Help - Search - Members - Calendar
Full Version: Unable to get rid of malware
BleepingComputer.com > Security > HijackThis Logs and Virus/Trojan/Spyware/Malware Removal
Pages: 1, 2
   
Superhobbit
Hi Everyone, I really hope someone can point me in the right direction as I am going around in circles at the moment. I seem to have an assortment of different adware and malware on my PC. I have steadily worked through it and have got rid of most of it, but I still seem to be having some problems. I have run HJT and I think the "O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll" is definitely one of the problems, but I want to make sure before I do something irreversible.
I run MScofig at startup and I can not stop Mobsync.exe running. Every time I delete it from the registry it still comes back, is this a known problem? Or am I barking up the wrong tree? Thanks in advance for your help. dry.gif

Logfile of HijackThis v1.99.1
Scan saved at 11:41:13, on 07/03/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\Explorer.EXE
C:\All Downloads\Spyware\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SystemTray] systray.exe
O4 - HKLM\..\Run: [MSConfig] C:\Documents and Settings\paul\Desktop\msconfig.exe /auto
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [nvsvca32] C:\WINDOWS\nvsvca32.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - Global Startup: Sygate Personal Firewall.lnk = C:\Program Files\Sygate\SPF\Smc.exe
O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~1\Office\1033\phdintl.dll/phdContext.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion...ctor/WebAAS.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
Daisuke
REBOOT normally.

Some items are disabled in MSCONFIG, and not all your startup items are visible.
Go to Start -> Run -> Type msconfig and press Enter.

Click the Startup tab and check all Startup items or press the Enable All button and Close. Then press the Exit without restart button. Do not reboot your computer.


Please run HijackThis! in Normal Mode and post a new log.
Superhobbit
Thanks Daisuke, I have rebooted and run HJT again. Here is the full log.

Logfile of HijackThis v1.99.1
Scan saved at 13:13:31, on 09/03/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Microsoft Office\Office\OUTLOOK.EXE
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\All Downloads\Spyware\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer by Paul Browne
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SystemTray] systray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SystemTraySD] C:\WINDOWS\system32\StopItBlockItSystemTray.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Progra~1\REGSHAVE\REGSHAVE.EXE /autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [MsnExplorer] C:\WINDOWS\msexploren.exe /i
O4 - HKLM\..\Run: [MonitorSD] C:\WINDOWS\system32\SDMonitor.exe
O4 - HKLM\..\Run: [element furth] c:\windows\system32\vert\repcale.exe c:\windows\system32\vert\palsp.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O4 - Global Startup: Sygate Personal Firewall.lnk = C:\Program Files\Sygate\SPF\Smc.exe
O8 - Extra context menu item: Open Picture in &Microsoft PhotoDraw - res://C:\PROGRA~1\MICROS~1\Office\1033\phdintl.dll/phdContext.htm
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion...ctor/WebAAS.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

I appreciate your help
Daisuke
Hi smile.gif

Download System Security Suite here:
System Security Suite Download. Unzip it to your desktop. Install the program. Don't use it yet.

Please print or copy these instructions because you are not able to access the Internet in SafeMode.

Make sure you are set to show hidden files and folders:
A. On the Tools menu in Windows Explorer, click Folder Options.
B. Click the View tab.
C. Under Hidden files and folders, click Show hidden files and folders.
D. Uncheck Hide extensions for known filetypes and Hide protected operating system files.
How to see hidden files in Windows

REBOOT into SafeMode by tapping F8 key repeatedly at bootup: Starting your computer in Safe mode

Run HijackThis!, press Scan, and put a check mark next to all these:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm

O4 - HKLM\..\Run: [element furth] c:\windows\system32\vert\repcale.exe c:\windows\system32\vert\palsp.exe


Check this if you don't know what it is
O4 - HKLM\..\Run: [SystemTraySD] C:\WINDOWS\system32\StopItBlockItSystemTray.exe

Close all other windows and browsers, and press the Fix Checked button.

Search for these files and delete them if present:
Delete this file if you dn't know what it is
C:\WINDOWS\system32\StopItBlockItSystemTray.exe <-- this file

Delete these folders, if present:
c:\windows\system32\vert\ <-- this folder

With all windows and browsers closed.
Clean out temporary and Temporary Internet Files.
A. Open System Security Suite.
B. In the Items to Clear tab thick:
- Internet Explorer (left pane): Cookies & Temporary files
- My Computer (right pane): Temporary files & Recycle Bin
Press the Clear Selected Items button.
Close the program.

REBOOT normally.

Perform a full scan here: BitDefender Free Online Virus Scan
Follow the instructions on the screen.
Tick all the boxes on the left and let him remove anything it findes.

Run HijackThis! again and post a new log please.
Superhobbit
Thanks Daisuke,

I have done as you suggested and things seem a lot better. However after I have run several scans and set up sygate firewall, and reinstalled Norton Antivirus 2005 and the updates. I started getting spoolsv.exe running in the processes. Looking it up on the web Backdoor.ciadoor is mentioned. I can not stop it as access is denied. I rebooted and killed it through msconfig.

Is there someway of getting contorl of my pc back free of viruses and then set up the firewall and antivirus so they work properly. I have been battling this for a number of weeks now and every time I seem to get somewhere it starts off again. Norton antivirus does not seem to pick up any of the threats that the other utilities do. Are they giving false positives or is Norton useless?

I have run regedit repeatedly, but the information given on the web does not seem to be present on my machine. Am I being duped into scanning the wrong registry file. All I know is that I seem to keep having odd things happening. I can not run the icons in control panel directly, I have to make shortcuts. There is also no right click available on the icons. If I boot in safe mode they all work ok. My home page has just swopped to MSN again. Please, please suggest a way forward from this. I desperately need this machine to work properly. My thanks in advance for any suggestions.
Daisuke
spoolsv.exe could be a legitimate file. Post a hijackthis log please.
Superhobbit
Here is my latest HJT log. It seems that some of this is being reinstalled again.

Logfile of HijackThis v1.99.1
Scan saved at 17:11:43, on 11/03/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QUICKENW\QAGENT.EXE
C:\WINDOWS\system32\SDMonitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\All Downloads\Spyware\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer by Paul Browne
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] systray.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [MonitorSD] C:\WINDOWS\system32\SDMonitor.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Sygate Personal Firewall.lnk = C:\Program Files\Sygate\SPF\Smc.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion...ctor/WebAAS.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Thanks in advance for your help.
Daisuke
Do you know what this file does ?

C:\WINDOWS\system32\SDMonitor.exe <-- this file

Run HijackThis!, press Scan, and put a check mark next to all these:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

Close all other windows and browsers, and press the Fix Checked button.

REBOOT your machine and post a new log.
Superhobbit
Hi Daisuke,

C:\WINDOWS\system32\SDMonitor.exe

No, I don't know what it does. I thought it was to do with spybot, but checking on the web it doesn't seem to be. Should I delete it?

I have done as you said and this is my latest log.

Logfile of HijackThis v1.99.1
Scan saved at 00:36:04, on 12/03/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QUICKENW\QAGENT.EXE
C:\WINDOWS\system32\SDMonitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\All Downloads\Spyware\Hijackthis\HijackThis.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer by Paul Browne
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] systray.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [MonitorSD] C:\WINDOWS\system32\SDMonitor.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Sygate Personal Firewall.lnk = C:\Program Files\Sygate\SPF\Smc.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -

http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -

http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -

http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) -

http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -

http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) -

http://download.zonelabs.com/bin/promotion...ctor/WebAAS.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. -

C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton

AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton

AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

How am I doing?

Thanks for all your great help.
Daisuke
QUOTE
Should I delete it?

No, let's see what it is first. Submit it please here:
http://www.bleepingcomputer.com/submit-malware.php

Thank you
Superhobbit
Hi Daisuke,

I have submitted the file you asked for. I don't know what it is for. I hope this helps. My PC is operating a bit better, but spoolsv.exe is still running and there are some odd symptoms. Thanks for your help.
Daisuke
spoolsv.exe is a legitimate Microsoft file: Microsoft Printer Spooler Service.
It handles the printing process to your local printers.

Please search for a file

ProcessMonitorDll.dll <-- this file
and submit it here:
http://www.bleepingcomputer.com/submit-malware.php

Please submit also the full path. It is probably c:\Windows\system32
Superhobbit
Daisuke,

I know spoolsv.exe is a valid microsoft file, but looking on the web it also states that it can be used as a cover for the Ciadoor.121 virus.

Ref: http://www.auditmypc.com/process/spoolsv.asp

I would have thought I could terminate terminate the spoolsv process with an administrator account, but I can not. It says "The "operation could not be completed" "Access is denied".
This does not seem normal for a print spooler.

I have submitted the .dll you asked for. What do you think that file was doing?

Thanks again for all your help.
Daisuke
QUOTE
but looking on the web it also states that it can be used as a cover for the Ciadoor.121 virus.

Trust me smile.gif. You don't have the Ciadoor virus. Your file is in the right place and it is a Microsoft file. Search for it, right click on it and select Properties. Click the version tab. It is a MS file, isn't it smile.gif.

We are getting closer.

Run HijackThis!, press Scan, and put a check mark next to all these:

O4 - HKLM\..\Run: [MonitorSD] C:\WINDOWS\system32\SDMonitor.exe

Close all other windows and browsers, and press the Fix Checked button.

REBOOT your machine.

Search for this file:
SpywareDetector.dll <-- this file
and submit it here
http://www.bleepingcomputer.com/submit-malware.php

Also look for files installed in the system32 folder on the same date.
Click View menu in Windows Explorer --> click Details --> right click the details bar (right pane) and select Date Created. Click twice the Date Created column heading. Look for files created on the same date like the SpywareDetector.dll and ProcessMonitorDll.dll files. Submit these files too if present (zip them).

SDMonitor looks like a spyware detector. I think it's a rogue one. I found no information about these files. Could be something new.
Superhobbit
Hi Daisuke,

I have submitted all the files that you wanted. I can't see any more created on the same dates. I hope this is of use.

The problem that I see with spoolsv is that i can't terminate it and even if I try to stop it running on startup with msconfig it still runs. Doesn't seem right to me.

I have had an alert on Spy Sweeper that SDmonitor.exe is still running on startup, but this may be a false positive. On the plus side I tried to Liveupdate Norton antivirus 2005 and it downloaded a lot of updates. Maybe coincidence or perhaps not??
Daisuke
QUOTE
even if I try to stop it running on startup with msconfig it still runs

Stopping windows services with msconfig is not recommended. Also stopping a Windows service via TaskManager is almost impossible. If you have a printer don't touch spoolsv.exe in the system32 folder. The file is a Microsoft file and it is legitimate.

Disable temporarily SpySweeper. It can interfere with the fix.

The files are StopItBlockIt Spyware Remover software. A (brand new) rogue anti-spy program.
http://www.spywarewarrior.com/rogue_anti-spyware.htm
Try first to uninstall it from Add/Remove Programs.

