYƶ!NÞ\M'âÃart8Z4;¤,¤2ðÿ`¸ÍÃ@´ÿWp°DAEEÁÓJÅ·DE@¡DÅDsÁ´rAÅÄ­¬ìê05)74Mº:k23ÝIÓnΨåܱr&aa0ùRßßø»¿ÎóSçSçý~x×%·aJªRv(qÎäq sgÞpÔ,lÝ­zíx^÷f |1ºR÷þ,­§óbú¬/¸~æÚ´·"D&ÌÞ®ªÛʲ­z¤Û\ ­ik<ØI<@|" קÚ9²’N 9Ôbb>ÄÆì=üO&Xöõõ8#Ü}ZÄE)@>otµd¬ÒléÞ4+èÉcÉìé?«¾9±râß·ªÚ®Rï7zÃ+×ßõ¸;Sagö2ι+óÇ"mol-´&^¹@¦²1"©ÆH¦û a#eÝ’6W ÎNyb@+ab"ø¯~x4ÅwÇ ü[Ø â'¤#¦ÝÛ75×ÙYÛLÂéB³ãáA÷bСg ÎDuËRÍs5Ôïlëz¥qQd k¸V#Ù6Ó}!"|Úù_!kõ 7NA&´^¡tå?l­#Rô~ûÔW.¸BÞD<Üv>~XÉ 3´¥v!S"±éqÙJq5î?KF9= ¾>!Çþ"J£¯xß+vºÜ3ÜQI0bÜ!^¡m0/­u{òcó϶~vàc¡î0Y>?'aå&¦dרŵz¨AÔZ[wêÅ’ W±}B ’ti!}¼0x1wñ·ë9Ø’Ò6P¤ÇôÄ67Án÷ÆÎË*d~¯³( ÁÑ T!G&I¹HèúxÀ¯´7³`ÁùÇÎS­a·uï6£ cR²d:z[dÒ²¶Ít¾jJ=ó!Ût©à8PcsStlôÎ 9Iæ\y¼Î"¡x[Ï|¯ýéÖRþԏh 0Cø:Sa½çü¾jÙ øÃáÀË=ÂÕ¤Á:q9o@¼¹["}MÚ)YÄ×NKöË~h:’þE#'¾ »Û¥{{6(ðNºcÔC¤$¾Ë>%®'÷§Z¬v©¬öo1µð*ë6ÈþÏÔ¿3tqÝ’ƹº£>©ÍeïÙe½g[Fg x.q.þíeÐ,øáÉqYö³"HòA ¿ùaRq%[¿n¨ÒQÞGQYÐîe}ìys¾O¬Ë©:9@ûÐèx¡9.:ùäà¥lZHCDà"ð¡D«4ÌqCS`ÚRÏwUäÂ!±kN¹;PMd2BSK*~6Z _gÆ,³qÖV4ýXÇýúrÁ¸4Æ}d'dç$ æÏõza±~G"Ø wç|`Hà|J{]ÿ³¥ *!¿ö!û ¬¿ªyÐ|½]föï²ÜXªý¦ÿOgfD£h-ì|ã3¿E+57!§|¯ñݹæºÍ-[V¬8YÞ0èä~<«¿å#·2ã#}ðøÍ_ ÝÍÿ#N +(é+(ó\AAõ5­Ûü´×<Ýß20×Z;ïàR­?fÏÄ°@¹_£tÇÊÌ:G L´`.¡õx´v´4òo÷këî ©ø÷ØmÊ®åfG·«-:³(;j$SRWü,æ­³IV:»:ÞKÞ« ª-lîÉ9èÞË¿oQE¿:"m:¢Ó¾0 S)×vË}AߝT椒V{îi}âã:zÅqÜóæ_¼S9s)m9!a¥°¨M'ÿ¼á]¬ó9n5cðîRRØ߬èmÛ^Ú}bí>õ" ?ó@a=ój²ãyðp÷ý×]ÕÐ0º{ö/~~Ý#õxêjr\&K~éæ öÉ×hX G;õÈW"0§¬s¦^|RyDêÇ3Dn84xî¬SãÝ÷½§~Yç2-aT&ÒÌðë/ÚY +¾SHþô0.ÓÔwæx!<`ª"TRÞ+ÆxW1ÑßÍÀpENQ~ÿc"á Ï:² `þÂY»I9ÙàHat¿6ñ$j>ô¼åsÍ þk®j#Ç·/ ógýú·00ÙR*Qð{waÖNÉçÕ¹\YñH[ñFÏCeö_ÆýÄõ­ÿ[R¬Fí«s|9ë￾O²<â'<41ù\x0áS}¹Æ+:X:y¾«,ìNʽÅÅípx3çmøî͵¼x!"àËHÏ:k6â+sz} À"ñÊM:C)¾dÁÞ *o^pBO²DíÇhNáó]®S4¾S]óäKÒt2~õ#$ ÎÉ~[aðįúð2iY°#ýºRàëûøNÝÇõgK_îØ "}¸LüO?;HòÿÎZ?^`Vàç;hÔeVÜ3 *¬T¬±ó-úaürø:<a xx4ߏ Àû»Ûì»ÆªxÙÌܽlÇûä_¤þ/_¦%øKÇ,Y½øC¿ fi³ÊÖ¿¾ß; ÆG"®:¤ ÒGp9øÌ0p¬|z?¤"L"WÞOׯOûï!÷x£ùa¼xö¡QHߥ"R/ÖpÆ:Kg§àyÁ9ÜÁ°C¿Ú`µ]âûrÇ×x%D¯`c<{L+¥wÿä´þæéEI®@ðyøé¦}ÑF?`ï5¬bÈß28`¸Íà>LðåÎU3ægÎÁ>a©%´®lÆaµg¡¥gR{ÉA, oSiéqØ£ ¾"ܵZÒÿÁDÐÊILRÆ*#Ý\ H·!±È¤Z¯O¢õìZRøÝû@dø9¸m~w0¹®dÖ~~*pÐ~vöHÄÖ/¿ÿÆkβStø¯:aÞýçÓ¡k?3Ò,j7Z)ã¢ÿ@æ!üx,ÜèGÍ0<Ôú1ÈòåI"kÿñØu" :~ïãBv RV9uz|Yu«¬i Zïþ2R¤«+Ñ­ûÜ<[~óµÿï&?øßä)ö ©Üo^Äá’tGY)¶|u^åÿ.!~tUÍ&½9~z²7à¯I}ÎR|!KÖÏÎ_kÞ’. ÕÓÝzÃïʯãÕ_ëËÃAî% Xÿ YÆJÔäYb¨w[ôÓ±ò¬=·¯±ÇÝóË¢Ex?2V0¯xÐÒÞ¡,ü"ì9bËß9|¥ ä½låÜëÎÎ:üxb7RlMO’¡îʼú07¼Èi ǾþÂMNFß/RÆ ¬\l{¿=çIf±±ÙOìæî`3< Té­Üü¿Ìª÷UÎSßù!Ü2뵪J°b:ü:ô)Y"9]c}^õ7Îe>åíÂKìÿòÕ× "eO3|sÍRKóÛ=.pq!¾äÂ*ó²Ñx#Þ\_ï×3f0#áÝ?¹¹5Yp}½Ï|ÀÜÜS]ƤwéÑI¬úÍ AXô.þh"îU9Á¹£øÑ¿Ö7º"¹B±U:ÿý×kÀ2÷t¶SôäU¿f~"Øj­0 É ð\Zþs½yqóèTÇûΪáåÒõ8ô!áOÏ’ü]ÒÞ÷îkÔÍÒÔ¬£Ásr$4vçù¤iöÌ»~Ø!G!PØe'3àÍÿ`0E¢'i\PÙÅÀVÒ§#~~öSx9>ºÂ^¶µÌeåyèÜÿ÷×ÕM¿ÝDä¬Þ~EÆ%Ôاæ°ô2¡ñå[+_K|<0}±OÙ°Ád¢K³â÷=»+NË^"üÅ"Í ÕGfàü¹5¡gÝäy5«&¥_tÖ Ëlµyª\dxR¾¼Zp<¸¨½þ¡Câ [ :ôm0ÕkëÂÂïÏÝ}v¶3'¢u÷½1ü²|ÒC\¢,¨_z%ñ ñ!¹,_Ð"ü#Ä-᳏"¶ @î½xd%ÿ¨1 § éY#åÜRà$²;Ò»#x{@û. £´Ñ­ãÆÅoföÆ£SçbÉßÝjÒ t$Ï¤Ò ªv{Üù$o¨Trª r=}.½*Ý=î<öÛ«&óxor ~Sÿ¶ûb×x *=`÷×ÄTrÁçIV÷· Ñ×k_{ÿ@Æ}x=øÊRª:÷~¡';Ó^}  A=Ìâ û¯xr_.Ú=[æCLp¿sÓD½·Rõßåüâ¿TDbNùíæN±$ܲðTôna&ýÔDq"á6sXP®[/?ÿò¢¶&ú­ÃQÏZg R6/9îrú1Ñ~äêøóþ¿ò  ê§MÃ7³¸Aï’?gI#)4ð¡Qîwܬ¤ë7Ìñ¥ínûf¬ ¹»ZtÀ4~uñ8ðú¿¬?ð þ°DzMÁåþ± -ÍpïÉÏ¥×,Ü-v~´óи×ǶÆ8FwàQ¢?Év¥ØÒ]H\LY½ÏÛlÁû2¿ÿM-  NNg[Ý¿Æòaïêvz±ë Ì]r¸bàbO2+³? %3ÆàÓöàϯRöÕ\ùÜ׏úS-W­/Àeä¹`#T ¯¥SÜ?§,ÅÒüB}0~¸¿x$:â-ûÃì»9%ÓAËrÝÂß)6Nã]ùkîðYB0/AÿØÓ`õ}ûÇ¿|Hsd­nr^"æ\d@.?a;-κÌgz½§1â!ì¹ 7,IL=ãõW¸T"ì³Ä|û7%daç¦ÜÿÜñ"R,5ÿ,8çI.e±ô¿oZeZÒV fg´½VÇ:l¹q.Ù÷¿6à? f±fxWÚá÷Qá~`à[] ­<Ó  þÙ©© MºÂ!WÞÍtYaå»_® |òÿv<!·m2꥽kü)õö¬"«:eáò~TÞ`W4}þ­»Tt~|ÓùèWez+±BsÖ\ÌbZÎ_5ÛSþÛ½´ø³{kÞWÞkgüÏhï>eÊVq¯ßºS¦F½üpuèÑGþsèÒìý¾ß¡QÞAéNºç,¼µ;lÒ²û3¼$폯õ`·¿ðÇOX¹aÜÞ\(N¹ï¹BH'~#

