debi239 Posted February 1, 2013 Posted February 1, 2013 I have somehow downloaded this browser hijacker and now cannot find it to uninstall it, any help would be greatly appreciated. Thanks.:) Quote
etavares Posted February 1, 2013 Posted February 1, 2013 Hi debi239, My name is etavares and I'll help you remove this. To begin, please follow these instructions in the link below: Before posting for Malware Removal help. Please copy/paste all requested logs directly into your reply this this thread. Thanks! -etavares Quote etavares is a member of:Alliance of Security Analysis ProfessionalsUnified Network of Instructors and Trained Eliminators
debi239 Posted February 2, 2013 Author Posted February 2, 2013 I'm sorry but I have to send each scan separate. Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.02.01.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Deb :: DEB-PC [administrator] 2/1/2013 7:39:44 AM mbam-log-2013-02-01 (07-39-44).txt Scan type: Full scan (C:\|D:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 1143749 Time elapsed: 9 hour(s), 56 minute(s), 14 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 37 HKCR\CLSID\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully. HKCR\funmoods.funmoodsHlpr.1 (PUP.FunMoods) -> Quarantined and deleted successfully. HKCR\funmoods.funmoodsHlpr (PUP.FunMoods) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully. HKCR\CLSID\{965B9DBE-B104-44AC-950A-8A5F97AFF439} (PUP.Funmoods) -> Quarantined and deleted successfully. HKCR\CLSID\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Quarantined and deleted successfully. HKCR\funmoods.dskBnd.1 (PUP.Funmoods) -> Quarantined and deleted successfully. HKCR\funmoods.dskBnd (PUP.Funmoods) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Quarantined and deleted successfully. HKCR\CLSID\{A9DB719C-7156-415E-B49D-BAD039DE4F13} (PUP.Funmoods) -> Quarantined and deleted successfully. HKCR\funmoodsApp.appCore.1 (PUP.Funmoods) -> Quarantined and deleted successfully. HKCR\funmoodsApp.appCore (PUP.Funmoods) -> Quarantined and deleted successfully. HKCR\CLSID\{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9} (PUP.Funmoods) -> Quarantined and deleted successfully. HKCR\f (PUP.Funmoods) -> Quarantined and deleted successfully. HKCR\Typelib\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3} (PUP.Funmoods) -> Quarantined and deleted successfully. HKCR\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191} (PUP.Funmoods) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{103089DA-0F31-4A8B-843F-7D24A7FE8345} (PUP.InfoAtoms) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{103089DA-0F31-4A8B-843F-7D24A7FE8345} (PUP.InfoAtoms) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{5D79F641-C168-40DF-A32F-BACEA7509E75} (PUP.MyWebSearch) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D79F641-C168-40DF-A32F-BACEA7509E75} (PUP.MyWebSearch) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{C98D5B61-B0EA-4D48-9839-1079D352D880} (PUP.MyWebSearch) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C98D5B61-B0EA-4D48-9839-1079D352D880} (PUP.MyWebSearch) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA} (PUP.MyWebSearch) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA} (PUP.MyWebSearch) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{04D2B915-19FF-41E9-994D-95DC898BEA43} (PUP.MyWebSearch) -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0696F815-A3A9-490A-BB14-9EC3350B1276} (PUP.MyWebSearch) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65bcd620-07dd-012f-819f-073cf1b8f7c6} (Adware.GamePlayLab) -> Quarantined and deleted successfully. HKCU\Software\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> Quarantined and deleted successfully. HKCU\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> Quarantined and deleted successfully. HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Quarantined and deleted successfully. Registry Values Detected: 2 HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Data: Funmoods Toolbar -> Quarantined and deleted successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Data: -> Quarantined and deleted successfully. Registry Data Items Detected: 5 HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (Hijack.SearchPage) -> Bad: (http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=) Good: (http://www.google.com) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL (Hijack.SearchPage) -> Bad: (http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=) Good: (http://www.google.com) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|Default_Search_URL (Hijack.SearchPage) -> Bad: (http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=) Good: (http://www.google.com/) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (Hijack.SearchPage) -> Bad: (http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=) Good: (http://www.google.com) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Internet Explorer\Search|Default_Search_URL (Hijack.SearchPage) -> Bad: (http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=) Good: (http://www.google.com/) -> Quarantined and repaired successfully. Folders Detected: 3 C:\Program Files (x86)\MyWebSearch (PUP.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files (x86)\MyWebSearch\bar (PUP.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files (x86)\MyWebSearch\bar\1.bin (PUP.MyWebSearch) -> Quarantined and deleted successfully. Files Detected: 10 C:\Program Files (x86)\64res.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files (x86)\64Uninstall TelevisionFanatic.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully. C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MEDINT.EXE (PUP.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files (x86)\WnSoft PicturesToExe\5.6\PicturesToExe.exe (Rogue.FakeMSE) -> Quarantined and deleted successfully. C:\Users\Deb\AppData\LocalLow\DailyBibleGuideEI\Installr\Cache\004632E3.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully. C:\Users\Deb\AppData\LocalLow\TelevisionFanaticEI\Installr\Cache\00216C3A.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully. C:\Users\Deb\Downloads\Program\CORE10k.EXE (Dont.Steal.Our.Software) -> Quarantined and deleted successfully. C:\Windows\System32\t5rdv.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully. C:\Program Files (x86)\MyWebSearch\bar\1.bin\CHROME.MANIFEST (PUP.MyWebSearch) -> Quarantined and deleted successfully. (end) Quote
debi239 Posted February 2, 2013 Author Posted February 2, 2013 This is what I get when I try to post the OTL scans. Is there any other way I can get them to you. [h=3]The following errors occurred with your submission[/h]The text that you have entered is too long (91261 characters). Please shorten it to 80000 characters long. Quote
RandyL Posted February 2, 2013 Posted February 2, 2013 Hi debi; Make two posts. Put part of the text in each post please. Quote We are all members helping other members. Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.Get help with computer problems. Join Free PC Help here Donations are welcome. Read Here
debi239 Posted February 2, 2013 Author Posted February 2, 2013 OTL logfile created on: 2/1/2013 5:52:35 PM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Deb\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.97 Gb Total Physical Memory | 1.43 Gb Available Physical Memory | 35.95% Memory free 7.93 Gb Paging File | 5.56 Gb Available in Paging File | 70.17% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 116.44 Gb Total Space | 26.69 Gb Free Space | 22.92% Space Free | Partition Type: NTFS Drive D: | 337.60 Gb Total Space | 87.33 Gb Free Space | 25.87% Space Free | Partition Type: NTFS Computer Name: DEB-PC | User Name: Deb | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Deb\Desktop\OTL.scr (OldTimer Tools) PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.) PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe () PRC - C:\Users\Deb\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) PRC - C:\Program Files (x86)\lg_fwupdate\fwupdate.exe (BitLeader) PRC - C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company) PRC - C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft Inc.) PRC - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbarsvc.exe (DailyBibleGuide) PRC - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbrmon.exe (DailyBibleGuide) PRC - C:\Program Files (x86)\Pando Networks\Pando\Pando.exe (Pando Networks) PRC - C:\Program Files (x86)\HiYo\Bin\HiYo.exe (IncrediMail, Ltd.) PRC - C:\Program Files (x86)\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.) PRC - C:\Windows\AsScrPro.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe () PRC - C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe (ASUSTeK Computer Inc.) PRC - C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe () PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.) PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe (ASUS) PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.) PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\Atouch64.exe () PRC - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.) PRC - C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe () PRC - C:\Program Files (x86)\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.) PRC - C:\Program Files (x86)\Webroot\Washer\wwDisp.exe (Webroot Software, Inc.) PRC - C:\Program Files\ATKGFNEX\GFNEXSrv.exe () PRC - C:\Sierra\Planner\PLNRnote.exe (Sierra Online) ========== Modules (No Company Name) ========== MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ff7c9a4f41f7cccc47e696c11b9f8469\PresentationFramework.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\19b3d17c3ce0e264c4fb62028161adf7\PresentationCore.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll () MOD - C:\Program Files (x86)\HiYo\Bin\AppServerCommunication.dll () MOD - C:\Program Files (x86)\HiYo\Bin\IMHttpComm.dll () MOD - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe () MOD - C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe () MOD - C:\Program Files (x86)\ASUS\VirtualCamera\virtualCamera.ax () MOD - C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe () MOD - C:\Program Files (x86)\Webroot\Washer\Languages\English.dll () MOD - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll () MOD - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll () ========== Services (SafeList) ========== SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation) SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV:64bit: - (ATKGFNEXSrv) -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe () SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (FBDiskOptimizer) -- C:\Program Files (x86)\FixBee\FBDefragSrv64.exe (FixBee., (www.fixbee.com)) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (RealNetworks Downloader Resolver Service) -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe () SRV - (Akamai) -- c:\program files (x86)\common files\akamai/netsession_win_ce5ba24.dll () SRV - (Kodak AiO Network Discovery Service) -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company) SRV - (ADExchange) -- C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft Inc.) SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.) SRV - (DailyBibleGuideService) -- C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbarsvc.exe (DailyBibleGuide) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) SRV - (FastBootAgent) -- C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe (ASUSTeK Computer Inc.) SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (YahooAUService) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.) SRV - (ADSMService) -- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.) SRV - (wwEngineSvc) -- C:\Program Files (x86)\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.) SRV - (Crypkey License) -- C:\Windows\SysWow64\Crypserv.exe (Kenonic Controls Ltd.) ========== Driver Services (SafeList) ========== DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (PCWinSoft) -- C:\Windows\SysNative\drivers\scrcamnetdriver_x64.sys (Windows ® Server 2003 DDK provider) DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation) DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (DigiartyVirtualCDBus) -- C:\Windows\SysNative\drivers\DigiartyVirtualCDBus.sys (Digiarty Software, Inc.) DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.) DRV:64bit: - (AnyDVD) -- C:\Windows\SysNative\drivers\AnyDVD.sys (SlySoft, Inc.) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation) DRV:64bit: - (FARMNTIO) -- C:\Windows\SysNative\drivers\FarMntIo.sys () DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:64bit: - (AsDsm) -- C:\Windows\SysNative\drivers\AsDsm.sys (ASUSTek Computer Inc) DRV:64bit: - (L1E) -- C:\Windows\SysNative\drivers\L1E62x64.sys (Atheros Communications, Inc.) DRV:64bit: - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( ) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation) DRV:64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.) DRV:64bit: - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronic Corp.) DRV:64bit: - (lullaby) -- C:\Windows\SysNative\drivers\lullaby.sys (Windows ® Win 7 DDK provider) DRV:64bit: - (SiSGbeLH) -- C:\Windows\SysNative\drivers\SiSG664.sys (Silicon Integrated Systems Corp.) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation) DRV:64bit: - (AmUStor) -- C:\Windows\SysNative\drivers\AmUStor.sys (Alcor Micro, Corp.) DRV:64bit: - (SNP2UVC) -- C:\Windows\SysNative\drivers\snp2uvc.sys () DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ATK64AMD.sys (ASUS) DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation) DRV:64bit: - (ASMMAP64) -- C:\Program Files\ATKGFNEX\ASMMAP64.sys () DRV:64bit: - (SCDEmu) -- C:\Windows\SysNative\drivers\scdemu.sys (PowerISO Computing, Inc.) DRV - (AnyDVD) -- C:\Windows\SysWOW64\drivers\AnyDVD.sys (SlySoft, Inc.) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) DRV - (NetworkX) -- C:\Windows\SysWOW64\Ckldrv.sys () ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=bf3&chnl=bf3&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0EtA0DyEyDtC0FtAyCtBtAtN0D0Tzu0CtBtAtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=801427480 IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2408}: "URL" = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=104&systemid=408&apn_dtid=BND408&apn_ptnrs=AGF&o=APN10654&apn_uid=7193510456114116&q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = about:blank IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=3204 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=3204 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=41460&home=true&tid=3204 IE - HKLM\..\URLSearchHook: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{34e26447-bf30-4c78-a5b9-61dfa8a55e67}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=XMxdm0488Jus&ptnrS=XMxdm0488Jus&si=100767&ptb=858F2DF0-1B0D-40B3-8F33-AD80FF15F0F6&psa=&ind=2011050310&st=sb&n=77de3146&searchfor={searchTerms} IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=bf3&chnl=bf3&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0EtA0DyEyDtC0FtAyCtBtAtN0D0Tzu0CtBtAtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=801427480 IE - HKLM\..\SearchScopes\{7C19EC30-6FAD-B9F6-82AA-0C5189279B17}: "URL" = http://search.certified-toolbar.com?si=41460&bs=true&tid=3204&q={searchTerms} IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2408}: "URL" = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=104&systemid=408&apn_dtid=BND408&apn_ptnrs=AGF&o=APN10654&apn_uid=7193510456114116&q={searchTerms} IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://www.google.com/ig IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = about:blank IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=3204 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://igoogle.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D6 0A A2 81 91 98 CB 01 [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://mystart.hiyo.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=3204 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=41460&home=true&tid=3204 IE - HKCU\..\URLSearchHook: {f15ff29f-85a1-43cd-9674-e5ba40016c97} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vSrcAs.dll (DailyBibleGuide) IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKCU\..\SearchScopes\{0169E633-8781-F882-9BC7-7B014AE4DE4E}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=Z206&form=ZGAIDF&install_date=20111005&iesrc={referrer:source} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{30CFB165-2CF1-7712-E58F-3A8DBE9E3CFA}: "URL" = http://www.incredimail-start.com/s/?q={searchTerms}&iesrc=IE-SearchBox&site=Bing&cfg=2-428-0-2x4co IE - HKCU\..\SearchScopes\{34e26447-bf30-4c78-a5b9-61dfa8a55e67}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=XMxdm0488Jus&ptnrS=XMxdm0488Jus&si=100767&ptb=858F2DF0-1B0D-40B3-8F33-AD80FF15F0F6&psa=&ind=2011050310&st=sb&n=77de3146&searchfor={searchTerms} IE - HKCU\..\SearchScopes\{4A7BC363-1B1A-469A-8A9F-B08D6190106D}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=685749&p={searchTerms} IE - HKCU\..\SearchScopes\{63EA0726-C83D-C02E-CF27-0160BA4048EB}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=ZUGO&form=ZGAIDF IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS409 IE - HKCU\..\SearchScopes\{7B778A05-D20F-5F8F-66DF-EA2ADE1B9C35}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=ZUGO&form=ZGAIDF IE - HKCU\..\SearchScopes\{7C19EC30-6FAD-B9F6-82AA-0C5189279B17}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS409 IE - HKCU\..\SearchScopes\{8B63A8D6-BBED-4341-8867-790E5F524C96}: "URL" = http://mystart.incredimail.com/?search={searchTerms}&loc=search_box IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2408}: "URL" = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=104&systemid=408&apn_dtid=BND408&apn_ptnrs=AGF&o=APN10654&apn_uid=7193510456114116&q={searchTerms} IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS409 IE - HKCU\..\SearchScopes\{C7576B9D-B442-46bc-AF74-080A9E723E01}: "URL" = http://websearch.search-results.com/redirect?client=ie&tb=BBY2-SRS&o=41647948&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=7S&apn_dtid=YYYYYYYYUS&apn_uid=9031D046-42A2-4C65-84EC-C9DFB269878A&apn_sauid=7AB86833-9B02-4D34-9041-8E0487E93484 IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com//?search={searchTerms}&loc=search_box&a=1pcqIQ5iKit IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local> ========== FireFox ========== FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@DailyBibleGuide.com/Plugin: C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\NP2vStub.dll (DailyBibleGuide) FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/28 07:33:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\2vffxtbr@DailyBibleGuide.com: C:\Program Files (x86)\DailyBibleGuide\bar\1.bin [2011/10/14 06:41:49 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/18 08:19:49 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/28 07:33:53 | 000,000,000 | ---D | M] [2013/02/01 05:54:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions ========== Chrome ========== CHR - plugin: Babylon Translator (Enabled) = dhkplhfnhceodhffomolpfigojocbpcb\1.4_0 CHR - plugin: Error reading preferences file CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\1.0_0\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\4.0_0\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.4_0\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpcpcabjajdjmbkfinphfdflfipmalnj\1.0_0\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.6.0_0\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.6.0_0\facemoods\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ O1 HOSTS File: ([2009/06/10 15:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation) O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll (Google Inc.) O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation) O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) O2 - BHO: (Search Assistant BHO) - {0631bff0-6846-48ca-982d-d62d7f376e97} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vSrcAs.dll (DailyBibleGuide) O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found. O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.) O2 - BHO: (Toolbar BHO) - {beea7fa9-d1f4-49a2-9b1f-6fb7a2d9bc2a} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (DailyBibleGuide) O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files (x86)\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited) O2 - BHO: (IncrediMail MediaBar 2 Toolbar) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.) O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc) O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation) O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (DailyBibleGuide) - {2a942ab7-2073-49bc-a7e1-77e93835889a} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (DailyBibleGuide) O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation) O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found. O3 - HKLM\..\Toolbar: (IncrediMail MediaBar 2 Toolbar) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {22E03916-85C5-44B0-8DC9-1830C11238D9} - No CLSID value found. O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (DailyBibleGuide) - {2A942AB7-2073-49BC-A7E1-77E93835889A} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (DailyBibleGuide) O3 - HKCU\..\Toolbar\WebBrowser: (IncrediMail MediaBar 2 Toolbar) - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.) O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (AlcorMicro Co., Ltd.) O4:64bit: - HKLM..\Run: [EKAIO2StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKAiO2MUI.exe (Eastman Kodak Company) O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [igfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS) O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [Conime] %windir%\system32\conime.exe File not found O4 - HKLM..\Run: [DailyBibleGuide Browser Plugin Loader] C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbrmon.exe (DailyBibleGuide) O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS) O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA) O4 - HKLM..\Run: [Hiyo] C:\Program Files (x86)\HiYo\bin\HiYo.exe (IncrediMail, Ltd.) O4 - HKLM..\Run: [LGODDFU] C:\Program Files (x86)\lg_fwupdate\lgfw.exe (Bitleader) O4 - HKLM..\Run: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [updateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKCU..\Run: [] File not found O4 - HKCU..\Run: [AdobeBridge] File not found O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Deb\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) O4 - HKCU..\Run: [MimarSinan Rubber Ducky Update Setup for All Users] C:\ProgramData\{C357FF4B-BB69-4DC2-9869-55F052974DA8}\Rubber Ducky.exe (MimarSinan International ) O4 - HKCU..\Run: [Pando] C:\Program Files (x86)\Pando Networks\Pando\pando.exe (Pando Networks) O4 - HKCU..\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.) O4 - HKCU..\Run: [Window Washer] C:\Program Files (x86)\Webroot\Washer\wwDisp.exe (Webroot Software, Inc.) O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found O8:64bit: - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html File not found O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html File not found O8:64bit: - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html File not found O8:64bit: - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm () O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html File not found O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html File not found O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html File not found O8 - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm () O9:64bit: - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files (x86)\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE_x64.dll () O9:64bit: - Extra 'Tools' menuitem : Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files (x86)\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE_x64.dll () O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus.com/select/asusTek_sys_ctrl3.cab (asusTek_sysctrl Class) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} http://imikimi.com/download/imikimi_plugin_0.5.1.cab (Imikimi_activex_plugin Control) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FFE16A46-948F-4F90-964E-E3E86D151408}: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\System32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) Quote
debi239 Posted February 2, 2013 Author Posted February 2, 2013 MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Event Reminder.lnk - C:\Program Files (x86)\Broderbund\PrintMaster\pmremind.exe - (Broderbund Properties LLC) MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk - C:\Windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe - () MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe - (Hewlett-Packard Co.) MsConfig:64bit - StartUpReg: AdobeAAMUpdater-1.0 - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) MsConfig:64bit - StartUpReg: facemoods - hkey= - key= - File not found MsConfig:64bit - StartUpReg: HP Software Update - hkey= - key= - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Hewlett-Packard) MsConfig:64bit - StartUpReg: InstallIQUpdater - hkey= - key= - C:\Program Files (x86)\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC) MsConfig:64bit - StartUpReg: Messenger (Yahoo!) - hkey= - key= - C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.) MsConfig:64bit - StartUpReg: PWRISOVM.EXE - hkey= - key= - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.) MsConfig:64bit - StartUpReg: Startup Defender - hkey= - key= - File not found MsConfig:64bit - StartUpReg: TelevisionFanatic Browser Plugin Loader - hkey= - key= - File not found MsConfig:64bit - State: "startup" - Reg Error: Key error. CREATERESTOREPOINT Restore point Set: OTL Restore Point ========== Files/Folders - Created Within 30 Days ========== [2013/02/01 17:44:54 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Deb\Desktop\OTL.scr [2013/02/01 17:25:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{42234831-8B08-43B1-96A6-6045FEE150A9} [2013/02/01 07:38:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013/02/01 07:37:59 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2013/02/01 07:36:21 | 010,156,344 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Deb\Desktop\mbam-setup-1.70.0.1100.exe [2013/02/01 05:25:08 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{95CF7132-8491-4CD2-9E5E-97B82B87D47A} [2013/01/31 10:01:41 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{5047659E-C3FF-4879-99C3-07F8CA609FA6} [2013/01/31 08:33:24 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{0287C327-9C05-46BF-B7A1-9086769A2D0C} [2013/01/30 08:59:26 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{0731825A-EC4A-41FA-8E38-BAD4E1A1B061} [2013/01/29 08:42:50 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{553FB952-2015-4903-A09D-4F0E26A63C5E} [2013/01/28 08:41:45 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{A1A41F13-03AE-4BBA-A4E2-D4A593DF6E31} [2013/01/27 09:26:47 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\Malwarebytes [2013/01/27 09:26:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2013/01/27 09:26:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2013/01/27 09:25:33 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\Programs [2013/01/27 08:40:52 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E65F738D-9443-4971-9352-F66A692643C4} [2013/01/24 19:47:50 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{740A36B2-621C-4272-845E-DF12E99C78C1} [2013/01/24 07:47:23 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{6B52BFC3-84B8-4BC2-896D-8D8E04863DC9} [2013/01/20 09:13:03 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E2E3FE0B-6FBE-4A1E-AF47-BD5041A3624B} [2013/01/19 21:08:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{B966D18E-7F69-47D5-8401-8BA6A11669E6} [2013/01/19 19:33:46 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client [2013/01/19 09:51:27 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\Anvisoft [2013/01/19 09:51:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anvisoft [2013/01/19 09:51:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Anvisoft [2013/01/19 05:54:49 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\FixBee [2013/01/19 05:54:49 | 000,000,000 | ---D | C] -- C:\ProgramData\FixBee [2013/01/18 21:07:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{2E3324BA-5C42-4324-A5C6-7336F189E63C} [2013/01/18 14:39:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FixBee Disk Optimizer [2013/01/18 14:38:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FixBee [2013/01/18 14:38:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SRToolbar [2013/01/18 09:07:11 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{8EC434FA-420B-47B7-9554-BD9441DB3FFE} [2013/01/18 08:14:08 | 000,000,000 | ---D | C] -- C:\Windows\pss [2013/01/17 19:55:16 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\WinRAR [2013/01/17 19:55:15 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\DownTango [2013/01/17 19:55:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DownTango [2013/01/17 19:54:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Red Sky [2013/01/17 19:53:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Protected Search [2013/01/17 09:06:14 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{2CA50C82-3F07-4F48-9707-A62F0F77B23D} [2013/01/16 17:48:37 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{4A67868C-A839-44EC-B25E-87C83532E0DF} [2013/01/16 07:05:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard 5.6.5 [2013/01/16 05:48:02 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{18C7CAE6-2D57-42B1-B823-8C0E23BBA00C} [2013/01/15 09:13:53 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{D8C64BCE-62CF-4985-90EC-1082D4CA5EF3} [2013/01/14 15:29:14 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E3C4DD56-2019-4342-B117-6974C6D81EEC} [2013/01/13 04:56:07 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{1E9789FD-D1E5-4F0A-8197-3C96A6246FC6} [2013/01/12 10:29:12 | 000,000,000 | ---D | C] -- C:\Users\Deb\Desktop\Good_morning! [2013/01/12 08:22:48 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{D5C04CAA-7B0D-46DC-A43D-5A8934F1A00A} [2013/01/11 16:37:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{86AE18EA-D2D7-4F78-A316-559CD87554C6} [2013/01/11 04:37:23 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{38263396-8971-473D-9686-D9E0B043A04E} [2013/01/10 07:19:53 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{66363DFD-6584-42C3-ABF6-26DF6393D0A3} [2013/01/09 08:19:55 | 000,750,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll [2013/01/09 08:19:55 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll [2013/01/09 08:19:39 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll [2013/01/09 08:19:36 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usp10.dll [2013/01/09 08:19:27 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\fpb.rs [2013/01/09 08:19:27 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\SysNative\fpb.rs [2013/01/09 08:19:27 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\oflc-nz.rs [2013/01/09 08:19:27 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\SysNative\oflc-nz.rs [2013/01/09 08:19:27 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegibbfc.rs [2013/01/09 08:19:27 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\csrr.rs [2013/01/09 08:19:27 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\SysNative\csrr.rs [2013/01/09 08:19:27 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\cob-au.rs [2013/01/09 08:19:27 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\SysNative\cob-au.rs [2013/01/09 08:19:26 | 002,746,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gameux.dll [2013/01/09 08:19:26 | 002,576,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gameux.dll [2013/01/09 08:19:26 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wpc.dll [2013/01/09 08:19:26 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegibbfc.rs [2013/01/09 08:19:26 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\usk.rs [2013/01/09 08:19:26 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\SysNative\usk.rs [2013/01/09 08:19:26 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\grb.rs [2013/01/09 08:19:26 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\SysNative\grb.rs [2013/01/09 08:19:26 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi-pt.rs [2013/01/09 08:19:26 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi-pt.rs [2013/01/09 08:19:26 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi.rs [2013/01/09 08:19:26 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi.rs [2013/01/09 08:19:26 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\djctq.rs [2013/01/09 08:19:26 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\SysNative\djctq.rs [2013/01/09 08:19:25 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Wpc.dll [2013/01/09 08:19:25 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\cero.rs [2013/01/09 08:19:25 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\SysNative\cero.rs [2013/01/09 08:19:25 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\esrb.rs [2013/01/09 08:19:25 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\SysNative\esrb.rs [2013/01/09 08:19:25 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\oflc.rs [2013/01/09 08:19:25 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\SysNative\oflc.rs [2013/01/09 08:19:25 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi-fi.rs [2013/01/09 08:19:25 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi-fi.rs [2013/01/09 08:18:51 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll [2013/01/09 08:18:49 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll [2013/01/09 08:18:49 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll [2013/01/09 08:18:48 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe [2013/01/09 08:18:48 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll [2013/01/09 08:18:48 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll [2013/01/09 08:18:48 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll [2013/01/09 08:18:48 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2013/01/09 08:18:48 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll [2013/01/09 08:18:48 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll [2013/01/09 08:18:48 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll [2013/01/09 08:18:48 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll [2013/01/09 08:18:48 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2013/01/09 08:18:48 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll [2013/01/09 08:18:48 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll [2013/01/09 08:18:48 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll [2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll [2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll [2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll [2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll [2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll [2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll [2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll [2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll [2013/01/09 08:18:47 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll [2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll [2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll [2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll [2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll [2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll [2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll [2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll [2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll [2013/01/09 08:18:46 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2013/01/09 08:18:46 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2013/01/09 08:18:46 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll [2013/01/09 08:18:46 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll [2013/01/09 08:18:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll [2013/01/09 08:18:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll [2013/01/09 08:18:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll [2013/01/09 08:18:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll [2013/01/09 08:18:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll [2013/01/09 08:18:45 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll [2013/01/09 08:18:45 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll [2013/01/09 08:18:45 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll [2013/01/09 08:18:45 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2013/01/09 08:18:29 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskhost.exe [2013/01/09 08:03:43 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{21D7C0B8-0255-4EBE-95C2-63E2609F7963} [2013/01/08 07:54:44 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{08D71E41-6BCB-4D7E-8115-90912FEFFEDF} [2013/01/07 06:58:03 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{AC76A610-688C-47B5-9263-19DF34042B56} [2013/01/06 06:04:06 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{C3841884-8F5F-4B2D-BB68-75D301AD91B2} [2013/01/05 07:11:51 | 000,000,000 | ---D | C] -- C:\Users\Deb\Documents\Medical Files [2013/01/05 06:03:16 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{3424CDF3-9FE0-42D6-B607-687B3EE116CC} [2008/08/11 22:45:20 | 000,155,648 | ---- | C] (ASUS) -- C:\Program Files (x86)\Common Files\MSIactionall.dll [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013/02/01 17:44:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Deb\Desktop\OTL.scr [2013/02/01 17:35:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013/02/01 17:35:00 | 000,000,314 | ---- | M] () -- C:\Windows\tasks\PrintProjects Communicator.job [2013/02/01 17:10:05 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013/02/01 