REBOOT into safemode and delete these files:
SDMonitor.exe
StopItBlockItLiveUpdate.exe
SpywareDetector.dll
ProcessMonitorDll.dll
FileSignature.dll

BlockCookiesSD.ini
StopItBlockItCloseAll.exe
StopItBlockItSystemTray.exe
CookiesSD.ini
ProcAccess.ini
ProcessSpy.DB
spyremoverlog.txt
sysconfigSD.ini
sysspyDelSD.ini
sysspyInsSD.ini
sysspyUpdSD.ini
sysversionSD.ini
wormcounts.ini


Delete this folder if present:
c:\Program Files\StopItBlockIt Spyware Remover\

Run HijackThis!, press Scan, and put a check mark next to all these:

O4 - HKLM\..\Run: [MonitorSD] C:\WINDOWS\system32\SDMonitor.exe

Close all other windows and browsers, and press the Fix Checked button.

REBOOT normally and post a new hijackthis log.
Superhobbit
Thanks Daisuke,

Sorry about hte delay, I hadn't noticed the thread had gone onto another page.

I have done exactly as you said. Here is the up to date log.

Logfile of HijackThis v1.99.1
Scan saved at 14:28:07, on 16/03/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QUICKENW\QAGENT.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\All Downloads\Spyware\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer by Paul Browne
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] systray.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Sygate Personal Firewall.lnk = C:\Program Files\Sygate\SPF\Smc.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -

http://housecall-beta.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -

http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -

http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) -

http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -

http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) -

http://download.zonelabs.com/bin/promotion...ctor/WebAAS.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. -

C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton

AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton

AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Thanks in advance.
Daisuke
Log looks clean...great job ! smile.gif

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

How did I get infected ? With steps so it does not happen again !

Glad I was able to help.
Superhobbit
Thanks for all your help. Things are definitely a lot better.

There are still some odd symptoms though which are probably the aftermath and can hopefully be solved relatively easily. I would like to see what you think before I do anything.

I can select Start - Settings - Control Panel , but I can not double click on the icons. Nothing happens. There is also no right click menu.

Also on the desktop I can not move the icons manually even with Auto arrange not selected.

Are any of these things known to you? Have you got any suggestions as I definitely don't want to do anything drastic now I've got this far.

Thanks for any advice and for all your great help.
Daisuke
Try this first:

Go to Start --> Run, and type cmd in the Open box, then click OK to open a command prompt.
Type sfc /scannow, note the space after sfc.

Insert you original Windows CD in the CD-ROM drive. This will restore your protected system files on your computer.
Superhobbit
Hi Daisuke,

I ran sfc /scannow with the disc in. When I rebooted I found that I could not type in anything on the web. That meant I could not write to you or input anything. I could type in on word documents but nothing on line. I reinstalled windows 2000 Pro and SP4. This seems to have worked, but I still can not double click on control panel, I have to drag and drop the icon to the start menu. I can now move icons on the desktop though.
Is there a command to run the control panel from the command line?
Daisuke
QUOTE
but I still can not double click on control panel

I have no idea what the problem is. I'm investigating this.
Daisuke
Please take a look if Remote Procedure Call (RPC) service is started.

Go to Start -> Run and type Services.msc, then press the OK button. Look for a service called Remote Procedure Call (RPC). Double click on that service and press the Start button if the service is stopped, and then set the Startup type to Automatic. Press OK, and close all the windows.

Is the problem solved ?
Superhobbit
I have done as you asked. RPC was started and is set on automatic start. The problem has not changed. When I first boot and try to double click an icon I get a quick glimpse of the egg timer, and then it is gone. It is almost as though the control panel is a false one.
I can not move icons on the desktop even with auto arrange deselected. I can not double click files to run in explorer either. This is not stopping me using the computer, but it is seriously affecting its usability.
Daisuke
Did you try to create a new user ?
Superhobbit
Yes, I created a duplicate administrator account. Logged on with it and went to control panel. Control panel is displayed as a narrow left hand window with the icons. When the icons are double clicked they work!! I don't know why there is a right hand pane.

I also got a message about "Due to your active X settings some parts of this page may not display properly". Could it be Local settings for my Active X?

It does prove that something on my account has been changed.

I'd appreciate your views. Thanks.
Daisuke
QUOTE
Could it be Local settings for my Active X?

I think so.

Delete the content of this folder:
C:\WINDOWS\Downloaded Program Files <-- empty folder don't delete it.

Check your Internet Explorer settings:
A. Open Internet Explorer
B. Click Tools -> Internet Options ...
C. Click on the Advanced tab.
D. At the bottom of the window click the Restore Defaults button.

Click the Security tab
- click the Internet icon - press Default Level button
- click the Local icon - press Default Level button
- click the Trusted icon - press Default Level button
- Press the Sites button -> remove all the entries.
- click the Restricted icon- press Default Level button

Download eScan
Save it on your desktop and run mwav.exe
Check Drive
Select All Local Drives and Scan All Files
Click Scan and when it has finished, what was found will be displayed in the lower pane. Highlight it, press CTRL C and then paste it here.
Superhobbit
I did as you said. I have posted the log on the malware site as I could not paste it in.

Thanks for your help.
Superhobbit
Hi Daisuke,

I did as you said. I then ran Mwav and here is the results pane:-

Wed Mar 23 14:37:36 2005 => ***** Scanning complete. *****
Wed Mar 23 14:37:36 2005 => Total Files Scanned: 69587
Wed Mar 23 14:37:36 2005 => Total Virus(es) Found: 15
Wed Mar 23 14:37:36 2005 => Total Disinfected Files: 0
Wed Mar 23 14:37:36 2005 => Total Files Renamed: 0
Wed Mar 23 14:37:36 2005 => Total Deleted Files: 0
Wed Mar 23 14:37:36 2005 => Total Errors: 2
Wed Mar 23 14:37:36 2005 => Time Elapsed: 01:19:27
Wed Mar 23 14:37:36 2005 => Virus Database Date: 2005/03/22
Wed Mar 23 14:37:36 2005 => Virus Database Count: 122913

Wed Mar 23 14:37:36 2005 => Scan Completed.

C:\WINDOWS\system32\ctbv2.dll infected by "not-a-virus:AdWare.Sahat.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\NLNP!3.exe infected by "not-a-virus:AdWare.IGetNet" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\NLNP13.dll infected by "not-a-virus:AdWare.IGetNet" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\vf534.exe infected by "Trojan.WinREG.LowZones.f" Virus. Action Taken: No Action Taken.
File C:\All Downloads\iMesh\iMeshV3.exe infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken.
File C:\All Downloads\Spyware\Removal Tools\L2mfix\l2mfix.exe tagged as not-a-virus:RiskWare.Tool.Processor.20. No Action Taken.
File C:\WINDOWS\SYSTEM32\ctbv2.dll infected by "not-a-virus:AdWare.Sahat.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\NLNP!3.exe infected by "not-a-virus:AdWare.IGetNet" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\NLNP13.dll infected by "not-a-virus:AdWare.IGetNet" Virus. Action Taken: No Action Taken.

File C:\WINDOWS\SYSTEM32\vf534.exe infected by "Trojan.WinREG.LowZones.f" Virus. Action Taken: No Action Taken.
File D:\Paul Data\Programs\VNC\vnc-3.3.7-x86_win32.exe tagged as not-a-virus:RiskWare.RemoteAdmin.WinVNC-based.c. No Action Taken.
File C:\WINDOWS\SYSTEM32\ctbv2.dll infected by "not-a-virus:AdWare.Sahat.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\NLNP!3.exe infected by "not-a-virus:AdWare.IGetNet" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\NLNP13.dll infected by "not-a-virus:AdWare.IGetNet" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\vf534.exe infected by "Trojan.WinREG.LowZones.f" Virus. Action Taken: No Action Taken.

I am still getting odd things happening with web pages that previously worked. I t must be the above stuff.

Thanks for any advice.
Daisuke
Download KillBox here: KillBox. Unzip it to your desktop.

Start Killbox and click on Tools --> Select Delete Temp Files. Click OK.


Select the Delete on reboot option.

Copy and paste the following file to the field labeled "Full path of file to delete"
C:\WINDOWS\system32\ctbv2.dll

Press the Delete button (the button that looks like a red circle with a white X in it).

A first dialog box will ask if you want to delete the file on reboot, press the YES button.

A second dialog box will ask you if you want to REBOOT now. Press the NO button.

Repeat steps above for these files:

C:\WINDOWS\system32\NLNP!3.exe

C:\WINDOWS\system32\NLNP13.dll



Copy and paste the following file to the field labeled "Full path of file to delete"
C:\WINDOWS\system32\vf534.exe

Press the Delete button (the button that looks like a red circle with a white X in it).

A first dialog box will ask if you want to delete the file on reboot, press the YES button.

A second dialog box will ask you if you want to REBOOT now. Press the YES button.


Your computer will reboot.

Run HijackThis, and post the log please.
Superhobbit
I have done as you asked. Here's the log:-

Logfile of HijackThis v1.99.1
Scan saved at 20:00:28, on 23/03/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\system32\stisvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QUICKENW\QAGENT.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\All Downloads\Spyware\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer by Paul Browne
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\QUICKENW\QAGENT.EXE
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Sygate Personal Firewall.lnk = C:\Program Files\Sygate\SPF\Smc.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Hope this works!!
Daisuke
Copy the contents of the Quote Box below to Notepad.
Click File menu -> Save and name the file as Ucontrolpanel.bat
Change the Save as Type to All Files
Save this file on the desktop.

QUOTE
regedit.exe /e Ucontrolpanel.reg HKEY_CURRENT_USER\Control Panel


Double click the Ucontrolpanel.bat file and it will produce a REG file on your desktop --> Ucontrolpanel.reg

Right click on it and select Edit. Copy and paste the content in your reply.
Superhobbit
I did as you asked, but I can not save directly to the desktop so I moved the file dirctly into desktop in explorer. I then ran it, but it does not put a ucontrolpanel.reg on the desktop. I searched in explorer and there is no such file.

Am I missing a command?
Daisuke
You will find Ucontrolpanel.reg in the same folder where Ucontrolpanel.bat is. Doesn't matter wher you put Ucontrolpanel.bat.

Create a folder: c:\nothing, move the Ucontrolpanel.bat here and run it. You will find in the same folder the REG file smile.gif.
Superhobbit
I have done that but it still is not creating a .reg file anywhere??
Daisuke
Let's see if you can open the registry editor ...

Go to Start --> Run --> type regedit and press the OK button.

