¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan | g3n-h@ckm@n | Saachaa | 4.01.15.1 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ~ ¤¤¤¤¤ XP | Vista | 7 | 8 - 32/64 bits ¤¤¤¤¤ - Start 20:48:41 ~ Update on 15/01/2014 | 12.50 by g3n-h@ckm@n ~ Evolution : http://security-helpzone.com/gen-hackman/pre_scan-2/changelog/2013-2/ ~ Pre_Script Infos : http://security-helpzone.com/gen-hackman/pre_scan-2/les-switchs-pre_script/ ~ Pre_scan Feedbacks : http://security-helpzone.com/gen-hackman/pre_scan-2/retours-bugs/ ~ [Mallo (Administrator)] - [MA2LO] ~ SID = S-1-5-21-2104438034-2892279384-448854132-1008 ~ System : Microsoft Windows XP (32 bits) Service Pack 3 ~ ProcessorNameString : Intel(R) Celeron(R) M CPU 530 @ 1.73GHz ~ Identifier : x86 Family 6 Model 22 Stepping 1 ~ Memory RAM = Total (MB) : 1039 | Free (MB) : 695 ~ Pagefile = Total (MB) : 2497 | Free (MB) : 2237 ~ Virtual = Total (MB) : 2097 | Free (MB) : 2013 ¤¤¤¤¤¤¤¤¤¤ | Boot's scripts ¤¤¤¤¤¤¤¤¤¤ | Drives c:\-> [Fixed] | [HDD] | Total : 68320 Mo | Free : 48660 Mo -> NTFS ¤¤¤¤¤¤¤¤¤¤ | Windows Updates Next search : 2014-01-21 00:44:29 ¤¤¤¤¤¤¤¤¤¤ | Sessions ~ C:\WINDOWS\system32\config\systemprofile ~ C:\Documents and Settings\LocalService ~ C:\Documents and Settings\NetworkService ~ C:\Documents and Settings\Mallo ~ C:\Documents and Settings\Administrateur New restorepoint created : To restore the registry : C:\Pre_Scan\Save\Scan\ERDNT.exe Standby deleted ! ¤¤¤¤¤¤¤¤¤¤ | Browsers IE : 6.0.2900.5512 (© Microsoft Corporation.) FF : 26.0.0.5087 (©Firefox and Mozilla Developers; available under the MPL 2 license.) GC : 32.0.1700.76 (Copyright 2012 Google Inc.) ¤¤¤¤¤¤¤¤¤¤ | FlashPlayer FlashPlayer Plugin : 12.0.0.43 ¤¤¤¤¤¤¤¤¤¤ | Security AV : avast! Antivirus Disabled AS : FW : WINDOWS Firewall ¤¤¤¤¤¤¤¤¤¤ | stopped Processes 532 | C:\WINDOWS\system32\spoolsv.exe (.Microsoft Corporation - Spooler SubSystem App.) - (5.1.2600.5512) -> C:\WINDOWS\system32\spoolsv.exe 680 | C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (.Microsoft Corporation - .NET Runtime Optimization Service.) - (2.0.50727.1433) -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 960 | C:\Program Files\Java\jre7\bin\jqs.exe (.Oracle Corporation - Java Quick Starter Service.) - (10.51.2.13) -> "C:\Program Files\Java\jre7\bin\jqs.exe" -service -config "C:\Program Files\Java\jre7\lib\deploy\jqs\jqs.conf" 1432 | C:\Program Files\System Control Manager\edd.exe (. - .) - (0.0.0.0) -> "C:\Program Files\System Control Manager\edd.exe" 1484 | C:\Program Files\CyberLink\Shared Files\RichVideo.exe (. - RichVideo Module.) - (1.1.0.808) -> "C:\Program Files\CyberLink\Shared Files\RichVideo.exe" 1692 | c:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (.Sonic Solutions - RoxSniffer9 Module.) - (9.0.5.89) -> "c:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe" 588 | C:\WINDOWS\system32\wdfmgr.exe (.Microsoft Corporation - Windows User Mode Driver Manager.) - (5.2.3790.1230) -> C:\WINDOWS\system32\wdfmgr.exe 1984 | c:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (.Sonic Solutions - RoxMediaDB9 Module.) - (9.0.5.89) -> "c:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe" 2304 | C:\WINDOWS\System32\alg.exe (.Microsoft Corporation - Application Layer Gateway Service.) - (5.1.2600.5512) -> C:\WINDOWS\System32\alg.exe 