10:10:01 | 000,000,888 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013/02/01 08:34:00 | 000,000,490 | ---- | M] () -- C:\Windows\tasks\03-31-2011_103440.job [2013/02/01 07:38:01 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2013/02/01 07:36:25 | 010,156,344 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Deb\Desktop\mbam-setup-1.70.0.1100.exe [2013/02/01 06:37:30 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/02/01 06:37:30 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/02/01 06:33:31 | 000,792,550 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013/02/01 06:33:31 | 000,669,298 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013/02/01 06:33:31 | 000,125,452 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013/02/01 06:31:37 | 000,000,344 | ---- | M] () -- C:\Windows\lgfwup.ini [2013/02/01 06:28:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013/02/01 06:28:48 | 3193,765,888 | -HS- | M] () -- C:\hiberfil.sys [2013/01/20 06:30:57 | 000,010,841 | ---- | M] () -- C:\Users\Deb\Documents\paisley.pat [2013/01/18 14:39:04 | 000,000,997 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FixBee Disk Optimizer.lnk [2013/01/18 14:39:03 | 000,002,057 | ---- | M] () -- C:\Users\Public\Desktop\FixBee Disk Optimizer.lnk [2013/01/18 09:41:22 | 000,001,056 | ---- | M] () -- C:\prefs.js [2013/01/17 19:55:01 | 000,000,000 | ---- | M] () -- C:\end [2013/01/17 19:54:59 | 000,000,000 | ---- | M] () -- C:\extensions.sqlite [2013/01/17 19:53:11 | 000,002,236 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Snagit 10.lnk [2013/01/17 19:53:11 | 000,001,897 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\TOSHIBA DVD PLAYER.lnk [2013/01/17 19:53:11 | 000,001,448 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Wondershare DVD Slideshow Builder Standard.lnk [2013/01/17 19:53:11 | 000,001,385 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Wondershare Photo Collage Studio.lnk [2013/01/17 19:53:11 | 000,001,319 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Picture Collage Maker.lnk [2013/01/17 19:53:11 | 000,001,303 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk [2013/01/17 19:53:11 | 000,001,279 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Pixpedia Publisher.lnk [2013/01/17 19:53:11 | 000,001,213 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Copy Pro.lnk [2013/01/17 19:53:11 | 000,001,085 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\XnView.lnk [2013/01/17 19:53:11 | 000,000,955 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Spyware Terminator.lnk [2013/01/17 19:53:11 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Xara3D6.lnk [2013/01/17 19:53:11 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\RegistryBooster.lnk [2013/01/17 19:53:11 | 000,000,426 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk [2013/01/17 19:53:11 | 000,000,408 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk [2013/01/17 19:53:10 | 000,002,825 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Jasc Paint Shop Pro 9.lnk [2013/01/17 19:53:10 | 000,002,813 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Jasc Paint Shop Pro 9 (1).lnk [2013/01/17 19:53:10 | 000,002,381 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [2013/01/17 19:53:10 | 000,002,300 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\mediAvatar Photo to Flash.lnk [2013/01/17 19:53:10 | 000,002,143 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk [2013/01/17 19:53:10 | 000,002,116 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Express.lnk [2013/01/17 19:53:10 | 000,001,579 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2013/01/17 19:53:10 | 000,001,315 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Free GMT AVI to DVD.lnk [2013/01/17 19:53:10 | 000,001,238 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk [2013/01/17 19:53:10 | 000,001,145 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\MiPony.lnk [2013/01/17 19:53:10 | 000,001,109 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\NeoPaint.lnk [2013/01/17 19:53:10 | 000,001,006 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk [2013/01/17 19:53:10 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk [2013/01/17 19:53:10 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Log Analysis - Sax2.lnk [2013/01/17 19:53:10 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Intrusion Detection System - Sax2.lnk [2013/01/17 19:53:09 | 000,002,231 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Corel Paint Shop Pro X.lnk [2013/01/17 19:53:09 | 000,001,498 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Batch Photo Watermarker.lnk [2013/01/17 19:53:09 | 000,001,362 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\ConvertXtoDVD 4.lnk [2013/01/17 19:53:09 | 000,001,265 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FoxTab AVI Converter.lnk [2013/01/17 19:53:09 | 000,001,259 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Free Easy Burner.lnk [2013/01/17 19:53:09 | 000,001,221 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Final*******.lnk [2013/01/17 19:53:09 | 000,001,214 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\easyQuizzy.lnk [2013/01/17 19:53:09 | 000,001,149 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\DVD Shrink 3.2.lnk [2013/01/17 19:53:09 | 000,001,149 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\BatchInpaint.lnk [2013/01/17 19:53:09 | 000,001,119 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\CollageIt.lnk [2013/01/17 19:53:08 | 000,002,584 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Aiseesoft Total Media Converter.lnk [2013/01/17 19:53:08 | 000,002,344 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions.lnk [2013/01/17 19:53:08 | 000,002,325 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\4Media Photo Slideshow Maker.lnk [2013/01/17 19:53:08 | 000,002,269 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\4Media Ringtone Maker.lnk [2013/01/17 19:53:08 | 000,001,254 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\AnyPic Image Resizer Pro.lnk [2013/01/17 19:53:08 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 2010 Advanced.lnk [2013/01/17 19:24:50 | 000,045,169 | ---- | M] () -- C:\Users\Deb\Desktop\PolkaDot_Baby_Blanket.pdf [2013/01/11 04:33:21 | 005,620,584 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013/01/10 07:42:38 | 000,786,766 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2013/01/09 10:35:18 | 000,697,864 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2013/01/09 10:35:18 | 000,074,248 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2013/01/03 07:18:52 | 000,015,360 | ---- | M] () -- C:\Windows\Launcher.exe [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2013/02/01 07:38:01 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2013/01/20 06:30:57 | 000,010,841 | ---- | C] () -- C:\Users\Deb\Documents\paisley.pat [2013/01/18 14:39:04 | 000,000,997 | ---- | C] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FixBee Disk Optimizer.lnk [2013/01/18 14:39:03 | 000,002,057 | ---- | C] () -- C:\Users\Public\Desktop\FixBee Disk Optimizer.lnk [2013/01/17 19:54:59 | 000,000,000 | ---- | C] () -- C:\extensions.sqlite [2013/01/17 19:54:50 | 000,000,000 | ---- | C] () -- C:\end [2013/01/17 19:53:13 | 000,015,360 | ---- | C] () -- C:\Windows\Launcher.exe [2013/01/17 19:24:49 | 000,045,169 | ---- | C] () -- C:\Users\Deb\Desktop\PolkaDot_Baby_Blanket.pdf [2012/08/20 09:46:35 | 000,384,844 | ---- | C] () -- C:\Users\Deb\AppData\Local\funmoods-speeddial.crx [2012/08/12 08:45:52 | 000,004,470 | ---- | C] () -- C:\Users\Deb\pspbrwse.jbf [2012/04/06 14:07:58 | 000,000,344 | ---- | C] () -- C:\Windows\lgfwup.ini [2011/11/27 07:09:54 | 000,161,694 | ---- | C] () -- C:\Windows\Animated Wallpaper Maker Uninstaller.exe [2011/11/13 13:30:25 | 000,000,288 | ---- | C] () -- C:\Windows\ODBC.INI [2011/11/13 13:30:24 | 000,001,644 | ---- | C] () -- C:\Windows\ODBCINST.INI [2011/10/05 08:31:08 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini [2011/10/05 08:31:07 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2011/10/05 08:31:07 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2011/09/28 04:49:43 | 000,087,040 | ---- | C] () -- C:\Windows\UnGins.exe [2011/08/15 12:34:07 | 000,044,544 | ---- | C] () -- C:\Windows\SysWow64\gif89.dll [2011/08/15 12:33:54 | 000,000,285 | ---- | C] () -- C:\Windows\SIERRA.INI [2011/08/15 04:20:07 | 000,007,597 | ---- | C] () -- C:\Users\Deb\AppData\Local\Resmon.ResmonCfg [2011/08/06 03:20:57 | 000,161,807 | ---- | C] () -- C:\Windows\Animated Screensaver Maker Uninstaller.exe [2011/07/11 13:27:17 | 000,026,000 | ---- | C] () -- C:\Windows\SysWow64\PteVideo.dll [2011/07/01 06:16:12 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini [2011/05/21 03:16:40 | 000,162,598 | ---- | C] () -- C:\Windows\DP Animation Maker Uninstaller.exe [2011/04/23 06:19:51 | 000,027,648 | R--- | C] () -- C:\Windows\Setup_ck.exe [2011/04/23 06:19:51 | 000,024,608 | ---- | C] () -- C:\Windows\SysWow64\Ckldrv.sys [2011/04/23 06:19:51 | 000,018,432 | ---- | C] () -- C:\Windows\Setup_ck.dll [2011/04/23 06:19:51 | 000,011,776 | ---- | C] () -- C:\Windows\Ckrfresh.exe [2011/04/20 09:44:49 | 000,000,368 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\wklnhst.dat [2011/03/23 16:54:15 | 000,786,766 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/03/18 16:13:04 | 000,000,042 | ---- | C] () -- C:\Windows\PCSPATS.DAT [2011/02/19 19:42:30 | 000,000,091 | ---- | C] () -- C:\Windows\Crypkey.ini [2010/12/21 10:06:03 | 000,000,069 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\IncrediMail Collection ManagerIcm.ini [2010/12/19 11:55:26 | 000,001,057 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\vso_ts_preview.xml [2010/12/15 12:16:53 | 000,035,840 | ---- | C] () -- C:\Users\Deb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/12/15 11:14:41 | 000,000,080 | -HS- | C] () -- C:\ProgramData\.zreglib [2010/12/11 13:35:07 | 019,985,265 | ---- | C] () -- C:\ProgramData\vlc-1.1.5-win32.exe [2009/04/08 11:31:56 | 000,106,496 | ---- | C] () -- C:\Program Files (x86)\Common Files\CPInstallAction.dll [2009/03/27 10:14:04 | 000,033,940 | ---- | C] () -- C:\Users\Deb\qotw.jpg [2009/03/22 13:46:48 | 000,016,769 | ---- | C] () -- C:\Users\Deb\flowers.PLC [2009/03/03 11:32:32 | 000,705,558 | ---- | C] () -- C:\Users\Deb\QBD_-_LaceBorderNFramesScripts.zip [2009/02/16 19:30:54 | 000,658,608 | ---- | C] () -- C:\Program Files (x86)\MagicDVDRipper.exe [2009/02/09 11:56:30 | 000,313,344 | ---- | C] () -- C:\Program Files (x86)\hjsplit.exe [2009/01/18 08:46:29 | 000,001,024 | ---- | C] () -- C:\Users\Deb\.rnd [2008/05/22 09:35:54 | 000,051,962 | ---- | C] () -- C:\Program Files (x86)\Common Files\banner.jpg [2006/11/02 06:50:50 | 000,000,174 | -HS- | C] () -- C:\Program Files (x86)\desktop (1).ini ========== ZeroAccess Check ========== [2011/07/03 14:29:46 | 000,000,000 | ---D | M] -- C:\$Recycle.bin\S-1-5-21-4070860634-2794675311-1628887733-1000\$ROXZ5D7\L [2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 23:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 19:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 06:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 19:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2011/04/27 17:18:59 | 000,000,000 | -HSD | M] -- C:\Users\Deb\AppData\Roaming\.# [2012/03/30 12:58:05 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\4Media [2013/01/19 19:38:06 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Anvisoft [2011/07/03 04:19:51 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\AnyPic Image Converter [2011/05/08 10:59:39 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\AnyPic Image Resizer Pro [2012/01/09 07:02:50 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Ashampoo [2011/11/14 13:03:49 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\BlitzCards [2011/06/21 08:31:19 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Byngo [2011/06/27 14:30:19 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\calibre [2011/11/19 09:21:55 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2011/10/28 05:57:48 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Digiarty [2010/12/17 12:55:31 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\DVDVideoSoft [2011/03/28 05:24:17 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Engelmann Media [2011/02/02 14:12:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Final******* [2013/01/19 19:48:35 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\FixBee [2012/03/30 12:58:05 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\FreeBurner [2011/02/01 19:03:46 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\gmt_free_avi_to_dvd [2010/12/10 13:18:51 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\HiYo [2010/12/11 20:29:08 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\ImageBadger [2010/12/21 10:06:03 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\IncrediMail Collection Manager [2011/04/23 05:54:59 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\IObit [2010/12/15 10:02:00 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Jasc [2011/04/10 04:32:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Leawo [2011/12/25 05:54:56 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\LifeSniffer [2011/04/03 05:29:09 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\mediAvatar [2011/12/14 16:38:12 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Mipony [2011/02/18 17:55:10 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Mobipocket [2011/04/10 04:32:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Moyea [2011/12/03 06:19:44 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Nik Software [2012/10/12 05:02:38 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Nuclear Coffee [2012/04/08 06:07:10 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PearlMountain [2011/04/27 18:09:56 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PearlMountainSoft [2011/01/18 15:25:42 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Pixpedia Publisher [2012/10/12 14:11:08 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PlayFirst [2011/04/10 04:32:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PPT2DVD [2011/10/05 08:54:49 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\QuizResultsAnalyzer.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1 [2012/08/20 09:46:30 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\SendSpace [2011/06/14 07:04:49 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Softplicity [2011/11/12 22:18:28 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Solveig Multimedia [2012/05/30 10:37:07 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Temp [2010/12/28 12:10:38 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Template [2011/10/15 13:45:53 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Thinstall [2011/08/01 17:33:44 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Tibo Software [2011/04/06 14:52:04 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Titanium Gears [2012/06/06 06:39:18 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Visan [2011/04/20 06:00:25 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\visualsearchpony.com [2010/12/19 11:56:10 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Vso [2010/12/10 13:55:37 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\WeatherBug [2010/12/10 13:26:42 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Windows Live Writer [2012/01/30 08:02:39 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\XnView ========== Purity Check ========== ========== Custom Scans ========== ========== Drive Information ========== Physical Drives --------------- Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media Interface type: IDE Media Type: Fixed hard disk media Model: ST9500325AS Partitions: 3 Status: OK Status Info: 0 Partitions --------------- DeviceID: Disk #0, Partition #0 PartitionType: Unknown Bootable: False BootPartition: False PrimaryPartition: True Size: 12.00GB Starting Offset: 1048576 Hidden sectors: 0 DeviceID: Disk #0, Partition #1 PartitionType: Installable File System Bootable: True BootPartition: True PrimaryPartition: True Size: 116.00GB Starting Offset: 12583960576 Hidden sectors: 0 DeviceID: Disk #0, Partition #2 PartitionType: Extended w/Extended Int 13 Bootable: False BootPartition: False PrimaryPartition: False Size: 338.00GB Starting Offset: 137610919936 Hidden sectors: 0 < %SYSTEMDRIVE%\*.* > [2005/07/06 13:12:58 | 000,060,370 | ---- | M] () -- C:\Air Freshener Covers Series BK1 1.gif [2005/07/06 13:13:14 | 000,057,415 | ---- | M] () -- C:\Air Freshener Covers Series BK1 2.gif [2005/07/06 13:13:30 | 000,064,908 | ---- | M] () -- C:\Air Freshener Covers Series BK1 3.gif [2005/07/06 13:13:46 | 000,059,575 | ---- | M] () -- C:\Air Freshener Covers Series BK1 4.gif [2005/07/06 13:14:06 | 000,061,367 | ---- | M] () -- C:\Air Freshener Covers Series BK1 5.gif [2005/07/06 13:14:24 | 000,045,478 | ---- | M] () -- C:\Air Freshener Covers Series BK1 6.gif [2005/07/06 13:14:40 | 000,028,722 | ---- | M] () -- C:\Air Freshener Covers Series BK1 bc.jpg [2005/07/06 13:12:40 | 000,024,648 | ---- | M] () -- C:\Air Freshener Covers Series BK1.jpg [2010/11/20 06:40:07 | 000,383,786 | RHS- | M] () -- C:\bootmgr [2009/07/29 00:03:37 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK [2010/03/16 07:13:46 | 000,013,114 | ---- | M] () -- C:\devlist.txt [2013/01/17 19:55:01 | 000,000,000 | ---- | M] () -- C:\end [2013/01/17 19:54:59 | 000,000,000 | ---- | M] () -- C:\extensions.sqlite [2010/03/16 07:13:46 | 000,000,009 | ---- | M] () -- C:\Finish.log [2013/02/01 06:28:48 | 3193,765,888 | -HS- | M] () -- C:\hiberfil.sys [2010/03/16 07:37:58 | 000,963,411 | ---- | M] () -- C:\inject.log.txt [2009/06/25 19:14:43 | 001,048,576 | RH-- | M] () -- C:\K60IJ.BIN [2009/08/09 21:04:57 | 000,000,019 | ---- | M] () -- C:\K60IJ_WIN7.10 [2011/04/09 00:54:52 | 002,729,984 | ---- | M] () -- C:\KahlownSetup.msi [2013/02/01 06:28:53 | 4258,357,248 | -HS- | M] () -- C:\pagefile.sys [2010/03/15 18:03:22 | 000,000,105 | ---- | M] () -- C:\Pass.txt [2009/12/16 23:48:04 | 000,000,277 | ---- | M] () -- C:\Patch_Win7.log [2011/01/17 10:49:26 | 018,420,224 | ---- | M] () -- C:\Pixo.msi [2013/01/18 09:41:22 | 000,001,056 | ---- | M] () -- C:\prefs.js [2009/08/09 21:04:57 | 000,000,007 | ---- | M] () -- C:\RECOVERY.DAT [2011/07/20 06:34:19 | 000,004,096 | RHS- | M] () -- C:\RESCUMBR.BIN [2013/01/17 19:53:12 | 000,000,351 | ---- | M] () -- C:\SetSearchAndHomepageInBrowserLog.txt [2012/08/05 10:39:00 | 000,000,540 | ---- | M] () -- C:\settings.ini [2010/03/16 07:00:55 | 000,000,090 | ---- | M] () -- C:\setup.log [2010/03/16 07:10:05 | 000,000,170 | ---- | M] () -- C:\SumHidd.txt [2010/03/16 07:09:51 | 000,000,098 | ---- | M] () -- C:\SumOS.txt [2009/09/16 12:04:46 | 000,000,024 | ---- | M] () -- C:\v82.txt < %systemroot%\system32\Spool\prtprocs\w32x86\*.dll > < %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles > [2012/10/27 00:23:14 | 011,020,800 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ieframe.dll [1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] < %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\system32\*.exe /lockedfiles > [1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ] < %systemroot%\System32\config\*.sav > < %PROGRAMFILES%\* > [2008/01/20 20:43:21 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop (1).ini [2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini [2007/02/01 18:02:54 | 000,313,344 | ---- | M] () -- C:\Program Files (x86)\hjsplit.exe [2006/04/02 01:23:06 | 000,658,608 | ---- | M] () -- C:\Program Files (x86)\MagicDVDRipper.exe < %USERPROFILE%\..|smtmp;true;true;true /FP > < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU > < hklm\software\clients\startmenuinternet|command /rs > HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --show-icons [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --hide-icons [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2010/11/20 06:17:13 | 000,176,128 | ---- | M] (Microsoft Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2010/11/20 06:17:13 | 000,176,128 | ---- | M] (Microsoft Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2010/11/20 06:17:13 | 000,176,128 | ---- | M] (Microsoft Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -extoff [2010/11/20 06:22:51 | 000,673,040 | ---- | M] (Microsoft Corporation) HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files (x86)\Internet Explorer\iexplore.exe [2010/11/20 06:22:51 | 000,673,040 | ---- | M] (Microsoft Corporation) < hklm\software\clients\startmenuinternet|command /64 /rs > 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --SHOW-ICONS [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.) 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --HIDE-ICONS [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.) 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --MAKE-DEFAULT-BROWSER [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.) 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.) 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW [2009/07/13 19:39:12 | 000,073,728 | ---- | M] (Microsoft Corporation) 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL [2009/07/13 19:39:12 | 000,073,728 | ---- | M] (Microsoft Corporation) 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE [2009/07/13 19:39:12 | 000,073,728 | ---- | M] (Microsoft Corporation) 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF [2010/11/20 06:22:51 | 000,673,040 | ---- | M] (Microsoft Corporation) 64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE [2010/11/20 06:22:51 | 000,673,040 | ---- | M] (Microsoft Corporation) ========== Alternate Data Streams ========== @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:22741C1F @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:A31FAD21 < End of report > Quote
debi239 Posted February 2, 2013 Author Posted February 2, 2013 OTL Extras logfile created on: 2/1/2013 5:52:35 PM - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Deb\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.97 Gb Total Physical Memory | 1.43 Gb Available Physical Memory | 35.95% Memory free 7.93 Gb Paging File | 5.56 Gb Available in Paging File | 70.17% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 116.44 Gb Total Space | 26.69 Gb Free Space | 22.92% Space Free | Partition Type: NTFS Drive D: | 337.60 Gb Total Space | 87.33 Gb Free Space | 25.87% Space Free | Partition Type: NTFS Computer Name: DEB-PC | User Name: Deb | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .html [@ = htmlfile] -- Reg Error: Key error. File not found ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" () Directory [bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [LovelyFolders] -- C:\Program Files (x86)\Lovely Folders\LFolders.exe "%1" (Lovelysoft) Directory [PlayWithVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [AddToPlaylistVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" () Directory [bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.) Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Directory [LovelyFolders] -- C:\Program Files (x86)\Lovely Folders\LFolders.exe "%1" (Lovelysoft) Directory [PlayWithVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" () Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{09420363-7A8A-4FA1-B16D-217877D3C30C}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | "{0AD6C65D-0EA8-4985-A7DA-56EE32509D56}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{16BA28AB-0081-4362-847F-DA36B36A0A27}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe | "{18E6E986-CE1A-4086-9640-1B45DDD631FA}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 | "{1ABF8D59-E6DA-4DE0-BF87-2A9F72ACBFA5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{20A3FAFB-9CC2-471D-80C2-AE6B331F8354}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface | "{29F51CD3-C1AD-4A36-9216-AAF8093DC64B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{36678064-DB2B-431F-956F-AC91E57E4F16}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{3791DCB3-43C3-4DE1-80D3-C453AA67200F}" = lport=138 | protocol=17 | dir=in | app=system | "{38B7FE68-261C-4FE0-B70C-3305162A9A73}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery | "{4EBBDFA6-89F3-4E7C-BB3D-39E724B33831}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{4FF65309-1A0B-4BB2-88A8-D47489C38DB7}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | "{53424228-80F3-4F48-8C11-15668BD41957}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{5BB8FA0B-834A-4B4F-98C4-DD97D6107EDE}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 | "{5FB42AA2-F072-4C49-B2C4-DB4114258E0F}" = rport=10243 | protocol=6 | dir=out | app=system | "{5FCFA5EC-ECB6-4889-BB4E-423C3C30C0E0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{64AF56FF-8F05-44AF-8B94-73B3CD2A4540}" = lport=10243 | protocol=6 | dir=in | app=system | "{6904FB5C-6436-4A36-B98F-015B8D0339D8}" = lport=2869 | protocol=6 | dir=in | app=system | "{6D8065E3-7C49-4563-A964-44F980522819}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{6EE8837B-A34A-4608-ACAE-B9AD2B4AFBDB}" = rport=137 | protocol=17 | dir=out | app=system | "{9D259EC5-A808-4BEB-99D5-0310163666F8}" = lport=139 | protocol=6 | dir=in | app=system | "{A4358BA7-3A66-48E2-A9FF-C4DB21AAEA3E}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery | "{A8BC8FD3-55EF-4988-9D2F-7B6F770E3968}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{AF734322-E583-4195-A0FA-2891178746F3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{B0CAA045-4311-4D03-9770-CCBD29A8A5BA}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B28F8BAF-BA5B-4D98-B14A-46CEAAD5416F}" = rport=139 | protocol=6 | dir=out | app=system | "{B2CB7B88-DC21-43B9-9386-36F9D001E79D}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe | "{B8F5DF16-0CEE-439B-BEB4-39B1BDF2E878}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{B9E4AAFA-6A5D-4F0C-9BD9-4038425331FC}" = lport=445 | protocol=6 | dir=in | app=system | "{C4A71CD3-D502-4C27-8D36-BC151EC86FA6}" = rport=138 | protocol=17 | dir=out | app=system | "{C888BECC-8399-433D-B5C6-29DDA78F8BE8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{CB25B4D3-A19B-4DFD-A57A-9B9BF118D105}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{CD808F78-38FB-4B5F-AECE-F0BBF2405D74}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe | "{CDDAB182-4079-41CB-A3E0-C62E4A33516F}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{D7638201-420F-4EFF-BD97-CCAFEF24C7FA}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe | "{DC3F4419-602E-44F0-ACAF-6682B3A6BB34}" = lport=137 | protocol=17 | dir=in | app=system | "{E703D467-9229-4E32-B44F-F565FAB4C3F5}" = rport=445 | protocol=6 | dir=out | app=system | "{F493EE6C-3798-4269-8D82-714B24C6E6F8}" = lport=49166 | protocol=6 | dir=in | name=akamai netsession interface | "{F62521A8-1CB6-4AC0-8715-CBAAE964F8E9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{FB10AB82-DEF7-4E1C-A38D-2915CC0E4975}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{FCB0B73A-9AE2-4912-A77E-6228A888D9EF}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{01CB0866-F8ED-48CF-B335-E0F882EDE588}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | "{05AB7D77-1AB1-4563-A5E3-78E12A13C1CB}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | "{086B1134-CBB7-497A-A997-D9EFCE8001C5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | "{08B92A59-6CEE-43B9-BFD3-254F379607EB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | "{1C1B540A-C68C-4E83-83BB-B6356F4D72E8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{212AE434-4794-4F2A-9A19-33B01D47EFD6}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | "{263EB0E1-ACE1-4D6D-911A-448918EC6BAE}" = protocol=6 | dir=in | app=c:\users\deb\appdata\local\akamai\netsession_win.exe | "{30BC4EB4-D801-4ABD-8AC0-5768AF967299}" = protocol=6 | dir=in | app=c:\programdata\kodak\installer\setup.exe | "{31D267AC-CC03-4741-8870-B4718A2348D3}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\center\aiohomecenter.exe | "{3939FFEA-B3BD-4446-8CB9-873E8EAF1F64}" = protocol=17 | dir=in | app=c:\users\deb\appdata\local\akamai\netsession_win.exe | "{3C188F9F-DD38-49A7-A257-9E87B0A61405}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{3E78EE9D-289C-4596-8A82-210BDAAB3C2F}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe | "{42C93078-E31A-4473-A5FD-F8EC9A7B3E35}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\pando\pando.exe | "{436B4BF2-51A4-41C3-9886-F7957106CDE1}" = protocol=17 | dir=in | app=c:\programdata\kodak\installer\setup.exe | "{43C6BCA9-E729-4476-9F64-9DC43A14B536}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | "{440120BC-665F-4A8F-B113-B6FEBD1C8B41}" = dir=out | app=c:\program files (x86)\protected search\protectedsearch.exe | "{466C76F7-0BC4-41C5-8A57-88BADD73D509}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\firmware\kodakaioupdater.exe | "{53401D4D-9306-4C24-B438-43FCDCE2B7CC}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\center\aiohomecenter.exe | "{5A98B82A-5F32-498C-91AA-8D1B4D31B85E}" = dir=in | app=c:\program files (x86)\finaltorrent\finaltorrent.exe | "{6352F1D8-2543-4387-86C2-E9640C0AA8A3}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{66552376-21C6-4E64-B653-912F29B63F04}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{68221AF8-6990-4CA3-9D6A-6721B2116E85}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | "{6BD7B9FF-22CB-40F5-86BA-4FA7A4454860}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{7061CAB0-CD28-420C-BD93-3C5544A03CBB}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{7145CB7E-C0C8-4618-ACAC-30EB1079AA06}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\pando\pando.exe | "{73012904-3E02-41D3-927A-A0E76BCD6FFE}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{76D16319-360E-43E9-B333-408135723B42}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{76DF68B8-7A1C-41B4-99DD-9BF92669ABC1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{77FD5C2D-0415-43BD-A4A3-AF3D6ECDCB4C}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{802BA8A5-7E2A-4C15-AD72-27B0778389EB}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | "{84B9DB2F-382F-435E-9AA0-4EED0A20097F}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\center\networkprinterdiscovery.exe | "{858CEDF3-BFA4-4C89-9F00-F6613A8E98CC}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\center\networkprinterdiscovery.exe | "{8F50342A-BEA0-44DF-ADF1-8939E3168856}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{8F88F43D-868D-4969-9839-B5A72F0BE6A8}" = dir=in | app=c:\program files (x86)\pando networks\pando\pando.exe | "{925A5C26-4FC3-4608-807B-921E0633361C}" = dir=in | app=c:\program files (x86)\protected search\protectedsearch.exe | "{93A0A1A5-AF75-42C4-A8E6-34B68A5835C8}" = protocol=6 | dir=in | app=c:\users\deb\appdata\local\microsoft\windows\temporary internet files\content.ie5\rwy1ik2t\aviconvertersetup[1].exe | "{96F35B97-0FB0-496C-B9F2-6E1597017791}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | "{973341D9-CB84-4595-ADF6-2B8EE21DCC72}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{981A034C-1263-49DF-8417-39E4AC586785}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | "{98DAA843-3BF7-40FE-BB79-8F1342FBC380}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | "{9DD47EF7-8560-49D0-861B-E5F1EFA11875}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{A02FC901-EE66-4B4D-B182-3FEAABBD4702}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{A1F6869D-4D1D-40E4-8991-27A07CB80A09}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe | "{A7B167E4-B722-447B-B3AB-5CC77B7E97C3}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\center\kodak.statistics.exe | "{A8537B52-BB25-4020-9D7C-F9A6686075AD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{AD350902-978F-4CF1-A58B-4EA6B2C38A84}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{B2885286-A65C-4A5E-82C4-E3AE9BC5A9D2}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe | "{B943B2E3-BB1D-490B-AA1B-2E7FFBC13B93}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{BA27E891-58D2-4950-B107-CDE9417B5ECE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{BB14BF45-6E48-4593-A6A7-4FC11C080796}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\center\kodak.statistics.exe | "{CE5669BE-4DBB-4253-A78B-B3A09CB3EF02}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{D2B227D4-42E8-4F79-A94F-1E1CF044C274}" = protocol=17 | dir=in | app=c:\users\deb\appdata\local\microsoft\windows\temporary internet files\content.ie5\rwy1ik2t\aviconvertersetup[1].exe | "{D5569629-8B97-4F73-935C-1F8B19BC92AB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | "{D5D76651-022E-4F74-9519-A93880C08789}" = protocol=6 | dir=out | app=system | "{DEEDCCF1-1B80-48CC-98A6-D64B2060B85A}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\firmware\kodakaioupdater.exe | "{DEF9FAFA-2D6A-4F67-A348-A4CF1F09BDF2}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe | "{E59EA0BB-20F3-4998-BC19-F70BE9B60601}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{E8F0ECE5-B3D2-47C6-B1E3-B2B98AED33B6}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{EAA9D16C-C96E-496C-AB8A-706C8022FBC7}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | "{EB7ED54F-0592-4CAA-983A-5D817C1093A1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | "{FA4EF43E-C321-4671-B98C-B2D547B3780D}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe | "{FB57E60A-692C-4294-B8C4-FD34C9F0EF1A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "TCP Query User{3C09D715-AA25-4E64-8B9D-818246E89C63}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "TCP Query User{6052DDC6-96D9-4361-A5B6-1B1C270DDDEB}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | "TCP Query User{F6DA13F1-B97A-4102-904D-AC4CD473BDCE}C:\users\deb\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\deb\appdata\local\akamai\netsession_win.exe | "UDP Query User{502BFDBB-4877-4317-9137-3C3EE3ABA889}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "UDP Query User{CFBE5BEF-FB7C-4F27-A51C-A427B95E0D05}C:\users\deb\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\deb\appdata\local\akamai\netsession_win.exe | "UDP Query User{D507254C-1C66-4CA5-AC61-1CB0867B78E9}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector "{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety "{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety "{1686C4D1-B1FD-42E8-B7A8-FB4C4DBA5BA8}" = ASUS Power4Gear Hybrid "{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant "{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64 "{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}" = Kodak AIO Printer "{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64 "{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources "{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources "{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64 "{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Runtime 1.10.01 "{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended "{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007 "{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007 "{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 "{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64 "{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64 "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64 "{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64 "{CDBF8C2D-04B0-4F9B-9AE1-7422F7F0EC94}" = HP Deskjet F2400 All-In-One Driver Software 13.0 Rel .6 "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer "Desktop Icon Toy_is1" = Desktop Icon Toy 4.6 "Elantech" = ETDWare PS/2-x64 7.0.5.7_WHQL "Folder Marker_is1" = Folder Marker Home v 3.2 GAOTD Edition "HDMI" = Intel® Graphics Media Accelerator Driver "HP Imaging Device Functions" = HP Imaging Device Functions 13.0 "HP Print Projects" = HP Print Projects 1.0 "HP Smart Web Printing" = HP Smart Web Printing 4.5 "HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0 "HPExtendedCapabilities" = HP Customer Participation Program 13.0 "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended "Shop for HP Supplies" = Shop for HP Supplies "WinX DVD Copy Pro_is1" = WinX DVD Copy Pro 3.0.0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00E1E235-AB45-4695-A156-073118949ED4}" = HiYo "{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = LG CyberLink YouCam "{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86 "{06585B02-F20D-4AB2-9A64-86EF2AE0F8F0}" = ASUS AI Recovery "{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan "{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller "{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86 "{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help "{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86 "{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch "{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer "{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail "{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker "{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X "{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.7.2 "{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3 "{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 "{1F2DF2C6-08F7-40BD-8E85-D16CB436E7F0}" = Free NaturalReader "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{1FAD9CDD-BEE6-4240-BE2C-A47A2573F29D}_is1" = Leawo PowerPoint to DVD Pro version 4.1.0.200 "{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = LG CyberLink Media Suite "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform "{20E674AD-8ECC-4680-92D6-18ABE4FC1DE0}" = Hallmark Comedy Card Studio "{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}" = Wireless Console 3 "{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery "{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer "{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java 6 Update 37 "{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program "{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1 "{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections "{297DCADA-86A1-4A42-8A13-66B7D7A09FD2}" = WeatherBug "{2A27F3BC-AB3D-4E25-89AF-6D31DE7E1927}_is1" = IncrediMail Collection Manager 2.04 "{2A304FDE-F4E3-446D-AA0D-31425C897B71}" = PrintMaster 12 "{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger "{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm "{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update "{2FCFFE64-B076-4C21-874E-1C8ADEE8B378}_is1" = AnyPic Image Converter 1.0.1 "{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2 "{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery "{3B05F2FB-745B-4012-ADF2-439F36B2E70B}" = ATKOSD2 "{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}" = Mega Manager "{3F41BA46-09C3-4500-96D7-DC4390AD0124}" = Acrobat X Suite "{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works "{42E2EEB2-D48E-4A47-B181-32ECA031D93B}" = DJ_AIO_06_F2400_SW_Min "{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg "{48B41C3A-9A92-4B81-B653-C97FEB85C910}" = C4USelfUpdater "{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter "{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Photo Story 3 for Windows "{4F93ABBE-5A1D-4D56-94CB-022F109FDE4D}" = Adobe Presenter 7 "{50206644-C226-498D-8273-9F5F300807E2}_is1" = NeoPaint 4.7c "{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion "{56BA241F-580C-43D2-8403-947241AAE633}" = center "{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack "{5A22D889-FBDD-4AE8-86EC-089D45FC133E}" = Alcor Micro USB Card Reader "{5B5E949E-3924-45E3-9229-84E8270BED68}" = ArcSoft Perfect365 "{5B65EF64-1DFA-414A-8C94-7BB726158E21}" = ControlDeck "{5BCC634A-58AD-42F9-B3C6-2EA52F81CF85}" = Snagit 10 "{607169F0-07F6-4797-99D2-D5E7C4715E20}" = Mega Manager "{6179550A-3E7C-499E-BCC9-9E8113E0A285}" = LG ODD Auto Firmware Update "{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86 "{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2 "{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{686695ED-BB3F-415D-B0DB-18CF535F7B50}" = Driver Manager "{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting "{69B6B9E1-A5DF-3177-2B1D-3B672F29EF86}" = Adobe Captivate Quiz Results Analyzer "{6A9736BC-F478-4C89-B6EB-7BC6BE1358B7}" = Event Planner "{6AB7673C-A0FE-4B67-A29E-323FE3AD17A6}" = ArcSoft PhotoStudio Paint "{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply "{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}" = ASUS CopyProtect "{6BAA71B6-8F43-4C72-931A-3354ABB0258A}" = F2400 "{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox "{6C47663A-C5B9-4404-A4BA-E75392F33B2C}_is1" = ScreenCamera.Net version 1.3.8.80 "{6D308A90-6C14-4A02-9B04-CB0EF17894A9}_is1" = Picture Collage Maker Pro 2.5.7 "{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0 "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime "{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com "{788A0222-5690-4212-AA9C-C48FD0E1C9AE}" = Photo Notifier and Animation Creator "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey "{7C4196CA-CA41-4F34-9C08-7724E7705D52}" = Jasc Animation Shop 3 "{7D466431-D6EE-4732-BF02-74BD0817E881}_is1" = AnyPic Image Resizer Pro 1.1.0 "{7EEE783B-C117-4DF5-B5BE-E94E99BE969B}" = calibre "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{8432FFD1-6F4D-F9B8-D641-5932E60359A2}" = Adobe Captivate Reviewer "{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert "{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}" = InstallIQ Updater Quote