Please report back.
Superhobbit
Done it.
Superhobbit
The registry editor is open and running. What do you want me to do next?
Daisuke
sorry, I got no notification ohmy.gif

Navigate to this key: HKEY_CURRENT_USER\Control Panel <-- this key

right click on it and select Export. Name the file Ucontrolpanel and save it somewhere. Right click on it and select Edit. Copy and paste the content in your reply.
Superhobbit
There is no Export selection upon right clicking. Just "Collapse, New, Find, Delete, Rename, Copy key name". Is this normal or has the export selection been taken out?
Daisuke
On the Registry menu, click Save Key.
In the Save inbox, select a location in which to save the .reg file, type Ucontrolpanel in the File name box, and then click Save.
Superhobbit
This is the file I think:-

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Control Panel]

[HKEY_CURRENT_USER\Control Panel\Accessibility]

[HKEY_CURRENT_USER\Control Panel\Accessibility\Blind Access]
"On"="0"

[HKEY_CURRENT_USER\Control Panel\Accessibility\HighContrast]
"Flags"="126"
"High Contrast Scheme"="High Contrast Black (large)"

[HKEY_CURRENT_USER\Control Panel\Accessibility\Keyboard Preference]
"On"="0"

[HKEY_CURRENT_USER\Control Panel\Accessibility\Keyboard Response]
"AutoRepeatDelay"="1000"
"AutoRepeatRate"="500"
"BounceTime"="0"
"DelayBeforeAcceptance"="1000"
"Flags"="126"

[HKEY_CURRENT_USER\Control Panel\Accessibility\MouseKeys]
"Flags"="62"
"MaximumSpeed"="80"
"TimeToMaximumSpeed"="3000"

[HKEY_CURRENT_USER\Control Panel\Accessibility\ShowSounds]
"On"="0"

[HKEY_CURRENT_USER\Control Panel\Accessibility\SoundSentry]
"Flags"="2"
"FSTextEffect"="0"
"WindowsEffect"="1"

[HKEY_CURRENT_USER\Control Panel\Accessibility\StickyKeys]
"Flags"="510"

[HKEY_CURRENT_USER\Control Panel\Accessibility\TimeOut]
"Flags"="2"
"TimeToWait"="300000"

[HKEY_CURRENT_USER\Control Panel\Accessibility\ToggleKeys]
"Flags"="62"

[HKEY_CURRENT_USER\Control Panel\Appearance]
"CustomColors"=hex:ff,ff,ff,00,ff,ff,ff,00,ff,ff,ff,00,ff,ff,ff,00,ff,ff,ff,00,\
ff,ff,ff,00,ff,ff,ff,00,ff,ff,ff,00,ff,ff,ff,00,ff,ff,ff,00,ff,ff,ff,00,ff,\
ff,ff,00,ff,ff,ff,00,ff,ff,ff,00,ff,ff,ff,00,ff,ff,ff,00
"RecentFourCharsets"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00