4040 | C:\WINDOWS\Explorer.EXE (.Microsoft Corporation - Explorateur Windows.) - (6.0.2900.5512) -> C:\WINDOWS\Explorer.EXE 4020 | C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (.Synaptics, Inc. - Synaptics TouchPad Enhancements.) - (8.4.2.0) -> "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" 4092 | C:\Program Files\System Control Manager\MGSysCtrl.exe (.MSI - System Control Manager.) - (1.2.9.0) -> "C:\Program Files\System Control Manager\MGSysCtrl.exe" 368 | C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (.Sonic Solutions - RoxMMTrayApp Module.) - (9.0.5.89) -> "C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" 320 | C:\apps\PowerDVD\PDVDServ.exe (.Cyberlink Corp. - PowerDVD RC Service.) - (7.0.2406.0) -> "C:\apps\PowerDVD\PDVDServ.exe" 1988 | c:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe (.Sonic Solutions - ROXHelpRunner Module.) - (9.0.5.89) -> "c:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe" Local\{2456C119-A24C-4B59-A03E-4A530CDEEEF0} 3416 | C:\WINDOWS\RTHDCPL.EXE (.Realtek Semiconductor Corp. - Realtek HD Audio Control Panel.) - (2.4.2.2) -> "C:\WINDOWS\RTHDCPL.EXE" 3296 | C:\WINDOWS\system32\igfxtray.exe (.Intel Corporation - igfxTray Module.) - (6.14.10.5218) -> "C:\WINDOWS\system32\igfxtray.exe" 3432 | C:\WINDOWS\system32\hkcmd.exe (.Intel Corporation - hkcmd Module.) - (6.14.10.5218) -> "C:\WINDOWS\system32\hkcmd.exe" 3444 | C:\WINDOWS\system32\igfxpers.exe (.Intel Corporation - persistence Module.) - (6.14.10.5218) -> "C:\WINDOWS\system32\igfxpers.exe" 2840 | C:\WINDOWS\system32\igfxsrvc.exe (.Intel Corporation - igfxsrvc Module.) - (6.14.10.5218) -> C:\WINDOWS\system32\igfxsrvc.exe -Embedding 3528 | C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe (.Oracle Corporation - Java(TM) Update Scheduler.) - (2.1.9.8) -> "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe" 2636 | C:\Program Files\Mozilla Firefox\firefox.exe (.Mozilla Corporation - Firefox.) - (26.0.0.5087) -> "C:\Program Files\Mozilla Firefox\firefox.exe" 2540 | C:\Program Files\Mozilla Firefox\plugin-container.exe (.Mozilla Corporation - Plugin Container for Firefox.) - (26.0.0.5087) -> "C:\Program Files\Mozilla Firefox\plugin-container.exe" --channel=2636.95f6f00.1117101737 "C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll" -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" - 2636 "\\.\pipe\gecko-crash-server-pipe.2636" plugin 3140 | C:\WINDOWS\system32\wscntfy.exe (.Microsoft Corporation - Windows Security Center Notification App.) - (5.1.2600.5512) -> C:\WINDOWS\system32\wscntfy.exe 2488 | C:\WINDOWS\system32\wuauclt.exe (.Microsoft Corporation - Windows Update.) - (7.6.7600.256) -> "C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[544]SUSDSf5f7eb417bde23468ff150116c634b3a Boot : Normal ¤¤¤¤¤¤¤¤¤¤ | Running processes [18/08/2004 16:11:17] - 936 | C:\WINDOWS\System32\smss.exe (.Microsoft Corporation - Gestionnaire de session Windows NT.) - (5.1.2600.5512) -> \SystemRoot\System32\smss.exe [50688 Ko] [18/08/2004 16:10:40] - 988 | C:\WINDOWS\system32\csrss.exe (.Microsoft Corporation - Client Server Runtime Process.) - (5.1.2600.5512) -> C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16 [6144 Ko] [18/08/2004 16:11:27] - 1016 | C:\WINDOWS\system32\winlogon.exe (.Microsoft Corporation - Application d'ouverture de session Windows NT.) - (5.1.2600.5512) -> winlogon.exe [512000 Ko] [18/08/2004 16:11:15] - 1064 | C:\WINDOWS\system32\services.exe (.Microsoft Corporation - Applications Services et Contrôleur.) - (5.1.2600.5512) -> C:\WINDOWS\system32\services.exe [109056 Ko] [18/08/2004 16:10:57] - 1076 | C:\WINDOWS\system32\lsass.exe (.Microsoft Corporation - LSA Shell (Export Version).) - (5.1.2600.5512) -> C:\WINDOWS\system32\lsass.exe [13312 Ko] [18/08/2004 16:11:21] - 1244 | C:\WINDOWS\system32\svchost.exe (.Microsoft Corporation - Generic Host Process for Win32 Services.) - (5.1.2600.5512) -> C:\WINDOWS\system32\svchost -k DcomLaunch [14336 Ko] [18/08/2004 16:11:21] - 1308 | C:\WINDOWS\system32\svchost.exe (.Microsoft Corporation - Generic Host Process for Win32 Services.) - (5.1.2600.5512) -> C:\WINDOWS\system32\svchost -k rpcss [14336 Ko] [18/08/2004 16:11:21] - 1348 | C:\WINDOWS\System32\svchost.exe (.Microsoft Corporation - Generic Host Process for Win32 Services.) - (5.1.2600.5512) -> C:\WINDOWS\System32\svchost.exe -k netsvcs [14336 Ko] [18/08/2004 16:11:21] - 1492 | C:\WINDOWS\system32\svchost.exe (.Microsoft Corporation - Generic Host Process for Win32 Services.) - (5.1.2600.5512) -> C:\WINDOWS\system32\svchost.exe -k NetworkService [14336 Ko] [18/08/2004 16:11:21] - 1528 | C:\WINDOWS\system32\svchost.exe (.Microsoft Corporation - Generic Host Process for Win32 Services.) - (5.1.2600.5512) -> C:\WINDOWS\system32\svchost.exe -k LocalService [14336 Ko] [20/01/2014 00:56:29] - 1796 | C:\Program Files\AVAST Software\Avast\AvastSvc.exe (.AVAST Software - avast! Service.) - (9.0.2011.263) -> "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" [50344 Ko] [18/08/2004 16:11:21] - 2312 | C:\WINDOWS\System32\svchost.exe (.Microsoft Corporation - Generic Host Process for Win32 Services.) - (5.1.2600.5512) -> C:\WINDOWS\System32\svchost.exe -k HTTPFilter [14336 Ko] [20/01/2014 00:56:29] - 252 | C:\Program Files\AVAST Software\Avast\AvastUI.exe (.AVAST Software - avast! Antivirus.) - (9.0.2011.263) -> "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui [3764024 Ko] [18/08/2004 16:27:37] - 1712 | C:\WINDOWS\system32\wbem\wmiprvse.exe (.Microsoft Corporation - WMI.) - (5.1.2600.5512) -> C:\WINDOWS\system32\wbem\wmiprvse.exe [218112 Ko] [20/01/2014 20:43:53] - 3816 | C:\Documents and Settings\Mallo\Mes documents\Téléchargements\winlogon.exe (. - Pre_Scan.) - (4.1.15.1) -> "C:\Documents and Settings\Mallo\Mes documents\Téléchargements\winlogon.exe w,e" [2697728 Ko] [18/08/2004 16:29:46] - 3896 | C:\WINDOWS\system32\wuauclt.exe (.Microsoft Corporation - Windows Update.) - (7.6.7600.256) -> "C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[544]SUSDS01fb91ae4279154f824b02a4a4330a82 [53784 Ko] [18/08/2004 16:11:28] - 2140 | C:\WINDOWS\system32\wscntfy.exe (.Microsoft Corporation - Windows Security Center Notification App.) - (5.1.2600.5512) -> C:\WINDOWS\system32\wscntfy.exe [13824 Ko] [18/08/2004 16:27:37] - 3268 | C:\WINDOWS\system32\wbem\wmiprvse.exe (.Microsoft Corporation - WMI.) - (5.1.2600.5512) -> C:\WINDOWS\system32\wbem\wmiprvse.exe [218112 Ko] [18/08/2004 16:11:20] - 2780 | C:\WINDOWS\system32\spoolsv.exe (.Microsoft Corporation - Spooler SubSystem App.) - (5.1.2600.5512) -> C:\WINDOWS\system32\spoolsv.exe [57856 