debi239 Posted February 2, 2013 Author Posted February 2, 2013 "{8E45B56B-F2BB-44D5-B728-7EAE92B6969D}_is1" = IncrediMail Data Manager 2.02 "{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash "{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007 "{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007 "{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007 "{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007 "{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007 "{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007 "{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007 "{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007 "{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007 "{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007 "{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007 "{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007 "{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007 "{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007 "{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007 "{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007 "{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007 "{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007 "{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2) "{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86 "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9CE2B4FB-8127-4058-B028-C5961242A480}" = Pattern Maker for cross stitch - v4 "{9D48531D-2135-49FC-BC29-ACCDA5396A76}" = ASUS MultiFrame "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh "{A16656CE-4B17-4484-A13F-22B9500E5223}" = Fast Boot "{A254D625} PicturesToExe 5.6_is1" = PicturesToExe 5.6 "{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR "{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection "{A61AE368-B88C-414C-9118-503EECFC3AC8}_is1" = Photo Toolbox for Windows version 1.7.4.5 "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime "{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup "{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer "{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}" = Pando "{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.5) "{ADD5DB49-72CF-11D8-9D75-000129760D75}" = LG CyberLink PowerBackup "{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status "{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}" = RealDownloader "{B07CB2BA-819B-41C5-BBE0-484A4C23972E}" = Easy Flyer Creator 3.0 "{B39DC03B-F2C0-4F7E-B1DD-328F73BD98FD}" = Font Thumbnail "{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86 "{BA413735-865A-4BF5-AAD2-B4D2998ED019}}_is1" = BatchInpaint 1.0 "{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations "{BE94C681-68E2-4561-8ABC-8D2E799168B4}" = essentials "{BFBCF96F-7361-486A-965C-54B17AC35421}" = ocr "{C2B9C70F-165E-450D-9EC1-F7B160016291}" = Living 3D Dolphin "{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant "{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LG CyberLink LabelPrint "{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail "{c6c214df-2922-4809-94aa-f4d67d4451ec}" = Music Oasis "{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects "{CA16B670-D9BD-4051-882A-B5AB057F7128}_is1" = FixBee Disk Optimizer "{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CD0DD6A4-B951-4021-8E05-C73733C5D15B}" = MimarSinan Rubber Ducky "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86 "{D1E5870E-E3E5-4475-98A6-ADD614524ADF}" = ATK Media "{D3CB90C2-BEC1-4D15-8E05-11623357861B}" = Kahlown "{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service "{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{D53599B0-AA76-4CC6-B9EF-CC2F27B56F24}_is1" = Picture Collage Maker 3.2.8 "{D8262480-2A04-407C-B2F7-1439B789C349}" = Print Artist Gold 21 "{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86 "{D9757258-30B2-496E-86F2-84920C5858E1}_is1" = CollageIt 1.2.2 "{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq "{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.2.336 "{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp "{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources "{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Software "{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger "{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update "{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera "{EF53BFAB-4C10-40DB-A82D-9B07111715C6}" = aioscnnr "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 "{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}" = ASUS FancyStart "{F2A69CA0-8BBF-4404-BA68-DB79A3548E34}" = PCStitch 7 "{F843C6A3-224D-4615-94F8-3C461BD9AEA0}" = Jasc Paint Shop Pro 9 "{FA2092C5-7979-412D-A962-6485274AE1EE}" = ASUS Data Security Manager "{FAAEB46F-6BEE-409B-8983-264C21B9C415}" = Pixo "{FAF26102-09D7-4C58-AB01-0D59A2E517CA}" = Copy "{FC274982-5AAD-4C20-848D-4424A5043009}_is1" = WinUtilities 9.98 Professional Edition "{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials "{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 "{gmt_free_avi_to_dvd-66712EEE-ECBC-AXXXX-videosoft}_is1" = Free GMT AVI to DVD 4.9.5.0 "4Media Photo Slideshow Maker" = 4Media Photo Slideshow Maker "4Media Ringtone Maker" = 4Media Ringtone Maker "7-Zip" = 7-Zip 9.20 "ABC Birthday Reminder_is1" = ABC Birthday Reminder version 2.6 "Adobe Acrobat 4.0" = Adobe Acrobat 4.0 "Adobe AIR" = Adobe AIR "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Adobe Photoshop CS5" = Adobe Photoshop CS5 "Adobe Presenter 7" = Adobe Presenter 7 "AdobeCaptivateReviewer2.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Captivate Reviewer "Aiseesoft Total Media Converter_is1" = Aiseesoft Total Media Converter 5.2.30 "Akamai" = Akamai NetSession Interface Service "Animated Screensaver Maker" = Animated Screensaver Maker "Animated Wallpaper Maker" = Animated Wallpaper Maker "AnvSoft Photo Flash Maker Free" = AnvSoft Photo Flash Maker Free 5.21 "AnyDVD" = AnyDVD "Ashampoo Burning Studio Elements_is1" = Ashampoo Burning Studio Elements 10.0.9 "Asus_Camera_ScreenSaver" = Asus_Camera_ScreenSaver "Avira AntiVir Desktop" = Avira Free Antivirus "Batch Photo Watermarker_is1" = Batch Photo Watermarker 3.5 "Blitz FlashCards (GOTD Version)" = Blitz FlashCards (GOTD Version) (remove only) "CCleaner" = CCleaner (remove only) "chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help "com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player "DailyBibleGuidebar Uninstall" = DailyBibleGuide "Desktop Crossword" = Desktop Crossword "Digital Editions" = Adobe Digital Editions "DP Animation Maker" = DP Animation Maker "DVD Photo Slideshow Professional_is1" = DVD Photo Slideshow Professional 8.00 "DVD Shrink_is1" = DVD Shrink 3.2 "EaseUS Data Recovery Wizard 5.6.5_is1" = EaseUS Data Recovery Wizard 5.6.5 "Easy Clone Detective1.4" = Easy Clone Detective "ENTERPRISE" = Microsoft Office Enterprise 2007 "Filters Unlimited_is1" = Filters Unlimited 2.0 "FinalTorrent_is1" = FinalTorrent 2010 "FineCrosser2_is1" = FineCrosser Pro 2.4.2 "Font Xplorer" = Font Xplorer 1.2.2 "Free Audio Converter_is1" = Free Audio Converter version 2.2.11 "Free Easy Burner_is1" = Free Easy Burner V 4.4.1 "FX - AVI Converter" = FoxTab AVI Converter (remove only) "Game Booster_is1" = Game Booster "Google Chrome" = Google Chrome "Halotea Lite" = Halotea Lite v1.105 "HiYo" = HiYo "IBN Video Joiner2.0.1" = IBN Video Joiner "Imikimi Plugin" = Imikimi Plugin "Incomedia WebSite X5 v8 - Smart" = Incomedia WebSite X5 v8 - Smart "IncrediMail" = IncrediMail 2.0 "IncrediMail_MediaBar_2 Toolbar" = IncrediMail MediaBar 2 Toolbar "InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = LG CyberLink YouCam "InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = LG CyberLink Media Suite "InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager "InstallShield_{5A22D889-FBDD-4AE8-86EC-089D45FC133E}" = Alcor Micro USB Card Reader "InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LG CyberLink LabelPrint "InstantStorm_is1" = InstantStorm 2.0 "Jigsaw Puzzle Platinum Edition Deluxe" = Jigsaw Puzzle Platinum Edition Deluxe "KLiteCodecPack_is1" = K-Lite Codec Pack 7.8.0 (Full) "Lovely Folders" = Lovely Folders "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100 "mediAvatar Photo to Flash" = mediAvatar Photo to Flash "MimarSinan Rubber Ducky" = MimarSinan Rubber Ducky "MiPony" = MiPony 1.5.2 "Nero8Lite_is1" = Nero 8 Lite 8.3.6.0 "OpenAL" = OpenAL "Photo Notifier and Animation Creator" = Photo Notifier and Animation Creator "Photo Stamp Remover_is1" = Photo Stamp Remover 3.1 "pixpedia-en_is1" = Pixpedia Publisher 3.0.8 "PowerISO" = PowerISO "PrintProjects" = PrintProjects "QuizResultsAnalyzer.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Captivate Quiz Results Analyzer "RealPlayer 16.0" = RealPlayer "Revo Uninstaller" = Revo Uninstaller 1.92 "RonyaSoft CD DVD Label Maker" = RonyaSoft CD DVD Label Maker 3.01 "Scrapbook Design Studio 2.0_is1" = Scrapbook Design Studio 2.0 "Simpo PDF to PowerPoint_is1" = Simpo PDF to PowerPoint "Slideshow Wizard Trial Version_is1" = Slideshow Wizard 3.2 Trial Version "ST6UNST #1" = Dispatch Labels v5.0 "SwordBible_is1" = SwordBible 5.42 "ThunderSoft Flash Slideshow Factory_is1" = ThunderSoft Flash Slideshow Factory (2.5.0.0) "Total Audio Converter_is1" = TotalAudioConverter "Uninstall_is1" = Uninstall 1.0.0.1 "VideoBooth" = Video Booth "VideoGet_is1" = Nuclear Coffee - VideoGet "Vizros Plug-ins 4.1" = Vizros Plug-ins 4.1 "VLC media player" = VLC media player 0.9.2 "WebPost" = Microsoft Web Publishing Wizard 1.52 "WinAVI Video Converter_is1" = WinAVI Video Converter "Window Washer" = Window Washer "WinLiveSuite" = Windows Live Essentials "WinRAR archiver" = WinRAR archiver "Wondershare DVD Slideshow Builder Standard_is1" = Wondershare DVD Slideshow Builder Standard(Build 6.1.1.46) "Wondershare Photo Collage Studio GOTD Edition_is1" = Wondershare Photo Collage Studio 4.2.16.5 "XnView_is1" = XnView 1.98.5 "Yahoo! Companion" = Yahoo! Toolbar "Yahoo! Messenger" = Yahoo! Messenger "Yahoo! Software Update" = Yahoo! Software Update "yBook_is1" = yBook ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Akamai" = Akamai NetSession Interface "Amazon Kindle" = Amazon Kindle "easyQuizzy_is1" = easyQuizzy 2.0.421 "ImageBadger Image Converter" = ImageBadger Image Converter "Password Manager Deluxe" = Password Manager Deluxe ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 1/24/2013 10:01:39 AM | Computer Name = Deb-PC | Source = Application Error | ID = 1000 Description = Faulting application name: IncMail.exe, version: 6.2.9.4978, time stamp: 0x4dd190e6 Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015, time stamp: 0x50b83c8a Exception code: 0xe06d7363 Fault offset: 0x0000c41f Faulting process id: 0x1a28 Faulting application start time: 0x01cdfa395eb57c87 Faulting application path: C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe Faulting module path: C:\Windows\syswow64\KERNELBASE.dll Report Id: 92a5ac20-662e-11e2-ac95-e0cb4e3d451f Error - 1/24/2013 9:16:34 PM | Computer Name = Deb-PC | Source = Application Hang | ID = 1002 Description = The program avscan.exe version 13.6.0.402 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 2098 Start Time: 01cdfa996394acbf Termination Time: 54451 Application Path: C:\Program Files (x86)\Avira\AntiVir Desktop\avscan.exe Report Id: aee53a52-668c-11e2-83e6-e0cb4e3d451f Error - 1/28/2013 3:56:43 AM | Computer Name = Deb-PC | Source = SideBySide | ID = 16842815 Description = Activation context generation failed for "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid. Error - 1/28/2013 3:59:55 AM | Computer Name = Deb-PC | Source = SideBySide | ID = 16842832 Description = Activation context generation failed for "c:\program files (x86)\Nero\nero toolkit\nero discspeed\DiscSpeed.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error - 1/31/2013 11:55:06 AM | Computer Name = Deb-PC | Source = Avira Antivirus | ID = 4110 Description = An unknown error occurred during init of the engine! Returned error code: 0x35 Error - 1/31/2013 12:21:13 PM | Computer Name = Deb-PC | Source = SideBySide | ID = 16842815 Description = Activation context generation failed for "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid. Error - 1/31/2013 12:22:12 PM | Computer Name = Deb-PC | Source = SideBySide | ID = 16842832 Description = Activation context generation failed for "c:\program files (x86)\Nero\nero toolkit\nero discspeed\DiscSpeed.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error - 2/1/2013 7:23:20 AM | Computer Name = Deb-PC | Source = Avira Antivirus | ID = 4110 Description = An unknown error occurred during init of the engine! Returned error code: 0x35 Error - 2/1/2013 1:14:25 PM | Computer Name = Deb-PC | Source = SideBySide | ID = 16842815 Description = Activation context generation failed for "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute "version" in element "assemblyIdentity" is invalid. Error - 2/1/2013 1:17:13 PM | Computer Name = Deb-PC | Source = SideBySide | ID = 16842832 Description = Activation context generation failed for "c:\program files (x86)\Nero\nero toolkit\nero discspeed\DiscSpeed.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. [ Media Center Events ] Error - 4/15/2011 11:17:18 AM | Computer Name = Deb-PC | Source = MCUpdate | ID = 0 Description = 10:17:17 AM - Failed to retrieve SportsSchedule (Error: The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel.) [ System Events ] Error - 2/1/2013 8:23:27 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 2/1/2013 8:23:35 AM | Computer Name = Deb-PC | Source = DCOM | ID = 10005 Description = Error - 2/1/2013 8:25:24 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 2/1/2013 8:25:24 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 2/1/2013 8:25:24 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 2/1/2013 8:25:24 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 2/1/2013 8:25:24 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 2/1/2013 8:25:24 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001 Description = The Computer Browser service depends on the Server service which failed to start because of the following error: %%1068 Error - 2/1/2013 8:29:05 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7000 Description = The Crypkey License service failed to start due to the following error: %%2 Error - 2/1/2013 8:29:32 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7026 Description = The following boot-start or system-start driver(s) failed to load: NetworkX < End of report > Quote
etavares Posted February 3, 2013 Posted February 3, 2013 Hello, debi239. Step 1 Please uninstall these programs via Add/Remove Programs: IncrediMail IncrediMail Collection Manager 2.04 IncrediMail Data Manager 2.02 DailyBibleGuide HiYo They come bundled with questionable toolbars that may contain tracking functionality. If you really want them, you can reinstall them once we're done. Step 2 Install ERUNT This tool will create a complete backup of your registry. After every reboot, a new backup is created to ensure we have a safety net after each step. Do not delete these backups until we are finished. Please download erunt-setup.exe to your desktop. Double click erunt-setup.exe. Follow the prompts and allow ERUNT to be installed with the settings at default. If you do not want a Desktop icon, feel free to uncheck that. When asked if you want to create an ERUNT entry in the startup folder, answer Yes. You can delete the installation file after use. Erunt will open when the installation is finished. Check all items to be backed up in the default location and click OK. The automatic part won't work with Vista or W7. Please backup manually using ERUNT with the following instructions: Please locate the ERUNT icon on the desktop. If it is not there, click Start and type ERUNT into the search box. Right click the ERUNT icon in the desktop or the Start menu, and select Run as Administrator Click OK at the first message box. Ensure the checkboxes for both "system registry" and "current user registry" are checked. Leave the default save location in there. Click OK. Click Yes to create the new folder. You'll get a window saying "registry backup complete" once it's done. Click OK. If you get an error message, please STOP here and let me know. Do not proceed with any additional instructions until you check back with me. Step 3 We need run an OTL ScriptPlease download OTL from one of the following mirrors if you do not still have it. This is first Mirror This is the second mirror [*]Save it to your desktop. [*]Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/OTL/otlDesktopIcon.png icon on your desktop. [*]Paste the following code under the Custom Scans/Fixes box at the bottom. :OTL IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=bf3...B&cr=801427480 IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2408}: "URL" = http://dts.search-results.com/sr?src...q={searchTerms} IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?...=true&tid=3204 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?...3204&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?...3204&bs=true&q= IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?...=true&tid=3204 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?...=true&tid=3204 IE - HKLM\..\URLSearchHook: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.) IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes\{34e26447-bf30-4c78-a5b9-61dfa8a55e67}: "URL" = http://search.mywebsearch.com/mywebs...r={searchTerms} IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.ph...B&cr=801427480 IE - HKLM\..\SearchScopes\{7C19EC30-6FAD-B9F6-82AA-0C5189279B17}: "URL" = http://search.certified-toolbar.com?...q={searchTerms} IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2408}: "URL" = http://dts.search-results.com/sr?src...q={searchTerms} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?...=true&tid=3204 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://igoogle.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://mystart.hiyo.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?...3204&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?...3204&bs=true&q= IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?...=true&tid=3204 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?...=true&tid=3204 IE - HKCU\..\URLSearchHook: {f15ff29f-85a1-43cd-9674-e5ba40016c97} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vSrcAs.dll (DailyBibleGuide) IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKCU\..\SearchScopes\{30CFB165-2CF1-7712-E58F-3A8DBE9E3CFA}: "URL" = http://www.incredimail-start.com/s/?...=2-428-0-2x4co IE - HKCU\..\SearchScopes\{34e26447-bf30-4c78-a5b9-61dfa8a55e67}: "URL" = http://search.mywebsearch.com/mywebs...r={searchTerms} IE - HKCU\..\SearchScopes\{8B63A8D6-BBED-4341-8867-790E5F524C96}: "URL" = http://mystart.incredimail.com/?sear...loc=search_box IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2408}: "URL" = http://dts.search-results.com/sr?src...q={searchTerms} IE - HKCU\..\SearchScopes\{C7576B9D-B442-46bc-AF74-080A9E723E01}: "URL" = http://websearch.search-results.com/...1-8E0487E93484 IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com//?sea...&a=1pcqIQ5iKit IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyOverride" = 127.0.0.1:9421;<local> FF - HKLM\Software\MozillaPlugins\@DailyBibleGuide.com/Plugin: C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\NP2vStub.dll (DailyBibleGuide) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extens ions\\2vffxtbr@DailyBibleGuide.com: C:\Program Files (x86)\DailyBibleGuide\bar\1.bin [2011/10/14 06:41:49 | 000,000,000 | ---D | M] O2 - BHO: (Search Assistant BHO) - {0631bff0-6846-48ca-982d-d62d7f376e97} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vSrcAs.dll (DailyBibleGuide) O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found. O2 - BHO: (Toolbar BHO) - {beea7fa9-d1f4-49a2-9b1f-6fb7a2d9bc2a} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (DailyBibleGuide) O2 - BHO: (IncrediMail MediaBar 2 Toolbar) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (DailyBibleGuide) - {2a942ab7-2073-49bc-a7e1-77e93835889a} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (DailyBibleGuide) O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found. O3 - HKLM\..\Toolbar: (IncrediMail MediaBar 2 Toolbar) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {22E03916-85C5-44B0-8DC9-1830C11238D9} - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (DailyBibleGuide) - {2A942AB7-2073-49BC-A7E1-77E93835889A} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (DailyBibleGuide) O3 - HKCU\..\Toolbar\WebBrowser: (IncrediMail MediaBar 2 Toolbar) - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.) O4 - HKLM..\Run: [DailyBibleGuide Browser Plugin Loader] C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbrmon.exe (DailyBibleGuide) O4 - HKLM..\Run: [Hiyo] C:\Program Files (x86)\HiYo\bin\HiYo.exe (IncrediMail, Ltd.) O4 - HKCU..\Run: [AdobeBridge] File not found O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) MsConfig:64bit - StartUpReg: facemoods - hkey= - key= - File not found MsConfig:64bit - StartUpReg: Startup Defender - hkey= - key= - File not found MsConfig:64bit - StartUpReg: TelevisionFanatic Browser Plugin Loader - hkey= - key= - File not found :files C:\Program Files (x86)\IncrediMail_MediaBar_2\ C:\Program Files (x86)\DailyBibleGuide C:\Program Files (x86)\HiYo C:\Program Files (x86)\Red Sky C:\Program Files (x86)\Protected Search [*]Click the Run Fix button at the top. [*]let the program run unhindered and reboot when it is done. [*]You will get a log when it is done, please post that in your reply. [*]Please then create a new OTL report.... [*]Click the "Scan All Users" checkbox. [*]Push the http://billy-oneal.com/Canned%20Speeches/speechimages/OTL/runscanbutton.png button. [*]A report will open, copy and paste it in a reply here. Step 4 Please lauch Malwarebytes' ANti-Malware, allow it to update and run a Quick Scan. Post the resulting log in your reply. Step 5 Please download shortcut cleaner and save it to your desktop. Double-click on the ss-cleaner.exe file that should now be on your desktop You will need to allow it to run when the prompt appears. Shortcut Cleaner will now start and scan your computer for hijacked Windows shortcuts and if any are found it will automatically clean them for you. When it is done, it will show you a log that contains a list of shortcuts that were cleaned. Please copy/paste it into your reply. etavares Quote etavares is a member of:Alliance of Security Analysis ProfessionalsUnified Network of Instructors and Trained Eliminators
debi239 Posted February 5, 2013 Author Posted February 5, 2013 Hello Etavares, everytime I get to Step 3 the OTL script won't run it says fix it says that it's not responding. Thank you. Quote
etavares Posted February 5, 2013 Posted February 5, 2013 Hello, debi239. OK, please run this instead and we'll do it manually. Download SystemLook from one of the links below and save it to your Desktop. Download Mirror #1 Download Mirror #2 If you have a 64-bit system, please download the 64 bit version from here: SystemLook (64-bit) Double-click SystemLook.exe to run it. A blank Windows shall open with the title "SystemLook v1.0-by Jpshortstuff". Copy and Paste the content of the following codebox into the main textfield under "File": :reg HKLM\Software\Microsoft\Internet Explorer\ /s HKCU\Software\Microsoft\Internet Explorer /s HKLM\Software\Mozilla\Firefox\Extensions\ /s HKLM\Software\MozillaPlugins\ /s Please Confirm everything is copied and Pasted as I have provided above Click the Look button to start the scan. When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. Note: The log can also be found on your Desktop entitled SystemLook.txt 2nd Note: The scan may take a while from several seconds to a minute or more depending on the number of files you have and how fast your computer can perform the task etavares Quote etavares is a member of:Alliance of Security Analysis ProfessionalsUnified Network of Instructors and Trained Eliminators
debi239 Posted February 5, 2013 Author Posted February 5, 2013 [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{00021a13-0000-0000-c000-000000000046}] "BlockType"="0x1" "Version"="0.0.0.0-11.65535.65535.65535" "DllName"="visio.exe" "CompatibilityFlags"="0x0" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{00021a14-0000-0000-c000-000000000046}] "BlockType"="0x1" "Version"="0.0.0.0-11.65535.65535.65535" "DllName"="visio.exe" "CompatibilityFlags"="0x0" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{053017A8-53F7-4EA3-AA38-A4CCAAF1F9E7}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=72976" "BlockType"="0x06" "Version"="0-2.0.0.7751" "DllName"="PluckExplorerBar.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{053F9267-DC04-4294-A72C-58F732D338C0}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=124993" "BlockType"="0x02" "Version"="0.0.0.0-2.15.9.0" "DllName"="hpswp_framework.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{06E58E5E-F8CB-4049-991E-A41C03BD419E}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=148101" "BlockType"="0x02" "Version"="2.4.1.9" "DllName"="upromisetoolbar.dll" "CompatibilityFlags"="0x00" Quote
debi239 Posted February 5, 2013 Author Posted February 5, 2013 [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{09AF76DD-6988-4664-97D0-362F1011E311}] "BlockType"="0x06" "Version"="0-2.0.0.7751" "DllName"="PluckExplorerBar.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{053017A8-53F7-4EA3-AA38-A4CCAAF1F9E7}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{11359F4A-B191-42D7-905A-594F8CF0387B}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71073" "BlockType"="0x05" "Version"="0-1.2.0.1" "DllName"="lexbar.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=199443" "BlockType"="0x40" "Version"="2.5.12000.509" "DllName"="alotBHO.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{179E4A98-A3C4-407D-8C66-E63B67BB6F4A}] "BlockType"="0x02" "Version"="0-1.0.0.1" "DllName"="mojibho.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{BF09613A-4564-4936-B6BB-B23B1D3D4FD7}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{22BF413B-C6D2-4D91-82A9-A0F997BA588C}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=124997" "BlockType"="0x01;0x11" "Version"="0-2.2.0.181;2.2.0.182-2.2.0.205" "DllName"="SkypeIEPlugin.dll;SkypeIEPlugin.dll" "CompatibilityFlags"="0x00;0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{22D8E815-4A5E-4DFB-845E-AAB64207F5BD}] "BlockType"="0x05" "Version"="0-2.3999.9999.9999" "DllName"="eBayTB.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{92085AD4-F48A-450D-BD93-B28CC7DF67CE}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=148102" "BlockType"="0x02" "Version"="2008.1.0.1" "DllName"="PCCBHO.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{2318C2B1-4965-11D4-9B18-009027A5CD4F}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=124995" "BlockType"="0x02;0x02;0x05;0x02;0x02;0x02;0x02" "Version"="2.0.114.10;3.0.131.0;4.0.513.2948;4.0.1020.6156;4.0.1602.12068;5.0.1112.3348;5.0.1112.7760" "DllName"="googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll" "CompatibilityFlags"="0x00;0x00;0x00;0x00;0x00;0x00;0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{238F6F83-B8B4-11CF-8771-00A024541EE3}] "FWLink"="http://www.citrix.com/downloadclients" "BlockType"="0x2" "Version"="0.0.0.0-9.150.39151.0" "DllName"="Wfica.ocx" "CompatibilityFlags"="0x0" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{2E5E800E-6AC0-411E-940A-369530A35E43}] "FWLink"="http://go.microsoft.com/fwlink/?LinkID=142880" "BlockType"="0x02" "Version"="0-2.0.0.1" "DllName"="TwcToolbarIe7.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{2F039DED-D55D-436B-ABF6-28D343C1F9E2}] "BlockType"="0x02" "Version"="0-1.0.0.4" "DllName"="logos_ie.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{C94158E1-6151-4442-ABE6-FD53D6534CCB}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{31CF9EBE-5755-4A1D-AC25-2834D952D9B4}] "FWLink"="http://go.microsoft.com/fwlink/?LinkID=142881" "BlockType"="0x02" "Version"="0.0.0.0-3.3.0.1" "DllName"="PDFCreator_Toolbar.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{387EDF53-1CF2-4523-BC2F-13462651BE8C}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71086" "BlockType"="0x02" "Version"="0-3.7.0.0" "DllName"="BhoCitUS.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}] "FWLink"="http://go.microsoft.com/fwlink/?LinkID=144284" "BlockType"="0x12" "Version"="8.0.0.101-8.0.0.184" "DllName"="avgssie.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{3EB9C349-7473-48AC-A59B-42F31751974B}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71085" "BlockType"="0x06" "Version"="0-3.0.0.0" "DllName"="TomahawkBar.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{43D9E6F0-1776-4897-AE14-ECEDECBAFEC0}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71084" "BlockType"="0x02;0x02" "Version"="0-3.0.16208.959;0-3.0.16208.959" "DllName"="askbarAB.dll;askbarAC.dll" "CompatibilityFlags"="0x00;0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{48FFE35F-36D9-44bd-A6CC-1D34414EAC0D}] "FWLink"="http://go.microsoft.com/fwlink/?LinkID=108474" "BlockType"="0x20" "Version"="0-1.0.2188.0" "DllName"="IEDevToolbar.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{CC7E636D-39AA-49B6-B511-65413DA137A1}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{4A5BE5EE-CFAD-11D9-8FAD-0007E9AA247E}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71094" "BlockType"="0x05" "Version"="0-1.0.0.1" "DllName"="RSS.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{4E7BD74F-2B8D-469E-8CB2-BC60BB9AAE22}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71093" "BlockType"="0x02" "Version"="0-4.0.1.26" "DllName"="aml_toolbar.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{4E7BD74F-2B8D-469E-99FF-FD60BB9AAE2D}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71087" "BlockType"="0x02" "Version"="0-4.0.1.113" "DllName"="YPTOOLBAR.DLL" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{57F02779-3D88-4958-8AD3-83C12D86ADC7}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71088" "BlockType"="0x06" "Version"="0-2.0.0.0" "DllName"="advancedsearchbar.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{5A074B21-F830-49DE-A31B-5BB9D7F6B407}] "BlockType"="0x02;0x02" "Version"="0-4.0.1.3;0-3.1.1.0" "DllName"="askBar.dll;ajBar.dll" "CompatibilityFlags"="0x00;0x00" "MasterCLSID"="{5A074B29-F830-49DE-A31B-5BB9D7F6B407}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{5A074B29-F830-49DE-A31B-5BB9D7F6B407}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71084" "BlockType"="0x02;0x02" "Version"="0-4.0.1.3;0-3.1.1.0" "DllName"="askBar.dll;ajBar.dll" "CompatibilityFlags"="0x00;0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=199443" "BlockType"="0x40" "Version"="2.5.12000.509" "DllName"="alot.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{5CA3D70E-1895-11CF-8E15-001234567890}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=124996" "BlockType"="0x02" "Version"="1-5.9999.9999.9999" "DllName"="*" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{64818d10-4f9b-11cf-86ea-00aa00b929e8}] "BlockType"="0x1" "Version"="0.0.0.0-11.65535.65535.65535" "DllName"="powerpnt.exe" "CompatibilityFlags"="0x0" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{69ABB8E4-3A44-461C-93BC-C3BB6BDF2DF3}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=194205" "BlockType"="0x40" "Version"="1.1.0.0" "DllName"="Backcountry.com.Steepandcheap.Toolbar.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{F98BA7F6-48D8-4CE7-A8D0-39D13FD6F14F}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{724D43A0-0D85-11D4-9908-00400523E39A}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71075" "BlockType"="0x06" "Version"="0-6.6.5" "DllName"="roboform.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{724D43A9-0D85-11D4-9908-00400523E39A}] "BlockType"="0x06" "Version"="0-6.6.5" "DllName"="roboform.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{724D43A0-0D85-11D4-9908-00400523E39A}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{777D0B4C-75C9-4874-ABFF-80B4BE8DC532}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71078" "BlockType"="0x05" "Version"="0-2.4.0.3" "DllName"="IEBand2.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{77BF5300-1474-4EC7-9980-D32B190E9B07}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=124997" "BlockType"="0x01;0x11" "Version"="0-2.2.0.181;2.2.0.182-2.2.0.205" "DllName"="SkypeIEPlugin.dll;SkypeIEPlugin.dll" "CompatibilityFlags"="0x00;0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{77FEF28E-EB96-44FF-B511-3185DEA48697}] "BlockType"="0x00;0x40;0x40;0x40" "Version"="*;2.0.5.32;2.0.6.10;2.0.6.12" "DllName"="baidubar.dll;BaiduBarX.dll;BaiduBarX.dll;BaiduBarX.dll" "CompatibilityFlags"="0x80000000;0x00;0x00;0x00" "MasterCLSID"="{B580CF65-E151-49C3-B73F-70B13FCA8E86}" "FWLink"="http://go.microsoft.com/fwlink/?LinkId=166124" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{79CEEA4E-C231-4614-9E3B-53B2A02F39B7}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=194273" "BlockType"="0x40" "Version"="1.0.0.9" "DllName"="comcastdx.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{855F3B16-6D32-4FE6-8A56-BBB695989046}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71098" "BlockType"="0x06" "Version"="0-1.0.10.20" "DllName"="toolbaru.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{8B4F961F-0B84-4201-BBB1-34E45368F39E}] "BlockType"="0x02" "Version"="0-1.0.0.4" "DllName"="adelphia.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{E5E2F8B2-79A4-495C-8581-90BA2C845CC2}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{8E929F51-5914-11D6-971F-0050FC3F9161}] "FWLink"="http://go.microsoft.com/fwlink/?LinkID=73332" "BlockType"="0x05" "Version"="0-1.2.0.4" "DllName"="Pictures.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{9030D464-4C02-4ABF-8ECC-5164760863C6}] "FWLink"="http://go.microsoft.com/fwlink/?LinkID=142882" "BlockType"="0x20" "Version"="0.0.0.0-5.0.817.0" "DllName"="WindowsLiveLogin.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{91397D20-1446-11D4-8AF4-0040CA1127B6}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=194275" "BlockType"="0x40;0x40" "Version"="4.4.0.1048;5.0.3.1147" "DllName"="yndbar.dll;yndbar.dll" "CompatibilityFlags"="0x00;0x00" Quote