Open in new window

0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 24778821
SeanPOBrien,

It will be to your own benefit to download Hijackthis from TrendMicro as that's the first place where all updates of Hijackthis takes place.
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

I went to that link xmachine is linking you through and I couldn't even open the downloaded file.
0
 

Author Comment

by:SeanPOBrien
ID: 24779140
Dear Sage and Master,

 here is the log file report after running download Hijackthis from TrendMicro. I just asked the application to scan and make a log report I did not ask hit to fix any error, please let me know next steps.

In the meantime MASTER i WILL TRY TO COMPLETE  Step 4, "Download & run GMER (rootkit scanner) from (http://www2.gmer.net/gmer.zip)" which I down loaded the computer crashed before I could run the application, which usually occurs when the computer gets hot after running for an hour or so. Anyway I will try it now again.

Thanks

Sean


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:44:10, on 05/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\PROGRA~1\MICROS~3\OFFICE11\OUTLOOK.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-21-621207314-1882582792-2072850948-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Marette')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1238665529109
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5603/mcfscan.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 7809 bytes
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 24779188
A lot of nasties no longer show up in the Hijackthis scan that's why I no longer suggest it as often as I used to, as there are other scanners that's better.

I just wanted you to know that if you need a Hijackthis.exe then the TrendMicro site is the right place to get it.

If you please scan with Combofix and show us the logfile also, thanks.

0
 

Author Comment

by:SeanPOBrien
ID: 24779594
Dear Sage,

 Thank you for the Feedback you are quite right the issue once not solve and thanks for understanding.

In the meantime I'v managed to complete part of step 4 (from Master's request) and attach the log for the GMER Scan which is for my c drive only. I also have an E. drive and I will scan that shortly and send it to you, hopefully the  computer does not crash again, I had to let it cool down for 3 hours before being able to complete this scan of the C drive.

Many thanks

Sean
GMER-log-report-5-July-09-v2-c-d.doc
0
 

Author Comment

by:SeanPOBrien
ID: 24779633
Hello Again Sage,

I also succeeded with the scan of the E drive without a crash. please see log attached. I will now try a scan with Combofix and show you the logfile also, thanks.

Sean
GMER-log-report-5-July-09-v2-e-d.doc
0
 

Author Comment

by:SeanPOBrien
ID: 24779725
Hello Again Sage,

Here is the log report attached from Combofix.

Let me know the next steps?

Kind Regards

Sean
combofix-log-5-July-09.txt
0
 

Author Comment

by:SeanPOBrien
ID: 24780901
Dear Xmachine,

When I run your sixth and final recommendation which is:

(http://www.nirsoft.net/utils/injecteddll.zip)

My avg says its a virus and I should not run it?

What do you think?

thanks

Sena
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 24785484
So far with Gmer and Combofix logs it's not showing us that this is caused by some nasties.
Sorry I misread your Title before thinking that it's the programs that closed but it's actually your pc shutting down.
This is most likely caused by overheating as you already had mentioned. I suggest trying to resolved that problem. Make sure that the fan is fully functioning, dust can build up inside too.
You may have to replace some components.
There are also programs that monitors fan speed and temperatures.

At startup you can also disable all your startup programs to troubleshoot that this is not a software conflict. You can also run chkdsk /x to fix bad sectors.

I would also run DrWebCureIt as already been suggested, to check if Gmer and Combofix missed something.

Is Ad-Aware been uninstalled? the file is missing, either it's uninstalled or the file was patched and had been deleted.
If it's already uninstalled we can then use Combofix to remove all its files that are still showing in the CF log.
0
 
LVL 3

Expert Comment

by:nhenny2009
ID: 24785580
0
 
LVL 26

Expert Comment

by:PCBONEZ
ID: 24793437
What motherboard and what power supply please.
0
 

Author Comment

by:SeanPOBrien
ID: 24833499
Dear Sage,

What programs should I run to test the fan and its temperatures?

I also as recommended ran chkdsk /x to fix bad sectors and the result was clean.

Yesterday evening I again ran AVG scan in slow mode on its own with all other programs closed and after 2.5 hours the computer closed down. Then I restarted it and tried to down load podcasts and within minutes it closed down again. This morning when the CPU is cool no problem downloading podcasts.

I ran DrWebCureIt and apperantly Gmer and Combofix missed nothing it was clean.

 Ad-Aware has been uninstalled, Therefore, I will then run Combofix and remove all its files that are still showing in the CF log and post the results here.

And finally thanks for adding two more zones to my question "Computer Fans and Cooling" and "Hardware Components"

Kind Regards

Sean
0
 
LVL 26

Expert Comment

by:PCBONEZ
ID: 24833816
It sounds to me like you have a malware issue AND a hardware issue.

What motherboard and what power supply please.
0
 

Author Comment

by:SeanPOBrien
ID: 24834575
HI PCBONEZ

Is this what you need in terms of the Motherboard:

.40 gigahertz Intel Pentium 4
16 kilobyte primary memory cache
2048 kilobyte secondary memory cache
64-bit ready
Hyper-threaded (2 total)

And for power supply I have a Mode No FSP350-60THAP
Max DG output 350w (+3.3V&+5v) equals 130 Max

Is that what you need?

Thanks

Sean
0
 
LVL 26

Expert Comment

by:PCBONEZ
ID: 24834882
No no.
For mobo I need make and model to check for known issues.
Info for PSU has what I need. "FSP350-60THAP" is a Fortron built unit.
-
Won't have time to research until later today.

0
 
LVL 26

Expert Comment

by:PCBONEZ
ID: 24836405
The FSP350-60THA-P Part Number corrolates to the Fortron Source Blue Storm Series even if it's not branded as such.
- It's a better than average PSU. -
There is one small OST cap but other than that the caps are all Teapo and CapXon which generally do well in power supplies. I can't find any major [as in many instances of the same] complaints about it.

Waiting on mobo info.
0
 

Author Comment

by:SeanPOBrien
ID: 24840722
Hi PCBonez

FUJITSU SIEMENS P5GD1-FM

Operating System   System Model
Windows XP Home Edition Service Pack 3 (build 2600)
Install Language: English (United States)
System Locale: English (United States)   FUJITSU SIEMENS P5GD1-FM  

Is this it?

Regards

Sean
0
 

Author Comment

by:SeanPOBrien
ID: 24840739
Hi PCBonez

May be you need this too:

Board: Fujitsu Siemens P5GD1-FM Rev 1.xx
Bus Clock: 200 megahertz
BIOS: American Megatrends Inc. 1011.001 08/22/2005

Kind Regards

Sean
0
 
LVL 26

Expert Comment

by:PCBONEZ
ID: 24845803
Okay.
Your motherboard was built by Asus for Fujitsu.
http://uk.ts.fujitsu.com/rl/servicesupport/techsupport/boards/Motherboards/asus/P5GD1-FM/asus-P5GD1-FM.pdf
-
It is very similar to the P5GD1-VM that Asus built for someone else. [Gateway?, HP?, not sure..]

The board have a long list of complaints: Not recognizing drives, RAM problems, refusing to go into or come out of standby, USB not working, sound not working, BSOD with a LAN cable attached.

- The manuals date indicates at least some of those were built in 2004.
There were some defective batches of Nichicon capacitors that got used on motherboards around then.
Look for Nichicon HM [black w/white writing] or Nichicon HN [black w/gold writing].
Also Chemicon KZG [brown w/white writing] or any kind of OST capacitor.
[Only need to look at caps bigger than a pencil eraser [6mm diameter and up].]
- If you have those that can explain why your system becomes unstable under load.
.
0
 

Author Comment

by:SeanPOBrien
ID: 24850973
Hi PCBONEZ,

Thanks for the advice but how do I go about looking for:

"Look for Nichicon HM [black w/white writing] or Nichicon HN [black w/gold writing].
Also Chemicon KZG [brown w/white writing] or any kind of OST capacitor.
[Only need to look at caps bigger than a pencil eraser [6mm diameter and up].]"

Kind Regards

Sean
0
 
LVL 26

Expert Comment

by:PCBONEZ
ID: 24853222
You open the case and look at the caps on the motherboard.
May need a flashlight if it's dark in there.
A cheap dental mirror from the dollar store doesn't hurt either if they are hard to see.