Ko] [24/10/2007 01:47:40] - 2796 | C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (.Microsoft Corporation - .NET Runtime Optimization Service.) - (2.0.50727.1433) -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [70144 Ko] ¤¤¤¤¤¤¤¤¤¤ | Winlogon User : OK ! ¤¤¤¤¤¤¤¤¤¤ | Winlogon Machine : OK ! Changed : [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]|[AutoRestartShell] : 1 -> 0 ¤¤¤¤¤¤¤¤¤¤ | Associations Repaired : [HKCR\InternetShortcut\shell\open\command] : rundll32.exe shdocvw.dll,OpenURL %l -> "C:\WINDOWS\System32\rundll32.exe" "C:\WINDOWS\System32\ieframe.dll",OpenURL %l Repaired : [HKCR\Application.Reference\shell\open\command] : rundll32.exe dfshim.dll,ShOpenVerbShortcut %1 -> rundll32.exe dfshim.dll,ShOpenVerbShortcut %1|%2 Repaired : [HKCR\Folder\shell\open\command] : %SystemRoot%\Explorer.exe /idlist,%I,%L -> C:\WINDOWS\Explorer.exe ¤ Repaired : [HKLM\Software\Clients\StartMenuInternet\IExplore.exe\shell\open\command] : "%programfiles%\Internet Explorer\iexplore.exe" -> "C:\Program Files\Internet Explorer\iexplore.exe" ¤¤¤¤¤¤¤¤¤¤ | Registry Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{20D04FE0-3AEA-1069-A2D8-08002B30309D}] : 1 -> 0 Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{208D2C60-3AEA-1069-A2D7-08002B30309D}] : 1 -> 0 Repaired : [HKU\S-1-5-21-2104438034-2892279384-448854132-1008\software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]|[Hidden] : 2 -> 0 ¤¤¤¤¤¤¤¤¤¤ | Taskmgr and Registry Access ¤¤¤¤¤¤¤¤¤¤ | SafeBoot | Control | Repair Safeboot Keys are O.K Alternate shell is OK ! ¤ Safeboot Minimal Subkeys : OK ! ¤ Safeboot Network Subkeys : O.K ! ¤¤¤¤¤¤¤¤¤¤ | IFEO ¤¤¤¤¤¤¤¤¤¤ | Mountpoints2 ¤¤¤¤¤¤¤¤¤¤ | Windows [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]|[Shell] : SYS:Microsoft\Windows NT\CurrentVersion\Winlogon [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini]|[winlogon] : SYS:Microsoft\Windows NT\CurrentVersion\Winlogon Winsrv : OK ! [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[AppInit_DLLS] : ¤¤¤¤¤¤¤¤¤¤ | Security Center ¤¤¤¤¤¤¤¤¤¤ | Services Corrections Repaired : [HKLM | Services\Parvdm] : 4 -> 2 Repaired : [HKLM | Services\agp440] : 0 -> 2 Repaired : [HKLM | Services\Browser] : 2 -> 3 Repaired : [HKLM | Services\Bits] : 3 -> 2 Repaired : [HKLM | Services\EapHost] : 3 -> 2 ¤¤¤¤¤¤¤¤¤¤ | Internet Explorer Repaired : [HKU\S-1-5-21-2104438034-2892279384-448854132-1008\Software\Microsoft\Internet Explorer\Main]|[Start Page] : http://fr.search.yahoo.com/?type=402027&fr=spigot-yhp-ie -> http://www.google.com/ Repaired : [HKLM\Software\Microsoft\Internet Explorer\Search]|[SearchAssistant] : http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> http://www.google.com/ie Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Start Page] : http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home -> http://go.microsoft.com/fwlink/?LinkId=69157 Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Local Page] : %SystemRoot%\system32\blank.htm -> C:\WINDOWS\system32\blank.htm Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Search_URL] : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> http://go.microsoft.com/fwlink/?LinkId=54896 Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Page_URL] : http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> http://go.microsoft.com/fwlink/?LinkId=69157 Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Search Page] : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> http://go.microsoft.com/fwlink/?LinkId=54896 ¤ Repaired : [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[MigrateProxy] : 0 -> 1 Repaired : [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[MigrateProxy] : 0 -> 1 Repaired : [HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[MigrateProxy] : 0 -> 1 Repaired : [HKU\S-1-5-21-2104438034-2892279384-448854132-1008\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[WarnonZoneCrossing] : 0 -> 1 ¤¤¤¤¤¤¤¤¤¤ | Hosts C:\WINDOWS\System32\Drivers\etc\hosts : Cleaned ¤¤¤¤¤¤¤¤¤¤ | reparsepoint ¤¤¤¤¤¤¤¤¤¤ | Offsets detection ¤¤¤¤¤¤¤¤¤¤ | Files | Folders | Registry Moved to quarantine successfully : C:\Recycler\S-1-5-21-324343713-762273870-2765037200-500\desktop.ini Moved to quarantine successfully : C:\Recycler\S-1-5-21-324343713-762273870-2765037200-500\INFO2 Moved to quarantine successfully : C:\Recycler\S-1-5-21-2104438034-2892279384-448854132-1008\Dc5.zip Moved to quarantine successfully : C:\Recycler\S-1-5-21-2104438034-2892279384-448854132-1008\Dc2.url Moved to quarantine successfully : C:\Recycler\S-1-5-21-2104438034-2892279384-448854132-1008\Dc6.txt Moved to quarantine successfully : C:\Recycler\S-1-5-21-2104438034-2892279384-448854132-1008\Dc4.mp3 Moved to quarantine successfully : C:\Recycler\S-1-5-21-2104438034-2892279384-448854132-1008\desktop.ini Moved to quarantine successfully : C:\Recycler\S-1-5-21-2104438034-2892279384-448854132-1008\Dc3 Moved to quarantine successfully : C:\Recycler\S-1-5-21-2104438034-2892279384-448854132-1008\INFO2 Removed : C:\Recycler\S-1-5-21-324343713-762273870-2765037200-500 Removed : C:\Recycler\S-1-5-21-2104438034-2892279384-448854132-1008 Moved to quarantine successfully : C:\WINDOWS\Tasks\Driver Booster Update.job Deleted : [HKLM\Software\Microsoft\Command Processor]|[AutoRun] : Moved to quarantine successfully : C:\Documents and Settings\Mallo\Local Settings\Application Data\fusioncache.dat Moved to quarantine successfully : C:\WINDOWS\System32\Config\SystemProfile\Local Settings\Application Data\fusioncache.dat Moved to quarantine successfully : C:\WINDOWS\assembly\tmp\ Moved to quarantine successfully : C:\Documents and Settings\Mallo\Application Data\Sun\Java\Deployment\cache\6.0 Moved to quarantine successfully : C:\Documents and Settings\Mallo\Local Settings\Application Data\Sun\Java\Deployment\cache\6.0 Moved to quarantine successfully : C:\Documents and Settings\Mallo\Local Settings\Application Data\Sun\Java\Deployment\cache\security Prefetch -> Emptied ¤¤¤¤¤¤¤¤¤¤ | Hidden files ~ [Drive C:] : Hidden : 4 | Restored : 4 ~ [Program Files] : Hidden : 2 | Restored : 2 ~ [Users] : Hidden : 2 | Restored : 2 ~ [Windows] : Hidden : 332 | Restored : 332 ~ [Libraries] : Hidden : 6 | Restored : 6 ¤¤¤¤¤¤¤¤¤¤ | Listing Partition(s) Disk: 0 Size= 76G Pos MBRndx Type/Name Size Active Hide Start Sector Sectors --- ------ ---------- ---- ------ ---- ------------ ------------ 0 0 1B-FAT32 8.0G No Yes 63 16,370,172 1 1 07-NTFS 68G Yes No 16,370,235 139,910,085 ¤¤¤¤¤¤¤¤¤¤ [HKLM | Winlogon] | AutoRestartShell : 0 -> 1 End : 20:54:04 Standby Restored ! ¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤ - 272