debi239 Posted February 5, 2013 Author Posted February 5, 2013 [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{92085AD4-F48A-450D-BD93-B28CC7DF67CE}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71081" "BlockType"="0x05" "Version"="0-2.3999.9999.9999" "DllName"="eBayTB.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}] "BlockType"="0x01" "Version"="0-1.2.5000.1021" "DllName"="stmain.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{A202B231-EF71-4A08-BDB9-4CE5AE8BDE0A}] "FWLink"="http://go.microsoft.com/fwlink/?LinkID=108474" "BlockType"="0x20" "Version"="0-1.0.2188.0" "DllName"="IEDevToolbar.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{CC7E636D-39AA-49B6-B511-65413DA137A1}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{A3BC75A2-1F87-4686-AA43-5347D756017C}] "FWLink"="http://go.microsoft.com/fwlink/?LinkID=166122" "BlockType"="0x40;0x40" "Version"="4.504.19.2;4.906.30.2" "DllName"="IEToolbar.dll;IEToolbar.dll" "CompatibilityFlags"="0x00;0x00" "MasterCLSID"="{CCC7A320-B3CA-4199-B1A6-9F516DD6982}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{A411D7F4-8D11-43EF-BDE4-AA921666388A}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=194274" "BlockType"="0x40" "Version"="5.0.0.4" "DllName"="Quero.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{A986E409-30CC-4185-89BB-AB212C104524}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=141062" "BlockType"="0x02" "Version"="1.0.0.24-1.0.0.27" "DllName"="DownloaderManager.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{AA58ED58-01DD-4D91-8333-CF10577473F7}] "BlockType"="0x02;0x02;0x05;0x02;0x02;0x02;0x02" "Version"="2.0.114.10;3.0.131.0;4.0.513.2948;4.0.1020.6156;4.0.1602.12068;5.0.1112.3348;5.0.1112.7760" "DllName"="googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll" "CompatibilityFlags"="0x00;0x00;0x00;0x00;0x00;0x00;0x00" "MasterCLSID"="{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{B580CF65-E151-49C3-B73F-70B13FCA8E86}] "BlockType"="0x00;0x40;0x40;0x40" "Version"="*;2.0.5.32;2.0.6.10;2.0.6.12" "DllName"="baidubar.dll;BaiduBarX.dll;BaiduBarX.dll;BaiduBarX.dll" "CompatibilityFlags"="0x80000000;0x00;0x00;0x00" "FWLink"="http://go.microsoft.com/fwlink/?LinkId=166124" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71067" "BlockType"="0x01" "Version"="0-1.2.5000.1021" "DllName"="msntb.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}] "BlockType"="0x01;0x00" "Version"="0-1.2.5000.1021;0-4.0.0.0" "DllName"="msntb.dll;msntb.dll" "CompatibilityFlags"="0x00;0x80000000" "MasterCLSID"="{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{BF09613A-4564-4936-B6BB-B23B1D3D4FD7}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71090" "BlockType"="0x02" "Version"="0-1.0.0.1" "DllName"="mojiie.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{BF8C499A-AC6E-4F58-82EA-9E5FCC41C34B}] "BlockType"="0x00" "Version"="0-1.0.1.2" "DllName"="ppupload.dll" "CompatibilityFlags"="0x80000000" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{C1D79200-7718-4656-A7B2-F23046E264E7}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71082" "BlockType"="0x06" "Version"="0-1.0.0.0" "DllName"="insptbar.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{C451C08A-EC37-45DF-AAAD-18B51AB5E837}] "FWLink"="http://go.microsoft.com/fwlink/?LinkID=142881" "BlockType"="0x02" "Version"="0.0.0.0-3.3.0.1" "DllName"="PDFCreator_Toolbar.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{31CF9EBE-5755-4A1D-AC25-2834D952D9B4}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{C94158E1-6151-4442-ABE6-FD53D6534CCB}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71091" "BlockType"="0x02" "Version"="0-1.0.0.4" "DllName"="logos_ie.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{CC7E636D-39AA-49B6-B511-65413DA137A1}] "BlockType"="0x20" "Version"="0-1.0.2188.0" "DllName"="IEDevToolbar.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{CC962137-2E78-4F94-975E-FC0C07DBD78F}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{CC7E636D-39AA-49B6-B511-65413DA137A1}\Subcomponents] "{48FFE35F-36D9-44bd-A6CC-1D34414EAC0D}"="" "{A202B231-EF71-4A08-BDB9-4CE5AE8BDE0A}"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{CC962137-2E78-4F94-975E-FC0C07DBD78F}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71074" "BlockType"="0x20" "Version"="0-1.0.2188.0" "DllName"="IEDevToolbar.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}] "FWLink"="http://go.microsoft.com/fwlink/?LinkID=166122" "BlockType"="0x40;0x40" "Version"="4.504.19.2;4.906.30.2" "DllName"="IEToolbar.dll;IEToolbar.dll" "CompatibilityFlags"="0x00;0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{CDEEC43D-3572-4E95-A2A5-F519D29F00C0}] "BlockType"="0x06" "Version"="0-2.0.0.0" "DllName"="advancedsearchbar.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{57F02779-3D88-4958-8AD3-83C12D86ADC7}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{CE000992-A58C-4441-8938-744CD72AB27F}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71070" "BlockType"="0x01" "Version"="0-4.2.1.0" "DllName"="i-nav_4_2_1.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{DC99E960-6594-45E3-9D5D-141D825B8096}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71077" "BlockType"="0x01" "Version"="0-1.1.0.5" "DllName"="PrvcBand.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{DCC70A83-E184-40A3-906B-779AF5E941C4}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=194276" "BlockType"="0x40" "Version"="1.0.0.14" "DllName"="xfinitydx.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{E5E2F8B2-79A4-495C-8581-90BA2C845CC2}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=71092" "BlockType"="0x02" "Version"="0-1.0.0.4" "DllName"="adelphia.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{E97B5F2E-CA8E-4D34-BDA3-44EEC4ED2B12}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=194271" "BlockType"="0x40" "Version"="3.3.317.0" "DllName"="ToolbarContainer101000317.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{EAEE5C74-6D0D-4ACA-9232-0DA4A7B866BA}] "FWLink"="http://go.microsoft.com/fwlink/?LinkID=142956" "BlockType"="0x02" "Version"="1.8.0.4272" "DllName"="piclens.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{EDC0F17F-F4B7-47E4-B73E-887FAEB376FA}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=148101" "BlockType"="0x02" "Version"="2.4.1.9" "DllName"="upromisetoolbar.dll" "CompatibilityFlags"="0x00" "MasterCLSID"="{06E58E5E-F8CB-4049-991E-A41C03BD419E}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{EF99BD32-C1FB-11D2-892F-0090271D4F88}] "BlockType"="0x0;0x0;0x0;0x0;0x0;0x0;0x0;0x0" "Version"="0.0.0-6.3.4;0.0.0-6.2.3;6.0-6.5;0.0.0-6.2.3;0.0.0-6.2.3;0.0.0-6.2.3;0.0.0-6.2.3;0.0.0-6.2.3" "DllName"="yt.dll;yt.dll;yt.dll;ycomp5_5_5_0.dll;ycomp5_5_7_0.dll;ycomp5_5_9_1.dll;ycomp5_6_0_0.dll;ycomp5_6_2_0.dll" "CompatibilityFlags"="0x08;0x06;0x01;0x06;0x06;0x06;0x06;0x06" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{F98BA7F6-48D8-4CE7-A8D0-39D13FD6F14F}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=194205" "BlockType"="0x40" "Version"="1.1.0.0" "DllName"="Backcountry.com.Steepandcheap.Toolbar.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=124993" "BlockType"="0x02" "Version"="100.0.0.0-110.0.19060.0" "DllName"="hpswp_BHO.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7}] "FWLink"="http://go.microsoft.com/fwlink/?LinkId=124993" "BlockType"="0x02" "Version"="3.0.0.0-3.0.17.0" "DllName"="hpswp_framework.dll" "CompatibilityFlags"="0x00" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extensions] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extensions\{88CFA58B-A63F-4A94-9C54-0C7A58E3333E}] "ButtonText"="Add to VideoGet" "ClsidExtension"="{17A84966-F1E9-4645-AA9E-5E771EE1C859}" "CLSID"="{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}" "Default Visible"="Yes" "Icon"="C:\Program Files (x86)\Nuclear Coffee\VideoGet\VideoGet.ico" "HotIcon"="C:\Program Files (x86)\Nuclear Coffee\VideoGet\VideoGet.ico" "MenuText"="Add to &VideoGet" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Feed Discovery] "Type1"="application/atom+xml" "Type0"="application/rss+xml" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Image Caching] "Number"=04 00 00 00 (REG_BINARY) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\InformationCard Token Provider] @="{D978F0CB-DEBA-4388-83BE-D3E106E02A4F}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\LinksBar] "Enabled"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights] "DefaultElevationPolicy"= 0x0000000002 (2) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{0002df01-0000-0000-c000-000000000046}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Program Files\Internet Explorer" "AppName"="iexplore.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{20D04FE0-3AEA-1069-A2D8-08002B30309D}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows" "AppName"="explorer.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{4becf16c-74f0-429b-8d3e-4fba507ac661}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Program Files (x86)\adobe\acrobat 7.0\reader" "AppName"="acrord32.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{95a4104c-1c49-4c2a-9830-1be0f47e926c}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat" "AppName"="acrobat.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{9da1d2cb-796d-4bec-bbaa-0aa9ccd80e15}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat Elements" "AppName"="Acrobat Elements.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{f1804479-982b-479f-95eb-c6972fb8c767}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Program Files (x86)\adobe\acrobat 6.0\reader" "AppName"="acrord32.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{F41E8255-3897-4cf4-AEC7-4F85171A0B3C}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows\System32" "AppName"="notepad.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{0002df01-0000-0000-c000-000000000046}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Program Files\Internet Explorer" "AppName"="iexplore.exe" "IID"="{9B61C454-C2A2-4685-8885-9752F9A3F28F}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{054aae20-4bea-4347-8a35-64a533254a9d}] "Policy"= 0x0000000001 (1) "AppPath"="C:\Program Files\Common Files\Microsoft Shared\Ink" "AppName"="tabtip.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows\System32" "AppName"="wpcer.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{08f24d68-9087-4b24-81ad-7b34af3e3ed5}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Program Files (x86)\adobe\acrobat 6.0\Acrobat Elements" "AppName"="Acrobat Elements.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows\System32" "AppName"="winfxdocobj.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{1138506a-b949-46a7-b6c0-ee26499fdeaf}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows\System32" "AppName"="wuapp.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{130c40f0-1bcb-4852-8b63-291cf90a600b}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows\System32" "AppName"="msdt.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{186e0934-aee9-11da-961b-0014223d2a70}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows\microsoft.net\framework64\v2.0.50727" "AppName"="dfsvc.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{186e0935-aee9-11da-961b-0014223d2a70}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows\microsoft.net\framework64\v2.0.50727" "AppName"="dfsvc.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{1A972DAF-A7EC-4ce3-B6C9-7B523CD6685F}] "AppName"="GoogleToolbarUser_32.exe" "AppPath"="C:\Program Files (x86)\Google\Google Toolbar" "Policy"= 0x0000000003 (3) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{1F1E561D-AF17-4510-B996-351BBA0862A7}] "CLSID"="{20FD4E26-8E0F-4F73-A0E0-F27B8C57BE6F}" "Policy"= 0x0000000003 (3) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{2391d819-9d17-44ec-9ac1-f6aa07549469}] "Policy"= 0x0000000003 (3) "AppPath"="%systemroot%\system32" "AppName"="wermgr.exe" "IID"="{aa586b2c-26ee-491f-955d-3dd0ac95c45b}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{26fe7361-bd5a-4dcb-b309-c6f42dde661c}] "Policy"= 0x0000000001 (1) "AppPath"="C:\Program Files\Internet Explorer" "AppName"="ieinstal.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{4becf16c-74f0-429b-8d3e-4fba507ac661}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Program Files (x86)\adobe\acrobat 7.0\reader" "AppName"="acrord32.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}] "Policy"= 0x0000000003 (3) "AppPath"="%ProgramFiles%\Windows Media Player" "AppName"="wmplayer.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}-32] "Policy"= 0x0000000003 (3) "AppPath"="%ProgramFiles(x86)%\Windows Media Player" "AppName"="wmplayer.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999}] "Policy"= 0x0000000001 (1) "AppPath"="C:\Program Files\Internet Explorer" "AppName"="iedw.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{78c7b664-c9bf-4ce9-8b3a-b05d442e451e}] "Policy"= 0x0000000003 (3) "AppName"="CertEnrollCtrl.exe" "AppPath"="C:\Windows\system32\" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{7aaae723-5fb5-4b2d-9327-75519f336825}] "Policy"= 0x0000000003 (3) "CLSID"="{33246F92-D56F-4E34-837A-9A49BFC91DF3}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{7eb01fb2-f185-445a-94e4-ec4e1ba2202c}] "Policy"= 0x0000000001 (1) "AppPath"="C:\Windows\System32" "AppName"="verclsid.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{80B84A0A-EDA4-47fd-8BE1-6B49F4197EE5}] "AppName"="GoogleToolbarNotifier.exe" "AppPath"="C:\Program Files (x86)\Google\GoogleToolbarNotifier" "Policy"= 0x0000000003 (3) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows\System32" "AppName"="ctfmon.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{86300DD7-B136-40d9-823C-22EBD55D7858}] "AppName"="Snagit32.exe" "AppPath"="C:\Program Files (x86)\TechSmith\Snagit 10" "Policy"= 0x0000000003 (3) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows" "AppName"="helppane.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{95a4104c-1c49-4c2a-9830-1be0f47e926c}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat" "AppName"="acrobat.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{9da1d2cb-796d-4bec-bbaa-0aa9ccd80e15}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat Elements" "AppName"="Acrobat Elements.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{a5a2d52a-4944-47c4-a3e0-8bd92e14d953}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows\SysWOW64\xpsviewer" "AppName"="xpsviewer.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{A5B020FD-E04B-4e67-B65A-E7DEED25B2CF}] "Policy"= 0x0000000001 (1) "AppPath"="%SystemRoot%\System32" "AppName"="wisptis.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{aff735eb-cdf9-4894-aa69-3e3131128618}] "Policy"= 0x0000000000 (0) "AppPath"="C:\Windows\System32" "AppName"="cmd.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01}] "AppName"="TSWbPrxy.exe" "Policy"= 0x0000000003 (3) "AppPath"="%systemroot%\system32" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{BD18A03F-31CC-4CC0-B52D-9E199122923D}] "Policy"= 0x0000000003 (3) "CLSID"="{6B9228DA-9C15-419e-856C-19E768A13BDC}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{C8999AEC-AECE-4E27-9BCB-5358B13F9FF9}] "AppName"="dfsvc.exe" "AppPath"="C:\Windows\Microsoft.NET\Framework\v4.0.30319\" "Policy"= 0x0000000003 (3) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{C8999AED-AECE-4E27-9BCB-5358B13F9FF9}] "AppName"="dfsvc.exe" "AppPath"="C:\Windows\Microsoft.NET\Framework64\v4.0.30319\" "Policy"= 0x0000000003 (3) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{dc6bf185-7ae4-444e-8c35-e447b0d2bd1e}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows\System32" "AppName"="notepad.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{e5f90a07-7db7-4dcb-bd6d-d3fecd376ca3}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Program Files (x86)\adobe\acrobat 6.0\reader" "AppName"="acrord32.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{EE0B94B9-335F-4d2c-8B43-DACCD1EA6FF1}] "AppName"="GoogleToolbarUser_64.exe" "AppPath"="C:\Program Files (x86)\Google\Google Toolbar" "Policy"= 0x0000000003 (3) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{eee261cc-4b3e-46e7-affb-61f297155bf2}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows\System32" "AppName"="presentationhost.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Windows\system32\Macromed\Flash" "AppName"="FlashUtil64_11_5_502_146_ActiveX.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{fb9e068b-c612-4fa8-bdb9-d728a716a420}] "Policy"= 0x0000000003 (3) "AppPath"="C:\Program Files (x86)\adobe\acrobat 6.0\Acrobat" "AppName"="acrobat.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm47.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm48.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm49.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4a.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4b.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4c.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4o.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4p.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4s.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4t.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4u.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4v.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4w.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4x.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4y.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4z.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm50.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm52.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm53.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm55.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm56.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm57.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm58.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm59.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5a.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5b.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5c.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5d.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5i.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5j.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5k.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5l.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5m.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5n.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5p.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5q.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5s.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5u.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5v.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5x.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5y.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5z.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm61.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm62.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm64.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm65.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm66.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm67.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm69.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6a.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6d.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6e.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6f.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6h.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6i.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6j.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6k.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6l.dll] (No values found) Quote
etavares Posted February 5, 2013 Posted February 5, 2013 Hi, you can attach it directly to your reply if it's easier than cutting and pasting. -etavares Quote etavares is a member of:Alliance of Security Analysis ProfessionalsUnified Network of Instructors and Trained Eliminators
debi239 Posted February 5, 2013 Author Posted February 5, 2013 [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6l.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6m.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6n.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6o.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6p.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6r.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6s.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6v.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6y.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6z.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm70.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm71.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm72.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm74.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm75.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm76.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm78.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm79.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7a.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7b.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7c.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7d.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7e.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7f.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7i.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7j.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7k.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7l.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7m.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7n.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7o.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7q.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7r.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7s.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7t.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7u.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7v.dll] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN] "AutoHide"="yes" "Security Risk Page"="about:SecurityRisk" "Extensions Off Page"="about:NoAdd-ons" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Anchor_Visitation_Horizon"=01 00 00 00 (REG_BINARY) "Cache_Percent_of_Disk"=0a 00 00 00 (REG_BINARY) "Placeholder_Width"=1a 00 00 00 (REG_BINARY) "Placeholder_Height"=1a 00 00 00 (REG_BINARY) "Default_Secondary_Page_URL"="" "Use_Async_DNS"="yes" "Start Page"="" "Local Page"="C:\Windows\System32\blank.htm" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Delete_Temp_Files_On_Exit"="yes" "Enable_Disk_Cache"="yes" "TabProcGrowth"="Medium" "Print_Background"= 0x0000000000 (0) "AlwaysShowMenus"= 0x0000000000 (0) "StatusBarWeb"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\ErrorThresholds] "406"= 0x0000000200 (512) "405"= 0x0000000100 (256) "501"= 0x0000000200 (512) "404"= 0x0000000200 (512) "500"= 0x0000000200 (512) "403"= 0x0000000100 (256) "409"= 0x0000000200 (512) "505"= 0x0000000200 (512) "408"= 0x0000000200 (512) "400"= 0x0000000200 (512) "410"= 0x0000000100 (256) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_96DPI_PIXEL] "WindowsAnytimeUpgradeUI.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION] "PresentationHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_ADDON_MANAGEMENT] "prevhost.exe"= 0x0000000001 (1) "wmplayer.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_BEHAVIORS] "*"= 0x0000000001 (1) "explorer.exe"= 0x0000000001 (1) "iexplore.exe"= 0x0000000001 (1) "infopath.exe"= 0x0000000000 (0) "msn6.exe"= 0x0000000000 (0) "wmplayer.exe"= 0x0000000001 (1) "ehExtHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS] "prevhost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_IMG] "PresentationHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT] "PresentationHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT] "PresentationHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION] "prevhost.exe"= 0x0000001f40 (8000) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_DISABLE_ISO_2022_JP_SNIFFING] "iexplore.exe"= 0x0000000001 (1) "*"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION] "PresentationHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL] "*"= 0x0000000001 (1) "explorer.exe"= 0x0000000001 (1) "iexplore.exe"= 0x0000000001 (1) "SAPfewgsrv.exe"= 0x0000000000 (0) "SAPGuiIT.exe"= 0x0000000000 (0) "SAPGUI.exe"= 0x0000000000 (0) "SAPLgPad.exe"= 0x0000000000 (0) "SAPLOGON.exe"= 0x0000000000 (0) "Scale_for_R3.exe"= 0x0000000000 (0) "wmplayer.exe"= 0x0000000001 (1) "ehExtHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP] "ieuser.exe"= 0x0000000001 (1) "iexplore.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL] "PresentationHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK] "YahooMusicEngine.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT] "devenv.exe"= 0x0000000001 (1) "dexplore.exe"= 0x0000000001 (1) "helppane.exe"= 0x0000000001 (1) "PresentationHost.exe"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_FEEDS] "msfeedssync.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS] "prevhost.exe"= 0x0000000001 (1) "PresentationHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_HIGH_CONTRAST_BACKGROUND_IMAGES] "sidebar.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE] "wmplayer.exe"= 0x0000000001 (1) "ehExtHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_IGNORE_XML_PROLOG] @="" "msiexec.exe"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_IMAGING_USE_ART] "wm.exe"= 0x0000000001 (1) "cs.exe"= 0x0000000001 (1) "waol.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS] "iexplore.exe"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_LEGACY_DISPPARAMS] "helppane.exe"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS] "wlmail.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN] "explorer.exe"= 0x0000000001 (1) "iexplore.exe"= 0x0000000001 (1) "prevhost.exe"= 0x0000000001 (1) "wmplayer.exe"= 0x0000000001 (1) "PresentationHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER] "explorer.exe"= 0x0000000004 (4) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER] "explorer.exe"= 0x0000000002 (2) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_MIME_HANDLING] "explorer.exe"= 0x0000000001 (1) "iexplore.exe"= 0x0000000001 (1) "prevhost.exe"= 0x0000000001 (1) "wmplayer.exe"= 0x0000000001 (1) "ehExtHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_MIME_SNIFFING] "explorer.exe"= 0x0000000001 (1) "iexplore.exe"= 0x0000000001 (1) "wmplayer.exe"= 0x0000000001 (1) "ehExtHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME] "mshta.exe"= 0x0000000001 (1) "outlook.exe"= 0x0000000001 (1) "sidebar.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_OBJECT_CACHING] "explorer.exe"= 0x0000000001 (1) "iexplore.exe"= 0x0000000001 (1) "wmplayer.exe"= 0x0000000001 (1) "ehExtHost.exe"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN] "explorer.exe"= 0x0000000000 (0) "iexplore.exe"= 0x0000000000 (0) "wmplayer.exe"= 0x0000000001 (1) "ehExtHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING] "communicator.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7] "prevhost.exe"= 0x0000000001 (1) "PresentationHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL] "prevhost.exe"= 0x0000000001 (1) "wmplayer.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD] "msimn.exe"= 0x0000000001 (1) "winmail.exe"= 0x0000000001 (1) "prevhost.exe"= 0x0000000001 (1) "wmplayer.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE] "PresentationHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ] "prevhost.exe"= 0x0000000001 (1) "PresentationHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT] "explorer.exe"= 0x0000000001 (1) "iexplore.exe"= 0x0000000001 (1) "wmplayer.exe"= 0x0000000001 (1) "ehExtHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_SECURITYBAND] "prevhost.exe"= 0x0000000001 (1) "wmplayer.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE] "prevhost.exe"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG] "PresentationHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_SSLUX] "PresentationHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN] "winmail.exe"= 0x0000000001 (1) "msimn.exe"= 0x0000000001 (1) "outlook.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_UNC_SAVEDFILECHECK] "wmplayer.exe"= 0x0000000001 (1) "ehExtHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL] "infopath.exe"= 0x0000000001 (1) "winword.exe"= 0x0000000001 (1) "excel.exe"= 0x0000000001 (1) "powerpnt.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL] "prevhost.exe"= 0x0000000001 (1) "wmplayer.exe"= 0x0000000001 (1) "ehExtHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD] "msn6.exe"= 0x0000000001 (1) "msn.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT] "explorer.exe"= 0x0000000001 (1) "iexplore.exe"= 0x0000000001 (1) "wmplayer.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_WINDOW_RESTRICTIONS] "explorer.exe"= 0x0000000001 (1) "iexplore.exe"= 0x0000000001 (1) "wmplayer.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_XSSFILTER] "iexplore.exe"= 0x0000000001 (1) "prevhost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_ZONE_ELEVATION] "explorer.exe"= 0x0000000001 (1) "iexplore.exe"= 0x0000000001 (1) "prevhost.exe"= 0x0000000001 (1) "PresentationHost.exe"= 0x0000000001 (1) "wmplayer.exe"= 0x0000000001 (1) "ehExtHost.exe"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\UrlTemplate] "1"="www.%s.com" "3"="www.%s.net" "2"="www.%s.org" "4"="www.%s.edu" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Migration] "IE Installed Date"=2a 41 7b 83 ba a6 cb 01 (REG_BINARY) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\P3] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\P3\Write] "Registration"=".microsoft.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\PhishingFilter] "EnabledV8"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Plugins] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Plugins\Extension] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Plugins\MIME] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Plugins\PluginsPage] @="http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Plugins\PluginsPageFriendlyName] @="Microsoft ActiveX Gallery" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\ProtocolExecute] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\ProtocolExecute\wpc] "WarnOnOpen"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Registration] "ProductId"="00359-OEM-8992687-00007" "DigitalProductId"=a4 00 00 00 03 00 00 00 30 30 33 35 39 2d 4f 45 4d 2d 38 39 39 32 36 38 37 2d 30 30 30 30 37 00 b2 00 00 00 58 31 35 2d 33 37 33 37 39 00 00 00 00 00 00 00 ab e7 ec 74 dd 42 75 40 36 3d 25 62 85 79 04 00 00 00 00 00 b7 76 6f 4a 9e dd d9 c3 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 54 b3 39 (REG_BINARY) "DigitalProductId4"=f8 04 00 00 04 00 00 00 30 00 30 00 33 00 35 00 39 00 2d 00 30 00 30 00 31 00 37 00 38 00 2d 00 39 00 32 00 36 00 2d 00 38 00 30 00 30 00 30 00 30 00 37 00 2d 00 30 00 32 00 2d 00 31 00 30 00 33 00 33 00 2d 00 37 00 36 00 30 00 30 00 2e 00 30 00 30 00 30 00 30 00 2d 00 32 00 30 00 39 00 32 00 30 00 30 00 39 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 64 00 32 00 63 00 30 00 34 00 65 00 39 00 30 00 2d 00 63 00 33 00 64 00 64 00 2d 00 34 00 32 00 36 00 30 00 2d 00 62 00 30 00 66 00 33 00 2d 00 66 00 38 00 34 00 35 00 66 00 35 00 64 00 32 00 37 00 64 00 36 00 34 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 48 00 6f 00 6d 00 65 00 50 00 72 00 65 00 6d 00 69 00 75 00 6d 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Safety] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Safety\PrivacIE] "Mode"= 0x0000000002 (2) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\SearchScopes] "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] @="Bing" "URL"="http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC" "DisplayName"="@ieframe.dll,-12512" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}] "DisplayName"="Google" "URL"="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7" "FaviconURL"="http://www.google.com/favicon.ico" "SuggestionsURL"="http://clients5.google.com/complete/search?hl={language}&q={searchTerms}&client=ie8&inputencoding={inputEncoding}&outputencoding={outputEncoding}" "ShowSearchSuggestions"= 0x0000000001 (1) "SortIndex"= 0x0000000000 (0) "TopResultURLFallback"="http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=bf3&chnl=bf3&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0EtA0DyEyDtC0FtAyCtBtAtN0D0Tzu0CtBtAtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=801427480" "FaviconURLFallback"="http://start.funmoods.com/favicon.ico" @="Funmoods" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\SearchUrl] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Security] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Security\DPA] "Flags"=1a 00 00 00 (REG_BINARY) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Security\MSN] "Flags"=0a 00 00 00 (REG_BINARY) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Security\Negotiate] "Flags"=18 00 00 00 (REG_BINARY) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Security\NTLM] "Flags"=08 00 00 00 (REG_BINARY) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Setup] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Setup\9.0] "DoNotOfferIE90"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Styles] "Count_Style_Sheets"=05 00 00 00 (REG_BINARY) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\TabbedBrowsing] "Groups"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Toolbar] "Locked"= 0x0000000000 (0) "{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3}"="" "{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=00 (REG_BINARY) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Transitions] "PageBack"="progid:DXImageTransform.Microsoft.Fade(Duration=0.4)" "PageForward"="progid:DXImageTransform.Microsoft.Fade(Duration=0.4)" "SiteNav"="progid:DXImageTransform.Microsoft.Fade(Duration=0.4)" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Unattend] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Unattend\New Windows] "AllowHTTPS"= 0x0000000000 (0) "BlockControls"= 0x0000000000 (0) "BlockUserInit"= 0x0000000000 (0) "UseHooks"= 0x0000000001 (1) "UseTimerMethod"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\CompanyName] "CompanyName"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\DisableFirstRunWizard] "DisableFirstRunWizard"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\DisableWelcomePage] "DisableWelcomePage"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesDelete] "FavoritesDelete"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesList] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesList\1] "FavTitle"="ASUS E-Service\ASUS Homepage" "FavURL"="http://www.asus.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesList\2] "FavTitle"="ASUS E-Service\ASUS Technical Support" "FavURL"="http://www.asus.com/support" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesList\3] "FavTitle"="ASUS E-Service\ASUS Member" "FavURL"="http://member.asus.com" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesList\4] "FavTitle"="ASUS E-Service\ASUS Software Download" "FavURL"="http://www.asus.com/support/download" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesOnTop] "FavoritesOnTop"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\Help_Page] "Help_Page"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\Home_Page] "Home_Page"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\IEWelcomeMsg] "IEWelcomeMsg"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\NoDial] "NoDial"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\UserAgent] "UserAgent"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\Window_Title_CN] "Window_Title_CN"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\AllowedSites] "AllowedSites"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\AllSitesCompatibilityMode] "AllSitesCompatibilityMode"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\BlockPopups] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\CommandLabelDisplay] "TextOption"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\CompatibilityViewDomains] "CompatibilityViewDomains"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\DisableAccelerators] "NoActivities"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\DisableDataExecutionPrevention] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\DisableDevTools] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\DisableOOBAccelerators] "NoOOBActivities"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\EnableLinksBar] "Enabled"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\FilterLevel] "FilterLevel"="Medium" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\FindProvidersURL] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\GroupTabs] "Groups"= 0x0000000001 (1) Quote