0
 

Author Comment

by:SeanPOBrien
ID: 24888614
Dear PCbonez

I checked but was not sure exactly what to look for so took some photos per the attached. If I have to do some more reading or watch a pod cast on this to better understand please advise best.

THANK YOU

Sean
Photo020.jpg
Photo021.jpg
Photo022.jpg
Photo023.jpg
Photo024.jpg
Photo025.jpg
0
 

Author Comment

by:SeanPOBrien
ID: 24913903
Dear All,

Have you forgotten me?

Thanks

Sean
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 24914869
Sean,

Sorry that you've been here still waiting for replies.

We'll ask the Mods to send alerts for more Experts to help here.
0
 

Author Comment

by:SeanPOBrien
ID: 24917505
Dear All,

Here are some more photos.

I did not find any capacitors with black tops.

Kind Regards

Sean
PICT0012.JPG
PICT0014.JPG
PICT0013.JPG
PICT0015.JPG
PICT0016.JPG
PICT0017.JPG
PICT0018.JPG
PICT0019.JPG
0
 
LVL 87

Expert Comment

by:rindi
ID: 24917864
I'd also agree with rpggamergirl, your system is overheating. Virus scanners when scanning, and multimedia software often exercise a PC to it's limits, heating it up. It looks like you have already cleaned out the system from dust, did you check the fan is working smoothly though?

I also suggest you remove the heatsink from the CPU, then very thoroughly clean off any residue of thermal pads or paste from the heatsink and the CPU. Both should be shiny. Then apply a very small drop of fresh thermal transfer paste to the CPU's surface and firmly reattach the heatsink. When you reattach the heatsink take care, sometimes you can only attach it in a certain direction as otherwise some parts on the mainboard might get in the way.
0
 
LVL 15

Expert Comment

by:f-king
ID: 24922903
The paste should fix it.

"Yesterday evening I again ran AVG scan in slow mode on its own with all other programs closed and after 2.5 hours the computer closed down"

Do you mean Safe Mode ?
If it happens in safe mode then its hardware and not software.

0
 

Author Comment

by:SeanPOBrien
ID: 25021906
I have now removed the heatsink from the CPU and cleaned thoroughly any residue of thermal pads or paste from the heatsink and the CPU. Both are now shiny. I then applied a very small drop of fresh thermal transfer paste to the CPU's surface and reattached the heatsink. The computer now seems to be running a little bit better and for longer with out closing down as often. However the computer is still closing down when running AVG scanner or downloading from Itunes!

I now need to check that the fan is working properly, what do you suggest?

Thanks

sean
0
 
LVL 87

Expert Comment

by:rindi
ID: 25021988
While the PC is running the fan should be turning, and with most modern PC's when you are doing something that heats up the CPU, the speed of the fan should increase. You should be able to verify this by watching the fan while the PC is running. Also, many BIOS have settings for the fan, here you can often increase the speed at which it runs. These speeds can often also be managed via an installed utility from the mainboard's manufacturer, so check their site for any such options.
0
 
LVL 18

Expert Comment

by:larstr
ID: 25040343
Have you monitored the temperature of your system while it's running? You could for example use the freely available application SpeedFan to monitor the temperatures. I also once had such a problem when the cpu fan died. The system would then power off when the cpu reached ~95C.

Lars
0
 
LVL 26

Expert Comment

by:PCBONEZ
ID: 25116399
[Just following up from earlier - I've been away.]
The caps I can see.
The yellow/black with the K-stamp is a Fujitsu Hybrid-Polymer. - Good caps.
Those with the T-stamp where the top bar is curved are Panasonic/Matsushita caps. - Good caps.
Video card has one Sanyo (good caps) and two Teapo (iffy there but shouldn't cause this problem).
The small aluminum canned ones on vid-card are solid polymer. - Rare to have problems regardless of brand.
The others I can't see well enough to be sure. The Y-stamp is far to common to call what they are.
The ones I can't see are located in your CPU power circuits. The ones under your heatsink are not visible at all and those are the most critical caps on a motherboard. (They are actually -IN- the V-core circuit and thus are connected directly to the CPU.)
.