[HKEY_CURRENT_USER\Control Panel\Appearance\Schemes]
"Brick"=hex:02,00,00,00,03,00,00,00,01,00,00,00,0d,00,00,00,0d,00,00,00,12,00,\
00,00,12,00,00,00,f4,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,bc,02,00,\
00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,f0,77,\
3f,00,3f,00,3f,00,3f,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,78,00,1c,\
10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,23,eb,77,0f,00,\
00,00,0f,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,\
00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,\
74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,\
00,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,00,14,00,12,00,\
00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,\
00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,\
74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,\
00,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,00,00,00,f5,ff,\
ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,\
00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,\
6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,\
00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,\
65,00,72,00,69,00,66,00,00,00,00,00,06,00,00,00,18,00,00,00,ff,ff,ff,ff,f0,\
4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,\
00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,\
00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,0c,10,00,01,e1,\
e0,d2,02,42,00,00,00,80,00,00,00,8d,89,61,00,c2,bf,a5,00,ff,ff,ff,00,00,00,\
00,02,00,00,00,00,00,00,00,00,e1,e0,d2,00,c2,bf,a5,00,c2,bf,a5,00,e1,e0,d2,\
00,8d,89,61,00,ff,ff,ff,00,c2,bf,a5,00,8d,89,61,02,8d,89,61,02,00,00,00,00,\
e1,e0,d2,00,e1,e0,d2,02,00,00,00,02,c2,bf,a5,02,80,00,00,00,e1,e0,d2,00,c0,\
c0,c0,00,80,00,00,02,b0,74,40,00,c8,b8,70,00
"Desert"=hex:02,00,00,00,03,00,00,00,01,00,00,00,0d,00,00,00,0d,00,00,00,12,00,\
00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,bc,02,00,\
00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,\
74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,\
00,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,23,eb,77,0f,00,\
00,00,0f,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,\
00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,\
74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,\
00,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,00,14,00,12,00,\
00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,\
00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,\
74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,\
00,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,00,00,00,f5,ff,\
ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,\
00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,\
6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,\
00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,\
65,00,72,00,69,00,66,00,00,00,00,00,06,00,00,00,18,00,00,00,ff,ff,ff,ff,f0,\
4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,\
00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,\
00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,0c,10,00,01,ea,\
e6,dd,02,a2,8d,68,02,00,80,80,00,a2,8d,68,00,d5,cc,bb,00,ff,ff,ff,02,00,00,\
00,02,00,00,00,00,00,00,00,00,ff,ff,ff,00,d5,cc,bb,02,d5,cc,bb,02,a2,8d,68,\
02,00,80,80,00,ff,ff,ff,00,d5,cc,bb,02,a2,8d,68,02,a2,8d,68,02,00,00,00,02,\
ff,ff,ff,00,ea,e6,dd,02,00,00,00,02,d5,cc,bb,02,00,00,00,00,ff,ff,ff,00,c0,\
c0,c0,00,00,80,80,02,84,bd,aa,00,e8,d0,80,00
"Eggplant"=hex:02,00,00,00,03,00,00,00,01,00,00,00,10,00,00,00,10,00,00,00,13,\
00,00,00,13,00,00,00,f1,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,bc,02,\
00,00,00,00,00,00,00,00,00,00,54,00,69,00,6d,00,65,00,73,00,20,00,4e,00,65,\
00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,00,00,00,00,78,00,\
1c,10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,23,eb,77,11,\
00,00,00,11,00,00,00,f3,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,bc,02,\
00,00,00,00,00,00,00,00,00,00,54,00,69,00,6d,00,65,00,73,00,20,00,4e,00,65,\
00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,00,00,00,20,14,00,\
ac,b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,00,14,00,12,\
00,00,00,12,00,00,00,f3,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,\
00,00,00,00,00,00,00,00,00,00,54,00,69,00,6d,00,65,00,73,00,20,00,4e,00,65,\
00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,00,00,00,00,00,00,\
80,05,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,00,00,00,f3,\
ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,\
00,00,54,00,69,00,6d,00,65,00,73,00,20,00,4e,00,65,00,77,00,20,00,52,00,6f,\
00,6d,00,61,00,6e,00,00,00,b4,c0,f0,77,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f3,ff,ff,ff,00,00,00,00,00,\
00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,69,00,6d,00,\
65,00,73,00,20,00,4e,00,65,00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,\
00,c8,0b,00,00,00,00,00,00,08,00,00,00,06,00,00,00,18,00,00,00,ff,ff,ff,ff,\
f0,4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,\
01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,\
66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,\
00,00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,0c,10,00,01,\
90,b0,a8,02,40,00,40,00,58,80,78,00,90,b0,a8,00,90,b0,a8,00,ff,ff,ff,02,00,\
00,00,02,00,00,00,00,00,00,00,00,ff,ff,ff,00,90,b0,a8,02,90,b0,a8,02,80,80,\
80,02,58,80,78,00,ff,ff,ff,00,90,b0,a8,02,58,80,78,02,58,80,78,02,00,00,00,\
02,58,80,78,00,c8,d8,d8,02,00,00,00,02,90,b0,a8,02,80,00,80,00,ff,ff,ff,00,\
c0,c0,c0,00,58,80,78,02,83,4b,83,00,cb,bd,d2,00
"High Contrast #1"=hex:02,00,00,00,46,00,00,00,01,00,00,00,11,00,00,00,11,00,\
00,00,14,00,00,00,14,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,\
00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,\
00,66,00,00,00,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,23,\
eb,77,0f,00,00,00,0f,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,\
00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,\
00,66,00,00,00,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,00,\
14,00,12,00,00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,\
00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,\
00,66,00,00,00,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,00,\
00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,\
00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,\
53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f5,ff,ff,ff,00,00,\
00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,\
00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,\
20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,06,00,00,00,18,00,00,00,ff,\
ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,\
00,00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,\
00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,\
69,00,66,00,00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,0c,\
10,00,01,00,00,00,02,00,00,00,02,00,00,ff,00,00,ff,ff,00,00,00,00,00,00,00,\
00,02,ff,ff,ff,02,ff,ff,ff,00,ff,ff,00,00,ff,ff,ff,00,00,00,ff,00,00,ff,ff,\
00,00,00,00,02,00,80,00,00,ff,ff,ff,00,00,00,00,02,80,80,80,02,00,ff,00,02,\
ff,ff,ff,02,00,00,00,00,c0,c0,c0,02,ff,ff,ff,02,ff,ff,ff,02,ff,ff,00,00,00,\
00,00,00,c0,c0,c0,00,80,00,80,02,00,00,ff,00,00,ff,ff,00
"High Contrast #1 (extra large)"=hex:02,00,00,00,46,00,00,00,06,00,00,00,20,00,\
00,00,20,00,00,00,26,00,00,00,26,00,00,00,e1,ff,ff,ff,00,00,00,00,00,00,00,\
00,00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,\
6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,\
00,00,00,00,00,78,00,1c,10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,\
00,00,98,23,eb,77,1d,00,00,00,1d,00,00,00,e9,ff,ff,ff,00,00,00,00,00,00,00,\
00,00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,\
6d,00,61,00,00,00,6c,00,61,00,63,00,6b,00,00,00,66,00,00,00,6e,00,00,00,00,\
00,00,00,00,20,14,00,ac,b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,\
14,00,00,00,14,00,26,00,00,00,26,00,00,00,e1,ff,ff,ff,00,00,00,00,00,00,00,\
00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,\
6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,\
00,00,00,00,00,00,00,80,05,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,\
00,00,20,00,00,00,e9,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,\
00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,\
53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,b4,c0,f0,77,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,e1,ff,\
ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,\
00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,\
66,00,00,00,6e,00,00,00,c8,0b,00,00,00,00,00,00,08,00,00,00,06,00,00,00,18,\
00,00,00,ff,ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,e9,ff,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,\
00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,c0,1d,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,\
fe,12,00,0c,10,00,01,00,00,00,02,00,00,00,02,00,00,ff,00,00,ff,ff,00,00,00,\
00,00,00,00,00,02,ff,ff,ff,02,ff,ff,ff,00,ff,ff,00,00,ff,ff,ff,00,00,00,ff,\
00,00,ff,ff,00,00,00,00,02,00,80,00,00,ff,ff,ff,00,00,00,00,02,80,80,80,02,\
00,ff,00,02,ff,ff,ff,02,00,00,00,00,c0,c0,c0,02,ff,ff,ff,02,ff,ff,ff,02,ff,\
ff,00,00,00,00,00,00,c0,c0,c0,00,80,00,80,02,00,00,ff,00,00,ff,ff,00
"High Contrast #1 (large)"=hex:02,00,00,00,46,00,00,00,06,00,00,00,1c,00,00,00,\
1c,00,00,00,1f,00,00,00,1f,00,00,00,e8,ff,ff,ff,00,00,00,00,00,00,00,00,00,\
00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,\
61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,00,00,\
00,00,00,78,00,1c,10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,\
98,23,eb,77,1a,00,00,00,1a,00,00,00,ec,ff,ff,ff,00,00,00,00,00,00,00,00,00,\
00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,\
61,00,00,00,6c,00,61,00,63,00,6b,00,00,00,66,00,00,00,6e,00,00,00,00,00,00,\
00,00,20,14,00,ac,b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,\
00,00,14,00,1e,00,00,00,1e,00,00,00,e8,ff,ff,ff,00,00,00,00,00,00,00,00,00,\
00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,\
61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,00,00,\
00,00,00,00,00,80,05,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,\
20,00,00,00,ec,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,\
00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,6c,00,61,00,\
63,00,6b,00,00,00,66,00,00,00,6e,00,00,00,b4,c0,f0,77,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,e8,ff,ff,ff,\
00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,\
00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,\
00,00,6e,00,00,00,c8,0b,00,00,00,00,00,00,08,00,00,00,06,00,00,00,18,00,00,\
00,ff,ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,ec,ff,ff,ff,00,00,00,00,00,00,00,00,\
00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,\
00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,c0,1d,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,\
00,0c,10,00,01,00,00,00,02,00,00,00,02,00,00,ff,00,00,ff,ff,00,00,00,00,00,\
00,00,00,02,ff,ff,ff,02,ff,ff,ff,00,ff,ff,00,00,ff,ff,ff,00,00,00,ff,00,00,\
ff,ff,00,00,00,00,02,00,80,00,00,ff,ff,ff,00,00,00,00,02,80,80,80,02,00,ff,\
00,02,ff,ff,ff,02,00,00,00,00,c0,c0,c0,02,ff,ff,ff,02,ff,ff,ff,02,ff,ff,00,\
00,00,00,00,00,c0,c0,c0,00,80,00,80,02,00,00,ff,00,00,ff,ff,00
"High Contrast #2"=hex:02,00,00,00,46,00,00,00,01,00,00,00,11,00,00,00,11,00,\
00,00,14,00,00,00,14,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,\
00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,\
00,66,00,00,00,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,23,\
eb,77,0f,00,00,00,0f,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,\
00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,\
00,66,00,00,00,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,00,\
14,00,12,00,00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,\
00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,\
00,66,00,00,00,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,00,\
00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,\
00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,\
53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f5,ff,ff,ff,00,00,\
00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,\
00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,\
20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,06,00,00,00,18,00,00,00,ff,\
ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,\
00,00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,\
00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,\
69,00,66,00,00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,0c,\
10,00,01,00,00,00,02,00,00,00,02,00,ff,ff,00,00,00,ff,00,00,00,00,00,00,00,\
00,02,ff,ff,ff,02,00,ff,00,00,00,ff,00,00,00,00,00,00,00,ff,ff,00,00,00,ff,\
00,ff,ff,ff,00,00,00,ff,00,ff,ff,ff,00,00,00,00,02,80,80,80,02,00,ff,00,02,\
00,ff,00,00,ff,ff,ff,00,c0,c0,c0,02,ff,ff,ff,02,ff,ff,ff,02,00,00,00,00,ff,\
ff,00,00,c0,c0,c0,00,80,00,80,02,00,ff,ff,00,00,00,ff,00
"High Contrast #2 (extra large)"=hex:02,00,00,00,46,00,00,00,06,00,00,00,20,00,\
00,00,20,00,00,00,26,00,00,00,26,00,00,00,e1,ff,ff,ff,00,00,00,00,00,00,00,\
00,00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,\
6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,\
00,00,00,00,00,78,00,1c,10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,\
00,00,98,23,eb,77,1c,00,00,00,1c,00,00,00,e9,ff,ff,ff,00,00,00,00,00,00,00,\
00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,\
6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,\
00,00,00,00,20,14,00,ac,b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,\
14,00,00,00,14,00,26,00,00,00,26,00,00,00,e1,ff,ff,ff,00,00,00,00,00,00,00,\
00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,\
6d,00,61,00,00,00,6c,00,61,00,63,00,6b,00,00,00,66,00,00,00,6e,00,00,00,00,\
00,00,00,00,00,00,00,80,05,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,\
00,00,20,00,00,00,e9,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,\
00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,\
53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,b4,c0,f0,77,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,e1,ff,\
ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,\
00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,\
66,00,00,00,6e,00,00,00,c8,0b,00,00,00,00,00,00,08,00,00,00,06,00,00,00,18,\
00,00,00,ff,ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,e9,ff,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,\
00,6d,00,61,00,00,00,6c,00,61,00,63,00,6b,00,00,00,00,00,74,00,79,00,6c,00,\
65,00,00,00,6f,00,6b,00,00,00,43,00,6f,00,6e,00,64,00,00,00,64,00,00,00,c0,\
fe,12,00,0c,10,00,01,00,00,00,02,00,00,00,02,00,ff,ff,00,00,00,ff,00,00,00,\
00,00,00,00,00,02,ff,ff,ff,02,00,ff,00,00,00,ff,00,00,00,00,00,00,00,ff,ff,\
00,00,00,ff,00,ff,ff,ff,00,00,00,ff,00,ff,ff,ff,00,00,00,00,02,80,80,80,02,\
00,ff,00,02,00,ff,00,00,ff,ff,ff,00,c0,c0,c0,02,ff,ff,ff,02,ff,ff,ff,02,00,\
00,00,00,ff,ff,00,00,c0,c0,c0,00,80,00,80,02,00,ff,ff,00,00,00,ff,00
"High Contrast #2 (large)"=hex:02,00,00,00,46,00,00,00,06,00,00,00,1c,00,00,00,\
1c,00,00,00,1f,00,00,00,1f,00,00,00,e8,ff,ff,ff,00,00,00,00,00,00,00,00,00,\
00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,\
61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,00,00,\
00,00,00,78,00,1c,10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,\
98,23,eb,77,1a,00,00,00,1a,00,00,00,ec,ff,ff,ff,00,00,00,00,00,00,00,00,00,\
00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,\
61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,00,00,\
00,00,20,14,00,ac,b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,\
00,00,14,00,1e,00,00,00,1e,00,00,00,e8,ff,ff,ff,00,00,00,00,00,00,00,00,00,\
00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,\
61,00,00,00,6c,00,61,00,63,00,6b,00,00,00,66,00,00,00,6e,00,00,00,00,00,00,\
00,00,00,00,00,80,05,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,\
20,00,00,00,ec,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,\
