ComboFix 13-06-06.04 - Aneta 2013-06-07 11:31:28.1.2 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1250.48.1045.18.2047.1230 [GMT 2:00] Uruchomiony z: c:\users\Aneta\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Utworzono nowy punkt przywracania . . ((((((((((((((((((((((((((((((((((((((( Usunięto ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\security\Database\tmp.edb c:\windows\wininit.ini . . ((((((((((((((((((((((((( Pliki utworzone od 2013-05-07 do 2013-06-07 ))))))))))))))))))))))))))))))) . . 2013-06-07 09:36 . 2013-06-07 09:37 -------- d-----w- c:\users\Aneta\AppData\Local\temp 2013-06-07 09:36 . 2013-06-07 09:36 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-06-07 09:29 . 2013-06-07 09:29 60872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{39004FC6-E851-47F0-8EE0-0EF25FF24923}\offreg.dll 2013-05-24 08:05 . 2013-05-13 23:49 7016152 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{39004FC6-E851-47F0-8EE0-0EF25FF24923}\mpengine.dll 2013-05-24 08:01 . 2013-03-19 04:53 186368 ----a-w- c:\windows\system32\wwansvc.dll 2013-05-24 08:01 . 2013-04-10 03:14 2347520 ----a-w- c:\windows\system32\win32k.sys 2013-05-24 08:01 . 2013-03-19 03:33 40960 ----a-w- c:\windows\system32\wwanprotdim.dll 2013-05-24 08:01 . 2013-04-10 05:18 728424 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-05-24 08:01 . 2013-04-10 05:18 218984 ----a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-05-24 07:59 . 2013-02-27 05:05 101720 ----a-w- c:\windows\system32\consent.exe 2013-05-24 07:59 . 2013-02-27 04:49 1796096 ----a-w- c:\windows\system32\authui.dll 2013-05-24 07:59 . 2013-02-27 04:49 47104 ----a-w- c:\windows\system32\appinfo.dll 2013-05-10 20:34 . 2013-05-25 10:32 -------- d-----r- c:\users\Aneta\Podcasts 2013-05-10 20:34 . 2013-05-10 20:34 -------- d-----w- c:\windows\system32\drivers\UMDF\ko-KR 2013-05-10 20:34 . 2013-05-10 20:34 -------- d-----w- c:\windows\system32\drivers\UMDF\ms-MY 2013-05-10 20:34 . 2013-05-10 20:34 -------- d-----w- c:\windows\system32\drivers\UMDF\id-ID 2013-05-10 20:34 . 2013-05-10 20:34 -------- d-----w- c:\windows\system32\drivers\UMDF\sv-SE 2013-05-10 20:34 . 2013-05-10 20:34 -------- d-----w- c:\windows\system32\drivers\UMDF\nb-NO 2013-05-10 20:30 . 2013-05-10 20:34 -------- d-----w- c:\program files\Zune . . . (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-05-21 07:48 . 2012-12-01 11:38 37664 ----a-w- c:\windows\system32\drivers\avgtpx86.sys 2013-05-15 16:39 . 2012-10-30 23:47 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-05-15 16:39 . 2012-10-30 23:47 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-05-09 08:59 . 2013-04-05 10:42 368944 ----a-w- c:\windows\system32\drivers\aswSP.sys 2013-05-09 08:59 . 2013-04-05 10:42 61680 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-05-09 08:59 . 2013-04-05 10:42 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2013-05-09 08:59 . 2013-04-05 10:42 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2013-05-09 08:59 . 2013-04-05 10:42 174664 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-05-09 08:59 . 2013-04-05 10:41 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-05-09 08:59 . 2013-04-05 10:41 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-05-09 08:59 . 2013-04-05 10:42 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-05-09 08:58 . 2013-04-05 10:41 41664 ----a-w- c:\windows\avastSS.scr 2013-05-09 08:58 . 2013-04-05 10:41 229648 ----a-w- c:\windows\system32\aswBoot.exe 2013-05-02 00:06 . 2012-10-31 00:31 238872 ------w- c:\windows\system32\MpSigStub.exe 2013-04-13 04:45 . 2013-05-24 08:01 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-04-13 04:45 . 2013-05-24 08:01 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll 2013-04-12 13:45 . 2013-05-02 14:18 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys 2013-03-19 05:04 . 2013-04-14 20:47 3968856 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-03-19 05:04 . 2013-04-14 20:47 3913560 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-03-19 04:48 . 2013-04-14 20:47 38912 ----a-w- c:\windows\system32\csrsrv.dll 2013-03-19 02:49 . 