Flaky VRM caps can cause heating issues because the VRM MOSFETs end up trying try to stabilize voltage fluctuations the caps -should- be doing [these fluctuations are faster than MOSFETs are designed for] and that heats the MOSFETs up considerably. [In some cases the MOSFETs will melt or pop. I've even seen it where the solder melts and the MOSFET falls off the motherboard.]
Same-same with a PSU that has flaky caps or other problems.
.
~~~~~~~~

AVG has a setting to automatically shut-down the PC when it's done scanning.
Are you sure that you don't have that feature turned on?

.

0
 

Author Comment

by:SeanPOBrien
ID: 25162218
Dear Larstra,

I have now run the Speed Fan and attach the results in a spread sheet. At no time during the 40 minutes test did the temperatures go above 70o C and the CPU fax seemed to turn on when the termperature got higher and turn off form time to time when it was not necessary. The RPM was about 3450 when in use

During the test I ran a lot of programs including iTunes and AVG and whilst iTunes now does not crash the computer as much as before (cleaning the heatsink) however AVG is reliable as ever and always succeeds in crashing the computer before completion.

By the way I ran Spybot yesterday and attach the following results it appears that it just can't get rid of some of the the following:
AdwareC.sbi
Malware. Sbi
MalwareC.sbi
PUPSC.sbi
Trojons.sbi
TorjansC.sbi
Dialer.sbi
DialerC.sbi
HeavyDuty.sib
Hijackers.sbi
HijackersC.sbi
Keyloggers.sbi
KeyloggersC.sii
Revision.sbi
Security.sbi
SecurityC.bi
Spybots.sib
Spyware.ssib
Tracks.uti

Any  suggestions?

Thanks

Sean
Fan-speed.xls
0
 

Author Comment

by:SeanPOBrien
ID: 25162227
Dear PCBONEZ

Thanks for your reply. Is it worthwhile opening the computer again and taking out the heatsink and taking more photos?

kind regards

Sean
0
 

Author Comment

by:SeanPOBrien
ID: 25185301
Hello Guys,

Any chance of a reply to my last two posts?

thanks

Sean
0
 
LVL 11

Expert Comment

by:govindarajan78
ID: 25202128
did you add any new hardwares recently if yes then remove those and check. Also keep your system in a colder place, below the air conditioner and check.

the symptoms looks like overheating. Also check the event log using event viewer;

control panel->administratrative tools-> event viewer; check the application and system error logs and check for errors
0
 
LVL 4

Expert Comment

by:jackmcleod
ID: 25202159
Well, if you really cannot get rid of them using spybot, you should really consider reformatting your PC. The word keylogger is what you dont want to see, as it probably sent your passwords to people who want access to things like, your email, your bank account, your paypal account. If you accessed those at any time, have your passwords changed (from a clean computer :))

The heating problem isnt necessarily that:
It could be the power in your house (do your lights seem to dim out at night sometimes?),
The powersupply could have weakened
My computer did that, then when i tried to change the place i plug it in, i realised my plug was scrap, so it could be the same thing.

If it shuts down every day, try a different computer in its place for a day and see if it does the same thing, if not, then you're 100% sure the problem is within the PC :)
0
 

Author Comment

by:SeanPOBrien
ID: 25207749
Hello jackmcleod,

Is there not someother anitirus/malware i could use to get rid of these "keylogger"?

Kind Regards

Sean

0
 

Author Comment

by:SeanPOBrien
ID: 25275049
Hello jackmcleod,

Folloiwng your advice from 28 August Is there not some other anitirus/malware programe I could use to get rid of these "keylogger"?

Kind Regards

Sean
0
 
LVL 11

Expert Comment

by:govindarajan78
ID: 25275139
try symantec antivirus; it works fine with my office notebook; blocks keyloggers
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 25278046
Hi Sean,

Spybot found keyloggers and Gmer didn't?
Is Spybot fully updated? Sorry if this has been asked before as I didn't read back the whole thread, it could just be false positive.

Maybe also try RootRepeal and see if it finds any hidden hooks.
If RootRepeal comes up clean, then we'll try IceSword, if there is a keylogger there IceSword should detect it.

Download RootRepeal from the following location and save it to your desktop.
Zip Mirrors: (Recommended)
http://rootrepeal.googlepages.com/RootRepeal.zip
http://ad13.geekstogo.com/RootRepeal.zip


Rar Mirror:
http://ad13.geekstogo.com/RootRepeal.rar


Extract RootRepeal.exe from the archive.
Open RootRepeal on your desktop.
Click the "Report" tab.
Click the "Scan" button.
Check all seven boxes:

o Drivers
o Files
o Processes
o SSDT
o Stealth Objects
o Hidden Services
o Shadow SSDT

Push Yes
Check the box for your main system drive (Usually C:), and press Ok.
Allow RootRepeal to run a scan of your system. This may take some time.
Once the scan completes, push the "Save Report" button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.


0
 
LVL 4

Expert Comment

by:jackmcleod
ID: 25278458
Sorry i didnt see this before now,

There are tons of ways to get rid of keyloggers, but the only certain way to be 100% certain is a reformat.
Trying what rpggamergirl said is the next best step to go to if you want to avoid a reformat.
0
 
LVL 15

Expert Comment

by:f-king
ID: 25279739
Also run Spybot ,Adaware  in safe mode ,also download cwshredder and run it in normal mode.

http://free.antivirus.com/cwshredder/
http://www.lavasoft.com/single/trialpay.php

Make sure they are fully updated too ,cwshredder will say it can't find any updates but since you download the latest version that isnt a problem.
0
 

Author Comment

by:SeanPOBrien
ID: 25376198
Dear rpggamergirl:

Yes I found key loggers on spybot and now I note that the Spybot programme is slow to start (does not respond after each request for 2 or 3 minutes) and when opened delivers the following message:

"When I start spybot I get the following message If you have the AdAware option to scan inside archives enabled, AdAware may find files in the Spybot-S and D folder. Spybot does not contain any spyware, but it creates backups of everything you fix (until you remove these backups from the Recovery list), and AdAware complains about these backups. You can safely ignore these backups found by adaware."

What should I do?

The reason why I don't want to reformat, is that the last time I asked my computer shop to reformat, I lost my email data for the last 3 years and in addition I had to reload may of my applications again. I took me a lot of time.  I still need to carry out your advice from 8 September.

Thanks

Sean
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 25376556
That's a weird message that you get when starting Spybot. I never really like Ad-Aware I used to have heaps of problem with its Ad-Watch, try uninstalling it.


 <<<"I lost my email data for the last 3 years and in addition I had to reload may of my applications again.">>>
If you first backup your emails(I can show you how) you will not lost a single one when you reformat.... I have reformatted a few times and I never lost a single email. I still have my Outlook Express emails from 2004.
You will also need to backup your other personal files so they won't be lost.


0
 

Author Comment

by:SeanPOBrien
ID: 25376722
Hello rpggamergirl,

Please see attach the report following you advice from 8 September.

I will now try Icesword

Please let me know what you think.

Kind Regards

Sean


RootRepeal.txt
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 25376786
RootRepeal doesn't show any malicious entries.

I'm not sure if someone has suggested CCleaner to clean the temp folders yet as I didn't read back the whole thread.
CCleaner:
http://www.ccleaner.com/download/



Here's the canned for IceSword:
Please download and unzip Icesword to its own folder on your desktop.

If you get a lot of "red entries" in an IceSword log, don't panic.

Step 1 : Close all windows and run IceSword. Click the Processes tab and watch for processes displayed in red color. A red colored process in this list indicates that it's hidden. Write down the PathName of any processes in red color. Then click on LOG at the top left. It will prompt you to save the log, call this Processes and save it to your desktop.

Step 2 : Click the Win32 Services tab and look out for red colored entries in the services list. Write down the Module name of any services in red color, you will need to expand out the Module tab to see the full name. Then click on LOG. It will prompt you to save the log, call this Services and save it to your desktop.

Step 3 : Click the Startup tab and look out for red colored entries in the startup list. Write down the Path of any startup entries in red color. Then click on LOG. It will prompt you to save the log, call this Startup and save it to your desktop.

Step 4 : Click the SSDT tab and check for red colored entries. If there are any, write down the KModule name.

Step 5 : Click the Message Hooks tab and check for any entries that are underneath Type and labelled WH_KEYBOARD. Write down the Process Path of these entries if present.

Plese post all of the data collected under the headings for :

Processes
Win32 Services
Startup
SSDT
Message Hooks




0
 

Author Comment

by:SeanPOBrien
ID: 25377021
Dear rpggamergirl

Please see report attached.

Regarding the message hook report I did not include all the file paths as they were all quite simimilar and well knows such as skype, firefox or hewlard pacard.

Kind Regards

Sean
Processes.log
Start-up.log
Services.log
SSDT----message-hook-report.doc
0
 

Author Comment

by:SeanPOBrien
ID: 25385584
Hi rpggamergirl

I don't have Adaware on my computer yet Spybot says I do, per my ealier message. What do you suggest?

I deleted Adaward, or did I not?

Thanks
Sean
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 25390492
Thanks for those logs..
The Message_hook report didn't show any keyloggers... those are all legit entries as well as the other logs.
It's possible that Spybot just mis-categorised something as keylogger.

Yes, as far as the Combofix and Hijackthis scans, Ad-Aware is still in the system... Look in Add/Remove Programs and uninstall it from there....or we can have Combofix delete all the files belonging to Ad-Aware if you like.
0
 

Author Comment

by:SeanPOBrien
ID: 25429284
Hi rpggamergirl,

I ran combofix again and I attach the log to see if Ad-aware is still there.

I looks like it is but I can't find it when I go into /Remove Programs.

What to do?

thanks

Sean
combofix-report-.txt
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 25429788
Okay, let's let Combofix remove Ad-Aware's folder, reg entry and service.

Run combofix again using this script.
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
------------------------------------------------------------------------

Folder::c:\program files\LavasoftDriver::Lavasoft Ad-Aware ServiceRegistry::[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
------------------------------------------------------------------------
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again and remove those.


0
 

Author Comment

by:SeanPOBrien
ID: 25433017
rpggamergirl:

Good day.

I have done that but not sure if I have successfully dragged the CFScript.txt into ComboFix.exe.

See report attached.

Kind Regards

Sean
combofix-report-.txt
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 25433077
Sean,

The log you just posted was the result of doubleclicking the Combofix.exe(not using the script), actually that is the same log as the one you posted before...ID:25429284

Please see the link below... it shows you the animation of the CFScript 'drag and drop' into the Combofix.exe... I hope that helps.
Scroll down to the middle of the page.
http://www.bleepingcomputer.com/forums/lofiversion/index.php/t167439.html
0
 

Author Comment

by:SeanPOBrien
ID: 25433743
rpggamergirl:

Hi downunder,

I think I'v got it this time.

See attached report.