00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,\
65,00,72,00,69,00,66,00,00,00,6e,00,00,00,b4,c0,f0,77,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,e8,ff,ff,ff,\
00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,\
00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,\
00,00,6e,00,00,00,c8,0b,00,00,00,00,00,00,08,00,00,00,06,00,00,00,18,00,00,\
00,ff,ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,ec,ff,ff,ff,00,00,00,00,00,00,00,00,\
00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,\
00,61,00,00,00,6c,00,61,00,63,00,6b,00,00,00,00,00,74,00,79,00,6c,00,65,00,\
00,00,6f,00,6b,00,00,00,43,00,6f,00,6e,00,64,00,00,00,64,00,00,00,c0,fe,12,\
00,0c,10,00,01,00,00,00,02,00,00,00,02,00,ff,ff,00,00,00,ff,00,00,00,00,00,\
00,00,00,02,ff,ff,ff,02,00,ff,00,00,00,ff,00,00,00,00,00,00,00,ff,ff,00,00,\
00,ff,00,ff,ff,ff,00,00,00,ff,00,ff,ff,ff,00,00,00,00,02,80,80,80,02,00,ff,\
00,02,00,ff,00,00,ff,ff,ff,00,c0,c0,c0,02,ff,ff,ff,02,ff,ff,ff,02,00,00,00,\
00,ff,ff,00,00,c0,c0,c0,00,80,00,80,02,00,ff,ff,00,00,00,ff,00
"High Contrast Black"=hex:02,00,00,00,46,00,00,00,01,00,00,00,11,00,00,00,11,\
00,00,00,14,00,00,00,14,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,\
00,00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,\
00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,\
69,00,66,00,00,00,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,\
23,eb,77,0f,00,00,00,0f,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,\
00,00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,\
00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,\
69,00,66,00,00,00,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,\
00,14,00,12,00,00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,\
00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,\
00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,\
69,00,66,00,00,00,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,\
00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,\
00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,\
00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f5,ff,ff,ff,00,\
00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,\
69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,\
00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,06,00,00,00,18,00,00,00,\
ff,ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,\
00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,\
73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,\
00,69,00,66,00,00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,\
0c,10,00,01,00,00,00,02,00,00,00,02,80,00,80,00,00,80,00,00,00,00,00,00,00,\
00,00,02,ff,ff,ff,02,ff,ff,ff,00,ff,ff,ff,00,ff,ff,ff,00,ff,ff,00,02,00,80,\
00,02,00,00,00,02,80,00,80,00,ff,ff,ff,00,00,00,00,02,80,80,80,02,00,ff,00,\
02,ff,ff,ff,02,ff,ff,ff,00,c0,c0,c0,02,ff,ff,ff,02,ff,ff,ff,02,ff,ff,ff,00,\
00,00,00,00,c0,c0,c0,00,80,00,80,02,80,00,80,00,00,80,00,00
"High Contrast Black (extra large)"=hex:02,00,00,00,46,00,00,00,06,00,00,00,20,\
00,00,00,20,00,00,00,25,00,00,00,25,00,00,00,e1,ff,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,\
00,6d,00,61,00,00,00,65,00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,\
00,00,00,00,00,00,78,00,1c,10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,\
00,00,00,98,23,eb,77,1c,00,00,00,1c,00,00,00,e9,ff,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,\
00,6d,00,61,00,00,00,65,00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,\
00,00,00,00,00,20,14,00,ac,b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,\
1f,14,00,00,00,14,00,26,00,00,00,26,00,00,00,e1,ff,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,\
00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,\
00,00,00,00,00,00,00,00,80,05,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,\
00,00,00,20,00,00,00,e9,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,\
00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,\
00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,b4,c0,f0,77,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,e1,\
ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,\
00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,\
00,66,00,00,00,6e,00,00,00,c8,0b,00,00,00,00,00,00,08,00,00,00,06,00,00,00,\
18,00,00,00,ff,ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,e9,ff,ff,ff,00,00,00,00,00,\
00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,\
6f,00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,c0,1d,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,\
c0,fe,12,00,0c,10,00,01,00,00,00,02,00,00,00,02,80,00,80,00,00,80,00,00,00,\
00,00,00,00,00,00,02,ff,ff,ff,02,ff,ff,ff,00,ff,ff,ff,00,ff,ff,ff,00,ff,ff,\
00,02,00,80,00,02,00,00,00,02,80,00,80,00,ff,ff,ff,00,00,00,00,02,80,80,80,\
02,00,ff,00,02,ff,ff,ff,02,ff,ff,ff,00,c0,c0,c0,02,ff,ff,ff,02,ff,ff,ff,02,\
ff,ff,ff,00,00,00,00,00,c0,c0,c0,00,80,00,80,02,80,00,80,00,00,80,00,00
"High Contrast Black (large)"=hex:02,00,00,00,46,00,00,00,06,00,00,00,1c,00,00,\
00,1c,00,00,00,1f,00,00,00,1f,00,00,00,e8,ff,ff,ff,00,00,00,00,00,00,00,00,\
00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,\
00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,00,\
00,00,00,00,78,00,1c,10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,\
00,98,23,eb,77,1a,00,00,00,1a,00,00,00,ec,ff,ff,ff,00,00,00,00,00,00,00,00,\
00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,\
00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,00,\
00,00,00,20,14,00,ac,b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,\
00,00,00,14,00,1e,00,00,00,1e,00,00,00,e8,ff,ff,ff,00,00,00,00,00,00,00,00,\
00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,\
00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,00,\
00,00,00,00,00,00,80,05,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,\
00,20,00,00,00,ec,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,\
00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,\
00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,b4,c0,f0,77,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,e8,ff,ff,\
ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,\
54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,\
00,00,00,6e,00,00,00,c8,0b,00,00,00,00,00,00,08,00,00,00,06,00,00,00,18,00,\
00,00,ff,ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,ec,ff,ff,ff,00,00,00,00,00,00,00,\
00,00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,\
6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,c0,1d,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,\
12,00,0c,10,00,01,00,00,00,02,00,00,00,02,80,00,80,00,00,80,00,00,00,00,00,\
00,00,00,00,02,ff,ff,ff,02,ff,ff,ff,00,ff,ff,ff,00,ff,ff,ff,00,ff,ff,00,02,\
00,80,00,02,00,00,00,02,80,00,80,00,ff,ff,ff,00,00,00,00,02,80,80,80,02,00,\
ff,00,02,ff,ff,ff,02,ff,ff,ff,00,c0,c0,c0,02,ff,ff,ff,02,ff,ff,ff,02,ff,ff,\
ff,00,00,00,00,00,c0,c0,c0,00,80,00,80,02,80,00,80,00,00,80,00,00
"High Contrast White"=hex:02,00,00,00,46,00,00,00,01,00,00,00,11,00,00,00,11,\
00,00,00,14,00,00,00,14,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,\
00,00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,\
00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,\
69,00,66,00,00,00,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,\
23,eb,77,0f,00,00,00,0f,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,\
00,00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,\
00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,\
69,00,66,00,00,00,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,\
00,14,00,12,00,00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,\
00,00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,\
00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,\
69,00,66,00,00,00,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,\
00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,\
00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,\
00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f5,ff,ff,ff,00,\
00,00,00,00,00,00,00,00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,\
69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,\
00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,06,00,00,00,18,00,00,00,\
ff,ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,\
00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,\
73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,\
00,69,00,66,00,00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,\
0c,10,00,01,ff,ff,ff,02,ff,ff,ff,02,00,00,00,00,ff,ff,ff,00,ff,ff,ff,00,ff,\
ff,ff,02,00,00,00,02,00,00,00,00,00,00,00,00,ff,ff,ff,00,80,80,80,02,c0,c0,\
c0,02,80,80,80,02,00,00,00,00,ff,ff,ff,00,ff,ff,ff,02,80,80,80,02,00,ff,00,\
02,00,00,00,02,00,00,00,00,c0,c0,c0,02,00,00,00,02,c0,c0,c0,02,00,00,00,00,\
ff,ff,ff,00,c0,c0,c0,00,00,00,00,02,00,00,00,00,ff,ff,ff,00
"High Contrast White (extra large)"=hex:02,00,00,00,46,00,00,00,06,00,00,00,1e,\
00,00,00,1e,00,00,00,26,00,00,00,26,00,00,00,e1,ff,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,\
00,6d,00,61,00,00,00,65,00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,\
00,00,00,00,00,00,78,00,1c,10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,\
00,00,00,98,23,eb,77,1c,00,00,00,1c,00,00,00,e9,ff,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,\
00,6d,00,61,00,00,00,65,00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,\
00,00,00,00,00,20,14,00,ac,b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,\
1f,14,00,00,00,14,00,26,00,00,00,26,00,00,00,e1,ff,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,\
00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,\
00,00,00,00,00,00,00,00,80,05,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,\
00,00,00,20,00,00,00,e9,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,\
00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,\
00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,b4,c0,f0,77,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,eb,\
ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,bc,02,00,00,00,00,00,00,00,00,\
00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,\
00,66,00,00,00,6e,00,00,00,c8,0b,00,00,00,00,00,00,08,00,00,00,06,00,00,00,\
18,00,00,00,ff,ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,e9,ff,ff,ff,00,00,00,00,00,\
00,00,00,00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,\
6f,00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,c0,1d,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,\
c0,fe,12,00,0c,10,00,01,ff,ff,ff,02,ff,ff,ff,02,00,00,00,00,ff,ff,ff,00,ff,\
ff,ff,00,ff,ff,ff,02,00,00,00,02,00,00,00,00,00,00,00,00,ff,ff,ff,00,80,80,\
80,02,c0,c0,c0,02,80,80,80,02,00,00,00,00,ff,ff,ff,00,ff,ff,ff,02,80,80,80,\
02,00,ff,00,02,00,00,00,02,00,00,00,00,c0,c0,c0,02,00,00,00,02,c0,c0,c0,02,\
00,00,00,00,ff,ff,ff,00,c0,c0,c0,00,00,00,00,02,00,00,00,00,ff,ff,ff,00
"High Contrast White (large)"=hex:02,00,00,00,46,00,00,00,07,00,00,00,1a,00,00,\
00,1a,00,00,00,1f,00,00,00,1f,00,00,00,e8,ff,ff,ff,00,00,00,00,00,00,00,00,\
00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,\
00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,00,\
00,00,00,00,78,00,1c,10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,\
00,98,23,eb,77,18,00,00,00,18,00,00,00,ed,ff,ff,ff,00,00,00,00,00,00,00,00,\
00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,\
00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,00,\
00,00,00,20,14,00,ac,b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,\
00,00,00,14,00,1b,00,00,00,1b,00,00,00,eb,ff,ff,ff,00,00,00,00,00,00,00,00,\
00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,\
00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,00,\
00,00,00,00,00,00,80,05,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,\
00,20,00,00,00,ed,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,\
00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,\
00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,b4,c0,f0,77,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,eb,ff,ff,\
ff,00,00,00,00,00,00,00,00,00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,\
54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,\
00,00,00,6e,00,00,00,c8,0b,00,00,00,00,00,00,08,00,00,00,06,00,00,00,18,00,\
00,00,ff,ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,ec,ff,ff,ff,00,00,00,00,00,00,00,\
00,00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,\
6d,00,61,00,00,00,6c,00,61,00,63,00,6b,00,00,00,66,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,c0,1d,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,\
12,00,0c,10,00,01,ff,ff,ff,02,ff,ff,ff,02,00,00,00,00,ff,ff,ff,00,ff,ff,ff,\
00,ff,ff,ff,02,00,00,00,02,00,00,00,00,00,00,00,00,ff,ff,ff,00,80,80,80,02,\
c0,c0,c0,02,80,80,80,02,00,00,00,00,ff,ff,ff,00,ff,ff,ff,02,80,80,80,02,00,\
ff,00,02,00,00,00,02,00,00,00,00,c0,c0,c0,02,00,00,00,02,c0,c0,c0,02,00,00,\
00,00,ff,ff,ff,00,c0,c0,c0,00,00,00,00,02,00,00,00,00,ff,ff,ff,00
"Lilac"=hex:02,00,00,00,03,00,00,00,01,00,00,00,0f,00,00,00,0f,00,00,00,16,00,\
00,00,16,00,00,00,f0,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,bc,02,00,\
00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,65,00,\
77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,00,00,00,00,78,00,1c,\
10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,23,eb,77,10,00,\
00,00,10,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,bc,02,00,\
00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,65,00,\
77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,00,00,00,20,14,00,ac,\
b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,00,14,00,12,00,\
00,00,12,00,00,00,f3,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,\
00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,\
53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,00,00,00,00,00,00,00,80,\
05,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,00,00,00,f5,ff,\
ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,\
00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,\
66,00,00,00,6e,00,00,00,b4,c0,f0,77,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f3,ff,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,\
00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,\
c8,0b,00,00,00,00,00,00,08,00,00,00,06,00,00,00,18,00,00,00,ff,ff,ff,ff,f0,\
4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,\
00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,\
00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
c0,1d,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,0c,10,00,01,ae,\
a8,d9,02,00,00,00,02,5a,4e,b1,00,80,80,80,00,ae,a8,d9,00,ff,ff,ff,02,00,00,\
00,02,00,00,00,00,00,00,00,00,ff,ff,ff,00,ae,a8,d9,02,ae,a8,d9,02,5a,4e,b1,\
02,5a,4e,b1,00,ff,ff,ff,00,ae,a8,d9,02,5a,4e,b1,02,5a,4e,b1,02,00,00,00,02,\
ff,ff,ff,00,d8,d5,ec,02,00,00,00,02,ae,a8,d9,02,00,00,00,00,ff,ff,ff,00,c0,\
c0,c0,00,5a,4e,b1,02,b6,8f,cb,00,b8,b4,d0,00
"Lilac (large)"=hex:02,00,00,00,03,00,00,00,01,00,00,00,0f,00,00,00,0f,00,00,\
00,1d,00,00,00,1d,00,00,00,e9,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,\
00,65,00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,00,00,00,00,\
78,00,1c,10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,23,eb,\
77,15,00,00,00,15,00,00,00,f0,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
bc,02,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,\
00,65,00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,00,00,00,20,\
14,00,ac,b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,00,14,\
00,15,00,00,00,15,00,00,00,f0,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,\
00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,00,00,00,00,00,00,00,00,00,\
00,00,80,05,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,00,00,\
00,f0,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,\
00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,65,00,72,\
00,69,00,66,00,00,00,6e,00,00,00,b4,c0,f0,77,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,ef,ff,ff,ff,00,00,00,\