debi239 Posted February 5, 2013 Author Posted February 5, 2013 [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\HKLMEmailName] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\IntranetCompatibilityMode] "IntranetCompatibilityMode"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\LocalIntranetSites] "LocalIntranetSites"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\LockToolbars] "Locked"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\MSCompatibilityMode] "MSCompatibilityMode"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\PlaySound] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\PrintBackground] "Print_Background"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\PrivacyAdvisorMode] "Mode"= 0x0000000002 (2) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ShowCommandBar] "Enabled"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ShowCompatibilityViewButton] "ShowCompatibilityViewButton"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ShowInformationBar] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ShowLeftAddressToolbar] "ShowLeftAddressToolbar"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ShowMenuBar] "AlwaysShowMenus"= 0x0000000000 (0) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ShowStatusBar] "StatusBarWeb"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\SmallCommandBarIcons] "SmallIcons"= 0x0000000001 (1) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\SuggestedSitesEnabled] (No values found) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\TabProcessGrowth] "TabProcGrowth"="Medium" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\TrustedSites] "TrustedSites"="" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\URL Compatibility] "Version"="5.1" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\URL Compatibility\~/CONNWIZ.HTM] "Compatibility Flags"= 0x0000000004 (4) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\URL Compatibility\~/CWIZINTR.HTM] "Compatibility Flags"= 0x0000000004 (4) [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Version Vector] "VML"="1.0" "IE"="8.0000" "WindowsEdition"="3" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer] "Download Directory"="C:\Users\Deb\Desktop" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\AboutURLs] "Tabs"="http://newtab.certified-toolbar.com/nie?si=41460&tid=3204&new=true" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation] "TLDUpdates"= 0x0000000000 (0) "UnattendLoaded"= 0x0000000001 (1) "MSCompatibilityMode"= 0x0000000001 (1) "IECompatVersionHigh"= 0x0000080000 (524288) "IECompatVersionLow"= 0x001db14503 (498156803) "StaleCompatCache"= 0x0000000000 (0) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\ClearableListData] (No values found) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\LowMic] "IECompatVersionHigh"= 0x0000080000 (524288) "IECompatVersionLow"= 0x001db14503 (498156803) "StaleCompatCache"= 0x0000000000 (0) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CaretBrowsing] (No values found) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar] "ToolBandWidth"= 0x0000000189 (393) "CompatibilityViewButtonBalloonCount"= 0x0000000002 (2) "CommandBarEnabled"= 0x0000000001 (1) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop] (No values found) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General] "WallpaperSource"="D:\Wallpapers\27.jpg" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Document Windows] "Maximized"="no" "height"=00 00 00 00 (REG_BINARY) "width"=00 00 00 80 (REG_BINARY) "x"=00 00 00 80 (REG_BINARY) "y"=00 00 00 00 (REG_BINARY) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage] (No values found) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\giveawayoftheday.com] @= 0x00000206ac (132780) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total] @= 0x00000206ac (132780) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download] "CheckExeSignatures"="yes" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars] (No values found) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{555D4D79-4BD2-4094-A395-CFC534424A05}] (No values found) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Help_Menu_URLs] (No values found) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools] "Pinned"= 0x0000000000 (0) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld] "IETldDllVersionHigh"= 0x0000080000 (524288) "IETldDllVersionLow"= 0x001db14640 (498157120) "IETldVersionHigh"= 0x0000000001 (1) "IETldVersionLow"= 0x0000000008 (8) "StaleIETldCache"= 0x0000000000 (0) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\LowMic] "IETldDllVersionHigh"= 0x0000080000 (524288) "IETldDllVersionLow"= 0x001db14640 (498157120) "IETldVersionHigh"= 0x0000000001 (1) "IETldVersionLow"= 0x0000000008 (8) "StaleIETldCache"= 0x0000000000 (0) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms] "PSMigrated"= 0x0000000001 (1) "AskUser"= 0x0000000000 (0) [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage1] "AE698CFE08B29271644798AD167B0FD791F9116BCB"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 f3 ae 35 65 6e 4e 50 1e 5c 6d b6 76 c1 41 08 29 e6 3b fc 9f 1f 9f c5 9c 26 66 6f 24 e7 85 dd dd 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 d3 03 ad ff 74 e6 ac 35 10 80 e9 39 5d 26 55 f0 bc ef 11 03 36 99 40 db 62 33 65 24 67 ea 81 b5 60 04 00 00 7b 44 ab a0 2d 0e 5c cb 78 a8 b3 88 4a 5b 1b ff 45 ab 8b c7 7c d2 a1 11 c7 3b 82 b1 e0 0a e7 6b 8a 08 50 84 db 02 98 50 8c b7 18 31 89 a9 35 94 32 c0 c6 f0 6e f9 07 61 53 a8 dd bc d0 b1 50 e4 0b 0a e8 9b b8 cf bf a3 25 0d c6 5d 0c 6a e6 c3 e8 4b 2e 37 97 eb 94 95 f5 0d dd b3 e1 b6 c7 48 62 72 d0 b4 20 a6 fd 68 6f 19 4d f6 d5 56 04 ab b5 04 d7 5a 46 d9 e4 fa a1 b4 a1 fe bf 00 4f 50 c2 0d ba eb 68 27 d8 f4 72 fc e6 7e eb 28 82 b6 52 53 67 84 0a 84 ab c0 b8 3d 19 3b 37 bf da 0b 3c 0f 23 bd ff c1 bb 84 0a 34 b7 88 1f 73 4e 36 c5 92 05 4b ce b0 f6 ce 4a c6 24 05 55 93 8a 42 fe d4 c8 (REG_BINARY) "DABBFD35854177D84D61FFF79D2BC7215D6470A506"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 7f 67 c4 e1 4e 16 f9 ae 7f b1 bd 4b 40 0e 8a 77 16 fe 17 d0 99 4f f3 a0 ea 3e 17 67 5a 00 5f b7 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7e e3 3f 12 00 17 86 79 73 0a 6e 89 fd 69 63 89 57 21 75 f2 4f 5f 77 26 ed 2d 12 09 6c e3 f2 79 10 02 00 00 01 6b 52 1f f2 94 9a 40 43 e1 70 35 a5 69 98 45 38 34 5e 87 48 9d c8 be c0 07 34 3a 6e 0e b3 13 eb ca a1 a4 d7 b8 07 cf bc 7d be 41 e4 76 d4 c0 5e cf f4 e7 a4 ad f0 09 cc 06 90 c4 04 4b be 85 49 3e e5 7f d3 33 df 03 a5 8f 60 f4 22 ab 72 f7 e5 cb 3f 33 09 23 5e fd fc 8b 11 82 3f dd e9 83 e1 fd 35 b0 ee ac 0c d7 52 2a b7 4b b1 65 fa cd 52 96 70 32 c4 e0 fd 5e 13 04 ad 8f b7 31 42 ab d2 d4 cb d2 2c 49 fa 99 3c 18 c2 9b df 20 28 bf f0 d2 01 62 56 9c 61 95 22 88 fd a3 09 d2 c5 dd f2 d7 12 a8 93 cb 48 33 04 48 07 e3 1c 99 ae 53 c6 d2 83 aa f5 f0 49 6d 4a 8c ee da 41 65 94 41 c8 64 75 (REG_BINARY) "924EB1974AFEBEB0FD6CC5317D3C6485375EB92C59"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 d7 b6 8b d0 11 5a b5 d2 a1 ce bd 9d 70 9a b4 db c4 4c 43 5a 83 0f 13 15 85 53 1d 3f 96 23 a3 21 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 78 4f f4 71 6f ec 6c aa 8e 1f 76 e6 dd 88 86 24 f3 e3 da 6d 55 18 ab ec 6a 9a 6f b0 57 26 9e 48 50 00 00 00 8c 28 52 59 ce d4 fe 1a 2c 58 c2 85 9a 68 8b 98 10 92 ef b1 7c 04 f6 28 2e c8 af b0 d5 89 b9 1c cd 1a 2f d8 6a fa d6 b3 bc eb ba 45 95 4d 35 37 7b 61 b5 84 42 ee ee c3 01 a1 29 85 78 11 bd 58 b4 40 76 ff 5b c6 f6 e8 97 82 72 2e d3 c4 98 03 40 00 00 00 07 56 9a 89 e0 0d 43 a5 87 62 8b 98 d9 6f 63 b3 f1 d5 a2 dd 20 6e 42 2f 73 66 a9 7a 64 72 80 55 a7 f9 21 8c 26 7a 74 e8 11 39 d9 1d 18 a7 d8 5b 0b ec 6e 99 a1 b8 9c a6 e9 28 b8 24 93 d4 fa 96 (REG_BINARY) "25D63977B5D48876833346C856116F99872EDE978F"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 20 d6 af fd 2c 4a 0a d3 cf 6c 74 58 cf f7 9a 6b 4a 63 62 71 82 59 1c a6 6f 0e fc aa a0 e3 c8 37 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 cf 02 69 d2 f7 a6 99 b6 44 ec f6 86 44 2b a1 c3 0d 4d b4 3b bd bd 9f dc ac 1a 3a 27 1a 86 98 0b 60 00 00 00 52 4e 00 76 f1 66 69 f0 c3 09 a0 cb 19 dc c5 a3 cf 61 00 50 83 ce 36 06 2a af 8a 89 b4 26 55 1d 0d 47 fb c8 f0 b2 94 e3 c9 50 21 53 37 ab c9 51 c4 3b 6e be e0 0c 5e 0a a4 e5 9b e1 eb 92 bb 62 0d 9b 02 0b ad a0 b0 e6 73 88 b1 c8 17 5f 96 cd dc 3f 7b 0c 79 dc 8f 99 2f 32 7b a6 d7 59 db 5e 40 00 00 00 46 32 bc 74 da a0 27 e0 1c 5c 0c 6b 44 fb fc c8 11 56 3a e4 7a de 29 48 5c ea 82 a9 95 e3 4a c8 12 51 64 11 eb ef 66 b0 ca 03 71 ed 2f 14 1a 00 65 28 d5 98 0f e9 01 46 38 d4 c6 12 d1 37 50 69 (REG_BINARY) "1C6C20FFA0A8BC6A180DD8A5004DA830FB5EC84D4A"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 f4 e0 1b 76 60 2b 9b 50 d6 19 2b 9d ee 91 ff 1c 89 98 81 f9 28 3e 36 40 dc c2 a9 47 ba 96 8e cb 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ac d1 37 bd 37 5f 4a 2a ba d0 a1 9f 6b 25 2a 3a 50 58 27 ad e9 cd 60 40 97 ae 4b 97 11 22 2d bd b0 00 00 00 94 05 5d 37 89 bf da 04 65 61 5c 21 f5 51 5e 67 1f 12 e7 99 be f7 14 c1 f8 2a b9 96 c6 1b 19 3f 9e 45 22 56 46 d8 79 e0 38 bb 9b f5 be 5d 83 b8 e0 8d ec 8d aa 31 a0 91 7f 98 a0 bd 57 8d ae f6 ca 2c 1e ea 5b 3a 65 4f b0 e5 6d b0 0a e9 5f 5f 09 ae 30 e2 d3 4c a3 3e 71 88 d4 1d fa 0f 36 80 5e ae 13 b8 2c bb 6e 5c de e1 da 6c 92 58 fd 09 5a 26 3b 79 be 09 ad a8 de 2a af fe 97 a6 bc 17 b0 99 9a c0 c8 68 66 36 c3 65 63 65 b1 8d d8 23 70 5e f3 23 ea 57 59 fd 04 19 31 f4 5d ed 46 19 8e 99 e6 d4 ea c5 08 61 75 27 9f be 7d d2 a0 29 40 00 00 00 75 cc a6 81 81 4d 24 53 3d 1c ca 5b 07 f9 3f (REG_BINARY) "C6FB044EC2BD401521D6B1082276415638196D8004"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 1f 53 91 f3 a8 a1 10 b2 8d 34 b8 b5 04 11 27 3c 02 83 39 1f 3b d5 04 ce fa a2 69 38 90 8c a1 33 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 31 25 0f 15 9a 06 ab 14 23 7f d5 c3 bf 53 0c 02 ea 66 88 4b e7 bc 2a 9b 30 e0 8d 60 6d fb b1 19 c0 0b 00 00 2b 36 2b 04 fe b4 88 2f a4 a8 1b 9b 16 22 94 71 c8 6c 33 70 78 d3 4b 12 93 ea 51 d2 0b 57 f4 3e d2 6f ec 08 7b 02 cf 37 45 08 79 95 9b b4 f8 ab f6 d7 2e 90 64 13 78 36 68 66 a5 f7 33 c9 ad 8c d3 35 12 d2 d2 e1 78 f4 e9 f7 52 e0 30 87 1e af 1b c1 09 a9 c2 87 83 9c aa 16 4b bf 8c 6d 6f 41 2a 19 40 b1 63 6b 97 31 ed ba 68 38 70 c7 75 fb 24 fa 5d fc 90 8d 74 03 de e5 2d cc 22 4c 81 35 14 19 ac 75 f1 58 ec 3d 83 44 5a 3b d1 1c e0 58 3a ee e2 57 fc 60 79 1a b2 b4 4b 58 1c 82 a6 49 05 55 63 68 33 be 73 88 5e 46 23 10 64 0f 6f 36 e9 ed 33 05 57 59 7a 31 2b e0 1f 99 34 55 2c 22 91 be 2b (REG_BINARY) "096420CE1C9A31839715B788EF20650AE3D02A535E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ca 7d 60 bf 7f d2 1d 42 b3 52 59 07 75 e1 a7 c5 8a 6b 71 4b 15 a1 b1 3a 52 11 8d f3 dc 5a 9c 04 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 c6 47 b2 03 4a 52 c1 6e d5 04 7c 40 ed b9 df b8 af 7f 0d 5e 67 59 7a ce f6 f4 64 b2 81 61 83 fd 80 00 00 00 65 4d c7 bf 4c 9f 74 fc cc 23 02 5a 2a 5d 1d e1 01 dd f5 46 a3 55 a7 a8 31 a9 92 cf ba 04 32 ee 48 c8 ab c8 ec a5 e2 20 e7 2e 24 84 59 b6 8f a0 67 6e 0e 45 2d cd 81 f7 96 f3 21 ec 10 c1 3f 24 79 03 7c 42 b5 05 df 32 bf ea 25 18 30 5a da ee 34 28 e8 63 58 c1 ce 9c e5 c9 24 a2 28 6c 2f 94 da 75 c3 98 aa 9c 49 5c 58 c9 04 a1 2f 6e 9c a9 d4 c0 01 0f 4d 1b ef 9d e9 23 bc 14 21 6a b9 86 40 00 00 00 d7 13 a1 c8 95 07 2c e5 14 6c 05 88 2c 2e 4f fe 1d a8 a2 ee fc 3f c6 33 d9 11 7b a2 83 49 3d 23 9f fb 70 b0 08 ea 2f da 95 4b eb 0d d4 fc 90 79 f8 41 c4 b7 3d de 0e a4 bb d4 56 95 a1 b4 2f (REG_BINARY) "4D13E0440141F4A946A15AD5D799B3182A6A7D9156"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 1f 07 7f e1 d2 59 d8 29 95 4a 70 a0 21 ee 16 26 63 ab f9 f0 eb 58 d2 56 27 3a 5a 97 10 ed 63 08 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ea cc 02 ed 7b 68 4c ca 0f a4 9b 6d 5f fc 41 31 eb 72 cf de 04 e4 eb f1 51 fa 46 fd ee 86 3d 09 80 00 00 00 ad 92 56 ca f3 b2 b4 32 98 3d b5 de 00 b7 b1 e1 4f 6f 3b 22 75 42 e5 73 cb ba da f6 52 16 0d 9b 0b ff 2d ae ab b7 35 6a de 68 ef 4e 4d 10 70 e6 4b 8e c4 72 96 db ef f7 9a 61 39 21 27 7f 75 6e 34 bd 6a 79 49 e2 dc 7f 89 a0 37 0b d0 06 50 52 93 54 2d 98 dc c4 3d 68 c4 a0 f9 fe 44 b8 e5 f3 7e 33 f6 f4 71 ed 4d b0 96 a5 c3 cd 3b 95 32 ce 2e 3d 0a 06 41 51 29 92 9e 70 17 86 64 cb 49 03 40 00 00 00 5d ce c3 4b 2c fc c9 24 81 fb d8 d9 9c e5 a7 cb 95 b6 d5 04 b7 db c0 73 0c 35 bf 9b 88 5e c5 6c b8 2d ce 85 ce 2b 1a 69 87 1e 2c 2c ed 5e 6a f7 fc eb 9b 1e b9 a2 dc f9 95 9c 8b 74 0d a3 35 (REG_BINARY) "6E93C85D71708197754FB5CA3C86A5FB920D941108"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 fa a7 1f 65 44 fb 3d 18 b6 60 43 e5 92 28 7c b1 a4 b3 4d 2f 78 59 77 18 aa 3f 06 8b d9 05 5d 8a 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 fb 76 09 58 ef 9f 72 51 7d b5 22 a4 f7 2d 2d 4b 87 2f c4 21 af d7 fe 3f f1 84 a2 79 44 e8 6a 88 20 01 00 00 95 a3 7c 64 54 23 04 ab ed 0f f7 7c 15 84 d2 7b e6 52 4d e6 56 f7 27 ed 1f 29 da ea 99 83 e1 fc 05 f1 b2 9c 1f a1 00 c2 aa 18 33 de 47 c4 c8 21 6b 10 ad 0e 9c 5c f9 a0 f5 e6 e1 34 90 88 bd a4 71 d6 07 43 38 4a fe 11 24 13 0e 39 ba dc fe 37 d9 2b 0f 00 a9 d6 13 f8 76 80 f1 24 5d 3e f8 68 48 7f b1 7a 81 4c 1a 6d 1a 0f 1f 0c 9f 3d a0 aa ca 2c 7d 35 08 c1 4b c0 dd f2 e6 fe 97 91 51 bd 70 0b 8a d7 d2 10 fd f5 66 58 b6 f1 ae 34 b6 10 3e 55 cc 50 c4 5a 03 d8 83 39 e7 dc 7a a9 29 e8 4b 30 e4 2b 17 a5 b0 86 76 43 ff e9 6b 83 34 bc 51 d6 e3 b4 8f ed 05 9f 5f dc 5a 51 45 62 3d 10 d5 0c 0f (REG_BINARY) "A7301AB81D7D809D725CB2004475E966776980AAF2"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 7d f0 bc 5c 1d ce 57 41 b2 1b 5d c0 56 9d a6 96 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 59 cd 88 b0 00 35 82 90 84 1a d9 31 93 55 a7 ee 71 1f 51 b3 b4 12 a0 d2 09 93 7e 55 32 da 34 6e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 b3 2e 23 20 18 e7 08 05 f8 96 d2 59 c4 ac 72 6f e3 96 a4 6c 49 38 8e 7c df df d7 2a 3e 8e b3 a9 c0 01 00 00 de 77 b8 05 1d 6f 50 d7 b9 4a 84 7b c0 f1 b4 97 cd 76 96 e1 6a 51 d1 eb 95 98 b2 be ef 20 3a c6 18 6d 6c 4a 10 d1 3d 45 74 82 e4 81 fc c9 e0 1b 65 cb ab 9c d7 0d 28 20 20 f8 f9 43 8b 0e 1b 13 05 ad dc 8f 2b e8 8c f1 4d 77 09 f0 86 d3 c6 60 94 63 87 97 b2 b3 86 57 34 00 ce 70 af 9c 9c b2 a7 ba fb 04 af c0 53 cc 4d 3a dc 93 f2 09 7c 9b c5 56 6c cc 8f d3 ef 64 c6 7a 4a a4 d4 10 e7 c6 67 c4 d0 80 06 05 88 b3 a1 24 8f 90 68 d2 a6 4e 8c cb 42 e0 54 7a 7e d3 80 59 9f 94 4b 61 f5 a8 23 16 01 90 62 a1 da 82 c8 ff 1f f5 da 81 01 97 fe 81 59 a6 ab 77 a9 f1 b2 4d f7 ee a7 d0 1b e6 49 27 7c (REG_BINARY) "E4C8031156725AE776172EF7EA1830E573F904FDFF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 fe 70 1d 86 73 0d bb 58 63 11 6c 3e a9 33 c9 38 19 77 38 3f b5 21 ea f2 09 30 4f 53 88 a8 35 51 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 0d b6 6a 44 f0 b7 69 03 86 6e 9c 89 ca 57 2d 29 dd 40 12 1e 51 da dd b8 a0 5c 91 5b 25 59 c6 45 50 00 00 00 05 2c 77 af a3 94 08 c0 39 21 28 8d 55 0f 91 9d b5 89 2e c5 c5 73 97 16 c2 f1 11 60 fb d8 5f 72 33 0e f1 f7 d7 21 c0 26 f8 89 62 c3 02 15 bf 6a f1 36 f3 74 49 1e 0c 9c 54 a9 fb 32 d0 b9 a3 54 53 9c 93 26 db e6 5f 15 14 b9 14 df d8 15 bc f3 40 00 00 00 89 84 e2 f8 d4 6c cc f3 d1 56 9b f2 60 ee 85 d8 d5 6d cb 93 cc 50 cd 91 4d 58 c7 22 50 8b 1b 99 ec e3 8a 97 47 79 6a 5c d1 e2 cf 6a bd 1e 66 de 5a 19 3d 4c 91 47 f0 2d 64 08 b2 ef dd 02 0b 34 (REG_BINARY) "37ADB64C2CDA898AC56C464BD00BAFF748AC1E267A"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 64 d4 61 ae 2a d5 2c 16 e7 b9 63 a0 d0 eb 6b 7d a5 28 b4 04 b6 a4 85 75 68 cb e0 99 ef 15 dd 59 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 61 12 cc 28 ff e3 b0 06 16 78 f7 98 7d df 63 b4 48 1c 0b 69 93 45 0f 8c 06 f0 59 db 51 2b b0 62 60 00 00 00 b4 5b 75 0d 1f 34 5b 63 31 2e 37 96 b5 94 88 ab e0 6b 3b 42 d9 e9 70 eb d6 a3 26 05 f7 40 cc 3f 26 15 fa af fe b2 af 71 94 b1 4c ce 1b fa f0 7b c1 1d d3 6c b8 a7 c7 59 ee e1 9f 77 bf c6 10 ac 2e 36 d9 bb cd 7a ca f3 87 8d 66 87 98 33 42 3a c5 fd 48 e0 c9 9d 98 64 dd 09 17 66 17 79 d6 ff 40 00 00 00 11 6b 7b c9 33 b6 07 76 ac d9 70 37 a7 aa 18 ef ca 28 72 eb 19 36 b6 b9 66 d1 1f 82 45 67 2c 06 18 24 0f ba 15 0f 95 f1 b8 6a 2a 7e 6d a9 18 0d 2f 33 15 0c d5 c1 df e0 a1 8d 75 d2 70 dc ad 2f (REG_BINARY) "BEE9113CBB15337F699571D41E7D887DDF37055CD0"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 2a 37 ee 95 a5 70 b0 28 cf 2c 6d 57 20 bb 31 ac c1 27 36 08 25 bc ad 71 6b 02 c8 56 ea 00 6a ac 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 84 eb 15 80 a4 32 ea 9c 61 1a cc 33 90 8a a5 d2 b9 ac 9c ad 1d 71 34 f4 cf 2f ad e1 35 53 b6 55 50 00 00 00 ec e5 75 9d af 33 02 e4 e2 6d 18 08 4b a6 d3 ce 5f 65 d5 7e 91 2a fd e2 db 65 26 dd b9 db b6 01 47 0a eb 1f aa f1 3e 45 9c e1 2e d7 7e ea ca 63 71 d1 11 2a 3c f1 bb 02 87 a1 44 48 5f 7a a8 43 6b 61 ab d0 71 a0 47 00 68 c3 20 9b c3 53 73 49 40 00 00 00 23 36 9f ac ea f2 bc 32 35 34 86 1a 13 de 5e a9 37 6b 87 74 77 82 a3 09 7d cd fd e5 a5 85 5a d2 f9 0e 22 bb 29 7a 21 0f d7 81 ea 27 75 43 50 7d 43 b6 3c 47 df b5 97 51 29 9f a8 ca 55 37 59 6a (REG_BINARY) "F10FD9E6D178A4A9BB12FCD905C528678472F70F4C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 47 33 e0 71 86 d2 ab 0e c1 91 8f ab 1b 34 66 bc 97 76 9b c1 65 5d eb d3 82 2a 0d cd f1 e2 52 bf 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4b 93 a0 12 a1 67 b4 a3 86 66 0d 93 40 ab 84 aa 1d ab 20 37 88 54 20 5c 62 00 43 b5 79 bc d8 7d 50 00 00 00 0c e1 b0 57 ad fd 20 c4 07 2f 38 41 9d ba 71 25 38 33 10 c4 49 1b 4b ce a7 6a 79 e7 aa 3f 65 67 67 13 c7 01 ad 9e 0f b9 c1 c5 9a d2 c1 9b ed e2 30 33 ac d0 33 3a c9 95 70 7b 65 9b d2 3b 0f 42 42 3b e1 2d 24 e4 8b 30 ed d6 89 47 79 04 6a a6 40 00 00 00 3b ab 9a 99 8a 71 81 98 6f 7b 59 28 e9 e2 89 00 89 89 dd 8d a8 9c 74 ab 1d 3b 7e 90 c3 c9 d8 d0 16 bf 43 09 e0 dd 67 d4 78 8c 3d 22 98 0c ba 37 51 ca a9 66 3c 41 bb b3 7b 89 62 c5 9b 89 09 1d (REG_BINARY) "CCE7D6897E34A3152B11E238F315AC9BE45C397610"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 1f 56 92 aa ea 83 a9 d2 00 a6 c8 57 9a 86 c9 83 a4 5f 67 eb ae 01 27 67 d9 fd 3e a4 65 c4 b2 6a 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 2d 2b 3b 0b 5e 37 06 ba a7 71 9b b9 57 ec 3e 21 45 67 8b 92 d8 58 fc 7a bf 1a 2b c8 dd 1f 32 73 40 00 00 00 c6 3d 0a 4c 82 1a 9a ff 81 12 0f 6c 0e ee 8c b0 6f f6 b3 7e 1a 4b b7 68 46 e7 0f 25 c2 1d 8b a4 47 d4 55 4e 76 a5 e1 47 53 9f ee 01 49 7a 67 1a e6 fe fc 4f 85 67 2f a0 c6 20 f9 39 95 98 e0 20 40 00 00 00 58 f8 a9 ff ae 3e 81 71 ff 8a 60 16 38 d7 b8 9c fe 11 a4 05 80 06 3d b8 27 03 f6 ee 46 36 c1 18 b3 51 0b 61 4c 13 d8 1d 00 3b 77 f9 08 e4 bb f5 0e 5d b6 e6 10 d4 93 8f 2a 20 f6 a0 58 bc 4e 67 (REG_BINARY) "DD043914DD02231ABE7740D90D427B313E31FDACAB"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 66 36 3a 18 2d aa 32 a7 5e 27 c9 84 b5 71 ab 8d 2c 49 54 e4 8f d0 d9 38 63 f1 1d 8c 86 7a b1 60 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 43 e7 13 95 c2 32 f8 02 ba a3 03 7e 40 73 a5 44 18 6d 31 a1 c5 d1 56 b1 5e 2f ae 99 16 87 e1 d8 50 00 00 00 4b ac ea 98 30 72 de 10 15 47 a1 b8 58 b6 33 07 7b 3e 13 ef da da c6 55 1a fe cc a0 6f 3d e8 0d 17 d4 8e b5 ee 9c 73 3b 01 13 da e8 e4 09 ac 73 89 be 42 7d 73 fd c2 62 d7 54 0a 57 fb ca 7d 20 f7 60 d4 f6 b0 cc cf ca 03 44 c2 65 a5 d7 d9 19 40 00 00 00 c4 61 63 5f 20 ca 54 8d 75 ac c4 27 6d d3 92 b3 61 9f f3 97 51 d2 fb 4f 51 57 a2 c6 60 d0 11 6e 4b 84 5b 09 7a 0a 69 c8 56 02 ab c9 cf 4d 59 d5 d9 5f dc 49 f1 c8 5e 03 c4 17 6d 93 21 12 c7 ba (REG_BINARY) "72B9F7879945CD82128EA98C1A81E14CF92DF9DC6E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 18 df ed ef 5b 09 35 b7 82 de b3 c4 e3 a4 30 c7 e2 6c a1 60 e4 06 19 64 6b 1a 19 c9 ac 43 48 b4 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 af d7 95 f6 d6 cf c6 c7 2f c9 3e 2c 34 14 da d9 65 35 aa db a4 93 b7 98 ee b2 05 65 f5 5e f4 17 40 00 00 00 7d de 9c 23 f2 c6 71 f6 56 67 5e 2f 30 66 50 8c 37 bc 0f d3 c6 54 49 2f 52 5a 60 3f 03 79 5e 75 d4 fb 95 c3 0e 31 aa e7 6e 89 e0 b3 d7 41 0e 3b 06 c8 2e 1e 68 2c 52 77 2b 8d af f2 95 cc 61 21 40 00 00 00 4e 71 9c 32 48 62 b8 17 0b f8 3e 74 93 f4 38 ad ce 83 6b dc a1 96 43 dd 8a fa 73 b2 74 36 5d bf 05 9f 60 3f b5 a9 31 55 30 b8 ab 9e 72 58 8f 83 f8 3a a1 4c 4f f2 9b 2d 8c b7 f2 c2 a6 91 f0 18 (REG_BINARY) "67027095D7C972F0846B26C33A9F1F2B488135D23B"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3e 1a 63 c6 55 b1 57 53 f6 50 fe d1 af 91 06 84 ca ad 0f 16 04 5f f7 38 99 b9 18 52 4e ef 5b 22 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 db 27 4d 42 4c 91 04 58 20 31 72 de 34 ee 49 17 b6 36 98 5e 39 c4 fb 7a 67 3d a0 8b 61 c6 76 a0 40 00 00 00 8d ea 9c f5 53 6b 4e 4b c5 02 28 71 80 2e 7b b1 06 f8 25 32 a7 4c 64 f4 f2 16 df 50 48 74 b6 f7 46 95 1c f2 28 5b 5e c5 5f 5c f8 a7 8e cd 14 e9 cf b3 8e 17 cc 72 8c 4f 15 25 b6 51 90 77 d5 0f 40 00 00 00 72 d3 cb c8 33 be e9 a9 0a ef e7 26 45 e3 86 22 5e 7c 45 19 10 c4 c6 22 5a fa db ad 9a fa ca 50 4a d9 d2 db 02 df d8 60 73 67 64 ca 63 4d 1a 84 0b 6e 32 22 ce a3 34 e3 8b 87 b3 6a 61 c4 f9 23 (REG_BINARY) "4A08BFF993FEB540429405C15C0AB12E10B9AF3E27"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 40 b9 2a 27 30 70 c1 95 4b e2 2d 95 db 5a ab 78 51 91 ec d2 91 97 07 35 65 2b f1 ad a7 2d ce d1 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 3a 46 87 63 96 e7 f6 7e 3b 22 7c 7b 4a 27 ad e9 db cc c7 4f 46 c9 ca a9 79 82 4b bd 61 42 76 77 40 00 00 00 13 fb 12 ff 9f aa a3 d2 d2 4c 74 09 79 37 6f dc 6c 7b ac ca eb a0 9f 2d 5c c2 31 6d 73 36 c1 48 74 b5 21 22 35 db 71 28 f9 da 1a dc 53 a8 32 4b 3c c4 af ce 99 7a 1e 93 97 09 b0 d0 a5 8c 17 f4 40 00 00 00 9f f9 cc 31 a4 c9 66 00 56 2f 1a 43 b6 82 66 09 03 b3 88 8a a5 29 1f a3 0d 3f ac 86 aa c9 4e 8d 89 b6 86 c7 75 b1 f7 0d 74 59 c0 31 9f 36 7b 73 5b 0e 7c 95 27 44 d7 d6 ed eb 67 9f 31 a7 c4 00 (REG_BINARY) "48AFA9E93B9296921462981A85E8595849AB1F15EC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ef 56 64 96 37 ac b8 36 b0 af f9 77 50 3d 6f c2 8f d1 09 7e 96 c9 a5 2c 5b d4 5b c2 2e de c6 6f 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 75 83 c9 88 63 0c 4e f0 59 50 d2 be 95 03 c9 76 dc bc d1 5b af 9c b7 e5 f7 8b ca 9b a3 bc 8b b0 40 00 00 00 7f c7 e2 2f a8 cc 79 42 8e e1 33 f3 b5 bd 92 e0 70 81 d2 4e 28 42 45 1b ea 21 e4 eb b7 01 ee 3f 9d 45 e7 57 9c f0 91 cb b2 f6 77 d8 e8 27 62 28 32 8e 72 7b be 77 ae 81 eb 10 85 70 fb 2b 82 ed 40 00 00 00 ea e5 45 c8 fc 68 c4 11 1b 53 6a 20 68 e6 62 f8 be 15 53 ff bc 88 c8 bd 17 a4 d8 4c d1 01 92 ba 5f cd 4d 39 9e d3 1c 5e 0b 02 23 6d 63 d5 f2 2a d9 bc ef 27 32 a6 83 69 ee 51 b6 90 80 3d 2e 0d (REG_BINARY) "D3C90BA40F9C3A2AF77BBF0C5C249A980BDF742DD4"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 eb a9 e2 1e b0 11 45 44 19 fb 5a be 75 d6 de 97 08 30 27 25 43 02 da 38 ac 0e b6 b4 1c ee 73 c5 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7c cf fe a6 58 32 24 26 08 8c 13 69 6b fa 54 a0 99 44 a1 24 70 23 56 70 ca 7a 0f 56 40 78 aa bc 60 00 00 00 bc 60 0d d8 97 40 ad 85 d1 e8 70 9d 85 e1 dc 83 6d 53 f0 d1 1f bf 80 f5 72 66 a8 97 3e 21 41 87 25 25 9f 00 29 1c 20 60 cf 42 f4 49 11 36 56 b9 bc 38 46 1c 02 a8 59 00 d6 1c c7 56 27 fa dd 38 72 01 33 99 d4 88 ff f5 1e 99 50 c8 99 02 58 b8 51 22 2d cd 1c 80 0b db e2 62 49 7e 04 71 e4 ea 40 00 00 00 1e 04 ea d6 63 cd df 99 89 30 53 80 3d 8d 45 33 82 1b f8 67 fa 93 84 1c 2b 1f 13 dd 76 c5 47 55 40 a2 3d 01 e5 2b 3f 02 c3 ea 30 ba db d7 ab d7 e9 fa 14 06 c6 69 2a 98 83 54 e4 be 72 40 47 06 (REG_BINARY) "A85DB3B00F8E4C2E6C71ADF6B7791E6E6A6B664238"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 08 54 c0 01 7b 76 b0 a0 d0 6a 4a 0a 35 13 23 fb 83 a8 c8 7f db 5c ba 07 f8 a0 df 08 26 92 c7 7c 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 a1 ea 79 74 86 44 60 13 92 f6 77 92 cc 2c a5 45 d3 99 4a 2b c5 9f 84 ab cb 87 d1 9c b5 2b a6 41 90 00 00 00 da 17 d4 c9 a2 5b ff a9 47 79 63 9f 87 df 8d ac 08 38 19 d1 bb 34 8c 8e 8d 89 84 fd 8a e8 71 b5 b9 c7 55 3b 73 7e 8e 73 d2 46 99 64 41 7f 3b 8e ea 6f 0f e1 e9 68 7f 6f f7 3a a4 02 47 4c 80 96 50 d4 2f 4f aa 89 8d 46 c8 34 4e e7 ba b3 56 28 76 fc 61 8a 3a 72 1c 3c 4a 76 e2 30 7f 8a a9 94 11 c6 03 c2 8f b4 d5 b6 ad af bb 04 53 d4 62 b1 11 e6 ee dc 6d b0 77 d7 5a d5 a8 3e 37 70 ab cf cf 8a 73 33 d5 da 3e 53 cc d0 d2 a2 7d a6 b3 80 40 00 00 00 fa d2 03 5e 05 45 97 c2 f2 19 40 32 53 f7 a1 3f 07 b6 02 f8 69 e8 97 5e df b5 23 2f f8 0d 8b c4 3d b1 45 58 50 b5 a2 e3 db bf e6 cf a6 f6 55 (REG_BINARY) "280960C8406F5B54472F854047DC521120CFA69BA8"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 10 4f b5 79 f3 76 0a 6b cc 4d 22 c7 f3 31 95 1e 20 5c 2a a6 8b 71 85 15 8f 06 ea ed 67 13 8a 18 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ad 7b a0 47 83 80 54 1e cf 0b 0a 39 88 6f f5 83 f0 a3 c0 f9 15 c5 0a a3 4c b6 bc 28 13 d1 b0 ec b0 00 00 00 26 1f d0 1e 9d e5 0d 76 30 40 1e 12 09 81 ff a6 b0 d0 f7 8a f0 68 5e b6 5f db 18 23 76 37 36 e8 e5 ad cc 32 25 23 02 1f 13 5b 7c 30 9b 2c 7f 65 c1 4f 60 a8 d3 b0 4e 55 10 1e 15 f5 1d 85 2b e8 12 9f ee 43 6e 85 0a 3c ff 1d 4f b0 fc fc ae 8e 98 2d da cf 60 66 b4 30 a4 76 02 31 54 b6 51 40 6e f9 ce de 9c b2 ed 92 58 24 3e db 3b 68 7c 87 3e 53 e1 66 fe 7e 62 59 79 49 43 6c 4d 92 63 24 d7 73 e5 a1 50 2f c0 a9 9e ca 6d 82 b1 c2 99 f9 b4 af e7 ec d7 8a 1b 2b ce 8b 3d af ca 03 21 9c 06 b4 15 09 c0 2b c5 e7 f4 c4 65 cb d4 9c 02 27 40 00 00 00 10 4d 30 17 39 3d eb 9c 9f a3 69 c1 98 ac 2e (REG_BINARY) "0BA59E6EA4F2E8C97BA317DBCEAE25A2847A942B13"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 e8 b5 77 77 e6 a1 bf f3 b4 ce db f7 04 b3 5c 94 7c 6b 72 b1 50 29 df 3a 9e 17 b8 df 27 aa ed 51 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4f bc b7 7d 44 37 bc 6c 85 9c 99 0c e5 58 02 0c c8 f7 25 7f 25 9b 8e 1c d2 c2 2d 07 fc ec b4 9b 50 00 00 00 f0 fb 56 a8 72 c2 92 d7 f4 5d b3 f3 20 f5 68 e1 da f4 c1 de 3f 59 d4 c8 77 2c 55 30 d7 ea 7c c4 7d 4a 29 ad ca 25 c7 c6 51 d5 3f 49 49 f5 83 b1 f3 66 2d e5 38 d1 ff 04 f0 ab 61 37 35 ef d0 d1 55 7b da 68 56 14 7b a8 8c 48 96 33 08 cf 82 27 40 00 00 00 f5 91 4a 97 36 fe d4 55 7d 03 ce 15 51 5d ea da 4a ee 2f 9b 86 84 85 f1 22 39 97 d2 ef 45 af ea fd bc 45 08 ba f6 0b 47 f0 53 5e ad 53 e1 11 72 d9 a0 08 6c 59 c7 a1 14 78 0b 74 b0 99 c3 00 88 (REG_BINARY) "710D91E52989D9063F237E934DFB5B9A1208775B21"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 22 60 b9 4c 9b af 66 62 44 c3 b6 ab a3 02 0d 6b c2 aa 73 30 f2 92 00 0a 14 f9 c2 40 bd 6e 47 28 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 5c b2 ac fc da 74 cd 3e f7 69 cb aa b7 fb 62 d1 6b 2f 90 74 9c bd 91 83 e7 3d d9 34 ac 66 36 14 60 00 00 00 55 8b 94 94 b6 5e 0a 21 34 5b 25 08 9b e9 d7 34 ff 3a d6 5f cb 5d 08 fd d6 64 93 36 b2 64 0d d9 46 9b ae 74 34 50 96 01 e1 46 d4 42 98 ec ad 51 bc d2 ab 24 60 9d da 67 a3 ef d7 ad 9c 84 0c 5f a3 79 6a f1 41 9b dc b5 76 07 15 75 de 42 95 d0 65 af 0f 5c ac 8e 85 45 02 38 eb 6b d9 a3 dc 32 40 00 00 00 91 6d 3e c0 8e f6 fd d7 bf 87 54 06 3a 8a 60 fc 52 75 57 8f fd a0 45 b9 9c b3 4e 57 e1 19 6f 18 a1 5b 9e 47 16 99 81 94 ac e6 2d b4 55 fa 77 60 61 3b 22 b7 f1 ea 7d 24 70 12 df d8 66 48 be 44 (REG_BINARY) "3EECBED6028B282FE1E7A5299DE569434BAEE41558"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6b 04 4e 5b 4a 43 83 39 91 65 9c 50 55 6e 98 dd b5 94 0d 97 28 04 71 ce ec bc 75 55 0f e2 51 80 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 34 a2 f1 ce 42 d3 31 be 9f c9 9c 9c 5e 25 84 92 77 fa 97 af d9 67 be 17 b5 a8 13 37 6f ac 81 51 50 00 00 00 8f 1c 19 9d a9 d9 60 45 d0 c0 ba e4 05 e6 9f 85 f2 b2 d2 2b 22 d0 62 4c 8b 60 f3 47 0e f4 5b 6e e7 9c ea b5 08 1b 38 7a d3 ec 47 d6 66 ed 90 86 9c 8a 21 ee 86 74 4f 58 d2 15 2e d8 bc 39 bb 0e fc 13 df 36 0a 61 8d ff 0a 9a 52 e5 72 d3 a8 f2 40 00 00 00 bc 3b 6e 59 c3 f2 11 21 81 95 e7 fa d3 b4 4e 73 96 a9 93 7b 9b fd c0 11 4f b2 db e0 42 8a d5 c2 eb 4a 7b 98 bb f9 79 c2 b2 c1 ff d0 95 87 a3 97 16 e2 a7 6d 8e 19 ca b6 3b 72 8c 86 84 8c 5f 82 (REG_BINARY) "047B0A999BE29C6465483501EA4893E81978A395F8"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 15 53 bd 12 ac d2 3d 07 46 5b cf f1 54 04 cc 59 d9 fc ad b0 70 e0 82 8d 71 c9 cf 07 a6 84 26 a4 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4a 4c 0e 66 c4 aa 74 be 6e 42 17 9a 5c de 83 28 46 dc 76 4f 0a ab f8 b8 6a 8c 5c 01 4a 40 1e 92 50 00 00 00 c3 d1 e8 74 af a4 c0 e8 56 9f f6 6d 11 30 7b 35 18 89 b2 9b 79 d7 c8 c2 74 db 94 e3 25 4a a2 df 81 92 84 b5 71 b1 2c bd 51 29 66 11 b2 22 98 ff 9d a2 b3 5a fd ce d2 f0 99 46 de a5 0f ca 27 46 15 b3 12 b2 d0 c8 5e 87 25 bc e9 30 5d 3f c8 36 40 00 00 00 08 f8 0d ee de eb fb ef 2b 3c 12 98 2b cc f6 fc 11 55 64 e8 9a 86 28 15 bd 91 3d 61 a1 0c d8 11 dc a4 e3 42 c9 24 fc 0d 32 36 04 83 62 bb e1 08 67 3d fb 8e 1c 48 99 b2 22 26 7d 24 0f 64 55 26 (REG_BINARY) "18F22D7CD3BBAEF4D6D1C9BF29FE5EC3BFB0404D56"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 71 e6 85 24 92 59 6e 5a 44 0d 88 d9 8c 8d a9 dc 68 dc ae 56 b2 95 34 ce 86 a0 01 45 3c 53 94 c8 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 8f 91 86 55 12 0f 98 02 68 37 17 09 f3 da 1e a1 a9 d4 78 c2 5c ab c0 ed 76 9c ed 28 0c a4 60 60 50 00 00 00 fc 99 9d b2 42 c5 09 a3 fd 56 33 9d e1 c8 3f b7 13 1b d0 50 3a fb f2 07 a2 ba f9 eb be bb fd cc ab 17 c9 46 b2 31 78 ef 10 e0 60 dd b7 bb e3 9d 70 47 17 e6 58 77 df 6e 7c b0 d2 66 85 a8 41 e0 cc c7 f5 ff 2e ff a5 23 96 a4 cc 6f 45 bb 3e 5a 40 00 00 00 e2 45 58 54 ae 81 96 28 4b 63 bf 79 fa bc 55 a8 ef 65 71 3b ed be 14 c5 41 13 e2 8c 1a d3 e5 6e 23 b7 86 2e 8e 4c e6 9a 64 81 8e 84 61 6b 1b d9 51 c9 c4 fe c8 c0 af 59 73 be c8 ac d5 b8 d3 ee (REG_BINARY) "7DAC7BC00FAF594202F3D0B9F92C48F45B0066F956"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 50 ee 8f 01 26 39 f3 51 95 42 87 1d 70 53 2d b1 c5 1e 2b 47 d5 fd 44 ed 27 dc 47 f6 c5 2a 1c 6d 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 6a 6c b4 7a a5 5e e4 3b 3e d2 56 43 b2 d5 e7 69 06 ac 40 32 1b 9a fc 2e 58 e9 70 6b 41 80 75 8a 40 00 00 00 6f 63 cf 54 48 e1 b8 42 24 46 e8 11 ce bb 1a 68 57 5a 26 97 1b d7 b6 57 a9 8d 78 90 85 92 81 18 41 fe 65 02 63 99 e4 de 3f 37 a5 3b c1 5d f9 4b e0 ce c0 b1 ae 42 0c ed 69 21 4c 09 02 8b 8a a3 40 00 00 00 69 9c 85 87 93 ae 98 98 64 82 d5 42 ad bd db d7 e5 0c 55 69 71 08 e9 4f c4 8f 35 6e d3 c2 78 d2 5f 45 ba 25 97 ca 00 40 06 26 bb 96 35 2d c1 ec 5f 90 11 c4 d9 6f 6c 74 a9 05 d5 c5 51 bd 15 6d (REG_BINARY) "9A487C01AF93AEF3F218373ED252D45069BAD6C0C2"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 da 7f d1 31 24 fd 5c 48 a1 10 76 d0 62 f1 bd c9 b3 30 0d f1 77 2a 0a a4 7b 63 70 13 c9 84 26 ae 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ff e5 af fb a1 2d 0e d3 b0 ab 67 e9 54 78 d2 03 09 31 f5 23 76 4f 11 7e 9f f8 1f 7c 5a 9d f4 51 60 00 00 00 f1 57 e4 c6 c4 4e 84 94 30 ec 55 df 73 5a f1 ec ba 49 02 50 60 19 69 b3 de 3e fc 04 46 36 1e 40 d1 c4 65 31 3a b0 84 ed 4f 09 f9 85 c1 f5 8e 52 90 bc 57 16 fe 3e b3 7b a2 e3 9b d3 24 81 a1 51 73 a0 34 a4 fd 9b 36 5c b3 64 25 50 4d c3 54 3b 4b 3b 90 b6 f8 c3 da bf 75 78 f8 9c c6 81 a1 4f 40 00 00 00 eb 56 dd cf a8 f0 fd bf 06 89 cf 21 bd 7c dd c0 7c 1a 51 c3 9a f7 89 90 46 87 cd 71 17 a0 55 68 dd 04 88 0f f7 81 6d 69 3c d9 ad bd 31 bc 28 44 3b a3 c7 01 77 39 fc 5a 9b 1c 13 95 91 bd cb 5d (REG_BINARY) "277687B2398A1345F223BE0F0889717B4494E7B5C4"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 aa 87 2c 45 94 73 76 44 61 50 2c a1 46 8f 1c 65 f3 40 62 f2 37 56 fd af a0 9e 8c 83 f5 dd 3c 0b 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7c 28 38 c1 44 52 a3 27 6e d3 6f ff 84 9c 4e d7 9e c4 49 df d7 c9 d4 57 e6 81 7b e3 bd d3 c0 98 a0 00 00 00 e3 07 97 08 81 6e 22 b0 9e 93 46 8e cb 1b 62 30 2c f4 f7 c5 22 cc 8d f2 69 3d b8 17 3d 20 8c 5e 61 88 5b 4b 38 ad 7d a1 63 0e d5 6d 99 46 f2 a5 ba f9 26 c9 b8 74 49 c3 f9 07 68 24 89 d6 87 5e c8 fc 18 f9 92 9b aa 62 06 bf 7f ba a3 a3 0a 58 62 b3 21 63 82 64 32 4d 97 89 af dd 2f 8d 7e 50 eb 61 15 c4 1a a0 d2 67 93 f9 0d a0 c4 ec 0b 76 4f 87 f4 f6 f8 26 c6 5e 59 0f b8 43 ee 65 59 1a 2e f9 f0 96 17 6a c4 80 ad 0b cf fd 80 c6 10 fc 08 ab 4c 5f 69 c3 d8 bf 56 ea 96 4e 40 d6 f8 9c 40 00 00 00 51 ee ec ed d8 58 d8 dd 87 b6 c9 68 6b 8b cc 33 5b 08 08 c8 80 99 7e 43 89 26 35 7f 86 a6 fd (REG_BINARY) "90D5C215D3DA44C6D0D6B7E9FD3CA053A5EFBEF1A8"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b1 a9 7e b2 31 5e ce 5a 8e b7 7e b1 60 b9 ff a6 bd 31 36 1a 41 b5 c9 43 c5 17 7d c3 bb e7 39 69 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 da 89 d3 e0 e2 76 2b 9f 90 5c 5b c2 86 b0 e7 b5 6a c1 59 ca 1c 22 96 10 65 89 b8 ff 3a e8 5d 58 d0 00 00 00 ea b6 8f e9 87 ab b8 b4 0c 66 f1 06 b9 59 50 95 cc 08 9e eb 23 d2 b9 67 55 86 c1 ce b2 84 8d c2 47 10 3d ea 7e 00 14 75 a5 db cf 4f 29 75 60 9e 8f 2e dd c0 0c ca 4c ff 18 17 7a f1 b1 b4 8f c7 cb 30 e9 06 2c b3 71 57 73 92 93 5d aa 3d e1 22 11 f0 b9 72 a1 68 aa 92 01 2c 63 9b b4 bf 5b 26 45 99 be 3a bd 0e f7 a6 2d 76 5e f2 d5 50 1c 5e 78 4c 6e c5 bf b9 36 21 39 e9 99 a9 3d 14 c1 21 01 de c8 a7 81 e0 91 bd c4 a9 bc e6 f2 3a e5 10 04 40 3c a6 e1 f9 95 42 85 13 5e dc 29 35 f7 5e 1c ff d9 7b 5e 86 0f 85 f7 c7 09 48 24 9f 53 62 67 1e a9 b5 f7 fb 3b 55 69 f7 be 27 86 f3 5a ce 3f f1 78 (REG_BINARY) "83EBB6A39BB833B1414D793064CB18F84F12266E69"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b8 81 dd b1 99 b5 75 62 ec 55 a9 34 15 44 e3 3e 50 81 46 5a 60 c2 d8 2f ec a6 c1 46 9b 02 bc 7e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 d5 4f 70 22 e1 83 5c 08 34 f8 84 74 bd 69 3a 30 81 6f 17 60 b7 c4 42 c3 30 30 37 58 24 f0 e4 63 50 00 00 00 e0 3e e7 74 29 c5 c4 9b 38 09 de c6 d3 06 9f fd 65 57 fd bf b6 1d 65 38 4b 44 e0 23 9a be 24 e5 e6 8a 52 14 2a a4 5e 79 fe 10 55 c0 5a 2e 04 f4 8c 04 74 3c 17 e9 5d 2a 55 4d 14 36 05 e7 c9 31 98 d6 2e 01 a9 e9 55 92 cf e5 d9 d3 d3 06 e1 5a 40 00 00 00 b5 1c 63 4b 8c 8d f6 5e a6 a4 a0 e4 3e ac dd d5 d4 15 9c 37 6a be 4b 39 5e ca 2f bb 65 b6 96 56 28 eb e8 e4 f8 d6 94 de a5 55 0d 26 99 fb 2f fd f8 9f d3 b8 43 4e db d5 56 b1 c7 8b a3 17 34 61 (REG_BINARY) "CCB7AA85A8A10855C2FD402E545B1A05776C11256C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6d 95 9e c4 70 76 b6 05 c5 1c a0 38 1f 53 46 03 c1 87 03 f3 6f 0d 2e 62 b1 5a a3 f9 19 39 d9 bd 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 e5 a6 ac 94 e0 81 ff 2e ea f7 70 15 78 e5 80 af 19 a1 7d ba 7e a1 d6 89 aa ec 05 8c aa c0 41 d8 50 00 00 00 4d a2 2e d0 03 d9 26 33 f0 af 8a 7c d5 c8 5a 10 06 80 09 31 1b 82 fa 2f da 21 5d 9d 52 0a 00 42 3b 3a d8 8a 3a b8 d9 2f 48 73 12 0d 09 1f cb fe 34 e2 0f 5b 9e fc 3f 65 7c f7 7d f2 8b a2 e3 46 de 6f 36 1c f3 10 18 18 4b 31 c3 b4 be fb 94 6b 40 00 00 00 64 94 69 f0 87 75 13 5a 17 a4 5e d4 73 08 af 6c 76 eb cd f7 aa 00 3c 49 91 3d c5 98 83 1d d5 59 10 c5 9d 94 f3 0f aa b2 ec 09 71 cc a3 01 36 35 cd 7c 93 97 fb 57 80 cb d8 5e 00 43 b3 86 70 a6 (REG_BINARY) "D54147DB1C362F0995D2B42EA73FA59BA45E4737B1"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 7a 6f 32 2a 20 23 f8 a3 ec c2 08 66 2b 2f b6 0b ee dd 41 bb c0 4a ee 03 a5 49 5c 41 12 9c f6 7f 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 a3 61 83 a5 f6 2b 13 31 97 8a c1 11 ef ff 95 d7 4f fc 4d 48 d3 85 7e 96 d5 fc f4 b5 68 c7 e7 a0 50 00 00 00 a1 61 42 92 20 04 79 7e 9d 66 6b af ea b2 e7 1c d7 cc 2b ef 87 f8 da 0b 5a 5e 22 fe 8f 8b d3 79 6a 3d e2 14 26 3d 05 e9 43 c0 ac 33 45 f5 96 01 99 57 4b ff 80 cc 59 1d 46 f7 41 b4 6d 1a ea f5 f8 99 27 e9 33 27 f5 ad c1 44 22 ce c9 4d 70 b0 40 00 00 00 2c 1e b1 e0 00 4e 92 23 93 1e fa 83 1b b9 9f fe d4 0d 7a 7b 2d 9e 54 d5 5a b5 ff 89 c4 42 ba eb 26 fc 28 63 1f d0 1d db 91 dc de 4c 90 0a 97 35 94 61 a9 53 27 24 fd a3 a6 38 f5 3b 53 ba 42 c0 (REG_BINARY) "151C5B278B9543FD3F7C057F70B7CF8B2318C31EEF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 54 eb b9 e4 2c c5 1c f7 fb f2 47 c9 23 54 d0 e0 82 92 73 d8 ae a1 29 3a 25 32 17 a5 9c 13 2b 1f 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 84 e7 1f 87 44 77 5f 71 46 ca 0e d6 b2 90 9b 61 3b 4b 25 06 0a 61 ca 69 c4 86 df 93 cc 3c 5a 5e 40 01 00 00 15 28 9a ed 38 5b 19 d8 b2 d9 5f 3e a3 ac 59 c0 86 a1 a2 a9 0d 57 2b 76 8b f9 8f 88 82 fc 27 79 94 27 f4 72 86 61 e6 58 27 93 d2 3d 18 f2 33 6f 44 54 53 6f a5 3e fb 61 94 64 14 03 93 91 c0 0f 49 54 cc 57 c4 09 72 cf 61 29 5e fd 6d 3d 6d a8 08 b0 0b 01 c0 01 a7 55 a3 90 42 25 95 0f 3c 32 2e e7 ee e6 ef dc e9 2b 0e 79 40 6f e2 83 89 24 d8 9b ee 32 76 e3 44 f0 8e 5f d1 99 69 e0 69 07 1a a5 92 41 91 32 90 15 5f 16 65 2f a3 eb 11 c7 97 24 45 8e d8 5f f9 1e 80 86 c5 77 1f 41 78 5e c9 78 c1 dd db 2a 31 9b a3 c9 7d 2d fc 37 a7 a2 a2 a9 ff d3 04 fd c5 f7 3d 3d 9e 7f bd e6 54 c7 93 56 d8 (REG_BINARY) "C410D75D9FAB47D9ED29D3544E241F537DA1B3D93D"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 43 e6 cb 62 cf 7f 65 bb d6 56 7b 1f bc b1 dc 7b 13 ea 81 7c 09 77 77 ca 56 40 ff 22 0e e9 44 78 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 74 d8 aa 02 1a be 8f 14 57 9a 35 04 11 e2 93 0d 0f ab ad a6 21 72 35 4a 07 83 fb 1a 30 4c ab 3b 50 00 00 00 b4 67 80 28 fc 3c b1 dc 3a 59 d9 48 79 9d d6 a0 77 c4 6b e5 55 b2 3a 6d 06 e6 6c 8c 79 f0 2a c9 5e 2d 5d 33 ad b7 14 f0 92 45 17 3b f8 d8 b5 16 80 f4 c3 a2 df 48 5d 03 8c 01 82 21 30 45 8e 58 cd 3e 21 3c f3 b6 d8 a5 89 1e 18 e0 5e d1 5b e2 40 00 00 00 0e 0f 7e fe a3 55 f5 ae 2e 80 db 45 4a 5b a2 da 72 17 e4 4c 0e 9d fb f4 af b6 f5 5c 64 61 3a eb a2 81 e2 6a 0b 34 c7 7b 09 bc 52 b3 8d af ac 64 00 3f 94 c8 2d a9 ec f0 7c d0 d3 26 c4 13 42 23 (REG_BINARY) "02043DC0EE6FA30DA5C5225FA57DCD4F6DEFFF4CE0"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 a9 cc 21 dc ae b6 fe 02 8d d5 62 a1 aa 52 25 38 4c 4f 4b f9 ec 59 de 5e c7 2b 3b e6 d4 34 82 1d 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7b 21 d0 5a d6 c8 25 be 5a d3 4b 1e ae 41 75 45 b9 7b a6 20 02 ca 77 8e e8 9d 51 7d 79 f1 39 1f 60 00 00 00 3a 34 3f 65 e2 de 00 26 42 3c a3 32 37 94 12 b7 db 76 a3 c4 c2 63 f0 4c df 2d 9b 3b b1 68 33 d6 bf ca 2a 18 0c d1 00 44 fb 65 c0 8f 16 7a 0f 54 5a e6 83 b0 d3 8e 86 16 ed cc fa e4 18 6d 27 93 2d b1 6a eb 2a 38 73 4e 33 60 b4 d1 f8 fc 4f 8e a7 c7 59 06 52 e1 cd a5 f2 e7 db 77 8c 90 52 96 40 00 00 00 db 28 ea 44 58 3c 52 a0 d7 da d0 f7 42 29 4b 22 f6 c5 66 1a aa 8a b7 8f dd 3d 56 d2 b8 9d 15 99 ad af f1 44 9f f5 93 40 96 cc 86 8e f5 1f f5 ca 65 b6 58 5d c1 ff 2c ce 8a fa 6e 30 9d cc ff 3b (REG_BINARY) Quote
etavares Posted February 5, 2013 Posted February 5, 2013 Hi, Instead of running Step 3, replace that with this instruction: Step 3A: Download and save the attached file (Fixme.zip) and save it to your desktop. Double-click to open it. MOve fixme.reg inside that folder onto your desktop. Double-click fixme.reg to run it. Allow it to run if Windows asks you. It will ask you to merge the information in it to the registry. Let it do so. ATTACHED FILE: [ATTACH]964.vB5-legacyid=1862[/ATTACH] Step 3B: Click Start --> Computer and delete these folders: C:\Program Files (x86)\DailyBibleGuide C:\Program Files (x86)\HiYo C:\Program Files (x86)\Red Sky C:\Program Files (x86)\Protected Search Step 3C: Then, run an OTL quick Scan and post the resulting log in your reply. Continue with Step 4 in the previous instructions. WARNING: The attached registry fix is custom made for this user. Yours will be different. Use at your own risk.fixme.zip Quote etavares is a member of:Alliance of Security Analysis ProfessionalsUnified Network of Instructors and Trained Eliminators