I ran again AVG but as usual it still crases my computer before terminating, what next?

Thanks

Sean


combofix-report-.txt
0
 

Author Comment

by:SeanPOBrien
ID: 25434442
rpggamergirl:

I just ran spybot again, guess what, it says i still have Adaware!j

What to do?

Best

Sean
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 25436274
Sean,

I'm sorry, but the last 3 Combofix logs that you posted are all the same.. I mean they are all the same logs from the same scan, and not from running with the CFScript.

Did you look on that Bleepingcomputer link (with animation on "drag and drop" that I asked you?
Combofix is still not running with the CFScript.

Running from: c:\documents and settings\Sean\Desktop\ComboFix.exe <-- this line tells me that you run Combofix by doubleclicking on its .exe or running without the script.

Otherwise this line below should show instead(if it was running with the script):
Running from: C:\Documents and Settings\Sean\Desktop\CFscript.txt


Here's another way of running the script without the 'drag and drop' method.
CFScript.txt must already be on the desktop.

Click the Windows 'Start' button > Select 'Run' - then copy/paste this bolded text below into  the run box & click OK

ComboFix "C:\Documents and Settings\Sean\Desktop\CFscript.txt"

0
 

Author Comment

by:SeanPOBrien
ID: 25488521
Hello RPG game girl

Please check the attached, which I think worked this time.


I will now run sypbot.

Cheers

Sean
log-4-Oct-09-.txt
0
 

Author Comment

by:SeanPOBrien
ID: 25488811

Hello Again RPG game girl

When I start spybot I still  get the following message" If you have the AdAware option to scan inside archives enabled, AdAware may find files in the Spybot-S and D folder. Spybot does not contain any spyware, but it creates backups of everything you fix (until you remove these backups from the Recovery list), and AdAware complains about these backups. You can safely ignore these backups found by adaware."

What to do?

Cheers

Sean
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 25489058
Yes, you did it correctly this time....though my fault there is still a service and file belonging to lavasoft.
Combofix is also now expired you can either update it or just delete that copy and download a new one.

Then run this script below:

Run combofix again using this script.
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
------------------------------------------------------------------------

File::
c:\windows\system32\drivers\Lbd.sys  Driver::Lbd

------------------------------------------------------------------------
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.


0
 

Author Comment

by:SeanPOBrien
ID: 25489100
Hi RPG Game Girl,

Remember I had problems using the drag and drop method (failed three times already) and you suggested using the following method

"Here's another way of running the script without the 'drag and drop' method.
CFScript.txt must already be on the desktop.

Click the Windows 'Start' button > Select 'Run' - then copy/paste this bolded text below into  the run box & click OK

ComboFix "C:\Documents and Settings\Sean\Desktop\CFscript.txt""

Are you able to suggest the same again?

thanks

Sean
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 25489477
Sorry, yes, the same step applies, if 'drag and drop' isn't working, so long as the CFScript.txt and Combofix.exe are both located on the desktop.

ComboFix "C:\Documents and Settings\Sean\Desktop\CFscript.txt"
0
 

Author Comment

by:SeanPOBrien
ID: 25498665
Hello rpggamergirl:,

Please let me know what you think about the attached log.

In the meantime I will run spy bot again.

Cheers

sean
Combofix-log-5-Oct-09.txt
0
 
LVL 15

Expert Comment

by:f-king
ID: 25503672
Do you have Adware running on real time protection? or maybe spybot?
If so disable them and then see if you ge that error again.
0
 
LVL 15

Expert Comment

by:f-king
ID: 25503691
As the error says you can safely ignore that message ,what happens is that Adaware finds the backed up information that was deleted by Spybot.
0
 

Author Comment

by:SeanPOBrien
ID: 25507743
Hi F-king,

In answer to your first query, I did not think I had Adaware running any more at all.

Regarding your second response, then what you are saying is that I have nothing more to do. However I still have the problem that I started with which is that AVG has not in the last months successfully completed a scan it continuously gives the following message:

"The Scan log is corrupted (scan has not finished properly)" on top of that it appears as mentioned in previous messages  Spybot still can't get rid of  the the following, with regard to the Key loggers I have looked at these and there is  nothing malicious::
AdwareC.sbi
Malware. Sbi
MalwareC.sbi
PUPSC.sbi
Trojons.sbi
TorjansC.sbi
Dialer.sbi
DialerC.sbi
HeavyDuty.sib
Hijackers.sbi
HijackersC.sbi
Keyloggers.sbi
KeyloggersC.sii
Revision.sbi
Security.sbi
SecurityC.bi
Spybots.sib
Spyware.ssib
Tracks.uti

Any suggestions?

thanks

Sean
0
 
LVL 15

Expert Comment

by:f-king
ID: 25513247
Have you run the scans in Safe Mode?
0
 
LVL 15

Expert Comment

by:f-king
ID: 25513399
Have you also uninstalled AVG and installed the latest copy from free.grisoft.com?
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 25514513
Sorry if this has been asked before... is AVG and Spybot fully updated? maybe AVG got corrupted?.  you may need to reinstall it.

With regards to Spybot not getting rid of those malicious entries you listed, can you please take a screenshot of where Spybot are showing those entries it can't get rid of?

It's hard to believe that IceSword didn't detect a keylogger and Spybot does, it could be flagging something as keylogger when it isn't.



0
 

Author Comment

by:SeanPOBrien
ID: 25541601
rpggamergirl:,

Hi,

I have attached a scan of the print out from Spy bot.

I will uninstall AVG and reinstall.

thanks

sean
scan0001.jpg
0
 

Author Comment

by:SeanPOBrien
ID: 25541918
Hello,

I have now also uninstalled AVG and installed the latest copy from free.grisoft.com. I ran it in fast mode and guess what yes it crashed the computer.

I have not run any scans in safe mode, because I don't know how to do that can you help?

Kind Regards

Sean
0
 

Author Comment

by:SeanPOBrien
ID: 25542577
Hi,

One strange thing I noticed after running avg again (it still crashed the computer before finishing) is that even though I reinstalled it today, when I checked the  history, it still had it going back to April when AVG was installed for the first time after being reformatted.

Does that sugggest anything?

All the best

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25542626
Hi Sean,
Long post!
When your machine crashes, do you get a blue screen crash?

If so could you check C:\Windows\minidump and see if there is any *.dmp files.
If there is some could you upload the three latest *.dmp files here.

(to upload them here rename them from .dmp to .txt)
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 25545064
<<<"it still had it going back to April when AVG was installed for the first time after being reformatted.">>>

Usually some of the infos will still be there if you just reinstalled on top..... if you uninstalled maybe some files were still left behind.

That Spybot log that you attached doesn't look like the result of a Spybot scan.... that list of files and names of trojans/viruses/keylogger don't mean that they are present in the system by the look... They must be those that are included in that build(that build detects).
I noticed that your Spybot says version 1.4 whereas mine says version 1.6 so it looks like you still have the older version?

0
 

Author Comment

by:SeanPOBrien
ID: 25545592

optoma:

When the screen crashes No I don't get a blue screen.

rpggamergirl:

When I run spy bot I get the programs stops during the scanning process with the folloiwng message
There were problems in the include file C:/Program files/Spybot-Search Destroy/includes/AdwareC.sbi SeeIncludes errors.log for details.

Which is repeated again 5 times for the following :

Malware. Sbi
MalwareC.sbi
PUPSC.sbi
TorjansC.sbi
SpybotsC.sbi

Therefore you appear to be quite right regarding the others not ticked on the attached report which I'm not sure now after your challenge is in fact an errors log.
scan0002.jpg
0
 
LVL 47

Expert Comment

by:rpggamergirl
ID: 25545664

<<<"When I run spy bot I get the programs stops during the scanning process with the folloiwng message
There were problems in the include file C:/Program files/Spybot-Search Destroy/includes/AdwareC.sbi SeeIncludes errors.log for details
.">>>

Error like this is usually the result of updates that you have missed or partially installed. So make sure that Spybot has downloaded all updates.
If there is an update labelled Plugin you need to install it as this is an extension to the detection engine which provide new ways of detecting malware.

And Spybot scan shows, Congratulations!: No immediate threats were found:
0
 

Author Comment

by:SeanPOBrien
ID: 25545927
Thanks rpggamergirl:

Should i uninstall Spybot and reinstall it again?

There is no update labelled Plugin, the updates that are received do not allow any particular selection its like all or nothing.

KR

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25547331
Hello Sean,
Ok so no blue screen crash.

Is there anything relevant in event viewer , notably errors and warnings?

http://support.microsoft.com/kb/308427
0
 

Author Comment

by:SeanPOBrien
ID: 25553983
Dear Optoma,

See attached event log and tell me what to do.

thanks

Sean
Event-log.doc
0
 

Author Comment

by:SeanPOBrien
ID: 25554015
Hi Optoma, missed this one see below:

Event Type:      Failure Audit
Event Source:      Security
Event Category:      Policy Change
Event ID:      615
Date:            12/10/2009
Time:            18:11:29
User:            NT AUTHORITY\NETWORK SERVICE
Computer:      PC-HOME1
Description:
IPSec Services:       IPSec Services failed to get the complete list of network interfaces on the machine. This can be a potential security hazard to the machine since some of the network interfaces may not get the protection as desired by the applied IPSec filters. Please run IPSec monitor snap-in to further diagnose the problem.



For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
0
 
LVL 22

Expert Comment

by:optoma
ID: 25554510
Hello Sean,
Nothing major there from what i can see.

What you could try and do (only for test purposes), is to create another profile on that machine and see if the machine exhibits the same issue within that profile.
0
 

Author Comment

by:SeanPOBrien
ID: 25559872
Hi Optoma,

Did you also look at the log (SEE 3 MESSAGES UP)  I thought that there were a lot of Errors and Warnings?

And how do I create another profile?

thanks

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25562177
Hello Sean,
I looked at them all but nothing major from what i can see.

To create a new profile:
Hit Start,run and type nusrmgr.cpl
Hit ok.

Select "create new acount"
Call it test.

Run the avg scan in the Test account and see if it crashes
0
 

Author Comment

by:SeanPOBrien
ID: 25563558
Dear optoma,

Hey it did not crash

What next I'm impressed.

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25564350
Hi Sean,
Did you run the complete(slow) Avg scan in that test profile?
Also try running that active scan which you mentioned in your question.

 If both of those complete and you have been logged into the "test" profile for a long duration, compared to the other account which crashes after approx 2.5 hrs....... It may be the case that you have a corrupt profile.

0
 

Author Comment

by:SeanPOBrien
ID: 25583073
HI optoma:

I ran AVG in slow and Fast versions in the Test account both worked. I downloaded Active Scan from Panda Security but it would not run or open.

In the meantime I will run spy bot and see what happens

thanks

Sean



0
 

Author Comment

by:SeanPOBrien
ID: 25595664
HI optoma:

Spybot is running as before, so what is the next step?

Kind Regards