00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,\
68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,6e,\
00,00,00,c8,0b,00,00,00,00,00,00,08,00,00,00,06,00,00,00,18,00,00,00,ff,ff,\
ff,ff,f0,4b,21,fc,00,c4,f0,77,f0,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,\
00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,\
00,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,c0,1d,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,0c,10,\
00,01,ae,a8,d9,02,00,00,00,02,5a,4e,b1,00,80,80,80,00,ae,a8,d9,00,ff,ff,ff,\
02,00,00,00,02,00,00,00,00,00,00,00,00,ff,ff,ff,00,ae,a8,d9,02,ae,a8,d9,02,\
5a,4e,b1,02,5a,4e,b1,00,ff,ff,ff,00,ae,a8,d9,02,5a,4e,b1,02,5a,4e,b1,02,00,\
00,00,02,ff,ff,ff,00,d8,d5,ec,02,00,00,00,02,ae,a8,d9,02,00,00,00,00,ff,ff,\
ff,00,c0,c0,c0,00,5a,4e,b1,02,b6,8f,cb,00,b8,b4,d0,00
"Maple"=hex:02,00,00,00,30,9a,08,00,01,00,00,00,0d,00,00,00,0d,00,00,00,12,00,\
00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,bc,02,00,\
00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,\
74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,\
00,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,23,eb,77,0f,00,\
00,00,0f,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,\
00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,\
74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,\
00,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,00,14,00,12,00,\
00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,\
00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,\
74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,\
00,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,00,00,00,f5,ff,\
ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,\
00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,\
6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,\
00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,\
65,00,72,00,69,00,66,00,00,00,00,00,06,00,00,00,18,00,00,00,ff,ff,ff,ff,f0,\
4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,\
00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,\
00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,0c,10,00,01,f2,\
ec,d7,02,00,00,00,02,80,00,00,00,c6,a6,46,00,e6,d8,ae,00,ff,ff,ff,02,00,00,\
00,02,00,00,00,00,00,00,00,00,ff,ff,ff,00,e6,d8,ae,02,e6,d8,ae,02,c6,a6,46,\
02,c6,a6,46,00,00,00,00,00,e6,d8,ae,02,c6,a6,46,02,c6,a6,46,02,00,00,00,02,\
f2,ec,d7,00,f2,ec,d7,02,00,00,00,02,e6,d8,ae,02,00,00,00,00,ff,ff,ff,00,c0,\
c0,c0,02,c6,a6,46,02,c0,9c,38,00,e0,c8,88,00
"Marine (high color)"=hex:02,00,00,00,03,00,00,00,01,00,00,00,0d,00,00,00,0d,\
00,00,00,12,00,00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,\
00,00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,\
00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,\
69,00,66,00,00,00,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,\
23,eb,77,0d,00,00,00,0d,00,00,00,f7,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,\
00,00,bc,02,00,00,00,00,00,00,00,00,00,00,53,00,6d,00,61,00,6c,00,6c,00,20,\
00,46,00,6f,00,6e,00,74,00,73,00,00,00,66,00,00,00,6e,00,00,00,00,00,00,00,\
00,20,14,00,ac,b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,\
00,14,00,12,00,00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,\
00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,\
00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,\
69,00,66,00,00,00,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,\
00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,\
00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,\
00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f5,ff,ff,ff,00,\
00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,\
69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,\
00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,06,00,00,00,18,00,00,00,\
ff,ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,\
00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,\
73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,\
00,69,00,66,00,00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,\
0c,10,00,01,c8,e0,d8,02,2c,4e,47,00,00,00,80,00,48,90,88,00,88,c0,b8,00,c8,\
e0,d8,02,00,00,00,02,00,00,00,00,00,00,00,00,ff,ff,ff,00,88,c0,b8,02,88,c0,\
b8,02,4b,8d,84,00,00,00,80,00,ff,ff,ff,00,88,c0,b8,02,48,90,88,02,48,90,88,\
02,00,00,00,02,c0,c0,c0,00,c8,e0,d8,02,00,00,00,02,88,c0,b8,02,00,00,00,00,\
c8,e0,d8,00,c0,c0,c0,00,00,00,80,02,18,b4,c0,00,78,cc,d8,00
"Plum (high color)"=hex:02,00,00,00,03,00,00,00,01,00,00,00,0d,00,00,00,0d,00,\
00,00,12,00,00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,\
00,bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,\
00,66,00,00,00,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,23,\
eb,77,0f,00,00,00,0f,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,\
00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,\
00,66,00,00,00,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,00,\
14,00,12,00,00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,\
00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,\
00,66,00,00,00,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,00,\
00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,\
00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,\
53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f5,ff,ff,ff,00,00,\
00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,\
00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,\
20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,06,00,00,00,18,00,00,00,ff,\
ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,\
00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,\
00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,\
69,00,66,00,00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,0c,\
10,00,01,d8,d0,c8,00,40,28,40,00,48,40,60,00,78,60,58,00,a8,98,90,00,d8,d0,\
c8,00,00,00,00,00,00,00,00,00,00,00,00,00,ff,ff,ff,00,a8,98,90,00,a8,98,90,\
00,74,63,5a,00,00,80,80,00,d8,d0,c8,00,a8,98,90,00,78,60,58,00,78,60,58,00,\
00,00,00,00,a8,98,90,00,d8,d0,c8,00,00,00,00,00,a8,98,90,00,30,00,58,00,d5,\
cc,c8,00,c0,c0,c0,00,48,40,60,00,a0,84,b8,00,a8,98,78,00
"Pumpkin (large)"=hex:02,00,00,00,03,00,00,00,01,00,00,00,15,00,00,00,15,00,00,\
00,1a,00,00,00,1a,00,00,00,ed,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,\
00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,\
66,00,00,00,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,23,eb,\
77,16,00,00,00,16,00,00,00,f0,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
bc,02,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,\
00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,\
66,00,00,00,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,00,14,\
00,16,00,00,00,16,00,00,00,f0,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,\
90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,\
00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,\
66,00,00,00,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,00,00,\
00,f3,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,\
00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,\
00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f0,ff,ff,ff,00,00,00,\
00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,\
63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,\
00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,06,00,00,00,18,00,00,00,ff,ff,\
ff,ff,f0,4b,21,fc,00,c4,f0,77,f0,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,\
00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,\
6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,\
00,66,00,00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,0c,10,\
00,01,f5,ea,cf,02,42,00,42,00,d7,a5,2f,00,a0,a0,a4,00,ec,d5,9d,00,ff,ff,ff,\
02,00,00,00,02,00,00,00,00,00,00,00,00,ff,ff,ff,00,ec,d5,9d,02,ec,d5,9d,02,\
f5,ea,cf,02,80,00,80,00,ff,ff,ff,00,ec,d5,9d,02,d7,a5,2f,02,d7,a5,2f,02,00,\
00,00,02,f5,ea,cf,00,f5,ea,cf,02,00,00,00,02,ec,d5,9d,02,80,00,80,00,ff,ff,\
ff,00,c0,c0,c0,00,d7,a5,2f,02,e0,cc,88,00,d0,cc,90,00
"Rainy Day"=hex:02,00,00,00,03,00,00,00,01,00,00,00,0d,00,00,00,0d,00,00,00,12,\
00,00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,bc,02,\
00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,\
00,00,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,23,eb,77,0f,\
00,00,00,0f,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,\
00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,\
00,00,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,00,14,00,12,\
00,00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,\
00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,\
00,00,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,00,00,00,f5,\
ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,\
00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,\
00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f5,ff,ff,ff,00,00,00,00,00,\
00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,\
72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,\
00,65,00,72,00,69,00,66,00,00,00,00,00,06,00,00,00,18,00,00,00,ff,ff,ff,ff,\
f0,4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,\
01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,\
66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,\
00,00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,0c,10,00,01,\
c1,cc,d9,02,00,00,00,02,4f,65,7d,00,80,80,80,00,83,99,b1,00,ff,ff,ff,02,00,\
00,00,02,00,00,00,00,00,00,00,00,ff,ff,ff,00,83,99,b1,02,83,99,b1,02,80,80,\
80,02,4f,65,7d,00,ff,ff,ff,00,83,99,b1,02,4f,65,7d,02,4f,65,7d,02,00,00,00,\
02,c1,cc,d9,00,c1,cc,d9,02,00,00,00,02,83,99,b1,02,00,00,00,00,ff,ff,ff,00,\
c0,c0,c0,00,4f,65,7d,02,80,b4,d0,00,b0,bc,d0,00
"Red, White, and Blue (VGA)"=hex:02,00,00,00,03,00,00,00,01,00,00,00,0d,00,00,\
00,0d,00,00,00,13,00,00,00,13,00,00,00,f1,ff,ff,ff,00,00,00,00,00,00,00,00,\
00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,69,00,6d,00,65,00,73,\
00,20,00,4e,00,65,00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,\
00,00,00,00,78,00,1c,10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,\
00,98,23,eb,77,11,00,00,00,11,00,00,00,f3,ff,ff,ff,00,00,00,00,00,00,00,00,\
00,00,00,00,bc,02,00,00,00,00,00,00,00,00,00,00,54,00,69,00,6d,00,65,00,73,\
00,20,00,4e,00,65,00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,\
00,00,00,20,14,00,ac,b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,\
00,00,00,14,00,12,00,00,00,12,00,00,00,f3,ff,ff,ff,00,00,00,00,00,00,00,00,\
00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,54,00,69,00,6d,00,65,00,73,\
00,20,00,4e,00,65,00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,\
00,00,00,00,00,00,80,05,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,\
00,20,00,00,00,f3,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,\
00,00,00,00,00,00,00,00,54,00,69,00,6d,00,65,00,73,00,20,00,4e,00,65,00,77,\
00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,b4,c0,f0,77,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f3,ff,ff,\
ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,\
54,00,69,00,6d,00,65,00,73,00,20,00,4e,00,65,00,77,00,20,00,52,00,6f,00,6d,\
00,61,00,6e,00,00,00,c8,0b,00,00,00,00,00,00,08,00,00,00,06,00,00,00,18,00,\
00,00,ff,ff,ff,ff,f0,4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,\
00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,\
6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,\
00,72,00,69,00,66,00,00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,\
12,00,0c,10,00,01,c0,c0,c0,02,00,00,42,00,80,00,00,00,80,80,80,00,c0,c0,c0,\
00,ff,ff,ff,02,00,00,00,02,00,00,00,00,00,00,00,00,ff,ff,ff,00,c0,c0,c0,02,\
c0,c0,c0,02,ff,ff,ff,02,80,00,00,00,ff,ff,ff,00,c0,c0,c0,02,80,80,80,02,80,\
80,80,02,00,00,00,02,c0,c0,c0,00,ff,ff,ff,02,00,00,00,02,c0,c0,c0,02,00,00,\
80,00,ff,ff,ff,00,c0,c0,c0,00,80,00,00,02,00,10,a8,00,ba,be,c9,00
"Rose"=hex:02,00,00,00,03,00,00,00,01,00,00,00,0f,00,00,00,0f,00,00,00,17,00,\
00,00,17,00,00,00,ed,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,\
00,00,00,00,00,00,00,00,00,54,00,69,00,6d,00,65,00,73,00,20,00,4e,00,65,00,\
77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,00,00,00,00,78,00,1c,\
10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,23,eb,77,11,00,\
00,00,11,00,00,00,f3,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,bc,02,00,\
00,00,00,00,00,00,00,00,00,54,00,69,00,6d,00,65,00,73,00,20,00,4e,00,65,00,\
77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,00,00,00,20,14,00,ac,\
b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,00,14,00,12,00,\
00,00,12,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,\
00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,\
74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,\
00,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,00,00,00,f5,ff,\
ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,\
00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,\
6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,7c,6b,e8,77,00,00,00,00,f5,ff,ff,ff,00,00,00,00,00,00,\
00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,\
00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,\
65,00,72,00,69,00,66,00,00,00,00,00,06,00,00,00,18,00,00,00,ff,ff,ff,ff,f0,\
4b,21,fc,00,c4,f0,77,f5,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,\
00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,\
00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,\
00,00,14,00,0b,00,00,00,00,ff,12,00,50,00,00,00,c0,fe,12,00,0c,10,00,01,cf,\
af,b7,02,80,80,80,02,9f,60,70,00,a0,a0,a4,00,cf,af,b7,00,ff,ff,ff,02,00,00,\
00,02,00,00,00,00,00,00,00,00,ff,ff,ff,00,cf,af,b7,02,cf,af,b7,02,9f,60,70,\
02,9f,60,70,00,ff,ff,ff,00,cf,af,b7,02,9f,60,70,02,9f,60,70,02,00,00,00,02,\
7d,7d,7d,00,e7,d8,dc,02,00,00,00,02,cf,af,b7,02,00,00,00,00,ff,ff,ff,00,c0,\
c0,c0,00,9f,60,70,02,d8,cc,d0,00,d0,d4,d0,00
"Rose (large)"=hex:02,00,00,00,03,00,00,00,02,00,00,00,11,00,00,00,11,00,00,00,\
1c,00,00,00,1c,00,00,00,e9,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,\
01,00,00,00,00,00,00,00,00,00,00,54,00,69,00,6d,00,65,00,73,00,20,00,4e,00,\
65,00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,00,00,00,00,78,\
00,1c,10,fc,7f,22,14,fc,7f,b0,fe,12,00,00,00,00,00,00,00,00,00,98,23,eb,77,\
15,00,00,00,15,00,00,00,f0,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,bc,\
02,00,00,00,00,00,00,00,00,00,00,54,00,69,00,6d,00,65,00,73,00,20,00,4e,00,\
65,00,77,00,20,00,52,00,6f,00,6d,00,61,00,6e,00,00,00,00,00,00,00,00,20,14,\
00,ac,b9,f0,77,00,20,14,00,00,00,00,10,80,05,14,00,f0,1f,14,00,00,00,14,00,\
16,00,00,00,16,00,00,00,ef,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,\
01,00,00,00,00,00,00,00,00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,\
66,00,74,00,20,00,53,00,61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,\
00,00,00,14,00,88,fb,e8,77,02,02,00,00,ac,b9,f0,77,00,00,00,00,20,00,00,00,\
f0,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,00,00,00,00,\
00,00,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,20,00,53,00,\
61,00,6e,00,73,00,20,00,53,00,65,00,72,00,69,00,66,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00,00,00,00,7c,6b,e8,7
Superhobbit
[HKEY_CURRENT_USER\Control Panel\Colors]
"ActiveBorder"="212 208 200"
"ActiveTitle"="10 36 106"
"AppWorkSpace"="128 128 128"
"Background"="58 110 165"
"ButtonAlternateFace"="181 181 181"
"ButtonDkShadow"="64 64 64"
"ButtonFace"="212 208 200"
"ButtonHilight"="255 255 255"
"ButtonLight"="212 208 200"
"ButtonShadow"="128 128 128"
"ButtonText"="0 0 0"
"GradientActiveTitle"="166 202 240"
"GradientInactiveTitle"="192 192 192"
"GrayText"="128 128 128"
"Hilight"="10 36 106"
"HilightText"="255 255 255"
"HotTrackingColor"="0 0 128"
"InactiveBorder"="212 208 200"
"InactiveTitle"="128 128 128"
"InactiveTitleText"="212 208 200"
"InfoText"="0 0 0"
"InfoWindow"="255 255 225"
"Menu"="212 208 200"
"MenuText"="0 0 0"
"Scrollbar"="212 208 200"
"TitleText"="255 255 255"
"Window"="255 255 255"
"WindowFrame"="0 0 0"
"WindowText"="0 0 0"