debi239 Posted February 5, 2013 Author Posted February 5, 2013 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage1] "AE698CFE08B29271644798AD167B0FD791F9116BCB"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 f3 ae 35 65 6e 4e 50 1e 5c 6d b6 76 c1 41 08 29 e6 3b fc 9f 1f 9f c5 9c 26 66 6f 24 e7 85 dd dd 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 d3 03 ad ff 74 e6 ac 35 10 80 e9 39 5d 26 55 f0 bc ef 11 03 36 99 40 db 62 33 65 24 67 ea 81 b5 60 04 00 00 7b 44 ab a0 2d 0e 5c cb 78 a8 b3 88 4a 5b 1b ff 45 ab 8b c7 7c d2 a1 11 c7 3b 82 b1 e0 0a e7 6b 8a 08 50 84 db 02 98 50 8c b7 18 31 89 a9 35 94 32 c0 c6 f0 6e f9 07 61 53 a8 dd bc d0 b1 50 e4 0b 0a e8 9b b8 cf bf a3 25 0d c6 5d 0c 6a e6 c3 e8 4b 2e 37 97 eb 94 95 f5 0d dd b3 e1 b6 c7 48 62 72 d0 b4 20 a6 fd 68 6f 19 4d f6 d5 56 04 ab b5 04 d7 5a 46 d9 e4 fa a1 b4 a1 fe bf 00 4f 50 c2 0d ba eb 68 27 d8 f4 72 fc e6 7e eb 28 82 b6 52 53 67 84 0a 84 ab c0 b8 3d 19 3b 37 bf da 0b 3c 0f 23 bd ff c1 bb 84 0a 34 b7 88 1f 73 4e 36 c5 92 05 4b ce b0 f6 ce 4a c6 24 05 55 93 8a 42 fe d4 c8 (REG_BINARY) "DABBFD35854177D84D61FFF79D2BC7215D6470A506"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 7f 67 c4 e1 4e 16 f9 ae 7f b1 bd 4b 40 0e 8a 77 16 fe 17 d0 99 4f f3 a0 ea 3e 17 67 5a 00 5f b7 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7e e3 3f 12 00 17 86 79 73 0a 6e 89 fd 69 63 89 57 21 75 f2 4f 5f 77 26 ed 2d 12 09 6c e3 f2 79 10 02 00 00 01 6b 52 1f f2 94 9a 40 43 e1 70 35 a5 69 98 45 38 34 5e 87 48 9d c8 be c0 07 34 3a 6e 0e b3 13 eb ca a1 a4 d7 b8 07 cf bc 7d be 41 e4 76 d4 c0 5e cf f4 e7 a4 ad f0 09 cc 06 90 c4 04 4b be 85 49 3e e5 7f d3 33 df 03 a5 8f 60 f4 22 ab 72 f7 e5 cb 3f 33 09 23 5e fd fc 8b 11 82 3f dd e9 83 e1 fd 35 b0 ee ac 0c d7 52 2a b7 4b b1 65 fa cd 52 96 70 32 c4 e0 fd 5e 13 04 ad 8f b7 31 42 ab d2 d4 cb d2 2c 49 fa 99 3c 18 c2 9b df 20 28 bf f0 d2 01 62 56 9c 61 95 22 88 fd a3 09 d2 c5 dd f2 d7 12 a8 93 cb 48 33 04 48 07 e3 1c 99 ae 53 c6 d2 83 aa f5 f0 49 6d 4a 8c ee da 41 65 94 41 c8 64 75 (REG_BINARY) "924EB1974AFEBEB0FD6CC5317D3C6485375EB92C59"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 d7 b6 8b d0 11 5a b5 d2 a1 ce bd 9d 70 9a b4 db c4 4c 43 5a 83 0f 13 15 85 53 1d 3f 96 23 a3 21 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 78 4f f4 71 6f ec 6c aa 8e 1f 76 e6 dd 88 86 24 f3 e3 da 6d 55 18 ab ec 6a 9a 6f b0 57 26 9e 48 50 00 00 00 8c 28 52 59 ce d4 fe 1a 2c 58 c2 85 9a 68 8b 98 10 92 ef b1 7c 04 f6 28 2e c8 af b0 d5 89 b9 1c cd 1a 2f d8 6a fa d6 b3 bc eb ba 45 95 4d 35 37 7b 61 b5 84 42 ee ee c3 01 a1 29 85 78 11 bd 58 b4 40 76 ff 5b c6 f6 e8 97 82 72 2e d3 c4 98 03 40 00 00 00 07 56 9a 89 e0 0d 43 a5 87 62 8b 98 d9 6f 63 b3 f1 d5 a2 dd 20 6e 42 2f 73 66 a9 7a 64 72 80 55 a7 f9 21 8c 26 7a 74 e8 11 39 d9 1d 18 a7 d8 5b 0b ec 6e 99 a1 b8 9c a6 e9 28 b8 24 93 d4 fa 96 (REG_BINARY) "25D63977B5D48876833346C856116F99872EDE978F"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 20 d6 af fd 2c 4a 0a d3 cf 6c 74 58 cf f7 9a 6b 4a 63 62 71 82 59 1c a6 6f 0e fc aa a0 e3 c8 37 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 cf 02 69 d2 f7 a6 99 b6 44 ec f6 86 44 2b a1 c3 0d 4d b4 3b bd bd 9f dc ac 1a 3a 27 1a 86 98 0b 60 00 00 00 52 4e 00 76 f1 66 69 f0 c3 09 a0 cb 19 dc c5 a3 cf 61 00 50 83 ce 36 06 2a af 8a 89 b4 26 55 1d 0d 47 fb c8 f0 b2 94 e3 c9 50 21 53 37 ab c9 51 c4 3b 6e be e0 0c 5e 0a a4 e5 9b e1 eb 92 bb 62 0d 9b 02 0b ad a0 b0 e6 73 88 b1 c8 17 5f 96 cd dc 3f 7b 0c 79 dc 8f 99 2f 32 7b a6 d7 59 db 5e 40 00 00 00 46 32 bc 74 da a0 27 e0 1c 5c 0c 6b 44 fb fc c8 11 56 3a e4 7a de 29 48 5c ea 82 a9 95 e3 4a c8 12 51 64 11 eb ef 66 b0 ca 03 71 ed 2f 14 1a 00 65 28 d5 98 0f e9 01 46 38 d4 c6 12 d1 37 50 69 (REG_BINARY) "1C6C20FFA0A8BC6A180DD8A5004DA830FB5EC84D4A"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 f4 e0 1b 76 60 2b 9b 50 d6 19 2b 9d ee 91 ff 1c 89 98 81 f9 28 3e 36 40 dc c2 a9 47 ba 96 8e cb 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ac d1 37 bd 37 5f 4a 2a ba d0 a1 9f 6b 25 2a 3a 50 58 27 ad e9 cd 60 40 97 ae 4b 97 11 22 2d bd b0 00 00 00 94 05 5d 37 89 bf da 04 65 61 5c 21 f5 51 5e 67 1f 12 e7 99 be f7 14 c1 f8 2a b9 96 c6 1b 19 3f 9e 45 22 56 46 d8 79 e0 38 bb 9b f5 be 5d 83 b8 e0 8d ec 8d aa 31 a0 91 7f 98 a0 bd 57 8d ae f6 ca 2c 1e ea 5b 3a 65 4f b0 e5 6d b0 0a e9 5f 5f 09 ae 30 e2 d3 4c a3 3e 71 88 d4 1d fa 0f 36 80 5e ae 13 b8 2c bb 6e 5c de e1 da 6c 92 58 fd 09 5a 26 3b 79 be 09 ad a8 de 2a af fe 97 a6 bc 17 b0 99 9a c0 c8 68 66 36 c3 65 63 65 b1 8d d8 23 70 5e f3 23 ea 57 59 fd 04 19 31 f4 5d ed 46 19 8e 99 e6 d4 ea c5 08 61 75 27 9f be 7d d2 a0 29 40 00 00 00 75 cc a6 81 81 4d 24 53 3d 1c ca 5b 07 f9 3f (REG_BINARY) "C6FB044EC2BD401521D6B1082276415638196D8004"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 1f 53 91 f3 a8 a1 10 b2 8d 34 b8 b5 04 11 27 3c 02 83 39 1f 3b d5 04 ce fa a2 69 38 90 8c a1 33 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 31 25 0f 15 9a 06 ab 14 23 7f d5 c3 bf 53 0c 02 ea 66 88 4b e7 bc 2a 9b 30 e0 8d 60 6d fb b1 19 c0 0b 00 00 2b 36 2b 04 fe b4 88 2f a4 a8 1b 9b 16 22 94 71 c8 6c 33 70 78 d3 4b 12 93 ea 51 d2 0b 57 f4 3e d2 6f ec 08 7b 02 cf 37 45 08 79 95 9b b4 f8 ab f6 d7 2e 90 64 13 78 36 68 66 a5 f7 33 c9 ad 8c d3 35 12 d2 d2 e1 78 f4 e9 f7 52 e0 30 87 1e af 1b c1 09 a9 c2 87 83 9c aa 16 4b bf 8c 6d 6f 41 2a 19 40 b1 63 6b 97 31 ed ba 68 38 70 c7 75 fb 24 fa 5d fc 90 8d 74 03 de e5 2d cc 22 4c 81 35 14 19 ac 75 f1 58 ec 3d 83 44 5a 3b d1 1c e0 58 3a ee e2 57 fc 60 79 1a b2 b4 4b 58 1c 82 a6 49 05 55 63 68 33 be 73 88 5e 46 23 10 64 0f 6f 36 e9 ed 33 05 57 59 7a 31 2b e0 1f 99 34 55 2c 22 91 be 2b (REG_BINARY) "096420CE1C9A31839715B788EF20650AE3D02A535E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ca 7d 60 bf 7f d2 1d 42 b3 52 59 07 75 e1 a7 c5 8a 6b 71 4b 15 a1 b1 3a 52 11 8d f3 dc 5a 9c 04 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 c6 47 b2 03 4a 52 c1 6e d5 04 7c 40 ed b9 df b8 af 7f 0d 5e 67 59 7a ce f6 f4 64 b2 81 61 83 fd 80 00 00 00 65 4d c7 bf 4c 9f 74 fc cc 23 02 5a 2a 5d 1d e1 01 dd f5 46 a3 55 a7 a8 31 a9 92 cf ba 04 32 ee 48 c8 ab c8 ec a5 e2 20 e7 2e 24 84 59 b6 8f a0 67 6e 0e 45 2d cd 81 f7 96 f3 21 ec 10 c1 3f 24 79 03 7c 42 b5 05 df 32 bf ea 25 18 30 5a da ee 34 28 e8 63 58 c1 ce 9c e5 c9 24 a2 28 6c 2f 94 da 75 c3 98 aa 9c 49 5c 58 c9 04 a1 2f 6e 9c a9 d4 c0 01 0f 4d 1b ef 9d e9 23 bc 14 21 6a b9 86 40 00 00 00 d7 13 a1 c8 95 07 2c e5 14 6c 05 88 2c 2e 4f fe 1d a8 a2 ee fc 3f c6 33 d9 11 7b a2 83 49 3d 23 9f fb 70 b0 08 ea 2f da 95 4b eb 0d d4 fc 90 79 f8 41 c4 b7 3d de 0e a4 bb d4 56 95 a1 b4 2f (REG_BINARY) "4D13E0440141F4A946A15AD5D799B3182A6A7D9156"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 1f 07 7f e1 d2 59 d8 29 95 4a 70 a0 21 ee 16 26 63 ab f9 f0 eb 58 d2 56 27 3a 5a 97 10 ed 63 08 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ea cc 02 ed 7b 68 4c ca 0f a4 9b 6d 5f fc 41 31 eb 72 cf de 04 e4 eb f1 51 fa 46 fd ee 86 3d 09 80 00 00 00 ad 92 56 ca f3 b2 b4 32 98 3d b5 de 00 b7 b1 e1 4f 6f 3b 22 75 42 e5 73 cb ba da f6 52 16 0d 9b 0b ff 2d ae ab b7 35 6a de 68 ef 4e 4d 10 70 e6 4b 8e c4 72 96 db ef f7 9a 61 39 21 27 7f 75 6e 34 bd 6a 79 49 e2 dc 7f 89 a0 37 0b d0 06 50 52 93 54 2d 98 dc c4 3d 68 c4 a0 f9 fe 44 b8 e5 f3 7e 33 f6 f4 71 ed 4d b0 96 a5 c3 cd 3b 95 32 ce 2e 3d 0a 06 41 51 29 92 9e 70 17 86 64 cb 49 03 40 00 00 00 5d ce c3 4b 2c fc c9 24 81 fb d8 d9 9c e5 a7 cb 95 b6 d5 04 b7 db c0 73 0c 35 bf 9b 88 5e c5 6c b8 2d ce 85 ce 2b 1a 69 87 1e 2c 2c ed 5e 6a f7 fc eb 9b 1e b9 a2 dc f9 95 9c 8b 74 0d a3 35 (REG_BINARY) "6E93C85D71708197754FB5CA3C86A5FB920D941108"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 fa a7 1f 65 44 fb 3d 18 b6 60 43 e5 92 28 7c b1 a4 b3 4d 2f 78 59 77 18 aa 3f 06 8b d9 05 5d 8a 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 fb 76 09 58 ef 9f 72 51 7d b5 22 a4 f7 2d 2d 4b 87 2f c4 21 af d7 fe 3f f1 84 a2 79 44 e8 6a 88 20 01 00 00 95 a3 7c 64 54 23 04 ab ed 0f f7 7c 15 84 d2 7b e6 52 4d e6 56 f7 27 ed 1f 29 da ea 99 83 e1 fc 05 f1 b2 9c 1f a1 00 c2 aa 18 33 de 47 c4 c8 21 6b 10 ad 0e 9c 5c f9 a0 f5 e6 e1 34 90 88 bd a4 71 d6 07 43 38 4a fe 11 24 13 0e 39 ba dc fe 37 d9 2b 0f 00 a9 d6 13 f8 76 80 f1 24 5d 3e f8 68 48 7f b1 7a 81 4c 1a 6d 1a 0f 1f 0c 9f 3d a0 aa ca 2c 7d 35 08 c1 4b c0 dd f2 e6 fe 97 91 51 bd 70 0b 8a d7 d2 10 fd f5 66 58 b6 f1 ae 34 b6 10 3e 55 cc 50 c4 5a 03 d8 83 39 e7 dc 7a a9 29 e8 4b 30 e4 2b 17 a5 b0 86 76 43 ff e9 6b 83 34 bc 51 d6 e3 b4 8f ed 05 9f 5f dc 5a 51 45 62 3d 10 d5 0c 0f (REG_BINARY) "A7301AB81D7D809D725CB2004475E966776980AAF2"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 7d f0 bc 5c 1d ce 57 41 b2 1b 5d c0 56 9d a6 96 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 59 cd 88 b0 00 35 82 90 84 1a d9 31 93 55 a7 ee 71 1f 51 b3 b4 12 a0 d2 09 93 7e 55 32 da 34 6e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 b3 2e 23 20 18 e7 08 05 f8 96 d2 59 c4 ac 72 6f e3 96 a4 6c 49 38 8e 7c df df d7 2a 3e 8e b3 a9 c0 01 00 00 de 77 b8 05 1d 6f 50 d7 b9 4a 84 7b c0 f1 b4 97 cd 76 96 e1 6a 51 d1 eb 95 98 b2 be ef 20 3a c6 18 6d 6c 4a 10 d1 3d 45 74 82 e4 81 fc c9 e0 1b 65 cb ab 9c d7 0d 28 20 20 f8 f9 43 8b 0e 1b 13 05 ad dc 8f 2b e8 8c f1 4d 77 09 f0 86 d3 c6 60 94 63 87 97 b2 b3 86 57 34 00 ce 70 af 9c 9c b2 a7 ba fb 04 af c0 53 cc 4d 3a dc 93 f2 09 7c 9b c5 56 6c cc 8f d3 ef 64 c6 7a 4a a4 d4 10 e7 c6 67 c4 d0 80 06 05 88 b3 a1 24 8f 90 68 d2 a6 4e 8c cb 42 e0 54 7a 7e d3 80 59 9f 94 4b 61 f5 a8 23 16 01 90 62 a1 da 82 c8 ff 1f f5 da 81 01 97 fe 81 59 a6 ab 77 a9 f1 b2 4d f7 ee a7 d0 1b e6 49 27 7c (REG_BINARY) "E4C8031156725AE776172EF7EA1830E573F904FDFF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 fe 70 1d 86 73 0d bb 58 63 11 6c 3e a9 33 c9 38 19 77 38 3f b5 21 ea f2 09 30 4f 53 88 a8 35 51 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 0d b6 6a 44 f0 b7 69 03 86 6e 9c 89 ca 57 2d 29 dd 40 12 1e 51 da dd b8 a0 5c 91 5b 25 59 c6 45 50 00 00 00 05 2c 77 af a3 94 08 c0 39 21 28 8d 55 0f 91 9d b5 89 2e c5 c5 73 97 16 c2 f1 11 60 fb d8 5f 72 33 0e f1 f7 d7 21 c0 26 f8 89 62 c3 02 15 bf 6a f1 36 f3 74 49 1e 0c 9c 54 a9 fb 32 d0 b9 a3 54 53 9c 93 26 db e6 5f 15 14 b9 14 df d8 15 bc f3 40 00 00 00 89 84 e2 f8 d4 6c cc f3 d1 56 9b f2 60 ee 85 d8 d5 6d cb 93 cc 50 cd 91 4d 58 c7 22 50 8b 1b 99 ec e3 8a 97 47 79 6a 5c d1 e2 cf 6a bd 1e 66 de 5a 19 3d 4c 91 47 f0 2d 64 08 b2 ef dd 02 0b 34 (REG_BINARY) "37ADB64C2CDA898AC56C464BD00BAFF748AC1E267A"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 64 d4 61 ae 2a d5 2c 16 e7 b9 63 a0 d0 eb 6b 7d a5 28 b4 04 b6 a4 85 75 68 cb e0 99 ef 15 dd 59 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 61 12 cc 28 ff e3 b0 06 16 78 f7 98 7d df 63 b4 48 1c 0b 69 93 45 0f 8c 06 f0 59 db 51 2b b0 62 60 00 00 00 b4 5b 75 0d 1f 34 5b 63 31 2e 37 96 b5 94 88 ab e0 6b 3b 42 d9 e9 70 eb d6 a3 26 05 f7 40 cc 3f 26 15 fa af fe b2 af 71 94 b1 4c ce 1b fa f0 7b c1 1d d3 6c b8 a7 c7 59 ee e1 9f 77 bf c6 10 ac 2e 36 d9 bb cd 7a ca f3 87 8d 66 87 98 33 42 3a c5 fd 48 e0 c9 9d 98 64 dd 09 17 66 17 79 d6 ff 40 00 00 00 11 6b 7b c9 33 b6 07 76 ac d9 70 37 a7 aa 18 ef ca 28 72 eb 19 36 b6 b9 66 d1 1f 82 45 67 2c 06 18 24 0f ba 15 0f 95 f1 b8 6a 2a 7e 6d a9 18 0d 2f 33 15 0c d5 c1 df e0 a1 8d 75 d2 70 dc ad 2f (REG_BINARY) "BEE9113CBB15337F699571D41E7D887DDF37055CD0"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 2a 37 ee 95 a5 70 b0 28 cf 2c 6d 57 20 bb 31 ac c1 27 36 08 25 bc ad 71 6b 02 c8 56 ea 00 6a ac 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 84 eb 15 80 a4 32 ea 9c 61 1a cc 33 90 8a a5 d2 b9 ac 9c ad 1d 71 34 f4 cf 2f ad e1 35 53 b6 55 50 00 00 00 ec e5 75 9d af 33 02 e4 e2 6d 18 08 4b a6 d3 ce 5f 65 d5 7e 91 2a fd e2 db 65 26 dd b9 db b6 01 47 0a eb 1f aa f1 3e 45 9c e1 2e d7 7e ea ca 63 71 d1 11 2a 3c f1 bb 02 87 a1 44 48 5f 7a a8 43 6b 61 ab d0 71 a0 47 00 68 c3 20 9b c3 53 73 49 40 00 00 00 23 36 9f ac ea f2 bc 32 35 34 86 1a 13 de 5e a9 37 6b 87 74 77 82 a3 09 7d cd fd e5 a5 85 5a d2 f9 0e 22 bb 29 7a 21 0f d7 81 ea 27 75 43 50 7d 43 b6 3c 47 df b5 97 51 29 9f a8 ca 55 37 59 6a (REG_BINARY) "F10FD9E6D178A4A9BB12FCD905C528678472F70F4C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 47 33 e0 71 86 d2 ab 0e c1 91 8f ab 1b 34 66 bc 97 76 9b c1 65 5d eb d3 82 2a 0d cd f1 e2 52 bf 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4b 93 a0 12 a1 67 b4 a3 86 66 0d 93 40 ab 84 aa 1d ab 20 37 88 54 20 5c 62 00 43 b5 79 bc d8 7d 50 00 00 00 0c e1 b0 57 ad fd 20 c4 07 2f 38 41 9d ba 71 25 38 33 10 c4 49 1b 4b ce a7 6a 79 e7 aa 3f 65 67 67 13 c7 01 ad 9e 0f b9 c1 c5 9a d2 c1 9b ed e2 30 33 ac d0 33 3a c9 95 70 7b 65 9b d2 3b 0f 42 42 3b e1 2d 24 e4 8b 30 ed d6 89 47 79 04 6a a6 40 00 00 00 3b ab 9a 99 8a 71 81 98 6f 7b 59 28 e9 e2 89 00 89 89 dd 8d a8 9c 74 ab 1d 3b 7e 90 c3 c9 d8 d0 16 bf 43 09 e0 dd 67 d4 78 8c 3d 22 98 0c ba 37 51 ca a9 66 3c 41 bb b3 7b 89 62 c5 9b 89 09 1d (REG_BINARY) "CCE7D6897E34A3152B11E238F315AC9BE45C397610"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 1f 56 92 aa ea 83 a9 d2 00 a6 c8 57 9a 86 c9 83 a4 5f 67 eb ae 01 27 67 d9 fd 3e a4 65 c4 b2 6a 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 2d 2b 3b 0b 5e 37 06 ba a7 71 9b b9 57 ec 3e 21 45 67 8b 92 d8 58 fc 7a bf 1a 2b c8 dd 1f 32 73 40 00 00 00 c6 3d 0a 4c 82 1a 9a ff 81 12 0f 6c 0e ee 8c b0 6f f6 b3 7e 1a 4b b7 68 46 e7 0f 25 c2 1d 8b a4 47 d4 55 4e 76 a5 e1 47 53 9f ee 01 49 7a 67 1a e6 fe fc 4f 85 67 2f a0 c6 20 f9 39 95 98 e0 20 40 00 00 00 58 f8 a9 ff ae 3e 81 71 ff 8a 60 16 38 d7 b8 9c fe 11 a4 05 80 06 3d b8 27 03 f6 ee 46 36 c1 18 b3 51 0b 61 4c 13 d8 1d 00 3b 77 f9 08 e4 bb f5 0e 5d b6 e6 10 d4 93 8f 2a 20 f6 a0 58 bc 4e 67 (REG_BINARY) "DD043914DD02231ABE7740D90D427B313E31FDACAB"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 66 36 3a 18 2d aa 32 a7 5e 27 c9 84 b5 71 ab 8d 2c 49 54 e4 8f d0 d9 38 63 f1 1d 8c 86 7a b1 60 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 43 e7 13 95 c2 32 f8 02 ba a3 03 7e 40 73 a5 44 18 6d 31 a1 c5 d1 56 b1 5e 2f ae 99 16 87 e1 d8 50 00 00 00 4b ac ea 98 30 72 de 10 15 47 a1 b8 58 b6 33 07 7b 3e 13 ef da da c6 55 1a fe cc a0 6f 3d e8 0d 17 d4 8e b5 ee 9c 73 3b 01 13 da e8 e4 09 ac 73 89 be 42 7d 73 fd c2 62 d7 54 0a 57 fb ca 7d 20 f7 60 d4 f6 b0 cc cf ca 03 44 c2 65 a5 d7 d9 19 40 00 00 00 c4 61 63 5f 20 ca 54 8d 75 ac c4 27 6d d3 92 b3 61 9f f3 97 51 d2 fb 4f 51 57 a2 c6 60 d0 11 6e 4b 84 5b 09 7a 0a 69 c8 56 02 ab c9 cf 4d 59 d5 d9 5f dc 49 f1 c8 5e 03 c4 17 6d 93 21 12 c7 ba (REG_BINARY) "72B9F7879945CD82128EA98C1A81E14CF92DF9DC6E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 18 df ed ef 5b 09 35 b7 82 de b3 c4 e3 a4 30 c7 e2 6c a1 60 e4 06 19 64 6b 1a 19 c9 ac 43 48 b4 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 af d7 95 f6 d6 cf c6 c7 2f c9 3e 2c 34 14 da d9 65 35 aa db a4 93 b7 98 ee b2 05 65 f5 5e f4 17 40 00 00 00 7d de 9c 23 f2 c6 71 f6 56 67 5e 2f 30 66 50 8c 37 bc 0f d3 c6 54 49 2f 52 5a 60 3f 03 79 5e 75 d4 fb 95 c3 0e 31 aa e7 6e 89 e0 b3 d7 41 0e 3b 06 c8 2e 1e 68 2c 52 77 2b 8d af f2 95 cc 61 21 40 00 00 00 4e 71 9c 32 48 62 b8 17 0b f8 3e 74 93 f4 38 ad ce 83 6b dc a1 96 43 dd 8a fa 73 b2 74 36 5d bf 05 9f 60 3f b5 a9 31 55 30 b8 ab 9e 72 58 8f 83 f8 3a a1 4c 4f f2 9b 2d 8c b7 f2 c2 a6 91 f0 18 (REG_BINARY) "67027095D7C972F0846B26C33A9F1F2B488135D23B"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3e 1a 63 c6 55 b1 57 53 f6 50 fe d1 af 91 06 84 ca ad 0f 16 04 5f f7 38 99 b9 18 52 4e ef 5b 22 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 db 27 4d 42 4c 91 04 58 20 31 72 de 34 ee 49 17 b6 36 98 5e 39 c4 fb 7a 67 3d a0 8b 61 c6 76 a0 40 00 00 00 8d ea 9c f5 53 6b 4e 4b c5 02 28 71 80 2e 7b b1 06 f8 25 32 a7 4c 64 f4 f2 16 df 50 48 74 b6 f7 46 95 1c f2 28 5b 5e c5 5f 5c f8 a7 8e cd 14 e9 cf b3 8e 17 cc 72 8c 4f 15 25 b6 51 90 77 d5 0f 40 00 00 00 72 d3 cb c8 33 be e9 a9 0a ef e7 26 45 e3 86 22 5e 7c 45 19 10 c4 c6 22 5a fa db ad 9a fa ca 50 4a d9 d2 db 02 df d8 60 73 67 64 ca 63 4d 1a 84 0b 6e 32 22 ce a3 34 e3 8b 87 b3 6a 61 c4 f9 23 (REG_BINARY) "4A08BFF993FEB540429405C15C0AB12E10B9AF3E27"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 40 b9 2a 27 30 70 c1 95 4b e2 2d 95 db 5a ab 78 51 91 ec d2 91 97 07 35 65 2b f1 ad a7 2d ce d1 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 3a 46 87 63 96 e7 f6 7e 3b 22 7c 7b 4a 27 ad e9 db cc c7 4f 46 c9 ca a9 79 82 4b bd 61 42 76 77 40 00 00 00 13 fb 12 ff 9f aa a3 d2 d2 4c 74 09 79 37 6f dc 6c 7b ac ca eb a0 9f 2d 5c c2 31 6d 73 36 c1 48 74 b5 21 22 35 db 71 28 f9 da 1a dc 53 a8 32 4b 3c c4 af ce 99 7a 1e 93 97 09 b0 d0 a5 8c 17 f4 40 00 00 00 9f f9 cc 31 a4 c9 66 00 56 2f 1a 43 b6 82 66 09 03 b3 88 8a a5 29 1f a3 0d 3f ac 86 aa c9 4e 8d 89 b6 86 c7 75 b1 f7 0d 74 59 c0 31 9f 36 7b 73 5b 0e 7c 95 27 44 d7 d6 ed eb 67 9f 31 a7 c4 00 (REG_BINARY) "48AFA9E93B9296921462981A85E8595849AB1F15EC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ef 56 64 96 37 ac b8 36 b0 af f9 77 50 3d 6f c2 8f d1 09 7e 96 c9 a5 2c 5b d4 5b c2 2e de c6 6f 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 75 83 c9 88 63 0c 4e f0 59 50 d2 be 95 03 c9 76 dc bc d1 5b af 9c b7 e5 f7 8b ca 9b a3 bc 8b b0 40 00 00 00 7f c7 e2 2f a8 cc 79 42 8e e1 33 f3 b5 bd 92 e0 70 81 d2 4e 28 42 45 1b ea 21 e4 eb b7 01 ee 3f 9d 45 e7 57 9c f0 91 cb b2 f6 77 d8 e8 27 62 28 32 8e 72 7b be 77 ae 81 eb 10 85 70 fb 2b 82 ed 40 00 00 00 ea e5 45 c8 fc 68 c4 11 1b 53 6a 20 68 e6 62 f8 be 15 53 ff bc 88 c8 bd 17 a4 d8 4c d1 01 92 ba 5f cd 4d 39 9e d3 1c 5e 0b 02 23 6d 63 d5 f2 2a d9 bc ef 27 32 a6 83 69 ee 51 b6 90 80 3d 2e 0d (REG_BINARY) "D3C90BA40F9C3A2AF77BBF0C5C249A980BDF742DD4"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 eb a9 e2 1e b0 11 45 44 19 fb 5a be 75 d6 de 97 08 30 27 25 43 02 da 38 ac 0e b6 b4 1c ee 73 c5 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7c cf fe a6 58 32 24 26 08 8c 13 69 6b fa 54 a0 99 44 a1 24 70 23 56 70 ca 7a 0f 56 40 78 aa bc 60 00 00 00 bc 60 0d d8 97 40 ad 85 d1 e8 70 9d 85 e1 dc 83 6d 53 f0 d1 1f bf 80 f5 72 66 a8 97 3e 21 41 87 25 25 9f 00 29 1c 20 60 cf 42 f4 49 11 36 56 b9 bc 38 46 1c 02 a8 59 00 d6 1c c7 56 27 fa dd 38 72 01 33 99 d4 88 ff f5 1e 99 50 c8 99 02 58 b8 51 22 2d cd 1c 80 0b db e2 62 49 7e 04 71 e4 ea 40 00 00 00 1e 04 ea d6 63 cd df 99 89 30 53 80 3d 8d 45 33 82 1b f8 67 fa 93 84 1c 2b 1f 13 dd 76 c5 47 55 40 a2 3d 01 e5 2b 3f 02 c3 ea 30 ba db d7 ab d7 e9 fa 14 06 c6 69 2a 98 83 54 e4 be 72 40 47 06 (REG_BINARY) "A85DB3B00F8E4C2E6C71ADF6B7791E6E6A6B664238"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 08 54 c0 01 7b 76 b0 a0 d0 6a 4a 0a 35 13 23 fb 83 a8 c8 7f db 5c ba 07 f8 a0 df 08 26 92 c7 7c 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 a1 ea 79 74 86 44 60 13 92 f6 77 92 cc 2c a5 45 d3 99 4a 2b c5 9f 84 ab cb 87 d1 9c b5 2b a6 41 90 00 00 00 da 17 d4 c9 a2 5b ff a9 47 79 63 9f 87 df 8d ac 08 38 19 d1 bb 34 8c 8e 8d 89 84 fd 8a e8 71 b5 b9 c7 55 3b 73 7e 8e 73 d2 46 99 64 41 7f 3b 8e ea 6f 0f e1 e9 68 7f 6f f7 3a a4 02 47 4c 80 96 50 d4 2f 4f aa 89 8d 46 c8 34 4e e7 ba b3 56 28 76 fc 61 8a 3a 72 1c 3c 4a 76 e2 30 7f 8a a9 94 11 c6 03 c2 8f b4 d5 b6 ad af bb 04 53 d4 62 b1 11 e6 ee dc 6d b0 77 d7 5a d5 a8 3e 37 70 ab cf cf 8a 73 33 d5 da 3e 53 cc d0 d2 a2 7d a6 b3 80 40 00 00 00 fa d2 03 5e 05 45 97 c2 f2 19 40 32 53 f7 a1 3f 07 b6 02 f8 69 e8 97 5e df b5 23 2f f8 0d 8b c4 3d b1 45 58 50 b5 a2 e3 db bf e6 cf a6 f6 55 (REG_BINARY) "280960C8406F5B54472F854047DC521120CFA69BA8"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 10 4f b5 79 f3 76 0a 6b cc 4d 22 c7 f3 31 95 1e 20 5c 2a a6 8b 71 85 15 8f 06 ea ed 67 13 8a 18 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ad 7b a0 47 83 80 54 1e cf 0b 0a 39 88 6f f5 83 f0 a3 c0 f9 15 c5 0a a3 4c b6 bc 28 13 d1 b0 ec b0 00 00 00 26 1f d0 1e 9d e5 0d 76 30 40 1e 12 09 81 ff a6 b0 d0 f7 8a f0 68 5e b6 5f db 18 23 76 37 36 e8 e5 ad cc 32 25 23 02 1f 13 5b 7c 30 9b 2c 7f 65 c1 4f 60 a8 d3 b0 4e 55 10 1e 15 f5 1d 85 2b e8 12 9f ee 43 6e 85 0a 3c ff 1d 4f b0 fc fc ae 8e 98 2d da cf 60 66 b4 30 a4 76 02 31 54 b6 51 40 6e f9 ce de 9c b2 ed 92 58 24 3e db 3b 68 7c 87 3e 53 e1 66 fe 7e 62 59 79 49 43 6c 4d 92 63 24 d7 73 e5 a1 50 2f c0 a9 9e ca 6d 82 b1 c2 99 f9 b4 af e7 ec d7 8a 1b 2b ce 8b 3d af ca 03 21 9c 06 b4 15 09 c0 2b c5 e7 f4 c4 65 cb d4 9c 02 27 40 00 00 00 10 4d 30 17 39 3d eb 9c 9f a3 69 c1 98 ac 2e (REG_BINARY) "0BA59E6EA4F2E8C97BA317DBCEAE25A2847A942B13"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 e8 b5 77 77 e6 a1 bf f3 b4 ce db f7 04 b3 5c 94 7c 6b 72 b1 50 29 df 3a 9e 17 b8 df 27 aa ed 51 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4f bc b7 7d 44 37 bc 6c 85 9c 99 0c e5 58 02 0c c8 f7 25 7f 25 9b 8e 1c d2 c2 2d 07 fc ec b4 9b 50 00 00 00 f0 fb 56 a8 72 c2 92 d7 f4 5d b3 f3 20 f5 68 e1 da f4 c1 de 3f 59 d4 c8 77 2c 55 30 d7 ea 7c c4 7d 4a 29 ad ca 25 c7 c6 51 d5 3f 49 49 f5 83 b1 f3 66 2d e5 38 d1 ff 04 f0 ab 61 37 35 ef d0 d1 55 7b da 68 56 14 7b a8 8c 48 96 33 08 cf 82 27 40 00 00 00 f5 91 4a 97 36 fe d4 55 7d 03 ce 15 51 5d ea da 4a ee 2f 9b 86 84 85 f1 22 39 97 d2 ef 45 af ea fd bc 45 08 ba f6 0b 47 f0 53 5e ad 53 e1 11 72 d9 a0 08 6c 59 c7 a1 14 78 0b 74 b0 99 c3 00 88 (REG_BINARY) "710D91E52989D9063F237E934DFB5B9A1208775B21"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 22 60 b9 4c 9b af 66 62 44 c3 b6 ab a3 02 0d 6b c2 aa 73 30 f2 92 00 0a 14 f9 c2 40 bd 6e 47 28 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 5c b2 ac fc da 74 cd 3e f7 69 cb aa b7 fb 62 d1 6b 2f 90 74 9c bd 91 83 e7 3d d9 34 ac 66 36 14 60 00 00 00 55 8b 94 94 b6 5e 0a 21 34 5b 25 08 9b e9 d7 34 ff 3a d6 5f cb 5d 08 fd d6 64 93 36 b2 64 0d d9 46 9b ae 74 34 50 96 01 e1 46 d4 42 98 ec ad 51 bc d2 ab 24 60 9d da 67 a3 ef d7 ad 9c 84 0c 5f a3 79 6a f1 41 9b dc b5 76 07 15 75 de 42 95 d0 65 af 0f 5c ac 8e 85 45 02 38 eb 6b d9 a3 dc 32 40 00 00 00 91 6d 3e c0 8e f6 fd d7 bf 87 54 06 3a 8a 60 fc 52 75 57 8f fd a0 45 b9 9c b3 4e 57 e1 19 6f 18 a1 5b 9e 47 16 99 81 94 ac e6 2d b4 55 fa 77 60 61 3b 22 b7 f1 ea 7d 24 70 12 df d8 66 48 be 44 (REG_BINARY) "3EECBED6028B282FE1E7A5299DE569434BAEE41558"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6b 04 4e 5b 4a 43 83 39 91 65 9c 50 55 6e 98 dd b5 94 0d 97 28 04 71 ce ec bc 75 55 0f e2 51 80 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 34 a2 f1 ce 42 d3 31 be 9f c9 9c 9c 5e 25 84 92 77 fa 97 af d9 67 be 17 b5 a8 13 37 6f ac 81 51 50 00 00 00 8f 1c 19 9d a9 d9 60 45 d0 c0 ba e4 05 e6 9f 85 f2 b2 d2 2b 22 d0 62 4c 8b 60 f3 47 0e f4 5b 6e e7 9c ea b5 08 1b 38 7a d3 ec 47 d6 66 ed 90 86 9c 8a 21 ee 86 74 4f 58 d2 15 2e d8 bc 39 bb 0e fc 13 df 36 0a 61 8d ff 0a 9a 52 e5 72 d3 a8 f2 40 00 00 00 bc 3b 6e 59 c3 f2 11 21 81 95 e7 fa d3 b4 4e 73 96 a9 93 7b 9b fd c0 11 4f b2 db e0 42 8a d5 c2 eb 4a 7b 98 bb f9 79 c2 b2 c1 ff d0 95 87 a3 97 16 e2 a7 6d 8e 19 ca b6 3b 72 8c 86 84 8c 5f 82 (REG_BINARY) "047B0A999BE29C6465483501EA4893E81978A395F8"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 15 53 bd 12 ac d2 3d 07 46 5b cf f1 54 04 cc 59 d9 fc ad b0 70 e0 82 8d 71 c9 cf 07 a6 84 26 a4 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4a 4c 0e 66 c4 aa 74 be 6e 42 17 9a 5c de 83 28 46 dc 76 4f 0a ab f8 b8 6a 8c 5c 01 4a 40 1e 92 50 00 00 00 c3 d1 e8 74 af a4 c0 e8 56 9f f6 6d 11 30 7b 35 18 89 b2 9b 79 d7 c8 c2 74 db 94 e3 25 4a a2 df 81 92 84 b5 71 b1 2c bd 51 29 66 11 b2 22 98 ff 9d a2 b3 5a fd ce d2 f0 99 46 de a5 0f ca 27 46 15 b3 12 b2 d0 c8 5e 87 25 bc e9 30 5d 3f c8 36 40 00 00 00 08 f8 0d ee de eb fb ef 2b 3c 12 98 2b cc f6 fc 11 55 64 e8 9a 86 28 15 bd 91 3d 61 a1 0c d8 11 dc a4 e3 42 c9 24 fc 0d 32 36 04 83 62 bb e1 08 67 3d fb 8e 1c 48 99 b2 22 26 7d 24 0f 64 55 26 (REG_BINARY) "18F22D7CD3BBAEF4D6D1C9BF29FE5EC3BFB0404D56"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 71 e6 85 24 92 59 6e 5a 44 0d 88 d9 8c 8d a9 dc 68 dc ae 56 b2 95 34 ce 86 a0 01 45 3c 53 94 c8 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 8f 91 86 55 12 0f 98 02 68 37 17 09 f3 da 1e a1 a9 d4 78 c2 5c ab c0 ed 76 9c ed 28 0c a4 60 60 50 00 00 00 fc 99 9d b2 42 c5 09 a3 fd 56 33 9d e1 c8 3f b7 13 1b d0 50 3a fb f2 07 a2 ba f9 eb be bb fd cc ab 17 c9 46 b2 31 78 ef 10 e0 60 dd b7 bb e3 9d 70 47 17 e6 58 77 df 6e 7c b0 d2 66 85 a8 41 e0 cc c7 f5 ff 2e ff a5 23 96 a4 cc 6f 45 bb 3e 5a 40 00 00 00 e2 45 58 54 ae 81 96 28 4b 63 bf 79 fa bc 55 a8 ef 65 71 3b ed be 14 c5 41 13 e2 8c 1a d3 e5 6e 23 b7 86 2e 8e 4c e6 9a 64 81 8e 84 61 6b 1b d9 51 c9 c4 fe c8 c0 af 59 73 be c8 ac d5 b8 d3 ee (REG_BINARY) "7DAC7BC00FAF594202F3D0B9F92C48F45B0066F956"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 50 ee 8f 01 26 39 f3 51 95 42 87 1d 70 53 2d b1 c5 1e 2b 47 d5 fd 44 ed 27 dc 47 f6 c5 2a 1c 6d 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 6a 6c b4 7a a5 5e e4 3b 3e d2 56 43 b2 d5 e7 69 06 ac 40 32 1b 9a fc 2e 58 e9 70 6b 41 80 75 8a 40 00 00 00 6f 63 cf 54 48 e1 b8 42 24 46 e8 11 ce bb 1a 68 57 5a 26 97 1b d7 b6 57 a9 8d 78 90 85 92 81 18 41 fe 65 02 63 99 e4 de 3f 37 a5 3b c1 5d f9 4b e0 ce c0 b1 ae 42 0c ed 69 21 4c 09 02 8b 8a a3 40 00 00 00 69 9c 85 87 93 ae 98 98 64 82 d5 42 ad bd db d7 e5 0c 55 69 71 08 e9 4f c4 8f 35 6e d3 c2 78 d2 5f 45 ba 25 97 ca 00 40 06 26 bb 96 35 2d c1 ec 5f 90 11 c4 d9 6f 6c 74 a9 05 d5 c5 51 bd 15 6d (REG_BINARY) "9A487C01AF93AEF3F218373ED252D45069BAD6C0C2"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 da 7f d1 31 24 fd 5c 48 a1 10 76 d0 62 f1 bd c9 b3 30 0d f1 77 2a 0a a4 7b 63 70 13 c9 84 26 ae 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ff e5 af fb a1 2d 0e d3 b0 ab 67 e9 54 78 d2 03 09 31 f5 23 76 4f 11 7e 9f f8 1f 7c 5a 9d f4 51 60 00 00 00 f1 57 e4 c6 c4 4e 84 94 30 ec 55 df 73 5a f1 ec ba 49 02 50 60 19 69 b3 de 3e fc 04 46 36 1e 40 d1 c4 65 31 3a b0 84 ed 4f 09 f9 85 c1 f5 8e 52 90 bc 57 16 fe 3e b3 7b a2 e3 9b d3 24 81 a1 51 73 a0 34 a4 fd 9b 36 5c b3 64 25 50 4d c3 54 3b 4b 3b 90 b6 f8 c3 da bf 75 78 f8 9c c6 81 a1 4f 40 00 00 00 eb 56 dd cf a8 f0 fd bf 06 89 cf 21 bd 7c dd c0 7c 1a 51 c3 9a f7 89 90 46 87 cd 71 17 a0 55 68 dd 04 88 0f f7 81 6d 69 3c d9 ad bd 31 bc 28 44 3b a3 c7 01 77 39 fc 5a 9b 1c 13 95 91 bd cb 5d (REG_BINARY) "277687B2398A1345F223BE0F0889717B4494E7B5C4"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 aa 87 2c 45 94 73 76 44 61 50 2c a1 46 8f 1c 65 f3 40 62 f2 37 56 fd af a0 9e 8c 83 f5 dd 3c 0b 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7c 28 38 c1 44 52 a3 27 6e d3 6f ff 84 9c 4e d7 9e c4 49 df d7 c9 d4 57 e6 81 7b e3 bd d3 c0 98 a0 00 00 00 e3 07 97 08 81 6e 22 b0 9e 93 46 8e cb 1b 62 30 2c f4 f7 c5 22 cc 8d f2 69 3d b8 17 3d 20 8c 5e 61 88 5b 4b 38 ad 7d a1 63 0e d5 6d 99 46 f2 a5 ba f9 26 c9 b8 74 49 c3 f9 07 68 24 89 d6 87 5e c8 fc 18 f9 92 9b aa 62 06 bf 7f ba a3 a3 0a 58 62 b3 21 63 82 64 32 4d 97 89 af dd 2f 8d 7e 50 eb 61 15 c4 1a a0 d2 67 93 f9 0d a0 c4 ec 0b 76 4f 87 f4 f6 f8 26 c6 5e 59 0f b8 43 ee 65 59 1a 2e f9 f0 96 17 6a c4 80 ad 0b cf fd 80 c6 10 fc 08 ab 4c 5f 69 c3 d8 bf 56 ea 96 4e 40 d6 f8 9c 40 00 00 00 51 ee ec ed d8 58 d8 dd 87 b6 c9 68 6b 8b cc 33 5b 08 08 c8 80 99 7e 43 89 26 35 7f 86 a6 fd (REG_BINARY) "90D5C215D3DA44C6D0D6B7E9FD3CA053A5EFBEF1A8"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b1 a9 7e b2 31 5e ce 5a 8e b7 7e b1 60 b9 ff a6 bd 31 36 1a 41 b5 c9 43 c5 17 7d c3 bb e7 39 69 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 da 89 d3 e0 e2 76 2b 9f 90 5c 5b c2 86 b0 e7 b5 6a c1 59 ca 1c 22 96 10 65 89 b8 ff 3a e8 5d 58 d0 00 00 00 ea b6 8f e9 87 ab b8 b4 0c 66 f1 06 b9 59 50 95 cc 08 9e eb 23 d2 b9 67 55 86 c1 ce b2 84 8d c2 47 10 3d ea 7e 00 14 75 a5 db cf 4f 29 75 60 9e 8f 2e dd c0 0c ca 4c ff 18 17 7a f1 b1 b4 8f c7 cb 30 e9 06 2c b3 71 57 73 92 93 5d aa 3d e1 22 11 f0 b9 72 a1 68 aa 92 01 2c 63 9b b4 bf 5b 26 45 99 be 3a bd 0e f7 a6 2d 76 5e f2 d5 50 1c 5e 78 4c 6e c5 bf b9 36 21 39 e9 99 a9 3d 14 c1 21 01 de c8 a7 81 e0 91 bd c4 a9 bc e6 f2 3a e5 10 04 40 3c a6 e1 f9 95 42 85 13 5e dc 29 35 f7 5e 1c ff d9 7b 5e 86 0f 85 f7 c7 09 48 24 9f 53 62 67 1e a9 b5 f7 fb 3b 55 69 f7 be 27 86 f3 5a ce 3f f1 78 (REG_BINARY) "83EBB6A39BB833B1414D793064CB18F84F12266E69"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b8 81 dd b1 99 b5 75 62 ec 55 a9 34 15 44 e3 3e 50 81 46 5a 60 c2 d8 2f ec a6 c1 46 9b 02 bc 7e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 d5 4f 70 22 e1 83 5c 08 34 f8 84 74 bd 69 3a 30 81 6f 17 60 b7 c4 42 c3 30 30 37 58 24 f0 e4 63 50 00 00 00 e0 3e e7 74 29 c5 c4 9b 38 09 de c6 d3 06 9f fd 65 57 fd bf b6 1d 65 38 4b 44 e0 23 9a be 24 e5 e6 8a 52 14 2a a4 5e 79 fe 10 55 c0 5a 2e 04 f4 8c 04 74 3c 17 e9 5d 2a 55 4d 14 36 05 e7 c9 31 98 d6 2e 01 a9 e9 55 92 cf e5 d9 d3 d3 06 e1 5a 40 00 00 00 b5 1c 63 4b 8c 8d f6 5e a6 a4 a0 e4 3e ac dd d5 d4 15 9c 37 6a be 4b 39 5e ca 2f bb 65 b6 96 56 28 eb e8 e4 f8 d6 94 de a5 55 0d 26 99 fb 2f fd f8 9f d3 b8 43 4e db d5 56 b1 c7 8b a3 17 34 61 (REG_BINARY) "CCB7AA85A8A10855C2FD402E545B1A05776C11256C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6d 95 9e c4 70 76 b6 05 c5 1c a0 38 1f 53 46 03 c1 87 03 f3 6f 0d 2e 62 b1 5a a3 f9 19 39 d9 bd 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 e5 a6 ac 94 e0 81 ff 2e ea f7 70 15 78 e5 80 af 19 a1 7d ba 7e a1 d6 89 aa ec 05 8c aa c0 41 d8 50 00 00 00 4d a2 2e d0 03 d9 26 33 f0 af 8a 7c d5 c8 5a 10 06 80 09 31 1b 82 fa 2f da 21 5d 9d 52 0a 00 42 3b 3a d8 8a 3a b8 d9 2f 48 73 12 0d 09 1f cb fe 34 e2 0f 5b 9e fc 3f 65 7c f7 7d f2 8b a2 e3 46 de 6f 36 1c f3 10 18 18 4b 31 c3 b4 be fb 94 6b 40 00 00 00 64 94 69 f0 87 75 13 5a 17 a4 5e d4 73 08 af 6c 76 eb cd f7 aa 00 3c 49 91 3d c5 98 83 1d d5 59 10 c5 9d 94 f3 0f aa b2 ec 09 71 cc a3 01 36 35 cd 7c 93 97 fb 57 80 cb d8 5e 00 43 b3 86 70 a6 (REG_BINARY) "D54147DB1C362F0995D2B42EA73FA59BA45E4737B1"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 7a 6f 32 2a 20 23 f8 a3 ec c2 08 66 2b 2f b6 0b ee dd 41 bb c0 4a ee 03 a5 49 5c 41 12 9c f6 7f 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 a3 61 83 a5 f6 2b 13 31 97 8a c1 11 ef ff 95 d7 4f fc 4d 48 d3 85 7e 96 d5 fc f4 b5 68 c7 e7 a0 50 00 00 00 a1 61 42 92 20 04 79 7e 9d 66 6b af ea b2 e7 1c d7 cc 2b ef 87 f8 da 0b 5a 5e 22 fe 8f 8b d3 79 6a 3d e2 14 26 3d 05 e9 43 c0 ac 33 45 f5 96 01 99 57 4b ff 80 cc 59 1d 46 f7 41 b4 6d 1a ea f5 f8 99 27 e9 33 27 f5 ad c1 44 22 ce c9 4d 70 b0 40 00 00 00 2c 1e b1 e0 00 4e 92 23 93 1e fa 83 1b b9 9f fe d4 0d 7a 7b 2d 9e 54 d5 5a b5 ff 89 c4 42 ba eb 26 fc 28 63 1f d0 1d db 91 dc de 4c 90 0a 97 35 94 61 a9 53 27 24 fd a3 a6 38 f5 3b 53 ba 42 c0 (REG_BINARY) "151C5B278B9543FD3F7C057F70B7CF8B2318C31EEF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 54 eb b9 e4 2c c5 1c f7 fb f2 47 c9 23 54 d0 e0 82 92 73 d8 ae a1 29 3a 25 32 17 a5 9c 13 2b 1f 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 84 e7 1f 87 44 77 5f 71 46 ca 0e d6 b2 90 9b 61 3b 4b 25 06 0a 61 ca 69 c4 86 df 93 cc 3c 5a 5e 40 01 00 00 15 28 9a ed 38 5b 19 d8 b2 d9 5f 3e a3 ac 59 c0 86 a1 a2 a9 0d 57 2b 76 8b f9 8f 88 82 fc 27 79 94 27 f4 72 86 61 e6 58 27 93 d2 3d 18 f2 33 6f 44 54 53 6f a5 3e fb 61 94 64 14 03 93 91 c0 0f 49 54 cc 57 c4 09 72 cf 61 29 5e fd 6d 3d 6d a8 08 b0 0b 01 c0 01 a7 55 a3 90 42 25 95 0f 3c 32 2e e7 ee e6 ef dc e9 2b 0e 79 40 6f e2 83 89 24 d8 9b ee 32 76 e3 44 f0 8e 5f d1 99 69 e0 69 07 1a a5 92 41 91 32 90 15 5f 16 65 2f a3 eb 11 c7 97 24 45 8e d8 5f f9 1e 80 86 c5 77 1f 41 78 5e c9 78 c1 dd db 2a 31 9b a3 c9 7d 2d fc 37 a7 a2 a2 a9 ff d3 04 fd c5 f7 3d 3d 9e 7f bd e6 54 c7 93 56 d8 (REG_BINARY) "C410D75D9FAB47D9ED29D3544E241F537DA1B3D93D"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 43 e6 cb 62 cf 7f 65 bb d6 56 7b 1f bc b1 dc 7b 13 ea 81 7c 09 77 77 ca 56 40 ff 22 0e e9 44 78 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 74 d8 aa 02 1a be 8f 14 57 9a 35 04 11 e2 93 0d 0f ab ad a6 21 72 35 4a 07 83 fb 1a 30 4c ab 3b 50 00 00 00 b4 67 80 28 fc 3c b1 dc 3a 59 d9 48 79 9d d6 a0 77 c4 6b e5 55 b2 3a 6d 06 e6 6c 8c 79 f0 2a c9 5e 2d 5d 33 ad b7 14 f0 92 45 17 3b f8 d8 b5 16 80 f4 c3 a2 df 48 5d 03 8c 01 82 21 30 45 8e 58 cd 3e 21 3c f3 b6 d8 a5 89 1e 18 e0 5e d1 5b e2 40 00 00 00 0e 0f 7e fe a3 55 f5 ae 2e 80 db 45 4a 5b a2 da 72 17 e4 4c 0e 9d fb f4 af b6 f5 5c 64 61 3a eb a2 81 e2 6a 0b 34 c7 7b 09 bc 52 b3 8d af ac 64 00 3f 94 c8 2d a9 ec f0 7c d0 d3 26 c4 13 42 23 (REG_BINARY) "02043DC0EE6FA30DA5C5225FA57DCD4F6DEFFF4CE0"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 a9 cc 21 dc ae b6 fe 02 8d d5 62 a1 aa 52 25 38 4c 4f 4b f9 ec 59 de 5e c7 2b 3b e6 d4 34 82 1d 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7b 21 d0 5a d6 c8 25 be 5a d3 4b 1e ae 41 75 45 b9 7b a6 20 02 ca 77 8e e8 9d 51 7d 79 f1 39 1f 60 00 00 00 3a 34 3f 65 e2 de 00 26 42 3c a3 32 37 94 12 b7 db 76 a3 c4 c2 63 f0 4c df 2d 9b 3b b1 68 33 d6 bf ca 2a 18 0c d1 00 44 fb 65 c0 8f 16 7a 0f 54 5a e6 83 b0 d3 8e 86 16 ed cc fa e4 18 6d 27 93 2d b1 6a eb 2a 38 73 4e 33 60 b4 d1 f8 fc 4f 8e a7 c7 59 06 52 e1 cd a5 f2 e7 db 77 8c 90 52 96 40 00 00 00 db 28 ea 44 58 3c 52 a0 d7 da d0 f7 42 29 4b 22 f6 c5 66 1a aa 8a b7 8f dd 3d 56 d2 b8 9d 15 99 ad af f1 44 9f f5 93 40 96 cc 86 8e f5 1f f5 ca 65 b6 58 5d c1 ff 2c ce 8a fa 6e 30 9d cc ff 3b (REG_BINARY) "47DC317DB95F9F35009E68790B029F6EC48636461C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 98 73 4d 85 df 0c f0 a4 53 df e3 cd 88 05 76 a7 2c ae 27 b1 11 9e 45 7e a5 2b b2 87 af 06 06 1a 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 25 35 44 7c 2e b5 c4 80 5f a5 45 2c d7 7a cb 4e ca 60 ff 89 71 08 a4 ef a6 3b ff ea e4 28 ac c9 10 01 00 00 0c e1 7d 34 6a dd 70 03 7a e3 34 2e 20 b0 4f 4b f1 79 21 c7 a9 59 0a b6 21 a5 37 38 79 36 7c 77 8a ea 0b 9d ff 2d 98 a7 30 df 4c c1 89 01 aa e8 ed 83 f0 9b b2 1d c5 b6 f2 65 25 ce 23 c7 b1 9f 34 20 82 28 83 8a 63 40 bf 8a f4 d6 ef 61 4b 8a e8 fc 3e e0 2f 36 05 68 47 c3 2f c7 ea 7d df 8c 58 35 49 ab 69 94 0f ca 1e 8c 6e 67 68 a9 20 e5 3b 71 66 a1 0e fb 00 5b 6c 7a 9e 8d 7a 79 4f 3e 57 04 01 85 af 3b 7b 97 13 81 32 75 47 b4 9f 20 11 70 b0 2a 4e 4b 3c af a6 5b 3e 8e d0 68 6c 43 e5 e9 71 55 c8 6d 4b 37 ee d2 83 fc 4f 17 46 1d 42 73 e6 58 97 3b d4 55 ba c1 ce 2e cc 40 53 cf be b1 ff (REG_BINARY) "CA1AF6DCC6287BCEA721C0EEC4B388720F0B7B83EC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 9e 92 c5 3b 78 52 6c e3 3d 3d b1 7c 62 d6 7c c2 cf 8f 8c 9e c0 3e 90 68 9f 47 65 2d 09 4e 3a 52 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 17 e3 ac 32 09 4c e6 55 d9 30 a5 68 c6 51 22 b5 16 f2 36 73 47 35 95 ed d6 e4 a5 0b 79 20 39 8d 80 00 00 00 ed b2 85 bb ef 58 bc b0 fb bc 5b c9 58 df 6e b5 94 4f 37 07 23 59 5c d7 65 e4 59 9c f6 c9 cc c5 aa 2c b1 7c d0 c6 0a 6a 06 4b 00 28 bb 76 bb e1 c3 64 44 0f b8 1b 6b 57 d7 8e f7 c2 4c 99 bd 5c 97 d3 7f 69 e3 91 3d 56 85 d5 3d fe 6c d1 03 3a c1 08 19 05 1e 61 6e ad ca 2c d4 3c bb 96 22 99 2b ec 0c cc b5 fe a3 f4 7a fc fe 6a 54 c6 c4 6f e1 94 bc 0d 1a bb 77 47 4a 10 57 00 8a 9e 1f 1a 40 00 00 00 7f 91 84 55 db 3e 4e 7b ca 74 94 18 47 e7 67 f5 05 1f 52 9e 2e d5 60 0f f5 81 84 77 9d 01 30 34 48 ad 1b 20 c6 f4 d9 ed 6d 4e 6d 63 65 3d 13 a0 ed ef b1 40 80 33 ec 96 db 3e ec 33 b7 6c 5f (REG_BINARY) "BBF96385C514B28DA9DAFBB609FF775CC344709DD7"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6a 55 a8 c0 4b 2c a5 d6 11 d8 e6 a3 52 b1 9c 42 7f 6a 8f f4 b2 52 37 cd 50 cc e8 40 28 49 27 c2 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 9b 7b 36 4e 0a 39 8e 12 87 43 6c c7 00 de 45 16 a4 20 71 0e ae 61 41 d1 93 ac 9f b2 d8 92 e3 6d b0 00 00 00 9b df e2 c3 24 ff 44 0c 3e c5 0d 67 f4 ec 6b 95 a6 88 24 b2 dd b2 69 1c 13 44 ad 43 eb f1 e0 68 13 f5 7c 1e 64 84 25 17 4b ad fb 5d 60 47 55 3f 35 84 72 b2 a0 04 2c 77 f2 11 a6 90 7e 61 3e f8 65 4f f8 0e d4 76 06 ab ee 69 47 e0 76 9f 5f 48 85 79 45 c4 9c f5 64 d1 cb 76 c8 67 e3 ae 59 e8 7f 1f 5d 6d 69 d0 f1 9d be f2 ea 0b 4e 4b 49 c8 93 f7 94 b5 56 28 ab 01 ca 11 aa 34 09 fc dd c1 de 2c 38 8d 89 43 9d ca d4 d6 9b f1 36 ed 2e bb 30 7b 3e b6 15 a8 f3 49 4b e7 bf 39 8b 9d 75 e5 0d 45 d0 7b 18 32 52 9f 99 28 c8 6a c7 01 71 dc 40 00 00 00 63 24 06 80 c4 aa 50 26 e5 e2 2a 1b dc 49 a2 (REG_BINARY) "C18721EFAB6878A8513E6AF97B2C1BA38FAABA5025"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 61 bb 07 e8 01 2c 97 58 34 f5 80 ac a2 12 e8 a2 95 9a 16 2e 77 62 87 95 2e 33 93 d4 68 51 a5 bb 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 bc d5 f0 6f e8 9c ba 45 9c a7 38 68 f0 f0 d4 bb b8 61 b2 f9 8d 2e f6 a2 fd e2 25 af 45 75 0f 65 60 00 00 00 61 92 95 a3 db 30 9f 82 70 45 e6 92 95 4f 64 97 1e a7 30 85 15 2b a0 ee 81 76 91 4b 94 18 2e db 16 bd 90 06 2a 3b 07 3a 6d bc 8d c7 94 8f 4e 37 dc 54 a2 cc 62 5e be e6 39 32 33 d1 1d 55 a4 da fe 68 19 0b 1d 39 b3 91 05 d2 a7 05 06 f9 5d 15 22 9d 9a 45 63 1c d7 12 3d 0d 9c 95 c8 11 a0 cc 40 00 00 00 92 92 0b 9c 92 34 84 52 c7 6c 9d 04 37 19 5b 98 12 fb 13 28 c5 79 75 cf be fa af 1b 3f 7c ce 6a f9 bd 51 40 5e 95 b2 e4 29 f3 3c bc dd e8 b2 39 ad 7c a0 57 a7 45 e1 0e ef d4 03 6e eb 32 0f 74 (REG_BINARY) "FEC428075B736AFF62839D75417AB78E124D623E1E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 18 8b 8b ff f1 cf dc d4 eb 38 27 48 0e 01 cd 22 6d ff 9c c6 5c b6 f4 aa e7 2e 82 a4 d8 b7 11 e6 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 47 4f 9c 26 47 34 d3 96 42 06 f9 30 3f f8 df 3d 8f 36 fb ff bd 6a 2b 98 78 0d ef 0f c0 f1 e0 25 60 00 00 00 86 05 be f8 83 ad ba 2c 82 47 2d 81 94 2d b7 a9 ea 36 2d 5e 10 58 16 32 3c 33 c4 84 d1 bc 2c 0a cc 5e a9 2a 67 6e 5d 2d a0 b6 4c 02 70 6d ca 72 89 39 3b 83 df 22 a0 b1 ce 90 85 13 32 80 7d ef c8 57 b1 b5 e9 a1 fb a4 f3 6f be e4 00 e5 36 7b b8 e6 4c f9 8b d9 51 7a 77 5b b6 b4 bc fa 9d f0 40 00 00 00 93 d1 5c 62 a1 f8 cb 38 b1 5a a3 c0 a8 bc 86 f0 6c 11 7e 74 fe dc 0f a5 d4 5c 4f cc b5 c0 1b df 3b 35 70 3a 8a a9 93 fd 67 05 20 5c 5d 59 24 26 c3 d3 30 3d 97 fd e0 ea 23 4d 6b 76 77 6a 79 3e (REG_BINARY) "7AA84842A4E0DAC7EEA7E524E2442BDEFC9A089BD7"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8e d5 05 4b 23 8e 0e 48 9e 87 56 5a b7 3a ed 67 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3c 2c 58 82 9f db e9 e7 7f 01 ac 69 6b c3 17 0f 29 cd 55 9c 87 6e 5e d2 94 37 8d 29 b0 4e b6 34 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 c3 ff 0d ed 14 6d 94 74 c8 d6 4a fa 38 f1 c3 3d 50 96 95 d0 3d d5 8f 77 93 98 84 d9 91 d8 fa 9b c0 03 00 00 7b 14 d2 7e 0d 76 cd 6d c1 23 4b f5 56 82 fd b8 16 89 18 03 d6 63 e5 37 e6 08 e9 4c 30 1f c6 64 c4 4b 73 b3 be ee a8 37 93 58 d3 4c 12 be 65 99 4e fc f2 2f fa 42 3d b1 5b 13 df f7 1b 1f d4 f2 3b 7d 40 ea b7 63 d7 5e c1 a5 6a d8 6e 66 d8 cb b8 ee ac 5d 79 96 63 f9 64 38 91 ab a8 2d 76 a2 48 69 fe 9b de 81 45 11 16 60 21 b0 5e 2a d4 e9 16 a9 b6 0a 8c 2f c8 12 56 f8 3f 66 fd 53 84 cd 35 5b b9 94 81 d1 83 25 4c 58 91 a2 31 a0 56 7b 3d 96 a7 9b 43 9a b4 a0 82 d4 00 40 a9 af f9 99 e5 05 80 4e 33 8f 07 7c 07 56 ce b4 6b e5 94 c4 fb f1 5b 7a ed 9e 66 dc e7 3b e3 e6 1e 4f 66 a2 3f 8c 70 (REG_BINARY) "942AAC68E084290B6F96F526CE78F25AE4DB7E4EA7"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 d3 f8 97 d5 88 56 96 73 44 1e bc 7c 28 62 e4 78 89 a9 94 e8 ab 10 56 3c a0 61 4f c4 ff a2 98 a5 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 34 df 25 8a d1 9c 7a 21 be d9 d0 c0 19 6a 39 28 78 e7 ba e9 b5 e7 00 77 f8 ca 93 3b f1 d9 1f 2e 50 00 00 00 08 b0 84 fe bb ac 44 ec 12 cb 87 aa 26 32 88 75 cf bd 8d 90 05 e5 92 08 4a de 4b 94 e4 dc 70 24 78 83 06 fb 5f 30 a7 65 8f a5 91 83 20 6d 43 d5 cf f5 83 d6 4b e8 09 ae 7e 10 31 16 42 7d 23 3e 57 e5 f6 4f cc f0 39 d7 f0 ab e4 d4 32 7a d7 29 40 00 00 00 9c cc 79 10 69 a0 df c8 5d 9d 54 5a 6c 2f 2b 19 f8 92 2c 50 84 2f 8b 47 fe 43 32 d5 0b 21 ae 18 2e 5e b6 fa f7 43 45 5b f0 4e 08 0a 77 32 34 a8 98 66 81 d9 bf 36 9f 2c 4f ad c0 60 82 c7 c8 5a (REG_BINARY) "9BC240B202D6B8D28B653AAA76A47E5AA8DFD07442"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 c4 ae 0f d2 7d 87 f7 bc 5d cf 59 dd 95 71 39 37 8b 74 71 82 f7 a8 16 ad d0 0f f2 fc c9 ef d3 9e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 e2 cb 19 ab 16 fa a5 4d 5c 19 58 8e 0c 42 1f 7d 6c 50 c4 4e 19 45 2c 12 18 85 72 28 04 e0 0b 5a 50 00 00 00 00 33 b9 7d 6c 72 50 65 be 4e 13 96 34 c3 29 82 07 94 19 20 f0 9d 9f f4 9d f9 82 40 33 cb 28 7a ee 8f 72 49 e9 9a 03 ad 79 ea b1 50 aa 9a 89 42 b5 cc 82 2c c0 e2 76 20 1a 89 8f 38 84 f2 09 e3 ee 2d df 88 c8 cc 85 9c 39 5d 4b b0 1b 4b 12 00 40 00 00 00 9c 69 9d 08 5c cd ab 1f b8 54 4e 4d cf 56 6b 72 60 12 ec 9a f3 7c e2 3c b4 3a cc 8f b2 7b 33 33 a6 a5 d9 1e a3 52 49 dc a2 eb 44 a4 34 2a db f3 2c 9a 30 bb 19 6b ae 41 b8 2f da bc 5c fc e3 c5 (REG_BINARY) "CC789E0CC6B535DAA1EEA742F205F55F60ABB7504D"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 e9 2c b4 48 94 0f d7 87 da f2 e6 6f c9 75 3a b9 99 01 c4 94 66 40 70 21 08 42 0c 11 de 8c 75 01 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 36 e6 09 05 17 e5 a6 c6 ce c5 6a 87 8b 95 16 4c cb 5c 03 97 5f 95 7b ab 29 27 02 5c cd b8 fa 89 50 00 00 00 6e c8 df 78 b0 ef 7a 27 39 f6 d5 87 6d a0 96 ae 2f 26 06 77 7d d8 c4 f5 87 38 47 93 7d 1d 83 fa 46 b1 e5 be 72 5f 8f 6b ae d6 52 66 98 c4 26 1e 7a 3c d1 7b 06 1c 14 96 44 27 4b 76 28 cc 6e 8c 24 44 88 b1 1d 29 91 be 7f b4 12 c5 26 b4 47 e5 40 00 00 00 26 f0 90 9d 0e 4b 20 49 fe 20 1d 7d ad 1b c8 87 6e 02 af b2 e5 37 11 8c 51 70 a4 78 c6 11 8c 7c 6e 23 88 33 1c de cc 8d a6 3a b9 76 7d dd c8 21 46 3e 1c 09 1e 6d 9c 8f 6b e5 2e df 47 82 8c ec (REG_BINARY) "4A245A629AAFE61C2397B17960D4364F640ED662BC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 17 85 d8 4f 0d 93 73 88 79 2a ae 80 0c 9a 78 8f 5e 80 6d 7a 94 40 53 9a 5d 66 83 72 5c 9d 1e 16 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 89 6a 52 8f f9 a4 b7 47 e5 ad 56 0c 31 58 30 cf 1c 8c be f6 ed ad e0 e0 05 ef 76 d8 70 83 80 cb 60 00 00 00 2a 70 34 87 87 05 19 00 c8 70 c4 31 32 1c db e5 aa d3 d5 fe 6d ef 61 5c 69 01 a0 90 b1 5b f3 db c0 55 59 43 2d 00 6e 1d a9 0c ad de 14 09 34 fd 18 ac 23 60 76 96 c9 ac d9 09 5d 85 53 6a 3c 8d 20 0d b7 29 fa f1 19 ad 12 95 b4 72 03 21 57 2a 36 ac d1 fd 99 6c 7f c4 26 8c 55 0b 8b 07 b1 6b 40 00 00 00 d3 44 31 ff c8 4e 12 f5 ed 15 3d 3b 48 71 21 bd 98 a2 3a 04 48 dd ef e3 e6 91 49 92 cb 8b ec d3 e7 04 96 b4 4b c1 ff 92 bb a5 c8 1b 2e 9e 29 93 21 55 8e 16 0c 6c b5 d3 03 fc 63 77 e2 55 b9 d4 (REG_BINARY) "94A17B8D29DF1B9AFE779145FA10E6F97EF9A458A1"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b8 84 1c af 0c 14 db 35 da 21 8f e0 8c 7e 0c 45 f9 15 08 f7 dc cf 25 5c eb 09 9c 36 0b 5f 3b 4e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 fd c6 38 89 75 8c 8a 5a cd a9 7e 32 92 33 dd df 03 56 2c c3 9a dd 38 15 bc 15 01 60 1b a4 a6 6e 20 01 00 00 d4 61 6f 6d a5 19 e4 b6 ce a3 eb e2 44 ad c2 26 90 4f 5d 70 3b 5b e2 2f e1 65 e7 18 2a b6 a5 b4 c1 c4 ac 1f 07 7c c5 e2 4e f5 9b e7 35 71 42 8f c7 01 3a 8c f4 54 76 d7 75 24 20 cc bf 15 b9 9f 3b 4d 6a 9a 78 db e2 c0 25 a8 b3 6c 4c 0a 05 d3 23 9a 95 73 ca a0 7f 8c 81 99 4b 01 49 3e 86 8d 97 e9 6b ac be ad 79 99 54 80 98 8f 8e 3e cf 15 65 5d 98 ce cd 74 74 7a 16 8c 7d 71 e3 78 0f 63 a4 35 0c 42 ed 18 ab d2 00 13 3b f1 3a cf 1f b9 db c3 02 ad 17 fa 3c 3a 67 a3 4f 0a c4 d1 bd 27 25 08 4d 1e 38 66 e0 80 95 eb ca 61 4b ce d1 a3 2d ee 54 47 ab ee c4 49 08 66 1f 3d 84 e4 8b 78 14 bc 55 (REG_BINARY) "B37488662C45CF4DFCB20FF8F84774C88542645653"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6f a9 4e d1 5a df a6 7d 55 09 3a 64 19 95 26 30 ab a5 ae f6 43 14 e4 09 2b 1b c0 96 7b e0 45 19 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 59 fb 5e cb 86 d6 bd 32 8b 86 73 e2 7c 01 ac 1c 7e 09 a0 d7 6f 10 43 49 a1 17 fe ce 2f ad 41 b0 90 00 00 00 46 70 42 ae b6 3c 05 48 48 aa aa d4 87 dc 9b 7a 8f 76 7f c8 f1 0c 51 a6 d6 9c 02 05 18 c1 67 e1 44 b9 8b d4 71 b3 9f ee 4e a1 94 92 f2 84 df f4 67 be 97 90 c2 17 e2 b8 b0 f5 b8 eb 28 87 79 98 cf 27 ee e7 64 c8 47 fb 62 c8 ee 85 c9 63 5f de 2d 15 7c e4 a1 86 39 c2 c6 c5 20 e1 b2 28 c4 0d f1 d7 9b 8b e6 01 6f ec 90 13 8f 71 d8 e4 33 42 8d 30 c6 03 61 b1 31 c0 2a 4a 97 59 fd ea 4a fd 61 d5 70 65 b1 2f 64 96 f1 c1 c6 fb e9 e3 98 2f 40 00 00 00 95 50 f7 76 d7 21 e4 f4 a4 73 d1 83 e2 54 0e 4c 39 d6 63 e2 57 b3 0c bc 42 46 8f 2c 20 21 5d ba bf bc 2f e2 60 f9 b1 72 8e 55 87 49 bc a8 d0 (REG_BINARY) "D5D8F7CEF4CBF3FB159FC54BF4757083D0002B144E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 eb ee b5 f6 41 8d 98 da de 3d 8a 53 03 f9 49 b1 10 94 f6 bc 73 d3 22 1a c2 cb 53 a9 14 79 8f 52 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 d8 00 73 79 04 19 c8 d3 7f 3d 74 cc b6 8c e1 c8 78 92 a7 eb 3a 8c 87 04 0b 11 ce 78 fa a7 26 54 60 00 00 00 32 c4 c3 93 4e 24 ca 0a 2f 78 30 b7 0a 2e 16 da a4 01 55 95 c0 71 bc 2c 91 d4 df f1 aa c8 1b 00 06 dd dd 46 67 48 b8 be 32 0b fa f2 99 03 4e 46 29 87 3a d0 6f da e7 fc f9 1e cb 03 cd f1 30 41 5a 16 29 92 16 9e 17 9e 60 89 d1 c3 33 8e ef f1 e8 a2 01 63 74 af fa 1f 9e 44 51 cd 27 eb f3 aa 40 00 00 00 25 da 20 6c 88 b8 fd d4 5d 64 97 8f 2b 7f 1e d8 2e 9a c3 fa 67 15 33 0f 02 23 d1 69 3c 75 e1 10 95 5f 20 31 6d 0f 8d ba f0 8b 74 32 cc 3a f8 b7 5a 89 c2 c4 1e 3a 52 f0 3d f9 96 43 b5 13 eb 9b (REG_BINARY) "25BF81B879AFDE75D14AA3BF8FD8EB93EF505851E2"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 97 e4 0e 31 08 40 d2 28 51 12 ac 0f 20 79 ef e9 63 6e 80 e9 79 df 12 ae 2b 80 aa 86 00 3c 33 45 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 90 93 38 66 e5 a6 f1 a0 64 f1 a6 59 1f b2 27 ac c8 9e 8e 5f f0 71 28 3c 32 78 b3 0a 9d e3 ee 93 60 00 00 00 f8 57 27 77 6f 5d ae 5a 6e d6 4d 3f 30 af 26 63 e6 04 3d d6 91 18 f7 32 5b f5 50 62 d8 63 89 60 f4 90 c7 af bf 69 27 41 4a da 61 51 e1 ba 1f 92 27 1a 82 d1 ed 64 d3 8e 6d 7e e0 dc 05 a5 41 c2 28 b9 cf c8 e4 7f fe 53 68 86 e3 c5 8c 2d a8 11 0e 02 ef 4e 73 1b 76 c7 45 4b 2f 84 02 5f 35 99 40 00 00 00 39 45 b7 1c da 6b ca 3c 5d da 60 45 af c7 b1 b3 51 d0 ad 8c 89 5b b3 0d d3 ee a0 f8 29 d5 f6 da 6f 73 f0 38 9f a9 e8 ee e5 97 96 1b d5 d9 10 bd 8a 00 35 7a 09 85 53 08 94 c8 8d ed 8f 05 5c 63 (REG_BINARY) "447259CD65F314BE302A4F150B744569A4FC4D9B79"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 bd 67 42 30 24 cc 51 1e 98 3a 57 0a 5d 37 98 48 2d f5 01 59 02 f9 78 f8 9b 84 74 59 ff 2e ca ee 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4b 95 2e b5 10 bc e5 d3 17 9d 24 b3 26 94 c4 d7 7a d7 30 41 84 c7 e9 05 eb c1 3d aa c9 09 39 70 60 00 00 00 f7 0e 65 b3 47 a7 a7 7f 3b 65 9a bb 39 d3 e9 db 87 02 e3 3e 38 43 b3 19 d0 2e 5d 68 c8 a6 a4 1d df 4e 7b af a6 39 05 6c cd 21 a9 e9 3d 61 15 f3 fd 70 0f 80 d2 c4 3b 32 40 94 22 99 17 94 eb 4a ee d1 61 2b 46 83 9a b7 d7 24 1c 92 fd ae 47 c9 78 7e ec be 79 40 25 76 f5 d1 4c 29 03 39 31 00 40 00 00 00 50 19 2b 15 e0 07 d5 20 05 8f e2 6b 55 4a c1 62 a3 27 0f 75 5e 6d 70 b7 1e 79 99 82 08 fe cb 5b 7f 55 47 b5 d4 53 7f 01 ce 6f 6e 14 45 89 14 05 23 90 f3 87 87 d9 22 f3 4f 12 bc 4e 3f d6 53 c9 (REG_BINARY) "E6F0BDB3AD91C56FBBB0F48F69EEA9133740617B0C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 78 9a cd 46 bb de 45 9d 84 90 83 fb 87 bf 5b 0b 38 6c 71 7a 84 a7 92 51 d9 45 4b e6 e4 ae e8 ee 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 45 ae 78 b1 b9 79 c0 42 17 81 a4 61 51 28 ec f3 14 4f 5c c5 36 6d cc 31 ef 15 7d 6b f7 70 6d 38 60 00 00 00 4e da 3d ed f4 c6 66 71 6e 92 11 d7 de 2f 6d 8d de 53 16 67 10 0f af 2d bb 69 89 b9 6c 9d 58 fe af 42 16 54 18 15 9f f1 22 9c c2 2c 15 10 85 48 a8 a5 5d d9 f3 99 4c c3 c9 8d 33 6c 6e c3 9b 13 91 66 86 c3 5b ac 4c d4 2e 50 93 f5 91 09 de 92 2d 4e e6 52 a3 b6 e9 d3 6f e2 05 36 c0 c7 eb 3c 40 00 00 00 dd f8 67 a3 67 ea bd 16 40 02 34 f2 bb aa 96 b9 3a 88 2e 65 37 a3 8a a2 67 df b6 1e f0 0f 8f df 5f 6e 5e 20 31 d7 44 db e4 ee 6f a4 e3 72 c7 67 d1 ce 01 15 43 56 fe 97 50 b2 d2 96 2b 6a d2 fa (REG_BINARY) "0D6FAE7C2B35388ECCDFE4C2A2E9437F457B9E37FF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b7 0e a5 02 03 2e c6 86 a0 1b 03 60 d2 9e b1 47 5a c6 89 02 ae e0 53 1a dc f0 06 7e bb 84 8e 88 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 e8 e5 6b 9f e2 58 05 32 d7 6b c2 e9 b8 d6 63 17 23 4c 00 e5 8a dd e5 45 14 c7 e2 cc b8 ed ce 40 b0 02 00 00 7d 7b 33 da 59 20 9d 1f 99 a4 fa 4b 83 f6 ef 19 f0 02 da 8a c0 b9 bb 7c 65 d4 37 0e 76 94 d8 22 06 f4 0d 36 d1 b9 8a 1d 64 ef 01 6a 0a 4d 56 68 a4 fa 43 29 ff bf 29 88 91 72 12 3b bb 06 55 e5 3d 92 1f 15 5f 86 23 0f eb cb d9 a9 c8 8b df c0 b5 31 96 cb 7e d5 a2 eb 1c d7 94 bc e2 1b fb 73 91 05 55 e8 d1 c7 ba 25 52 2e 5f 1e c5 60 2d 60 5b 3e 4c 7a e9 fd a4 d3 30 50 df 57 d9 2e e7 0e 7d 70 3b 38 37 5a c6 96 d8 53 2a 29 cc a3 67 ad d0 13 88 20 f0 f2 f7 98 fb 7f 00 a1 f9 fe b1 98 0b 92 0b 62 34 e6 c7 ea 06 4a 58 1d 26 5a b4 99 e6 c0 09 b3 a1 4e 8f 44 b9 a4 9b a5 f8 88 5d ea 86 37 2f (REG_BINARY) Quote
debi239 Posted February 5, 2013 Author Posted February 5, 2013 "F0169FC51E57A67BD4F6AF9381526773AD249C1B41"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 af 34 e8 b8 b2 92 f2 69 c8 e8 a4 c7 e5 45 34 66 f6 3b 2d 10 9a 97 a9 7c c4 a4 4e e0 6e a6 74 a7 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 80 00 20 ad d0 91 14 bb 2d 59 2f 0c 50 70 26 1f 0b eb e0 80 df 91 4f ff 85 ed 45 fb 55 de bd 8b 60 00 00 00 25 d1 71 5d 05 4f dd d0 be c3 b6 0d cd 22 58 ac d7 2f 46 2f 0f 65 99 0e 16 e2 db 8e 65 1a cc 9c 2b 5e 21 a1 37 56 a1 07 58 fa d3 25 b7 54 c5 5e eb 0d 12 15 25 67 c1 f1 f9 8e 35 4d 61 9e 1e c1 04 d4 e4 cf 36 8a aa 5f c4 0b 34 61 3a 0b 56 15 a1 9a ee 41 8a e1 45 53 8a 55 ee 69 db 8d 3e 73 40 00 00 00 fd 56 c6 fd ac b9 7e be 58 64 2c ae 9c 6c 63 d3 e3 66 50 34 ff 2d df db 83 b8 ce ab b4 a7 84 d4 8b ae a4 7f ca 48 5e ba e0 cc 45 15 62 b1 f1 ad 5a b2 f8 15 a7 d8 b6 f8 d8 53 3d c3 0f 1e e0 6c (REG_BINARY) "88DAF2A867C7432E10C8970C65572E6ED91593CDBC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 e5 d7 e2 96 8e d9 43 05 e9 7c 28 f2 ce e6 aa 57 e1 b0 05 9b cc 24 e5 b3 89 58 4a de c7 8d b7 49 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 50 c1 e4 f1 c4 9b 2f de d4 94 17 58 b0 eb 12 59 41 6f 9c 8e b9 89 db 6c 12 99 50 ab 22 ab 9f 20 60 00 00 00 16 56 53 4d 2b 72 d8 6d 2d 7f 5c ca 27 f1 64 a0 30 1c 7e 52 9b d0 28 35 99 c5 4c 41 b7 a2 e6 b4 b7 e9 f4 3f 57 f6 a4 0d 00 e9 a3 4f 26 53 58 bd 8e d2 f0 fb 13 b3 b5 64 68 93 d1 20 e1 1f 67 2c 29 6e fe 42 0e 9b 34 23 4e fa 15 f0 b8 30 5c 7e 87 fe e9 a8 2d 1c 38 77 4c b6 4b 7b 44 10 cc a0 40 00 00 00 60 81 07 c5 fb eb 7b 0d 01 c9 35 ba 3e a4 ad 83 54 e3 7c 49 f5 28 3d 3f ca b7 0f bc 4e 6b e0 2e 2c 14 86 29 68 d4 53 b5 c9 6f 79 71 62 46 9a eb 58 27 94 31 55 16 bd 8e 25 fc 4d bc 53 17 c4 f6 (REG_BINARY) "05EDD52A1C47828E32194CA52DA6C380C12E3619F4"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 d1 d0 92 20 a6 09 11 13 91 e6 5e 28 3d 41 63 36 e9 80 38 48 9b f9 74 c5 32 2d d9 ae ae 36 c1 dd 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 f0 74 5a 7b 06 fd 4e 3b bf ec a6 ea 21 25 94 c4 ad ea 29 cc 17 5f 05 f2 23 57 3f a4 6a 36 aa 91 60 00 00 00 08 bd 1c 4c 93 45 f8 f3 1a f3 28 aa b2 42 a1 89 bc 79 19 8b 34 6e c0 f5 3b 91 cc 5d 5b 27 0d 5a 14 93 7d 77 2b 81 c3 0a 42 61 40 31 b6 af 7f e1 67 91 dc a8 b4 c1 59 2b 71 50 c6 43 6b 70 71 b1 9e 30 a0 f8 f5 91 5e 0e 29 26 2e c5 ac 30 2f d4 75 0a 35 07 c1 47 eb ad 02 e9 61 da b2 06 a7 8b 40 00 00 00 e0 5c 49 4d 2e 96 ed 82 40 7f d3 2d af ec 95 b2 e6 92 99 5f 3f 15 73 e0 32 df c4 79 e5 82 73 77 90 3b ac 35 55 8c fb 8a 7d 3e 4c ca 2e ac 72 b7 54 81 6e 90 60 23 68 91 b8 13 bc 58 6f 95 7b 17 (REG_BINARY) "2D9243EE5A78DDC0CEA68060732D25A695B01747C1"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8e d5 05 4b 23 8e 0e 48 9e 87 56 5a b7 3a ed 67 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ae ec c5 d4 a2 20 71 05 d9 48 83 e7 da 39 77 15 45 7a 32 32 f0 43 89 7d 7e 92 9d 0b 2c f9 f1 99 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 69 fe 3b 9d 0f 56 d4 be 92 80 4c b4 6e 24 6f 55 8d 7d 0c c8 0b 10 82 4d f0 11 db 27 24 91 cd c3 80 00 00 00 84 ea cc 49 b3 82 24 9e a2 08 7b 08 8f b6 a4 3c 30 35 6f dc 47 ee fc 06 9d b4 d2 15 6e 16 15 2f 10 e7 65 b0 23 a6 eb d1 91 2f dc dd cc 2e 76 e4 a7 01 7f 4e 77 12 96 94 51 07 d0 ac 3a 9c c8 2d 65 40 9a dd d5 aa 65 fa 67 6f c4 88 12 89 c3 93 e7 52 8c d0 a0 79 10 44 e8 a2 e0 50 76 63 fb 47 40 7c 4f 84 22 3b 47 3d 96 8a 0d 05 51 8d 86 a2 10 ae e1 81 ff e2 95 f9 1a 4d 5c db 65 88 38 11 40 00 00 00 ac 9b 4d 09 09 7a 56 3a e6 a5 58 0d 27 80 c3 3d 1f 3f 38 bc dd 4c 53 ab 2f 7f 26 dc 59 7f 09 c5 14 47 8a e7 06 3d 2b 16 ba c3 8c 6a be cf 72 45 11 e8 46 19 68 85 f6 f6 4d a3 e8 34 30 14 b6 (REG_BINARY) "DE38A809115A60CFBB28C98C7C7F72BD58C4F47C4F"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 46 3a 28 be 04 b6 16 58 d9 c7 8b 0d 7f f2 cd 1b 97 8b a0 f8 00 e1 1e a3 5a 3c 96 9f 6d 3f 25 e0 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 83 e4 ba f0 d6 1d cc ea b7 9f 9d e4 00 5b 7d 97 99 0e 7c 5e 0e 44 58 a1 04 35 7f bb a3 a3 a6 ed 60 00 00 00 b8 cc 5f 91 66 d9 0e e7 0d f2 99 94 47 6e a8 ac 77 f6 b0 78 e3 62 d3 33 5e 6e 65 83 fa 93 34 b3 1b f9 f6 92 61 ea 8b 80 9a 58 4a 8f 6b 91 2a 12 84 f0 99 fe 41 1b 95 c9 f7 51 fe 98 38 0c 7b ad 3f b7 1d e5 7f 9d ad 92 e0 f5 a7 91 b8 1e 0d 30 e7 36 c9 56 00 4f 8e 9a bf 37 67 76 b7 8a 35 4f 40 00 00 00 28 96 ae 84 6a f2 97 35 c4 a7 9a 74 3d 6d 69 23 82 07 f2 62 49 0d 20 b2 d4 e3 b0 d5 c4 5c e7 bb d2 e4 56 f9 ee 23 c7 2b c5 1e 57 84 2d 3f a2 03 22 c6 68 e6 18 fc 7e b8 1a 5b a2 9a 4d 78 bb 82 (REG_BINARY) "915B07A2BAC07D1998162388E3347747A4B4B4A483"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3e a4 0f 3a e4 2d 02 f2 95 ca 6c 4b 26 6f 07 3f 50 cb 4d 1a 05 1c 9e 5b 47 32 59 73 db c4 2d d0 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 82 72 08 c4 7b 9c e4 44 62 54 2c b2 20 1e 4b cd e5 d5 4b 80 67 de 45 4f 0b 46 9b b2 1e cf 52 81 60 00 00 00 7b 98 24 87 d3 06 d6 9e 98 dd dc fb be f6 f4 f2 2a ac 79 4f 9b 87 b6 4b 24 eb 61 b3 73 fb 58 c5 a1 87 65 0d d8 5e e0 ba 31 57 cd c4 4b 4b cf df 7f d5 bd de 74 1b 07 01 52 cd 71 85 c1 4a a9 52 32 ab 6a 11 d7 9f fd 19 ba 9b 06 1e 07 79 ef bf 5c f0 c3 3e 1d ca 26 f3 9e 1e fe 40 71 84 68 a1 40 00 00 00 24 21 12 84 81 12 66 46 8c 0e 07 54 22 c6 da 5e f1 55 49 a9 8e e5 a8 b0 a4 51 25 7e 6b c1 82 bc 2d 0a 5c c8 d4 99 be 64 e6 5a fd 66 93 dd 53 f7 8a de 2d fe 32 39 e3 84 01 10 b3 9a f3 0f 72 6c (REG_BINARY) "3BC25C35155E4E1FA00056CE58A9268C05EF55D0FE"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 e1 62 6f c2 7b 59 ac 2b aa 4c 63 9b 52 d6 2a d1 a5 10 f9 2c 46 e7 d5 b9 41 67 e2 d2 be bd 50 34 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 c3 42 5a d9 0d 20 ce 48 2c 4a b1 3f 8a 5f c0 77 4c 5e ee 5a 94 ea 30 a9 11 43 aa a9 98 20 11 9c 60 00 00 00 42 a3 ca 90 58 22 82 4c 24 8d e7 09 7b 4d c8 74 ca eb 48 18 a2 8d cc 85 ba c3 e5 82 3e 01 5b 53 8d 41 13 39 ec ad 82 f1 23 86 7a 01 31 69 73 43 40 62 83 5a b5 6b 47 f7 58 84 70 eb 8c 9c ea 23 a5 ae 07 62 0f 7b c2 35 ce 9a b5 6f 60 d0 5a 0e 62 5a 35 2c 23 5f 63 df 54 3e ef c4 99 d9 74 91 40 00 00 00 14 4d 97 65 9d 0f c6 b0 f1 14 06 22 39 62 f2 79 80 5b 05 ea ed 45 70 3d 54 87 fe e6 7c 4a 7d 9f 8a 1e b1 01 a8 0e 8d 82 d9 63 d1 f9 81 7d bc ce 77 c3 f5 53 3f 4e e5 f9 74 2b 2c 84 e4 76 84 92 (REG_BINARY) "7D5C9CE3BD4114A8CE61D594F3C51623E542AF75E6"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 f7 a5 cd 6b d6 25 b0 3d 0f 50 92 02 8c fc 9f a8 f4 f9 ed 95 99 a6 1d c1 e8 b7 a3 a5 c0 21 ef 78 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 f1 18 20 ba fd 0a 55 2f 7f 11 29 8c 59 d4 6b 60 a0 1b d3 a7 f5 7a 1d 7c 75 99 c0 ca fc 2c 6c 60 50 00 00 00 aa 07 46 80 0b 81 9d 56 2f 43 99 ac cb 98 12 9c f1 03 9c 05 3c 7d b5 5e f3 2a 0f bc 19 2c a1 8d eb f0 64 36 bd 05 47 5d 16 9a 08 72 7a 5c c8 df 91 62 ec ac 31 1f 29 1a b9 d1 b8 3c bf 38 94 2c 51 72 ce 80 9a f5 d9 81 bd 2d e6 02 d4 b9 9e 33 40 00 00 00 05 4e 22 84 be db 7c 0c b2 37 70 27 8e e2 16 fa 3e ec de c5 03 0d 73 29 92 b7 50 94 6c 61 14 d6 ca 90 a2 27 ed 36 4a 26 d4 f2 ab eb 9b 8e c1 7f 42 a4 78 b1 e4 18 59 2b c8 71 cf 5f 74 4a 36 d6 (REG_BINARY) "3AE4650B05C9544EB1EC8EA9B4BED0E7B41B06EDBD"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6f 0f ef d1 d8 7d dc 35 69 e7 86 b9 9c 8c 9c ff 66 5d 1d b4 3b b7 f5 8f dd 50 c0 af 11 99 d4 73 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 1d 23 7d 7c d4 47 fd 59 e8 b2 94 1f 9b ec 95 db 97 1b 4a fe df 8d 80 d9 e6 9b 9d ac 9c b8 b5 9b 40 00 00 00 47 2f 19 36 9c 6a f1 42 90 1a ed 76 85 23 b3 b5 98 40 78 a5 79 2c 1b f9 f7 b7 63 df af 01 2e 59 ad 9e 3c f1 00 11 5b 27 62 1c 2a db 1d 56 9b 23 30 a8 40 0e 7f a8 fd 0f ff 12 be 19 d7 63 9e ed 40 00 00 00 ec 3d 0b c1 6d f1 ec a4 a6 c1 67 03 5d 36 1f 0f 58 4e 70 c9 5e ef 21 6e 4f 90 65 30 5c 98 1d a0 b6 e2 0e 20 5a 55 ba 0a d8 4a 05 c0 5e 86 ea 46 70 26 d9 dc bb d8 b3 72 c1 07 f9 75 03 39 6d 97 (REG_BINARY) "2B5D9B7FEC2D58A6C20F022454BDC0719314356E3C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 95 f9 d1 2e d9 c3 8b 73 a8 b0 79 34 eb 10 2b 3c 02 0f c3 c2 36 85 56 8f 1b c2 74 87 11 54 4f 51 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 77 f4 e3 d1 5e b0 77 f6 71 04 74 e5 ac 35 9a 43 c0 5d b0 78 51 12 e8 bb a9 f9 ee ca e6 7e 24 b5 80 00 00 00 d9 ff 6f f2 3d 9f e3 2e a9 ed 8e c9 26 ba 99 98 b5 dd f3 8c 90 4b 86 66 e5 93 c4 50 9e e4 3a fa 9e 1d 52 4f 0c 53 e2 9d 32 8c 8c 3f da 70 a7 ee 47 30 9b bf 20 b2 03 73 90 bb a3 07 5c 6f 99 d8 58 95 cd a9 f1 27 32 cb 93 2f 7a 21 62 3f 1a 03 96 b4 d1 cd 7b f3 4f fe 74 93 29 5b 39 73 c6 fe 11 26 f2 0f 98 b6 d7 15 4f 11 50 e3 85 c1 cf 37 bd be 18 1f 00 4c d8 92 55 6b d6 20 ee 94 a7 b0 40 00 00 00 71 0b 57 97 99 5d eb 4b 66 41 d0 24 71 f3 13 ee b4 a4 a7 10 0d 5b 27 72 d8 8f fe 80 a5 8b 4d 25 ae e6 85 f8 fc da fb ee 46 68 3b a0 0a 37 1a 73 0e cd 26 0a 07 b5 12 01 78 20 a9 bd b0 68 d4 (REG_BINARY) "F1E2945585FB1D924A01AF0BBECA1AB77310173B1E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3a 4e 7d 86 b7 7a 23 3a 8a 50 87 b4 79 e6 d9 ff bb 4c e8 54 5c 28 8c e5 18 b0 24 c3 d9 98 48 c9 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 b8 fe c9 95 13 be e1 25 da b0 0b 9f 83 4b 9b 57 77 08 04 ad 5e a5 7d 1e 15 81 40 8e 7e 4f 8b b6 a0 00 00 00 d2 f9 0a e5 b0 ed f1 cc 28 fa a6 2e 25 3b cc 07 1a 02 b3 0f 25 ad 0f bb 30 7d a6 9a 67 1b c7 52 9e 8a a7 85 d0 dc 3a 4e 39 c9 fc f4 db 8e 6e 14 d3 63 ce 52 4f 26 9c 24 be ea 85 6f bb a2 bd 77 8f ef 46 f3 1f 12 fb 87 6b cc 77 ef fc 8a 37 5c 21 b0 2f dd 5d 08 a2 68 3f a0 6c 20 43 30 1f 49 97 0e b4 77 22 f1 17 8f db 04 9e 4e ab 70 38 dd 27 9d 2a 98 22 f2 9e 05 83 83 04 c6 fa 45 cf 4a f2 18 bf 15 73 b9 0d 7e d8 81 ae 34 75 4f 46 4d e6 c5 5f 4e 3c ea ce f4 32 b9 70 ae da f6 7e ea 40 00 00 00 58 36 19 3b d9 c0 70 12 98 af 4a 9a 1f 0a f6 d0 c9 b3 3c b6 ec 9f 73 65 67 13 16 28 aa 9a f6 (REG_BINARY) "3A1A5DAC28DF0ACB8FFB59A5115A14F42A714E0E2B"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 d8 5b 3c 5f 1d da 33 a9 c8 7e 84 a8 67 e0 89 71 86 5d d0 09 99 a9 19 5e 17 65 cd cf 27 ac 10 bc 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 b9 81 5e 6b eb fe f2 8f 46 58 6c cd 16 a6 7b 58 e2 e6 79 be 45 19 83 c6 42 9b 02 99 69 bd 19 10 50 00 00 00 c5 28 71 b8 5b 78 d3 00 c8 73 fb c0 ed 76 24 21 70 e5 a5 9a ae d9 33 7b bd 34 1f a5 ba a8 0c 42 62 20 76 21 dd 23 31 0f 38 87 ab e7 dc 70 0f 5e 6b 01 69 40 89 b5 3f f6 39 d0 fd 25 23 6b b6 dc 5b 56 02 0c af fe 33 32 22 cd d9 46 0e 48 16 e8 40 00 00 00 3a f9 76 72 5a 14 63 60 79 36 32 9e 5d 10 25 44 fc 85 47 1b 5c 1e 24 4d d1 b8 68 cc 58 4b 4a 6b b4 07 3e fa 1c 1c 3d 9b 75 f3 5e 33 d5 91 b7 2b 10 5a a3 5c 2f 99 80 bf 66 cf 95 f9 0c 0a 59 89 (REG_BINARY) "32259F446D4B75F2968EE3A1FD0C9653CFBA85BFC0"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 e4 ba f7 e5 22 21 6d 04 e9 e7 2d d9 a8 aa 88 b6 39 35 02 bb e4 be 77 8e f7 20 09 02 26 9b cc b1 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 6e df b0 49 40 0d 3c c8 c5 7a 45 eb 2b d6 72 b5 7c 6d 24 53 2e e7 5c 06 6d 4f 00 70 7b ce a2 ea 40 00 00 00 8e 57 5f 44 c0 9d 8f 08 2e ee fb 76 f7 9d 43 af 09 2c 6c 95 c4 5f 76 16 e8 93 d6 cc 24 dc 74 6d 08 ff 2c 51 04 d9 10 a3 aa 09 af b4 91 b9 f5 78 0b 8a 50 7a 0b 48 36 c1 66 5b f2 1e 4a 5b 8f 1d 40 00 00 00 9e 88 da 67 39 d2 f9 6f f3 b0 42 c7 7c 98 74 c9 b4 b6 b9 f1 de cb 0f 2a 0c 41 8a 51 e0 4a 29 29 1d 54 0e 1c 73 82 fa d8 20 be 05 38 3c 03 5a 8a 76 e2 c1 14 1d f0 90 c8 9b 0e 9a 76 6b a1 05 fa (REG_BINARY) "9700E94438D3AEAA6D6955EDB5B6FC4EBDE8A11D57"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 00 6f 5a ed 4c 7c 4e 93 0b df 55 9a e2 65 b0 9a 70 51 51 8d 8f 7a 0b ff 96 14 41 18 bf 7b 4e 5e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 23 e5 20 f3 05 90 9b 04 f0 46 c4 21 fa 04 fe 93 76 c5 e9 b2 b4 3c 4f e2 ca a5 ee 3b 73 da 0d cd 50 00 00 00 cf 1e a6 4b f5 3b 3e bd f1 0b 24 3b 42 6f 75 f5 87 c2 98 b2 3d 68 16 38 72 df d9 40 94 99 9c 4d e5 56 4a a6 ff a4 72 3a 58 80 be d0 42 fd 29 bd af e8 6f 2f 57 ca 3f 65 40 46 ee ed 60 54 58 d1 80 66 a0 57 17 53 08 9f 25 36 bf 01 a7 34 05 da 40 00 00 00 60 4a 02 44 24 a6 b8 b0 98 10 5a fd 25 18 ec 03 78 0e 61 0b 12 fa 88 b0 7a 2d 66 54 0e 54 66 d2 39 98 65 00 61 73 df d1 d4 36 6c be 4d c4 16 d7 82 e7 63 96 58 f3 83 41 a3 4b a9 f6 bf 9a fc aa (REG_BINARY) "D7883309B1B98AFBAD651E958876B1E5C1C454E29E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 14 03 e4 af ae 21 b4 95 da a6 cd 1d ba 00 fc 34 6a d4 d9 88 88 ad fe 7a 16 68 ce 96 3d d1 f4 b0 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 69 ef ed 60 58 72 30 ba 85 c4 85 64 ee 55 a4 7e b4 3e 3f 16 01 c5 bf 28 83 10 12 0e 86 c1 49 91 60 00 00 00 56 ec df 7e 31 90 9a 8e 78 fc 9d aa 28 bb 55 88 86 fd 74 5d 37 2e 37 11 e2 b9 39 f1 87 98 8b 60 84 39 4e 26 a2 93 8d bb 7f 4d 76 8c 06 f3 79 12 c4 0e fd 6c 3b fa 81 45 5d 52 d9 6a cc ef 8d 46 26 39 c7 0c c0 b9 34 17 9f d6 37 02 16 ca bd 7f 04 ae 7e 73 02 d9 a2 ed b8 95 e9 94 dc f1 f3 66 40 00 00 00 20 80 7e c4 9e ac 76 b7 bb 0a a9 94 4f 2e d8 36 1e 40 2d 52 82 4c 27 52 aa 44 6a 58 14 f7 29 55 bb 9e 3e a2 86 75 08 da 9c 56 07 b6 6e 3b 82 7a 3a d8 37 77 ca ab 60 95 8e 05 88 ba 36 a6 08 f3 (REG_BINARY) "4DE4260E881842D72B0374C044DFA586D1BCD14B77"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 8d dd 29 f7 7a 5b 9a c9 f8 02 bb f6 a7 a4 2d f4 9b 12 9f 35 71 2d 86 e2 80 03 db db f7 d5 2e 92 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 52 d6 34 41 23 2b 3e 80 26 68 46 db e2 0d db dd b2 a3 aa e9 bb f6 c4 23 ee 53 4e 9a d1 88 12 fd 50 00 00 00 ba 79 5c 6a ba 36 cd 94 a3 d8 7b 7d 7c 5b 3f 18 29 c1 6c fe 30 aa 4f 76 a9 fa 33 ac 9a 35 e4 33 06 2e cd 34 58 06 81 4d ac 5c da 09 c2 a9 11 31 a3 19 20 e0 36 8c 44 46 76 1d 3a f0 8a 1c 19 5d e1 84 ad 25 e1 fa 5f 3f b9 a9 0c af 6f f0 d1 5e 40 00 00 00 79 36 08 fc bc c3 2e 90 22 4d e7 de 18 08 f2 e9 13 a8 5b 86 30 c6 70 d8 4b ff 3f df e9 fd 19 8c 8a b9 bf 07 c7 0e b8 af 6f 7f ed 76 05 8e ed 36 05 72 67 a2 56 1b 8d 8f 2e ce 0b 44 0f 11 9e 9b (REG_BINARY) "C91CD10AED922E47D5EA6AAFFD08F901D0651F6A49"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 c3 08 1a 0a 83 27 f8 0c 5e 6e d9 56 42 b3 cb 7c 1b e4 cf 8a 52 e1 f4 27 71 6b e6 77 c1 ce 18 0b 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ed 90 89 dc 0a 52 25 e5 a2 59 57 42 c5 57 f8 af f6 a9 d6 43 ab 83 4e 48 aa c8 99 90 e4 5c eb 4c 70 00 00 00 a0 71 1c 17 8a 3e a6 56 15 55 e9 ce c3 be 68 6d 7e 87 8f 8e 89 2b a4 d0 e4 6e 8f 64 44 cb b6 b9 30 8f a9 c3 af f6 73 38 43 d1 58 13 4d 75 d6 ca 29 8f 53 da 59 03 5d 83 6b b4 b4 c1 3e 29 ef 67 96 34 a3 2a c5 fb 78 53 6e cd 86 fc 82 16 70 a3 af f5 cd bd 50 af a7 42 bb 01 81 5d 71 84 ca 3b d3 1e 24 0c 7d 99 d7 d9 d7 39 c1 67 69 fb b7 7e 40 00 00 00 80 f8 50 53 f0 a6 50 d1 14 a5 d7 86 96 8e dc 13 fb ad d2 64 b0 e8 fa f4 00 f4 d4 dc cc 18 9a 93 50 85 c5 9c cc 24 a5 64 33 d5 28 1a a9 e3 a9 5d 00 63 a8 b6 26 bd 34 d5 a5 75 8d ee ca 6b 7c a5 (REG_BINARY) "FFFA2924C66AF231499B3841AA2DC74100601BE434"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 5e ea 30 bb cf 6e f7 46 11 bd 0e 0b 58 78 f8 e8 92 55 2d 7b 06 9a 33 af 98 b7 ac 5e 94 51 20 35 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 37 8c 98 95 a3 fb 5a 5c 22 2c 0e 89 3d 92 12 e4 b5 03 9c 0a 3f 28 41 e1 c4 75 ad 4b 4d 04 3b 0c 40 00 00 00 22 76 18 1e 40 6a 49 96 fb 1a fc 33 08 55 f6 df 55 39 af ae 17 93 d5 ff 50 3e 24 47 17 f8 4f 3b 32 a3 de d9 3c ec d0 66 74 8e f7 16 65 37 ae fb 2a 8d 85 3b 19 08 6b fd bd af 0f 1e 75 18 29 b6 40 00 00 00 30 90 f4 63 06 89 41 d5 b5 d1 f5 20 49 a3 6c c2 fc f4 aa cb 23 ad 45 09 fa b1 4b cb 63 58 d9 41 0b e8 1e 05 4e fa c0 02 fd 86 67 4b e4 d7 9f e3 30 1e 63 cb b4 74 7f 80 dc 91 f6 00 32 97 27 a9 (REG_BINARY) "C9062DEE7E3AAD85824A03114AAB249397521F3DA5"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ff ab ee d2 25 e1 51 bd f6 f4 e0 d7 c2 44 14 cf c4 19 c6 d8 ab af 46 8d 2b 6a b6 ae 10 6a 65 c4 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 b9 8d 71 a1 c5 bf f7 b7 2f ba 48 86 0c 4a 71 5f 83 1e 18 f1 34 c1 03 71 64 70 95 71 b0 06 e4 4d 60 00 00 00 dd 85 b0 85 6a e8 7d d8 95 05 e9 7d 47 75 39 9e 92 5b b6 fc bf 4e 73 69 d6 c4 88 20 81 ae a0 20 97 34 b6 d8 4a cc 12 75 c2 a9 4a 48 49 ae 33 00 f3 50 97 9f 85 a0 2f 5b 07 80 1f ab b2 8f b2 39 40 bc 76 ba 56 ce d5 ae c3 b3 67 e6 46 f7 9e d2 2e e2 99 b0 15 41 3f 47 a2 af bf ad d2 1b f6 fa 40 00 00 00 7b 78 79 97 fd 98 a5 05 04 56 da 8f 1a 11 85 13 76 7f c6 0c 56 8b b9 77 56 c6 da b1 fc ab 2a 85 ba 80 02 d5 b5 41 af 42 74 3f 41 7a f4 9f e5 38 0c 78 d4 4e a9 8c b0 db 00 80 0f 2e 19 ea 21 a8 (REG_BINARY) "E3215E5922E11C5E0CFEFF708CF1E85CCC929AF55F"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 00 ca 71 17 79 f2 2c ac 95 7f ca ce dd ee 9d 1f 44 49 32 f8 1d 5d 50 91 b3 fe f5 6a ca 9a 91 6d 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 99 72 cc 05 8f 55 20 6f 94 61 d1 bc 14 1e 8d f5 06 8d 5a 21 8f 79 e2 96 50 2d 3b ac 9e 44 ee 7b 60 00 00 00 8f 70 92 67 6f dc dd f7 4f 10 9c 9b b6 d1 69 66 70 34 94 3a 00 89 80 e5 fa 16 38 3f 76 da 89 77 73 85 c2 5c 70 9c 80 ec 15 b2 29 10 55 89 c3 64 5e d9 70 1d b8 32 8c ca 11 92 68 b3 b5 2b 07 e6 bf ed 6c a3 35 20 74 34 45 04 26 0e 7b 04 cb 79 45 96 8a 0d 2b 64 2c a7 46 92 76 8f 6b c0 ca 3f 40 00 00 00 62 7c 96 54 4c 7f bc 9a 05 0b 51 5b ce 3f 74 1d 67 1b 46 4e 9b bb 41 26 b7 31 f9 34 74 27 c6 67 c6 c7 ac 7e bb 51 99 50 c2 0c 1a 11 6f 74 46 16 24 af 42 11 47 7b 7d 51 c5 0a 96 e9 c1 62 55 f2 (REG_BINARY) "33802FC307D8BE3623706BFBC50FF360E14E9A93F4"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3d eb e4 1e 32 9d 08 59 87 c6 61 c1 1d aa 33 f1 fb 06 8a a2 ad c8 20 55 d9 c9 7b 33 58 b9 59 d0 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 a6 f4 42 1a e1 7a 28 95 d7 35 dd 6d 61 7c 66 48 f1 71 5f 5d 95 a1 13 46 bd 4a b5 09 e3 17 44 85 50 00 00 00 61 cb 1a 0c 0b 5a 94 5c 50 be 76 df a6 f3 2f 7f 64 32 f1 d6 e9 fa f0 9e ad ab 8b e8 cc 86 fe ce 38 85 e4 15 74 20 30 27 39 9d 0c fe aa cc 80 4a b5 94 a1 0f 16 ff a3 fd 85 96 a0 8b 1d 65 a0 8a 80 39 bc 82 92 8a 2c 17 a7 73 d5 f8 37 92 48 b6 40 00 00 00 ab bd 13 51 4a 24 03 64 0f 09 b7 6b c8 87 2f e2 66 86 a0 fa f0 e3 c7 ce 5c 23 42 21 77 53 8b 09 89 92 b6 0b a9 73 8a 67 f2 cc e3 6b d0 ee c7 fb b9 82 12 ea dd af 29 39 f5 f1 6b 60 d9 9d 19 cc (REG_BINARY) "D43FA22B8ACC593CE9F35BFB24153E1252BA2D904F"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 78 60 a1 94 7b 27 f1 44 2a 94 46 70 0a 99 9d e4 4b 66 57 36 67 7b f5 4d 8c 5d 76 53 f5 16 0d 87 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 83 68 05 4f 2b 8f 2c cd 7a 34 7e f1 02 7b 76 94 bd 60 4d 19 e2 8c ba 93 43 2d 24 00 dc c5 26 e9 50 00 00 00 09 4e e6 c6 73 a4 af 7d 15 eb 2e c7 2b dc 7d 55 6f 49 1e 65 f6 2f 62 dc 6b 01 4b 36 0d ad 20 0c 2f bd b4 c6 75 bc 06 88 9d e5 9a f7 bb 5a 31 af 67 c0 83 b8 a7 cb 92 e8 b5 49 27 3f a4 3d 2e a7 60 27 26 5b 3e e0 93 e4 f6 af 81 7e 06 c9 d0 bf 40 00 00 00 68 69 09 cf da ec 21 39 6f 9f 6c ca 06 ca 68 6b 63 3e 17 ef 3f b8 bb 65 ff f5 37 72 17 e8 19 f5 4e f8 ed b9 fe b6 46 a0 ff 4c 66 94 6c d9 27 07 92 07 27 c4 49 d3 74 d3 96 eb eb ff b1 da 14 40 (REG_BINARY) "E1A9A82E434C82B6EAE2CE82465ED147531791504A"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 c9 26 79 dc b9 8d 1d d3 a0 6d 93 c9 41 db c6 69 ff a2 83 75 3a 40 33 54 e8 b8 0e 6e f2 fa 79 f7 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 9e b7 41 7b ad 87 65 90 6b 46 ac 59 f1 37 e5 37 6e 1e 56 21 8e f4 e1 20 66 bc bf da fc 02 67 14 70 00 00 00 f1 46 75 06 c3 b9 79 cb 33 c6 7e 44 6e 7f e1 4c 13 74 0a 0c a8 05 96 5c 6e 49 29 5b 11 7c 48 23 61 55 1c 34 5e 93 2f 3d f1 f4 be b3 76 fd 05 92 d6 13 c1 ad 96 e4 57 b2 75 7a 7d 66 94 8e 96 af 14 7e a5 56 64 6c c1 96 64 10 9d 86 f0 9f ba 4f 0f be c3 f5 7c 35 b5 88 a5 a4 09 bd d1 56 04 43 2c 41 e0 19 f1 45 bd 66 c3 33 db 50 5f af e2 d6 40 00 00 00 c3 c9 41 98 61 75 9a 00 c4 04 64 97 64 5f ed cd 0c 16 e0 55 49 1d 7d 7b 2e 0e 39 c7 7b 7c d1 d6 6a 99 cd 10 b3 f0 5e 07 13 73 48 26 68 24 9a 2c 62 a9 c5 9a 8c 9b d9 e2 6e 2b 1b 34 cc da 66 7d (REG_BINARY) "F6145C3E79E007DFBA4DFD252BD4D96C53A98EE3BD"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b0 33 cc 66 75 f4 17 74 b7 1e 65 41 f9 79 7e 94 20 f9 38 fb 8e 67 56 c7 3c c2 f0 c8 ce 0d 5a 5c 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 21 e1 b8 e0 71 f1 4c a0 0c 70 93 2a 36 4d c0 95 11 8e 12 68 7f b3 31 bb b1 05 c7 81 04 81 48 b8 60 00 00 00 a7 c5 81 d5 f6 a7 07 f6 ee 33 39 1f 7b 4c 30 20 43 33 54 fe 38 e7 69 f3 e0 c3 38 b4 be ee 80 c7 f9 fa d0 e3 4e 72 f8 57 58 54 f7 eb 1d 41 e8 68 66 74 9f 27 4f ec a0 0d ba db cd bf 24 78 42 c8 99 49 10 48 1b ca 56 f4 55 15 61 dd 5a 78 82 c2 f2 36 91 7a 7f fd 86 c9 ca ab 70 4c 9e e3 fe f8 40 00 00 00 c5 ae 89 e5 f2 c6 d4 0a b0 4b 26 3d 0d 16 a9 68 25 b2 6c 01 39 73 80 4a f5 16 48 f5 7d 6d c4 e2 8b af ab 83 05 97 d3 4d 1d 84 9d de 7d 08 e4 ef 4c 24 7d 9a 9f 85 71 2e fb da e4 ba 32 6a eb 6b (REG_BINARY) "74CF5A55DE86BEC85988D7B5023A29D5DED8AF02EA"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b4 51 b2 f8 20 cd 16 6c 10 e6 60 a5 a8 fb 82 b4 ce 15 84 14 c5 af 35 5c f6 d2 d5 6f f0 cc d3 9d 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 03 ac c7 28 ba b9 b6 06 7d 3e 67 b7 59 da ce ab cd 86 9b d2 9f cf aa 8a f9 e5 6c 27 6b 84 3e f2 70 00 00 00 db 13 20 d2 ab b6 1b 64 c4 92 e5 a1 a9 20 5b b1 f1 7d e8 d2 d6 97 4d 1e 65 b2 13 12 85 d1 b7 79 93 64 bf e6 f1 e3 26 b8 7d 29 c0 6a ee ea ad 00 73 d2 8c e2 cb 5d 8d 36 4f 9e 18 d2 2a 2a f5 9c ea 2e b3 6b f9 3d 2f 16 ee 72 85 a0 79 15 39 16 b9 b7 c3 9d 1f dc 3b 3f 6e 47 eb 86 f0 5a f7 6e c1 00 18 d4 39 9c 4f 12 6a b8 a1 3f e8 dd 46 da 40 00 00 00 3e cf 30 9e ad 3f 7d ac 6a 35 88 bd e8 79 b6 3b d0 8b 06 9c d4 6a cf 81 14 b3 3c c0 59 cf 4d e0 db 0a 1b 5f f5 eb 51 b0 79 c5 84 c0 c6 e8 55 d8 5d 56 bf dc ff 4e 82 4a f4 9a e1 72 ec 7b ca 15 (REG_BINARY) "4609967E23E6BA2CCA5C6B292E54CD8484EA0867BC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 58 a9 dc aa 12 e8 c1 eb aa 11 69 21 b0 52 ab 80 69 4e f5 8e 5c 20 72 d4 13 c5 1e 73 ce 8e 61 46 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 91 95 03 2a fa 31 f1 cf ec bf 3e fc 81 8e 09 df e8 98 22 31 88 1d 08 4b 64 f1 a9 d9 64 42 9a f7 60 00 00 00 56 79 06 1c c8 36 02 c9 2f c5 58 53 b9 8d 19 37 bb 48 b0 70 3f 63 83 eb b4 35 8e bb 65 d9 ec 3b 53 d9 1b 24 97 49 55 d0 d7 f8 59 7c 98 43 a5 8a 17 e4 52 a7 99 1c d1 ba 3f 0d 72 01 e7 bb 5d 04 04 df be 08 c5 4d d5 f7 11 31 57 5d b8 f4 b1 46 22 54 4e cb 69 9b c8 6e d5 ae a6 03 7e fe dd a8 40 00 00 00 17 92 be bb 1b 52 39 c8 0d 1c f6 dc b0 00 d0 59 90 f2 1e 28 71 50 33 0b 55 0e ed f3 45 be 19 a1 6d f0 fb c1 6a 21 be 2d 4f 91 bb a8 fe af 92 59 ef 4c 3d e5 b8 3f a8 cc b5 c4 05 6e 7b 88 75 11 (REG_BINARY) "0CE5F1B4C5BC1884C7FE398173D12A11DBA732E54A"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 75 24 67 41 0d 05 de 2d 52 31 ef e9 a3 9e ee 1c 94 3b 76 91 1b ed e6 d2 57 73 0f 87 37 a0 a2 2b 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 5d e5 38 8b 43 a5 ab 15 d0 65 3a dd 24 31 12 7c 34 bf 6f 0c cc e8 eb 3c b8 f5 b1 2d 5f c6 dc 43 e0 00 00 00 6d 6e a1 01 c2 1c 9d ef e1 65 bd 41 36 3e 8f cc 30 38 91 e0 35 a5 6b a2 1c 7d cc 20 9b 67 31 98 18 81 3f 04 53 00 c0 4c 94 f8 47 53 b1 73 04 73 dc 85 e2 1d 0d ed 25 95 26 b1 0b 77 f1 45 1f b5 a2 ad 1e 8a 12 35 d0 7b c4 53 35 fd 3a 0a 85 e7 13 52 a7 65 75 44 1c 47 00 0a a8 0b b4 90 8b b1 5d 7f 7e 83 67 fc b0 b4 01 88 78 b7 90 33 f1 30 c5 30 b0 d0 b2 68 c9 d8 0e d5 a8 98 54 55 a3 71 05 20 5a a2 0c 92 e5 81 0b 6e 06 c8 21 97 b9 51 6e 84 b4 d8 f2 fd 9e 31 fd a6 c1 03 9c 0d bd 77 33 8a e9 af 99 9b 65 95 36 01 96 ae 90 f5 a8 07 30 a7 15 c3 37 5d 92 ae 41 d4 99 4a 15 c3 51 1d 64 27 f1 (REG_BINARY) "04E550A815712535D3C4C3F8FDAFC1E8A95B3E8D37"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8e d5 05 4b 23 8e 0e 48 9e 87 56 5a b7 3a ed 67 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 d4 d0 c9 00 b3 4d bf 42 ea c9 f6 ff bd b4 5c a6 e8 c6 e6 97 68 a9 09 62 9a 0d 53 82 90 f4 2d ad 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 89 dc b1 94 49 aa 1b cf 12 71 f7 8f 86 00 cd fb d7 0f 3c 98 2b 9e fc 80 01 ef 9a af 90 d1 dc d0 60 00 00 00 4f e8 25 06 e3 cd 6a ce 24 6c 4d 20 75 61 fe 29 61 1b f6 3e 89 bc 6b a0 6a d8 17 0b 93 bb b1 13 09 e2 1a 2b d0 e3 7f d8 aa d2 99 ae dc 4c 9b fd 62 9c dd b2 78 7e 51 4d c1 d7 e8 88 9a 1f 5e 48 f0 c2 a9 74 29 60 9e 29 5a 39 8e bc 1c 33 31 d6 7b 23 1f f7 ea 9f 75 b2 18 bf c0 ab dd 6f e0 f1 40 00 00 00 97 4d 1a e0 ac db 26 40 f6 5d 94 39 a9 70 3b 05 86 54 fa 1c f6 ac 89 1a 24 65 73 bb 72 ed 61 c7 53 16 f8 0c 75 4f 6e ab 4c 62 58 9b 56 ca c6 10 81 7a cd 1d c5 ac 7c e1 de c6 cd f8 11 cb e9 f5 (REG_BINARY) "C625BBF0A44848A848212DEBB4F79650F0F01E6EF0"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ee 28 c3 7a 9c d2 d9 e8 dc 0f 77 1b 90 c5 1d 7e c5 a3 21 6b e1 46 be ab 1c e4 9d ef 67 c0 89 60 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 90 ae a3 99 c6 28 bb 18 b7 2f 2d 9c f5 97 aa d9 9d 85 99 78 db 61 8b b0 a9 19 15 08 83 ee 9e 31 40 00 00 00 bc bb 80 41 7c 1a 71 10 96 c0 19 af 55 52 cb a4 58 9f be 0b 6c b7 02 ad 7f c7 2c a2 d4 e5 dc 4b 69 fe 9d f0 3f 53 45 2d 8c 6d 4e b7 3e 1a 3b 97 2e 3d 06 50 3f 57 8d bb 63 58 29 f1 3c bf a4 98 40 00 00 00 ef ed b5 a2 f3 2d 91 09 12 d0 29 b7 87 22 80 67 62 5f 25 f3 98 cd 67 33 e8 4d a3 2b ac fd 20 28 32 60 a3 57 0a e1 ff 91 1b 8f 7d a6 53 fa e7 b4 a3 7c 7a 8b 5a 69 e7 1f ec 3e ff 35 53 f3 3d 97 (REG_BINARY) "B8CB6B3DE866F2FD1F17996FEE01CEC4748A03E810"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 2e 5d f1 3c 8a db 92 24 9e f9 28 db 89 77 1d 47 d1 20 37 48 af 41 7d e7 ca e0 2c 2e 8b ac 93 0e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 5e 80 0b b9 98 75 53 5c 56 05 ad bb 48 fb 6b a1 ab bd 37 75 ef 8a 14 ea 4a dd 71 8c f2 05 87 b0 50 00 00 00 97 69 6a 40 b0 7c d0 7e 88 33 07 7a d9 34 cc cd 5f 8e 30 61 ad f5 72 b3 af bb ec bd fd 74 76 0d 7b 6d 8d e7 a8 ff f4 09 56 c0 69 52 fb e3 12 07 1d d4 a5 4c 3d 46 3e f2 9e 3b 06 cb fc e3 df ef dc d1 31 36 82 9e 62 e4 62 37 13 ff 75 9d 2b 02 40 00 00 00 21 c8 eb f2 a0 93 a8 a6 de 55 c9 63 ed 0f 87 f0 3e 77 ef 42 a3 35 5a 2d d0 97 87 1f 1b a2 d3 8e 3c 55 77 00 17 09 37 c5 c0 e5 a2 d7 88 3a 06 8d 85 b4 0e d5 ab 29 3c 8a af bc ca 2a d9 df f9 55 (REG_BINARY) "A6EB104D7914E611C8994C43DD7044A32569CD0EFF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3c 4a ed 13 33 41 f1 85 2f 2f ea 2e ec 34 77 d4 19 81 5a bc 2c 0f e1 fb 45 16 a8 d5 26 07 50 18 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ff 25 5a 5a bf 12 d5 2c ab 7b cd f1 7b 91 d4 7f e7 6e 09 81 b6 4c 1c 69 3c e5 5b 6a f6 d3 16 e2 50 00 00 00 bf 9e d8 02 49 8d 7d 34 f7 59 55 e2 8a da 8a 9c 16 e1 51 07 d8 8f ac 19 b2 71 db 07 d6 f2 1f c3 28 e0 76 41 75 7e a2 5b b5 fc 85 c6 c7 87 a0 b1 98 fb 95 c0 d8 62 dd b2 d6 11 37 0f 7d 7c c7 28 c0 40 1f 84 d9 75 ad d4 55 ce 39 26 06 bf 19 56 40 00 00 00 a6 3c bc 81 7e eb f0 65 54 4c e1 f1 7c 73 ec 59 dd 9c e9 8d 6b d6 9f 22 34 c7 04 9a b5 c5 b9 ce 57 55 76 4f 7e 95 38 35 66 38 cc a1 ac b5 d6 27 df fa 76 43 f4 22 5f 35 7b 80 f5 d1 c8 34 ef 06 (REG_BINARY) "9B0711DD64BFAFDB50CE97C460B59EBF89920695DE"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 21 d8 7b e5 86 27 cc ec 8f cd ee 9c b6 7a 6a 54 9c 45 bc be 21 d7 98 94 4a 77 de 01 ed 4d 50 05 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 04 a6 a3 9c 14 f1 4e b5 42 2b b2 a8 83 41 3a 6a 24 3e 62 9d 0f e7 2c e5 ab 84 88 dc e1 85 f6 80 50 00 00 00 97 81 1a 71 f9 6d 18 23 15 4f 00 c7 00 60 63 3d b7 19 65 19 66 3f 5a 70 dc 81 69 7d 2c 31 52 01 39 38 b9 a3 db a2 1a bd 06 6a 3c ac 4b b8 a0 af 03 f3 c8 27 ac 41 8c 68 41 d8 6e 37 cf 77 fd c9 56 6b bd f5 38 22 cc 0d a8 42 22 62 ba 3d 9c 1b 40 00 00 00 0c 12 d4 7f 37 8a be 8f b5 b1 d3 25 c2 2d eb b6 10 0e 32 47 eb 80 d7 3f e8 75 14 20 dd 6e 63 05 08 3d 01 e9 ef af d3 7e 28 57 5e 75 30 ec ef d8 3a ac b3 4a 5b 3d 7d 5a b4 ac f1 78 4e f5 9c 02 (REG_BINARY) "9220068F01E11F7898C5DB3230434E7A7B99260DAC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3c 9e 64 9e a1 d8 ed 45 53 c4 70 15 b4 a3 01 d4 65 a1 ee 8d 9d 96 85 63 d0 2c 0f 9d d2 94 41 a9 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 c9 dd 3b bc d0 14 0d af ff a0 0f 57 90 c4 8f 43 a6 1a 04 11 30 89 cb 27 2c 3f 69 b3 92 81 81 e3 60 00 00 00 15 2a 48 0a 01 24 54 42 a4 12 7c 59 a2 96 43 f1 61 c1 f5 3f fd 23 73 bd 7a 57 51 7b 51 4d dc 74 88 f2 4d d3 f1 a0 56 9d 49 8a 29 a4 3b 92 d1 3e 97 81 5a 9b a1 93 18 70 aa a7 6c 4a ab fb 09 63 6c 2f 2c 07 4c e6 66 4f fc 92 75 47 bc d2 13 cc 0c eb df 8c d3 56 bb e6 40 0d 68 3c 90 8d cc b3 40 00 00 00 19 d6 23 4e 6c 31 ff c9 f8 5f a8 60 0d 65 e9 37 e8 56 e3 b3 43 34 43 e9 0f 7f 5c 48 ac f0 72 2c 0b fc 6e 05 46 42 ee a9 10 cd e1 55 dc c1 4c 20 73 70 cc 06 47 c7 b2 81 99 12 c4 c3 f2 1f c5 b7 (REG_BINARY) "1D850C0E1C604DE03CB4CC154F67A2CFCE11681BBF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 5f d9 89 9f a4 a9 f7 b8 fa 9c 56 99 be b0 50 12 7d 13 87 0d 58 bf e1 2f 8d b0 c5 bc 18 9c 31 ce 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 df b8 00 76 90 76 5a cc a6 20 66 b3 cd 7d 5b 68 0b 0e 19 2b ee e6 90 b3 95 1a 0b 35 f5 b4 12 b3 60 00 00 00 31 5e 78 84 77 28 0c ee b6 fc 70 00 55 c6 e3 62 eb 1c 3c 8a 13 b2 58 4d cd 55 0a 90 42 ee 9a cf 52 2c 98 a5 ee 59 29 9c 8d 1e fa b5 75 84 8f 5c 1e ed 9e 2a 6a 07 7b 94 7f 6b 25 86 20 36 2e b5 49 ed 3e c1 dd a9 1d 09 60 d6 82 cd 92 ec 8f a8 2f 6d e6 85 33 5b f1 29 3f 8b d7 f7 a4 19 1d 0d 40 00 00 00 0b 33 ed e8 23 95 ec f3 61 0c ac 71 96 f2 a7 8d 28 99 df 9b 33 1d a7 78 56 64 7c 6f a6 4f b2 5b 94 8d c3 50 fd 7c 45 17 5a 68 64 70 93 07 ba 54 0f 03 81 41 81 51 ba 05 9c 3e d3 10 9d 9b 72 37 (REG_BINARY) "95EC8654092CE24121C49BFC33AC064C32236A1837"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8e d5 05 4b 23 8e 0e 48 9e 87 56 5a b7 3a ed 67 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 13 f5 f5 36 97 09 8f 7e a0 d5 f0 54 34 ea 23 e5 0b 07 dd 92 c7 b9 07 f0 95 81 db 39 41 15 28 e8 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 35 58 70 99 f6 88 f1 37 f3 97 70 1e 53 3a bf bc 76 d7 09 bd d9 8d 37 ad f7 86 a7 b7 9e 60 af 8c c0 00 00 00 a1 b5 d8 87 94 44 11 fc 20 7d 94 a4 d0 61 8f 9b b4 4f 85 9f 3b 0c 84 9c 9b b4 3f e5 81 b9 35 2a 70 92 e2 cc 4a 0c 25 23 fe d1 84 e7 48 8f cd 90 c6 0e 85 08 e7 6a 07 47 4d 48 cc b5 72 83 9e cd e6 c8 8f 8d b5 fe f6 63 af 83 b1 b7 b1 d7 d4 49 94 9d b3 9b 16 0f 74 7b 1c 2c 80 bb 7a 7d 66 08 63 c8 20 f7 7f 43 0e 0f 47 b8 9e 5f 6a b7 9f 29 19 f5 2f 71 26 2c 45 10 9e 45 a4 86 d4 de e4 a4 ff 96 92 2c 17 35 48 cf 34 9c d8 90 97 a0 c5 3e fd 86 28 f5 70 67 13 61 7e c1 32 5b f4 90 35 c8 2e f6 36 e6 d3 2d f5 35 b5 d9 92 a7 da 62 b4 bb 2c 71 11 43 0b 11 90 96 36 ab 72 c3 bd 8b 5e c1 40 00 00 (REG_BINARY) Quote