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25595823
Has the machine shut down on you at all in either your normal account or test account in the last few days, after some hours of usage?
0
 

Author Comment

by:SeanPOBrien
ID: 25606277
optoma:

Yesterday on both accounts I played videos from Youtube which  usually closes down the normal account quickly and yes it did but on the new Test account no problem kept going for hours and never crashed.

Looks like you might have found the problem, what next?

Cheers

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25608529
Hello Sean.
Firstly, Do you have any way of backing up your important data to a removable device(memory stick,external usb drive)?
If you dont, it would be wise to have some backup device :)
                               ...........................................................
What you have to do is transfer your data from the corrupted account(the one which shuts your machine down), into the "test" account
                                                              1
Below link is how to transfer your data from the corrupted (normal) account into the new "test" account.
http://support.microsoft.com/kb/811151

Read through it and any doubts on how to proceed let us know.

                                                             2
Regarding your emails:
What email client are you using?

                                                             3
You use Itunes:
If you get through "1" ok on your own, when you open Itunes in the (new) "test" account, Itunes will go through its initial setup........At this point in ITunes it will ask you to automatically add wma and mp3 from your PC--->Uncheck those options.
                             ............................................................

NB:Dont delete the old account yet!

See how you get on :)
0
 

Author Comment

by:SeanPOBrien
ID: 25652892
Hi Optoma,

In response to item 2 I am using Microsoft Outlook for emails.

Have not done anything else yet.

Thanks

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25653417
Hi Sean,
You can fire away with step 1.
Since everything is being copied and pasted and nothing is being deleted, all data will be there in two locations at the end.

Regarding outlook, what version are you running and do you know how to setup your email account(s) within outlook?
0
 

Author Comment

by:SeanPOBrien
ID: 25656248
Hi Optoma,

Regarding step 4 below please note that I could not find "    * Ntuser.ini"

4   Press and hold down the CTRL key while you click each file and subfolder in this folder, except the following files:

    * Ntuser.dat
    * Ntuser.dat.log
    * Ntuser.ini

In addition everything went well until I tried step 7 regarding the pasting which worked for a couple of seconds and then stopped due to a Kodak programme and then I checked an nothing seemed to be copies across. Do I need to do something with the Kodak application?

As regards to what version of outlook it is 2003.

Kind Regards

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25658425
Since you are not copying ntuser.ini, it dosn't matter

Try the copying procedure again but firstly look at the icons in the taskbar beside the time:is there a kodak icon?
If so right click on it and end/shut the kodak program down and try copying.


If that still dosn't work write down the exact error message about kodak
0
 

Author Comment

by:SeanPOBrien
ID: 25698938
Hi optoma:

I clicked on the icon for Kodak and closed it but it still did not work.

So the error message I am getting is the following:

"Cannot copy Cary it Easy.  Access denied make sure the disk is not full or write protected and that the file is not currently is use."

Waiting your instructions.

Thanks

sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25699249
Ok, a little bit more tricky:)
It won't let you copy some files or folders due to permissions.ie, the new account dosn't have permissions(rights) to some of those files.

Heres another link from microsoft, on how to take ownership:
http://support.microsoft.com/kb/308421
0
 

Author Comment

by:SeanPOBrien
ID: 25701244
HI Optoma,

These are the steps I followed:
"To start System Restore using the Command prompt, follow these steps:
1.      Restart your computer, and then press and hold F8 during the initial startup to start your computer in safe mode with a Command prompt.
2.      Use the arrow keys to select the Safe mode with a Command prompt option.
3.      If you are prompted to select an operating system, use the arrow keys to select the appropriate operating system for your computer, and then press ENTER.
4.      Log on as an administrator or with an account that has administrator credentials."

After step  4 when I logged on to the new Admministrator account in safe mode I got a black screen with the message: "C/docuuments and Settiings"  so I assume I need to type something after and press enter?

What do you suggest or should I just delete the programme Kodak and reinstall it. If so am I able to keep all the photos that are already saved on the computer?

Thanks

Sean



0
 
LVL 22

Expert Comment

by:optoma
ID: 25701330
Try tapping "f8" again and just enter "safe mode" and follow the instructions.
Disregard--> "304449   (http://support.microsoft.com/kb/304449/ )  How to start the System Restore tool at a command prompt in Windows XP "-->that bit!

There should't be a need to uninstall Kodak so leave it as it is..
0
How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

 
LVL 15

Expert Comment

by:f-king
ID: 25702069
See this question has been going on for about 4 months ,hope you get it solved.
0
 

Author Comment

by:SeanPOBrien
ID: 25708752
Thanks F-king,

To you this sounds like a long time and I agree. However on the positive side I'm not unhappy as at least my computer is still running. Whereas if  I had not have signed up with you I would have called in an expert by now.

0
 

Author Comment

by:SeanPOBrien
ID: 25708837
optoma:

I went into Safe mode change the and logged on to my account which has administrator credentials and changed the Security setting to myself. Then I restarted the computer went through the same steps again and got the same error message:

"Cannot copy Cary it Easy.  Access denied make sure the disk is not full or write protected and that the file is not currently is use."

By the way I did close the Kodak ICON in the source account (There are three accounts in total the Soruce acccouts my wife's/the corrupted account -mine/And the target account-Test) Should I have also closed the ICON in my account?

Thanks

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25708941
"cary it easy" What type of file is it?
Download unlocker and install it. On that file right click on it and select "unlocker".
The only action you want to take is to "unlock" the file-Not delete or move.
0
 

Author Comment

by:SeanPOBrien
ID: 25708942
Since going into Safe mode this morning i have now noticed that the Excel program is not responding. It open and then after one or two simple tasks it freezes?

What to do?

thanks as always

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25709005
Is this happening in the buggy profile? If so the problems are starting to extend more and more so.
It might be worth considering dropping the machine into a reputable repair shop and getting them to fix the machine. Sometimes, in these cases, its better to actually have the machine physically in front of you to work on.

Posting links on how to fix and amend certains issues can sometimes be complicated and "long winded"

If you do decide to drop it to a repair shop, they should be able to prevent any data loss since the data is on the machine and you are able to access it.
0
 

Author Comment

by:SeanPOBrien
ID: 25709109
thanks Optoma,

I note your comment but feel that I am now close to a solution finally and besides with all due respect does it not defeat the purpose of having you. I know it may be very frustrating for you, but from my perspective I have learned so much from you and going to the shop is really the last resort its like I have given up and is only an option when the computer does not work any more. So keep up the good work. In the past i use to do that and would have done so about 4 months ago if I did not have you. However they usually keep the computer for a week give it back to and after a few weeks still have the same problem. So I think if we can get this new profile set up we should be mostly there.

Carry it Easy is a programme which for the moment I have never used. It is on my usb memorty stick. (see manual attached)

Generally I work between two computers one at home, which is where the problem is and one in work and I use the memory stick as the master storage and use the computer for backing up the data from the stick.

I have done a search on my whole computer and can't find the programme.

Cheers


Password-Protection-User-Manual-.pdf
0
 

Author Comment

by:SeanPOBrien
ID: 25709152
PS Optoma- Excel is working normally again!
0
 
LVL 22

Expert Comment

by:optoma
ID: 25709775
Hi Sean,
Ill have a read through the manual and will get back to you. From what you're saying your important data is already backed up which is good!
Will reply soon!
0
 
LVL 22

Expert Comment

by:optoma
ID: 25710013
Ok could you run this program in the new profile that you are getting the error message when trying to copy.

Autoruns (dont make any changes within autoruns)
Autoruns http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx

Extract the files and run autoruns.exe
When it has finished scanning, hit CTRL+S and select save

The file saved will be called autoruns.arn
Upload that file here.

NB:In order to upload that file here, right click+ rename the original autoruns.arn file to autoruns.txt
0
 

Author Comment

by:SeanPOBrien
ID: 25713285
Hi Optoma,

Bad news the new Test account is no longer stable it crashed yesterday during an AVG run
and today again during normal use.

What to do now? I am a bit demotivated. By the way this computer is now 4 years old, is it time to replace it.

Thanks
Sean
0
 

Author Comment

by:SeanPOBrien
ID: 25713324
There seems to be another programe running on my computer since yeterday and I can't detect it in Task manager, what could it be.

Kind Regards

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25713336
Hi Sean, could you follow the autoruns instructions above. It will give us a clue!
Run autoruns in whatever account that the unknown program is in :)
0
 

Author Comment

by:SeanPOBrien
ID: 25714209
Hi Optoma,

Did you see my message from 11.59hrs today?

Cheers
Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25714323
Sorry Sean. Overlooked that post. Machine only 4years old so is fairly new. Test account acting up now to. It may look like a clean install but firstly upload that file :)
0
 

Author Comment

by:SeanPOBrien
ID: 25742401
Hi Optoma,

Can do anything now will revert on the weekend.

Thanks

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25744433
Hi Sean,
No probs. Still be here!
0
 

Author Comment

by:SeanPOBrien
ID: 25760397
Here you go Optoma,


AutoRuns.txt
0
 
LVL 22

Expert Comment

by:optoma
ID: 25764145
Thanks,
Could you search for this file first and upload it to these online scanners.
http://www.virustotal.com/
http://virusscan.jotti.org/en
Dont know what it is!

C:\Windows\System32\giveio.sys  <----??

0
 

Author Comment

by:SeanPOBrien
ID: 25765564
Hi Optomaa;

Uploaded it and both scans came up negative.

Where to next?

Cheers

sean
0
 

Author Comment

by:SeanPOBrien
ID: 25765568
Hi Optoma,

Uploaded it to both scans, ran it and came up with zero,

Where to next.

Cheers
sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25765600
Hi Sean,
Since the other account is also acting up it would probably be best to wipe the machine and install windows all over again.
All avenues have been tried and tested and all comes up good but you still have an issue which more than likely should be fixed with a clean install.