[HKEY_CURRENT_USER\Control Panel\Current]

[HKEY_CURRENT_USER\Control Panel\Cursors]
@=""
"Scheme Source"=dword:00000000

[HKEY_CURRENT_USER\Control Panel\Cursors\Schemes]
"Animated Hourglasses"=",,C:\\WINDOWS\\Cursors\\appstart.ani,C:\\WINDOWS\\Cursors\\hourglas.ani,,,,,,,,,,"
"Windows Standard"=",,,,,,,,,,,,,"

[HKEY_CURRENT_USER\Control Panel\Custom Colors]
"ColorA"="FFFFFF"
"ColorB"="FFFFFF"
"ColorC"="FFFFFF"
"ColorD"="FFFFFF"
"ColorE"="FFFFFF"
"ColorF"="FFFFFF"
"ColorG"="FFFFFF"
"ColorH"="FFFFFF"
"ColorI"="FFFFFF"
"ColorJ"="FFFFFF"
"ColorK"="FFFFFF"
"ColorL"="FFFFFF"
"ColorM"="FFFFFF"
"ColorN"="FFFFFF"
"ColorO"="FFFFFF"
"ColorP"="FFFFFF"

[HKEY_CURRENT_USER\Control Panel\desktop]
"FontSmoothing"="2"
"DragFullWindows"="1"
"wallpaper"=""
"TileWallpaper"="0"
"ScreenSaveTimeOut"="840"
"UserPreferencemask"=hex:be,00,00,00
"WallpaperStyle"="2"
"ActiveWndTrkTimeout"=dword:00000000
"AutoEndTasks"="0"
"CaretWidth"=dword:00000001
"CoolSwitch"="1"
"CoolSwitchColumns"="7"
"CoolSwitchRows"="3"
"CursorBlinkRate"="530"
"DragHeight"="4"
"DragWidth"="4"
"ForegroundFlashCount"=dword:00000003
"ForegroundLockTimeout"=dword:00030d40
"GridGranularity"="0"
"HungAppTimeout"="5000"
"LowPowerActive"="0"
"LowPowerTimeOut"="0"
"MenuShowDelay"="155"
"PaintDesktopVersion"=dword:00000000
"Pattern"="(None)"
"PowerOffActive"="0"
"PowerOffTimeOut"="0"
"ScreenSaveActive"="1"
"ScreenSaverIsSecure"="0"
"UserPreferencesMask"=hex:90,32,00,80
"WaitToKillAppTimeout"="20000"
"WheelScrollLines"="3"

[HKEY_CURRENT_USER\Control Panel\desktop\ResourceLocale]
@="00000409"

[HKEY_CURRENT_USER\Control Panel\desktop\WindowMetrics]
"CaptionFont"=hex:08,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,bc,02,00,00,\
00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,\
00,65,00,72,00,69,00,66,00,00,00,68,c2,d2,06,b6,71,ea,65,bc,c2,d2,06,01,00,\
00,00,00,00,00,00,02,86,ea,65,f0,c2,d2,06,d3,70,ea,65,32,00,00,00
"IconFont"=hex:08,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,\
00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,\
65,00,72,00,69,00,66,00,00,00,68,c2,d2,06,b6,71,ea,65,bc,c2,d2,06,01,00,00,\
00,00,00,00,00,02,86,ea,65,f0,c2,d2,06,d3,70,ea,65,32,00,00,00
"MenuFont"=hex:08,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,00,\
00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,00,\
65,00,72,00,69,00,66,00,00,00,68,c2,d2,06,b6,71,ea,65,bc,c2,d2,06,01,00,00,\
00,00,00,00,00,02,86,ea,65,f0,c2,d2,06,d3,70,ea,65,32,00,00,00
"MessageFont"=hex:08,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,\
00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,\
00,65,00,72,00,69,00,66,00,00,00,68,c2,d2,06,b6,71,ea,65,bc,c2,d2,06,01,00,\
00,00,00,00,00,00,02,86,ea,65,f0,c2,d2,06,d3,70,ea,65,32,00,00,00
"SmCaptionFont"=hex:08,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,\
00,00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,\
53,00,65,00,72,00,69,00,66,00,00,00,68,c2,d2,06,b6,71,ea,65,bc,c2,d2,06,01,\
00,00,00,00,00,00,00,02,86,ea,65,f0,c2,d2,06,d3,70,ea,65,32,00,00,00
"StatusFont"=hex:08,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,90,01,00,00,\
00,00,00,00,00,00,00,00,54,00,61,00,68,00,6f,00,6d,00,61,00,00,00,20,00,53,\
00,65,00,72,00,69,00,66,00,00,00,68,c2,d2,06,b6,71,ea,65,bc,c2,d2,06,01,00,\
00,00,00,00,00,00,02,86,ea,65,f0,c2,d2,06,d3,70,ea,65,32,00,00,00
"Shell Icon BPP"="16"
"IconSpacingFactor"="100"
"BorderWidth"="-15"
"ScrollWidth"="-240"
"ScrollHeight"="-240"
"CaptionWidth"="-270"
"CaptionHeight"="-270"
"SmCaptionWidth"="-195"
"SmCaptionHeight"="-225"
"MenuWidth"="-270"
"MenuHeight"="-270"
"IconSpacing"="-1125"
"IconVerticalSpacing"="-1125"
"IconTitleWrap"="1"
"MinAnimate"="0"

[HKEY_CURRENT_USER\Control Panel\don't load]
"ncpa.cpl"="No"
"odbccp32.cpl"="No"
"snd.cpl"="no"
"joystick.cpl"="no"
"midimap.drv"="no"

[HKEY_CURRENT_USER\Control Panel\Input Method]
"Show Status"="1"

[HKEY_CURRENT_USER\Control Panel\Input Method\Hot Keys]

[HKEY_CURRENT_USER\Control Panel\Input Method\Hot Keys\00000010]
"Key Modifiers"=hex:02,c0,00,00
"Target IME"=hex:00,00,00,00
"Virtual Key"=hex:20,00,00,00

[HKEY_CURRENT_USER\Control Panel\Input Method\Hot Keys\00000011]
"Key Modifiers"=hex:04,c0,00,00
"Target IME"=hex:00,00,00,00
"Virtual Key"=hex:20,00,00,00

[HKEY_CURRENT_USER\Control Panel\Input Method\Hot Keys\00000012]
"Key Modifiers"=hex:02,c0,00,00
"Target IME"=hex:00,00,00,00
"Virtual Key"=hex:be,00,00,00

[HKEY_CURRENT_USER\Control Panel\Input Method\Hot Keys\00000070]
"Key Modifiers"=hex:02,c0,00,00
"Target IME"=hex:00,00,00,00
"Virtual Key"=hex:20,00,00,00

[HKEY_CURRENT_USER\Control Panel\Input Method\Hot Keys\00000071]
"Key Modifiers"=hex:04,c0,00,00
"Target IME"=hex:00,00,00,00
"Virtual Key"=hex:20,00,00,00

[HKEY_CURRENT_USER\Control Panel\Input Method\Hot Keys\00000072]
"Key Modifiers"=hex:03,c0,00,00
"Target IME"=hex:00,00,00,00
"Virtual Key"=hex:bc,00,00,00

[HKEY_CURRENT_USER\Control Panel\Input Method\Hot Keys\00000200]
"Key Modifiers"=hex:03,c0,00,00
"Target IME"=hex:00,00,00,00
"Virtual Key"=hex:47,00,00,00

[HKEY_CURRENT_USER\Control Panel\Input Method\Hot Keys\00000201]
"Key Modifiers"=hex:03,c0,00,00
"Target IME"=hex:00,00,00,00
"Virtual Key"=hex:4b,00,00,00

[HKEY_CURRENT_USER\Control Panel\Input Method\Hot Keys\00000202]
"Key Modifiers"=hex:03,c0,00,00
"Target IME"=hex:00,00,00,00
"Virtual Key"=hex:4c,00,00,00