2013-04-14 20:47 69632 ----a-w- c:\windows\system32\smss.exe 2013-03-15 22:13 . 2013-03-15 22:13 745472 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-03-15 22:13 . 2013-03-15 22:13 73728 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-03-15 22:13 . 2013-03-15 22:13 61952 ----a-w- c:\windows\system32\tdc.ocx 2013-03-15 22:13 . 2013-03-15 22:13 523264 ----a-w- c:\windows\system32\vbscript.dll 2013-03-15 22:13 . 2013-03-15 22:13 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-03-15 22:13 . 2013-03-15 22:13 38400 ----a-w- c:\windows\system32\imgutil.dll 2013-03-15 22:13 . 2013-03-15 22:13 185344 ----a-w- c:\windows\system32\elshyph.dll 2013-03-15 22:13 . 2013-03-15 22:13 158720 ----a-w- c:\windows\system32\msls31.dll 2013-03-15 22:13 . 2013-03-15 22:13 150528 ----a-w- c:\windows\system32\iexpress.exe 2013-03-15 22:13 . 2013-03-15 22:13 138752 ----a-w- c:\windows\system32\wextract.exe 2013-03-15 22:13 . 2013-03-15 22:13 137216 ----a-w- c:\windows\system32\ieUnatt.exe 2013-03-15 22:13 . 2013-03-15 22:13 12800 ----a-w- c:\windows\system32\mshta.exe 2013-03-15 22:13 . 2013-03-15 22:13 110592 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-03-15 22:13 . 2013-03-15 22:13 719360 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-03-15 22:13 . 2013-03-15 22:13 361984 ----a-w- c:\windows\system32\html.iec 2013-03-15 22:13 . 2013-03-15 22:13 23040 ----a-w- c:\windows\system32\licmgr10.dll 2013-03-15 22:13 . 2013-03-15 22:13 1441280 ----a-w- c:\windows\system32\inetcpl.cpl 2013-03-15 22:12 . 2013-03-15 22:12 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-03-15 22:12 . 2013-03-15 22:12 906240 ----a-w- c:\windows\system32\FntCache.dll 2013-03-15 22:12 . 2013-03-15 22:12 604160 ----a-w- c:\windows\system32\d3d10level9.dll 2013-03-15 22:12 . 2013-03-15 22:12 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-03-15 22:12 . 2013-03-15 22:12 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-03-15 22:12 . 2013-03-15 22:12 417792 ----a-w- c:\windows\system32\WMPhoto.dll 2013-03-15 22:12 . 2013-03-15 22:12 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-03-15 22:12 . 2013-03-15 22:12 364544 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2013-03-15 22:12 . 2013-03-15 22:12 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-03-15 22:12 . 2013-03-15 22:12 3419136 ----a-w- c:\windows\system32\d2d1.dll 2013-03-15 22:12 . 2013-03-15 22:12 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-03-15 22:12 . 2013-03-15 22:12 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-03-15 22:12 . 2013-03-15 22:12 293376 ----a-w- c:\windows\system32\dxgi.dll 2013-03-15 22:12 . 2013-03-15 22:12 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-03-15 22:12 . 2013-03-15 22:12 249856 ----a-w- c:\windows\system32\d3d10_1core.dll 2013-03-15 22:12 . 2013-03-15 22:12 2284544 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2013-03-15 22:12 . 2013-03-15 22:12 220160 ----a-w- c:\windows\system32\d3d10core.dll 2013-03-15 22:12 . 2013-03-15 22:12 207872 ----a-w- c:\windows\system32\WindowsCodecsExt.dll 2013-03-15 22:12 . 2013-03-15 22:12 1988096 ----a-w- c:\windows\system32\d3d10warp.dll 2013-03-15 22:12 . 2013-03-15 22:12 187392 ----a-w- c:\windows\system32\UIAnimation.dll 2013-03-15 22:12 . 2013-03-15 22:12 161792 ----a-w- c:\windows\system32\d3d10_1.dll 2013-03-15 22:12 . 2013-03-15 22:12 1504768 ----a-w- c:\windows\system32\d3d11.dll 2013-03-15 22:12 . 2013-03-15 22:12 1247744 ----a-w- c:\windows\system32\DWrite.dll 2013-03-15 22:12 . 2013-03-15 22:12 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll 2013-03-15 22:12 . 2013-03-15 22:12 1158144 ----a-w- c:\windows\system32\XpsPrint.dll 2013-03-15 22:12 . 2013-03-15 22:12 1080832 ----a-w- c:\windows\system32\d3d10.dll 2013-03-15 22:12 . 2013-03-15 22:12 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-05-19 11:17 . 2013-05-19 11:17 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ------- Sigcheck ------- Note: Unsigned files aren't necessarily malware. . [-] 2012-12-05 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7601.17514] . . c:\windows\System32\user32.dll [7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll [7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll . ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] 2013-05-21 07:48 1991344 ----a-w- c:\program files\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll" [2013-05-21 1991344] . [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1] [HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-09 08:58 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GGDriveOverlay1] @="{E68D0A50-3C40-4712-B90D-DCFA93FF2534}" [HKEY_CLASSES_ROOT\CLSID\{E68D0A50-3C40-4712-B90D-DCFA93FF2534}] 2012-06-05 09:41 1232896 ----a-w- c:\programdata\GG\ggdrive\ggdrive-overlay.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GGDriveOverlay2] @="{E68D0A51-3C40-4712-B90D-DCFA93FF2534}" [HKEY_CLASSES_ROOT\CLSID\{E68D0A51-3C40-4712-B90D-DCFA93FF2534}] 2012-06-05 09:41 1232896 ----a-w- c:\programdata\GG\ggdrive\ggdrive-overlay.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GGDriveOverlay3] @="{E68D0A52-3C40-4712-B90D-DCFA93FF2534}" [HKEY_CLASSES_ROOT\CLSID\{E68D0A52-3C40-4712-B90D-DCFA93FF2534}] 2012-06-05 09:41 1232896 ----a-w- c:\programdata\GG\ggdrive\ggdrive-overlay.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GGDriveOverlay4] @="{E68D0A53-3C40-4712-B90D-DCFA93FF2534}" [HKEY_CLASSES_ROOT\CLSID\{E68D0A53-3C40-4712-B90D-DCFA93FF2534}] 2012-06-05 09:41 1232896 ----a-w- c:\programdata\GG\ggdrive\ggdrive-overlay.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ALLUpdate"="c:\program files\ALLPlayer\ALLUpdate.exe" [2012-10-08 2991616] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2012-10-31 396152] "KSPlus"="c:\program files\Komputer Świat Plus\KSPlus.exe" [2013-04-03 44000456] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-10 61440] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2013-05-08 41056] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-05-26 1159168] "ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688] "vProt"="c:\program files\AVG Secure Search\vprot.exe" [2013-05-21 1226928] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 159456] "Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1425208] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2012-08-20 15576] R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2012-08-20 10200] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Usługa Technologie aktywacji systemu Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-12-05 1343400] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2013-05-21 37664] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-05-09 66336] S2 vToolbarUpdater15.2.0;vToolbarUpdater15.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe [2013-05-21 1015984] . . Zawartość folderu 'Zaplanowane zadania' . 2013-06-06 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-10-30 16:39] . . ------- Skan uzupełniający ------- . uStart Page = hxxp://www.onet.pl/ IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Wyślij &do programu OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 192.168.1.1 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll FF - ProfilePath - c:\users\Aneta\AppData\Roaming\Mozilla\Firefox\Profiles\thngthz9.default\ . - - - - USUNIĘTO PUSTE WPISY - - - - . URLSearchHooks-{d43723ae-1ae1-4a25-a6a4-bf0929273cab} - (no file) WebBrowser-{D43723AE-1AE1-4A25-A6A4-BF0929273CAB} - (no file) . . . --------------------- ZABLOKOWANE KLUCZE REJESTRU --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*] @="?????????????????? v1" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*1*\CLSID] @="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*] @="?????????????????? v2" . [HKEY_LOCAL_MACHINE\software\Classes\VideoLAN.VLCPlugin.*2*\CLSID] @="{9BE31822-FDAD-461B-AD51-BE1D1C159921}" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Czas ukończenia: 2013-06-07 11:39:01 ComboFix-quarantined-files.txt 2013-06-07 09:39 . Przed: 457 711 263 744 bajtów wolnych Po: 460 248 354 816 bajtów wolnych . - - End Of File - - 050B4E715B3B458E94CB74116F231A42 A36C5E4F47E84449FF07ED3517B43A31