With a clean install everything is gone/wiped so you would have to make sure all your data,favourites,emails and email settings are backed up and triple check that you have all you need backed up!

What you also need is you xp installation cd and your office cd with the office product key and machines driver cd.

If you have all that you need to do this and feel confident enough have a read through this firstly and let me know first!
http://michaelstevenstech.com/cleanxpinstall.html
0
 
LVL 22

Expert Comment

by:optoma
ID: 25765603
Oh, be back later (work to get to!)
0
 

Author Comment

by:SeanPOBrien
ID: 25788068
Hi Optoma,

I don't have the original XP or office cd to reinstall what I have is a cd with a Ghost image that was made in Oct 05 when I first bought the computer and this was used earlier this year to reinstall those two items and numberous other applications. I must admit that I am a bit nervous to do this as last time it was done by an IT guy with plenty of experience. What do you advise.

cheers

sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 25790288
The last time that ghost image was used was earlier this year. Was it after using the image that your data was lost?
0
 

Author Comment

by:SeanPOBrien
ID: 25796874
Hi Optoma,

No. Before the reinstallation from the Ghost image the computer was closing down like it is currently and the IT guy took it away and reinstalled windows XP and office from the Ghost image. This worked again for a couple of months and then the computer reverted to its own habits. But nevertheless with all your assistance in the meantime I hav somehow managed to keep it alive.

Cheers

Sean

0
 
LVL 22

Expert Comment

by:optoma
ID: 25797540
Hi Sean,
Sometimes a ghost image could be buggy and may be causing the issue.
If there was anyway of doing a clean fresh install it may fix the issue but if you were to go down that road you need your xp + office cd for starters!

Generally, if a machine was going to be wiped and reinstalled from scratch, the IT Technician should be able to save all your created data and reinstall your office with your product key and your xp with its product key and along with some other programs if available through cds or downloads from the manufacturers website.

Your ghost image is from 05 so thats 4years ago. If that was used previously,with no data backup, all your data is gone and if used again, with no prior data backup, bye bye to your data ! :(
0
 
LVL 26

Expert Comment

by:PCBONEZ
ID: 25808325
It still looks to me like you have a few Nichicon HM scattered about including some in your VRM.
Those manufactured in 2001 through 2004 were defective.
Black can, white lettering, Y shaped vent, have HM(M) marked on them.

Nichicon HN series has the same problem.
Black can, gold lettering, Y shaped vent, have HN(M) marked on them.

Before the manufacturing error was known those caps were considered higher-end high quality and they were commonly used parts in -better- gear. They affected several hundred different motherboard models. At least a few models from everyone, including Apple/MAC and high-end server gear.

~
Asus also favors using OST caps which fail with no bloating or visual indication of a problem.

~
Bad caps. -> -> Excessive noise in power plane.

Excessive noise in power plane. -> -> Corrupted signals created by IC chips that get power from the affected plane.
[IC chips includes drive controllers, USB, the processor, the chipset, the RAM, LAN chips, - any IC.]

Corrupted signals. -> -> The IC that is being controlled by that signal won't work right.
Corrupted signals. -> -> If it is a data signal the data can be corrupted.
Corrupted signals. -> -> Good RAM can fail memtest because the signals to/from are full of noise.
Corrupted signals. -> -> Chipset corrupts data between RAM and CPU.
Corrupted signals. -> -> Files sent to HDD's can be corrupted en route to the drive.
Corrupted signals. -> -> BIOS instructions unreadable by the chip receiving the instructions.
Corrupted signals. -> -> If I think hard I could probably list 50 possible specific problems.
Depending on the cap it might only cause one of these problems or it might cause dozens.

Bad caps in the power supply can cause all these same problems.

~
I suggested taking a serious look at the caps 3 months ago and you still haven't.
What would it take? 30 minutes? An hour? - And then you'd KNOW if it's a possible problem.

.
0
 

Author Comment

by:SeanPOBrien
ID: 26034621
Hi PC Bonez,

Yes I will now have some time over Xmas and I will do that.

Optoma

In the meantime in previous messages you advised me to set up a Test Account. Can I now delete this to create more space on the computer?

thanks

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 26034834
Hi Sean,
Yeah no problem in deleting the test account as no data was copied to it. Was only for testing but the issue still happened.
0
 

Author Comment

by:SeanPOBrien
ID: 26035190
Over the last 6 months or so I downloaded a lot of programs to troubleshoot for various problems and now I don't have enough memory space.

What should I do?

Thanks

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 26035991
Your drive must be partitioned-split up.
Run xp disk cleanup + Atf cleaner to clear temp files http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25

See how much space you have after that
0
 

Author Comment

by:SeanPOBrien
ID: 26039744
Optoma,

Quite right the disk is spit in two. And now I have 25% free on my c drive, whereas before it was Zero.  The space was mainly created by compressing old files.

As mentioned earlier over the last 6 months or so I downloaded a lot of programs to troubleshoot for various problems should I not delete them and if so how do I now identify them?

Cheers

Sean

0
 
LVL 22

Expert Comment

by:optoma
ID: 26040369
Its up to yourself to remove them but they wouldn't take up much space.
In add/remove programs would list all programs installed on machine and show what size they are. Dont uninstall everything or anything!
0
 
LVL 26

Expert Comment

by:PCBONEZ
ID: 26041002
When you get one that's this freakin' nasty the best thing to do is remove the drive and connect it to another system with a USB adapter.
-- DON'T OPEN ANY FILES ON THE PROBLEM DRIVE!!!!!!
The run the anti-virus program from the host system on the problem drive.
-- WRITE EVERYTHING IT FINDS OR DOES DOWN!!!!!
-- WRITE EVERYTHING YOU DO DOWN!!!!!
-- And look up everything that comes up via google before you delete things.

The anti-virus and OS on the host PC won't be hindered by the nasty tricks the virus plays and can actually get to the bugger[s] to do something. [For example there won't be any "Cannot delete this file" garbage that way.]

[Why to write things down.]
You may have to replace some files that have been corrupted or replaced by the virus with 'clean' files from another system AFTER AFTER AFTER you get rid of all the problems.
You will need to know what you changed and what got deleted.

When you return it to the home system Run Combo-Fix again.
Then see if the anti-v and spybot will run and run them to catch any non-virus malware still hanging around.
[You may have to reinstall them.]
- Then do a repair install from a clean OS CD and redo all the MS Updates to fix any residual OS problems.

I've only had to go that far a few times [and I hate it] but some viruses are just THAT bad.
.
0
 

Expert Comment

by:Techservice
ID: 26107620
I agree with the previous comment. If this infection is that bad, then the best thing to do is reformat/reinstall.

Mount the Drive using an adapter, and pull the data that you need off of it.
     *******BE SURE TO SCAN THIS DATA THOROUGHLY FIRST

Completely reformat the drive and reinstall. My Suggestion is to make sure that you have the SP's and AV downloaded and accessible prior to reloading to avoid picking up MasterBlaster or other such nasties while reloading.

Going to this extent is very difficult and usually incurs it's own residual problems. As PCBonez very sufficiently illuminated, you would need to document ANYTHING/EVERYTHING done in order to ensure that you know what files may need to be replaced.

I still believe that if the system is acting as you have described, that there are hardware problems. If you have verified that Heat/PSU/CPU are not a problem, then it is probably either the MOBO or RAM.

Is it shutting down while you are looking at it?

If so, is it blue screening?

If so, have you tried to read the dump files using windebug?
0
 
LVL 1

Expert Comment

by:1UpTech
ID: 26376759
Hello Everyone,

Coming in new here there is a lot to comment on. A didn't read absolutely ever post in detail but I did look at most the files and I think I get the gist of it. Correct me if I'm wrong.

We come in with the original post thinking the problem is software related (Virus, Malware, Etc.) We perform multiple scans with various software. Run checks on the registry, startup locations and processes, etc... You do find something and remove it despite finding it was extremely difficult. The problem continues.

Between all of that we start looking at heating issues. Then to bad caps. So now we are on hardware issues. The bad caps theory was a pretty good one and even though the tops aren't bulging and they appear to be of good quality they could still be leaky. Unfortunately the only way to test is a real pain. Might as well just replace them if you have to test them.

Then the test profile works or seems to work. Then it doesn't. The even log's don't show any major issue. I've seen those errors on machines that work fine. I believe the machines that had those errors were also infected at one time.

Through all of this I haven't seen anyone suggest a BIOS update. Did I miss it that post perhaps? Is there even one available for this motherboard. Who offer support for the board? ASUS? Fujitsu? Computer Manufacturer?

Have you tried a BIOS update yet?
0
 

Author Comment

by:SeanPOBrien
ID: 26410687
Hi 1 uptech,

How do i do a BIOS update?

On my C drive I have a folder called Qoobox that takes up 25g of capacity (13G remaining on my C drive) and as I'm short of capacity I was wondering what purpose this file serves?

Thank
Sean
0
 
LVL 1

Expert Comment

by:1UpTech
ID: 26412206
Wow, that is a huge folder. That is supposed to be the quarantine folder for combofix. If you uninstall combo fix it should go away. You can uninstall combo fix by opening the run dialog box. Click start -> run and type the following; ComboFix /u . If combofix is installed it will be uninstalled and the folder should be removed. I am a bit confused though. From reading the previous threads it seemed like you were unable to find any infections. If that is true I don't understand why or how the Qoobox folder would be so large.

When you scanned your system with combofix and malwarebytes did your computer shutdown?

What about when you just do a file search. Click on start->search. All files and folders. Type *.dll in the top box and start searching. Let me know if your computer shuts down when doing a search.

I will follow up with flashing the BIOS after I get some things straight with this situation. Flashing the BIOS is something you don't want to do unless it is needed. As it looks everything else has been tried.
0
 
LVL 22

Expert Comment

by:optoma
ID: 26412254
Hi, i think it has been changed to:

combofix /uninstall
0
 

Author Comment

by:SeanPOBrien
ID: 26445829
Woh, I have just uninstalled combofix and gained 25g

thank you so much
0
 

Author Comment

by:SeanPOBrien
ID: 26447899
Hi 1UpTech

I have now deleted the  Qoobox folder and ran the AVG anti virus in slow mode overnight and it was clean.

I regularly scan the  system with malwarebytes and the computer  does not shutdown?

I did a file search using *.dll in the top box and found about 10000 items and the computer did not close.

I will now ask AVG to do a SCAN using the fast mode and see if it closes.
Thanks

Sean
0
 

Author Comment

by:SeanPOBrien
ID: 26448348