[HKEY_CURRENT_USER\Control Panel\International]
"Locale"="00000809"
"iCountry"="44"
"iCurrDigits"="2"
"iCurrency"="0"
"iDate"="1"
"iDigits"="2"
"iLZero"="1"
"iMeasure"="0"
"iNegCurr"="1"
"iTime"="1"
"iTLZero"="1"
"s1159"="AM"
"s2359"="PM"
"sCountry"="United Kingdom"
"sCurrency"="£"
"sDate"="/"
"sDecimal"="."
"sLanguage"="ENG"
"sList"=","
"sLongDate"="dd MMMM yyyy"
"sShortDate"="dd/MM/yyyy"
"sThousand"=","
"sTime"=":"
"sTimeFormat"="HH:mm:ss"
"iTimePrefix"="0"
"sMonDecimalSep"="."
"sMonThousandSep"=","
"iNegNumber"="1"
"sNativeDigits"="0123456789"
"NumShape"="1"
"iCalendarType"="1"
"iFirstDayOfWeek"="0"
"iFirstWeekOfYear"="0"
"sGrouping"="3;0"
"sMonGrouping"="3;0"
"sPositiveSign"=""
"sNegativeSign"="-"

[HKEY_CURRENT_USER\Control Panel\IOProcs]
"MVB"="mvfs32.dll"

[HKEY_CURRENT_USER\Control Panel\Keyboard]
"InitialKeyboardIndicators"="2"
"KeyboardDelay"="1"
"KeyboardSpeed"="31"

[HKEY_CURRENT_USER\Control Panel\Microsoft Input Devices]

[HKEY_CURRENT_USER\Control Panel\Microsoft Input Devices\Mouse]

[HKEY_CURRENT_USER\Control Panel\Microsoft Input Devices\Mouse\Exceptions]

[HKEY_CURRENT_USER\Control Panel\Microsoft Input Devices\Mouse\Exceptions\1001]
"Description"="Internet Explorer"
"FileName"="IEXPLORE.EXE"
"Version"=dword:00050000

[HKEY_CURRENT_USER\Control Panel\Microsoft Input Devices\Mouse\Exceptions\1002]
"Description"="Microsoft PhotoDraw"
"Filename"="PHOTODRW.EXE"
"Version"=dword:00020000

[HKEY_CURRENT_USER\Control Panel\MMCPL]
"mlcfg32.cpl"="C:\\PROGRA~1\\COMMON~1\\System\\MAPI\\1033\\nt\\mlcfg32.cpl"
"Adobe Gamma"="C:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma.cpl"

[HKEY_CURRENT_USER\Control Panel\Mouse]
"ActiveWindowTracking"=dword:00000000
"DoubleClickHeight"="4"
"DoubleClickSpeed"="627"
"DoubleClickWidth"="4"
"MouseSpeed"="1"
"MouseThreshold1"="6"
"MouseThreshold2"="10"
"SnapToDefaultButton"="0"
"SwapMouseButtons"="0"
"MouseSensitivity"="10"

[HKEY_CURRENT_USER\Control Panel\Patterns]
"(None)"="(None)"
"50% Gray"="170 85 170 85 170 85 170 85"
"Boxes"="127 65 65 65 65 65 127 0"
"Critters"="0 80 114 32 0 5 39 2"
"Diamonds"="32 80 136 80 32 0 0 0"
"Paisley"="2 7 7 2 32 80 80 32"
"Pattern"="224 128 142 136 234 10 14 0"
"Quilt"="130 68 40 17 40 68 130 1"
"Scottie"="64 192 200 120 120 72 0 0"
"Spinner"="20 12 200 121 158 19 48 40"
"Thatches"="248 116 34 71 143 23 34 113"
"Tulip"="0 0 84 124 124 56 146 124"
"Waffle"="0 0 0 0 128 128 128 240"
"Weave"="136 84 34 69 136 21 34 81"
"Bricks"="187 95 174 93 186 117 234 245"
"Buttons"="170 125 198 71 198 127 190 85"
"Cargo Net"="120 49 19 135 225 200 140 30"
"Circuits"="82 41 132 66 148 41 66 132"
"Cobblestones"="40 68 146 171 214 108 56 16"
"Colosseum"="130 1 1 1 171 85 170 85"
"Daisies"="30 140 216 253 191 27 49 120"
"Dizzy"="62 7 225 7 62 112 195 112"
"Field Effect"="86 89 166 154 101 149 106 169"
"Key"="254 2 250 138 186 162 190 128"
"Live Wire"="239 239 14 254 254 254 224 239"
"Plaid"="240 240 240 240 170 85 170 85"
"Rounder"="215 147 40 215 40 147 213 215"
"Scales"="225 42 37 146 85 152 62 247"
"Stone"="174 77 239 255 8 77 174 77"
"Tile"="69 130 1 0 1 130 69 170"
"Triangles"="135 7 6 4 0 247 231 199"
"Waffle's Revenge"="77 154 8 85 239 154 77 154"

[HKEY_CURRENT_USER\Control Panel\PowerCfg]
"CurrentPowerPolicy"="3"

[HKEY_CURRENT_USER\Control Panel\PowerCfg\GlobalPowerPolicy]
"Policies"=hex:01,00,00,00,06,00,00,00,03,00,00,00,00,00,00,00,06,00,00,00,03,\
00,00,00,00,00,00,00,02,00,00,00,03,00,00,00,00,00,00,00,02,00,00,00,03,00,\
00,00,00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,01,00,00,\
00,00,00,00,00,01,00,00,00,03,00,00,00,02,00,00,00,04,00,00,c0,01,00,00,00,\
02,00,00,00,01,00,00,00,0a,00,00,00,00,00,00,00,03,00,00,00,01,00,01,00,01,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,00,\
00,02,00,00,00

[HKEY_CURRENT_USER\Control Panel\PowerCfg\PowerPolicies]

[HKEY_CURRENT_USER\Control Panel\PowerCfg\PowerPolicies\0]
"Name"="Home/Office Desk"
"Description"="This scheme is suited to most home or desktop computers that are left plugged in all the time."
"Policies"=hex:01,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,02,00,00,00,00,\
00,00,00,00,00,00,00,b0,04,00,00,3c,00,00,00,32,32,00,00,02,00,00,00,02,00,\
00,00,60,00,00,00,43,00,3a,00,84,03,00,00,78,00,00,00,08,07,00,00,58,02,00,\
00,00,00,64,64,64,64,73,00

[HKEY_CURRENT_USER\Control Panel\PowerCfg\PowerPolicies\1]
"Name"="Portable/Laptop"
"Description"="This scheme is designed for extended battery life for portable computers on the road."
"Policies"=hex:01,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,02,00,00,00,01,\
00,00,00,00,00,00,00,b0,04,00,00,2c,01,00,00,32,32,00,00,04,00,00,00,05,00,\
00,00,00,00,00,00,00,00,00,00,84,03,00,00,78,00,00,00,08,07,00,00,b4,00,00,\
00,01,01,64,50,64,64,00,00

[HKEY_CURRENT_USER\Control Panel\PowerCfg\PowerPolicies\2]
"Name"="Presentation"
"Description"="This scheme keeps the monitor on for doing presentations."
"Policies"=hex:01,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,02,00,00,00,01,\
00,00,00,00,00,00,00,00,00,00,00,84,03,00,00,32,32,00,00,04,00,00,00,04,00,\
00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,2c,01,00,\
00,01,01,50,50,64,64,00,00

[HKEY_CURRENT_USER\Control Panel\PowerCfg\PowerPolicies\3]
"Name"="Always On"
"Description"="This scheme keeps the computer running so that it can be accessed from the network. Use this scheme if you do not have network wakeup hardware."
"Policies"=hex:01,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,02,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,2c,01,00,00,32,32,00,00,02,00,00,00,02,00,\
00,00,60,00,00,00,43,00,3a,00,00,00,00,00,78,00,00,00,00,00,00,00,b4,00,00,\
00,00,00,64,64,64,64,73,00

[HKEY_CURRENT_USER\Control Panel\PowerCfg\PowerPolicies\4]
"Name"="Minimal Power Management"
"Description"="This scheme keeps the computer on and optimizes it for high performance."
"Policies"=hex:01,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,02,00,00,00,00,\
00,00,00,00,00,00,00,00,00,00,00,2c,01,00,00,32,32,00,00,04,00,00,00,04,00,\
00,00,00,00,00,00,00,00,00,00,84,03,00,00,2c,01,00,00,00,00,00,00,84,03,00,\
00,00,01,64,64,64,64,00,00

[HKEY_CURRENT_USER\Control Panel\PowerCfg\PowerPolicies\5]
"Name"="Max Battery"
"Description"="This scheme is extremely aggressive for saving power."
"Policies"=hex:01,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,02,00,00,00,05,\
00,00,00,00,00,00,00,b0,04,00,00,78,00,00,00,32,32,00,00,04,00,00,00,04,00,\
00,00,00,00,00,00,00,00,00,00,84,03,00,00,3c,00,00,00,00,00,00,00,b4,00,00,\
00,01,01,64,32,64,32,00,00

[HKEY_CURRENT_USER\Control Panel\Screen Saver.3DFlyingObj]

[HKEY_CURRENT_USER\Control Panel\Screen Saver.3DPipes]

[HKEY_CURRENT_USER\Control Panel\Screen Saver.Bezier]

[HKEY_CURRENT_USER\Control Panel\Screen Saver.Marquee]
"BackgroundColor"="0 0 128"
"CharSet"="0"
"Font"="Tahoma"
"Mode"="1"
"Size"="24"
"Speed"="14"
"Text"="Your text goes here."
"TextColor"="255 0 255"

[HKEY_CURRENT_USER\Control Panel\Screen Saver.Mystify]
"Active1"="1"
"Active2"="1"
"Clear Screen"="1"
"EndColor1"="255 255 255"
"EndColor2"="255 255 255"
"Lines1"="7"
"Lines2"="12"
"StartColor1"="0 0 0"
"StartColor2"="0 0 0"
"WalkRandom1"="1"
"WalkRandom2"="1"

[HKEY_CURRENT_USER\Control Panel\Screen Saver.Stars]
"Density"="50"
"WarpSpeed"="10"

[HKEY_CURRENT_USER\Control Panel\Sound]
"Beep"="yes"
"ExtendedSounds"="yes"

[HKEY_CURRENT_USER\Control Panel\Sounds]
"SystemDefault"=","

Rest of file
Daisuke
I'm not sure if you can post the file. It's a big file.

Rename it Ucontrolpanel.REG --> Ucontrolpanel.TXT, attach it, and send it to my yahoo address: [edited]@yahoo.com
Daisuke
It's OK, don't sent it.
Daisuke
Export please also these keys, if present:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Desktop

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Superhobbit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Desktop

is not present.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop

The contents are:-

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\AdminComponent]


HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

is not present.
Daisuke
Let's see if you can open a Control Panel applet with a command.


Go to Start --> Run, and type cmd in the Open box, then click OK

A DOS windows will open.

Type control appwiz.cpl (there is a space between control and appwiz.cpl). This should open the Add or Remove Programs Windows. Did it open the window ?
Superhobbit
Yes it worked ok.
Superhobbit
Hi Daisuke,

Is there anyhting else you want me to do?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.