debi239 Posted February 5, 2013 Author Posted February 5, 2013 It would be much easier to attach it but I'm not sure how could you explain please. Thanks Quote
debi239 Posted February 5, 2013 Author Posted February 5, 2013 OTL logfile created on: 2/5/2013 12:01:27 PM - Run 3 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Deb\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 8.0.7601.17514) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.97 Gb Total Physical Memory | 2.09 Gb Available Physical Memory | 52.60% Memory free 7.93 Gb Paging File | 5.85 Gb Available in Paging File | 73.71% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 116.44 Gb Total Space | 26.65 Gb Free Space | 22.88% Space Free | Partition Type: NTFS Drive D: | 337.60 Gb Total Space | 87.33 Gb Free Space | 25.87% Space Free | Partition Type: NTFS Computer Name: DEB-PC | User Name: Deb | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Users\Deb\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.) PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe () PRC - C:\Users\Deb\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) PRC - C:\Program Files (x86)\lg_fwupdate\fwupdate.exe (BitLeader) PRC - C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company) PRC - C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft Inc.) PRC - C:\Program Files (x86)\Pando Networks\Pando\Pando.exe (Pando Networks) PRC - C:\Program Files (x86)\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.) PRC - C:\Windows\AsScrPro.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe () PRC - C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe (ASUSTeK Computer Inc.) PRC - C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe () PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.) PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe (ASUS) PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.) PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe (ASUS) PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\Atouch64.exe () PRC - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.) PRC - C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe () PRC - C:\Program Files (x86)\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.) PRC - C:\Program Files (x86)\Webroot\Washer\wwDisp.exe (Webroot Software, Inc.) PRC - C:\Program Files\ATKGFNEX\GFNEXSrv.exe () PRC - C:\Sierra\Planner\PLNRnote.exe (Sierra Online) ========== Modules (No Company Name) ========== MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ff7c9a4f41f7cccc47e696c11b9f8469\PresentationFramework.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\19b3d17c3ce0e264c4fb62028161adf7\PresentationCore.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll () MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll () MOD - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe () MOD - C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe () MOD - C:\Program Files (x86)\ASUS\VirtualCamera\virtualCamera.ax () MOD - C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe () MOD - C:\Program Files (x86)\Webroot\Washer\Languages\English.dll () MOD - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll () MOD - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll () ========== Services (SafeList) ========== SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation) SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation) SRV:64bit: - (ATKGFNEXSrv) -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe () SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated) SRV - (FBDiskOptimizer) -- C:\Program Files (x86)\FixBee\FBDefragSrv64.exe (FixBee., (www.fixbee.com)) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (RealNetworks Downloader Resolver Service) -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe () SRV - (Akamai) -- c:\program files (x86)\common files\akamai/netsession_win_ce5ba24.dll () SRV - (Kodak AiO Network Discovery Service) -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company) SRV - (ADExchange) -- C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft Inc.) SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) SRV - (FastBootAgent) -- C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe (ASUSTeK Computer Inc.) SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) SRV - (YahooAUService) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.) SRV - (ADSMService) -- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.) SRV - (wwEngineSvc) -- C:\Program Files (x86)\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.) SRV - (Crypkey License) -- C:\Windows\SysWow64\Crypserv.exe (Kenonic Controls Ltd.) ========== Driver Services (SafeList) ========== DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG) DRV:64bit: - (PCWinSoft) -- C:\Windows\SysNative\drivers\scrcamnetdriver_x64.sys (Windows ® Server 2003 DDK provider) DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation) DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (DigiartyVirtualCDBus) -- C:\Windows\SysNative\drivers\DigiartyVirtualCDBus.sys (Digiarty Software, Inc.) DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.) DRV:64bit: - (AnyDVD) -- C:\Windows\SysNative\drivers\AnyDVD.sys (SlySoft, Inc.) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation) DRV:64bit: - (FARMNTIO) -- C:\Windows\SysNative\drivers\FarMntIo.sys () DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation) DRV:64bit: - (AsDsm) -- C:\Windows\SysNative\drivers\AsDsm.sys (ASUSTek Computer Inc) DRV:64bit: - (L1E) -- C:\Windows\SysNative\drivers\L1E62x64.sys (Atheros Communications, Inc.) DRV:64bit: - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( ) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation) DRV:64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.) DRV:64bit: - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronic Corp.) DRV:64bit: - (lullaby) -- C:\Windows\SysNative\drivers\lullaby.sys (Windows ® Win 7 DDK provider) DRV:64bit: - (SiSGbeLH) -- C:\Windows\SysNative\drivers\SiSG664.sys (Silicon Integrated Systems Corp.) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation) DRV:64bit: - (AmUStor) -- C:\Windows\SysNative\drivers\AmUStor.sys (Alcor Micro, Corp.) DRV:64bit: - (SNP2UVC) -- C:\Windows\SysNative\drivers\snp2uvc.sys () DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ATK64AMD.sys (ASUS) DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation) DRV:64bit: - (ASMMAP64) -- C:\Program Files\ATKGFNEX\ASMMAP64.sys () DRV:64bit: - (SCDEmu) -- C:\Windows\SysNative\drivers\scdemu.sys (PowerISO Computing, Inc.) DRV - (AnyDVD) -- C:\Windows\SysWOW64\drivers\AnyDVD.sys (SlySoft, Inc.) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) DRV - (NetworkX) -- C:\Windows\SysWOW64\Ckldrv.sys () ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = about:blank IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes,DefaultScope = IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://www.google.com/ig IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = about:blank IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D6 0A A2 81 91 98 CB 01 [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKCU\..\SearchScopes\{0169E633-8781-F882-9BC7-7B014AE4DE4E}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=Z206&form=ZGAIDF&install_date=20111005&iesrc={referrer:source} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKCU\..\SearchScopes\{4A7BC363-1B1A-469A-8A9F-B08D6190106D}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=685749&p={searchTerms} IE - HKCU\..\SearchScopes\{63EA0726-C83D-C02E-CF27-0160BA4048EB}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=ZUGO&form=ZGAIDF IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS409 IE - HKCU\..\SearchScopes\{7B778A05-D20F-5F8F-66DF-EA2ADE1B9C35}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=ZUGO&form=ZGAIDF IE - HKCU\..\SearchScopes\{7C19EC30-6FAD-B9F6-82AA-0C5189279B17}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS409 IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS409 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local> ========== FireFox ========== FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer) FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/28 07:33:53 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/18 08:19:49 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/28 07:33:53 | 000,000,000 | ---D | M] [2013/02/01 05:54:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions ========== Chrome ========== CHR - plugin: Babylon Translator (Enabled) = dhkplhfnhceodhffomolpfigojocbpcb\1.4_0 CHR - plugin: Error reading preferences file CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\1.0_0\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\4.0_0\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.4_0\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpcpcabjajdjmbkfinphfdflfipmalnj\1.0_0\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.6.0_0\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.6.0_0\facemoods\ CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\ O1 HOSTS File: ([2009/06/10 15:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation) O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll (Google Inc.) O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation) O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader) O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found. O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.) O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files (x86)\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited) O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc) O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation) O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation) O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found. O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.) O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {22E03916-85C5-44B0-8DC9-1830C11238D9} - No CLSID value found. O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (AlcorMicro Co., Ltd.) O4:64bit: - HKLM..\Run: [EKAIO2StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKAiO2MUI.exe (Eastman Kodak Company) O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.) O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [igfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation) O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS) O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [Conime] %windir%\system32\conime.exe File not found O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS) O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA) O4 - HKLM..\Run: [LGODDFU] C:\Program Files (x86)\lg_fwupdate\lgfw.exe (Bitleader) O4 - HKLM..\Run: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated) O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [updateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.) O4 - HKCU..\Run: [] File not found O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Deb\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.) O4 - HKCU..\Run: [MimarSinan Rubber Ducky Update Setup for All Users] C:\ProgramData\{C357FF4B-BB69-4DC2-9869-55F052974DA8}\Rubber Ducky.exe (MimarSinan International ) O4 - HKCU..\Run: [Pando] C:\Program Files (x86)\Pando Networks\Pando\pando.exe (Pando Networks) O4 - HKCU..\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.) O4 - HKCU..\Run: [Window Washer] C:\Program Files (x86)\Webroot\Washer\wwDisp.exe (Webroot Software, Inc.) O4 - Startup: C:\Users\Deb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files (x86)\ERUNT\AUTOBACK.EXE () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found O8:64bit: - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html File not found O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html File not found O8:64bit: - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html File not found O8:64bit: - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm () O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html File not found O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html File not found O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html File not found O8 - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm () O9:64bit: - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files (x86)\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE_x64.dll () O9:64bit: - Extra 'Tools' menuitem : Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files (x86)\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE_x64.dll () O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16:64bit: - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} Reg Error: Key error. (Reg Error: Key error.) O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus.com/select/asusTek_sys_ctrl3.cab (asusTek_sysctrl Class) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37) O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} http://imikimi.com/download/imikimi_plugin_0.5.1.cab (Imikimi_activex_plugin Control) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FFE16A46-948F-4F90-964E-E3E86D151408}: DhcpNameServer = 192.168.2.1 O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\ms-help - No CLSID value found O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\System32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 30 Days ========== [2013/02/05 06:42:20 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E3756A3F-B05C-4224-9CBD-BBAE953FF279} [2013/02/05 05:04:05 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Deb\Desktop\OTL.exe [2013/02/05 04:52:48 | 000,000,000 | ---D | C] -- C:\_OTL [2013/02/05 04:37:03 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT [2013/02/05 04:35:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT [2013/02/05 04:35:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT [2013/02/05 04:33:08 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\Deb\Desktop\erunt-setup.exe [2013/02/04 18:41:45 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{FE96027B-A669-40AD-99A0-36E5122AF23F} [2013/02/03 04:21:30 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{57F1C703-D27F-4A5F-BE56-3776BC2A973E} [2013/02/02 09:31:42 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\ArcticLine [2013/02/02 09:31:06 | 000,000,000 | R--D | C] -- C:\Users\Deb\Desktop\OTL [2013/02/02 09:17:19 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{EDD7F6B1-436A-4ABD-832B-59ECF22C6960} [2013/02/01 17:25:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{42234831-8B08-43B1-96A6-6045FEE150A9} [2013/02/01 07:38:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013/02/01 07:37:59 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2013/02/01 07:36:21 | 010,156,344 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Deb\Desktop\mbam-setup-1.70.0.1100.exe [2013/02/01 05:25:08 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{95CF7132-8491-4CD2-9E5E-97B82B87D47A} [2013/01/31 10:01:41 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{5047659E-C3FF-4879-99C3-07F8CA609FA6} [2013/01/31 08:33:24 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{0287C327-9C05-46BF-B7A1-9086769A2D0C} [2013/01/30 08:59:26 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{0731825A-EC4A-41FA-8E38-BAD4E1A1B061} [2013/01/29 08:42:50 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{553FB952-2015-4903-A09D-4F0E26A63C5E} [2013/01/28 08:41:45 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{A1A41F13-03AE-4BBA-A4E2-D4A593DF6E31} [2013/01/27 09:26:47 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\Malwarebytes [2013/01/27 09:26:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2013/01/27 09:26:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2013/01/27 09:25:33 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\Programs [2013/01/27 08:40:52 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E65F738D-9443-4971-9352-F66A692643C4} [2013/01/24 19:47:50 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{740A36B2-621C-4272-845E-DF12E99C78C1} [2013/01/24 07:47:23 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{6B52BFC3-84B8-4BC2-896D-8D8E04863DC9} [2013/01/20 09:13:03 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E2E3FE0B-6FBE-4A1E-AF47-BD5041A3624B} [2013/01/19 21:08:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{B966D18E-7F69-47D5-8401-8BA6A11669E6} [2013/01/19 19:33:46 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client [2013/01/19 09:51:27 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\Anvisoft [2013/01/19 09:51:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anvisoft [2013/01/19 09:51:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Anvisoft [2013/01/19 05:54:49 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\FixBee [2013/01/19 05:54:49 | 000,000,000 | ---D | C] -- C:\ProgramData\FixBee [2013/01/18 21:07:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{2E3324BA-5C42-4324-A5C6-7336F189E63C} [2013/01/18 14:39:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FixBee Disk Optimizer [2013/01/18 14:38:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FixBee [2013/01/18 14:38:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SRToolbar [2013/01/18 09:07:11 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{8EC434FA-420B-47B7-9554-BD9441DB3FFE} [2013/01/18 08:14:08 | 000,000,000 | ---D | C] -- C:\Windows\pss [2013/01/17 19:55:16 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\WinRAR [2013/01/17 19:55:15 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\DownTango [2013/01/17 19:55:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DownTango [2013/01/17 09:06:14 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{2CA50C82-3F07-4F48-9707-A62F0F77B23D} [2013/01/16 17:48:37 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{4A67868C-A839-44EC-B25E-87C83532E0DF} [2013/01/16 07:05:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard 5.6.5 [2013/01/16 05:48:02 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{18C7CAE6-2D57-42B1-B823-8C0E23BBA00C} [2013/01/15 09:13:53 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{D8C64BCE-62CF-4985-90EC-1082D4CA5EF3} [2013/01/14 15:29:14 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E3C4DD56-2019-4342-B117-6974C6D81EEC} [2013/01/13 04:56:07 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{1E9789FD-D1E5-4F0A-8197-3C96A6246FC6} [2013/01/12 10:29:12 | 000,000,000 | ---D | C] -- C:\Users\Deb\Desktop\Good_morning! [2013/01/12 08:22:48 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{D5C04CAA-7B0D-46DC-A43D-5A8934F1A00A} [2013/01/11 16:37:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{86AE18EA-D2D7-4F78-A316-559CD87554C6} [2013/01/11 04:37:23 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{38263396-8971-473D-9686-D9E0B043A04E} [2013/01/10 07:19:53 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{66363DFD-6584-42C3-ABF6-26DF6393D0A3} [2013/01/09 08:03:43 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{21D7C0B8-0255-4EBE-95C2-63E2609F7963} [2013/01/08 07:54:44 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{08D71E41-6BCB-4D7E-8115-90912FEFFEDF} [2013/01/07 06:58:03 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{AC76A610-688C-47B5-9263-19DF34042B56} [2008/08/11 22:45:20 | 000,155,648 | ---- | C] (ASUS) -- C:\Program Files (x86)\Common Files\MSIactionall.dll [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2013/02/05 11:54:10 | 000,000,803 | ---- | M] () -- C:\Users\Deb\Desktop\fixme.zip [2013/02/05 11:50:00 | 000,002,098 | ---- | M] () -- C:\Users\Deb\Desktop\FIXME.reg [2013/02/05 11:35:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013/02/05 11:35:00 | 000,000,314 | ---- | M] () -- C:\Windows\tasks\PrintProjects Communicator.job [2013/02/05 11:23:54 | 000,000,780 | ---- | M] () -- C:\Users\Deb\Desktop\System Look.lnk [2013/02/05 11:10:00 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2013/02/05 10:10:00 | 000,000,888 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2013/02/05 09:49:10 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013/02/05 09:49:10 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013/02/05 09:44:25 | 000,165,376 | ---- | M] () -- C:\Users\Deb\Desktop\SystemLook_x64.exe [2013/02/05 08:34:00 | 000,000,490 | ---- | M] () -- C:\Windows\tasks\03-31-2011_103440.job [2013/02/05 06:19:40 | 000,792,550 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013/02/05 06:19:40 | 000,669,298 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013/02/05 06:19:40 | 000,125,452 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013/02/05 06:18:27 | 000,000,344 | ---- | M] () -- C:\Windows\lgfwup.ini [2013/02/05 06:15:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013/02/05 06:15:00 | 3193,765,888 | -HS- | M] () -- C:\hiberfil.sys [2013/02/05 05:34:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Deb\Desktop\OTL.exe [2013/02/05 04:46:09 | 000,001,110 | ---- | M] () -- C:\Users\Deb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2013/02/05 04:45:53 | 000,000,930 | ---- | M] () -- C:\Users\Deb\Desktop\NTREGOPT.lnk [2013/02/05 04:45:53 | 000,000,911 | ---- | M] () -- C:\Users\Deb\Desktop\ERUNT.lnk [2013/02/05 04:33:09 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\Deb\Desktop\erunt-setup.exe [2013/02/05 04:30:17 | 000,000,048 | ---- | M] () -- C:\Windows\wininit.ini [2013/02/01 07:38:01 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2013/02/01 07:36:25 | 010,156,344 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Deb\Desktop\mbam-setup-1.70.0.1100.exe [2013/01/20 06:30:57 | 000,010,841 | ---- | M] () -- C:\Users\Deb\Documents\paisley.pat [2013/01/18 14:39:04 | 000,000,997 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FixBee Disk Optimizer.lnk [2013/01/18 14:39:03 | 000,002,057 | ---- | M] () -- C:\Users\Public\Desktop\FixBee Disk Optimizer.lnk [2013/01/18 09:41:22 | 000,001,056 | ---- | M] () -- C:\prefs.js [2013/01/17 19:55:01 | 000,000,000 | ---- | M] () -- C:\end [2013/01/17 19:54:59 | 000,000,000 | ---- | M] () -- C:\extensions.sqlite [2013/01/17 19:53:11 | 000,002,236 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Snagit 10.lnk [2013/01/17 19:53:11 | 000,001,897 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\TOSHIBA DVD PLAYER.lnk [2013/01/17 19:53:11 | 000,001,448 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Wondershare DVD Slideshow Builder Standard.lnk [2013/01/17 19:53:11 | 000,001,385 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Wondershare Photo Collage Studio.lnk [2013/01/17 19:53:11 | 000,001,319 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Picture Collage Maker.lnk [2013/01/17 19:53:11 | 000,001,303 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk [2013/01/17 19:53:11 | 000,001,279 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Pixpedia Publisher.lnk [2013/01/17 19:53:11 | 000,001,213 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Copy Pro.lnk [2013/01/17 19:53:11 | 000,001,085 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\XnView.lnk [2013/01/17 19:53:11 | 000,000,955 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Spyware Terminator.lnk [2013/01/17 19:53:11 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Xara3D6.lnk [2013/01/17 19:53:11 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\RegistryBooster.lnk [2013/01/17 19:53:11 | 000,000,426 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk [2013/01/17 19:53:11 | 000,000,408 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk [2013/01/17 19:53:10 | 000,002,825 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Jasc Paint Shop Pro 9.lnk [2013/01/17 19:53:10 | 000,002,813 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Jasc Paint Shop Pro 9 (1).lnk [2013/01/17 19:53:10 | 000,002,381 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [2013/01/17 19:53:10 | 000,002,300 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\mediAvatar Photo to Flash.lnk [2013/01/17 19:53:10 | 000,002,116 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Express.lnk [2013/01/17 19:53:10 | 000,001,579 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [2013/01/17 19:53:10 | 000,001,315 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Free GMT AVI to DVD.lnk [2013/01/17 19:53:10 | 000,001,238 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk [2013/01/17 19:53:10 | 000,001,145 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\MiPony.lnk [2013/01/17 19:53:10 | 000,001,109 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\NeoPaint.lnk [2013/01/17 19:53:10 | 000,001,006 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk [2013/01/17 19:53:10 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk [2013/01/17 19:53:10 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Log Analysis - Sax2.lnk [2013/01/17 19:53:10 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Intrusion Detection System - Sax2.lnk [2013/01/17 19:53:09 | 000,002,231 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Corel Paint Shop Pro X.lnk [2013/01/17 19:53:09 | 000,001,498 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Batch Photo Watermarker.lnk [2013/01/17 19:53:09 | 000,001,362 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\ConvertXtoDVD 4.lnk [2013/01/17 19:53:09 | 000,001,265 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FoxTab AVI Converter.lnk [2013/01/17 19:53:09 | 000,001,259 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Free Easy Burner.lnk [2013/01/17 19:53:09 | 000,001,221 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FinalTorrent.lnk [2013/01/17 19:53:09 | 000,001,214 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\easyQuizzy.lnk [2013/01/17 19:53:09 | 000,001,149 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\DVD Shrink 3.2.lnk [2013/01/17 19:53:09 | 000,001,149 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\BatchInpaint.lnk [2013/01/17 19:53:09 | 000,001,119 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\CollageIt.lnk [2013/01/17 19:53:08 | 000,002,584 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Aiseesoft Total Media Converter.lnk [2013/01/17 19:53:08 | 000,002,344 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions.lnk [2013/01/17 19:53:08 | 000,002,325 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\4Media Photo Slideshow Maker.lnk [2013/01/17 19:53:08 | 000,002,269 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\4Media Ringtone Maker.lnk [2013/01/17 19:53:08 | 000,001,254 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\AnyPic Image Resizer Pro.lnk [2013/01/17 19:53:08 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 2010 Advanced.lnk [2013/01/17 19:24:50 | 000,045,169 | ---- | M] () -- C:\Users\Deb\Desktop\PolkaDot_Baby_Blanket.pdf [2013/01/11 04:33:21 | 005,620,584 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013/01/10 07:42:38 | 000,786,766 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI [1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ] [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ] ========== Files Created - No Company Name ========== [2013/02/05 11:57:15 | 000,002,098 | ---- | C] () -- C:\Users\Deb\Desktop\FIXME.reg [2013/02/05 11:54:10 | 000,000,803 | ---- | C] () -- C:\Users\Deb\Desktop\fixme.zip [2013/02/05 11:23:54 | 000,000,780 | ---- | C] () -- C:\Users\Deb\Desktop\System Look.lnk [2013/02/05 09:44:23 | 000,165,376 | ---- | C] () -- C:\Users\Deb\Desktop\SystemLook_x64.exe [2013/02/05 04:46:09 | 000,001,110 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk [2013/02/05 04:35:05 | 000,000,930 | ---- | C] () -- C:\Users\Deb\Desktop\NTREGOPT.lnk [2013/02/05 04:35:05 | 000,000,911 | ---- | C] () -- C:\Users\Deb\Desktop\ERUNT.lnk [2013/02/05 04:30:17 | 000,000,048 | ---- | C] () -- C:\Windows\wininit.ini [2013/02/01 07:38:01 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2013/01/20 06:30:57 | 000,010,841 | ---- | C] () -- C:\Users\Deb\Documents\paisley.pat [2013/01/18 14:39:04 | 000,000,997 | ---- | C] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FixBee Disk Optimizer.lnk [2013/01/18 14:39:03 | 000,002,057 | ---- | C] () -- C:\Users\Public\Desktop\FixBee Disk Optimizer.lnk [2013/01/17 19:54:59 | 000,000,000 | ---- | C] () -- C:\extensions.sqlite [2013/01/17 19:54:50 | 000,000,000 | ---- | C] () -- C:\end [2013/01/17 19:53:13 | 000,015,360 | ---- | C] () -- C:\Windows\Launcher.exe [2013/01/17 19:24:49 | 000,045,169 | ---- | C] () -- C:\Users\Deb\Desktop\PolkaDot_Baby_Blanket.pdf [2012/08/20 09:46:35 | 000,384,844 | ---- | C] () -- C:\Users\Deb\AppData\Local\funmoods-speeddial.crx [2012/08/12 08:45:52 | 000,004,470 | ---- | C] () -- C:\Users\Deb\pspbrwse.jbf [2012/04/06 14:07:58 | 000,000,344 | ---- | C] () -- C:\Windows\lgfwup.ini [2011/11/27 07:09:54 | 000,161,694 | ---- | C] () -- C:\Windows\Animated Wallpaper Maker Uninstaller.exe [2011/11/13 13:30:25 | 000,000,288 | ---- | C] () -- C:\Windows\ODBC.INI [2011/11/13 13:30:24 | 000,001,644 | ---- | C] () -- C:\Windows\ODBCINST.INI [2011/10/05 08:31:08 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini [2011/10/05 08:31:07 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll [2011/10/05 08:31:07 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll [2011/09/28 04:49:43 | 000,087,040 | ---- | C] () -- C:\Windows\UnGins.exe [2011/08/15 12:34:07 | 000,044,544 | ---- | C] () -- C:\Windows\SysWow64\gif89.dll [2011/08/15 12:33:54 | 000,000,285 | ---- | C] () -- C:\Windows\SIERRA.INI [2011/08/15 04:20:07 | 000,007,597 | ---- | C] () -- C:\Users\Deb\AppData\Local\Resmon.ResmonCfg [2011/08/06 03:20:57 | 000,161,807 | ---- | C] () -- C:\Windows\Animated Screensaver Maker Uninstaller.exe [2011/07/11 13:27:17 | 000,026,000 | ---- | C] () -- C:\Windows\SysWow64\PteVideo.dll [2011/07/01 06:16:12 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini [2011/05/21 03:16:40 | 000,162,598 | ---- | C] () -- C:\Windows\DP Animation Maker Uninstaller.exe [2011/04/23 06:19:51 | 000,027,648 | R--- | C] () -- C:\Windows\Setup_ck.exe [2011/04/23 06:19:51 | 000,024,608 | ---- | C] () -- C:\Windows\SysWow64\Ckldrv.sys [2011/04/23 06:19:51 | 000,018,432 | ---- | C] () -- C:\Windows\Setup_ck.dll [2011/04/23 06:19:51 | 000,011,776 | ---- | C] () -- C:\Windows\Ckrfresh.exe [2011/04/20 09:44:49 | 000,000,368 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\wklnhst.dat [2011/03/23 16:54:15 | 000,786,766 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/03/18 16:13:04 | 000,000,042 | ---- | C] () -- C:\Windows\PCSPATS.DAT [2011/02/19 19:42:30 | 000,000,091 | ---- | C] () -- C:\Windows\Crypkey.ini [2010/12/21 10:06:03 | 000,000,069 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\IncrediMail Collection ManagerIcm.ini [2010/12/19 11:55:26 | 000,001,057 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\vso_ts_preview.xml [2010/12/15 12:16:53 | 000,035,840 | ---- | C] () -- C:\Users\Deb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/12/15 11:14:41 | 000,000,080 | -HS- | C] () -- C:\ProgramData\.zreglib [2010/12/11 13:35:07 | 019,985,265 | ---- | C] () -- C:\ProgramData\vlc-1.1.5-win32.exe [2009/04/08 11:31:56 | 000,106,496 | ---- | C] () -- C:\Program Files (x86)\Common Files\CPInstallAction.dll [2009/03/27 10:14:04 | 000,033,940 | ---- | C] () -- C:\Users\Deb\qotw.jpg [2009/03/22 13:46:48 | 000,016,769 | ---- | C] () -- C:\Users\Deb\flowers.PLC [2009/03/03 11:32:32 | 000,705,558 | ---- | C] () -- C:\Users\Deb\QBD_-_LaceBorderNFramesScripts.zip [2009/02/16 19:30:54 | 000,658,608 | ---- | C] () -- C:\Program Files (x86)\MagicDVDRipper.exe [2009/02/09 11:56:30 | 000,313,344 | ---- | C] () -- C:\Program Files (x86)\hjsplit.exe [2009/01/18 08:46:29 | 000,001,024 | ---- | C] () -- C:\Users\Deb\.rnd [2008/05/22 09:35:54 | 000,051,962 | ---- | C] () -- C:\Program Files (x86)\Common Files\banner.jpg [2006/11/02 06:50:50 | 000,000,174 | -HS- | C] () -- C:\Program Files (x86)\desktop (1).ini ========== ZeroAccess Check ========== [2011/07/03 14:29:46 | 000,000,000 | ---D | M] -- C:\$Recycle.bin\S-1-5-21-4070860634-2794675311-1628887733-1000\$ROXZ5D7\L [2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 23:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 19:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 06:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 19:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] ========== LOP Check ========== [2011/04/27 17:18:59 | 000,000,000 | -HSD | M] -- C:\Users\Deb\AppData\Roaming\.# [2012/03/30 12:58:05 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\4Media [2013/01/19 19:38:06 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Anvisoft [2011/07/03 04:19:51 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\AnyPic Image Converter [2011/05/08 10:59:39 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\AnyPic Image Resizer Pro [2013/02/02 09:31:42 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\ArcticLine [2012/01/09 07:02:50 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Ashampoo [2011/11/14 13:03:49 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\BlitzCards [2011/06/21 08:31:19 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Byngo [2011/06/27 14:30:19 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\calibre [2011/11/19 09:21:55 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2011/10/28 05:57:48 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Digiarty [2010/12/17 12:55:31 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\DVDVideoSoft [2011/03/28 05:24:17 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Engelmann Media [2011/02/02 14:12:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\FinalTorrent [2013/01/19 19:48:35 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\FixBee [2012/03/30 12:58:05 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\FreeBurner [2011/02/01 19:03:46 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\gmt_free_avi_to_dvd [2010/12/10 13:18:51 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\HiYo [2010/12/11 20:29:08 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\ImageBadger [2010/12/21 10:06:03 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\IncrediMail Collection Manager [2011/04/23 05:54:59 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\IObit [2010/12/15 10:02:00 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Jasc [2011/04/10 04:32:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Leawo [2011/12/25 05:54:56 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\LifeSniffer [2011/04/03 05:29:09 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\mediAvatar [2011/12/14 16:38:12 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Mipony [2011/02/18 17:55:10 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Mobipocket [2011/04/10 04:32:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Moyea [2011/12/03 06:19:44 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Nik Software [2012/10/12 05:02:38 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Nuclear Coffee [2012/04/08 06:07:10 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PearlMountain [2011/04/27 18:09:56 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PearlMountainSoft [2011/01/18 15:25:42 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Pixpedia Publisher [2012/10/12 14:11:08 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PlayFirst [2011/04/10 04:32:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PPT2DVD [2011/10/05 08:54:49 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\QuizResultsAnalyzer.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1 [2012/08/20 09:46:30 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\SendSpace [2011/06/14 07:04:49 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Softplicity [2011/11/12 22:18:28 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Solveig Multimedia [2012/05/30 10:37:07 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Temp [2010/12/28 12:10:38 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Template [2011/10/15 13:45:53 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Thinstall [2011/08/01 17:33:44 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Tibo Software [2011/04/06 14:52:04 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Titanium Gears [2012/06/06 06:39:18 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Visan [2011/04/20 06:00:25 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\visualsearchpony.com [2010/12/19 11:56:10 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Vso [2010/12/10 13:55:37 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\WeatherBug [2010/12/10 13:26:42 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Windows Live Writer [2012/01/30 08:02:39 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\XnView ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:22741C1F @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:A31FAD21 < End of report > Quote
debi239 Posted February 5, 2013 Author Posted February 5, 2013 Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.02.01.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Deb :: DEB-PC [administrator] 2/5/2013 12:19:41 PM mbam-log-2013-02-05 (12-19-41).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 224280 Time elapsed: 5 minute(s), 43 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) Quote
debi239 Posted February 5, 2013 Author Posted February 5, 2013 The scan and Step 4 is on page 2. Thank you so very much for your patience and help. Debbie Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.