Yes after using AVG in fast mode after about 1 hour the computer crashed. So no change yet.
0
 
LVL 1

Expert Comment

by:1UpTech
ID: 26450349
I don't recall anyone instructing you to do turn off automatic restart on blue screen. Right click my computer either on your desktop or via start menu and select properties from the shortcut menu that appears. This will open system properties. Select the advanced tab and then click the settings button in the Startup and recovery section. Now uncheck automatically restart. Click Ok until you are all the way out in order to apply the settings. Perform the AVG scan again and let me know if you get a blue screen. If you do get a blue screen note the first set of numbers (0x0000007e) and post back.
0
 

Author Comment

by:SeanPOBrien
ID: 26508548
Hi 1UpTech:

Did all that still got No Blue screen.

Ran AVG today in slow mode and worked, but I know that computer will crash if I run it in Fast speed.

Thanks

Sean

0
 
LVL 1

Expert Comment

by:1UpTech
ID: 26517331
I was about to start with the BIOS update procedure but I just had an interesting thought. What external devices are plugged in to your computer when you perform a scan? e.g. Printer, scanner, memory card reader, usb flash drive, external storage device, etc....?

Check all of your usb ports, memory card ports, internal power supply connections and make sure that none of the wires are broke, touching, or disconnected when they should be connected.

This kind of problem will usually show it's symptom at other time besides scanning the hard drive but I'm just trying to exhaust all of our options before the BIOS update.
0
 

Author Comment

by:SeanPOBrien
ID: 26526904
Hi 1 UpTech,

Usually there is a printer/scanner and USB flash drive connected when I'm carrying out the scanning, but if it was a problem regading power supply why is it that when I leave AVG in slow mode scan the machine remains running for many hours 6 or 7, as soon as I hit the fast mode it will close the computer down in 1 to 2 hours. On top of that if it was a "short" then why would after the computer closing down by itself, would it immediately start up again.

Thanks for your help
0
 
LVL 1

Expert Comment

by:1UpTech
ID: 26527325
A short will usually keep a computer from coming on at all but in rare cases I've seen a short just cause mysterious problems. More specifically an issue with a usb port or memory card reader. When doing a fast scan more speed consumes more power.

Have you tried doing the scan without any other devices connected? Have you performed the fast mode scan while running windows in safe mode? If so did it shutdown?
0
 

Author Comment

by:SeanPOBrien
ID: 26532176
1Up Tech

I Have not tried doing the scan without any other devices connected, but I shall do it now. And I have not performed the fast mode scan while running windows in safe mode, I would not know how to do this?

Thanks

Sean
0
 
LVL 1

Expert Comment

by:1UpTech
ID: 26536731
Do the scan with out anything else connected first. If the computer still shuts down then try safe mode.

To enter safe mode.

From the off state turn on the computer. Now wait for video to display on the screen. If your computer beeps when it boots that's what we really want to wait for. But either way after you see video or after you hear the beep start tapping your F8 key. This will take you to what looks like a DOS screen with several options. Use your arrow keys on your keyboard to select safe mode and hit enter.

Please note that some motherboards use the F8 key for boot options. If this is your case then simply select Local Disk or Hard Drive press enter and then immediately start tapping the F8 key.

Once you get in to safe mode it's just like what you are use to with the exception of some major differences. First of all it's going to look weird because the Operating system is using a generic video driver. Some things will not run in safe mode. That last I checked, which was around AVG 6, AVG will run in safemode. The majority of your other hardware will not function properly and you can not install programs that use windows installer.

By using safe mode that will either eliminate your other hardware and/or drivers or confirm the other hardware and/or drivers as the problem.

Let us know how this goes.
0
 
LVL 1

Expert Comment

by:1UpTech
ID: 26573193
Hey Sean,

Did anything come of the previous suggestions? Have you ran any diagnostics on your hard drive?
0
 

Author Comment

by:SeanPOBrien
ID: 26610414
HI 1Up Tech,

Yes I ran the scan with everthing disconnected and yes the computer crashed as before.

In addition I ran it again in safe mode which took quite a long time serveral hours and in the the end it crashed also.

Re diagnostices , I usually do a Check Dist for errors and defragment but that all.

Cheers

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 26610961
Hi Sean,
Cant remember but the version of Avg>is it free version?
0
 

Author Comment

by:SeanPOBrien
ID: 26611000
Hi opoma,

Its the free edition and its version 9. By the way its not just AVG that crashes the computer, once the computer has been turned on for 2 hours, it closes. I think I may have mentioned this before.

Cheers

Sean
0
 
LVL 22

Expert Comment

by:optoma
ID: 26612813
Thanks Sean.
I also can't remember if Avg was uninstalled off machine completely and try a different AV product just to see if it makes a difference

http://download.avg.com/filedir/util/avg_arm_sup_____.dir/avgremover.exe

http://www.avast.com/free-antivirus-download
0
 
LVL 1

Expert Comment

by:1UpTech
ID: 26613309
Check disk isn't the most efficient in detecting hard drive errors. Let's figure out what brand hard drive you have and download a diagnostic tool from the manufacturer.

1. Open up system manager.
    a. right click my computer -> left click manage.

2. On the left side click device manager.
    a. Your devices will show up on the right side.

3. Get the manufacturer and model
     a. On the right side click the + sign beside Disk drives. Post back everything you see under disk drives.

Once we get that information I will post a link to download the diag tool from the manufacturer.

Also, just so that I'm clear that when you say the computer closes you mean the computer turns off correct? That means no lights on the tower. And does it come on by it self after this happens or do you have to turn it on your self?
0
 

Author Comment

by:SeanPOBrien
ID: 26678042
Manufactured and supported by Fujitsu Siemesns  Intel (R) Pentius (R) 4 CPU 3.40GHz 3.39 GHz 1.00GB Ram / MS Widows XP Version 2002 Service pack . I remember this question being asked earlier and check back up the thread between 12 July and 14 July and you will find what you are looking for.


Under Disk drives I saw:
Generic Storage Device USB device
 Generic Storage Device USB device
Generic Storage Device USB device
Generic Storage Device USB device
Generic Storage Device USB device
Samsung SP 2504C

Also, just so that I'm clear that when you say the computer closes you mean the computer turns off correct?  Yes it does  That means no lights on the tower. Yes  And does it come on by it self after this happens Yes it turns itself on automatically .

Thanks for your help
0
 
LVL 87

Expert Comment

by:rindi
ID: 26692223
I still think your system is overheating as some of us mentioned a lot earlier. That is most of the time the cause of such shutdowns. Make double sure that the CPU's heatsink is firmly attached (it must fit snuggly and tightly to the CPU) and the Fan is running smoothly. Some heatsinks can be difficult to mount properly. Also look at other heatsinks, like those on the chipset or the VGA card, You can apply the same procedures on those as for the CPU.

Or, another cause are bad caps like PCBONEZ mentioned, but he's the better expert for that than me.
0
 
LVL 1

Expert Comment

by:1UpTech
ID: 26822768
We explored both of those theories as they are the most likely but turned up nothing. All though just because we didn't see any capacitors leaking from the top or bulging they can still leak from below which would require motherboard removal for closer inspection.

Sean,

Do you know how to create a boot disk? Below is the link to download the diag software for Samsung drives. You need to burn a bootable CD and put the software on the disk. bootdisk.com will point you in the right direction.

http://www.samsung.com/us/consumer/office/hard-disk-drives/spinpoint-p-series/SP2504C/index.idx?pagetype=prd_detail&tab=support

 It is possible that it's not your processor that is over heating it could just as easily be a part of your chipset. That's the chips located underneath the black ASUS heatsinks. Have you tried replacing the cooling pads under those?

0
 
LVL 22

Expert Comment

by:senad
ID: 26856418
Get rid of AVG and get yourself a decent protection.
Try COMODO http://personalfirewall.comodo.com/
AVG IMHO is worse than an virus...
0
 
LVL 3

Expert Comment

by:prd00
ID: 27015666
Ok.. Sean.. I think I'll ask you some quick test..
First, try to grab GMER again, I will need you to clean it manually. DO NOT DO ANY SCAN. When GMER loaded, it will do initial scan.. Now tell me is there still a red flagged item? Any hidden application are red flagged.
http://www.gmer.net/

Second, do a quick memtest test. Download it here
http://hcidesign.com/memtest/download.html

Then get superpi to check computer stability
http://www.techpowerup.com/downloads/366/Super_PI_Mod_v1.5.html
0
 
LVL 6

Expert Comment

by:oneononecomp
ID: 27300432
I have just been alerted to your question and read the entire thread.  I give you credit for patience but I would have reformatted sometime last summer.  My first inclination was bad memory so please do run memtest but after that I would buy a new hard drive for $60 usd and install the os from a clean disk (not a Ghost image). Then move files over after the new os is fully patched and virus protected with A good paid AV program.
0
 

Author Comment

by:SeanPOBrien
ID: 27648299
Hi 1Uptech

Do you know how to create a boot disk? No

I have downloaded the diag software for Samsung drives and burned a bootable CD and put the software on the disk (See attached) Then I went on to  bootdisk.com looking for the right direction and I did not know where to start. Can you help?.

Thanks
Sean
0
 

Author Comment

by:SeanPOBrien
ID: 27648314
senad:

Regarding Getting  rid of AVG and and replacing it with COMODO http://personalfirewall.comodo.com/I
When you say AVG IMHO is worse than an virus..do yo mean the free version?

Thanks.
0
 
LVL 22

Expert Comment

by:senad
ID: 27648352
I mean even a payed one....I have really seen some 'weird' issues with AVG that
I honestly do not what to make of it.Once it kept blocking our card reader/writer
software busting balls it was a virus.Which was nonsense,of course.
Once it screwed internet connection so bad only windows reinstall was possible.
Once firewall blocked connections it took days to find this crap was behind it.Too many issues really....
The product comes from the Czech republic.
Comodo,on the other hand is the best firewall arround.Not much of an antivirus
(it detects many false positives) but at least it does not gnaw into the system like others.


0
 

Author Comment

by:SeanPOBrien
ID: 27648521
prd00:

HI I ran GMER again 3 times on the first tow ocassion it stalled and after about 20 minues of scanning.

And during that time no red flagges were found.

ON the 3rd ocassion the computer shut down with the following message" a problem has been detected and windows has been shut down to prevent damage to your computer. The problem sees to be caused by the folloiwng file: uwloapow.sys page_in_nonpaged_area.".

I will now close the computer and see if if restarts.

Thanks

Sean
0
 

Author Comment

by:SeanPOBrien
ID: 27649509
Hi Pdr00,

Well I restarted the computer and yes it does work again.

Were to from here?

Cheers

Sean
0
 
LVL 22

Expert Comment

by:senad
ID: 27649645
uwloapow.sys  ????
never heard of it .....
are you sure you spelled it right ?
0
 

Author Comment

by:SeanPOBrien